kontrola logu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Baron Prášil
Master Level 7
Master Level 7
Příspěvky: 4882
Registrován: červen 06
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod Baron Prášil » 24 bře 2008 12:51

no,to je právě to! :D když klikneš na tento podtržený nápis nouzový režim ,tak se to dovíš.

Reklama
Jan John
Level 1
Level 1
Příspěvky: 57
Registrován: únor 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: kontrola logu

Příspěvekod Jan John » 24 bře 2008 13:15

Už jsem si to našel v návodu na netu, nechce se mi nouzový režim spustit ,dal jsem možnost jen Safe mode a i Safe mode with network a přes obrazovku vyjede spoustu řádků ,co se spouští a pak se to sekne.
Combo fix ,když zapnu ,jako by se chtělo otevřít nějaké okno,které se hned v zápětí vypne. I když vypnu firewall a vše jiné.

Uživatelský avatar
Baron Prášil
Master Level 7
Master Level 7
Příspěvky: 4882
Registrován: červen 06
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod Baron Prášil » 24 bře 2008 13:21

Stáhni si SUPERAntiSpyware
Nainstaluj a spusť ho a klikni na tlačítko Check for Updates...
Po provedení Update klikni na tlačítko: Scan your computer
Zvol možnost: Perform Complete Scan a klikni na tlačítko Další >

Proběhne kontrola, po skončení vypíše vše co našel. a vše dej smazat

a pošli info

Jan John
Level 1
Level 1
Příspěvky: 57
Registrován: únor 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: kontrola logu

Příspěvekod Jan John » 25 bře 2008 02:11

takže jsem stáhnul super spyware ,psal si ať si ho stáhnu,nevím proč to tady není už zobrazené.
šlo o to ,že jsem měl vyjet log z combo fix,jen se otevíra jakoby okno a vzápětí se hned zavře.Nevím jak ho spustit a nouzový režim se mi sekne při spuštění.
pvytvoří na C:\Combofix s většinnou batových souborů.
SuperAntiSpyware našel a vymazal dva trojský koně a jeden Adware -Foto.Moto.gen
Jak spustím Combo fix? Abych se nějak posunul dále?

Jan John
Level 1
Level 1
Příspěvky: 57
Registrován: únor 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: kontrola logu

Příspěvekod Jan John » 25 bře 2008 02:55

Nouzový režim už se spustí,ale po zadání hesla do windows se okamžitě restartuje do normálního režimu.
Nevím co s tím ,asi už bych nejradši reinstaloval Windows,ale nevím jak.Po koupi noťase se instalovo vše komplet z harddisku.Nemám instalační cd,bylo jen na antivir.
Lze tedy nějak problémy vyřešit,když mě nic nejde? Možná Combo chce spustit jen z plochy? Ale z plochy mi nejde spustit nic.Jeden z problémů uvedených výše.

Uživatelský avatar
Baron Prášil
Master Level 7
Master Level 7
Příspěvky: 4882
Registrován: červen 06
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod Baron Prášil » 25 bře 2008 08:35

zkus na opravu plochy použít nnncleaner http://down.ne-e.eu/nnncleaner.exe
spust,klik na nástroje a opravit plochu

combfix se spouští s plochy.po akci s nnncleanerem ho opět zkus

Jan John
Level 1
Level 1
Příspěvky: 57
Registrován: únor 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: kontrola logu

Příspěvekod Jan John » 29 bře 2008 05:39

combo fix už jde a to ,protože jsem si založil nový účet windows a starý vymazal,nebo ,že jsem ho přejmenoval z combofix(1) na combofix.


Running from: C:\Documents and Settings\Administrator ja\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\regedit.com
C:\WINDOWS\system32\f3PSSavr.scr
C:\WINDOWS\system32\pskill.exe
C:\WINDOWS\system32\taskmgr.com

.
((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-29 )))))))))))))))))))))))))))))))
.

