Prosím o kontrolu HJT- pomoc Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
pistabaci
Level 1
Level 1
Příspěvky: 92
Registrován: březen 07
Bydliště: Košice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu HJT- pomoc

Příspěvekod pistabaci » 13 zář 2009 23:25

dal si zle linky na download AVP Tool skusil som najst na googli je to Kaspersky Virus Removal Tool ?

Reklama
Uživatelský avatar
Damned
Tvůrce článků
Master Level 9
Master Level 9
Příspěvky: 8353
Registrován: prosinec 06
Bydliště: Rokycany
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu HJT- pomoc

Příspěvekod Damned » 13 zář 2009 23:51

Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner

Uživatelský avatar
pistabaci
Level 1
Level 1
Příspěvky: 92
Registrován: březen 07
Bydliště: Košice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu HJT- pomoc

Příspěvekod pistabaci » 14 zář 2009 12:21

posielam dalsi log , po 6 hod hladaní kaspersky virus removed nenasiel nič. Myslím si už že to nie je vír ale nejaké nastavenie ktoré sa pobabralo.

Scan
----
Scanned: 580775
Detected: 0
Untreated: 0
Start time: 14.9.2009 5:57:08
Duration: 06:04:18
Finish time: 14.9.2009 12:01:26


Detected
--------
Status Object
------ ------


Events
------
Time Name Status Reason
---- ---- ------ ------
14.9.2009 5:57:45 Running module: smss.exe\smss.exe ok scanned


Statistics
----------
Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted
------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ ---------


Settings
--------
Parameter Value
--------- -----
Security Level Recommended
Action Prompt for action when the scan is complete
Run mode Manually
File types Scan all files
Scan only new and changed files No
Scan archives All
Scan embedded OLE objects All
Skip if object is larger than No
Skip if scan takes longer than No
Parse email formats No
Scan password-protected archives No
Enable iChecker technology No
Enable iSwift technology No
Show detected threats on "Detected" tab Yes
Rootkits search Yes
Deep rootkits search No
Use heuristic analyzer Yes


Quarantine
----------
Status Object Size Added
------ ------ ---- -----


Backup
------
Status Object Size
------ ------ ----

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43287
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu HJT- pomoc

Příspěvekod jaro3 » 14 zář 2009 14:51

Najdi a smaž složku:
c:\windows\system32\ANTIWPA

ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix[mezera]/u

vyčisti systém CCleanerem

a použij i T-Cleaner
smaže vše po Combu,SDFixu,Avengeru,MWAVu atd.-stáhneš>spustíš

Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.


Stahni si SREng --System Repair Engineer
- rozbal na plochu a spust ho
- zvol "zvol Smart Scan", nech nastaveni tak jak je
- zvol "Verify the digital signature of process modules"
- klik na "Scan"
- klik na Save Reports, uloz log na plochu a cely obsah logu zkopirujt sem
- rozbal na plochu a spust ho
+
- Spusť ho a zvol možnost System Repair
- Na první záložce File Associations pokud bude zatrhnutý/vybraný některý čtvereček z výpisu, tak klikni dole na tlačítko Repair
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
pistabaci
Level 1
Level 1
Příspěvky: 92
Registrován: březen 07
Bydliště: Košice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu HJT- pomoc

Příspěvekod pistabaci » 14 zář 2009 17:04

2009-09-14,16:58:31

System Repair Engineer 2.8.1.1279
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 3 (Build 2600) - Administrative User - Completed Functions Allowed

Follow item(s) have been selected:
All Boot Items (Including Registry, Startup Folders, Services and so on)
Browser Add-ons
Running Processes (Including process model information)
File Associations
Winsock Provider
Autorun.Inf
HOSTS File
Process Privileges Scan
Scheduled Tasks
Windows Security Update Check
API HOOK
Hidden Process


Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<egui><"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice> [(Verified)"ESET, spol. s r.o."]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Component Publisher]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll> [(Verified)Microsoft Windows Component Publisher]
<{B5A7F190-DDA6-4420-B3BA-52453494E6CD}><C:\PROGRA~1\MICROS~2\Office12\GrooveShellExtensions.dll> [(Verified)Microsoft Corporation]
<{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}><C:\Program Files\SUPERAntiSpyware\SASSEH.DLL> [SuperAdBlocker.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<PostBootReminder><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher]
<CDBurn><%SystemRoot%\system32\SHELL32.dll> [(Verified)Microsoft Windows Component Publisher]
<WebCheck><C:\WINDOWS\system32\webcheck.dll> [(Verified)Microsoft Windows]
<SysTray><%systemroot%\system32\stobject.dll> [(Verified)Microsoft Windows Component Publisher]
<WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
<WinlogonNotify: !SASWinLogon><C:\Program Files\SUPERAntiSpyware\SASWINLO.dll> [SUPERAntiSpyware.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
<WinlogonNotify: crypt32chain><crypt32.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
<WinlogonNotify: cryptnet><cryptnet.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
<WinlogonNotify: cscdll><cscdll.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
<WinlogonNotify: dimsntfy><%SystemRoot%\System32\dimsntfy.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
<WinlogonNotify: ScCertProp><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
<WinlogonNotify: Schedule><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
<WinlogonNotify: sclgntfy><sclgntfy.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
<WinlogonNotify: SensLogn><WlNotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
<WinlogonNotify: termsrv><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
<WinlogonNotify: wlballoon><wlnotify.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
<{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\System32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
<{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\System32\browseui.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
<Aktualizace verze aplikace Internet Explorer><C:\WINDOWS\system32\ieudinit.exe> [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{0E2E3E38-0C20-4F2B-854F-7B236106F949}]
<Browser Customizations><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
<Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
<Internet Explorer><C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
<Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<Adresář 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
<Aktualizace plochy systému Windows><regsvr32.exe /s /n /i:U shell32.dll> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
<Internet Explorer><C:\WINDOWS\system32\ie4uinit.exe -BaseSettings> [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
<N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install> [(Verified)Microsoft Corporation]

==================================
Startup Folders
N/A

==================================
Services
[Acronis Scheduler2 Service / AcrSch2Svc][Stopped/Manual Start]
<"C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe"><Acronis>
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
<C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart][Stopped/Auto Start]
<C:\WINDOWS\system32\ati2sgag.exe><>
[Defragmentation-Service / DfSdkS][Stopped/Manual Start]
<"C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe"><mst software GmbH, Germany>
[Eset HTTP Server / EHttpSrv][Stopped/Manual Start]
<"C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe"><ESET>
[Eset Service / ekrn][Running/Auto Start]
<"C:\Program Files\ESET\ESET Smart Security\ekrn.exe"><ESET>
[Přístup k zařízením standardu HID / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<"C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe"><Macrovision Corporation>
[Java Quick Starter / JavaQuickStarterService][Running/Auto Start]
<"C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"><Sun Microsystems, Inc.>
[Lavasoft Ad-Aware Service / Lavasoft Ad-Aware Service][Stopped/Manual Start]
<"C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe"><Lavasoft>
[MBAMService / MBAMService][Running/Auto Start]
<"C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe"><Malwarebytes Corporation>
[O&O Defrag / O&O Defrag][Running/Auto Start]
<C:\WINDOWS\System32\oodag.exe><O&O Software GmbH>
[TuneUp Drive Defrag Service / TuneUp.Defrag][Stopped/Manual Start]
<C:\WINDOWS\System32\TuneUpDefragService.exe><TuneUp Software>
[TuneUp Program Statistics Service / TuneUp.ProgramStatisticsSvc][Running/Auto Start]
<C:\WINDOWS\System32\TUProgSt.exe><TuneUp Software>

