Prosím o kontrolu logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 04 bře 2012 22:06

Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
DRV - (NwlnkFwd) -- File not found
DRV - (NwlnkFlt) -- File not found
DRV - (IpInIp) -- File not found
DRV - (catchme) -- File not found
DRV - (ay22qd1p) -- File not found
DRV - (ALSysIO) -- File not found
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.2.1
FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.1.7.0190
FF - prefs.js..extensions.enabledItems: 2020Player_IKEA@2020Technologies.com:5.0.7.0
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.3.0.7550
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.23
[2011.03.03 19:37:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Pavel\AppData\Roaming\Mozilla\Extensions
[2011.03.03 19:37:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Pavel\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011.03.03 19:36:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Pavel\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2011.08.23 06:35:37 | 000,002,395 | ---- | M] () -- C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\odmiluok.default\searchplugins\askcom.xml
[2011.07.15 10:53:43 | 000,002,055 | ---- | M] () -- C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\odmiluok.default\searchplugins\daemon-search.xml
[2011.12.13 20:22:32 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2011.04.24 22:58:29 | 000,001,211 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 3dns.adobe.com 3dns-1.adobe.com 3dns-2.adobe.com 3dns-3.adobe.com 3dns-4.adobe.com activate.adobe.com activate-sea.adobe.com activate-sjc0.adobe.com activate.wip.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip1.adobe.com activate.wip2.adobe.com activate.wip3.adobe.com activate.wip4.adobe.com adobe-dns.adobe.com adobe-dns-1.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com adobe-dns-4.adobe.com
O1 - Hosts: 127.0.0.1 adobeereg.com practivate.adobe practivate.adobe.com practivate.adobe.newoa practivate.adobe.ntp practivate.adobe.ipp ereg.adobe.com ereg.wip.adobe.com ereg.wip1.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip2.adobe.com ereg.wip3.adobe.com ereg.wip4.adobe.com hl2rcv.adobe.com wip.adobe.com wip1.adobe.com wip2.adobe.com wip3.adobe.com wip4.adobe.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com wwis-dubc1-vip60.adobe.com www.wip.adobe.com www.wip1.adobe.com
O1 - Hosts: 127.0.0.1 www.wip2.adobe.com www.wip3.adobe.com www.wip4.adobe.com wwis-dubc1-vip60.adobe.com crl.verisign.net CRL.VERISIGN.NET ood.opsource.net
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4 - HKCU..\Run: [] File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O18 - Protocol\Handler\msdaipp - No CLSID value found
[2012.02.15 22:26:39 | 000,596,386 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2012.02.15 22:26:39 | 000,114,502 | ---- | M] () -- C:\Windows\System32\perfc005.dat
@Alternate Data Stream - 24 bytes -> C:\WINDOWS:30664EC915B01A92

