Skocz do zawartości

Zarchiwizowany

Ten temat jest archiwizowany i nie można dodawać nowych odpowiedzi.

Vergil

Hijcak This i inne logi - wklejamy tutaj

Polecane posty

wrzuć nowy log.

-=MARCIN=- -> nie podoba mi się:

C:WINDOWSsystem32PuXpMan.exe

i te wpisy:

O4 - HKLM..Run: [mspwr] C:WINDOWSsystem32PuXpMan.exe

O4 - HKLM..Run: [PwrUpTweakMe] C:WINDOWSsystem32PuXpTwks.exe /TWEAK

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

Link do komentarza
Udostępnij na innych stronach

tzn zeby odpalic program killbox w nim podac sciezki folderow ktore chcesz usunac i zaznaczyc opcje delete on reboot ( usunc przy restarcie ) wtedy komp sie zrestartuje i juz powinno tych folderow nie byc :P

wiem bo wies.niak mowil i sam to robilem :)

przy okazji wrzuce moj log zeby wies.niak sprawdzil jak moze :):P

Logfile of HijackThis v1.99.1

Scan saved at 2:44:40 PM, on 1/13/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSsystem32spoolsv.exe

C:Program FilesNetropaMultimedia Keyboardnhksrv.exe

C:Program FilesGrisoftAVG Anti-Spyware 7.5guard.exe

C:PROGRA~1F-SECU~1backweb4476822ProgramSERVIC~1.EXE

C:Program FilesF-Secure Internet SecurityAnti-Virusfsgk32st.exe

C:Program FilesF-Secure Internet Securitybackweb4476822programfsbwsys.exe

C:Program FilesF-Secure Internet SecurityAnti-VirusFSGK32.EXE

C:Program FilesF-Secure Internet SecurityCommonFSMA32.EXE

C:Program FilesF-Secure Internet SecurityAnti-Virusfssm32.exe

C:Program FilesF-Secure Internet SecurityCommonFSMB32.EXE

C:Program FilesAnalog DevicesSoundMAXSMAgent.exe

C:WINDOWSsystem32svchost.exe

C:Program FilesF-Secure Internet SecurityCommonFCH32.EXE

C:Program FilesF-Secure Internet SecurityCommonFAMEH32.EXE

C:Program FilesF-Secure Internet SecurityAnti-Virusfsqh.exe

C:Program FilesF-Secure Internet SecurityAnti-Virusfsrw.exe

C:Program FilesF-Secure Internet SecurityFWESProgramfsdfwd.exe

C:Program FilesF-Secure Internet SecurityAnti-Virusfsav32.exe

C:Program FilesAlienGUIsewbload.exe

C:WINDOWSExplorer.EXE

C:Program FilesTrustMI-2500X OPTICAL MOUSEMouse32a.exe

C:Program FilesNetropaMultimedia KeyboardMMKeybd.exe

C:WINDOWSvsnpstd.exe

C:Program FilesHPHP Software UpdateHPWuSchd2.exe

C:Program FilesAnalog DevicesSoundMAXSMax4PNP.exe

C:Program FilesAnalog DevicesSoundMAXSmax4.exe

C:Program FilesCyberLinkPowerDVDPDVDServ.exe

C:Program FilesPowerISOPWRISOVM.EXE

C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe

C:WINDOWSsystem32qttask.exe

C:Program FilesNokiaNokia PC Suite 6LaunchApplication.exe

C:Program FilesGrisoftAVG Anti-Spyware 7.5avgas.exe

C:Program FilesF-Secure Internet SecurityCommonFSM32.EXE

C:WINDOWSsystem32ctfmon.exe

C:Program FilesMSN MessengerMsnMsgr.Exe

C:Program FilesMessengermsmsgs.exe

C:Program FilesF-Secure Internet Securitybackweb4476822Programfspex.exe

C:Program FilesHPDigital Imagingbinhpqtra08.exe

C:PROGRA~1F-SECU~1ANTI-S~1fsaw.exe

C:Program FilesF-Secure Internet SecurityFSGUIfsguidll.exe

C:Program FilesPC Connectivity SolutionServiceLayer.exe

C:Program FilesNetropaMultimedia KeyboardTrayMon.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSsystem32wuauclt.exe

C:Program FilesNetropaOnscreen DisplayOSD.exe

C:Program FilesHPDigital Imagingbinhpqimzone.exe

C:Program FilesHPDigital ImagingbinhpqSTE08.exe

C:Program FilesHPDigital ImagingProduct Assistantbinhprblog.exe

C:WINDOWSsystem32svchost.exe

C:Program FilesWindows Media Playerwmplayer.exe

C:Program FilesOperaOpera.exe

C:Documents and SettingsOwnerDesktopHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =

R1 - HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:PROGRA~1MICROS~2Office12GRA8E1~1.DLL

O4 - HKLM..Run: [FLMOFFICE4DMOUSE] C:Program FilesTrustMI-2500X OPTICAL MOUSEMouse32a.exe

O4 - HKLM..Run: [MULTIMEDIA KEYBOARD] C:Program FilesNetropaMultimedia KeyboardMMKeybd.exe

O4 - HKLM..Run: [snpstd] C:WINDOWSvsnpstd.exe

O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe

O4 - HKLM..Run: [HP Software Update] C:Program FilesHPHP Software UpdateHPWuSchd2.exe

O4 - HKLM..Run: [soundMAXPnP] C:Program FilesAnalog DevicesSoundMAXSMax4PNP.exe

O4 - HKLM..Run: [soundMAX] "C:Program FilesAnalog DevicesSoundMAXSmax4.exe" /tray

O4 - HKLM..Run: [RemoteControl] "C:Program FilesCyberLinkPowerDVDPDVDServ.exe"

O4 - HKLM..Run: [PWRISOVM.EXE] C:Program FilesPowerISOPWRISOVM.EXE

O4 - HKLM..Run: [GrooveMonitor] "C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe"

O4 - HKLM..Run: [QuickTime Task] "C:WINDOWSsystem32qttask.exe" -atboottime

O4 - HKLM..Run: [PCSuiteTrayApplication] C:Program FilesNokiaNokia PC Suite 6LaunchApplication.exe -startup

O4 - HKLM..Run: [!AVG Anti-Spyware] "C:Program FilesGrisoftAVG Anti-Spyware 7.5avgas.exe" /minimized

O4 - HKLM..Run: [F-Secure Manager] "C:Program FilesF-Secure Internet SecurityCommonFSM32.EXE" /splash

O4 - HKLM..Run: [F-Secure TNB] "C:Program FilesF-Secure Internet SecurityTNBTNBUtil.exe" /CHECKALL /WAITFORSW

