po sprawdzeniu loga wciź le ––––pleas

sprawdziłem na http://www.hijackthis.de/index.php#anl

i niestety częć zostaje np. O10 – Broken Internet access because of LSP provider 'xfire_lsp_10226.dll' missing

przesyłam loga i prosze o pomoc:

Logfile of HijackThis v1.99.1
Scan saved at 19:50:18, on 2005–10–01
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Winamp\Winampa.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\NEOSTR~1\CnxMon.exe
C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
C:\WINDOWS\System32\efsdfgxg.exe
C:\winstall.exe
C:\Program Files\leol\pcoa.exe
C:\WINDOWS\System32\vxh8jkdq2.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\Serv–U\SERVUD~1.EXE
C:\WINDOWS\System32\vxh8jkdq2.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\kernels32.exe
C:\WINDOWS\System32\vxh8jkdq2.exe
C:\WINDOWS\System32\split.exe
C:\WINDOWS\System32\split.exe
C:\PROGRA~1\NEOSTR~1\NeostradaTP.exe
C:\PROGRA~1\NEOSTR~1\ComComp.exe
C:\PROGRA~1\NEOSTR~1\Watch.exe
C:\WINDOWS\System32\vxgame2.exe
C:\WINDOWS\System32\vxgame3.exe
C:\WINDOWS\System32\vxgame4.exe
C:\WINDOWS\System32\vxgame4.exe
C:\WINDOWS\System32\vxgame3.exe
C:\WINDOWS\System32\vxgame4.exe
C:\WINDOWS\System32\vxgame4.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\kernels32.exe
C:\WINDOWS\System32\vxh8jkdq2.exe
C:\WINDOWS\System32\vxh8jkdq6.exe
C:\WINDOWS\System32\vxh8jkdq7.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\DOCUME~1\khaine\USTAWI~1\Temp\Rar$EX76.327\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\khaine\USTAWI~1\Temp\Rar$EX00.952\KillBox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE

R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://szukaj.wp.pl
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neostrada.pl
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada TP
R0 – HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łcza
R3 – URLSearchHook: Search Class – {08C06D61–F1F3–4799–86F8–BE1A89362C85} – C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 – BHO: SearchToolbar – {08BEC6AA–49FC–4379–3587–4B21E286C19E} – C:\WINDOWS\System32\otzjf.dll
O2 – BHO: (no name) – {9C5875B8–93F3–429D–FF34–660B206D897A} – C:\WINDOWS\System32\performent011.dll
O2 – BHO: Google Toolbar Helper – {AA58ED58–01DD–4d91–8333–CF10577473F7} – c:\program files\google\googletoolbar2.dll
O3 – Toolbar: SearchToolbar – {08BEC6AA–49FC–4379–3587–4B21E286C19E} – C:\WINDOWS\System32\otzjf.dll
O4 – HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 – HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 – HKLM\..\Run: [ssmgr] ssmon
O4 – HKLM\..\Run: [svhost] ssmon
O4 – HKLM\..\Run: [hifmyv] C:\WINDOWS\System32\shtmwo.exe
O4 – HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 – HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" –osboot
O4 – HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 – HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\NEOSTR~1\CnxMon.exe
O4 – HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe
O4 – HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
O4 – HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 –k
O4 – HKLM\..\Run: [Explorer32] C:\WINDOWS\System32\efsdfgxg.exe
O4 – HKCU\..\Run: [WrCtrl] "C:\Program Files\WinRoute Pro\wrctrl.exe"
O4 – HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 – HKCU\..\Run: [Cpsh] "C:\Program Files\leol\pcoa.exe" –vt mt
O4 – HKCU\..\Run: [SNInstall] C:\WINDOWS\System32\vxh8jkdq2.exe
O4 – HKCU\..\Run: [Bazjr] C:\WINDOWS\System32\??plorer.exe
O8 – Extra context menu item: &Google Search – res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 – Extra context menu item: &Translate English Word – res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 – Extra context menu item: Backward Links – res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 – Extra context menu item: Cached Snapshot of Page – res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 – Extra context menu item: Download with GetRight – C:\Program Files\GetRight\GRdownload.htm
O8 – Extra context menu item: Open with GetRight Browser – C:\Program Files\GetRight\GRbrowse.htm
O8 – Extra context menu item: Similar Pages – res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 – Extra context menu item: Translate Page into English – res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O10 – Broken Internet access because of LSP provider 'xfire_lsp_10226.dll' missing
O15 – Trusted IP range: 67.19.178.84
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
O17 – HKLM\System\CCS\Services\Tcpip\..\{0040E994–0928–4C1B–AD51–12820D15A8A9}: NameServer = 85.255.113.140,85.255.112.10
O17 – HKLM\System\CCS\Services\Tcpip\..\{21F4DFC2–5DFF–4380–AE60–A7F20419F844}: NameServer = 85.255.113.140,85.255.112.10
O17 – HKLM\System\CCS\Services\Tcpip\..\{50C82731–36E2–441C–8FED–3D553DD59949}: NameServer = 85.255.113.140,85.255.112.10
O17 – HKLM\System\CCS\Services\Tcpip\..\{AB53B2DD–9ABD–42A7–81F9–89E9E51D6342}: NameServer = 85.255.113.140,85.255.112.10
O17 – HKLM\System\CCS\Services\Tcpip\..\{C1CBED8E–7D4E–4A73–A78B–D907A628B10B}: NameServer = 85.255.113.140,85.255.112.10
O17 – HKLM\System\CCS\Services\Tcpip\..\{D756C167–D809–4EF5–B08E–A85866570341}: NameServer = 85.255.113.140,85.255.112.10
O17 – HKLM\System\CCS\Services\Tcpip\..\{EEC73858–2179–4E8B–9421–0266D3AC9EF8}: NameServer = 194.204.152.34 217.98.63.164
O17 – HKLM\System\CS1\Services\Tcpip\..\{0040E994–0928–4C1B–AD51–12820D15A8A9}: NameServer = 85.255.113.140,85.255.112.10
O21 – SSODL: mtklefa – {AA271BF4–8516–480B–DF84–08D0F0CEFB28} – C:\WINDOWS\System32\fjkk32.dll
O21 – SSODL: mtklefa – {AA271BF4–8516–480B–DF84–08D0F0CEFB28} – C:\WINDOWS\System32\fjkk32.dll
O21 – SSODL: Adobe Photoshop Elements 2.0 – {1D3169B4–FCC4–49CF–F831–8BAB11424B1B} – c:\program files\adobe\photoshop elements 2\winqaop4.dll
O23 – Service: NVIDIA Driver Helper Service (NVSvc) – NVIDIA Corporation – C:\WINDOWS\System32\nvsvc32.exe
O23 – Service: Serv–U FTP Server (Serv–U) – Unknown owner – C:\PROGRA~1\Serv–U\SERVUD~1.EXE
O23 – Service: SymWMI Service (SymWSC) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe




dzięki!!!

Odpowiedzi: 1

Graboll:
sprawdziłem na http://www.hijackthis.de/index.php#anl

i niestety częć zostaje np. O10 – Broken Internet access because of LSP provider 'xfire_lsp_10226.dll' missing
Czesc zostaje ? Przeciez tu wiecej smiecia niz na wysypisku.
Zobacz jakie pliki mozesz miec na dysku i jakie trzeba usunac –> http://research.sunbelt–software.com/threat_display.cfm?name=Trojan.vxgame&threatid=39597

Usuwasz rowniez pliki z dysku – recznie. Nakazujac systemowi pokazanie plikow ukrytych i systemowych.

