Moc prosim o kontrolu logu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

lukash
nováček
Příspěvky: 36
Registrován: prosinec 06
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod lukash » 30 pro 2006 11:23

sakiri
jak mám tohle máznout,když nevím tu cestu.Co znamená HKLM a HKCU

HKLM\Software\magnet

HKCU\software\microsoft\windows\currentversion\explorer\menuorder\start menu2\programs\whenusearch
HKCU\magnet

HKLM\System\CurrentControlSet\Services\iprip

HKLM\System\ControlSet001\Services\iprip

HKLM\System\ControlSet002\Services\iprip

Reklama
sakiri
Level 3.5
Level 3.5
Příspěvky: 747
Registrován: červen 06
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod sakiri » 30 pro 2006 11:37

sorry :oops: úplně jsem zapomněl.


Dej Start>spustit>do volného řádku napiš regedit a stiskni enter.

HKLM znamená HKEY_LOCAL_MACHINE
HKCU znamená HKEY_CURRENT_USER

A smaž tam to co jsem označil červeně.

lukash
nováček
Příspěvky: 36
Registrován: prosinec 06
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod lukash » 30 pro 2006 12:36

Sakiri
Díky moc za trpělivost.Tohle jsem tam nenašel HKCU\magnet a HKLM\System\ControlSet001\Services\iprip
Posílám MWAV předtím jsem kontroloval jen program files teď už all files :idea:
Sat Dec 30 12:16:35 2006 => Total Objects Scanned: 29268
Sat Dec 30 12:16:35 2006 => Total Critical Objects: 1
Sat Dec 30 12:16:35 2006 => Total Disinfected Objects: 0
Sat Dec 30 12:16:35 2006 => Total Objects Renamed: 0
Sat Dec 30 12:16:35 2006 => Total Deleted Objects: 0
Sat Dec 30 12:16:35 2006 => Total Errors: 81
Sat Dec 30 12:16:35 2006 => Time Elapsed: 00:09:05
Sat Dec 30 12:16:35 2006 => Virus Database Date: 12/30/2006
Sat Dec 30 12:16:36 2006 => Virus Database Count: 255137

Sat Dec 30 12:16:36 2006 => Scan Completed.


Sat Dec 30 12:09:41 2006 => Offending Key found: HKCU\\magnet !!!
Sat Dec 30 12:09:44 2006 => Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken.

Sat Dec 30 12:09:59 2006 => Checking CLSID Reference Entries...
Sat Dec 30 12:10:01 2006 => Entry "HKCR\ICQPhone.SipxPhoneManager" refers to invalid object "{82308D15-1A2C-416A-A5BE-21DAF85DDB75}". Action Taken: No Action Taken.

Sat Dec 30 12:10:01 2006 => Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken.

Sat Dec 30 12:10:01 2006 => Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.

Sat Dec 30 12:10:01 2006 => Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.

Sat Dec 30 12:10:03 2006 => Entry "HKCR\NMUIEngine.NMUIResourceLoaderHarddisk" refers to invalid object "{03DC5606-EA66-4f02-AB52-2065524B03821}". Action Taken: No Action Taken.
Sat Dec 30 12:10:05 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Nero\Nero 7\Nero BackItUp\NeroFiles\NeroCsy.txt". Action Taken: No Action Taken.

Sat Dec 30 12:10:05 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Nero\Nero 7\Nero BackItUp\NeroFiles\NeroDeu.txt". Action Taken: No Action Taken.

Sat Dec 30 12:10:05 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Nero\Nero 7\Nero BackItUp\NeroBackItUp_deu.chm". Action Taken: No Action Taken.

Sat Dec 30 12:10:05 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Nero\Nero 7\Nero BackItUp\NeroBackItUp_eng.chm". Action Taken: No Action Taken.

Sat Dec 30 12:10:05 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Nero\Nero 7\Nero BackItUp\BackItUp-CSY.nls". Action Taken: No Action Taken.

Sat Dec 30 12:10:05 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Nero\Nero 7\Nero BackItUp\BackItUp-DEU.nls". Action Taken: No Action Taken.

Sat Dec 30 12:10:05 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Nero\Nero 7\Nero BackItUp\BackItUp.exe". Action Taken: No Action Taken.

Sat Dec 30 12:10:05 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Nero\Nero 7\Nero CoverDesigner\NeroCoverDesigner_deu.chm". Action Taken: No Action Taken.

