Pełno okien

Gdy połączę sięz netem otwiera mi sie wiele okienem z jakąś pseudo–wyszukiwarką, 5 okien IE i kilka stron w operze ( porno :/ )

mam zawalony startup..
log:


Logfile of HijackThis v1.99.0
Scan saved at 22:31:06, on 2004–12–24
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
G:WINDOWSSystem32smss.exe
G:WINDOWSsystem32winlogon.exe
G:WINDOWSsystem32services.exe
G:WINDOWSsystem32lsass.exe
G:WINDOWSsystem32svchost.exe
G:WINDOWSSystem32svchost.exe
G:WINDOWSsystem32spoolsv.exe
G:WINDOWSSystem32CTsvcCDA.EXE
C:WINDOWSSystem32svchost.exe
G:WINDOWSSystem32 vsvc32.exe
G:Program FilesVMwareVMware Workstationvmware–authd.exe
G:WINDOWSSystem32vmnat.exe
G:WINDOWSSystem32MsPMSPSv.exe
C:WINDOWSSystem32Fast.exe
G:WINDOWSSystem32vmnetdhcp.exe
C:PROGRA~1COMMON~1StardockSDMCP.exe
D:Program FilesStardockObject DesktopWindowBlindswbload.exe
G:WINDOWSExplorer.EXE
C:WINDOWSSystem32 askswitch.exe
C:WINDOWSSystem32fast.exe
G:WINDOWSSystem32RUNDLL32.EXE
C:Program FilesJavaj2re1.4.2_05injusched.exe
D:Program FilesD–Toolsdaemon.exe
D:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE
C:PROGRA~1A4TechMouseAmoumain.exe
D:Program FilesToniArtsEasyCleanerEasyClea.exe
G:Program FilesWindows ControlAdWinCtlAd.exe
D:Program FilesClocXClocX.exe
D:Program FilesCreativeMediaSourceGoCTCMSGo.exe
D:Program FilesCreativeMediaSourceDetectorCTDetect.exe
C:Program Files22M WLANWLANMON.exe
C:Program FilesMultiKeyboard DriverKbdDrv.exe
G:Program FilesWindows ControlAdWinCtlAdAlt.exe
D:Program FilesPanda SoftwarePanda Antivirus PlatinumpavProxy.exe
G:WINDOWSsystem32cmd.exe
G:WINDOWSsystem32ftp.exe
G:WINDOWSSystem32svchost.exe
C:Program FilesFlashGetflashget.exe
G:WINDOWSSystem32 askmgr.exe
C:Program FilesOpera7opera.exe
G:WINDOWSSystem32smsss.exe
D:PROGRA~1INCRED~1inIMApp.exe
D:PROGRA~1INCRED~1inIncMail.exe
D:Program FilesAkukuAkuku.exe
G:Documents and SettingsBartekMoje dokumentyhijackthisHijackThis.exe

