Prosba o kontrolu logu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

TKroupa323
nováček
Příspěvky: 4
Registrován: prosinec 13
Pohlaví: Muž
Stav:
Offline

Prosba o kontrolu logu

Příspěvekod TKroupa323 » 04 pro 2013 21:40

Ahoj lidi,
myslím, že jde o Vám dobře známej problém s psaním háčků a čárek (ˇˇ ´´), prosím o kontrolu logu:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:34:53, on 4.12.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal

Running processes:
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\windows\system32\msiexec.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\windows\system32\igfxsrvc.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\windows\system32\conhost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\McAfee Security Scan\3.0.285\SSScheduler.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files\SopCast\SopCast.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe
C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe
C:\windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com/?l=dis&o=14672
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O2 - BHO: GomPicker - {F0181C6E-9218-4792-9F3C-E8DF52B2F1AC} - C:\Program Files\GRETECH\GomPicker\GomPickerBHO.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [QLBController] C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [IgfxTray] C:\windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [NeroCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [DivX Download Manager] "C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe" start
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [NSU_agent] "C:\Program Files\Nokia\Nokia Software Updater\nsu3ui_agent.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\RunOnce: [NCPluginUpdater] "C:\Program Files\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update
O4 - HKCU\..\Run: [ISUSPM] -scheduler
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [iTV] C:\Program Files\iTV\iTV.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [EPSON Stylus SX400 Series] C:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIEGE.EXE /FU "C:\Users\tom\AppData\Local\Temp\E_SC464.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Uggeor] C:\Users\tom\AppData\Roaming\Ogortu\uggeor.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.0.285\SSScheduler.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://c:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést cíl vazby do existujícího PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést do existujícího PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést vybrané vazby do Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést vybrané vazby do existujícího PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Převést výběr do Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést výběr do existujícího PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: @C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.mcafee.com (HKLM)
O15 - Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://www.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://*.mcafee.com (HKLM)
O15 - ESC Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://www.mcafeeasap.com (HKLM)
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\aestsrv.exe
O23 - Service: AppBooster Service (AppBoosterService) - 2tox - C:\Program Files\Common Files\2ToX Common\BoostService.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Hotkey Monitor (hpHotkeyMonitor) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.0.285\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\stlang.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe

--
End of file - 16145 bytes
Díky za pomoc ;-)
Naposledy upravil(a) TKroupa323 dne 04 pro 2013 21:49, celkem upraveno 1 x.

Reklama
Uživatelský avatar
wattmetr
Master Level 7.5
Master Level 7.5
Příspěvky: 5744
Registrován: duben 13
Pohlaví: Nespecifikováno
Stav:
Offline

Re: ˇˇ/´´

Příspěvekod wattmetr » 04 pro 2013 21:42

Vítej na PC-help!

Dej tomu nějaký normální název, jinak se obávám, že se pomoci nedočkáš.
Trvalý BAN za trolling a dlouhodobé nerespektování pravidel fóra, duplicitní účty tohoto uživatele: satam, peyrac10, wattmetr, gracia (vydávání se za ženu), jamesbond, jamesbond1...

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosba o kontrolu logu

Příspěvekod jaro3 » 05 pro 2013 09:49

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.


Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.

Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

TKroupa323
nováček
Příspěvky: 4
Registrován: prosinec 13
Pohlaví: Muž
Stav:
Offline

Re: Prosba o kontrolu logu

Příspěvekod TKroupa323 » 05 pro 2013 11:19

# AdwCleaner v3.014 - Report created 05/12/2013 at 10:55:56
# Updated 01/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
# Username : tom - TOM_NTB
# Running from : C:\Users\tom\Desktop\adwcleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

File Found : C:\windows\System32\Tasks\YourFile Update
Folder Found C:\ProgramData\Ask
Folder Found C:\Users\tom\AppData\Local\OpenCandy
Folder Found C:\Users\tom\AppData\LocalLow\boost_interprocess
Folder Found C:\Users\tom\AppData\LocalLow\Toolbar4

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\APN PIP
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\FLEXnet
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Found : HKCU\Software\Pokki
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\StartSearch
Key Found : HKCU\Software\YahooPartnerToolbar
Key Found : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{3BCF582D-CA87-4C6F-AF3D-B3548A976AB3}
Key Found : HKLM\Software\Conduit
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4250488A-CB24-0893-C066-B1AEA57BCFF2}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{603C4CC9-5DC6-4C44-873F-8281509DF953}
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_pokemon-simulator_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_pokemon-simulator_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\YourFile_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\YourFile_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\YourFileUpdater_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\YourFileUpdater_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\YourFile Update
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4F6E7A6F-67B9-4F54-BBFD-40A98D9CD74E}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
Key Found : HKLM\Software\PIP
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{0329E7D6-6F54-462D-93F6-F5C3118BADF2}]

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428

Setting Found : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://eu.ask.com/?l=dis&o=14672

-\\ Mozilla Firefox v25.0.1 (cs)

[ File : C:\Users\tom\AppData\Roaming\Mozilla\Firefox\Profiles\16r8e0ik.default-1379603259417\prefs.js ]


*************************

AdwCleaner[R0].txt - [4047 octets] - [05/12/2013 10:55:56]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [4107 octets] ##########

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2013.12.04.09

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.16428
tom :: TOM_NTB [administrátor]

5.12.2013 11:09:37
mbam-log-2013-12-05 (11-09-37).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 219644
Uplynulý čas: 9 minut, 2 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosba o kontrolu logu

Příspěvekod jaro3 » 05 pro 2013 18:43

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
Klikni na „ Vymazat-Clean
Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [S?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool

na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Zkontroluj , zda máš zaškrtnuto:
Kontrola MBR
Kontrola Faked
Antirootkit

-Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

TKroupa323
nováček
Příspěvky: 4
Registrován: prosinec 13
Pohlaví: Muž
Stav:
Offline

Re: Prosba o kontrolu logu

Příspěvekod TKroupa323 » 12 pro 2013 22:00

# AdwCleaner v3.015 - Report created 12/12/2013 at 21:22:21
# Updated 10/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
# Username : tom - TOM_NTB
# Running from : C:\Users\tom\Desktop\Sračky\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\Users\tom\AppData\Local\OpenCandy
Folder Deleted : C:\Users\tom\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\tom\AppData\LocalLow\Toolbar4
File Deleted : C:\windows\System32\Tasks\YourFile Update

