Chcesz sprawdzić swój log z Hijackthisa? Wklej go tutaj...

Status
Zamknięty.

0wn3r

Były Moderator
Dołączył
Marzec 10, 2007
Posty
1330
No to tak :

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb

O2 - BHO: (no name) - Software - (no file) - wtf?

O2 - BHO: (no name) - {140BD8E3-C167-11D4-B4A3-080000180323} - (no file) - j.w

Tylko teraz dokładnie nie wiem co to jest :

O17 - HKLMSystemCS1ServicesTcpipParameters: NameServer = 85.255.114.67 85.255.112.140

O17 - HKLMSystemCS2ServicesTcpipParameters: NameServer = 85.255.114.67 85.255.112.140

O17 - HKLMSystemCCSServicesTcpipParameters: NameServer = 85.255.114.67 85.255.112.140

Poza tym co tu wymieniłem, log czysty.
 

sayer

Użytkownik
Dołączył
Październik 9, 2007
Posty
1
Jeśli ktoś mógłby sprawdzić byłbym wdzięczny
smile.gif


Kod:
Logfile of HijackThis v1.99.1

Scan saved at 16:19:09, on 2007-10-11

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)



Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

C:Program FilesAlwil SoftwareAvast4ashServ.exe

C:WINDOWSExplorer.EXE

C:WINDOWSsystem32spoolsv.exe

C:WINDOWSsystem32RUNDLL32.EXE

C:WINDOWSsystem32sstray.exe

C:PROGRA~1NEOSTR~1CnxMon.exe

C:Program FilesThomsonSpeedTouch USBDragdiag.exe

C:PROGRA~1NEOSTR~1TaskbarIcon.exe

C:PROGRA~1ALWILS~1Avast4ashDisp.exe

C:Program FilesD-Toolsdaemon.exe

C:Program FilesJavajre1.5.0_04binjusched.exe

C:Program FilesCreativeSBLiveAudioHQAHQTB.EXE

C:Program FilesCommon FilesRealUpdate_OBrealsched.exe

C:PROGRA~1NokiaNOKIAP~1LAUNCH~1.EXE

D:ProgramyWinampwinampa.exe

C:WINDOWSvsnpstd.exe

C:WINDOWSsystem32ctfmon.exe

C:Program FilesNokiaNokia PC Suite 6PcSync2.exe

C:Program FilesMessengermsmsgs.exe

C:PROGRA~1COMMON~1NokiaMPAPIMPAPI3s.exe

C:WINDOWSsystem32nvsvc32.exe

C:WINDOWSsystem32svchost.exe

C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe

C:Program FilesAlwil SoftwareAvast4ashWebSv.exe

C:Program FilesCommon FilesPCSuiteServicesServiceLayer.exe

C:WINDOWSsystem32wuauclt.exe

C:Program FilesNeostrada TPNeostradaTP.exe

C:Program FilesNeostrada TPComComp.exe

C:Program FilesNeostrada TPWatch.exe

D:ProgramymIRCmirc.exe

C:Program FilesMozilla Firefoxfirefox.exe

C:Program FilesGadu-Gadugg.exe

D:Programyfoobar2000foobar2000.exe

C:Program FilesHijackThisHijackThis.exe



R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = [url]http://szukaj.wp.pl[/url]

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = [url]http://www.neostrada.pl[/url]

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Neostrada TP

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:PROGRA~1NEOSTR~1SEARCH~1.DLL

R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:PROGRA~1ICQTOO~1toolbaru.dll

O2 - BHO: XTTBPos00 Class - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:PROGRA~1ICQTOO~1toolbaru.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:PROGRA~1SkypePhoneIEPluginSKYPEI~1.DLL

O2 - BHO: (no name) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)

O2 - BHO: MEGAUPLOADTOOLBAR - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:PROGRA~1MEGAUP~1MEGAUP~1.DLL

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:program filesgooglegoogletoolbar2.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program filesgooglegoogletoolbar2.dll

O3 - Toolbar: MEGAUPLOADTOOLBAR - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:PROGRA~1MEGAUP~1MEGAUP~1.DLL

O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:PROGRA~1ICQTOO~1toolbaru.dll

O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup

O4 - HKLM..Run: [nwiz] nwiz.exe /install

O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit

O4 - HKLM..Run: [nForce Tray Options] sstray.exe /r

O4 - HKLM..Run: [WooCnxMon] C:PROGRA~1NEOSTR~1CnxMon.exe

O4 - HKLM..Run: [SpeedTouch USB Diagnostics] "C:Program FilesThomsonSpeedTouch USBDragdiag.exe" /icon

O4 - HKLM..Run: [WOOWATCH] C:PROGRA~1NEOSTR~1Watch.exe

O4 - HKLM..Run: [WOOTASKBARICON] C:PROGRA~1NEOSTR~1TaskbarIcon.exe

O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe

O4 - HKLM..Run: [DAEMON Tools-1033] "C:Program FilesD-Toolsdaemon.exe"  -lang 1033

O4 - HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavajre1.5.0_04binjusched.exe

O4 - HKLM..Run: [AudioHQ] C:Program FilesCreativeSBLiveAudioHQAHQTB.EXE

O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe

O4 - HKLM..Run: [TkBellExe] "C:Program FilesCommon FilesRealUpdate_OBrealsched.exe"  -osboot

O4 - HKLM..Run: [PCSuiteTrayApplication] C:PROGRA~1NokiaNOKIAP~1LAUNCH~1.EXE -startup

O4 - HKLM..Run: [WinampAgent] D:ProgramyWinampwinampa.exe

O4 - HKLM..Run: [snpstd] C:WINDOWSvsnpstd.exe

O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime

O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe

O4 - HKCU..Run: [Gadu-Gadu] "C:Program FilesGadu-Gadugg.exe" /tray

O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifier1.2.1128.5462GoogleToolbarNotifier.exe

O4 - HKCU..Run: [PcSync] C:Program FilesNokiaNokia PC Suite 6PcSync2.exe /NoDialog

O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background

O4 - HKCU..Run: [Steam] "d:grysteamsteam.exe" -silent

O4 - HKCU..Run: [ares] "D:ProgramyAresAres.exe" -h

O4 - Startup: Adobe Gamma.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe

O8 - Extra context menu item: Download All by FlashGet - D:ProgramyFlashGetjc_all.htm

O8 - Extra context menu item: Download using FlashGet - D:ProgramyFlashGetjc_link.htm

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000

O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_04binnpjpi150_04.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_04binnpjpi150_04.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:PROGRA~1SkypePhoneIEPluginSKYPEI~1.DLL

O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL

O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:Program FilesICQLiteICQLite.exe (file missing)

O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:Program FilesICQLiteICQLite.exe (file missing)

O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:Program FilesICQ6ICQ.exe

O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:Program FilesICQ6ICQ.exe

O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} (Ganymede Board Games) - [url]http://67.15.101.33/g_bin/pl/boards_2_0_0_34.cab[/url]

O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - [url]http://go.divx.com/plugin/DivXBrowserPlugin.cab[/url]

O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} (GameDesire Poker Games) - [url]http://67.15.101.33/g_bin/pl/poker_2_0_0_49.cab[/url]

O16 - DPF: {A1FE3DE0-CF77-11D4-8340-0080C8D7ED4A} (GameDesire Pinball Demon) - [url]http://67.15.101.3/g_bin/pl/demon_2_0_0_30.cab[/url]

O16 - DPF: {A1FE3DEF-CF77-11D4-8340-0080C8D7ED4A} (GameDesire Pinball Pirate) - [url]http://67.15.101.3/g_bin/pl/pirate_2_0_0_30.cab[/url]

O16 - DPF: {A6212120-01D4-11D5-9A39-0080C8D85044} (GameDesire Slots 70th) - [url]http://67.15.101.33/g_bin/pl/slots70_2_0_0_35.cab[/url]

O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) - [url]http://67.15.101.3/g_bin/pl/billard8_2_0_0_35.cab[/url]

O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C2} (GameDesire Pool 9) - [url]http://67.15.101.33/g_bin/pl/billard9_2_0_0_35.cab[/url]

O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C4} (GameDesire Pool Training) - [url]http://67.15.101.3/g_bin/pl/billardt_2_0_0_34.cab[/url]

O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C5} (GameDesire Snooker) - [url]http://67.15.101.3/g_bin/pl/snooker_2_0_0_35.cab[/url]

O17 - HKLMSystemCCSServicesTcpip..{8D597CD0-E989-4785-9C44-E6D44A7A4950}: NameServer = 194.204.159.1 217.98.63.164

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL

O20 - Winlogon Notify: WgaLogon - C:WINDOWS

O23 - Service: Adobe LM Service - Adobe Systems - C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe

O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - d:ProgramyAreschatServer.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:Program FilesAlwil SoftwareAvast4ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashWebSv.exe" /service (file missing)

O23 - Service: Google Updater Service (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe

O23 - Service: MSSQLServerADHelper - Unknown owner - C:Program FilesMicrosoft SQL Server80ToolsBinnsqladhlp.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe

O23 - Service: ServiceLayer - Nokia. - C:Program FilesCommon FilesPCSuiteServicesServiceLayer.exe

Edit: Dzięki 0wn3r
<
 

0wn3r

Były Moderator
Dołączył
Marzec 10, 2007
Posty
1330
Usuń to :

Kod:
O2 - BHO: (no name) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)

oraz

Kod:
     O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

Tak ogólnie to masz log czysty..
 

wzór

Użytkownik
Dołączył
Sierpień 29, 2007
Posty
27
Unexpected error occurred!
Error #52 (Bad file name or number) in Sub GetLongPath(?.exe).

