Nie moge usunąć spywara
Mam spywar'a na dysku. Zablokowal mi explorera i nie moge przeglądać katalogów zeby go usunąć. To mój log z Hijacka:
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesEPSONEBAPIeEBSVC.exe
C:Program FilesCommon FilesEPSONEBAPISAgent2.exe
C:WINDOWSSystem32 vsvc32.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32RunDll32.exe
C:Program FilesTrust3011A WIRELESS OPTICAL DESKSETKeyboardkbdap32a.EXE
C:Program FilesTrust3011A WIRELESS OPTICAL DESKSETMousemouse32a.exe
C:Program FilesJavaj2re1.4.2_06injusched.exe
C:WINDOWSsystem32 undll32.exe
C:WINDOWSSystem32spoolDRIVERSW32X863E_S10IC2.EXE
C:Program FilesSpyware Doctorswdoctor.exe
C:WINDOWSexplorer.exe
C:Program FilesEnglish Translator 2ET.exe
C:WINDOWSsystem32 askmgr.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
D:InternetMatMOJE PLIKIINNEINSTALKISoftwareHijackHijackThis.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:DOCUME~1HomenetUSTAWI~1Tempse.dll/sp.html
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:DOCUME~1HomenetUSTAWI~1Tempse.dll/sp.html
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R1 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = w3cache.man.lodz.pl:8080
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 – BHO: (no name) – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll
O2 – BHO: (no name) – {1EF51CAA–32DC–4494–8F9C–78784488870F} – C:WINDOWSsystem32edok.dll
O2 – BHO: (no name) – {53707962–6F74–2D53–2644–206D7942484F} – C:Program FilesSpybot – Search & DestroySDHelper.dll
O2 – BHO: (no name) – {5C8B2A36–3DB1–42A4–A3CB–D426709BBFEB} – C:PROGRA~1SPYWAR~1 oolsiesdsg.dll
O2 – BHO: Google Desktop Search Capture – {7c1ce531–09e9–4fc5–9803–1c2956615786} – C:Program FilesGoogleGoogle Desktop SearchGoogleDesktopIE.dll
O2 – BHO: (no name) – {83DE62E0–5805–11D8–9B25–00E04C60FAF2} – C:WINDOWS2_0_1browserhelper2.dll (file missing)
O2 – BHO: (no name) – {AA58ED58–01DD–4d91–8333–CF10577473F7} – c:program filesgooglegoogletoolbar2.dll
O2 – BHO: (no name) – {B56A7D7D–6927–48C8–A975–17DF180C71AC} – C:PROGRA~1SPYWAR~1 oolsiesdpb.dll
O2 – BHO: TGTSoft Explorer Toolbar Changer – {C333CF63–767F–4831–94AC–E683D962C63C} – (no file)
O3 – Toolbar: &Google – {2318C2B1–4965–11d4–9B18–009027A5CD4F} – c:program filesgooglegoogletoolbar2.dll
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [SiSUSBRG] C:WINDOWSSiSUSBrg.exe
O4 – HKLM..Run: [EPSON Stylus CX3200] C:WINDOWSSystem32spoolDRIVERSW32X863E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
O4 – HKLM..Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [OFFICEKB] C:Program FilesTrust3011A WIRELESS OPTICAL DESKSETKeyboardkbdap32a.EXE
O4 – HKLM..Run: [FLMOFFICE4DMOUSE] C:Program FilesTrust3011A WIRELESS OPTICAL DESKSETMousemouse32a.exe
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_06injusched.exe
O4 – HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" –atboottime
O4 – HKLM..Run: [sp] rundll32 C:DOCUME~1HomenetUSTAWI~1Tempse.dll,DllInstall
O4 – HKCU..Run: [EPSON Stylus CX3200] C:WINDOWSSystem32spoolDRIVERSW32X863E_S10IC2.EXE /A "C:WINDOWSsystem32E_SA5.tmp"
O4 – HKCU..Run: [Spyware Doctor] "C:Program FilesSpyware Doctorswdoctor.exe" /Q
O8 – Extra context menu item: &Google Search – res://c:program filesgoogleGoogleToolbar2.dll/cmsearch.html
