wyskakuje okienko :(

mam problemik :( po uruchomieniu sie kompa wyskakuje mi komunikat: nie moźna odnaleźć pliku C:/Windows/Downloaded Program Files/bridge.dll o co chodzi ?? pomocy proshem bo jestem z tego kompletnie zielona.... :(

Odpowiedzi: 20

dafnis:
... a nic mi sie nie uśmiechnij ?
Przy takim zasobie slownictwa, jak i przy tych wszystkich:
shybciej
przyshłość
jeshcze
jush
wshystko
...mozesz jeszcze opierdziel dostac.
Rozumiem bledy ortograficzne, ale te "perelki" rodem z czatow dla dzieci przyprawiaja mnie o odruch wymiotny.
EL NINO
Dodano
27.11.2004 21:48:02
Wszystko to syfior, leci bez zmruźenia okiem do kosza
Bobi
Dodano
27.11.2004 20:09:39
ahaś czyli rozumiem, źe mam to teraz ręcznie usunąć, to co teraz napisałeś, tak ?? :?: :?:
a nic mi sie nie spierdoli ?
dafnis
Dodano
27.11.2004 20:06:20
dafnis:
nio i odrazu shybciej śmiga :D a jakie pliczki i foldery ??
a tak na przyshłość to co trza jeshcze robić, źeby se tak nie zasyfiało ??

Trzeba uwazac co sie "klika"
Od czasu do czasu przeleciec jakim SpyBotem,Ad–awerem, w razie potrzeby CWShredderem


Wywaliłaś ??:
twaintec.dll
C:Program FilesMyWebSearch\r aso.dll
2_0_1browserhelper2.dll >> poszukaj dobrze
bridge.dll >> –II–
nvms.dll >> –II–
C:Program FilesHotbar
mscb.dll >> –II–
apuc.dll
C:Program FilesDashBar
C:Program FilesISTsvc
C:Program FilesBullsEye Network
c: emp
alchem.exe
fol.exe
C:Program FilesCommon FilesCMEII
elgnwj.exe
C:Program FilesWeb_Rebates
C:Program FilesWindows AdControl
Bobi
Dodano
27.11.2004 19:45:54
nio i odrazu shybciej śmiga :D a jakie pliczki i foldery ??
a tak na przyshłość to co trza jeshcze robić, źeby se tak nie zasyfiało ??
dafnis
Dodano
27.11.2004 19:34:17
W sumie jest lepiej, ale bylo bardzo źle

Wylacz jeszcze:
WinAdCtl.exe
WinAdAlt.exe
WebRebates1.exe
WebRebates0.exe

FIX:
O4 – HKLM..Run: [Windows AdControl] C:Program FilesWindows AdControlWinAdCtl.exe
O4 – Startup: MyWebSearch Email Plugin.lnk = C:Program FilesMyWebSearchar1.binMWSOEMON.EXE
O4 – Global Startup: MyWebSearch Email Plugin.lnk = C:Program FilesMyWebSearchar1.binMWSOEMON.EXE


Pamietaj o przywracaniu bo jak bedziesz chciala sobie system przywrocic to Ci sie znow wszysko moze zaladowac
pliki i katalogi wywalone z dysku ??
Bobi
Dodano
27.11.2004 19:25:46
Logfile of HijackThis v1.97.7
Scan saved at 18:17:32, on 2004–11–27
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSSYSTEM32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:Program FilesAntiVirenKit professionalAVKService.exe
C:Program FilesAntiVirenKit professionalAVKWCtl.exe
C:WINDOWSSystem32 vsvc32.exe
C:Program FilesCommon FilesPanda SoftwarePavShldpavprsrv.exe
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004Pavsrv51.exe
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004PsImSvc.exe
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004AVENGINE.EXE
C:WINDOWSSOUNDMAN.EXE
C:Program FilesJavaj2re1.4.2_05injusched.exe
C:Program FilesHotbarin4.5.1.0WeatherOnTray.exe
C:PROGRA~1MYWEBS~1ar1.binmwsoemon.exe
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004APVXDWIN.EXE
C:Program FilesWinampwinampa.exe
C:Program FilesAntiVirenKit professionalAVKPOP.EXE
C:Program FilesGadu–Gadugg.exe
C:Program FilesMessengermsmsgs.exe
E:TLEN len.exe
C:Program FilesSAGEMSAGEM F@st 800–840DSLMON.exe
C:Program FilesAVERTV2KQuickTV.exe
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004WebProxy.exe
C:Program FilesWindows AdControlWinAdCtl.exe
C:Program FilesWindows AdControlWinAdAlt.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesWeb_RebatesWebRebates1.exe
C:Program FilesWeb_RebatesWebRebates0.exe
C:Program FilesHotbarin4.5.1.0HbSrv.exe
C:Documents and SettingspppMoje dokumentyinstalkiHijackThis.exe

