Chcesz sprawdzić swój log z Hijackthisa? Wklej go tutaj...

Status
Zamknięty.

astRX

Użytkownik
Dołączył
Maj 17, 2005
Posty
188
proces
Kod:
C:WINDOWScsrss.exe
jest baaaaardzo podejrzany - prawidłowy katalog tego procesu to:
Kod:
C:WINDOWSSystem32


Przeskanuj TU ten plik C:WINDOWScsrss.exe a potem go wywal bo to na bank trojek
<
<
 

Sz@kal

Użytkownik
Dołączył
Maj 9, 2006
Posty
21
Testowany plik: csrss.exe
Rozmiar testowanego pliku: 104.5 kB

Typ testowanego pliku: application/octet-stream


Do testu wykorzystano rozszerzone antywirusowe bazy danych z dnia 15-05-2006, wykrywające 193932 szkodników (wirusów, trojanów, programów spyware itp.).

csrss.exe - ZAINFEKOWANY

Wykryte wirusy:
Trojan-PSW.Win32.Tibia.u


Teraz jest taki problem nie chce sie to usunoć!! Ale jakoś go załatwie.
 

DJ_Max

Użytkownik
Dołączył
Październik 2, 2005
Posty
28
Hej, no, a czy ktoś raczyłby sprawdzić mój log? Jest stronę do tyłu. Bardzo was proszę...
 

Sz@kal

Użytkownik
Dołączył
Maj 9, 2006
Posty
21
O18 - Protocol: wpmsg - {2E0AC5A0-3597-11D6-B3ED-0001021DC1C3} - C:program FilesSpikurl_wpmsg.dll

O17 - HKLMSystemCS1ServicesTcpip..{6C80199F-5FA8-4CC5-949D-4DDDD81C8638}: NameServer = 194.72.0.98,194.72.9.38

O17 - HKLMSystemCCSServicesTcpip..{6C80199F-5FA8-4CC5-949D-4DDDD81C8638}: NameServer = 194.72.0.98,194.72.9.38

Dj Max moim zdaniem to są te podejrzane pliki. Lepiej usuń bądź co bądź uważaj na nie, Przeskanuj je tu Link
 

YRS

Użytkownik
Dołączył
Maj 15, 2006
Posty
22
Siema od pewnego czasu mam problemy z PC niewiem czy mam jakiegos wira oto moje logi, jakby ktos mial chwile czasu to prosze je przejzec. dziekuje

