Skocz do zawartości

Zarchiwizowany

Ten temat jest archiwizowany i nie można dodawać nowych odpowiedzi.

Vergil

Hijcak This i inne logi - wklejamy tutaj

Polecane posty

z loga wynika, że masz jednego syfka:

C:WINDOWSsvchost.exe

tylko nie pomyl z plikiem w system32. usuwanie killbox'em z opcją delete on reboot.

jeśli nie korzystasz z messengera, wyłącz go.

wpis zbędny, ale nieszkodliwy:

O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe

Link do komentarza
Udostępnij na innych stronach

ostatnio mialem " lekkie " problemy z kompem , sciagnolem program [ Golden Wave ?] i jak sie okazalo z trojanem , cofnalem system o jeden dzien i jest cacy , tylko chyba zostaly jakies smieci wiec prosze o sprawdzenie Log-a :)

Logfile of HijackThis v1.99.1

Scan saved at 10:57:10 PM, on 5/18/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32Ati2evxx.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSsystem32spoolsv.exe

C:Program FilesGrisoftAVG Anti-Spyware 7.5guard.exe

C:Program FilesCommon FilesMcAfeeHackerWatchHWAPI.exe

C:PROGRA~1McAfeeMSCmcmscsvc.exe

c:program filescommon filesmcafeemnamcnasvc.exe

C:PROGRA~1McAfeeVIRUSS~1mcods.exe

C:PROGRA~1McAfeeMSCmcpromgr.exe

c:PROGRA~1COMMON~1mcafeeredirsvcredirsvc.exe

C:PROGRA~1McAfeeVIRUSS~1mcshield.exe

C:PROGRA~1McAfeeVIRUSS~1mcsysmon.exe

C:Program FilesMcAfeeMPFMPFSrv.exe

C:Program FilesSiteAdvisor6066SAService.exe

C:WINDOWSSystem32snmp.exe

C:Program FilesAnalog DevicesSoundMAXSMAgent.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSsystem32Ati2evxx.exe

C:WINDOWSExplorer.EXE

c:PROGRA~1mcafee.comagentmcagent.exe

C:WINDOWSvsnpstd.exe

C:Program FilesHPHP Software UpdateHPWuSchd2.exe

C:Program FilesAnalog DevicesSoundMAXSMax4PNP.exe

C:Program FilesAnalog DevicesSoundMAXSmax4.exe

C:Program FilesCyberLinkPowerDVDPDVDServ.exe

C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe

C:Program FilesSony EricssonMobile2Application LauncherApplication Launcher.exe

C:Program FilesATI TechnologiesATI.ACEcli.exe

C:WINDOWSsystem32ctfmon.exe

C:Program FilesCommon FilesAheadLibNMBgMonitor.exe

C:Program FilesSmart PC SolutionsMagic SpeedMagicSpeedBooster.exe

C:Program FilesCommon FilesAheadLibNMIndexStoreSvr.exe

C:Program FilesATI TechnologiesATI.ACECLI.exe

C:WINDOWSsystem32wuauclt.exe

C:Program FilesCommon FilesTeleca SharedGeneric.exe

C:Program FilesSony EricssonMobile2Mobile Phone Monitorepmworker.exe

C:Program FilesMSN Messengerusnsvc.exe

C:Documents and SettingsOwnerDesktopYASU.exe

C:Program FilesMSN Messengermsnmsgr.exe

C:Program FilesSiteAdvisor6066SiteAdv.exe

C:Program FilesWinampwinamp.exe

C:Program FilesGadu-Gadugg.exe

C:Program FilesOperaOpera.exe

C:Program FilesMSN Messengerlivecall.exe

C:Documents and SettingsOwnerDesktopDesktopHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll

O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:Program FilesSiteAdvisor6066SiteAdv.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:PROGRA~1MICROS~2Office12GRA8E1~1.DLL

O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:program filesmcafeevirusscanscriptcl.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:Program FilesSiteAdvisor6066SiteAdv.dll

O4 - HKLM..Run: [snpstd] C:WINDOWSvsnpstd.exe

O4 - HKLM..Run: [HP Software Update] C:Program FilesHPHP Software UpdateHPWuSchd2.exe

O4 - HKLM..Run: [soundMAXPnP] C:Program FilesAnalog DevicesSoundMAXSMax4PNP.exe

O4 - HKLM..Run: [soundMAX] "C:Program FilesAnalog DevicesSoundMAXSmax4.exe" /tray

O4 - HKLM..Run: [RemoteControl] "C:Program FilesCyberLinkPowerDVDPDVDServ.exe"

O4 - HKLM..Run: [PWRISOVM.EXE] C:Program FilesPowerISOPWRISOVM.EXE

O4 - HKLM..Run: [GrooveMonitor] "C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe"

O4 - HKLM..Run: [NeroFilterCheck] C:Program FilesCommon FilesAheadLibNeroCheck.exe

O4 - HKLM..Run: [sony Ericsson PC Suite] "C:Program FilesSony EricssonMobile2Application LauncherApplication Launcher.exe" /startoptions

O4 - HKLM..Run: [LClock] C:Program FilesLClockLClock.exe

O4 - HKLM..Run: [Vista Sidebar] C:Program FilesVista Sidebarsidebar.exe

O4 - HKLM..Run: [VisualTooltip] C:Program FilesVisualTooltipVisualToolTip.exe

O4 - HKLM..Run: [blaero Start Orb] C:Program FilesBlaero Start OrbBlaero Start Orb.exe

O4 - HKLM..Run: [styler] C:Program FilesStylerStyler.exe

O4 - HKLM..Run: [ATICCC] "C:Program FilesATI TechnologiesATI.ACEcli.exe" runtime

O4 - HKLM..Run: [WireLessKeyboard] C:Program FilesOffice Keyboard DriverStartAutorun.exe PS2USBKbdDrv.exe

O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe

O4 - HKCU..Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:Program FilesCommon FilesAheadLibNMBgMonitor.exe"

O4 - HKCU..Run: [MagicSpeedBooster] C:Program FilesSmart PC SolutionsMagic SpeedMagicSpeedBooster.exe

O4 - HKCU..Run: [Yodm3D] C:Documents and SettingsOwnerDesktopYodm3DYodm3D.exe

O4 - Startup: Adobe Gamma.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe

O4 - Global Startup: ATI CATALYST System Tray.lnk = C:Program FilesATI TechnologiesATI.ACECLI.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MICROS~2Office12EXCEL.EXE/3000

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~2Office12ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~2Office12ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2Office12REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:PROGRA~1MICROS~2Office12GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:Program FilesCommon FilesMicrosoft SharedHelphxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL

O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:Program FilesSiteAdvisor6066SiteAdv.dll

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:PROGRA~1COMMON~1MICROS~1OFFICE12MSOXMLMF.DLL

O20 - Winlogon Notify: WB - C:Program FilesAlienGUIsefastload.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:WINDOWSsystem32WPDShServiceObj.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe

O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:Program FilesAreschatServer.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:Program FilesGrisoftAVG Anti-Spyware 7.5guard.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:Program FilesCommon FilesSymantec SharedccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:PROGRA~1COMMON~1McAfeeEmProxyemproxy.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver1150Intel 32IDriverT.exe

O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:Program FilesCommon FilesMcAfeeHackerWatchHWAPI.exe

O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:PROGRA~1McAfeeMSCmcupdmgr.exe

O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:PROGRA~1McAfeeMSCmcmscsvc.exe

O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:program filescommon filesmcafeemnamcnasvc.exe

O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:PROGRA~1McAfeeVIRUSS~1mcods.exe

O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:PROGRA~1McAfeeMSCmcpromgr.exe

O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:PROGRA~1COMMON~1mcafeeredirsvcredirsvc.exe

O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:PROGRA~1McAfeeVIRUSS~1mcshield.exe

O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:PROGRA~1McAfeeVIRUSS~1mcsysmon.exe

O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:Program FilesMcAfeeMPFMPFSrv.exe

O23 - Service: NBService - Nero AG - C:Program FilesNeroNero 7Nero BackItUpNBService.exe