Please send a report to [email protected], mentioning what you were doing, and what version of Windows you have.

This message has been copied to your clipboard.

Logfile of HijackThis v1.99.1
Scan saved at 01:31:27, on 2002-01-13
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 SP2 (7.00.5730.0011)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:program FilesAheadInCDInCDsrv.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:program FilesG DATA AntiVirus TrialAVKAVKService.exe
C:program FilesG DATA AntiVirus TrialAVKAVKWCtl.exe
C:program FilesF-Secure Internet SecurityAnti-Virusfsgk32st.exe
C:program FilesF-Secure Internet SecurityAnti-VirusFSGK32.EXE
C:program FilesF-Secure Internet SecurityCommonFSMA32.EXE
C:WINDOWSsystem32SearchIndexer.exe
C:program FilesCommon FilesG DATAAVKProxyAVKProxy.exe
C:program FilesATI TechnologiesATI.ACECLI.EXE
C:WINDOWSSOUNDMAN.EXE
C:program FilesAheadInCDInCD.exe
C:program Fileslg_fwupdatefwupdate.exe
C:program FilesWinampwinampa.exe
C:program FilesG DATA AntiVirus TrialAVKTrayAVKTray.exe
D:Gadu-Gadugg.exe
C:program FilesHide IP Platinumhideippla.exe
C:WINDOWSsystem32ctfmon.exe
C:pROGRA~1MOZILL~1FIREFOX.EXE
C:program FilesF-Secure Internet SecurityAnti-Virusfssm32.exe
C:program FilesATI TechnologiesATI.ACEcli.exe
C:program FilesATI TechnologiesATI.ACEcli.exe
C:WINDOWSsystem32SearchProtocolHost.exe
C:WINDOWSsystem32wscntfy.exe
C:program FilesF-Secure Internet SecurityCommonFSLAUNCH.EXE
D:Warezshrek 3hijackthis_sfx.exe
D:Warezshrek 3HijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.windowsxlive.net
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:program FilesSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:program FilesJavajre1.6.0_02binssv.dll
O3 - Toolbar: Peer2Mail Toolbar - {43F2A7F9-06F6-48a5-B0DC-8530BF29CE66} - C:program FilesPeer2Mail Toolbarv2.0.0.0Peer2Mail_Toolbar.dll (file missing)
O4 - HKLM..Run: [ATICCC] "C:program FilesATI TechnologiesATI.ACECLIStart.exe"
O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM..Run: [InCD] C:program FilesAheadInCDInCD.exe
O4 - HKLM..Run: [LGODDFU] "C:program Fileslg_fwupdatefwupdate.exe" blrun
O4 - HKLM..Run: [WinampAgent] C:program FilesWinampwinampa.exe
O4 - HKLM..Run: [AVKTray] "C:program FilesG DATA AntiVirus TrialAVKTrayAVKTray.exe"
O4 - HKLM..Run: [F-Secure Manager] "C:program FilesF-Secure Internet SecurityCommonFSM32.EXE" /splash
O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k
O4 - HKCU..Run: [Gadu-Gadu] "D:Gadu-Gadugg.exe" /tray
O4 - HKCU..Run: [Hide IP Platinum] C:program FilesHide IP Platinumhideippla.exe
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - Startup: Internet.lnk = ?
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:pROGRA~1MICROS~2Office12EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.6.0_02binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.6.0_02binssv.dll
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:pROGRA~1MICROS~2Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:pROGRA~1MICROS~2Office12ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:program FilesSkypeToolbarsInternet ExplorerSkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:pROGRA~1MICROS~2Office12REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:program FilesMessengermsmsgs.exe
O10 - Unknown file in Winsock LSP: c:program filesf-secure internet securityfspsprogramfslsp.dll
O10 - Unknown file in Winsock LSP: c:program filesf-secure internet securityfspsprogramfslsp.dll
O10 - Unknown file in Winsock LSP: c:program filesf-secure internet securityfspsprogramfslsp.dll
O10 - Unknown file in Winsock LSP: c:program filesf-secure internet securityfspsprogramfslsp.dll
O10 - Unknown file in Winsock LSP: c:program filesf-secure internet securityfspsprogramfslsp.dll
O10 - Unknown file in Winsock LSP: c:program filesf-secure internet securityfspsprogramfslsp.dll
O10 - Unknown file in Winsock LSP: c:program filesf-secure internet securityfspsprogramfslsp.dll
O10 - Unknown file in Winsock LSP: c:program filesf-secure internet securityfspsprogramfslsp.dll
O10 - Unknown file in Winsock LSP: c:program filesf-secure internet securityfspsprogramfslsp.dll
O10 - Unknown file in Winsock LSP: c:program filesf-secure internet securityfspsprogramfslsp.dll
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:program FilesInternet ExplorerPluginsNPDocBox.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwa...ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:pROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:pROGRA~1COMMON~1MICROS~1OFFICE12MSOXMLMF.DLL
O20 - Winlogon Notify: WgaLogon - C:WINDOWSSYSTEM32WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:WINDOWSsystem32WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe
O23 - Service: AVKProxy - G DATA Software AG - C:program FilesCommon FilesG DATAAVKProxyAVKProxy.exe
O23 - Service: AVK Service (AVKService) - G DATA Software AG - C:program FilesG DATA AntiVirus TrialAVKAVKService.exe
O23 - Service: Strażnik AVK (AVKWCtl) - G DATA Software AG - C:program FilesG DATA AntiVirus TrialAVKAVKWCtl.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:program FilesF-Secure Internet SecurityAnti-Virusfsgk32st.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:program FilesF-Secure Internet SecurityFSAUAprogramfsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:program FilesF-Secure Internet SecurityFWESProgramfsdfwd.exe
O23 - Service: Agent zarządzania F-Secure (FSMA) - F-Secure Corporation - C:program FilesF-Secure Internet SecurityCommonFSMA32.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:program FilesCommon FilesInstallShieldDriver1050Intel 32IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:program FilesAheadInCDInCDsrv.exe
 

0wn3r

Były Moderator
Dołączył
Marzec 10, 2007
Posty
1330
Log czysty..

Tylko nie wiem co to jest :

Kod:
     O3 - Toolbar: Peer2Mail Toolbar - {43F2A7F9-06F6-48a5-B0DC-8530BF29CE66} - C:Program FilesPeer2Mail Toolbarv2.0.0.0Peer2Mail_Toolbar.dll (file missing)
 

sarsik87

Użytkownik
Dołączył
Kwiecień 21, 2007
Posty
40
Kod:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)

Scan saved at 22:21:04, on 2007-10-15

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

Boot mode: Normal



Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesCommon FilesSymantec SharedccSetMgr.exe

C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe

C:WINDOWSsystem32spoolsv.exe

C:Program FilesCommon FilesSymantec SharedccProxy.exe

C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE

C:Program FilesNorton Internet SecurityNorton AntiVirusnavapsvc.exe

C:Program FilesNorton Internet SecurityNorton AntiVirusSAVScan.exe

C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe

C:WINDOWSExplorer.EXE

C:WINDOWSSOUNDMAN.EXE

C:Program FilesZTE CorporationZXDSL852CnxDslTb.exe

C:Program FilesCommon FilesSymantec SharedccApp.exe

C:WINDOWSsystem32ctfmon.exe

C:WINDOWSsystem32wscntfy.exe

C:WINDOWSsystem32svchost.exe

C:Documents and SettingssarsikPulpitHiJackThis_v2.exe

C:Program FilesMozilla Firefoxfirefox.exe



R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = about:blank

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:PROGRA~1NEOSTR~1SEARCH~1.DLL (file missing)

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll

O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:PROGRA~1FlashGetjccatch.dll

O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:Program FilesMyGlobalSearchbar1.binMGSBAR.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_01binssv.dll

O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:Program FilesCommon FilesSymantec SharedAdBlockingNISShExt.dll

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:Program FilesNorton Internet SecurityNorton AntiVirusNavShExt.dll

O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:Program FilesFlashGetgetflash.dll

O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:Program FilesCommon FilesSymantec SharedAdBlockingNISShExt.dll

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:Program FilesNorton Internet SecurityNorton AntiVirusNavShExt.dll

O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:Program FilesFlashGetfgiebar.dll

O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:Program FilesMyGlobalSearchbar1.binMGSBAR.DLL

O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE

O4 - HKLM..Run: [CnxDslTaskBar] "C:Program FilesZTE CorporationZXDSL852CnxDslTb.exe" "ZTE CorporationZXDSL852"

O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"

