Zkontrolujete mi Hijack log PLS?? Bojuji se spyware...

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Zéla
nováček
Příspěvky: 34
Registrován: červen 06
Bydliště: Chrudim
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

MWAV Log!!!

Příspěvekod Zéla » 13 čer 2006 15:18

Tue Jun 13 14:26:36 2006 => File C:\Documents and Settings\Zelda\Desktop\Recenze\Bombermania - odeslano\Bombermania.exe tagged as "not-a-virus:AdWare.Win32.Relevant.a". Action Taken: No Action Taken.

Tue Jun 13 14:26:49 2006 => File C:\Documents and Settings\Zelda\Desktop\Recenze\Real Pool - odeslano\Real_Pool.exe tagged as "not-a-virus:AdWare.Win32.Relevant.a". Action Taken: No Action Taken.

Tue Jun 13 14:27:01 2006 => File C:\Documents and Settings\Zelda\Desktop\Recenze\Magic Pets - odeslano\Magic_Pets.exe tagged as "not-a-virus:AdWare.Win32.Relevant.a". Action Taken: No Action Taken.

Tue Jun 13 14:28:36 2006 => System found infected with funweb Spyware/Adware ({147a976f-eee1-4377-8ea7-4716e4cdd239})! Action taken: No Action Taken.
Tue Jun 13 14:28:37 2006 => System found infected with alexa Spyware/Adware ({f1fabe79-25fc-46de-8c5a-2c6db9d64333})! Action taken: No Action Taken.
Tue Jun 13 14:30:48 2006 => System found infected with alexa Spyware/Adware ({547ab549-4dd8-4ea0-b070-f6ea062148ff})! Action taken: No Action Taken.
Tue Jun 13 14:30:48 2006 => System found infected with media pass Spyware/Adware ({00ada225-ea6c-4fb3-82e8-68189201ccb9})! Action taken: No Action Taken.
Tue Jun 13 14:30:48 2006 => System found infected with alexa Spyware/Adware ({0bbb0424-e98e-4405-9a94-481854765c80})! Action taken: No Action Taken.
Tue Jun 13 14:30:48 2006 => System found infected with alexa Spyware/Adware ({0f3332b5-bc98-48af-9fac-05fec94ebe73})! Action taken: No Action Taken.
Tue Jun 13 14:30:49 2006 => System found infected with alexa Spyware/Adware ({3e60160f-0ed6-4dcc-b6b6-850cde4fd217})! Action taken: No Action Taken.
Tue Jun 13 14:30:49 2006 => System found infected with alexa Spyware/Adware ({a69107cc-bec8-4a34-b474-211b0f46a764})! Action taken: No Action Taken.
Tue Jun 13 14:30:49 2006 => System found infected with alexa Spyware/Adware ({b7b84995-8b92-46bf-94aa-fa2f3dd23b84})! Action taken: No Action Taken.
Tue Jun 13 14:30:49 2006 => System found infected with alexa Spyware/Adware ({fa77ad79-09cf-41fb-b171-cc856f9e737f})! Action taken: No Action Taken.
Tue Jun 13 14:30:49 2006 => Offending Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\uninstall\alexa toolbar !!!
Tue Jun 13 14:30:49 2006 => Object "alexa Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jun 13 14:30:50 2006 => Offending Key found: HKLM\Software\alexa internet !!!
Tue Jun 13 14:30:50 2006 => Object "alexa Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jun 13 14:30:50 2006 => Offending Key found: HKLM\Software\alexa toolbar !!!
Tue Jun 13 14:30:50 2006 => Object "alexa Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jun 13 14:30:51 2006 => Offending Key found: HKCU\software\microsoft\windows\currentversion\explorer\menuorder\start menu\programs\180search assistant !!!
Tue Jun 13 14:30:51 2006 => Object "180searchassistant Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jun 13 14:30:52 2006 => Offending Key found: HKCU\software\microsoft\windows\currentversion\explorer\menuorder\start menu\programs\toptext ilookup !!!
Tue Jun 13 14:30:52 2006 => Object "ezula Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jun 13 14:30:52 2006 => Offending Key found: HKCU\software\microsoft\windows\currentversion\explorer\menuorder\start menu\programs\whenu !!!
Tue Jun 13 14:30:52 2006 => Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jun 13 14:30:52 2006 => Offending Key found: HKCU\software\microsoft\windows\currentversion\explorer\menuorder\start menu\programs\whenusearch !!!
Tue Jun 13 14:30:52 2006 => Object "whenu/search Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jun 13 14:30:52 2006 => Offending Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\180search assistant !!!
Tue Jun 13 14:30:52 2006 => Object "180searchassistant Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jun 13 14:30:52 2006 => Offending Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\toptext ilookup !!!
Tue Jun 13 14:30:52 2006 => Object "ezula Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jun 13 14:30:52 2006 => Offending Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\whenu !!!
Tue Jun 13 14:30:52 2006 => Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jun 13 14:30:52 2006 => Offending Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\whenusearch !!!
Tue Jun 13 14:30:52 2006 => Object "whenu/search Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jun 13 14:30:53 2006 => Offending file found: C:\WINDOWS\ezulains.exe
Tue Jun 13 14:30:53 2006 => System found infected with ezula toptext Spyware/Adware (ezulains.exe)! Action taken: No Action Taken.