O4 - HKLM..Run: [F-Secure Startup Wizard] "C:Program FilesF-Secure Internet SecurityFSGUIFSSW.EXE" /reboot

O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe

O4 - HKCU..Run: [MsnMsgr] "C:Program FilesMSN MessengerMsnMsgr.Exe" /background

O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background

O4 - HKCU..Run: [PeerGuardian] C:Program FilesPeerGuardian2pg2.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exe

O4 - Global Startup: F-Secure Anti-Virus 2006.lnk = C:Program FilesF-Secure Internet Securitybackweb4476822Programfspex.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:Program FilesHPDigital Imagingbinhpqtra08.exe

O4 - Global Startup: HP Image Zone Fast Start.lnk = C:Program FilesHPDigital Imagingbinhpqthb08.exe

O8 - Extra context menu item: &Block this popup - C:Program FilesF-Secure Internet SecurityAnti-Spywareblockpopups.htm

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MICROS~2Office12EXCEL.EXE/3000

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~2Office12ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~2Office12ONBttnIE.dll

O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:Program FilesF-Secure Internet SecurityAnti-Spywareieshield.dll

O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:Program FilesF-Secure Internet SecurityAnti-Spywareieshield.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2Office12REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:PROGRA~1MICROS~2Office12GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:Program FilesCommon FilesMicrosoft SharedHelphxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:PROGRA~1COMMON~1MICROS~1OFFICE12MSOXMLMF.DLL

O20 - Winlogon Notify: WB - C:Program FilesAlienGUIsefastload.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:WINDOWSsystem32WPDShServiceObj.dll

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:Program FilesGrisoftAVG Anti-Spyware 7.5guard.exe

O23 - Service: F-Secure Anti-Virus 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - C:PROGRA~1F-SECU~1backweb4476822ProgramSERVIC~1.EXE

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:Program FilesCommon FilesSymantec SharedccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:Program FilesF-Secure Internet SecurityAnti-Virusfsgk32st.exe

O23 - Service: fsbwsys - F-Secure Corp. - C:Program FilesF-Secure Internet Securitybackweb4476822programfsbwsys.exe

O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:Program FilesF-Secure Internet SecurityFWESProgramfsdfwd.exe

O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:Program FilesF-Secure Internet SecurityCommonFSMA32.EXE

O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:Program FilesNetropaMultimedia Keyboardnhksrv.exe

O23 - Service: ServiceLayer - Nokia. - C:Program FilesPC Connectivity SolutionServiceLayer.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:Program FilesAnalog DevicesSoundMAXSMAgent.exe

Dzieki !!

Link do komentarza
Udostępnij na innych stronach

Mam tu log z HiJacka. Czy mógłby mi ktoś go sprawdzić bo podejrzewam że jakiegoś śmiecia złapałem. A tak konkretnie to zmienia mi sie styl z winxp na standardowy windows, po czym wszystko wysiada :(

Logfile of HijackThis v1.99.1

Scan saved at 16:51:56, on 2007-01-26

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSsystem32spoolsv.exe

C:Program FilesAOLActive Virus Shieldavp.exe

C:WINDOWSsystem32nvsvc32.exe

C:Program FilesCommon FilesUlead SystemsDVDULCDRSvr.exe

C:WINDOWSExplorer.EXE

C:WINDOWSsystem32wscntfy.exe

C:WINDOWSsystem32RUNDLL32.EXE

C:Program FilesNVIDIA CorporationNvMixerNVMixerTray.exe

C:Program FilesWinFastWFTVFMWFWIZ.exe

C:Program FilesThomsonSpeedTouch USBDragdiag.exe

C:Program FilesAOLActive Virus Shieldavp.exe

C:Program FilesSpybot - Search & DestroyTeaTimer.exe

C:WINDOWSSystem32svchost.exe

C:Documents and SettingsAdrianPulpithijackthisHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_10binssv.dll

O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup

O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit

O4 - HKLM..Run: [NVMixerTray] "C:Program FilesNVIDIA CorporationNvMixerNVMixerTray.exe"

O4 - HKLM..Run: [WinFast Schedule] C:Program FilesWinFastWFTVFMWFWIZ.exe

O4 - HKLM..Run: [speedTouch USB Diagnostics] "C:Program FilesThomsonSpeedTouch USBDragdiag.exe" /icon

O4 - HKLM..Run: [aol] "C:Program FilesAOLActive Virus Shieldavp.exe"

O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k

O4 - HKCU..Run: [spybotSD TeaTimer] C:Program FilesSpybot - Search & DestroyTeaTimer.exe

O4 - HKCU..Run: [HijackThis startup scan] C:Documents and SettingsAdrianPulpithijackthisHijackThis.exe /startupscan

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binnpjpi150_10.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binnpjpi150_10.dll

O17 - HKLMSystemCCSServicesTcpip..{5A18243A-BC7E-473D-BA65-6A0E27B256E3}: NameServer = 194.204.152.34 217.98.63.164

O20 - Winlogon Notify: klogon - C:WINDOWSsystem32klogon.dll

O23 - Service: Active Virus Shield (AVP) - Unknown owner - C:Program FilesAOLActive Virus Shieldavp.exe" -r (file missing)

O23 - Service: NBService - Nero AG - C:Program FilesNeroNero 7Nero BackItUpNBService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe

O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:Program FilesCommon FilesUlead SystemsDVDULCDRSvr.exe

Link do komentarza
Udostępnij na innych stronach

Niemam dwóch antywirów:) mam tylko Active Virus Shield. A co do programów to nie używalem żadnych. Komp jest czysty po formacie. Coś takiego sie dzieje tylko po posiedzeniu kilku minut w necie. Tak, występuje to na wszystkich profilach. Mam nie zaktualizowany windows. Czy może być to wina braku jakiejś łatki czy cuś?