Logfile of HijackThis v1.99.1
Scan saved at 10:17:25, on 2006-05-16
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSSystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSOUNDMAN.EXE
C:program FilesATI TechnologiesATI Control Panelatiptaxx.exe
C:pROGRA~1ALWILS~1Avast4ashDisp.exe
C:program FilesWinampwinampa.exe
C:program FilesiTunesiTunesHelper.exe
C:program FilesQuickTimeqttask.exe
C:program FilesJavajre1.5.0_06binjusched.exe
C:program FilesBPKd1337.exe
C:program FilesCommon FilesAheadLibNMBgMonitor.exe
C:program FilesAlwil SoftwareAvast4aswUpdSv.exe
C:program FilesAlwil SoftwareAvast4ashServ.exe
C:program FilesKerioPersonal Firewall 4kpf4ss.exe
C:program FilesKerioPersonal Firewall 4kpf4gui.exe
C:program FilesAlwil SoftwareAvast4ashWebSv.exe
C:program FilesKerioPersonal Firewall 4kpf4gui.exe
C:program FilesAlwil SoftwareAvast4ashMaiSv.exe
C:program FilesiPodbiniPodService.exe
C:WINDOWSSystem32wuauclt.exe
C:program FilesMozilla Firefoxfirefox.exe
C:WINDOWSSystem32svchost.exe
C:DOCUME~1AdminUSTAWI~1TempRar$EX00.562HijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:program FilesJavajre1.5.0_06binssv.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:pROGRA~1FLASHGETjccatch.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k
O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM..Run: [ATIPTA] C:program FilesATI TechnologiesATI Control Panelatiptaxx.exe
O4 - HKLM..Run: [avast!] C:pROGRA~1ALWILS~1Avast4ashDisp.exe
O4 - HKLM..Run: [WinampAgent] C:program FilesWinampwinampa.exe
O4 - HKLM..Run: [iTunesHelper] "C:program FilesiTunesiTunesHelper.exe"
O4 - HKLM..Run: [QuickTime Task] "C:program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [SunJavaUpdateSched] C:program FilesJavajre1.5.0_06binjusched.exe
O4 - HKLM..Run: [CloneCDTray] "C:program FilesSlySoftCloneCDCloneCDTray.exe" /s
O4 - HKLM..Run: [NeroFilterCheck] C:program FilesCommon FilesAheadLibNeroCheck.exe
O4 - HKLM..Run: [d1337] C:program FilesBPKd1337.exe
O4 - HKCU..Run: [MsnMsgr] "C:program FilesMSN MessengerMsnMsgr.Exe" /background
O4 - HKCU..Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:program FilesCommon FilesAheadLibNMBgMonitor.exe"
O4 - HKCU..Run: [Gadu-Gadu] "C:program FilesGadu-Gadugg.exe" /tray
O4 - Global Startup: Microsoft Office.lnk = C:program FilesMicrosoft OfficeOfficeOSA9.EXE
O8 - Extra context menu item: Download All by FlashGet - C:program FilesFlashGetjc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:program FilesFlashGetjc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.5.0_06binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.5.0_06binssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:pROGRA~1FLASHGETflashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:pROGRA~1FLASHGETflashget.exe
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:pROGRA~1MSNMES~1msgrapp.dll" (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:program FilesAlwil SoftwareAvast4aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:WINDOWSSystem32Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe
O23 - Service: avast! Antivirus - Unknown owner - C:program FilesAlwil SoftwareAvast4ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:program FilesAlwil SoftwareAvast4ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:program FilesiPodbiniPodService.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:program FilesKerioPersonal Firewall 4kpf4ss.exe
 

astRX

Użytkownik
Dołączył
Maj 17, 2005
Posty
188
Zrób Windows Update
smile.gif
a poza tym podejrzewam że masz na kompie aktywnego Perfect Keyloggera:
Kod:
C:Program FilesBPKd1337.exe

Poza tym log czysty...
 

patology

Były Moderator
Dołączył
Październik 30, 2005
Posty
205
Originally posted by YRS
ten pliczek jest akurat mój
<

nieuruchamiany
Ja bym na twoim miejscu, usunal ten wpis, ale najpierw po skonfigurowaniu BPK usunal bym klienta, zostawil tylko serwer. Po co zasmiecac sobie kompa klientami?

wpis mozesz usunac.
 
X

xanusek

Gość
Kod:
Logfile of HijackThis v1.99.1

Scan saved at 17:08:50, on 2006-05-19

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)



Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSsystem32spoolsv.exe

C:WINDOWSExplorer.EXE

C:WINDOWSSOUNDMAN.EXE

C:Program FilesABITABITEQabiteq.exe

C:Program FilesJavajre1.5.0_06binjusched.exe

C:WINDOWSsystem32ctfmon.exe

C:Program FilesLogitechSetPointSetPoint.exe

C:Program FilesCommon FilesLogitechKHALKHALMNPR.EXE

C:WINDOWSsystem32nvsvc32.exe

C:Program FilesAlcohol SoftAlcohol 120StarWindStarWindService.exe

C:WINDOWSsystem32WgaTray.exe

C:WINDOWSsystem32wuauclt.exe

C:PROGRA~1MOZILL~1FIREFOX.EXE

C:Documents and Settings1PulpitHijackThis.exe



R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = [url]http://www.google.pl/[/url]

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Microsoft Internet Explorer

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_06binssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:program filesgooglegoogletoolbar2.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program filesgooglegoogletoolbar2.dll

O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE

O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup

O4 - HKLM..Run: [nwiz] nwiz.exe /install

O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit

O4 - HKLM..Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM..Run: [ABITEQ] C:Program FilesABITABITEQabiteq.exe -M

O4 - HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavajre1.5.0_06binjusched.exe

O4 - HKLM..Run: [KAVPersonal50] "C:Program FilesKaspersky LabKaspersky Anti-Virus Personal Prokav.exe" /minimize