Tue Jun 13 14:30:53 2006 => Offending file found: C:\WINDOWS\gpinstall.exe
Tue Jun 13 14:30:53 2006 => System found infected with conducent flexpak Spyware/Adware (gpinstall.exe)! Action taken: No Action Taken.

Tue Jun 13 14:30:53 2006 => Offending file found: C:\WINDOWS\alexaie.dll
Tue Jun 13 14:30:53 2006 => System found infected with alexa Spyware/Adware (alexaie.dll)! Action taken: No Action Taken.

Tue Jun 13 14:30:53 2006 => Offending file found: C:\WINDOWS\alxie328.dll
Tue Jun 13 14:30:53 2006 => System found infected with alexa Spyware/Adware (alxie328.dll)! Action taken: No Action Taken.

Tue Jun 13 14:30:53 2006 => Offending file found: C:\WINDOWS\alxtb1.dll
Tue Jun 13 14:30:53 2006 => System found infected with alexa Spyware/Adware (alxtb1.dll)! Action taken: No Action Taken.

Tue Jun 13 14:30:53 2006 => Offending file found: C:\WINDOWS\susp.exe
Tue Jun 13 14:30:53 2006 => System found infected with unknown pest Spyware/Adware (susp.exe)! Action taken: No Action Taken.

Tue Jun 13 14:30:53 2006 => Offending file found: C:\WINDOWS\zserv.dll
Tue Jun 13 14:30:53 2006 => System found infected with transponder parasite variant Spyware/Adware (zserv.dll)! Action taken: No Action Taken.

Tue Jun 13 14:30:53 2006 => Offending file found: C:\WINDOWS\btgrab.dll
Tue Jun 13 14:30:53 2006 => System found infected with btgrab Spyware/Adware (btgrab.dll)! Action taken: No Action Taken.

Tue Jun 13 14:30:53 2006 => Offending file found: C:\WINDOWS\pynix.dll
Tue Jun 13 14:30:53 2006 => System found infected with pynix Spyware/Adware (pynix.dll)! Action taken: No Action Taken.

Tue Jun 13 14:30:53 2006 => Offending file found: C:\WINDOWS\dlmax.dll
Tue Jun 13 14:30:53 2006 => System found infected with transponder parasite variant Spyware/Adware (dlmax.dll)! Action taken: No Action Taken.

Tue Jun 13 14:30:53 2006 => Offending file found: C:\WINDOWS\system32\ide21201.vxd
Tue Jun 13 14:30:53 2006 => System found infected with windupdate Spyware/Adware (ide21201.vxd)! Action taken: No Action Taken.

Tue Jun 13 14:30:54 2006 => Offending file found: C:\WINDOWS\system32\n8l80i3ue8.dll
Tue Jun 13 14:30:54 2006 => System found infected with look2me Adware (n8l80i3ue8.dll)! Action taken: No Action Taken.