==================================
Drivers
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Stopped/Manual Start]
<system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[ati2mtag / ati2mtag][Running/Manual Start]
<system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Belarc SMBios Access / BANTExt][Running/System Start]
<\SystemRoot\System32\Drivers\BANTExt.sys><N/A>
[eamon / eamon][Running/Auto Start]
<system32\DRIVERS\eamon.sys><ESET>
[easdrv / easdrv][Running/System Start]
<system32\DRIVERS\easdrv.sys><ESET>
[epfw / epfw][Running/Auto Start]
<system32\DRIVERS\epfw.sys><ESET>
[Eset Personal Firewall / Epfwndis][Running/Manual Start]
<system32\DRIVERS\Epfwndis.sys><ESET>
[epfwtdi / epfwtdi][Running/System Start]
<system32\DRIVERS\epfwtdi.sys><ESET>
[GEAR ASPI Filter Driver / GEARAspiWDM][Running/Manual Start]
<system32\DRIVERS\GEARAspiWDM.sys><GEAR Software Inc.>
[giveio / giveio][Running/Boot Start]
<\SystemRoot\system32\giveio.sys><N/A>
[ISO DVD/CD-ROM Device Driver / ISODrive][Running/System Start]
<\??\C:\Program Files\UltraISO\drivers\ISODrive.sys><EZB Systems, Inc.>
[Lbd / Lbd][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\Lbd.sys><Lavasoft AB>
[Logitech HID/USB Mouse Filter Driver / LHidFlt2][Running/Manual Start]
<system32\DRIVERS\LHidFlt2.Sys><Logitech, Inc.>
[Logitech USB Receiver device driver / LHidUsb][Running/Manual Start]
<System32\Drivers\LHidUsb.Sys><Logitech, Inc.>
[Logitech Mouse Class Filter Driver / LMouFlt2][Running/Manual Start]
<system32\DRIVERS\LMouFlt2.Sys><Logitech, Inc.>
[MBAMProtector / MBAMProtector][Running/Manual Start]
<\??\C:\WINDOWS\system32\drivers\mbam.sys><Malwarebytes Corporation>
[TRUST 320 SPACEC@M / ovt519][Stopped/Manual Start]
<System32\Drivers\ov519vid.sys><OmniVision Technologies, Inc.>
[PSI / PSI][Stopped/Manual Start]
<system32\DRIVERS\psi_mf.sys><Secunia>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[Realtek 10/100/1000 PCI NIC Family NDIS XP Driver / RTL8023xp][Running/Manual Start]
<system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
<System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[SASDIFSV / SASDIFSV][Running/System Start]
<\??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS><SUPERAdBlocker.com and SUPERAntiSpyware.com>
[SASENUM / SASENUM][Stopped/Manual Start]
<\??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS><SUPERAdBlocker.com and SUPERAntiSpyware.com>
[SASKUTIL / SASKUTIL][Running/System Start]
<\??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys><SUPERAdBlocker.com and SUPERAntiSpyware.com>
[Secdrv / Secdrv][Stopped/Manual Start]
<System32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[Acronis Snapshots Manager (Build 380) / snapman380][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\snman380.sys><Acronis>
[speedfan / speedfan][Running/Boot Start]
<\SystemRoot\system32\speedfan.sys><Windows (R) 2000 DDK provider>
[sptd / sptd][Running/Boot Start]
<\SystemRoot\System32\Drivers\sptd.sys><N/A>
[Symantec Volume Snap Shot Driver / symsnap][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\symsnap.sys><StorageCraft>
[Acronis True Image FS Filter / tifsfilter][Running/Auto Start]
<system32\DRIVERS\tifsfilt.sys><Acronis>
[Acronis True Image Backup Archive Explorer / timounter][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\timntr.sys><Acronis>
[Symantec V2i Mount Driver / v2imount][Running/Auto Start]
<system32\DRIVERS\v2imount.sys><Symantec Corporation>
[Vinyl AC'97 Audio Controller (WDM) / VIAudio][Running/Manual Start]
<system32\drivers\vinyl97.sys><VIA Technologies, Inc.>

