Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:07:33, on 25.10.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Ad-Aware 2007\aawservice.exe
C:\Program Files\Avast4\aswUpdSv.exe
C:\Program Files\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag\bin\aDefragService.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag\bin\defragActivityMonitor.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avast4\ashMaiSv.exe
C:\Program Files\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\PROGRA~1\Avast4\ashDisp.exe
C:\Program Files\SensorsView\sview.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Comodo\Firewall\CPF.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\uTorrent\utorrent.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Launchy\Launchy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://ask.askredir.com/search/cfg_redi ... com/web&q=%s&l=dis&o=13010
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Zástupce stránky vlastností sběrnice High Definition Audio] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SensorsView] C:\Program Files\SensorsView\sview.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\utorrent.exe"
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Zástupce - aDefragCtrl.lnk = C:\Program Files\Ashampoo\Ashampoo Magical Defrag\bin\aDefragCtrl.exe
O4 - Startup: Zástupce - Launchy.lnk = C:\Program Files\Launchy\Launchy.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout Free Download Managerem - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Stáhnout vybrané Free Download Managerem - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Stáhnout vše Free Download Managerem - file://C:\Program Files\Free Download Manager\dlall.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Ad-Aware 2007\aawservice.exe
O23 - Service: AshampooDefragService - - C:\Program Files\Ashampoo\Ashampoo Magical Defrag\bin\aDefragService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: GoogleDesktopManager - Unknown owner - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\WINDOWS\system32\sfrem01.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
--
End of file - 9649 bytes
Prosím o kotrolu logu - pomalý náběh PC
- Baron Prášil
- Master Level 7
- Příspěvky: 4882
- Registrován: červen 06
- Pohlaví:
- Stav:
Offline
log je naprosto v pořádku.
vyčisti systém CCleanerem a RegCleanerem
defragmentuj,pokud to bude třeba
třeba tímto O&O Defrag 2000
když to nezabere udělej log z MWAV
vyčisti systém CCleanerem a RegCleanerem
defragmentuj,pokud to bude třeba
třeba tímto O&O Defrag 2000
když to nezabere udělej log z MWAV
MWAV
Thu Oct 25 14:38:27 2007 => **********************************************************
Thu Oct 25 14:38:27 2007 => MicroWorld Anti Virus & Spyware Toolkit Utility.
Thu Oct 25 14:38:27 2007 => Copyright © MicroWorld
Thu Oct 25 14:38:27 2007 => **********************************************************
Thu Oct 25 14:38:27 2007 => Source: D:\STAHOV~1\mwav.exe
Thu Oct 25 14:38:27 2007 => Version 9.4.9 (C:\DOCUME~1\ROMA~1\LOCALS~1\Temp\mexe.com)
Thu Oct 25 14:38:27 2007 => Log File: C:\DOCUME~1\ROMA~1\LOCALS~1\Temp\MWAV.LOG
Thu Oct 25 14:38:27 2007 => MWAV Registered: FALSE.
Thu Oct 25 14:38:27 2007 => User Account: Romča (Administrator Mode)
Thu Oct 25 14:38:27 2007 => OS Type: Windows Workstation
Thu Oct 25 14:38:27 2007 => OS: Windows XP
Thu Oct 25 14:38:27 2007 => Ver: Service Pack 2 (Build 2600)
Thu Oct 25 14:38:27 2007 => Windows Root Folder: C:\WINDOWS
Thu Oct 25 14:38:27 2007 => Windows Sys32 Folder: C:\WINDOWS\system32
Thu Oct 25 14:38:27 2007 => DHCP NameServer: 213.46.172.36 213.46.172.37
Thu Oct 25 14:38:27 2007 => Interface0 DHCPNameServer: 213.46.172.36 213.46.172.37
Thu Oct 25 14:38:27 2007 => Local Fixed Drives: c:\,d:\
Thu Oct 25 14:38:27 2007 => MWAV Mode: Only Scan files.
Thu Oct 25 14:38:27 2007 => ********** Files created/modified during last fortnight in Windows Folder **********
Thu Oct 25 14:38:28 2007 => C:\WINDOWS\NeroDigital.ini (116), 20-Oct-2007
Thu Oct 25 14:38:28 2007 => C:\WINDOWS\Setup1.exe (249856), 20-Oct-2007, Microsoft Corporation, Visual Basic
Thu Oct 25 14:38:28 2007 => C:\WINDOWS\ST6UNST.EXE (73216), 20-Oct-2007, Microsoft Corporation, Microsoft® Visual Basic for Windows
Thu Oct 25 14:38:28 2007 => C:\WINDOWS\system.ini (827), 17-Oct-2007
Thu Oct 25 14:38:28 2007 => C:\WINDOWS\tbub.ini (52), 25-Oct-2007
Thu Oct 25 14:38:28 2007 => C:\WINDOWS\win.ini (803), 25-Oct-2007
Thu Oct 25 14:38:28 2007 => C:\WINDOWS\system32\PerfStringBackup.INI (1018134), 19-Oct-2007
Thu Oct 25 14:38:28 2007 => C:\WINDOWS\system32\SpOrder.dll (11264), 17-Oct-2007, Microsoft Corporation, Microsoft(R) Windows NT(TM) Operating System
Thu Oct 25 14:38:28 2007 => ************************************************************************************
Thu Oct 25 14:38:28 2007 => Latest Date of files inside MWAV: 24 Oct 2007 08:38:1.
Thu Oct 25 14:38:39 2007 => AV Library Loaded...
Thu Oct 25 14:38:39 2007 => MWAV doing self scanning...
Thu Oct 25 14:38:39 2007 => Scanning File C:\DOCUME~1\ROMA~1\LOCALS~1\Temp\getvlist.exe
Thu Oct 25 14:38:39 2007 => Scanning File C:\DOCUME~1\ROMA~1\LOCALS~1\Temp\main.avi
Thu Oct 25 14:38:39 2007 => Scanning File C:\DOCUME~1\ROMA~1\LOCALS~1\Temp\virus.avi
Thu Oct 25 14:38:39 2007 => Scanning File C:\DOCUME~1\ROMA~1\LOCALS~1\Temp\ScanningProcess.exe
Thu Oct 25 14:38:39 2007 => Scanning File C:\DOCUME~1\ROMA~1\LOCALS~1\Temp\kave.dll
Thu Oct 25 14:38:39 2007 => Scanning File C:\DOCUME~1\ROMA~1\LOCALS~1\Temp\prloader.dll
Thu Oct 25 14:38:39 2007 => MWAV files are clean.
Thu Oct 25 14:38:50 2007 => Datum vydání databáze: 10/24/2007
Thu Oct 25 14:38:50 2007 => Verze virové databáze: 443589
Thu Oct 25 14:40:09 2007 => Generování virus listu... getvlist.exe C:\DOCUME~1\ROMA~1\LOCALS~1\Temp\vlist.txt
Thu Oct 25 14:38:27 2007 => MicroWorld Anti Virus & Spyware Toolkit Utility.
Thu Oct 25 14:38:27 2007 => Copyright © MicroWorld
Thu Oct 25 14:38:27 2007 => **********************************************************
Thu Oct 25 14:38:27 2007 => Source: D:\STAHOV~1\mwav.exe
Thu Oct 25 14:38:27 2007 => Version 9.4.9 (C:\DOCUME~1\ROMA~1\LOCALS~1\Temp\mexe.com)
Thu Oct 25 14:38:27 2007 => Log File: C:\DOCUME~1\ROMA~1\LOCALS~1\Temp\MWAV.LOG
Thu Oct 25 14:38:27 2007 => MWAV Registered: FALSE.
Thu Oct 25 14:38:27 2007 => User Account: Romča (Administrator Mode)
Thu Oct 25 14:38:27 2007 => OS Type: Windows Workstation
Thu Oct 25 14:38:27 2007 => OS: Windows XP
Thu Oct 25 14:38:27 2007 => Ver: Service Pack 2 (Build 2600)
Thu Oct 25 14:38:27 2007 => Windows Root Folder: C:\WINDOWS
Thu Oct 25 14:38:27 2007 => Windows Sys32 Folder: C:\WINDOWS\system32
Thu Oct 25 14:38:27 2007 => DHCP NameServer: 213.46.172.36 213.46.172.37
Thu Oct 25 14:38:27 2007 => Interface0 DHCPNameServer: 213.46.172.36 213.46.172.37
Thu Oct 25 14:38:27 2007 => Local Fixed Drives: c:\,d:\
Thu Oct 25 14:38:27 2007 => MWAV Mode: Only Scan files.
Thu Oct 25 14:38:27 2007 => ********** Files created/modified during last fortnight in Windows Folder **********
Thu Oct 25 14:38:28 2007 => C:\WINDOWS\NeroDigital.ini (116), 20-Oct-2007
Thu Oct 25 14:38:28 2007 => C:\WINDOWS\Setup1.exe (249856), 20-Oct-2007, Microsoft Corporation, Visual Basic
Thu Oct 25 14:38:28 2007 => C:\WINDOWS\ST6UNST.EXE (73216), 20-Oct-2007, Microsoft Corporation, Microsoft® Visual Basic for Windows
Thu Oct 25 14:38:28 2007 => C:\WINDOWS\system.ini (827), 17-Oct-2007
Thu Oct 25 14:38:28 2007 => C:\WINDOWS\tbub.ini (52), 25-Oct-2007
Thu Oct 25 14:38:28 2007 => C:\WINDOWS\win.ini (803), 25-Oct-2007
Thu Oct 25 14:38:28 2007 => C:\WINDOWS\system32\PerfStringBackup.INI (1018134), 19-Oct-2007
Thu Oct 25 14:38:28 2007 => C:\WINDOWS\system32\SpOrder.dll (11264), 17-Oct-2007, Microsoft Corporation, Microsoft(R) Windows NT(TM) Operating System
Thu Oct 25 14:38:28 2007 => ************************************************************************************
Thu Oct 25 14:38:28 2007 => Latest Date of files inside MWAV: 24 Oct 2007 08:38:1.
Thu Oct 25 14:38:39 2007 => AV Library Loaded...
Thu Oct 25 14:38:39 2007 => MWAV doing self scanning...
Thu Oct 25 14:38:39 2007 => Scanning File C:\DOCUME~1\ROMA~1\LOCALS~1\Temp\getvlist.exe
Thu Oct 25 14:38:39 2007 => Scanning File C:\DOCUME~1\ROMA~1\LOCALS~1\Temp\main.avi
Thu Oct 25 14:38:39 2007 => Scanning File C:\DOCUME~1\ROMA~1\LOCALS~1\Temp\virus.avi
Thu Oct 25 14:38:39 2007 => Scanning File C:\DOCUME~1\ROMA~1\LOCALS~1\Temp\ScanningProcess.exe
Thu Oct 25 14:38:39 2007 => Scanning File C:\DOCUME~1\ROMA~1\LOCALS~1\Temp\kave.dll
Thu Oct 25 14:38:39 2007 => Scanning File C:\DOCUME~1\ROMA~1\LOCALS~1\Temp\prloader.dll
Thu Oct 25 14:38:39 2007 => MWAV files are clean.
Thu Oct 25 14:38:50 2007 => Datum vydání databáze: 10/24/2007
Thu Oct 25 14:38:50 2007 => Verze virové databáze: 443589
Thu Oct 25 14:40:09 2007 => Generování virus listu... getvlist.exe C:\DOCUME~1\ROMA~1\LOCALS~1\Temp\vlist.txt
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 117 hostů