2008-03-29 04:01 . 2008-03-29 04:01 <DIR> d-a------ C:\WINDOWS\zts2.exe
2008-03-29 04:01 . 2008-03-29 04:01 <DIR> d-a------ C:\WINDOWS\system32\vcmgcd32.dll
2008-03-29 04:01 . 2008-03-29 04:01 <DIR> d-a------ C:\WINDOWS\system32\iifgfgf.dll
2008-03-29 04:01 . 2008-03-29 04:01 <DIR> d-a------ C:\WINDOWS\rundll16.exe
2008-03-29 04:01 . 2008-03-29 04:01 <DIR> d-a------ C:\WINDOWS\rundl132.dll
2008-03-29 04:01 . 2008-03-29 04:01 <DIR> d-a------ C:\WINDOWS\logo1_.exe
2008-03-29 04:00 . 2004-08-10 20:00 224,256 --a------ C:\WINDOWS\R.COM
2008-03-29 04:00 . 2004-08-10 20:00 221,184 --a------ C:\WINDOWS\system32\T.COM
2008-03-29 04:00 . 2008-03-29 04:01 50 --a------ C:\WINDOWS\Lic.xxx
2008-03-29 03:48 . 2008-03-29 03:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-03-29 03:38 . 2008-03-29 03:38 <DIR> d-------- C:\Program Files\CCleaner
2008-03-28 12:03 . 2008-03-28 12:03 <DIR> d--hs---- C:\FOUND.003
2008-03-28 02:24 . 2008-03-28 02:24 <DIR> d-------- C:\ComboFix(1)
2008-03-28 01:58 . 2008-03-28 01:58 <DIR> d-------- C:\Documents and Settings\Administrator ja\Application Data\ViStart
2008-03-28 01:55 . 2008-03-28 01:55 <DIR> d-------- C:\WINDOWS\system32\VIRepair
2008-03-28 01:55 . 2008-03-28 01:55 <DIR> d-------- C:\Program Files\WinFlip
2008-03-28 01:55 . 2008-03-28 01:55 <DIR> d-------- C:\Program Files\VisualTooltip
2008-03-28 01:55 . 2008-03-28 01:55 <DIR> d-------- C:\Program Files\ViStart
2008-03-28 01:55 . 2008-03-28 01:55 <DIR> d-------- C:\Program Files\ViOrb
2008-03-28 01:55 . 2008-03-28 01:55 <DIR> d-------- C:\Program Files\TrueTransparency
2008-03-28 01:55 . 2008-03-28 01:55 <DIR> d-------- C:\Documents and Settings\Administrator ja\Application Data\Styler
2008-03-28 01:55 . 2007-11-30 05:56 329,029 --a------ C:\WINDOWS\system32\viwc.exe
2008-03-28 01:54 . 2008-03-28 01:54 <DIR> d-------- C:\Program Files\Vista Sidebar
2008-03-28 01:54 . 2008-03-28 01:55 <DIR> d-------- C:\Program Files\Styler
2008-03-28 01:54 . 2008-03-28 01:54 <DIR> d-------- C:\Program Files\LClock
2008-03-28 01:54 . 2007-04-15 01:32 7,333,376 --a------ C:\WINDOWS\system32\vistaui.exe
2008-03-28 01:54 . 2006-12-11 01:15 498,176 --a------ C:\WINDOWS\system32\logon.scr
2008-03-28 01:54 . 2004-09-20 01:27 172,032 --a------ C:\WINDOWS\system32\LClock.cpl
2008-03-28 01:54 . 2007-11-25 22:11 49,208 --a------ C:\WINDOWS\system32\vistartup.bmp
2008-03-28 01:47 . 2008-03-28 01:47 <DIR> d-------- C:\WINDOWS\system32\VITrans
2008-03-28 01:47 . 2008-03-28 01:47 <DIR> d-------- C:\VTPFiles
2008-03-28 01:47 . 2006-12-03 17:15 111,104 --a------ C:\WINDOWS\system32\Uharc.exe
2008-03-28 01:47 . 2008-03-28 01:47 78,942 --a------ C:\WINDOWS\Icon_1.ico
2008-03-28 01:47 . 2006-12-03 17:15 19,968 --a------ C:\WINDOWS\system32\reico.exe
2008-03-28 01:47 . 2006-12-03 17:14 8,636 --a------ C:\WINDOWS\system32\modifype.exe
2008-03-28 00:56 . 2008-03-28 00:56 <DIR> d-------- C:\WINDOWS\Performance
2008-03-28 00:54 . 2008-03-28 00:54 <DIR> d-------- C:\Program Files\Microsoft Windows Vista Upgrade Advisor
2008-03-28 00:54 . 2008-03-28 00:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Corporation
2008-03-27 11:04 . 2008-03-27 11:04 <DIR> d--hs---- C:\FOUND.002
