Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:27:48, on 19.8.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programy\Avast4\aswUpdSv.exe
C:\Programy\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programy\Avast4\ashDisp.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programy\DAEMON Tools Pro\DTProAgent.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Programy\Avast4\ashMaiSv.exe
C:\Programy\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://longtailvideo.ourtoolbar.com/SetupFinish
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Roman\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\Programy\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Programy\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKCU\..\RunOnce: [WiseStubReboot] MSIEXEC /quiet SKIP_PPU_DRIVER_INSTALL=1 /I "C:\Program Files\Common Files\Wise Installation Wizard\WISDD1865F0AD7340FBB23E1822E02396FF_9_09_0203.MSI" TRANSFORMS="C:\Program Files\Common Files\Wise Installation Wizard\WISDD1865F0AD7340FBB23E1822E02396FF_9_09_0203.MST" WISE_SETUP_EXE_PATH="f:\driver\2k_xp\182.06\PhysX_9.09.0203_SystemSoftware.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\Programy\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programy\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: QIP Infium - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP Infium\infium.exe (HKCU)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programy\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programy\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programy\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programy\Avast4\ashWebSv.exe
O23 - Service: NBService - Nero AG - C:\Programy\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
--
End of file - 5589 bytes
Prosím o kontrolu logu
Prosím o kontrolu logu
KINGSTON 4GB RAM | nVIDIA GeForce GTX 560 | Intel Core2 Quad Q8400 @ 2.67GHz | LCPOWER 600W | Gigabyte GA-EP35-DS4 | SAMSUNG SpinPoint F3 1000Gb, Hitachi 500GB | W7
Re: Prosím o kontrolu logu
Aky mame problem? :)
Stiahni DDS. Uloz na plochu, ukonci vsetky spustene programy a spust ho. Po skonceni scanu sa otvoria vysledky v 2 oknach - DDS.txt a Attach.txt. Vloz sem obsah DDS.txt.
Stiahni DDS. Uloz na plochu, ukonci vsetky spustene programy a spust ho. Po skonceni scanu sa otvoria vysledky v 2 oknach - DDS.txt a Attach.txt. Vloz sem obsah DDS.txt.
Nemam rad amaterizmus...
A adresat odkazu to vie :)
A adresat odkazu to vie :)
Re: Prosím o kontrolu logu
DDS (Ver_09-07-30.01) - NTFSx86
Run by Roman at 14:02:31,37 on źt 20.08.2009
Internet Explorer: 6.0.2900.5512
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2046.1599 [GMT 2:00]
AV: avast! antivirus 4.8.1335 [VPS 090819-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Programy\Avast4\aswUpdSv.exe
C:\Programy\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programy\Avast4\ashDisp.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programy\DAEMON Tools Pro\DTProAgent.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Programy\Avast4\ashMaiSv.exe
C:\Programy\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Xfire\Xfire.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Documents and Settings\Roman\Plocha\dds.pif
============== Pseudo HJT Report ===============
uSearch Page = hxxp://search.qip.ru
uDefault_Page_URL = hxxp://search.qip.ru
uDefault_Search_URL = hxxp://search.qip.ru
uSearch Bar = hxxp://search.qip.ru/ie
uInternet Connection Wizard,ShellNext = hxxp://longtailvideo.ourtoolbar.com/SetupFinish
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
uURLSearchHooks: H - No File
BHO: Podpora odkazu pro Adobe PDF Reader: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: QIPBHO Class: {a55f9c95-2bb1-4ea2-bc77-dfaab78832ce} - c:\documents and settings\roman\data aplikací\microsoft\internet explorer\qipsearchbar.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [DAEMON Tools Pro Agent] "c:\programy\daemon tools pro\DTProAgent.exe"
uRunOnce: [WiseStubReboot] MSIEXEC /quiet SKIP_PPU_DRIVER_INSTALL=1 /I "c:\program files\common files\wise installation wizard\wisdd1865f0ad7340fbb23e1822e02396ff_9_09_0203.msi" transforms="c:\program files\common files\wise installation wizard\wisdd1865f0ad7340fbb23e1822e02396ff_9_09_0203.mst" wise_setup_exe_path="f:\driver\2k_xp\182.06\PhysX_9.09.0203_SystemSoftware.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [JMB36X IDE Setup] c:\windows\raidtool\xInsIDE.exe
mRun: [36X Raid Configurer] c:\windows\system32\xRaidSetup.exe boot
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [avast!] c:\programy\avast4\ashDisp.exe
mRun: [CHotkey] mHotkey.exe
mRun: [Easy-PrintToolBox] c:\program files\canon\easy-printtoolbox\BJPSMAIN.EXE /logon
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: E&xportovat do aplikace Microsoft Excel - c:\programy\micros~1\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\programy\micros~1\office12\REFIEBAR.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\roman\dataap~1\mozilla\firefox\profiles\sz3li4fv.default\
FF - prefs.js: browser.search.selectedEngine - QIP Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - plugin: c:\programy\reader 8.0\reader\browser\nppdf32.dll
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.XMLHttpRequest.channel", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.SOAPEncoding.schemaCollection", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.default.XMLHttpRequest.channel", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("security.checkloaduri", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("bidi.characterset", 1);
c:\program files\mozilla firefox\defaults\pref\channel-prefs.js - pref("app.update.channel", "release");
c:\program files\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-8-14 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-8-14 20560]
R2 avast! Antivirus;avast! Antivirus;c:\programy\avast4\ashServ.exe [2009-8-14 138680]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\programy\avast4\ashMaiSv.exe [2009-8-14 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\programy\avast4\ashWebSv.exe [2009-8-14 352920]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [2004-8-3 69120]
=============== Created Last 30 ================
2009-08-20 14:01 <DIR> --d-h--- c:\windows\PIF
2009-08-20 13:22 <DIR> --d----- c:\program files\SteelSeries Ikari Laser
2009-08-19 22:55 189,768 a------- c:\windows\system32\PnkBstrB.xtr
2009-08-19 20:27 <DIR> --d----- c:\program files\Trend Micro
2009-08-19 18:06 <DIR> --d----- c:\program files\QIP1
