Prosím o kontrolu logu (vyřešeno) Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
cervena_karkulka
nováček
Příspěvky: 32
Registrován: leden 08
Bydliště: temný les
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod cervena_karkulka » 10 led 2008 22:13

//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Syntax error in line --- no registry value to delete found. Line will be ignored.
Error code: 0
Line: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msvcc25


Error: could not create zip file.
Error code: 0


//////////////////////////////////////////


Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\jjibbvwb

*******************

Script file located at: \??\C:\qaxuuqna.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\SYSTEM32\rqqss.bak1 deleted successfully.
File C:\WINDOWS\SYSTEM32\rqqss.bak2 deleted successfully.
File C:\WINDOWS\SYSTEM32\xxywu.exe deleted successfully.
File C:\WINDOWS\U29sYXJlbnpvIEFsYW1hbmRyYQ\oZ6PsrL5vBDSKHIPsqY1vAlVsk.vbs deleted successfully.

Completed script processing.

*******************

Finished! Terminate.//////////////////////////////////////////


Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\vbxfenam

*******************

Script file located at: \??\C:\Documents and Settings\jihtrsiv.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



File C:\WINDOWS\SYSTEM32\rqqss.bak1 not found!
Deletion of file C:\WINDOWS\SYSTEM32\rqqss.bak1 failed!

Could not process line:
C:\WINDOWS\SYSTEM32\rqqss.bak1
Status: 0xc0000034



File C:\WINDOWS\SYSTEM32\rqqss.bak2 not found!
Deletion of file C:\WINDOWS\SYSTEM32\rqqss.bak2 failed!

Could not process line:
C:\WINDOWS\SYSTEM32\rqqss.bak2
Status: 0xc0000034



File C:\WINDOWS\SYSTEM32\xxywu.exe not found!
Deletion of file C:\WINDOWS\SYSTEM32\xxywu.exe failed!

Could not process line:
C:\WINDOWS\SYSTEM32\xxywu.exe
Status: 0xc0000034



File C:\WINDOWS\U29sYXJlbnpvIEFsYW1hbmRyYQ\oZ6PsrL5vBDSKHIPsqY1vAlVsk.vbs not found!
Deletion of file C:\WINDOWS\U29sYXJlbnpvIEFsYW1hbmRyYQ\oZ6PsrL5vBDSKHIPsqY1vAlVsk.vbs failed!

Could not process line:
C:\WINDOWS\U29sYXJlbnpvIEFsYW1hbmRyYQ\oZ6PsrL5vBDSKHIPsqY1vAlVsk.vbs
Status: 0xc0000034


Completed script processing.

*******************

Finished! Terminate.

Reklama
Uživatelský avatar
cervena_karkulka
nováček
Příspěvky: 32
Registrován: leden 08
Bydliště: temný les
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod cervena_karkulka » 10 led 2008 22:15

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:05:46, on 10.1.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\Norton Utilities\NPROTECT.EXE
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\HijackThis\HiJackThis.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -s
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Win Tasks 32] wintasks32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Win Tasks 32] wintasks32.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O17 - HKLM\System\CCS\Services\Tcpip\..\{054F7896-4A97-4218-8162-8AE648B6DD6A}: NameServer = 160.218.10.200 160.218.43.200
O17 - HKLM\System\CCS\Services\Tcpip\..\{A15320C6-6B30-4996-A975-35FD184491C7}: NameServer = 192.168.1.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{054F7896-4A97-4218-8162-8AE648B6DD6A}: NameServer = 160.218.10.200 160.218.43.200
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton Utilities\NPROTECT.EXE
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 3915 bytes

Uživatelský avatar
Baron Prášil
Master Level 7
Master Level 7
Příspěvky: 4882
Registrován: červen 06
Pohlaví: Muž
Stav:
Offline

Příspěvekod Baron Prášil » 11 led 2008 14:45

tak fixni ještě toto
O4 - HKUS\S-1-5-18\..\Run: [Win Tasks 32] wintasks32.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Win Tasks 32] wintasks32.exe (User 'Default user')

stáhni si killbox ObrázekObrázek
rozbal,spust a do okýnka zkopíruj tučné
C:\WINDOWS\system32\wintasks32.exe
zaškrtni Delete on Reboot a klikni na křížek.stroj pude do restartu.po něm ještě jeden hijackthis,pls

Uživatelský avatar
cervena_karkulka
nováček
Příspěvky: 32
Registrován: leden 08
Bydliště: temný les
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod cervena_karkulka » 12 led 2008 12:04

Provedeno, zasílám log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:32:47, on 12.1.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\Norton Utilities\NPROTECT.EXE
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -s
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O17 - HKLM\System\CCS\Services\Tcpip\..\{054F7896-4A97-4218-8162-8AE648B6DD6A}: NameServer = 160.218.10.200 160.218.43.200
O17 - HKLM\System\CCS\Services\Tcpip\..\{A15320C6-6B30-4996-A975-35FD184491C7}: NameServer = 192.168.1.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{054F7896-4A97-4218-8162-8AE648B6DD6A}: NameServer = 160.218.10.200 160.218.43.200
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton Utilities\NPROTECT.EXE
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 3604 bytes

Uživatelský avatar
Baron Prášil
Master Level 7
Master Level 7
Příspěvky: 4882
Registrován: červen 06
Pohlaví: Muž
Stav:
Offline

Příspěvekod Baron Prášil » 12 led 2008 15:55

log je v pořádku.co komp?

Uživatelský avatar
cervena_karkulka
nováček
Příspěvky: 32
Registrován: leden 08
Bydliště: temný les
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod cervena_karkulka » 13 led 2008 10:01

Sart Windowsů je poněkud zdlouhavý, ale to je v pořádku - je to dáno nevhodným OS vzhledem k hardwarové kapacitě...

Samotný chod počítače se značně zrychlil. Myslím, že vše je ok :)

Velmi Vám děkuji za Vaší pomoc a čaš.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 1 host