2008-03-27 01:58 . 2008-03-27 01:58 <DIR> d-------- C:\Documents and Settings\Administrator ja\Application Data\SUPERAntiSpyware.com
2008-03-27 01:45 . 2008-03-27 01:45 <DIR> d-------- C:\Documents and Settings\Vopice\Application Data\TuneUp Software
2008-03-27 01:32 . 2008-03-27 01:32 <DIR> d-------- C:\Documents and Settings\Administrator ja\Application Data\uTorrent
2008-03-27 00:38 . 2008-03-27 00:38 <DIR> d-------- C:\Documents and Settings\Administrator ja\Application Data\Webshots
2008-03-26 02:24 . 2008-03-26 02:24 <DIR> d-------- C:\Documents and Settings\Vopice\Application Data\Apple Computer
2008-03-26 01:48 . 2008-03-26 01:48 <DIR> d-------- C:\Documents and Settings\Vopice\Application Data\OpenOffice.org2
2008-03-26 01:43 . 2008-03-26 01:43 <DIR> d-------- C:\Documents and Settings\Vopice\Application Data\ESTSoft
2008-03-26 01:38 . 2008-03-26 01:38 <DIR> d-------- C:\Documents and Settings\Vopice\Application Data\SUPERAntiSpyware.com
2008-03-26 01:05 . 2008-03-26 01:05 <DIR> d-------- C:\Documents and Settings\Vopice\Application Data\skypePM
2008-03-26 01:03 . 2008-03-26 01:03 <DIR> d-------- C:\Documents and Settings\Vopice\Application Data\Skype
2008-03-26 00:58 . 2008-03-26 00:58 <DIR> d-------- C:\Documents and Settings\Vopice\Application Data\ICQ
2008-03-26 00:36 . 2008-03-26 00:36 <DIR> d-------- C:\Documents and Settings\Vopice\Application Data\Yahoo!
2008-03-26 00:36 . 2008-03-26 00:36 <DIR> d-------- C:\Documents and Settings\Vopice\Application Data\ICQ Toolbar
2008-03-26 00:19 . 2008-03-26 00:19 <DIR> d-------- C:\Documents and Settings\Vopice\Application Data\Winamp
2008-03-26 00:18 . 2008-03-26 00:18 <DIR> d-------- C:\Documents and Settings\Vopice\Application Data\Spyware Terminator
2008-03-26 00:18 . 2008-03-26 00:18 <DIR> d-------- C:\Documents and Settings\Vopice\Application Data\Comodo
2008-03-26 00:00 . 2008-03-26 00:00 <DIR> d-------- C:\Program Files\ESTsoft
2008-03-26 00:00 . 2008-03-26 00:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESTsoft
2008-03-26 00:00 . 2008-03-26 00:00 <DIR> d-------- C:\Documents and Settings\Administrator ja\Application Data\ESTSoft
2008-03-25 23:59 . 2008-03-25 23:59 8,659,652 --a------ C:\Documents and Settings\UTILITY\ALSong.exe
2008-03-25 23:44 . 2008-03-25 23:44 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\yahoo!
2008-03-25 23:43 . 2008-03-11 19:10 2,187,392 --a------ C:\ytb_7.1.2.0_1.5.1_ysp_1.2_bts_pub_us_setup_.exe
2008-03-25 23:34 . 2008-03-25 23:34 <DIR> d-------- C:\Documents and Settings\Administrator ja\Application Data\OpenOffice.org2
2008-03-25 23:11 . 2008-03-25 23:11 <DIR> d-------- C:\Documents and Settings\Administrator ja\Application Data\LimeWire
2008-03-25 22:55 . 2008-03-25 22:55 <DIR> d-------- C:\Documents and Settings\Administrator ja\Application Data\Winamp
2008-03-25 22:49 . 2008-03-25 22:49 <DIR> d-------- C:\Documents and Settings\Administrator ja\Application Data\skypePM
2008-03-25 22:48 . 2008-03-25 22:48 <DIR> d-------- C:\Documents and Settings\Administrator ja\Application Data\Skype
2008-03-25 22:41 . 2008-03-25 22:41 <DIR> d-------- C:\Documents and Settings\Administrator ja\Application Data\TuneUp Software
2008-03-25 02:51 . 2008-03-25 02:51 <DIR> d-------- C:\Documents and Settings\Administrator ja\Application Data\Yahoo!