Tue Jun 13 14:30:54 2006 => Offending file found: C:\WINDOWS\system32\winapi32.dll
Tue Jun 13 14:30:54 2006 => System found infected with w32/zmark-a trojan Spyware/Adware (winapi32.dll)! Action taken: No Action Taken.

Tue Jun 13 14:30:54 2006 => Offending file found: C:\WINDOWS\system32\winapi32.dll
Tue Jun 13 14:30:54 2006 => System found infected with w32/zmark-a trojan Spyware/Adware (winapi32.dll)! Action taken: No Action Taken.

Tue Jun 13 14:30:54 2006 => Offending file found: C:\WINDOWS\system32\alxres.dll
Tue Jun 13 14:30:54 2006 => System found infected with alexa Spyware/Adware (alxres.dll)! Action taken: No Action Taken.

Tue Jun 13 14:30:54 2006 => Offending file found: C:\WINDOWS\system32\dailytoolbar.dll
Tue Jun 13 14:30:54 2006 => System found infected with dailytoolbar parasite Spyware/Adware (dailytoolbar.dll)! Action taken: No Action Taken.

Tue Jun 13 14:30:54 2006 => Offending file found: C:\WINDOWS\system32\tcpservice2.exe
Tue Jun 13 14:30:54 2006 => System found infected with admess Spyware/Adware (tcpservice2.exe)! Action taken: No Action Taken.

Tue Jun 13 14:30:54 2006 => Offending file found: C:\WINDOWS\system32\wstart.dll
Tue Jun 13 14:30:54 2006 => System found infected with admess Spyware/Adware (wstart.dll)! Action taken: No Action Taken.

Tue Jun 13 14:30:54 2006 => Offending file found: C:\WINDOWS\system32\txfdb32.dll
Tue Jun 13 14:30:54 2006 => System found infected with midaddle Spyware/Adware (txfdb32.dll)! Action taken: No Action Taken.

Tue Jun 13 14:30:54 2006 => Offending file found: C:\WINDOWS\system32\a.exe
Tue Jun 13 14:30:54 2006 => System found infected with bridge Spyware/Adware (a.exe)! Action taken: No Action Taken.

Tue Jun 13 14:30:54 2006 => Offending file found: C:\WINDOWS\system32\bridge.dll
Tue Jun 13 14:30:54 2006 => System found infected with loudmarketing Spyware/Adware (bridge.dll)! Action taken: No Action Taken.

Tue Jun 13 14:30:54 2006 => Offending file found: C:\WINDOWS\system32\jao.dll
Tue Jun 13 14:30:54 2006 => System found infected with bridge Spyware/Adware (jao.dll)! Action taken: No Action Taken.

Tue Jun 13 14:30:54 2006 => Offending file found: C:\WINDOWS\system32\questmod.dll
Tue Jun 13 14:30:54 2006 => System found infected with 1.dll - adware.sa Spyware/Adware (questmod.dll)! Action taken: No Action Taken.

Tue Jun 13 14:31:30 2006 => File C:\WINDOWS\eZulains.exe tagged as "not-a-virus:AdWare.Win32.EZula.ak". Action Taken: No Action Taken.

Tue Jun 13 14:31:44 2006 => File C:\WINDOWS\NDNuninstall7_14.exe tagged as "not-a-virus:AdWare.Win32.NewDotNet.e". Action Taken: No Action Taken.

Tue Jun 13 14:31:45 2006 => Scanning File C:\WINDOWS\NDNuninstall7_22.exe
Tue Jun 13 14:31:45 2006 => File C:\WINDOWS\NDNuninstall7_22.exe tagged as "not-a-virus:AdWare.Win32.NewDotNet.e". Action Taken: No Action Taken.

Tue Jun 13 14:33:58 2006 => File C:\WINDOWS\system32\o7372hhp.ini tagged as "not-a-virus:AdWare.Win32.Sahat.ao". Action Taken: No Action Taken.