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{0329E7D6-6F54-462D-93F6-F5C3118BADF2}]
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4F6E7A6F-67B9-4F54-BBFD-40A98D9CD74E}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4F6E7A6F-67B9-4F54-BBFD-40A98D9CD74E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YourFile_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YourFile_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YourFileUpdater_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\YourFileUpdater_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_pokemon-simulator_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_pokemon-simulator_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3BCF582D-CA87-4C6F-AF3D-B3548A976AB3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4250488A-CB24-0893-C066-B1AEA57BCFF2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{603C4CC9-5DC6-4C44-873F-8281509DF953}
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\FLEXnet
Key Deleted : HKCU\Software\Pokki
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\StartSearch
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\dt soft\daemon tools toolbar
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

-\\ Mozilla Firefox v25.0.1 (cs)

[ File : C:\Users\tom\AppData\Roaming\Mozilla\Firefox\Profiles\16r8e0ik.default-1379603259417\prefs.js ]


*************************

AdwCleaner[R0].txt - [4187 octets] - [05/12/2013 10:55:56]
AdwCleaner[R1].txt - [4574 octets] - [12/12/2013 21:20:24]
AdwCleaner[S0].txt - [4598 octets] - [12/12/2013 21:22:21]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4658 octets] ##########



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x86
Ran by tom on źt 12.12.2013 at 21:43:34,47
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values




~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{83E0F7CA-383E-4723-8046-1DF12C109DA6}



~~~ Files



~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{04446F5B-5C41-482E-B9C2-551E6D8448B5}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{1239C97B-0850-403B-B00F-3F686276C8E1}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{14E1BB4D-6F48-439B-A69A-5655B2F94D45}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{1BC38E1E-FE1A-491C-A3D9-C7BDB8FAE4CB}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{1D2029A1-4C3C-42F0-9913-99D763E26D80}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{30253118-235F-42A1-9CF2-B2DF143E5E1A}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{305EA76C-DB36-42FA-9CD7-03B0A737CBBC}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{3FA957B9-4AD8-4861-A579-41EC4885F197}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{4CB53989-58FE-4AA8-8480-0353AED0739F}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{53609FBC-1EF4-4F00-8A83-6D8F09E89FAA}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{53A15FEE-C9E9-41F2-906C-AC32022FB3D5}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{545CFB1F-2176-4F02-9D10-9B847841B7DA}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{5B61F957-2856-4E79-B2B6-C1AEBF2D0398}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{5CAA2B99-11CD-4F49-B10A-B3D448C512F9}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{5E0E070E-A2F6-4711-A1E8-617DFEBFEED4}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{6ACE36EE-65AD-4CC4-88BE-B417B2C4B7A2}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{6C98418B-4B91-4A5D-B4D7-E27B9B6151D6}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{713BDC8E-90D2-426A-AC9F-FDE20F226DF0}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{86523BFB-E30A-4869-8126-4C044F7F02C8}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{8C860AEA-27B1-44CD-803B-EAFC9621CF95}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{8F36FE13-CDF0-4C5C-B92F-4711CA01E157}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{9B0371FD-661E-4E4F-AD9D-9CC3BF6B0FD5}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{A3787A22-DB3B-4C82-8393-FD5A07763C2E}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{B3AB0FF5-74D8-4F8B-B0CD-2E7009A34947}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{B3FBCF23-D2ED-4E58-A768-A9D2DA37B7E0}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{BB0E2D3D-A9B6-40C0-969C-2D80C5E6907D}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{C1719272-CF75-48CF-AC1A-07C41C3E5777}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{C3A788CF-CCED-43EB-A496-BBA19ADE9324}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{C572D52C-3213-4CA4-A5DE-AB5865E5E785}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{CA57D2A1-D241-443F-A5FF-B9E6EB81628C}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{CA76D92A-64DA-4DCF-A460-1EC39B9C6781}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{CF0DD9D2-D973-4888-B6EF-F1275A307AF7}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{E8854BF4-28E6-4333-86A0-210E94FED72C}
Successfully deleted: [Empty Folder] C:\Users\tom\appdata\local\{FC4058B2-831D-4CCB-90FE-FBB0FD2F4BFB}



~~~ FireFox

Emptied folder: C:\Users\tom\AppData\Roaming\mozilla\firefox\profiles\16r8e0ik.default-1379603259417\minidumps [25 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 12.12.2013 at 21:49:19,81
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


RogueKiller V8.7.11 [Dec 3 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : tom [Práva správce]
Mód : Kontrola -- Datum : 12/12/2013 21:56:26
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 7 ¤¤¤
[SUSP PATH] gifsapleagog.exe -- C:\Users\tom\gifsapleagog.exe [-] -> SMAZÁNO [TermProc]
[HJNAME] csrss.exe -- C:\Users\tom\AppData\Roaming\csrss.exe [-] -> SMAZÁNO [TermProc]
[SVCHOST] svchost.exe -- C:\Windows\System32\svchost.exe [7] -> SMAZÁNO [TermProc]
[SVCHOST] svchost.exe -- C:\Windows\System32\svchost.exe [7] -> SMAZÁNO [TermProc]
[SVCHOST] svchost.exe -- C:\Windows\System32\svchost.exe [7] -> SMAZÁNO [TermProc]
[SVCHOST] svchost.exe -- C:\Windows\System32\svchost.exe [7] -> SMAZÁNO [TermProc]
[SVCHOST] svchost.exe -- C:\Windows\System32\svchost.exe [7] -> SMAZÁNO [TermProc]