O23 - Service: ServiceLayer - Nokia. - C:Program FilesPC Connectivity SolutionServiceLayer.exe

O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:Program FilesSiteAdvisor6066SAService.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:Program FilesAnalog DevicesSoundMAXSMAgent.exe

Link do komentarza
Udostępnij na innych stronach

Czy moglibyście rzucić na to okiem. Nic nie instalowałem ale coś mi się wydaje że nie jest tak jak powinno ;D

Logfile of HijackThis v1.99.1

Scan saved at 15:13:40, on 2007-05-19

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16441)



Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32Ati2evxx.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSsystem32Ati2evxx.exe

C:WINDOWSsystem32spoolsv.exe

C:WINDOWSExplorer.EXE

C:Program FilesNetropaMultimedia Keyboardnhksrv.exe

C:Program FilesKaspersky LabKaspersky Internet Security 6.0avp.exe

C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE

C:WINDOWSsystem32HPZipm12.exe

C:WINDOWSsystem32svchost.exe

C:Program FilesKaspersky LabKaspersky Internet Security 6.0avp.exe

C:Program FilesJavajre1.5.0_11binjusched.exe

C:WINDOWSSOUNDMAN.EXE

C:Program FilesNetropaMultimedia KeyboardMMKeybd.exe

C:Program FilesMagicRotationMagicPvt.exe

C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe

C:Program FilesHPHP Software UpdateHPWuSchd2.exe

C:WINDOWSsystem32ctfmon.exe

C:Program FilesNetropaOnscreen DisplayOSD.exe

C:Program FilesOperaOpera.exe

C:Documents and SettingsDelmaqPulpithijackthisHijackThis.exe



R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =

R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll

O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:Program FilesFlashGetjccatch.dll

O2 - BHO: IE to GetRight Helper - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:Documents and SettingsDelmaqMoje dokumentygr6proxx2gr.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_11binssv.dll

O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:Program FilesFlashGetgetflash.dll

O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:Program FilesFlashGetfgiebar.dll

O4 - HKLM..Run: [AVP] "C:Program FilesKaspersky LabKaspersky Internet Security 6.0avp.exe"

O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.5.0_11binjusched.exe"

O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE

O4 - HKLM..Run: [MULTIMEDIA KEYBOARD] C:Program FilesNetropaMultimedia KeyboardMMKeybd.exe

O4 - HKLM..Run: [MagicRotation] C:Program FilesMagicRotationMagicPvt.exe

O4 - HKLM..Run: [ISUSScheduler] "C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe" -start

O4 - HKLM..Run: [ISUSPM Startup] C:PROGRA~1COMMON~1INSTAL~1UPDATE~1ISUSPM.exe -startup

O4 - HKLM..Run: [HP Software Update] C:Program FilesHPHP Software UpdateHPWuSchd2.exe

O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe

O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background

O4 - HKCU..Run: [XPRepairPro2007] C:Program FilesXP Repair Pro 2007XPRepairPro.exe /r

O8 - Extra context menu item: &Ściągnij przy pomocy FlashGet'a - C:Program FilesFlashGetjc_link.htm

O8 - Extra context menu item: &Ściągnij wszystko przy pomocy FlashGet'a - C:Program FilesFlashGetjc_all.htm

O8 - Extra context menu item: Add to Anti-Banner - C:Program FilesKaspersky LabKaspersky Internet Security 6.0ie_banner_deny.htm

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_11binssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_11binssv.dll

O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:Program FilesKaspersky LabKaspersky Internet Security 6.0scieplugin.dll

O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL

O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:Program FilesFlashGetFlashGet.exe

O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:Program FilesFlashGetFlashGet.exe

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O11 - Options group: [INTERNATIONAL] International*

O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:Program FilesCommon FilesMicrosoft SharedHelphxds.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL

O20 - AppInit_DLLs: C:PROGRA~1KASPER~2KASPER~1.0adialhk.dll

O20 - Winlogon Notify: klogon - C:WINDOWSsystem32klogon.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe

O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:Program FilesAreschatServer.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe

O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Unknown owner - C:Program FilesKaspersky LabKaspersky Internet Security 6.0avp.exe" -r (file missing)

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe

O23 - Service: License Management Service ESD - Unknown owner - C:Program FilesCommon Fileselement5 SharedServiceLicence Manager ESD.exe

O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:Program FilesNetropaMultimedia Keyboardnhksrv.exe

O23 - Service: Pml Driver HPZ12 - HP - C:WINDOWSsystem32HPZipm12.exe

Link do komentarza
Udostępnij na innych stronach

Ale mi sie syf w kompie zrobił. Pewnego dnia ni z tego ni z owego mój avast stwierdził że mam od cholery i ciut trojanów na dysku. No i niby je usuwa, ale jakoś tak opornie mu to idzie, bo cały czas wykrywa nowe (w ogóle cały system strasznie sie ślimaczy). Co wywalić albo jaki jeszcze program ściągnąć do przeczyszczenia?

Logfile of HijackThis v1.99.1

Scan saved at 13:12:04, on 2003-05-28

Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

C:Program FilesAlwil SoftwareAvast4ashServ.exe

C:WINDOWSExplorer.EXE

C:WINDOWSsystem32LEXBCES.EXE

C:WINDOWSsystem32spoolsv.exe

C:WINDOWSsystem32LEXPPS.EXE

C:WINDOWSSystem32RUNDLL32.EXE

C:Program FilesJavajre1.5.0_06binjusched.exe

C:Program FilesLexmark X74-X75lxbbbmgr.exe

C:WINDOWSabc5026def.exe

C:Program FilesLexmark X74-X75lxbbbmon.exe

C:windowssystem32driversuzcx.exe

C:WINDOWSSystem32ctfmon.exe

C:Program FilesMessengermsmsgs.exe

C:Program FilesErrorSafe Freeuers.exe

C:PROGRA~1MOZILL~1FIREFOX.EXE

C:WINDOWSSystem32nvsvc32.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesAlwil SoftwareAvast4ashWebSv.exe

C:Program FilesInternet Exploreriexplore.exe

C:WINDOWSbtn5026v7.exe

C:WINDOWSSystem32ipmon.exe

C:WINDOWSSystem32ipmon.exe

C:WINDOWSsmanager.7.exe

C:Documents and SettingsMarcelload.exe

C:Program FilesDriveCleaner FreeUDC6cw.exe

C:Program FilesCommon FilesDriveCleaner Freeudcsdr.exe

C:Program FilesCommon FilesDriveCleaner Freeudcpas.exe

C:Program FilesDriveCleaner FreeUDC.exe

C:WINDOWSSystem32rundll32.exe

C:DOCUME~1MarcelUSTAWI~1Tempserverserver.exe

C:WINDOWSavp.exe

C:Program FilesGadu-Gadugg.exe

C:Documents and SettingsMarcelPulpitHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.sportowefakty.pl/

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSsystem32msdxm.ocx

O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup

O4 - HKLM..Run: [nwiz] nwiz.exe /install

O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe

O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit

O4 - HKLM..Run: [sunJavaUpdateSched] C:Program FilesJavajre1.5.0_06binjusched.exe

O4 - HKLM..Run: [services] C:WINDOWSSystem32xasj.exe

O4 - HKLM..Run: [Lexmark X74-X75] "C:Program FilesLexmark X74-X75lxbbbmgr.exe"