Tue Jun 13 14:35:31 2006 => File C:\WINDOWS\system32\k4080edueh080.dll tagged as "not-a-virus:AdWare.Win32.Look2Me.ab". Action Taken: No Action Taken.

Tue Jun 13 14:35:50 2006 => File C:\WINDOWS\system32\hr0m05d1e.dll tagged as "not-a-virus:AdWare.Win32.Look2Me.ab". Action Taken: No Action Taken.

Tue Jun 13 14:35:55 2006 => File C:\WINDOWS\system32\n8l80i3ue8.dll tagged as "not-a-virus:AdWare.Win32.Look2Me.ab". Action Taken: No Action Taken.

Tue Jun 13 14:35:56 2006 => File C:\WINDOWS\system32\i042laho1d4c.dll tagged as "not-a-virus:AdWare.Win32.Look2Me.ab". Action Taken: No Action Taken.

Ted jsem hledal virus

Tue Jun 13 14:30:52 2006 => Offending Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\time zones !!!
Tue Jun 13 14:30:52 2006 => Object "win32.passma Virus" found in File System! Action Taken: No Action Taken.

Tue Jun 13 14:31:43 2006 => File C:\WINDOWS\keyboard9.exe infected by "Trojan-Downloader.Win32.VB.aaf" Virus! Action Taken: No Action Taken.

Tue Jun 13 14:31:44 2006 => File C:\WINDOWS\newname9.exe infected by "Trojan-Downloader.Win32.VB.aaf" Virus! Action Taken: No Action Taken.

Tue Jun 13 14:31:45 2006 => File C:\WINDOWS\mousepad9.exe infected by "Trojan-Clicker.Win32.VB.mo" Virus! Action Taken: No Action Taken.

Tue Jun 13 14:31:49 2006 => File C:\WINDOWS\keyboard18.exe infected by "Trojan-Downloader.Win32.VB.abj" Virus! Action Taken: No Action Taken.

Tue Jun 13 14:31:49 2006 => File C:\WINDOWS\defender1.exe infected by "Trojan-Clicker.Win32.VB.ly" Virus! Action Taken: No Action Taken.

Tue Jun 13 14:31:49 2006 => File C:\WINDOWS\newname18.exe infected by "Trojan-Downloader.Win32.VB.acn" Virus! Action Taken: No Action Taken.

Tue Jun 13 14:31:49 2006 => File C:\WINDOWS\wallpap.exe infected by "Trojan-Clicker.Win32.Agent.gp" Virus! Action Taken: No Action Taken.

Tue Jun 13 14:36:39 2006 => File C:\WINDOWS\system32\zhopaizdupla.exe infected by "Trojan-Downloader.Win32.Small.atl" Virus! Action Taken: No Action Taken.

Tue Jun 13 14:36:40 2006 => File C:\WINDOWS\system32\parad.raw.exe infected by "Packed.Win32.Tibs" Virus! Action Taken: No Action Taken.

Tue Jun 13 14:36:40 2006 => File C:\WINDOWS\system32\taskdir.dll infected by "Trojan-Proxy.Win32.Lager.aq" Virus! Action Taken: No Action Taken.

Tue Jun 13 14:36:40 2006 => File C:\WINDOWS\system32\taskdir~.exe infected by "SpamTool.Win32.Agent.g" Virus! Action Taken: No Action Taken.

Tue Jun 13 14:36:41 2006 => File C:\WINDOWS\system32\xdpjswkb.exe infected by "Trojan-Downloader.Win32.VB.aan" Virus! Action Taken: No Action Taken.

Tue Jun 13 14:36:41 2006 => File C:\WINDOWS\system32\winbl32.dll infected by "not-virus:Hoax.Win32.VB.l" Virus! Action Taken: No Action Taken.

Tue Jun 13 14:36:41 2006 => File C:\WINDOWS\system32\winapi32.dll infected by "Trojan-Downloader.Win32.VB.aan" Virus! Action Taken: No Action Taken.

