Prosba o sprawdzenie Loga


(Biedronka01) #1

Logfile of HijackThis v1.98.0

Scan saved at 15:03:43, on 2005-01-04

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

D:\WINDOWS\System32\smss.exe

D:\WINDOWS\system32\winlogon.exe

D:\WINDOWS\system32\services.exe

D:\WINDOWS\system32\lsass.exe

D:\WINDOWS\system32\svchost.exe

D:\WINDOWS\System32\svchost.exe

D:\WINDOWS\Explorer.EXE

D:\WINDOWS\system32\spoolsv.exe

D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\TEMP\ashDisp.exe

C:\TEMP\ashmaisv.exe

D:\WINDOWS\system32\rundll32.exe

D:\WINDOWS\system32\ctfmon.exe

D:\Program Files\Messenger\msmsgs.exe

D:\Program Files\iMesh\Client\iMeshClient.exe

C:\TEMP\aswUpdSv.exe

C:\TEMP\ashServ.exe

D:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe

D:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE

D:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE

D:\WINDOWS\System32\svchost.exe

E:\Instalki\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.onet.pl/

O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - D:\Program Files\MySearch\bar\1.bin\S4BAR.DLL

O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - D:\Program Files\NewDotNet\newdotnet6_38.dll

O2 - BHO: D:\WINDOWS\lbbho.dll - {B44381F2-BD31-4E3B-8867-2EEF1C783FB8} - D:\WINDOWS\lbbho.dll

O3 - Toolbar: My Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - D:\Program Files\MySearch\bar\1.bin\S4BAR.DLL

O4 - HKLM..\Run: [NeroCheck] D:\WINDOWS\System32\NeroCheck.exe

O4 - HKLM..\Run: [RemoteControl] "D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM..\Run: [ec513535a9d74823c100b7e5af1f6fa3] D:\Program Files\Internet Explorer\ec513535a9d74823c100b7e5af1f6fa3.exe

O4 - HKLM..\Run: [avast!] C:\TEMP\ashDisp.exe

O4 - HKLM..\Run: [ashMaiSv] C:\TEMP\ashmaisv.exe

O4 - HKLM..\Run: [Onet.pl AutoUpdate] "D:\Program Files\Common Files\Onet.pl\NewAutoUpdate.exe" /updateexetsr

O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM..\Run: [New.net Startup] rundll32 D:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s

O4 - HKCU..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe

O4 - HKCU..\Run: [Gadu-Gadu] "D:\Program Files\Gadu-Gadu\gg.exe" /tray

O4 - HKCU..\Run: [Komunikator] C:\TEMP\tlen.exe

O4 - HKCU..\Run: [Yahoo! Pager] D:\Program Files\Yahoo!\Messenger\ypager.exe -quiet

O4 - HKCU..\Run: [skype] "C:\TEMP\Skype.exe" /nosplash /minimized

O4 - Startup: iMesh.lnk = D:\Program Files\iMesh\Client\iMeshClient.exe

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe

O10 - Hijacked Internet access by New.Net

O10 - Hijacked Internet access by New.Net

O10 - Hijacked Internet access by New.Net

O10 - Hijacked Internet access by New.Net

O10 - Hijacked Internet access by New.Net

O16 - DPF: ING Bank Online - https://ssl.bsk.com.pl/bskonl/component/INGOnl.cab

O16 - DPF: {342999A3-728D-4DF6-BB81-CDD1A743096A} (MRActivXUI Class) - http://comp.mediaring.com/consumer/pcph ... iph544.cab

O16 - DPF: {631FF594-EC25-4CFF-B869-402DF294E1D6} (Instalator oprogramowania Onet.pl) - http://slimak.onet.pl/_m/kamerzysta/One ... or012s.ocx

O16 - DPF: {92ECE6FA-AC2E-4042-BFAE-0C8608E52A43} (SignActivX Control) - https://www.bph.pl/pi/components/SignActivX.cab

O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) - http://skaner.mks.com.pl/SkanerOnline.cab


(Lewy) #2

O4 - HKLM..\Run: [ec513535a9d74823c100b7e5af1f6fa3] D:\Program Files\Internet Explorer\ec513535a9d74823c100b7e5af1f6fa3.exe


(Kuz5) #3

Najpierw sprawdz żadnych szpiegów najlepiej programem Ad-Aware i dopiero podaj loga.


(Jablek 88) #4

O10 - Hijacked Internet access by New.Net

O10 - Hijacked Internet access by New.Net

O10 - Hijacked Internet access by New.Net

O10 - Hijacked Internet access by New.Net

O10 - Hijacked Internet access by New.Net

Narazie to reszte sprawdze pózniej 8)


(Biedronka01) #5

Sprawdzilam komputer ad-awarem,usunelam to co radziliscie.Czy teraz jest wszystko w porzadku?