O4 - HKLM..Run: [Windows Logon Application] C:WINDOWSSystem32winIogon.exe

O4 - HKLM..Run: [Advanced DHTML Enable] C:WINDOWSSystem32wglv.exe

O4 - HKLM..Run: [ipmon] ipmon.exe

O4 - HKLM..Run: [AutoSys] C:WINDOWSSystem32autosys.exe

O4 - HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe

O4 - HKLM..Run: [avp] C:WINDOWSavp.exe

O4 - HKLM..Run: [system] C:WINDOWSSystem32kernels32.exe

O4 - HKLM..Run: [sManager] smanager.7.exe

O4 - HKLM..Run: [iut75] c:windowssystem32driversuzcx.exe

O4 - HKLM..Run: [setup] rundll32.exe "C:WINDOWSSystem32ecxexvbr.dll",realset

O4 - HKLM..Run: [was_check] C:Program FilesErrorSafe FreeWASmon.exe

O4 - HKLM..Run: [uerscw] C:Program FilesErrorSafe Freeuerscw.exe -c

O4 - HKLM..Run: [userFaultCheck] %systemroot%system32dumprep 0 -u

O4 - HKLM..Run: [statemdd] autcwykq.exe

O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k

O4 - HKLM..Run: [WindowsHive] C:WINDOWSSystem32rpcc.exe

O4 - HKLM..Run: [smgr] smgr.exe

O4 - HKLM..Run: [Neospace Internet Security] "C:Program FilesNeospace Internet Securityisec30.exe"

O4 - HKLM..Run: [DriveCleaner Free] "C:Program FilesDriveCleaner FreeUDC.exe" /min

O4 - HKLM..Run: [sDR6_Check] "C:Program FilesCommon FilesDriveCleaner Freeudcsdr.exe"

O4 - HKLM..Run: [PAS_Check] "C:Program FilesCommon FilesDriveCleaner Freeudcpas.exe"

O4 - HKLM..Run: [uDC6cw] "C:Program FilesDriveCleaner FreeUDC6cw.exe" -c

O4 - HKLM..Run: [!ewido] "C:Program Filesewido anti-spyware 4.0ewido.exe" /minimized

O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe

O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background

O4 - HKCU..Run: [Windows update loader] C:Windowsxpupdate.exe

O4 - HKCU..Run: [ErrorSafeFree] C:Program FilesErrorSafe Freeuers.exe /scan

O4 - HKCU..Run: [ErrorSafeGratis] "C:Program FilesErrorSafe Freeuers.exe" /min

O4 - HKCU..Run: [statemdd] autcwykq.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_06binssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_06binssv.dll

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm

O10 - Broken Internet access because of LSP provider 'rsvp322.dll' missing

O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/inst...leanerstart.cab

O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvlution.com/KooPlayer.ocx

O20 - AppInit_DLLs: c:windowssystem32ldcore.dll

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:Program FilesAlwil SoftwareAvast4ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashWebSv.exe" /service (file missing)

O23 - Service: MS Internet Countermeasures Framework (ICF) - Unknown owner - C:WINDOWSSystem32svchost.exe:exe.exe (file missing)

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:WINDOWSsystem32LEXBCES.EXE

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSSystem32nvsvc32.exe

Link do komentarza
Udostępnij na innych stronach

do wywalenia:

C:WINDOWSabc5026def.exe

C:windowssystem32driversuzcx.exe

C:Program FilesErrorSafe Freeuers.exe

C:WINDOWSbtn5026v7.exe

C:WINDOWSSystem32ipmon.exe

C:WINDOWSsmanager.7.exe

C:Documents and SettingsMarcelload.exe <- jeśli znasz, to zostaw

C:Program FilesDriveCleaner FreeUDC6cw.exe <- cały katalog drrivercleaner ma zniknąć

C:Program FilesCommon FilesDriveCleaner Freeudcsdr.exe <- j/w

C:Program FilesCommon FilesDriveCleaner Freeudcpas.exe

C:Program FilesDriveCleaner FreeUDC.exe

C:DOCUME~1MarcelUSTAWI~1Tempserverserver.exe

wpisy do zafiksowania:

O4 - HKLM..Run: [services] C:WINDOWSSystem32xasj.exe

O4 - HKLM..Run: [Windows Logon Application] C:WINDOWSSystem32winIogon.exe

O4 - HKLM..Run: [Advanced DHTML Enable] C:WINDOWSSystem32wglv.exe

O4 - HKLM..Run: [ipmon] ipmon.exe

O4 - HKLM..Run: [AutoSys] C:WINDOWSSystem32autosys.exe

O4 - HKLM..Run: [system] C:WINDOWSSystem32kernels32.exe

O4 - HKLM..Run: [sManager] smanager.7.exe

O4 - HKLM..Run: [iut75] c:windowssystem32driversuzcx.exe

O4 - HKLM..Run: [setup] rundll32.exe "C:WINDOWSSystem32ecxexvbr.dll",realset

O4 - HKLM..Run: [was_check] C:Program FilesErrorSafe FreeWASmon.exe

O4 - HKLM..Run: [uerscw] C:Program FilesErrorSafe Freeuerscw.exe -c

O4 - HKLM..Run: [statemdd] autcwykq.exe

O4 - HKLM..Run: [WindowsHive] C:WINDOWSSystem32rpcc.exe

O4 - HKLM..Run: [smgr] smgr.exe

O4 - HKLM..Run: [DriveCleaner Free] "C:Program FilesDriveCleaner FreeUDC.exe" /min

O4 - HKLM..Run: [sDR6_Check] "C:Program FilesCommon FilesDriveCleaner Freeudcsdr.exe"

O4 - HKLM..Run: [PAS_Check] "C:Program FilesCommon FilesDriveCleaner Freeudcpas.exe"

O4 - HKLM..Run: [uDC6cw] "C:Program FilesDriveCleaner FreeUDC6cw.exe" -c

O4 - HKCU..Run: [Windows update loader] C:Windowsxpupdate.exe

O4 - HKCU..Run: [ErrorSafeFree] C:Program FilesErrorSafe Freeuers.exe /scan

O4 - HKCU..Run: [ErrorSafeGratis] "C:Program FilesErrorSafe Freeuers.exe" /min

O4 - HKCU..Run: [statemdd] autcwykq.exe

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm

O10 - Broken Internet access because of LSP provider 'rsvp322.dll' missing

O20 - AppInit_DLLs: c:windowssystem32ldcore.dll

O23 - Service: MS Internet Countermeasures Framework (ICF) - Unknown owner - C:WINDOWSSystem32svchost.exe:exe.exe (file missing)

poza plikami z "pierwszej części", wywal też wszystkie pliki wymienione we wpisach do zafiksowania. użyj do tego programu killbox - wrzuć do niego najpierw wszystkie pliki bez kasowania ich, zaznacz opcję delete on reboot i dopiero skasuj. zaliczysz reset i po resecie powinno być czysto. wtedy odpal hjt i wywal wszystkie wpisy. na czas całego oczyszczania odłącz net, najlepiej fizycznie kabelek wyciagnij.

po czyszczeniu log do kontroli.

Link do komentarza
Udostępnij na innych stronach

Dzień dobry. Wrzucam loga, gdyż coś mi się nie podoba w sposobie działania mojego systemu. A że ostatnio działa on coraz bardziej topornie, a ja jestem n00b, liczę na fachową pomoc z Waszej strony. Dziękuję z góry. ;]

Logfile of HijackThis v1.99.1

Scan saved at 22:12:50, on 2165-05-31

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)



Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesAheadInCDInCDsrv.exe

C:Program FilesTGTSoftStyleXPStyleXPService.exe

C:WINDOWSsystem32spoolsv.exe

C:Program FilesAntiVir PersonalEdition Classicsched.exe

C:Program FilesAntiVir PersonalEdition Classicavguard.exe

C:Program Filesewido anti-malwareewidoctrl.exe

C:Program FilesCommon FilesLightScribeLSSrvc.exe

C:WINDOWSsystem32nvsvc32.exe

C:WINDOWSsystem32WgaTray.exe

C:WINDOWSExplorer.EXE

C:WINDOWSMixer.exe

C:WINDOWSsystem32spooldriversw32x863hpztsb04.exe

C:Program FilesQuickTimeqttask.exe

C:Program FilesAntiVir PersonalEdition Classicavgnt.exe

C:Program FilesHPHP Software UpdateHPWuSchd2.exe

C:Program FilesHPhpcoretechhpcmpmgr.exe

C:Program FilesJavajre1.5.0_10binjusched.exe

D:Program FilesWinampwinampa.exe

C:Program FilesCyberLink DVD SolutionPowerDVDPDVDServ.exe

C:Program FilesAheadInCDInCD.exe

C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe

C:WINDOWSsystem32ctfmon.exe

C:Program FilesMessengermsmsgs.exe

C:Program FilesLClocklclock.exe

D:Program FilesGadu-Gadugg.exe

C:WINDOWSsystem32RaConfig.exe

C:WINDOWSBricoPacksVista InspiratObjectDockObjectDock.exe

C:WINDOWSsystem32wuauclt.exe

d:Program FilesWinampwinamp.exe

C:Program FilesJavajre1.5.0_10binjucheck.exe

C:Program FilesMozilla Firefoxfirefox.exe

C:Program FilesmIRCmirc.exe

C:Documents and SettingsArnoldPulpitHijackThis.exe



R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://google.icq.com/search/search_frame.php

