Jak wleic loga z Hi Jacka
Wyskakuje mi info źe rozszeźenie pliku jest nieprawidłowe, o co chodzi.Nie wiem jak go wysłac na forum.
Odpowiedzi: 4
Powylaczaj procesy drwtsn32.exe
To: O2 – BHO: BrowserHelper Class – {EBCDDA60–2A68–11D3–8A43–0060083CFB9C} – C:WINDOWSsystem32 zdd.dl
Zostaw
To: O2 – BHO: BrowserHelper Class – {EBCDDA60–2A68–11D3–8A43–0060083CFB9C} – C:WINDOWSsystem32 zdd.dl
Zostaw
O2 – BHO: BrowserHelper Class – {EBCDDA60–2A68–11D3–8A43–0060083CFB9C} – C:WINDOWSsystem32
zdd.dl Fix
Ogolnie jest ok
Poprosze o sprawdzenie i instrukcje co jak mam zrobić z góry dziękuje.
Logfile of HijackThis v1.99.0
Scan saved at 18:10:14, on 2005–01–19
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:Program FilesNorton Internet SecurityNISUM.EXE
C:Program FilesNorton Internet SecurityccPxySvc.exe
C:Program FilesNorton AntiVirus avapsvc.exe
C:WINDOWSsystem32 vsvc32.exe
C:Program FilesAnalog DevicesSoundMAXSMAgent.exe
C:Program FilesCommon FilesSymantec SharedSecurity CenterSymWSC.exe
C:Program FilesAnalog DevicesSoundMAXSMax4PNP.exe
C:Program FilesAnalog DevicesSoundMAXSmax4.exe
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:Program FilesJavaj2re1.4.2_05injusched.exe
C:Program FilesD–Toolsdaemon.exe
C:WINDOWSsystem32RUNDLL32.EXE
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:Program FilesGadu–Gadugg.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSexplorer.exe
C:WINDOWSsystem32drwtsn32.exe
F:Nowy folderFILMYV Player i Bestplayer 1,0vlc–0.8.1 SVCDvlc.exe
C:WINDOWSsystem32wisptis.exe
C:Program FilesInternet Exploreriexplore.exe
C:Documents and Settingsp4PulpitHijackThis.exe
C:Program FilesInternet Exploreriexplore.exe
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.interia.pl/
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 – BHO: NAV Helper – {BDF3E430–B101–42AD–A544–FADC6B084872} – C:Program FilesNorton AntiVirusNavShExt.dll
O2 – BHO: BrowserHelper Class – {EBCDDA60–2A68–11D3–8A43–0060083CFB9C} – C:WINDOWSsystem32 zdd.dll
O3 – Toolbar: Norton AntiVirus – {42CDD1BF–3FFB–4238–8AD1–7859DF00B1D6} – C:Program FilesNorton AntiVirusNavShExt.dll
O4 – HKLM..Run: [SoundMAXPnP] C:Program FilesAnalog DevicesSoundMAXSMax4PNP.exe
O4 – HKLM..Run: [SoundMAX] "C:Program FilesAnalog DevicesSoundMAXSmax4.exe" /tray
O4 – HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 – HKLM..Run: [ccRegVfy] "C:Program FilesCommon FilesSymantec SharedccRegVfy.exe"
O4 – HKLM..Run: [Symantec NetDriver Monitor] C:PROGRA~1SYMNET~1SNDMon.exe
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_05injusched.exe
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [DAEMON Tools–1033] "C:Program FilesD–Toolsdaemon.exe" –lang 1033
O4 – HKLM..Run: [THGuard] "F:TrojanHunter 4.1THGuard.exe"
O4 – HKCU..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NVMCTRAY.DLL,NvTaskbarInit
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – HKCU..Run: [C:Program FilesNetMeterNetMeter.exe] C:Program FilesNetMeterNetMeter.exe
O4 – Global Startup: Adobe Gamma Loader.exe.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O4 – Global Startup: RealDownload.lnk = C:Program FilesRealDownloadRealdownload.exe
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O8 – Extra context menu item: Pobierz z &BitSpirit
– C:Program FilesBitSpiritsurl.htm
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:WINDOWSsystem32msjava.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:WINDOWSsystem32msjava.dll
O9 – Extra button: Badanie – {92780B25–18CC–41C8–B9BE–3C9C571A8263} – C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O23 – Service: Symantec Event Manager – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
O23 – Service: Symantec Password Validation Service – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccPwdSvc.exe
O23 – Service: Symantec Proxy Service – Symantec Corporation – C:Program FilesNorton Internet SecurityccPxySvc.exe
O23 – Service: Usługa Auto–Protect w programie Norton AntiVirus – Symantec Corporation – C:Program FilesNorton AntiVirus avapsvc.exe
O23 – Service: Norton Internet Security Accounts Manager – Symantec Corporation – C:Program FilesNorton Internet SecurityNISUM.EXE
O23 – Service: NVIDIA Display Driver Service – NVIDIA Corporation – C:WINDOWSsystem32 vsvc32.exe
O23 – Service: ScriptBlocking Service – Symantec Corporation – C:PROGRA~1COMMON~1SYMANT~1SCRIPT~1SBServ.exe
O23 – Service: Symantec Network Drivers Service – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe
O23 – Service: SoundMAX Agent Service – Analog Devices, Inc. – C:Program FilesAnalog DevicesSoundMAXSMAgent.exe
O23 – Service: SymWMI Service – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedSecurity CenterSymWSC.exe
Logfile of HijackThis v1.99.0
Scan saved at 18:10:14, on 2005–01–19
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:Program FilesNorton Internet SecurityNISUM.EXE
C:Program FilesNorton Internet SecurityccPxySvc.exe
C:Program FilesNorton AntiVirus avapsvc.exe
C:WINDOWSsystem32 vsvc32.exe
C:Program FilesAnalog DevicesSoundMAXSMAgent.exe
C:Program FilesCommon FilesSymantec SharedSecurity CenterSymWSC.exe
C:Program FilesAnalog DevicesSoundMAXSMax4PNP.exe
C:Program FilesAnalog DevicesSoundMAXSmax4.exe
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:Program FilesJavaj2re1.4.2_05injusched.exe
C:Program FilesD–Toolsdaemon.exe
C:WINDOWSsystem32RUNDLL32.EXE
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:Program FilesGadu–Gadugg.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSsystem32drwtsn32.exe
C:WINDOWSexplorer.exe
C:WINDOWSsystem32drwtsn32.exe
F:Nowy folderFILMYV Player i Bestplayer 1,0vlc–0.8.1 SVCDvlc.exe
C:WINDOWSsystem32wisptis.exe
C:Program FilesInternet Exploreriexplore.exe
C:Documents and Settingsp4PulpitHijackThis.exe
C:Program FilesInternet Exploreriexplore.exe
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.interia.pl/
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 – BHO: NAV Helper – {BDF3E430–B101–42AD–A544–FADC6B084872} – C:Program FilesNorton AntiVirusNavShExt.dll
O2 – BHO: BrowserHelper Class – {EBCDDA60–2A68–11D3–8A43–0060083CFB9C} – C:WINDOWSsystem32 zdd.dll
O3 – Toolbar: Norton AntiVirus – {42CDD1BF–3FFB–4238–8AD1–7859DF00B1D6} – C:Program FilesNorton AntiVirusNavShExt.dll
O4 – HKLM..Run: [SoundMAXPnP] C:Program FilesAnalog DevicesSoundMAXSMax4PNP.exe
O4 – HKLM..Run: [SoundMAX] "C:Program FilesAnalog DevicesSoundMAXSmax4.exe" /tray
O4 – HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 – HKLM..Run: [ccRegVfy] "C:Program FilesCommon FilesSymantec SharedccRegVfy.exe"
O4 – HKLM..Run: [Symantec NetDriver Monitor] C:PROGRA~1SYMNET~1SNDMon.exe
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_05injusched.exe
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [DAEMON Tools–1033] "C:Program FilesD–Toolsdaemon.exe" –lang 1033
O4 – HKLM..Run: [THGuard] "F:TrojanHunter 4.1THGuard.exe"
O4 – HKCU..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NVMCTRAY.DLL,NvTaskbarInit
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – HKCU..Run: [C:Program FilesNetMeterNetMeter.exe] C:Program FilesNetMeterNetMeter.exe
O4 – Global Startup: Adobe Gamma Loader.exe.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O4 – Global Startup: RealDownload.lnk = C:Program FilesRealDownloadRealdownload.exe
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O8 – Extra context menu item: Pobierz z &BitSpirit
– C:Program FilesBitSpiritsurl.htm
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:WINDOWSsystem32msjava.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:WINDOWSsystem32msjava.dll
O9 – Extra button: Badanie – {92780B25–18CC–41C8–B9BE–3C9C571A8263} – C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O10 – Unknown file in Winsock LSP: c:windowssystem32ua_lsp.dll
O23 – Service: Symantec Event Manager – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
O23 – Service: Symantec Password Validation Service – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccPwdSvc.exe
O23 – Service: Symantec Proxy Service – Symantec Corporation – C:Program FilesNorton Internet SecurityccPxySvc.exe
O23 – Service: Usługa Auto–Protect w programie Norton AntiVirus – Symantec Corporation – C:Program FilesNorton AntiVirus avapsvc.exe
O23 – Service: Norton Internet Security Accounts Manager – Symantec Corporation – C:Program FilesNorton Internet SecurityNISUM.EXE
O23 – Service: NVIDIA Display Driver Service – NVIDIA Corporation – C:WINDOWSsystem32 vsvc32.exe
O23 – Service: ScriptBlocking Service – Symantec Corporation – C:PROGRA~1COMMON~1SYMANT~1SCRIPT~1SBServ.exe
O23 – Service: Symantec Network Drivers Service – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe
O23 – Service: SoundMAX Agent Service – Analog Devices, Inc. – C:Program FilesAnalog DevicesSoundMAXSMAgent.exe
O23 – Service: SymWMI Service – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedSecurity CenterSymWSC.exe
Strona 1 / 1