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
c:\windows\Tasks\*.job
C:\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\Users\Pavel\AppData\Local\{4346567C-EE68-4F47-BABD-4283A115554E}
C:\32788R22FWJFW
C:\Users\Pavel\AppData\Local\{AB868BEA-71F9-4A6F-B656-BB412376A1BE}
C:\Users\Pavel\AppData\Local\{5DF074BD-7442-4092-AF1C-F8AAAB35B228}
C:\Users\Pavel\AppData\Local\{A2CABE67-19AA-4543-917B-F39FE06F0E3A}
C:\Users\Pavel\AppData\Local\{FDC915BB-9CE7-4D5D-AD8E-7AB506E985C9}
C:\Users\Pavel\AppData\Local\{7D6226AE-419B-4174-A66B-CFDE9F9E6B3D}
C:\Users\Pavel\AppData\Local\{E29BBD28-D7FD-47E9-B547-1C9972D31F4B}
C:\Users\Pavel\AppData\Local\{7FEF3781-70AE-4D77-9122-4C87B12B0310}
C:\Users\Pavel\AppData\Local\{60246203-E202-45EE-8A56-CCF00736166A}
C:\Users\Pavel\AppData\Local\{0D089E07-2300-4BE8-9180-BF41138972BF}
C:\Users\Pavel\AppData\Local\{C6B6842B-356A-49F3-81F8-4FC521AA0FBA}
C:\Users\Pavel\AppData\Local\{6C69EBB2-E732-4EEF-A9F2-B70679705924}
C:\Users\Pavel\AppData\Local\{B80FE49E-ED34-4299-BDA3-49102AB4A273}
C:\Users\Pavel\AppData\Local\{C5BB8ACF-C7EA-4B0D-827F-3BAA0A203CB6}
C:\Users\Pavel\AppData\Local\{E3EB04E2-9C73-4E77-8724-079F45AF3911}
C:\Users\Pavel\AppData\Local\{63C25B11-CC37-426E-8500-36ED82FA4F7E}
C:\Users\Pavel\AppData\Local\{48B744AB-5666-47B5-871F-CB74B079F68D}
C:\Users\Pavel\AppData\Local\{B6C1FED8-6BB4-4327-94BC-8C0EAB341E9E}
C:\Users\Pavel\AppData\Local\{8F1615BC-8A60-4546-9436-10F048A9B2D7}
C:\Users\Pavel\AppData\Local\{D9ADE3A9-013A-4982-8DC7-89DF08B7BD8F}
C:\Users\Pavel\AppData\Local\{630F00AB-BE21-43C6-B20F-E3B547C581C4}
C:\Users\Pavel\AppData\Local\{E2F12C4E-38AB-401D-A1C0-9F4450FC72D1}
C:\Users\Pavel\AppData\Local\6fd4b17e
C:\Users\Pavel\AppData\Local\{A5797B60-AEAC-4805-A971-BB8CC7997550}
C:\Users\Pavel\AppData\Local\{D72583BE-A44C-46D0-B86D-8EAF4CCADCFE}
C:\Users\Pavel\AppData\Local\{A9B8C2EF-2710-4C17-BBA8-C3887A35B599}
C:\Users\Pavel\AppData\Local\{911DE75B-803E-4CE9-A84F-909D5A15989B}
C:\Users\Pavel\AppData\Local\{646669E3-2BBA-410F-A5E4-1FE01AAC45F6}
C:\Users\Pavel\AppData\Local\{8874E827-83C2-4776-A929-AD2CFB4F73D8}
C:\Users\Pavel\AppData\Local\{A189E901-F219-43A6-8941-D2A135DD534D}
C:\Users\Pavel\AppData\Local\{45603B14-68FE-4F13-BD68-E033C959444E}
C:\Users\Pavel\AppData\Local\{960EAE33-C787-4CC7-AB05-4F3F0FAA4F51}
C:\Users\Pavel\AppData\Local\{B86F6C0B-F240-4D9F-AD0B-C1A0C80D5E2B}
C:\Users\Pavel\AppData\Local\{A5C021F1-3474-4163-9D23-61923318B65B}
C:\Users\Pavel\AppData\Local\{47B299C6-FC68-4064-A9FF-E8C316DCEA31}
C:\Users\Pavel\AppData\Local\{C5B3873D-E038-4055-AE1C-FAACD045D169}
C:\Users\Pavel\AppData\Local\{8320FDBA-7410-4B14-9BCE-323A57945315}
C:\Users\Pavel\AppData\Local\{3ED4130C-F75F-4DC0-8EC9-27437C4BAA22}
C:\Users\Pavel\AppData\Local\{92C2AFFD-EC61-4860-A2ED-B3593899BDE3}
C:\Users\Pavel\AppData\Local\{3F82BC81-388A-43B1-A1E0-352478D9757B}
C:\Users\Pavel\AppData\Local\{5B5D4159-7D50-43C3-89B0-FA036E3797A6}
C:\Users\Pavel\AppData\Local\{B9FB6702-FE90-4028-8D6D-E8B345F09D81}
C:\Users\Pavel\AppData\Local\{767A234B-F00C-4F1B-AE26-1E0B680B9823}
C:\Users\Pavel\AppData\Local\{9B5CB62B-6A8B-4971-8774-A770FAD8DD71}
C:\Users\Pavel\AppData\Local\{C35B6800-D036-476C-BE8F-A0C673F4DF3D}
C:\Users\Pavel\AppData\Local\{65D2A6B0-DE5B-4A9F-9BE4-2C817D55DAE5}
C:\Users\Pavel\AppData\Local\{25CEC230-045F-42A8-BDA3-E57A1EE5DB7C}
