Problem z svchost.exe i paroma innymi


(Pawel2827) #1

Witam!

Od kilku dni na moim kompie jest proces z svchost.exe nod32 go wykrywa lecz nie moze go usunac co robic? jest jeszcze pare innych dziwnych procesow takich jak:spoolsv.exe czy lsass.exe

Wrzuce tu mojego loga z hijacka moze to cos wam pomoze:

Logfile of HijackThis v1.99.1

Scan saved at 10:47:22, on 2006-12-28

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


Running processes:

G:\WINDOWS\System32\smss.exe

G:\WINDOWS\system32\winlogon.exe

G:\WINDOWS\system32\services.exe

G:\WINDOWS\system32\lsass.exe

G:\WINDOWS\system32\svchost.exe

G:\WINDOWS\System32\svchost.exe

G:\WINDOWS\system32\spoolsv.exe

G:\Program Files\Eset\nod32krn.exe

G:\WINDOWS\system32\nvsvc32.exe

G:\WINDOWS\Explorer.EXE

G:\Program Files\Analog Devices\SoundMAX\Smax4.exe

G:\WINDOWS\system32\RUNDLL32.EXE

G:\Program Files\Analog Devices\Core\smax4pnp.exe

G:\Program Files\D-Tools\daemon.exe

G:\Program Files\Java\jre1.5.0_09\bin\jusched.exe

G:\Program Files\Unlocker\UnlockerAssistant.exe

G:\Program Files\LClock\LClock.exe

G:\Program Files\Internet Explorer\iexplore.exe

G:\Program Files\VisualTooltip\VisualToolTip.exe

G:\Program Files\Styler\Styler.exe

G:\Program Files\IObit\Advanced WindowsCare V2 Pro\Awc.exe

G:\Program Files\Eset\nod32kui.exe

G:\WINDOWS\system32\ctfmon.exe

G:\Program Files\D-Link AirPlus\AirPlus.exe

G:\DOCUME~1\PAWE~1\USTAWI~1\Temp\{3F0E6A4E-4A4B-4D20-9731-89E6122B1935}\Blaero Start Orb.exe

G:\DOCUME~1\PAWE~1\USTAWI~1\Temp\{F654BBF9-350E-4748-A282-3EE1093BB49C}\sidebar.exe

G:\DOCUME~1\PAWE~1\USTAWI~1\Temp\{81AD2028-D2F2-412B-80DC-B1A07FA083B1}\sidebar.exe

G:\WINDOWS\system32\wuauclt.exe

G:\Program Files\Opera\Opera.exe

G:\Program Files\Gadu-Gadu\gg.exe

G:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe

G:\Documents and Settings\Paweł\Pulpit\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowsxlive.net

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowsxlive.net

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 

O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - G:\PROGRA~1\FlashFXP\IEFlash.dll

O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)

O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - G:\Program Files\Styler\TB\StylerTB.dll

O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe

O4 - HKLM\..\Run: [SoundMAX] "G:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [FastCache] G:\Program Files\AnalogX\FastCache\fc.exe

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE G:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [platform obj view city] G:\Documents and Settings\All Users\Dane aplikacji\PokeUploadPlatformObj\Show Mp3.exe

O4 - HKLM\..\Run: [SoundMAXPnP] G:\Program Files\Analog Devices\Core\smax4pnp.exe

O4 - HKLM\..\Run: [DAEMON Tools-1033] "G:\Program Files\D-Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [Fresh Desktop] G:\Documents and Settings\Paweł\Pulpit\fresh_desktop\freshdesktop fix.exe

O4 - HKLM\..\Run: [NeroFilterCheck] G:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [SunJavaUpdateSched] "G:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"

O4 - HKLM\..\Run: [UnlockerAssistant] "G:\Program Files\Unlocker\UnlockerAssistant.exe"

