Chcesz sprawdzić swój log z Hijackthisa? Wklej go tutaj...

Status
Zamknięty.

patology

Były Moderator
Dołączył
Październik 30, 2005
Posty
205
O4 - HKLM..RunOnce: [iMeshBar Uninstall] rundll32 C:pROGRA~1UNINST~1.DLL,O -2

O8 - Extra context menu item: Open using &Advanced JPEG Compressor - C:program FilesAdvanced JPEG Compressorajcieex.htm

O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -[/b]
fixujesz a to, a tak to ok
 

Speedie88

Użytkownik
Dołączył
Styczeń 31, 2006
Posty
148
Dziękówa chłopaki
<
k:
<
k:
<
k:
 

T4j3mn1czy

Użytkownik
Dołączył
Styczeń 2, 2006
Posty
4
Zobaczcie mój
smile.gif

Kod:
Logfile of HijackThis v1.99.1

Scan saved at 14:06:28, on 2006-03-17

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)



Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSsystem32spoolsv.exe

C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE

c:usrMYSQLbinmysqld.exe

C:WINDOWSExplorer.EXE

C:WINDOWSsystem32WgaTray.exe

C:WINDOWSsystem32wscntfy.exe

C:Program FilesJavajre1.5.0_06binjusched.exe

C:WINDOWSsystem32ctfmon.exe

C:Program FilesGadu-Gadugg.exe

C:Program FilesMozilla Firefoxfirefox.exe

C:Program FilesBitCometBitComet.exe

C:Program FilesWindows Media Playerwmplayer.exe

F:instalkiHijackThis.exe



R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll

O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:Program FilesRXToolBarsfcont.dll (file missing)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_06binssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:program filesgooglegoogletoolbar2.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program filesgooglegoogletoolbar2.dll

O4 - HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavajre1.5.0_06binjusched.exe

O4 - HKLM..Run: [SemanticInsight] C:Program FilesRXToolBarSemantic InsightSemanticInsight.exe

O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe

O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengerMSMSGS.EXE" /background

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exe

O8 - Extra context menu item: &Google Search - res://c:program filesgoogleGoogleToolbar2.dll/cmsearch.html

O8 - Extra context menu item: &Translate English Word - res://c:program filesgoogleGoogleToolbar2.dll/cmwordtrans.html

O8 - Extra context menu item: Backward Links - res://c:program filesgoogleGoogleToolbar2.dll/cmbacklinks.html

O8 - Extra context menu item: Cached Snapshot of Page - res://c:program filesgoogleGoogleToolbar2.dll/cmcache.html

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:PROGRA~1MICROS~3OFFICE11EXCEL.EXE/3000

O8 - Extra context menu item: Similar Pages - res://c:program filesgoogleGoogleToolbar2.dll/cmsimilar.html

O8 - Extra context menu item: Translate Page into English - res://c:program filesgoogleGoogleToolbar2.dll/cmtrans.html

O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:Program FilesVisualRoutevrie.dll

O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:Program FilesVisualRoutevrie.dll

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_06binssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_06binssv.dll

O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~3OFFICE11REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O17 - HKLMSystemCCSServicesTcpip..{C8690E8E-811F-4D17-986E-55BDCB1CF08F}: NameServer = 194.204.152.34,217.98.63.164

O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:Program FilesRXToolBarsfcont.dll

O20 - Winlogon Notify: WgaLogon - C:WINDOWSSYSTEM32WgaLogon.dll

O23 - Service: MySql - Unknown owner - c:usr/MYSQL/bin/mysqld.exe

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%WinPcaprpcapd.exe" -d -f "%ProgramFiles%WinPcaprpcapd.ini (file missing)
 

patology

Były Moderator
Dołączył
Październik 30, 2005
Posty
205
O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:program FilesRXToolBarsfcont.dll (file missing)

O17 - HKLMSystemCCSServicesTcpip..{C8690E8E-811F-4D17-986E-55BDCB1CF08F}: NameServer = 194.204.152.34,217.98.63.164