2009-08-19 17:56 <DIR> --d----- c:\docume~1\roman\dataap~1\QIP
2009-08-19 17:56 <DIR> --d----- c:\program files\QIP Infium
2009-08-19 14:20 <DIR> --d----- c:\program files\uTorrent
2009-08-19 14:20 <DIR> --d----- c:\docume~1\roman\dataap~1\uTorrent
2009-08-16 22:42 309 a------- c:\windows\game.ini
2009-08-16 22:37 <DIR> --d----- c:\docume~1\roman\dataap~1\Xfire
2009-08-16 22:37 <DIR> --d----- c:\program files\Xfire
2009-08-16 22:25 <DIR> --dsh--- c:\windows\ftpcache
2009-08-16 21:45 34,064 a------- c:\windows\system32\lhacm.acm
2009-08-16 21:45 <DIR> --d----- c:\program files\Teamspeak2_RC2
2009-08-16 20:27 198,656 a------- c:\windows\system32\CNMLM8N.DLL
2009-08-16 20:26 <DIR> --d----- c:\program files\Canon
2009-08-16 20:03 <DIR> --d----- c:\program files\Microsoft Games for Windows - LIVE
2009-08-16 19:14 56 a---h--- c:\windows\system32\ezsidmv.dat
2009-08-16 19:11 <DIR> --d--r-- c:\program files\Skype
2009-08-16 18:43 107,888 a------- c:\windows\system32\CmdLineExt.dll
2009-08-16 18:40 22,328 a------- c:\windows\system32\drivers\PnkBstrK.sys
2009-08-16 18:40 22,328 a------- c:\docume~1\roman\dataap~1\PnkBstrK.sys
2009-08-16 18:40 103,736 a------- c:\windows\system32\PnkBstrB.exe
2009-08-16 18:40 2,250,024 a------- c:\windows\system32\pbsvc.exe
2009-08-16 18:40 75,064 a------- c:\windows\system32\PnkBstrA.exe
2009-08-16 16:28 25,856 ac------ c:\windows\system32\dllcache\usbprint.sys
2009-08-16 16:28 25,856 a------- c:\windows\system32\drivers\usbprint.sys
2009-08-16 15:24 4,308 a------- c:\windows\NT4_98.reg
2009-08-16 15:24 4,290 a------- c:\windows\MeXP.reg
2009-08-16 15:24 490 a------- c:\windows\Instit.ini
2009-08-16 15:24 547,840 a------- c:\windows\mHotkey.exe
2009-08-16 15:24 294,912 a------- c:\windows\PIC.dll
2009-08-16 15:24 233,472 a------- c:\windows\InstIt.exe
2009-08-16 15:24 24,576 a------- c:\windows\HKNTDLL.dll
2009-08-16 15:24 5,280 a------- c:\windows\hotbtnv.vxd
2009-08-16 15:24 4,306 a------- c:\windows\2K.reg
2009-08-16 15:24 4,290 a------- c:\windows\Other.reg
2009-08-16 15:24 <DIR> --d----- c:\program files\KYE
2009-08-15 13:05 26,368 ac------ c:\windows\system32\dllcache\usbstor.sys
2009-08-15 11:35 <DIR> --d----- c:\docume~1\roman\dataap~1\Pharaohs Secret
2009-08-15 00:59 3,072 a------- c:\windows\system32\drivers\audstub.sys
2009-08-15 00:59 21,504 a------- c:\windows\system32\hidserv.dll
2009-08-15 00:59 23,040 a------- c:\windows\system32\drivers\mouclass.sys
2009-08-15 00:59 12,160 a------- c:\windows\system32\drivers\mouhid.sys
2009-08-15 00:59 58,496 a------- c:\windows\system32\drivers\redbook.sys
2009-08-15 00:58 6,400 a------- c:\windows\system32\drivers\enum1394.sys
2009-08-15 00:58 75,264 a------- c:\windows\system32\usbui.dll
2009-08-15 00:57 <DIR> --d----- c:\program files\common files\ODBC
2009-08-15 00:57 <DIR> --d----- c:\program files\common files\SpeechEngines
2009-08-15 00:57 <DIR> --d-h--- c:\documents and settings\all users\Šablony
2009-08-15 00:57 <DIR> --d--r-- c:\documents and settings\all users\Nabídka Start
2009-08-15 00:57 <DIR> --d--r-- c:\documents and settings\all users\Dokumenty
2009-08-15 00:57 <DIR> --d----- c:\documents and settings\all users\Plocha
2009-08-15 00:57 <DIR> --d----- c:\documents and settings\all users\Oblíbené položky
2009-08-15 00:55 1,014,483 ac------ c:\windows\system32\dllcache\SP2.CAT
