log

Logfile of HijackThis v1.97.7
Scan saved at 14:05:16, on 2005–02–11
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32ctfmon.exe
C:WINDOWSSystem32devldr32.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesBearPaw 2448TA ProDriverWATCH.exe
C:Program FilesUlead SystemsUlead Photo Express 4.0 SECalCheck.exe
C:KMaestroKMaestro.exe
C:Program FilesInternet Exploreriexplore.exe
C:ProgramyThunderbirdSetup–0.6–pl–PL.exe
C:DOCUME~1magdaUSTAWI~1Temp s_tempSETUP.EXE
C:ProgramyHijackThis.exe

R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://lookfor.cc/sp.php?pin=29126
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://lookfor.cc/sp.php?pin=29126
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.onet.pl/
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://lookfor.cc?pin=29126
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://lookfor.cc/sp.php?pin=29126
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://lookfor.cc/sp.php?pin=29126
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://lookfor.cc?pin=29126
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://lookfor.cc/sp.php?pin=29126
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page = C:WINDOWSSYSTEMlank.htm
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R3 – URLSearchHook: (no name) – _{CFBFAE00–17A6–11D0–99CB–00C04FD64497} – (no file)
O2 – BHO: (no name) – {00000010–6F7D–442C–93E3–4A4827C2E4C8} – C:WINDOWSNEM220.DLL
O2 – BHO: (no name) – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:PROGRAM FILESADOBEACROBAT 5.0READERACTIVEXACROIEHELPER.OCX
O2 – BHO: NAV Helper – {BDF3E430–B101–42AD–A544–FADC6B084872} – C:Program FilesNorton AntiVirusNavShExt.dll
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O3 – Toolbar: Norton AntiVirus – {42CDD1BF–3FFB–4238–8AD1–7859DF00B1D6} – C:Program FilesNorton AntiVirusNavShExt.dll
O4 – HKLM..Run: [SystemTray] SysTray.Exe
O4 – HKLM..Run: [KeyMaestro] C:KMaestroKMaestro.exe
O4 – HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 – HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 – Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOfficeOSA9.EXE
O4 – Global Startup: Watch.lnk = C:Program FilesBearPaw 2448TA ProDriverWATCH.exe
O4 – Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:Program FilesUlead SystemsUlead Photo Express 4.0 SECalCheck.exe
O9 – Extra button: Related (HKLM)
O9 – Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 – Plugin for .spop: C:PROGRA~1INTERN~1PluginsNPDocBox.dll
O15 – Trusted Zone: *.05p.com
O15 – Trusted Zone: *.blazefind.com
O15 – Trusted Zone: *.clickspring.net
O15 – Trusted Zone: *.flingstone.com
O15 – Trusted Zone: *.mt–download.com
O15 – Trusted Zone: *.my–internet.info
O15 – Trusted Zone: *.scoobidoo.com
O15 – Trusted Zone: *.searchbarcash.com
O15 – Trusted Zone: *.searchmiracle.com
O15 – Trusted Zone: *.slotch.com
O15 – Trusted Zone: *.xxxtoolbar.com
O16 – DPF: Win32 Classes –
O16 – DPF: {9A9307A0–7DA4–4DAF–B042–5009F29E09E1} (ActiveScan Installer Class) – http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab

prosze o porade, co jest niepotrzebne

Odpowiedzi: 2

dzięki za podpowiedz


a tak swoją drogą to fajna temotka przy tym nicku ;)
beznicku
Dodano
11.02.2005 21:37:11
Jesli dlla nie bedzie dalo sie usunac to go najpierw wyrejestruj: regsvr32 /u C:WINDOWSNEM220.DLL.
Oraz fix ponizszych pozycji:

C:DOCUME~1magdaUSTAWI~1Temp s_tempSETUP.EXE
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://lookfor.cc/sp.php?pin=29126
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://lookfor.cc/sp.php?pin=29126
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.onet.pl/
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://lookfor.cc?pin=29126
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://lookfor.cc/sp.php?pin=29126
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://lookfor.cc/sp.php?pin=29126
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://lookfor.cc?pin=29126
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://lookfor.cc/sp.php?pin=29126
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page = C:WINDOWSSYSTEMlank.htm
R3 – URLSearchHook: (no name) – _{CFBFAE00–17A6–11D0–99CB–00C04FD64497} – (no file)
O2 – BHO: (no name) – {00000010–6F7D–442C–93E3–4A4827C2E4C8} – C:WINDOWSNEM220.DLL
O15 – Trusted Zone: *.05p.com
O15 – Trusted Zone: *.blazefind.com
O15 – Trusted Zone: *.clickspring.net
O15 – Trusted Zone: *.flingstone.com
O15 – Trusted Zone: *.mt–download.com
O15 – Trusted Zone: *.my–internet.info
O15 – Trusted Zone: *.scoobidoo.com
O15 – Trusted Zone: *.searchbarcash.com
O15 – Trusted Zone: *.searchmiracle.com
O15 – Trusted Zone: *.slotch.com
O15 – Trusted Zone: *.xxxtoolbar.com
O16 – DPF: Win32 Classes –
wins
Dodano
11.02.2005 16:06:36
beznicku
Dodano:
11.02.2005 15:18:57
Komentarzy:
2
Strona 1 / 1