C:\Users\Pavel\AppData\Local\{6F75C112-B725-4FB7-902D-19D9DA29D5B9}
C:\Users\Pavel\AppData\Local\{5AD719EA-4668-4C91-B872-B0A7281502BC}
C:\Users\Pavel\AppData\Local\{6B73B974-750F-4417-AF17-9FDA0CC183FE}
C:\Users\Pavel\AppData\Local\{62455961-818A-4427-974D-25AF443836EB}
C:\Users\Pavel\AppData\Local\{CDDA935F-066A-479E-9AC6-9176AF7EEE71}
C:\Users\Pavel\AppData\Local\{09692F2B-DD21-46A5-BB89-259779006FB4}
C:\Users\Pavel\AppData\Local\{C2B93CAE-EC34-45CB-8655-2940C69D1FA0}
C:\Users\Pavel\AppData\Local\{8EFC7019-0A0A-4AE8-A6F3-44FF804E86EB}
C:\Users\Pavel\AppData\Local\{BCFCB235-2D0D-43BE-8D73-7574FD7A4AEE}
C:\Users\Pavel\AppData\Local\{3F9A9B88-DBBB-49EA-81B4-9D3EC0D051CF}
C:\Users\Pavel\AppData\Local\{BBD2FFC1-40C0-4428-AC31-86E18737EFC8}
C:\Users\Pavel\AppData\Local\{30E5239C-32AA-4C76-B97C-FFFB0BA5E03E}
C:\Users\Pavel\AppData\Local\{9033C297-F740-42C8-862B-E294BCB25602}
C:\Users\Pavel\AppData\Local\{69E8F162-192B-4DA1-84EB-3141A0C1458B}
C:\Users\Pavel\AppData\Local\{6A7BCC4A-2B80-45B6-8443-EB8053D2B28D}
C:\Users\Pavel\AppData\Local\{3A72C56E-8F0D-4894-BF43-3B3B98447098}
C:\Users\Pavel\AppData\Local\{E18A9741-5793-4B4E-8022-E94FAFA331A5}
C:\Users\Pavel\AppData\Local\{7C510711-FC78-4F94-87DF-F7E68084808D}
C:\Users\Pavel\AppData\Local\{F1F5BB94-359F-4477-8D48-040253FBB1B9}
C:\Users\Pavel\AppData\Local\{98E1F4F6-05A7-463E-A430-A1C54093F00D}
C:\Users\Pavel\AppData\Local\{A4B0CF9D-A5B3-4EFC-B683-11A61E996D32}
C:\Users\Pavel\AppData\Local\{BC450099-1197-49F4-B74A-811474D65DF9}
C:\Users\Pavel\AppData\Local\{F6C3CD53-156A-4EFA-A6E3-1385869AA500}
C:\Users\Pavel\AppData\Local\{623D8503-D4AE-44CA-B38C-E8535A91BB5B}
C:\Users\Pavel\AppData\Local\{C4720592-E523-4F02-8F97-DE6C51141164}
C:\Users\Pavel\AppData\Local\{2F3EA626-A7DD-4A5C-AF5C-801DA2B716D2}
C:\Users\Pavel\AppData\Local\{9D3A2F72-72A8-4A7C-8BB8-552ECDB82B04}
C:\Users\Pavel\AppData\Local\{12BBC18F-C489-4226-B7AB-0210CFAFCCB9}
C:\Users\Pavel\AppData\Local\{AB590C1B-A2DE-4CEF-ADE5-B00EDBBD87D3}
C:\Users\Pavel\AppData\Local\{EF9811F2-7833-41C3-A4D7-3E8CA48244D0}
C:\Users\Pavel\AppData\Local\{1D7DD209-7822-4983-A140-C5A7CD71C3DE}
C:\Users\Pavel\AppData\Local \{98FBB903-39FA-4795-B7E8-DAE3BC461BD6}
C:\Users\Pavel\AppData\Local\{31630DF1-D800-4402-A7C1-0A9240CC4D8F}
C:\Users\Pavel\AppData\Local\{00A74554-13DC-4F0A-9BD8-96B81441A19F}
C:\Users\Pavel\AppData\Local\{F8492A4F-7CF3-4D3F-86B4-34F19F2A8131}
C:\Users\Pavel\AppData\Local\{24E3F626-F90C-4DEF-8FC9-795A5A0A89AD}
C:\Users\Pavel\AppData\Local\{1A64A377-012A-4664-9184-13A1569E1D4F}
C:\Users\Pavel\AppData\Local\{9DBA71EF-606E-4EE6-BD5A-5B2691ECBC7F}
C:\Users\Pavel\AppData\Local\{39AB1633-CA14-4E99-9164-61217B5F9102}
C:\Users\Pavel\AppData\Local\{FEF6CCAC-8D4F-4FFC-8700-BCC7154B1CF1}
C:\Users\Pavel\AppData\Local\{E786E943-AEB9-4EFF-A27E-F55006A222A8}
C:\Users\Pavel\AppData\Local\{F33872F9-BDF4-468F-BE2F-8FF0FA84E3CB}
C:\Users\Pavel\AppData\Local\{54862B81-6752-4DC7-9E12-6761A4B4F827}
C:\Users\Pavel\AppData\Local\{362BB96A-AA5E-4268-9B76-EEEB6399711D}
C:\Windows\bthservsdp.dat
C:\Users\Pavel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\Users\Pavel\AppData\Local\Temp5.html
C:\Users\Pavel\AppData\Local\Temp14.html
C:\Users\Pavel\AppData\Local\Temp1.html
C:\ProgramData\ezsidmv.dat
C:\Users\Pavel\AppData\Roaming\wklnhst.dat
C:\Windows\ativpsrm.bin