O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:program FilesRXToolBarsfcont.dll[/b]
to FIX
 

T4j3mn1czy

Użytkownik
Dołączył
Styczeń 2, 2006
Posty
4
Ok dzięki
smile.gif
Ale to są moje dnsy " O17 - HKLMSystemCCSServicesTcpip..{C8690E8E-811F-4D17-986E-55BDCB1CF08F}: NameServer = 194.204.152.34,217.98.63.164 "

Więc raczej nie powinienem tego usuwać
smile.gif
 

patology

Były Moderator
Dołączył
Październik 30, 2005
Posty
205
Originally posted by T4j3mn1czy
Ok dzięki
smile.gif
Ale to są moje dnsy " O17 - HKLMSystemCCSServicesTcpip..{C8690E8E-811F-4D17-986E-55BDCB1CF08F}: NameServer = 194.204.152.34,217.98.63.164 "

Więc raczej nie powinienem tego usuwać
smile.gif
'194.204.152.34,217.98.63.164'

Sorry, nie usuwaj to jest prawidlowe =]
 

rit3ks

Użytkownik
Dołączył
Luty 21, 2006
Posty
2
...

Możecie powiedziec cos na temat tych dwuch wpisów.
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)(file missing), O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:program FilesCommon FilesSoftwinBitDefender Update Servicelivesrv.exe" /service (file missing)[/b]
Mam jeszcze jedno pyatnie. Otóż przeskanowałem system antywirusem (BitDefender 9 Professional Plus) i wykrył mi coś takiego:
C:WINDOWSsvchost.exe Infected: BehavesLike:Trojan.FirewallBypass[/b]
O ile się nie myle to ten plik jest niezbedny do prawidłowego działania systemu, jeżeli jest on zainfekowany da się go przywrucic do poprzedniego stanu??
 

DJ_Max

Użytkownik
Dołączył
Październik 2, 2005
Posty
28
To ja tylko wtrącę z takim pytaniem, nie możecie po prostu powiedzieć po czym poznać nieprawidłowości?
 

red_ag

Były Moderator
Dołączył
Listopad 26, 2005
Posty
261
Komputer zaczyna się "nienormalnie" zachowywać: wolno pracuje, wolno otwierają się strony WWW, zamiast strony X otwiera się Y, często pojawiają się dziwne błędy i komunikaty, nowe (Dziwne) przyciski na pasku przeglądarki IE, na pasku obok zegara (Najczęściej dialery) zaczynają tajemniczo znikać pliki, połączenie z Internetem trwa 30s ... itp.

Może oznaczać tylko jedno - mamy gościa ...

by Aniołek.
 

patology

Były Moderator
Dołączył
Październik 30, 2005
Posty
205
Re: ...

Originally posted by rit3ks
Możecie powiedziec cos na temat tych dwuch wpisów.
<div class='quotetop'>CYTAT
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)(file missing), O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:program FilesCommon FilesSoftwinBitDefender Update Servicelivesrv.exe" /service (file missing)
Mam jeszcze jedno pyatnie. Otóż przeskanowałem system antywirusem (BitDefender 9 Professional Plus) i wykrył mi coś takiego:
C:WINDOWSsvchost.exe Infected: BehavesLike:Trojan.FirewallBypass[/b]
O ile się nie myle to ten plik jest niezbedny do prawidłowego działania systemu, jeżeli jest on zainfekowany da się go przywrucic do poprzedniego stanu??[/b][/quote]
O ile sie nie myle to prawidlowy svchost jest tu --> C:Windowssystem32. Ten svchost z c:windows jest trojanem --> usun wpis w hijackthis, nastepnie usun plik w killboxie.