O8 – Extra context menu item: Backward Links – res://c:program filesgoogleGoogleToolbar2.dll/cmbacklinks.html
O8 – Extra context menu item: Cached Snapshot of Page – res://c:program filesgoogleGoogleToolbar2.dll/cmcache.html
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O8 – Extra context menu item: Similar Pages – res://c:program filesgoogleGoogleToolbar2.dll/cmsimilar.html
O8 – Extra context menu item: Translate into English – res://c:program filesgoogleGoogleToolbar2.dll/cmtrans.html
O9 – Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 – Extra button: Spyware Doctor (HKLM)
O10 – Unknown file in Winsock LSP: c:program filesgooglegoogle desktop searchgoogledesktopnetwork1.dll
O10 – Unknown file in Winsock LSP: c:program filesgooglegoogle desktop searchgoogledesktopnetwork1.dll
O10 – Unknown file in Winsock LSP: c:program filesgooglegoogle desktop searchgoogledesktopnetwork1.dll
O10 – Unknown file in Winsock LSP: c:program filesgooglegoogle desktop searchgoogledesktopnetwork1.dll
O10 – Unknown file in Winsock LSP: c:program filesulletproofsoft.comps spyware & adware removerapptoport.dll
O16 – DPF: {31B7EB4E–8B4B–11D1–A789–00A0CC6651A8} (Cult3D ActiveX Player) – http://www.cult3d.com/download/cult.cab
O16 – DPF: {9A9307A0–7DA4–4DAF–B042–5009F29E09E1} (ActiveScan Installer Class) – http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 – DPF: {FDDBE2B8–6602–4AD8–946D–94C5A32FA6C1} (GameDesire Pool 8) – http://67.15.101.3/g_bin/pl/billard8_2_0_0_21.cab
O16 – DPF: {FDDBE2B8–6602–4AD8–946D–94C5A32FA6C5} (GameDesire Snooker) – http://67.15.101.3/g_bin/pl/snooker_2_0_0_21.cab
Niestety nie wiem co tu zmienić i czy to w ogóle cos pomoźe Proszę o pomoc.
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesEPSONEBAPIeEBSVC.exe
C:Program FilesCommon FilesEPSONEBAPISAgent2.exe
C:WINDOWSSystem32 vsvc32.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32RunDll32.exe
C:Program FilesTrust3011A WIRELESS OPTICAL DESKSETKeyboardkbdap32a.EXE
C:Program FilesTrust3011A WIRELESS OPTICAL DESKSETMousemouse32a.exe
C:Program FilesJavaj2re1.4.2_06injusched.exe
C:WINDOWSsystem32 undll32.exe
C:WINDOWSSystem32spoolDRIVERSW32X863E_S10IC2.EXE
C:Program FilesSpyware Doctorswdoctor.exe
C:WINDOWSexplorer.exe
C:Program FilesEnglish Translator 2ET.exe
C:WINDOWSsystem32 askmgr.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
D:InternetMatMOJE PLIKIINNEINSTALKISoftwareHijackHijackThis.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:DOCUME~1HomenetUSTAWI~1Tempse.dll/sp.html
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:DOCUME~1HomenetUSTAWI~1Tempse.dll/sp.html
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R1 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = w3cache.man.lodz.pl:8080
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 – BHO: (no name) – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll
O2 – BHO: (no name) – {1EF51CAA–32DC–4494–8F9C–78784488870F} – C:WINDOWSsystem32edok.dll
O2 – BHO: (no name) – {53707962–6F74–2D53–2644–206D7942484F} – C:Program FilesSpybot – Search & DestroySDHelper.dll
O2 – BHO: (no name) – {5C8B2A36–3DB1–42A4–A3CB–D426709BBFEB} – C:PROGRA~1SPYWAR~1 oolsiesdsg.dll
O2 – BHO: Google Desktop Search Capture – {7c1ce531–09e9–4fc5–9803–1c2956615786} – C:Program FilesGoogleGoogle Desktop SearchGoogleDesktopIE.dll
O2 – BHO: (no name) – {83DE62E0–5805–11D8–9B25–00E04C60FAF2} – C:WINDOWS2_0_1browserhelper2.dll (file missing)
O2 – BHO: (no name) – {AA58ED58–01DD–4d91–8333–CF10577473F7} – c:program filesgooglegoogletoolbar2.dll
O2 – BHO: (no name) – {B56A7D7D–6927–48C8–A975–17DF180C71AC} – C:PROGRA~1SPYWAR~1 oolsiesdpb.dll
O2 – BHO: TGTSoft Explorer Toolbar Changer – {C333CF63–767F–4831–94AC–E683D962C63C} – (no file)
O3 – Toolbar: &Google – {2318C2B1–4965–11d4–9B18–009027A5CD4F} – c:program filesgooglegoogletoolbar2.dll
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [SiSUSBRG] C:WINDOWSSiSUSBrg.exe
O4 – HKLM..Run: [EPSON Stylus CX3200] C:WINDOWSSystem32spoolDRIVERSW32X863E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
O4 – HKLM..Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [OFFICEKB] C:Program FilesTrust3011A WIRELESS OPTICAL DESKSETKeyboardkbdap32a.EXE
O4 – HKLM..Run: [FLMOFFICE4DMOUSE] C:Program FilesTrust3011A WIRELESS OPTICAL DESKSETMousemouse32a.exe
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_06injusched.exe
O4 – HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" –atboottime
O4 – HKLM..Run: [sp] rundll32 C:DOCUME~1HomenetUSTAWI~1Tempse.dll,DllInstall
O4 – HKCU..Run: [EPSON Stylus CX3200] C:WINDOWSSystem32spoolDRIVERSW32X863E_S10IC2.EXE /A "C:WINDOWSsystem32E_SA5.tmp"
O4 – HKCU..Run: [Spyware Doctor] "C:Program FilesSpyware Doctorswdoctor.exe" /Q
O8 – Extra context menu item: &Google Search – res://c:program filesgoogleGoogleToolbar2.dll/cmsearch.html
O8 – Extra context menu item: Backward Links – res://c:program filesgoogleGoogleToolbar2.dll/cmbacklinks.html
O8 – Extra context menu item: Cached Snapshot of Page – res://c:program filesgoogleGoogleToolbar2.dll/cmcache.html
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O8 – Extra context menu item: Similar Pages – res://c:program filesgoogleGoogleToolbar2.dll/cmsimilar.html
O8 – Extra context menu item: Translate into English – res://c:program filesgoogleGoogleToolbar2.dll/cmtrans.html
O9 – Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 – Extra button: Spyware Doctor (HKLM)
O10 – Unknown file in Winsock LSP: c:program filesgooglegoogle desktop searchgoogledesktopnetwork1.dll
O10 – Unknown file in Winsock LSP: c:program filesgooglegoogle desktop searchgoogledesktopnetwork1.dll
O10 – Unknown file in Winsock LSP: c:program filesgooglegoogle desktop searchgoogledesktopnetwork1.dll
O10 – Unknown file in Winsock LSP: c:program filesgooglegoogle desktop searchgoogledesktopnetwork1.dll
O10 – Unknown file in Winsock LSP: c:program filesulletproofsoft.comps spyware & adware removerapptoport.dll
O16 – DPF: {31B7EB4E–8B4B–11D1–A789–00A0CC6651A8} (Cult3D ActiveX Player) – http://www.cult3d.com/download/cult.cab
O16 – DPF: {9A9307A0–7DA4–4DAF–B042–5009F29E09E1} (ActiveScan Installer Class) – http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 – DPF: {FDDBE2B8–6602–4AD8–946D–94C5A32FA6C1} (GameDesire Pool 8) – http://67.15.101.3/g_bin/pl/billard8_2_0_0_21.cab
O16 – DPF: {FDDBE2B8–6602–4AD8–946D–94C5A32FA6C5} (GameDesire Snooker) – http://67.15.101.3/g_bin/pl/snooker_2_0_0_21.cab
Niestety nie wiem co tu zmienić i czy to w ogóle cos pomoźe Proszę o pomoc.
