Ahoj, prosím o kontrolu logu... pocitac se mi pravidelne restartuje bez varovani v intervalech tak 2-3 minut, tak si rikam, ze jsem byl necim napaden...
diky
Logfile of HijackThis v1.99.1
Scan saved at 15:27:14, on 15.6.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\HiJackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = devetsil.vse.cz:5555
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Hgni_BHO - {888826A1-3C63-4687-8696-482FDBB129DF} - C:\WINDOWS\system32\hgni_ecol.dll
O3 - Toolbar: (no name) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ICQ Lite] "C:\Program Files\ICQLite\ICQLite.exe" -minimize
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
Prosím o kontrolu logu, dekuji
- Baron Prášil
- Master Level 7
- Příspěvky: 4882
- Registrován: červen 06
- Pohlaví:
- Stav:
Offline
nainstaluj
FIREWALL
vyber si tady,doporučuju Comodo
ANTISPYWARE
doporučuju Spybot S&D nebo Spyware Terminator
fixni
v okně programu HJT zaškrtni nalevo u položek co napíšu a potom klik na Fix checked
O2 - BHO: Hgni_BHO - {888826A1-3C63-4687-8696-482FDBB129DF} - C:\WINDOWS\system32\hgni_ecol.dll
O3 - Toolbar: (no name) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
tučně označenej smaž
FIREWALL
vyber si tady,doporučuju Comodo
ANTISPYWARE
doporučuju Spybot S&D nebo Spyware Terminator
fixni
v okně programu HJT zaškrtni nalevo u položek co napíšu a potom klik na Fix checked
O2 - BHO: Hgni_BHO - {888826A1-3C63-4687-8696-482FDBB129DF} - C:\WINDOWS\system32\hgni_ecol.dll
O3 - Toolbar: (no name) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
tučně označenej smaž
Pocitac se restartuje...
Tak vybrane problemy jsem odstranil... nicmene pocitac se mi neustale tak po dvou minutach restartuje... nesetkal jsi se s tim nekdy? Podotykam, ze bez jakekoliv hlasky... proste se jen tak restartne!
dik
j
dik
j
- Baron Prášil
- Master Level 7
- Příspěvky: 4882
- Registrován: červen 06
- Pohlaví:
- Stav:
Offline
zastav restarty takto
1. Pravym tlacitkem na Tento pocitac a Vlastnosti.
2. Zalozka Upresnit.
3. V casti Spusteni a zotaveni systemu tlacitko Nastaveni.
4. Zruste zaskrtnuti u polozky Automaticky restartovat
udělej log z MWAV
a pošli log z hijackthis
1. Pravym tlacitkem na Tento pocitac a Vlastnosti.
2. Zalozka Upresnit.
3. V casti Spusteni a zotaveni systemu tlacitko Nastaveni.
4. Zruste zaskrtnuti u polozky Automaticky restartovat
udělej log z MWAV
a pošli log z hijackthis
Restart počítače podruhe....
Ahoj,
tak jsem udelal, jak jsi rikal... pocitac se nerestartoval, ale nahodila se modra obrazovka! Vetsina veci, o kterych se tam psalo se tocilo kolem pameti... tak jsem neco smazal, aby tam bylo vic mista....
ale stejne nic.... tak jsem spustil pocitac v nouzovem rezimu...
Prikladam log z HiJackThis - ten je jeste za stavu pred nouzovim rezimeme:
Logfile of HijackThis v1.99.1
Scan saved at 23:11:30, on 18.6.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HiJackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = devetsil.vse.cz:5555
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ICQ Lite] "C:\Program Files\ICQLite\ICQLite.exe" -minimize
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
A potom log z MWAV ten je ve stavu nouze - naslo to tohle:
Mon Jun 18 23:19:05 2007 => **********************************************************
Mon Jun 18 23:19:05 2007 => MicroWorld Anti Virus & Spyware Toolkit Utility.
Mon Jun 18 23:19:05 2007 => Copyright © 2003-2006, MicroWorld Technologies Inc.
Mon Jun 18 23:19:05 2007 => **********************************************************
Mon Jun 18 23:19:05 2007 => Source: G:\Software\Antiviry\placene\mwav.exe
Mon Jun 18 23:19:05 2007 => Version 9.2.2 (C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mexe.com)
Mon Jun 18 23:19:05 2007 => Log File: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\MWAV.LOG
Mon Jun 18 23:19:05 2007 => Last Scan Date and Time: 17.06.2007 21:32:14
Mon Jun 18 23:19:05 2007 => MWAV Registered: FALSE.