==================================
Browser Add-ons
[Adobe PDF Link Helper]
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll, (Signed) Adobe Systems Incorporated>
[Groove GFS Browser Helper]
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} <C:\PROGRA~1\MICROS~2\Office12\GrooveShellExtensions.dll, (Signed) Microsoft Corporation>
[Java(tm) Plug-In 2 SSV Helper]
{DBC80044-A445-435b-BC74-9C25C1C588A9} <C:\Program Files\Java\jre6\bin\jp2ssv.dll, (Signed) Sun Microsystems, Inc.>
[JQSIEStartDetectorImpl Class]
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} <C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll, Sun Microsystems, Inc.>
[Send to OneNote from Internet Explorer button]
{2670000A-7350-4f3c-8081-5663EE0C6C49} <C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll, (Signed) Microsoft Corporation>
[]
{77BF5300-1474-4EC7-9980-D32B190E9B07} <, >
[&Zdroje informací]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL, (Signed) Microsoft Corporation>
[]
{e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, (Signed) N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <, >
[QIP Infium]
{2691C3E6-0886-4CB7-B775-5CE281346DD5} <, >
[MUWebControl Class]
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\system32\muweb.dll, (Signed) Microsoft Corporation>
[Java Plug-in 1.6.0_15]
{8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre6\bin\jp2iexp.dll, (Signed) >
[Java Plug-in 1.6.0_14]
{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} <C:\Program Files\Java\jre6\bin\jp2iexp.dll, (Signed) >
[Java Plug-in 1.6.0_15]
{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} <C:\Program Files\Java\jre6\bin\jp2iexp.dll, (Signed) >
[Java Plug-in 1.6.0_15]
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre6\bin\npjpi160_15.dll, (Signed) Sun Microsystems, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\FlDbg9i.ocx, (Signed) Adobe Systems, Inc.>
[]
{0329E7D6-6F54-462D-93F6-F5C3118BADF2} <, >
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corporation>
[Adobe PDF Link Helper]
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll, (Signed) Adobe Systems Incorporated>
[]
{1EF681F7-A04B-4D6D-9012-A307CCA55610} <, >
[]
{201F27D4-3704-41D6-89C1-AA35E39143ED} <, >
[]
{22BF413B-C6D2-4D91-82A9-A0F997BA588C} <, >
[]
{2670000A-7350-4F3C-8081-5663EE0C6C49} <, >
[]
{2691C3E6-0886-4CB7-B775-5CE281346DD5} <, >
[]
{2DB66063-BB98-466A-AA0D-3E7ACF5ED853} <, >
[]
{32099AAC-C132-4136-9E9A-4E364A424E17} <, >
[]
{44627E97-789B-40D4-B5C2-58BD171129A1} <, >
[]
{4E430174-1673-4FF3-BF28-A3B37F6573E7} <, >
[Microsoft Terminal Services Client Control (redist)]
{4eb89ff4-7f78-4a0f-8b8d-2bf02e94e4b2} <%systemroot%\system32\mstscax.dll, (Signed) N/A>
[Microsoft Terminal Services Client Control (redist)]
{4EDCB26C-D24C-4e72-AF07-B576699AC0DE} <%systemroot%\system32\mstscax.dll, (Signed) N/A>
[]
{53707962-6F74-2D53-2644-206D7942484F} <, >
[]
{57BDEE5A-1E29-4CFD-AEE7-EF32118EB6D6} <, >
[WUWebControl Class]
{6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, (Signed) Microsoft Corporation>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation>
[MUWebControl Class]
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\system32\muweb.dll, (Signed) Microsoft Corporation>
[Microsoft Terminal Services Client Control (redist)]
{7390f3d8-0439-4c05-91e3-cf5cb290c3d0} <%systemroot%\system32\mstscax.dll, (Signed) N/A>
[Microsoft Terminal Services Client Control (redist)]
{7584c670-2274-4efb-b00b-d6aaba6d3850} <%systemroot%\system32\mstscax.dll, (Signed) N/A>
[]
{77BF5300-1474-4EC7-9980-D32B190E9B07} <, >
[]
{7E6A20FB-153F-402C-A84B-1A64E1955D3D} <, >
[]
{855F3B16-6D32-4FE6-8A56-BBB695989046} <, >
[Microsoft Web Browser]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\ieframe.dll, (Signed) Microsoft Corporation>
[Microsoft Terminal Services Client Control (redist)]
{9059f30f-4eb1-4bd2-9fdc-36f43a218f4a} <%systemroot%\system32\mstscax.dll, (Signed) N/A>
[]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <, >
[]
{A1056498-D09A-41E4-864B-505EDD640D9E} <, >
[]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} <, >
[]
{CC59E0F9-7E43-44FA-9FAA-8377850BF205} <, >
[]
{CC963627-B1DC-40E0-B52A-CF21EE748449} <, >
[]
{CC963627-B1DC-40E0-B52A-CF21EE748450} <, >
[]
{CC963627-B1DC-40E0-B52A-CF21EE748451} <, >
[]
{CC963627-B1DC-40E0-B52A-CF21EE748452} <, >
[Microsoft Url Search Hook]
{CFBFAE00-17A6-11D0-99CB-00C04FD64497} <C:\WINDOWS\system32\ieframe.dll, (Signed) Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\FlDbg9i.ocx, (Signed) Adobe Systems, Inc.>
[Java(tm) Plug-In 2 SSV Helper]
{DBC80044-A445-435B-BC74-9C25C1C588A9} <C:\Program Files\Java\jre6\bin\jp2ssv.dll, (Signed) Sun Microsystems, Inc.>
[]
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} <, >
[]
{E2E2DD38-D088-4134-82B7-F2BA38496583} <, >
[]
{E59EB121-F339-4851-A3BA-FE49C35617C2} <, >
[]
{E5A1691B-D188-4419-AD02-90002030B8EE} <, >
[JQSIEStartDetectorImpl Class]
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} <C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll, Sun Microsystems, Inc.>
[XML HTTP Request]
{ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[XML HTTP]
{F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[]
{FB5F1910-F110-11D2-BB9E-00C04F795683} <, >
[]
{FF7C3CF0-4B15-11D1-ABED-709549C10000} <, >
[E&xportovat do aplikace Microsoft Excel]
<res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000, N/A>
[E&xportovať do programu Microsoft Excel]
<, >