Link do komentarza
Udostępnij na innych stronach

Logfile of HijackThis v1.99.1

Scan saved at 22:19:53, on 31-01-2007

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesCommon FilesSymantec SharedccSvcHst.exe

C:Program FilesCommon FilesSymantec SharedAppCoreAppSvc32.exe

C:WINDOWSsystem32brsvc01a.exe

C:WINDOWSsystem32spoolsv.exe

C:WINDOWSsystem32brss01a.exe

C:Program FilesCommon FilesAcronisSchedule2schedul2.exe

C:Program FilesSymantecLiveUpdateALUSchedulerSvc.exe

C:Program FilesDiskeeper CorporationDiskeeperDkService.exe

C:WINDOWSsystem32nvsvc32.exe

C:WINDOWSsystem32r_server.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSExplorer.EXE

C:Program FilesAcronisTrueImageTrueImageMonitor.exe

C:Program FilesCommon FilesAcronisSchedule2schedhlp.exe

C:WINDOWSsystem32RunDLL32.exe

C:Program FilesJavajre1.5.0_10binjusched.exe

C:Program FilesCommon FilesSymantec SharedccApp.exe

C:WINDOWSsystem32ctfmon.exe

C:Program FilesCommon FilesAheadlibNMBgMonitor.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe

C:Documents and SettingsH&MPulpithijackthisHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =

R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:Acrobat 7.0ActiveXAcroIEHelper.dll

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:Program FilesCommon FilesSymantec SharedcoSharedBrowser1.0NppBho.dll

O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:Program FilesGetRightxx2gr.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_10binssv.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll

O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:Program FilesCommon FilesSymantec SharedcoSharedBrowser1.0UIBHO.dll

O4 - HKLM..Run: [DiskeeperSystray] "C:Program FilesDiskeeper CorporationDiskeeperDkIcon.exe"

O4 - HKLM..Run: [TrueImageMonitor.exe] C:Program FilesAcronisTrueImageTrueImageMonitor.exe

O4 - HKLM..Run: [Acronis Scheduler2 Service] "C:Program FilesCommon FilesAcronisSchedule2schedhlp.exe"

O4 - HKLM..Run: [NeroFilterCheck] C:Program FilesCommon FilesAheadLibNeroCheck.exe

O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup

O4 - HKLM..Run: [nwiz] nwiz.exe /install

O4 - HKLM..Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit

O4 - HKLM..Run: [setDefPrt] C:Program FilesBrotherBrmfl05aBrStDvPt.exe

O4 - HKLM..Run: [ControlCenter2.0] C:Program FilesBrotherControlCenter2brctrcen.exe /autorun

O4 - HKLM..Run: [sunJavaUpdateSched] "C:Program FilesJavajre1.5.0_10binjusched.exe"

O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"

O4 - HKLM..Run: [osCheck] "D:NortonosCheck.exe"

O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe

O4 - HKCU..Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:Program FilesCommon FilesAheadlibNMBgMonitor.exe"

O4 - Startup: Xfire.lnk = D:Xfirexfire.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:Acrobat 7.0Readerreader_sl.exe

O4 - Global Startup: Status Monitor.lnk = C:Program FilesBrotherBrmfcmonBrMfcWnd.exe

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll

O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1153165481187

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) - http://javadl-esd.sun.com/update/1.5.0/jin...indows-i586.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL

O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:Program FilesCommon FilesAcronisSchedule2schedul2.exe

O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:Program FilesSymantecLiveUpdateALUSchedulerSvc.exe

O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:WINDOWSsystem32brsvc01a.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:Program FilesCommon FilesSymantec SharedccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:Program FilesCommon FilesSymantec SharedccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:Program FilesCommon FilesSymantec SharedccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: COM Host (comHost) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedVAScannercomHost.exe

O23 - Service: Diskeeper - Diskeeper Corporation - C:Program FilesDiskeeper CorporationDiskeeperDkService.exe

O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - D:NortonisPwdSvc.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:PROGRA~1SymantecLIVEUP~1LUCOMS~1.EXE

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe

O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:WINDOWSsystem32r_server.exe" /service (file missing)

O23 - Service: Symantec Core LC - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe

O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedAppCoreAppSvc32.exe

Czy coś jest nie tak? Ostatnio komp mi dziwnie zamula...

Link do komentarza
Udostępnij na innych stronach

instalowałeś program do zdalnej administracji? jeśli nie to usuń ten plik (za pomocą programu killbox) przy odłączonym necie:

C:WINDOWSsystem32r_server.exe

wtedy usuń też wpis

O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:WINDOWSsystem32r_server.exe" /service (file missing)

przeskanuj sobie komputer programem ewido.

poza tym czysto.

Link do komentarza
Udostępnij na innych stronach

Nowy log do sprawdzenia, tym razem z okropnie przymulającego laptopa. Z góry dziękuję za pomoc. Użyłem analizatora ze strony www.hijackthis.de , ale, jak sam napisałeś, nie jest on bezbłędny.

Logfile of HijackThis v1.99.1

Scan saved at 23:42:19, on 2007-02-02

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32Ati2evxx.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSsystem32spoolsv.exe

c:program filescommon fileslogishrdlvmvfmLVPrcSrv.exe

C:Program FilesCA Internet Security SuiteCA Anti-VirusISafe.exe

C:Program FilesTOSHIBAConfigFreeCFSvcs.exe

C:WINDOWSsystem32svchost.exe

C:Program FilesCA Internet Security SuiteCA Anti-VirusVetMsg.exe

C:WINDOWSsystem32wuauclt.exe

C:WINDOWSsystem32Ati2evxx.exe

C:WINDOWSExplorer.EXE

C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe

C:Program FilesSynapticsSynTPSynTPLpr.exe

C:Program FilesSynapticsSynTPSynTPEnh.exe

C:Program FilesToshibaWindows UtilitiesHotkey.exe

C:Program FilesTOSHIBAConfigFreeNDSTray.exe

C:Program FilesTOSHIBAProgram narzędziowy TOSHIBA Zooming UtilitySmoothView.exe

C:Program FilesTOSHIBATouch and LaunchPadExe.exe

C:WINDOWSsystem32dlatfswctrl.exe

C:Program FilesCA Internet Security Suitecctraycctray.exe

C:Program FilesCA Internet Security SuiteCA Anti-VirusCAVRID.exe

C:Program FilesCommon FilesLogiShrdLComMgrCommunications_Helper.exe

C:Program FilesCommon FilesRealUpdate_OBrealsched.exe

C:Program FilesTOSHIBATOSCDSPDtoscdspd.exe

C:WINDOWSsystem32CTFMON.EXE

C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exe

C:Documents and SettingsHubertPulpithijackthisHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:PROGRA~1MEGAUP~1MEGAUP~1.DLL

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:WINDOWSsystem32dlatfswshx.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:PROGRA~1MEGAUP~1MEGAUP~1.DLL

O4 - HKLM..Run: [ATIPTA] "C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe"

O4 - HKLM..Run: [synTPLpr] C:Program FilesSynapticsSynTPSynTPLpr.exe

O4 - HKLM..Run: [synTPEnh] C:Program FilesSynapticsSynTPSynTPEnh.exe

O4 - HKLM..Run: [Toshiba Hotkey Utility] "C:Program FilesToshibaWindows UtilitiesHotkey.exe" /lang PL

