Stránka 1 z 2

Prosím o kontrolu logu. Dík.

Napsal: 15 dub 2008 19:29
od hranol
Téma rozděleno, příště si založ vlastní téma, i kdyby se v daném tématu řešil stejný problém jako máš ty.
fredik


Preji dobry vecer.....

Jsem stary kozel....uz pres 50 jařin,ale delam chyby v PC.....no jo stari...chtel bych poprosit..jestli by jste se me nepodivali na logo......a dalsi vec......dekuji moc.....



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:09:20, on 15.4.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
D:\AvastPro\aswUpdSv.exe
D:\AvastPro\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
D:\Office12\GrooveMonitor.exe
C:\Program Files\Hmonitor\hmonitor.exe
D:\HP Software Update\HPWuSchd2.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spoolsv.exe
D:\AvastPro\ashDisp.exe
C:\Program Files\Chronograph\chrono.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\PowerArchiver\PASTARTER.EXE
C:\Program Files\History Sweeper\sweeper.exe
C:\Program Files\Restore Desktop\RestoreDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
D:\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\AvastPro\ashMaiSv.exe
D:\AvastPro\ashWebSv.exe
D:\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\WINDOWS\WebIE.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Seznam Bezpečný Internet - {B71B15CE-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam Bezpecny Internet\SBI.dll
O4 - HKLM\..\Run: [SeznamAntidialer] "C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [hmonitor] C:\Program Files\Hmonitor\hmonitor.exe
O4 - HKLM\..\Run: [HP Software Update] "D:\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DefragTaskBar] "C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [avast!] D:\AvastPro\ashDisp.exe
O4 - HKCU\..\Run: [Chronograph] "C:\Program Files\Chronograph\chrono.exe" /autorun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [PowerArchiver Tray] C:\Program Files\PowerArchiver\PASTARTER.EXE
O4 - HKCU\..\Run: [Sweeper.exe] C:\Program Files\History Sweeper\sweeper.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RestoreDesktop] C:\Program Files\Restore Desktop\RestoreDesktop.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Reader\AdobeCollabSync.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Rychlé spuštění aplikace HP Image Zone.lnk = D:\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Přelož do češtiny - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5034
O8 - Extra context menu item: Block frame with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_frame
O8 - Extra context menu item: Block image with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_image
O8 - Extra context menu item: Block link with Ad Muncher - http://www.admuncher.com/request_will_b ... nu_ie_link
O8 - Extra context menu item: Don't filter page with Ad Muncher - http://www.admuncher.com/request_will_b ... ie_exclude
O8 - Extra context menu item: Hledej v &Seznamu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5033
O8 - Extra context menu item: Hledej v Seznam &Fulltextu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5035
O8 - Extra context menu item: Report page to the Ad Muncher developers - http://www.admuncher.com/request_will_b ... _ie_report
O8 - Extra context menu item: Stáhnout obsah FLV videa s IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Stáhnout pomocí FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Stáhnout s IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Stáhnout vše pomocí FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O15 - Trusted Zone: http://toolbar.imageshack.us
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 6571819750
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/Im ... oolbar.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7BEF656D-72B5-4513-B854-E88C725548AC}: NameServer = 212.158.128.2 212.158.128.3
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Office12\GR99D3~1.DLL
O21 - SSODL: ogxtsepr - {11950FF4-1E7F-4782-BF43-5762784FFB81} - C:\WINDOWS\ogxtsepr.dll
O23 - Service: AshampooDefragService - - C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\AvastPro\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\AvastPro\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\AvastPro\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\AvastPro\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 10788 bytes

===================================================

dale me to vyhazuje chybu nekolikrat za den .....

instrukce na adrese 0x03c8508c odkazovala na adresu pameti 0x00000020.s pametí nelze provest operaci:read.
Klepnutim na tlacitko OK ukoncete program.


====================================================

dalsi......................

runtime error!

program:C/Programnfiles/internet explorer/explore.exe

R6025
- pure virtual function call


====================================================


dalsi.......................

pri spusteni nebo nebo i v prubehu me naskakuje oznameni,ze jsem zapojen offline....

======================================================

pouzivam Operu a IE 7.....Opera bez problemů...ale ,v prubehu pripojeni na net....jsem pripojen pres Operu a znicehonic se me spusti IE a naskoci me stranka Bitdefender centrum...uz jsem z toho vseho nestastny....
viz....

Kód: Vybrat vše

http://www.system-defender.com/freeware/2/?wmid=6010&mid=MjI6Mzc6MTgxNjM=&lndid=37&p=01


Dik moooooocccccccc za pomoc!!!!!!!!!!


Zdravi Hranolo

Obrázek

Re: Prosím o kontrolu logu. Dík.

Napsal: 15 dub 2008 20:53
od fredik
Vítej na fóru

Stáhni si SDFix
- Spusť ho a rozbalí se ti na disk kde je nainstalovaný Windows (typicky to je C:\SDfix)
- Pak restartuj PC do nouzového režimu (zvol možnost: Stav nouze, ne Stav nouze s práci v síti)
- Otevři adresář kde je vybalený SDFix a spusť soubor RunThis.bat tím spustíš program.
* Pak stiskni klávesu Y a pak Enter pro zahájení čistícího procesu.
* Pro dokončení kontroly budeš vyzván ke stisknoutí libovolné klávesy a počítač se restartuje.
* Při nabíhání operačního systému se program spustí znovu a dokončí čistící proces. Až se objeví Finish, budeš muset po vyzvání stisknout libovolnou klávesu, tim se ukončí program a zobrazí se ti ikony na ploše
- Když se skončí načítání ikon na ploše, otevře se ti na obrazovce log z SDFix a zároveň ho uloží do adresáře kde je rozbalený SDFix jako soubor Report.txt
Pak sem zkopíruj jeho obsah + nový log z HijackThis.

Re: Prosím o kontrolu logu. Dík.

Napsal: 16 dub 2008 00:49
od hranol
Jo...jasny...ja to bral...jako stejny.....dik moc....no zkusim to....

Re: Prosím o kontrolu logu. Dík.

Napsal: 16 dub 2008 01:48
od hranol
SDFix: Version 1.171
Run by hranol on st 16.04.2008 at 19:54

Microsoft Windows XP [Verze 5.1.2600]
Running From: C:\PROGRA~1\SDFix

Checking Services :


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting


Checking Files :

No Trojan Files Found






Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1353.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-16 20:06:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:87,59,51,95,5f,01,36,53,d0,df,de,ce,82,84,7e,67,e6,d1,f2,00,27,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:87,59,51,95,5f,01,36,53,d0,df,de,ce,82,84,7e,67,e6,d1,f2,00,27,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:87,59,51,95,5f,01,36,53,d0,df,de,ce,82,84,7e,67,e6,d1,f2,00,27,..

scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes]
"\f\1e?r?n?é? ?u?k?a?z?a?t?e?l?e? ?"="C:\WINDOWS\cursors\arrow_r.cur,C:\WINDOWS\cursors\help_r.cur,C:\WINDOWS\cursors\wait_r.cur,C:\WINDOWS\cursors\busy_r.cur,C:\WINDOWS\cursors\cross_r.cur,C:\WINDOWS\cursors\beam_r.cur,C:\WINDOWS\cursors\pen_r.cur,C:\WINDOWS\cursors\no_r.cur,C:\WINDOWS\cursors\size4_r.cur,C:\WINDOWS\cursors\size3_r.cur,C:\WINDOWS\cursors\size2_r.cur,C:\WINDOWS\cursors\size1_r.cur,C:\WINDOWS\cursors\move_r.cur,C:\WINDOWS\cursors\up_r.cur"
"\f\1e?r?n?é? ?u?k?a?z?a?t?e?l?e? ?(?v?e?l?k?é?)?"="C:\WINDOWS\cursors\arrow_rm.cur,C:\WINDOWS\cursors\help_rm.cur,C:\WINDOWS\cursors\wait_rm.cur,C:\WINDOWS\cursors\busy_rm.cur,C:\WINDOWS\cursors\cross_rm.cur,C:\WINDOWS\cursors\beam_rm.cur,C:\WINDOWS\cursors\pen_rm.cur,C:\WINDOWS\cursors\no_rm.cur,C:\WINDOWS\cursors\size4_rm.cur,C:\WINDOWS\cursors\size3_rm.cur,C:\WINDOWS\cursors\size2_rm.cur,C:\WINDOWS\cursors\size1_rm.cur,C:\WINDOWS\cursors\move_rm.cur,C:\WINDOWS\cursors\up_rm.cur"
"\f\1e?r?n?é? ?u?k?a?z?a?t?e?l?e? ?(?n?e?j?v?\e\1t?a\1í?)?"="C:\WINDOWS\cursors\arrow_rl.cur,C:\WINDOWS\cursors\help_rl.cur,C:\WINDOWS\cursors\wait_rl.cur,C:\WINDOWS\cursors\busy_rl.cur,C:\WINDOWS\cursors\cross_rl.cur,C:\WINDOWS\cursors\beam_rl.cur,C:\WINDOWS\cursors\pen_rl.cur,C:\WINDOWS\cursors\no_rl.cur,C:\WINDOWS\cursors\size4_rl.cur,C:\WINDOWS\cursors\size3_rl.cur,C:\WINDOWS\cursors\size2_rl.cur,C:\WINDOWS\cursors\size1_rl.cur,C:\WINDOWS\cursors\move_rl.cur,C:\WINDOWS\cursors\up_rl.cur"