Logfile of HijackThis v1.98.0

Scan saved at 11:26:30, on 2005-01-06

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

D:\WINDOWS\System32\smss.exe

D:\WINDOWS\system32\winlogon.exe

D:\WINDOWS\system32\services.exe

D:\WINDOWS\system32\lsass.exe

D:\WINDOWS\system32\svchost.exe

D:\WINDOWS\System32\svchost.exe

D:\WINDOWS\Explorer.EXE

D:\WINDOWS\system32\spoolsv.exe

D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\TEMP\ashDisp.exe

C:\TEMP\ashmaisv.exe

D:\WINDOWS\system32\rundll32.exe

D:\WINDOWS\system32\ctfmon.exe

C:\TEMP\tlen.exe

C:\TEMP\Skype.exe

C:\TEMP\aswUpdSv.exe

C:\TEMP\ashServ.exe

D:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe

D:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE

D:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE

D:\WINDOWS\System32\svchost.exe

D:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe

D:\Program Files\Internet Explorer\iexplore.exe

E:\Instalki\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.onet.pl/

O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - D:\Program Files\MySearch\bar\1.bin\S4BAR.DLL

O2 - BHO: D:\WINDOWS\lbbho.dll - {B44381F2-BD31-4E3B-8867-2EEF1C783FB8} - D:\WINDOWS\lbbho.dll

O3 - Toolbar: My Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - D:\Program Files\MySearch\bar\1.bin\S4BAR.DLL

O4 - HKLM..\Run: [NeroCheck] D:\WINDOWS\System32\NeroCheck.exe

O4 - HKLM..\Run: [RemoteControl] "D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM..\Run: [avast!] C:\TEMP\ashDisp.exe

O4 - HKLM..\Run: [ashMaiSv] C:\TEMP\ashmaisv.exe

O4 - HKLM..\Run: [Onet.pl AutoUpdate] "D:\Program Files\Common Files\Onet.pl\NewAutoUpdate.exe" /updateexetsr

O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM..\Run: [New.net Startup] rundll32 D:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s

O4 - HKLM..\RunOnce: [Ad-aware] "D:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-aware.exe" "+b1"

O4 - HKCU..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe

O4 - HKCU..\Run: [Gadu-Gadu] "D:\Program Files\Gadu-Gadu\gg.exe" /tray

O4 - HKCU..\Run: [Komunikator] C:\TEMP\tlen.exe

O4 - HKCU..\Run: [Yahoo! Pager] D:\Program Files\Yahoo!\Messenger\ypager.exe -quiet

O4 - HKCU..\Run: [skype] "C:\TEMP\Skype.exe" /nosplash /minimized

O4 - Startup: iMesh.lnk = D:\Program Files\iMesh\Client\iMeshClient.exe

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe

O16 - DPF: ING Bank Online - https://ssl.bsk.com.pl/bskonl/component/INGOnl.cab

O16 - DPF: {342999A3-728D-4DF6-BB81-CDD1A743096A} (MRActivXUI Class) - http://comp.mediaring.com/consumer/pcph ... iph544.cab

O16 - DPF: {631FF594-EC25-4CFF-B869-402DF294E1D6} (Instalator oprogramowania Onet.pl) - http://slimak.onet.pl/_m/kamerzysta/One ... or012s.ocx

O16 - DPF: {92ECE6FA-AC2E-4042-BFAE-0C8608E52A43} (SignActivX Control) - https://www.bph.pl/pi/components/SignActivX.cab

O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) - http://skaner.mks.com.pl/SkanerOnline.cab


(Damian) #6
O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - D:\Program Files\MySearch\bar\1.bin\S4BAR.DLL

O2 - BHO: D:\WINDOWS\lbbho.dll - {B44381F2-BD31-4E3B-8867-2EEF1C783FB8} - D:\WINDOWS\lbbho.dll

O3 - Toolbar: My Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - D:\Program Files\MySearch\bar\1.bin\S4BAR.DLL

O4 - HKLM\..\Run: [Onet.pl AutoUpdate] "D:\Program Files\Common Files\Onet.pl\NewAutoUpdate.exe" /updateexetsr

O4 - HKLM\..\Run: [New.net Startup] rundll32 D:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s

O16 - DPF: {342999A3-728D-4DF6-BB81-CDD1A743096A} (MRActivXUI Class) - http://comp.mediaring.com/consumer/pcphone/ver5.4.4.0/wbaxuiph544.ca

(wieszak) #7

Start--> uruchom-->msconfig -->zakładka uruchamianie

Odznacz

Jak masz Nortona to (pozostały jakieś resztki Avasta) wywal To :


(Dragonlnx) #8

:shock: C:\TEMP\tlen.exe

Lepiej przeinstaluj Tlena i zainstaluj w C:\Program Files\Tlen :wink: