kolejna sprawa.....

program HijackThis znalazł mi tkaie coś:

Logfile of HijackThis v1.99.0
Scan saved at 08:45:04, on 2004–12–18
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:Program FilesWinamp3winampa.exe
C:Program FilesAVPersonalAVGNT.EXE
C:Program FilesJavaj2re1.4.2_06injusched.exe
C: empsalm.exe
C:Program FilesWindows ControlAdWinCtlAd.exe
C:WINDOWSSystem32ctfmon.exe
C:Program FilesWindows ControlAdWinCtlAdAlt.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesAVPersonalAVGUARD.EXE
C:Program FilesAVPersonalAVWUPSRV.EXE
C:WINDOWSSystem32 vsvc32.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesGadu–Gadugg.exe
C:WINDOWSsystem32SPs–.exe
C:Program FilesInternet ExplorerIEXPLORE.EXE
C:WINDOWSs–sy.exe
C:WINDOWSsystem32SPs–hhmsPE.exe
C:Program FilesOpera7opera.exe
C:Documents and SettingsAdministratorPulpitHijackThis.exe

R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://search–system.com/re.html
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 – BHO: Search Relevancy – {1D7E3B41–23CE–469B–BE1B–A64B877923E1} – C:PROGRA~1SEARCH~1SEARCH~1.DLL (file missing)
O2 – BHO: IeCatch2 Class – {A5366673–E8CA–11D3–9CD9–0090271D075B} – C:PROGRA~1FlashGetjccatch.dll
O2 – BHO: (no name) – {AA3922D4–7CED–C0BE–B03F–A20D1A6E4C72} – C:WINDOWSsystem32msadblock32.dll
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O3 – Toolbar: FlashGet Bar – {E0E899AB–F487–11D5–8D29–0050BA6940E3} – C:PROGRA~1FlashGetfgiebar.dll
O4 – HKLM..Run: [SiSSetCDfmt] C:WINDOWSSystem32SetCDfmt.exe
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 – HKLM..Run: [ScanRegistry] C:W
O4 – HKLM..Run: [WinampAgent] "C:Program FilesWinamp3winampa.exe"
O4 – HKLM..Run: [AVGCtrl] "C:Program FilesAVPersonalAVGNT.EXE" /min
O4 – HKLM..Run: [msadcheck] C:WINDOWSsystem32msadcheck32.exe
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_06injusched.exe
O4 – HKLM..Run: [WebRebates0] "C:Program FilesWeb_RebatesWebRebates0.exe"
O4 – HKLM..Run: [salm] c: empsalm.exe
O4 – HKLM..Run: [Windows ControlAd] C:Program FilesWindows ControlAdWinCtlAd.exe
O4 – HKLM..Run: [Onet.pl AutoUpdate] C:Program FilesCommon FilesOnet.plNewAutoUpdate.exe /tsr
O4 – HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 –k
O4 – HKLM..Run: [ImInstaller_IncrediMail] C:DOCUME~1ADMINI~1USTAWI~1TempImInstallerIncrediMailimloader.exe –startup –product IncrediMail
O4 – HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 – HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 – HKCU..Run: [msadcheck] C:WINDOWSsystem32msadcheck32.exe
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O8 – Extra context menu item: Ściągnij przy pomocy FlashGet'a – C:Program FilesFlashGetjc_link.htm
O8 – Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a – C:Program FilesFlashGetjc_all.htm
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:Program FilesJavaj2re1.4.2_06in pjpi142_06.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:Program FilesJavaj2re1.4.2_06in pjpi142_06.dll
O9 – Extra button: FlashGet – {D6E814A0–E0C5–11d4–8D29–0050BA6940E3} – C:PROGRA~1FlashGetflashget.exe
O9 – Extra 'Tools' menuitem: &FlashGet – {D6E814A0–E0C5–11d4–8D29–0050BA6940E3} – C:PROGRA~1FlashGetflashget.exe
O15 – Trusted Zone: http://*.windupdates.com
O15 – Trusted Zone: http://*.xxxtoolbar.com
O16 – DPF: {15AD4789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://public.windupdates.com/get_file.php?bt=ie&p=f1be8880edb636b73fa27f6fcd08fb5b519f70b1d9b8e268cd15c1774202686c5ab30a37623052f16aff2a1f6cefa5397ebb544431:e95763ddefb15e38c92daddcab541bee
O16 – DPF: {631FF594–EC25–4CFF–B869–402DF294E1D6} (Instalator oprogramowania Onet.pl) – http://slimak.onet.pl/_m/kamerzysta/OnetInstalator012s.ocx
O16 – DPF: {F00F4763–7355–4725–82F7–0DA94A256D46} (IncrediMail) – http://www5.incredimail.com/contents/setup/downloader_sp1/imloader.cab
O23 – Service: AntiVir Service – H+BEDV Datentechnik GmbH – C:Program FilesAVPersonalAVGUARD.EXE
O23 – Service: AntiVir Update – H+BEDV Datentechnik GmbH, Germany – C:Program FilesAVPersonalAVWUPSRV.EXE
O23 – Service: NVIDIA Driver Helper Service – NVIDIA Corporation – C:WINDOWSSystem32 vsvc32.exe

