Co w logu piszczy
Rzućcie na to profesjonalnym oczkiem:
Po wrzuceniu go do analizatora na tej stronie zapluł się na kilka rzeczy (possible nasty):
Poza tym:
––>If the entry 'E&ksport do programu Microsoft Excel ' is not needed anymore, it should be fixed.
–––>If the entry '' is not needed anymore, it should be fixed.
–––>If the entry 'Sun Java Console ' is not needed anymore, it should be fixed.
–––>To be fixed if the entry 'Badanie ' is unknown.
Czy ja mogę fixnąć te rzeczy, na które on się pluje? Co to w ogóle jest?
Acha i jeszcze napisane jest, źe:
–––>Not dangerous, but unnecessary. (co to jest?)
–––>Not dangerous, but unnecessary.
Logfile of HijackThis v1.99.1
Scan saved at 17:01:38, on 2005–02–22
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSSystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe
C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exe
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesAutodesk SharedServiceAdskScSrv.exe
C:Program FilesKerioPersonal Firewall 4kpf4ss.exe
C:Program FilesNorton AntiVirus avapsvc.exe
C:Program FilesNorton AntiVirusIWPNPFMntor.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedCCPD–LCsymlcsvc.exe
C:Program FilesKerioPersonal Firewall 4kpf4gui.exe
C:WINDOWSSystem32Tablet.exe
C:WINDOWSSystem32MsPMSPSv.exe
C:Program FilesKerioPersonal Firewall 4kpf4gui.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:Program FilesCreativeSBAudigy2ZSSurround MixerCTSysVol.exe
C:Program FilesJavajre1.5.0_01injusched.exe
C:Program FilesTlen.pl len.exe
C:Program FilesSAGEMSAGEM F@st 800–840dslmon.exe
C:PROGRA~1MOZILL~2THUNDE~1.EXE
E:Programyhijackthis_199HijackThis.exe
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 – BHO: NAV Helper – {BDF3E430–B101–42AD–A544–FADC6B084872} – C:Program FilesNorton AntiVirusNavShExt.dll
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O3 – Toolbar: Norton AntiVirus – {42CDD1BF–3FFB–4238–8AD1–7859DF00B1D6} – C:Program FilesNorton AntiVirusNavShExt.dll
O4 – HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 – HKLM..Run: [SSC_UserPrompt] C:Program FilesCommon FilesSymantec SharedSecurity CenterUsrPrmpt.exe
O4 – HKLM..Run: [Symantec NetDriver Monitor] C:PROGRA~1SYMNET~1SNDMon.exe
O4 – HKLM..Run: [CTSysVol] C:Program FilesCreativeSBAudigy2ZSSurround MixerCTSysVol.exe /r
O4 – HKLM..Run: [SBDrvDet] C:Program FilesCreativeSB Drive DetSBDrvDet.exe /r
O4 – HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
O4 – HKLM..Run: [BootSkin Startup Jobs] "C:Program FilesStardockWinCustomizeBootSkinBootSkin.exe" /StartupJobs
O4 – HKLM..Run: [TkBellExe] "C:Program FilesCommon FilesRealUpdate_OB ealsched.exe" –osboot
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavajre1.5.0_01injusched.exe
O4 – HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" –atboottime
O4 – HKLM..RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:WINDOWSSystem32sti_ci.dll,WiaCreateWizardMenu
O4 – HKCU..Run: [Komunikator] C:Program FilesTlen.pl len.exe
O4 – Global Startup: DSLMON.lnk = C:Program FilesSAGEMSAGEM F@st 800–840dslmon.exe
O4 – Global Startup: Adobe Gamma Loader.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O4 – Global Startup: Adobe Reader Speed Launch.lnk = C:Program FilesAdobeAcrobat 7.0Reader eader_sl.exe
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:Program FilesJavajre1.5.0_01in pjpi150_01.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:Program FilesJavajre1.5.0_01in pjpi150_01.dll
O9 – Extra button: Badanie – {92780B25–18CC–41C8–B9BE–3C9C571A8263} – C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O16 – DPF: {31B7EB4E–8B4B–11D1–A789–00A0CC6651A8} (Cult3D ActiveX Player) – http://www.cult3d.com/download/cult.cab