R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.interia.pl/
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R1 – HKCUSoftwareMicrosoftInternet Connection Wizard,Shellnext = iexplore
O2 – BHO: (no name) – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_05injusched.exe
O4 – HKLM..Run: [APVXDWIN] "C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004APVXDWIN.EXE" /s
O4 – HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe
O4 – HKLM..Run: [AVK Mail Checker] "C:Program FilesAntiVirenKit professionalAVKPOP.EXE"
O4 – HKLM..Run: [Windows AdControl] C:Program FilesWindows AdControlWinAdCtl.exe
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 – HKCU..Run: [Komunikator] E:TLEN len.exe
O4 – Startup: MyWebSearch Email Plugin.lnk = C:Program FilesMyWebSearchar1.binMWSOEMON.EXE
O4 – Global Startup: DSLMON.lnk = C:Program FilesSAGEMSAGEM F@st 800–840DSLMON.exe
O4 – Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O4 – Global Startup: MyWebSearch Email Plugin.lnk = C:Program FilesMyWebSearchar1.binMWSOEMON.EXE
O4 – Global Startup: QuickTV.lnk = C:Program FilesAVERTV2KQuickTV.exe
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 – Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 – Extra button: Messenger (HKLM)
O9 – Extra 'Tools' menuitem: Windows Messenger (HKLM)
O10 – Unknown file in Winsock LSP: c:program filespanda softwarepanda titanium antivirus 2004pavlsp.dll
O10 – Unknown file in Winsock LSP: c:program filespanda softwarepanda titanium antivirus 2004pavlsp.dll
O10 – Unknown file in Winsock LSP: c:program filespanda softwarepanda titanium antivirus 2004pavlsp.dll
O10 – Unknown file in Winsock LSP: c:program filespanda softwarepanda titanium antivirus 2004pavlsp.dll
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 – DPF: {6414512B–B978–451D–A0D8–FCFDF33E833C} (WUWebControl Class) – http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093273663093
O16 – DPF: {9A9307A0–7DA4–4DAF–B042–5009F29E09E1} (ActiveScan Installer Class) – http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
O17 – HKLMSystemCCSServicesTcpip..{778F4757–7FB6–45DE–B697–095ADBB70263}: NameServer = 194.204.152.34 217.98.63.164



i jak lepiej ?? czy jeshcze coś trza zrobić ??
dafnis
Dodano
27.11.2004 19:20:09
Szczerze to troche mnie glowa rozbolala

Alt+Ctrl+Del >> zakladka procesy, po kolei zaznaczasz jeden i Zakoncz proces
az nie wylaczysz wszyskich o ktorych pisalem czyli:
istsvc.exe
msbb.exe
CMESys.exe
WeatherOnTray.exe
mwsoemon.exe
WinAdCtl.exe
WinAdAlt.exe
HbInst.exe
GMT.exe
HbSrv.exe
WebRebates1.exe
WebRebates0.exe


Potem stawiasz w programie HijackThis "ptaszka" (V)
przy pozycjach ktore wymienilem w ramce KOD wyzej
i >> Fix checked