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\ICQLite\\ICQLite.exe"="C:\\Program Files\\ICQLite\\ICQLite.exe:*:Enabled:ICQ Lite"
"D:\\Office12\\OUTLOOK.EXE"="D:\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"D:\\Office12\\GROOVE.EXE"="D:\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"D:\\Office12\\ONENOTE.EXE"="D:\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\Chronograph\\chrono.exe"="C:\\Program Files\\Chronograph\\chrono.exe:*:Enabled:Chronograph"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Ad Muncher\\AdMunch.exe"="C:\\Program Files\\Ad Muncher\\AdMunch.exe:*:Enabled:AdMunch"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files :


File Backups: - C:\PROGRA~1\SDFix\backups\backups.zip

Files with Hidden Attributes :

Sat 4 Aug 2007 48 ..SH. --- "C:\WINDOWS\S0602AC15.tmp"
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Sun 3 Feb 2008 23 A.SH. --- "C:\WINDOWS\system32\ecfdef_r.dll"
Sun 16 Mar 2008 23 A.SH. --- "C:\WINDOWS\system32\ecfdef_z.dll"
Thu 17 May 2007 23 A.SH. --- "C:\WINDOWS\system32\faecaf9_r.dll"
Thu 16 Feb 2006 72,704 ..SHR --- "C:\Program Files\AsefSoft\Quick Smile 3\Uninstall.exe"
Sat 2 Feb 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Tue 1 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0a67b6c406b1d7e0f5c1e6f6d44a3f6e\BIT61.tmp"
Tue 1 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\18b19374451d28a8fbaf1939cf31ff45\BIT65.tmp"
Tue 1 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\26924cbc8132a10b438ce6e2b49d4652\BIT60.tmp"
Tue 1 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\911362f9031af35c5b51e12ecc909800\BIT62.tmp"
Tue 1 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ddd366874e802b7f73320d55edd2e34f\BIT64.tmp"
Tue 1 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\e691f694d870764b4c31a5eb30b26139\BIT63.tmp"
Tue 1 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f3a3b2a2e8ef3845fb7855c997a48858\BIT66.tmp"

Finished!


nejde me nahodit napoveda a odborna pomoc.......


================================================================================================

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:21:57, on 16.4.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe
D:\Office12\GrooveMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Hmonitor\hmonitor.exe
D:\HP Software Update\HPWuSchd2.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Chronograph\chrono.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\PowerArchiver\PASTARTER.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Restore Desktop\RestoreDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
D:\Digital Imaging\bin\hpqtra08.exe
D:\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\WINDOWS\WebIE.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Seznam Bezpečný Internet - {B71B15CE-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam Bezpecny Internet\SBI.dll
O4 - HKLM\..\Run: [SeznamAntidialer] "C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [hmonitor] C:\Program Files\Hmonitor\hmonitor.exe
O4 - HKLM\..\Run: [HP Software Update] "D:\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DefragTaskBar] "C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [8cf3f77c] rundll32.exe "C:\WINDOWS\system32\twxxmvux.dll",b
O4 - HKLM\..\Run: [BM8fc0c4e0] Rundll32.exe "C:\WINDOWS\system32\mrfegpyi.dll",s
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [Chronograph] "C:\Program Files\Chronograph\chrono.exe" /autorun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [PowerArchiver Tray] C:\Program Files\PowerArchiver\PASTARTER.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RestoreDesktop] C:\Program Files\Restore Desktop\RestoreDesktop.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Reader\AdobeCollabSync.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Rychlé spuštění aplikace HP Image Zone.lnk = D:\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Přelož do češtiny - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5034
O8 - Extra context menu item: Block frame with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_frame
O8 - Extra context menu item: Block image with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_image
O8 - Extra context menu item: Block link with Ad Muncher - http://www.admuncher.com/request_will_b ... nu_ie_link
O8 - Extra context menu item: Don't filter page with Ad Muncher - http://www.admuncher.com/request_will_b ... ie_exclude
O8 - Extra context menu item: Hledej v &Seznamu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5033
O8 - Extra context menu item: Hledej v Seznam &Fulltextu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5035
O8 - Extra context menu item: Report page to the Ad Muncher developers - http://www.admuncher.com/request_will_b ... _ie_report
O8 - Extra context menu item: Stáhnout obsah FLV videa s IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Stáhnout s IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O15 - Trusted Zone: http://toolbar.imageshack.us
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 6571819750
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/Im ... oolbar.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7BEF656D-72B5-4513-B854-E88C725548AC}: NameServer = 212.158.128.2 212.158.128.3
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Office12\GR99D3~1.DLL
O23 - Service: AshampooDefragService - - C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\AvastPro\aswUpdSv.exe (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe

--
End of file - 10573 bytes

Re: Prosím o kontrolu logu. Dík.

Napsal: 16 dub 2008 22:58
od fredik
Rezidentní ochranu od Spybota máš zapnutou?, protože neběží ale je nastaveno její spouštění.

Takže mrkni se jestli je zapnuta a pokud bude tak ji vypni :
- spusť Spybot - Search & Destroy
- nahoře v menu zvol: Režim => Pro pokročilé
- objeví se ti varovné okno kde zvol Ano
- okno programu se ti přepne do pokročilého zobrazení a tam zvol: Nástroje => Rezidentní
- tam zruš zatržení pokud bude u položky: Rezidentní program "TeaTimer" (Ochrana ...)
tt.JPG
- zavři program
Restartuj PC.

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

Stáhni si ComboFix (by sUBs) a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah

Re: Prosím o kontrolu logu. Dík.

Napsal: 17 dub 2008 09:57
od hranol
ComboFix 08-04-16.5 - hranol 2008-04-17 9:27:00.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.539 [GMT 2:00]
Running from: C:\Documents and Settings\hranol\Plocha\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
/wow section - STAGE 38
pv: No matching processes found
Nesprávná syntaxe příkazu


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\pskt.ini
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\auhrxwhc.ini
C:\WINDOWS\system32\fsrixmrp.ini
C:\WINDOWS\system32\LnnUBcdd.ini
C:\WINDOWS\system32\LnnUBcdd.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mopAyGgh.ini
C:\WINDOWS\system32\mopAyGgh.ini2
C:\WINDOWS\system32\qvghwyhj.ini
C:\WINDOWS\system32\Rqtuvyay.ini
C:\WINDOWS\system32\Rqtuvyay.ini2
C:\WINDOWS\system32\sysdm.exe
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\system32\UvxEOqru.ini
C:\WINDOWS\system32\UvxEOqru.ini2
C:\WINDOWS\system32\yayvutqR.dll
C:\WINDOWS\system32\yJQtsuvw.ini
C:\WINDOWS\system32\yJQtsuvw.ini2

.
((((((((((((((((((((((((( Files Created from 2008-03-17 to 2008-04-17 )))))))))))))))))))))))))))))))
.