2008-03-25 02:51 . 2008-03-25 02:51 <DIR> d-------- C:\Documents and Settings\Administrator ja\Application Data\ICQ Toolbar
2008-03-25 02:36 . 2008-03-25 02:36 <DIR> d-------- C:\Documents and Settings\Administrator ja\Application Data\Spyware Terminator
2008-03-25 02:36 . 2008-03-25 02:36 <DIR> d-------- C:\Documents and Settings\Administrator ja\Application Data\Comodo
2008-03-25 02:36 . 2008-03-25 02:36 <DIR> d-------- C:\Documents and Settings\Administrator ja\Application Data\ATI
2008-03-24 23:39 . 2008-03-24 23:39 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-03-24 23:39 . 2008-03-24 23:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-24 11:55 . 2008-03-24 11:55 <DIR> d--hs---- C:\FOUND.001
2008-03-24 00:39 . 2005-07-20 09:34 264,875 --a------ C:\sfp.zip
2008-03-23 13:44 . 2008-03-23 13:44 <DIR> d-------- C:\Program Files\Spyware Terminator
2008-03-23 13:44 . 2008-03-23 13:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-03-23 13:44 . 2008-03-23 13:44 138,752 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-03-23 02:35 . 2008-03-23 02:35 <DIR> d-------- C:\Program Files\ICQToolbar
2008-03-23 02:34 . 2008-03-23 02:34 <DIR> d-------- C:\Program Files\ICQ6
2008-03-23 02:25 . 2008-03-23 02:25 <DIR> d-------- C:\Documents and Settings\ICQ\478096090
2008-03-22 21:38 . 2008-03-22 21:38 <DIR> d-------- C:\Program Files\Webshots
2008-03-22 21:38 . 2008-03-22 21:38 <DIR> d-------- C:\Documents and Settings\Webshots Data\album-10000
2008-03-22 21:36 . 2007-11-05 20:58 6,391,520 --a------ C:\wbsamp5.exe
2008-03-22 16:51 . 2008-03-22 16:51 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-03-22 16:38 . 2007-07-09 14:16 582,656 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-03-22 15:50 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-03-22 15:48 . 2007-12-05 06:09 749,608 --a------ C:\WindowsXP-KB943055-x86-CSY.exe
2008-03-22 15:47 . 2006-10-30 19:41 2,345,272 --a------ C:\WindowsXP-KB896256-v4-x86-CSY.exe
2008-03-22 02:33 . 2008-03-22 02:33 <DIR> d-------- C:\Documents and Settings\UTILITY\mobil
2008-03-22 01:28 . 2005-04-15 19:58 1,071,088 --a------ C:\WINDOWS\system32\MSCOMCTL.OCX
2008-03-22 01:28 . 2004-03-09 16:45 662,288 --a------ C:\WINDOWS\system32\MSCOMCT2.OCX
2008-03-22 00:14 . 2006-10-05 14:30 51,374 --a------ C:\intel33.mp3
2008-03-22 00:14 . 2006-06-24 15:28 7,391 --a------ C:\Birds sing.mp3
2008-03-22 00:13 . 2006-06-24 15:29 78,573 --a------ C:\Frogs.mp3
2008-03-21 21:23 . 2008-03-20 07:45 9,185 --a------ C:\11129769.html.gz
2008-03-21 21:23 . 2008-03-20 07:50 5,298 --a------ C:\11082436.html.gz
2008-03-21 19:21 . 2008-03-21 19:22 <DIR> d-------- C:\Program Files\Common Files\ACD Systems
2008-03-21 19:18 . 2007-11-26 17:54 35,574,848 --a------ C:\acdsee-10-0-238-en.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-28 17:06 --------- d-----w C:\Program Files\Xi
2008-02-28 01:29 5,990 ----a-w C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
2008-02-28 01:29 --------- d-----w C:\Program Files\Support Tools
2008-02-27 23:15 2,155,208 ----a-w C:\Documents and Settings\UTILITY\tcmd702a.exe
2008-02-27 16:26 --------- d-----w C:\Program Files\ICQLite
2008-02-27 13:09 --------- d-----w C:\Program Files\Reference Assemblies