2009-08-15 00:55 <DIR> --d-hr-- c:\documents and settings\all users\Data aplikací
2009-08-15 00:54 <DIR> --d----- C:\Documents and Settings
2009-08-15 00:53 261 a------- c:\windows\system32\$winnt$.inf
2009-08-14 23:15 <DIR> --d----- c:\program files\Realtek
2009-08-14 23:09 <DIR> --d-hr-- c:\documents and settings\roman\Data aplikací
2009-08-14 23:09 <DIR> --d-h--- c:\documents and settings\roman\Okolní tiskárny
2009-08-14 23:09 <DIR> --d-h--- c:\documents and settings\roman\Okolní síť
2009-08-14 23:09 <DIR> --d-h--- c:\documents and settings\roman\Šablony
2009-08-14 23:09 <DIR> --d--r-- c:\documents and settings\roman\Oblíbené položky
2009-08-14 23:09 <DIR> --d--r-- c:\documents and settings\roman\Nabídka Start
2009-08-14 23:09 <DIR> --d--r-- c:\documents and settings\roman\Dokumenty
2009-08-14 23:09 <DIR> --d----- c:\documents and settings\roman\Plocha
2009-08-14 23:06 <DIR> --dsh--- c:\documents and settings\all users\DRM
2009-08-14 23:05 <DIR> --d-h--- c:\program files\WindowsUpdate
2009-08-14 23:05 <DIR> --d----- c:\program files\Online Services
2009-08-14 23:05 <DIR> --d----- c:\program files\common files\MSSoap
2009-08-14 23:04 <DIR> --d----- c:\program files\Messenger
2009-08-14 23:04 <DIR> --d----- c:\program files\MSN Gaming Zone
2009-08-14 23:03 <DIR> --d----- c:\program files\Windows NT
2009-08-14 21:26 <DIR> --d----- c:\temp\LT
2009-08-14 21:22 <DIR> --d----- c:\documents and settings\roman\dwhelper
2009-08-14 21:20 <DIR> --d----- c:\program files\Morgan
2009-08-14 20:33 <DIR> --d----- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-08-14 19:46 <DIR> --d----- c:\docume~1\roman\dataap~1\Playrix Entertainment
2009-08-14 19:40 <DIR> --d----- c:\docume~1\alluse~1\dataap~1\MinigolfAdventures
2009-08-14 19:39 <DIR> --d----- c:\program files\common files\Oberon Media
2009-08-14 19:39 <DIR> --d----- c:\program files\Gamenext
2009-08-14 18:18 <DIR> --d----- c:\program files\Microsoft Visual Studio 8
2009-08-14 18:07 <DIR> --d----- c:\docume~1\roman\dataap~1\DAEMON Tools Pro
2009-08-14 18:07 <DIR> --d----- c:\docume~1\alluse~1\dataap~1\DAEMON Tools Pro
2009-08-14 17:53 <DIR> --d----- c:\program files\ConvertHelper
2009-08-14 17:34 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
==================== Find3M ====================
2009-08-14 23:23 16,608 a------- c:\windows\gdrv.sys
2009-08-14 23:15 315,392 a------- c:\windows\HideWin.exe
2009-08-14 23:04 21,812 a------- c:\windows\system32\emptyregdb.dat
2009-08-14 21:13 428,750 a------- c:\windows\system32\perfh005.dat
2009-08-14 21:13 77,872 a------- c:\windows\system32\perfc005.dat
2009-08-14 20:31 219,648 a------- c:\windows\system32\uxtheme.dll
2009-08-14 20:31 65,701 a------- c:\windows\BricoPackUninst.cmd
2009-08-14 20:31 6,114 a------- c:\windows\BricoPackFoldersDelete.cmd
2009-08-14 19:04 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-08-14 18:03 685,816 a------- c:\windows\system32\drivers\sptd.sys
2009-08-13 21:53 41,872 a------- c:\windows\system32\xfcodec.dll
2009-07-29 06:36 119,808 a------- c:\windows\system32\t2embed.dll
2009-07-29 06:36 81,920 a------- c:\windows\system32\fontsub.dll
2009-07-17 21:04 58,880 a------- c:\windows\system32\atl.dll
2009-06-26 18:51 667,648 a------- c:\windows\system32\wininet.dll
2009-06-26 18:51 81,920 a------- c:\windows\system32\ieencode.dll
