Log z HJT
Czy moze ktos zerknac na loga z hjt??
Problem polega na slabych transferach przy laczu 0,5 MBit. System Windows XP z SP2.
Pozdrawiam
Logfile of HijackThis v1.99.1
Scan saved at 18:32:58, on 2005–07–07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\ANDZEJ\Desktop\HijackThis.exe
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.co.uk/myway
R3 – URLSearchHook: (no name) – {4D25F926–B9FE–4682–BF72–8AB8210D6D75} – C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 – BHO: (no name) – {4D25F921–B9FE–4682–BF72–8AB8210D6D75} – C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 – BHO: DriveLetterAccess – {5CA3D70E–1895–11CF–8E15–001234567890} – C:\WINDOWS\system32\dla\tfswshx.dll
O4 – HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 – HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 – HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16
O4 – HKLM\..\Run: [hgfedcba] c:\windows\system32\hgfedcba.exe /install
O4 – HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 – HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 – HKCU\..\Run: [Gadu–Gadu] "C:\Program Files\Gadu–Gadu\gg.exe" /tray
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 – Extra button: Real.com – {CD67F990–D8E9–11d2–98FE–00C0F0318AFE} – C:\WINDOWS\system32\Shdocvw.dll
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
O18 – Filter: application/x–internet–signup – {A173B69A–1F9B–4823–9FDA–412F641E65D6} – C:\Program Files\Tiscali\Tiscali Internet\dlls\tiscalifilter.dll
O20 – Winlogon Notify: igfxcui – C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 – Service: dlbt_device – Dell – C:\WINDOWS\system32\dlbtcoms.exe
O23 – Service: iPod Service (iPodService) – Apple Computer, Inc. – C:\Program Files\iPod\bin\iPodService.exe
O23 – Service: Intel NCS NetService (NetSvc) – Intel(R) Corporation – C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 – Service: Symantec Network Drivers Service (SNDSrvc) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
Problem polega na slabych transferach przy laczu 0,5 MBit. System Windows XP z SP2.
Pozdrawiam
Odpowiedzi: 2
Dodatkowo odinstalowac \MyWaySA i w HJ usunac:
R3 – URLSearchHook: (no name) – {4D25F926–B9FE–4682–BF72–8AB8210D6D75} – C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 – BHO: (no name) – {4D25F921–B9FE–4682–BF72–8AB8210D6D75} – C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
Potrzebne Ci te wpisy Della?
MYWay to zapewne jakiś syf.
Skasuj:
Dodatkowo szukasz pliku c:\windows\system32\hgfedcba.exe i kasujesz.
MYWay to zapewne jakiś syf.
Skasuj:
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.co.uk/myway
Dodatkowo szukasz pliku c:\windows\system32\hgfedcba.exe i kasujesz.
Strona 1 / 1