O4 - HKLM..Run: [NDSTray.exe] NDSTray.exe

O4 - HKLM..Run: [smoothView] C:Program FilesTOSHIBAProgram narzędziowy TOSHIBA Zooming UtilitySmoothView.exe

O4 - HKLM..Run: [PadTouch] C:Program FilesTOSHIBATouch and LaunchPadExe.exe

O4 - HKLM..Run: [dla] C:WINDOWSsystem32dlatfswctrl.exe

O4 - HKLM..Run: [cctray] "C:Program FilesCA Internet Security Suitecctraycctray.exe"

O4 - HKLM..Run: [CAVRID] "C:Program FilesCA Internet Security SuiteCA Anti-VirusCAVRID.exe"

O4 - HKLM..Run: [CFSServ.exe] CFSServ.exe -NoClient

O4 - HKLM..Run: [LogitechCommunicationsManager] "C:Program FilesCommon FilesLogiShrdLComMgrCommunications_Helper.exe"

O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime

O4 - HKLM..Run: [TkBellExe] "C:Program FilesCommon FilesRealUpdate_OBrealsched.exe" -osboot

O4 - HKCU..Run: [TOSCDSPD] C:Program FilesTOSHIBATOSCDSPDtoscdspd.exe

O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe

O4 - Startup: Szybkie uruchamianie programu Microsoft Office OneNote 2003.lnk = C:Program FilesMicrosoft OfficeOFFICE11ONENOTEM.EXE

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exe

O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...?p=ZJxdm130YYPL

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_02binnpjpi150_02.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_02binnpjpi150_02.dll

O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...tup1.0.0.15.cab

O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v6.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe

O23 - Service: CAISafe - Computer Associates International, Inc. - C:Program FilesCA Internet Security SuiteCA Anti-VirusISafe.exe

O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:Program FilesTOSHIBAConfigFreeCFSvcs.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe

O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:program filescommon fileslogishrdlvmvfmLVPrcSrv.exe

O23 - Service: LVSrvLauncher - Logitech Inc. - C:Program FilesCommon FilesLogiShrdSrvLnchSrvLnch.exe

O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:Program FilesCA Internet Security SuiteCA Anti-VirusVetMsg.exe

Link do komentarza
Udostępnij na innych stronach

c:program filescommon fileslogishrdlvmvfmLVPrcSrv.exe - masz kamere internetowa :?:

C:Program FilesCommon FilesLogiShrdLComMgrCommunications_Helper.exe - co to :?:

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:PROGRA~1MEGAUP~1MEGAUP~1.DLL - korzystasz z czegos takiego :?:

O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...?p=ZJxdm130YYPL - a z czegos takiego :?:

O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL - a z tego :?:

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...tup1.0.0.15.cab - a z tego :?:

Nie wiem co to jest ten Communication_Helper, ale jak na mnie to komp jest poprostu zapchany. Wywal troche softu. Wywal to internet security. Wylacz systemowego Firewall'a. Powylaczaj czesc uslug systemowych. Zwlaszcza Indeksowania, AutoUpdate. Korzystales kiedys z przywracania systemu :?: Nie, to tez wylacz. Zainstaluj sobie jakas prosta i szybka scianke jak Kerio PF. Do tego jakis antyvirus, ktory bedziesz odpalac tylko od czasu do czasu, a nie mulic kompa nie ustannym skanem. Oczysc katalogi Temp, Prefetch. Na koniec zrob defragmentacje dyskow twardych.

Warto tez sciagnac sobie MS Bootvis i go odpalic. To powinno przyspieszyc bootowanie windowsa.

Link do komentarza
Udostępnij na innych stronach

Witam i że tak powiem HELP:

Logfile of HijackThis v1.99.1

Scan saved at 14:19:59, on 2007-02-14

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesAvast4aswUpdSv.exe

C:Program FilesAvast4ashServ.exe

C:Program FilesGrisoftAVG Anti-Spyware 7.5guard.exe

C:Program FilescFosSpeedspd.exe

C:Program FilesSunbelt SoftwarePersonal Firewallkpf4ss.exe

C:Program FilesSunbelt SoftwarePersonal Firewallkpf4gui.exe

C:Program FilesAvast4ashMaiSv.exe

C:Program FilesAvast4ashWebSv.exe

C:Program FilesSunbelt SoftwarePersonal Firewallkpf4gui.exe

C:Program FilescFosSpeedcFosSpeed.exe

C:WINDOWSexplorer.exe

C:Program FilesBitTyrantAzureus.exe

C:Program FilesOperaOpera.exe

C:Program FilesDAPDAP.EXE

C:DOCUME~1AdminUSTAWI~1TempRar$EX00.046HijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Microsoft Internet Explorer

R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:PROGRA~1MegauploadToolbarmegauploadtoolbar.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_10binssv.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:PROGRA~1MegauploadToolbarmegauploadtoolbar.dll

O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} - C:WINDOWSImageShackToolbarImageShackToolbar.dll

O4 - HKLM..Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM..Run: [cFosSpeed] C:Program FilescFosSpeedcFosSpeed.exe

O4 - HKLM..Run: [DownloadAccelerator] "C:Program FilesDAPDAP.EXE" /STARTUP

O4 - HKLM..Run: [avast!] C:PROGRA~1Avast4ashDisp.exe

O4 - HKLM..Run: [!AVG Anti-Spyware] "C:Program FilesGrisoftAVG Anti-Spyware 7.5avgas.exe" /minimized

O4 - HKCU..Run: [AQQ] C:PROGRA~1WapsterAQQAQQ.exe

O4 - Startup: BitTyrant.lnk = C:Program FilesBitTyrantAzureus.exe

O8 - Extra context menu item: &Clean Traces - C:Program FilesDAPPrivacy Packagedapcleanerie.htm

O8 - Extra context menu item: &Download with &DAP - C:Program FilesDAPdapextie.htm

O8 - Extra context menu item: Download &all with DAP - C:Program FilesDAPdapextie2.htm

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:PROGRA~1Microsoft OfficeOFFICE11EXCEL.EXE/3000

O8 - Extra context menu item: Post Image to Blog - res://C:WINDOWSImageShackToolbarImageShackToolbar.dll/5003

O8 - Extra context menu item: Tag This Image - res://C:WINDOWSImageShackToolbarImageShackToolbar.dll/5002

O8 - Extra context menu item: Transload Image to ImageShack - res://C:WINDOWSImageShackToolbarImageShackToolbar.dll/5004

O8 - Extra context menu item: Upload All Images to ImageShack - res://C:WINDOWSImageShackToolbarImageShackToolbar.dll/5000

O8 - Extra context menu item: Upload Image to ImageShack - res://C:WINDOWSImageShackToolbarImageShackToolbar.dll/5001

