Log [czy wszystko w porządku].

Logfile of HijackThis v1.99.1
Scan saved at 16:02:17, on 2005–02–24
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSSYSTEM32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:WINDOWSexplorer.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesAcronisSchedule2schedul2.exe
C:Program FilesAcronisTrueImageTrueImageMonitor.exe
C:Program FilesCommon FilesAcronisSchedule2schedhlp.exe
C:Program FilescFoscFosDNT.exe
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:Program FilesD–Toolsdaemon.exe
C:Program FilesAutoConnectAutoConnect.exe
C:Program FilesSAGEMSAGEM F@st 800–840dslmon.exe
C:Program FilesKaspersky LabKaspersky Anti–HackerKAVPF.exe
C:Program FilesRainlendarRainlendar.exe
C:PROGRA~1NORTON~1NORTON~1NPROTECT.EXE
C:WINDOWSSystem32 vsvc32.exe
C:PROGRA~1NORTON~1NORTON~1SPEEDD~1NOPDB.EXE
C:Program FilesCommon FilesSymantec SharedCCPD–LCsymlcsvc.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesSpyware Doctorswdoctor.exe
C:Documents and SettingsTATAMoje dokumentyTC PowerPack otalcmd.exe
D:TATAPROGRAMY [instalki]Winampwinampa.exe
D:TATATorrenty z Bit CometNowy folderHijackThis 1.99.1HijackThis.exe

R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.onet.pl/
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
R1 – HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = http://www.pandasoftware.com/redirector/?prod=103&app=Renewals〈=pol
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
F2 – REG:system.ini: Shell=explorer.exe
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – D:TATAPROGRAMY [instalki]Adobe ReaderReaderActiveXAcroIEHelper.dll
O2 – BHO: (no name) – {53707962–6F74–2D53–2644–206D7942484F} – C:Program FilesSpybot – Search & DestroySDHelper.dll
O2 – BHO: PCTools Site Guard – {5C8B2A36–3DB1–42A4–A3CB–D426709BBFEB} – C:PROGRA~1SPYWAR~1 oolsiesdsg.dll
O2 – BHO: PCTools Browser Monitor – {B56A7D7D–6927–48C8–A975–17DF180C71AC} – C:PROGRA~1SPYWAR~1 oolsiesdpb.dll
O4 – HKLM..Run: [Gainward] C:WINDOWSTBPanel.exe /A
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [Acronis True Image Monitor] "C:Program FilesAcronisTrueImageTrueImageMonitor.exe"
O4 – HKLM..Run: [Acronis Scheduler2 Service] "C:Program FilesCommon FilesAcronisSchedule2schedhlp.exe"
O4 – HKLM..Run: [cFosDNT] C:Program FilescFoscFosDNT.exe
O4 – HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 – HKLM..Run: [KAVPersonal50] C:Program FilesKaspersky LabKaspersky Anti–Virus Personalkav.exe /minimize
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [DAEMON Tools–1033] "C:Program FilesD–Toolsdaemon.exe" –lang 1033
O4 – HKLM..Run: [WinampAgent] D:TATAPROGRAMY [instalki]Winampwinampa.exe
O4 – HKCU..Run: [AutoConnect] C:Program FilesAutoConnectAutoConnect.exe
O4 – HKCU..Run: [Norton SystemWorks] "C:Program FilesNorton SystemWorkscfgwiz.exe" /GUID {05858CFD–5CC4–4ceb–AAAF–CF00BF39736A} /MODE CfgWiz
O4 – HKCU..Run: [Spyware Doctor] "C:Program FilesSpyware Doctorswdoctor.exe" /Q
O4 – Startup: Rainlendar.lnk = C:Program FilesRainlendarRainlendar.exe
O4 – Global Startup: DSLMON.lnk = C:Program FilesSAGEMSAGEM F@st 800–840dslmon.exe
O4 – Global Startup: Kaspersky Anti–Hacker.lnk = ?
O9 – Extra button: Spyware Doctor – {2D663D1A–8670–49D9–A1A5–4C56B4E14E84} – C:PROGRA~1SPYWAR~1 oolsiesdpb.dll
O17 – HKLMSystemCCSServicesTcpip..{50B9EAE3–9471–4CC7–8405–B7820955D7B3}: NameServer = 194.204.152.34 217.98.63.164
O23 – Service: Acronis Scheduler2 Service (AcrSch2Svc) – Acronis – C:Program FilesCommon FilesAcronisSchedule2schedul2.exe
O23 – Service: Symantec Event Manager (ccEvtMgr) – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
O23 – Service: Symantec Password Validation (ccPwdSvc) – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccPwdSvc.exe
O23 – Service: Symantec Settings Manager (ccSetMgr) – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
O23 – Service: kavsvc – Kaspersky Lab – C:Program FilesKaspersky LabKaspersky Anti–Virus Personalkavsvc.exe
O23 – Service: Norton Unerase Protection (NProtectService) – Symantec Corporation – C:PROGRA~1NORTON~1NORTON~1NPROTECT.EXE
O23 – Service: NVIDIA Driver Helper Service (NVSvc) – NVIDIA Corporation – C:WINDOWSSystem32 vsvc32.exe
O23 – Service: Speed Disk service – Symantec Corporation – C:PROGRA~1NORTON~1NORTON~1SPEEDD~1NOPDB.EXE
O23 – Service: Symantec Core LC – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedCCPD–LCsymlcsvc.exe


Czy mogę to usunąć?


R1 – HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = http://www.pandasoftware.com/redirector/?prod=103&app=Renewals〈=pol

Odpowiedzi: 5

Nie ma nic, ale zastanawia mnie ten R1. Pandy nie masz, co po kiego to tam ma byc ?
EL NINO
Dodano
25.02.2005 13:13:23
A teraz czy wszystko jest o.k. :oops:

Logfile of HijackThis v1.99.1
Scan saved at 07:31:48, on 2005–02–25
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSSYSTEM32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:Program FilesCommon FilesAcronisSchedule2schedul2.exe
C:WINDOWSExplorer.EXE
C:PROGRA~1NORTON~1NORTON~1NPROTECT.EXE
C:WINDOWSSystem32 vsvc32.exe
C:PROGRA~1NORTON~1NORTON~1SPEEDD~1NOPDB.EXE
C:Program FilesCommon FilesSymantec SharedCCPD–LCsymlcsvc.exe
C:Program FilesAcronisTrueImageTrueImageMonitor.exe
C:Program FilesCommon FilesAcronisSchedule2schedhlp.exe
C:Program FilescFoscFosDNT.exe
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:Program FilesD–Toolsdaemon.exe
C:Program FilesAutoConnectAutoConnect.exe
C:Program FilesSpyware Doctorswdoctor.exe
C:Program FilesSAGEMSAGEM F@st 800–840dslmon.exe
C:Program FilesKaspersky LabKaspersky Anti–HackerKAVPF.exe
C:Program FilesRainlendarRainlendar.exe
C:Program FilesMozilla Firefoxfirefox.exe
D:TATATorrenty z Bit CometNowy folderHijackThis 1.99.1HijackThis.exe

R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
R1 – HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = http://www.pandasoftware.com/redirector/?prod=103&app=Renewals&lang=pol
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – D:TATAPROGRAMY [instalki]Adobe ReaderReaderActiveXAcroIEHelper.dll
O2 – BHO: (no name) – {53707962–6F74–2D53–2644–206D7942484F} – C:Program FilesSpybot – Search & DestroySDHelper.dll
O2 – BHO: PCTools Site Guard – {5C8B2A36–3DB1–42A4–A3CB–D426709BBFEB} – C:PROGRA~1SPYWAR~1 oolsiesdsg.dll
O2 – BHO: PCTools Browser Monitor – {B56A7D7D–6927–48C8–A975–17DF180C71AC} – C:PROGRA~1SPYWAR~1 oolsiesdpb.dll
O4 – HKLM..Run: [Gainward] C:WINDOWSTBPanel.exe /A
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [Acronis True Image Monitor] "C:Program FilesAcronisTrueImageTrueImageMonitor.exe"
O4 – HKLM..Run: [Acronis Scheduler2 Service] "C:Program FilesCommon FilesAcronisSchedule2schedhlp.exe"
O4 – HKLM..Run: [cFosDNT] C:Program FilescFoscFosDNT.exe
O4 – HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 – HKLM..Run: [KAVPersonal50] C:Program FilesKaspersky LabKaspersky Anti–Virus Personalkav.exe /minimize
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [DAEMON Tools–1033] "C:Program FilesD–Toolsdaemon.exe" –lang 1033
O4 – HKCU..Run: [AutoConnect] C:Program FilesAutoConnectAutoConnect.exe
O4 – HKCU..Run: [Norton SystemWorks] "C:Program FilesNorton SystemWorkscfgwiz.exe" /GUID {05858CFD–5CC4–4ceb–AAAF–CF00BF39736A} /MODE CfgWiz
O4 – HKCU..Run: [Spyware Doctor] "C:Program FilesSpyware Doctorswdoctor.exe" /Q
O4 – Startup: Rainlendar.lnk = C:Program FilesRainlendarRainlendar.exe
O4 – Global Startup: DSLMON.lnk = C:Program FilesSAGEMSAGEM F@st 800–840dslmon.exe
O4 – Global Startup: Kaspersky Anti–Hacker.lnk = ?
O23 – Service: Acronis Scheduler2 Service (AcrSch2Svc) – Acronis – C:Program FilesCommon FilesAcronisSchedule2schedul2.exe
O23 – Service: Symantec Event Manager (ccEvtMgr) – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
O23 – Service: Symantec Password Validation (ccPwdSvc) – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccPwdSvc.exe
O23 – Service: Symantec Settings Manager (ccSetMgr) – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
O23 – Service: kavsvc – Kaspersky Lab – C:Program FilesKaspersky LabKaspersky Anti–Virus Personalkavsvc.exe
O23 – Service: Norton Unerase Protection (NProtectService) – Symantec Corporation – C:PROGRA~1NORTON~1NORTON~1NPROTECT.EXE
O23 – Service: NVIDIA Driver Helper Service (NVSvc) – NVIDIA Corporation – C:WINDOWSSystem32 vsvc32.exe
O23 – Service: Speed Disk service – Symantec Corporation – C:PROGRA~1NORTON~1NORTON~1SPEEDD~1NOPDB.EXE
O23 – Service: Symantec Core LC – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedCCPD–LCsymlcsvc.exe
JARO33
Dodano
25.02.2005 08:32:39
Mozesz, ale Analizator rozpoznal ten wpis jako Bezpieczny (Safe).
Zajmnij sie lepiej "Possibly nasty", gdyz analizator nie rozpoznal tych wpisów, byc moze sa one szkodliwe.
brtx
Dodano
25.02.2005 01:21:20
gusioo:
http://www.hijackthis.de/logfiles/5d70c987d7cdc485529a08e6e00b6a38.html


Moźe jednak lepiej po polsku. :oops: :oops:
JARO33
Dodano
24.02.2005 22:51:46
http://www.hijackthis.de/logfiles/5d70c987d7cdc485529a08e6e00b6a38.html
Anonymous
Dodano
24.02.2005 18:35:12
JARO33
Dodano:
24.02.2005 17:03:40
Komentarzy:
5
Strona 1 / 1