Prosze o sprawdzenie loga!

  • Logfile of HijackThis v1.99.1

Sposób usuwania:

Kasacja

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\cmd32.exe

   	O1 - Hosts: 217.96.35.130 auto.search.msn.com

   	O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)  	 

   	O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\system32\gah95on6.exe

   	O4 - HKLM\..\Run: [salm] c:\temp\salm.exe

   	O4 - HKLM\..\Run: [ofyx] C:\WINDOWS\ofyx.exe

   	O4 - HKLM\..\Run: [Media Pass] C:\Program Files\Media Pass\MediaPassK.exe

   	O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u

   	O4 - HKLM\..\RunServices: [CMD] cmd32.exe

O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/CDT/ie/bridge-c282.cab

Potem na nowo log.

Jeżeli nie używasz windows messenger możesz go usunąć

start>>uruchom>> i wklejasz to :

RunDll32 advpack.dll,LaunchINFSection %windir%INFmsmsgs.inf,BLC.Remove
  • Logfile of HijackThis v1.99.1

Scan saved at 18:39:27, on 2005-04-01

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\WINDOWS\system32\drivers\CDAC11BA.EXE

C:\WINDOWS\system32\cisvc.exe

C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe

C:\Program Files\Analog Devices\SoundMAX\Smtray.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

D:\PrograMy\DU Meter\DUMeter.exe

D:\PrograMy\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\Realtek\Rtl8180\RtlWake.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\WINDOWS\system32\cidaemon.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\Documents and Settings\KabeS\Pulpit\HijackThis1991.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wp.pl/

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PrograMy\Spybot - Search & Destroy\SDHelper.dll

O4 - HKLM…\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM…\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe

O4 - HKLM…\Run: [MKS_MENU] C:\Program Files\MKS\Bin\mks_menu.exe

O4 - HKLM…\Run: [smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe

O4 - HKLM…\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM…\Run: [TkBellExe] “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

O4 - HKLM…\Run: [DU Meter] D:\PrograMy\DU Meter\DUMeter.exe

O4 - HKCU…\Run: [spybotSD TeaTimer] D:\PrograMy\Spybot - Search & Destroy\TeaTimer.exe

O4 - Startup: VirtuaGirl2.lnk = E:\Gierki\Vg\VirtuaGirl2.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O4 - Global Startup: RtlWake.lnk = ?

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) - http://skaner.mks.com.pl/SkanerOnline.cab

O17 - HKLM\System\CCS\Services\Tcpip…{99CCBDA4-5C5A-4EB3-823C-8F2B511F25E3}: NameServer = 192.168.100.252 80.51.166.189

O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

[list=]

Wielkie dzieki

ok 8)

Już czysto. Jeśli chcesz, możesz wywalić Windows Messengera: TYM

Z autostartu - Start -> Uruchom -> msconfig możesz odznaczyć:

jusched.exe

realsched.exe

Real Playera możesz zastąpić pakietem Real Alternative.