¤¤¤ ¤¤¤ Záznamy Registrů: : 19 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : Uggeor (C:\Users\tom\AppData\Roaming\Ogortu\uggeor.exe [-]) -> NALEZENO
[RUN][SUSP PATH] HKCU\[...]\Run : gifsapleagog (C:\Users\tom\gifsapleagog.exe [-]) -> NALEZENO
[RUN][HJNAME] HKCU\[...]\Run : Client Server Runtime Process (C:\Users\tom\AppData\Roaming\System32\csrss.exe [-]) -> NALEZENO
[RUN][HJNAME] HKCU\[...]\Run : Host-process Windows (Rundll32.exe) (C:\Users\tom\AppData\Roaming\csrss.exe [-]) -> NALEZENO
[RUN][HJNAME] HKCU\[...]\Run : Service Host Process for Windows (C:\Users\tom\AppData\Roaming\System32\svchost.exe [-]) -> NALEZENO
[RUN][HJNAME] HKLM\[...]\Run : Client Server Runtime Process (C:\Users\tom\AppData\Roaming\System32\csrss.exe [-]) -> NALEZENO
[RUN][HJNAME] HKLM\[...]\Run : Host-process Windows (Rundll32.exe) (C:\Users\tom\AppData\Roaming\csrss.exe [-]) -> NALEZENO
[RUN][HJNAME] HKLM\[...]\Run : Service Host Process for Windows (C:\Users\tom\AppData\Roaming\System32\svchost.exe [-]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-1777807130-2460741638-1131617361-1001\[...]\Run : Uggeor (C:\Users\tom\AppData\Roaming\Ogortu\uggeor.exe [-]) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-1777807130-2460741638-1131617361-1001\[...]\Run : gifsapleagog (C:\Users\tom\gifsapleagog.exe [-]) -> NALEZENO
[RUN][HJNAME] HKUS\S-1-5-21-1777807130-2460741638-1131617361-1001\[...]\Run : Client Server Runtime Process (C:\Users\tom\AppData\Roaming\System32\csrss.exe [-]) -> NALEZENO
[RUN][HJNAME] HKUS\S-1-5-21-1777807130-2460741638-1131617361-1001\[...]\Run : Host-process Windows (Rundll32.exe) (C:\Users\tom\AppData\Roaming\csrss.exe [-]) -> NALEZENO
[RUN][HJNAME] HKUS\S-1-5-21-1777807130-2460741638-1131617361-1001\[...]\Run : Service Host Process for Windows (C:\Users\tom\AppData\Roaming\System32\svchost.exe [-]) -> NALEZENO
[RUN][SUSP PATH] HKLM\[...]\Run : 4991 (c:\progra~2\msrgva.exe [-]) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> NALEZENO
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
[Inline] IAT @explorer.exe (TranslateMessage) : USER32.dll -> HOOKED (Unknown @ 0x000A0C30)
[Inline] EAT @explorer.exe (LdrLoadDll) : ntdll.dll -> HOOKED (Unknown @ 0x000A6ED7)
[Inline] EAT @explorer.exe (NtCreateUserProcess) : ntdll.dll -> HOOKED (Unknown @ 0x000A6CFA)
[Inline] EAT @explorer.exe (ZwCreateUserProcess) : ntdll.dll -> HOOKED (Unknown @ 0x000A6CFA)
[Inline] EAT @explorer.exe (GetClipboardData) : USER32.dll -> HOOKED (Unknown @ 0x000A0C96)
[Inline] EAT @explorer.exe (TranslateMessage) : USER32.dll -> HOOKED (Unknown @ 0x000A0C30)
[Inline] EAT @explorer.exe (DecryptMessage) : SSPICLI.DLL -> HOOKED (Unknown @ 0x0009053F)
[Inline] EAT @explorer.exe (DeleteSecurityContext) : SSPICLI.DLL -> HOOKED (Unknown @ 0x000904B1)
[Inline] EAT @explorer.exe (EncryptMessage) : SSPICLI.DLL -> HOOKED (Unknown @ 0x000904FB)
[Inline] EAT @explorer.exe (SealMessage) : SSPICLI.DLL -> HOOKED (Unknown @ 0x000904FB)
[Inline] EAT @explorer.exe (UnsealMessage) : SSPICLI.DLL -> HOOKED (Unknown @ 0x0009053F)
[Inline] EAT @explorer.exe (FreeAddrInfoW) : WS2_32.dll -> HOOKED (Unknown @ 0x00097EFD)
[Inline] EAT @explorer.exe (GetAddrInfoW) : WS2_32.dll -> HOOKED (Unknown @ 0x00097D84)
[Inline] EAT @explorer.exe (WSAGetOverlappedResult) : WS2_32.dll -> HOOKED (Unknown @ 0x000982DE)
[Inline] EAT @explorer.exe (WSARecv) : WS2_32.dll -> HOOKED (Unknown @ 0x000980A1)
[Inline] EAT @explorer.exe (WSASend) : WS2_32.dll -> HOOKED (Unknown @ 0x00098232)
[Inline] EAT @explorer.exe (closesocket) : WS2_32.dll -> HOOKED (Unknown @ 0x00097FF2)
[Inline] EAT @explorer.exe (freeaddrinfo) : WS2_32.dll -> HOOKED (Unknown @ 0x00097EFD)
[Inline] EAT @explorer.exe (getaddrinfo) : WS2_32.dll -> HOOKED (Unknown @ 0x00097E83)
[Inline] EAT @explorer.exe (gethostbyname) : WS2_32.dll -> HOOKED (Unknown @ 0x00097F83)
[Inline] EAT @explorer.exe (recv) : WS2_32.dll -> HOOKED (Unknown @ 0x00098049)
[Inline] EAT @explorer.exe (send) : WS2_32.dll -> HOOKED (Unknown @ 0x000981E0)
[Inline] EAT @explorer.exe (PFXImportCertStore) : CRYPT32.dll -> HOOKED (Unknown @ 0x0009D74A)
[Inline] EAT @explorer.exe (HttpQueryInfoA) : WININET.dll -> HOOKED (Unknown @ 0x000A423B)
[Inline] EAT @explorer.exe (HttpQueryInfoW) : WININET.dll -> HOOKED (Unknown @ 0x000A425F)
[Inline] EAT @explorer.exe (HttpSendRequestA) : WININET.dll -> HOOKED (Unknown @ 0x000A399C)
[Inline] EAT @explorer.exe (HttpSendRequestExA) : WININET.dll -> HOOKED (Unknown @ 0x000A39E2)
[Inline] EAT @explorer.exe (HttpSendRequestExW) : WININET.dll -> HOOKED (Unknown @ 0x000A3A05)
[Inline] EAT @explorer.exe (HttpSendRequestW) : WININET.dll -> HOOKED (Unknown @ 0x000A39BF)
[Inline] EAT @explorer.exe (InternetCloseHandle) : WININET.dll -> HOOKED (Unknown @ 0x000A2ED8)
[Inline] EAT @explorer.exe (InternetQueryDataAvailable) : WININET.dll -> HOOKED (Unknown @ 0x000A419E)
[Inline] EAT @explorer.exe (InternetReadFile) : WININET.dll -> HOOKED (Unknown @ 0x000A412C)
[Inline] EAT @explorer.exe (InternetReadFileExA) : WININET.dll -> HOOKED (Unknown @ 0x000A4152)
[Inline] EAT @explorer.exe (InternetReadFileExW) : WININET.dll -> HOOKED (Unknown @ 0x000A4178)
[Inline] EAT @explorer.exe (InternetWriteFile) : WININET.dll -> HOOKED (Unknown @ 0x000A3B88)