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll

O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1Microsoft OfficeOFFICE11REFIEBAR.DLL

O10 - Unknown file in Winsock LSP: c:program filesbonjourmdnsnsp.dll

O15 - Trusted Zone: http://toolbar.imageshack.us

O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:Program FilesAvast4aswUpdSv.exe

O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe

O23 - Service: avast! Antivirus - Unknown owner - C:Program FilesAvast4ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:Program FilesAvast4ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:Program FilesAvast4ashWebSv.exe" /service (file missing)

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:Program FilesGrisoftAVG Anti-Spyware 7.5guard.exe

O23 - Service: cFosSpeed System Service (cFosSpeedS) - Unknown owner - C:Program FilescFosSpeedspd.exe" -service (file missing)

O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:Program FilesSunbelt SoftwarePersonal Firewallkpf4ss.exe

Jakieś sugestie? :roll:

Link do komentarza
Udostępnij na innych stronach

wywal w hijak this:

R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local

poza tym odpal regedit, przejdź do tego klucza i wywal wartość ProxyOverride.

użyj LSP-Fix aby usunąć

O10 - Unknown file in Winsock LSP: c:program filesbonjourmdnsnsp.dll

poza tym ImageShack toolbar wydaje mi się zbędny, ale to kwestia gustu.

jeśli masz jakiś konkretny problem, opisz na czym on polega.

Link do komentarza
Udostępnij na innych stronach

Głównie chodzi mi o pozbycie się nadmiaru svhost'ów :roll:

Logfile of HijackThis v1.99.1

Scan saved at 15:39:20, on 2007-02-14

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesAvast4aswUpdSv.exe

C:Program FilesAvast4ashServ.exe

C:Program FilesGrisoftAVG Anti-Spyware 7.5guard.exe

C:Program FilescFosSpeedspd.exe

C:Program FilesSunbelt SoftwarePersonal Firewallkpf4ss.exe

C:Program FilesSunbelt SoftwarePersonal Firewallkpf4gui.exe

C:Program FilesAvast4ashMaiSv.exe

C:Program FilesAvast4ashWebSv.exe

C:Program FilesSunbelt SoftwarePersonal Firewallkpf4gui.exe

C:Program FilescFosSpeedcFosSpeed.exe

C:WINDOWSexplorer.exe

C:Program FilesBitTyrantAzureus.exe

C:Program FilesDAPDAP.EXE

C:Program FilesWapsterAQQAQQ.exe

C:Program FilesOperaOpera.exe

D:ProgramyHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_10binssv.dll

O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - (no file)

O4 - HKLM..Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM..Run: [cFosSpeed] C:Program FilescFosSpeedcFosSpeed.exe

O4 - HKLM..Run: [DownloadAccelerator] "C:Program FilesDAPDAP.EXE" /STARTUP

O4 - HKLM..Run: [avast!] C:PROGRA~1Avast4ashDisp.exe

O4 - HKLM..Run: [!AVG Anti-Spyware] "C:Program FilesGrisoftAVG Anti-Spyware 7.5avgas.exe" /minimized

O4 - HKCU..Run: [AQQ] C:PROGRA~1WapsterAQQAQQ.exe

O4 - Startup: BitTyrant.lnk = C:Program FilesBitTyrantAzureus.exe

O8 - Extra context menu item: Post Image to Blog - res://C:WINDOWSImageShackToolbarImageShackToolbar.dll/5003

O8 - Extra context menu item: Tag This Image - res://C:WINDOWSImageShackToolbarImageShackToolbar.dll/5002

O8 - Extra context menu item: Transload Image to ImageShack - res://C:WINDOWSImageShackToolbarImageShackToolbar.dll/5004

O8 - Extra context menu item: Upload All Images to ImageShack - res://C:WINDOWSImageShackToolbarImageShackToolbar.dll/5000

O8 - Extra context menu item: Upload Image to ImageShack - res://C:WINDOWSImageShackToolbarImageShackToolbar.dll/5001

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll

O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1Microsoft OfficeOFFICE11REFIEBAR.DLL

O15 - Trusted Zone: http://toolbar.imageshack.us

O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) - http://toolbar.imageshack.us/toolbar/ImageShackToolbar.cab

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:Program FilesAvast4aswUpdSv.exe

O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe

O23 - Service: avast! Antivirus - Unknown owner - C:Program FilesAvast4ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:Program FilesAvast4ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:Program FilesAvast4ashWebSv.exe" /service (file missing)

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:Program FilesGrisoftAVG Anti-Spyware 7.5guard.exe

O23 - Service: cFosSpeed System Service (cFosSpeedS) - Unknown owner - C:Program FilescFosSpeedspd.exe" -service (file missing)

O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:Program FilesSunbelt SoftwarePersonal Firewallkpf4ss.exe

Link do komentarza
Udostępnij na innych stronach

tak długo jak są to procesy pliku %WINDIR%system32svchost.exe to wszystko jest ok. nie dzis się, że jest ich kilka (u mnie 7).

jeśli chcesz zobaczyć co "kryje się" za każdym procesem, możesz odpalić polecenie "tasklist /svc".

Link do komentarza
Udostępnij na innych stronach

Kk, zrozumiałem. A od czego (albo do czego) jest 'lsass.exe'?

cyt. "Proces Lsass.exe odpowiada m.in. za zarządzanie uwierzytelnianiem domeny urzędu zabezpieczeń lokalnych i zarządzanie usługą Active Directory. Proces ten obsługuje uwierzytelnianie zarówno klienta, jak i serwera, a także steruje aparatem usługi Active Directory. Proces Lsass.exe odpowiada m.in. za działanie następujących składników:

* Urząd zabezpieczeń lokalnych

* Usługa Logowanie do sieci

* Usługa Menedżer kont zabezpieczeń

* Usługa Serwer LSA

* Protokół SSL (Secure Sockets Layer)

* Protokół uwierzytelniania Kerberos v5

* Protokół uwierzytelniania NTLM

'lsass.exe' moze byc rowniez :

lsass.exe Trojan.W32.Satiloler

lsass.exe Trojan.W32.Downloader

lsass.exe Trojan.W32.Rontokbr

lsass.exe Trojan.W32.KELVIR

lsass.exe Trojan.W32.satiloler

lsass.exe Trojan.W32.Webus

lsass.exe Trojan.W32.Windang, Trojan.W32.Spybot & backdoor.W32.ratsou

Link do komentarza
Udostępnij na innych stronach

Kolejny raz prosił bym o pomoc:

