bardzo prosze o sprawdzenie tego loga

Logfile of HijackThis v1.99.1
Scan saved at 13:12:54, on 2005–03–04
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\vaio media music server\SSSvr.exe
C:\Program Files\sony\photo server 20\appsrv\PicAppSrv.exe
C:\Program Files\Common Files\sony shared\vaio media platform\SV_Httpd.exe
C:\Program Files\Common Files\sony shared\vaio media platform\UPnPFramework.exe
C:\Program Files\Common Files\Sony Shared\vaio media platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\vaio media platform\UPnPFramework.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Sony\HotKey Utility\HKserv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\atwtusb.exe
C:\WINDOWS\system32\pingppac.exe
C:\WINDOWS\system32\msusb32.exe
C:\WINDOWS\system32\scpuinit.exe
C:\WINDOWS\System32\gah95on6.exe
C:\WINDOWS\rphak.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Gadu–Gadu\gg.exe
C:\WINDOWS\system32\msusb32.exe
C:\WINDOWS\system32\safecr40.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\SAGEM\TalkTalk Broadband\dslmon.exe
C:\Program Files\Sony\HotKey Utility\HKWnd.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\dl1.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Tomasz\LOCALS~1\Temp\Rar$EX00.757\HijackThis.exe

R1 – HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://google.com
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.onet.pl/
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club–vaio.sony–europe.com/
O2 – BHO: (no name) – {53707962–6F74–2D53–2644–206D7942484F} – C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 – HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 – HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 – HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 – HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 – HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe
O4 – HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 – HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 – HKLM\..\Run: [atwtusb] atwtusb.exe beta
O4 – HKLM\..\Run: [PPPOEO] pingppac.exe
O4 – HKLM\..\Run: [MS USB 2.0 Windows Support] msusb32.exe
O4 – HKLM\..\Run: [antiware] C:\windows\system32\elitenca32.exe
O4 – HKLM\..\Run: [os8U3tX] scpuinit.exe
O4 – HKLM\..\Run: [gah95on6] C:\WINDOWS\System32\gah95on6.exe
O4 – HKLM\..\Run: [JUgCHcgPd] C:\WINDOWS\rphak.exe
O4 – HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 – HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 – HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe –startgui
O4 – HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 – HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 – HKLM\..\RunServices: [PPPOEO] pingppac.exe
O4 – HKLM\..\RunServices: [MS USB 2.0 Windows Support] msusb32.exe
O4 – HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 – HKCU\..\Run: [Gadu–Gadu] "C:\Program Files\Gadu–Gadu\gg.exe" /tray
O4 – HKCU\..\Run: [MS USB 2.0 Windows Support] msusb32.exe
O4 – HKCU\..\Run: [ZBr8Rjb2W] safecr40.exe
O4 – HKCU\..\Run: [BlockAds] "C:\Program Files\Tweak–XP Pro 3\AdBlocker.exe"
O4 – Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 – Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\TalkTalk Broadband\dslmon.exe
O4 – Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
O12 – Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O14 – IERESET.INF: START_PAGE_URL=http://www.club–vaio.sony–europe.com/
O15 – Trusted Zone: *.Sony–europe.com
O15 – Trusted Zone: *.Sonystyle–europe.com
O15 – Trusted Zone: *.Vaio–link.com
O16 – DPF: {17492023–C23A–453E–A040–C7C580BBF700} (Windows Genuine Advantage Validation Tool) – http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O17 – HKLM\System\CCS\Services\Tcpip\..\{E9989E27–567E–4235–AE9A–88931CEC2B97}: NameServer = 62.24.199.10 62.24.199.20
O23 – Service: Ati HotKey Poller – Unknown owner – C:\WINDOWS\System32\Ati2evxx.exe
O23 – Service: AVG7 Alert Manager Server (Avg7Alrt) – GRISOFT, s.r.o. – C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 – Service: AVG7 Update Service (Avg7UpdSvc) – GRISOFT, s.r.o. – C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 – Service: Symantec Event Manager (ccEvtMgr) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 – Service: Symantec Password Validation Service (ccPwdSvc) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 – Service: InCD Helper (InCDsrv) – AHEAD Software – C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 – Service: Norton AntiVirus Auto Protect Service (navapsvc) – Symantec Corporation – C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 – Service: ScriptBlocking Service (SBService) – Symantec Corporation – C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 – Service: Sygate Personal Firewall (SmcService) – Sygate Technologies, Inc. – C:\Program Files\Sygate\SPF\smc.exe
O23 – Service: Sony SPTI Service (SPTISRV) – Sony Corporation – C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 – Service: VAIO Media Music Server (Application) (VAIOMediaPlatform–MusicServer–AppServer) – Unknown owner – C:\Program Files\Sony\vaio media music server\SSSvr.exe" /Service=VAIOMediaPlatform–MusicServer–AppServer /DisplayName="VAIO Media Music Server (Application) (file missing)
O23 – Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform–MusicServer–HTTP) – Unknown owner – C:\Program Files\Common Files\Sony Shared\vaio media platform\sv_httpd.exe" /Service=VAIOMediaPlatform–MusicServer–HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 – Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform–MusicServer–UPnP) – Sony Corporation – C:\Program Files\Common Files\Sony Shared\vaio media platform\UPnPFramework.exe
O23 – Service: VAIO Media Photo Server (Application) (VAIOMediaPlatform–PhotoServer–AppServer) – Unknown owner – C:\Program Files\sony\photo server 20\appsrv\PicAppSrv.exe
O23 – Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform–PhotoServer–HTTP) – Unknown owner – C:\Program Files\Common Files\sony shared\vaio media platform\SV_Httpd.exe" /Service=VAIOMediaPlatform–PhotoServer–HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 – Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform–PhotoServer–UPnP) – Sony Corporation – C:\Program Files\Common Files\sony shared\vaio media platform\UPnPFramework.exe

tomek

Odpowiedzi: 5

serdeczne dzieki panowie za pomoc wszelaka:)
dontomeo
Dodano
04.03.2005 17:44:15
EL NINO:
najarales sie Bobik zes takiego przyspieszenia dostal ? :P