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) TOSHIBA MK3256GSY +++++
--- User ---
[MBR] 98d0f102c8959dc4104e8a89260e0197
[BSP] 14f54d4019d670c9d0444b40265b046d : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] LINUX-SWP (0x42) [VISIBLE] Offset (sectors): 63 | Size: 0 Mo
1 - [ACTIVE] LINUX-SWP (0x42) [VISIBLE] Offset (sectors): 2048 | Size: 300 Mo
2 - [XXXXXX] LINUX-SWP (0x42) [VISIBLE] Offset (sectors): 616448 | Size: 160534 Mo
3 - [XXXXXX] LINUX-SWP (0x42) [VISIBLE] Offset (sectors): 329390080 | Size: 144409 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_S_12122013_215625.txt >>

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosba o kontrolu logu

Příspěvekod jaro3 » 13 pro 2013 10:50

Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller. 2.8.16.0_(datum)_log.txt , vlož sem prosím celý obsah logu.

Co problémy?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

TKroupa323
nováček
Příspěvky: 4
Registrován: prosinec 13
Pohlaví: Muž
Stav:
Offline

Re: Prosba o kontrolu logu

Příspěvekod TKroupa323 » 16 pro 2013 11:10

´11:07:52.0154 0x13dc TDSS rootkit removing tool 3.0.0.19 Nov 18 2013 09:27:50
11:07:54.0213 0x13dc ============================================================
11:07:54.0213 0x13dc Current date / time: 2013/12/16 11:07:54.0213
11:07:54.0213 0x13dc SystemInfo:
11:07:54.0213 0x13dc
11:07:54.0213 0x13dc OS Version: 6.1.7601 ServicePack: 1.0
11:07:54.0213 0x13dc Product type: Workstation
11:07:54.0213 0x13dc ComputerName: TOM_NTB
11:07:54.0213 0x13dc UserName: tom
11:07:54.0213 0x13dc Windows directory: C:\windows
11:07:54.0213 0x13dc System windows directory: C:\windows
11:07:54.0213 0x13dc Processor architecture: Intel x86
11:07:54.0213 0x13dc Number of processors: 2
11:07:54.0213 0x13dc Page size: 0x1000
11:07:54.0213 0x13dc Boot type: Normal boot
11:07:54.0213 0x13dc ============================================================
11:07:59.0689 0x13dc KLMD registered as C:\windows\system32\drivers\09329492.sys
11:07:59.0938 0x13dc System UUID: {3BB2C84A-BF20-43A7-D7B2-EC52D8753979}
11:08:00.0921 0x13dc Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
11:08:00.0937 0x13dc ============================================================
11:08:00.0937 0x13dc \Device\Harddisk0\DR0:
11:08:00.0937 0x13dc MBR partitions:
11:08:00.0937 0x13dc Initialize success
11:08:00.0937 0x13dc ============================================================
11:08:08.0456 0x0540 ============================================================
11:08:08.0456 0x0540 Scan started
11:08:08.0456 0x0540 Mode: Manual;
11:08:08.0456 0x0540 ============================================================
11:08:08.0456 0x0540 KSN ping started
11:08:11.0202 0x0540 KSN ping finished: true
11:08:11.0498 0x0540 ================ Scan system memory ========================
11:08:11.0498 0x0540 System memory - ok
11:08:11.0498 0x0540 ================ Scan services =============================
11:08:11.0545 0x0540 1394ohci - ok
11:08:11.0560 0x0540 ACPI - ok
11:08:11.0560 0x0540 AcpiPmi - ok
11:08:11.0576 0x0540 Adobe LM Service - ok
11:08:11.0623 0x0540 AdobeARMservice - ok
11:08:11.0685 0x0540 AdobeFlashPlayerUpdateSvc - ok
11:08:11.0716 0x0540 adp94xx - ok
11:08:11.0716 0x0540 adpahci - ok
11:08:11.0732 0x0540 adpu320 - ok
11:08:11.0732 0x0540 AeLookupSvc - ok
11:08:11.0763 0x0540 AESTFilters - ok
11:08:11.0779 0x0540 AFD - ok
11:08:11.0794 0x0540 AgereSoftModem - ok
11:08:11.0810 0x0540 agp440 - ok
11:08:11.0810 0x0540 aic78xx - ok
11:08:11.0826 0x0540 ALG - ok
11:08:11.0841 0x0540 aliide - ok
11:08:11.0841 0x0540 amdagp - ok
11:08:11.0857 0x0540 amdide - ok
11:08:11.0857 0x0540 AmdK8 - ok
11:08:11.0872 0x0540 AmdPPM - ok
11:08:11.0872 0x0540 amdsata - ok
11:08:11.0888 0x0540 amdsbs - ok
11:08:11.0888 0x0540 amdxata - ok
11:08:11.0935 0x0540 AppBoosterService - ok
11:08:11.0966 0x0540 AppID - ok
11:08:11.0982 0x0540 AppIDSvc - ok
11:08:11.0997 0x0540 Appinfo - ok
11:08:12.0013 0x0540 arc - ok
11:08:12.0013 0x0540 arcsas - ok
11:08:12.0044 0x0540 AsyncMac - ok