==================================
Running Processes
[PID: 712 / SYSTEM][\SystemRoot\System32\smss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1128 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1164 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[C:\Program Files\SUPERAntiSpyware\SASWINLO.dll] [SUPERAntiSpyware.com, 1, 0, 0, 1054]
[C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4178]
[PID: 1248 / SYSTEM][C:\WINDOWS\system32\services.exe] [(Verified) Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)]
[PID: 1260 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
[C:\WINDOWS\system32\relog_ap.dll] [Acronis, 1,0,0,10]
[PID: 1472 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4222]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2514]
[C:\WINDOWS\system32\atipdlxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2550]
[PID: 1496 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1744 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1868 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[c:\windows\system32\uxtuneup.dll] [TuneUp Software, 8.0.3100.31]
[PID: 1936 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4222]
[C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2514]
[C:\WINDOWS\system32\atipdlxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2550]
[C:\WINDOWS\system32\ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4178]
[PID: 2028 / NETWORK SERVICE][C:\WINDOWS\System32\svchost.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 744 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\hpprn02.dll] [Hewlett-Packard Corporation, 02.00.12.02]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.1897.0]
[PID: 948 / Štefan][C:\WINDOWS\Explorer.EXE] [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\system32\BROWSEUI.dll] [Společnost Microsoft, 6.00.2900.5512 (xpsp.080413-2105)]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\Program Files\SUPERAntiSpyware\SASSEH.DLL] [SuperAdBlocker.com, 1, 0, 0, 1012]
[C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 9.1.0.2009022700]
[C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\ContextHandler.dll] [N/A, ]
[C:\Program Files\Unlocker\UnlockerCOM.dll] [N/A, ]
[C:\PROGRA~1\Trojan Remover\Trshlex.dll] [Simply Super Software, 1.1.0.47]
[C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll] [Malwarebytes Corporation, 1, 2, 0, 0]
[C:\Program Files\Lavasoft\Ad-Aware\ShellExt.dll] [, 1.0.0.1]
[C:\Program Files\ESET\ESET Smart Security\shellExt.dll] [ESET, 3.0.669 ]
[C:\Program Files\SUPERAntiSpyware\SASCTXMN.DLL] [SUPERAntiSpyware.com, 1, 0, 0, 1004]
[C:\Program Files\UltraISO\isoshell.dll] [EZB Systems, Inc., 1, 0, 0, 2]
[C:\Program Files\TuneUp Utilities 2009\SDShelEx-win32.dll] [TuneUp Software, 8.0.3100.31]
[C:\Program Files\TuneUp Utilities 2009\DseShExt-x86.dll] [TuneUp Software, 8.0.3100.31]
[C:\Program Files\Advanced System Optimizer\ShellExt.dll] [Systweak Inc, 2 , 20 , 4 , 731]
[C:\Program Files\7-Zip\7-zip.dll] [Igor Pavlov, 9.07 beta]
[PID: 1688 / Štefan][C:\Program Files\ESET\ESET Smart Security\egui.exe] [ESET, 3.0.669 ]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\Program Files\ESET\ESET Smart Security\eguiScan.dll] [ESET, 3.0.669 ]
[C:\Program Files\ESET\ESET Smart Security\eguiAmon.dll] [ESET, 3.0.669 ]
[C:\Program Files\ESET\ESET Smart Security\eguiEmon.dll] [ESET, 3.0.669 ]
[C:\Program Files\ESET\ESET Smart Security\eguiEpfw.dll] [ESET, 3.0.669 ]
[C:\Program Files\ESET\ESET Smart Security\eguiSmon.dll] [ESET, 3.0.669 ]
[C:\Program Files\ESET\ESET Smart Security\eguiUpdate.dll] [ESET, 3.0.669 ]
[C:\Program Files\ESET\ESET Smart Security\eguiMailPlugins.dll] [ESET, 3.0.669 ]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.DLL] [Microsoft Corporation, 8.00.50727.762]
[PID: 1696 / Štefan][C:\WINDOWS\system32\ctfmon.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[PID: 372 / SYSTEM][C:\Program Files\ESET\ESET Smart Security\ekrn.exe] [ESET, 3.0.669 ]
[C:\Program Files\ESET\ESET Smart Security\ekrnScan.dll] [ESET, 3.0.669 ]
[C:\Program Files\ESET\ESET Smart Security\ekrnAmon.dll] [ESET, 3.0.669 ]
[C:\Program Files\ESET\ESET Smart Security\ekrnEmon.dll] [ESET, 3.0.669 ]
[C:\Program Files\ESET\ESET Smart Security\ekrnEpfw.dll] [ESET, 3.0.669 ]
[C:\Program Files\ESET\ESET Smart Security\ekrnSmon.dll] [ESET, 3.0.669 ]
[C:\Program Files\ESET\ESET Smart Security\ekrnUpdate.dll] [ESET, 3.0.669 ]
[C:\Program Files\ESET\ESET Smart Security\updater.dll] [ESET, 3.0.669 ]
[C:\Program Files\ESET\ESET Smart Security\ekrnMailPlugins.dll] [ESET, 3.0.669 ]
[PID: 400 / SYSTEM][C:\WINDOWS\system32\inetsrv\inetinfo.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[PID: 340 / SYSTEM][C:\Program Files\Java\jre6\bin\jqs.exe] [Sun Microsystems, Inc., 6.0.150.3]
[C:\Program Files\Java\jre6\bin\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\WINDOWS\system32\netfxperf.dll] [Microsoft Corporation, 1.1.4322.573]
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll] [Microsoft Corporation, 1.1.4322.2407]
[PID: 548 / SYSTEM][C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe] [Malwarebytes Corporation, 1.04]
[PID: 996 / SYSTEM][C:\WINDOWS\System32\oodag.exe] [O&O Software GmbH, 11.0.3289]
[C:\WINDOWS\System32\OODAGRS.DLL] [O&O Software GmbH, 11.0.3000.172]
[PID: 1808 / SYSTEM][C:\WINDOWS\System32\snmp.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[PID: 1840 / SYSTEM][C:\WINDOWS\System32\TUProgSt.exe] [TuneUp Software, 8.0.3100.31]
[PID: 2688 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[PID: 3120 / SYSTEM][C:\WINDOWS\System32\wbem\wmiapsrv.exe] [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)]
[PID: 2124 / Štefan][C:\Program Files\Opera\opera.exe] [Opera Software, 1750]
[C:\Program Files\Opera\Opera.dll] [Opera Software, 1750]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\Program Files\SUPERAntiSpyware\SASSEH.DLL] [SuperAdBlocker.com, 1, 0, 0, 1012]
[PID: 3648 / Štefan][C:\Program Files\7-Zip\7zFM.exe] [Igor Pavlov, 9.07 beta]
[C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.DLL] [Microsoft Corporation, 8.00.50727.762]
[C:\Program Files\7-Zip\7z.dll] [Igor Pavlov, 9.07 beta]
[C:\Program Files\SUPERAntiSpyware\SASSEH.DLL] [SuperAdBlocker.com, 1, 0, 0, 1012]
[PID: 424 / Štefan][C:\DOCUME~1\TEFAN~1\LOCALS~1\Temp\7zOB7.tmp\SREngLdr.EXE] [Smallfrogs Studio, 2.8.1.1279]
[PID: 2764 / Štefan][C:\DOCUME~1\TEFAN~1\LOCALS~1\Temp\7zOB7.tmp\SRE47d4baac.EXE] [Smallfrogs Studio, 2.8.1.1279]

==================================
File Associations
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS Error. [NOTEPAD.EXE %1]
.JS Error. [NOTEPAD.EXE %1]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
N/A

==================================
Autorun.Inf
N/A

==================================
HOSTS File
127.0.0.1 localhost

==================================
Process Privileges Scan
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 3648, C:\PROGRAM FILES\7-ZIP\7ZFM.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 424, C:\DOCUME~1\TEFAN~1\LOCALS~1\TEMP\7ZOB7.TMP\SRENGLDR.EXE]

==================================
Scheduled Tasks
[Enabled] Ad-Aware Update (Weekly).job
C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
[Enabled] 1-Click Maintenance.job
C:\Program Files\TuneUp Utilities 2009\OneClickStarter.exe

==================================
Windows Security Update Check
Microsoft .NET Framework 1.1, sada pro češtinu
KB940157, Služba Windows Search 4.0 pro systém Windows XP (KB940157)
KB928416, Sada Microsoft .NET Framework 3.0: x86 Language Pack (KB928416)
KB943729, Rozšíření předvoleb zásad skupiny pro klientskou část pro systém Windows XP (KB943729)
KB909520, Balíček Základní zprostředkovatel kryptografických služeb společnosti Microsoft pro čipové karty: x86 (KB909520)
KB931125, Aktualizace pro kořenové certifikáty [květen 2009] (KB931125)
KB973874, Aktualizace pro seznam Kompatibilní zobrazení aplikace Internet Explorer 8 pro systém Windows XP (KB973874)

==================================
API HOOK
N/A

==================================
Hidden Process
N/A

==================================


//nedávej logy do code. jaro3

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43287
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu HJT- pomoc

Příspěvekod jaro3 » 14 zář 2009 18:50

použil jsi tl. Repair u:
.VBS Error. [NOTEPAD.EXE %1]
.JS Error. [NOTEPAD.EXE %1] ?

Zkus nyní reinstal WinRar.

Pokud nepůjde , bude třeba opravit windows.

Stáhni si Dial-a-fix
Klikni na kladívko-další možnosti:
SFC scan - Spustí nástroj pro kontrolu systémových souborů (případná potřeba instalačního media Windows).
Klikni na službu a potom na GO.

Funguje Ti Windows Installer ?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
pistabaci
Level 1
Level 1
Příspěvky: 92
Registrován: březen 07
Bydliště: Košice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu HJT- pomoc

Příspěvekod pistabaci » 14 zář 2009 20:06

"použil jsi tl. Repair u:
.VBS Error. [NOTEPAD.EXE %1]
.JS Error. [NOTEPAD.EXE %1] ?" kde ? neviem....

Windows Installer Clean Up funguje.

Ostatné nepomohlo.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43287
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu HJT- pomoc

Příspěvekod jaro3 » 14 zář 2009 20:22

Stahni si SREng --System Repair Engineer
- rozbal na plochu a spust ho
- zvol "zvol Smart Scan", nech nastaveni tak jak je
- zvol "Verify the digital signature of process modules"
- klik na "Scan"
- klik na Save Reports, uloz log na plochu a cely obsah logu zkopirujt sem
- rozbal na plochu a spust ho
+
- Spusť ho a zvol možnost System Repair
- Na první záložce File Associations pokud bude zatrhnutý/vybraný některý čtvereček z výpisu, tak klikni dole na tlačítko [b]Repair[/quote]
[/b]

Windows Installer Clean Up jsem po Tobě vůbec nechtěl, funguje Ti bez problémů instalace programů?

použil si Dial-a-fix?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
pistabaci
Level 1
Level 1
Příspěvky: 92
Registrován: březen 07
Bydliště: Košice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu HJT- pomoc

Příspěvekod pistabaci » 14 zář 2009 21:10

Inštalácia programov funguje, veď všetky programy čo mi dávaš link sťahujem a spúšťam . Dial a fix som spustil ale Windows XP Profi na diskete mam s SP1 a v PC SP3 do Diamontu Tools som dal ISO s SP3 takze asi 4x zastal ale stále som dal som pokracovat až skončil. System Repair....stvrdol na scaning HOSTS file idem ho spustit znova.

Uživatelský avatar
pistabaci
Level 1
Level 1
Příspěvky: 92
Registrován: březen 07
Bydliště: Košice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu HJT- pomoc

Příspěvekod pistabaci » 15 zář 2009 11:03

Kód: Vybrat vše


2009-09-15,10:57:11

System Repair Engineer 2.8.1.1279
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 3 (Build 2600) - Administrative User - Completed Functions Allowed

Follow item(s) have been selected:
    All Boot Items (Including Registry, Startup Folders, Services and so on)
    Browser Add-ons
    Running Processes (Including process model information)
    File Associations
    Winsock Provider
    Autorun.Inf
    HOSTS File
    Process Privileges Scan
    Scheduled Tasks
    Windows Security Update Check
    API HOOK
    Hidden Process


Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <egui><"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice>  [(Verified)"ESET, spol. s r.o."]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Windows Component Publisher]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Windows Component Publisher]
    <UIHost><logonui.exe>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{AEB6717E-7E19-11d0-97EE-00C04FD91972}><shell32.dll>  [(Verified)Microsoft Windows Component Publisher]
    <{B5A7F190-DDA6-4420-B3BA-52453494E6CD}><C:\PROGRA~1\MICROS~2\Office12\GrooveShellExtensions.dll>  [(Verified)Microsoft Corporation]
    <{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}><C:\Program Files\SUPERAntiSpyware\SASSEH.DLL>  [SuperAdBlocker.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    <PostBootReminder><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Component Publisher]
    <CDBurn><%SystemRoot%\system32\SHELL32.dll>  [(Verified)Microsoft Windows Component Publisher]
    <WebCheck><C:\WINDOWS\system32\webcheck.dll>  [(Verified)Microsoft Windows]
    <SysTray><%systemroot%\system32\stobject.dll>  [(Verified)Microsoft Windows Component Publisher]
    <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
    <WinlogonNotify: !SASWinLogon><C:\Program Files\SUPERAntiSpyware\SASWINLO.dll>  [SUPERAntiSpyware.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    <WinlogonNotify: crypt32chain><crypt32.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    <WinlogonNotify: cryptnet><cryptnet.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    <WinlogonNotify: cscdll><cscdll.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
    <WinlogonNotify: dimsntfy><%SystemRoot%\System32\dimsntfy.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
    <WinlogonNotify: ScCertProp><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
    <WinlogonNotify: Schedule><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    <WinlogonNotify: sclgntfy><sclgntfy.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    <WinlogonNotify: SensLogn><WlNotify.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
    <WinlogonNotify: termsrv><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
    <WinlogonNotify: wlballoon><wlnotify.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    <{438755C2-A8BA-11D1-B96B-00A0C90312E1}><%SystemRoot%\System32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
    <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\System32\browseui.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
    <Aktualizace verze aplikace Internet Explorer><C:\WINDOWS\system32\ieudinit.exe>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{0E2E3E38-0C20-4F2B-854F-7B236106F949}]
    <Browser Customizations><RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    <Windows Media Player><C:\WINDOWS\inf\unregmp2.exe /ShowWMP>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
    <Internet Explorer><C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
    <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
    <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
    <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
    <Adresář 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
    <Aktualizace plochy systému Windows><regsvr32.exe /s /n /i:U shell32.dll>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
    <Internet Explorer><C:\WINDOWS\system32\ie4uinit.exe -BaseSettings>  [(Verified)Microsoft Windows Component Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
    <N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install>  [(Verified)Microsoft Corporation]

==================================
Startup Folders
N/A

==================================
Services
[Acronis Scheduler2 Service / AcrSch2Svc][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe"><Acronis>
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
  <C:\WINDOWS\system32\Ati2evxx.exe><ATI Technologies Inc.>
[ATI Smart / ATI Smart][Stopped/Auto Start]
  <C:\WINDOWS\system32\ati2sgag.exe><>
[Crypkey License / Crypkey License][Running/Auto Start]
  <crypserv.exe><CrypKey (Canada) Ltd.>
[Defragmentation-Service / DfSdkS][Stopped/Manual Start]
  <"C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe"><mst software GmbH, Germany>
[Eset HTTP Server / EHttpSrv][Stopped/Manual Start]
  <"C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe"><ESET>
[Eset Service / ekrn][Running/Auto Start]
  <"C:\Program Files\ESET\ESET Smart Security\ekrn.exe"><ESET>
[Přístup k zařízením standardu HID / HidServ][Stopped/Disabled]
  <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
  <"C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe"><Macrovision Corporation>
[Java Quick Starter / JavaQuickStarterService][Running/Auto Start]
  <"C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"><Sun Microsystems, Inc.>
[Lavasoft Ad-Aware Service / Lavasoft Ad-Aware Service][Stopped/Manual Start]
  <"C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe"><Lavasoft>
[MBAMService / MBAMService][Running/Auto Start]
  <"C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe"><Malwarebytes Corporation>
[O&O Defrag / O&O Defrag][Running/Auto Start]
  <C:\WINDOWS\System32\oodag.exe><O&O Software GmbH>
[TuneUp Drive Defrag Service / TuneUp.Defrag][Stopped/Manual Start]
  <C:\WINDOWS\System32\TuneUpDefragService.exe><TuneUp Software>
[TuneUp Program Statistics Service / TuneUp.ProgramStatisticsSvc][Running/Auto Start]
  <C:\WINDOWS\System32\TUProgSt.exe><TuneUp Software>