Mon Jun 18 23:19:05 2007 => User Account: Administrator
Mon Jun 18 23:19:05 2007 => OS Type: Windows Workstation
Mon Jun 18 23:19:05 2007 => OS: Windows XP
Mon Jun 18 23:19:05 2007 => Ver: Service Pack 2 (Build 2600)
Mon Jun 18 23:19:05 2007 => Windows Root Folder: C:\WINDOWS
Mon Jun 18 23:19:05 2007 => Windows Sys32 Folder: C:\WINDOWS\system32
Mon Jun 18 23:19:05 2007 => Local Fixed Drives: c:\,f:\,g:\
Mon Jun 18 23:19:05 2007 => MWAV Mode: Only Scan files.
Mon Jun 18 23:19:05 2007 => Latest Date of files inside MWAV: 10 May 2007 18:16:1.
Mon Jun 18 23:19:10 2007 => AV Library Loaded...
Mon Jun 18 23:19:10 2007 => MWAV doing self scanning...
Mon Jun 18 23:19:10 2007 => Scanning File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\getvlist.exe
Mon Jun 18 23:19:10 2007 => Scanning File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\main.avi
Mon Jun 18 23:19:10 2007 => Scanning File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\virus.avi
Mon Jun 18 23:19:10 2007 => Scanning File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ScanningProcess.exe
Mon Jun 18 23:19:10 2007 => Scanning File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\kave.dll
Mon Jun 18 23:19:10 2007 => Scanning File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\msvl64.dll
Mon Jun 18 23:19:10 2007 => Scanning File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\prloader.dll
Mon Jun 18 23:19:10 2007 => MWAV files are clean.
Mon Jun 18 23:19:10 2007 => Virus Database Date: 5/10/2007
Mon Jun 18 23:19:10 2007 => Virus Database Count: 316304
Mon Jun 18 23:19:29 2007 => **********************************************************
Mon Jun 18 23:19:29 2007 => MicroWorld Anti Virus & Spyware Toolkit Utility.
Mon Jun 18 23:19:29 2007 => Copyright © 2003-2006, MicroWorld Technologies Inc.
Mon Jun 18 23:19:29 2007 =>
Mon Jun 18 23:19:29 2007 => Support: support@mwti.net
Mon Jun 18 23:19:29 2007 => Web: http://www.mwti.net
Mon Jun 18 23:19:29 2007 => **********************************************************
Mon Jun 18 23:19:29 2007 => Version 9.2.2 (C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mexe.com)
Mon Jun 18 23:19:29 2007 => Log File: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\MWAV.LOG
Mon Jun 18 23:19:29 2007 => User Account: Administrator
Mon Jun 18 23:19:29 2007 => Windows Root Folder: C:\WINDOWS
Mon Jun 18 23:19:29 2007 => Windows Sys32 Folder: C:\WINDOWS\system32
Mon Jun 18 23:19:29 2007 => OS: Windows XP
Mon Jun 18 23:19:29 2007 => Ver: Service Pack 2 (Build 2600)
Mon Jun 18 23:19:29 2007 => Latest Date of files inside MWAV: 10 May 2007 18:16:1.
Mon Jun 18 23:19:29 2007 => Options Selected by User:
Mon Jun 18 23:19:29 2007 => Memory Check: Enabled
Mon Jun 18 23:19:29 2007 => Registry Check: Enabled
Mon Jun 18 23:19:29 2007 => StartUp Folder Check: Enabled
Mon Jun 18 23:19:29 2007 => System Folder Check: Enabled
Mon Jun 18 23:19:29 2007 => System Area Check: Disabled
Mon Jun 18 23:19:29 2007 => Services Check: Enabled
Mon Jun 18 23:19:29 2007 => Drive Check Option Disabled
Mon Jun 18 23:19:29 2007 => Folder Check: Disabled
Mon Jun 18 23:19:50 2007 => Scanning File C:\PROGRA~1\WinRAR\rarext.dll
Mon Jun 18 23:19:50 2007 => ERROR!!! ScanFile Fails...
Mon Jun 18 23:19:53 2007 => ERROR!!! Invalid Entry NeroHomeFirstStart = C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe (in key SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce). No Action Taken.
Mon Jun 18 23:20:06 2007 => Offending Key found: HKLM\Software\magnet !!!
Mon Jun 18 23:20:07 2007 => Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken.
Mon Jun 18 23:20:07 2007 => Offending Key found: HKCU\\magnet !!!
Mon Jun 18 23:20:07 2007 => Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken.
Mon Jun 18 23:21:32 2007 => ***** Scanning complete. *****
Mon Jun 18 23:21:32 2007 => Total Objects Scanned: 25330
Mon Jun 18 23:21:32 2007 => Total Critical Objects: 2
Mon Jun 18 23:21:32 2007 => Total Disinfected Objects: 0
Mon Jun 18 23:21:32 2007 => Total Objects Renamed: 0
Mon Jun 18 23:21:32 2007 => Total Deleted Objects: 0
Mon Jun 18 23:21:32 2007 => Total Errors: 2
Mon Jun 18 23:21:32 2007 => Time Elapsed: 00:02:02
Mon Jun 18 23:21:32 2007 => Virus Database Date: 5/10/2007
Mon Jun 18 23:21:32 2007 => Virus Database Count: 316304
Mon Jun 18 23:21:32 2007 => Scan Completed.
tak jsem udelal, jak jsi rikal... pocitac se nerestartoval, ale nahodila se modra obrazovka! Vetsina veci, o kterych se tam psalo se tocilo kolem pameti... tak jsem neco smazal, aby tam bylo vic mista....
ale stejne nic.... tak jsem spustil pocitac v nouzovem rezimu...
Prikladam log z HiJackThis - ten je jeste za stavu pred nouzovim rezimeme:
Logfile of HijackThis v1.99.1
Scan saved at 23:11:30, on 18.6.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HiJackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = devetsil.vse.cz:5555
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ICQ Lite] "C:\Program Files\ICQLite\ICQLite.exe" -minimize
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
A potom log z MWAV ten je ve stavu nouze - naslo to tohle:
Mon Jun 18 23:19:05 2007 => **********************************************************
Mon Jun 18 23:19:05 2007 => MicroWorld Anti Virus & Spyware Toolkit Utility.
Mon Jun 18 23:19:05 2007 => Copyright © 2003-2006, MicroWorld Technologies Inc.
Mon Jun 18 23:19:05 2007 => **********************************************************
Mon Jun 18 23:19:05 2007 => Source: G:\Software\Antiviry\placene\mwav.exe
Mon Jun 18 23:19:05 2007 => Version 9.2.2 (C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mexe.com)
Mon Jun 18 23:19:05 2007 => Log File: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\MWAV.LOG
Mon Jun 18 23:19:05 2007 => Last Scan Date and Time: 17.06.2007 21:32:14
Mon Jun 18 23:19:05 2007 => MWAV Registered: FALSE.
Mon Jun 18 23:19:05 2007 => User Account: Administrator
Mon Jun 18 23:19:05 2007 => OS Type: Windows Workstation
Mon Jun 18 23:19:05 2007 => OS: Windows XP
Mon Jun 18 23:19:05 2007 => Ver: Service Pack 2 (Build 2600)
Mon Jun 18 23:19:05 2007 => Windows Root Folder: C:\WINDOWS
Mon Jun 18 23:19:05 2007 => Windows Sys32 Folder: C:\WINDOWS\system32
Mon Jun 18 23:19:05 2007 => Local Fixed Drives: c:\,f:\,g:\
Mon Jun 18 23:19:05 2007 => MWAV Mode: Only Scan files.
Mon Jun 18 23:19:05 2007 => Latest Date of files inside MWAV: 10 May 2007 18:16:1.
Mon Jun 18 23:19:10 2007 => AV Library Loaded...
Mon Jun 18 23:19:10 2007 => MWAV doing self scanning...
Mon Jun 18 23:19:10 2007 => Scanning File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\getvlist.exe
Mon Jun 18 23:19:10 2007 => Scanning File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\main.avi
Mon Jun 18 23:19:10 2007 => Scanning File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\virus.avi
Mon Jun 18 23:19:10 2007 => Scanning File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ScanningProcess.exe
Mon Jun 18 23:19:10 2007 => Scanning File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\kave.dll
Mon Jun 18 23:19:10 2007 => Scanning File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\msvl64.dll
Mon Jun 18 23:19:10 2007 => Scanning File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\prloader.dll
Mon Jun 18 23:19:10 2007 => MWAV files are clean.
Mon Jun 18 23:19:10 2007 => Virus Database Date: 5/10/2007
Mon Jun 18 23:19:10 2007 => Virus Database Count: 316304
Mon Jun 18 23:19:29 2007 => **********************************************************
Mon Jun 18 23:19:29 2007 => MicroWorld Anti Virus & Spyware Toolkit Utility.
Mon Jun 18 23:19:29 2007 => Copyright © 2003-2006, MicroWorld Technologies Inc.
Mon Jun 18 23:19:29 2007 =>
Mon Jun 18 23:19:29 2007 => Support: support@mwti.net
Mon Jun 18 23:19:29 2007 => Web: http://www.mwti.net
Mon Jun 18 23:19:29 2007 => **********************************************************
Mon Jun 18 23:19:29 2007 => Version 9.2.2 (C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mexe.com)
Mon Jun 18 23:19:29 2007 => Log File: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\MWAV.LOG
Mon Jun 18 23:19:29 2007 => User Account: Administrator
Mon Jun 18 23:19:29 2007 => Windows Root Folder: C:\WINDOWS
Mon Jun 18 23:19:29 2007 => Windows Sys32 Folder: C:\WINDOWS\system32
Mon Jun 18 23:19:29 2007 => OS: Windows XP
Mon Jun 18 23:19:29 2007 => Ver: Service Pack 2 (Build 2600)
Mon Jun 18 23:19:29 2007 => Latest Date of files inside MWAV: 10 May 2007 18:16:1.
Mon Jun 18 23:19:29 2007 => Options Selected by User:
Mon Jun 18 23:19:29 2007 => Memory Check: Enabled
Mon Jun 18 23:19:29 2007 => Registry Check: Enabled
Mon Jun 18 23:19:29 2007 => StartUp Folder Check: Enabled
Mon Jun 18 23:19:29 2007 => System Folder Check: Enabled
Mon Jun 18 23:19:29 2007 => System Area Check: Disabled
Mon Jun 18 23:19:29 2007 => Services Check: Enabled
Mon Jun 18 23:19:29 2007 => Drive Check Option Disabled
Mon Jun 18 23:19:29 2007 => Folder Check: Disabled
Mon Jun 18 23:19:50 2007 => Scanning File C:\PROGRA~1\WinRAR\rarext.dll
Mon Jun 18 23:19:50 2007 => ERROR!!! ScanFile Fails...
Mon Jun 18 23:19:53 2007 => ERROR!!! Invalid Entry NeroHomeFirstStart = C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe (in key SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce). No Action Taken.
Mon Jun 18 23:20:06 2007 => Offending Key found: HKLM\Software\magnet !!!
Mon Jun 18 23:20:07 2007 => Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken.
Mon Jun 18 23:20:07 2007 => Offending Key found: HKCU\\magnet !!!
Mon Jun 18 23:20:07 2007 => Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken.
Mon Jun 18 23:21:32 2007 => ***** Scanning complete. *****
Mon Jun 18 23:21:32 2007 => Total Objects Scanned: 25330
Mon Jun 18 23:21:32 2007 => Total Critical Objects: 2
Mon Jun 18 23:21:32 2007 => Total Disinfected Objects: 0
Mon Jun 18 23:21:32 2007 => Total Objects Renamed: 0
Mon Jun 18 23:21:32 2007 => Total Deleted Objects: 0
Mon Jun 18 23:21:32 2007 => Total Errors: 2
Mon Jun 18 23:21:32 2007 => Time Elapsed: 00:02:02
Mon Jun 18 23:21:32 2007 => Virus Database Date: 5/10/2007
Mon Jun 18 23:21:32 2007 => Virus Database Count: 316304
Mon Jun 18 23:21:32 2007 => Scan Completed.
- Baron Prášil
- Master Level 7
- Příspěvky: 4882
- Registrován: červen 06
- Pohlaví:
- Stav:
Offline
nálezy mwavu nestojej za řeč.
v hijackthis můžeš fixnout zbytečnosti
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
dam svůj zaPrášenej krk na to,že je problém v ram paměti (tak už nic nemaž
)
je třeba opsat text z modré obrazovky.pokud je tam krátce,tak ofotit. a poslat sem.
ale ne do sekce Hijackthis.do sekce Problémy s hardwarem
a až to vyřešíš tak nezapomeň na ten firewall a antispy.
v hijackthis můžeš fixnout zbytečnosti
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
dam svůj zaPrášenej krk na to,že je problém v ram paměti (tak už nic nemaž

je třeba opsat text z modré obrazovky.pokud je tam krátce,tak ofotit. a poslat sem.
ale ne do sekce Hijackthis.do sekce Problémy s hardwarem
a až to vyřešíš tak nezapomeň na ten firewall a antispy.
- Baron Prášil
- Master Level 7
- Příspěvky: 4882
- Registrován: červen 06
- Pohlaví:
- Stav:
Offline
antispam není antispyware. nahoře jsem doporučil. jinak-hodně štěstí v hardwareové sekci.
pak to tady můžeš klidně oživit a pořešíme to zabezpečení
a nemáš zač
//takže problémem byl rootkit a pokračování sem připojil ze sekce Problémy s hardwarem
pak to tady můžeš klidně oživit a pořešíme to zabezpečení

a nemáš zač

//takže problémem byl rootkit a pokračování sem připojil ze sekce Problémy s hardwarem
Naposledy upravil(a) Baron Prášil dne 19 čer 2007 01:47, celkem upraveno 1 x.
Pocitac se neustale vypina...
Ahoj,
problem zacal tim, ze se pocitac neustale restartoval... tak jsem postupoval takto (postup mam z jine sekce pc-helpu:):
1. tento pocitac
2. zalozka upresnit
3. Tlacitko nastaveni
4. Odfajfkovat automaticky restartovat
Po tomto procesu se pocitac prestar v pravidelnych intervalech restartovat, nicmene se po chvilce provozu objevi modra obrazovka, kde je napsano zhruba:
Byly zjisteny potize a system byl ukoncen....
pokud je to poprve....
Zkontrolujte, zda mate dostatek mista na disku - MAM!
Pokud je v koncove zprave urcen ovladac, ovladac zakazte nebo se obratne na dodavatele ovladace a vyzadejte si jeho posledni verzi. Zkuzte zmenit videoadaptery. a pak neco o BIOSU.
Technicke info:
*** STOP: 0x0000008E (0x0000005, 0xB2FF15A3, 0xF8B2CA20, 0x00000000)
*** system32:lzx32.sys - address B2FF15A3 base at B2FEF000, DateStamp 46532710
Zahajovani vypisu fyzicke pameti RAm
vypis fyzicke pameti je dokoncen
Pozadejte o pomoc spravce systemu nebo skupinu technicke podpory...
To je vse, vi si nekdo rady?
diky moc
problem zacal tim, ze se pocitac neustale restartoval... tak jsem postupoval takto (postup mam z jine sekce pc-helpu:):
1. tento pocitac
2. zalozka upresnit
3. Tlacitko nastaveni
4. Odfajfkovat automaticky restartovat
Po tomto procesu se pocitac prestar v pravidelnych intervalech restartovat, nicmene se po chvilce provozu objevi modra obrazovka, kde je napsano zhruba:
Byly zjisteny potize a system byl ukoncen....
pokud je to poprve....
Zkontrolujte, zda mate dostatek mista na disku - MAM!
Pokud je v koncove zprave urcen ovladac, ovladac zakazte nebo se obratne na dodavatele ovladace a vyzadejte si jeho posledni verzi. Zkuzte zmenit videoadaptery. a pak neco o BIOSU.
Technicke info:
*** STOP: 0x0000008E (0x0000005, 0xB2FF15A3, 0xF8B2CA20, 0x00000000)
*** system32:lzx32.sys - address B2FF15A3 base at B2FEF000, DateStamp 46532710
Zahajovani vypisu fyzicke pameti RAm
vypis fyzicke pameti je dokoncen
Pozadejte o pomoc spravce systemu nebo skupinu technicke podpory...
To je vse, vi si nekdo rady?
diky moc
- Baron Prášil
- Master Level 7
- Příspěvky: 4882
- Registrován: červen 06
- Pohlaví:
- Stav:
Offline
aha.je to asi rootkit.
tady fredikův návod
Použij tento program ten by to měl odstranit:
Stáhni si tento program:
http://www.uploads.ejvindh.net/rustbfix.exe
Spusť ho, pokud program virus najde, odstraní jej a následně vytvoří soubor C:\rustbfis\pelog.txt -vlož sem jeho obsah
Bude chtít pravděpodobně restart, ten může chvíli trvat a možná bude potřeba restartovat ještě jednou ale to by se mělo stát automaticky.
tady fredikův návod
Použij tento program ten by to měl odstranit:
Stáhni si tento program:
http://www.uploads.ejvindh.net/rustbfix.exe
Spusť ho, pokud program virus najde, odstraní jej a následně vytvoří soubor C:\rustbfis\pelog.txt -vlož sem jeho obsah
Bude chtít pravděpodobně restart, ten může chvíli trvat a možná bude potřeba restartovat ještě jednou ale to by se mělo stát automaticky.
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 105 hostů