LOG Prosze o pomoc

Cześć. pomóżcie bo niemam już siły do tego komputera

Logfile of HijackThis v1.99.1

Scan saved at 20:41:59, on 2005-10-28

Platform: Windows XP (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 (6.00.2600.0000)


Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Sygate\SPF\smc.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Gizmo Project\mDNSResponder.exe

C:\Program Files\Eset\nod32krn.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\spool.exe

C:\WINDOWS\System32\slsys.exe

C:\PROGRA~1\APLIKA~1\DAP\DAP.EXE

C:\PROGRA~1\Wanadoo\TaskbarIcon.exe

C:\WINDOWS\System32\svcnet.exe

C:\Program Files\winupdates\winupdates.exe

C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe

C:\WINDOWS\System32\paytime.exe

C:\WINDOWS\System32\leeman.exe

C:\WINDOWS\sachostx.exe

C:\WINDOWS\System32\Installteleponeoncmp.exe

C:\winstall.exe

C:\WINDOWS\System32\paytime.exe

C:\WINDOWS\tool2.exe

C:\WINDOWS\tool2.exe

C:\Program Files\Wanadoo\EspaceWanadoo.exe

C:\Program Files\Wanadoo\ComComp.exe

C:\Program Files\Wanadoo\Watch.exe

C:\Program Files\Gadu-Gadu\gg.exe

C:\WINDOWS\System32\sachostc.exe

C:\WINDOWS\System32\sachostb.exe

C:\WINDOWS\System32\sachosts.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\WINDOWS\system32\m?dtc.exe

C:\Documents and Settings\Kubacka.KUBACKA-LFNFU77\Pulpit\HijackThis.exe


R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=135849

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.couldnotfind.com/search_page.html?&account_id=135849

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=135849

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.neostrada.pl

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada Plus wita Cie w Internecie

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza

R3 - URLSearchHook: (no name) - {CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - (no file)

O1 - Hosts: 127.0.0.4 n-glx.s-redirect.com

O1 - Hosts: 127.0.0.4 x.full-tgp.net

O1 - Hosts: 127.0.0.4 counter.sexmaniack.com

O1 - Hosts: 127.0.0.4 autoescrowpay.com

O1 - Hosts: 127.0.0.4 www.autoescrowpay.com

O1 - Hosts: 127.0.0.4 www.awmdabest.com

O1 - Hosts: 127.0.0.4 www.sexfiles.nu

O1 - Hosts: 127.0.0.4 awmdabest.com

O1 - Hosts: 127.0.0.4 sexfiles.nu

O1 - Hosts: 127.0.0.4 allforadult.com

O1 - Hosts: 127.0.0.4 www.allforadult.com

O1 - Hosts: 127.0.0.4 www.iframe.biz

O1 - Hosts: 127.0.0.4 iframe.biz

O1 - Hosts: 127.0.0.4 www.newiframe.biz

O1 - Hosts: 127.0.0.4 newiframe.biz

O1 - Hosts: 127.0.0.4 www.vesbiz.biz

O1 - Hosts: 127.0.0.4 vesbiz.biz

O1 - Hosts: 127.0.0.4 www.pizdato.biz

O1 - Hosts: 127.0.0.4 pizdato.biz

O1 - Hosts: 127.0.0.4 www.aaasexypics.com

O1 - Hosts: 127.0.0.4 aaasexypics.com

O1 - Hosts: 127.0.0.4 www.virgin-tgp.net

O1 - Hosts: 127.0.0.4 virgin-tgp.net

O1 - Hosts: 127.0.0.4 www.awmcash.biz

O1 - Hosts: 127.0.0.4 awmcash.biz

O1 - Hosts: 127.0.0.4 buldog-stats.com

O1 - Hosts: 127.0.0.4 www.buldog-stats.com

O1 - Hosts: 127.0.0.4 fregat.drocherway.com

O1 - Hosts: 127.0.0.4 slutmania.biz

O1 - Hosts: 127.0.0.4 www.slutmania.biz

O1 - Hosts: 127.0.0.4 toolbarpartner.com

O1 - Hosts: 127.0.0.4 www.toolbarpartner.com

O1 - Hosts: 127.0.0.4 www.megapornix.com

O1 - Hosts: 127.0.0.4 megapornix.com

O1 - Hosts: 127.0.0.4 www.sp2fucked.biz

O1 - Hosts: 127.0.0.4 sp2fucked.biz

O1 - Hosts: 127.0.0.4 greg-tut.com

O1 - Hosts: 127.0.0.4 www.greg-tut.com

O1 - Hosts: 127.0.0.4 nylonsexy.com

O1 - Hosts: 127.0.0.4 www.nylonsexy.com

O1 - Hosts: 127.0.0.4 vparivalka.com

O1 - Hosts: 127.0.0.4 www.vparivalka.com

O1 - Hosts: 127.0.0.4 iframeprofit.com

O1 - Hosts: 127.0.0.4 www.iframeprofit.com

O1 - Hosts: 127.0.0.4 topsearch10.com

O1 - Hosts: 127.0.0.4 www.topsearch10.com

O1 - Hosts: 127.0.0.4 statscash.biz

O1 - Hosts: 127.0.0.4 www.statscash.biz

O1 - Hosts: 127.0.0.4 vxiframe.biz

O1 - Hosts: 127.0.0.4 www.vxiframe.biz

O1 - Hosts: 127.0.0.4 crazy-toolbar.com

O1 - Hosts: 127.0.0.4 www.crazy-toolbar.com

O1 - Hosts: 127.0.0.4 topcash.biz

O1 - Hosts: 127.0.0.4 www.topcash.biz

O1 - Hosts: 127.0.0.4 loadcash.biz

O1 - Hosts: 127.0.0.4 www.loadcash.biz

O1 - Hosts: 127.0.0.4 txiframe.biz

O1 - Hosts: 127.0.0.4 www.txiframe.biz

O1 - Hosts: 127.0.0.4 procounter.biz

O1 - Hosts: 127.0.0.4 www.procounter.biz

O1 - Hosts: 127.0.0.4 advadmin.biz

O1 - Hosts: 127.0.0.4 www.advadmin.biz

O1 - Hosts: 127.0.0.4 trafficbest.net

O1 - Hosts: 127.0.0.4 www.trafficbest.net

O1 - Hosts: 127.0.0.4 besthvac.com

O1 - Hosts: 127.0.0.4 www.besthvac.com

O1 - Hosts: 127.0.0.4 traff4.com

O1 - Hosts: 127.0.0.4 www.traff4.com

O1 - Hosts: 127.0.0.4 ambush-script.com

O1 - Hosts: 127.0.0.4 www.ambush-script.com

O1 - Hosts: 127.0.0.4 beehappyy.biz

O1 - Hosts: 127.0.0.4 www.beehappyy.biz

O1 - Hosts: 127.0.0.4 tracktraff.cc

O1 - Hosts: 127.0.0.4 www.tracktraff.cc

O1 - Hosts: 127.0.0.4 allcount.net

O1 - Hosts: 127.0.0.4 www.allcount.net

O1 - Hosts: 127.0.0.4 onedayoffer.biz

O1 - Hosts: 127.0.0.4 www.onedayoffer.biz

O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\Program Files\Aplikacje\DAP\DAPBHO.dll

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\aplikacje\sterowniki od scana\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll

O2 - BHO: (no name) - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - (no file)

O2 - BHO: (no name) - {8EBBEC5E-1888-0E00-9D29-7F2C72D90FFE} - C:\WINDOWS\System32\kwzwn.dll

O2 - BHO: (no name) - {BB96DC5E-35BB-3B34-B019-4F0142E922CE} - C:\WINDOWS\System32\kwzwn.dll

O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)

O2 - BHO: (no name) - {BE96DE5E-35B8-4D34-B01D-3901469F22CB} - C:\WINDOWS\System32\kwzwn.dll

O2 - BHO: (no name) - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - (no file)

O2 - BHO: (no name) - {F1D961AD-C424-83F0-3F86-F5F41FBC77A0} - (no file)

O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\Program Files\Aplikacje\DAP\DAPIEBar.dll

O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)

O3 - Toolbar: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [Microsoft Update Machine] explorer.exe

O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\APLIKA~1\\DAP\DAP.EXE /STARTUP

O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe

O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe

O4 - HKLM\..\RunServices: [Microsoft Update Machine] explorer.exe

O4 - HKLM\..\RunServices: [CMD] cmd32.exe

O4 - HKLM\..\RunServices: [SystemSAS] system32.exe

O4 - HKLM\..\RunServices: [IDE] C:\WINDOWS\System32\IDE\ide.exe

O4 - HKLM\..\RunServices: [p2pnetwork] p2pnetwork.exe

O4 - HKLM\..\RunServices: [microsft Updates] msupdate32.exe

O4 - HKLM\..\RunServices: [Windows Update 32] slsys.exe

O4 - HKLM\..\RunServices: [leeman] C:\WINDOWS\System32\leeman.exe

O4 - HKLM\..\RunOnce: [Windows Update 32] slsys.exe

O4 - HKCU\..\RunServices: [Start Uppings] mssupdate.exe

O4 - HKCU\..\RunServices: [] iexpl0res.exe

O4 - HKCU\..\RunServices: [p2pnetwork] p2pnetwork.exe

O4 - HKCU\..\RunOnce: [Windows Update 32] slsys.exe

O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\APLIKA~1\\DAP\dapextie.htm

O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\APLIKA~1\\DAP\dapextie2.htm

O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll

O9 - Extra button: Wyslij SMS'a - {215940F1-E7E0-4801-BEE3-44D045534106} - C:\Program Files\Common Files\moje.js

O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\APLIKA~1\\DAP\DAP.EXE

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O15 - Trusted Zone: *.blazefind.com

O15 - Trusted Zone: *.clickspring.net

O15 - Trusted Zone: *.flingstone.com

O15 - Trusted Zone: *.iframedollars.biz

O15 - Trusted Zone: *.mt-download.com

O15 - Trusted Zone: *.my-internet.info

O15 - Trusted Zone: *.searchbarcash.com

O15 - Trusted Zone: *.searchmiracle.com

O15 - Trusted Zone: *.skoobidoo.com

O15 - Trusted Zone: *.slotch.com

O15 - Trusted Zone: *.slotchbar.com

O15 - Trusted Zone: *.windupdates.com

O15 - Trusted Zone: *.xxxtoolbar.com

O15 - Trusted Zone: *.ysbweb.com

O15 - Trusted Zone: *.blazefind.com (HKLM)

O15 - Trusted Zone: *.clickspring.net (HKLM)

O15 - Trusted Zone: *.flingstone.com (HKLM)

O15 - Trusted Zone: *.iframedollars.biz (HKLM)

O15 - Trusted Zone: *.mt-download.com (HKLM)

O15 - Trusted Zone: *.my-internet.info (HKLM)

O15 - Trusted Zone: *.searchbarcash.com (HKLM)

O15 - Trusted Zone: *.searchmiracle.com (HKLM)

O15 - Trusted Zone: *.skoobidoo.com (HKLM)

O15 - Trusted Zone: *.slotch.com (HKLM)

O15 - Trusted Zone: *.slotchbar.com (HKLM)

O15 - Trusted Zone: *.windupdates.com (HKLM)

O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)

O15 - Trusted Zone: *.ysbweb.com (HKLM)

O15 - Trusted IP range: 213.159.117.202

O15 - Trusted IP range: 213.159.117.202 (HKLM)

O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!http://iframedollars.biz/dl/adv481/x.chm::/load.exe

O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - ms-its:mhtml:file://c:\adsuntdt.mht!http://adextension.com/ext2/lca.chm::/Bridge-c139.cab

O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - ms-its:mhtml:file://c:\adsuntdt.mht!http://adextension.com/ext2/lca.chm::/bridge-c46.cab

O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab

O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab

O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab

O16 - DPF: {33331111-1111-1111-1111-622221193458} - file://c:\ex.cab

O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} - http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_regular.cab

O16 - DPF: {64311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab

O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} - http://static.topconverting.com/activex/loader2.ocx

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - ms-its:mhtml:file://c:\adsuntdt.mht!http://adextension.com/ext2/mta.chm::/MediaTicketsInstaller.cab

O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) - http://skaner.mks.com.pl/SkanerOnline.cab

O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) - http://67.15.101.3/g_bin/pl/billard8_2_0_0_22.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{A0F7FB07-1D4A-4439-89B9-E9248D158206}: NameServer = 157.25.5.3

O17 - HKLM\System\CCS\Services\Tcpip\..\{A65A8D9E-F448-41B2-8BA8-06ED0205BA9F}: NameServer = 194.204.152.34 217.98.63.164

O21 - SSODL: Web Event Logger - {79FEACFF-FFCE-815E-A900-316290B5B738} - (no file)

O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2.dll

O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Gizmo Project\mDNSResponder.exe

O23 - Service: ISEXEng - Unknown owner - C:\WINDOWS\System32\angelex.exe (file missing)

O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Program Files\Eset\nod32krn.exe

O23 - Service: SAVScan - Unknown owner - D:\Programy\partitoin magic\works2004\Norton Antivirus\SAVScan.exe (file missing)

O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

O23 - Service: Windows Spooler (winspool32) - Unknown owner - C:\WINDOWS\spool.exe

====================================

Uwaga: Jak wklejasz loga to obejmuj go znacznikiem (tagiem) CODE lub QUOTE

Proponuje poczytać TEN temat i zobacz jaka jest prośba do userów wklejających loga.

Pozdrawiam kuz5

masz tyle syfu że chyba takiego jeszcze loga nigdy nie widziałem :shock: :shock:

Przeskanuj dysk tym i wywal wszystko:

Panda

Kaspersky

mks_vir

CWShredder 2.15

SpyBot - Search & Destroy v1.4 PL

Ad-aware SE Personal 1.06

PestPatrol

potem wrzuc log z HijackThis 8)

a wiesz czemu masz tyle tego ? Bo brak SP2 :!:

Polemizowałbym. Wystarczy sp1 i nieco rozsądku, bo widzicie, z wirusami jest jak z chorobą weneryczną. Wiemy wszyscy skąd się bierze ale nikt nie mówi o tym głośno.

hehe - polukaj sobie na logi. Największy syf wchodzi do sysa jak ktoś ma gołego XP lub tylko SP1. SP2 to dobra rzecz + oczywiście AV i dobry firewall 8)

Widziałem logi. Trudno przegapić.

Ja sam mam “zaledwie” sp1 bo zwyczajnie “dobrodziejstwa” sp2 do mnie nie przemówiły. A jak już zasugerowałem, gdy nie patrzysz na co klikasz to i wypasiony sp2 wespół ze sztabem antyświrusów nie pomogą.