O4 - HKLM\..\Run: [LClock] G:\Program Files\LClock\LClock.exe

O4 - HKLM\..\Run: [Vista Sidebar] G:\Program Files\Vista Sidebar\sidebar.exe

O4 - HKLM\..\Run: [VisualTooltip] G:\Program Files\VisualTooltip\VisualToolTip.exe

O4 - HKLM\..\Run: [Blaero Start Orb] G:\Program Files\Blaero Start Orb\Blaero Start Orb.exe

O4 - HKLM\..\Run: [Styler] G:\Program Files\Styler\Styler.exe

O4 - HKLM\..\Run: [Advanced WindowsCare V2 Pro] "G:\Program Files\IObit\Advanced WindowsCare V2 Pro\Awc.exe" /startup

O4 - HKLM\..\Run: [nod32kui] "G:\Program Files\Eset\nod32kui.exe" /WAITSERVICE

O4 - HKCU\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\ctfmon.exe

O4 - Startup: Vista sidebar.lnk = G:\Program Files\Vista Sidebar\sidebar.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = G:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: D-Link AirPlus.lnk = ?

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.5.0_09\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.5.0_09\bin\ssv.dll

O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 127.0.0.1

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 127.0.0.1

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 127.0.0.1

O20 - Winlogon Notify: WgaLogon - G:\WINDOWS\SYSTEM32\WgaLogon.dll

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - G:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - G:\Program Files\Eset\nod32krn.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - G:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Power Manager (PowerManager) - Unknown owner - G:\WINDOWS\svchost.exe (file missing)

Prosze o pomoc z gory dzieki 8)

edit:dodam jeszcze ze przy wlaczaniu kompa sam mi sie wlacza proces iexplorer.exe i wysakuja jakies okienka z stronami ....


(Bbieniol) #2

Użyj tej szczepionki -> http://wirusy.antivirenkit.pl/pl/szczepionki/Jeefo.html

Start -> uruchom -> services.msc -> zatrzymaj i wyłącz usługe Power Manager

Otwórz hijackthis -> open misc tools section -> delete a NT service -> wpisz PowerManager i ok

W trybie awaryjnym z wyłączonym przywracaniem systemu usuwasz (wpisy Hijackiem, pliki/foldery na czerwono ręcznie z dysku):

Po zabiegach nowy log z Hijacka + log z Silent Runners


(Pawel2827) #3

usunalem te ktore mi tu napisales:

to usuanlem oprocz svchost.exe :shock: w trybie awaryjnym jak juz chcialem usunac to wyskoczylo mi takie cos

922e3d2fd0386b31b869fced089a4345.jpg

A oto log z silenta:

"Silent Runners.vbs", revision 49, http://www.silentrunners.org/

Operating System: Windows XP SP2

Output limited to non-default values, except where indicated by "{++}"



Startup items buried in registry:

---------------------------------


HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}

"CTFMON.EXE" = "G:\WINDOWS\system32\ctfmon.exe" [MS]


HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}

"High Definition Audio Property Page Shortcut" = "HDAShCut.exe" ["Windows (R) Server 2003 DDK provider"]

"SoundMAX" = ""G:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray" ["Analog Devices, Inc."]

"NvCplDaemon" = "RUNDLL32.EXE G:\WINDOWS\system32\NvCpl.dll,NvStartup" [MS]

"FastCache" = "G:\Program Files\AnalogX\FastCache\fc.exe" [file not found]

"NvMediaCenter" = "RUNDLL32.EXE G:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit" [MS]

"platform obj view city" = "G:\Documents and Settings\All Users\Dane aplikacji\PokeUploadPlatformObj\Show Mp3.exe" [file not found]

"SoundMAXPnP" = "G:\Program Files\Analog Devices\Core\smax4pnp.exe" ["Analog Devices, Inc."]

