prosim o kontrolu Vyřešeno
Napsal: 02 led 2011 19:50
Logfile of Trend Micro HijackThis
v2.0.4
Scan saved at 19:47:41, on 2.1.2011
Platform: Windows XP SP3 (WinNT
5.01.2600)
MSIE: Internet Explorer v8.00
(8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\inetsrv\inetinfo
.exe
C:\Program
Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program
Files\LogMeIn\x86\RaMaint.exe
C:\Program
Files\LogMeIn\x86\LogMeIn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program
Files\TouchKit\xTouchMon.exe
C:\Program Files\HP\HP Software
Update\HPWuSchd.exe
C:\Program
Files\LogMeIn\x86\LogMeInSystray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program
Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital
Imaging\bin\hpqtra08.exe
C:\Program
Files\RALINK\Common\RaUI.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program
Files\AWIS\AWKasa\bin\mysqld-nt.exe
C:\Program Files\Internet
Explorer\iexplore.exe
C:\Program Files\Internet
Explorer\iexplore.exe
C:\Program Files\Trend
Micro\HiJackThis\HiJackThis.exe
R0 -
HKCU\Software\Microsoft\Internet
Explorer\Main,Start Page =
http://seznam.cz/
R1 -
HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?Link
Id=69157
R1 -
HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?Link
Id=54896
R1 -
HKLM\Software\Microsoft\Internet
Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?Link
Id=54896
R0 -
HKLM\Software\Microsoft\Internet
Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?Link
Id=69157
R0 -
HKCU\Software\Microsoft\Internet
Explorer\Toolbar,LinksFolderName =
Odkazy
R3 - URLSearchHook: (no name) - -
(no file)
O2 - BHO: AcroIEHelperStub -
{18DF081C-E8AD-4283-A596-FA578C2EBDC
3} - C:\Program Files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEHe
lperShim.dll
O4 - HKLM\..\Run: [RTHDCPL]
RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr]
ALCMTR.EXE
O4 - HKLM\..\Run: [xTouchMon]
C:\Program
Files\TouchKit\xTouchMon.exe
O4 - HKLM\..\Run: [HP Software
Update] "C:\Program Files\HP\HP
Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [DXDllRegExe]
dxdllreg.exe
O4 - HKLM\..\Run: [Adobe Reader
Speed Launcher] "C:\Program
Files\Adobe\Reader
9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LogMeIn GUI]
"C:\Program
Files\LogMeIn\x86\LogMeInSystray.exe
"
O4 - HKLM\..\Run: [NvCplDaemon]
RUNDLL32.EXE
C:\WINDOWS\system32\NvCpl.dll,NvStar
tup
O4 - HKLM\..\Run: [NvMediaCenter]
RUNDLL32.EXE
C:\WINDOWS\system32\NvMcTray.dll,NvT
askbarInit
O4 - HKCU\..\Run: [MSMSGS]
"C:\Program
Files\Messenger\msmsgs.exe"
/background
O4 - HKCU\..\Run: [ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run:
[CTFMON.EXE]
C:\WINDOWS\system32\CTFMON.EXE (User
'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run:
[CTFMON.EXE]
C:\WINDOWS\system32\CTFMON.EXE (User
'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run:
[CTFMON.EXE]
C:\WINDOWS\system32\CTFMON.EXE (User
'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run:
[CTFMON.EXE]
C:\WINDOWS\system32\CTFMON.EXE (User
'Default user')
O4 - Global Startup: HP Digital
Imaging Monitor.lnk = C:\Program
Files\HP\Digital
Imaging\bin\hpqtra08.exe
O4 - Global Startup: Ralink Wireless
Utility.lnk = C:\Program
Files\RALINK\Common\RaUI.exe
O9 - Extra button: (no name) -
{e2e2dd38-d088-4134-82b7-f2ba3849658
3} - C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem:
@xpsp3res.dll,-20001 -
{e2e2dd38-d088-4134-82b7-f2ba3849658
3} - C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F79568
3} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows
Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F79568
3} - C:\Program
Files\Messenger\msmsgs.exe
O16 - DPF:
{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC
9} (Performance Viewer Activex
Control) -
https://secure.logmein.com/activex/r
actrl.cab?lmi=100
O22 - SharedTaskScheduler: Browseui
preloader -
{438755C2-A8BA-11D1-B96B-00A0C90312E
1} -
C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces
mezipaměti kategorií součástí -
{8C7461EF-2B13-11d2-BE35-3078302C203
0} -
C:\WINDOWS\system32\browseui.dll
O23 - Service: LMIGuardianSvc -
LogMeIn, Inc. - C:\Program
Files\LogMeIn\x86\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance
Service (LMIMaint) - LogMeIn, Inc. -
C:\Program
Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn,
Inc. - C:\Program
Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: MySQL - Unknown owner
- C:\Program
Files\AWIS\AWKasa\bin\mysqld-nt.exe
O23 - Service: NVIDIA Display Driver
Service (NVSvc) - NVIDIA Corporation
- C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP
- C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 5000 bytes
v2.0.4
Scan saved at 19:47:41, on 2.1.2011
Platform: Windows XP SP3 (WinNT
5.01.2600)
MSIE: Internet Explorer v8.00
(8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\inetsrv\inetinfo
.exe
C:\Program
Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program
Files\LogMeIn\x86\RaMaint.exe
C:\Program
Files\LogMeIn\x86\LogMeIn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program
Files\TouchKit\xTouchMon.exe
C:\Program Files\HP\HP Software
Update\HPWuSchd.exe
C:\Program
Files\LogMeIn\x86\LogMeInSystray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program
Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital
Imaging\bin\hpqtra08.exe
C:\Program
Files\RALINK\Common\RaUI.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program
Files\AWIS\AWKasa\bin\mysqld-nt.exe
C:\Program Files\Internet
Explorer\iexplore.exe
C:\Program Files\Internet
Explorer\iexplore.exe
C:\Program Files\Trend
Micro\HiJackThis\HiJackThis.exe
R0 -
HKCU\Software\Microsoft\Internet
Explorer\Main,Start Page =
http://seznam.cz/
R1 -
HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?Link
Id=69157
R1 -
HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?Link
Id=54896
R1 -
HKLM\Software\Microsoft\Internet
Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?Link
Id=54896
R0 -
HKLM\Software\Microsoft\Internet
Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?Link
Id=69157
R0 -
HKCU\Software\Microsoft\Internet
Explorer\Toolbar,LinksFolderName =
Odkazy
R3 - URLSearchHook: (no name) - -
(no file)
O2 - BHO: AcroIEHelperStub -
{18DF081C-E8AD-4283-A596-FA578C2EBDC
3} - C:\Program Files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEHe
lperShim.dll
O4 - HKLM\..\Run: [RTHDCPL]
RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr]
ALCMTR.EXE
O4 - HKLM\..\Run: [xTouchMon]
C:\Program
Files\TouchKit\xTouchMon.exe
O4 - HKLM\..\Run: [HP Software
Update] "C:\Program Files\HP\HP
Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [DXDllRegExe]
dxdllreg.exe
O4 - HKLM\..\Run: [Adobe Reader
Speed Launcher] "C:\Program
Files\Adobe\Reader
9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LogMeIn GUI]
"C:\Program
Files\LogMeIn\x86\LogMeInSystray.exe
"
O4 - HKLM\..\Run: [NvCplDaemon]
RUNDLL32.EXE
C:\WINDOWS\system32\NvCpl.dll,NvStar
tup
O4 - HKLM\..\Run: [NvMediaCenter]
RUNDLL32.EXE
C:\WINDOWS\system32\NvMcTray.dll,NvT
askbarInit
O4 - HKCU\..\Run: [MSMSGS]
"C:\Program
Files\Messenger\msmsgs.exe"
/background
O4 - HKCU\..\Run: [ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run:
[CTFMON.EXE]
C:\WINDOWS\system32\CTFMON.EXE (User
'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run:
[CTFMON.EXE]
C:\WINDOWS\system32\CTFMON.EXE (User
'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run:
[CTFMON.EXE]
C:\WINDOWS\system32\CTFMON.EXE (User
'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run:
[CTFMON.EXE]
C:\WINDOWS\system32\CTFMON.EXE (User
'Default user')
O4 - Global Startup: HP Digital
Imaging Monitor.lnk = C:\Program
Files\HP\Digital
Imaging\bin\hpqtra08.exe
O4 - Global Startup: Ralink Wireless
Utility.lnk = C:\Program
Files\RALINK\Common\RaUI.exe
O9 - Extra button: (no name) -
{e2e2dd38-d088-4134-82b7-f2ba3849658
3} - C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem:
@xpsp3res.dll,-20001 -
{e2e2dd38-d088-4134-82b7-f2ba3849658
3} - C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F79568
3} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows
Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F79568
3} - C:\Program
Files\Messenger\msmsgs.exe
O16 - DPF:
{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC
9} (Performance Viewer Activex
Control) -
https://secure.logmein.com/activex/r
actrl.cab?lmi=100
O22 - SharedTaskScheduler: Browseui
preloader -
{438755C2-A8BA-11D1-B96B-00A0C90312E
1} -
C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces
mezipaměti kategorií součástí -
{8C7461EF-2B13-11d2-BE35-3078302C203
0} -
C:\WINDOWS\system32\browseui.dll
O23 - Service: LMIGuardianSvc -
LogMeIn, Inc. - C:\Program
Files\LogMeIn\x86\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance
Service (LMIMaint) - LogMeIn, Inc. -
C:\Program
Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn,
Inc. - C:\Program
Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: MySQL - Unknown owner
- C:\Program
Files\AWIS\AWKasa\bin\mysqld-nt.exe
O23 - Service: NVIDIA Display Driver
Service (NVSvc) - NVIDIA Corporation
- C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP
- C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 5000 bytes