PROSBA - prosim o kontroli logu
Logfile of HijackThis v1.99.1
Scan saved at 6:25:16, on 8.4.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\RealVNC\WinVNC\winvnc.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NWTRAY.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Documents and Settings\petrx\Plocha\mwav\upm\upm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\petrx\Plocha\mwav\viry\Balicek\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\RealVNC\WinVNC\winvnc.exe" -servicehelper
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.cz/buxus/docs/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{57154B9A-3A2A-4C58-B5E9-26251ABD2510}: NameServer = 212.11.99.97,195.146.100.5
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Služba brány aplikačního rozhraní (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\RealVNC\WinVNC\winvnc.exe" -service (file missing)
log hijackthis
- Yelkinson
- Level 3
- Příspěvky: 582
- Registrován: listopad 07
- Bydliště: Plzen
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: log hijackthis
Mas starou verzi HJT novou mas u me v podpisu! 

Re: log hijackthis
diky, zkusim to s novou verzi
- Baron Prášil
- Master Level 7
- Příspěvky: 4882
- Registrován: červen 06
- Pohlaví:
- Stav:
Offline
Re: log hijackthis
log je v pořádku.
chybí firewall
vyber si tady,doporučuju ZoneAlarm,Comodo nebo Ashampoo
návod na ZA http://www.kn.vutbr.cz/docs/conf/zonealarm/
na comodo http://www.nforce.cz/modules.php?name=N ... cle&sid=18
Ashampoo Firewall free + čeština
nainstaluj,pošli log z nové vreze HJT a popis problému,pls
chybí firewall
vyber si tady,doporučuju ZoneAlarm,Comodo nebo Ashampoo
návod na ZA http://www.kn.vutbr.cz/docs/conf/zonealarm/
na comodo http://www.nforce.cz/modules.php?name=N ... cle&sid=18
Ashampoo Firewall free + čeština
nainstaluj,pošli log z nové vreze HJT a popis problému,pls

Re: log hijackthis
stahnul jsem si novou verzi Hijackthis a posílám log z druheho pc, ale problem stejny - to jest vraci se maily od mail serveru poslane na neexistujici adresy.tak to vypada, ze si nekdo ze mne udelal spam bot.Budu vdecny za jakoukoli radu.Dekuji
Re: log hijackthis
jeste posilam ten log:
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\NOVELL\CLIENT32\NWRECMSG.EXE
C:\NOVELL\CLIENT32\WM95.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\DPMW32.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGAMSVR.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGW.EXE
H:\HOME\COPY\LADA_ZPRAVA\TOTALCMD.EXE
C:\WINDOWS\PLOCHA\VIRY\BALICEK\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\SYSTEM\dpmw32.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVG7\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVG7\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVG7\AVGAMSVR.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [Workstation Scheduler] C:\novell\client32\wm95.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O11 - Options group: [Usnadnění přístupu] Usnadnění přístupu
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: Win32 Classes - file://C:\WINDOWS\Java\classes\win32ie4.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = a
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 212.11.99.97,195.146.100.5
--
End of file - 3160 bytes
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\NOVELL\CLIENT32\NWRECMSG.EXE
C:\NOVELL\CLIENT32\WM95.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\DPMW32.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGAMSVR.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGW.EXE
H:\HOME\COPY\LADA_ZPRAVA\TOTALCMD.EXE
C:\WINDOWS\PLOCHA\VIRY\BALICEK\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\SYSTEM\dpmw32.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVG7\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVG7\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVG7\AVGAMSVR.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [Workstation Scheduler] C:\novell\client32\wm95.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O11 - Options group: [Usnadnění přístupu] Usnadnění přístupu
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: Win32 Classes - file://C:\WINDOWS\Java\classes\win32ie4.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = a
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 212.11.99.97,195.146.100.5
--
End of file - 3160 bytes
- Baron Prášil
- Master Level 7
- Příspěvky: 4882
- Registrován: červen 06
- Pohlaví:
- Stav:
Offline
Re: log hijackthis
tady fixni
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O11 - Options group: [Usnadnění přístupu] Usnadnění přístupu
O16 - DPF: Win32 Classes - file://C:\WINDOWS\Java\classes\win32ie4.cab
pokračovat budeme tak,že dozabezpečíš ty kompy.
na 98ičky nainstaluj firewall a antispyware
FIREWALL
vyber si tady,doporučuju ZoneAlarm,Comodo nebo Ashampoo
návod na ZA http://www.kn.vutbr.cz/docs/conf/zonealarm/
na comodo http://www.nforce.cz/modules.php?name=N ... cle&sid=18
Ashampoo Firewall free + čeština
ANTISPYWARE
Spyware Terminator nebo Spybot S&D
návod na ST http://www.viry.cz/forum/viewtopic.php?t=44730
návod na Spybot http://www.jaknato.com/index.php?clanek ... tne-slouzi
a na XPčka ten firewall a pošli znovu oba logy hijackthis (do jednoho příspěvku)
posla by jsi mohl i ta hlášení o poště
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O11 - Options group: [Usnadnění přístupu] Usnadnění přístupu
O16 - DPF: Win32 Classes - file://C:\WINDOWS\Java\classes\win32ie4.cab
pokračovat budeme tak,že dozabezpečíš ty kompy.
na 98ičky nainstaluj firewall a antispyware
FIREWALL
vyber si tady,doporučuju ZoneAlarm,Comodo nebo Ashampoo
návod na ZA http://www.kn.vutbr.cz/docs/conf/zonealarm/
na comodo http://www.nforce.cz/modules.php?name=N ... cle&sid=18
Ashampoo Firewall free + čeština
ANTISPYWARE
Spyware Terminator nebo Spybot S&D
návod na ST http://www.viry.cz/forum/viewtopic.php?t=44730
návod na Spybot http://www.jaknato.com/index.php?clanek ... tne-slouzi
a na XPčka ten firewall a pošli znovu oba logy hijackthis (do jednoho příspěvku)
posla by jsi mohl i ta hlášení o poště
Re: log hijackthis
posilam ty logy.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:59:52, on 11.4.2008
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\DPMW32.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGAMSVR.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\PLOCHA\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\SYSTEM\dpmw32.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVG7\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVG7\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVG7\AVGAMSVR.EXE
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\.DEFAULT\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = a
A JESTE:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:32:14, on 11.4.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\RealVNC\WinVNC\winvnc.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Documents and Settings\petrx\Plocha\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\RealVNC\WinVNC\winvnc.exe" -servicehelper
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.cz/buxus/docs/OnlineScanner.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: VNC Server (winvnc) - RealVNC Ltd. - C:\Program Files\RealVNC\WinVNC\winvnc.exe
DEKUJI ZA ZAJEM
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:59:52, on 11.4.2008
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\DPMW32.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGAMSVR.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\PLOCHA\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\SYSTEM\dpmw32.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVG7\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVG7\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVG7\AVGAMSVR.EXE
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\.DEFAULT\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = a
A JESTE:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:32:14, on 11.4.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\RealVNC\WinVNC\winvnc.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Documents and Settings\petrx\Plocha\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\RealVNC\WinVNC\winvnc.exe" -servicehelper
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.cz/buxus/docs/OnlineScanner.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: VNC Server (winvnc) - RealVNC Ltd. - C:\Program Files\RealVNC\WinVNC\winvnc.exe
DEKUJI ZA ZAJEM
- Baron Prášil
- Master Level 7
- Příspěvky: 4882
- Registrován: červen 06
- Pohlaví:
- Stav:
Offline
Re: log hijackthis
na ty xpéčka jsi měl nainstalit jen firewall.ten spy terminator je navíc-odinstaluj ho (nebo spybot-jak chceš)
jinak jsou logy v pořádku. problém trvá? hlášení pošťáka ukážeš?
jinak jsou logy v pořádku. problém trvá? hlášení pošťáka ukážeš?
Re: log hijackthis
posílám ten mail, tu mailovou adresu na kterou se to vraci uz dlouho nepouzivam
This message was created automatically by mail delivery software (Exim).