O16 – DPF: {C5E28B9D–0A68–4B50–94E9–E8F6B4697514} (NsvPlayX Control) – http://www.vibesman.pwp.blueyonder.co.uk/nsvplayx_vp3_mp3.cab
O17 – HKLMSystemCCSServicesTcpip..{88C0A27A–6D7D–4CFD–9CB6–489D15408EAA}: NameServer = 194.204.152.34 217.98.63.164
O17 – HKLMSystemCCSServicesTcpip..{9AEDF4C8–B1C0–42D6–B2DE–F4DA193C2ECE}: NameServer = 194.204.159.1,194.204.152.34
O23 – Service: Adobe LM Service – Unknown owner – C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe
O23 – Service: Ati HotKey Poller – Unknown owner – C:WINDOWSSystem32Ati2evxx.exe
O23 – Service: ATI Smart – Unknown owner – C:WINDOWSsystem32ati2sgag.exe
O23 – Service: Autodesk Licensing Service – Unknown owner – C:Program FilesCommon FilesAutodesk SharedServiceAdskScSrv.exe
O23 – Service: Symantec Event Manager (ccEvtMgr) – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
O23 – Service: Symantec Password Validation (ccPwdSvc) – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccPwdSvc.exe
O23 – Service: Symantec Settings Manager (ccSetMgr) – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
O23 – Service: Kerio Personal Firewall 4 (KPF4) – Kerio Technologies – C:Program FilesKerioPersonal Firewall 4kpf4ss.exe
O23 – Service: Macromedia Licensing Service – Unknown owner – C:Program FilesCommon FilesMacromedia SharedServiceMacromedia Licensing.exe
O23 – Service: Norton AntiVirus Auto–Protect Service (navapsvc) – Symantec Corporation – C:Program FilesNorton AntiVirus avapsvc.exe
O23 – Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) – Symantec Corporation – C:Program FilesNorton AntiVirusIWPNPFMntor.exe
O23 – Service: SAVScan – Symantec Corporation – C:Program FilesNorton AntiVirusSAVScan.exe
O23 – Service: ScriptBlocking Service (SBService) – Symantec Corporation – C:PROGRA~1COMMON~1SYMANT~1SCRIPT~1SBServ.exe
O23 – Service: Symantec Network Drivers Service (SNDSrvc) – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe
O23 – Service: Symantec SPBBCSvc (SPBBCSvc) – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exe
O23 – Service: Symantec Core LC – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedCCPD–LCsymlcsvc.exe
O23 – Service: TabletService – Wacom Technology, Corp. – C:WINDOWSSystem32Tablet.exe
Po wrzuceniu go do analizatora na tej stronie zapluł się na kilka rzeczy (possible nasty):
C:Program FilesCommon FilesAutodesk SharedServiceAdskScSrv.exe
O4 – HKLM..RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:WINDOWSSystem32sti_ci.dll,WiaCreateWizardMenu
O9 – Extra button: Badanie – {92780B25–18CC–41C8–B9BE–3C9C571A8263} – C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
Poza tym:
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
––>If the entry 'E&ksport do programu Microsoft Excel ' is not needed anymore, it should be fixed.
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:Program FilesJavajre1.5.0_01in pjpi150_01.dll
–––>If the entry '' is not needed anymore, it should be fixed.
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:Program FilesJavajre1.5.0_01in pjpi150_01.dll
–––>If the entry 'Sun Java Console ' is not needed anymore, it should be fixed.
O9 – Extra button: Badanie – {92780B25–18CC–41C8–B9BE–3C9C571A8263} – C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
–––>To be fixed if the entry 'Badanie ' is unknown.
Czy ja mogę fixnąć te rzeczy, na które on się pluje? Co to w ogóle jest?
Acha i jeszcze napisane jest, źe:
O4 – HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
–––>Not dangerous, but unnecessary. (co to jest?)
O4 – HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" –atboottime
–––>Not dangerous, but unnecessary.
Odpowiedzi: 1
Masz czysto. Te wpisy to od Autodeska przez jakas kamere po Creative.
Strona 1 / 1