O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe

O4 - HKCU..Run: [Gadu-Gadu] "C:Program FilesGadu-Gadugg.exe" /tray

O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'USŁUGA LOKALNA')

O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'USŁUGA SIECIOWA')

O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SYSTEM')

O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: &Clean Traces - C:Program FilesDAPPrivacy Packagedapcleanerie.htm

O8 - Extra context menu item: &Download with &DAP - C:Program FilesDAPdapextie.htm

O8 - Extra context menu item: &Ściągnij przy pomocy FlashGet'a - C:PROGRA~1FlashGetjc_link.htm

O8 - Extra context menu item: &Ściągnij wszystko przy pomocy FlashGet'a - C:PROGRA~1FlashGetjc_all.htm

O8 - Extra context menu item: Download &all with DAP - C:Program FilesDAPdapextie2.htm

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000

O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL

O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:Program FilesFlashGetFlashGet.exe

O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:Program FilesFlashGetFlashGet.exe

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe (file missing)

O17 - HKLMSystemCCSServicesTcpip..{A23527D0-FFB1-46F3-A7BE-008B9EA73FCF}: NameServer = 194.204.159.1 217.98.63.164

O22 - SharedTaskScheduler: Moduł wstępnego ładowania interfejsu Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:WINDOWSsystem32browseui.dll

O22 - SharedTaskScheduler: Demon buforu kategorii składników - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:WINDOWSsystem32browseui.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe

O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccProxy.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccSetMgr.exe

O23 - Service: Usługa Auto Protect programu Norton AntiVirus (navapsvc) - Symantec Corporation - C:Program FilesNorton Internet SecurityNorton AntiVirusnavapsvc.exe

O23 - Service: SAVScan - Symantec Corporation - C:Program FilesNorton Internet SecurityNorton AntiVirusSAVScan.exe

O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:PROGRA~1COMMON~1SYMANT~1SCRIPT~1SBServ.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe



--

End of file - 6751 bytes

sprawdzcie czy wszystko gra
smile.gif
 

WunD3r

Użytkownik
Dołączył
Kwiecień 25, 2007
Posty
54
Witam ;]
Kod:
Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 14:06:29, on 2007-10-18

Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Boot mode: Normal



Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSsystem32spoolsv.exe

C:WINDOWSExplorer.EXE

C:WINDOWSSystem32RUNDLL32.EXE

D:INTERN~1MEDIAKEY.EXE

C:WINDOWSSystem32CTHELPER.EXE

D:Esetnod32kui.exe

C:WINDOWSSystem32MMTray.exe

D:INTERN~1KBOSDCtl.EXE

D:INTERN~1KCodeMsg.EXE

D:Zone LabsZoneAlarmzlclient.exe

C:WINDOWSSystem32spooldriversw32x863hpztsb10.exe

C:Program FilesHPhpcoretechhpcmpmgr.exe

C:Program FilesHewlett-PackardHP Software UpdateHPWuSchd2.exe

C:Program FilesCyberLinkPowerDVDPDVDServ.exe

C:Program FilesJavajre1.5.0_10binjusched.exe

D:NOKIANOKIAP~1LAUNCH~1.EXE

D:A4TechMouseAmoumain.exe

C:WINDOWSVM303_STI.EXE

C:WINDOWSSystem32ctfmon.exe

C:Program FilesMessengermsmsgs.exe

D:Konnektkonnekt.exe

C:Program FilesMicrosoft ActiveSyncwcescomm.exe

C:PROGRA~1MICROS~3rapimgr.exe

C:PROGRA~1COMMON~1PCSuiteServicesSERVIC~1.EXE

C:WINDOWSsystem32Ctsvccda.exe

D:Gadu-Gadugg.exe

D:StatBarStatBar.exe

d:Esetnod32krn.exe

C:WINDOWSSystem32nvsvc32.exe

C:WINDOWSSystem32PnkBstrA.exe

C:Program FilesCyberLinkShared filesRichVideo.exe

D:Alcohol SoftAlcohol 120StarWindStarWindServiceAE.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSsystem32ZoneLabsvsmon.exe

D:lgLGSyncManager.exe

D:Program FilesLightSurfCommonIconMgr.exe

D:Program FilesLightSurfColorifichgcctl95.exe

D:TORVidalia BundlePrivoxyprivoxy.exe

C:WINDOWSSystem32MsPMSPSv.exe

D:Program FilesLightSurfColor IndicatorTICIcon.exe

C:Program FilesCommon FilesAheadLibNMIndexingService.exe

D:PROGRA~1MOZILL~1FIREFOX.EXE

C:Program FilesJavajre1.5.0_10binjucheck.exe

D:mIRCmirc.exe

C:Program FilesTrend MicroHijackThisHijackThis.exe

C:WINDOWSregedit.exe



R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = [url]http://wp.pl/[/url]

R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = [url]http://www.windowsxlive.net[/url]

R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = 4.235.107.214:8000

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:Program FilesAskTBarSrchAstt1.binA5SRCHAS.DLL (file missing)

F2 - REG:system.ini: Shell=explorer.exe ,svchost.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:AdobeAcrobat 7.0ActiveXAcroIEHelper.dll

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - D:BitConnetBitComettoolsBitCometBHO_1.1.3.28.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_10binssv.dll

O2 - BHO: Expressivo - {85F685C3-20D9-4943-95E4-EB4224056C3F} - D:ivonoweExpressivo Demointegrih-iexplorerIH_iexplorer.dll

O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:Program FilesAskTBarSrchAstt1.binA5SRCHAS.DLL (file missing)

O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:FlashGetjccatch.dll

O2 - BHO: (no name) - {D61D7E1A-6613-49CA-B6F9-51DB248E209D} - C:Program FilesVideo ActiveX Accessiesplg.dll (file missing)

O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:Program FilesAskTBarbar1.binASKTBAR.DLL

O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:FlashGetfgiebar.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx

O3 - Toolbar: Protection Bar - {29C5A3B6-9A8D-4FA0-B5AD-3E20F4AA5C00} - C:Program FilesVideo ActiveX Accessiesbpl.dll (file missing)

O3 - Toolbar: Expressivo - {85F685C3-20D9-4943-95E4-EB4224056C3F} - D:ivonoweExpressivo Demointegrih-iexplorerIH_iexplorer.dll

O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:Program FilesAskTBarbar1.binASKTBAR.DLL

O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup

O4 - HKLM..Run: [nwiz] nwiz.exe /install

O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit

O4 - HKLM..Run: [MediaKey] D:INTERN~1MEDIAKEY.EXE

O4 - HKLM..Run: [CTHelper] CTHELPER.EXE

O4 - HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE

O4 - HKLM..Run: [Jet Detection] d:CreativeSBLivePROGRAMADGJDet.exe

O4 - HKLM..Run: [nod32kui] "d:Esetnod32kui.exe" /WAITSERVICE

O4 - HKLM..Run: [MMTray] MMTray.exe

O4 - HKLM..Run: [Zone Labs Client] d:Zone LabsZoneAlarmzlclient.exe

O4 - HKLM..Run: [HPDJ Taskbar Utility] C:WINDOWSSystem32spooldriversw32x863hpztsb10.exe

O4 - HKLM..Run: [HP Component Manager] "C:Program FilesHPhpcoretechhpcmpmgr.exe"

O4 - HKLM..Run: [HP Software Update] "C:Program FilesHewlett-PackardHP Software UpdateHPWuSchd2.exe"

O4 - HKLM..Run: [RemoteControl] "C:Program FilesCyberLinkPowerDVDPDVDServ.exe"

O4 - HKLM..Run: [LanguageShortcut] "C:Program FilesCyberLinkPowerDVDLanguageLanguage.exe"

O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.5.0_10binjusched.exe"

O4 - HKLM..Run: [Adobe Photo Downloader] "C:Program FilesAdobePhotoshop Album Starter Edition3.0Appsapdproxy.exe"

O4 - HKLM..Run: [PCSuiteTrayApplication] D:NOKIANOKIAP~1LAUNCH~1.EXE -onlytray

O4 - HKLM..Run: [Vista Sidebar] C:Program FilesVista Sidebarsidebar.exe

O4 - HKLM..Run: [WheelMouse] d:A4TechMouseAmoumain.exe

O4 - HKLM..Run: [PinnacleDriverCheck] C:WINDOWSSystem32PSDrvCheck.exe

O4 - HKLM..Run: [NBKeyScan] "D:neroNero 7Nero BackItUpNBKeyScan.exe"

O4 - HKLM..Run: [NeroFilterCheck] C:Program FilesCommon FilesAheadLibNeroCheck.exe

O4 - HKLM..Run: [BigDog303] C:WINDOWSVM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)

O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe

O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background

O4 - HKCU..Run: [Konnekt] "D:Konnektkonnekt.exe" /autostart

O4 - HKCU..Run: [H/PC Connection Agent] "C:Program FilesMicrosoft ActiveSyncwcescomm.exe"

O4 - HKCU..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /nosplash /minimized

O4 - HKCU..Run: [Gadu-Gadu] "D:Gadu-Gadugg.exe" /tray

O4 - HKCU..Run: [StatBar] D:StatBarStatBar.exe

O4 - HKCU..Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:Program FilesCommon FilesAheadLibNMBgMonitor.exe"

O4 - HKCU..Run: [Vidalia] "D:TORVidalia BundleVidaliavidalia.exe"

O4 - HKCU..Run: [RocketDock] "D:Program FilesRocketDockRocketDock.exe"

O4 - HKLM..PoliciesExplorerRun: [user32.dll] C:Program FilesVideo ActiveX Accessiesmn.exe

O4 - HKLM..PoliciesExplorerRun: [rare] C:Program FilesVideo ActiveX Accessimsmain.exe

O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User '?')