2008-02-26 21:25 --------- d-----w C:\Program Files\Counter-Strike 1.6 Patch Version 26
2008-02-26 19:35 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-02-26 19:35 --------- d-----w C:\Program Files\Hamachi
2008-02-26 17:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-26 14:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-02-25 22:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-02-25 22:21 2,124,600 ----a-w C:\Documents and Settings\UTILITY\WindowsXP-KB917425-x86-CSY.exe
2008-02-25 22:05 881,192 ----a-w C:\Documents and Settings\UTILITY\WGAPluginInstall.exe
2008-02-25 20:55 --------- d-----w C:\Program Files\Winamp
2008-02-25 14:33 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2008-02-25 11:40 --------- d-----w C:\Program Files\iColorFolder
2008-02-24 23:46 --------- d-----w C:\Program Files\ElcomSoft
2008-02-24 01:42 --------- d-----w C:\Program Files\Activision
2008-02-24 01:30 53,339 ----a-w C:\Documents and Settings\UTILITY\DAPCtxMenuShell.dll
2008-02-24 01:30 50,688 ----a-w C:\WINDOWS\system32\wbhelp2.dll
2008-02-24 00:41 --------- d-----w C:\Program Files\Microsoft Visual Studio .NET 2003
2008-02-24 00:41 --------- d-----w C:\Program Files\Halpsoft
2008-02-23 16:30 --------- d-----w C:\Program Files\Common Files\xing shared
2008-02-23 16:29 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-02-23 16:29 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-02-21 23:24 --------- d-----w C:\Program Files\EasyLanguage
2008-02-21 20:03 --------- d-----w C:\Program Files\iredsoft
2008-02-21 18:22 --------- d-----w C:\Program Files\Microton 2006
2008-02-20 14:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Rising
2008-02-19 22:14 23,859,824 ----a-w C:\Documents and Settings\UTILITY\mpcstar_setup.exe
2008-02-19 22:14 --------- d-----w C:\Program Files\MpcStar
2008-02-18 18:58 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-02-18 18:54 --------- d---a-w C:\Program Files\Skype
2008-02-18 18:54 --------- d---a-w C:\Program Files\Common Files\Skype
2008-02-18 18:54 --------- d---a-w C:\Documents and Settings\All Users\Application Data\Skype
2008-02-18 16:30 1,430,115 ----a-w C:\Documents and Settings\UTILITY\K800i-java-R1GB001.zip
2008-02-18 10:17 951,793 ----a-w C:\Documents and Settings\UTILITY\nastavenisite.zip
2008-02-18 09:59 --------- d---a-w C:\Program Files\Snow for Windows
2008-02-17 23:11 --------- d---a-w C:\Program Files\TSw
2008-02-17 23:10 586,991 ----a-w C:\Documents and Settings\UTILITY\SMTPTrackerSetup.zip
2008-02-17 22:52 --------- d---a-w C:\Documents and Settings\All Users\Application Data\NETGATE
2008-02-17 22:51 27,162,976 ----a-w C:\Documents and Settings\UTILITY\se-setup.exe
2008-02-17 22:44 4,012,245 ----a-w C:\Documents and Settings\UTILITY\ntkernelfw_trial.zip
2008-02-17 22:25 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2008-02-17 21:29 --------- d---a-w C:\Program Files\Common Files\Softwin
2008-02-17 19:27 --------- d---a-w C:\Program Files\Rising
2008-02-17 17:39 --------- d---a-w C:\Program Files\Common Files\GeoVid
2008-02-17 17:38 --------- d---a-w C:\Program Files\GeoVid
2008-02-17 17:37 20,931,928 ----a-w C:\Documents and Settings\UTILITY\presentation-to-video.exe