R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page_bak = about:blank
R1 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = 10.10.11.45:8080
R1 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = http://localhost;
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R3 – URLSearchHook: (no name) – _{CA0E28FA–1AFD–4C21–A8DC–70EB5BE2F076} – (no file)
F2 – REG:system.ini: UserInit=C:WINDOWSsystem32userinit.exe,
O2 – BHO: &EliteBar – {28CAEFF3–0F18–4036–B504–51D73BD81ABC} – G:WINDOWSEliteToolBarEliteToolBar version 58.dll
O3 – Toolbar: &EliteBar – {825CF5BD–8862–4430–B771–0C15C5CA8DEF} – G:WINDOWSEliteToolBarEliteToolBar version 58.dll
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [CoolSwitch] C:WINDOWSSystem32 askswitch.exe
O4 – HKLM..Run: [FastUser] C:WINDOWSSystem32fast.exe
O4 – HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_05injusched.exe
O4 – HKLM..Run: [DAEMON Tools–1033] "D:Program FilesD–Toolsdaemon.exe" –lang 1033
O4 – HKLM..Run: [SCANINICIO] "D:Program FilesPanda SoftwarePanda Antivirus PlatinumInicio.exe"
O4 – HKLM..Run: [APVXDWIN] "D:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE" /s
O4 – HKLM..Run: [NeroFilterCheck] G:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [BootSkin Startup Jobs] "D:Program FilesStardockWinCustomizeBootSkinBootSkin.exe" /StartupJobs
O4 – HKLM..Run: [WheelMouse] C:PROGRA~1A4TechMouseAmoumain.exe
O4 – HKLM..Run: [ToniArts EasyCleaner] "D:Program FilesToniArtsEasyCleanerEasyClea.exe" –s –startup
O4 – HKLM..Run: [Windows ControlAd] G:Program FilesWindows ControlAdWinCtlAd.exe
O4 – HKLM..Run: [kalvsys] G:windowssystem32kalvoks32.exe
O4 – HKLM..Run: [ISUSPM Startup] C:PROGRA~1COMMON~1INSTAL~1UPDATE~1ISUSPM.exe –startup
O4 – HKLM..Run: [UpdReg] G:WINDOWSUpdReg.EXE
O4 – HKLM..Run: [start uploading] smsss.exe
O4 – HKLM..RunServices: [start uploading] smsss.exe
O4 – HKCU..Run: [ClocX] D:Program FilesClocXClocX.exe
O4 – HKCU..Run: [AQQ] D:Program FilesAkukuAkuku.exe
O4 – HKCU..Run: [Creative MediaSource Go] D:Program FilesCreativeMediaSourceGoCTCMSGo.exe /SCB
O4 – HKCU..Run: [Creative Detector] D:Program FilesCreativeMediaSourceDetectorCTDetect.exe /R
O4 – HKCU..Run: [start uploading] smsss.exe
O4 – HKCU..Run: [IncrediMail] D:Program FilesIncrediMailinIncMail.exe /c
O4 – HKCU..RunServices: [start uploading] smsss.exe
O4 – Startup: MutiKeyboard Driver.lnk = C:Program FilesMultiKeyboard DriverKbdDrv.exe
O4 – Global Startup: 22M WLAN Adapter Utility.lnk = C:Program Files22M WLANWLANMON.exe
O8 – Extra context menu item: &Add animation to IncrediMail Style Box – D:PROGRA~1INCRED~1in esourcesWebMenuImg.htm
O8 – Extra context menu item: Ściągnij przy pomocy FlashGet'a – C:Program FilesFlashGetjc_link.htm
O8 – Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a – C:Program FilesFlashGetjc_all.htm
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:Program FilesJavaj2re1.4.2_05in pjpi142_05.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:Program FilesJavaj2re1.4.2_05in pjpi142_05.dll
O9 – Extra button: FlashGet – {D6E814A0–E0C5–11d4–8D29–0050BA6940E3} – C:PROGRA~1FLASHGETflashget.exe
O9 – Extra 'Tools' menuitem: &FlashGet – {D6E814A0–E0C5–11d4–8D29–0050BA6940E3} – C:PROGRA~1FLASHGETflashget.exe
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengerMSMSGS.EXE
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengerMSMSGS.EXE
O12 – Plugin for .exe: C:Program FilesOpera7PLUGINSNPFgc1.dll
O16 – DPF: {00B71CFB–6864–4346–A978–C0A14556272C} (Checkers Class) – http://messenger.zone.msn.com/binary/msgrchkr.cab27571.cab
O16 – DPF: {2917297F–F02B–4B9D–81DF–494B6333150B} (Minesweeper Flags Class) – http://messenger.zone.msn.com/binary/MineSweeper.cab27571.cab
O16 – DPF: {54B52E52–8000–4413–BD67–FC7FE24B59F2} (EARTPatchX Class) – http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab
O16 – DPF: {8E0D4DE5–3180–4024–A327–4DFAD1796A8D} (MessengerStatsClient Class) – http://messenger.zone.msn.com/binary/MessengerStatsClient.cab27571.cab
O16 – DPF: {91433D86–9F27–402C–B5E3–DEBDD122C339} – http://www.netvenda.com/sites/games–intl/pl/games4.cab
O16 – DPF: {F6BF0D00–0B2A–4A75–BF7B–F385591623AF} (Solitaire Showdown Class) – http://messenger.zone.msn.com/binary/SolitaireShowdown.cab27571.cab
O17 – HKLMSystemCCSServicesTcpip..{253701A9–36F8–46F9–B36B–CB922B82681E}: NameServer = 80.51.189.2
O17 – HKLMSystemCS1ServicesTcpip..{253701A9–36F8–46F9–B36B–CB922B82681E}: NameServer = 80.51.189.2
O18 – Protocol hijack: about – {53B95211–7D77–11D2–9F81–00104B107C96}
O18 – Protocol: start – (no CLSID) – (no file)
O23 – Service: Adobe LM Service – Unknown – C:Program FilesCommon FilesAdobe Systems SharedServiceAdobelmsvc.exe
O23 – Service: AVK Service – Unknown – D:Program FilesAntiVirenKitAVKService.exe (file missing)
O23 – Service: Straźnik AVK – Unknown – D:Program FilesAntiVirenKitAVKWCtl.exe (file missing)
O23 – Service: Creative Service for CDROM Access – Creative Technology Ltd – G:WINDOWSSystem32CTsvcCDA.EXE
O23 – Service: iPod Service – Apple Computer, Inc. – C:Program FilesiPodiniPodService.exe
O23 – Service: MySql – Unknown – c:usr/MYSQL/bin/mysqld.exe (file missing)
O23 – Service: NVIDIA Display Driver Service – NVIDIA Corporation – G:WINDOWSSystem32 vsvc32.exe
O23 – Service: VMware Authorization Service – VMware, Inc. – G:Program FilesVMwareVMware Workstationvmware–authd.exe
O23 – Service: VMware DHCP Service – VMware, Inc. – G:WINDOWSSystem32vmnetdhcp.exe
O23 – Service: VMware NAT Service – VMware, Inc. – G:WINDOWSSystem32vmnat.exe
O23 – Service: ZESOFT – Unknown – G:WINDOWSzeta.exe