E *** tam najarałes... bo kibelka siem spiesze to tempo wieksze musiałem narzucic :mrgreen:
Bobi
Dodano
04.03.2005 16:59:45
Usuwasz:

C:\WINDOWS\system32\pingppac.exe
C:\WINDOWS\system32\msusb32.exe
C:\WINDOWS\system32\scpuinit.exe
C:\WINDOWS\System32\gah95on6.exe
C:\WINDOWS\rphak.exe
C:\WINDOWS\system32\msusb32.exe
C:\WINDOWS\system32\safecr40.exe

O4 – HKLM\..\Run: [PPPOEO] pingppac.exe
O4 – HKLM\..\Run: [MS USB 2.0 Windows Support] msusb32.exe
O4 – HKLM\..\Run: [antiware] C:\windows\system32\elitenca32.exe
O4 – HKLM\..\Run: [os8U3tX] scpuinit.exe
O4 – HKLM\..\Run: [gah95on6] C:\WINDOWS\System32\gah95on6.exe
O4 – HKLM\..\Run: [JUgCHcgPd] C:\WINDOWS\rphak.exe
O4 – HKLM\..\RunServices: [PPPOEO] pingppac.exe
O4 – HKLM\..\RunServices: [MS USB 2.0 Windows Support] msusb32.exe
O4 – HKCU\..\Run: [MS USB 2.0 Windows Support] msusb32.exe
O4 – HKCU\..\Run: [ZBr8Rjb2W] safecr40.exe


Co to jest ? Znasz to ?
c:\dl1.exe

Update:
najarales sie Bobik zes takiego przyspieszenia dostal ? :P
EL NINO
Dodano
04.03.2005 16:34:24
Wylacz przywracanie

Zakoncz procesy:
pingppac.exe
msusb32.exe
scpuinit.exe
gah95on6.exe
rphak.exe
msusb32.exe
safecr40.exe

Razem z plikami usuwasz:
O4 – HKLM\..\Run: [PPPOEO] pingppac.exe
O4 – HKLM\..\Run: [MS USB 2.0 Windows Support] msusb32.exe
O4 – HKLM\..\Run: [antiware] C:\windows\system32\elitenca32.exe
O4 – HKLM\..\Run: [os8U3tX] scpuinit.exe
O4 – HKLM\..\Run: [gah95on6] C:\WINDOWS\System32\gah95on6.exe
O4 – HKLM\..\Run: [JUgCHcgPd] C:\WINDOWS\rphak.exe
O4 – HKLM\..\RunServices: [PPPOEO] pingppac.exe
O4 – HKLM\..\RunServices: [MS USB 2.0 Windows Support] msusb32.exe
O4 – HKCU\..\Run: [MS USB 2.0 Windows Support] msusb32.exe
O4 – HKCU\..\Run: [ZBr8Rjb2W] safecr40.exe
O23 – Service: VAIO Media Music Server (Application) (VAIOMediaPlatform–MusicServer–AppServer) – Unknown owner – C:\Program Files\Sony\vaio media music server\SSSvr.exe" /Service=VAIOMediaPlatform–MusicServer–AppServer /DisplayName="VAIO Media Music Server (Application) (file missing)
O23 – Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform–MusicServer–HTTP) – Unknown owner – C:\Program Files\Common Files\Sony Shared\vaio media platform\sv_httpd.exe" /Service=VAIOMediaPlatform–MusicServer–HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 – Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform–PhotoServer–HTTP) – Unknown owner – C:\Program Files\Common Files\sony shared\vaio media platform\SV_Httpd.exe" /Service=VAIOMediaPlatform–PhotoServer–HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)


To pewnie prezeny od Sony:
O14 – IERESET.INF: START_PAGE_URL=http://www.club–vaio.sony–europe.com/
O15 – Trusted Zone: *.Sony–europe.com
O15 – Trusted Zone: *.Sonystyle–europe.com
O15 – Trusted Zone: *.Vaio–link.com


Powznie zastanawialbym sie nad kopnieciem w dupe AVG i zainstalowanie czegos innego

PS: @Piotr zonk.... zgubiłes Spybota
Bobi
Dodano
04.03.2005 16:33:16
kosz
O4 – HKLM\..\Run: [os8U3tX] scpuinit.exe
O4 – HKLM\..\Run: [gah95on6] C:\WINDOWS\System32\gah95on6.exe
O4 – HKLM\..\Run: [JUgCHcgPd] C:\WINDOWS\rphak.exe
O4 – HKLM\..\RunServices: [PPPOEO] pingppac.exe
O4 – HKLM\..\RunServices: [MS USB 2.0 Windows Support] msusb32.exe – tak jak niźej
O4 – HKLM\..\Run: [MS USB 2.0 Windows Support] msusb32.exe – nie jestem pewien bo taka końcówke ma

O4 – HKCU\..\Run: [ZBr8Rjb2W] safecr40.exe
O15 – Trusted Zone: *.Sony–europe.com
O15 – Trusted Zone: *.Sonystyle–europe.com
O15 – Trusted Zone: *.Vaio–link.com

te 015 jak sam dodałes to nie usuwaj
Anonymous
Dodano
04.03.2005 16:33:04
dontomeo
Dodano:
04.03.2005 16:14:35
Komentarzy:
5
Strona 1 / 1