O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User '?')

O4 - HKUSS-1-5-21-842925246-1275210071-682003330-1005..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe (User '?')

O4 - HKUSS-1-5-21-842925246-1275210071-682003330-1005..Run: [H/PC Connection Agent] "C:Program FilesMicrosoft ActiveSyncwcescomm.exe" (User '?')

O4 - HKUSS-1-5-21-842925246-1275210071-682003330-1005..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /nosplash /minimized (User '?')

O4 - HKUSS-1-5-21-842925246-1275210071-682003330-1005..Run: [Gadu-Gadu] "D:Gadu-Gadugg.exe" /tray (User '?')

O4 - HKUSS-1-5-21-842925246-1275210071-682003330-1005..Run: [StatBar] D:StatBarStatBar.exe (User '?')

O4 - HKUSS-1-5-21-842925246-1275210071-682003330-1005..Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:Program FilesCommon FilesAheadLibNMBgMonitor.exe" (User '?')

O4 - HKUSS-1-5-21-842925246-1275210071-682003330-1005..Run: [Vidalia] "D:TORVidalia BundleVidaliavidalia.exe" (User '?')

O4 - HKUSS-1-5-21-842925246-1275210071-682003330-1005..Run: [RocketDock] "D:Program FilesRocketDockRocketDock.exe" (User '?')

O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User '?')

O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSSystem32CTFMON.EXE (User 'Default user')

O4 - S-1-5-21-842925246-1275210071-682003330-1005 Startup: Adobe Gamma.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe (User '?')

O4 - S-1-5-21-842925246-1275210071-682003330-1005 Startup: Vista sidebar.lnk = C:Program FilesVista Sidebarsidebar.exe (User '?')

O4 - Startup: Adobe Gamma.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe

O4 - Startup: Vista sidebar.lnk = C:Program FilesVista Sidebarsidebar.exe

O4 - Global Startup: Expressivo.lnk = C:Program FilesivoExpressivo Demoexpressivo.exe

O4 - Global Startup: LG SyncManager.lnk = D:lgLGSyncManager.exe

O4 - Global Startup: LightSurf.lnk = D:Program FilesLightSurfCommonIconMgr.exe

O4 - Global Startup: Microsoft Office.lnk = D:Microsoft OfficeOfficeOSA9.EXE

O4 - Global Startup: Privoxy.lnk = D:TORVidalia BundlePrivoxyprivoxy.exe

O8 - Extra context menu item: Download All by FlashGet - D:FlashGetjc_all.htm

O8 - Extra context menu item: Download all links using BitComet - res://D:BitConnetBitCometBitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Download all videos using BitComet - res://D:BitConnetBitCometBitComet.exe/AddVideo.htm

O8 - Extra context menu item: Download link using &BitComet - res://D:BitConnetBitCometBitComet.exe/AddLink.htm

O8 - Extra context menu item: Download using FlashGet - D:FlashGetjc_link.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll

O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:PROGRA~1MICROS~3INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:PROGRA~1MICROS~3INetRepl.dll

O9 - Extra 'Tools' menuitem: Utwórz łącze Ulubione dla urządzenia przenośnego... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:PROGRA~1MICROS~3INetRepl.dll

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm

O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:FlashGetflashget.exe

O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:FlashGetflashget.exe

O16 - DPF: {18506D80-9B80-11D4-82C2-0080C8D7ED4A} (GameDesire Roulette) - [url]http://67.15.101.3/g_bin/pl/roulette_2_0_0_21.cab[/url]

O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - [url]http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab[/url]

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - [url]http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1169818200140[/url]

O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - [url]http://www.mks.com.pl/skaner/SkanerOnline.cab[/url]

O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - [url]http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab[/url]

O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) - [url]http://67.15.101.3/g_bin/pl/billard8_2_0_0_28.cab[/url]

O22 - SharedTaskScheduler: convalescently - {cea2e5cd-e849-427b-80f0-59298caef1c4} - C:WINDOWSSystem32cqsfk.dll (file missing)

O23 - Service: Adobe LM Service - Adobe Systems - C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:WINDOWSsystem32Ctsvccda.exe

O23 - Service: NBService - Nero AG - D:nero2222Nero 7Nero BackItUpNBService.exe

O23 - Service: NMIndexingService - Nero AG - C:Program FilesCommon FilesAheadLibNMIndexingService.exe

O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - d:Esetnod32krn.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSSystem32nvsvc32.exe

O23 - Service: PnkBstrA - Unknown owner - C:WINDOWSSystem32PnkBstrA.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:Program FilesCyberLinkShared filesRichVideo.exe

O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:Alcohol SoftAlcohol 120StarWindStarWindServiceAE.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:WINDOWSsystem32ZoneLabsvsmon.exe



--

End of file - 13107 bytes
 

0wn3r

Były Moderator
Dołączył
Marzec 10, 2007
Posty
1330
Nie wiem co to jest :

Kod:
     O4 - HKLM..PoliciesExplorerRun: [user32.dll] C:Program FilesVideo ActiveX Accessiesmn.exe

&

Kod:
O4 - HKLM..PoliciesExplorerRun: [rare] C:Program FilesVideo ActiveX Accessimsmain.exe

Kod:
Unknown

    O16 - DPF: {18506D80-9B80-11D4-82C2-0080C8D7ED4A} (GameDesire Roulette) - [url]http://67.15.101.3/g_bin/pl/roulette_2_0_0_21.cab[/url]

Kod:
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) - [url]http://67.15.101.3/g_bin/pl/billard8_2_0_0_28.cab[/url]

Tak pozatym to masz czysty log
<
 

H4CK3R4M

Użytkownik
Dołączył
Marzec 24, 2006
Posty
45
Sprawdzcie mojego wirusy mi weszly na kompa troche poczyscilem i nie wiem czy to juz wszystko ale dalej cos niebardzo komp chodzi i komunikaty od av ze wykryto wirusa

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:program FilesAlwil SoftwareAvast4aswUpdSv.exe
C:program FilesAlwil SoftwareAvast4ashServ.exe
C:WINDOWSsystem32spoolsv.exe
C:pROGRA~1ALWILS~1Avast4ashDisp.exe
C:program FilesSunbelt SoftwarePersonal Firewallkpf4ss.exe
C:program FilesMessengermsmsgs.exe
C:program FilesGadu-Gadugg.exe
C:WINDOWSSystem32nvsvc32.exe
C:program FilesSunbelt SoftwarePersonal Firewallkpf4gui.exe
C:program FilesAlwil SoftwareAvast4ashWebSv.exe
C:program FilesAlwil SoftwareAvast4ashMaiSv.exe
C:program FilesSunbelt SoftwarePersonal Firewallkpf4gui.exe
C:WINDOWSSystem32wuauclt.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:program FilesUnlockerUnlockerAssistant.exe
C:program FilesLavasoftAd-Aware 2007aawservice.exe
C:program FilesSpyware TerminatorSpywareTerminator.exe
C:WINDOWSSystem32svchost.exe
C:program FilesInternet Exploreriexplore.exe
C:pROGRA~1CrawlerToolbarCToolbar.exe
D:KubaPULPIT NAJNOWSZYYNowy folder (2)HijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.onet.pl/
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:pROGRA~1CrawlerToolbarctbr.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program filesgooglegoogletoolbar1.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:pROGRA~1MEGAUP~1MEGAUP~1.DLL
O4 - HKLM..Run: [Soltek] C:WINDOWSSystem32autorun.exe
O4 - HKLM..Run: [avast!] C:pROGRA~1ALWILS~1Avast4ashDisp.exe
O4 - HKLM..Run: [BearShare] "C:program FilesBearShareBearShare.exe" /pause
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [UnlockerAssistant] "C:program FilesUnlockerUnlockerAssistant.exe"
O4 - HKLM..Run: [SunJavaUpdateSched] "C:program FilesJavajre1.6.0_01binjusched.exe"
O4 - HKLM..Run: [Flashget] "C:program FilesFlashGetFlashGet.exe" /min
O4 - HKCU..Run: [MSMSGS] "C:program FilesMessengermsmsgs.exe" /background
O4 - HKCU..Run: [Gadu-Gadu] "C:program FilesGadu-Gadugg.exe" /tray
O4 - HKCU..Run: [DAEMON Tools] "C:program FilesDAEMON Toolsdaemon.exe" -lang 1033
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:program FilesAdobeAcrobat 7.0Readerreader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:program FilesMicrosoft OfficeOfficeOSA9.EXE
O8 - Extra context menu item: &Ściągnij przy pomocy FlashGet'a - C:program FilesFlashGetjc_link.htm
O8 - Extra context menu item: &Ściągnij wszystko przy pomocy FlashGet'a - C:program FilesFlashGetjc_all.htm
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.6.0_01binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.6.0_01binssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSwebrelated.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:program FilesFlashGetFlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:program FilesFlashGetFlashGet.exe
O16 - DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} (MainControl Class) - http://slimak.onet.pl/_m/wirusy/ArcaOnline.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1178815143467
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1178815103039
O20 - AppInit_DLLs: C:WINDOWSSystem32sulimo.dat
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:program FilesLavasoftAd-Aware 2007aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:program FilesAlwil SoftwareAvast4aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:program FilesAlwil SoftwareAvast4ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:program FilesAlwil SoftwareAvast4ashWebSv.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: ICF - Unknown owner - C:WINDOWSSystem32svchost.exe:exe.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:program FilesSunbelt SoftwarePersonal Firewallkpf4ss.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:WINDOWSSystem32nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:WINDOWSSystem32PnkBstrA.exe
 