"DAEMON Tools-1033" = ""G:\Program Files\D-Tools\daemon.exe" -lang 1033" ["DAEMON'S HOME"]

"Fresh Desktop" = "G:\Documents and Settings\Paweł\Pulpit\fresh_desktop\freshdesktop fix.exe" [file not found]

"NeroFilterCheck" = "G:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]

"SunJavaUpdateSched" = ""G:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"" ["Sun Microsystems, Inc."]

"UnlockerAssistant" = ""G:\Program Files\Unlocker\UnlockerAssistant.exe"" [null data]

"LClock" = "G:\Program Files\LClock\LClock.exe" [null data]

"Vista Sidebar" = "G:\Program Files\Vista Sidebar\sidebar.exe" [null data]

"VisualTooltip" = "G:\Program Files\VisualTooltip\VisualToolTip.exe" ["Christian Salmon"]

"Blaero Start Orb" = "G:\Program Files\Blaero Start Orb\Blaero Start Orb.exe" [file not found]

"Styler" = "G:\Program Files\Styler\Styler.exe" ["ta2027"]

"Advanced WindowsCare V2 Pro" = ""G:\Program Files\IObit\Advanced WindowsCare V2 Pro\Awc.exe" /startup" ["IObit"]


HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

{E5A1691B-D188-4419-AD02-90002030B8EE}\(Default) = (no title provided)

  - {HKLM...CLSID} = "FlashFXP Helper for Internet Explorer"

                   \InProcServer32\(Default) = "G:\PROGRA~1\FlashFXP\IEFlash.dll" ["IniCom Networks, Inc."]


HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\

"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"

  - {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"

                   \InProcServer32\(Default) = "deskpan.dll" [file not found]

"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"

  - {HKLM...CLSID} = "HyperTerminal Icon Ext"

                   \InProcServer32\(Default) = "G:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]

"{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"

  - {HKLM...CLSID} = "DesktopContext Class"

                   \InProcServer32\(Default) = "G:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"]

"{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"

  - {HKLM...CLSID} = "NVIDIA CPL Extension"

                   \InProcServer32\(Default) = "G:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"]

"{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"

  - {HKLM...CLSID} = "Desktop Explorer"

                   \InProcServer32\(Default) = "G:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]

"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"

  - {HKLM...CLSID} = (no title provided)

                   \InProcServer32\(Default) = "G:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]

"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"

  - {HKLM...CLSID} = "nView Desktop Context Menu"

                   \InProcServer32\(Default) = "G:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]

"{e57ce731-33e8-4c51-8354-bb4de9d215d1}" = "Uniwersalne urządzenia Plug and Play"

  - {HKLM...CLSID} = "Uniwersalne urządzenia Plug and Play"

                   \InProcServer32\(Default) = "G:\WINDOWS\system32\upnpui.dll" [MS]

"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"

  - {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "G:\Program Files\WinRAR\rarext.dll" [null data]

"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"

  - {HKLM...CLSID} = (no title provided)

                   \InProcServer32\(Default) = "G:\Program Files\Microsoft Office\OFFICE11\msohev.dll" [MS]

"{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}" = "UnlockerShellExtension"

  - {HKLM...CLSID} = "UnlockerShellExtension"

                   \InProcServer32\(Default) = "G:\Program Files\Unlocker\UnlockerCOM.dll" [null data]


HKLM\Software\Classes\PROTOCOLS\Filter\

 text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"

  - {HKLM...CLSID} = (no title provided)

                   \InProcServer32\(Default) = "G:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS]


HKLM\Software\Classes\Folder\shellex\ColumnHandlers\

{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"

  - {HKLM...CLSID} = "PDF Shell Extension"

                   \InProcServer32\(Default) = "G:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]


HKLM\Software\Classes\*\shellex\ContextMenuHandlers\

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  - {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "G:\Program Files\WinRAR\rarext.dll" [null data]


HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  - {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "G:\Program Files\WinRAR\rarext.dll" [null data]


HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\

UnlockerShellExtension\(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}"

  - {HKLM...CLSID} = "UnlockerShellExtension"

                   \InProcServer32\(Default) = "G:\Program Files\Unlocker\UnlockerCOM.dll" [null data]

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  - {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "G:\Program Files\WinRAR\rarext.dll" [null data]


HKLM\Software\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\

UnlockerShellExtension\(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}"

  - {HKLM...CLSID} = "UnlockerShellExtension"

                   \InProcServer32\(Default) = "G:\Program Files\Unlocker\UnlockerCOM.dll" [null data]



Group Policies {GPedit.msc branch and setting}:

-----------------------------------------------


Note: detected settings may not have any effect.


HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\


"LinkResolveIgnoreLinkInfo" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\


"LinkResolveIgnoreLinkInfo" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


"NoResolveSearch" = (REG_DWORD) hex:0x00000001

{unrecognized setting}


HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\


"NoUpdateCheck" = (REG_DWORD) hex:0x00000001

{unrecognized setting}


HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\


"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001

{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|

Shutdown: Allow system to be shut down without having to log on}


"undockwithoutlogon" = (REG_DWORD) hex:0x00000001

{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|

Devices: Allow undock without having to log on}



Active Desktop and Wallpaper:

-----------------------------


Active Desktop may be disabled at this entry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState


Displayed if Active Desktop enabled and wallpaper not set by Group Policy:

HKCU\Software\Microsoft\Internet Explorer\Desktop\General\

"Wallpaper" = "G:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"


Displayed if Active Desktop disabled and wallpaper not set by Group Policy:

HKCU\Control Panel\Desktop\

"Wallpaper" = "G:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"



Enabled Screen Saver:

---------------------


HKCU\Control Panel\Desktop\

"SCRNSAVE.EXE" = "G:\WINDOWS\CURIOU~1.SCR" (curious_cats_free.scr) [null data]



Startup items in "Paweł" "All Users" startup folders:

-------------------------------------------------------


G:\Documents and Settings\Paweł\Menu Start\Programy\Autostart

"Vista sidebar" - shortcut to: "G:\Program Files\Vista Sidebar\sidebar.exe" [null data]


G:\Documents and Settings\All Users\Menu Start\Programy\Autostart

"Adobe Reader Speed Launch" - shortcut to: "G:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"]

"D-Link AirPlus" - shortcut to: "G:\Program Files\D-Link AirPlus\AirPlus.exe" ["D-Link"]



Enabled Scheduled Tasks:

------------------------


"Advanced WindowsCare V2 Pro" - launches: "G:\Program Files\IObit\Advanced WindowsCare V2 Pro\AutoCare.exe /care" ["IObit"]

"AwcProUpdate" - launches: "G:\Program Files\IObit\Advanced WindowsCare V2 Pro\AutoUpdate.exe /schedule" ["IObit"]



Winsock2 Service Provider DLLs:

-------------------------------


Namespace Service Providers


HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}

000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]

000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]


Transport Service Providers


HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}

0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:

%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 13

%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05



Toolbars, Explorer Bars, Extensions:

------------------------------------


Toolbars


HKLM\Software\Microsoft\Internet Explorer\Toolbar\

"{D2F8F919-690B-4EA2-9FA7-A203D1E04F75}" = (no title provided)

  - {HKLM...CLSID} = "StylerToolBar"

                   \InProcServer32\(Default) = "G:\Program Files\Styler\TB\StylerTB.dll" ["StyleFantasist"]


Explorer Bars


HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\


HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "Badanie"

Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]

InProcServer32\(Default) = "G:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL" [MS]


Extensions (Tools menu items, main toolbar menu buttons)


HKLM\Software\Microsoft\Internet Explorer\Extensions\

{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\

"MenuText" = "Sun Java Console"

"CLSIDExtension" = "{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}"

  - {HKCU...CLSID} = "Java Plug-in 1.5.0_09"

                   \InProcServer32\(Default) = "G:\Program Files\Java\jre1.5.0_09\bin\ssv.dll" ["Sun Microsystems, Inc."]