11:08:12.0075 0x0540 atapi - ok
11:08:12.0091 0x0540 AudioEndpointBuilder - ok
11:08:12.0091 0x0540 Audiosrv - ok
11:08:12.0106 0x0540 avg9wd - ok
11:08:12.0122 0x0540 Avgfwfd - ok
11:08:12.0122 0x0540 avgfws9 - ok
11:08:12.0138 0x0540 AVGIDSAgent - ok
11:08:12.0138 0x0540 AVGIDSDriverw7x - ok
11:08:12.0153 0x0540 AVGIDSErHrw7x - ok
11:08:12.0169 0x0540 AVGIDSFilterw7x - ok
11:08:12.0169 0x0540 AVGIDSShimw7x - ok
11:08:12.0184 0x0540 AvgLdx86 - ok
11:08:12.0200 0x0540 AvgMfx86 - ok
11:08:12.0216 0x0540 AvgRkx86 - ok
11:08:12.0216 0x0540 AvgTdiX - ok
11:08:12.0231 0x0540 AxInstSV - ok
11:08:12.0247 0x0540 b06bdrv - ok
11:08:12.0247 0x0540 b57nd60x - ok
11:08:12.0262 0x0540 BDESVC - ok
11:08:12.0278 0x0540 Beep - ok
11:08:12.0278 0x0540 BFE - ok
11:08:12.0294 0x0540 BITS - ok
11:08:12.0294 0x0540 blbdrive - ok
11:08:12.0309 0x0540 bowser - ok
11:08:12.0309 0x0540 BrFiltLo - ok
11:08:12.0325 0x0540 BrFiltUp - ok
11:08:12.0325 0x0540 Browser - ok
11:08:12.0340 0x0540 Brserid - ok
11:08:12.0340 0x0540 BrSerWdm - ok
11:08:12.0356 0x0540 BrUsbMdm - ok
11:08:12.0372 0x0540 BrUsbSer - ok
11:08:12.0387 0x0540 BthEnum - ok
11:08:12.0387 0x0540 BTHMODEM - ok
11:08:12.0403 0x0540 BthPan - ok
11:08:12.0403 0x0540 BTHPORT - ok
11:08:12.0418 0x0540 bthserv - ok
11:08:12.0434 0x0540 BTHUSB - ok
11:08:12.0434 0x0540 btwaudio - ok
11:08:12.0465 0x0540 btwavdt - ok
11:08:12.0481 0x0540 btwdins - ok
11:08:12.0496 0x0540 btwl2cap - ok
11:08:12.0512 0x0540 btwrchid - ok
11:08:12.0512 0x0540 cdfs - ok
11:08:12.0528 0x0540 cdrom - ok
11:08:12.0543 0x0540 CertPropSvc - ok
11:08:12.0543 0x0540 circlass - ok
11:08:12.0559 0x0540 CLFS - ok
11:08:12.0574 0x0540 clr_optimization_v2.0.50727_32 - ok
11:08:12.0574 0x0540 clr_optimization_v4.0.30319_32 - ok
11:08:12.0590 0x0540 CmBatt - ok
11:08:12.0590 0x0540 cmdide - ok
11:08:12.0606 0x0540 CNG - ok
11:08:12.0621 0x0540 Compbatt - ok
11:08:12.0637 0x0540 CompositeBus - ok
11:08:12.0637 0x0540 COMSysApp - ok
11:08:12.0652 0x0540 crcdisk - ok
11:08:12.0668 0x0540 CryptSvc - ok
11:08:12.0699 0x0540 CrystalSysInfo - ok
11:08:12.0699 0x0540 DcomLaunch - ok
11:08:12.0715 0x0540 defragsvc - ok
11:08:12.0730 0x0540 DfsC - ok
11:08:12.0746 0x0540 Dhcp - ok
11:08:12.0746 0x0540 discache - ok
11:08:12.0762 0x0540 Disk - ok
11:08:12.0762 0x0540 Dnscache - ok
11:08:12.0777 0x0540 dot3svc - ok
11:08:12.0777 0x0540 DPS - ok
11:08:12.0793 0x0540 drmkaud - ok
11:08:12.0824 0x0540 dtsoftbus01 - ok
11:08:12.0840 0x0540 DXGKrnl - ok
11:08:12.0840 0x0540 EapHost - ok
11:08:12.0855 0x0540 ebdrv - ok
11:08:12.0855 0x0540 EFS - ok
11:08:12.0871 0x0540 ehRecvr - ok
11:08:12.0871 0x0540 ehSched - ok
11:08:12.0902 0x0540 Elite Antikeylogger monitoring service - ok
11:08:12.0918 0x0540 elxstor - ok
11:08:12.0933 0x0540 ErrDev - ok
11:08:12.0949 0x0540 EventSystem - ok
11:08:12.0964 0x0540 exfat - ok
11:08:12.0964 0x0540 fastfat - ok
11:08:12.0980 0x0540 Fax - ok
11:08:12.0980 0x0540 fdc - ok
11:08:12.0996 0x0540 fdPHost - ok
11:08:13.0011 0x0540 FDResPub - ok
11:08:13.0011 0x0540 FileInfo - ok
11:08:13.0027 0x0540 Filetrace - ok
11:08:13.0027 0x0540 flpydisk - ok
11:08:13.0042 0x0540 FltMgr - ok
11:08:13.0058 0x0540 FontCache - ok
11:08:13.0074 0x0540 FontCache3.0.0.0 - ok
11:08:13.0074 0x0540 FsDepends - ok
11:08:13.0089 0x0540 Fs_Rec - ok
11:08:13.0089 0x0540 fvevol - ok
11:08:13.0105 0x0540 gagp30kx - ok
11:08:13.0105 0x0540 gpsvc - ok
11:08:13.0120 0x0540 gupdate - ok
11:08:13.0136 0x0540 gupdatem - ok
11:08:13.0167 0x0540 hamachi - ok
11:08:13.0167 0x0540 hcw85cir - ok
11:08:13.0183 0x0540 HdAudAddService - ok
11:08:13.0183 0x0540 HDAudBus - ok
11:08:13.0198 0x0540 HidBatt - ok
11:08:13.0214 0x0540 HidBth - ok
11:08:13.0230 0x0540 HidIr - ok
11:08:13.0230 0x0540 hidserv - ok
11:08:13.0245 0x0540 HidUsb - ok
11:08:13.0261 0x0540 hkmsvc - ok
11:08:13.0276 0x0540 HomeGroupListener - ok
11:08:13.0276 0x0540 HomeGroupProvider - ok
11:08:13.0292 0x0540 HP Support Assistant Service - ok
11:08:13.0308 0x0540 HPDrvMntSvc.exe - ok
11:08:13.0323 0x0540 hpHotkeyMonitor - ok