Tue Jun 13 14:36:43 2006 => File C:\WINDOWS\system32\ad.html infected by "Trojan-Clicker.JS.Agent.e" Virus! Action Taken: No Action Taken.

Tue Jun 13 14:36:42 2006 => File C:\WINDOWS\system32\repigsp.exe infected by "not-virus:Hoax.Win32.VB.l" Virus! Action Taken: No Action Taken.

Ted jsem jeste pro jistotu hledal hijac

Tue Jun 13 14:30:54 2006 => Offending file found: C:\WINDOWS\system32\ncompat.tlb
Tue Jun 13 14:30:54 2006 => System found infected with smitfraud Browser Hijacker (ncompat.tlb)! Action taken: No Action Taken.

Tue Jun 13 14:30:54 2006 => Offending file found: C:\WINDOWS\system32\svcp.csv
Tue Jun 13 14:30:54 2006 => System found infected with smitfraud Browser Hijacker (svcp.csv)! Action taken: No Action Taken.

Tue Jun 13 14:30:54 2006 => Offending file found: C:\WINDOWS\system32\winsub.xml
Tue Jun 13 14:30:54 2006 => System found infected with smitfraud Browser Hijacker (winsub.xml)! Action taken: No Action Taken.

Tue Jun 13 14:30:54 2006 => Offending file found: C:\WINDOWS\system32\zlbw.dll
Tue Jun 13 14:30:54 2006 => System found infected with smitfraud Browser Hijacker (zlbw.dll)! Action taken: No Action Taken.

Tue Jun 13 14:31:16 2006 => Offending file found: C:\WINDOWS\start.exe
Tue Jun 13 14:31:16 2006 => System found infected with cws.smartsearch Browser Hijacker (C:\WINDOWS\start.exe)! Action taken: No Action Taken.

vynechaval jsem odkazy jak hijackthis.exe a pod, o kterych jsem vedel ze jsou ciste... jen se v nazvu obevuje jeden ze zadanych vyrazu...

Prosim o kontrolu a o instrukce jak se tech hajzééélúúú zbavit...

jo a kdyz spustim tu BLbeta, tak to napise prakticky tu samou hlasku co punk buster... ze bud nejsem administrator, nebo ze mam virus ktery to blokuje!! bohuzel nevim jak se vlozi do diskuze obrazek... jinak bych ho vlozil...

Reklama
Uživatelský avatar
Zéla
nováček
Příspěvky: 34
Registrován: červen 06
Bydliště: Chrudim
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

blbeta obr

Příspěvekod Zéla » 13 čer 2006 15:29

tak uz sem zjistil jak nahrat obrazek... je tady Obrázek

Uživatelský avatar
mijaja
Tvůrce článků
Level 6.5
Level 6.5
Příspěvky: 4136
Registrován: září 05
Bydliště: Zlín
Pohlaví: Muž
Stav:
Offline
Kontakt:

Příspěvekod mijaja » 13 čer 2006 18:18

No máš co dělat. Musíš si otevřít editor registrů a vymazat tyhle klíče:

HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} = pozústatek MyWebSearchu
HKEY_CLASSES_ROOT\CLSID\{F1FABE79-25FC-46de-8C5A-2C6DB9D64333} = Alexa
HKEY_CLASSES_ROOT\Interface\{0BBB0424-E98E-4405-9A94-481854765C80}\(Default)"="IBubbles" = Alexa
HKEY_CLASSES_ROOT\Interface\{A69107CC-BEC8-4A34-B474-211B0F46A764}\ProxyStubClsid\(Default)"="{00020424-0000-0000-C000-000000000046}"
"HKEY_CLASSES_ROOT\Interface\{B7B84995-8B92-46BF-94AA-FA2F3DD23B84}\(Default)"="IHost"
"HKEY_CLASSES_ROOT\Interface\{3E60160F-0ED6-4DCC-B6B6-850CDE4FD217}\(Default)"="IPopMenu"
HKEY_CLASSES_ROOT\Interface\{FA77AD79-09CF-41FB-B171-CC856F9E737F}\(Default)"="ISystem"
"HKEY_CLASSES_ROOT\Interface\{0F3332B5-BC98-48AF-9FAC-05FEC94EBE73}\(Default)"="IBblWnd"
HKEY_CLASSES_ROOT\TypeLib\{547AB549-4DD8-4ea0-B070-F6EA062148FF} = Alexa
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00ADA225-EA6C-4FB3-82E8-68189201CCB9} = Adware.MediaPass
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\uninstall\alexa toolbar
HKEY_LOCAL_MACHINE\SOFTWARE\alexa internet
HKEY_LOCAL_MACHINE\SOFTWARE\alexa toolbar !!!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\time zones !!!
HKEY_CURRENT_USER\SOFTWARE\microsoft\windows\currentversion\explorer\menuorder\start menu\programs\180search assistant !!!
HKEY_CURRENT_USER\SOFTWARE\microsoft\windows\currentversion\explorer\menuorder\start
menu\programs\toptext ilookup !!!
HKEY_CURRENT_USER\SOFTWARE\microsoft\windows\currentversion\explorer\menuorder\start menu\programs\whenu !!!
HKEY_CURRENT_USER\SOFTWARE\microsoft\windows\currentversion\explorer\menuorder\start menu\programs\whenusearch !!!

Musí všechny pryč.

Potom si nastav v Možnostech složky zobrazování skrytých a systémových souborů a najdi a vymaž všechny tyto soubory:

C:\WINDOWS\ezulains.exe
C:\WINDOWS\gpinstall.exe
C:\WINDOWS\alexaie.dll
C:\WINDOWS\alxie328.dll
C:\WINDOWS\alxtb1.dll
C:\WINDOWS\susp.exe
C:\WINDOWS\zserv.dll
C:\WINDOWS\btgrab.dll
C:\WINDOWS\pynix.dll
C:\WINDOWS\dlmax.dll
C:\WINDOWS\NDNuninstall7_14.exe
C:\WINDOWS\NDNuninstall7_22.exe
C:\WINDOWS\keyboard9.exe
C:\WINDOWS\newname9.exe
C:\WINDOWS\mousepad9.exe
C:\WINDOWS\keyboard18.exe
C:\WINDOWS\defender1.exe
C:\WINDOWS\newname18.exe
C:\WINDOWS\wallpap.exe
C:\WINDOWS\start.exe
C:\WINDOWS\system32\alxres.dll
C:\WINDOWS\system32\ide21201.vxd
C:\WINDOWS\system32\n8l80i3ue8.dll
C:\WINDOWS\system32\dailytoolbar.dll
C:\WINDOWS\system32\tcpservice2.exe
C:\WINDOWS\system32\wstart.dll
C:\WINDOWS\system32\txfdb32.dll
C:\WINDOWS\system32\a.exe
C:\WINDOWS\system32\bridge.dll
C:\WINDOWS\system32\jao.dll
C:\WINDOWS\system32\winapi32.dll
C:\WINDOWS\system32\questmod.dll
C:\WINDOWS\system32\zhopaizdupla.exe
C:\WINDOWS\system32\parad.raw.exe
C:\WINDOWS\system32\taskdir.dll
C:\WINDOWS\system32\taskdir~.exe
C:\WINDOWS\system32\xdpjswkb.exe
C:\WINDOWS\system32\winbl32.dll
C:\WINDOWS\system32\ad.html
C:\WINDOWS\system32\repigsp.exe
C:\WINDOWS\system32\ncompat.tlb
C:\WINDOWS\system32\o7372hhp.ini
C:\WINDOWS\system32\k4080edueh080.dll
C:\WINDOWS\system32\hr0m05d1e.dll
C:\WINDOWS\system32\n8l80i3ue8.dll
C:\WINDOWS\system32\i042laho1d4c.dll
C:\WINDOWS\system32\svcp.csv
C:\WINDOWS\system32\winsub.xml
C:\WINDOWS\system32\zlbw.dll

Měl by sis tohle vytisknout a poznačit si potom, které soubory a klíče jsi nenašel, nebo nešly vymazat. Na ně potom vymyslíme něco jiného.