To ja tylko wtrącę z takim pytaniem, nie możecie po prostu powiedzieć po czym poznać nieprawidłowości?[/b]
http://www.searchengines.pl/phpbb203/index...showtopic=15989
 

rinesk

Użytkownik
Dołączył
Wrzesień 1, 2004
Posty
33
Logfile of HijackThis v1.99.1
Scan saved at 23:01:26, on 19/04/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32csrss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSSystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:program FilesCommon FilesSymantec SharedccSetMgr.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:program FilesCommon FilesSymantec SharedccApp.exe
C:program FilesMessengermsmsgs.exe
C:WINDOWSwupdmgr.exe
C:WINDOWSosaupd.exe
C:WINDOWSsystem32spoolsv.exe
C:program FilesCommon FilesSymantec SharedccProxy.exe
C:WINDOWSS2F0aWUcommand.exe
C:program FilesNorton Internet SecurityNorton AntiVirusnavapsvc.exe
C:program FilesNorton Internet SecurityNorton AntiVirusSAVScan.exe
C:program FilesCommon FilesSymantec SharedSNDSrvc.exe
C:program FilesInventelGatewaywlancfg.exe
C:WINDOWSSystem32wuauclt.exe
C:WINDOWSsystem32ezSP_Px.exe
C:program FilesWindows Media Playerwmplayer.exe
C:program FilesInternet Exploreriexplore.exe
C:program FilesInternet Exploreriexplore.exe
C:program FilesInternet Exploreriexplore.exe
c:progra~1intern~1iexplore.exe
C:Documents and SettingsKatieDesktopHiJackHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = about:blank
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.wanadoo.co.uk/iesearch/default.htm
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.wanadoo.co.uk/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = http://www.wanadoo.co.uk/cd_redirects/wanadoohome
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Microsoft Internet Explorer provided by Wanadoo
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:pROGRA~1WanadooWSBarWSBar.dll
O4 - HKLM..Run: [ccApp] "C:program FilesCommon FilesSymantec SharedccApp.exe"
O4 - HKLM..Run: [URLLSTCK.exe] C:program FilesNorton Internet SecurityUrlLstCk.exe
O8 - Extra context menu item: &Google Search - res://c:program filesgoogleGoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:program filesgoogleGoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:program filesgoogleGoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:program filesgoogleGoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download with NetPumper - C:program FilesNetPumperAddUrl.htm
O8 - Extra context menu item: Search with Wanadoo - res://C:pROGRA~1WanadooWSBarWSBar.dll/VSearch.htm
O8 - Extra context menu item: Similar Pages - res://c:program filesgoogleGoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:program filesgoogleGoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavaj2re1.4.2_03binnpjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavaj2re1.4.2_03binnpjpi142_03.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} (GameDesire Poker Games) - http://67.15.101.3/g_bin/pl/poker_2_0_0_39.cab
O16 - DPF: {A6212120-01D4-11D5-9A39-0080C8D85044} (GameDesire Slots 70th) - http://67.15.101.3/g_bin/pl/slots70_2_0_0_26.cab
O16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} - http://www.azebar.com/install/1.cab
O20 - Winlogon Notify: ThemeManager - C:WINDOWSsystem32lv0609dse.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:WINDOWSSystem32Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:program FilesCommon FilesSymantec SharedccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:program FilesCommon FilesSymantec SharedccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:program FilesCommon FilesSymantec SharedccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:program FilesCommon FilesSymantec SharedccSetMgr.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:WINDOWSS2F0aWUcommand.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:program FilesNorton Internet SecurityNorton AntiVirusnavapsvc.exe
O23 - Service: PACSPTISVR - Unknown owner - C:program FilesCommon FilesSony SharedAVLibPacsptisvr.exe
O23 - Service: SAVScan - Symantec Corporation - C:program FilesNorton Internet SecurityNorton AntiVirusSAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:pROGRA~1COMMON~1SYMANT~1SCRIPT~1SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:program FilesCommon FilesSymantec SharedSNDSrvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:program FilesCommon FilesSony SharedAVLibSptisrv.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:program Filessonyvaio media music serverSSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:program FilesCommon FilesSony Sharedvaio media platformsv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="SoftwareSony CorporationVAIO Media Platform2.0" /RegExt="ApplicationsMusicServerHTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:program FilesCommon FilesSony Sharedvaio media platformUPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:program Filessonyphoto serverappsrvPhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:program FilesCommon Filessony sharedvaio media platformSV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="SoftwareSony CorporationVAIO Media Platform2.0" /RegExt="ApplicationsPhotoServerHTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:program FilesCommon Filessony sharedvaio media platformUPnPFramework.exe
O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:program FilesInventelGatewaywlancfg.exe




