Prosím o kontrolu logu + Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu +

Příspěvekod jaro3 » 13 kvě 2011 10:26

WMP vím asi 4x sem ho přeinstalovával a nic ( "C:\Documents and Settings\Michal\Data aplikací\app
"1505118141.elitistjerks.com" = Rawr" mi nic neříká
jinak chtěl bych se zaptat proč mám 3xwindows v PC když ho zapínám mám ho tam 3x

Zkus stáhnout dvanáctku:
http://windows.microsoft.com/cs-CZ/wind ... dia-player

a nainstalovat...

To jsou špatné instalace , musíš opravit boot..
http://support.microsoft.com/kb/888023/cs

A odinstaluj si ten cracklý NOD32 a stáhni a nainstaluj free antivir:
Avira10 , Avast 6 nebo AVG 11....

Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

:Files
C:\Documents and Settings\Michal\Data aplikací\app
C:\WINDOWS\scmunins.exe
C:\Program Files\BearShare Applications\BearShare
C:\Documents and Settings\Michal\Local Settings\Apps

:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\BearShare Applications\BearShare\BearShare.exe" =-
"C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\CurseClient.exe" =-
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"1505118141.elitistjerks.com" =-

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]


Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Reklama
jogin
Level 1.5
Level 1.5
Příspěvky: 143
Registrován: říjen 10
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu +

Příspěvekod jogin » 14 kvě 2011 00:06

wmp 12 je pouze pro windows 7 :-( opět sem zkusil naistalovat wmp 11 a žádná změna :-( jinak ty windows se mi zobrazilo po použití combofixu... nod32 smazán nahrazen avira 10
-----------------------------------------------------------
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
========== FILES ==========
C:\Documents and Settings\Michal\Data aplikací\app folder moved successfully.
C:\WINDOWS\scmunins.exe moved successfully.
File\Folder C:\Program Files\BearShare Applications\BearShare not found.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\Data\3THVD6X8.K35\12E912MR.6K9\logm...app_43a0dbe7f0f75062_0002.0000_fb2d049b9d9d1328\Data folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\Data\3THVD6X8.K35\12E912MR.6K9\logm...app_43a0dbe7f0f75062_0002.0000_fb2d049b9d9d1328 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\Data\3THVD6X8.K35\12E912MR.6K9\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\Data\4.0.0.10 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\Data\3THVD6X8.K35\12E912MR.6K9\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\Data folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\Data\3THVD6X8.K35\12E912MR.6K9\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\Data\3THVD6X8.K35\12E912MR.6K9\curs..tion_eee711038731a406_0004.0000_1829574f2226d088\Data\4.0.0.10 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\Data\3THVD6X8.K35\12E912MR.6K9\curs..tion_eee711038731a406_0004.0000_1829574f2226d088\Data folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\Data\3THVD6X8.K35\12E912MR.6K9\curs..tion_eee711038731a406_0004.0000_1829574f2226d088 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\Data\3THVD6X8.K35\12E912MR.6K9 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\Data\3THVD6X8.K35 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\Data folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\zlib.net_47d7877cb3620160_0001.0000_none_755f576146efa063 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\xcee..rols_ba83ff368b7563c6_0003.0005_none_844b5f88f02013c1 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\xcee..grid_ba83ff368b7563c6_0003.0005_none_594a4965080405af folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\wpf.themes_8a76f3ebbd64ea05_0001.0000_none_7cf45c5deb30ea73 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\win3..erop_aa54df1bbb4d668d_0001.0000_none_3657a85e54652c34 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\micr..hell_31bf3856ad364e35_0003.0000_none_c495b3ffab1bf08e folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\manifests folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\logm..pper_b0844f777c844322_0001.0000_none_6cc4e9af56ac7e9d folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\logm...exe_43a0dbe7f0f75062_0002.0000_none_5ab79e38f031f926 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\logm...app_43a0dbe7f0f75062_0002.0000_fb2d049b9d9d1328 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\inte..elib_c85bb4cad3a5dfb5_0001.0000_none_2de83b338c8598e1 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\icsh..plib_08a258a57e9138b3_0000.0055_none_392f0ecbd2490bc8 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\gamm..glcd_79429b4c9fe572da_0001.0001_none_dbd9ed1f84806644 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\gamm..glcd_7904f4aa6fca30ba_0001.0001_none_1567cfb883b21611 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\gamm...wpf_f3239ab6a2f8f304_0001.0001_none_4082f3cc1e3c6874 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\gamm...wpf_79429b4c9fe572da_0001.0001_none_283a3ff44400930d folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curse_a9ab3e4b97c6f141_0001.0000_none_2639d79cd6d239af folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..zers_c85bb4cad3a5dfb5_0001.0000_none_311750f664a5eb21 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\fr-FR folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\ClientIcons folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..tion_eee711038731a406_0004.0000_1829574f2226d088\fr-FR folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..tion_eee711038731a406_0004.0000_1829574f2226d088\ClientIcons folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..tion_eee711038731a406_0004.0000_1829574f2226d088 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..tion_b0514d04fccbdb72_0001.0000_none_31aa88590a5e716c folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..tech_aa8c8c3656845a34_0001.0000_none_9f528297112c886a folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..tead_9511c547168a9246_0001.0000_none_790845a53f52abe0 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..rols_00072c358aa93735_0001.0000_none_b9453a0fa2a31513 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..rces_b0514d04fccbdb72_0001.0000_fr-fr_dd2c1cd776e13c74 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..mmon_c85bb4cad3a5dfb5_0001.0000_none_590134cd92e07a01 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..kens_447bcc00e712a048_0001.0000_none_5b0b9063dd0b7ca4 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..ions_7e7f879797d04a51_0001.0000_none_a248efbfe62cb319 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..ient_3cbc29eb0a26dbf9_0004.0000_none_0c5254890c13bfbf folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..hash_8432f15c15e06b4f_0001.0000_none_54bc766006c2d238 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..dons_a7ce87cfdd4ba154_0001.0000_none_88033998b61b4817 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..dels_823b3ca1d8c473c0_0001.0000_none_828d8225eff00f16 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs...exe_eee711038731a406_0004.0000_none_ba0e2cd14b9b2713\ClientIcons folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs...exe_eee711038731a406_0004.0000_none_ba0e2cd14b9b2713 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs...exe_eee711038731a406_0004.0000_none_23379ba22ddddf3d\ClientIcons folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs...exe_eee711038731a406_0004.0000_none_23379ba22ddddf3d folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps\2.0 folder moved successfully.
C:\Documents and Settings\Michal\Local Settings\Apps folder moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\BearShare Applications\BearShare\BearShare.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Documents and Settings\Michal\Local Settings\Apps\2.0\BP3AXN8K.38P\PDTP45A5.371\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\CurseClient.exe deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\\1505118141.elitistjerks.com not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: Admin

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Michal
->Temp folder emptied: 9849942 bytes
->Temporary Internet Files folder emptied: 5758984 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 64046773 bytes
->Flash cache emptied: 9697 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 555520 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1591 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 79981896 bytes

Total Files Cleaned = 153,00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 05142011_000032

Files\Folders moved on Reboot...
File\Folder C:\Documents and Settings\Michal\Local Settings\Temp\Perflib_Perfdata_838.dat not found!

Registry entries deleted on Reboot...

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu +

Příspěvekod jaro3 » 14 kvě 2011 10:58

Spusť OTL a klikni na Vyčisti.
Pak můžeš OTL smazat , C:\_OTL

Stáhni si Dial-a-fix

Explorer/IE/OE/shell/WMP - Pokusí se o opravu Internet Exploreru, Outlook Expressu, Windows Media Playeru atd.
Klikni na službu(dej zatržítko) a potom na GO.

Instalace programů Ti funguje?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

jogin
Level 1.5
Level 1.5
Příspěvky: 143
Registrován: říjen 10
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu +

Příspěvekod jogin » 15 kvě 2011 02:42

instalace programu funguje jen sem malinko nepochopil stím Dial-a-fix ... zaškrtnu Explorer/IE/OE/shell/WMP a go a nic se nestalo :-(....jen to projelo a nic :-( (asi mám dlouhý vedení)

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu +

Příspěvekod jaro3 » 15 kvě 2011 15:40

Jo , jen dát zatržítko a potom kliknout na GO.

http://wiki.lunarsoft.net/wiki/Dial-a-fix#WARNINGS
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

jogin
Level 1.5
Level 1.5
Příspěvky: 143
Registrován: říjen 10
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu +

Příspěvekod jogin » 15 kvě 2011 18:19

udělal sem a nic :-(

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu +

Příspěvekod jaro3 » 15 kvě 2011 20:34

Zkus zadat nové téma do sekce Software či Windows.

Vypni rez.ochrany a firewall.

Spusť F-Secure Online Scanner

Tento skener je možno použít jen v prohlížeči Internet Explorer! Postupuj podle instrukcí na stránce F-Secure pro správnou instalaci. Akceptuj licenci. Po instalaci ActiveX, klikni na Full System Scan. Když stahování skončeno, automaticky začne sken . Vyčkej konce skenu, po jeho dobu neprováděj jiné operace ani neklikej myší. Když skončí sken klikni na tlačítko Automatic clearing (recommended). Poté klikni na tlačítko Show Report a zkopíruj a vlož sem .
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 83 hostů