Po wszystkim wklej nowy log
Bobi
Dodano
27.11.2004 18:52:54
dziękować ci bardzo ale jak jush pisałam to jestem zielona w tym bardzo :P i kompletnie nie wiem jak to niby mam zrobić , więc jakby ktoś mógł dokładniej to objaśnić ....
dafnis
Dodano
27.11.2004 18:47:24
Syfu w cholere i jeszcze troche :roll:
Chyba rekord padł
Ale co tam pewnie moje spostrzezenia na za wiele sie nie zdadzą

Wylacz przywracanie systemu

Wylacz procesy w tasku:
C:Program FilesISTsvcistsvc.exe
C: empmsbb.exe
CMESys.exe
WeatherOnTray.exe
mwsoemon.exe
WinAdCtl.exe
WinAdAlt.exe
HbInst.exe
GMT.exe
HbSrv.exe
WebRebates1.exe
WebRebates0.exe



Zarowno z loga jak i dysku leca pliki/katalogi
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://www.hotbar.com/dyn/hotbar/3.0/sb_searchPageHome.htm
R1 – HKCUSoftwareMicrosoftInternet Connection Wizard,Shellnext = iexplore
O2 – BHO: (no name) – {000020DD–C72E–4113–AF77–DD56626C6C42} – C:WINDOWS waintec.dll
O2 – BHO: MyWebSearch Search Assistant BHO – {00A6FAF1–072E–44cf–8957–5838F569A31D} – C:Program FilesMyWebSearchSrchAstt1.binMWSSRCAS.DLL
O2 – BHO: mwsBar BHO – {07B18EA1–A523–4961–B6BB–170DE4475CCA} – C:Program FilesMyWebSearchar1.binMWSBAR.DLL
O2 – BHO: (no name) – {4CA9145E–9E17–01BD–D706–12550DAE2815} – C:WINDOWSSystem32aso.dll
02 – BHO: (no name) – {83DE62E0–5805–11D8–9B25–00E04C60FAF2} – C:WINDOWS2_0_1browserhelper2.dll (file missing)
O2 – BHO: (no name) – {9C691A33–7DDA–4C2F–BE4C–C176083F35CF} – C:WINDOWSDownloaded Program Filesridge.dll (file missing)
O2 – BHO: (no name) – {AEECBFDA–12FA–4881–BDCE–8C3E1CE4B344} – C:WINDOWSSystem32 vms.dll (file missing)
O2 – BHO: Hotbar – {B195B3B3–8A05–11D3–97A4–0004ACA6948E} – C:Program FilesHotbarin4.5.1.0HbHostIE.dll
O2 – BHO: (no name) – {CE188402–6EE7–4022–8868–AB25173A3E14} – C:WINDOWSSystem32mscb.dll (file missing)
O2 – BHO: Url Catcher – {CE31A1F7–3D90–4874–8FBE–A5D97F8BC8F1} – C:WINDOWSSystem32apuc.dll
O3 – Toolbar: DashBar Toolbar – {CC90CDA0–74A0–45b4–80EF–D89CA8C249B8} – C:Program FilesDashBarDashBar17.dll
O3 – Toolbar: &Hotbar – {B195B3B3–8A05–11D3–97A4–0004ACA6948E} – C:Program FilesHotbarin4.5.1.0HbHostIE.dll
O3 – Toolbar: My &Web Search – {07B18EA9–A523–4961–B6BB–170DE4475CCA} – C:Program FilesMyWebSearchar1.binMWSBAR.DLL
O4 – HKLM..Run: [IST Service] C:Program FilesISTsvcistsvc.exe
O4 – HKLM..Run: [BullsEye Network] C:Program FilesBullsEye Networkinargains.exe
O4 – HKLM..Run: [klwkibp] C:WINDOWSSystem32 abembmk.exe
O4 – HKLM..Run: [msbb] c: empmsbb.exe
O4 – HKLM..Run: [alchem] C:WINDOWSalchem.exe
O4 – HKLM..Run: [fol] C:WINDOWSfol.exe
O4 – HKLM..Run: [CMESys] "C:Program FilesCommon FilesCMEIICMESys.exe"
O4 – HKLM..Run: [elgnwj] C:WINDOWSelgnwj.exe
O4 – HKLM..Run: [WebRebates0] "C:Program FilesWeb_RebatesWebRebates0.exe"
O4 – HKLM..Run: [WeatherOnTray] C:Program FilesHotbarin4.5.1.0WeatherOnTray.exe
O4 – HKLM..Run: [MyWebSearch Email Plugin] C:PROGRA~1MYWEBS~1ar1.binmwsoemon.exe
O4 – HKLM..Run: [Windows AdControl] C:Program FilesWindows AdControlWinAdCtl.exe