2008-04-16 17:08 . 2008-04-16 17:55 <DIR> d-------- C:\Program Files\Avira
2008-04-16 13:46 . 2008-04-16 19:08 1,570,343 ---hs---- C:\WINDOWS\system32\xuvmxxwt.ini
2008-04-16 13:45 . 2008-04-16 18:06 101,197 --a------ C:\WINDOWS\BM8fc0c4e0.xml
2008-04-16 00:57 . 2008-04-16 00:58 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-16 00:48 . 2008-04-16 20:12 <DIR> d-------- C:\Program Files\SDFix
2008-04-16 00:28 . 2008-04-16 00:28 <DIR> d-------- C:\Program Files\ESET
2008-04-15 18:55 . 2008-04-15 18:55 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-14 06:24 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-04-14 06:24 . 2008-03-29 19:23 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-04-14 06:24 . 2008-03-29 19:35 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-04-14 06:24 . 2008-01-17 17:34 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-04-14 06:24 . 2008-03-29 19:31 75,856 --a------ C:\WINDOWS\system32\drivers\aswSP.sys
2008-04-14 06:24 . 2008-03-29 19:27 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-04-14 06:24 . 2008-03-29 19:26 26,944 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-04-14 06:24 . 2008-03-29 19:29 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-04-14 06:24 . 2008-03-29 19:35 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys
2008-04-14 02:30 . 2008-04-14 02:30 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-13 20:19 . 2008-04-13 22:33 121 --a------ C:\WINDOWS\bdagent.INI
2008-04-13 13:09 . 2004-08-17 15:49 2,026,496 --a------ C:\WINDOWS\system32\netshell.backup
2008-04-13 13:09 . 2003-04-16 14:00 1,232,384 --a------ C:\WINDOWS\system32\write.backup
2008-04-13 13:09 . 2007-06-13 15:23 1,033,728 --a------ C:\WINDOWS\explorer.backup
2008-04-13 13:09 . 2004-08-17 15:49 260,096 --a------ C:\WINDOWS\system32\sndrec32.backup
2008-04-13 13:09 . 2005-07-06 14:58 219,648 --a------ C:\WINDOWS\system32\uxtheme.backup
2008-04-13 13:09 . 2003-04-16 14:00 152,064 --a------ C:\WINDOWS\system32\sndvol32.backup
2008-04-13 13:09 . 2004-08-17 15:49 77,824 --a------ C:\WINDOWS\system32\stobject.backup
2008-04-13 13:08 . 2007-10-25 18:44 8,464,384 --a------ C:\WINDOWS\system32\shell32.backup
2008-04-13 13:08 . 2004-08-17 15:49 924,672 --a------ C:\WINDOWS\system32\spider.backup
2008-04-13 13:08 . 2003-04-16 14:00 512,512 --a------ C:\WINDOWS\system32\mshearts.backup
2008-04-13 13:08 . 2003-04-16 14:00 504,832 --a------ C:\WINDOWS\system32\winmine.backup
2008-04-13 13:08 . 2003-04-16 14:00 441,856 --a------ C:\WINDOWS\system32\sol.backup
2008-04-13 13:08 . 2003-04-16 14:00 440,320 --a------ C:\WINDOWS\system32\freecell.backup
2008-04-13 13:08 . 2004-08-17 15:49 69,632 --a------ C:\WINDOWS\notepad.backup
2008-04-13 13:07 . 2001-11-08 06:56 6,094,336 --a------ C:\WINDOWS\system32\logonui.backup
2008-04-13 13:07 . 2004-08-17 15:48 2,927,616 --a------ C:\WINDOWS\system32\xpsp2res.backup
2008-04-13 13:07 . 2004-08-17 15:49 1,671,680 --a------ C:\WINDOWS\system32\msgina.backup
2008-04-13 13:07 . 2004-08-17 15:49 847,360 --a------ C:\WINDOWS\system32\mydocs.backup
2008-04-13 13:07 . 2004-08-17 15:49 727,040 --a------ C:\WINDOWS\system32\mspaint.backup
2008-04-13 13:07 . 2003-04-16 14:00 465,920 --a------ C:\WINDOWS\system32\charmap.backup
2008-04-13 13:07 . 2003-04-16 14:00 117,760 --a------ C:\WINDOWS\system32\calc.backup
2008-04-13 13:07 . 2004-08-17 15:49 76,288 --a------ C:\WINDOWS\system32\magnify.backup
2008-04-13 13:06 . 2004-08-17 15:49 2,376,704 --a------ C:\WINDOWS\system32\shimgvw.backup
2008-04-13 13:03 . 2008-04-13 13:03 <DIR> d-------- C:\WINDOWS\VCP_SAVE
2008-04-13 13:03 . 2008-04-13 13:03 <DIR> d-------- C:\Program Files\Wallpapers
2008-04-13 13:03 . 2008-04-13 13:03 <DIR> d-------- C:\Program Files\Fonts
2008-04-13 13:03 . 2005-09-28 02:31 49,152 --a------ C:\WINDOWS\system32\icon.exe
2008-04-13 13:02 . 2008-04-13 13:09 <DIR> d-------- C:\WINDOWS\VCP_TEMP
2008-04-13 12:38 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-04-13 01:22 . 2008-04-13 01:25 2,554 --a------ C:\WINDOWS\unins000.dat
2008-04-12 22:38 . 2008-04-12 23:12 354 --ahs---- C:\WINDOWS\system32\iatqmtmc.ini
2008-04-12 18:51 . 2008-04-12 19:39 466 --ahs---- C:\WINDOWS\system32\ugplfqaj.ini
2008-04-11 13:17 . 2008-04-11 13:17 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-04-11 13:13 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-04-11 13:09 . 2008-04-11 13:29 104,643 --a------ C:\WINDOWS\hpoins04.dat
2008-04-11 13:09 . 2004-06-21 22:02 17,176 --------- C:\WINDOWS\hpomdl04.dat
2008-04-11 12:45 . 2008-01-14 18:44 104,250 --------- C:\WINDOWS\hpoins04.dat.temp
2008-04-11 12:45 . 2004-06-21 22:02 17,176 --------- C:\WINDOWS\hpomdl04.dat.temp
2008-04-09 08:08 . 2008-03-01 15:02 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-04-09 08:08 . 2007-04-17 11:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-04-09 08:08 . 2007-03-08 07:09 1,024,000 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-04-09 08:08 . 2008-03-01 15:02 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-04-09 08:08 . 2008-03-01 15:02 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-04-09 08:08 . 2008-03-01 15:02 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-04-09 08:08 . 2008-03-01 15:02 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-04-09 08:08 . 2008-03-01 15:02 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-04-09 08:08 . 2008-02-22 12:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-06 10:22 . 2008-04-06 10:22 <DIR> d-------- C:\Program Files\inKline Global
2008-03-22 06:29 . 2008-03-22 06:29 <DIR> d-------- C:\Program Files\directx

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-16 14:45 --------- d-----w C:\Program Files\PowerArchiver
2008-04-16 03:16 --------- d-----w C:\Program Files\Java
2008-04-14 01:41 --------- d-----w C:\Program Files\FlashGet
2008-04-13 19:18 --------- d-----w C:\Program Files\H264
2008-04-13 07:53 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-04-13 07:11 --------- d-----w C:\Program Files\DVDFab Platinum 4
2008-04-12 23:25 72,537 ----a-w C:\WINDOWS\unins000.exe
2008-04-06 11:50 --------- d-----w C:\Program Files\Opera
2008-04-03 06:13 --------- d-----w C:\Program Files\CD Eject Tool
2008-03-17 19:06 --------- d-----w C:\Program Files\History Sweeper
2008-03-16 07:43 --------- d-----w C:\Program Files\totalcmd
2008-03-16 07:07 --------- d-----w C:\Program Files\Ashampoo
2008-03-15 15:33 --------- d-----w C:\Program Files\Webteh
2008-03-13 14:52 71,176 ----a-w C:\WINDOWS\system32\drivers\epfw.sys
2008-03-13 14:52 54,280 ----a-w C:\WINDOWS\system32\drivers\epfwtdi.sys
2008-03-13 14:52 30,728 ----a-w C:\WINDOWS\system32\drivers\epfwndis.sys
2008-03-13 14:44 29,704 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2008-03-13 14:43 40,456 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
2008-03-12 12:05 --------- d-----w C:\Program Files\%temp&
2008-03-02 18:12 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-29 19:48 --------- d-----w C:\Program Files\FastStone Capture
2008-02-24 07:26 --------- d-----w C:\Program Files\DivX
2008-02-24 07:03 --------- d-----w C:\Program Files\Internet Download Manager
2007-05-17 21:16 23 -csha-w C:\WINDOWS\system32\faecaf9_r.dll
.