Chcialoby się komuś to moźe sprawdzić? byłbym super wdzięczny..

jestem zielony więc.. nie obraziłbym się gdyby ktoś mi powiedział jak wyłączyć przywracanie bo wiem źe to moźe być konieczne :)

Odpowiedzi: 1

Wylaczasz przywracanie(moj komputer>wlasciwosci>zakladka przywracanie systemu)
i killujesz exeki w menedzerze zadan i usuwasz je z dysku

G:Program FilesWindows ControlAdWinCtlAd.exe
G:Program FilesWindows ControlAdWinCtlAdAlt.exe
G:WINDOWSSystem32smsss.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page_bak = about:blank
R1 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = 10.10.11.45:8080
R1 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = http://localhost;
R3 – URLSearchHook: (no name) – _{CA0E28FA–1AFD–4C21–A8DC–70EB5BE2F076} – (no file)
O2 – BHO: &EliteBar – {28CAEFF3–0F18–4036–B504–51D73BD81ABC} – G:WINDOWSEliteToolBarEliteToolBar version 58.dll
O3 – Toolbar: &EliteBar – {825CF5BD–8862–4430–B771–0C15C5CA8DEF} – G:WINDOWSEliteToolBarEliteToolBar version 58.dll
O4 – HKLM..Run: [Windows ControlAd] G:Program FilesWindows ControlAdWinCtlAd.exe
O4 – HKLM..Run: [kalvsys] G:windowssystem32kalvoks32.exe
O4 – HKLM..Run: [start uploading] smsss.exe
O4 – HKLM..RunServices: [start uploading] smsss.exe
O4 – HKCU..Run: [start uploading] smsss.exe
O4 – HKCU..RunServices: [start uploading] smsss.exe
O18 – Protocol hijack: about – {53B95211–7D77–11D2–9F81–00104B107C96}
O18 – Protocol: start – (no CLSID) – (no file)
O23 – Service: AVK Service – Unknown – D:Program FilesAntiVirenKitAVKService.exe (file missing)
own – D:Program FilesAntiVirenKitAVKWCtl.exe (file missing)
O23 – Service: Straźnik AVK – Unknown – D:Program FilesAntiVirenKitAVKWCtl.exe (file missing)
O23 – Service: MySql – Unknown – c:usr/MYSQL/bin/mysqld.exe (file missing)
O23 – Service: ZESOFT – Unknown – G:WINDOWSzeta.exe

nastepnie skanujesz system Cwshredder, aktualizujesz posiadanego antywirusa o najnowsze bazy i gruntowny skan, instalujesz service packa
wins
Dodano
25.12.2004 02:41:51
XenonX
Dodano:
24.12.2004 23:31:59
Komentarzy:
1
Strona 1 / 1