Czy moźecie przeananlizować wynik skanowania cwshreddera
Nie zrobię jeszcz eraz bo coś nie wyszło
Wolę zwrócić się o do specjalistów bo
mimo sprawdzalem w archiwum, to znalazłem tylko kilka podobnych wpisów więc do was się zwracam. Jak sam zacząłem kasować wszystko po koleii to musiałem reinstalować system. Zaraz spróbuję wkleić plik.
RUN: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
RUN: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
RUN: [nwiz] nwiz.exe /install
RUN: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
RUN: [GhostStartTrayApp] C:Program FilesNorton SystemWorksNorton GhostGhostStartTrayApp.exe
RUN: [AcctMgr] C:Program FilesNorton SystemWorksPassword ManagerAcctMgr.exe /startup
RUN: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" –atboottime
RUN: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
RUN: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NVMCTRAY.DLL,NvTaskbarInit
RUN: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
RUN: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
**** Browser Helper Objects ****
BHO: [AcroIEHlprObj Class] C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
BHO: [CNavExtBho Class] C:Program FilesNorton SystemWorksNorton AntivirusNavShExt.dll
BHO: [Cls] C:WINDOWSsystem32spm1316.dll
BHO: [Cls] C:WINDOWSsystem32wer1316.dll
**** IE Toolbars ****
TOOLBAR: [Norton AntiVirus] C:Program FilesNorton SystemWorksNorton AntivirusNavShExt.dll
**** IE Extensions ****
IEExt: [Messenger] C:Program FilesMessengermsmsgs.exe
**** Hosts File Entries ****
HOSTS: 127.0.0.1 localhost
HOSTS: 127.0.0.1 localhost
**** IE Settings ****
Default Page: http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default Search: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Local Page: C:WINDOWSsystem32lank.htm
Search Page: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
**** IE Context Menu (Right click) ****
IEContext: [E&ksport do programu Microsoft Excel] res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
**** Layered Service Providers ****
LSP: MSAFD Tcpip [TCP/IP]
LSP: MSAFD Tcpip [UDP/IP]
LSP: RSVP UDP Service Provider
LSP: RSVP TCP Service Provider
LSP: MSAFD NetBIOS [DeviceNetBT_Tcpip_{ED31122E–D350–4BE9–8D7B–F5ACDE0B3642}] SEQPACKET 3
LSP: MSAFD NetBIOS [DeviceNetBT_Tcpip_{ED31122E–D350–4BE9–8D7B–F5ACDE0B3642}] DATAGRAM 3
LSP: MSAFD NetBIOS [DeviceNetBT_Tcpip_{3481250B–7BFB–49A1–9F2B–0F97852A0139}] SEQPACKET 0
LSP: MSAFD NetBIOS [DeviceNetBT_Tcpip_{3481250B–7BFB–49A1–9F2B–0F97852A0139}] DATAGRAM 0
LSP: MSAFD NetBIOS [DeviceNetBT_Tcpip_{2BBCEA51–707A–4380–AA22–E00FB3A915F1}] SEQPACKET 1
LSP: MSAFD NetBIOS [DeviceNetBT_Tcpip_{2BBCEA51–707A–4380–AA22–E00FB3A915F1}] DATAGRAM 1
LSP: MSAFD NetBIOS [DeviceNetBT_Tcpip_{BFA531D6–008D–4473–AD7E–E16B50145987}] SEQPACKET 2
LSP: MSAFD NetBIOS [DeviceNetBT_Tcpip_{BFA531D6–008D–4473–AD7E–E16B50145987}] DATAGRAM 2
**** Blocked Control Panel Items ****
BLOCKED: [ncpa.cpl] No
BLOCKED: [odbccp32.cpl] No
**** Downloaded Program Files ****
DirectAnimation Java Classes [file://C:WINDOWSJavaclassesdajava.cab]
Microsoft XML Parser for Java [file://C:WINDOWSJavaclassesxmldso.cab]
**** Custom IE Search Items ****
SEARCH: [SearchAssistant] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
SEARCH: [CustomizeSearch] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
Wolę zwrócić się o do specjalistów bo
mimo sprawdzalem w archiwum, to znalazłem tylko kilka podobnych wpisów więc do was się zwracam. Jak sam zacząłem kasować wszystko po koleii to musiałem reinstalować system. Zaraz spróbuję wkleić plik.