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://start.icq.com/

R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:PROGRA~1ICQTOO~1toolbaru.dll

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx

O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:Program FilesDesktop Sidebarsbhelp.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_10binssv.dll

O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:Program FilesTGTSoftStyleXPTGT_BHO.dll

O2 - BHO: WebManager Class - {D5792AA9-D373-4039-8670-2CDAB6A71F15} - C:Program FilesBitGrabberTorrentManager.dll (file missing)

O3 - Toolbar: BitComet Toolbar - {2E608F70-C430-4bc5-96F6-608E02EBA5B2} - C:Program FilesBitComet Toolbarv2.0.0.4BitComet_Toolbar.dll

O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:PROGRA~1ICQTOO~1toolbaru.dll

O4 - HKLM..Run: [C-Media Mixer] Mixer.exe /startup

O4 - HKLM..Run: [HPDJ Taskbar Utility] C:WINDOWSsystem32spooldriversw32x863hpztsb04.exe

O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe

O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup

O4 - HKLM..Run: [nwiz] nwiz.exe /install

O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit

O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime

O4 - HKLM..Run: [avgnt] "C:Program FilesAntiVir PersonalEdition Classicavgnt.exe" /min

O4 - HKLM..Run: [HP Software Update] "C:Program FilesHPHP Software UpdateHPWuSchd2.exe"

O4 - HKLM..Run: [HP Component Manager] "C:Program FilesHPhpcoretechhpcmpmgr.exe"

O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.5.0_10binjusched.exe"

O4 - HKLM..Run: [WinampAgent] d:Program FilesWinampwinampa.exe

O4 - HKLM..Run: [RemoteControl] "C:Program FilesCyberLink DVD SolutionPowerDVDPDVDServ.exe"

O4 - HKLM..Run: [InCD] C:Program FilesAheadInCDInCD.exe

O4 - HKLM..Run: [googletalk] C:Program FilesGoogleGoogle Talkgoogletalk.exe /autostart

O4 - HKLM..Run: [ISUSPM Startup] C:PROGRA~1COMMON~1INSTAL~1UPDATE~1ISUSPM.exe -startup

O4 - HKLM..Run: [ISUSScheduler] "C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe" -start

O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe

O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background

O4 - HKCU..Run: [Ttab] "C:Program Filesshchebdc.exe" -vt yazr

O4 - HKCU..Run: [STYLEXP] C:Program FilesTGTSoftStyleXPStyleXP.exe -Hide

O4 - HKCU..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /nosplash /minimized

O4 - HKCU..Run: [LClock] C:Program FilesLClocklclock.exe

O4 - HKCU..Run: [Gadu-Gadu] "D:Program FilesGadu-Gadugg.exe" /tray

O4 - Startup: desktop(2)(2).ini

O4 - Startup: desktop(2).ini

O4 - Startup: desktop(3).ini

O4 - Startup: Stardock ObjectDock.lnk = C:WINDOWSBricoPacksVista InspiratObjectDockObjectDock.exe

O4 - Global Startup: desktop(2)(2).ini

O4 - Global Startup: desktop(2).ini

O4 - Global Startup: desktop(3).ini

O4 - Global Startup: RaConfig.lnk = C:WINDOWSsystem32RaConfig.exe

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll

O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:Program FilesDesktop Sidebarsbhelp.dll

O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:Program FilesDesktop Sidebarsbhelp.dll

O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL

O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:Program FilesICQ6ICQ.exe

O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:Program FilesICQ6ICQ.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O12 - Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL

O20 - Winlogon Notify: CSCSettings - C:WINDOWS

O20 - Winlogon Notify: WgaLogon - C:WINDOWSSYSTEM32WgaLogon.dll

O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:Program FilesAntiVir PersonalEdition Classicsched.exe

O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:Program FilesAntiVir PersonalEdition Classicavguard.exe

O23 - Service: ewido security suite control - ewido networks - C:Program Filesewido anti-malwareewidoctrl.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:Program FilesAheadInCDInCDsrv.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:Program FilesCommon FilesLightScribeLSSrvc.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe

O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:Program FilesSpyware Doctorsvcntaux.exe

O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:Program FilesSpyware Doctorswdsvc.exe

O23 - Service: StyleXPService - Unknown owner - C:Program FilesTGTSoftStyleXPStyleXPService.exe

Pozdrawiam!

Link do komentarza
Udostępnij na innych stronach

Do usunięcia:

O4 - HKCU..Run: [Ttab] "C:Program Filesshchebdc.exe" -vt yazr <- cały ten katalog usuń

O4 - Startup: desktop(2)(2).ini <- może to być związane z tymi modyfikacjami systemu, których używasz, ale raczej bym się tego pozbył

O4 - Startup: desktop(2).ini

O4 - Startup: desktop(3).ini

O4 - Global Startup: desktop(2)(2).ini

O4 - Global Startup: desktop(2).ini

O4 - Global Startup: desktop(3).ini

Czyli poza tym pierwszym (i pozostałymi, co do których mam wątpliwości), masz czysto. Jedynie masz dość dużo oprogramowania, może warto coś przyciąć w autostarcie?

Ewentualnie wrzuć log z comboscan, w nim znacznie więcej widać.

Link do komentarza
Udostępnij na innych stronach

Witam!Mam prośbę czy mógłby ktoś rzucić okiem na log.....i mam pytanie co to jest System Volume Information, ponieważ Avast! cały czas pokazuje w raporcie te pliki a usunąć ich nie idzie???z gory dziiękii:

Logfile of HijackThis v1.99.1

Scan saved at 17:02:24, on 2007-06-01

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

C:Program FilesAlwil SoftwareAvast4ashServ.exe

C:WINDOWSExplorer.EXE

C:WINDOWSsystem32spoolsv.exe

C:Program FilesGrisoftAVG Anti-Spyware 7.5guard.exe

C:PROGRA~1ALWILS~1Avast4ashDisp.exe

C:Program FilesJavajre1.6.0_01binjusched.exe

C:Program FilesThomsonSpeedTouch USBDragdiag.exe

C:WINDOWSsystem32RUNDLL32.EXE

C:WINDOWSsystem32nvsvc32.exe

C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe

C:Program FilesAlwil SoftwareAvast4ashWebSv.exe

C:WINDOWSsystem32wscntfy.exe

C:Program FilesGadu-Gadugg.exe

C:Program FilesWinampwinamp.exe

C:Program FilesMozilla Firefoxfirefox.exe

C:DOCUME~1szefunioUSTAWI~1TempRar$EX00.093HijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_01binssv.dll

O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe

O4 - HKLM..Run: [sunJavaUpdateSched] "C:Program FilesJavajre1.6.0_01binjusched.exe"

O4 - HKLM..Run: [speedTouch USB Diagnostics] "C:Program FilesThomsonSpeedTouch USBDragdiag.exe" /icon

O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup

O4 - HKLM..Run: [nwiz] nwiz.exe /install

O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit

O4 - HKCU..Run: [DAEMON Tools] "C:Program FilesDAEMON Toolsdaemon.exe" -lang 1033

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_01binssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_01binssv.dll

O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL

O17 - HKLMSystemCCSServicesTcpip..{AD63D84B-D30A-4683-9A31-FE2A7EE73FA9}: NameServer = 213.241.79.37 83.238.255.76

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:Program FilesAlwil SoftwareAvast4ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashWebSv.exe" /service (file missing)