------- Sigcheck -------

2007-06-13 15:23 4919808 24b1ff8bd1f86242d90fd09f66484c84 C:\WINDOWS\explorer.exe
2007-06-13 15:11 1033728 9b32416bd5988c97b6397ce0b02caf97 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2003-04-16 14:00 1004544 11d80755545cfb5eb9659ee88440eae2 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-17 15:49 4918784 c6c0c8de8425eed7c666f10f5d9104f0 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2007-06-13 15:23 4919808 24b1ff8bd1f86242d90fd09f66484c84 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2007-06-13 15:23 1033728 ed7b460b142a32097b8a8f6ecc941815 C:\WINDOWS\VCP_SAVE\explorer.exe
2007-06-13 15:23 4919808 24b1ff8bd1f86242d90fd09f66484c84 C:\WINDOWS\VCP_TEMP\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02715E47-5A8E-495B-8F63-0D30470B8E72}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{03FF3484-1297-4C3A-ACBE-212F5454A3A2}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{09FFD943-C05E-4B80-8893-46AD971FE34E}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0FB0E60C-BFC0-4DBD-8084-698CDB280AF7}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{121E4E37-30F9-4DEA-9160-5166F5522BAE}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{15ACA267-FDFD-4A1E-81B0-E211F0BAFED4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1A43C67A-0787-4436-B0FD-B25BF65498CA}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C6E4C4F-36FD-4EDE-A6BE-D244F8BF66A1}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{21EA63A7-04EB-41FF-9EF2-9382B8458885}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{23E5396C-AC49-4D96-83E2-2A59E1E5AAA3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2766E49D-FAD1-4C13-B78A-9C038FD797DF}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2776798E-74DF-4499-A893-EEA0F32BCF1E}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{288395DD-F28F-4E1E-9415-A40A0C81679F}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2AEE8F68-BFB8-4D05-87D4-361BB69F109A}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3ACF159E-367E-454B-8E15-A94980B69FA6}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3BD1BD0B-9B33-4298-B6F7-40F97AFE039D}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{443695FE-8E2B-49CC-BC65-499C39E7F3B3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4CA86686-2441-4973-BCA4-B817F6B52927}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51A67331-7A47-4016-A705-205DCE341360}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{52A1B778-3C44-4EBA-AA2A-D8044ED18487}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53020DEF-D30A-4443-A76F-9EF08524BA18}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{594A022E-4C88-4AAF-BB18-EC272D257FB5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{60B58FAF-1385-4918-B248-06C730A9C909}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{60C06EB2-00DC-46FF-8DDF-D892FB65EBA9}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6730A117-332F-477F-8977-9CB21743CFEB}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6DEB2CD9-D07F-4A0E-9858-4E497F0EC508}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{763A8F24-01F1-4FE3-B7B7-B112FF07E25B}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{78C16285-70C9-493C-AA86-CA7E5C43E223}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7936A975-CD71-47C5-9B7F-CF849DF460CB}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{81A83AA6-1712-4DE2-B7CD-19FA613CBBC3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8562332D-A8F5-4395-A28E-BBC45855E56D}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{885E8919-33F0-4AF5-93F3-0C428BF3FA46}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8A5DBEBA-3277-428A-B6A5-2E81EE9C1B13}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8F1E2C9B-0F73-4BD5-A641-FF3FC334C5A1}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91D761C1-F3DF-4A2F-8C6A-B8A4073C9705}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97DCEDC8-04C8-4D37-AC6F-EEA7D17A1BC9}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9D30B3F7-8411-4C66-AF72-95CE9B73F6E9}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ACFDB92D-A0D9-4B22-AF23-D0C28B7A8A74}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BD0B5165-B525-4C86-BEBB-ABA416A6719C}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CFDA6CCD-E94F-4D08-8E24-B7DFFDD53FBA}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DB470C87-8A40-45CB-94A8-8936A775931E}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E45E37BD-600F-4224-A827-AED1D3043BE0}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E8D03F4A-2731-43A3-B1E3-3481A212D996}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F20FEEC0-B86E-4337-A363-640D9F567ED5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FA7D85A4-3C51-44C3-88D7-34DB5271DAE7}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FBE1F40F-29BC-4A6E-A109-DBC7B10E5395}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FBFFDD72-0C03-4CAD-9865-16FF32AC9AC9}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Chronograph"="C:\Program Files\Chronograph\chrono.exe" [2007-04-26 00:04 3762768]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-07-02 23:28 171448]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2008-02-21 08:44 2594224]
"PowerArchiver Tray"="C:\Program Files\PowerArchiver\PASTARTER.EXE" [2008-01-24 19:36 141352]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"RestoreDesktop"="C:\Program Files\Restore Desktop\RestoreDesktop.exe" [2003-03-11 10:52 45056]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SeznamAntidialer"="C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe" [2005-01-24 11:11 286720]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"GrooveMonitor"="D:\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"hmonitor"="C:\Program Files\Hmonitor\hmonitor.exe" [2006-11-14 18:15 860160]
"HP Software Update"="D:\HP Software Update\HPWuSchd2.exe" [2004-02-12 14:38 49152]
"DefragTaskBar"="C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe" [2007-08-28 17:31 169312]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 15:18 241664]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2008-03-13 16:48 1443072]
"8cf3f77c"="C:\WINDOWS\system32\twxxmvux.dll" [ ]
"BM8fc0c4e0"="C:\WINDOWS\system32\mrfegpyi.dll" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-17 15:49 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnMEUOG]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\yayvutqR

[HKLM\~\startupfolder\C:^Documents and Settings^hranol^Nabídka Start^Programy^Po spuštění^AdMuncher.lnk]
backup=C:\WINDOWS\pss\AdMuncher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\8cf3f77c]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cleanup]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 2006-09-28 21:21 57344 C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-17 15:49 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iconcache]
--a------ 2006-02-18 07:19 621 c:\windows\vcp_temp\iconcache\icon.bat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
--a------ 2006-07-11 12:16 3147872 C:\Program Files\ICQLite\ICQLite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 18:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nero DriveSpeed]
--------- 2005-04-20 17:46 593920 D:\Ahead\NEROTO~1\DRIVES~1.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEXPRESS]
--a------ 2007-05-17 13:58 26624 C:\WINDOWS\OETRN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QSmile]
--------- 2006-02-16 05:27 689017 C:\Program Files\AsefSoft\Quick Smile 3\QSmile.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sweeper.exe]
--a------ 2008-02-26 01:06 176128 C:\Program Files\History Sweeper\sweeper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sp_rssrv"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\ICQLite\\ICQLite.exe"=
"D:\\Office12\\OUTLOOK.EXE"=
"D:\\Office12\\GROOVE.EXE"=
"D:\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Chronograph\\chrono.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Ad Muncher\\AdMunch.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 hmonitor;hmonitor;C:\WINDOWS\system32\drivers\hmonitor.sys [2006-10-05 14:31]
R3 AEXPAM;Philips SmartManage Service;C:\WINDOWS\system32\Drivers\aexpamdrv.sys [2004-09-01 14:10]
R3 DynCal;Dynamic Calibration Service;C:\WINDOWS\system32\drivers\Dyncal.sys [2001-05-21 14:01]
R3 PAC7311;Phenix-Q8;C:\WINDOWS\system32\DRIVERS\PA707UCM.SYS [2005-10-18 11:48]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
S3 RockfireAnalogJoystickEnabler;Rockfire Analog Gamedevice driver;C:\WINDOWS\system32\drivers\RFTBtn.sys [2001-05-21 11:28]

.
Contents of the 'Scheduled Tasks' folder
"2008-04-16 14:00:37 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-17 09:36:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Chronograph"="\"C:\\Program Files\\Chronograph\\chrono.exe\" /autorun"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
C:\WINDOWS\system32\PAStiSvc.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
D:\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
D:\Digital Imaging\bin\hpqgalry.exe
.
**************************************************************************
.
Completion time: 2008-04-17 9:44:50 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-17 07:44:13

Adresářů: 16, Volných bajtů: 5,099,896,832
Adres ý…: 18, Volněch bajt…: 5,013,934,080
.
2008-04-14 09:07:14 --- E O F ---


=============================================

takze napoveda se mi objevila....sláva.....jinak dekuji moc......a tesim se na dalsi pokyny......

Hranol

Re: Prosím o kontrolu logu. Dík.

Napsal: 17 dub 2008 12:46
od hranol
Jo jeste me ESS vyhodil do karanteny pri projizdeni Combem soubor viz..

Obrázek

a

pri startu a restartu me skace hláška

Obrázek

a
pri zapnuti IE me to obcas vyhodi tuto hlasku viz

Obrázek

Jinak PC slape tedka o 1000 proc.lepe...jses borec......dik moc....a cekam na dalsi pokyny .....

Hranol

Re: Prosím o kontrolu logu. Dík.

Napsal: 17 dub 2008 20:00
od fredik
Neřekl jsi nič ohledně toho TeaTimeru?

Ten soubor co našel NOD je v pořádku, více o něm se můžeš dočíst nař. zde

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok)
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

File::
C:\WINDOWS\system32\xuvmxxwt.ini
C:\WINDOWS\BM8fc0c4e0.xml
C:\WINDOWS\system32\iatqmtmc.ini
C:\WINDOWS\system32\ugplfqaj.ini

Folder::
C:\Program Files\SDFix

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02715E47-5A8E-495B-8F63-0D30470B8E72}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{03FF3484-1297-4C3A-ACBE-212F5454A3A2}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{09FFD943-C05E-4B80-8893-46AD971FE34E}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0FB0E60C-BFC0-4DBD-8084-698CDB280AF7}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{121E4E37-30F9-4DEA-9160-5166F5522BAE}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{15ACA267-FDFD-4A1E-81B0-E211F0BAFED4}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1A43C67A-0787-4436-B0FD-B25BF65498CA}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C6E4C4F-36FD-4EDE-A6BE-D244F8BF66A1}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{21EA63A7-04EB-41FF-9EF2-9382B8458885}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{23E5396C-AC49-4D96-83E2-2A59E1E5AAA3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2766E49D-FAD1-4C13-B78A-9C038FD797DF}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2776798E-74DF-4499-A893-EEA0F32BCF1E}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{288395DD-F28F-4E1E-9415-A40A0C81679F}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2AEE8F68-BFB8-4D05-87D4-361BB69F109A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3ACF159E-367E-454B-8E15-A94980B69FA6}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3BD1BD0B-9B33-4298-B6F7-40F97AFE039D}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{443695FE-8E2B-49CC-BC65-499C39E7F3B3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4CA86686-2441-4973-BCA4-B817F6B52927}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51A67331-7A47-4016-A705-205DCE341360}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{52A1B778-3C44-4EBA-AA2A-D8044ED18487}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53020DEF-D30A-4443-A76F-9EF08524BA18}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{594A022E-4C88-4AAF-BB18-EC272D257FB5}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{60B58FAF-1385-4918-B248-06C730A9C909}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{60C06EB2-00DC-46FF-8DDF-D892FB65EBA9}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6730A117-332F-477F-8977-9CB21743CFEB}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6DEB2CD9-D07F-4A0E-9858-4E497F0EC508}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{763A8F24-01F1-4FE3-B7B7-B112FF07E25B}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{78C16285-70C9-493C-AA86-CA7E5C43E223}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7936A975-CD71-47C5-9B7F-CF849DF460CB}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{81A83AA6-1712-4DE2-B7CD-19FA613CBBC3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8562332D-A8F5-4395-A28E-BBC45855E56D}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{885E8919-33F0-4AF5-93F3-0C428BF3FA46}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8A5DBEBA-3277-428A-B6A5-2E81EE9C1B13}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8F1E2C9B-0F73-4BD5-A641-FF3FC334C5A1}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91D761C1-F3DF-4A2F-8C6A-B8A4073C9705}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{97DCEDC8-04C8-4D37-AC6F-EEA7D17A1BC9}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9D30B3F7-8411-4C66-AF72-95CE9B73F6E9}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ACFDB92D-A0D9-4B22-AF23-D0C28B7A8A74}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BD0B5165-B525-4C86-BEBB-ABA416A6719C}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CFDA6CCD-E94F-4D08-8E24-B7DFFDD53FBA}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DB470C87-8A40-45CB-94A8-8936A775931E}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E45E37BD-600F-4224-A827-AED1D3043BE0}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E8D03F4A-2731-43A3-B1E3-3481A212D996}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F20FEEC0-B86E-4337-A363-640D9F567ED5}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FA7D85A4-3C51-44C3-88D7-34DB5271DAE7}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FBE1F40F-29BC-4A6E-A109-DBC7B10E5395}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FBFFDD72-0C03-4CAD-9865-16FF32AC9AC9}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"8cf3f77c"=-
"BM8fc0c4e0"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnMEUOG]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\8cf3f77c]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cleanup]