A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:
aoztdd@izhavia.udm.ru
unknown local-part "aoztdd" in domain "izhavia.udm.ru"
------ This is a copy of the message, including all the headers. ------
Return-path: <ladad@nb.czcom.cz>
Received: from mail by izhavia.izhavia.udm.ru with spam-scanned (Exim 3.36 #1 (Debian))
id 1JlJse-0003TE-00
for <aoztdd@izhavia.udm.ru>; Mon, 14 Apr 2008 13:21:05 +0500
Received: from [84.120.101.78] (helo=84.120.101.78.dyn.user.ono.com)
by izhavia.izhavia.udm.ru with esmtp (Exim 3.36 #1 (Debian))
id 1JlJsd-0003Sw-00
for <aoztdd@izhavia.udm.ru>; Mon, 14 Apr 2008 13:17:35 +0500
Message-ID: <000901c89e08$05e176d4$87f983b6@utomxft>
From: "kean eliphalet" <kovoplast@nb.czcom.cz>
To: <aoztdd@izhavia.udm.ru>
Subject: =?koi8-r?B?8sXHydPU0sHDydEgwNLJxMnexdPLycggzMnD?=
Date: Mon, 14 Apr 2008 06:32:01 +0000
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0006_01C89E08.05E00593"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.3138
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3198
This is a multi-part message in MIME format.
------=_NextPart_000_0006_01C89E08.05E00593
Content-Type: text/plain;
charset="koi8-r"
Content-Transfer-Encoding: quoted-printable
=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =EF=EF=EF, =FA=E1=EF, =EF=E1=EF, =
=E9=F0, =D7=CE=C5=D3=C5=CE=C9=C5 =C9=DA=CD=C5=CE=C5=CE=C9=CA =
=CC=C0=C2=CF=CA =D3=CC=CF=D6=CE=CF=D3=D4=C9!
=F7=C9=C4 =D5=D3=CC=D5=C7=C9=20
=F3=D4=CF=C9=CD=CF=D3=D4=D8=20
=20
=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =EF=EF=EF=20
7000 =D2=D5=C2.
=20
=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =FA=E1=EF
10000 =D2=D5=C2.
=20
=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =EF=E1=EF
10000 =D2=D5=C2.
=20
=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =
=CE=C5=CB=CF=CD=CD=C5=D2=DE=C5=D3=CB=C9=C8 =
=CF=D2=C7=C1=CE=C9=DA=C1=C3=C9=CA
=EF=D4 15000 =D2=D5=C2.
=20
=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =E9=F0
5000 =D2=D5=C2.
=20
=F7=CE=C5=D3=C5=CE=C9=C5 =C9=DA=CD=C5=CE=C5=CE=C9=CA =D7 =
=D5=DE=D2=C5=C4=C9=D4=C5=CC=D8=CE=D9=C5 =C4=CF=CB=D5=CD=C5=CE=D4=D9=20
=EF=D4 4500 =D2=D5=C2.
=20
=F7=CE=C5=C2=C0=C4=D6=C5=D4=CE=D9=C5 =C6=CF=CE=C4=D9
2500 =D2=D5=C2. (=DA=C1 3 =C6=CF=CE=C4=C1)
=20
=EC=C9=CB=D7=C9=C4=C1=C3=C9=D1 =C6=C9=D2=CD
=EF=D4 20000 =D2=D5=C2.
=20
=F3=CC=C9=D1=CE=C9=C5
30000 =D2=D5=C2.
=20
=E0=D2=C9=C4=C9=DE=C5=D3=CB=C9=C5 =C1=C4=D2=C5=D3=C1
=EF=D4 15000 =D2=D5=C2.
=20
=E9=DA=C7=CF=D4=CF=D7=CC=C5=CE=C9=C5 =D0=C5=DE=C1=D4=C5=CA
=EF=D4 450 =D2=D5=C2.
=20
=F0=CF=CC=D5=DE=C5=CE=C9=C5 =D7=D9=D0=C9=D3=CB=C9 =C9=DA =
=E5=E7=F2=E0=EC =DA=C1 1 =C4=C5=CE=D8
1500 =D2=D5=C2.
=20
=EE=C1=DB=C9 =CB=CC=C9=C5=CE=D4=D9 =CE=C5 =D0=D2=C9=C5=CD=CC=C0=D4 =
=CE=C5=D5=C4=C1=DE =D7 =C2=C9=DA=CE=C5=D3=C5, =
=CF=C2=D2=C1=DD=C1=CA=D4=C5=D3=D8 - =D0=CF=CD=CF=D6=C5=CD!
=F4=C5=CC. [ 495 ] 6 29961 1
=F4=C5=CC. [ 499 ] 4 08968 3
=F0=D2=C9=CE=CF=D3=C9=CD =D3=D7=CF=C9 =C9=DA=D7=C9=CE=C5=CE=C9=D1, =
=C5=D3=CC=C9 =C4=C1=CE=CE=C1=D1 =D2=C1=D3=D3=D9=CC=CB=C1 =F7=C1=CD =
=CE=C5 =CE=D5=D6=CE=C1.
------=_NextPart_000_0006_01C89E08.05E00593
Content-Type: text/html;
charset="koi8-r"
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; charset=3Dkoi8-r">
<META content=3D"MSHTML 6.00.2900.3199" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<P align=3D"center" style=3D"font-size:19px; font-weight:bold; =
color:#0000FF ">=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =EF=EF=EF, =FA=E1=EF, =
=EF=E1=EF, =E9=F0, =D7=CE=C5=D3=C5=CE=C9=C5 =C9=DA=CD=C5=CE=C5=CE=C9=CA =
=CC=C0=C2=CF=CA =D3=CC=CF=D6=CE=CF=D3=D4=C9!</P>
<TABLE cellspacing=3D"0" cellpadding=3D"5" width=3D"600" =
align=3D"center" border=3D"1">
<TR>
<TD><P align=3D"center"><STRONG> =F7=C9=C4 =D5=D3=CC=D5=C7=C9 =
</STRONG></P></TD>
<TD><P align=3D"center"><STRONG> =F3=D4=CF=C9=CD=CF=D3=D4=D8 =
</STRONG></P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =EF=EF=EF =
</P></TD>
<TD valign=3D"top"><P>7000 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =
=FA=E1=EF</P></TD>
<TD valign=3D"top"><P>10000 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =
=EF=E1=EF</P></TD>
<TD valign=3D"top"><P>10000 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =
=CE=C5=CB=CF=CD=CD=C5=D2=DE=C5=D3=CB=C9=C8 =
=CF=D2=C7=C1=CE=C9=DA=C1=C3=C9=CA</P></TD>
<TD valign=3D"top"><P>=EF=D4 15000 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =
=E9=F0</P></TD>
<TD valign=3D"top"><P>5000 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=F7=CE=C5=D3=C5=CE=C9=C5 =
=C9=DA=CD=C5=CE=C5=CE=C9=CA =D7 =D5=DE=D2=C5=C4=C9=D4=C5=CC=D8=CE=D9=C5 =
=C4=CF=CB=D5=CD=C5=CE=D4=D9 </P></TD>
<TD valign=3D"top"><P>=EF=D4 4500 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=F7=CE=C5=C2=C0=C4=D6=C5=D4=CE=D9=C5 =
=C6=CF=CE=C4=D9</P></TD>
<TD valign=3D"top"><P>2500 =D2=D5=C2. (=DA=C1 3 =
=C6=CF=CE=C4=C1)</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=EC=C9=CB=D7=C9=C4=C1=C3=C9=D1 =
=C6=C9=D2=CD</P></TD>
<TD valign=3D"top"><P>=EF=D4 20000 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=F3=CC=C9=D1=CE=C9=C5</P></TD>
<TD valign=3D"top"><P>30000 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=E0=D2=C9=C4=C9=DE=C5=D3=CB=C9=C5 =
=C1=C4=D2=C5=D3=C1</P></TD>
<TD valign=3D"top"><P>=EF=D4 15000 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=E9=DA=C7=CF=D4=CF=D7=CC=C5=CE=C9=C5 =