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:Program FilesGrisoftAVG Anti-Spyware 7.5guard.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe

Link do komentarza
Udostępnij na innych stronach

nowy log:

Logfile of HijackThis v1.99.1

Scan saved at 16:17:54, on 2007-06-03

Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSsystem32spoolsv.exe

C:WINDOWSExplorer.EXE

C:WINDOWSSystem32RUNDLL32.EXE

C:Program FilesAOLActive Virus Shieldavp.exe

C:WINDOWSSystem32CTHELPER.EXE

C:WINDOWSSystem32ctfmon.exe

C:Program FilesAOLActive Virus Shieldavp.exe

C:Documents and SettingsMarcelPulpitHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx

O2 - BHO: XBTP06568 - {311F9DE8-6126-4EEE-B15F-65CBB3B4F9F6} - C:Program FilesAOL Security ToolbarAOL_security_toolbar.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx

O3 - Toolbar: AOL Security Toolbar - {3BB63FD4-3C00-44D7-94A9-5DE211900DEF} - C:Program FilesAOL Security ToolbarAOL_security_toolbar.dll

O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup

O4 - HKLM..Run: [nwiz] nwiz.exe /install

O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit

O4 - HKLM..Run: [aol] "C:Program FilesAOLActive Virus Shieldavp.exe"

O4 - HKLM..Run: [CTHelper] CTHELPER.EXE

O4 - HKLM..Run: [updReg] C:WINDOWSUpdReg.EXE

O4 - HKLM..Run: [Jet Detection] "C:Program FilesCreativeSBLivePROGRAMADGJDet.exe"

O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm

O12 - Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll

O20 - Winlogon Notify: klogon - C:WINDOWSSystem32klogon.dll

O23 - Service: Active Virus Shield (AVP) - AOL - C:Program FilesAOLActive Virus Shieldavp.exe

O23 - Service: Creative Service for CDROM Access - Unknown owner - C:WINDOWSSystem32CTsvcCDA.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:WINDOWSSystem32nvsvc32.exe (file missing)

O23 - Service: WMDM PMSP Service - Unknown owner - C:WINDOWSSystem32MsPMSPSv.exe (file missing)

Link do komentarza
Udostępnij na innych stronach

Dopiero ucze się sprawdzać logi ale coś mi się nie podoba w moim .

Oto i on:

Logfile of HijackThis v1.99.1

Scan saved at 17:43:12, on 2007-06-02

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:windowsSystem32smss.exe

C:windowssystem32winlogon.exe

C:windowssystem32services.exe

C:windowssystem32lsass.exe

C:windowssystem32svchost.exe

C:windowsSystem32svchost.exe

C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

C:Program FilesAlwil SoftwareAvast4ashServ.exe

C:windowsExplorer.EXE

C:windowssystem32spoolsv.exe

C:Program FilesVIARAIDraid_tool.exe

C:windowsSOUNDMAN.EXE

C:Program FilesWinampwinampa.exe

C:Program FilesJavajre1.6.0_01binjusched.exe

C:PROGRA~1SonySONICS~1SsAAD.exe

C:PROGRA~1ALWILS~1Avast4ashDisp.exe

C:Program FilesDAEMON Toolsdaemon.exe

C:windowssystem32ctfmon.exe

C:Program FilesCommon FilesAheadLibNMBgMonitor.exe

c:progra~1intern~1iexplore.exe

C:Program FilesCommon FilesAheadLibNMIndexStoreSvr.exe

C:windowssystem32ircomm2k.exe

C:windowssystem32svchost.exe

C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe

C:Program FilesAlwil SoftwareAvast4ashWebSv.exe

C:Program FilesGadu-Gadugg.exe

C:windowssystem32wuauclt.exe

C:Program FilesOperaOpera.exe

C:Documents and SettingsKamilPulpitHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://search.bearshare.com/sidebar.html?src=ssb

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://google.bearshare.com/pl/

R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

R3 - URLSearchHook: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - (no file)

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:Program FilesBitComettoolsBitCometBHO.dll

O2 - BHO: (no name) - {711B571A-7547-4918-AA58-C48AC791C4F1} - C:WINDOWSsystem32khfghgd.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_01binssv.dll

O2 - BHO: WebManager Class - {D5792AA9-D373-4039-8670-2CDAB6A71F15} - C:Program FilesTorrent101TorrentManager.dll

O2 - BHO: XBTP01621 - {F6104497-54FD-4688-9162-5115CC8AB0FB} - C:PROGRA~1BEARSH~1BEARSH~2MediaBar.dll

O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:Program FilesBearShare applicationsBearShare MediaBarMediaBar.dll

O4 - HKLM..Run: [RaidTool] C:Program FilesVIARAIDraid_tool.exe

O4 - HKLM..Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe

O4 - HKLM..Run: [NeroFilterCheck] C:Program FilesCommon FilesAheadLibNeroCheck.exe

O4 - HKLM..Run: [sunJavaUpdateSched] "C:Program FilesJavajre1.6.0_01binjusched.exe"

O4 - HKLM..Run: [ssAAD.exe] C:PROGRA~1SonySONICS~1SsAAD.exe

O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe

O4 - HKLM..Run: [DAEMON Tools] "C:Program FilesDAEMON Toolsdaemon.exe" -lang 1033

O4 - HKCU..Run: [CTFMON.EXE] C:windowssystem32ctfmon.exe

O4 - HKCU..Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:Program FilesCommon FilesAheadLibNMBgMonitor.exe"

O4 - HKCU..Run: [Vcbat] C:DOCUME~1KamilDANEAP~1FILESH~1dead does.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exe

O8 - Extra context menu item: Download all links using BitComet - res://C:Program FilesBitCometBitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Download all videos using BitComet - res://C:Program FilesBitCometBitComet.exe/AddVideo.htm

O8 - Extra context menu item: Download link using &BitComet - res://C:Program FilesBitCometBitComet.exe/AddLink.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_01binssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_01binssv.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O20 - Winlogon Notify: khfghgd - C:windowsSYSTEM32khfghgd.dll

O20 - Winlogon Notify: winmfu32 - C:windowsSYSTEM32winmfu32.dll

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:Program FilesAlwil SoftwareAvast4ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashWebSv.exe" /service (file missing)

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe

O23 - Service: Virtual IR COM Port, Service Program (IrCOMM2kSvc) - Jan Kiszka - C:windowssystem32ircomm2k.exe

O23 - Service: MSCSPTISRV - Sony Corporation - C:Program FilesCommon FilesSony SharedAVLibMSCSPTISRV.exe

O23 - Service: NBService - Nero AG - C:Program FilesNeroNero 7Nero BackItUpNBService.exe

O23 - Service: PACSPTISVR - Sony Corporation - C:Program FilesCommon FilesSony SharedAVLibPACSPTISVR.exe

O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:Program FilesCommon FilesSony SharedAVLibSPTISRV.exe

O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:Program FilesCommon FilesSony SharedAVLibSSScsiSV.exe

Link do komentarza
Udostępnij na innych stronach

F@mas -> Czy od ostatniego włączenia komputera (lub restartu) instalowałeś jakiś program? Jeśli tak, to zrób reboot i daj nowy log (najlepiej edytuj ten stary i daj mi znać przez pw, gdybym nie zauważył).

Kamil Walas -> Wywal bearshare i wszystko, co z nim związane.

Później, jeśli jeszcze coś w logu hijack this zostanie, to wywalaj. Poniżej masz wpisy, ale jeśli są ścieżki do plików, to też usuń pliki. Jeśli jakiś plik stanowi problem, użyj programu killbox.