Moze ktos pomoc mam cos w rejestrze co sie nazywa cmdservice i nei mozna usunac . po za tym wiele innych procesow uruchamia sie podczas otwierania komputera. Nie mozan polowy usunac probowalem spybootem regdoctorem winoptimizerem niszczarkoplikow recznie wszystko i nic nie poskutkowalo nadal jest a uzywalem tez l2mfix.

Nic nie pomaga jakies dziadostwa sie uruchamia przy kazdorazowym uruchomieniu komputera i nie wiemjak to wywalic. Bo nic nie dziala. Mam nortona chociaz wiem ze to beznadziejny antywirus jak naprawie wgram lepszy ale co jest z tym ze nie mozna usunac tego cmdservice?? A razem z tym wszystkim uruchamia sie wiele innych programow min Adware Reviews ktory otwiera co sekunde strony np
http://www.topadwarereviews.com/?adv=196&ads=d

Pomozcie mam na dysku dane ktore ie chce utracic podczas formatowania.

Jesli mozna prosic o pomoc bede wdzieczny
 

RedCrow

Użytkownik
Dołączył
Luty 6, 2006
Posty
8
W trybie awaryjnym i bez przywracania systemu
znajdz i usuń pliki z dysku
C:WINDOWSwupdmgr.exe <--
C:WINDOWSosaupd.exe <--
C:WINDOWSS2F0aWUcommand.exe <-- cały folder "S2F0aWU" wywal
jak bedą oporne użyj Killboxa
KillBox
Instrukcja do Killbox

Fix w Hijack
Kod:
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank



R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank



O8 - Extra context menu item: Search with Wanadoo - res://C:PROGRA~1WanadooWSBarWSBar.dll/VSearch.htm



O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm



O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm



O16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} - [url]http://www.azebar.com/install/1.cab[/url]



O20 - Winlogon Notify: ThemeManager - C:WINDOWSsystem32lv0609dse.dll (file missing)



O23 - Service: Command Service (cmdService) - Unknown owner - C:WINDOWSS2F0aWUcommand.exe

Jak instalowałes to zostaw jak nie to wywal:
Kod:
     O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:Program Filessonyvaio media music serverSSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing



     O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:Program FilesCommon FilesSony Sharedvaio media platformsv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="SoftwareSony CorporationVAIO Media Platform2.0" /RegExt="ApplicationsMusicServerHTTP (file missing)



       O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:Program FilesCommon Filessony sharedvaio media platformSV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="SoftwareSony CorporationVAIO Media Platform2.0" /RegExt="ApplicationsPhotoServerHTTP (file missing)

Skan Ewido lub Spybot
Sp2 by się przydał i zmien albo aktualizuj IE bo dziurawiec ;/
 

DJ_Max

Użytkownik
Dołączył
Październik 2, 2005
Posty
28
TO i ja sobie nie będę żałował. Ściągnąłem podejrzaną gierkę któa się nie chciała zainstalować nigdzie indziej niż w C:/Windows. CTOP:

Logfile of HijackThis v1.99.1
Scan saved at 1:32:28 PM, on 5/7/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSSystem32CTHELPER.EXE
C:program FilesJavajre1.5.0_06binjusched.exe
C:program FilesiTunesiTunesHelper.exe
C:program FilesQuickTimeqttask.exe
C:WINDOWSSystem32ctfmon.exe
C:program FilesMSN MessengerMsnMsgr.Exe
C:program FilesSkypePhoneSkype.exe
C:WINDOWSSystem32nvsvc32.exe
C:WINDOWSSystem32svchost.exe
C:program FilesiPodbiniPodService.exe
C:program FilesGadu-Gadugg.exe
C:program FilesMozilla Firefoxfirefox.exe
C:program FilesWinRARWinRAR.exe
C:DOCUME~1MaxLOCALS~1TempRar$EX00.966HijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://g.msn.com/0SEENUS/SAOS01
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:program FilesJavajre1.5.0_06binssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O4 - HKLM..Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
O4 - HKLM..Run: [Jet Detection] "C:program FilesCreativeSBLivePROGRAMADGJDet.exe"
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit
O4 - HKLM..Run: [SunJavaUpdateSched] C:program FilesJavajre1.5.0_06binjusched.exe
O4 - HKLM..Run: [iTunesHelper] "C:program FilesiTunesiTunesHelper.exe"
O4 - HKLM..Run: [QuickTime Task] "C:program FilesQuickTimeqttask.exe" -atboottime
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 - HKCU..Run: [MsnMsgr] "C:program FilesMSN MessengerMsnMsgr.Exe" /background
O4 - HKCU..Run: [Skype] "C:program FilesSkypePhoneSkype.exe" /nosplash /minimized
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.5.0_06binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.5.0_06binssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm
O17 - HKLMSystemCCSServicesTcpip..{6C80199F-5FA8-4CC5-949D-4DDDD81C8638}: NameServer = 194.72.0.98,194.72.9.38
O17 - HKLMSystemCS1ServicesTcpip..{6C80199F-5FA8-4CC5-949D-4DDDD81C8638}: NameServer = 194.72.0.98,194.72.9.38
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:pROGRA~1MSNMES~1msgrapp.dll" (file missing)
O18 - Protocol: wpmsg - {2E0AC5A0-3597-11D6-B3ED-0001021DC1C3} - C:program FilesSpikurl_wpmsg.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:program FilesiPodbiniPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSSystem32nvsvc32.exe
 

Bartek_wawa

Użytkownik
Dołączył
Styczeń 16, 2006
Posty
29
Logfile of HijackThis v1.99.1
Scan saved at 17:14:34, on 2006-05-08
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
D:program FilesSygateSPFsmc.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
d:program FilesBorlandInterBasebinibguard.exe
d:program FilesEsetnod32krn.exe
d:program FilesBorlandInterBasebinibserver.exe
C:WINDOWSSOUNDMAN.EXE
C:program FilesJavajre1.5.0_06binjusched.exe
C:program FilesDAEMON Toolsdaemon.exe
D:program FilesEsetnod32kui.exe
D:pROGRAM FILESFRAPSFRAPS.EXE
C:program FilesLinksysWireless-B PCI AdapterOdHost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32svchost.exe
D:program FilesSkypePhoneSkype.exe
D:program FilesVentSrvventrilo_srv.exe
D:gryCall of DutyQ3E Minimizer_v1.45.exe
D:program FileseMule 0.47a-MorphXTv8.0-binemuleemule.exe
D:program Filesfoobar2000foobar2000.exe
D:program FilesOperaOpera.exe
D:program FilesGadu-Gadugg.exe
d:program FilesWinRARWinRAR.exe
C:DOCUME~1BartekUSTAWI~1TempRar$EX00.656HijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.wirusy.onet.pl/
R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = http://megapanel.gem.pl/q.php?s=ORPAYyUXg9...4161222&n=1
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:program FilesAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - d:program FilesSpybot - Search & DestroySDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:program FilesJavajre1.5.0_06binssv.dll
O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM..Run: [SunJavaUpdateSched] C:program FilesJavajre1.5.0_06binjusched.exe
O4 - HKLM..Run: [DAEMON Tools] "C:program FilesDAEMON Toolsdaemon.exe" -lang 1033
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [SmcService] D:pROGRA~1SygateSPFsmc.exe -startgui
O4 - HKLM..Run: [nod32kui] "d:program FilesEsetnod32kui.exe" /WAITSERVICE
O4 - HKCU..Run: [Fraps] D:pROGRAM FILESFRAPSFRAPS.EXE
O4 - HKCU..Run: [eMuleAutoStart] D:program FileseMule 0.47a-MorphXTv8.0-binemuleemule.exe -AutoStart
O4 - Startup: Xfire.lnk = D:program FilesXfireXfire.exe
O4 - Global Startup: Wireless-B Notebook Adapter Utility.lnk = C:program FilesLinksysWireless-B PCI AdapterStartup.exe
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:pROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O8 - Extra context menu item: Pobierz z &BitSpirit - C:program FilesBitSpiritbsurl.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.5.0_06binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.5.0_06binssv.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:pROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O16 - DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} (MainControl Class) - http://bezpieczenstwo.onet.pl/skaner/ArcaOnline.cab
O17 - HKLMSystemCCSServicesTcpip..{5BD238BE-EFEF-4065-91CF-3F122DC06FBA}: NameServer = 195.225.121.1
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe
O23 - Service: InterBase Guardian (InterBaseGuardian) - Borland Software Corporation - d:program FilesBorlandInterBasebinibguard.exe
O23 - Service: InterBase Server (InterBaseServer) - Borland Software Corporation - d:program FilesBorlandInterBasebinibserver.exe
O23 - Service: MySql - Unknown owner - c:usr/MYSQL/bin/mysqld.exe (file missing)
O23 - Service: NICSer_WMP11 - Unknown owner - C:program FilesLinksysWireless-B PCI AdapterNICServ.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - d:program FilesEsetnod32krn.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - D:program FilesSygateSPFsmc.exe