2009-06-15 12:45 78,336 a------- c:\windows\system32\telnet.exe
2009-06-15 12:45 81,408 a------- c:\windows\system32\tlntsess.exe
2009-06-10 16:15 84,992 a------- c:\windows\system32\avifil32.dll
2009-06-10 08:16 132,096 a------- c:\windows\system32\wkssvc.dll
2009-06-03 21:11 1,293,824 a------- c:\windows\system32\quartz.dll
============= FINISH: 14:02:46,07 ===============
Run by Roman at 14:02:31,37 on źt 20.08.2009
Internet Explorer: 6.0.2900.5512
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2046.1599 [GMT 2:00]
AV: avast! antivirus 4.8.1335 [VPS 090819-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Programy\Avast4\aswUpdSv.exe
C:\Programy\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programy\Avast4\ashDisp.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programy\DAEMON Tools Pro\DTProAgent.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Programy\Avast4\ashMaiSv.exe
C:\Programy\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Xfire\Xfire.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Documents and Settings\Roman\Plocha\dds.pif
============== Pseudo HJT Report ===============
uSearch Page = hxxp://search.qip.ru
uDefault_Page_URL = hxxp://search.qip.ru
uDefault_Search_URL = hxxp://search.qip.ru
uSearch Bar = hxxp://search.qip.ru/ie
uInternet Connection Wizard,ShellNext = hxxp://longtailvideo.ourtoolbar.com/SetupFinish
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
uURLSearchHooks: H - No File
BHO: Podpora odkazu pro Adobe PDF Reader: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: QIPBHO Class: {a55f9c95-2bb1-4ea2-bc77-dfaab78832ce} - c:\documents and settings\roman\data aplikací\microsoft\internet explorer\qipsearchbar.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [DAEMON Tools Pro Agent] "c:\programy\daemon tools pro\DTProAgent.exe"
uRunOnce: [WiseStubReboot] MSIEXEC /quiet SKIP_PPU_DRIVER_INSTALL=1 /I "c:\program files\common files\wise installation wizard\wisdd1865f0ad7340fbb23e1822e02396ff_9_09_0203.msi" transforms="c:\program files\common files\wise installation wizard\wisdd1865f0ad7340fbb23e1822e02396ff_9_09_0203.mst" wise_setup_exe_path="f:\driver\2k_xp\182.06\PhysX_9.09.0203_SystemSoftware.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [JMB36X IDE Setup] c:\windows\raidtool\xInsIDE.exe
mRun: [36X Raid Configurer] c:\windows\system32\xRaidSetup.exe boot
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [avast!] c:\programy\avast4\ashDisp.exe
mRun: [CHotkey] mHotkey.exe
mRun: [Easy-PrintToolBox] c:\program files\canon\easy-printtoolbox\BJPSMAIN.EXE /logon
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: E&xportovat do aplikace Microsoft Excel - c:\programy\micros~1\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\programy\micros~1\office12\REFIEBAR.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\roman\dataap~1\mozilla\firefox\profiles\sz3li4fv.default\
FF - prefs.js: browser.search.selectedEngine - QIP Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - plugin: c:\programy\reader 8.0\reader\browser\nppdf32.dll
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.XMLHttpRequest.channel", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.SOAPEncoding.schemaCollection", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.default.XMLHttpRequest.channel", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("security.checkloaduri", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("bidi.characterset", 1);