==================================
Drivers
[Service for Realtek AC97 Audio (WDM) / ALCXWDM][Stopped/Manual Start]
  <system32\drivers\ALCXWDM.SYS><Realtek Semiconductor Corp.>
[ati2mtag / ati2mtag][Running/Manual Start]
  <system32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
[Belarc SMBios Access / BANTExt][Running/System Start]
  <\SystemRoot\System32\Drivers\BANTExt.sys><N/A>
[catchme / catchme][Stopped/Manual Start]
  <\??\C:\ComboFix\catchme.sys><N/A>
[eamon / eamon][Running/Auto Start]
  <system32\DRIVERS\eamon.sys><ESET>
[easdrv / easdrv][Running/System Start]
  <system32\DRIVERS\easdrv.sys><ESET>
[epfw / epfw][Running/Auto Start]
  <system32\DRIVERS\epfw.sys><ESET>
[Eset Personal Firewall / Epfwndis][Running/Manual Start]
  <system32\DRIVERS\Epfwndis.sys><ESET>
[epfwtdi / epfwtdi][Running/System Start]
  <system32\DRIVERS\epfwtdi.sys><ESET>
[GEAR ASPI Filter Driver / GEARAspiWDM][Running/Manual Start]
  <system32\DRIVERS\GEARAspiWDM.sys><GEAR Software Inc.>
[giveio / giveio][Running/Boot Start]
  <\SystemRoot\system32\giveio.sys><N/A>
[ISO DVD/CD-ROM Device Driver / ISODrive][Running/System Start]
  <\??\C:\Program Files\UltraISO\drivers\ISODrive.sys><EZB Systems, Inc.>
[Lbd / Lbd][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\Lbd.sys><Lavasoft AB>
[Logitech HID/USB Mouse Filter Driver / LHidFlt2][Running/Manual Start]
  <system32\DRIVERS\LHidFlt2.Sys><Logitech, Inc.>
[Logitech USB Receiver device driver / LHidUsb][Running/Manual Start]
  <System32\Drivers\LHidUsb.Sys><Logitech, Inc.>
[Logitech Mouse Class Filter Driver / LMouFlt2][Running/Manual Start]
  <system32\DRIVERS\LMouFlt2.Sys><Logitech, Inc.>
[MBAMProtector / MBAMProtector][Running/Manual Start]
  <\??\C:\WINDOWS\system32\drivers\mbam.sys><Malwarebytes Corporation>
[NetworkX / NetworkX][Running/System Start]
  <\SystemRoot\system32\ckldrv.sys><N/A>
[TRUST 320 SPACEC@M / ovt519][Stopped/Manual Start]
  <System32\Drivers\ov519vid.sys><OmniVision Technologies, Inc.>
[PSI / PSI][Stopped/Manual Start]
  <system32\DRIVERS\psi_mf.sys><Secunia>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
  <\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[Realtek 10/100/1000 PCI NIC Family NDIS XP Driver / RTL8023xp][Running/Manual Start]
  <system32\DRIVERS\Rtnicxp.sys><Realtek Semiconductor Corporation>
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Stopped/Manual Start]
  <System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[SASDIFSV / SASDIFSV][Running/System Start]
  <\??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS><SUPERAdBlocker.com and SUPERAntiSpyware.com>
[SASENUM / SASENUM][Stopped/Manual Start]
  <\??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS><SUPERAdBlocker.com and SUPERAntiSpyware.com>
[SASKUTIL / SASKUTIL][Running/System Start]
  <\??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys><SUPERAdBlocker.com and SUPERAntiSpyware.com>
[Secdrv / Secdrv][Stopped/Manual Start]
  <System32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[Acronis Snapshots Manager (Build 380) / snapman380][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\snman380.sys><Acronis>
[speedfan / speedfan][Running/Boot Start]
  <\SystemRoot\system32\speedfan.sys><Windows (R) 2000 DDK provider>
[sptd / sptd][Running/Boot Start]
  <\SystemRoot\System32\Drivers\sptd.sys><N/A>
[Symantec Volume Snap Shot Driver / symsnap][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\symsnap.sys><StorageCraft>
[Acronis True Image FS Filter / tifsfilter][Running/Auto Start]
  <system32\DRIVERS\tifsfilt.sys><Acronis>
[Acronis True Image Backup Archive Explorer / timounter][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\timntr.sys><Acronis>
[Symantec V2i Mount Driver / v2imount][Running/Auto Start]
  <system32\DRIVERS\v2imount.sys><Symantec Corporation>
[Vinyl AC'97 Audio Controller (WDM) / VIAudio][Running/Manual Start]
  <system32\drivers\vinyl97.sys><VIA Technologies, Inc.>