  - {HKLM...CLSID} = "Java Plug-in 1.5.0_09"

                   \InProcServer32\(Default) = "G:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll" ["Sun Microsystems, Inc."]


{92780B25-18CC-41C8-B9BE-3C9C571A8263}\

"ButtonText" = "Badanie"



Running Services (Display Name, Service Name, Path {Service DLL}):

------------------------------------------------------------------


NVIDIA Display Driver Service, NVSvc, "G:\WINDOWS\system32\nvsvc32.exe" ["NVIDIA Corporation"]



Print Monitors:

---------------


HKLM\System\CurrentControlSet\Control\Print\Monitors\

Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS]



----------

: Suspicious data at a malware launch point.


+ This report excludes default entries except where indicated.

+ To see *everywhere* the script checks and *everything* it finds,

  launch it from a command prompt or a shortcut with the -all parameter.

+ To search all directories of local fixed drives for DESKTOP.INI

  DLL launch points, use the -supp parameter or answer "No" at the

  first message box and "Yes" at the second message box.

---------- (total run time: 38 seconds, including 5 seconds for message boxes)

(adam9870) #4

Otwórz Notatnik i wklej w nim to:

Plik >>> Zapisz jako >>> Zmień rozszerzenie z TXT na Wszystkie pliki >>> Zapisz pod nazwą FIX.REG i uruchom go w trybie awaryjnym.

Po wykonaniu wklej nowy log z hijacka i silenta.


(Pawel2827) #5

dodalem tego fixa w trybie awryjnym ale nadal ma procesy tj.

svchost.exe ,lsass.exe czy crss.exe :?

log z hijacka:

G:\Program Files\Analog Devices\SoundMAX\Smax4.exe

G:\WINDOWS\system32\RUNDLL32.EXE

G:\Program Files\Analog Devices\Core\smax4pnp.exe

G:\Program Files\D-Tools\daemon.exe

G:\Program Files\Java\jre1.5.0_09\bin\jusched.exe

G:\Program Files\Unlocker\UnlockerAssistant.exe

G:\Program Files\LClock\LClock.exe

G:\Program Files\VisualTooltip\VisualToolTip.exe

G:\Program Files\Styler\Styler.exe

G:\Program Files\IObit\Advanced WindowsCare V2 Pro\Awc.exe

G:\WINDOWS\system32\ctfmon.exe

G:\Program Files\D-Link AirPlus\AirPlus.exe

G:\DOCUME~1\PAWE~1\USTAWI~1\Temp\{111DF88B-6FB4-4AAB-AB7D-E987718D2614}\sidebar.exe

G:\WINDOWS\system32\wuauclt.exe

G:\Program Files\Opera\Opera.exe

G:\Program Files\Gadu-Gadu\gg.exe

G:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe

G:\Documents and Settings\Paweł\Pulpit\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowsxlive.net

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowsxlive.net

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 

F2 - REG:system.ini: Shell=explorer.exe 

O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - G:\PROGRA~1\FlashFXP\IEFlash.dll

O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)

O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - G:\Program Files\Styler\TB\StylerTB.dll

O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe

O4 - HKLM\..\Run: [SoundMAX] "G:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE G:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [SoundMAXPnP] G:\Program Files\Analog Devices\Core\smax4pnp.exe

O4 - HKLM\..\Run: [DAEMON Tools-1033] "G:\Program Files\D-Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [NeroFilterCheck] G:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [SunJavaUpdateSched] "G:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"

O4 - HKLM\..\Run: [UnlockerAssistant] "G:\Program Files\Unlocker\UnlockerAssistant.exe"

O4 - HKLM\..\Run: [LClock] G:\Program Files\LClock\LClock.exe

O4 - HKLM\..\Run: [Vista Sidebar] G:\Program Files\Vista Sidebar\sidebar.exe

O4 - HKLM\..\Run: [VisualTooltip] G:\Program Files\VisualTooltip\VisualToolTip.exe

O4 - HKLM\..\Run: [Styler] G:\Program Files\Styler\Styler.exe

O4 - HKLM\..\Run: [Advanced WindowsCare V2 Pro] "G:\Program Files\IObit\Advanced WindowsCare V2 Pro\Awc.exe" /startup

O4 - HKCU\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\ctfmon.exe

O4 - Startup: Vista sidebar.lnk = G:\Program Files\Vista Sidebar\sidebar.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = G:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: D-Link AirPlus.lnk = ?

