Prosím o kontrolu logu - problém s google Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaojao
Level 5.5
Level 5.5
Příspěvky: 2600
Registrován: srpen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu - problém s google

Příspěvekod jaojao » 19 říj 2010 14:01

tu je ten původní:
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
Service HidServ stopped successfully!
Service HidServ deleted successfully!
File C:\WINDOWS\System32\hidserv.dll File not found not found.
Service axvodka stopped successfully!
Service axvodka deleted successfully!
File C:\WINDOWS\System32\DRIVERS\axvodka.sys File not found not found.
Service axvdkbus stopped successfully!
Service axvdkbus deleted successfully!
File C:\WINDOWS\System32\DRIVERS\axvdkbus.sys File not found not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Security Risk Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\CustomizeSearch| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\Default_Search_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Search_URL| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
127.0.0.1 localhost removed from HOSTS file successfully
127.0.0.1 007guard.com removed from HOSTS file successfully
127.0.0.1 008i.com removed from HOSTS file successfully
127.0.0.1 008k.com removed from HOSTS file successfully
127.0.0.1 00hq.com removed from HOSTS file successfully
127.0.0.1 010402.com removed from HOSTS file successfully
127.0.0.1 032439.com removed from HOSTS file successfully
127.0.0.1 0scan.com removed from HOSTS file successfully
127.0.0.1 1000gratisproben.com removed from HOSTS file successfully
127.0.0.1 1001namen.com removed from HOSTS file successfully
127.0.0.1 100888290cs.com removed from HOSTS file successfully
127.0.0.1 100sexlinks.com removed from HOSTS file successfully
127.0.0.1 10sek.com removed from HOSTS file successfully
127.0.0.1 1-2005-search.com removed from HOSTS file successfully
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ipp\ deleted successfully.
File Protocol\Handler\ipp - No CLSID value found not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\ deleted successfully.
File Protocol\Handler\msdaipp - No CLSID value found not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{56d61f00-7e42-11df-b226-0016e6ddea99}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56d61f00-7e42-11df-b226-0016e6ddea99}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session manager\\BootExecute:autocheck autochk * deleted successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:C31F31E6 deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\System32\*.tmp not found.
C:\WINDOWS\SET25.tmp moved successfully.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
c:\windows\Tasks\SmartDefrag.job moved successfully.
File\Folder C:\*.tmp not found.
File\Folder C:\WINDOWS\System32\VCCLSID.exe not found.
C:\WINDOWS\System32\SrchSTS.exe moved successfully.
File\Folder C:\WINDOWS\System32\swreg.exe not found.
File\Folder C:\WINDOWS\System32\swxcacls.exe not found.
C:\WINDOWS\System32\Agent.OMZ.Fix.exe moved successfully.
File\Folder C:\WINDOWS\System32\VACFix.exe not found.
File\Folder C:\WINDOWS\System32\IEDFix.exe not found.
File\Folder C:\WINDOWS\System32\IEDFix.C.exe not found.
File\Folder C:\WINDOWS\System32\404Fix.exe not found.
C:\WINDOWS\System32\o4Patch.exe moved successfully.
C:\WINDOWS\System32\Process.exe moved successfully.
File\Folder C:\WINDOWS\System32\tmp.reg not found.
C:\WINDOWS\System32\drivers\etc\hosts.20101014-103255.backup moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20101010-193638.backup moved successfully.
C:\WINDOWS\System32\perfh009.dat moved successfully.
C:\WINDOWS\System32\perfh005.dat moved successfully.
C:\WINDOWS\System32\perfc005.dat moved successfully.
C:\WINDOWS\System32\perfc009.dat moved successfully.
C:\Documents and Settings\All Users\Data aplikací\KGyGaAvL.sys moved successfully.
C:\Documents and Settings\All Users\Data aplikací\4290E65C95.sys moved successfully.
C:\WINDOWS\System32\drivers\etc\hosts.20101005-085140.backup moved successfully.
File\Folder C:\WINDOWS\System32\WS2Fix.exe not found.
File\Folder C:\WINDOWS\System32\dumphive.exe not found.
File\Folder C:\Documents and Settings\XXXXXX\Data aplikací\inst.exe not found.
C:\WINDOWS\System32\KGyGaAvL.sys moved successfully.
========== REGISTRY ==========
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 204800 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Horák
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 114822 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 71087984 bytes
->Flash cache emptied: 511 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 12799194 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 81,00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User

User: Horák
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.15.2 log created on 10192010_131714

Files\Folders moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...
Intel > nvidia > WD > Kingston > Seasonic > LG > XP <<< takhle nějak :) a zde např.: https://1url.cz/iriwZ (ta dívka tam to je dcera )

Reklama
Uživatelský avatar
jaojao
Level 5.5
Level 5.5
Příspěvky: 2600
Registrován: srpen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu - problém s google

Příspěvekod jaojao » 19 říj 2010 14:02

A tady ten nový:
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
Process firefox.exe killed successfully!
Error: No service named HidServ was found to stop!
Service\Driver key HidServ not found.
File C:\WINDOWS\System32\hidserv.dll File not found not found.
Error: No service named axvodka was found to stop!
Service\Driver key axvodka not found.
File C:\WINDOWS\System32\DRIVERS\axvodka.sys File not found not found.
Error: No service named axvdkbus was found to stop!
Service\Driver key axvdkbus not found.
File C:\WINDOWS\System32\DRIVERS\axvdkbus.sys File not found not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Security Risk Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\CustomizeSearch| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\Default_Search_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Search_URL| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
127.0.0.1 localhost removed from HOSTS file successfully
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ipp\ not found.
File Protocol\Handler\ipp - No CLSID value found not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\ not found.
File Protocol\Handler\msdaipp - No CLSID value found not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{56d61f00-7e42-11df-b226-0016e6ddea99}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56d61f00-7e42-11df-b226-0016e6ddea99}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session manager\\BootExecute:autocheck autochk * deleted successfully.
Unable to delete ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:C31F31E6 .
========== FILES ==========
File\Folder C:\WINDOWS\System32\*.tmp not found.
File\Folder C:\WINDOWS\*.tmp not found.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
File\Folder c:\windows\Tasks\*.job not found.
File\Folder C:\*.tmp not found.
File\Folder C:\WINDOWS\System32\VCCLSID.exe not found.
File\Folder C:\WINDOWS\System32\SrchSTS.exe not found.
File\Folder C:\WINDOWS\System32\swreg.exe not found.
File\Folder C:\WINDOWS\System32\swxcacls.exe not found.
File\Folder C:\WINDOWS\System32\Agent.OMZ.Fix.exe not found.
File\Folder C:\WINDOWS\System32\VACFix.exe not found.
File\Folder C:\WINDOWS\System32\IEDFix.exe not found.
File\Folder C:\WINDOWS\System32\IEDFix.C.exe not found.
File\Folder C:\WINDOWS\System32\404Fix.exe not found.
File\Folder C:\WINDOWS\System32\o4Patch.exe not found.
File\Folder C:\WINDOWS\System32\Process.exe not found.
File\Folder C:\WINDOWS\System32\tmp.reg not found.
File\Folder C:\WINDOWS\System32\drivers\etc\hosts.20101014-103255.backup not found.
File\Folder C:\WINDOWS\System32\drivers\etc\hosts.20101010-193638.backup not found.
File\Folder C:\WINDOWS\System32\perfh009.dat not found.
File\Folder C:\WINDOWS\System32\perfh005.dat not found.
File\Folder C:\WINDOWS\System32\perfc005.dat not found.
File\Folder C:\WINDOWS\System32\perfc009.dat not found.
File\Folder C:\Documents and Settings\All Users\Data aplikací\KGyGaAvL.sys not found.
File\Folder C:\Documents and Settings\All Users\Data aplikací\4290E65C95.sys not found.
File\Folder C:\WINDOWS\System32\drivers\etc\hosts.20101005-085140.backup not found.
File\Folder C:\WINDOWS\System32\WS2Fix.exe not found.
File\Folder C:\WINDOWS\System32\dumphive.exe not found.
C:\Documents and Settings\Horák\Data aplikací\inst.exe moved successfully.
File\Folder C:\WINDOWS\System32\KGyGaAvL.sys not found.
========== REGISTRY ==========
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Horák
->Temp folder emptied: 669065 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 33160778 bytes
->Flash cache emptied: 511 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 483 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 7154366 bytes

Total Files Cleaned = 39,00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User

User: Horák
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.15.2 log created on 10192010_135359

Files\Folders moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...
Intel > nvidia > WD > Kingston > Seasonic > LG > XP <<< takhle nějak :) a zde např.: https://1url.cz/iriwZ (ta dívka tam to je dcera )

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43297
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu - problém s google

Příspěvekod jaro3 » 19 říj 2010 19:38

Spusť OTL a klikni na Vyčisti.
Pak můžeš OTL smazat , C:\_OTL

Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
jaojao
Level 5.5
Level 5.5
Příspěvky: 2600
Registrován: srpen 07
Pohlaví: Nespecifikováno
Stav:
Offline

Re: Prosím o kontrolu logu - problém s google  Vyřešeno

Příspěvekod jaojao » 19 říj 2010 19:49

OK a díky .
Intel > nvidia > WD > Kingston > Seasonic > LG > XP <<< takhle nějak :) a zde např.: https://1url.cz/iriwZ (ta dívka tam to je dcera )


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 112 hostů