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť
Obrázek
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT.

Re: Prosím o kontrolu logu. Dík.

Napsal: 17 dub 2008 22:03
od hranol
ComboFix 08-04-16.5 - hranol 2008-04-17 21:08:50.3 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.530 [GMT 2:00]
Running from: C:\Documents and Settings\hranol\Plocha\ComboFix.exe
Command switches used :: C:\Documents and Settings\hranol\Plocha\CFScript.txt
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\BM8fc0c4e0.xml
C:\WINDOWS\system32\iatqmtmc.ini
C:\WINDOWS\system32\ugplfqaj.ini
C:\WINDOWS\system32\xuvmxxwt.ini
.
/wow section - STAGE 38
pv: No matching processes found
Nesprávná syntaxe příkazu


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\hranol\Data aplikací\ezpinst.log
C:\Program Files\SDFix
C:\Program Files\SDFix\apps\assosfix.reg
C:\Program Files\SDFix\apps\cliptext.exe
C:\Program Files\SDFix\apps\download.exe
C:\Program Files\SDFix\apps\dummy.sys
C:\Program Files\SDFix\apps\Enable_Command_Prompt.reg
C:\Program Files\SDFix\apps\ERDNT.E_E
C:\Program Files\SDFix\apps\ERDNTDOS.LOC
C:\Program Files\SDFix\apps\ERDNTWIN.LOC
C:\Program Files\SDFix\apps\ERUNT.EXE
C:\Program Files\SDFix\apps\ERUNT.LOC
C:\Program Files\SDFix\apps\fix.reg
C:\Program Files\SDFix\apps\FixBH.reg
C:\Program Files\SDFix\apps\FixComponents.reg
C:\Program Files\SDFix\apps\FIXCU.reg
C:\Program Files\SDFix\apps\FIXLM.reg
C:\Program Files\SDFix\apps\FixPath.exe
C:\Program Files\SDFix\apps\FixRedir.reg
C:\Program Files\SDFix\apps\FixSchedule.reg
C:\Program Files\SDFix\apps\FixWebCheck.reg
C:\Program Files\SDFix\apps\fixXP.reg
C:\Program Files\SDFix\apps\FixXPsp2.reg
C:\Program Files\SDFix\apps\grep.exe
C:\Program Files\SDFix\apps\HPFix.reg
C:\Program Files\SDFix\apps\HPFix2.reg
C:\Program Files\SDFix\apps\HPFix3.reg
C:\Program Files\SDFix\apps\HPFix4.reg
C:\Program Files\SDFix\apps\HPFix5.reg
C:\Program Files\SDFix\apps\HPFix6.reg
C:\Program Files\SDFix\apps\HPFix7.reg
C:\Program Files\SDFix\apps\isadmin.exe
C:\Program Files\SDFix\apps\leg2.txt
C:\Program Files\SDFix\apps\legacy.txt
C:\Program Files\SDFix\apps\legacybk.txt
C:\Program Files\SDFix\apps\locate.com
C:\Program Files\SDFix\apps\LS.exe
C:\Program Files\SDFix\apps\MD5File.exe
C:\Program Files\SDFix\apps\MyGcpvFix.reg
C:\Program Files\SDFix\apps\MyGkFix2.reg
C:\Program Files\SDFix\apps\Process.exe
C:\Program Files\SDFix\apps\procs.exe
C:\Program Files\SDFix\apps\psservice.exe
C:\Program Files\SDFix\apps\Rem.txt
C:\Program Files\SDFix\apps\Rem2.txt
C:\Program Files\SDFix\apps\Replace\regedit.exe
C:\Program Files\SDFix\apps\Replace\W2K.exe
C:\Program Files\SDFix\apps\Replace\w2k\beep.sys
C:\Program Files\SDFix\apps\Replace\w2k\null.sys
C:\Program Files\SDFix\apps\Replace\XP.exe
C:\Program Files\SDFix\apps\Replace\xp\beep.sys
C:\Program Files\SDFix\apps\Replace\xp\null.sys
C:\Program Files\SDFix\apps\Reset_AppInit_DLLs.reg
C:\Program Files\SDFix\apps\RestartIt!.exe
C:\Program Files\SDFix\apps\Restore_SecurityCenter.reg
C:\Program Files\SDFix\apps\Restore_SharedAccess.reg
C:\Program Files\SDFix\apps\sc.exe
C:\Program Files\SDFix\apps\sed.exe
C:\Program Files\SDFix\apps\SF.exe
C:\Program Files\SDFix\apps\shutdown.exe
C:\Program Files\SDFix\apps\srv2.txt
C:\Program Files\SDFix\apps\srv2bk.txt
C:\Program Files\SDFix\apps\svc.txt
C:\Program Files\SDFix\apps\svcbk.txt
C:\Program Files\SDFix\apps\swreg.exe
C:\Program Files\SDFix\apps\swsc.exe
C:\Program Files\SDFix\apps\unzip.exe
C:\Program Files\SDFix\apps\vfind.exe
C:\Program Files\SDFix\apps\WINMSG.EXE
C:\Program Files\SDFix\apps\winsec.reg
C:\Program Files\SDFix\apps\zip.exe
C:\Program Files\SDFix\backups\backupreg.zip
C:\Program Files\SDFix\backups\backups.zip
C:\Program Files\SDFix\backups\HOSTS
C:\Program Files\SDFix\backups_old\backupreg.zip
C:\Program Files\SDFix\backups_old\backups.zip
C:\Program Files\SDFix\backups_old\HOSTS
C:\Program Files\SDFix\backups_old1\backupreg.zip
C:\Program Files\SDFix\backups_old1\backups.zip
C:\Program Files\SDFix\backups_old1\HOSTS
C:\Program Files\SDFix\catchme.exe
C:\Program Files\SDFix\dummy.sys
C:\Program Files\SDFix\Report.txt
C:\Program Files\SDFix\Report_old_1.txt
C:\Program Files\SDFix\RunThis.bat
C:\Program Files\SDFix\SDFIX_ReadMe_Online.url
C:\WINDOWS\BM8fc0c4e0.xml
C:\WINDOWS\system32\aaccae5_r.dll
C:\WINDOWS\system32\ecfdef_r.dll
C:\WINDOWS\system32\ecfdef_z.dll
C:\WINDOWS\system32\iatqmtmc.ini
C:\WINDOWS\system32\ugplfqaj.ini
C:\WINDOWS\system32\xuvmxxwt.ini

.
((((((((((((((((((((((((( Files Created from 2008-03-17 to 2008-04-17 )))))))))))))))))))))))))))))))
.

