Bardzo prosze o pomoc!!!! httpfilter.dll
Logfile of HijackThis v1.98.2
Scan saved at 19:39:45, on 2004–12–02
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:Program FilesGadu–Gadugg.exe
C:Program FilesKodakKodak EasyShare softwareinEasyShare.exe
C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe
C:WINDOWSsystem32driversKodakCCS.exe
C:Program FilesCommon FilesMicrosoft SharedVS7Debugmdm.exe
C:WINDOWSSystem32 vsvc32.exe
C:WINDOWSsystem32scagent.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32wuauclt.exe
D:HijackThis.exe
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.wp.pl/
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [SysMon] C:windowssystem32mswkkmi32.exe
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – Global Startup: Kodak EasyShare software.lnk = C:Program FilesKodakKodak EasyShare softwareinEasyShare.exe
O4 – Global Startup: Kodak software updater.lnk = C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe
O15 – Trusted Zone: http://*.frame.crazywinnings.com
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
O18 – Filter: text/html – {EE7A946E–61FA–4979–87B8–A6C462E6FA62} – C:WINDOWShttpfilter.dll
Pozdrawiam i z gory bardzo dziekuje
Filip
Scan saved at 19:39:45, on 2004–12–02
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:Program FilesGadu–Gadugg.exe
C:Program FilesKodakKodak EasyShare softwareinEasyShare.exe
C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe
C:WINDOWSsystem32driversKodakCCS.exe
C:Program FilesCommon FilesMicrosoft SharedVS7Debugmdm.exe
C:WINDOWSSystem32 vsvc32.exe
C:WINDOWSsystem32scagent.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32wuauclt.exe
D:HijackThis.exe
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.wp.pl/
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [SysMon] C:windowssystem32mswkkmi32.exe
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – Global Startup: Kodak EasyShare software.lnk = C:Program FilesKodakKodak EasyShare softwareinEasyShare.exe
O4 – Global Startup: Kodak software updater.lnk = C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe
O15 – Trusted Zone: http://*.frame.crazywinnings.com
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
O18 – Filter: text/html – {EE7A946E–61FA–4979–87B8–A6C462E6FA62} – C:WINDOWShttpfilter.dll
Pozdrawiam i z gory bardzo dziekuje
Filip
Odpowiedzi: 3
Zaznacz w HJ te wpisy i usun. Odpal komputer w awaryjnym i pozbadz sie tych plikow z dysku.
C:WINDOWSsystem32scagent.exe
O4 – HKLM..Run: [SysMon] C:windowssystem32mswkkmi32.exe
O15 – Trusted Zone: http://*.frame.crazywinnings.com
O18 – Filter: text/html – {EE7A946E–61FA–4979–87B8–A6C462E6FA62} – C:WINDOWShttpfilter.dll
C:WINDOWSsystem32scagent.exe
O4 – HKLM..Run: [SysMon] C:windowssystem32mswkkmi32.exe
O15 – Trusted Zone: http://*.frame.crazywinnings.com
O18 – Filter: text/html – {EE7A946E–61FA–4979–87B8–A6C462E6FA62} – C:WINDOWShttpfilter.dll
problem polega na tym ze jest sobie plik httpfilter.ddl ktory jest wirusem i nie da sie go usunac. I tyle......
Filip
Filip
I co z tego? Bo jakos nie zajarzylem :) Moze przedstawisz na czym problem polega ;)
Strona 1 / 1