c:\program files\mozilla firefox\defaults\pref\channel-prefs.js - pref("app.update.channel", "release");
c:\program files\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-8-14 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-8-14 20560]
R2 avast! Antivirus;avast! Antivirus;c:\programy\avast4\ashServ.exe [2009-8-14 138680]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\programy\avast4\ashMaiSv.exe [2009-8-14 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\programy\avast4\ashWebSv.exe [2009-8-14 352920]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [2004-8-3 69120]
=============== Created Last 30 ================
2009-08-20 14:01 <DIR> --d-h--- c:\windows\PIF
2009-08-20 13:22 <DIR> --d----- c:\program files\SteelSeries Ikari Laser
2009-08-19 22:55 189,768 a------- c:\windows\system32\PnkBstrB.xtr
2009-08-19 20:27 <DIR> --d----- c:\program files\Trend Micro
2009-08-19 18:06 <DIR> --d----- c:\program files\QIP1
2009-08-19 17:56 <DIR> --d----- c:\docume~1\roman\dataap~1\QIP
2009-08-19 17:56 <DIR> --d----- c:\program files\QIP Infium
2009-08-19 14:20 <DIR> --d----- c:\program files\uTorrent
2009-08-19 14:20 <DIR> --d----- c:\docume~1\roman\dataap~1\uTorrent
2009-08-16 22:42 309 a------- c:\windows\game.ini
2009-08-16 22:37 <DIR> --d----- c:\docume~1\roman\dataap~1\Xfire
2009-08-16 22:37 <DIR> --d----- c:\program files\Xfire
2009-08-16 22:25 <DIR> --dsh--- c:\windows\ftpcache
2009-08-16 21:45 34,064 a------- c:\windows\system32\lhacm.acm
2009-08-16 21:45 <DIR> --d----- c:\program files\Teamspeak2_RC2
2009-08-16 20:27 198,656 a------- c:\windows\system32\CNMLM8N.DLL
2009-08-16 20:26 <DIR> --d----- c:\program files\Canon
2009-08-16 20:03 <DIR> --d----- c:\program files\Microsoft Games for Windows - LIVE
2009-08-16 19:14 56 a---h--- c:\windows\system32\ezsidmv.dat
2009-08-16 19:11 <DIR> --d--r-- c:\program files\Skype
2009-08-16 18:43 107,888 a------- c:\windows\system32\CmdLineExt.dll
2009-08-16 18:40 22,328 a------- c:\windows\system32\drivers\PnkBstrK.sys
2009-08-16 18:40 22,328 a------- c:\docume~1\roman\dataap~1\PnkBstrK.sys
2009-08-16 18:40 103,736 a------- c:\windows\system32\PnkBstrB.exe
2009-08-16 18:40 2,250,024 a------- c:\windows\system32\pbsvc.exe
2009-08-16 18:40 75,064 a------- c:\windows\system32\PnkBstrA.exe
2009-08-16 16:28 25,856 ac------ c:\windows\system32\dllcache\usbprint.sys
2009-08-16 16:28 25,856 a------- c:\windows\system32\drivers\usbprint.sys
2009-08-16 15:24 4,308 a------- c:\windows\NT4_98.reg
2009-08-16 15:24 4,290 a------- c:\windows\MeXP.reg
2009-08-16 15:24 490 a------- c:\windows\Instit.ini
2009-08-16 15:24 547,840 a------- c:\windows\mHotkey.exe
2009-08-16 15:24 294,912 a------- c:\windows\PIC.dll
2009-08-16 15:24 233,472 a------- c:\windows\InstIt.exe
2009-08-16 15:24 24,576 a------- c:\windows\HKNTDLL.dll
2009-08-16 15:24 5,280 a------- c:\windows\hotbtnv.vxd
2009-08-16 15:24 4,306 a------- c:\windows\2K.reg
2009-08-16 15:24 4,290 a------- c:\windows\Other.reg
2009-08-16 15:24 <DIR> --d----- c:\program files\KYE
2009-08-15 13:05 26,368 ac------ c:\windows\system32\dllcache\usbstor.sys