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSsystem32spoolsv.exe

C:WINDOWSExplorer.EXE

D:ProgramyAvastaswUpdSv.exe

D:ProgramyAvastashServ.exe

C:Program FilesSunbelt SoftwarePersonal Firewallkpf4ss.exe

C:Program FilesMicrosoft Analysis ServicesBinmsmdsrv.exe

C:WINDOWSsystem32nvsvc32.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesSunbelt SoftwarePersonal Firewallkpf4gui.exe

C:WINDOWSSOUNDMAN.EXE

C:WINDOWSSystem32RUNDLL32.EXE

D:ProgramyAvastashDisp.exe

D:Programycyber link soulutionPowerDVDPDVDServ.exe

C:Program FilesJavajre1.5.0_10binjusched.exe

C:WINDOWSSystem32spooldriversw32x863hpztsb07.exe

D:ProgramyDAPDAP.EXE

C:Program FilesHPHP Software UpdateHPWuSchd2.exe

D:ProgramyGadu-Gadugg.exe

C:Program FilesDAEMON Toolsdaemon.exe

C:Program FilesCommon FilesAheadlibNMBgMonitor.exe

C:Program FilesSAGEMSAGEM F@st 800-840dslmon.exe

C:Program FilesHPDigital Imagingbinhpqtra08.exe

C:Program FilesSunbelt SoftwarePersonal Firewallkpf4gui.exe

D:ProgramyAvastashMaiSv.exe

C:WINDOWSBricoPacksVista InspiratObjectDockObjectDock.exe

C:Program FilesOpenOffice.org 2.0programsoffice.exe

C:WINDOWSBricoPacksVista InspiratYzToolbarYzToolBar.exe

C:Program FilesOpenOffice.org 2.0programsoffice.BIN

D:ProgramyAvastashWebSv.exe

C:Program FilesHPDigital ImagingbinhpqSTE08.exe

D:ProgramyBitCometBitComet.exe

C:WINDOWSsystem32HPZipm12.exe

C:Program FilesAdobePhotoshop Album Starter Edition3.0Appsapdproxy.exe

D:ProgramyMozilla Firefoxfirefox.exe

C:WINDOWSSystem32cmd.exe

C:Documents and SettingsChmiel.CHMIEL-01PulpitHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = http://py.com/

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_10binssv.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll

O4 - HKLM..Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup

O4 - HKLM..Run: [nwiz] nwiz.exe /install

O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit

O4 - HKLM..Run: [avast!] D:ProgramyAvastashDisp.exe

O4 - HKLM..Run: [Adobe Photo Downloader] "C:Program FilesAdobePhotoshop Album Starter Edition3.0Appsapdproxy.exe"

O4 - HKLM..Run: [RemoteControl] "D:Programycyber link soulutionPowerDVDPDVDServ.exe"

O4 - HKLM..Run: [sunJavaUpdateSched] "C:Program FilesJavajre1.5.0_10binjusched.exe"

O4 - HKLM..Run: [HPDJ Taskbar Utility] C:WINDOWSSystem32spooldriversw32x863hpztsb07.exe

O4 - HKLM..Run: [DownloadAccelerator] "D:ProgramyDAPDAP.EXE" /STARTUP

O4 - HKLM..Run: [speedOptimizer] C:PROGRA~1SPEEDO~1SPO.EXE -s

O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k

O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSSystem32NeroCheck.exe

O4 - HKLM..Run: [HP Software Update] C:Program FilesHPHP Software UpdateHPWuSchd2.exe

O4 - HKCU..Run: [Gadu-Gadu] "D:ProgramyGadu-Gadugg.exe" /tray

O4 - HKCU..Run: [DAEMON Tools] "C:Program FilesDAEMON Toolsdaemon.exe" -lang 1033

O4 - HKCU..Run: [PowerBar] "D:Programycyber link soulutionMultimedia LauncherPowerBar.exe" /AtBootTime

O4 - HKCU..Run: [NETIANET] C:Documents and SettingsChmiel.CHMIEL-01Pulpitnetianet.exe

O4 - HKCU..Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:Program FilesCommon FilesAheadlibNMBgMonitor.exe"

O4 - Startup: OpenOffice.org 2.0.lnk = C:Program FilesOpenOffice.org 2.0programquickstart.exe

O4 - Startup: Stardock ObjectDock.lnk = C:WINDOWSBricoPacksVista InspiratObjectDockObjectDock.exe

O4 - Startup: Y'z ToolBar.lnk = C:WINDOWSBricoPacksVista InspiratYzToolbarYzToolBar.exe

O4 - Global Startup: DSLMON.lnk = C:Program FilesSAGEMSAGEM F@st 800-840dslmon.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:Program FilesHPDigital Imagingbinhpqtra08.exe

O8 - Extra context menu item: &Clean Traces - D:ProgramyDAPPrivacy Packagedapcleanerie.htm

O8 - Extra context menu item: &Download with &DAP - D:ProgramyDAPdapextie.htm

O8 - Extra context menu item: Download &all with DAP - D:ProgramyDAPdapextie2.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O17 - HKLMSystemCCSServicesTcpip..{8DD16EF7-7786-45A1-9150-224752D35DFE}: NameServer = 213.241.79.37 83.238.255.76

O17 - HKLMSystemCS1ServicesTcpip..{8DD16EF7-7786-45A1-9150-224752D35DFE}: NameServer = 213.241.79.37 83.238.255.76

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:ProgramyAvastaswUpdSv.exe

O23 - Service: avast! Antivirus - Unknown owner - D:ProgramyAvastashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - D:ProgramyAvastashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - D:ProgramyAvastashWebSv.exe" /service (file missing)

O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:Program FilesSunbelt SoftwarePersonal Firewallkpf4ss.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:WINDOWSsystem32HPZipm12.exe

Link do komentarza
Udostępnij na innych stronach

wywal:

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm

ale to jest niegroźne śmiecie. poza tym czysto. pomijam fakt, że log jest niekompletny.

opisz problem.

Link do komentarza
Udostępnij na innych stronach

Ostatnio podczas skanowania avast wykrył mi Win32 CTX......wywaliłem go ale w razie czego zrobiłem loga.....