:Reg
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.

Aktualizuj javu:
Java SE Runtime Environment 7

Klikni na Accept License Agreement
Vyber si OS (Windows nebo Windows x64, Offline Installation)
jre-7-windows-i586-p.exe nebo
jre-7-windows-x64.exe
Stáhni ( download) a nainstaluj.
Ostatní javy odeber v přidat/odebrat programy.

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
C:\Windows\tbuninst2.exe
C:\Windows\System32\trc.dll
C:\Windows\System32\IcdSptSvps.dll
C:\Windows\System32\dsp_trc.dll
C:\Windows\System32\StructuredQuerySchema.bin

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.


C:\Users\Pavel\Desktop\hj---znáš?
C:\Users\Pavel\01046997.xlt ---znáš?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Reklama
jaruska
Level 2.5
Level 2.5
Příspěvky: 285
Registrován: listopad 07
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaruska » 05 bře 2012 07:07

C:\Users\Pavel\Desktop\hj - tady mám uložený hijackthis a měla jsem tady uložené logy.
C:\Users\Pavel\01046997.xlt - šablona aplikace Misrosft Office Excel (stažené z netu - na výpočet nákladů na přestavbu kuchyně) bohužel už si nevzpomenu odkud jsem to stáhla. Mám to smazat?

A tady je log z OTL

All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
Service NwlnkFwd stopped successfully!
Service NwlnkFwd deleted successfully!
File File not found not found.
Service NwlnkFlt stopped successfully!
Service NwlnkFlt deleted successfully!
File File not found not found.
Service IpInIp stopped successfully!
Service IpInIp deleted successfully!
File File not found not found.
Service catchme stopped successfully!
Service catchme deleted successfully!
File File not found not found.
Error: No service named ay22qd1p was found to stop!
Service\Driver key ay22qd1p not found.
File File not found not found.
Service ALSysIO stopped successfully!
Service ALSysIO deleted successfully!
File File not found not found.
Prefs.js: "Ask.com" removed from browser.search.defaultengine
Prefs.js: "Ask.com" removed from browser.search.defaultenginename
Prefs.js: "Ask.com" removed from browser.search.order.1
Prefs.js: {20a82645-c095-46ed-80e3-08825760534b}:1.2.1 removed from extensions.enabledItems
Prefs.js: DTToolbar@toolbarnet.com:1.1.7.0190 removed from extensions.enabledItems
Prefs.js: 2020Player_IKEA@2020Technologies.com:5.0.7.0 removed from extensions.enabledItems
Prefs.js: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.3.0.7550 removed from extensions.enabledItems
Prefs.js: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.23 removed from extensions.enabledItems
C:\Users\Pavel\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} folder moved successfully.
C:\Users\Pavel\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} folder moved successfully.
C:\Users\Pavel\AppData\Roaming\Mozilla\Extensions folder moved successfully.
Folder C:\Users\Pavel\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}\ not found.
Folder C:\Users\Pavel\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\ not found.
C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\odmiluok.default\searchplugins\askcom.xml moved successfully.
C:\Users\Pavel\AppData\Roaming\Mozilla\Firefox\Profiles\odmiluok.default\searchplugins\daemon-search.xml moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\chrome\icons\default folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\chrome\icons folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\chrome folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions folder moved successfully.
127.0.0.1 localhost removed from HOSTS file successfully
127.0.0.1 3dns.adobe.com 3dns-1.adobe.com 3dns-2.adobe.com 3dns-3.adobe.com 3dns-4.adobe.com activate.adobe.com activate-sea.adobe.com activate-sjc0.adobe.com activate.wip.adobe.com removed from HOSTS file successfully