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.5.0_09\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.5.0_09\bin\ssv.dll

O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 127.0.0.1

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 127.0.0.1

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 127.0.0.1

O20 - Winlogon Notify: WgaLogon - G:\WINDOWS\SYSTEM32\WgaLogon.dll

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - G:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - G:\WINDOWS\system32\nvsvc32.exe

silent:

"Silent Runners.vbs", revision 49, http://www.silentrunners.org/

Operating System: Windows XP SP2

Output limited to non-default values, except where indicated by "{++}"



Startup items buried in registry:

---------------------------------


HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}

"CTFMON.EXE" = "G:\WINDOWS\system32\ctfmon.exe" [MS]


HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}

"High Definition Audio Property Page Shortcut" = "HDAShCut.exe" ["Windows (R) Server 2003 DDK provider"]

"SoundMAX" = ""G:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray" ["Analog Devices, Inc."]

"NvCplDaemon" = "RUNDLL32.EXE G:\WINDOWS\system32\NvCpl.dll,NvStartup" [MS]

"NvMediaCenter" = "RUNDLL32.EXE G:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit" [MS]

"SoundMAXPnP" = "G:\Program Files\Analog Devices\Core\smax4pnp.exe" ["Analog Devices, Inc."]

"DAEMON Tools-1033" = ""G:\Program Files\D-Tools\daemon.exe" -lang 1033" ["DAEMON'S HOME"]

"NeroFilterCheck" = "G:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]

"SunJavaUpdateSched" = ""G:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"" ["Sun Microsystems, Inc."]

"UnlockerAssistant" = ""G:\Program Files\Unlocker\UnlockerAssistant.exe"" [null data]

"LClock" = "G:\Program Files\LClock\LClock.exe" [null data]

"Vista Sidebar" = "G:\Program Files\Vista Sidebar\sidebar.exe" [null data]

"VisualTooltip" = "G:\Program Files\VisualTooltip\VisualToolTip.exe" ["Christian Salmon"]

"Styler" = "G:\Program Files\Styler\Styler.exe" ["ta2027"]

"Advanced WindowsCare V2 Pro" = ""G:\Program Files\IObit\Advanced WindowsCare V2 Pro\Awc.exe" /startup" ["IObit"]


HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

{E5A1691B-D188-4419-AD02-90002030B8EE}\(Default) = (no title provided)

  -> {HKLM...CLSID} = "FlashFXP Helper for Internet Explorer"

                   \InProcServer32\(Default) = "G:\PROGRA~1\FlashFXP\IEFlash.dll" ["IniCom Networks, Inc."]


HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\

"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"

  -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"

                   \InProcServer32\(Default) = "deskpan.dll" [file not found]

"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"

  -> {HKLM...CLSID} = "HyperTerminal Icon Ext"

                   \InProcServer32\(Default) = "G:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]

"{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"

  -> {HKLM...CLSID} = "DesktopContext Class"

                   \InProcServer32\(Default) = "G:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"]

"{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"

  -> {HKLM...CLSID} = "NVIDIA CPL Extension"

                   \InProcServer32\(Default) = "G:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"]

"{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"

  -> {HKLM...CLSID} = "Desktop Explorer"

                   \InProcServer32\(Default) = "G:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]

"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"

  -> {HKLM...CLSID} = (no title provided)

                   \InProcServer32\(Default) = "G:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]

"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"

  -> {HKLM...CLSID} = "nView Desktop Context Menu"

                   \InProcServer32\(Default) = "G:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]

"{e57ce731-33e8-4c51-8354-bb4de9d215d1}" = "Uniwersalne urządzenia Plug and Play"

  -> {HKLM...CLSID} = "Uniwersalne urządzenia Plug and Play"

                   \InProcServer32\(Default) = "G:\WINDOWS\system32\upnpui.dll" [MS]

"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "G:\Program Files\WinRAR\rarext.dll" [null data]

"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"

  -> {HKLM...CLSID} = (no title provided)

                   \InProcServer32\(Default) = "G:\Program Files\Microsoft Office\OFFICE11\msohev.dll" [MS]

"{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}" = "UnlockerShellExtension"

  -> {HKLM...CLSID} = "UnlockerShellExtension"

                   \InProcServer32\(Default) = "G:\Program Files\Unlocker\UnlockerCOM.dll" [null data]


HKLM\Software\Classes\PROTOCOLS\Filter\

<> text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"

  -> {HKLM...CLSID} = (no title provided)

                   \InProcServer32\(Default) = "G:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS]


HKLM\Software\Classes\Folder\shellex\ColumnHandlers\

{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"

  -> {HKLM...CLSID} = "PDF Shell Extension"

                   \InProcServer32\(Default) = "G:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]


HKLM\Software\Classes\*\shellex\ContextMenuHandlers\

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "G:\Program Files\WinRAR\rarext.dll" [null data]


HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "G:\Program Files\WinRAR\rarext.dll" [null data]


HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\

UnlockerShellExtension\(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}"

  -> {HKLM...CLSID} = "UnlockerShellExtension"

                   \InProcServer32\(Default) = "G:\Program Files\Unlocker\UnlockerCOM.dll" [null data]

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "G:\Program Files\WinRAR\rarext.dll" [null data]


HKLM\Software\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\

UnlockerShellExtension\(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}"

  -> {HKLM...CLSID} = "UnlockerShellExtension"

                   \InProcServer32\(Default) = "G:\Program Files\Unlocker\UnlockerCOM.dll" [null data]



Group Policies {GPedit.msc branch and setting}:

-----------------------------------------------


Note: detected settings may not have any effect.


HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\


"LinkResolveIgnoreLinkInfo" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\


"LinkResolveIgnoreLinkInfo" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


"NoResolveSearch" = (REG_DWORD) hex:0x00000001

{unrecognized setting}


HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\


"NoUpdateCheck" = (REG_DWORD) hex:0x00000001

{unrecognized setting}


HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\


"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001

{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|

Shutdown: Allow system to be shut down without having to log on}


"undockwithoutlogon" = (REG_DWORD) hex:0x00000001

{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|

Devices: Allow undock without having to log on}



Active Desktop and Wallpaper:

-----------------------------


Active Desktop may be disabled at this entry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState


Displayed if Active Desktop enabled and wallpaper not set by Group Policy:

HKCU\Software\Microsoft\Internet Explorer\Desktop\General\

"Wallpaper" = "G:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"


Displayed if Active Desktop disabled and wallpaper not set by Group Policy:

HKCU\Control Panel\Desktop\

"Wallpaper" = "G:\Documents and Settings\Paweł\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"



Enabled Screen Saver:

---------------------


HKCU\Control Panel\Desktop\

"SCRNSAVE.EXE" = "G:\WINDOWS\CURIOU~1.SCR" (curious_cats_free.scr) [null data]



Startup items in "Paweł" & "All Users" startup folders:

-------------------------------------------------------


G:\Documents and Settings\Paweł\Menu Start\Programy\Autostart

"Vista sidebar" -> shortcut to: "G:\Program Files\Vista Sidebar\sidebar.exe" [null data]


G:\Documents and Settings\All Users\Menu Start\Programy\Autostart

"Adobe Reader Speed Launch" -> shortcut to: "G:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"]

"D-Link AirPlus" -> shortcut to: "G:\Program Files\D-Link AirPlus\AirPlus.exe" ["D-Link"]



Enabled Scheduled Tasks:

------------------------


"Advanced WindowsCare V2 Pro" -> launches: "G:\Program Files\IObit\Advanced WindowsCare V2 Pro\AutoCare.exe /care" ["IObit"]

"AwcProUpdate" -> launches: "G:\Program Files\IObit\Advanced WindowsCare V2 Pro\AutoUpdate.exe /schedule" ["IObit"]



Winsock2 Service Provider DLLs:

-------------------------------


Namespace Service Providers


HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}

000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]

000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]


Transport Service Providers


HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}

0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:

%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 13

%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05



Toolbars, Explorer Bars, Extensions:

------------------------------------


Toolbars


HKLM\Software\Microsoft\Internet Explorer\Toolbar\

"{D2F8F919-690B-4EA2-9FA7-A203D1E04F75}" = (no title provided)

  -> {HKLM...CLSID} = "StylerToolBar"

                   \InProcServer32\(Default) = "G:\Program Files\Styler\TB\StylerTB.dll" ["StyleFantasist"]


Explorer Bars


HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\


HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Badanie"

Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]

InProcServer32\(Default) = "G:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL" [MS]


Extensions (Tools menu items, main toolbar menu buttons)


HKLM\Software\Microsoft\Internet Explorer\Extensions\

{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\

"MenuText" = "Sun Java Console"

"CLSIDExtension" = "{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}"

  -> {HKCU...CLSID} = "Java Plug-in 1.5.0_09"

                   \InProcServer32\(Default) = "G:\Program Files\Java\jre1.5.0_09\bin\ssv.dll" ["Sun Microsystems, Inc."]

  -> {HKLM...CLSID} = "Java Plug-in 1.5.0_09"

                   \InProcServer32\(Default) = "G:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll" ["Sun Microsystems, Inc."]


{92780B25-18CC-41C8-B9BE-3C9C571A8263}\

"ButtonText" = "Badanie"



Running Services (Display Name, Service Name, Path {Service DLL}):

------------------------------------------------------------------


NVIDIA Display Driver Service, NVSvc, "G:\WINDOWS\system32\nvsvc32.exe" ["NVIDIA Corporation"]



Print Monitors:

---------------


HKLM\System\CurrentControlSet\Control\Print\Monitors\

Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS]



----------

<>: Suspicious data at a malware launch point.


+ This report excludes default entries except where indicated.

+ To see *everywhere* the script checks and *everything* it finds,

  launch it from a command prompt or a shortcut with the -all parameter.

+ To search all directories of local fixed drives for DESKTOP.INI

  DLL launch points, use the -supp parameter or answer "No" at the

  first message box and "Yes" at the second message box.

---------- (total run time: 38 seconds, including 3 seconds for message boxes)

(adam9870) #6

Logi są ok.

Możesz kosmetycznie ciachnąć.

Nie przejmuj się ponieważ teraz są to prawidłowe procesy.

Proszę popatrz na lokalizację śmiecia, którego miałeś:

G:\WINDOWS\svchost.exe

a teraz na prawidłowy plik:

G:\WINDOWS\System32\svchost.exe


(Pawel2827) #7

dzieki za pomodc wszytkim

ale jak to usunac {E0E899AB-F487-11D5-8D29-0050BA6940E3} co to oznacza gdzie tam wejsc bo nei wiem :stuck_out_tongue:


(adam9870) #8

Po prostu kasujesz wpisz w HijackThis. Czyli uruchamiasz hijacka => klikasz Do a system scan only => pokaże się lista wpisów => stawiasz ptaszek przy wpisie:

=> klikasz Fix checked i potwierdzasz usunięcie.

Ale to tylko kosmetyka, a nie żaden syf etc.


(Pawel2827) #9

ok wielkie dzieki za pomoc :lol:

pozdro :mrgreen: