Moj komputer przesadza! To sie dopiero nazywa złośliwość!
Wiec w zakladce zaawansowane(gdzie musze zaznaczyc opcje udostepniania łacza) wyskakuje cos takiego jak na zalaczniku. Nie wiem co to i jak to naprawic. Nie moge niestety skorzystac z opcji przywracania systemu poniewaz nie ma punktu przywracania... Wiec ogolnie kolko sie zamyka... Do tego zostałem zaatakowany przez wirusa i cos mi siedzi na svchost(100% procka ;)) Jest strasznie!!!! zaraz sie porycze! Co chwile do mnie dzwoni sasiad(namolny gowniarz) i sie pyta dlaczego nie ma internetu! jak zaraz tego nie naprawie, a otrzymam choc jeden telefon, to pojde do niego i po prostu przypie***** mu w ryja! Naprawde prosze o pomoc to dla mnie bardzo wazne... Z gory dziekuje
Odpowiedzi: 8
Skoro nie pomoglo, z Uruchom –> sfc /scannow, lub odpalaj kompa z plyty i naprawiaj.
z wirusami sie uporałem...ale co z pierwszym problemem?
"Sprobuj zresetowac TCP/IP – z Uruchom –> "netsh int ip reset resetlog.txt". Dopiero pozniej trzeba sie zajac wirusami czy tez trojanami."
Co mam zrobic?? naprawde nie wiem
"Sprobuj zresetowac TCP/IP – z Uruchom –> "netsh int ip reset resetlog.txt". Dopiero pozniej trzeba sie zajac wirusami czy tez trojanami."
Co mam zrobic?? naprawde nie wiem
To jest pikuś pospolita Alexa
Wywal ja np Ad–awere'em
Za to to drugie to robak Agobot
Wywal ja np Ad–awere'em
Za to to drugie to robak Agobot
wiec zasadniczo tych dwoch :
O9 – Extra button: Related (HKLM)
O9 – Extra 'Tools' menuitem: Show &Related Links (HKLM)
nie da sie usunac... zaznaczam robie fix a one nadal sa... przywracanie wylaczylem:]
O9 – Extra button: Related (HKLM)
O9 – Extra 'Tools' menuitem: Show &Related Links (HKLM)
nie da sie usunac... zaznaczam robie fix a one nadal sa... przywracanie wylaczylem:]
A widziałes przycisk usun (x) ??
Wylacz przywracanie systemu
Wylacz proces:
winasp.exe
Usun z HDD:
winasp.exe
Tego sie pozbadz:
Wylacz przywracanie systemu
Wylacz proces:
winasp.exe
Usun z HDD:
winasp.exe
Tego sie pozbadz:
O4 – HKLM..Run: [NvCplScan] winasp.exe
O4 – HKLM..RunServices: [NvCplScan] winasp.exe
O4 – HKCU..Run: [NvCplScan] winasp.exe
O4 – HKLM..RunOnce: [NvCplScan] winasp.exe
O4 – HKCU..RunOnce: [NvCplScan] winasp.exe
O9 – Extra button: Related (HKLM)
O9 – Extra 'Tools' menuitem: Show &Related Links (HKLM)
Wiec skanuje wszystko mks on line i jak narazie wykrył pare świnstewek :] Oto Log :
Logfile of HijackThis v1.97.7
Scan saved at 22:25:07, on 2005–01–27
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSSYSTEM32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSSystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSSYSTEM32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32CTsvcCDA.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumFirewallPavFires.exe
C:Program FilesPanda SoftwarePanda Antivirus Platinumpavsrv51.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32oneLabsvsmon.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumAVENGINE.EXE
C:WINDOWSSystem32MsPMSPSv.exe
C:WINDOWSSystem32winasp.exe
C:Program FilesWinampwinampa.exe
C:Program FilesJavaj2re1.4.2_05injusched.exe
C:Program FilesD–Toolsdaemon.exe
C:PROGRA~1MICROS~2GAMECO~1commonswtrayv4.exe
C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE
C:WINDOWSSystem32CTHELPER.EXE
C:WINDOWSSystem32ctfmon.exe
C:Program FilesGadu–Gadugg.exe
C:Program FilesSkypePhoneSkype.exe
C:Program FilesCreativeSBAudigyTaskBarCTLTray.exe
C:Program FilesCreativeSBAudigyTaskBarCTLTask.exe
C:Program FilesKalendarz XPKalendarz.exe
C:Program Filesone LabsoneAlarmzonealarm.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumpavProxy.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesKazaa Lite K++KazaaLite.kpp
C:Program FilesInternet Exploreriexplore.exe
C:Documents and SettingsAdministrator.SERWERMoje dokumentyHijackThisHijackThis.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R1 – HKCUSoftwareMicrosoftInternet Connection Wizard,Shellnext = http://www.sygate.com/swat/support/spf50_help.htm
O2 – BHO: (no name) – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O4 – HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_05injusched.exe
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [DAEMON Tools–1033] "C:Program FilesD–Toolsdaemon.exe" –lang 1033
O4 – HKLM..Run: [NeroCheck] C:WINDOWSSystem32\NeroCheck.exe
O4 – HKLM..Run: [SideWinderTrayV4] C:PROGRA~1MICROS~2GAMECO~1commonswtrayv4.exe
O4 – HKLM..Run: [ATIPTA] C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
O4 – HKLM..Run: [SCANINICIO] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumInicio.exe"
O4 – HKLM..Run: [APVXDWIN] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE" /s
O4 – HKLM..Run: [WINDVDPatch] CTHELPER.EXE
O4 – HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
O4 – HKLM..Run: [Jet Detection] "C:Program FilesCreativeSBAudigyPROGRAMADGJDet.exe"
O4 – HKLM..Run: [CTStartup] C:Program FilesCreativeSplash ScreenCTEaxSpl.EXE /run
O4 – HKLM..Run: [NvCplScan] winasp.exe
O4 – HKLM..RunServices: [NvCplScan] winasp.exe
O4 – HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – HKCU..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /nosplash /minimized
O4 – HKCU..Run: [TaskTray] "C:Program FilesCreativeSBAudigyTaskBarCTLTray.exe"
O4 – HKCU..Run: [TaskBar] "C:Program FilesCreativeSBAudigyTaskBarCTLTask.exe"
O4 – HKCU..Run: [NvCplScan] winasp.exe
O4 – HKLM..RunOnce: [NvCplScan] winasp.exe
O4 – HKCU..RunOnce: [NvCplScan] winasp.exe
O4 – Global Startup: Kalendarz XP.lnk = C:Program FilesKalendarz XPKalendarz.exe
O4 – Global Startup: ZoneAlarm.lnk = C:Program Filesone LabsoneAlarmzonealarm.exe
O9 – Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 – Extra button: Related (HKLM)
O9 – Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 – DPF: {02BF25D5–8C17–4B23–BC80–D3488ABDDC6B} – http://www.apple.com/qtactivex/qtplugin.cab
O16 – DPF: {166B1BCA–3F9C–11CF–8075–444553540000} (Shockwave ActiveX Control) – http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 – DPF: {D27CDB6E–0000–0000–0000–000000000000} – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R1 – HKCUSoftwareMicrosoftInternet Connection Wizard,Shellnext = http://www.sygate.com/swat/support/spf50_help.htm
O2 – BHO: (no name) – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O4 – HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_05injusched.exe
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [DAEMON Tools–1033] "C:Program FilesD–Toolsdaemon.exe" –lang 1033
O4 – HKLM..Run: [NeroCheck] C:WINDOWSSystem32\NeroCheck.exe
O4 – HKLM..Run: [SideWinderTrayV4] C:PROGRA~1MICROS~2GAMECO~1commonswtrayv4.exe
O4 – HKLM..Run: [ATIPTA] C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
O4 – HKLM..Run: [SCANINICIO] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumInicio.exe"
O4 – HKLM..Run: [APVXDWIN] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE" /s
O4 – HKLM..Run: [WINDVDPatch] CTHELPER.EXE
O4 – HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
O4 – HKLM..Run: [Jet Detection] "C:Program FilesCreativeSBAudigyPROGRAMADGJDet.exe"
O4 – HKLM..Run: [CTStartup] C:Program FilesCreativeSplash ScreenCTEaxSpl.EXE /run
O4 – HKLM..Run: [NvCplScan] winasp.exe
O4 – HKLM..RunServices: [NvCplScan] winasp.exe
O4 – HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – HKCU..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /nosplash /minimized
O4 – HKCU..Run: [TaskTray] "C:Program FilesCreativeSBAudigyTaskBarCTLTray.exe"
O4 – HKCU..Run: [TaskBar] "C:Program FilesCreativeSBAudigyTaskBarCTLTask.exe"
O4 – HKCU..Run: [NvCplScan] winasp.exe
O4 – HKLM..RunOnce: [NvCplScan] winasp.exe
O4 – HKCU..RunOnce: [NvCplScan] winasp.exe
O4 – Global Startup: Kalendarz XP.lnk = C:Program FilesKalendarz XPKalendarz.exe
O4 – Global Startup: ZoneAlarm.lnk = C:Program Filesone LabsoneAlarmzonealarm.exe
O9 – Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 – Extra button: Related (HKLM)
O9 – Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 – DPF: {02BF25D5–8C17–4B23–BC80–D3488ABDDC6B} – http://www.apple.com/qtactivex/qtplugin.cab
O16 – DPF: {166B1BCA–3F9C–11CF–8075–444553540000} (Shockwave ActiveX Control) – http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 – DPF: {D27CDB6E–0000–0000–0000–000000000000} – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
Logfile of HijackThis v1.97.7
Scan saved at 22:25:07, on 2005–01–27
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSSYSTEM32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSSystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSSYSTEM32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32CTsvcCDA.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumFirewallPavFires.exe
C:Program FilesPanda SoftwarePanda Antivirus Platinumpavsrv51.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32oneLabsvsmon.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumAVENGINE.EXE
C:WINDOWSSystem32MsPMSPSv.exe
C:WINDOWSSystem32winasp.exe
C:Program FilesWinampwinampa.exe
C:Program FilesJavaj2re1.4.2_05injusched.exe
C:Program FilesD–Toolsdaemon.exe
C:PROGRA~1MICROS~2GAMECO~1commonswtrayv4.exe
C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE
C:WINDOWSSystem32CTHELPER.EXE
C:WINDOWSSystem32ctfmon.exe
C:Program FilesGadu–Gadugg.exe
C:Program FilesSkypePhoneSkype.exe
C:Program FilesCreativeSBAudigyTaskBarCTLTray.exe
C:Program FilesCreativeSBAudigyTaskBarCTLTask.exe
C:Program FilesKalendarz XPKalendarz.exe
C:Program Filesone LabsoneAlarmzonealarm.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumpavProxy.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesKazaa Lite K++KazaaLite.kpp
C:Program FilesInternet Exploreriexplore.exe
C:Documents and SettingsAdministrator.SERWERMoje dokumentyHijackThisHijackThis.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R1 – HKCUSoftwareMicrosoftInternet Connection Wizard,Shellnext = http://www.sygate.com/swat/support/spf50_help.htm
O2 – BHO: (no name) – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O4 – HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_05injusched.exe
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [DAEMON Tools–1033] "C:Program FilesD–Toolsdaemon.exe" –lang 1033
O4 – HKLM..Run: [NeroCheck] C:WINDOWSSystem32\NeroCheck.exe
O4 – HKLM..Run: [SideWinderTrayV4] C:PROGRA~1MICROS~2GAMECO~1commonswtrayv4.exe
O4 – HKLM..Run: [ATIPTA] C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
O4 – HKLM..Run: [SCANINICIO] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumInicio.exe"
O4 – HKLM..Run: [APVXDWIN] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE" /s
O4 – HKLM..Run: [WINDVDPatch] CTHELPER.EXE
O4 – HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
O4 – HKLM..Run: [Jet Detection] "C:Program FilesCreativeSBAudigyPROGRAMADGJDet.exe"
O4 – HKLM..Run: [CTStartup] C:Program FilesCreativeSplash ScreenCTEaxSpl.EXE /run
O4 – HKLM..Run: [NvCplScan] winasp.exe
O4 – HKLM..RunServices: [NvCplScan] winasp.exe
O4 – HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – HKCU..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /nosplash /minimized
O4 – HKCU..Run: [TaskTray] "C:Program FilesCreativeSBAudigyTaskBarCTLTray.exe"
O4 – HKCU..Run: [TaskBar] "C:Program FilesCreativeSBAudigyTaskBarCTLTask.exe"
O4 – HKCU..Run: [NvCplScan] winasp.exe
O4 – HKLM..RunOnce: [NvCplScan] winasp.exe
O4 – HKCU..RunOnce: [NvCplScan] winasp.exe
O4 – Global Startup: Kalendarz XP.lnk = C:Program FilesKalendarz XPKalendarz.exe
O4 – Global Startup: ZoneAlarm.lnk = C:Program Filesone LabsoneAlarmzonealarm.exe
O9 – Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 – Extra button: Related (HKLM)
O9 – Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 – DPF: {02BF25D5–8C17–4B23–BC80–D3488ABDDC6B} – http://www.apple.com/qtactivex/qtplugin.cab
O16 – DPF: {166B1BCA–3F9C–11CF–8075–444553540000} (Shockwave ActiveX Control) – http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 – DPF: {D27CDB6E–0000–0000–0000–000000000000} – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R1 – HKCUSoftwareMicrosoftInternet Connection Wizard,Shellnext = http://www.sygate.com/swat/support/spf50_help.htm
O2 – BHO: (no name) – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O4 – HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_05injusched.exe
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [DAEMON Tools–1033] "C:Program FilesD–Toolsdaemon.exe" –lang 1033
O4 – HKLM..Run: [NeroCheck] C:WINDOWSSystem32\NeroCheck.exe
O4 – HKLM..Run: [SideWinderTrayV4] C:PROGRA~1MICROS~2GAMECO~1commonswtrayv4.exe
O4 – HKLM..Run: [ATIPTA] C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
O4 – HKLM..Run: [SCANINICIO] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumInicio.exe"
O4 – HKLM..Run: [APVXDWIN] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE" /s
O4 – HKLM..Run: [WINDVDPatch] CTHELPER.EXE
O4 – HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
O4 – HKLM..Run: [Jet Detection] "C:Program FilesCreativeSBAudigyPROGRAMADGJDet.exe"
O4 – HKLM..Run: [CTStartup] C:Program FilesCreativeSplash ScreenCTEaxSpl.EXE /run
O4 – HKLM..Run: [NvCplScan] winasp.exe
O4 – HKLM..RunServices: [NvCplScan] winasp.exe
O4 – HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – HKCU..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /nosplash /minimized
O4 – HKCU..Run: [TaskTray] "C:Program FilesCreativeSBAudigyTaskBarCTLTray.exe"
O4 – HKCU..Run: [TaskBar] "C:Program FilesCreativeSBAudigyTaskBarCTLTask.exe"
O4 – HKCU..Run: [NvCplScan] winasp.exe
O4 – HKLM..RunOnce: [NvCplScan] winasp.exe
O4 – HKCU..RunOnce: [NvCplScan] winasp.exe
O4 – Global Startup: Kalendarz XP.lnk = C:Program FilesKalendarz XPKalendarz.exe
O4 – Global Startup: ZoneAlarm.lnk = C:Program Filesone LabsoneAlarmzonealarm.exe
O9 – Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 – Extra button: Related (HKLM)
O9 – Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 – DPF: {02BF25D5–8C17–4B23–BC80–D3488ABDDC6B} – http://www.apple.com/qtactivex/qtplugin.cab
O16 – DPF: {166B1BCA–3F9C–11CF–8075–444553540000} (Shockwave ActiveX Control) – http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 – DPF: {D27CDB6E–0000–0000–0000–000000000000} – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
Sprobuj zresetowac TCP/IP – z Uruchom –> "netsh int ip reset resetlog.txt". Dopiero pozniej trzeba sie zajac wirusami czy tez trojanami.
Na początek wywal wirusa.
Skan antywirem,zlokalizowanie ,usunięcie.
Moźesz dać teź loga HJ.
Jeźeli nie ma punktów przywracania ,naprawa systemu z płyty Xp.
Skan antywirem,zlokalizowanie ,usunięcie.
Moźesz dać teź loga HJ.
Jeźeli nie ma punktów przywracania ,naprawa systemu z płyty Xp.
Strona 1 / 1