127.0.0.1 activate.wip1.adobe.com activate.wip2.adobe.com activate.wip3.adobe.com activate.wip4.adobe.com adobe-dns.adobe.com adobe-dns-1.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com adobe-dns-4.adobe.com removed from HOSTS file successfully
127.0.0.1 adobeereg.com practivate.adobe practivate.adobe.com practivate.adobe.newoa practivate.adobe.ntp practivate.adobe.ipp ereg.adobe.com ereg.wip.adobe.com ereg.wip1.adobe.com removed from HOSTS file successfully
127.0.0.1 ereg.wip2.adobe.com ereg.wip3.adobe.com ereg.wip4.adobe.com hl2rcv.adobe.com wip.adobe.com wip1.adobe.com wip2.adobe.com wip3.adobe.com wip4.adobe.com removed from HOSTS file successfully
127.0.0.1 www.adobeereg.com wwis-dubc1-vip60.adobe.com www.wip.adobe.com www.wip1.adobe.com removed from HOSTS file successfully
127.0.0.1 www.wip2.adobe.com www.wip3.adobe.com www.wip4.adobe.com wwis-dubc1-vip60.adobe.com crl.verisign.net CRL.VERISIGN.NET ood.opsource.net removed from HOSTS file successfully
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Infodelivery\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\ deleted successfully.
File Protocol\Handler\msdaipp - No CLSID value found not found.
C:\WINDOWS\System32\perfh005.dat moved successfully.
C:\WINDOWS\System32\perfc005.dat moved successfully.
ADS C:\WINDOWS:30664EC915B01A92 deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\System32\*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\System32\dllcache\*.tmp not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully.
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully.
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2350472932-3067249167-3264205739-1000Core.job moved successfully.
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2350472932-3067249167-3264205739-1000UA.job moved successfully.
File\Folder C:\*.tmp not found.
File\Folder C:\Documents and Settings\All Users\Data aplikací\*.tmp not found.
C:\Users\Pavel\AppData\Local\{4346567C-EE68-4F47-BABD-4283A115554E} folder moved successfully.
C:\32788R22FWJFW folder moved successfully.
C:\Users\Pavel\AppData\Local\{AB868BEA-71F9-4A6F-B656-BB412376A1BE} folder moved successfully.
C:\Users\Pavel\AppData\Local\{5DF074BD-7442-4092-AF1C-F8AAAB35B228} folder moved successfully.
C:\Users\Pavel\AppData\Local\{A2CABE67-19AA-4543-917B-F39FE06F0E3A} folder moved successfully.
C:\Users\Pavel\AppData\Local\{FDC915BB-9CE7-4D5D-AD8E-7AB506E985C9} folder moved successfully.
C:\Users\Pavel\AppData\Local\{7D6226AE-419B-4174-A66B-CFDE9F9E6B3D} folder moved successfully.
C:\Users\Pavel\AppData\Local\{E29BBD28-D7FD-47E9-B547-1C9972D31F4B} folder moved successfully.
C:\Users\Pavel\AppData\Local\{7FEF3781-70AE-4D77-9122-4C87B12B0310} folder moved successfully.
C:\Users\Pavel\AppData\Local\{60246203-E202-45EE-8A56-CCF00736166A} folder moved successfully.
C:\Users\Pavel\AppData\Local\{0D089E07-2300-4BE8-9180-BF41138972BF} folder moved successfully.
C:\Users\Pavel\AppData\Local\{C6B6842B-356A-49F3-81F8-4FC521AA0FBA} folder moved successfully.
C:\Users\Pavel\AppData\Local\{6C69EBB2-E732-4EEF-A9F2-B70679705924} folder moved successfully.
C:\Users\Pavel\AppData\Local\{B80FE49E-ED34-4299-BDA3-49102AB4A273} folder moved successfully.
C:\Users\Pavel\AppData\Local\{C5BB8ACF-C7EA-4B0D-827F-3BAA0A203CB6} folder moved successfully.
C:\Users\Pavel\AppData\Local\{E3EB04E2-9C73-4E77-8724-079F45AF3911} folder moved successfully.
C:\Users\Pavel\AppData\Local\{63C25B11-CC37-426E-8500-36ED82FA4F7E} folder moved successfully.
C:\Users\Pavel\AppData\Local\{48B744AB-5666-47B5-871F-CB74B079F68D} folder moved successfully.
C:\Users\Pavel\AppData\Local\{B6C1FED8-6BB4-4327-94BC-8C0EAB341E9E} folder moved successfully.
C:\Users\Pavel\AppData\Local\{8F1615BC-8A60-4546-9436-10F048A9B2D7} folder moved successfully.
C:\Users\Pavel\AppData\Local\{D9ADE3A9-013A-4982-8DC7-89DF08B7BD8F} folder moved successfully.