2008-02-17 17:10 12,271,552 ----a-w C:\Documents and Settings\UTILITY\stop-sign_install.exe
2008-02-17 17:03 20 ---ha-w C:\sccfg.sys
2008-02-17 16:59 --------- d---a-w C:\Program Files\MSECache
2008-02-17 16:15 13,614,008 ----a-w C:\Documents and Settings\UTILITY\AdbeRdr602_cze.exe
2008-02-17 15:17 693,991 ----a-w C:\Documents and Settings\UTILITY\Vyladte_si_Win_XP.zip
2008-02-17 13:59 2,825,712 ----a-w C:\Documents and Settings\UTILITY\setupxv.exe
2008-02-17 13:55 481,696 ----a-w C:\Documents and Settings\UTILITY\realarcade_r1home_stub.exe
2008-02-17 13:53 739,240 ----a-w C:\Documents and Settings\UTILITY\vnc-4_1_2-x86_win32.exe
2008-02-16 22:26 1,997,611 ----a-w C:\Documents and Settings\UTILITY\CDex.zip
2008-02-16 22:11 299,774 ----a-w C:\Documents and Settings\UTILITY\wordmaster-setup.exe
2008-02-16 11:02 --------- d---a-w C:\Program Files\Moje slovíčka
2008-02-16 10:59 --------- d---a-w C:\Program Files\Nepravidelná slovesa 3
2008-02-15 20:42 860,094 ----a-w C:\Documents and Settings\UTILITY\pack.zip
2008-02-15 19:21 --------- d---a-w C:\Documents and Settings\All Users\Application Data\Azureus
2008-02-15 19:15 --------- d-----w C:\Program Files\Azureus
2008-02-15 17:59 40,314 ----a-w C:\Documents and Settings\UTILITY\elt_englishexpress.zip
2008-02-12 22:45 --------- d---a-w C:\Program Files\Sony Ericsson
2008-02-12 22:44 6,099,513 ----a-w C:\Documents and Settings\UTILITY\themes_creator_3.17.zip
2008-02-12 22:42 39,703,430 ----a-w C:\Documents and Settings\UTILITY\pcsuite.zip
2008-02-12 22:41 3,015,753 ----a-w C:\Documents and Settings\UTILITY\audacity.zip
2008-02-12 22:33 --------- d---a-w C:\Program Files\MyPhoneExplorer
2008-02-12 20:04 --------- d---a-w C:\Program Files\Real
2008-02-12 20:04 --------- d---a-w C:\Program Files\Common Files\Real
2008-02-07 19:46 831,160 ----a-w C:\Documents and Settings\UTILITY\SMInstall.exe
2008-02-06 21:25 715,248 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-02-06 20:26 --------- d---a-w C:\Program Files\Hide Folders XP 2
2008-02-06 20:01 --------- d---a-w C:\Program Files\Common Files\NacreWare
2008-02-06 20:01 --------- d---a-w C:\Program Files\AMC2000
2008-02-06 12:05 --------- d---a-w C:\Program Files\Windows Media Connect 2
2008-02-06 11:48 --------- d---a-w C:\Program Files\QuickTime
2008-02-06 11:48 --------- d---a-w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-06 11:19 --------- d---a-w C:\Program Files\Common Files\Adobe
2008-02-06 07:59 86,400 ----a-w C:\WINDOWS\~GLC0000.TMP
2008-02-04 17:09 --------- d---a-w C:\Program Files\ICQToolbar(2)
2008-02-01 15:47 --------- d---a-w C:\Documents and Settings\All Users\Application Data\Avira
2008-02-01 15:40 --------- d---a-w C:\Program Files\Netscape
2008-02-01 14:46 --------- d---a-w C:\Program Files\IObit
2008-01-11 05:53 44,544 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-01-04 21:58 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2008-01-04 21:58 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2008-01-04 21:58 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2008-01-04 21:56 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-08-04 22:28 34,304 ----a-w C:\Documents and Settings\UTILITY\myuninst.exe
2006-12-23 17:21 251 ----a-w C:\Program Files\wt3d.ini
.