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://search.bearshare.com/sidebar.html?src=ssb

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://google.bearshare.com/pl/

R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb

R3 - URLSearchHook: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - (no file)

O2 - BHO: (no name) - {711B571A-7547-4918-AA58-C48AC791C4F1} - C:WINDOWSsystem32khfghgd.dll <- Usuń też plik

O2 - BHO: XBTP01621 - {F6104497-54FD-4688-9162-5115CC8AB0FB} - C:PROGRA~1BEARSH~1BEARSH~2MediaBar.dll

O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:Program FilesBearShare applicationsBearShare MediaBarMediaBar.dll

O4 - HKCU..Run: [Vcbat] C:DOCUME~1KamilDANEAP~1FILESH~1dead does.exe <- Nie znam, na google nie ma

O20 - Winlogon Notify: khfghgd - C:windowsSYSTEM32khfghgd.dll

O20 - Winlogon Notify: winmfu32 - C:windowsSYSTEM32winmfu32.dll

Link do komentarza
Udostępnij na innych stronach

Log z hijack this:

Logfile of HijackThis v1.99.1

Scan saved at 22:28:23, on 2007-06-01

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)



Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:Program FilesPanda SoftwarePanda Antivirus + Firewall 2007pavsrv51.exe

C:Program FilesPanda SoftwarePanda Antivirus + Firewall 2007AVENGINE.EXE

C:WINDOWSsystem32svchost.exe

C:Program FilesPanda SoftwarePanda Antivirus + Firewall 2007TPSrv.exe

c:program filespanda softwarepanda antivirus + firewall 2007firewallPNMSRV.EXE

C:WINDOWSsystem32spoolsv.exe

C:WINDOWSExplorer.EXE

C:WINDOWSsystem32CTsvcCDA.exe

C:Program FilesCommon FilesMicrosoft SharedVS7Debugmdm.exe

C:WINDOWSSystem32nvsvc32.exe

C:Program FilesPanda SoftwarePanda Antivirus + Firewall 2007PavFnSvr.exe

C:Program FilesCommon FilesPanda SoftwarePavShldpavprsrv.exe

C:Program FilesPanda SoftwarePanda Antivirus + Firewall 2007PsImSvc.exe

C:Program FilesAnalog DevicesSoundMAXSMAgent.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesPanda SoftwarePanda Antivirus + Firewall 2007APVXDWIN.EXE

C:Program FilesJavajre1.6.0_01binjusched.exe

C:Program FilesXfirexfiremusic.exe

C:Program FilesCyberLinkPowerDVDPDVDServ.exe

C:Program FilesGadu-Gadugg.exe

C:WINDOWSsystem32ctfmon.exe

C:program filessteamsteam.exe

c:program filespanda softwarepanda antivirus + firewall 2007WebProxy.exe

C:Program FilesLast.fmLastFM.exe

D:YzdockYzDock.exe

C:modysikacjeYzToolbarYzToolBar.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesXfirexfire.exe

C:Program Filesfoobar2000foobar2000.exe

C:Program FilesPanda SoftwarePanda Antivirus + Firewall 2007AvTask.exe

C:Program FilesMozilla Firefoxfirefox.exe

C:Program FilesHijackThisHijackThis.exe

C:WINDOWSsystem32wscntfy.exe



R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:PROGRA~1MEGAUP~1MEGAUP~1.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_01binssv.dll

O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:Program FilesStylerTBStylerTB.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:PROGRA~1MEGAUP~1MEGAUP~1.DLL

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll

O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup

O4 - HKLM..Run: [nwiz] nwiz.exe /install

O4 - HKLM..Run: [APVXDWIN] "C:Program FilesPanda SoftwarePanda Antivirus + Firewall 2007APVXDWIN.EXE" /s

O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.6.0_01binjusched.exe"

O4 - HKLM..Run: [Xfire Music] "C:Program FilesXfirexfiremusic.exe"

O4 - HKLM..Run: [RemoteControl] "C:Program FilesCyberLinkPowerDVDPDVDServ.exe"

O4 - HKLM..Run: [DAEMON Tools] "C:Program FilesDAEMON Toolsdaemon.exe" -lang 1033

O4 - HKLM..Run: [CloneCDTray] "C:Program FilesSlySoftCloneCDCloneCDTray.exe" /s

O4 - HKCU..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NVMCTRAY.DLL,NvTaskbarInit

O4 - HKCU..Run: [Gadu-Gadu] "C:Program FilesGadu-Gadugg.exe" /tray

O4 - HKCU..Run: [AQQ] C:PROGRA~1WapsterAQQAQQ.exe

O4 - HKCU..Run: [Taskbar Hide] C:PROGRA~1TASKBA~1TaskBar.exe -Start

O4 - HKCU..Run: [CTSyncU.exe] "C:Program FilesCreativeSync Manager UnicodeCTSyncU.exe"

O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe

O4 - HKCU..Run: [Steam] "c:program filessteamsteam.exe" -silent

O4 - Startup: Adobe Gamma.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe

O4 - Startup: Last.fm (2).lnk = C:Program FilesLast.fmLastFM.exe

O4 - Startup: Skrót do YzDock.lnk = D:YzdockYzDock.exe

O4 - Startup: Skrót do YzToolBar.lnk = C:modysikacjeYzToolbarYzToolBar.exe

O4 - Startup: Xfire.lnk = C:Program FilesXfirexfire.exe

O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE

O4 - Global Startup: Scanner Finder.lnk = C:Program FilesScanWizard 5ScannerFinder.exe

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_01binnpjpi160_01.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_01binnpjpi160_01.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O20 - Winlogon Notify: avldr - C:WINDOWSSYSTEM32avldr.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:WINDOWSsystem32CTsvcCDA.exe

O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:WINDOWSSystem32nvsvc32.exe

O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:Program FilesPanda SoftwarePanda Antivirus + Firewall 2007PavFnSvr.exe

O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:Program FilesCommon FilesPanda SoftwarePavShldpavprsrv.exe

O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:Program FilesPanda SoftwarePanda Antivirus + Firewall 2007pavsrv51.exe

O23 - Service: Panda Network Manager (PNMSRV) - Panda Software International - c:program filespanda softwarepanda antivirus + firewall 2007firewallPNMSRV.EXE

O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software - C:Program FilesPanda SoftwarePanda Antivirus + Firewall 2007PsImSvc.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:Program FilesAnalog DevicesSoundMAXSMAgent.exe

O23 - Service: Panda TPSrv (TPSrv) - Panda Software - C:Program FilesPanda SoftwarePanda Antivirus + Firewall 2007TPSrv.exe

Czysto :).

[wies.niak]

Link do komentarza
Udostępnij na innych stronach

Logfile of HijackThis v1.99.1

Scan saved at 14:05:14, on 2007-06-18

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

C:Program FilesAlwil SoftwareAvast4ashServ.exe

C:WINDOWSsystem32spoolsv.exe

C:Program FilescFosSpeedspd.exe

C:WINDOWSsystem32nvsvc32.exe

C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe

C:Program FilesAlwil SoftwareAvast4ashWebSv.exe

C:WINDOWSSystem32svchost.exe

C:PROGRA~1COMMON~1StardockSDMCP.exe

C:WINDOWSExplorer.EXE

C:Program FilesPicasa2PicasaMediaDetector.exe

C:Program FilescFosSpeedcFosSpeed.exe

C:PROGRA~1ALWILS~1Avast4ashDisp.exe

C:WINDOWSsystem32RUNDLL32.EXE

C:PROGRA~1MYWEBS~1bar1.binmwsoemon.exe

C:Program FilesGadu-Gadugg.exe

C:Program FilesMessengermsmsgs.exe

C:Program FilesDAEMON Toolsdaemon.exe

C:WINDOWSsystem32svchost.exe

C:Program FilesSiber SystemsAI RoboFormRoboTaskBarIcon.exe

C:Program FilesSAGEM WiFi managerWLANUTL.exe

C:Program FilesOpenOffice.org 2.0programsoffice.exe

C:Program FilesOpenOffice.org 2.0programsoffice.BIN

C:Program FilesNetPanelNetPanel.exe

C:WINDOWSsystem32wuauclt.exe

C:PROGRA~1Mozilla Firefoxfirefox.exe

C:Program FilesAlwil SoftwareAvast4ashSimpl.exe

C:DOCUME~1mord00kUSTAWI~1TempKatalog tymczasowy 1 dla hijackthis.zipHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = http://www.neostrada.pl/

R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = 200.238.102.170:8080

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:PROGRA~1MEGAUP~1MEGAUP~1.DLL

