Komp wysyla caly czas maile
Witam
Mam problem – moj komp wysyla caly czas maile
Oto log z hijacka:
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\skrzynka bogiego\skrzynka.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\wi32.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\alex\Pulpit\HijackThis.exe
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://onet.pl/
R3 – URLSearchHook: (no name) – {00000000–0000–0000–0000–000000000000} – (no file)
O2 – BHO: (no name) – {1543353E–4097–477B–8726–16B3564E6090} – C:\WINDOWS\system32\Q21894773.dll (file missing)
O2 – BHO: (no name) – {338FBC9A–0E37–4CFF–86B0–D6049C10C7F5} – C:\WINDOWS\system32\Q4032508.dll
O2 – BHO: (no name) – {53707962–6F74–2D53–2644–206D7942484F} – C:\Program Files\Spybot – Search & Destroy\SDHelper.dll
O2 – BHO: (no name) – {670BD572–0E01–41B5–BEF5–EC55F9BE29C1} – C:\WINDOWS\system32\Q4032508.dll
O2 – BHO: (no name) – {9C7932C1–C85D–49C9–AB70–EC1242A20CEB} – C:\WINDOWS\system32\Q21894773.dll (file missing)
O2 – BHO: (no name) – {AB10CF5A–0071–49FC–86CB–53E00B60B7EB} – C:\WINDOWS\system32\Q21894773.dll (file missing)
O2 – BHO: NAV Helper – {BDF3E430–B101–42AD–A544–FADC6B084872} – C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 – BHO: (no name) – {C1AD7F09–7A34–4459–9DCD–02765375FC12} – C:\WINDOWS\system32\spfhl.dll
O2 – BHO: (no name) – {C8A52F36–0F05–4996–BE13–44F37A3EF477} – C:\WINDOWS\system32\Q21894773.dll (file missing)
O2 – BHO: (no name) – {EF36A04C–3101–4341–8092–9750B2F867EC} – C:\WINDOWS\system32\Q21894773.dll (file missing)
O3 – Toolbar: Norton AntiVirus – {42CDD1BF–3FFB–4238–8AD1–7859DF00B1D6} – C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 – Toolbar: (no name) – {00000000–0000–0000–0000–000000000000} – (no file)
O4 – HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 – HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 – HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 – HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 – HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 – HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 – HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 – HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 – HKCU\..\Run: [skrzynka bogiego] C:\Program Files\skrzynka bogiego\skrzynka.exe
O4 – HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 – HKCU\..\Run: [StatusCheck] powerdll.exe
O4 – HKCU\..\Run: [atl_helper] StartCpl.exe
O4 – HKCU\..\Run: [wupd] C:\WINDOWS\system32\wi32.exe
O9 – Extra button: Search (HKLM)
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Prosze o pomoc i z gory dziekuje
Mam problem – moj komp wysyla caly czas maile
Oto log z hijacka:
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\skrzynka bogiego\skrzynka.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\wi32.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\alex\Pulpit\HijackThis.exe
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://onet.pl/
R3 – URLSearchHook: (no name) – {00000000–0000–0000–0000–000000000000} – (no file)
O2 – BHO: (no name) – {1543353E–4097–477B–8726–16B3564E6090} – C:\WINDOWS\system32\Q21894773.dll (file missing)
O2 – BHO: (no name) – {338FBC9A–0E37–4CFF–86B0–D6049C10C7F5} – C:\WINDOWS\system32\Q4032508.dll
O2 – BHO: (no name) – {53707962–6F74–2D53–2644–206D7942484F} – C:\Program Files\Spybot – Search & Destroy\SDHelper.dll
O2 – BHO: (no name) – {670BD572–0E01–41B5–BEF5–EC55F9BE29C1} – C:\WINDOWS\system32\Q4032508.dll
O2 – BHO: (no name) – {9C7932C1–C85D–49C9–AB70–EC1242A20CEB} – C:\WINDOWS\system32\Q21894773.dll (file missing)
O2 – BHO: (no name) – {AB10CF5A–0071–49FC–86CB–53E00B60B7EB} – C:\WINDOWS\system32\Q21894773.dll (file missing)
O2 – BHO: NAV Helper – {BDF3E430–B101–42AD–A544–FADC6B084872} – C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 – BHO: (no name) – {C1AD7F09–7A34–4459–9DCD–02765375FC12} – C:\WINDOWS\system32\spfhl.dll
O2 – BHO: (no name) – {C8A52F36–0F05–4996–BE13–44F37A3EF477} – C:\WINDOWS\system32\Q21894773.dll (file missing)
O2 – BHO: (no name) – {EF36A04C–3101–4341–8092–9750B2F867EC} – C:\WINDOWS\system32\Q21894773.dll (file missing)
O3 – Toolbar: Norton AntiVirus – {42CDD1BF–3FFB–4238–8AD1–7859DF00B1D6} – C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 – Toolbar: (no name) – {00000000–0000–0000–0000–000000000000} – (no file)
O4 – HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 – HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 – HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 – HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 – HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 – HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 – HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 – HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 – HKCU\..\Run: [skrzynka bogiego] C:\Program Files\skrzynka bogiego\skrzynka.exe
O4 – HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 – HKCU\..\Run: [StatusCheck] powerdll.exe
O4 – HKCU\..\Run: [atl_helper] StartCpl.exe
O4 – HKCU\..\Run: [wupd] C:\WINDOWS\system32\wi32.exe
O9 – Extra button: Search (HKLM)
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Prosze o pomoc i z gory dziekuje
Odpowiedzi: 3
dziala
Chyle czola !
Chyle czola !
Tego sie pozbadz:
C:\WINDOWS\system32\wi32.exe
R3 – URLSearchHook: (no name) – {00000000–0000–0000–0000–000000000000} – (no file)
O2 – BHO: (no name) – {1543353E–4097–477B–8726–16B3564E6090} – C:\WINDOWS\system32\Q21894773.dll (file missing)
O2 – BHO: (no name) – {338FBC9A–0E37–4CFF–86B0–D6049C10C7F5} – C:\WINDOWS\system32\Q4032508.dll
O2 – BHO: (no name) – {670BD572–0E01–41B5–BEF5–EC55F9BE29C1} – C:\WINDOWS\system32\Q4032508.dll
O2 – BHO: (no name) – {9C7932C1–C85D–49C9–AB70–EC1242A20CEB} – C:\WINDOWS\system32\Q21894773.dll (file missing)
O2 – BHO: (no name) – {AB10CF5A–0071–49FC–86CB–53E00B60B7EB} – C:\WINDOWS\system32\Q21894773.dll (file missing)
O2 – BHO: (no name) – {C1AD7F09–7A34–4459–9DCD–02765375FC12} – C:\WINDOWS\system32\spfhl.dll
O2 – BHO: (no name) – {C8A52F36–0F05–4996–BE13–44F37A3EF477} – C:\WINDOWS\system32\Q21894773.dll (file missing)
O2 – BHO: (no name) – {EF36A04C–3101–4341–8092–9750B2F867EC} – C:\WINDOWS\system32\Q21894773.dll (file missing)
O3 – Toolbar: (no name) – {00000000–0000–0000–0000–000000000000} – (no file)
O4 – HKCU\..\Run: [StatusCheck] powerdll.exe
O4 – HKCU\..\Run: [atl_helper] StartCpl.exe
O4 – HKCU\..\Run: [wupd] C:\WINDOWS\system32\wi32.exe
Taka to raczej srednia odpowiedz – bo antywirusa nortona wlaczonego mam, a jaki anty– spy by mi konkretnie pomogl nie napisales.
Jak rowniez ktory wpis w rejestrze mi to powoduje – tez nie wiem
Jak rowniez ktory wpis w rejestrze mi to powoduje – tez nie wiem
Strona 1 / 1