Logfile of HijackThis v1.99.1

Scan saved at 19:58:58, on 2007-03-10

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSsystem32spoolsv.exe

C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

C:Program FilesAlwil SoftwareAvast4ashServ.exe

C:WINDOWSsystem32nvsvc32.exe

C:WINDOWSExplorer.EXE

C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe

C:WINDOWSsystem32wscntfy.exe

C:PROGRA~1ALWILS~1Avast4ashDisp.exe

C:Program FilesThomsonSpeedTouch USBDragdiag.exe

C:Program FilesJavajre1.5.0_07binjusched.exe

C:Program FilesAlwil SoftwareAvast4ashWebSv.exe

C:PROGRA~1A4TechMouseAmoumain.exe

C:WINDOWSsystem32RUNDLL32.EXE

C:Program FilesGadu-Gadugg.exe

C:Documents and SettingsszefunioPulpitutorrent.exe

C:Program FilesMozilla Firefoxfirefox.exe

C:DOCUME~1szefunioUSTAWI~1TempRar$EX00.477HijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =

R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =

R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =

R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =

R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =

R3 - Default URLSearchHook is missing

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_07binssv.dll

O4 - HKLM..Run: [siSSetCDfmt] C:WINDOWSsystem32SetCDfmt.exe

O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe

O4 - HKLM..Run: [speedTouch USB Diagnostics] "C:Program FilesThomsonSpeedTouch USBDragdiag.exe" /icon

O4 - HKLM..Run: [sunJavaUpdateSched] C:Program FilesJavajre1.5.0_07binjusched.exe

O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k

O4 - HKLM..Run: [WheelMouse] C:PROGRA~1A4TechMouseAmoumain.exe

O4 - HKLM..Run: [DAEMON Tools] "C:Program FilesDAEMON Toolsdaemon.exe" -lang 1033

O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup

O4 - HKLM..Run: [nwiz] nwiz.exe /install

O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit

O4 - HKLM..Run: [bearShare] "C:Program FilesBearShareBearShare.exe" /pause

O4 - HKCU..Run: [Gadu-Gadu] "C:Program FilesGadu-Gadugg.exe" /tray

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exe

O17 - HKLMSystemCCSServicesTcpip..{D34DB015-8A7B-4109-842A-075AB1E14702}: NameServer = 213.241.79.37 83.238.255.76

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

O23 - Service: avast! Antivirus - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashWebSv.exe" /service (file missing)

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver1150Intel 32IDriverT.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe

O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:WINDOWSsystem32sfrem01.exe

Link do komentarza
Udostępnij na innych stronach

usuń:

R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =

R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =

nic groźnego, po prostu śmiecie.

poza tym czysto.

jedynie polecam pozbyć się bearshare - już przy instalacji wyrażasz zgodę na instalację softu spyware'owego. zwykle nie zwraca się na to uwagi, tak jak na licencję i klika się dalej, a tam właśnie pisze że spyware (oczywiście nie bezpośrednio).

Link do komentarza
Udostępnij na innych stronach

Logfile of HijackThis v1.99.1

Scan saved at 4:55:49 PM, on 3/11/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSsystem32spoolsv.exe

C:Program FilesNetropaMultimedia Keyboardnhksrv.exe

C:Program FilesGrisoftAVG Anti-Spyware 7.5guard.exe

C:Program FilesCommon FilesMcAfeeHackerWatchHWAPI.exe

C:PROGRA~1McAfeeMSCmcmscsvc.exe

c:program filescommon filesmcafeemnamcnasvc.exe

C:PROGRA~1McAfeeVIRUSS~1mcods.exe

C:PROGRA~1McAfeeMSCmcpromgr.exe

c:PROGRA~1COMMON~1mcafeeredirsvcredirsvc.exe

C:PROGRA~1McAfeeVIRUSS~1mcshield.exe

C:PROGRA~1McAfeeVIRUSS~1mcsysmon.exe

C:Program FilesMcAfeeMPFMPFSrv.exe

C:Program FilesSiteAdvisor6028SAService.exe

C:Program FilesAnalog DevicesSoundMAXSMAgent.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesAlienGUIsewbload.exe

C:WINDOWSExplorer.EXE

c:PROGRA~1mcafee.comagentmcagent.exe

C:Program FilesTrustMI-2500X OPTICAL MOUSEMouse32a.exe

C:Program FilesNetropaMultimedia KeyboardMMKeybd.exe

C:WINDOWSvsnpstd.exe

C:Program FilesHPHP Software UpdateHPWuSchd2.exe

C:Program FilesAnalog DevicesSoundMAXSMax4PNP.exe

C:Program FilesAnalog DevicesSoundMAXSmax4.exe

C:Program FilesCyberLinkPowerDVDPDVDServ.exe

C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe

C:Program FilesNokiaNokia PC Suite 6LaunchApplication.exe

C:Program FilesSiteAdvisor6028SiteAdv.exe

C:WINDOWSsystem32ctfmon.exe

C:Program FilesMessengermsmsgs.exe

C:Program FilesCommon FilesAheadLibNMBgMonitor.exe

C:Program FilesPC Connectivity SolutionServiceLayer.exe

C:Program FilesHPDigital Imagingbinhpqtra08.exe

C:Program FilesCommon FilesAheadLibNMIndexStoreSvr.exe

C:Program FilesNetropaMultimedia KeyboardTrayMon.exe

C:Program FilesNetropaOnscreen DisplayOSD.exe

C:Program FilesHPDigital ImagingbinhpqSTE08.exe

C:Program FilesHPDigital Imagingbinhpqimzone.exe

C:Program FilesMSN Messengerusnsvc.exe

C:Program FilesWinampwinamp.exe

C:Program FilesMSN Messengermsnmsgr.exe

C:Program FilesOperaOpera.exe

C:WINDOWSsystem32wuauclt.exe

C:Documents and SettingsOwnerDesktopHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll

O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:Program FilesSiteAdvisor6028SiteAdv.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:PROGRA~1MICROS~2Office12GRA8E1~1.DLL

O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:program filesmcafeevirusscanscriptcl.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:Program FilesSiteAdvisor6028SiteAdv.dll

O4 - HKLM..Run: [FLMOFFICE4DMOUSE] C:Program FilesTrustMI-2500X OPTICAL MOUSEMouse32a.exe

O4 - HKLM..Run: [MULTIMEDIA KEYBOARD] C:Program FilesNetropaMultimedia KeyboardMMKeybd.exe

O4 - HKLM..Run: [snpstd] C:WINDOWSvsnpstd.exe

O4 - HKLM..Run: [HP Software Update] C:Program FilesHPHP Software UpdateHPWuSchd2.exe

O4 - HKLM..Run: [soundMAXPnP] C:Program FilesAnalog DevicesSoundMAXSMax4PNP.exe

O4 - HKLM..Run: [soundMAX] "C:Program FilesAnalog DevicesSoundMAXSmax4.exe" /tray

O4 - HKLM..Run: [RemoteControl] "C:Program FilesCyberLinkPowerDVDPDVDServ.exe"

O4 - HKLM..Run: [PWRISOVM.EXE] C:Program FilesPowerISOPWRISOVM.EXE

O4 - HKLM..Run: [GrooveMonitor] "C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe"