------- Sigcheck -------

2007-02-28 09:38 2027008 381ebd2c9520884f4a391f79f756bda6 C:\WINDOWS\system32\ntkrnlpa.exe
2007-02-28 09:38 2057600 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2007-02-28 09:38 2015744 a58ac1c6199ef34228abee7fc057ae09 C:\WINDOWS\system32\VITrans\ntkrnlpa.exe
2005-03-02 01:34 2056832 81013f36b21c7f72cf784cc6731e0002 C:\WINDOWS\SoftwareDistribution\Download\dc3b8fb011c281dea1cb7a45f880da78\sp2gdr\ntkrnlpa.exe
2005-03-02 01:36 2056832 d8aba3eab509627e707a3b14f00fbb6b C:\WINDOWS\SoftwareDistribution\Download\dc3b8fb011c281dea1cb7a45f880da78\sp2qfe\ntkrnlpa.exe
2007-02-28 09:38 2057600 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\SoftwareDistribution\Download\10e16e65c532d077de7c89a212bd8df8\sp2gdr\ntkrnlpa.exe
2007-02-28 10:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\SoftwareDistribution\Download\10e16e65c532d077de7c89a212bd8df8\sp2qfe\ntkrnlpa.exe
2005-03-02 01:36 2056832 d8aba3eab509627e707a3b14f00fbb6b C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2007-02-28 10:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2004-08-10 20:00 2015232 fb142b7007ca2eea76966c6c5cc12150 C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
2005-03-02 01:34 2015232 3cd941e472ddf3534e53038535719771 C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe

2007-02-28 10:08 2147328 2f97c59526b48d414ee3938b6625f65d C:\WINDOWS\system32\ntoskrnl.exe
2007-02-28 10:10 2180352 582a8dbaa58c3b1f176eb2817daee77c C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2007-02-28 10:08 2136064 1220faf071dea8653ee21de7dcda8bfd C:\WINDOWS\system32\VITrans\ntoskrnl.exe
2005-03-02 01:59 2179328 4d4cf2c14550a4b7718e94a6e581856e C:\WINDOWS\SoftwareDistribution\Download\dc3b8fb011c281dea1cb7a45f880da78\sp2gdr\ntoskrnl.exe
2005-03-02 02:04 2179456 28187802b7c368c0d3aef7d4c382aabb C:\WINDOWS\SoftwareDistribution\Download\dc3b8fb011c281dea1cb7a45f880da78\sp2qfe\ntoskrnl.exe
2007-02-28 10:10 2180352 582a8dbaa58c3b1f176eb2817daee77c C:\WINDOWS\SoftwareDistribution\Download\10e16e65c532d077de7c89a212bd8df8\sp2gdr\ntoskrnl.exe
2007-02-28 10:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\SoftwareDistribution\Download\10e16e65c532d077de7c89a212bd8df8\sp2qfe\ntoskrnl.exe
2005-03-02 02:04 2179456 28187802b7c368c0d3aef7d4c382aabb C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2007-02-28 10:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2004-08-10 20:00 2148352 626309040459c3915997ef98ec1c8d40 C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe
2005-03-02 01:57 2135552 48b3e89af7074cee0314a3e0c7faffdb C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe

2007-06-13 11:23 1423360 e4368d08c22012b357bef3ba239ac667 C:\WINDOWS\explorer.exe
2007-06-13 11:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 11:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\system32\VITrans\explorer.exe
2007-06-13 11:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2gdr\explorer.exe
2007-06-13 12:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2qfe\explorer.exe
2007-06-13 12:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-10 20:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{994B5FB4-0103-44A6-B6B3-C73572B362BC}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AF7E9EBB-E1CF-7F7C-C608-13185698F3E9}]
2007-12-30 21:48 1019904 --a------ C:\Program Files\InternetSoftware\InternetSoftware-2.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 20:00 15360]
"ViStart"="C:\Program Files\ViStart\ViStart.exe" [2007-11-26 19:27 593920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2008-03-20 12:26 1115728]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-03-21 00:24 249896]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-03-23 13:44 2957824]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 20:00 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 1 (0x1)
"NoStartMenuEjectPC"= 0 (0x0)
"NoResolveSearch"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=sockspy.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ViOrb"=C:\Program Files\ViOrb\ViOrb.exe
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
"LClock"=C:\Program Files\LClock\LClock.exe
"Internet Explorer"=C:\Program Files\Internet Explorer\iexplore.exe
"Vista Sidebar"=C:\Program Files\Vista Sidebar\sidebar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Alcmtr"=ALCMTR.EXE
"SkyTel"=SkyTel.EXE
"Tweak UI"=RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
"RTHDCPL"=RTHDCPL.EXE
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"eRecoveryService"=C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
"Synchronization Manager"=%SystemRoot%\system32\mobsync.exe /logon
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"Boot"=C:\Acer\Empowering Technology\ePower\Boot.exe
"Acer ePresentation HPD"=C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"ePower_DMC"=C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
"WinampAgent"="C:\Program Files\Winamp\winampa.exe"
"PostSetupCheck"=C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\cpmsky.dll" DllStart

