Log hijackthis.. znowu jakis rundll

hmm witam, po formacie znowu jakieś ustrojstwo się chyba dorwało.. rundll.exe, a jak :roll:

Logfile of HijackThis v1.99.1
Scan saved at 10:58:10, on 2005–04–09
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
D:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe
D:\Program Files\Registry Defragmentation\RegManServ.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\Microsoft AntiSpyware\gcasServ.exe
D:\Program Files\SurfControl\CyberPatrol\cphq.exe
C:\WINDOWS\system32\RUNDLL32.EXE
D:\Program Files\MWSnap\MWSnap.exe
D:\Program Files\ktr\ktr.exe
C:\Program Files\PLANET\WL–8303\RtlWake.exe
C:\Program Files\Miranda IM\miranda32.exe
D:\Program Files\SurfControl\CyberPatrol\cpserver.exe
D:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
D:\Program Files\SurfControl\CyberPatrol\cpACtrl.exe
D:\Program Files\SurfControl\CyberPatrol\cpCCtrl.exe
D:\Program Files\SurfControl\CyberPatrol\cpkbinst.exe
C:\WINDOWS\system32\wscntfy.exe
D:\PROGRA~1\FIREFOX\FIREFOX.EXE
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
D:\Program Files\TGTSoft\StyleBuilder\StyleBuilder.exe
D:\Program Files\IrfanView\i_view32.exe
D:\Program Files\WinRAR\WinRAR.exe
C:\Documents and Settings\Home\Moje dokumenty\HijackThis\HijackThis.exe

R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.pl
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://onet.pl
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.pl
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://onet.pl
R1 – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.10.11.254:8080
R0 – HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 – URLSearchHook: (no name) – {00A6FAF6–072E–44cf–8957–5838F569A31D} – C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 – BHO: MyWebSearch Search Assistant BHO – {00A6FAF1–072E–44cf–8957–5838F569A31D} – C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 – BHO: mwsBar BHO – {07B18EA1–A523–4961–B6BB–170DE4475CCA} – C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 – BHO: Idea2 SidebarBrowserMonitor Class – {45AD732C–2CE2–4666–B366–B2214AD57A49} – D:\Program Files\Desktop Sidebar\sbhelp.dll
O2 – BHO: TGTSoft Explorer Toolbar Changer – {C333CF63–767F–4831–94AC–E683D962C63C} – C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O4 – HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 – HKLM\..\Run: [gcasServ] "D:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 – HKLM\..\Run: [Outpost Firewall] D:\Program Files\Agnitum\Outpost Firewall\outpost.exe /waitservice
O4 – HKLM\..\Run: [CyberPatrolNew] "D:\Program Files\SurfControl\CyberPatrol\cphq.exe" /m
O4 – HKLM\..\Run: [nwiz] nwiz.exe /install
O4 – HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 – HKCU\..\Run: [MWSnap] "D:\Program Files\MWSnap\MWSnap.exe"
O4 – HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe –Hide
O4 – HKCU\..\Run: [ktr] D:\Program Files\ktr\ktr.exe
O4 – Startup: Miranda IM.lnk = C:\Program Files\Miranda IM\miranda32.exe
O4 – Global Startup: PLANET WL–8303.lnk = ?
O8 – Extra context menu item: &Search – http://bar.mywebsearch.com/menusearch.html?p=ZS
O8 – Extra context menu item: Subscribe in Desktop Sidebar – res://D:\Program Files\Desktop Sidebar\sbhelp.dll/menuhandler.html
O8 – Extra context menu item: Ściągnij przy pomocy FlashGet'a – D:\Program Files\FlashGet\jc_link.htm
O8 – Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a – D:\Program Files\FlashGet\jc_all.htm
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 – Extra button: Subscribe in Desktop Sidebar – {09FE188B–6E85–479e–9411–51FB2220DF80} – D:\Program Files\Desktop Sidebar\sbhelp.dll
O9 – Extra 'Tools' menuitem: Subscribe in Desktop Sidebar – {09FE188B–6E85–479e–9411–51FB2220DF80} – D:\Program Files\Desktop Sidebar\sbhelp.dll
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 – Extra button: Trashcan – {072F3B8A–2DA2–40e2–B841–88899F240200} – D:\PROGRA~1\Agnitum\OUTPOS~1\TRASH.EXE (HKCU)
O9 – Extra 'Tools' menuitem: Show Trashcan – {072F3B8A–2DA2–40e2–B841–88899F240200} – D:\PROGRA~1\Agnitum\OUTPOS~1\TRASH.EXE (HKCU)
O12 – Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 – DPF: {9A9307A0–7DA4–4DAF–B042–5009F29E09E1} (ActiveScan Installer Class) – http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 – HKLM\System\CCS\Services\Tcpip\..\{629AD252–41D2–4166–91AD–F86554458A36}: NameServer = 10.10.11.253,64.157.143.38,80.51.189.2
O23 – Service: iPod Service (iPodService) – Apple Computer, Inc. – C:\Program Files\iPod\bin\iPodService.exe
O23 – Service: NVIDIA Display Driver Service (Omega 1.6693) (Q) (NVSvc) – NVIDIA Corporation – C:\WINDOWS\system32\nvsvc32.exe
O23 – Service: Outpost Firewall Service (OutpostFirewall) – Agnitum – D:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe
O23 – Service: Registry Management Service (RegManServ) – Unknown owner – D:\Program Files\Registry Defragmentation\RegManServ.exe
O23 – Service: StyleXPService – Unknown owner – C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe


a.. :) jak mozecie.. powiedzcie dokladnie JAK sie tego pozbyc ;) w punktaach, czo? :]

Odpowiedzi: 1

RUNDLL32.EXE w tym towarzystwie jest w porzadku

Wyłacz przywracanie
Zakoncz proces:
ktr.exe

Pozbadz sie wpisów oraz pogrubionych przeze mnie plikow/katalogow z dysku:
R3 – URLSearchHook: (no name) – {00A6FAF6–072E–44cf–8957–5838F569A31D} – C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 – BHO: MyWebSearch Search Assistant BHO – {00A6FAF1–072E–44cf–8957–5838F569A31D} – C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 – BHO: mwsBar BHO – {07B18EA1–A523–4961–B6BB–170DE4475CCA} – C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O4 – HKCU\..\Run: [ktr] D:\Program Files\ktr\ktr.exe
O8 – Extra context menu item: &Search – http://bar.mywebsearch.com/menusearch.html?p=ZS
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:\Program Files\Messenger\msmsgs.exe (file missing)
Bobi
Dodano
09.04.2005 14:35:26
XenonX
Dodano:
09.04.2005 13:02:48
Komentarzy:
1
Strona 1 / 1