Chyba wszystko wporządku... ale może jednak :>
 

Piotrosz

Użytkownik
Dołączył
Grudzień 30, 2005
Posty
7
Logfile of HijackThis v1.99.1
Scan saved at 21:23:49, on 2006-05-11
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32csrss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
c:program FilesCommon FilesMicrosoft SharedVS7Debugmdm.exe
C:program FilesEsetnod32krn.exe
C:program FilesSpyware Doctorsdhelp.exe
C:WINDOWSsystem32slserv.exe
C:WINDOWSsystem32wdfmgr.exe
C:WINDOWSSystem32alg.exe
C:WINDOWSExplorer.EXE
C:program FilesQuickTimeqttask.exe
C:program FilesEsetnod32kui.exe
C:program FilesJavajre1.5.0_06binjusched.exe
C:program FilesWinampwinampa.exe
C:WINDOWSsystem32ctfmon.exe
C:WINDOWSBricoPacksVista InspiratObjectDockObjectDock.exe
C:WINDOWSBricoPacksVista InspiratYzToolbarYzToolBar.exe
C:Mozilla FireFoxfirefox.exe
C:Gadu - gaduGadu-Gadugg.exe
C:Documents and SettingsIrena WilkockaPulpithijackthisHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.silkroad-online.pl/
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O1 - Hosts: 222.111.150.111 gwgt1.joymax.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:program FilesAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:pROGRA~1SPYWAR~1toolsiesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:program FilesJavajre1.5.0_06binssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:pROGRA~1SPYWAR~1toolsiesdpb.dll
O4 - HKLM..Run: [QuickTime Task] "C:program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [nod32kui] "C:program FilesEsetnod32kui.exe" /WAITSERVICE
O4 - HKLM..Run: [SunJavaUpdateSched] C:program FilesJavajre1.5.0_06binjusched.exe
O4 - HKLM..Run: [WinampAgent] C:program FilesWinampwinampa.exe
O4 - HKCU..Run: [Gadu-Gadu] "C:Gadu - gaduGadu-Gadugg.exe" /tray
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - Startup: Stardock ObjectDock.lnk = C:WINDOWSBricoPacksVista InspiratObjectDockObjectDock.exe
O4 - Startup: Y'z ToolBar.lnk = C:WINDOWSBricoPacksVista InspiratYzToolbarYzToolBar.exe
O4 - Global Startup: Microsoft Office.lnk = C:program FilesOfficeOffice10OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.5.0_06binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.5.0_06binssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:pROGRA~1SPYWAR~1toolsiesdpb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:program FilesMessengermsmsgs.exe
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) - http://skaner.mks.com.pl/SkanerOnline.cab
O17 - HKLMSystemCCSServicesTcpip..{2502161A-B12E-4A2B-AAB3-78CAF29E9CE2}: NameServer = 192.168.2.1
O17 - HKLMSystemCCSServicesTcpip..{3A8CF8DB-89FD-4763-B312-EE68A65D4C61}: NameServer = 192.168.2.1
O17 - HKLMSystemCS1ServicesTcpip..{2502161A-B12E-4A2B-AAB3-78CAF29E9CE2}: NameServer = 192.168.2.1
O20 - Winlogon Notify: igfxcui - C:WINDOWSSYSTEM32igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:WINDOWSSYSTEM32WgaLogon.dll
O23 - Service: AVK Service (AVKService) - Unknown owner - C:program FilesAntiVirenKitAVKService.exe (file missing)
O23 - Service: Strażnik AVK (AVKWCtl) - Unknown owner - C:program FilesAntiVirenKitAVKWCtl.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:program FilesEsetnod32krn.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:program FilesSpyware Doctorsdhelp.exe
O23 - Service: SmartLinkService (SLService) - - C:WINDOWSSYSTEM32slserv.exe