2008-04-16 17:08 . 2008-04-16 17:55 <DIR> d-------- C:\Program Files\Avira
2008-04-16 00:57 . 2008-04-16 00:58 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-16 00:28 . 2008-04-16 00:28 <DIR> d-------- C:\Program Files\ESET
2008-04-15 23:16 . 2008-04-15 23:16 <DIR> d-------- C:\Documents and Settings\hranol\Data aplikací\URSoft
2008-04-15 18:55 . 2008-04-15 18:55 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-14 06:24 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-04-14 06:24 . 2008-03-29 19:23 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-04-14 06:24 . 2008-03-29 19:35 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-04-14 06:24 . 2008-01-17 17:34 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-04-14 06:24 . 2008-03-29 19:31 75,856 --a------ C:\WINDOWS\system32\drivers\aswSP.sys
2008-04-14 06:24 . 2008-03-29 19:27 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-04-14 06:24 . 2008-03-29 19:26 26,944 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-04-14 06:24 . 2008-03-29 19:29 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-04-14 06:24 . 2008-03-29 19:35 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys
2008-04-14 02:30 . 2008-04-14 02:30 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-13 20:19 . 2008-04-13 22:33 121 --a------ C:\WINDOWS\bdagent.INI
2008-04-13 13:09 . 2004-08-17 15:49 2,026,496 --a------ C:\WINDOWS\system32\netshell.backup
2008-04-13 13:09 . 2003-04-16 14:00 1,232,384 --a------ C:\WINDOWS\system32\write.backup
2008-04-13 13:09 . 2007-06-13 15:23 1,033,728 --a------ C:\WINDOWS\explorer.backup
2008-04-13 13:09 . 2004-08-17 15:49 260,096 --a------ C:\WINDOWS\system32\sndrec32.backup
2008-04-13 13:09 . 2005-07-06 14:58 219,648 --a------ C:\WINDOWS\system32\uxtheme.backup
2008-04-13 13:09 . 2003-04-16 14:00 152,064 --a------ C:\WINDOWS\system32\sndvol32.backup
2008-04-13 13:09 . 2004-08-17 15:49 77,824 --a------ C:\WINDOWS\system32\stobject.backup
2008-04-13 13:08 . 2007-10-25 18:44 8,464,384 --a------ C:\WINDOWS\system32\shell32.backup
2008-04-13 13:08 . 2004-08-17 15:49 924,672 --a------ C:\WINDOWS\system32\spider.backup
2008-04-13 13:08 . 2003-04-16 14:00 512,512 --a------ C:\WINDOWS\system32\mshearts.backup
2008-04-13 13:08 . 2003-04-16 14:00 504,832 --a------ C:\WINDOWS\system32\winmine.backup
2008-04-13 13:08 . 2003-04-16 14:00 441,856 --a------ C:\WINDOWS\system32\sol.backup
2008-04-13 13:08 . 2003-04-16 14:00 440,320 --a------ C:\WINDOWS\system32\freecell.backup
2008-04-13 13:08 . 2004-08-17 15:49 69,632 --a------ C:\WINDOWS\notepad.backup
2008-04-13 13:07 . 2001-11-08 06:56 6,094,336 --a------ C:\WINDOWS\system32\logonui.backup
2008-04-13 13:07 . 2004-08-17 15:48 2,927,616 --a------ C:\WINDOWS\system32\xpsp2res.backup
2008-04-13 13:07 . 2004-08-17 15:49 1,671,680 --a------ C:\WINDOWS\system32\msgina.backup
2008-04-13 13:07 . 2004-08-17 15:49 847,360 --a------ C:\WINDOWS\system32\mydocs.backup
2008-04-13 13:07 . 2004-08-17 15:49 727,040 --a------ C:\WINDOWS\system32\mspaint.backup
2008-04-13 13:07 . 2003-04-16 14:00 465,920 --a------ C:\WINDOWS\system32\charmap.backup
2008-04-13 13:07 . 2003-04-16 14:00 117,760 --a------ C:\WINDOWS\system32\calc.backup
2008-04-13 13:07 . 2004-08-17 15:49 76,288 --a------ C:\WINDOWS\system32\magnify.backup
2008-04-13 13:06 . 2004-08-17 15:49 2,376,704 --a------ C:\WINDOWS\system32\shimgvw.backup
2008-04-13 13:03 . 2008-04-13 13:03 <DIR> d-------- C:\WINDOWS\VCP_SAVE
2008-04-13 13:03 . 2008-04-13 13:03 <DIR> d-------- C:\Program Files\Wallpapers
2008-04-13 13:03 . 2008-04-13 13:03 <DIR> d-------- C:\Program Files\Fonts
2008-04-13 13:03 . 2005-09-28 02:31 49,152 --a------ C:\WINDOWS\system32\icon.exe
2008-04-13 13:02 . 2008-04-13 13:09 <DIR> d-------- C:\WINDOWS\VCP_TEMP
2008-04-13 12:38 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-04-13 01:22 . 2008-04-13 01:25 2,554 --a------ C:\WINDOWS\unins000.dat
2008-04-12 23:25 . 2008-04-14 00:41 <DIR> d-------- C:\Documents and Settings\hranol\Data aplikací\SUPERAntiSpyware.com
2008-04-12 18:41 . 2008-04-13 16:00 <DIR> d-------- C:\Documents and Settings\hranol\Data aplikací\TmpRecentIcons
2008-04-11 13:17 . 2008-04-11 13:17 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-04-11 13:17 . 2008-04-11 13:17 <DIR> d----c--- C:\Documents and Settings\All Users\Data aplikací\Hewlett-Packard
2008-04-11 13:13 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-04-11 13:09 . 2008-04-11 13:29 104,643 --a------ C:\WINDOWS\hpoins04.dat
2008-04-11 13:09 . 2004-06-21 22:02 17,176 --------- C:\WINDOWS\hpomdl04.dat
2008-04-11 12:45 . 2008-01-14 18:44 104,250 --------- C:\WINDOWS\hpoins04.dat.temp
2008-04-11 12:45 . 2004-06-21 22:02 17,176 --------- C:\WINDOWS\hpomdl04.dat.temp
2008-04-09 08:08 . 2008-03-01 15:02 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-04-09 08:08 . 2007-04-17 11:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-04-09 08:08 . 2007-03-08 07:09 1,024,000 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-04-09 08:08 . 2008-03-01 15:02 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-04-09 08:08 . 2008-03-01 15:02 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-04-09 08:08 . 2008-03-01 15:02 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-04-09 08:08 . 2008-03-01 15:02 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-04-09 08:08 . 2008-03-01 15:02 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-04-09 08:08 . 2008-02-22 12:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-06 10:22 . 2008-04-06 10:22 <DIR> d-------- C:\Program Files\inKline Global
2008-03-22 06:29 . 2008-03-22 06:29 <DIR> d-------- C:\Program Files\directx

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-17 15:12 --------- d-----w C:\Documents and Settings\hranol\Data aplikací\DMCache
2008-04-16 15:00 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2008-04-16 14:45 --------- d-----w C:\Program Files\PowerArchiver
2008-04-16 03:16 --------- d-----w C:\Program Files\Java
2008-04-15 21:18 --------- d---a-w C:\Documents and Settings\All Users\Data aplikací\TEMP
2008-04-14 01:41 --------- d-----w C:\Program Files\FlashGet
2008-04-14 00:32 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2008-04-14 00:11 --------- d-----w C:\Documents and Settings\hranol\Data aplikací\Vso
2008-04-13 19:18 --------- d-----w C:\Program Files\H264
2008-04-13 07:53 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-04-13 07:11 --------- d-----w C:\Program Files\DVDFab Platinum 4
2008-04-12 23:25 72,537 ----a-w C:\WINDOWS\unins000.exe
2008-04-09 06:47 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2008-04-06 11:50 --------- d-----w C:\Program Files\Opera
2008-04-03 06:13 --------- d-----w C:\Program Files\CD Eject Tool
2008-03-28 19:14 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Skype
2008-03-28 19:13 --------- d-----w C:\Documents and Settings\hranol\Data aplikací\Skype
2008-03-20 08:09 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-17 19:06 --------- d-----w C:\Program Files\History Sweeper
2008-03-16 07:43 --------- d-----w C:\Program Files\totalcmd
2008-03-16 07:07 --------- dc----w C:\Documents and Settings\All Users\Data aplikací\Ashampoo
2008-03-16 07:07 --------- d-----w C:\Program Files\Ashampoo
2008-03-15 15:33 --------- d-----w C:\Program Files\Webteh
2008-03-15 15:33 --------- d-----w C:\Documents and Settings\hranol\Data aplikací\BSplayer PRO
2008-03-14 22:24 93,128 ----a-w C:\WINDOWS\system32\ElbyCDIO.dll
2008-03-13 14:52 71,176 ----a-w C:\WINDOWS\system32\drivers\epfw.sys
2008-03-13 14:52 54,280 ----a-w C:\WINDOWS\system32\drivers\epfwtdi.sys
2008-03-13 14:52 30,728 ----a-w C:\WINDOWS\system32\drivers\epfwndis.sys
2008-03-13 14:44 29,704 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2008-03-13 14:43 40,456 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
2008-03-12 12:05 --------- d-----w C:\Program Files\%temp&
2008-03-11 21:05 --------- d-----w C:\Documents and Settings\hranol\Data aplikací\GARMIN
2008-03-02 18:12 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-01 13:02 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-29 19:48 --------- d-----w C:\Program Files\FastStone Capture
2008-02-24 07:26 --------- d-----w C:\Program Files\DivX
2008-02-24 07:03 --------- d-----w C:\Program Files\Internet Download Manager
2008-02-21 02:05 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-02-21 02:05 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-02-21 02:05 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-02-21 02:05 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-02-21 02:04 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-02-21 02:04 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-02-21 02:04 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-02-21 02:04 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-02-21 02:04 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-02-21 02:04 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-02-21 02:04 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-02-21 02:04 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-02-21 02:03 156,992 -c--a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-02-21 02:03 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-15 15:12 206,256 ----a-w C:\WINDOWS\system32\idmmbc.dll
2008-02-04 17:23 693,792 ----a-w C:\WINDOWS\system32\OGACheckControl.DLL
2007-04-15 16:53 87,608 -c--a-w C:\Documents and Settings\hranol\Data aplikací\ezpinst.exe
2007-04-15 16:53 47,360 -c--a-w C:\Documents and Settings\hranol\Data aplikací\pcouffin.sys
2007-05-17 21:16 23 -csha-w C:\WINDOWS\system32\faecaf9_r.dll
.