11:08:13.0339 0x0540 HpqKbFiltr - ok
11:08:13.0370 0x0540 hpqwmiex - ok
11:08:13.0370 0x0540 HpSAMD - ok
11:08:13.0401 0x0540 HTTP - ok
11:08:13.0401 0x0540 hwpolicy - ok
11:08:13.0417 0x0540 i8042prt - ok
11:08:13.0417 0x0540 IAANTMON - ok
11:08:13.0448 0x0540 iaStor - ok
11:08:13.0464 0x0540 iaStorV - ok
11:08:13.0464 0x0540 IDriverT - ok
11:08:13.0479 0x0540 idsvc - ok
11:08:13.0495 0x0540 IEEtwCollectorService - ok
11:08:13.0510 0x0540 igfx - ok
11:08:13.0526 0x0540 iirsp - ok
11:08:13.0526 0x0540 IKEEXT - ok
11:08:13.0557 0x0540 IntcHdmiAddService - ok
11:08:13.0557 0x0540 intelide - ok
11:08:13.0573 0x0540 intelppm - ok
11:08:13.0588 0x0540 IPBusEnum - ok
11:08:13.0588 0x0540 IpFilterDriver - ok
11:08:13.0604 0x0540 iphlpsvc - ok
11:08:13.0620 0x0540 IPMIDRV - ok
11:08:13.0635 0x0540 IPNAT - ok
11:08:13.0651 0x0540 IRENUM - ok
11:08:13.0666 0x0540 isapnp - ok
11:08:13.0682 0x0540 iScsiPrt - ok
11:08:13.0698 0x0540 kbdclass - ok
11:08:13.0698 0x0540 kbdhid - ok
11:08:13.0713 0x0540 KeyIso - ok
11:08:13.0744 0x0540 KMWDFILTERx86 - ok
11:08:13.0760 0x0540 KSecDD - ok
11:08:13.0776 0x0540 KSecPkg - ok
11:08:13.0791 0x0540 KtmRm - ok
11:08:13.0807 0x0540 LanmanServer - ok
11:08:13.0807 0x0540 LanmanWorkstation - ok
11:08:13.0838 0x0540 LightScribeService - ok
11:08:13.0854 0x0540 lltdio - ok
11:08:13.0854 0x0540 lltdsvc - ok
11:08:13.0869 0x0540 lmhosts - ok
11:08:13.0885 0x0540 LSI_FC - ok
11:08:13.0885 0x0540 LSI_SAS - ok
11:08:13.0900 0x0540 LSI_SAS2 - ok
11:08:13.0900 0x0540 LSI_SCSI - ok
11:08:13.0916 0x0540 luafv - ok
11:08:13.0932 0x0540 Mcx2Svc - ok
11:08:13.0932 0x0540 megasas - ok
11:08:13.0947 0x0540 MegaSR - ok
11:08:13.0947 0x0540 Microsoft SharePoint Workspace Audit Service - ok
11:08:13.0963 0x0540 MMCSS - ok
11:08:13.0963 0x0540 Modem - ok
11:08:13.0978 0x0540 monitor - ok
11:08:13.0978 0x0540 mouclass - ok
11:08:13.0994 0x0540 mouhid - ok
11:08:14.0010 0x0540 mountmgr - ok
11:08:14.0041 0x0540 MozillaMaintenance - ok
11:08:14.0041 0x0540 mpio - ok
11:08:14.0056 0x0540 mpsdrv - ok
11:08:14.0072 0x0540 MpsSvc - ok
11:08:14.0072 0x0540 MRxDAV - ok
11:08:14.0088 0x0540 mrxsmb - ok
11:08:14.0088 0x0540 mrxsmb10 - ok
11:08:14.0103 0x0540 mrxsmb20 - ok
11:08:14.0103 0x0540 msahci - ok
11:08:14.0119 0x0540 msdsm - ok
11:08:14.0119 0x0540 MSDTC - ok
11:08:14.0150 0x0540 Msfs - ok
11:08:14.0150 0x0540 mshidkmdf - ok
11:08:14.0166 0x0540 msisadrv - ok
11:08:14.0166 0x0540 MSiSCSI - ok
11:08:14.0181 0x0540 msiserver - ok
11:08:14.0259 0x0540 MSKSSRV - ok
11:08:14.0275 0x0540 MSPCLOCK - ok
11:08:14.0275 0x0540 MSPQM - ok
11:08:14.0290 0x0540 MsRPC - ok
11:08:14.0290 0x0540 mssmbios - ok
11:08:14.0306 0x0540 MSTEE - ok
11:08:14.0306 0x0540 MTConfig - ok
11:08:14.0322 0x0540 Mup - ok
11:08:14.0322 0x0540 napagent - ok
11:08:14.0337 0x0540 NativeWifiP - ok
11:08:14.0353 0x0540 NDIS - ok
11:08:14.0353 0x0540 NdisCap - ok
11:08:14.0368 0x0540 NdisTapi - ok
11:08:14.0384 0x0540 Ndisuio - ok
11:08:14.0384 0x0540 NdisWan - ok
11:08:14.0400 0x0540 NDProxy - ok
11:08:14.0400 0x0540 NetBIOS - ok
11:08:14.0415 0x0540 NetBT - ok
11:08:14.0431 0x0540 Netlogon - ok
11:08:14.0431 0x0540 Netman - ok
11:08:14.0446 0x0540 netprofm - ok
11:08:14.0446 0x0540 NetTcpPortSharing - ok
11:08:14.0462 0x0540 nfrd960 - ok
11:08:14.0462 0x0540 NlaSvc - ok
11:08:14.0493 0x0540 nmwcd - ok
11:08:14.0524 0x0540 nmwcdc - ok
11:08:14.0524 0x0540 nmwcdnsu - ok
11:08:14.0540 0x0540 nmwcdnsuc - ok
11:08:14.0556 0x0540 Npfs - ok
11:08:14.0556 0x0540 nsi - ok
11:08:14.0571 0x0540 nsiproxy - ok
11:08:14.0587 0x0540 Ntfs - ok
11:08:14.0587 0x0540 Null - ok
11:08:14.0602 0x0540 nvraid - ok
11:08:14.0602 0x0540 nvstor - ok
11:08:14.0618 0x0540 nv_agp - ok
11:08:14.0618 0x0540 ohci1394 - ok
11:08:14.0649 0x0540 ose - ok
11:08:14.0665 0x0540 osppsvc - ok
11:08:14.0680 0x0540 p2pimsvc - ok
11:08:14.0696 0x0540 p2psvc - ok
11:08:14.0696 0x0540 Parport - ok
11:08:14.0712 0x0540 partmgr - ok
11:08:14.0712 0x0540 Parvdm - ok
11:08:14.0727 0x0540 PcaSvc - ok
11:08:14.0727 0x0540 pccsmcfd - ok