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

R1 cpuidlep;CpuIdle Pro System Driver;C:\WINDOWS\system32\drivers\cpuidlep.sys [2008-03-03 01:42]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-03-23 13:44]
R2 AntiVirScheduler;AntiVir PersonalEdition Classic Scheduler;"C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe" [2007-08-28 13:16]
R2 dvdmmg;dvdmmg;C:\WINDOWS\system32\drivers\dvdmmg.sys [2007-09-06 12:15]
R2 Ethpdrv;Ethernet Packet Driver;C:\WINDOWS\system32\DRIVERS\ethpdrv.sys [2005-09-08 02:18]
R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [2004-08-10 20:00]
R3 NWRDR;NetWare Rdr;C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2006-10-13 11:23]
R3 PSched;QoS Packet Scheduler;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-10 20:00]
S0 ElbyVCD;ElbyVCD;C:\WINDOWS\system32\DRIVERS\ElbyVCD.sys []
S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;C:\WINDOWS\system32\eLock2BurnerLockDriver.sys []
S2 eLock2FSCTLDriver;eLock2FSCTLDriver;C:\WINDOWS\system32\eLock2FSCTLDriver.sys []
S3 IpwP;IPWireless 3G PCMCIA Network Adapter;C:\WINDOWS\system32\DRIVERS\ipwpnet.sys [2005-07-30 12:29]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

.
Contents of the 'Scheduled Tasks' folder
"2008-03-29 00:17:36 C:\WINDOWS\Tasks\{F897AA24-BDC3-11D1-B85B-00C04FB93981}_ACER_Jannis.job"
- C:\WINDOWS\system32\mobsync.exe@ /Schedule=
"2008-02-26 15:16:42 C:\WINDOWS\Tasks\Low Battery Alarm Program.job"
"2008-02-26 15:17:14 C:\WINDOWS\Tasks\Critical Battery Alarm Program.job"
"2008-03-06 00:10:08 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-03-26 00:10:02 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-03-18 11:13:32 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2006\SystemOptimizer.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-29 04:19:24
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASFWHide]
"ImagePath"="\??\C:\DOCUME~1\Jannis\LOCALS~1\Temp\ASFWHide"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\ViStart\MainHook.Dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
c:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-03-29 4:21:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-29 03:21:30
.
2007-07-16 01:00:20 --- E O F ---

Uživatelský avatar
Baron Prášil
Master Level 7
Master Level 7
Příspěvky: 4882
Registrován: červen 06
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu

Příspěvekod Baron Prášil » 29 bře 2008 11:26

nic tam nevidím,krom mnoha pokusů o změnu xp na visty. a myslim,že si si tim rozkopal systém.

Jan John
Level 1
Level 1
Příspěvky: 57
Registrován: únor 08
Pohlaví: Nespecifikováno
Stav:
Offline

Re: kontrola logu

Příspěvekod Jan John » 29 bře 2008 14:14

Rozkopal system v jakym smyslu?Snad se to dá odinstalovat.
Abych se přiznal už je vše vpohodě. Co se týče plochy,sekání atd.Buď to byly šmejdi a nebo nějaká haluz.
Jelikož sleuduji,že od založení nového účtu je vše ok,ale nemusí to s tím souviset.
Akorát mám problém dostat windows zpět do češtiny,s novým účtem se mi objevila angličtina a to i v explorer internet a jiných programech.V nastavení v ovládacích panelech je snad vše na cz.

Děkuji


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 108 hostů