Uživatelský avatar
Zéla
nováček
Příspěvky: 34
Registrován: červen 06
Bydliště: Chrudim
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

RE

Příspěvekod Zéla » 14 čer 2006 13:58

takze jsem se nezbavil akorat tehlech pajchantu :

C:\WINDOWS\susp.exe

C:\WINDOWS\system32\tcpservice2.exe

C:\WINDOWS\system32\a.exe
doufam ze se ty hajzly ktere jsem vymazal nezkopirovali jinam... nebo tak neco... ale stit u F-Secure antiviru me nic nehlasil... takze by toi melo byt v pohode... tyhle3 se mi nepodarilo vymazat ani prejmenovat... az me poradite jak se zbavit tehlech tak projedu PC SpySweeperem a F-Secure antivirem... doufam ze se konecne zbavim toho blokovani nekterych programu...

Uživatelský avatar
mijaja
Tvůrce článků
Level 6.5
Level 6.5
Příspěvky: 4136
Registrován: září 05
Bydliště: Zlín
Pohlaví: Muž
Stav:
Offline
Kontakt:

Příspěvekod mijaja » 14 čer 2006 15:19

No výborně. Teď si stáhni Killbox a nechej si ho na ploše. Vypni Obnovu systému, aby se ti šmejdi neobnovovali z Obnovy (Dofejme, že tam nejsou už teď zase zpátky). Spusť Killbox a do okénka zkopíruj ty tři řádky (jako celek)

Kód: Vybrat vše

C:\WINDOWS\susp.exe
C:\WINDOWS\system32\tcpservice2.exe
C:\WINDOWS\system32\a.exe



a po volbě Delete On Reboot zmáčkni červený kruh s křížem. Komp půjde do restartu a po něm zkontroluj, jestli tam někde nejsou ještě ti šmejdi. Koukni i po těch, co jsi už předtím vymazal a zkus znovu tu BlackLightBetu.

Uživatelský avatar
Zéla
nováček
Příspěvky: 34
Registrován: červen 06
Bydliště: Chrudim
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

JOOOOOOOOOOOOOOOOO

Příspěvekod Zéla » 14 čer 2006 17:30

KONECNE SEM SE TECH HA*ZLU ZBAVIL!!! TECH CU*AK* CO ME ZAS*A*I Punk Buster!!!! tak ted mam dobrou naladu tak pomuzu vsem co maj taky tenhla problem!!( PB kikuje ze hry se hlaskou inadecuate os privilegies) takze za 1) proctete si toto forum!!
2) Stahnete si hijack this a udelejte log... (navod na tomto foru) poslete ho na forum
3) pouzijte podle navodu na tomto foru program MWAV a odeslete log na forum
4) stahnete programy KillBox (bude potreba pri odstranovani souboru) A take program VX2Finder(126)
5)zbavte se vsech parchantu (instrukce jak na to dostanete po zaslani a po prosbe o kontrolu logu)
6) Stahnete si programy Ccleaner a PCon Point ty nastartujte (nejdrive pouzijte jeden pak druhy... ne najednou..) a pouzijte prislusnym zpusobem... (vycisti vam pc od jineho bordelu )
7) uuuplne na konec po vyreseni vsech problemu s viry,spyware atd. nastartujte VX2Finder(126).exe dejte restore policy a restartujte pc.

Pak uz by hra mnela bez problemu fungovat...

OPAKUJI prectete si pozorne toto forum najdete zde navod na pouziti vsech programu!! (az na navod k PConPoint - na nem neni nic sloziteho... a na navod na VX2Finder(126) ale v bode 7) jsem poskytl veskere info ktere je potreba k funkci tohoto programu...)


Mozna ze je tenhle help trochu nejasnej :D psal sem ho v euforii z toho ze me vse konecne chodi tak jak ma :smile:
klidne me napiste na ICQ a ja vam ho podam srozumitelnejsi formou !!

