Oglądasz wypowiedzi wyszukane dla słów: Power Project
Temat: *.exe co nie chce się usubąć.
Witam ponownie. Szukałem drct16.dll w Windows/system32 i nie znalazłem, ale za
to avastem wyrzuciłem kilka trojanów. Jestem bardzo bardzo wdzięczny za twoją
wielką pomoc. Widzę, że pomagasz tu wielu osobom, gdybym był blokersem czy
innym hiphopowcem powiedziałbym respect dla ciebie :). Wybawiłeś mnie z
kłopotów i od gniewu mojej kobiety ;))
A teraz to wygląda tak:
Logfile of HijackThis v1.99.1
Scan saved at 09:51:26, on 2005-04-21
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSSYSTEM32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32LEXBCES.EXE
C:WINDOWSsystem32LEXPPS.EXE
C:WINDOWSsystem32spoolsv.exe
C:PROGRA~1ALWILS~1Avast4ashDisp.exe
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
C:Program FilesAlwil SoftwareAvast4ashServ.exe
C:Program FilesKerioPersonal Firewall 4kpf4ss.exe
C:Program FilesCommon FilesMicrosoft SharedVS7Debugmdm.exe
C:WINDOWSSystem32
vsvc32.exe
C:Program FilesKerioPersonal Firewall 4kpf4gui.exe
C:Program FilesAlwil SoftwareAvast4ashWebSv.exe
C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe
C:Program FilesKerioPersonal Firewall 4kpf4gui.exe
C:WINDOWSSystem32wuauclt.exe
C:Documents and SettingsxPulpitHijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar =
res://C:DOCUME~1xUSTAWI~1Tempse.dll/spage.html
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
www.onet.pl/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar =
res://C:DOCUME~1xUSTAWI~1Tempse.dll/spage.html
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:Program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:WINDOWSSystem32msdxm.ocx
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32
NvCpl.dll,NvStartup
O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe
O4 - HKCU..Run: [Komunikator] C:Program FilesTlen.pl len.exe
O4 - Startup:
Power Project.lnk = C:Program FilesGadu-GaduPowerGG.exe
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft
OfficeOffice10OSA.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:Program FilesMessengerMSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:Program FilesMessengerMSMSGS.EXE
O12 - Plugin for .pdf: C:Program FilesInternet ExplorerPLUGINS
ppdf32.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
software-dl.real.com/06f89839c68b5326f406/netzip/RdxIE601.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility
Class) -
security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
skaner.mks.com.pl/SkanerOnline.cab
O17 - HKLMSystemCCSServicesTcpip..{3955CAD2-E82B-4F2E-A7DC-94A8D0D9FCC3}:
NameServer = 194.204.152.34,194.204.159.1
O17 - HKLMSystemCS1ServicesTcpip..{3955CAD2-E82B-4F2E-A7DC-94A8D0D9FCC3}:
NameServer = 194.204.152.34,194.204.159.1
O17 - HKLMSystemCS2ServicesTcpip..{3955CAD2-E82B-4F2E-A7DC-94A8D0D9FCC3}:
NameServer = 194.204.152.34,194.204.159.1
O17 - HKLMSystemCS3ServicesTcpip..{3955CAD2-E82B-4F2E-A7DC-94A8D0D9FCC3}:
NameServer = 194.204.152.34,194.204.159.1
O18 - Filter: text/html - {D01559F4-6D59-42F6-8B79-1D9D4824AED6} -
C:WINDOWSSystem32ohnn.dll
O18 - Filter: text/plain - {D01559F4-6D59-42F6-8B79-1D9D4824AED6} -
C:WINDOWSSystem32ohnn.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner -
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:Program FilesAlwil
SoftwareAvast4ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:Program FilesAlwil
SoftwareAvast4ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:Program FilesAlwil
SoftwareAvast4ashWebSv.exe" /service (file missing)
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies -
C:Program FilesKerioPersonal Firewall 4kpf4ss.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. -
C:WINDOWSsystem32LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
C:WINDOWSSystem32
vsvc32.exe
Przeglądaj resztę wypowiedzi z tematu
Temat: download.trojan jak usunąć? help!
oto nowy log (juz po usunieciu "zbednych plikow").
proszę, podajcie co jeszcze jest nie tak...
w dalszym ciagu Norton nie moze usunąc tego "download.trojan"
wyswietlaja mi sie tez co trochę jakies strony z reklamami, wyszukiwarkami
itp...
co zrobic z plikami w folderze hijackthisackups ? maja sobie tam zostac?
czy moge oprocz nortona antywirusa 2005 zastosowac jakiegos firewall'a?
(jesli tak to jakiego byscie mi polecali)
Logfile of HijackThis v1.99.1
Scan saved at 23:14:06, on 2005-03-28
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe
C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exe
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesHewlett-PackardHP Software UpdateHPWuSchd.exe
C:WINDOWSSystem32spooldriversw32x863hpztsb08.exe
C:Program FilesWinampwinampa.exe
C:WINDOWSSystem32RUNDLL32.EXE
C:Program FilesKazaa Litekazaalite.kpp
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:Program FilesMessengermsmsgs.exe
C:PROGRA~1GADU-G~12gg.exe
D:programy
orton antywirus
avapsvc.exe
D:programy
orton antywirusIWPNPFMntor.exe
C:WINDOWSSystem32
vsvc32.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe
C:WINDOWSSystem32wuauclt.exe
C:WINDOWSexplorer.exe
C:Program FilesInternet ExplorerIEXPLORE.EXE
E:KAPEChijackthisHijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
www.o2.pl/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar =
res://C:DOCUME~1PAWE~1USTAWI~1Tempse.dll/spage.html
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
D:programySPYBOT~1SDHelper.dll
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} -
C:WINDOWSisrvssysupd.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} -
D:programy
orton antywirusNavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
D:programy
orton antywirusNavShExt.dll
O4 - HKLM..Run: [NeroCheck] C:WINDOWSSystem32\NeroCheck.exe
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32
NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [HP Software Update] C:Program FilesHewlett-PackardHP
Software UpdateHPWuSchd.exe
O4 - HKLM..Run: [HPDJ Taskbar Utility] C:WINDOWSSystem32
spooldriversw32x863hpztsb08.exe
O4 - HKLM..Run: [100% Clock] D:programyAlfaClockAlfaClock.exe
O4 - HKLM..Run: [KAZAA] "C:Program FilesKazaa Litekpp.exe" "C:Program
FilesKazaa Litekazaalite.kpp" /SYSTRAY
O4 - HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe
O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32
NvMcTray.dll,NvTaskbarInit
O4 - HKLM..Run: [Desktop Search] C:WINDOWSisrvsdesktop.exe
O4 - HKLM..Run: [ffis] C:WINDOWSisrvsffisearch.exe
O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec
SharedccApp.exe"
O4 - HKLM..Run: [SSC_UserPrompt] C:Program FilesCommon FilesSymantec
SharedSecurity CenterUsrPrmpt.exe
O4 - HKLM..Run: [Symantec NetDriver Monitor] C:PROGRA~1SYMNET~1SNDMon.exe
O4 - HKLM..Run: [etbrun] C:windowssystem32eliteupt32.exe
O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 - HKCU..Run: [Skype] "D:programyPhone
SkypeSkype.exe" /nosplash /minimized
O4 - HKCU..Run: [Gadu-Gadu] "C:PROGRA~1GADU-G~12gg.exe" /tray
O4 - Startup:
Power Project.lnk = C:Program FilesGadu-GaduPowerGG.exe
O8 - Extra context menu item: &Google Search - res://c:program
filesgoogleGoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:program
filesgoogleGoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:program
filesgoogleGoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:program
filesgoogleGoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:program
filesgoogleGoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
skaner.mks.com.pl/SkanerOnline.cab
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} -
C:WINDOWSisrvsmfiltis.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation -
C:Program FilesCommon FilesSymantec SharedccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -
C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec
Corporation - D:programy
orton antywirus
avapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec
Corporation - D:programy
orton antywirusIWPNPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
C:WINDOWSSystem32
vsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - D:programy
orton
antywirusSAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -
C:PROGRA~1COMMON~1SYMANT~1SCRIPT~1SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec
Corporation - C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:Program
FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:Program
FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe
Przeglądaj resztę wypowiedzi z tematu
Temat: download.trojan jak usunąć? help!
oto nowy log:
Logfile of HijackThis v1.99.1
Scan saved at 14:24:23, on 2005-04-06
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe
C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exe
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:Program FilesHewlett-PackardHP Software UpdateHPWuSchd.exe
C:WINDOWSSystem32spooldriversw32x863hpztsb08.exe
C:Program FilesWinampwinampa.exe
C:WINDOWSSystem32RUNDLL32.EXE
C:Program FilesKazaa Litekazaalite.kpp
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:Program FilesMessengermsmsgs.exe
C:PROGRA~1GADU-G~12gg.exe
D:programy
orton antywirus
avapsvc.exe
D:programy
orton antywirusIWPNPFMntor.exe
C:WINDOWSSystem32
vsvc32.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe
C:WINDOWSSystem32wuauclt.exe
C:WINDOWSSystem32wuauclt.exe
E:KAPEChijackthisHijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
www.o2.pl/
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
D:programySPYBOT~1SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} -
D:programy
orton antywirusNavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
D:programy
orton antywirusNavShExt.dll
O4 - HKLM..Run: [NeroCheck] C:WINDOWSSystem32\NeroCheck.exe
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32
NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [HP Software Update] C:Program FilesHewlett-PackardHP
Software UpdateHPWuSchd.exe
O4 - HKLM..Run: [HPDJ Taskbar Utility] C:WINDOWSSystem32
spooldriversw32x863hpztsb08.exe
O4 - HKLM..Run: [100% Clock] D:programyAlfaClockAlfaClock.exe
O4 - HKLM..Run: [KAZAA] "C:Program FilesKazaa Litekpp.exe" "C:Program
FilesKazaa Litekazaalite.kpp" /SYSTRAY
O4 - HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe
O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32
NvMcTray.dll,NvTaskbarInit
O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec
SharedccApp.exe"
O4 - HKLM..Run: [SSC_UserPrompt] C:Program FilesCommon FilesSymantec
SharedSecurity CenterUsrPrmpt.exe
O4 - HKLM..Run: [Symantec NetDriver Monitor] C:PROGRA~1SYMNET~1SNDMon.exe
O4 - HKLM..Run: [etbrun] C:windowssystem32eliteupt32.exe
O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 - HKCU..Run: [Skype] "D:programyPhone
SkypeSkype.exe" /nosplash /minimized
O4 - HKCU..Run: [Gadu-Gadu] "C:PROGRA~1GADU-G~12gg.exe" /tray
O4 - Startup:
Power Project.lnk = C:Program FilesGadu-GaduPowerGG.exe
O8 - Extra context menu item: &Google Search - res://c:program
filesgoogleGoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:program
filesgoogleGoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:program
filesgoogleGoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:program
filesgoogleGoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:program
filesgoogleGoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
skaner.mks.com.pl/SkanerOnline.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation -
C:Program FilesCommon FilesSymantec SharedccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -
C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec
Corporation - D:programy
orton antywirus
avapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec
Corporation - D:programy
orton antywirusIWPNPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
C:WINDOWSSystem32
vsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - D:programy
orton
antywirusSAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -
C:PROGRA~1COMMON~1SYMANT~1SCRIPT~1SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec
Corporation - C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:Program
FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:Program
FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe
i jak to wygląda?
Przeglądaj resztę wypowiedzi z tematu
Temat: Proszę o sprawdzenie loga
Proszę o sprawdzenie loga
Biały pulpit, podświetlone ikony
Logfile of HijackThis v1.99.1
Scan saved at 18:38:29, on 2005-12-28
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:Program FilesHewlett-PackardHP Share-to-Webhpgs2wnd.exe
C:Program FilesWinampwinampa.exe
C:PROGRA~1ALWILS~1Avast4ashDisp.exe
C:WINDOWSSystem32ctfmon.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesSkypePhoneSkype.exe
C:Program FilesGadu-Gadugg.exe
C:Program FilesHewlett-PackardDigital Imaginginhpobnz08.exe
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
C:Program FilesAlwil SoftwareAvast4ashServ.exe
C:Program FilesCommon FilesMicrosoft SharedVS7Debugmdm.exe
C:Program FilesHewlett-PackardHP Share-to-Webhpgs2wnf.exe
C:Program FilesEset
od32krn.exe
C:Program FilesHewlett-PackardDigital Imaginginhpoevm08.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32slserv.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesAlwil SoftwareAvast4ashWebSv.exe
C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe
C:Program FilesInternet ExplorerIEXPLORE.EXE
C:WINDOWSTemporary Internet FilesContent.IE54P6VODANhijackthis[1].exe
C:WINDOWSTemporary Internet FilesContent.IE54P6VODANhijackthis[2].exe
C:WINDOWSsystem32NOTEPAD.EXE
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
www.interia.pl/
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R3 - URLSearchHook: (no name) - _{57AD7E09-FC3D-9256-A407-A3E33E4DE42A} - (no
file)
F3 - REG:win.ini: run=C:WINDOWSinet20003services.exe
F2 - REG:system.ini: UserInit=C:WINDOWSSystem32userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:Program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {33E36124-7AB2-3669-CE78-E1CCA0741027} -
C:WINDOWSCwakdlci.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:program filesgooglegoogletoolbar2.dll
O2 - BHO: RedirectPage Class - {DC8240DF-E60D-4193-B984-5111847DC7E6} -
C:PROGRA~1WEBLOO~1WEBLOO~1.DLL (file missing)
O3 - Toolbar: Search - {11E00B82-13FA-BBE0-2D5C-C49C079EF26B} -
C:WINDOWSCwakdlci.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program
filesgooglegoogletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:WINDOWSSystem32msdxm.ocx
O4 - HKLM..Run: [internat.exe] internat.exe
O4 - HKLM..Run: [NeroCheck] C:WINDOWSSystem32\NeroCheck.exe
O4 - HKLM..Run: [avserve2.exe] C:WINDOWSavserve2.exe
O4 - HKLM..Run: [lsasss.exe] C:WINDOWSlsasss.exe
O4 - HKLM..Run: [Share-to-Web Namespace Daemon] C:Program FilesHewlett-
PackardHP Share-to-Webhpgs2wnd.exe
O4 - HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe
O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe
O4 - HKLM..Run: [timessquare] C:windows imessquare.exe
O4 - HKLM..Run: [WinHound] C:Program FilesWinHoundWinHound.exe
O4 - HKLM..Run: [UserFaultCheck] %systemroot%system32dumprep 0 -u
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 - HKCU..Run: [Skype] "C:Program
FilesSkypePhoneSkype.exe" /nosplash /minimized
O4 - HKCU..Run: [Komunikator] C:Program FilesTlen.pl len.exe
O4 - HKCU..Run: [Gadu-Gadu] "C:Program FilesGadu-Gadugg.exe" /tray
O4 - Startup:
Power Project.lnk = C:Program FilesGadu-GaduPowerGG.exe
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft
OfficeOffice10OSA.EXE
O4 - Global Startup: hp psc 2000 Series.lnk = C:Program FilesHewlett-
PackardDigital Imaginginhpobnz08.exe
O4 - Global Startup: officejet 6100.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:program
filesgoogleGoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:program
filesgoogleGoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:program
filesgoogleGoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:program
filesgoogleGoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:program
filesgoogleGoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
C:WINDOWSweb
elated.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-
00aa003c157a} - C:WINDOWSweb
elated.htm
O10 - Broken Internet access because of LSP provider 'c:program
files
ewdotnet
ewdotnet6_38.dll' missing
O16 - DPF: Win32 Classes -
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer
Class) -
acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
bezpieczenstwo.onet.pl/skaner/SkanerOnline.cab
O17 - HKLMSystemCCSServicesTcpip..{AD3C4A58-34F3-4460-B7A2-
01E572C2D623}: NameServer = 194.204.152.34,194.204.159.1
O18 - Filter: text/html - {B72F75B8-93F3-429D-B13E-660B206D897A} - (no file)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner -
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:Program FilesAlwil
SoftwareAvast4ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:Program FilesAlwil
SoftwareAvast4ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:Program FilesAlwil
SoftwareAvast4ashWebSv.exe" /service (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:Program
FilesEset
od32krn.exe
O23 - Service: Pml Driver HPZ12 - HP - C:WINDOWSSystem32HPZipm12.exe
O23 - Service: SmartLinkService (SLService) - - C:WINDOWSSYSTEM32
slserv.exe
O23 - Service: Security Logging Messaging (WksPatch) - Unknown owner -
C:WINDOWSSystem32driverssvchost.exe (file missing)
Przeglądaj resztę wypowiedzi z tematu
Temat: Proszę o pomoc. Wpadłem w pułapke.
Proszę o pomoc. Wpadłem w pułapke.
Szukałem napisów do filmu i wszedłem na strone www.napisy.tv/ i zainstalował
mi się jakiś newdialer, który dokucza mi okropnie.
Wygląda to tak:
Logfile of HijackThis v1.99.1
Scan saved at 11:52:01, on 2005-08-07
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32LEXBCES.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32LEXPPS.EXE
C:WINDOWSExplorer.EXE
C:winstall.exe
C:WINDOWS ool2.exe
C:Program FilesCommon FilesRealUpdate_OB
ealsched.exe
C:Program FilesQuickTimeqttask.exe
C:Program FilesMessengerMSMSGS.EXE
C:WINDOWSSystem32paytime.exe
C:WINDOWSSystem32paytime.exe
C:WINDOWSmsmsgrxp.exe
C:Program FilesSpySheriffSpySheriff.exe
C:WINDOWS ool2.exe
C:WINDOWS ool2.exe
C:WINDOWSSystem32 ibs.exe
C:WINDOWSSystem32 ibs.exe
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
C:Program FilesCommon FilesMicrosoft SharedVS7Debugmdm.exe
C:WINDOWSSystem32
vsvc32.exe
C:Documents and SettingsxPulpitHijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
195.95.218.172/index.php
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
195.95.218.172/index.php
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
195.95.218.172/index.php
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
195.95.218.172/index.php
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
195.95.218.172/index.php
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
195.95.218.172/index.php
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:Program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll
O2 - BHO: Loader Class - {2E246FAE-8420-11D9-870D-000C2917DE7F} -
C:WINDOWSSYSTEMLoader.dll
O2 - BHO: (no name) - {72462721-4562-7362-5732-ACAD7254AFFF} -
C:WINDOWSSystem32msvbc.dll
O2 - BHO: (no name) - {78364D99-A640-4ddf-B91A-67EFF8373045} -
C:WINDOWSsystem32appwiz.dll
O2 - BHO: BHOmodObj Class - {7F6828CA-9E42-462C-BC60-418C8144012C} -
c:windowssystemBHOmod.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:WINDOWSSystem32msdxm.ocx
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32
NvCpl.dll,NvStartup
O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe
O4 - HKLM..Run: [TkBellExe] "C:Program FilesCommon
FilesRealUpdate_OB
ealsched.exe" -osboot
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -
atboottime
O4 - HKLM..Run: [SysMemory manager] c:windowssystem32mdms.exe
O4 - HKLM..Run: [PayTime] C:WINDOWSSystem32paytime.exe
O4 - HKLM..Run: [_Cat3] C:WINDOWSmsmsgrxp.exe
O4 - HKCU..Run: [Komunikator] C:Program FilesTlen.pl len.exe
O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengerMSMSGS.EXE" /background
O4 - HKCU..Run: [PayTime] C:WINDOWSSystem32paytime.exe
O4 - HKCU..Run: [Windows installer] C:winstall.exe
O4 - HKCU..Run: [SNInstall] C:WINDOWS ool2.exe
O4 - HKCU..Run: [SpySheriff] C:Program FilesSpySheriffSpySheriff.exe
O4 - Startup:
Power Project.lnk = C:Program FilesGadu-GaduPowerGG.exe
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft
OfficeOffice10OSA.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:Program FilesMessengerMSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:Program FilesMessengerMSMSGS.EXE
O12 - Plugin for .pdf: C:Program FilesInternet ExplorerPLUGINS
ppdf32.dll
O17 - HKLMSystemCCSServicesTcpip..{3955CAD2-E82B-4F2E-A7DC-
94A8D0D9FCC3}: NameServer = 194.204.152.34,194.204.159.1
O17 - HKLMSystemCS1ServicesTcpip..{3955CAD2-E82B-4F2E-A7DC-
94A8D0D9FCC3}: NameServer = 194.204.152.34,194.204.159.1
O17 - HKLMSystemCS2ServicesTcpip..{3955CAD2-E82B-4F2E-A7DC-
94A8D0D9FCC3}: NameServer = 194.204.152.34,194.204.159.1
O17 - HKLMSystemCS3ServicesTcpip..{3955CAD2-E82B-4F2E-A7DC-
94A8D0D9FCC3}: NameServer = 194.204.152.34,194.204.159.1
O20 - Winlogon Notify: drct16 - C:WINDOWSSYSTEM32drct16.dll
O20 - Winlogon Notify: tcpG4T - C:WINDOWSSYSTEM32 cpG4T.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner -
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:Program FilesAlwil
SoftwareAvast4ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:Program FilesAlwil
SoftwareAvast4ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:Program FilesAlwil
SoftwareAvast4ashWebSv.exe" /service (file missing)
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies -
C:Program FilesKerioPersonal Firewall 4kpf4ss.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. -
C:WINDOWSsystem32LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
C:WINDOWSSystem32
vsvc32.exe
Przeglądaj resztę wypowiedzi z tematu
zanotowane.pldoc.pisz.plpdf.pisz.plwitch-world.pev.pl
Strona
3 z
3 • Wyszukano 123 wyników •
1,
2,
3