I ja teź nieśmiało proszę o analizę loga

Oto ono:

Logfile of HijackThis v1.99.1
Scan saved at 22:35:08, on 2005–02–21
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesAheadInCDInCDsrv.exe
C:WINDOWSExplorer.EXE
C:Program FilesAheadInCDInCD.exe
C:WINDOWSsystem32UMonit2k.exe
C:Program FilesWinampWinampa.exe
C:PROGRA~1SoftwinBITDEF~1dmcon.exe
C:Program FilesSoftwinBitDefender8doesrv.exe
C:Program FilesSoftwinBitDefender8dswitch.exe
C:Program FilesLavasoftAd–Aware SE ProfessionalAd–Watch.exe
C:WINDOWSsystem32 undll32.exe
C:Program FilesDU MeterDUMeter.exe
C:Program FilesSkypePhoneSkype.exe
C:Program FilesGadu–Gadugg.exe
C:Program FilesGetRightgetright.exe
C:Program FilesInterVideoCommonBinWinCinemaMgr.exe
C:Program FilesGetRightgetright.exe
C:WINDOWSsystem32 vsvc32.exe
C:Program FilesCommon FilesSoftwinBitDefender Communicatorxcommsvr.exe
C:Program FilesCommon FilesSoftwinBitDefender Scan Serverdss.exe
C:Program FilesSoftwinBitDefender8vsserv.exe
C:Program FilesTC PowerPack otalcmd.exe
E:DownloadsHijackThis.exe

R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Microsoft Internet Explorer
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 5.0 CEReaderActiveXAcroIEHelper.ocx
O4 – HKLM..Run: [InCD] C:Program FilesAheadInCDInCD.exe
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [Gene USB Monitor] C:WINDOWSsystem32UMonit2k.exe
O4 – HKLM..Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 – HKLM..Run: [WinampAgent] "C:Program FilesWinampWinampa.exe"
O4 – HKLM..Run: [BDMCon] C:PROGRA~1SoftwinBITDEF~1dmcon.exe
O4 – HKLM..Run: [BDOESRV] C:Program FilesSoftwinBitDefender8\bdoesrv.exe
O4 – HKLM..Run: [BDNewsAgent] C:PROGRA~1SoftwinBITDEF~1dnagent.exe
O4 – HKLM..Run: [BDSwitchAgent] C:Program FilesSoftwinBitDefender8\bdswitch.exe
O4 – HKLM..Run: [AWMON] "C:Program FilesLavasoftAd–Aware SE ProfessionalAd–Watch.exe"
O4 – HKLM..Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 – HKLM..Run: [DU Meter] C:Program FilesDU MeterDUMeter.exe
O4 – HKCU..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /nosplash /minimized
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–GaduPowerGG.exe"
O4 – Global Startup: GetRight – Tray Icon.lnk = C:Program FilesGetRightgetright.exe
O4 – Global Startup: InterVideo WinCinema Manager.lnk = C:Program FilesInterVideoCommonBinWinCinemaMgr.exe
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O16 – DPF: {17492023–C23A–453E–A040–C7C580BBF700} (Windows Genuine Advantage Validation Tool) – http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O23 – Service: BitDefender Scan Server (bdss) – Unknown owner – C:Program FilesCommon FilesSoftwinBitDefender Scan Serverdss.exe" /service (file missing)
O23 – Service: InCD Helper (InCDsrv) – Nero AG – C:Program FilesAheadInCDInCDsrv.exe
O23 – Service: NVIDIA Display Driver Service (NVSvc) – NVIDIA Corporation – C:WINDOWSsystem32 vsvc32.exe
O23 – Service: BitDefender Virus Shield (VSSERV) – Unknown owner – C:Program FilesSoftwinBitDefender8vsserv.exe" /service (file missing)
O23 – Service: BitDefender Communicator (XCOMM) – Unknown owner – C:Program FilesCommon FilesSoftwinBitDefender Communicatorxcommsvr.exe" /service (file missing)

Odpowiedzi: 1

Dzięki
klamot
Dodano
21.02.2005 23:49:16
klamot
Dodano:
21.02.2005 23:40:32
Komentarzy:
1
Strona 1 / 1