Stránka 1 z 9

worman (KONTROLA LOGOV) NOVÉ ..

Napsal: 28 pro 2006 08:30
od worman
Logfile of HijackThis v1.99.1
Scan saved at 8:13:54, on 28.12.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AOL\Active Virus Shield\avp.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\AOL\Active Virus Shield\avp.exe
C:\Program Files\AOL\Active Security Monitor\ASMonitor.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Hamachi\hamachi.exe
D:\Best Programs in PC\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [aol] "C:\Program Files\AOL\Active Virus Shield\avp.exe"
O4 - HKLM\..\Run: [ASM] "C:\Program Files\AOL\Active Security Monitor\ASMonitor.exe" HIDEMAIN
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O23 - Service: Active Virus Shield (AVP) - Unknown owner - C:\Program Files\AOL\Active Virus Shield\avp.exe" -r (file missing)
O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\Peko\LOCALS~1\Temp\hpdj.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: WinFast(R) Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

Napsal: 28 pro 2006 08:33
od Rudy
Ukončete v Taskmanageru a smažte:


C:\Program Files\AOL\Active Security Monitor\ASMonitor.exe

Fixněte v HijackThis:


O4 - HKLM\..\Run: [ASM] "C:\Program Files\AOL\Active Security Monitor\ASMonitor.exe" HIDEMAIN

Napsal: 28 pro 2006 10:16
od worman
Rudy píše:Ukončete v Taskmanageru a smažte:


C:\Program Files\AOL\Active Security Monitor\ASMonitor.exe

Fixněte v HijackThis:


O4 - HKLM\..\Run: [ASM] "C:\Program Files\AOL\Active Security Monitor\ASMonitor.exe" HIDEMAIN
Vsetkemu rozumiem len ten Active Monitor je na pixu? Preto ho mam dat prec? O tvojich vedomostiach nepochybujem :wink: idem na to :!:

Napsal: 28 pro 2006 10:20
od Rudy
ASMonitor je považován za Spyware: http://www.liutilities.com/products/win ... asmonitor/ .

Napsal: 28 pro 2006 10:22
od worman
Rudy píše:ASMonitor je považován za Spyware: http://www.liutilities.com/products/win ... asmonitor/ .
:shock: ooo tak toto si velmi vazim, vobec som o tom nevedel a ja ze co sa tak spomalil, moc dik :idea:

Napsal: 28 pro 2006 10:23
od Rudy
Není zač!

Napsal: 28 pro 2006 10:34
od worman
:arrow: Tak, snad je to uz dobre a mam este par otazok, nevadi? :oops:


Logfile of HijackThis v1.99.1
Scan saved at 10:33:58, on 28.12.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AOL\Active Virus Shield\avp.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\AOL\Active Virus Shield\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\Program Files\Winamp\winamp.exe
D:\Best Programs in PC\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [aol] "C:\Program Files\AOL\Active Virus Shield\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O23 - Service: Active Virus Shield (AVP) - Unknown owner - C:\Program Files\AOL\Active Virus Shield\avp.exe" -r (file missing)
O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\Peko\LOCALS~1\Temp\hpdj.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: WinFast(R) Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

Napsal: 28 pro 2006 10:40
od Rudy
Log vypadá čistý. Ptejte se.

Napsal: 28 pro 2006 10:55
od worman
:arrow: No najprv ma uz dlho trapia tie hnusne updaty s Microsoftu, mam ich vypnute ale ta ikonka pri hodinach sa mi nepaci ( myslim ten stit ) a vlastne ci su tie updaty potrebne alebo ich netreba vobec? :roll:
:arrow: Ja nemam spybot na spyware, staci mi CCleaner? :oops:
:arrow: Ako predidem chybnym hlaseniam a pomalosti PC? Moze byt za tym aj maticna? ("Nvidia nForce 4 MCP").
:arrow: Windows/ Temp v tej zlozke ak su nejake subory mozem ich mazat ? je to pravda ? A ak nejake nejdu Zmazat co potom?
:arrow: Mal som Nero 7 ale nejak som to zle odinstaloval a po kazdom zapnuti PC mi vyhodi 2 hlasenia ohladom NERO 7, neda sa odinstalovat a vymazat, ako s nim prec?
:arrow: Tiez mam hlasenia ActiveX a taketo kraviny :cry:
... viem som narocny, neviem asi najlepsi liek je reinstal XP ale ako potom NATO, aby TO BOLO DO BUDUCNA V PORIADKU?
:arrow: Este jedna otazocka, tvoj PC mas urcite dobre chraneny a perfektne fungujuci, co tam mas za programy, aby si bol so svojim PC spokojny ?
... ak teto otravne otazky uz nepatria do Logov co asi nie tak to nejak presun, ak to vadi :oops:

VOPRED VÁM, ĎAKUJEM :worship:

Napsal: 28 pro 2006 11:07
od Rudy
Sytémové záplaty jsou potřebné. Nejlepší je nastavit aut. aktualizaci.
CCleaner je čistič PC od balastu. Tudíž nechytá spyware. Nainstalujte atispy, což nemusí být Spybot. Optimální by byl asi SpyweraTerminator.
Chybovým hláškám nepředejdete, občas se stane, že některý sw zkolabuje. Pomalosti předejdete občasným čištěním od balastu a defragmentací disku.
Temp (obsah složky) můžete mazat celý.
Zbytky Nero7 zlkvidujte ručně z registry podle návodu: http://www.viry.cz/forum/viewtopic.php?t=2791 a zbytek adresáře v ProgramFiles smažte.
Kde máte hlášení ActuiveX?
Já používám Avast jako AV, FW Kerio, antispy Ad-aware jako skener, prohlížeč Firefox a vlastní hlavu.

Napsal: 28 pro 2006 13:12
od worman
A ked sa mi neda vymazat subor ( "~DFEF28.tmp" -- sa vola ten subor ) v zlozke TEMP, tak ako? :oops:
A ked zapnem tie aktualizacie, tak ma najde BILL ci? :cry:
ActiveX mi vyhodi ked zapnem ICQ :?:
dik

Napsal: 28 pro 2006 13:17
od Rudy
Soubor je neškodný, ignorujte.
Bill vás najde, a co má být?
Žádný ActiveX prvek není v logu spuštěn.

Napsal: 28 pro 2006 13:29
od worman
Rudy píše:Soubor je neškodný, ignorujte.
Bill vás najde, a co má být?
Žádný ActiveX prvek není v logu spuštěn.
Irituje ma, ze sa neda vymazat a stale tam kvasi:(
A tiez ma stve, ze ma najde Bill tie hlasenia vies a pod. :?: Stihat ma teda nemoze? :roll:
dik

Napsal: 28 pro 2006 14:12
od Rudy
Pokud máte legální Win, pak určitě ne. Ty nelegální se tu neřeší.

Napsal: 28 pro 2006 15:51
od worman
Chapem a zatial dakujem :wink:

:arrow: Topic premenujem na nazov mojho nicku a budem pisat moje problemy len sem, ok? Nevadi?
Presuniete mi to prosim Vas do sekcie, kde by to mohlo patrit?
Dakujem