Uživatelský avatar
Zéla
nováček
Příspěvky: 34
Registrován: červen 06
Bydliště: Chrudim
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Příspěvekod Zéla » 14 čer 2006 17:34

navody na programy potrebne pro tyhle operace ma mijaja napsane cervene vzdy na konci zpravy... NAKOPEJTE VSEM TEM SPYWARE PR*** :D

GL!!!

Uživatelský avatar
Zéla
nováček
Příspěvky: 34
Registrován: červen 06
Bydliště: Chrudim
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Radsi :wink:

Příspěvekod Zéla » 15 čer 2006 14:42

Radeji prikladam zaverecny hijack thiss log a prosim o kontrolu... zaroven bych se chtel zeptat... pripada mi totiz ze me PC bezi pomaleji nez pred vycistenim... je to sice divny ale proste me to tak pripada... kdyby ste nekdo znal nejaky navod jak zrychlit FPS u her tak pls napiste ;)

Logfile of HijackThis v1.99.1
Scan saved at 14:40:05, on 15.6.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\F-Secure\Common\FSMA32.EXE
C:\Program Files\F-Secure\Common\FSMB32.EXE
C:\Program Files\F-Secure\Common\FCH32.EXE
C:\Program Files\F-Secure\Common\FAMEH32.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
D:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
D:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\F-Secure\Common\FNRB32.EXE
C:\Program Files\F-Secure\Common\FSM32.exe
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
C:\Program Files\F-Secure\Common\FIH32.EXE
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gamespot.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fortum.com
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Media Player\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "D:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Shortcut to FSM32.exe.lnk = C:\Program Files\F-Secure\Common\FSM32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: KB KTpro Pack - https://www.mojebanka.cz/jars/kt_pro_v1101.cab
O16 - DPF: KB SH Pack - https://www.mojebanka.cz/jars/sh_pack.cab
O16 - DPF: MIB Pack - https://www.mojebanka.cz/jars/mib_pack_v1400.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
O23 - Service: F-Secure Authentication Agent (FSAA) - F-Secure Corporation. All Rights Reserved. - C:\Program Files\F-Secure\Common\FSAA.EXE
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - D:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

Uživatelský avatar
mijaja
Tvůrce článků
Level 6.5
Level 6.5
Příspěvky: 4136
Registrován: září 05
Bydliště: Zlín
Pohlaví: Muž
Stav:
Offline
Kontakt:

Příspěvekod mijaja » 15 čer 2006 16:26

No bezva. :D

Pokud to chceš trochu zrychlit, tak ještě můžeš povypínat programy, které nemusí jet na pozadí woken a ubírat systémových prostředků:

v nabídce start dej spustit a do okénka napiš msconfig a dej OK. Po naběhnutí tabulky vejdi do karty Po spuštění a zruš zatržítko u procesů:

C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\NeroCheck.exe
D:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime Media Player\qttask.exe" - nic z toho není důležité pro chod kompu.

Potom zavři msconfig a v Hijackthisu ještě fixni tyto řádky:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Media Player\qttask.exe" -atboottime


Jinak udělej si defragmentaci disku a registrů - já na to používám WinAso Registry Optimizer - je dobrý a i v trial verzi je funkční.
Jinak mírná změna rychlosti přichází se změnou softu vždy - jen je otázka jestli do + nebo -
:idea:

Uživatelský avatar
Zéla
nováček
Příspěvky: 34
Registrován: červen 06
Bydliště: Chrudim
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Este jedna malickost...

Příspěvekod Zéla » 16 čer 2006 14:32

este sem se chtel zeptat... hraju na PC hry... v a konkretne Call of Duty 1 a 2 multiplayeru se me stava ze kurzor nechodi tak jak by mel... nejede plynule ale "sekane" po urcitych usecich neda se s tim hrat a stve me to... vada mysi je vyloucena ptz ve windowsech jezdi mys normalne plynule... pomale PC je take vylouceno ptz za a) sem to hral naposled +/- pred mesicem a jelo to v pohode a za b) FPS (frames per second) mam okolo 60... takze fakt nevim... jinak dekuju moc za pomoc s resenim predchoziho problemu...


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 3 hosti