Prosilbym o sprawdzenie mojego Scana
 

KSD

Użytkownik
Dołączył
Maj 9, 2006
Posty
11
Co mam wywalic??

Kod:
Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSsystem32logonui.exe

C:WINDOWSsystem32spoolsv.exe

C:WINDOWSExplorer.EXE

C:Program FilesLexmark 5200 serieslxbtbmgr.exe

C:Program FilesWinampwinampa.exe

C:WINDOWSSystem32winzip.exe

C:Program FilesLexmark 5200 serieslxbtbmon.exe

C:Program FilesGadu-Gadugg.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSSystem32wuauclt.exe

C:Program FilesWinampwinamp.exe

C:Program FilesMozilla Firefoxfirefox.exe

C:Documents and SettingsChudyPulpitHijackThis.exe



R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = [url]ftp://[email protected]/[/url]

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx

O4 - HKLM..Run: [Lexmark 5200 series] "C:Program FilesLexmark 5200 serieslxbtbmgr.exe"

O4 - HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe

O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k

O4 - HKLM..Run: [Microsoft Machinex] omgs.exe

O4 - HKLM..Run: [AdobeReaderPro] winzip.exe

O4 - HKLM..RunServices: [Microsoft Machinex] omgs.exe

O4 - HKLM..RunServices: [AdobeReaderPro] winzip.exe

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm

O23 - Service: MySql - Unknown owner - c:usr/MYSQL/bin/mysqld.exe (file missing)
 

Retix

Użytkownik
Dołączył
Maj 10, 2006
Posty
5
Meżecie mi sprawdzić to:

Logfile of HijackThis v1.99.1
Scan saved at 17:48:57, on 2006-05-13
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:program FilesGadu-Gadugg.exe
C:program FilesRAM Idle StandardRAM_2K.exe
C:program FilesSkypePhoneSkype.exe
C:program FilesInternet Exploreriexplore.exe
C:program FilesBearShareBearShare.exe
C:program FilesFlashGetflashget.exe
C:program FilesYNSYNS.exe
C:program FilesInternet Exploreriexplore.exe
C:program FilesWinRARWinRAR.exe
C:DOCUME~1SzymonUSTAWI~1TempRar$EX00.324HijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.onet.pl/
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:program filesgooglegoogletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program filesgooglegoogletoolbar1.dll
O4 - HKLM..Run: [RAM Idle] C:program FilesRAM Idle StandardRAM_2K.exe
O4 - HKLM..Run: [YNS] C:program FilesYNSYNS.exe
O4 - HKCU..Run: [Gadu-Gadu] "C:program FilesGadu-Gadugg.exe" /tray
O4 - HKCU..Run: [Skype] "C:program FilesSkypePhoneSkype.exe" /nosplash /minimized
O4 - Startup: Gadu-Gadu.lnk = C:program FilesGadu-Gadugg.exe
O4 - Startup: Dzieńdobry!.lnk = ?
O4 - Global Startup: Skype.lnk = C:program FilesSkypePhoneSkype.exe
O4 - Global Startup: eTrust EZ Antivirus.lnk = C:program FilesCAeTrust EZ ArmoreTrust EZ AntivirusCAV.exe
O4 - Global Startup: BearShare.lnk = C:program FilesBearShareBearShare.exe
O8 - Extra context menu item: &Google Search - res://C:program FilesGoogleGoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:program FilesGoogleGoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:program FilesGoogleGoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:program FilesGoogleGoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:program FilesGoogleGoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:program FilesGoogleGoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Ściągnij przy pomocy FlashGet'a - C:program FilesFlashGetjc_link.htm
O8 - Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a - C:program FilesFlashGetjc_all.htm
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar1.google.com/data/pl/big/1.1...g/GoogleNav.cab
O20 - Winlogon Notify: WgaLogon - C:WINDOWS
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:program FilesCAeTrust EZ ArmoreTrust EZ AntivirusVetMsg.exe
 

Sz@kal

Użytkownik
Dołączył
Maj 9, 2006
Posty
21
C:WINDOWSsystem32svchost.exe
C:WINDOWScsrss.exe
C:WINDOWSSOUNDMAN.EXE
C:program FilesD-Toolsdaemon.exe
C:program FilesJavajre1.5.0_06binjusched.exe
C:WINDOWSsystem32LVCOMSX.EXE
C:program FilesLogitechVideoLogiTray.exe
C:pROGRA~1ALWILS~1Avast4ashDisp.exe
C:program FilesGadu-Gadugg.exe
C:program FilesD-Link AirPlusAirPlus.exe
C:program FilesLogitechVideoFxSvr2.exe
C:program FilesAlwil SoftwareAvast4ashSimpl.exe
C:program FilesInternet Exploreriexplore.exe
C:WINDOWSsystem32NOTEPAD.EXE
C:Documents and SettingsWiejakPulpitHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:program FilesJavajre1.5.0_06binssv.dll
O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM..Run: [DAEMON Tools-1033] "C:program FilesD-Toolsdaemon.exe" -lang 1045
O4 - HKLM..Run: [SunJavaUpdateSched] C:program FilesJavajre1.5.0_06binjusched.exe
O4 - HKLM..Run: [LVCOMSX] C:WINDOWSsystem32LVCOMSX.EXE
O4 - HKLM..Run: [LogitechVideoRepair] C:program FilesLogitechVideoISStart.exe
O4 - HKLM..Run: [LogitechVideoTray] C:program FilesLogitechVideoLogiTray.exe
O4 - HKLM..Run: [avast!] C:pROGRA~1ALWILS~1Avast4ashDisp.exe
O4 - HKLM..Run: [Synchronization Manager] %SystemRoot%system32mobsync.exe /logon
O4 - HKLM..Run: [PinnacleDriverCheck] C:WINDOWSsystem32PSDrvCheck.exe -CheckReg
O4 - HKCU..Run: [Gadu-Gadu] "C:program FilesGadu-Gadugg.exe" /tray
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:program FilesAdobeAcrobat 7.0Readerreader_sl.exe
O4 - Global Startup: D-Link AirPlus.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.5.0_06binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.5.0_06binssv.dll
O20 - AppInit_DLLs: sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:program FilesAlwil SoftwareAvast4aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:program FilesAlwil SoftwareAvast4ashServ.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe










Szczególny nacisk klade na C:WINDOWScsrss.exe cos nie tak z tym moim zdanie
 
Status
Zamknięty.
Do góry Bottom