Sat Dec 30 12:10:05 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Nero\Nero 7\Nero CoverDesigner\NeroCoverDesigner_eng.chm". Action Taken: No Action Taken.

Sat Dec 30 12:10:05 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Nero\Nero 7\Nero CoverDesigner\covered-csy.nls". Action Taken: No Action Taken.

Sat Dec 30 12:10:05 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Nero\Nero 7\Nero CoverDesigner\covered-deu.nls". Action Taken: No Action Taken.

Sat Dec 30 12:10:05 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Nero\Nero 7\Nero CoverDesigner\Templates\Data.nct". Action Taken: No Action Taken.

Sat Dec 30 12:10:05 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Nero\Nero 7\Nero CoverDesigner\CoverDes.exe". Action Taken: No Action Taken.

Sat Dec 30 12:10:05 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\Drivers\imagesrv.sys". Action Taken: No Action Taken.

Sat Dec 30 12:10:05 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\pxwma.dll". Action Taken: No Action Taken.

Sat Dec 30 12:10:05 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\pxinsi64.exe". Action Taken: No Action Taken.

Sat Dec 30 12:10:05 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\pxcpyi64.exe". Action Taken: No Action Taken.

Sat Dec 30 12:10:05 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Nero\Nero 7\Nero BackItUp\\BackItUp-Deu.nls". Action Taken: No Action Taken.

Sat Dec 30 12:10:05 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Nero\Nero 7\Nero BackItUp\\BackItUp-Jpn.nls". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.Windows.Forms.tlb". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Windows.Forms.tlb". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorlib.tlb". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscoree.tlb". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Drawing.tlb". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.EnterpriseServices.tlb". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Microsoft.JScript.tlb". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Microsoft.Vsa.tlb". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.Drawing.tlb". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscoree.tlb". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.tlb". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.tlb". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.JScript.tlb". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.tlb". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.Vb.CodeDOMProcessor.tlb". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscorlib.tlb". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.tlb". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Microsoft.Vsa.Vb.CodeDOMProcessor.tlb". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Checking Installer Entries...
Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Norton AntiVirus\". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Common Files\Symantec Shared\SPBBC\". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Nabídka Start\Programy\Firaxis Games\Sid Meier's Pirates!\". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Nabídka Start\Programy\Firaxis Games\". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "D:\!!HRY!!\Football Manager 2005\data\". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "D:\!!HRY!!\Football Manager 2005\". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "D:\!!HRY!!\Football Manager 2005\data\languages\". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "D:\!!HRY!!\Children of the Nile\documents\". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "D:\!!HRY!!\SilentHunterIII\data\". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "D:\!!HRY!!\SilentHunterIII\data\Menu\". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "D:\!!HRY!!\SilentHunterIII\data\Menu\Gui\". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "D:\!!HRY!!\SilentHunterIII\data\Menu\MouseCurs\". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Nabídka Start\Programy\Ubisoft\Silent Hunter III\". Action Taken: No Action Taken.

Sat Dec 30 12:10:06 2006 => Checking Shared Tools Entries...
Sat Dec 30 12:10:07 2006 => Checking File Extension Entries...
Sat Dec 30 12:10:07 2006 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".BWI". Action Taken: No Action Taken.

Sat Dec 30 12:10:07 2006 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".BWS". Action Taken: No Action Taken.

Sat Dec 30 12:10:07 2006 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".com/pub/aec/". Action Taken: No Action Taken.

Sat Dec 30 12:10:07 2006 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".dctmp". Action Taken: No Action Taken.

Sat Dec 30 12:10:07 2006 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".e_e". Action Taken: No Action Taken.

Sat Dec 30 12:10:07 2006 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".FPK". Action Taken: No Action Taken.

Sat Dec 30 12:10:07 2006 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".lang". Action Taken: No Action Taken.

Sat Dec 30 12:10:07 2006 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".md0". Action Taken: No Action Taken.

Sat Dec 30 12:10:07 2006 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".mdf". Action Taken: No Action Taken.

Sat Dec 30 12:10:07 2006 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".mds". Action Taken: No Action Taken.

Sat Dec 30 12:10:07 2006 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".old". Action Taken: No Action Taken.

Sat Dec 30 12:10:07 2006 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".ref". Action Taken: No Action Taken.

Sat Dec 30 12:10:07 2006 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".sfv". Action Taken: No Action Taken.

Sat Dec 30 12:10:07 2006 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object "OpenWithList". Action Taken: No Action Taken.

Sat Dec 30 12:10:07 2006 => Checking Application Cache Entries...
Sat Dec 30 12:10:07 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Freelancer 1.0". Action Taken: No Action Taken.

Sat Dec 30 12:10:07 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Hitman: Contracts". Action Taken: No Action Taken.

Sat Dec 30 12:10:07 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "ICQ". Action Taken: No Action Taken.

Sat Dec 30 12:10:07 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "InstallShield_{1632FD86-1BA4-4FC4-8B25-A8C655D63F68}". Action Taken: No Action Taken.

Sat Dec 30 12:10:07 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "InstallShield_{9720C029-0C2C-4D1E-9DE0-E89971C4C8C7}". Action Taken: No Action Taken.

sakiri
Level 3.5
Level 3.5
Příspěvky: 747
Registrován: červen 06
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod sakiri » 30 pro 2006 13:08

ten magnet skoro nikdo nenajde stejnak to není skoro žádné nebezpečí.

U toho iprip pokus si chceš být jistý tak postupuj takhle:

Spusť Avengera pod účtem administrátora pokud ho už nemáš tak ho znovu stáhni.
Zvol volbu-Input script manually a klikni na ikonku lupy vyskočí i prázdné okno kam zkopíruj ten tučně označený text:
Registry keys to delete:
HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iprip

Pak klikni na Done.
Poté klikni na ikonku semafory.Vyskočí ti hláška kde odklikni Yes poté další kde odklikni také Yes.
PC se restartuje po restartu by ti měl vyskočit výpis Avengeru tak ho sem zkopíruj.

a na ty chyby v registrech použij CCleaner

lukash
nováček
Příspěvky: 36
Registrován: prosinec 06
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod lukash » 30 pro 2006 13:28

tady je
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\fdpsisnu

*******************

Script file located at: \??\C:\jpkbsfoe.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



Registry key HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iprip not found!
Deletion of registry key HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iprip failed!

Could not process line:
HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iprip
Status: 0xc0000034


Completed script processing.

*******************

Finished! Terminate.

lukash
nováček
Příspěvky: 36
Registrován: prosinec 06
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod lukash » 30 pro 2006 14:20

Sakiri
Moc děkuju za rychlost odpovědí.Udělal jsem to jak jsi mi psal a tady je výsledek(MWAV)
Sat Dec 30 14:13:43 2006 => Total Objects Scanned: 24232
Sat Dec 30 14:13:43 2006 => Total Critical Objects: 1
Sat Dec 30 14:13:43 2006 => Total Disinfected Objects: 0
Sat Dec 30 14:13:43 2006 => Total Objects Renamed: 0
Sat Dec 30 14:13:44 2006 => Total Deleted Objects: 0
Sat Dec 30 14:13:44 2006 => Total Errors: 14
Sat Dec 30 14:13:44 2006 => Time Elapsed: 00:04:31
Sat Dec 30 14:13:44 2006 => Virus Database Date: 12/30/2006
Sat Dec 30 14:13:44 2006 => Virus Database Count: 255144

Sat Dec 30 14:13:44 2006 => Scan Completed.
Sat Dec 30 14:11:10 2006 => Offending Key found: HKCU\\magnet !!!
Sat Dec 30 14:11:13 2006 => Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken.

Sat Dec 30 14:11:27 2006 => Checking CLSID Reference Entries...
Sat Dec 30 14:11:30 2006 => Entry "HKCR\Microsoft.ActiveXPlugin" refers to invalid object "{06DD38D3-D187-11CF-A80D-00C04FD74AD8}". Action Taken: No Action Taken.

Sat Dec 30 14:11:30 2006 => Entry "HKCR\Microsoft.ActiveXPlugin.1" refers to invalid object "{06DD38D3-D187-11CF-A80D-00C04FD74AD8}". Action Taken: No Action Taken.

Sat Dec 30 14:11:30 2006 => Entry "HKCR\MSMAPI.MAPIMessages" refers to invalid object "{20C62CAB-15DA-101B-B9A8-444553540000}". Action Taken: No Action Taken.

Sat Dec 30 14:11:30 2006 => Entry "HKCR\MSMAPI.MAPIMessages.1" refers to invalid object "{20C62CAB-15DA-101B-B9A8-444553540000}". Action Taken: No Action Taken.

Sat Dec 30 14:11:30 2006 => Entry "HKCR\MSMAPI.MAPISession" refers to invalid object "{20C62CA0-15DA-101B-B9A8-444553540000}". Action Taken: No Action Taken.

Sat Dec 30 14:11:30 2006 => Entry "HKCR\MSMAPI.MAPISession.1" refers to invalid object "{20C62CA0-15DA-101B-B9A8-444553540000}". Action Taken: No Action Taken.

Sat Dec 30 14:11:32 2006 => Entry "HKCR\PDFGEN.PdfgenCtrl.1" refers to invalid object "{423790A3-9A27-479F-A6C2-97063CCE032E}". Action Taken: No Action Taken.
Sat Dec 30 14:11:35 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "The Godfather ". Action Taken: No Action Taken.

Uživatelský avatar
mikel
Level 5
Level 5
Příspěvky: 2298
Registrován: květen 05
Bydliště: Karviná
Pohlaví: Muž
Stav:
Offline

Příspěvekod mikel » 30 pro 2006 15:42

Zbývá tam už jen HKCU\\magnet.

V registrech si otevři větev HOT_KEY_CURRENT_USER a měl bys tam najít další větev beze jména. Tu zkus otevřít a v ní najdeš větev magnet, kterou celou smažeš.

Pak bych ti doporučoval pročistit registry např. pomocí CCleaneru.
Znáte pravidla?
Tipy a triky ve Windows XP
Návody: HijackThis, MWAV, CCleaner (THX to mijaja)
Problémy, které chcete vyřešit pište sem do fóra. Neposílejte je emailem ani po ICQ!

lukash
nováček
Příspěvky: 36
Registrován: prosinec 06
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod lukash » 30 pro 2006 16:15

mikel
Registry jsem před chvilkou čistil pomocí CCleaneru.
.Jsem asi slepej nic takového tam nevidím v HKCU mám tyto složky
+ApEvents
console
+control panel
Environment
EugInitialization
+Identities
+keyboart Layout
MyShortcots
NFD
+Printers
SessionInformatoion
+Software
UNICODE Program Grups
Volatile Euvironment
Windows 3.1 Migration Status

Uživatelský avatar
mikel
Level 5
Level 5
Příspěvky: 2298
Registrován: květen 05
Bydliště: Karviná
Pohlaví: Muž
Stav:
Offline

Příspěvekod mikel » 30 pro 2006 16:25

Ještě ho můžeš zkusit vyhledat pomocí Úpravy/Najít. Napíšeš tam magnet a zaškrtneš Hledat pouze celý řetězec.
Znáte pravidla?
Tipy a triky ve Windows XP
Návody: HijackThis, MWAV, CCleaner (THX to mijaja)
Problémy, které chcete vyřešit pište sem do fóra. Neposílejte je emailem ani po ICQ!

lukash
nováček
Příspěvky: 36
Registrován: prosinec 06
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod lukash » 30 pro 2006 16:50

Mikel
dal jsem hledat a našlo mě to magnet tady
HKLM/software/classes/magnet.
Nic víc.

Uživatelský avatar
mikel
Level 5
Level 5
Příspěvky: 2298
Registrován: květen 05
Bydliště: Karviná
Pohlaví: Muž
Stav:
Offline

Příspěvekod mikel » 30 pro 2006 21:52

V tom případě smaž ten magnet tam.
Znáte pravidla?
Tipy a triky ve Windows XP
Návody: HijackThis, MWAV, CCleaner (THX to mijaja)
Problémy, které chcete vyřešit pište sem do fóra. Neposílejte je emailem ani po ICQ!

lukash
nováček
Příspěvky: 36
Registrován: prosinec 06
Pohlaví: Nespecifikováno
Stav:
Offline

Příspěvekod lukash » 30 pro 2006 22:23

mikel
Moc ti děkuji i všem ostatním.Teď ještě musím vyřešit ten tcpsvcs.exe


Sat Dec 30 22:20:02 2006 => Total Objects Scanned: 24167
Sat Dec 30 22:20:02 2006 => Total Critical Objects: 0
Sat Dec 30 22:20:02 2006 => Total Disinfected Objects: 0
Sat Dec 30 22:20:02 2006 => Total Objects Renamed: 0
Sat Dec 30 22:20:02 2006 => Total Deleted Objects: 0
Sat Dec 30 22:20:02 2006 => Total Errors: 7
Sat Dec 30 22:20:02 2006 => Time Elapsed: 00:04:19
Sat Dec 30 22:20:02 2006 => Virus Database Date: 12/30/2006
Sat Dec 30 22:20:02 2006 => Virus Database Count: 255222

Sat Dec 30 22:20:02 2006 => Scan Completed.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Karrex a 124 hostů