Odpowiedzi: 5
Widzisz "ociosałes" log i nawet nie wiem czy masz SP2 ktory blokuje pop–upy
Masz jakis firewall, antywirus, program pełniacy takie funkcje ??
PS: Nie wyswietla czyli ?? Blokuje, nie widać zawartosci... itd itp.
Moze są we flashu ??
Masz jakis firewall, antywirus, program pełniacy takie funkcje ??
PS: Nie wyswietla czyli ?? Blokuje, nie widać zawartosci... itd itp.
Moze są we flashu ??
Cos jedak jest nie tak, gdyź wiele okienek reklamowych na stronach www lub w GG nie wyswietla sie. Nie wiem dlaczego?
mkowalski:Dziękuje bardzo,hyba pomogło.
Oby to "hyba" nie powierdziło sie ale przez "ch" :wink:
Dziękuje bardzo,hyba pomogło.
Wylacz przywracanie systemu
Usun:
edok.dll
C:PROGRA~1SPYWAR~1
oproznij Tempy
FIX:
Nie wiem dlaczego Google siedza w strukturze Winsock
Odinstalowałbym to ale wczesniej sciagnał winsockfix aby w razie czego wskrzesic neta
Usun:
edok.dll
C:PROGRA~1SPYWAR~1
oproznij Tempy
FIX:
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:DOCUME~1HomenetUSTAWI~1Tempse.dll/sp.html
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:DOCUME~1HomenetUSTAWI~1Tempse.dll/sp.html
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank
O2 – BHO: (no name) – {1EF51CAA–32DC–4494–8F9C–78784488870F} – C:WINDOWSsystem32edok.dll
O2 – BHO: (no name) – {5C8B2A36–3DB1–42A4–A3CB–D426709BBFEB} – C:PROGRA~1SPYWAR~1 oolsiesdsg.dll
O2 – BHO: (no name) – {83DE62E0–5805–11D8–9B25–00E04C60FAF2} – C:WINDOWS2_0_1browserhelper2.dll (file missing)
O2 – BHO: (no name) – {B56A7D7D–6927–48C8–A975–17DF180C71AC} – C:PROGRA~1SPYWAR~1 oolsiesdpb.dll
O2 – BHO: TGTSoft Explorer Toolbar Changer – {C333CF63–767F–4831–94AC–E683D962C63C} – (no file)
O4 – HKLM..Run: [sp] rundll32 C:DOCUME~1HomenetUSTAWI~1Tempse.dll,DllInstall
Nie wiem dlaczego Google siedza w strukturze Winsock
O10 – Unknown file in Winsock LSP: c:program filesgooglegoogle desktop searchgoogledesktopnetwork1.dll
O10 – Unknown file in Winsock LSP: c:program filesgooglegoogle desktop searchgoogledesktopnetwork1.dll
O10 – Unknown file in Winsock LSP: c:program filesgooglegoogle desktop searchgoogledesktopnetwork1.dll
O10 – Unknown file in Winsock LSP: c:program filesgooglegoogle desktop searchgoogledesktopnetwork1.dll
O10 – Unknown file in Winsock LSP: c:program filesulletproofsoft.comps spyware & adware removerapptoport.dll
Odinstalowałbym to ale wczesniej sciagnał winsockfix aby w razie czego wskrzesic neta
Strona 1 / 1