O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:Program FilesSiber SystemsAI RoboFormroboform.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_10binssv.dll

O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:Program FilesNetPanelIEHelper.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:PROGRA~1MEGAUP~1MEGAUP~1.DLL

O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:Program FilesSiber SystemsAI RoboFormroboform.dll

O4 - HKLM..Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe

O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe

O4 - HKLM..Run: [Picasa Media Detector] C:Program FilesPicasa2PicasaMediaDetector.exe

O4 - HKLM..Run: [NetPanel] "C:Program FilesNetPanelStarter.exe" /path="C:Program FilesNetPanel"

O4 - HKLM..Run: [cFosSpeed] C:Program FilescFosSpeedcFosSpeed.exe

O4 - HKLM..Run: [LClock] C:Program FilesLClockLClock.exe

O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe

O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup

O4 - HKLM..Run: [nwiz] nwiz.exe /install

O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit

O4 - HKLM..RunOnce: [MyWebSearch bar Uninstall] rundll32 C:PROGRA~1UNINST~1.DLL,O -2

O4 - HKCU..Run: [Gadu-Gadu] "C:Program FilesGadu-Gadugg.exe" /tray

O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background

O4 - HKCU..Run: [DAEMON Tools] "C:Program FilesDAEMON Toolsdaemon.exe" -lang 1033

O4 - HKCU..Run: [PeerGuardian] C:Program FilesPeerGuardian2pg2.exe

O4 - HKCU..Run: [Expressivo] "C:Program FilesivoExpressivo Demoexpressivo.exe" -t

O4 - HKCU..Run: [Aim6] "C:Program FilesAIM6aim6.exe" /d locale=en-US ee://aol/imApp

O4 - HKCU..Run: [PSwitch] C:Program FilesProxy Switcher StandardProxySwitcher.exe

O4 - HKCU..Run: [VS Online] "C:Program FilesVS OnlineVSOnline.exe" /tray

O4 - HKCU..Run: [RoboForm] "C:Program FilesSiber SystemsAI RoboFormRoboTaskBarIcon.exe"

O4 - Startup: Adobe Gamma.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe

O4 - Startup: OpenOffice.org 2.0.lnk = C:Program FilesOpenOffice.org 2.0programquickstart.exe

O4 - Startup: Stardock ObjectDock.lnk = C:Program FilesStardockObjectDockObjectDock.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:Program FilesAdobeReader 8.0Readerreader_sl.exe

O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:Program FilesAdobeReader 8.0ReaderAdobeCollabSync.exe

O4 - Global Startup: Program sieciowy dla SAGEM Wi-Fi 11g USB adapter.lnk = ?

O8 - Extra context menu item: Pasek Narzędzi RoboForm - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComShowToolbar.html

O8 - Extra context menu item: Personalizuj Menu - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComCustomizeIEMenu.html

O8 - Extra context menu item: Wypełnij Pola - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComFillForms.html

O8 - Extra context menu item: Zapisz Pola - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComSavePass.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll

O9 - Extra button: Wypełnij pola - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComFillForms.html

O9 - Extra 'Tools' menuitem: Wypełnij Pola - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComFillForms.html

O9 - Extra button: Zapisz - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComSavePass.html

O9 - Extra 'Tools' menuitem: Zapisz Pola - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComSavePass.html

O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComShowToolbar.html

O9 - Extra 'Tools' menuitem: Pasek Narzędzi RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComShowToolbar.html

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O16 - DPF: {65D72393-E210-4A2A-B8E0-10AC45986770} (GWebInstallControl Object) - http://megapanel.gem.pl/WebInstaller.dll

O20 - Winlogon Notify: MCPClient - C:PROGRA~1COMMON~1Stardockmcpstub.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:Program FilesAlwil SoftwareAvast4ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashWebSv.exe" /service (file missing)

O23 - Service: cFosSpeed System Service (cFosSpeedS) - Unknown owner - C:Program FilescFosSpeedspd.exe" -service (file missing)

O23 - Service: Google Updater Service (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver1050Intel 32IDriverT.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe

proszę o pomoc ;]

Link do komentarza
Udostępnij na innych stronach

Jeśli coś stawia opór, użyj programu killbox z zaznaczoną opcją delete on reboot.

Usuń:

C:PROGRA~1MYWEBS~1bar1.binmwsoemon.exe < cały katalog mywebs~1 (mywebsearch pewnie) ma zniknąć

O4 - HKLM..RunOnce: [MyWebSearch bar Uninstall] rundll32 C:PROGRA~1UNINST~1.DLL,O -2

Link do komentarza
Udostępnij na innych stronach

Wywaliłem po prostu cały mywebsearch przez uninstalkę... styka? Bo już nie mam tych wskazanych przez Ciebie w logu ;]

Dzięki

Logfile of HijackThis v1.99.1

Scan saved at 20:36:13, on 2007-06-18

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

C:Program FilesAlwil SoftwareAvast4ashServ.exe

C:WINDOWSsystem32spoolsv.exe

C:Program FilescFosSpeedspd.exe

C:WINDOWSsystem32nvsvc32.exe

C:PROGRA~1COMMON~1StardockSDMCP.exe

C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe

C:Program FilesAlwil SoftwareAvast4ashWebSv.exe

C:WINDOWSExplorer.EXE

C:WINDOWSSystem32svchost.exe

C:Program FilesPicasa2PicasaMediaDetector.exe

C:WINDOWSsystem32svchost.exe

C:Program FilescFosSpeedcFosSpeed.exe

C:PROGRA~1ALWILS~1Avast4ashDisp.exe

C:WINDOWSsystem32RUNDLL32.EXE

C:Program FilesGadu-Gadugg.exe

C:Program FilesMessengermsmsgs.exe

C:Program FilesDAEMON Toolsdaemon.exe

C:Program FilesNetPanelNetPanel.exe

C:Program FilesSiber SystemsAI RoboFormRoboTaskBarIcon.exe

C:Program FilesSAGEM WiFi managerWLANUTL.exe

C:Program FilesOpenOffice.org 2.0programsoffice.exe

C:Program FilesOpenOffice.org 2.0programsoffice.BIN

C:WINDOWSsystem32wuauclt.exe

C:PROGRA~1Mozilla Firefoxfirefox.exe

C:DOCUME~1mord00kUSTAWI~1TempKatalog tymczasowy 3 dla hijackthis.zipHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = http://www.neostrada.pl/

R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = 200.238.102.170:8080

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:PROGRA~1MEGAUP~1MEGAUP~1.DLL

O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:Program FilesSiber SystemsAI RoboFormroboform.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_10binssv.dll

O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:Program FilesNetPanelIEHelper.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:PROGRA~1MEGAUP~1MEGAUP~1.DLL

O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:Program FilesSiber SystemsAI RoboFormroboform.dll

O4 - HKLM..Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe

O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe

O4 - HKLM..Run: [Picasa Media Detector] C:Program FilesPicasa2PicasaMediaDetector.exe

O4 - HKLM..Run: [NetPanel] "C:Program FilesNetPanelStarter.exe" /path="C:Program FilesNetPanel"

O4 - HKLM..Run: [cFosSpeed] C:Program FilescFosSpeedcFosSpeed.exe

O4 - HKLM..Run: [LClock] C:Program FilesLClockLClock.exe

O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe

O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup

O4 - HKLM..Run: [nwiz] nwiz.exe /install

O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit

O4 - HKCU..Run: [Gadu-Gadu] "C:Program FilesGadu-Gadugg.exe" /tray

O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background

O4 - HKCU..Run: [DAEMON Tools] "C:Program FilesDAEMON Toolsdaemon.exe" -lang 1033

O4 - HKCU..Run: [PeerGuardian] C:Program FilesPeerGuardian2pg2.exe

O4 - HKCU..Run: [Expressivo] "C:Program FilesivoExpressivo Demoexpressivo.exe" -t

O4 - HKCU..Run: [Aim6] "C:Program FilesAIM6aim6.exe" /d locale=en-US ee://aol/imApp

O4 - HKCU..Run: [PSwitch] C:Program FilesProxy Switcher StandardProxySwitcher.exe

O4 - HKCU..Run: [VS Online] "C:Program FilesVS OnlineVSOnline.exe" /tray

O4 - HKCU..Run: [RoboForm] "C:Program FilesSiber SystemsAI RoboFormRoboTaskBarIcon.exe"

O4 - Startup: Adobe Gamma.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe

O4 - Startup: OpenOffice.org 2.0.lnk = C:Program FilesOpenOffice.org 2.0programquickstart.exe

O4 - Startup: Stardock ObjectDock.lnk = C:Program FilesStardockObjectDockObjectDock.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:Program FilesAdobeReader 8.0Readerreader_sl.exe

O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:Program FilesAdobeReader 8.0ReaderAdobeCollabSync.exe

O4 - Global Startup: Program sieciowy dla SAGEM Wi-Fi 11g USB adapter.lnk = ?