=D0=C5=DE=C1=D4=C5=CA</P></TD>
<TD valign=3D"top"><P>=EF=D4 450 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=F0=CF=CC=D5=DE=C5=CE=C9=C5 =
=D7=D9=D0=C9=D3=CB=C9 =C9=DA =E5=E7=F2=E0=EC =DA=C1 1 =
=C4=C5=CE=D8</P></TD>
<TD valign=3D"top"><P>1500 =D2=D5=C2.</P></TD>
</TR>
</TABLE>
<P align=3D"center"><STRONG>=EE=C1=DB=C9 =CB=CC=C9=C5=CE=D4=D9 =CE=C5 =
=D0=D2=C9=C5=CD=CC=C0=D4 =CE=C5=D5=C4=C1=DE =D7 =C2=C9=DA=CE=C5=D3=C5, =
=CF=C2=D2=C1=DD=C1=CA=D4=C5=D3=D8 - =D0=CF=CD=CF=D6=C5=CD!</STRONG></P>
<P align=3D"center"><STRONG>=F4=C5=CC. [ 495 ] 6 29961 1<BR>
=F4=C5=CC. [ 499 ] 4 08968 3
</STRONG></P>
<P align=3D"center"><STRONG>=F0=D2=C9=CE=CF=D3=C9=CD =D3=D7=CF=C9 =
=C9=DA=D7=C9=CE=C5=CE=C9=D1, =C5=D3=CC=C9 =C4=C1=CE=CE=C1=D1 =
=D2=C1=D3=D3=D9=CC=CB=C1 =F7=C1=CD =CE=C5 =
=CE=D5=D6=CE=C1.</STRONG></P></BODY></HTML>
------=_NextPart_000_0006_01C89E08.05E00593--
This message was created automatically by mail delivery software (Exim).
A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:
aoztdd@izhavia.udm.ru
unknown local-part "aoztdd" in domain "izhavia.udm.ru"
------ This is a copy of the message, including all the headers. ------
Return-path: <ladad@nb.czcom.cz>
Received: from mail by izhavia.izhavia.udm.ru with spam-scanned (Exim 3.36 #1 (Debian))
id 1JlJse-0003TE-00
for <aoztdd@izhavia.udm.ru>; Mon, 14 Apr 2008 13:21:05 +0500
Received: from [84.120.101.78] (helo=84.120.101.78.dyn.user.ono.com)
by izhavia.izhavia.udm.ru with esmtp (Exim 3.36 #1 (Debian))
id 1JlJsd-0003Sw-00
for <aoztdd@izhavia.udm.ru>; Mon, 14 Apr 2008 13:17:35 +0500
Message-ID: <000901c89e08$05e176d4$87f983b6@utomxft>
From: "kean eliphalet" <kovoplast@nb.czcom.cz>
To: <aoztdd@izhavia.udm.ru>
Subject: =?koi8-r?B?8sXHydPU0sHDydEgwNLJxMnexdPLycggzMnD?=
Date: Mon, 14 Apr 2008 06:32:01 +0000
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0006_01C89E08.05E00593"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.3138
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3198
This is a multi-part message in MIME format.
------=_NextPart_000_0006_01C89E08.05E00593
Content-Type: text/plain;
charset="koi8-r"
Content-Transfer-Encoding: quoted-printable
=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =EF=EF=EF, =FA=E1=EF, =EF=E1=EF, =
=E9=F0, =D7=CE=C5=D3=C5=CE=C9=C5 =C9=DA=CD=C5=CE=C5=CE=C9=CA =
=CC=C0=C2=CF=CA =D3=CC=CF=D6=CE=CF=D3=D4=C9!
=F7=C9=C4 =D5=D3=CC=D5=C7=C9=20
=F3=D4=CF=C9=CD=CF=D3=D4=D8=20
=20
=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =EF=EF=EF=20
7000 =D2=D5=C2.
=20
=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =FA=E1=EF
10000 =D2=D5=C2.
=20
=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =EF=E1=EF
10000 =D2=D5=C2.