C:\Users\Pavel\AppData\Local\{630F00AB-BE21-43C6-B20F-E3B547C581C4} folder moved successfully.
C:\Users\Pavel\AppData\Local\{E2F12C4E-38AB-401D-A1C0-9F4450FC72D1} folder moved successfully.
C:\Users\Pavel\AppData\Local\6fd4b17e\U folder moved successfully.
C:\Users\Pavel\AppData\Local\6fd4b17e folder moved successfully.
C:\Users\Pavel\AppData\Local\{A5797B60-AEAC-4805-A971-BB8CC7997550} folder moved successfully.
C:\Users\Pavel\AppData\Local\{D72583BE-A44C-46D0-B86D-8EAF4CCADCFE} folder moved successfully.
C:\Users\Pavel\AppData\Local\{A9B8C2EF-2710-4C17-BBA8-C3887A35B599} folder moved successfully.
C:\Users\Pavel\AppData\Local\{911DE75B-803E-4CE9-A84F-909D5A15989B} folder moved successfully.
C:\Users\Pavel\AppData\Local\{646669E3-2BBA-410F-A5E4-1FE01AAC45F6} folder moved successfully.
C:\Users\Pavel\AppData\Local\{8874E827-83C2-4776-A929-AD2CFB4F73D8} folder moved successfully.
C:\Users\Pavel\AppData\Local\{A189E901-F219-43A6-8941-D2A135DD534D} folder moved successfully.
C:\Users\Pavel\AppData\Local\{45603B14-68FE-4F13-BD68-E033C959444E} folder moved successfully.
C:\Users\Pavel\AppData\Local\{960EAE33-C787-4CC7-AB05-4F3F0FAA4F51} folder moved successfully.
C:\Users\Pavel\AppData\Local\{B86F6C0B-F240-4D9F-AD0B-C1A0C80D5E2B} folder moved successfully.
C:\Users\Pavel\AppData\Local\{A5C021F1-3474-4163-9D23-61923318B65B} folder moved successfully.
C:\Users\Pavel\AppData\Local\{47B299C6-FC68-4064-A9FF-E8C316DCEA31} folder moved successfully.
C:\Users\Pavel\AppData\Local\{C5B3873D-E038-4055-AE1C-FAACD045D169} folder moved successfully.
C:\Users\Pavel\AppData\Local\{8320FDBA-7410-4B14-9BCE-323A57945315} folder moved successfully.
C:\Users\Pavel\AppData\Local\{3ED4130C-F75F-4DC0-8EC9-27437C4BAA22} folder moved successfully.
C:\Users\Pavel\AppData\Local\{92C2AFFD-EC61-4860-A2ED-B3593899BDE3} folder moved successfully.
C:\Users\Pavel\AppData\Local\{3F82BC81-388A-43B1-A1E0-352478D9757B} folder moved successfully.
C:\Users\Pavel\AppData\Local\{5B5D4159-7D50-43C3-89B0-FA036E3797A6} folder moved successfully.
C:\Users\Pavel\AppData\Local\{B9FB6702-FE90-4028-8D6D-E8B345F09D81} folder moved successfully.
C:\Users\Pavel\AppData\Local\{767A234B-F00C-4F1B-AE26-1E0B680B9823} folder moved successfully.
C:\Users\Pavel\AppData\Local\{9B5CB62B-6A8B-4971-8774-A770FAD8DD71} folder moved successfully.
C:\Users\Pavel\AppData\Local\{C35B6800-D036-476C-BE8F-A0C673F4DF3D} folder moved successfully.
C:\Users\Pavel\AppData\Local\{65D2A6B0-DE5B-4A9F-9BE4-2C817D55DAE5} folder moved successfully.
C:\Users\Pavel\AppData\Local\{25CEC230-045F-42A8-BDA3-E57A1EE5DB7C} folder moved successfully.
C:\Users\Pavel\AppData\Local\{6F75C112-B725-4FB7-902D-19D9DA29D5B9} folder moved successfully.
C:\Users\Pavel\AppData\Local\{5AD719EA-4668-4C91-B872-B0A7281502BC} folder moved successfully.
C:\Users\Pavel\AppData\Local\{6B73B974-750F-4417-AF17-9FDA0CC183FE} folder moved successfully.
C:\Users\Pavel\AppData\Local\{62455961-818A-4427-974D-25AF443836EB} folder moved successfully.
C:\Users\Pavel\AppData\Local\{CDDA935F-066A-479E-9AC6-9176AF7EEE71} folder moved successfully.
C:\Users\Pavel\AppData\Local\{09692F2B-DD21-46A5-BB89-259779006FB4} folder moved successfully.
C:\Users\Pavel\AppData\Local\{C2B93CAE-EC34-45CB-8655-2940C69D1FA0} folder moved successfully.
C:\Users\Pavel\AppData\Local\{8EFC7019-0A0A-4AE8-A6F3-44FF804E86EB} folder moved successfully.
C:\Users\Pavel\AppData\Local\{BCFCB235-2D0D-43BE-8D73-7574FD7A4AEE} folder moved successfully.
C:\Users\Pavel\AppData\Local\{3F9A9B88-DBBB-49EA-81B4-9D3EC0D051CF} folder moved successfully.
C:\Users\Pavel\AppData\Local\{BBD2FFC1-40C0-4428-AC31-86E18737EFC8} folder moved successfully.
C:\Users\Pavel\AppData\Local\{30E5239C-32AA-4C76-B97C-FFFB0BA5E03E} folder moved successfully.
C:\Users\Pavel\AppData\Local\{9033C297-F740-42C8-862B-E294BCB25602} folder moved successfully.