==================================
Browser Add-ons
[Adobe PDF Link Helper]
  {18DF081C-E8AD-4283-A596-FA578C2EBDC3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll, (Signed) Adobe Systems Incorporated>
[Groove GFS Browser Helper]
  {72853161-30C5-4D22-B7F9-0BBC1D38A37E} <C:\PROGRA~1\MICROS~2\Office12\GrooveShellExtensions.dll, (Signed) Microsoft Corporation>
[Java(tm) Plug-In 2 SSV Helper]
  {DBC80044-A445-435b-BC74-9C25C1C588A9} <C:\Program Files\Java\jre6\bin\jp2ssv.dll, (Signed) Sun Microsystems, Inc.>
[JQSIEStartDetectorImpl Class]
  {E7E6F031-17CE-4C07-BC86-EABFE594F69C} <C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll, Sun Microsystems, Inc.>
[Send to OneNote from Internet Explorer button]
  {2670000A-7350-4f3c-8081-5663EE0C6C49} <C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll, (Signed) Microsoft Corporation>
[]
  {77BF5300-1474-4EC7-9980-D32B190E9B07} <, >
[&Zdroje informací]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL, (Signed) Microsoft Corporation>
[]
  {e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, (Signed) N/A>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} <, >
[QIP Infium]
  {2691C3E6-0886-4CB7-B775-5CE281346DD5} <, >
[MUWebControl Class]
  {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\system32\muweb.dll, (Signed) Microsoft Corporation>
[Java Plug-in 1.6.0_15]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre6\bin\jp2iexp.dll, (Signed) >
[Java Plug-in 1.6.0_14]
  {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} <C:\Program Files\Java\jre6\bin\jp2iexp.dll, (Signed) >
[Java Plug-in 1.6.0_15]
  {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} <C:\Program Files\Java\jre6\bin\jp2iexp.dll, (Signed) >
[Java Plug-in 1.6.0_15]
  {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre6\bin\npjpi160_15.dll, (Signed) Sun Microsystems, Inc.>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\FlDbg9i.ocx, (Signed) Adobe Systems, Inc.>
[]
  {0329E7D6-6F54-462D-93F6-F5C3118BADF2} <, >
[Windows Genuine Advantage Validation Tool]
  {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corporation>
[Adobe PDF Link Helper]
  {18DF081C-E8AD-4283-A596-FA578C2EBDC3} <C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll, (Signed) Adobe Systems Incorporated>
[]
  {1EF681F7-A04B-4D6D-9012-A307CCA55610} <, >
[]
  {201F27D4-3704-41D6-89C1-AA35E39143ED} <, >
[]
  {22BF413B-C6D2-4D91-82A9-A0F997BA588C} <, >
[]
  {2670000A-7350-4F3C-8081-5663EE0C6C49} <, >
[]
  {2691C3E6-0886-4CB7-B775-5CE281346DD5} <, >
[]
  {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} <, >
[]
  {32099AAC-C132-4136-9E9A-4E364A424E17} <, >
[]
  {44627E97-789B-40D4-B5C2-58BD171129A1} <, >
[]
  {4E430174-1673-4FF3-BF28-A3B37F6573E7} <, >
[Microsoft Terminal Services Client Control (redist)]
  {4eb89ff4-7f78-4a0f-8b8d-2bf02e94e4b2} <%systemroot%\system32\mstscax.dll, (Signed) N/A>
[Microsoft Terminal Services Client Control (redist)]
  {4EDCB26C-D24C-4e72-AF07-B576699AC0DE} <%systemroot%\system32\mstscax.dll, (Signed) N/A>
[]
  {53707962-6F74-2D53-2644-206D7942484F} <, >
[]
  {57BDEE5A-1E29-4CFD-AEE7-EF32118EB6D6} <, >
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\system32\wuweb.dll, (Signed) Microsoft Corporation>
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, (Signed) Microsoft Corporation>
[MUWebControl Class]
  {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} <C:\WINDOWS\system32\muweb.dll, (Signed) Microsoft Corporation>
[Microsoft Terminal Services Client Control (redist)]
  {7390f3d8-0439-4c05-91e3-cf5cb290c3d0} <%systemroot%\system32\mstscax.dll, (Signed) N/A>
[Microsoft Terminal Services Client Control (redist)]
  {7584c670-2274-4efb-b00b-d6aaba6d3850} <%systemroot%\system32\mstscax.dll, (Signed) N/A>
[]
  {77BF5300-1474-4EC7-9980-D32B190E9B07} <, >
[]
  {7E6A20FB-153F-402C-A84B-1A64E1955D3D} <, >
[]
  {855F3B16-6D32-4FE6-8A56-BBB695989046} <, >
[Microsoft Web Browser]
  {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\ieframe.dll, (Signed) Microsoft Corporation>
[Microsoft Terminal Services Client Control (redist)]
  {9059f30f-4eb1-4bd2-9fdc-36f43a218f4a} <%systemroot%\system32\mstscax.dll, (Signed) N/A>
[]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <, >
[]
  {A1056498-D09A-41E4-864B-505EDD640D9E} <, >
[]
  {BFC32E1D-EE75-4A48-BC60-104E11EE2431} <, >
[]
  {CC59E0F9-7E43-44FA-9FAA-8377850BF205} <, >
[]
  {CC963627-B1DC-40E0-B52A-CF21EE748449} <, >
[]
  {CC963627-B1DC-40E0-B52A-CF21EE748450} <, >
[]
  {CC963627-B1DC-40E0-B52A-CF21EE748451} <, >
[]
  {CC963627-B1DC-40E0-B52A-CF21EE748452} <, >
[Microsoft Url Search Hook]
  {CFBFAE00-17A6-11D0-99CB-00C04FD64497} <C:\WINDOWS\system32\ieframe.dll, (Signed) Microsoft Corporation>
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\FlDbg9i.ocx, (Signed) Adobe Systems, Inc.>
[Java(tm) Plug-In 2 SSV Helper]
  {DBC80044-A445-435B-BC74-9C25C1C588A9} <C:\Program Files\Java\jre6\bin\jp2ssv.dll, (Signed) Sun Microsystems, Inc.>
[]
  {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} <, >
[]
  {E2E2DD38-D088-4134-82B7-F2BA38496583} <, >
[]
  {E59EB121-F339-4851-A3BA-FE49C35617C2} <, >
[]
  {E5A1691B-D188-4419-AD02-90002030B8EE} <, >
[JQSIEStartDetectorImpl Class]
  {E7E6F031-17CE-4C07-BC86-EABFE594F69C} <C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll, Sun Microsystems, Inc.>
[XML HTTP Request]
  {ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[XML HTTP]
  {F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[]
  {FB5F1910-F110-11D2-BB9E-00C04F795683} <, >
[]
  {FF7C3CF0-4B15-11D1-ABED-709549C10000} <, >
[E&xportovat do aplikace Microsoft Excel]
  <res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000, N/A>
[E&xportovať do programu Microsoft Excel]
  <, >