11:08:14.0743 0x0540 pci - ok
11:08:14.0743 0x0540 pciide - ok
11:08:14.0758 0x0540 pcmcia - ok
11:08:14.0758 0x0540 pcw - ok
11:08:14.0790 0x0540 PEAUTH - ok
11:08:14.0821 0x0540 pla - ok
11:08:14.0852 0x0540 PlugPlay - ok
11:08:14.0852 0x0540 PNRPAutoReg - ok
11:08:14.0868 0x0540 PNRPsvc - ok
11:08:14.0883 0x0540 PolicyAgent - ok
11:08:14.0883 0x0540 Power - ok
11:08:14.0899 0x0540 PptpMiniport - ok
11:08:14.0899 0x0540 Processor - ok
11:08:14.0914 0x0540 ProfSvc - ok
11:08:14.0914 0x0540 ProtectedStorage - ok
11:08:14.0930 0x0540 Psched - ok
11:08:14.0946 0x0540 PxHelp20 - ok
11:08:14.0961 0x0540 ql2300 - ok
11:08:14.0961 0x0540 ql40xx - ok
11:08:14.0977 0x0540 QWAVE - ok
11:08:14.0977 0x0540 QWAVEdrv - ok
11:08:14.0992 0x0540 RasAcd - ok
11:08:15.0008 0x0540 RasAgileVpn - ok
11:08:15.0008 0x0540 RasAuto - ok
11:08:15.0024 0x0540 Rasl2tp - ok
11:08:15.0024 0x0540 RasMan - ok
11:08:15.0070 0x0540 RasPppoe - ok
11:08:15.0070 0x0540 RasSstp - ok
11:08:15.0086 0x0540 rdbss - ok
11:08:15.0102 0x0540 rdpbus - ok
11:08:15.0102 0x0540 RDPCDD - ok
11:08:15.0117 0x0540 RDPENCDD - ok
11:08:15.0133 0x0540 RDPREFMP - ok
11:08:15.0148 0x0540 RDPWD - ok
11:08:15.0164 0x0540 rdyboost - ok
11:08:15.0164 0x0540 RemoteAccess - ok
11:08:15.0180 0x0540 RemoteRegistry - ok
11:08:15.0211 0x0540 RFCOMM - ok
11:08:15.0258 0x0540 RMCAST - ok
11:08:15.0273 0x0540 RoxMediaDB10 - ok
11:08:15.0273 0x0540 RpcEptMapper - ok
11:08:15.0289 0x0540 RpcLocator - ok
11:08:15.0304 0x0540 RpcSs - ok
11:08:15.0320 0x0540 rspndr - ok
11:08:15.0336 0x0540 RTL8167 - ok
11:08:15.0351 0x0540 rtl8192se - ok
11:08:15.0382 0x0540 rtsuvc - ok
11:08:15.0398 0x0540 SamSs - ok
11:08:15.0429 0x0540 sbp2port - ok
11:08:15.0445 0x0540 SCardSvr - ok
11:08:15.0445 0x0540 scfilter - ok
11:08:15.0460 0x0540 Schedule - ok
11:08:15.0476 0x0540 SCPolicySvc - ok
11:08:15.0492 0x0540 SDRSVC - ok
11:08:15.0523 0x0540 SeaPort - ok
11:08:15.0538 0x0540 secdrv - ok
11:08:15.0538 0x0540 seclogon - ok
11:08:15.0554 0x0540 SENS - ok
11:08:15.0570 0x0540 SensrSvc - ok
11:08:15.0570 0x0540 Serenum - ok
11:08:15.0585 0x0540 Serial - ok
11:08:15.0601 0x0540 sermouse - ok
11:08:15.0632 0x0540 ServiceLayer - ok
11:08:15.0648 0x0540 SessionEnv - ok
11:08:15.0663 0x0540 sffdisk - ok
11:08:15.0663 0x0540 sffp_mmc - ok
11:08:15.0679 0x0540 sffp_sd - ok
11:08:15.0694 0x0540 sfloppy - ok
11:08:15.0710 0x0540 SharedAccess - ok
11:08:15.0726 0x0540 ShellHWDetection - ok
11:08:15.0726 0x0540 sisagp - ok
11:08:15.0741 0x0540 SiSRaid2 - ok
11:08:15.0757 0x0540 SiSRaid4 - ok
11:08:15.0772 0x0540 SkypeUpdate - ok
11:08:15.0788 0x0540 Smb - ok
11:08:15.0804 0x0540 SNMPTRAP - ok
11:08:15.0819 0x0540 spldr - ok
11:08:15.0819 0x0540 Spooler - ok
11:08:15.0835 0x0540 sppsvc - ok
11:08:15.0835 0x0540 sppuinotify - ok
11:08:15.0866 0x0540 sptd - ok
11:08:15.0882 0x0540 srv - ok
11:08:15.0882 0x0540 srv2 - ok
11:08:15.0897 0x0540 srvnet - ok
11:08:15.0913 0x0540 SSDPSRV - ok
11:08:15.0913 0x0540 SstpSvc - ok
11:08:15.0944 0x0540 STacSV - ok
11:08:15.0975 0x0540 Steam Client Service - ok
11:08:15.0975 0x0540 stexstor - ok
11:08:15.0991 0x0540 STHDA - ok
11:08:16.0006 0x0540 StiSvc - ok
11:08:16.0022 0x0540 stllssvr - ok
11:08:16.0022 0x0540 swenum - ok
11:08:16.0038 0x0540 swprv - ok
11:08:16.0069 0x0540 SynTP - ok
11:08:16.0069 0x0540 SysMain - ok
11:08:16.0084 0x0540 TabletInputService - ok
11:08:16.0100 0x0540 TapiSrv - ok
11:08:16.0116 0x0540 TBS - ok
11:08:16.0116 0x0540 Tcpip - ok
11:08:16.0131 0x0540 TCPIP6 - ok
11:08:16.0147 0x0540 tcpipreg - ok
11:08:16.0162 0x0540 TDPIPE - ok
11:08:16.0162 0x0540 TDTCP - ok
11:08:16.0178 0x0540 tdx - ok
11:08:16.0194 0x0540 TermDD - ok
11:08:16.0194 0x0540 TermService - ok
11:08:16.0209 0x0540 Themes - ok
11:08:16.0225 0x0540 THREADORDER - ok
11:08:16.0240 0x0540 TPM - ok
11:08:16.0256 0x0540 TrkWks - ok
11:08:16.0272 0x0540 TrustedInstaller - ok
11:08:16.0287 0x0540 tssecsrv - ok
11:08:16.0318 0x0540 TsUsbFlt - ok
11:08:16.0334 0x0540 tunnel - ok
11:08:16.0350 0x0540 uagp35 - ok