------- Sigcheck -------

2007-06-13 15:23 4919808 24b1ff8bd1f86242d90fd09f66484c84 C:\WINDOWS\explorer.exe
2007-06-13 15:11 1033728 9b32416bd5988c97b6397ce0b02caf97 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2003-04-16 14:00 1004544 11d80755545cfb5eb9659ee88440eae2 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-17 15:49 4918784 c6c0c8de8425eed7c666f10f5d9104f0 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2007-06-13 15:23 4919808 24b1ff8bd1f86242d90fd09f66484c84 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2007-06-13 15:23 1033728 ed7b460b142a32097b8a8f6ecc941815 C:\WINDOWS\VCP_SAVE\explorer.exe
2007-06-13 15:23 4919808 24b1ff8bd1f86242d90fd09f66484c84 C:\WINDOWS\VCP_TEMP\explorer.exe
.
((((((((((((((((((((((((((((( snapshot@2008-04-17_ 9.43.31.62 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-17 07:35:33 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-17 15:11:18 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2007-12-15 15:53:19 166,455 ----a-w C:\WINDOWS\PCHealth\HelpCtr\OfflineCache\index.dat
+ 2008-04-17 07:50:51 166,455 ----a-w C:\WINDOWS\PCHealth\HelpCtr\OfflineCache\index.dat
- 2007-12-15 15:53:21 5,194 ----a-w C:\WINDOWS\PCHealth\HelpCtr\PackageStore\SkuStore.bin
+ 2008-04-17 07:50:51 5,194 ----a-w C:\WINDOWS\PCHealth\HelpCtr\PackageStore\SkuStore.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Chronograph"="C:\Program Files\Chronograph\chrono.exe" [2007-04-26 00:04 3762768]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-07-02 23:28 171448]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2008-02-21 08:44 2594224]
"PowerArchiver Tray"="C:\Program Files\PowerArchiver\PASTARTER.EXE" [2008-01-24 19:36 141352]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"RestoreDesktop"="C:\Program Files\Restore Desktop\RestoreDesktop.exe" [2003-03-11 10:52 45056]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49 15360]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"ICQ Lite"="C:\Program Files\ICQLite\ICQLite.exe" [2006-07-11 12:16 3147872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SeznamAntidialer"="C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe" [2005-01-24 11:11 286720]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"GrooveMonitor"="D:\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"hmonitor"="C:\Program Files\Hmonitor\hmonitor.exe" [2006-11-14 18:15 860160]
"HP Software Update"="D:\HP Software Update\HPWuSchd2.exe" [2004-02-12 14:38 49152]
"DefragTaskBar"="C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe" [2007-08-28 17:31 169312]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 15:18 241664]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2008-03-13 16:48 1443072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-17 15:49 15360]

C:\Documents and Settings\hranol\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - D:\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]

C:\Documents and Settings\hranol\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - D:\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]

C:\Documents and Settings\hranol\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - D:\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]

C:\Documents and Settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - D:\Reader\reader_sl.exe [2006-10-23 02:48:00 40048]
Adobe Reader Synchronizer.lnk - D:\Reader\AdobeCollabSync.exe [2007-05-11 11:29:22 738968]
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-04-14 16:56:01 962663]
HP Digital Imaging Monitor.lnk - D:\Digital Imaging\bin\hpqtra08.exe [2004-05-28 23:31:38 241664]
Rychl‚ spuçtŘnˇ aplikace HP Image Zone.lnk - D:\Digital Imaging\bin\hpqthb08.exe [2004-05-29 00:06:36 53248]

[HKLM\~\startupfolder\C:^Documents and Settings^hranol^Nabídka Start^Programy^Po spuštění^AdMuncher.lnk]
backup=C:\WINDOWS\pss\AdMuncher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 2006-09-28 21:21 57344 C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-17 15:49 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iconcache]
--a------ 2006-02-18 07:19 621 c:\windows\vcp_temp\iconcache\icon.bat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
--a------ 2006-07-11 12:16 3147872 C:\Program Files\ICQLite\ICQLite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 18:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nero DriveSpeed]
--------- 2005-04-20 17:46 593920 D:\Ahead\NEROTO~1\DRIVES~1.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEXPRESS]
--a------ 2007-05-17 13:58 26624 C:\WINDOWS\OETRN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QSmile]
--------- 2006-02-16 05:27 689017 C:\Program Files\AsefSoft\Quick Smile 3\QSmile.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sweeper.exe]
--a------ 2008-02-26 01:06 176128 C:\Program Files\History Sweeper\sweeper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sp_rssrv"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\ICQLite\\ICQLite.exe"=
"D:\\Office12\\OUTLOOK.EXE"=
"D:\\Office12\\GROOVE.EXE"=
"D:\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Chronograph\\chrono.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Ad Muncher\\AdMunch.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 hmonitor;hmonitor;C:\WINDOWS\system32\drivers\hmonitor.sys [2006-10-05 14:31]
R3 AEXPAM;Philips SmartManage Service;C:\WINDOWS\system32\Drivers\aexpamdrv.sys [2004-09-01 14:10]
R3 DynCal;Dynamic Calibration Service;C:\WINDOWS\system32\drivers\Dyncal.sys [2001-05-21 14:01]
R3 PAC7311;Phenix-Q8;C:\WINDOWS\system32\DRIVERS\PA707UCM.SYS [2005-10-18 11:48]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
S3 RockfireAnalogJoystickEnabler;Rockfire Analog Gamedevice driver;C:\WINDOWS\system32\drivers\RFTBtn.sys [2001-05-21 11:28]

.
Contents of the 'Scheduled Tasks' folder
"2008-04-16 14:00:37 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-17 21:12:39
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Chronograph"="\"C:\\Program Files\\Chronograph\\chrono.exe\" /autorun"
.
Completion time: 2008-04-17 21:16:51
ComboFix-quarantined-files.txt 2008-04-17 19:15:46
ComboFix2.txt 2008-04-17 08:41:47
ComboFix3.txt 2008-04-17 07:44:52

Adresářů: 16, Volných bajtů: 5,450,489,856
Adresářů: 18, Volných bajtů: 5,438,689,280
.
2008-04-14 09:07:14 --- E O F ---
================================================================================================

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:20:42, on 17.4.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe
D:\Office12\GrooveMonitor.exe
C:\Program Files\Hmonitor\hmonitor.exe
D:\HP Software Update\HPWuSchd2.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Chronograph\chrono.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\PowerArchiver\PASTARTER.EXE
C:\Program Files\Restore Desktop\RestoreDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
D:\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Program Files\ICQToolbar\tbu21C4\toolbaru.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\WINDOWS\WebIE.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\WINDOWS\WebIE.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Seznam Bezpečný Internet - {B71B15CE-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam Bezpecny Internet\SBI.dll
O4 - HKLM\..\Run: [SeznamAntidialer] "C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [hmonitor] C:\Program Files\Hmonitor\hmonitor.exe
O4 - HKLM\..\Run: [HP Software Update] "D:\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DefragTaskBar] "C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Chronograph] "C:\Program Files\Chronograph\chrono.exe" /autorun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [PowerArchiver Tray] C:\Program Files\PowerArchiver\PASTARTER.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RestoreDesktop] C:\Program Files\Restore Desktop\RestoreDesktop.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Reader\AdobeCollabSync.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Rychlé spuštění aplikace HP Image Zone.lnk = D:\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Přelož do češtiny - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5034
O8 - Extra context menu item: Block frame with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_frame
O8 - Extra context menu item: Block image with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_image
O8 - Extra context menu item: Block link with Ad Muncher - http://www.admuncher.com/request_will_b ... nu_ie_link
O8 - Extra context menu item: Don't filter page with Ad Muncher - http://www.admuncher.com/request_will_b ... ie_exclude
O8 - Extra context menu item: Hledej v &Seznamu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5033
O8 - Extra context menu item: Hledej v Seznam &Fulltextu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5035
O8 - Extra context menu item: Report page to the Ad Muncher developers - http://www.admuncher.com/request_will_b ... _ie_report
O8 - Extra context menu item: Stáhnout obsah FLV videa s IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Stáhnout s IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O15 - Trusted Zone: http://toolbar.imageshack.us
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 6571819750
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/Im ... oolbar.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7BEF656D-72B5-4513-B854-E88C725548AC}: NameServer = 212.158.128.2 212.158.128.3
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: opnMEUOG - C:\WINDOWS\
O23 - Service: AshampooDefragService - - C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
O23 - Service: aswUpdSv - ALWIL Software - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe

--
End of file - 11397 bytes
================================================================================================

Kód: Vybrat vše

http://trendsecure.custhelp.com/cgi-bin/trendsecure.cfg/php/enduser/std_alp.php


Tohle se me ukazalo pri Hijacku.....viz nahore http.......kdyz jsem spustil Hijack,chvilicku jel...potom naskocila chyba.....kdyz jsem dal...odklikl,tak naskocila ta stranka a Hijack normalne dokoncil kontrolu....zapomnel jsem
vypnout net....
Spybot....mel jsem zatrhlou rez.......jak jsi psal...tak jsem ji vypl.....