C:\WINDOWS\System32\efsdfgxg.exe
C:\winstall.exe
C:\Program Files\leol\pcoa.exe
C:\WINDOWS\System32\vxh8jkdq2.exe
C:\WINDOWS\System32\vxh8jkdq2.exe
C:\WINDOWS\System32\kernels32.exe
C:\WINDOWS\System32\vxh8jkdq2.exe
C:\WINDOWS\System32\vxgame2.exe
C:\WINDOWS\System32\vxgame3.exe
C:\WINDOWS\System32\vxgame4.exe
C:\WINDOWS\System32\vxgame4.exe
C:\WINDOWS\System32\vxgame3.exe
C:\WINDOWS\System32\vxgame4.exe
C:\WINDOWS\System32\vxgame4.exe
C:\WINDOWS\System32\kernels32.exe
C:\WINDOWS\System32\vxh8jkdq2.exe
C:\WINDOWS\System32\vxh8jkdq6.exe
C:\WINDOWS\System32\vxh8jkdq7.exe
O2 – BHO: SearchToolbar – {08BEC6AA–49FC–4379–3587–4B21E286C19E} – C:\WINDOWS\System32\otzjf.dll
O2 – BHO: (no name) – {9C5875B8–93F3–429D–FF34–660B206D897A} – C:\WINDOWS\System32\performent011.dll
O3 – Toolbar: SearchToolbar – {08BEC6AA–49FC–4379–3587–4B21E286C19E} – C:\WINDOWS\System32\otzjf.dll
O4 – HKLM\..\Run: [ssmgr] ssmon
O4 – HKLM\..\Run: [svhost] ssmon
O4 – HKLM\..\Run: [hifmyv] C:\WINDOWS\System32\shtmwo.exe
O4 – HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 –k
O4 – HKLM\..\Run: [Explorer32] C:\WINDOWS\System32\efsdfgxg.exe
O4 – HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 – HKCU\..\Run: [Cpsh] "C:\Program Files\leol\pcoa.exe" –vt mt
O4 – HKCU\..\Run: [SNInstall] C:\WINDOWS\System32\vxh8jkdq2.exe
O4 – HKCU\..\Run: [Bazjr] C:\WINDOWS\System32\??plorer.exe
O10 – Broken Internet access because of LSP provider 'xfire_lsp_10226.dll' missing
O15 – Trusted IP range: 67.19.178.84
O17 – HKLM\System\CCS\Services\Tcpip\..\{0040E994–0928–4C1B–AD51–12820D15A8A9}: NameServer = 85.255.113.140,85.255.112.10
O17 – HKLM\System\CCS\Services\Tcpip\..\{21F4DFC2–5DFF–4380–AE60–A7F20419F844}: NameServer = 85.255.113.140,85.255.112.10
O17 – HKLM\System\CCS\Services\Tcpip\..\{50C82731–36E2–441C–8FED–3D553DD59949}: NameServer = 85.255.113.140,85.255.112.10
O17 – HKLM\System\CCS\Services\Tcpip\..\{AB53B2DD–9ABD–42A7–81F9–89E9E51D6342}: NameServer = 85.255.113.140,85.255.112.10
O17 – HKLM\System\CCS\Services\Tcpip\..\{C1CBED8E–7D4E–4A73–A78B–D907A628B10B}: NameServer = 85.255.113.140,85.255.112.10
O17 – HKLM\System\CCS\Services\Tcpip\..\{D756C167–D809–4EF5–B08E–A85866570341}: NameServer = 85.255.113.140,85.255.112.10
O17 – HKLM\System\CS1\Services\Tcpip\..\{0040E994–0928–4C1B–AD51–12820D15A8A9}: NameServer = 85.255.113.140,85.255.112.10
O21 – SSODL: mtklefa – {AA271BF4–8516–480B–DF84–08D0F0CEFB28} – C:\WINDOWS\System32\fjkk32.dll
O21 – SSODL: mtklefa – {AA271BF4–8516–480B–DF84–08D0F0CEFB28} – C:\WINDOWS\System32\fjkk32.dll


Uzyj programiku LSPfix do zalatwienia sprawy LSP z wpisu O10.
EL NINO
Dodano
02.10.2005 03:13:20
Graboll
Dodano:
01.10.2005 21:50:51
Komentarzy:
1
Strona 1 / 1