C:\Users\Pavel\AppData\Local\{69E8F162-192B-4DA1-84EB-3141A0C1458B} folder moved successfully.
C:\Users\Pavel\AppData\Local\{6A7BCC4A-2B80-45B6-8443-EB8053D2B28D} folder moved successfully.
C:\Users\Pavel\AppData\Local\{3A72C56E-8F0D-4894-BF43-3B3B98447098} folder moved successfully.
C:\Users\Pavel\AppData\Local\{E18A9741-5793-4B4E-8022-E94FAFA331A5} folder moved successfully.
C:\Users\Pavel\AppData\Local\{7C510711-FC78-4F94-87DF-F7E68084808D} folder moved successfully.
C:\Users\Pavel\AppData\Local\{F1F5BB94-359F-4477-8D48-040253FBB1B9} folder moved successfully.
C:\Users\Pavel\AppData\Local\{98E1F4F6-05A7-463E-A430-A1C54093F00D} folder moved successfully.
C:\Users\Pavel\AppData\Local\{A4B0CF9D-A5B3-4EFC-B683-11A61E996D32} folder moved successfully.
C:\Users\Pavel\AppData\Local\{BC450099-1197-49F4-B74A-811474D65DF9} folder moved successfully.
C:\Users\Pavel\AppData\Local\{F6C3CD53-156A-4EFA-A6E3-1385869AA500} folder moved successfully.
C:\Users\Pavel\AppData\Local\{623D8503-D4AE-44CA-B38C-E8535A91BB5B} folder moved successfully.
C:\Users\Pavel\AppData\Local\{C4720592-E523-4F02-8F97-DE6C51141164} folder moved successfully.
C:\Users\Pavel\AppData\Local\{2F3EA626-A7DD-4A5C-AF5C-801DA2B716D2} folder moved successfully.
C:\Users\Pavel\AppData\Local\{9D3A2F72-72A8-4A7C-8BB8-552ECDB82B04} folder moved successfully.
C:\Users\Pavel\AppData\Local\{12BBC18F-C489-4226-B7AB-0210CFAFCCB9} folder moved successfully.
C:\Users\Pavel\AppData\Local\{AB590C1B-A2DE-4CEF-ADE5-B00EDBBD87D3} folder moved successfully.
C:\Users\Pavel\AppData\Local\{EF9811F2-7833-41C3-A4D7-3E8CA48244D0} folder moved successfully.
C:\Users\Pavel\AppData\Local\{1D7DD209-7822-4983-A140-C5A7CD71C3DE} folder moved successfully.
File\Folder C:\Users\Pavel\AppData\Local \{98FBB903-39FA-4795-B7E8-DAE3BC461BD6} not found.
C:\Users\Pavel\AppData\Local\{31630DF1-D800-4402-A7C1-0A9240CC4D8F} folder moved successfully.
C:\Users\Pavel\AppData\Local\{00A74554-13DC-4F0A-9BD8-96B81441A19F} folder moved successfully.
C:\Users\Pavel\AppData\Local\{F8492A4F-7CF3-4D3F-86B4-34F19F2A8131} folder moved successfully.
C:\Users\Pavel\AppData\Local\{24E3F626-F90C-4DEF-8FC9-795A5A0A89AD} folder moved successfully.
C:\Users\Pavel\AppData\Local\{1A64A377-012A-4664-9184-13A1569E1D4F} folder moved successfully.
C:\Users\Pavel\AppData\Local\{9DBA71EF-606E-4EE6-BD5A-5B2691ECBC7F} folder moved successfully.
C:\Users\Pavel\AppData\Local\{39AB1633-CA14-4E99-9164-61217B5F9102} folder moved successfully.
C:\Users\Pavel\AppData\Local\{FEF6CCAC-8D4F-4FFC-8700-BCC7154B1CF1} folder moved successfully.
C:\Users\Pavel\AppData\Local\{E786E943-AEB9-4EFF-A27E-F55006A222A8} folder moved successfully.
C:\Users\Pavel\AppData\Local\{F33872F9-BDF4-468F-BE2F-8FF0FA84E3CB} folder moved successfully.
C:\Users\Pavel\AppData\Local\{54862B81-6752-4DC7-9E12-6761A4B4F827} folder moved successfully.
C:\Users\Pavel\AppData\Local\{362BB96A-AA5E-4268-9B76-EEEB6399711D} folder moved successfully.
C:\Windows\bthservsdp.dat moved successfully.
C:\Users\Pavel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.
C:\Users\Pavel\AppData\Local\Temp5.html moved successfully.
C:\Users\Pavel\AppData\Local\Temp14.html moved successfully.
C:\Users\Pavel\AppData\Local\Temp1.html moved successfully.
C:\ProgramData\ezsidmv.dat moved successfully.
C:\Users\Pavel\AppData\Roaming\wklnhst.dat moved successfully.
C:\Windows\ativpsrm.bin moved successfully.
========== REGISTRY ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56502 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Hanka
->Temp folder emptied: 25208059 bytes
->Temporary Internet Files folder emptied: 287419 bytes
->Java cache emptied: 115472 bytes
->FireFox cache emptied: 5208862 bytes
->Google Chrome cache emptied: 6480122 bytes
->Opera cache emptied: 21296122 bytes
->Flash cache emptied: 2189 bytes