11:08:16.0365 0x0540 udfs - ok
11:08:16.0381 0x0540 UI0Detect - ok
11:08:16.0396 0x0540 uliagpkx - ok
11:08:16.0412 0x0540 umbus - ok
11:08:16.0412 0x0540 UmPass - ok
11:08:16.0428 0x0540 upnphost - ok
11:08:16.0443 0x0540 upperdev - ok
11:08:16.0459 0x0540 usbbus - ok
11:08:16.0459 0x0540 usbccgp - ok
11:08:16.0474 0x0540 usbcir - ok
11:08:16.0474 0x0540 UsbDiag - ok
11:08:16.0490 0x0540 usbehci - ok
11:08:16.0506 0x0540 usbhub - ok
11:08:16.0521 0x0540 USBModem - ok
11:08:16.0521 0x0540 usbohci - ok
11:08:16.0537 0x0540 usbprint - ok
11:08:16.0552 0x0540 usbscan - ok
11:08:16.0568 0x0540 usbser - ok
11:08:16.0599 0x0540 UsbserFilt - ok
11:08:16.0599 0x0540 USBSTOR - ok
11:08:16.0615 0x0540 usbuhci - ok
11:08:16.0630 0x0540 usbvideo - ok
11:08:16.0630 0x0540 UxSms - ok
11:08:16.0646 0x0540 VaultSvc - ok
11:08:16.0662 0x0540 vdrvroot - ok
11:08:16.0662 0x0540 vds - ok
11:08:16.0677 0x0540 vga - ok
11:08:16.0677 0x0540 VgaSave - ok
11:08:16.0693 0x0540 vhdmp - ok
11:08:16.0693 0x0540 viaagp - ok
11:08:16.0708 0x0540 ViaC7 - ok
11:08:16.0724 0x0540 viaide - ok
11:08:16.0740 0x0540 volmgr - ok
11:08:16.0755 0x0540 volmgrx - ok
11:08:16.0755 0x0540 volsnap - ok
11:08:16.0771 0x0540 vsmraid - ok
11:08:16.0786 0x0540 VSS - ok
11:08:16.0786 0x0540 vwifibus - ok
11:08:16.0802 0x0540 vwififlt - ok
11:08:16.0802 0x0540 vwifimp - ok
11:08:16.0818 0x0540 W32Time - ok
11:08:16.0833 0x0540 WacomPen - ok
11:08:16.0833 0x0540 WANARP - ok
11:08:16.0849 0x0540 Wanarpv6 - ok
11:08:16.0880 0x0540 WatAdminSvc - ok
11:08:16.0880 0x0540 wbengine - ok
11:08:16.0896 0x0540 WbioSrvc - ok
11:08:16.0896 0x0540 wcncsvc - ok
11:08:16.0911 0x0540 WcsPlugInService - ok
11:08:16.0911 0x0540 Wd - ok
11:08:16.0927 0x0540 Wdf01000 - ok
11:08:16.0942 0x0540 WdiServiceHost - ok
11:08:16.0942 0x0540 WdiSystemHost - ok
11:08:16.0958 0x0540 WebClient - ok
11:08:16.0958 0x0540 Wecsvc - ok
11:08:16.0974 0x0540 wercplsupport - ok
11:08:16.0989 0x0540 WerSvc - ok
11:08:16.0989 0x0540 WfpLwf - ok
11:08:17.0005 0x0540 WIMMount - ok
11:08:17.0005 0x0540 WinDefend - ok
11:08:17.0036 0x0540 WinHttpAutoProxySvc - ok
11:08:17.0036 0x0540 Winmgmt - ok
11:08:17.0052 0x0540 WinRM - ok
11:08:17.0083 0x0540 WinUsb - ok
11:08:17.0083 0x0540 Wlansvc - ok
11:08:17.0098 0x0540 wlidsvc - ok
11:08:17.0114 0x0540 WmiAcpi - ok
11:08:17.0114 0x0540 wmiApSrv - ok
11:08:17.0130 0x0540 WMPNetworkSvc - ok
11:08:17.0145 0x0540 WPCSvc - ok
11:08:17.0145 0x0540 WPDBusEnum - ok
11:08:17.0161 0x0540 ws2ifsl - ok
11:08:17.0161 0x0540 wscsvc - ok
11:08:17.0192 0x0540 wseak - ok
11:08:17.0192 0x0540 WSearch - ok
11:08:17.0208 0x0540 wuauserv - ok
11:08:17.0223 0x0540 WudfPf - ok
11:08:17.0223 0x0540 WUDFRd - ok
11:08:17.0239 0x0540 wudfsvc - ok
11:08:17.0239 0x0540 WwanSvc - ok
11:08:17.0270 0x0540 ================ Scan global ===============================
11:08:17.0286 0x0540 [ Global ] - ok
11:08:17.0286 0x0540 ================ Scan MBR ==================================
11:08:17.0301 0x0540 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
11:08:17.0598 0x0540 \Device\Harddisk0\DR0 - ok
11:08:17.0598 0x0540 ================ Scan VBR ==================================
11:08:17.0722 0x0540 AV detected via SS2: AVG Internet Security, C:\Program Files\AVG\AVG9\avgwsc.exe ( 9.0.0.832 ), 0x40000 ( disabled : updated )
11:08:17.0722 0x0540 FW detected via SS2: AVG Firewall, C:\Program Files\AVG\AVG9\avgwsc.exe ( 9.0.0.832 ), 0x70010 ( disabled )
11:08:17.0738 0x0540 Win FW state via NFP2: enabled
11:08:20.0484 0x0540 ============================================================
11:08:20.0484 0x0540 Scan finished
11:08:20.0484 0x0540 ============================================================
11:08:20.0484 0x08cc Detected object count: 0
11:08:20.0484 0x08cc Actual detected object count: 0
11:08:26.0536 0x1404 Deinitialize success

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosba o kontrolu logu

Příspěvekod Orcus » 16 pro 2013 18:40

jaro3 píše:Co problémy?
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 22 hostů