O8 - Extra context menu item: Pasek Narzędzi RoboForm - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComShowToolbar.html

O8 - Extra context menu item: Personalizuj Menu - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComCustomizeIEMenu.html

O8 - Extra context menu item: Wypełnij Pola - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComFillForms.html

O8 - Extra context menu item: Zapisz Pola - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComSavePass.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll

O9 - Extra button: Wypełnij pola - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComFillForms.html

O9 - Extra 'Tools' menuitem: Wypełnij Pola - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComFillForms.html

O9 - Extra button: Zapisz - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComSavePass.html

O9 - Extra 'Tools' menuitem: Zapisz Pola - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComSavePass.html

O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComShowToolbar.html

O9 - Extra 'Tools' menuitem: Pasek Narzędzi RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:Program FilesSiber SystemsAI RoboFormRoboFormComShowToolbar.html

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O16 - DPF: {65D72393-E210-4A2A-B8E0-10AC45986770} (GWebInstallControl Object) - http://megapanel.gem.pl/WebInstaller.dll

O20 - Winlogon Notify: MCPClient - C:PROGRA~1COMMON~1Stardockmcpstub.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:Program FilesAlwil SoftwareAvast4ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashWebSv.exe" /service (file missing)

O23 - Service: cFosSpeed System Service (cFosSpeedS) - Unknown owner - C:Program FilescFosSpeedspd.exe" -service (file missing)

O23 - Service: Google Updater Service (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver1050Intel 32IDriverT.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe

Link do komentarza
Udostępnij na innych stronach

Dzisiaj przed momentem pierwszy raz użyłem Hijack-a, musze przyznac że zabardzo nie wiem co by stąd usunąć:

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32csrss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSsystem32svchost.exe

D:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

D:Program FilesAlwil SoftwareAvast4ashServ.exe

C:WINDOWSExplorer.EXE

C:WINDOWSsystem32spoolsv.exe

C:WINDOWSsystem32RunDLL32.exe

D:Program FilesSpyware DoctorSDTrayApp.exe

C:Program FilesCommon FilesLightScribeLSSrvc.exe

C:Program FilesCommon FilesOnet.plAutoUpdate.exe

C:Program FilesJavajre1.6.0_01binjusched.exe

C:WINDOWSsystem32nvsvc32.exe

D:PROGRA~1ALWILS~1Avast4ashDisp.exe

D:Program FilesSpyware Doctorsvcntaux.exe

C:WINDOWSCTHELPER.EXE

C:WINDOWSsystem32ctfmon.exe

D:Program FilesGadu-Gadugg.exe

D:Program FilesSpyware Doctorswdsvc.exe

C:Program FilesMozilla Firefoxfirefox.exe

D:Program FilesTSWCSysSrvc.exe

D:Program FilesAlwil SoftwareAvast4ashMaiSv.exe

D:Program FilesAlwil SoftwareAvast4ashWebSv.exe

C:WINDOWSSystem32alg.exe

C:WINDOWSsystem32wuauclt.exe

C:Program FilesWindows Media Playerwmplayer.exe

C:DOCUME~1M@TH3VUSTAWI~1TempRar$EX00.797HijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://google.bearshare.com/pl/

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =

R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = http://google.bearshare.com/pl/

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll

O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:Program FilesMyGlobalSearchbar1.binMGSBAR.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_01binssv.dll

O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:Program FilesMyGlobalSearchbar1.binMGSBAR.DLL

O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup

O4 - HKLM..Run: [nwiz] nwiz.exe /install

O4 - HKLM..Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit

O4 - HKLM..Run: [sDTray] "D:Program FilesSpyware DoctorSDTrayApp.exe"

O4 - HKLM..Run: [Onet.pl AutoUpdate] C:Program FilesCommon FilesOnet.plAutoUpdate.exe /tsr

O4 - HKLM..Run: [sunJavaUpdateSched] "C:Program FilesJavajre1.6.0_01binjusched.exe"

O4 - HKLM..Run: [avast!] D:PROGRA~1ALWILS~1Avast4ashDisp.exe

O4 - HKLM..Run: [LogonStudio] "D:Program FilesWinCustomizeLogonStudiologonstudio.exe" /RANDOM

O4 - HKLM..Run: [CTHelper] CTHELPER.EXE

O4 - HKLM..Run: [CTxfiHlp] CTXFIHLP.EXE

O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe

O4 - HKCU..Run: [Gadu-Gadu] "D:Program FilesGadu-Gadugg.exe" /tray

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_01binssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_01binssv.dll

O9 - Extra button: Pop-Up Blocker - {84536FE2-ABCD-3586-DCAB-40E286323737} - D:Program FilesWINnerTweak3PopUp Blocker.exe

O9 - Extra 'Tools' menuitem: Pop-Up Blocker - {84536FE2-ABCD-3586-DCAB-40E286323737} - D:Program FilesWINnerTweak3PopUp Blocker.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O17 - HKLMSystemCCSServicesTcpip..{5D124FFE-EF3B-46B2-A450-F352EE545F5F}: NameServer = 10.1.11.254,190.150.77.18

O17 - HKLMSystemCS1ServicesTcpip..{5D124FFE-EF3B-46B2-A450-F352EE545F5F}: NameServer = 10.1.11.254,190.150.77.18

O17 - HKLMSystemCS2ServicesTcpip..{5D124FFE-EF3B-46B2-A450-F352EE545F5F}: NameServer = 10.1.11.254,190.150.77.18

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:WINDOWSsystem32WPDShServiceObj.dll

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - D:Program FilesAlwil SoftwareAvast4ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - D:Program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - D:Program FilesAlwil SoftwareAvast4ashWebSv.exe" /service (file missing)

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:Program FilesCommon FilesLightScribeLSSrvc.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe

O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - D:Program FilesSpyware Doctorsvcntaux.exe

O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - D:Program FilesSpyware Doctorswdsvc.exe

O23 - Service: SysSrvc - Unknown owner - D:Program FilesTSWCSysSrvc.exe

i teraz mam prośbe jeżeli ktoś mi poda co mam usunąć to prosze o uzasadnienie dlaczego, czy jest jaki poradnik do Hijack?

Link do komentarza
Udostępnij na innych stronach

Usuń te wpisy:

O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:Program FilesMyGlobalSearchbar1.binMGSBAR.DLL

O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:Program FilesMyGlobalSearchbar1.binMGSBAR.DLL

Poza tym cały katalog MyGlobalSearch ma zniknąć. Jeśli jakiś plik stawia opór, użyj killbox w trybie delete on reboot.

Co do Twojego pytania:

www.google.pl

www.hijackthis.de

Korzystam z tych stron analizując logi, jeśli nie rozpoznaję jakichś plików.

Poradniki są, chyba nawet na searchengines widziałem jakiś.

Po przeanalizowaniu kilkudziesięciu logów, zwykle nie trzeba korzystać z pomocy, bo zna się dość dobrze system i typowe pliki.

Link do komentarza
Udostępnij na innych stronach

Gość
Temat jest zablokowany i nie można w nim pisać.


  • Kto przegląda   0 użytkowników

    • Brak zalogowanych użytkowników przeglądających tę stronę.

×
×
  • Utwórz nowe...