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:20:42, on 17.4.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe
D:\Office12\GrooveMonitor.exe
C:\Program Files\Hmonitor\hmonitor.exe
D:\HP Software Update\HPWuSchd2.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Chronograph\chrono.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\PowerArchiver\PASTARTER.EXE
C:\Program Files\Restore Desktop\RestoreDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
D:\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Program Files\ICQToolbar\tbu21C4\toolbaru.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\WINDOWS\WebIE.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\WINDOWS\WebIE.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Seznam Bezpečný Internet - {B71B15CE-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam Bezpecny Internet\SBI.dll
O4 - HKLM\..\Run: [SeznamAntidialer] "C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [hmonitor] C:\Program Files\Hmonitor\hmonitor.exe
O4 - HKLM\..\Run: [HP Software Update] "D:\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DefragTaskBar] "C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Chronograph] "C:\Program Files\Chronograph\chrono.exe" /autorun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [PowerArchiver Tray] C:\Program Files\PowerArchiver\PASTARTER.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RestoreDesktop] C:\Program Files\Restore Desktop\RestoreDesktop.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Reader\AdobeCollabSync.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Rychlé spuštění aplikace HP Image Zone.lnk = D:\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Přelož do češtiny - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5034
O8 - Extra context menu item: Block frame with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_frame
O8 - Extra context menu item: Block image with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_image
O8 - Extra context menu item: Block link with Ad Muncher - http://www.admuncher.com/request_will_b ... nu_ie_link
O8 - Extra context menu item: Don't filter page with Ad Muncher - http://www.admuncher.com/request_will_b ... ie_exclude
O8 - Extra context menu item: Hledej v &Seznamu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5033
O8 - Extra context menu item: Hledej v Seznam &Fulltextu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5035
O8 - Extra context menu item: Report page to the Ad Muncher developers - http://www.admuncher.com/request_will_b ... _ie_report
O8 - Extra context menu item: Stáhnout obsah FLV videa s IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Stáhnout s IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O15 - Trusted Zone: http://toolbar.imageshack.us
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 6571819750
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/Im ... oolbar.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7BEF656D-72B5-4513-B854-E88C725548AC}: NameServer = 212.158.128.2 212.158.128.3
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: opnMEUOG - C:\WINDOWS\
O23 - Service: AshampooDefragService - - C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
O23 - Service: aswUpdSv - ALWIL Software - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe

--
End of file - 11397 bytes

Re: Prosím o kontrolu logu. Dík.

Napsal: 17 dub 2008 22:07
od hranol
Jinak znova, dik Ti moc za ochotu a cekam na dalsi pokyny.....

Zdravi Hranol.......

Re: Prosím o kontrolu logu. Dík.

Napsal: 18 dub 2008 22:13
od fredik
Rezidentní ochranu máš momentálně u SpyBota zapnutou, musíš si ji nastavit tak jak bylo popsáno a je znázorněno na obrázku.

Máš tam také pozůstatky po Avastu, tak použij na odstranění jeho pozůstatků tento nástroj:
Odinstalační nástroj pro avast!

Otestuj tento soubor na VirusTotal
C:\WINDOWS\system32\faecaf9_r.dll
rovnou zkopíruj celou cestu k souboru v okně na VirusTotal a vlož sem pak výsledek.

Re: Prosím o kontrolu logu. Dík.

Napsal: 18 dub 2008 22:45
od hranol
Antivirus Verze Poslední aktualizace Výsledek
AhnLab-V3 2008.4.19.0 2008.04.18 -
AntiVir 7.8.0.8 2008.04.18 -
Authentium 4.93.8 2008.04.18 -
Avast 4.8.1169.0 2008.04.17 -
AVG 7.5.0.516 2008.04.18 -
BitDefender 7.2 2008.04.18 -
CAT-QuickHeal 9.50 2008.04.18 -
ClamAV 0.92.1 2008.04.18 -
DrWeb 4.44.0.09170 2008.04.18 -
eSafe 7.0.15.0 2008.04.17 -
eTrust-Vet 31.3.5709 2008.04.18 -
Ewido 4.0 2008.04.18 -
F-Prot 4.4.2.54 2008.04.18 -
F-Secure 6.70.13260.0 2008.04.18 -
FileAdvisor 1 2008.04.18 -
Fortinet 3.14.0.0 2008.04.18 -
Ikarus T3.1.1.26 2008.04.18 -
Kaspersky 7.0.0.125 2008.04.18 -
McAfee 5277 2008.04.18 -
Microsoft 1.3408 2008.04.18 -
NOD32v2 3039 2008.04.18 -
Norman 5.80.02 2008.04.18 -
Panda 9.0.0.4 2008.04.18 -
Prevx1 V2 2008.04.18 -
Rising 20.40.42.00 2008.04.18 -
Sophos 4.28.0 2008.04.18 -
Sunbelt 3.0.1056.0 2008.04.17 -
Symantec 10 2008.04.18 -
TheHacker 6.2.92.282 2008.04.18 -
VBA32 3.12.6.4 2008.04.16 -
VirusBuster 4.3.26:9 2008.04.18 -
Webwasher-Gateway 6.6.2 2008.04.18 -
Rozšiřující informace
File size: 23 bytes
MD5...: d78a1fa307e61d6e0cecd79c612271b2
SHA1..: 768226a75747e8252445b9d0fb44b76afc9d6cf7
SHA256: 574249cb7682b4f1f020dbb4261e39a7bd280206d9cad3833248ded4abe24972
SHA512: f525e6a9ba7a207a6d1dd54fd8fdfa6b574932284152143e4944e2732392f76e
3115bdae38696bc8fa7e5b1e080947aef3ae5f1d69eed9ff5bfb99577750594d
PEiD..: -
PEInfo: -
=================================================================================================


Ten Spybot jsem opravil...sorry...ja si toho spatne vsiml.

tady Ti poslu jeste jednou pro jistotu Hijack...

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:41:47, on 18.4.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe
D:\Office12\GrooveMonitor.exe
C:\Program Files\Hmonitor\hmonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
D:\HP Software Update\HPWuSchd2.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Chronograph\chrono.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\PowerArchiver\PASTARTER.EXE
C:\Program Files\Restore Desktop\RestoreDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
D:\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Program Files\ICQToolbar\tbu21C4\toolbaru.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\WINDOWS\WebIE.dll
O2 - BHO: (no name) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\WINDOWS\WebIE.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Seznam Bezpečný Internet - {B71B15CE-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam Bezpecny Internet\SBI.dll
O4 - HKLM\..\Run: [SeznamAntidialer] "C:\Program Files\Seznam Bezpecny Internet\SBIAntiDialer.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [hmonitor] C:\Program Files\Hmonitor\hmonitor.exe
O4 - HKLM\..\Run: [HP Software Update] "D:\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DefragTaskBar] "C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Chronograph] "C:\Program Files\Chronograph\chrono.exe" /autorun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [PowerArchiver Tray] C:\Program Files\PowerArchiver\PASTARTER.EXE
O4 - HKCU\..\Run: [RestoreDesktop] C:\Program Files\Restore Desktop\RestoreDesktop.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = D:\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Reader\AdobeCollabSync.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Rychlé spuštění aplikace HP Image Zone.lnk = D:\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Přelož do češtiny - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5034
O8 - Extra context menu item: Block frame with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_frame
O8 - Extra context menu item: Block image with Ad Muncher - http://www.admuncher.com/request_will_b ... u_ie_image
O8 - Extra context menu item: Block link with Ad Muncher - http://www.admuncher.com/request_will_b ... nu_ie_link
O8 - Extra context menu item: Don't filter page with Ad Muncher - http://www.admuncher.com/request_will_b ... ie_exclude
O8 - Extra context menu item: Hledej v &Seznamu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5033
O8 - Extra context menu item: Hledej v Seznam &Fulltextu - res://C:\Program Files\Seznam Bezpecny Internet\SBI.dll/5035
O8 - Extra context menu item: Report page to the Ad Muncher developers - http://www.admuncher.com/request_will_b ... _ie_report
O8 - Extra context menu item: Stáhnout obsah FLV videa s IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Stáhnout pomocí FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Stáhnout s IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Stáhnout vše pomocí FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O15 - Trusted Zone: http://toolbar.imageshack.us
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 6571819750
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/Im ... oolbar.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7BEF656D-72B5-4513-B854-E88C725548AC}: NameServer = 212.158.128.2 212.158.128.3
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: opnMEUOG - C:\WINDOWS\
O23 - Service: AshampooDefragService - - C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
O23 - Service: aswUpdSv - ALWIL Software - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe

--
End of file - 11139 bytes
================================================================================================

Opet diky moc za ochotu ......................a cekam na dalsi pokyny

Zdravi Hranol