teedy6
(Teedy6)
6 Luty 2008 18:38
#1
Witam
Prosze o sprawdzenie loga.
Windows dziala wolno, antyvirus odinstalowany.
http://www.wklej.org/id/443806272d
1. Logfile of HijackThis v1.99.1 2. Scan saved at 19:30:10, on 2008-02-06 3. Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600) 4. MSIE: Internet Explorer v7.00 (7.00.6000.20627) 5. 6. Running processes: 7. C:\WINDOWS\System32\smss.exe 8. C:\WINDOWS\system32\winlogon.exe 9. C:\WINDOWS\system32\services.exe 10. C:\WINDOWS\system32\lsass.exe 11. C:\WINDOWS\system32\Ati2evxx.exe 12. C:\WINDOWS\system32\svchost.exe 13. C:\WINDOWS\System32\svchost.exe 14. C:\WINDOWS\system32\Ati2evxx.exe 15. C:\WINDOWS\system32\spoolsv.exe 16. C:\WINDOWS\system32\EXPLORER.EXE 17. C:\WINDOWS\Explorer.EXE 18. C:\WINDOWS\SOUNDMAN.EXE 19. C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe 20. C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe 21. C:\WINDOWS\system32\ctfmon.exe 22. C:\Program Files\Gadu-Gadu\gg.exe 23. C:\Program Files\SmartPCTools\Registry Repair Wizard\RCHelper.exe 24. C:\Program Files\ProgDVB\winlirc.exe 25. C:\Program Files\Bonjour\mDNSResponder.exe 26. C:\Program Files\CyberLink\Shared files\RichVideo.exe 27. C:\Program Files\Spyware Doctor\svcntaux.exe 28. E:\Gry\RBRally\CamHack.exe 29. C:\Program Files\Mozilla Firefox\firefox.exe 30. C:\Program Files\ProgDVB\ProgDVB.exe 31. C:\DOCUME~1\teedy6\USTAWI~1\Temp\Rar$EX00.625\HijackThis.exe 32. 33. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage 34. 35. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 36. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 37. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 38. R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 39. R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 40. R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 41. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 42. R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local 43. R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 44. R3 - Default URLSearchHook is missing 45. F2 - REG:system.ini: UserInit=userinit.exe,EXPLORER.EXE 46. O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll 47. O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll 48. O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll 49. O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll 50. O4 - HKLM…\Run: [soundMan] SOUNDMAN.EXE 51. O4 - HKLM…\Run: [NVMixerTray] “C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe” 52. O4 - HKLM…\Run: [AtiPTA] atiptaxx.exe 53. O4 - HKLM…\Run: [Flashget] C:\Program Files\FlashGet\FlashGet.exe /min 54. O4 - HKLM…\Run: [sunJavaUpdateSched] “C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” 55. O4 - HKLM…\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k 56. O4 - HKCU…\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe 57. O4 - HKCU…\Run: [Gadu-Gadu] “C:\Program Files\Gadu-Gadu\gg.exe” /tray 58. O4 - HKCU…\Run: [EXPLORER.EXE] EXPLORER.EXE 59. O4 - HKCU…\Run: [Registry Repair Wizard Scheduler] “C:\Program Files\SmartPCTools\Registry Repair Wizard\RCHelper.exe” /startup 60. O4 - HKCU…\Run: [wsctf.exe] wsctf.exe 61. O4 - Global Startup: winlirc.lnk = C:\Program Files\ProgDVB\winlirc.exe 62. O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm 63. O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm 64. O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000 65. O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll 66. O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll 67. O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL 68. O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe 69. O9 - Extra ‘Tools’ menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe 70. O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) 71. O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll ,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) 72. O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll 73. O11 - Options group: [iNTERNATIONAL] International* 74. O11 - Options group: [TABS] Tabbed Browsing 75. O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll 76. O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe 77. O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe 78. O23 - Service: ##Id_String1 .6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe 79. O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe 80. O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe 81. O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe 82. O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
Leon1
(Leon$)
6 Luty 2008 19:02
#2
wpisy
F2 - REG:system.ini: UserInit=userinit.exe,EXPLORER.EXE
O4 - HKCU\..\Run: [EXPLORER.EXE] EXPLORER.EXE
O4 - HKCU\..\Run: [wsctf.exe] wsctf.exe
usuń HijackThisem >> Fix checked Pobierz Combofix http://www.bezpieczenstwosystemow.pl/index.php?topic=18.0 otwórz notatnik i wklej
File::
C:\Autorun.inf
C:\WINDOWS\system32\EXPLORER.EXE
C:\WINDOWS\system32\wsctf.exe
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2]
zapisz jako CFScript.txt (zapisz by ikonka CFScript.txt była obok ikonki ComboFix.exe) >> Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe
http://img.wklej.org/images/88953CFScri … iemoes.gif
Powinno rozpocząć się usuwanie
Potem log z usuwania
Po restarcie usuń ręcznie folder C: \Qoobox
Gutek
(Gutek)
6 Luty 2008 19:04
#3
Zmiana zasad wklejania logów na forum - viewtopic.php?f=16&t=213350
Zastosuj się do tego Tematu i zmień tytuł tematu na konkretny inaczej KOSZ
Pozdrawiam Gutek2222