=20
=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =
=CE=C5=CB=CF=CD=CD=C5=D2=DE=C5=D3=CB=C9=C8 =
=CF=D2=C7=C1=CE=C9=DA=C1=C3=C9=CA
=EF=D4 15000 =D2=D5=C2.
=20
=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =E9=F0
5000 =D2=D5=C2.
=20
=F7=CE=C5=D3=C5=CE=C9=C5 =C9=DA=CD=C5=CE=C5=CE=C9=CA =D7 =
=D5=DE=D2=C5=C4=C9=D4=C5=CC=D8=CE=D9=C5 =C4=CF=CB=D5=CD=C5=CE=D4=D9=20
=EF=D4 4500 =D2=D5=C2.
=20
=F7=CE=C5=C2=C0=C4=D6=C5=D4=CE=D9=C5 =C6=CF=CE=C4=D9
2500 =D2=D5=C2. (=DA=C1 3 =C6=CF=CE=C4=C1)
=20
=EC=C9=CB=D7=C9=C4=C1=C3=C9=D1 =C6=C9=D2=CD
=EF=D4 20000 =D2=D5=C2.
=20
=F3=CC=C9=D1=CE=C9=C5
30000 =D2=D5=C2.
=20
=E0=D2=C9=C4=C9=DE=C5=D3=CB=C9=C5 =C1=C4=D2=C5=D3=C1
=EF=D4 15000 =D2=D5=C2.
=20
=E9=DA=C7=CF=D4=CF=D7=CC=C5=CE=C9=C5 =D0=C5=DE=C1=D4=C5=CA
=EF=D4 450 =D2=D5=C2.
=20
=F0=CF=CC=D5=DE=C5=CE=C9=C5 =D7=D9=D0=C9=D3=CB=C9 =C9=DA =
=E5=E7=F2=E0=EC =DA=C1 1 =C4=C5=CE=D8
1500 =D2=D5=C2.
=20
=EE=C1=DB=C9 =CB=CC=C9=C5=CE=D4=D9 =CE=C5 =D0=D2=C9=C5=CD=CC=C0=D4 =
=CE=C5=D5=C4=C1=DE =D7 =C2=C9=DA=CE=C5=D3=C5, =
=CF=C2=D2=C1=DD=C1=CA=D4=C5=D3=D8 - =D0=CF=CD=CF=D6=C5=CD!
=F4=C5=CC. [ 495 ] 6 29961 1
=F4=C5=CC. [ 499 ] 4 08968 3
=F0=D2=C9=CE=CF=D3=C9=CD =D3=D7=CF=C9 =C9=DA=D7=C9=CE=C5=CE=C9=D1, =
=C5=D3=CC=C9 =C4=C1=CE=CE=C1=D1 =D2=C1=D3=D3=D9=CC=CB=C1 =F7=C1=CD =
=CE=C5 =CE=D5=D6=CE=C1.
------=_NextPart_000_0006_01C89E08.05E00593
Content-Type: text/html;
charset="koi8-r"
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; charset=3Dkoi8-r">
<META content=3D"MSHTML 6.00.2900.3199" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<P align=3D"center" style=3D"font-size:19px; font-weight:bold; =
color:#0000FF ">=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =EF=EF=EF, =FA=E1=EF, =
=EF=E1=EF, =E9=F0, =D7=CE=C5=D3=C5=CE=C9=C5 =C9=DA=CD=C5=CE=C5=CE=C9=CA =
=CC=C0=C2=CF=CA =D3=CC=CF=D6=CE=CF=D3=D4=C9!</P>
<TABLE cellspacing=3D"0" cellpadding=3D"5" width=3D"600" =
align=3D"center" border=3D"1">
<TR>
<TD><P align=3D"center"><STRONG> =F7=C9=C4 =D5=D3=CC=D5=C7=C9 =
</STRONG></P></TD>
<TD><P align=3D"center"><STRONG> =F3=D4=CF=C9=CD=CF=D3=D4=D8 =
</STRONG></P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =EF=EF=EF =
</P></TD>
<TD valign=3D"top"><P>7000 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =
=FA=E1=EF</P></TD>
<TD valign=3D"top"><P>10000 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =
=EF=E1=EF</P></TD>
<TD valign=3D"top"><P>10000 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =
=CE=C5=CB=CF=CD=CD=C5=D2=DE=C5=D3=CB=C9=C8 =
=CF=D2=C7=C1=CE=C9=DA=C1=C3=C9=CA</P></TD>
<TD valign=3D"top"><P>=EF=D4 15000 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=F2=C5=C7=C9=D3=D4=D2=C1=C3=C9=D1 =
=E9=F0</P></TD>
<TD valign=3D"top"><P>5000 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=F7=CE=C5=D3=C5=CE=C9=C5 =
=C9=DA=CD=C5=CE=C5=CE=C9=CA =D7 =D5=DE=D2=C5=C4=C9=D4=C5=CC=D8=CE=D9=C5 =
=C4=CF=CB=D5=CD=C5=CE=D4=D9 </P></TD>
<TD valign=3D"top"><P>=EF=D4 4500 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=F7=CE=C5=C2=C0=C4=D6=C5=D4=CE=D9=C5 =
=C6=CF=CE=C4=D9</P></TD>
<TD valign=3D"top"><P>2500 =D2=D5=C2. (=DA=C1 3 =
=C6=CF=CE=C4=C1)</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=EC=C9=CB=D7=C9=C4=C1=C3=C9=D1 =
=C6=C9=D2=CD</P></TD>
<TD valign=3D"top"><P>=EF=D4 20000 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=F3=CC=C9=D1=CE=C9=C5</P></TD>
<TD valign=3D"top"><P>30000 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=E0=D2=C9=C4=C9=DE=C5=D3=CB=C9=C5 =
=C1=C4=D2=C5=D3=C1</P></TD>
<TD valign=3D"top"><P>=EF=D4 15000 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=E9=DA=C7=CF=D4=CF=D7=CC=C5=CE=C9=C5 =
=D0=C5=DE=C1=D4=C5=CA</P></TD>
<TD valign=3D"top"><P>=EF=D4 450 =D2=D5=C2.</P></TD>
</TR>
<TR>
<TD valign=3D"top"><P>=F0=CF=CC=D5=DE=C5=CE=C9=C5 =
=D7=D9=D0=C9=D3=CB=C9 =C9=DA =E5=E7=F2=E0=EC =DA=C1 1 =
=C4=C5=CE=D8</P></TD>
<TD valign=3D"top"><P>1500 =D2=D5=C2.</P></TD>
</TR>
</TABLE>
<P align=3D"center"><STRONG>=EE=C1=DB=C9 =CB=CC=C9=C5=CE=D4=D9 =CE=C5 =
=D0=D2=C9=C5=CD=CC=C0=D4 =CE=C5=D5=C4=C1=DE =D7 =C2=C9=DA=CE=C5=D3=C5, =
=CF=C2=D2=C1=DD=C1=CA=D4=C5=D3=D8 - =D0=CF=CD=CF=D6=C5=CD!</STRONG></P>
<P align=3D"center"><STRONG>=F4=C5=CC. [ 495 ] 6 29961 1<BR>
=F4=C5=CC. [ 499 ] 4 08968 3
</STRONG></P>
<P align=3D"center"><STRONG>=F0=D2=C9=CE=CF=D3=C9=CD =D3=D7=CF=C9 =
=C9=DA=D7=C9=CE=C5=CE=C9=D1, =C5=D3=CC=C9 =C4=C1=CE=CE=C1=D1 =
=D2=C1=D3=D3=D9=CC=CB=C1 =F7=C1=CD =CE=C5 =
=CE=D5=D6=CE=C1.</STRONG></P></BODY></HTML>
------=_NextPart_000_0006_01C89E08.05E00593--
- Baron Prášil
- Master Level 7
- Příspěvky: 4882
- Registrován: červen 06
- Pohlaví:
- Stav:
Offline
Re: log hijackthis
bude asi lepší na to založit téma v sekci Komunikace na internetu.
k tomu by měl říci něco,někdo kdo ví o co gou
k tomu by měl říci něco,někdo kdo ví o co gou

Re: log hijackthis
diky
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 108 hostů