O4 – HKLM..Run: [Hotbar] C:Program FilesHotbarin4.5.1.0HbInst.exe /Upgrade
O4 – HKCU..Run: [MyWebSearch Email Plugin] C:PROGRA~1MYWEBS~1ar1.binmwsoemon.exe
O4 – Startup: MyWebSearch Email Plugin.lnk = C:Program FilesMyWebSearchar1.binMWSOEMON.EXE

O4 – Global Startup: MyWebSearch Email Plugin.lnk = C:Program FilesMyWebSearchar1.binMWSOEMON.EXE
O8 – Extra context menu item: &Search – http://bar.mywebsearch.com/menusearch.html?p=ZRxdm185XXUS
O8 – Extra context menu item: Web Rebates – file://C:Program FilesWeb_RebatesSy1150Tp1150scri1150a.htm


O16 – DPF: {02C20140–76F8–4763–83D5–B660107B7A90} (Moniker32 Class) – http://63.217.29.115/cax.cab
O16 – DPF: {15AD4789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://public.windupdates.com/get_file.php?
bt=ie&p=9fbcec573a93c31d08e492706c0f86e1a54a066ea79ee775b02d03ff653d2984f2cd67659ef9f087890b19ad86be505f1d49d9cb927650ecea87f9:207b8bbba6efe004661d0d88309f9efb
O16 – DPF: {1D4DB7D2–6EC9–47A3–BD87–1E41684E07BB} – http://imgfarm.com/images/nocache/funwebproducts/ei/PopularScreenSaversInitialSetup1.0.0.8.cab
O16 – DPF: {386A771C–E96A–421F–8BA7–32F1B706892F} (Installer Class) – http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_regular.cab
O16 – DPF: {3E339D3C–4B12–4E8C–A529–9CC4BEEAFD4F} (VacPro.russia_ver3) – http://www.advnt01.com/dialer/russia.CAB
O16 – DPF: {91433D86–9F27–402C–B5E3–DEBDD122C339} – http://www.netvenda.com/sites/games–intl/pl/games4.cab
O16 – DPF: {9C691A33–7DDA–4C2F–BE4C–C176083F35CF} (brdg Class) – http://static.flingstone.com/cab/2000XP/CDTInc/bridge.cab
O16 – DPF: {9EB320CE–BE1D–4304–A081–4B4665414BEF} – http://www.mt–download.com/MediaTicketsInstaller.cab


Wlacz przywracanie
Bobi
Dodano
27.11.2004 18:43:53
nooo dziękować, teraz jush wiem :D
a to ten yyy noo, log :D