0wn3r

Były Moderator
Dołączył
Marzec 10, 2007
Posty
1330
O23 - Service: ICF - Unknown owner - C:WINDOWSSystem32svchost.exe:exe.exe

O20 - AppInit_DLLs: C:WINDOWSSystem32sulimo.dat

To może być coś szkodliwego.. co do drugiego nie jestem pewien

Edit : zmień sobie antywirusa z Avasta na inny (Avast = shit)
 

H4CK3R4M

Użytkownik
Dołączył
Marzec 24, 2006
Posty
45
To pierwsze mam od zawsze to raczej nic groznego a to drugie mam wlasnie od wczoraj i niebardzo da sie usunac w hijak this jakis error wyskakuje
 

jakiskoles

Użytkownik
Dołączył
Sierpień 13, 2007
Posty
5
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:27:21, on 2007-10-20
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:program FilesIntelIntel Matrix Storage ManagerIaantmon.exe
C:program FilesCommon FilesLightScribeLSSrvc.exe
C:WINDOWSsystem32wscntfy.exe
C:WINDOWSExplorer.EXE
C:program FilesWinampwinampa.exe
C:WINDOWSsystem32ctfmon.exe
C:WINDOWSsystem32temp1.exe
C:WINDOWSsystem32msiexec.exe
C:program FilesWinampwinamp.exe
C:program FilesSony EricssonMobile2Application LauncherApplication Launcher.exe
C:program FilesCommon FilesTeleca SharedCapabilityManager.exe
C:program FilesCommon FilesTeleca SharedGeneric.exe
C:program FilesSony EricssonMobile2Mobile Phone Monitorepmworker.exe
C:Documents and SettingsAdministratorPulpithijackthis.com

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
F3 - REG:win.ini: load=C:WINDOWSsvchost.exe
O4 - HKLM..Run: [BroadcomWireless] C:program FilesBroadcomWirelessUtilityWlanUtil.exe
O4 - HKLM..Run: [WinampAgent] C:program FilesWinampwinampa.exe
O4 - HKLM..Run: [Sony Ericsson PC Suite] "C:program FilesSony EricssonMobile2Application LauncherApplication Launcher.exe" /startoptions
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:program FilesCommon FilesAheadLibNMBgMonitor.exe"
O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SYSTEM')
O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:pROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:program FilesMessengermsmsgs.exe
O23 - Service: IntelŽ Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:program FilesIntelIntel Matrix Storage ManagerIaantmon.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:program FilesCommon FilesLightScribeLSSrvc.exe

--
End of file - 2862 bytes










ComboFix 07-10-20.6 - Administrator 2007-10-20 18:28:45.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1635 [GMT 2:00]
Running from: C:Documents and SettingsAdministratorPulpitComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:Autorun.inf
C:autorun.inf
C:copy.exe
C:copy.exe
C:host.exe
C:WINDOWSautorun.inf
C:WINDOWSsvchost.exe
C:WINDOWSsystem32temp1.exe
C:WINDOWSsystem32temp2.exe
C:WINDOWSxcopy.exe
D:autorun.inf
D:Autorun.inf
D:copy.exe
D:copy.exe
D:host.exe

.
((((((((((((((((((((((((( Files Created from 2007-09-20 to 2007-10-20 )))))))))))))))))))))))))))))))
.

2007-10-20 18:27 51,200 --a------ C:WINDOWSNirCmd.exe
2007-10-20 18:21 <DIR> d-------- C:program FilesSony Ericsson
2007-10-20 18:21 <DIR> d-------- C:program FilesCommon FilesTeleca Shared
2007-10-20 18:21 <DIR> d-------- C:Documents and SettingsAll UsersDocuments
2007-10-20 18:21 <DIR> d-------- C:Documents and SettingsAll UsersDane aplikacjiTeleca
2007-10-20 18:21 <DIR> d-------- C:Documents and SettingsAll UsersDane aplikacjiSony Ericsson
2007-10-20 18:21 <DIR> d-------- C:Documents and SettingsAdministratorDane aplikacjiTeleca
2007-10-20 18:19 <DIR> d-------- C:WINDOWSDownloaded Installations
2007-10-20 18:19 85,408 --a------ C:WINDOWSsystem32driversw810mgmt.sys
2007-10-20 18:19 83,344 --a------ C:WINDOWSsystem32driversw810obex.sys
2007-10-20 18:18 94,064 --a------ C:WINDOWSsystem32driversw810mdm.sys
2007-10-20 18:18 8,336 --a------ C:WINDOWSsystem32driversw810mdfl.sys
2007-10-20 18:18 6,176 --a------ C:WINDOWSsystem32driversw810cmnt.sys
2007-10-20 18:18 6,176 --a------ C:WINDOWSsystem32driversw810cm.sys
2007-10-20 18:15 <DIR> d-------- C:WINDOWSLastGood
2007-10-20 18:15 58,288 -ra------ C:WINDOWSsystem32driversw810bus.sys
2007-10-20 18:15 5,808 -ra------ C:WINDOWSsystem32driversw810whnt.sys
2007-10-20 18:15 5,808 -ra------ C:WINDOWSsystem32driversw810wh.sys
2007-10-18 15:36 <DIR> d-------- C:program Filesffdshow
2007-10-18 15:19 <DIR> d-------- C:program FilesMarBit
2007-10-18 14:27 <DIR> d-------- C:program FilesCommon FilesLightScribe
2007-10-18 14:26 <DIR> d-------- C:Documents and SettingsAdministratorDane aplikacjiAhead
2007-10-18 14:23 <DIR> d-------- C:program FilesNero
2007-10-18 14:23 <DIR> d-------- C:program FilesCommon FilesAhead
2007-10-18 12:57 <DIR> d-------- C:WINDOWSpss
2007-10-18 08:39 <DIR> d-------- C:WINDOWSShellNew
2007-10-17 21:10 247,256 --a------ C:WINDOWSAlcmtr.exe
2007-10-16 18:05 <DIR> d-------- C:Documents and SettingsAdministratorDane aplikacjiMusicIP
2007-10-16 18:04 <DIR> d-------- C:program FilesWinamp
2007-10-16 16:27 <DIR> d-------- C:Documents and SettingsAdministratorDane aplikacjiOpenOffice.ux.pl2
2007-10-16 08:31 <DIR> d-------- C:program FilesOpenOffice.ux.pl 2.2.0
2007-10-15 22:35 <DIR> d-------- C:program FilesCONEXANT
2007-10-15 22:31 60,288 --a------ C:WINDOWSsystem32driversdrmk.sys
2007-10-15 22:31 60,288 --a--c--- C:WINDOWSsystem32dllcachedrmk.sys
2007-10-15 22:31 4,096 --a------ C:WINDOWSsystem32ksuser.dll
2007-10-15 22:31 4,096 --a--c--- C:WINDOWSsystem32dllcacheksuser.dll
2007-10-15 22:28 <DIR> d-------- C:program FilesRealtek
2007-10-15 22:27 520,192 --a------ C:WINDOWSRtlExUpd.dll
2007-10-15 22:27 493,012 --a------ C:WINDOWSHideWin.exe
2007-10-15 22:20 160,256 -ra------ C:WINDOWSsystem32driversb57xp32.sys
2007-10-15 22:20 160,256 --a--c--- C:WINDOWSsystem32dllcacheb57xp32.sys
2007-10-15 22:18 <DIR> d-------- C:program FilesSynaptics
2007-10-15 22:18 191,936 --a------ C:WINDOWSsystem32driversSynTP.sys
2007-10-15 22:18 114,688 --a------ C:WINDOWSsystem32SynCtrl.dll
2007-10-15 22:18 94,297 --a------ C:WINDOWSsystem32SynTPAPI.dll
2007-10-15 22:18 82,012 --a------ C:WINDOWSsystem32SynCOM.dll
2007-10-15 22:18 81,920 --a------ C:WINDOWSsystem32SynTPCo2.dll
2007-10-15 22:18 69,721 --a------ C:WINDOWSsystem32SynTPFcs.dll
2007-10-15 22:16 180,224 --a------ C:WINDOWSsystem32igfxres.dll
2007-10-15 22:12 <DIR> d-------- C:program FilesCommon FilesInstallShield
2007-10-15 22:12 <DIR> d-------- C:program FilesBroadcom
2007-10-15 22:12 754,688 --a------ C:WINDOWSsystem32driversbcmwl564.sys
2007-10-15 22:12 604,928 --a------ C:WINDOWSsystem32driversbcmwl5.sys
2007-10-15 22:12 28,544 --a------ C:WINDOWSsystem32driverscallistx.sys
2007-10-15 22:10 <DIR> d-------- C:WINDOWStiinst
2007-10-15 22:10 290,304 --a------ C:WINDOWSsystem32driverstifm21.sys
2007-10-15 22:08 <DIR> d-------- C:WINDOWSsystem32PLK
2007-10-15 22:08 304,602 --a------ C:WINDOWSsystem32Imsmudlg.exe
2007-10-15 22:07 <DIR> d--h----- C:program FilesInstallShield Installation Information
2007-10-15 22:07 <DIR> d-------- C:Documents and SettingsAdministratorDane aplikacjiInstallShield
2007-10-15 22:04 <DIR> d----c--- C:WINDOWSsystem32DRVSTORE
2007-10-15 22:04 <DIR> d-------- C:program FilesIntel
2007-10-15 22:04 <DIR> d-------- C:Intel
2007-10-15 22:02 988,800 --a------ C:WINDOWSsystem32driversHSF_DPV.sys
2007-10-15 22:02 730,112 --a------ C:WINDOWSsystem32driversHSF_CNXT.sys
2007-10-15 22:02 209,664 --a------ C:WINDOWSsystem32driversHSFHWAZL.sys
2007-10-15 22:02 176,128 --a------ C:WINDOWSsystem32UCI32M16.dll
2007-10-15 22:02 94,208 --a------ C:WINDOWSsystem32mdmxsdk.dll
2007-10-15 22:02 12,672 --a------ C:WINDOWSsystem32driversmdmxsdk.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-15 19:51 --------- d-----w C:program Filesmicrosoft frontpage
2007-10-15 19:50 --------- d-----w C:program FilesUsługi online
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"BroadcomWireless"="C:program FilesBroadcomWirelessUtilityWlanUtil.exe" []
"WinampAgent"="C:program FilesWinampwinampa.exe" [2007-04-23 19:57]
"Sony Ericsson PC Suite"="C:program FilesSony EricssonMobile2Application LauncherApplication Launcher.exe" [2005-10-26 16:17]