I CO Z TYM MAM ZROBIĆ ??

Odpowiedzi: 2

vacoss15 musze Cie niezle opitolic
Co co zakladasz az 3 tematy w tej samej sprawie
Nie mogles sie dopisac do tego ktory zalozyles na poczatku ??
Brzydki byl czy jak ??


Wylacz przywracanie

Zakoncz procesy:
WinCtlAd.exe
WinCtlAdAlt.exe
salm.exe
SPs–.exe
s–sy.exe
SPs–hhmsPE.exe


Wyszukujesz pliki/katalogi z loga ponizej i usuwasz je pozniej ptaszek i FIX:
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://search–system.com/re.html
O2 – BHO: Search Relevancy – {1D7E3B41–23CE–469B–BE1B–A64B877923E1} – C:PROGRA~1SEARCH~1SEARCH~1.DLL (file missing)
O2 – BHO: (no name) – {AA3922D4–7CED–C0BE–B03F–A20D1A6E4C72} – C:WINDOWSsystem32msadblock32.dll
O4 – HKLM..Run: [SiSSetCDfmt] C:WINDOWSSystem32SetCDfmt.exe
O4 – HKLM..Run: [ScanRegistry] C:W
O4 – HKLM..Run: [msadcheck] C:WINDOWSsystem32msadcheck32.exe
O4 – HKLM..Run: [WebRebates0] "C:Program FilesWeb_RebatesWebRebates0.exe"
O4 – HKLM..Run: [salm] c: empsalm.exe
O4 – HKLM..Run: [Windows ControlAd] C:Program FilesWindows ControlAdWinCtlAd.exe
O4 – HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 –k
O4 – HKCU..Run: [msadcheck] C:WINDOWSsystem32msadcheck32.exe
O15 – Trusted Zone: http://*.windupdates.com
O15 – Trusted Zone: http://*.xxxtoolbar.com
O16 – DPF: {15AD4789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://public.windupdates.com/get_file.php?bt=ie&p=f1be8880edb636b73fa27f6fcd08fb5b519f70b1d9b8e268cd15c1774202686c5ab30a37623052f16aff2a1f6cefa5397ebb544431:e95763ddefb15e38c92daddcab541bee

Tych plikow: SPs–.exe, s–sy.exe, SPs–hhmsPE.exe
tez sie pozbadz
Bobi
Dodano
18.12.2004 10:27:28
Przenosze do dzialu Bezpieczenstwo
Poz tym anlizator logow : http://www.hijackthis.de/en
brtx
Dodano
18.12.2004 10:25:47
vacoss15
Dodano:
18.12.2004 09:50:24
Komentarzy:
2
Strona 1 / 1