O4 - HKLM..Run: [QuickTime Task] "C:WINDOWSsystem32qttask.exe" -atboottime

O4 - HKLM..Run: [PCSuiteTrayApplication] C:Program FilesNokiaNokia PC Suite 6LaunchApplication.exe -startup

O4 - HKLM..Run: [NeroFilterCheck] C:Program FilesCommon FilesAheadLibNeroCheck.exe

O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k

O4 - HKLM..Run: [DAEMON Tools] "C:Program FilesDAEMON Toolsdaemon.exe" -lang 1033

O4 - HKLM..Run: [siteAdvisor] C:Program FilesSiteAdvisor6028SiteAdv.exe

O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe

O4 - HKCU..Run: [MsnMsgr] "C:Program FilesMSN MessengerMsnMsgr.Exe" /background

O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background

O4 - HKCU..Run: [PeerGuardian] C:Program FilesPeerGuardian2pg2.exe

O4 - HKCU..Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:Program FilesCommon FilesAheadLibNMBgMonitor.exe"

O4 - HKCU..Run: [Windows Registry Repair Pro] C:Program Files3B SoftwareWindows Registry Repair ProRegistryRepairPro.exe 4

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:Program FilesHPDigital Imagingbinhpqtra08.exe

O4 - Global Startup: HP Image Zone Fast Start.lnk = C:Program FilesHPDigital Imagingbinhpqthb08.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MICROS~2Office12EXCEL.EXE/3000

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~2Office12ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~2Office12ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2Office12REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:PROGRA~1MICROS~2Office12GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:Program FilesCommon FilesMicrosoft SharedHelphxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL

O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:Program FilesSiteAdvisor6028SiteAdv.dll

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:PROGRA~1COMMON~1MICROS~1OFFICE12MSOXMLMF.DLL

O20 - Winlogon Notify: WB - C:Program FilesAlienGUIsefastload.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:WINDOWSsystem32WPDShServiceObj.dll

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:Program FilesGrisoftAVG Anti-Spyware 7.5guard.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:Program FilesCommon FilesSymantec SharedccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:PROGRA~1COMMON~1McAfeeEmProxyemproxy.exe

O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:Program FilesCommon FilesMcAfeeHackerWatchHWAPI.exe

O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:PROGRA~1McAfeeMSCmcupdmgr.exe

O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:PROGRA~1McAfeeMSCmcmscsvc.exe

O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:program filescommon filesmcafeemnamcnasvc.exe

O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:PROGRA~1McAfeeVIRUSS~1mcods.exe

O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:PROGRA~1McAfeeMSCmcpromgr.exe

O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:PROGRA~1COMMON~1mcafeeredirsvcredirsvc.exe

O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:PROGRA~1McAfeeVIRUSS~1mcshield.exe

O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:PROGRA~1McAfeeVIRUSS~1mcsysmon.exe

O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:Program FilesMcAfeeMPFMPFSrv.exe

O23 - Service: NBService - Nero AG - C:Program FilesNeroNero 7Nero BackItUpNBService.exe

O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:Program FilesNetropaMultimedia Keyboardnhksrv.exe

O23 - Service: ServiceLayer - Nokia. - C:Program FilesPC Connectivity SolutionServiceLayer.exe

O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:Program FilesSiteAdvisor6028SAService.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:Program FilesAnalog DevicesSoundMAXSMAgent.exe

prosze a sprawdzenie log-a;)

antyvirus wykryl mi 10 badziewi a kiedy whodze w moje dokumenty a potem zamkne to przez chwile komp mi zamula nie wiem od czego :roll:

Link do komentarza
Udostępnij na innych stronach

Chyba mam wiry w kompie :x Zrobiłem skan i loga wrzucam tu.Co skasowac??

Logfile of HijackThis v1.99.1

Scan saved at 07:47:27, on 2007-05-12

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSsystem32spoolsv.exe

C:WINDOWSExplorer.EXE

C:Program FilesAnalog DevicesSoundMAXSMax4PNP.exe

C:Program FilesAnalog DevicesSoundMAXSmax4.exe

C:Program FilesJavajre1.5.0_05binjusched.exe

C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe

C:WINDOWSsystem32ctfmon.exe

C:Program FilesAdobeReader 8.0Readerreader_sl.exe

C:Program FilesQuickTimeqttask.exe

C:WINDOWSsystem32nvsvc32.exe

C:WINDOWSsystem32PnkBstrA.exe

C:Program FilesAnalog DevicesSoundMAXSMAgent.exe

C:Program FilesAlcohol SoftAlcohol 120StarWindStarWindService.exe

C:WINDOWSsystem32wscntfy.exe

C:WINDOWSsvchost.exe

C:Documents and SettingsTomekMoje dokumentyHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.torrenty.org/

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:PROGRA~1MICROS~3Office12GRA8E1~1.DLL

O4 - HKLM..Run: [soundMAXPnP] C:Program FilesAnalog DevicesSoundMAXSMax4PNP.exe

O4 - HKLM..Run: [soundMAX] "C:Program FilesAnalog DevicesSoundMAXSmax4.exe" /tray

O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime

O4 - HKLM..Run: [sunJavaUpdateSched] C:Program FilesJavajre1.5.0_05binjusched.exe

O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup

O4 - HKLM..Run: [nwiz] nwiz.exe /install

O4 - HKLM..Run: [GrooveMonitor] "C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe"

O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe

O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit

O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe

O4 - HKCU..Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:Program FilesCommon FilesAheadlibNMBgMonitor.exe"

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:Program FilesAdobeReader 8.0Readerreader_sl.exe

O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:Program FilesAdobeReader 8.0ReaderAdobeCollabSync.exe

O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:PROGRA~1MICROS~3Office12EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_05binnpjpi150_05.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_05binnpjpi150_05.dll

O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~3Office12ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~3Office12ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~3Office12REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:PROGRA~1MICROS~3Office12GR99D3~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:Program FilesCommon FilesMicrosoft SharedHelphxds.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:PROGRA~1COMMON~1MICROS~1OFFICE12MSOXMLMF.DLL

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe

O23 - Service: PnkBstrA - Unknown owner - C:WINDOWSsystem32PnkBstrA.exe

O23 - Service: PnkBstrB - Unknown owner - C:WINDOWSsystem32PnkBstrB.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:Program FilesAnalog DevicesSoundMAXSMAgent.exe

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:Program FilesAlcohol SoftAlcohol 120StarWindStarWindService.exe

Link do komentarza
Udostępnij na innych stronach

Gość
Temat jest zablokowany i nie można w nim pisać.


  • Kto przegląda   0 użytkowników

    • Brak zalogowanych użytkowników przeglądających tę stronę.

×
×
  • Utwórz nowe...