O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe

O4 - HKCU..Run: [LDM] C:Program FilesLogitechDesktop Messenger8876480ProgramLogitechDesktopMessenger.exe

O4 - Global Startup: Adobe Gamma Loader.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe

O4 - Global Startup: Logitech Desktop Messenger.lnk = C:Program FilesLogitechDesktop Messenger8876480ProgramLDMConf.exe

O4 - Global Startup: Logitech SetPoint.lnk = C:Program FilesLogitechSetPointSetPoint.exe

O8 - Extra context menu item: &Google Search - res://c:program filesgoogleGoogleToolbar2.dll/cmsearch.html

O8 - Extra context menu item: Backward Links - res://c:program filesgoogleGoogleToolbar2.dll/cmbacklinks.html

O8 - Extra context menu item: Similar Pages - res://c:program filesgoogleGoogleToolbar2.dll/cmsimilar.html

O8 - Extra context menu item: Translate Page into English - res://c:program filesgoogleGoogleToolbar2.dll/cmtrans.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_06binssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_06binssv.dll

O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - [url]http://go.microsoft.com/fwlink/?linkid=48835[/url]

O17 - HKLMSystemCCSServicesTcpip..{22179916-3DF0-4CCB-BCA0-A50F2AE9C617}: NameServer = 10.0.0.2

O17 - HKLMSystemCS1ServicesTcpip..{22179916-3DF0-4CCB-BCA0-A50F2AE9C617}: NameServer = 10.0.0.2

O17 - HKLMSystemCS2ServicesTcpip..{22179916-3DF0-4CCB-BCA0-A50F2AE9C617}: NameServer = 10.0.0.2

O18 - Protocol: bw+0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw+0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw-0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw-0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw00 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw00s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw10 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw10s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw20 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw20s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw30 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw30s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw40 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw40s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw50 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw50s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw60 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw60s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw70 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw70s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw80 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw80s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw90 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bw90s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwa0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwa0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwb0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwb0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwc0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwc0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwd0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwd0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwe0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwe0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwf0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwf0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:Program FilesLogitechDesktop Messenger8876480ProgramGAPlugProtocol-8876480.dll

O18 - Protocol: bwg0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwg0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwh0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwh0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwi0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwi0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwj0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwj0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwk0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwk0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwl0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwl0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwm0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwm0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwn0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwn0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwo0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwo0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwp0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwp0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwq0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwq0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwr0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwr0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bws0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bws0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwt0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwt0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwu0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwu0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwv0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwv0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bww0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bww0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwx0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwx0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwy0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwy0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwz0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: bwz0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O18 - Protocol: offline-8876480 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll

O20 - Winlogon Notify: WgaLogon - C:WINDOWSSYSTEM32WgaLogon.dll

O23 - Service: Adobe LM Service - Unknown owner - C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe

O23 - Service: kavsvc - Kaspersky Lab - C:Program FilesKaspersky LabKaspersky Anti-Virus Personal Prokavsvc.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%WinPcaprpcapd.exe" -d -f "%ProgramFiles%WinPcaprpcapd.ini (file missing)

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:Program FilesAlcohol SoftAlcohol 120StarWindStarWindService.exe
Ostatnio komp mi coś zamula.. Anty vir nic nie znajduje.. prosze o pomoc, z gory dziekuje
<
 

patology

Były Moderator
Dołączył
Październik 30, 2005
Posty
205
O17 - HKLMSystemCCSServicesTcpip..{22179916-3DF0-4CCB-BCA0-A50F2AE9C617}: NameServer = 10.0.0.2
O17 - HKLMSystemCS1ServicesTcpip..{22179916-3DF0-4CCB-BCA0-A50F2AE9C617}: NameServer = 10.0.0.2
O17 - HKLMSystemCS2ServicesTcpip..{22179916-3DF0-4CCB-BCA0-A50F2AE9C617}: NameServer = 10.0.0.2
O18 - Protocol: bw+0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:program FilesLogitechDesktop Messenger8876480ProgramGAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {CD04836C-06C7-48F1-891D-70155438A90E} - C:program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol-8876480.dll[/b]
Usuń.
 

puchacz47

Użytkownik
Dołączył
Maj 19, 2006
Posty
2
Logfile of HijackThis v1.99.1
Scan saved at 18:58:47, on 2006-05-19
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:program FilesCommon FilesSymantec SharedccSetMgr.exe
C:program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe
C:WINDOWSsystem32spoolsv.exe
C:program FilesSymantecLiveUpdateALUSchedulerSvc.exe
C:WINDOWSsystem32CTsvcCDA.exe
C:program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:program FilesNorton AntiVirusnavapsvc.exe
C:program FilesNorton AntiVirusIWPNPFMntor.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32MsPMSPSv.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32WgaTray.exe
C:WINDOWSsystem32CTHELPER.EXE
C:program FilesATI TechnologiesATI Control Panelatiptaxx.exe
C:program FilesCreativeSBLiveAudioHQAHQTBU.EXE
C:program FilesHPHP Software UpdateHPWuSchd2.exe
C:program FilesiTunesiTunesHelper.exe
C:program FilesJavajre1.5.0_06binjusched.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32LVCOMSX.EXE
C:program FilesLogitechVideoLogiTray.exe
C:program FilesiPodbiniPodService.exe
C:program FilesCommon FilesSymantec SharedccApp.exe
C:program FilesCommon FilesRealUpdate_OBrealsched.exe
C:WINDOWSsystem32ctfmon.exe
C:program FilesSkypePhoneSkype.exe
C:program FilesRSSoftRSEDNClient.exe
C:program FilesSteamSteam.exe
C:Windowsctfmon.exe
C:program FilesHPDigital Imagingbinhpqtra08.exe
C:program FilesLogitechVideoFxSvr2.exe
C:program FilesHPDigital Imagingbinhpqimzone.exe
C:program FilesHPDigital ImagingbinhpqSTE08.exe
C:program FilesCommon FilesSymantec SharedSecurity ConsoleNSCSRVCE.EXE
C:program FilesHPDigital ImagingProduct Assistantbinhprblog.exe
C:program FilesGadu-Gadugg.exe
C:program FilesInternet ExplorerIEXPLORE.EXE
C:DOCUME~1abcUSTAWI~1TempRar$EX00.609HijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.onet.pl/
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:program FilesGetRightxx2gr.dll
O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:pROGRA~1RXTOOL~1sfcont.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:program FilesJavajre1.5.0_06binssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:program FilesNorton AntiVirusNavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:program filesgooglegoogletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:program FilesNorton AntiVirusNavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program filesgooglegoogletoolbar1.dll
O4 - HKLM..Run: [SiSUSBRG] C:WINDOWSSiSUSBrg.exe
O4 - HKLM..Run: [CTHelper] CTHELPER.EXE
O4 - HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
O4 - HKLM..Run: [Jet Detection] "C:program FilesCreativeSBLivePROGRAMADGJDet.exe"
O4 - HKLM..Run: [ATIPTA] C:program FilesATI TechnologiesATI Control Panelatiptaxx.exe
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [AudioHQU] C:program FilesCreativeSBLiveAudioHQAHQTBU.EXE
O4 - HKLM..Run: [HP Software Update] C:program FilesHPHP Software UpdateHPWuSchd2.exe
O4 - HKLM..Run: [iTunesHelper] "C:program FilesiTunesiTunesHelper.exe"
O4 - HKLM..Run: [QuickTime Task] "C:program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [SunJavaUpdateSched] C:program FilesJavajre1.5.0_06binjusched.exe
O4 - HKLM..Run: [LVCOMSX] C:WINDOWSsystem32LVCOMSX.EXE
O4 - HKLM..Run: [LogitechVideoRepair] C:program FilesLogitechVideoISStart.exe
O4 - HKLM..Run: [LogitechVideoTray] C:program FilesLogitechVideoLogiTray.exe
O4 - HKLM..Run: [Adobe Photo Downloader] "C:program FilesAdobePhotoshop Album Starter Edition3.0Appsapdproxy.exe"
O4 - HKLM..Run: [ccApp] "C:program FilesCommon FilesSymantec SharedccApp.exe"
O4 - HKLM..Run: [WinampAgent] C:program FilesWinampwinampa.exe
O4 - HKLM..Run: [TkBellExe] "C:program FilesCommon FilesRealUpdate_OBrealsched.exe" -osboot
O4 - HKLM..Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [Gadu-Gadu] "C:program FilesGadu-Gadugg.exe" /tray
O4 - HKCU..Run: [Skype] "C:program FilesSkypePhoneSkype.exe" /nosplash /minimized
O4 - HKCU..Run: [LogitechSoftwareUpdate] "C:program FilesLogitechVideoManifestEngine.exe" boot
O4 - HKCU..Run: [QuickTime Task] "C:program FilesQuickTimeqttask.exe" -atboottime
O4 - HKCU..Run: [Red Swoosh EDN Client] C:program FilesRSSoftRSEDNClient.exe
O4 - HKCU..Run: [Steam] "C:program FilesSteamSteam.exe" -silent
O4 - HKCU..Run: [ctfmon] C:Windowsctfmon.exe
O4 - HKCU..Run: [shost32.exe] C:WINDOWSshost32.exe
O4 - Global Startup: GetRight - Tray Icon.lnk = C:program FilesGetRightgetright.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:program FilesHPDigital Imagingbinhpqtra08.exe
O4 - Global Startup: HP Image Zone - szybkie uruchamianie.lnk = C:program FilesHPDigital Imagingbinhpqthb08.exe
O8 - Extra context menu item: &Google Search - res://c:program filesgoogleGoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://kn.bar.need2find.com/KN/menusearch.html?p=KN
O8 - Extra context menu item: &Translate English Word - res://c:program filesgoogleGoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:program filesgoogleGoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:program filesgoogleGoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download with GetRight - C:program FilesGetRightGRdownload.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:pROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O8 - Extra context menu item: Konwertuj do Adobe PDF - res://C:program FilesAdobeAcrobat 7.0AcrobatAcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Konwertuj miejsce docelowe łącza do Adobe PDF - res://C:program FilesAdobeAcrobat 7.0AcrobatAcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Konwertuj miejsce docelowe łącza do istniejącego pliku PDF - res://C:program FilesAdobeAcrobat 7.0AcrobatAcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Konwertuj wybrane łącza do Adobe PDF - res://C:program FilesAdobeAcrobat 7.0AcrobatAcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Konwertuj zaznaczenie do Adobe PDF - res://C:program FilesAdobeAcrobat 7.0AcrobatAcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Konwertuj zaznaczenie do istniejącego pliku PDF - res://C:program FilesAdobeAcrobat 7.0AcrobatAcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Open with GetRight Browser - C:program FilesGetRightGRbrowse.htm
O8 - Extra context menu item: Similar Pages - res://c:program filesgoogleGoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:program filesgoogleGoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.5.0_06binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.5.0_06binssv.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:pROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:program FilesMessengermsmsgs.exe
O16 - DPF: {37A49D66-2735-4BB9-8503-82BA5E2333D0} (MailCfg Control) - http://poczta.wp.pl/d606/mailcfg.ocx
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:pROGRA~1RXTOOL~1sfcont.dll
O20 - Winlogon Notify: WgaLogon - C:WINDOWSSYSTEM32WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:program FilesSymantecLiveUpdateALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:program FilesCommon FilesSymantec SharedccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:program FilesCommon FilesSymantec SharedccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:WINDOWSsystem32CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:program FilesiPodbiniPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:pROGRA~1SymantecLIVEUP~1LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:program FilesNorton AntiVirusnavapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:program FilesNorton AntiVirusIWPNPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:program FilesCommon FilesSymantec SharedSecurity ConsoleNSCSRVCE.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:WINDOWSsystem32HPZipm12.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:program FilesNorton AntiVirusSAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:program FilesCommon FilesSymantec SharedSNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:program FilesCommon FilesSymantec SharedSecurity CenterSymWSC.exe




Prosze o pomoc ;]
 

Mo4x

Były Moderator
Dołączył
Grudzień 26, 2005
Posty
704
Originally posted by puchacz47
C:WINDOWSsystem32Ati2evxx.exe
C:program FilesSymantecLiveUpdateALUSchedulerSvc.exe
C:WINDOWSsystem32CTsvcCDA.exe
C:program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:WINDOWSsystem32MsPMSPSv.exe
C:WINDOWSsystem32WgaTray.exe
C:WINDOWSsystem32CTHELPER.EXE
C:program FilesHPHP Software UpdateHPWuSchd2.exe
C:program FilesiTunesiTunesHelper.exe
C:program FilesJavajre1.5.0_06binjusched.exe
C:WINDOWSsystem32LVCOMSX.EXE
C:program FilesCommon FilesRealUpdate_OBrealsched.exe
C:program FilesRSSoftRSEDNClient.exe
C:program FilesSteamSteam.exe
C:Windowsctfmon.exe
C:program FilesGadu-Gadugg.exe
Te procesy są niepotrzebne ;]
 

patology

Były Moderator
Dołączył
Październik 30, 2005
Posty
205
Originally posted by puchacz47
Dzieki usunolem te wszystkie.....

A trojankow zadnych nie ma??;]

Usuwasz TO:

C:program FilesRSSoftRSEDNClient.exe
R3 - Default URLSearchHook is missing
O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:pROGRA~1RXTOOL~1sfcont.dll (file missing)
O4 - HKCU..Run: [Red Swoosh EDN Client] C:program FilesRSSoftRSEDNClient.exe
O4 - HKCU..Run: [shost32.exe] C:WINDOWSshost32.exe
O8 - Extra context menu item: &Search - http://kn.bar.need2find.c...earch.html?p=KN
O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:pROGRA~1RXTOOL~1sfcont.dll[/b]

btw. masz trojana :

O4 - HKCU..Run: [shost32.exe] C:WINDOWSshost32.exe[/b]
Usuwasz wpis, nastepnie plik, podszywajacy sie pod aplikacje z c:windowssystem32
 

damianciech

Użytkownik
Dołączył
Kwiecień 12, 2006
Posty
1
Logfile of HijackThis v1.99.1
Scan saved at 16:33:27, on 2006-05-20
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSSystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:program FilesnortonNISUM.EXE
C:WINDOWSsystem32spoolsv.exe
C:program FilesnortonccPxySvc.exe
C:program FilesCommon FilesMicrosoft SharedVS7Debugmdm.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32UAService7.exe
C:WINDOWSSystem32ctfmon.exe
C:program FilesVIARAIDraid_tool.exe
C:program FilesNeostrada TPNeostradaTP.exe
C:program FilesNeostrada TPComComp.exe
C:program FilesNeostrada TPWatch.exe
C:program FilesInternet Exploreriexplore.exe
C:WINDOWSSystem32wuauclt.exe
C:Documents and SettingsDamianUstawienia lokalneTempKatalog tymczasowy 1 dla hijackthis.zipHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://szukaj.wp.pl
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.neostrada.pl
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Neostrada TP
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:pROGRA~1NEOSTR~1SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:program FilesAdobeAcrobat 5.0 CEReaderActiveXAcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:pROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:program FilesNavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:program FilesNavShExt.dll
O4 - HKLM..Run: [Symantec NetDriver Monitor] C:pROGRA~1SYMNET~1SNDMon.exe
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:program FilesATI TechnologiesATI.ACECLI.exe
O4 - Global Startup: Microsoft Office.lnk = C:program FilesMicrosoft OfficeOffice10OSA.EXE
O4 - Global Startup: VIA RAID TOOL.lnk = C:program FilesVIARAIDraid_tool.exe
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:pROGRA~1MICROS~2Office10EXCEL.EXE/3000
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/0159868ccde6b9...ip/RdxIE601.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/downl...lscbase7617.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1145395741388
O17 - HKLMSystemCCSServicesTcpip..{0B65F64E-774F-4645-A231-840EFFF38EC8}: NameServer = 194.204.152.34 217.98.63.164
O17 - HKLMSystemCS1ServicesTcpip..{0B65F64E-774F-4645-A231-840EFFF38EC8}: NameServer = 194.204.152.34 217.98.63.164
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSSystem32Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:program FilesCommon FilesSymantec SharedccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:program FilesCommon FilesSymantec SharedccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:program FilesnortonccPxySvc.exe
O23 - Service: Usługa Auto-Protect w programie Norton AntiVirus (navapsvc) - Symantec Corporation - D:program Filesnavapsvc.exe
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:program FilesnortonNISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:pROGRA~1COMMON~1SYMANT~1SCRIPT~1SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:program FilesCommon FilesSymantec SharedSNDSrvc.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:WINDOWSSystem32UAService7.exe

proszę o sprawdzenie loga.
 

prosty_st

Użytkownik
Dołączył
Maj 13, 2006
Posty
2
Kod:
Logfile of HijackThis v1.99.1

Scan saved at 11:10:40, on 2006-05-21

Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)



Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSSystem32Ati2evxx.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSsystem32spoolsv.exe

C:Program FilesEsetnod32krn.exe

C:Program FilesVMwareVMware Workstationvmware-authd.exe

C:Program FilesCommon FilesVMwareVMware Virtual Image Editingvmount2.exe

C:WINDOWSSystem32vmnat.exe

C:WINDOWSSystem32vmnetdhcp.exe

C:WINDOWSsystem32Ati2evxx.exe

C:WINDOWSExplorer.EXE

C:Program FilesVIARAIDraid_tool.exe

C:Program FilesNetLimiterNetLimiter.exe

C:Program FilesEsetnod32kui.exe

C:WINDOWSSystem32RunDll32.exe

C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe

C:Program FilesJavajre1.5.0_06binjusched.exe

C:PROGRA~1A4TechMouseAmoumain.exe

C:Program FilesD-Toolsdaemon.exe

C:Program FilesGadu-Gadugg.exe

C:Program FilesLavasoftAd-aware 6Ad-aware.exe

C:Program FilestotalcmdTOTALCMD.EXE

c:DownloadshijackthisHijackThis.exe



R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_06binssv.dll

O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:PROGRA~1FLASHGETjccatch.dll

O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:PROGRA~1FlashFXPIEFlash.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx

O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:PROGRA~1FLASHGETfgiebar.dll

O4 - HKLM..Run: [RaidTool] C:Program FilesVIARAIDraid_tool.exe

O4 - HKLM..Run: [NetLimiter] C:Program FilesNetLimiterNetLimiter.exe /s

O4 - HKLM..Run: [nod32kui] "C:Program FilesEsetnod32kui.exe" /WAITSERVICE

O4 - HKLM..Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM..Run: [ATIPTA] "C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe"

O4 - HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavajre1.5.0_06binjusched.exe

O4 - HKLM..Run: [WheelMouse] C:PROGRA~1A4TechMouseAmoumain.exe

O4 - HKLM..Run: [DAEMON Tools-1033] "C:Program FilesD-Toolsdaemon.exe"  -lang 1033

O4 - HKCU..Run: [Gadu-Gadu] "C:Program FilesGadu-Gadugg.exe" /tray

O4 - HKCU..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /nosplash /minimized

O8 - Extra context menu item: Download All by FlashGet - C:PROGRA~1FLASHGETjc_all.htm

O8 - Extra context menu item: Download using FlashGet - C:PROGRA~1FLASHGETjc_link.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_06binssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_06binssv.dll

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm

O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:PROGRA~1FLASHGETflashget.exe

O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:PROGRA~1FLASHGETflashget.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSSystem32Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe

O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:Program FilesEsetnod32krn.exe

O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:Program FilesVMwareVMware Workstationvmware-authd.exe

O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:WINDOWSSystem32vmnetdhcp.exe

O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:Program FilesCommon FilesVMwareVMware Virtual Image Editingvmount2.exe

O23 - Service: VMware NAT Service - VMware, Inc. - C:WINDOWSSystem32vmnat.exe

moglibyscie sprawdzic ? :/ bo ostatnio mysle ze cos sie dzieje
 

boness

Użytkownik
Dołączył
Październik 29, 2005
Posty
209
Logfile of HijackThis v1.99.1
Scan saved at 17:13:21, on 2006-05-23
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:program FilesCommon FilesSymantec SharedccSetMgr.exe
C:WINDOWSExplorer.EXE
C:program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:WINDOWSsystem32spoolsv.exe
C:program FilesAlwil SoftwareAvast4aswUpdSv.exe
C:program FilesAlwil SoftwareAvast4ashServ.exe
C:program FilesJavajre1.5.0_02binjusched.exe
C:WINDOWSsoundman.exe
C:program FilesCommon FilesSymantec SharedccApp.exe
C:program FilesVVSNVVSN.exe
C:pROGRA~1ALWILS~1Avast4ashDisp.exe
C:WINDOWSsystem32ctfmon.exe
C:program FilesMessengermsmsgs.exe
C:program FilesAlwil SoftwareAvast4ashMaiSv.exe
C:program FilesAlwil SoftwareAvast4ashWebSv.exe
C:WINDOWSsystem32wscntfy.exe
C:pROGRA~1GADU-G~1gg.exe
C:program FilesWinampwinamp.exe
C:program FilesGadu-Gadugg.exe
C:program FilesInternet ExplorerIEXPLORE.EXE
C:Documents and SettingskolesPulpitThomashijackthis1.99.1HijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.onet.pl/
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:program filesgooglegoogletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:program FilesNorton AntiVirusNavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:program FilesNorton AntiVirusNavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program filesgooglegoogletoolbar2.dll
O4 - HKLM..Run: [SunJavaUpdateSched] C:program FilesJavajre1.5.0_02binjusched.exe
O4 - HKLM..Run: [SoundMan] soundman.exe
O4 - HKLM..Run: [WinampAgent] "C:program FilesWinampWinampa.exe"
O4 - HKLM..Run: [ccApp] "C:program FilesCommon FilesSymantec SharedccApp.exe"
O4 - HKLM..Run: [Microsoft Windows Update] mswins.exe
O4 - HKLM..Run: [VVSN] C:program FilesVVSNVVSN.exe
O4 - HKLM..Run: [DAEMON Tools] "C:Documents and SettingskolesPulpitDAEMON Toolsdaemon.exe" -lang 1033
O4 - HKLM..Run: [avast!] C:pROGRA~1ALWILS~1Avast4ashDisp.exe
O4 - HKLM..RunServices: [Microsoft Windows Update] mswins.exe
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [MSMSGS] "C:program FilesMessengermsmsgs.exe" /background
O4 - HKCU..Run: [VoipBuster] "C:program FilesVoipBuster.comVoipBusterVoipBuster.exe" -nosplash -minimized
O4 - HKCU..Run: [Skype] "C:program FilesSkypePhoneSkype.exe" /nosplash /minimized
O4 - HKCU..Run: [EdHTML] C:program FilesBinboyEdHTMLv5.0EdHTML.exe /none
O4 - HKCU..Run: [VoipStunt] "C:program FilesVoipStunt.comVoipStuntVoipStunt.exe" -nosplash -minimized
O4 - HKCU..Run: [Komunikator] "C:program FilesTlen.pltlen.exe" --confdir=home
O4 - Global Startup: Adobe Gamma Loader.lnk = C:program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O8 - Extra context menu item: &Google Search - res://c:program filesgoogleGoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:program filesgoogleGoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:program filesgoogleGoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:program filesgoogleGoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:program filesgoogleGoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:program filesgoogleGoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.5.0_02binnpjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.5.0_02binnpjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:program FilesMessengermsmsgs.exe
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:program FilesAlwil SoftwareAvast4aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:program FilesAlwil SoftwareAvast4ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:program FilesAlwil SoftwareAvast4ashWebSv.exe" /service (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:program FilesCommon FilesSymantec SharedccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:program FilesCommon FilesSymantec SharedccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:program FilesCommon FilesSymantec SharedccSetMgr.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%WinPcaprpcapd.exe" -d -f "%ProgramFiles%WinPcaprpcapd.ini (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe[/b]

sprawdzcie...
<
 

pkoper

Były Moderator
Dołączył
Marzec 9, 2006
Posty
302
przede wszystkim pousuwaj wszystkie wpisy (file missing).

Widze tez rózne toolbary, nie wiem czy je potrzebujesz.

I jushed.exe.

Ale niech jeszcze ktos sie wypowie.
 

astRX

Użytkownik
Dołączył
Maj 17, 2005
Posty
188
jushed.exe to od Javy Sun`a więc ok.
C:program FilesVVSNVVSN.exe (+wpis w rejestrze) to adware WhenU.WeatherCast - wywal to
 
Status
Zamknięty.
Do góry Bottom