User: Pavel
->Temp folder emptied: 2102623 bytes
->Temporary Internet Files folder emptied: 3007552 bytes
->Java cache emptied: 1843915 bytes
->FireFox cache emptied: 47623841 bytes
->Google Chrome cache emptied: 0 bytes
->Opera cache emptied: 7446886 bytes
->Flash cache emptied: 57427 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 444029 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 116,00 mb


OTL by OldTimer - Version 3.2.35.0 log created on 03052012_064600

Files\Folders moved on Reboot...
File\Folder C:\Windows\temp\SEPA7F5.tmp not found!

Registry entries deleted on Reboot...


Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 05 bře 2012 09:19

Když to znáš , tak to nemusíš mazat.

Spusť OTL a klikni na Vyčisti.

Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

jaruska
Level 2.5
Level 2.5
Příspěvky: 285
Registrován: listopad 07
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaruska » 05 bře 2012 21:08

OTL spuštěno, PC vyčištěn, ale zůstal mi ještě jeden problém. V průběhu opravy PC přestala fungovat čtečka prstů. Vím, že se to nastavovalo při instalaci, ale teď to nemůžu najít, kde to nastavit. Můžete mi poradit ještě s tímto?

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 05 bře 2012 22:43

S tím asi ne , zadej nové téma do jiné sekce , tady dej zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

jaruska
Level 2.5
Level 2.5
Příspěvky: 285
Registrován: listopad 07
Pohlaví: Žena
Stav:
Offline

Re: Prosím o kontrolu logu  Vyřešeno

Příspěvekod jaruska » 05 bře 2012 22:50

Díky moc všem za pomoc. Jarka


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 94 hostů