==================================
Running Processes
[PID: 716 / SYSTEM][\SystemRoot\System32\smss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1468 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1508 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
    [C:\Program Files\SUPERAntiSpyware\SASWINLO.dll]  [SUPERAntiSpyware.com, 1, 0, 0, 1054]
    [C:\WINDOWS\system32\Ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4178]
[PID: 1592 / SYSTEM][C:\WINDOWS\system32\services.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)]
[PID: 1604 / SYSTEM][C:\WINDOWS\system32\lsass.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2113)]
    [C:\WINDOWS\system32\relog_ap.dll]  [Acronis, 1,0,0,10]
[PID: 1820 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4222]
    [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2514]
    [C:\WINDOWS\system32\atipdlxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2550]
[PID: 1852 / SYSTEM][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 2012 / NETWORK SERVICE][C:\WINDOWS\system32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 468 / SYSTEM][C:\WINDOWS\System32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
    [c:\windows\system32\uxtuneup.dll]  [TuneUp Software, 8.0.3100.31]
[PID: 560 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe]  [ATI Technologies Inc., 6.14.10.4222]
    [C:\WINDOWS\system32\Ati2edxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2514]
    [C:\WINDOWS\system32\atipdlxx.dll]  [ATI Technologies, Inc., 6, 14, 10, 2550]
    [C:\WINDOWS\system32\ati2evxx.dll]  [ATI Technologies Inc., 6.14.10.4178]
[PID: 356 / NETWORK SERVICE][C:\WINDOWS\System32\svchost.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2111)]
[PID: 1060 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\hpprn02.dll]  [Hewlett-Packard Corporation, 02.00.12.02]
    [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll]  [Microsoft Corporation, 11.3.1897.0]
[PID: 1264 / Štefan][C:\WINDOWS\Explorer.EXE]  [(Verified) Microsoft Corporation, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\system32\BROWSEUI.dll]  [Společnost Microsoft, 6.00.2900.5512 (xpsp.080413-2105)]
    [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll]  [Adobe Systems, Inc., 9.1.0.2009022700]
    [C:\Program Files\SUPERAntiSpyware\SASSEH.DLL]  [SuperAdBlocker.com, 1, 0, 0, 1012]
[PID: 364 / Štefan][C:\Program Files\ESET\ESET Smart Security\egui.exe]  [ESET, 3.0.669 ]
    [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\ESET\ESET Smart Security\eguiScan.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiAmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiEmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiEpfw.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiSmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiUpdate.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\eguiMailPlugins.dll]  [ESET, 3.0.669 ]
    [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.DLL]  [Microsoft Corporation, 8.00.50727.762]
[PID: 380 / Štefan][C:\WINDOWS\system32\ctfmon.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2105)]
[PID: 804 / SYSTEM][C:\WINDOWS\system32\crypserv.exe]  [CrypKey (Canada) Ltd., 1, 0, 1, 2]
[PID: 1004 / SYSTEM][C:\Program Files\ESET\ESET Smart Security\ekrn.exe]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnScan.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnAmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnEmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnEpfw.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnSmon.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnUpdate.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\updater.dll]  [ESET, 3.0.669 ]
    [C:\Program Files\ESET\ESET Smart Security\ekrnMailPlugins.dll]  [ESET, 3.0.669 ]
[PID: 1112 / SYSTEM][C:\WINDOWS\system32\inetsrv\inetinfo.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[PID: 1156 / SYSTEM][C:\Program Files\Java\jre6\bin\jqs.exe]  [Sun Microsystems, Inc., 6.0.150.3]
    [C:\Program Files\Java\jre6\bin\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\WINDOWS\system32\netfxperf.dll]  [Microsoft Corporation, 1.1.4322.573]
    [C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll]  [Microsoft Corporation, 1.1.4322.2407]
    [C:\Program Files\Java\jre6\bin\client\jvm.dll]  [Sun Microsystems, Inc., 14.1.0.02]
[PID: 1096 / SYSTEM][C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe]  [Malwarebytes Corporation, 1.04]
[PID: 1532 / SYSTEM][C:\WINDOWS\System32\oodag.exe]  [O&O Software GmbH, 11.0.3289]
    [C:\WINDOWS\System32\OODAGRS.DLL]  [O&O Software GmbH, 11.0.3000.172]
[PID: 772 / SYSTEM][C:\WINDOWS\System32\snmp.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[PID: 808 / SYSTEM][C:\WINDOWS\System32\TUProgSt.exe]  [TuneUp Software, 8.0.3100.31]
[PID: 2980 / LOCAL SERVICE][C:\WINDOWS\System32\alg.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-0852)]
[PID: 3332 / SYSTEM][C:\WINDOWS\System32\wbem\wmiapsrv.exe]  [(Verified) Microsoft Corporation, 5.1.2600.5512 (xpsp.080413-2108)]
[PID: 924 / Štefan][C:\Program Files\DAEMON Tools Lite\daemon.exe]  [DT Soft Ltd, 4.30.4.0027]
    [C:\Program Files\DAEMON Tools Lite\DTCommonRes.dll]  [DT Soft Ltd, 4.30.4.0027]
    [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\DAEMON Tools Lite\Engine.dll]  [DT Soft Ltd, 4.30.4.0027]
    [C:\Program Files\DAEMON Tools Lite\imgengine.dll]  [DT Soft Ltd., 1.17.0.0]
[PID: 1456 / Štefan][C:\Program Files\Opera\opera.exe]  [Opera Software, 1750]
    [C:\Program Files\Opera\Opera.dll]  [Opera Software, 1750]
    [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\SUPERAntiSpyware\SASSEH.DLL]  [SuperAdBlocker.com, 1, 0, 0, 1012]
[PID: 964 / Štefan][C:\Program Files\WinRAR\WinRAR.exe]  [, ]
    [C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\WINDOWS\System32\browseui.dll]  [Společnost Microsoft, 6.00.2900.5512 (xpsp.080413-2105)]
[PID: 2132 / Štefan][C:\Documents and Settings\Štefan\Plocha\SREngLdr.EXE]  [Smallfrogs Studio, 2.8.1.1279]
[PID: 2208 / Štefan][C:\Documents and Settings\Štefan\Plocha\SRE47d4baac.EXE]  [Smallfrogs Studio, 2.8.1.1279]
    [C:\Documents and Settings\Štefan\Plocha\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]

==================================
File Associations
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  Error. [NOTEPAD.EXE %1]
.JS   Error. [NOTEPAD.EXE %1]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
N/A

==================================
Autorun.Inf
N/A

==================================
HOSTS File
127.0.0.1       localhost

==================================
Process Privileges Scan
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 964, C:\PROGRAM FILES\WINRAR\WINRAR.EXE]
Special Privileges Enabled: SeLoadDriverPrivilege [PID = 2132, C:\DOCUMENTS AND SETTINGS\ŠTEFAN\PLOCHA\SRENGLDR.EXE]

==================================
Scheduled Tasks
[Enabled] Ad-Aware Update (Weekly).job
        C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
[Enabled] 1-Click Maintenance.job
        C:\Program Files\TuneUp Utilities 2009\OneClickStarter.exe

==================================
Windows Security Update Check
 Microsoft .NET Framework 1.1, sada pro češtinu
KB940157,  Služba Windows Search 4.0 pro systém Windows XP (KB940157)
KB928416,  Sada Microsoft .NET Framework 3.0: x86 Language Pack (KB928416)
KB943729,  Rozšíření předvoleb zásad skupiny pro klientskou část pro systém Windows XP (KB943729)
KB909520,  Balíček Základní zprostředkovatel kryptografických služeb společnosti Microsoft pro čipové karty: x86 (KB909520)
KB931125,  Aktualizace pro kořenové certifikáty [květen 2009] (KB931125)
KB973874,  Aktualizace pro seznam Kompatibilní zobrazení aplikace Internet Explorer 8 pro systém Windows XP (KB973874)

==================================
API HOOK
N/A

==================================
Hidden Process
N/A

==================================



Uživatelský avatar
pistabaci
Level 1
Level 1
Příspěvky: 92
Registrován: březen 07
Bydliště: Košice
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu HJT- pomoc

Příspěvekod pistabaci » 15 zář 2009 12:40

Uf už som sa chystal preinštalovať cely počítač. No nakoniec to ide !!!!
Super vďaka .
Juhočeši sú naj, vďaka za trpezlivosť a ochotu už si ma vytiahol z bryndy 2x. Prvýkrát asi pred rokom.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43287
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu HJT- pomoc

Příspěvekod jaro3 » 15 zář 2009 20:21

Nemáš zač, můžeš dát vyřešeno , fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 53 hostů