RUN: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
RUN: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
RUN: [nwiz] nwiz.exe /install
RUN: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
RUN: [GhostStartTrayApp] C:Program FilesNorton SystemWorksNorton GhostGhostStartTrayApp.exe
RUN: [AcctMgr] C:Program FilesNorton SystemWorksPassword ManagerAcctMgr.exe /startup
RUN: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" –atboottime
RUN: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
RUN: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NVMCTRAY.DLL,NvTaskbarInit
RUN: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
RUN: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
**** Browser Helper Objects ****
BHO: [AcroIEHlprObj Class] C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
BHO: [CNavExtBho Class] C:Program FilesNorton SystemWorksNorton AntivirusNavShExt.dll
BHO: [Cls] C:WINDOWSsystem32spm1316.dll
BHO: [Cls] C:WINDOWSsystem32wer1316.dll
**** IE Toolbars ****
TOOLBAR: [Norton AntiVirus] C:Program FilesNorton SystemWorksNorton AntivirusNavShExt.dll
**** IE Extensions ****
IEExt: [Messenger] C:Program FilesMessengermsmsgs.exe
**** Hosts File Entries ****
HOSTS: 127.0.0.1 localhost
HOSTS: 127.0.0.1 localhost
**** IE Settings ****
Default Page: http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default Search: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Local Page: C:WINDOWSsystem32lank.htm
Search Page: http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
**** IE Context Menu (Right click) ****
IEContext: [E&ksport do programu Microsoft Excel] res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
**** Layered Service Providers ****
LSP: MSAFD Tcpip [TCP/IP]
LSP: MSAFD Tcpip [UDP/IP]
LSP: RSVP UDP Service Provider
LSP: RSVP TCP Service Provider
LSP: MSAFD NetBIOS [DeviceNetBT_Tcpip_{ED31122E–D350–4BE9–8D7B–F5ACDE0B3642}] SEQPACKET 3
LSP: MSAFD NetBIOS [DeviceNetBT_Tcpip_{ED31122E–D350–4BE9–8D7B–F5ACDE0B3642}] DATAGRAM 3
LSP: MSAFD NetBIOS [DeviceNetBT_Tcpip_{3481250B–7BFB–49A1–9F2B–0F97852A0139}] SEQPACKET 0
LSP: MSAFD NetBIOS [DeviceNetBT_Tcpip_{3481250B–7BFB–49A1–9F2B–0F97852A0139}] DATAGRAM 0
LSP: MSAFD NetBIOS [DeviceNetBT_Tcpip_{2BBCEA51–707A–4380–AA22–E00FB3A915F1}] SEQPACKET 1
LSP: MSAFD NetBIOS [DeviceNetBT_Tcpip_{2BBCEA51–707A–4380–AA22–E00FB3A915F1}] DATAGRAM 1
LSP: MSAFD NetBIOS [DeviceNetBT_Tcpip_{BFA531D6–008D–4473–AD7E–E16B50145987}] SEQPACKET 2
LSP: MSAFD NetBIOS [DeviceNetBT_Tcpip_{BFA531D6–008D–4473–AD7E–E16B50145987}] DATAGRAM 2
**** Blocked Control Panel Items ****
BLOCKED: [ncpa.cpl] No
BLOCKED: [odbccp32.cpl] No
**** Downloaded Program Files ****
DirectAnimation Java Classes [file://C:WINDOWSJavaclassesdajava.cab]
Microsoft XML Parser for Java [file://C:WINDOWSJavaclassesxmldso.cab]
**** Custom IE Search Items ****
SEARCH: [SearchAssistant] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
SEARCH: [CustomizeSearch] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
Odpowiedzi: 1
Wklej jeszcze log z HJT
Widac juz jakas z wersji Backdoor.Win32.Agent
BTW: Czemu nie w bezieczenstwie ??
Widac juz jakas z wersji Backdoor.Win32.Agent
C:WINDOWSsystem32spm1316.dll
C:WINDOWSsystem32wer1316.dll
BTW: Czemu nie w bezieczenstwie ??
Strona 1 / 1