Logfile of HijackThis v1.97.7
Scan saved at 17:22:05, on 2004–11–27
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSSYSTEM32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSSystem32 vsvc32.exe
C:Program FilesCommon FilesPanda SoftwarePavShldpavprsrv.exe
C:WINDOWSSOUNDMAN.EXE
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004Pavsrv51.exe
C:Program FilesISTsvcistsvc.exe
C: empmsbb.exe
C:Program FilesCommon FilesCMEIICMESys.exe
C:Program FilesJavaj2re1.4.2_05injusched.exe
C:Program FilesHotbarin4.5.1.0WeatherOnTray.exe
C:PROGRA~1MYWEBS~1ar1.binmwsoemon.exe
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004APVXDWIN.EXE
C:Program FilesWindows AdControlWinAdCtl.exe
C:Program FilesWinampwinampa.exe
C:Program FilesWindows AdControlWinAdAlt.exe
C:Program FilesHotbarin4.5.1.0HbInst.exe
C:Program FilesMessengermsmsgs.exe
E:TLEN len.exe
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004PsImSvc.exe
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004AVENGINE.EXE
C:Program FilesSAGEMSAGEM F@st 800–840DSLMON.exe
C:Program FilesAVERTV2KQuickTV.exe
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004WebProxy.exe
C:Program FilesCommon FilesGMTGMT.exe
C:Program FilesWinampwinamp.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesHotbarin4.5.1.0HbSrv.exe
C:Program FilesInternet Exploreriexplore.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesGadu–Gadugg.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesWeb_RebatesWebRebates1.exe
C:Program FilesAntiVirenKit professionalAVKPOP.EXE
C:Program FilesAntiVirenKit professionalAVKWCtl.exe
C:Program FilesWeb_RebatesWebRebates0.exe
C:Program FilesAntiVirenKit professionalAVKService.exe
C:Program FilesAntiVirenKit professionalAVK.exe
C:Documents and SettingspppMoje dokumentyinstalkiHijackThis.exe

R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.interia.pl/
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://www.hotbar.com/dyn/hotbar/3.0/sb_searchPageHome.htm
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R1 – HKCUSoftwareMicrosoftInternet Connection Wizard,Shellnext = iexplore
O2 – BHO: (no name) – {000020DD–C72E–4113–AF77–DD56626C6C42} – C:WINDOWS waintec.dll
O2 – BHO: MyWebSearch Search Assistant BHO – {00A6FAF1–072E–44cf–8957–5838F569A31D} – C:Program FilesMyWebSearchSrchAstt1.binMWSSRCAS.DLL
O2 – BHO: (no name) – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O2 – BHO: mwsBar BHO – {07B18EA1–A523–4961–B6BB–170DE4475CCA} – C:Program FilesMyWebSearchar1.binMWSBAR.DLL
O2 – BHO: (no name) – {4CA9145E–9E17–01BD–D706–12550DAE2815} – C:WINDOWSSystem32aso.dll
O2 – BHO: (no name) – {83DE62E0–5805–11D8–9B25–00E04C60FAF2} – C:WINDOWS2_0_1browserhelper2.dll (file missing)
O2 – BHO: (no name) – {9C691A33–7DDA–4C2F–BE4C–C176083F35CF} – C:WINDOWSDownloaded Program Filesridge.dll (file missing)
O2 – BHO: (no name) – {AEECBFDA–12FA–4881–BDCE–8C3E1CE4B344} – C:WINDOWSSystem32 vms.dll (file missing)
O2 – BHO: Hotbar – {B195B3B3–8A05–11D3–97A4–0004ACA6948E} – C:Program FilesHotbarin4.5.1.0HbHostIE.dll
O2 – BHO: (no name) – {CE188402–6EE7–4022–8868–AB25173A3E14} – C:WINDOWSSystem32mscb.dll (file missing)
O2 – BHO: Url Catcher – {CE31A1F7–3D90–4874–8FBE–A5D97F8BC8F1} – C:WINDOWSSystem32apuc.dll
O3 – Toolbar: DashBar Toolbar – {CC90CDA0–74A0–45b4–80EF–D89CA8C249B8} – C:Program FilesDashBarDashBar17.dll
O3 – Toolbar: &Hotbar – {B195B3B3–8A05–11D3–97A4–0004ACA6948E} – C:Program FilesHotbarin4.5.1.0HbHostIE.dll
O3 – Toolbar: My &Web Search – {07B18EA9–A523–4961–B6BB–170DE4475CCA} – C:Program FilesMyWebSearchar1.binMWSBAR.DLL
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 – HKLM..Run: [IST Service] C:Program FilesISTsvcistsvc.exe
O4 – HKLM..Run: [BullsEye Network] C:Program FilesBullsEye Networkinargains.exe
O4 – HKLM..Run: [klwkibp] C:WINDOWSSystem32 abembmk.exe
O4 – HKLM..Run: [msbb] c: empmsbb.exe
O4 – HKLM..Run: [alchem] C:WINDOWSalchem.exe
O4 – HKLM..Run: [fol] C:WINDOWSfol.exe
O4 – HKLM..Run: [CMESys] "C:Program FilesCommon FilesCMEIICMESys.exe"
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_05injusched.exe
O4 – HKLM..Run: [elgnwj] C:WINDOWSelgnwj.exe
O4 – HKLM..Run: [WebRebates0] "C:Program FilesWeb_RebatesWebRebates0.exe"
O4 – HKLM..Run: [WeatherOnTray] C:Program FilesHotbarin4.5.1.0WeatherOnTray.exe
O4 – HKLM..Run: [MyWebSearch Email Plugin] C:PROGRA~1MYWEBS~1ar1.binmwsoemon.exe
O4 – HKLM..Run: [APVXDWIN] "C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004APVXDWIN.EXE" /s
O4 – HKLM..Run: [Windows AdControl] C:Program FilesWindows AdControlWinAdCtl.exe
O4 – HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe
O4 – HKLM..Run: [Hotbar] C:Program FilesHotbarin4.5.1.0HbInst.exe /Upgrade
O4 – HKLM..Run: [AVK Mail Checker] "C:Program FilesAntiVirenKit professionalAVKPOP.EXE"
O4 – HKCU..Run: [MyWebSearch Email Plugin] C:PROGRA~1MYWEBS~1ar1.binmwsoemon.exe
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 – HKCU..Run: [Komunikator] E:TLEN len.exe
O4 – Startup: MyWebSearch Email Plugin.lnk = C:Program FilesMyWebSearchar1.binMWSOEMON.EXE
O4 – Global Startup: DSLMON.lnk = C:Program FilesSAGEMSAGEM F@st 800–840DSLMON.exe
O4 – Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O4 – Global Startup: MyWebSearch Email Plugin.lnk = C:Program FilesMyWebSearchar1.binMWSOEMON.EXE
O4 – Global Startup: QuickTV.lnk = C:Program FilesAVERTV2KQuickTV.exe
O8 – Extra context menu item: &Search – http://bar.mywebsearch.com/menusearch.html?p=ZRxdm185XXUS
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O8 – Extra context menu item: Web Rebates – file://C:Program FilesWeb_RebatesSy1150Tp1150scri1150a.htm
O9 – Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 – Extra button: Messenger (HKLM)
O9 – Extra 'Tools' menuitem: Windows Messenger (HKLM)
O10 – Unknown file in Winsock LSP: c:program filespanda softwarepanda titanium antivirus 2004pavlsp.dll
O10 – Unknown file in Winsock LSP: c:program filespanda softwarepanda titanium antivirus 2004pavlsp.dll
O10 – Unknown file in Winsock LSP: c:program filespanda softwarepanda titanium antivirus 2004pavlsp.dll
O10 – Unknown file in Winsock LSP: c:program filespanda softwarepanda titanium antivirus 2004pavlsp.dll
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 – DPF: {02C20140–76F8–4763–83D5–B660107B7A90} (Moniker32 Class) – http://63.217.29.115/cax.cab
O16 – DPF: {15AD4789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://public.windupdates.com/get_file.php?bt=ie&p=9fbcec573a93c31d08e492706c0f86e1a54a066ea79ee775b02d03ff653d2984f2cd67659ef9f087890b19ad86be505f1d49d9cb927650ecea87f9:207b8bbba6efe004661d0d88309f9efb
O16 – DPF: {1D4DB7D2–6EC9–47A3–BD87–1E41684E07BB} – http://imgfarm.com/images/nocache/funwebproducts/ei/PopularScreenSaversInitialSetup1.0.0.8.cab
O16 – DPF: {386A771C–E96A–421F–8BA7–32F1B706892F} (Installer Class) – http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_regular.cab
O16 – DPF: {3E339D3C–4B12–4E8C–A529–9CC4BEEAFD4F} (VacPro.russia_ver3) – http://www.advnt01.com/dialer/russia.CAB
O16 – DPF: {6414512B–B978–451D–A0D8–FCFDF33E833C} (WUWebControl Class) – http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093273663093
O16 – DPF: {91433D86–9F27–402C–B5E3–DEBDD122C339} – http://www.netvenda.com/sites/games–intl/pl/games4.cab
O16 – DPF: {9A9307A0–7DA4–4DAF–B042–5009F29E09E1} (ActiveScan Installer Class) – http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 – DPF: {9C691A33–7DDA–4C2F–BE4C–C176083F35CF} (brdg Class) – http://static.flingstone.com/cab/2000XP/CDTInc/bridge.cab
O16 – DPF: {9EB320CE–BE1D–4304–A081–4B4665414BEF} – http://www.mt–download.com/MediaTicketsInstaller.cab
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
O17 – HKLMSystemCCSServicesTcpip..{778F4757–7FB6–45DE–B697–095ADBB70263}: NameServer = 194.204.152.34 217.98.63.164


i cioo wy na to ?? PS. skąd y to wshystko wiecie ?? :wink:
dafnis
Dodano
27.11.2004 18:26:16
dafnis:
buuu kompletnie nic nie rozumiem a z tym logiem to jush wogóle, aha no i czytałam tamto Hijack This ale i tak zielono .... :(

Czego nie rozmiesz ??
Jak zrobic loga ??
Przeciez w bezpieczenstwie wszystko opisane w temacie o Hijack This

Sciagasz program z tad >> http://www.spychecker.com/program/hijackthis.html
Uruchamiasz, dajesz SCAN a pozniej SAVE LOG
Uruchamia Ci sie notatnik, kopiujesz tekst i wklejasz go do posta

Cala filozofia
Bobi
Dodano
27.11.2004 17:45:45
Przed logiem.

Antywirus i ad–aware 1.05,uaktualnić i scan.


http://dobreprogramy.com/index.php?dz=1&t=30
http://dobreprogramy.com/index.php?dz=2&id=107&t=55
http://skaner.mks.com.pl/
JNJN
Dodano
27.11.2004 16:24:11
Zapodaj log z Hijack This.
Małe Know How na temat tego narzędzia znajdziesz w dziale Bezpieczeństwo ( przyklejony temat ).
McScr@by
Dodano
27.11.2004 16:15:02
thx MC :D a niby jak mam shybciutko i dobrze doprowadzić to do porządku ??

tylko sie nie śmiać ze mnie plosem !! :D
dafnis
Dodano
27.11.2004 16:12:27
7 wartość klucza od dołu to bridge, do wywalenia.
BTW, maly bałagan masz w systemie, więc chyba trzeba postrzątać.
Trochę Malware zaległo się w systemie.
McScr@by
Dodano
27.11.2004 16:08:30
źebym o ja jeshcze wiedziała jak :p.... tak wystarczy ??

http://niunia_nadine.w.interia.pl/rej.bmp
dafnis
Dodano
27.11.2004 15:45:58
Hmm,

System się pluje a w Run nie ma brige.dll .
Troche dziwne, ale co tam.

Pokaź klucz HKEY LOCAL MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun
McScr@by
Dodano
27.11.2004 15:30:43
Odptasz to znaczy odznacz źeby pole przy tym wpisie w kwadracie było puste.
JNJN
Dodano
27.11.2004 15:30:38
hmmm... baaaardzo dziwne :P otuź nie znalazłam tego odptasz czy co to tam je :P ale za to było bridge i cio mam robić ?? :?: :roll:
dafnis
Dodano
27.11.2004 15:27:05
dafnis
Dodano:
27.11.2004 14:33:05
Komentarzy:
20
Strona 1 / 2