[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="C:WINDOWSsystem32ctfmon.exe" [2004-08-04 00:44]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:program FilesCommon FilesAheadLibNMBgMonitor.exe" []

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupfolderC:^Documents and Settings^Administrator^Menu Start^Programy^Autostart^OpenOffice.ux.pl 2.2.0.lnk]
path=C:Documents and SettingsAdministratorMenu StartProgramyAutostartOpenOffice.ux.pl 2.2.0.lnk
backup=C:WINDOWSpssOpenOffice.ux.pl 2.2.0.lnkStartup

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupfolderC:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Microsoft Office.lnk]
path=C:Documents and SettingsAll UsersMenu StartProgramyAutostartMicrosoft Office.lnk
backup=C:WINDOWSpssMicrosoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAlcmtr]
ALCMTR.EXE

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAzMixerSel]
C:program FilesRealtekInstallShieldAzMixerSel.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregHotKeysCmds]
C:WINDOWSsystem32hkcmd.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregIAAnotif]
"C:program FilesIntelIntel Matrix Storage ManagerIaanotif.exe"

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregIgfxTray]
C:WINDOWSsystem32igfxtray.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregPersistence]
C:WINDOWSsystem32igfxpers.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregRTHDCPL]
RTHDCPL.EXE

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSynTPEnh]
C:program FilesSynapticsSynTPSynTPEnh.exe


[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{2c0
ccb9c-7b67-11dc-a348-806d6172696f}]
AutoRuncommand - E:start.exe

[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{3dd
4c2d0-7bab-11dc-a355-001c26c61d33}]
AutoRuncommand - C:WINDOWSsystem32RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe

[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{552
c5c9e-7b65-11dc-9197-806d6172696f}]
AutoRuncommand - C:WINDOWSsystem32RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe

[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{552
c5c9f-7b65-11dc-9197-806d6172696f}]
AutoRuncommand - C:WINDOWSsystem32RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe

*Newly Created Service* - CATCHME
.
**************************************************************************

catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-20 18:29:33
Windows 5.1.2600 Dodatek Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-20 18:29:51
.
--- E O F ---





Heh y pocyatku nie yroyumialme o co ci chodyi. Nie mam ya bardyo dostepu do neta zeby szybko odpisywac
smile.gif
 

Lupek

Użytkownik
Dołączył
Maj 4, 2007
Posty
4
log

Kod:
Logfile of HijackThis v1.99.1

Scan saved at 19:54:07, on 07-10-22

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)



Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSsystem32spoolsv.exe

C:WINDOWSmsappsIEXPLORE.EXE

C:WINDOWSSystem32svchost.exe

C:Program FilesCommon FilesMicrosoft SharedVS7Debugmdm.exe

C:Program FilesMicrosoft SQL ServerMSSQLBinnsqlservr.exe

C:Program FilesNeroNero8Nero BackItUpNBService.exe

C:Program FilesAnalog DevicesSoundMAXSMAgent.exe

C:Program FilesAlcohol SoftAlcohol 120StarWindStarWindService.exe

C:WINDOWSsystem32svchost.exe

C:Program FilesDialNetWrOS.EXE

C:WINDOWSExplorer.EXE

C:PROGRA~1ALWILS~1Avast4ashDisp.exe

C:Program FilesAnalog DevicesSoundMAXSMTray.exe

C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe

C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe

C:WINDOWSsystem32LVCOMSX.EXE

C:WINDOWSsystem32ezSP_Px.exe

C:Program FilesJavajre1.6.0_03binjusched.exe

C:Program FilesQuickTimeqttask.exe

C:Program FilesLogitechVideoLogiTray.exe

C:WINDOWSsystem32taskswitch.exe

C:Program FilesSony EricssonMobile2Application LauncherApplication Launcher.exe

C:Program FilesNeroNero8Nero BackItUpNBKeyScan.exe

C:Program FilesDialNetwinpppoverethernet.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSsystem32ctfmon.exe

C:Program FilesBySoft FreeRAMFreeRAM.exe

C:Program FilesTlen.pltlen.exe

C:Program FilesProlinkPlayTV ProTVRMVCR.EXE

C:Program FilesProlinkPlayTV ProTVSCHL.EXE

C:Program FilesVIARAIDraid_tool.exe

C:Program FilesMustek 1200 UB PlusDriverWATCH.exe

C:Program FilesLogitechVideoFxSvr2.exe

C:WINDOWSVTTray.exe

C:WINDOWSsystem32cmd.exe

C:WINDOWSsystem32cscript.exe

C:WINDOWSsystem32cscript.exe

C:WINDOWSsystem32cscript.exe

C:WINDOWSsystem32cscript.exe

C:DOCUME~1SYNUSIEUSTAWI~1Temp63exhmrgml2_2.exe

C:WINDOWSsystem32cscript.exe

C:WINDOWSsystem32cscript.exe

C:WINDOWSsystem32cmd.exe

C:WINDOWSsystem32cscript.exe

C:Documents and SettingsSYNUSIEMoje dokumentyGadu-Gadugg.exe

C:Program FilesMozilla Firefoxfirefox.exe

C:Program FilesFlashGetFlashGet.exe

C:WINDOWSsystem32cmd.exe

C:WINDOWSsystem32cscript.exe

C:DOCUME~1SYNUSIEUSTAWI~1Temp60exgmsimpst0.exe

C:WINDOWSsystem32cmd.exe

C:WINDOWSsystem32cscript.exe

C:WINDOWSsystem32cmd.exe

C:WINDOWSsystem32cscript.exe

C:Documents and SettingsSYNUSIEMoje dokumentyHijackThisHijackThis.exe



R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = [url]http://google.com/[/url]

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page = 

R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = 85.214.77.184:80

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

F2 - REG:system.ini: Shell=Explorer.exe %WINDIR%VTTray.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll

O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:Program FilesFlashGetjccatch.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_03binssv.dll

O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)

O3 - Toolbar: DosPop Toolbar - {BFB5F154-9212-46F3-B547-AC6106030A54} - C:Program FilesDosPop Toolbardospop.dll (file missing)

O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe

O4 - HKLM..Run: [Smapp] C:Program FilesAnalog DevicesSoundMAXSMTray.exe

O4 - HKLM..Run: [ISUSPM Startup] "C:Program FilesCommon FilesInstallShieldUpdateServiceisuspm.exe" -startup

O4 - HKLM..Run: [ISUSScheduler] "C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe" -start

O4 - HKLM..Run: [ATIPTA] C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe

O4 - HKLM..Run: [LVCOMSX] C:WINDOWSsystem32LVCOMSX.EXE

O4 - HKLM..Run: [ezShieldProtector for Px] C:WINDOWSsystem32ezSP_Px.exe

O4 - HKLM..Run: [WellPhone DirectSync - ScheduleSync] C:PROGRA~1WELLPH~1SCHEDU~1.EXE

O4 - HKLM..Run: [SmartSync - ScheduleSync] C:PROGRA~1MOBILE~1SMARTS~1SCHEDU~1.EXE

O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.6.0_03binjusched.exe"

O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime

O4 - HKLM..Run: [LogitechVideoTray] C:Program FilesLogitechVideoLogiTray.exe

O4 - HKLM..Run: [LogitechVideoRepair] C:Program FilesLogitechVideoISStart.exe 

O4 - HKLM..Run: [CoolSwitch] C:WINDOWSsystem32taskswitch.exe

O4 - HKLM..Run: [Sony Ericsson PC Suite] "C:Program FilesSony EricssonMobile2Application LauncherApplication Launcher.exe" /startoptions

O4 - HKLM..Run: [NBKeyScan] "C:Program FilesNeroNero8Nero BackItUpNBKeyScan.exe"

O4 - HKLM..Run: [NeroFilterCheck] C:Program FilesCommon FilesNeroLibNeroCheck.exe

O4 - HKLM..Run: [a-winpoet-service] "C:Program FilesDialNetwinpppoverethernet.exe"

O4 - HKLM..Run: [z-wrdialer] "C:Program FilesDialNetwrdialer.exe"

O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe

O4 - HKCU..Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:Program FilesCommon FilesAheadLibNMBgMonitor.exe"

O4 - HKCU..Run: [Gadu-Gadu] "C:Documents and SettingsSYNUSIEMoje dokumentyGadu-Gadugg.exe" /tray

O4 - HKCU..Run: [z-WrDialer] C:Program FilesDialNetWrDialer.exe

O4 - HKCU..Run: [BySoft FreeRAM] C:Program FilesBySoft FreeRAMFreeRAM.exe

O4 - HKCU..Run: [Komunikator] C:Program FilesTlen.pltlen.exe

O4 - Startup: Xfire.lnk = C:Program FilesXfireXfire.exe

O4 - Global Startup: Adobe Gamma.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:Program FilesAdobeReader 8.0Readerreader_sl.exe

O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:Program FilesAdobeReader 8.0ReaderAdobeCollabSync.exe

O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE

O4 - Global Startup: Remote Control.lnk = C:Program FilesProlinkPlayTV ProTVRMVCR.EXE

O4 - Global Startup: Schedule Manager.lnk = C:Program FilesProlinkPlayTV ProTVSCHL.EXE

O4 - Global Startup: Service Manager.lnk = C:Program FilesMicrosoft SQL Server80ToolsBinnsqlmangr.exe

O4 - Global Startup: VIA RAID TOOL.lnk = C:Program FilesVIARAIDraid_tool.exe

O4 - Global Startup: Watch.lnk = C:Program FilesMustek 1200 UB PlusDriverWATCH.exe

O8 - Extra context menu item: Append to existing PDF - res://C:Program FilesAdobeAcrobat 8.0AcrobatAcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:Program FilesAdobeAcrobat 8.0AcrobatAcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert link target to existing PDF - res://C:Program FilesAdobeAcrobat 8.0AcrobatAcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:Program FilesAdobeAcrobat 8.0AcrobatAcroIEFavClient.dll/AcroIECaptureSelLinks.html

O8 - Extra context menu item: Convert selected links to existing PDF - res://C:Program FilesAdobeAcrobat 8.0AcrobatAcroIEFavClient.dll/AcroIEAppendSelLinks.html

O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:Program FilesAdobeAcrobat 8.0AcrobatAcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert selection to existing PDF - res://C:Program FilesAdobeAcrobat 8.0AcrobatAcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert to Adobe PDF - res://C:Program FilesAdobeAcrobat 8.0AcrobatAcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_03binssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_03binssv.dll

O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:Program FilesFlashGetFlashGet.exe

O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:Program FilesFlashGetFlashGet.exe

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe (file missing)

O15 - Trusted Zone: [url]http://www.mks.com.pl[/url]

O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - [url]http://www.mks.com.pl/skaner/SkanerOnline.cab[/url]

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:Program FilesSkypePlugin ManagerSkype4COM.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:WINDOWSsystem32WPDShServiceObj.dll

O23 - Service: Adobe LM Service - Unknown owner - C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe

O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe

O23 - Service: DirectX Service (DirectXokx) - Unknown owner - c:windowssystem32directx.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:Program FilesCommon FilesMacrovision SharedFLEXnet PublisherFNPLicensingService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe

O23 - Service: License Management Service ESD - Unknown owner - C:Program FilesCommon Fileselement5 SharedServiceLicence Manager ESD.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:Program FilesNeroNero8Nero BackItUpNBService.exe

O23 - Service: NMIndexingService - Nero AG - C:Program FilesCommon FilesNeroLibNMIndexingService.exe

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%WinPcaprpcapd.exe" -d -f "%ProgramFiles%WinPcaprpcapd.ini (file missing)

O23 - Service: s3contrl (32-bit) - Unknown owner - C:WINDOWSVTTray.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:Program FilesAnalog DevicesSoundMAXSMAgent.exe

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:Program FilesAlcohol SoftAlcohol 120StarWindStarWindService.exe

O23 - Service: WinPPPoverEthernet - Fine Point Technologies, Inc. - C:Program FilesDialNetWrOS.EXE

Proszę o sprawdzenie
 

H4CK3R4M

Użytkownik
Dołączył
Marzec 24, 2006
Posty
45
Wie ktos moze co to za proces bo nie wiem czy wywalac

O23 - Service: ICF - Unknown owner - C:WINDOWSSystem32svchost.exe:exe.exe
 

0wn3r

Były Moderator
Dołączył
Marzec 10, 2007
Posty
1330
Lupek, usuń to :

C:DOCUME~1SYNUSIEUSTAWI~1Temp63exhmrgml2_2.exe

C:DOCUME~1SYNUSIEUSTAWI~1Temp60exgmsimpst0.exe

C:WINDOWSsystem32cscript.exe - nie wiem co to jest

Sprawdź to :

O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
Kind

i jeszcze to :

O4 - HKCU..Run: [z-WrDialer] C:program FilesDialNetWrDialer.exe

@UP :

zainstaluj program Starter, zobacz do Processe's i spróbuj kliknąć na ten proces i dać Terminate i potem to usunąć.
 

lopesz

Użytkownik
Dołączył
Październik 7, 2007
Posty
16
kurde niby czysty log ale mam wirusy. Tam mam 2 wirusy kturch nie moge usunonc
Kod:
Logfile of HijackThis v1.99.1

Scan saved at 18:46:57, on 2007-10-27

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.5730.0011)



Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSSYSTEM32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32savedump.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesTGTSoftStyleXPStyleXPService.exe

C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

C:Program FilesAlwil SoftwareAvast4ashServ.exe

C:WINDOWSsystem32spoolsv.exe

C:Program FilesCyberLinkShared FilesRichVideo.exe

C:WINDOWSsystem32svchost.exe

C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe

C:Program FilesAlwil SoftwareAvast4ashWebSv.exe

C:WINDOWSExplorer.EXE

C:WINDOWSsystem32wscntfy.exe

C:WINDOWSsystem32RunDll32.exe

C:PROGRA~1NEOSTR~1CnxMon.exe

C:Program FilesThomsonSpeedTouch USBDragdiag.exe

C:PROGRA~1NEOSTR~1TaskbarIcon.exe

C:Program FilesDAEMON Toolsdaemon.exe

C:Program FilesJavajre1.5.0_10binjusched.exe

C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe

C:Program FilesCyberLinkPowerDVDPDVDServ.exe

C:PROGRA~1ALWILS~1Avast4ashDisp.exe

C:WINDOWSsystem32ctfmon.exe

C:Program FilesSkypePhoneSkype.exe

C:Program FilesNokiaPC Suite for Nokia N-Gageconnmngmntbox.exe

C:Program FilesNokiaPC Suite for Nokia N-Gageectaskscheduler.exe

C:PROGRA~1NokiaPCSUIT~1Elogerr.exe

C:WINDOWSsystem32wuauclt.exe

C:WINDOWSPacksCrystal XPYzToolbarYzToolbar.exe

C:PROGRA~1NokiaPCSUIT~1BROADC~1.EXE

C:PROGRA~1IntuwaveSharedMROUTE~1MROUTE~2.EXE

C:PROGRA~1NokiaPCSUIT~1SCRFS.exe

C:Program FilesSkypePlugin ManagerskypePM.exe

C:Program FilesAlwil SoftwareAvast4setupavast.setup

C:Documents and SettingsSkubiPulpithijackthisHijackThis.exe



R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = [url]http://go.microsoft.com/fwlink/?LinkId=69157[/url]

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = [url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = [url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]

R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = [url]http://go.microsoft.com/fwlink/?LinkId=69157[/url]

R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = 

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Neostrada TP

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:PROGRA~1NEOSTR~1SEARCH~1.DLL

R3 - URLSearchHook: Online_TV - {40d1c3a7-4ffb-4443-b3a0-a64b2df7fc3b} - C:Program FilesOnline_TVtbOnl1.dll

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll

R3 - URLSearchHook: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - (no file)

R3 - URLSearchHook: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:Program FilesMulti_MediatbMult.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:PROGRA~1SkypePhoneIEPluginSKYPEI~1.DLL

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:Program FilesBitComettoolsBitCometBHO_1.1.5.19.dll

O2 - BHO: Online_TV - {40d1c3a7-4ffb-4443-b3a0-a64b2df7fc3b} - C:Program FilesOnline_TVtbOnl1.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:PROGRA~1MICROS~2Office12GRA8E1~1.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_10binssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:program filesgooglegoogletoolbar2.dll

O2 - BHO: Camfrog Toolbar - {AF2A1C5A-1AED-4E92-8BA8-D708EB79537E} - C:Program FilesCamfrogCamfrogBarCamfrogBar.dll

O2 - BHO: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:Program FilesMulti_MediatbMult.dll

O2 - BHO: CoTGT_BHO Class - {C333CF63-767F-4831-94AC-E683D962C63C} - C:Program FilesTGTSoftStyleXPTGT_BHO.dll

O3 - Toolbar: Camfrog Toolbar - {AF2A1C5A-1AED-4E92-8BA8-D708EB79537E} - C:Program FilesCamfrogCamfrogBarCamfrogBar.dll

O3 - Toolbar: Online_TV - {40d1c3a7-4ffb-4443-b3a0-a64b2df7fc3b} - C:Program FilesOnline_TVtbOnl1.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program filesgooglegoogletoolbar2.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll

O3 - Toolbar: Multi Media Toolbar - {b5146c40-189a-4311-bda9-fbae3e023187} - C:Program FilesMulti_MediatbMult.dll

O4 - HKLM..Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM..Run: [WooCnxMon] C:PROGRA~1NEOSTR~1CnxMon.exe

O4 - HKLM..Run: [SpeedTouch USB Diagnostics] "C:Program FilesThomsonSpeedTouch USBDragdiag.exe" /icon

O4 - HKLM..Run: [WOOWATCH] C:PROGRA~1NEOSTR~1Watch.exe

O4 - HKLM..Run: [WOOTASKBARICON] C:PROGRA~1NEOSTR~1TaskbarIcon.exe

O4 - HKLM..Run: [ATIModeChange] Ati2mdxx.exe

O4 - HKLM..Run: [DAEMON Tools] "C:Program FilesDAEMON Toolsdaemon.exe" -lang 1033

O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.5.0_10binjusched.exe"

O4 - HKLM..Run: [GrooveMonitor] "C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe"

O4 - HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe

O4 - HKLM..Run: [stool] "c:program filesst32.exe"

O4 - HKLM..Run: [RemoteControl] "C:Program FilesCyberLinkPowerDVDPDVDServ.exe"

O4 - HKLM..Run: [LanguageShortcut] "C:Program FilesCyberLinkPowerDVDLanguageLanguage.exe"

O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime

O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe

O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k

O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe

O4 - HKCU..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /nosplash /minimized

O4 - HKCU..Run: [Gadu-Gadu] "F:Gadu-GaduPowerGG.exe"

O4 - HKCU..Run: [STYLEXP] C:Program FilesTGTSoftStyleXPStyleXP.exe -Hide

O4 - HKCU..Run: [BeFaster] C:Program FilesBeFasterbefaster3.exe

O4 - Startup: Adobe Gamma.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe

O4 - Startup: Y'z Toolbar.lnk = ?

O4 - Global Startup: PCSuiteForNokiaN-Gage Detect.lnk = ?

O4 - Global Startup: PCSuiteForNokiaN-Gage TS.lnk = ?

O4 - Global Startup: TVR Scheduler.lnk = ?

O8 - Extra context menu item: Download all links using BitComet - res://C:Program FilesBitCometBitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Download all videos using BitComet - res://C:Program FilesBitCometBitComet.exe/AddVideo.htm

O8 - Extra context menu item: Download link using &BitComet - res://C:Program FilesBitCometBitComet.exe/AddLink.htm

O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:PROGRA~1MICROS~2Office12EXCEL.EXE/3000

O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll

O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~2Office12ONBttnIE.dll

O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~2Office12ONBttnIE.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:PROGRA~1SkypePhoneIEPluginSKYPEI~1.DLL

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2Office12REFIEBAR.DLL

O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:Program FilesShoppingReportBin2.0.24ShoppingReport.dll (file missing)

O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:Program FilesShoppingReportBin2.0.24ShoppingReport.dll (file missing)

O11 - Options group: [INTERNATIONAL] International*

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - [url]http://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab[/url]

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - [url]http://go.microsoft.com/fwlink/?linkid=39204[/url]

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:Program FilesYahoo!Commonyinsthelper.dll

O17 - HKLMSystemCCSServicesTcpip..{635DB035-7D21-45EE-BC2C-8CB3143620D4}: NameServer = 194.204.159.1 217.98.63.164

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:PROGRA~1MICROS~2Office12GR99D3~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:Program FilesCommon FilesMicrosoft SharedHelphxds.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:PROGRA~1COMMON~1MICROS~1OFFICE12MSOXMLMF.DLL

O23 - Service: Adobe LM Service - Adobe Systems - C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe

O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:Program FilesAreschatServer.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

O23 - Service: Ati HotKey Poller - Unknown owner - C:WINDOWSsystem32Ati2evxx.exe (file missing)

O23 - Service: avast! Antivirus - ALWIL Software - C:Program FilesAlwil SoftwareAvast4ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashWebSv.exe" /service (file missing)

O23 - Service: Google Updater Service (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver11Intel 32IDriverT.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:Program FilesCyberLinkShared FilesRichVideo.exe

O23 - Service: StyleXPService - Unknown owner - C:Program FilesTGTSoftStyleXPStyleXPService.exe
 

mobi11

Użytkownik
Dołączył
Sierpień 28, 2006
Posty
78
rzuccie okiem na mój:

Logfile of HijackThis v1.99.1
Scan saved at 19:02:45, on 2007-10-27
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:program FilesNVIDIA CorporationNetworkAccessManagerApache GroupApache2binapache.exe
C:WINDOWSsystem32HDDSvc.exe
C:program FilesNeroNero8Nero BackItUpNBService.exe
C:program FilesNVIDIA CorporationNetworkAccessManagerApache GroupApache2binapache.exe
C:program FilesEsetnod32krn.exe
C:program FilesNVIDIA CorporationNetworkAccessManagerbinnSvcIp.exe
C:program FilesNVIDIA CorporationNetworkAccessManagerbinnSvcLog.exe
C:WINDOWSsystem32nvsvc32.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSOUNDMAN.EXE
C:WINDOWSsystem32ctfmon.exe
C:program FilesGadu-Gadugg.exe
C:program Filesfoobar2000foobar2000.exe
C:program FilesMozilla Firefoxfirefox.exe
D:SetupHijackHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.toggle.com/index.php?rvs=hompag
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:program FilesJavajre1.6.0_01binssv.dll
O4 - HKLM..Run: [Zone Labs Client] "C:program FilesZone LabsZoneAlarmzlclient.exe"
O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM..Run: [nTrayFw] C:program FilesNVIDIA CorporationNetworkAccessManagerbinnTrayFw.exe
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nod32kui] "C:program FilesEsetnod32kui.exe" /WAITSERVICE
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [Gadu-Gadu] "C:program FilesGadu-Gadugg.exe" /tray
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.6.0_01binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:program FilesJavajre1.6.0_01binssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:program FilesMessengermsmsgs.exe
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:pROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:program FilesNVIDIA CorporationNetworkAccessManagerApache GroupApache2binapache.exe" -k runservice (file missing)
O23 - Service: HDD Information Service (HDDSvc) - AltrixSoft (http://www.altrixsoft.com/) - C:WINDOWSsystem32HDDSvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:program FilesNeroNero8Nero BackItUpNBService.exe
O23 - Service: NMIndexingService - Nero AG - C:program FilesCommon FilesNeroLibNMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:program FilesEsetnod32krn.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:program FilesNVIDIA CorporationNetworkAccessManagerbinnSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:program FilesNVIDIA CorporationNetworkAccessManagerbinnSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:WINDOWSsystem32ZoneLabsvsmon.exe
 

lopesz

Użytkownik
Dołączył
Październik 7, 2007
Posty
16

0wn3r

Były Moderator
Dołączył
Marzec 10, 2007
Posty
1330
lopesz, nie wiem co to jest :

O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:program FilesShoppingReportBin2.0.24ShoppingReport.dll (file missing)

O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:program FilesShoppingReportBin2.0.24ShoppingReport.dll (file missing)

a tak pozatym to log czysty.
 
Status
Zamknięty.
Do góry Bottom