2009-08-15 11:35 <DIR> --d----- c:\docume~1\roman\dataap~1\Pharaohs Secret
2009-08-15 00:59 3,072 a------- c:\windows\system32\drivers\audstub.sys
2009-08-15 00:59 21,504 a------- c:\windows\system32\hidserv.dll
2009-08-15 00:59 23,040 a------- c:\windows\system32\drivers\mouclass.sys
2009-08-15 00:59 12,160 a------- c:\windows\system32\drivers\mouhid.sys
2009-08-15 00:59 58,496 a------- c:\windows\system32\drivers\redbook.sys
2009-08-15 00:58 6,400 a------- c:\windows\system32\drivers\enum1394.sys
2009-08-15 00:58 75,264 a------- c:\windows\system32\usbui.dll
2009-08-15 00:57 <DIR> --d----- c:\program files\common files\ODBC
2009-08-15 00:57 <DIR> --d----- c:\program files\common files\SpeechEngines
2009-08-15 00:57 <DIR> --d-h--- c:\documents and settings\all users\Šablony
2009-08-15 00:57 <DIR> --d--r-- c:\documents and settings\all users\Nabídka Start
2009-08-15 00:57 <DIR> --d--r-- c:\documents and settings\all users\Dokumenty
2009-08-15 00:57 <DIR> --d----- c:\documents and settings\all users\Plocha
2009-08-15 00:57 <DIR> --d----- c:\documents and settings\all users\Oblíbené položky
2009-08-15 00:55 1,014,483 ac------ c:\windows\system32\dllcache\SP2.CAT
2009-08-15 00:55 <DIR> --d-hr-- c:\documents and settings\all users\Data aplikací
2009-08-15 00:54 <DIR> --d----- C:\Documents and Settings
2009-08-15 00:53 261 a------- c:\windows\system32\$winnt$.inf
2009-08-14 23:15 <DIR> --d----- c:\program files\Realtek
2009-08-14 23:09 <DIR> --d-hr-- c:\documents and settings\roman\Data aplikací
2009-08-14 23:09 <DIR> --d-h--- c:\documents and settings\roman\Okolní tiskárny
2009-08-14 23:09 <DIR> --d-h--- c:\documents and settings\roman\Okolní síť
2009-08-14 23:09 <DIR> --d-h--- c:\documents and settings\roman\Šablony
2009-08-14 23:09 <DIR> --d--r-- c:\documents and settings\roman\Oblíbené položky
2009-08-14 23:09 <DIR> --d--r-- c:\documents and settings\roman\Nabídka Start
2009-08-14 23:09 <DIR> --d--r-- c:\documents and settings\roman\Dokumenty
2009-08-14 23:09 <DIR> --d----- c:\documents and settings\roman\Plocha
2009-08-14 23:06 <DIR> --dsh--- c:\documents and settings\all users\DRM
2009-08-14 23:05 <DIR> --d-h--- c:\program files\WindowsUpdate
2009-08-14 23:05 <DIR> --d----- c:\program files\Online Services
2009-08-14 23:05 <DIR> --d----- c:\program files\common files\MSSoap
2009-08-14 23:04 <DIR> --d----- c:\program files\Messenger
2009-08-14 23:04 <DIR> --d----- c:\program files\MSN Gaming Zone
2009-08-14 23:03 <DIR> --d----- c:\program files\Windows NT
2009-08-14 21:26 <DIR> --d----- c:\temp\LT
2009-08-14 21:22 <DIR> --d----- c:\documents and settings\roman\dwhelper
2009-08-14 21:20 <DIR> --d----- c:\program files\Morgan
2009-08-14 20:33 <DIR> --d----- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-08-14 19:46 <DIR> --d----- c:\docume~1\roman\dataap~1\Playrix Entertainment
2009-08-14 19:40 <DIR> --d----- c:\docume~1\alluse~1\dataap~1\MinigolfAdventures
2009-08-14 19:39 <DIR> --d----- c:\program files\common files\Oberon Media
2009-08-14 19:39 <DIR> --d----- c:\program files\Gamenext
2009-08-14 18:18 <DIR> --d----- c:\program files\Microsoft Visual Studio 8
2009-08-14 18:07 <DIR> --d----- c:\docume~1\roman\dataap~1\DAEMON Tools Pro
2009-08-14 18:07 <DIR> --d----- c:\docume~1\alluse~1\dataap~1\DAEMON Tools Pro
2009-08-14 17:53 <DIR> --d----- c:\program files\ConvertHelper
2009-08-14 17:34 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
==================== Find3M ====================
2009-08-14 23:23 16,608 a------- c:\windows\gdrv.sys
2009-08-14 23:15 315,392 a------- c:\windows\HideWin.exe
2009-08-14 23:04 21,812 a------- c:\windows\system32\emptyregdb.dat
2009-08-14 21:13 428,750 a------- c:\windows\system32\perfh005.dat
2009-08-14 21:13 77,872 a------- c:\windows\system32\perfc005.dat
2009-08-14 20:31 219,648 a------- c:\windows\system32\uxtheme.dll
2009-08-14 20:31 65,701 a------- c:\windows\BricoPackUninst.cmd
2009-08-14 20:31 6,114 a------- c:\windows\BricoPackFoldersDelete.cmd
2009-08-14 19:04 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-08-14 18:03 685,816 a------- c:\windows\system32\drivers\sptd.sys
2009-08-13 21:53 41,872 a------- c:\windows\system32\xfcodec.dll
2009-07-29 06:36 119,808 a------- c:\windows\system32\t2embed.dll
2009-07-29 06:36 81,920 a------- c:\windows\system32\fontsub.dll
2009-07-17 21:04 58,880 a------- c:\windows\system32\atl.dll
2009-06-26 18:51 667,648 a------- c:\windows\system32\wininet.dll
2009-06-26 18:51 81,920 a------- c:\windows\system32\ieencode.dll
2009-06-15 12:45 78,336 a------- c:\windows\system32\telnet.exe
2009-06-15 12:45 81,408 a------- c:\windows\system32\tlntsess.exe
2009-06-10 16:15 84,992 a------- c:\windows\system32\avifil32.dll
2009-06-10 08:16 132,096 a------- c:\windows\system32\wkssvc.dll
2009-06-03 21:11 1,293,824 a------- c:\windows\system32\quartz.dll
============= FINISH: 14:02:46,07 ===============
KINGSTON 4GB RAM | nVIDIA GeForce GTX 560 | Intel Core2 Quad Q8400 @ 2.67GHz | LCPOWER 600W | Gigabyte GA-EP35-DS4 | SAMSUNG SpinPoint F3 1000Gb, Hitachi 500GB | W7
Re: Prosím o kontrolu logu
Mas nejaky konkretny problem, alebo ide len o preventivku?
Nemam rad amaterizmus...
A adresat odkazu to vie :)
A adresat odkazu to vie :)
Re: Prosím o kontrolu logu
Spíš o preventivku , protože mam nový pc a instaloval jsem tu nove programy atd... co myslíš je to v pořádku ?
KINGSTON 4GB RAM | nVIDIA GeForce GTX 560 | Intel Core2 Quad Q8400 @ 2.67GHz | LCPOWER 600W | Gigabyte GA-EP35-DS4 | SAMSUNG SpinPoint F3 1000Gb, Hitachi 500GB | W7
- Scary
- Level 2.5
- Příspěvky: 396
- Registrován: květen 09
- Bydliště: Čáslav
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: Prosím o kontrolu logu
Nech si radši poradit od zkušeného. Je vůbec rádce pověřen radění v olasti HJT? Moc se mi to nezdá, počkej na jaro3 nebo Dammed, až tu budou, tak ti určitě poradějí...
MSI GX620X - Windows 7 Ultimate 64bit | mouse: SteelSeries IKARI | headset: SteelSeries Siberia v2
Re: Prosím o kontrolu logu
Pocuj scary, uz som ti raz pisal, ze kvalifikaciu mam dostatocnu, ak si chces pokecat o tomto probleme, prosim. Ale cez SS, nespamuj thread. THX
@roady: Ak je teda vsetko OK, sprav nasledujuce:
Fixni v HJT (zasrktni stvorcek pri danom riadku a stlac "Fix Checked"):
Doinstaluj firewall a antispyware.
@roady: Ak je teda vsetko OK, sprav nasledujuce:
Fixni v HJT (zasrktni stvorcek pri danom riadku a stlac "Fix Checked"):
Kód: Vybrat vše
R3 - URLSearchHook: (no name) - - (no file)
Doinstaluj firewall a antispyware.
Nemam rad amaterizmus...
A adresat odkazu to vie :)
A adresat odkazu to vie :)
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 5 hostů