podły robak albo wszędobylska reklama



Od kilkunastu dni borykam sie z tymi reklamami i z przekierowaniem na jakąś dziwna strone po wyszukiwaniu w google
http://www.camouflageclothingonline.net/siedlce.cfm?nft=1&t=4&p=4 to jest link na który przekierowało mnie po wyszukaniu "siedlce" i kliknięciu w link urzędu miasta a na zdjęciach przykłady tych reklam jeden z centumXP drugi ze strony logowania inteligo. Komputer skanowałem antywirusem ( kaspersky ) i programem do adwarów spywarów itp.( spyware doctor ) prosze o rade co z tym fantem zrobić moźe w ustawieniech IE da sie to coś wyłączyć[/url]

Odpowiedzi: 10

Czysto to tutaj nie ma.

WINBRUME.DLL
EL NINO
Dodano
30.04.2006 22:30:53
Logfile of HijackThis v1.99.1
Scan saved at 19:53:24, on 2006–04–30
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti–Virus Personal Pro\avpcc.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti–Hacker\KAVPF.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti–Virus Personal Pro\avpcc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti–Virus Personal Pro\avpm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\SpeedFan\speedfan.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\HijackThis.exe

R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R0 – HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 – BHO: (no name) – {196B9CB5–4C83–46F7–9B06–9672ECD9D99B} – C:\WINDOWS\system32\winbrume.dll
O2 – BHO: (no name) – {53707962–6F74–2D53–2644–206D7942484F} – C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 – BHO: PCTools Site Guard – {5C8B2A36–3DB1–42A4–A3CB–D426709BBFEB} – C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 – BHO: SSVHelper Class – {761497BB–D6F0–462C–B6EB–D4DAF1D92D43} – C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 – BHO: PCTools Browser Monitor – {B56A7D7D–6927–48C8–A975–17DF180C71AC} – C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 – HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 – HKLM\..\Run: [nwiz] nwiz.exe /install
O4 – HKLM\..\Run: [OfficeGuard RegChecker] "C:\Program Files\Kaspersky Lab\Kaspersky Anti–Virus Personal Pro\ogrc.exe"
O4 – HKLM\..\Run: [AVPCC] "C:\Program Files\Kaspersky Lab\Kaspersky Anti–Virus Personal Pro\avpcc.exe" /wait
O4 – HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 – HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 – Global Startup: Kaspersky Anti–Hacker.lnk = ?
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 – Extra button: Spyware Doctor – {2D663D1A–8670–49D9–A1A5–4C56B4E14E84} – C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 – Extra button: Badanie – {92780B25–18CC–41C8–B9BE–3C9C571A8263} – C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
O15 – Trusted Zone: http://www.mks.com.pl
O16 – DPF: {0EB0E74A–2A76–4AB3–A7FB–9BD8C29F7F75} (CKAVWebScan Object) – http://www.kaspersky.com/downloads/kws/kavwebscan_unicode.cab
O16 – DPF: {17492023–C23A–453E–A040–C7C580BBF700} (Windows Genuine Advantage Validation Tool) – http://go.microsoft.com/fwlink/?linkid=39204
O16 – DPF: {2BC66F54–93A8–11D3–BEB6–00105AA9B6AE} (Symantec AntiVirus scanner) – http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 – DPF: {31B7EB4E–8B4B–11D1–A789–00A0CC6651A8} (Cult3D ActiveX Player) – http://host.cycore.net/plugins/windows/ie/Cult3D_IE_5.3.0.228.cab
O16 – DPF: {6414512B–B978–451D–A0D8–FCFDF33E833C} (WUWebControl Class) – http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1102958186334
O16 – DPF: {644E432F–49D3–41A1–8DD5–E099162EEEC5} (Symantec RuFSI Utility Class) – http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 – DPF: {80DD2229–B8E4–4C77–B72F–F22972D723EA} (AvxScanOnline Control) – http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 – DPF: {A3009861–330C–4E10–822B–39D16EC8829D} (CRAVOnline Object) – http://www.ravantivirus.com/scan/ravonline.cab
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://www.mks.com.pl/skaner/SkanerOnline.cab
O20 – Winlogon Notify: WRNotifier – WRLogonNTF.dll (file missing)
O23 – Service: AVP Control Centre Service (AVPCC) – Unknown owner – C:\Program Files\Kaspersky Lab\Kaspersky Anti–Virus Personal Pro\avpcc.exe" /service (file missing)
O23 – Service: KAV Monitor Service (KAVMonitorService) – Unknown owner – C:\Program Files\Kaspersky Lab\Kaspersky Anti–Virus Personal Pro\avpm.exe" /service (file missing)
O23 – Service: LexBce Server (LexBceS) – Lexmark International, Inc. – C:\WINDOWS\system32\LEXBCES.EXE
O23 – Service: NVIDIA Driver Helper Service (NVSvc) – NVIDIA Corporation – C:\WINDOWS\system32\nvsvc32.exe
O23 – Service: PC Tools Spyware Doctor (SDhelper) – PC Tools Research Pty Ltd – C:\Program Files\Spyware Doctor\sdhelp.exe
reksio50
Dodano
30.04.2006 21:54:37
Entry Kind
(Safe, Nasty, Unknown) Description Tip
C:\WINDOWS\System32\smss.exe
Safe. This entry was classified from our visitors as good.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
C:\WINDOWS\system32\csrss.exe
Safe. running process. (csrss.exe)
Systemprozess – Client Server Runtime


C:\WINDOWS\SYSTEM32\winlogon.exe
Safe. running process. (winlogon.exe)
Systemprozess – Windows Login Routine


C:\WINDOWS\system32\services.exe
Safe. This entry was classified from our visitors as good.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
C:\WINDOWS\system32\lsass.exe
Safe. This entry was classified from our visitors as good.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
C:\WINDOWS\system32\svchost.exe
Safe. This entry was classified from our visitors as good.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
C:\WINDOWS\system32\svchost.exe
Safe. This entry was classified from our visitors as good.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
C:\WINDOWS\System32\svchost.exe
Safe. running process. (svchost.exe)
Systemprozess – Allgemeiner Hostprozessname fr Dienste.


C:\WINDOWS\system32\svchost.exe
Safe. This entry was classified from our visitors as good.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
C:\WINDOWS\system32\svchost.exe
Safe. This entry was classified from our visitors as good.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
C:\WINDOWS\Explorer.exe
Safe. running process. (Explorer.exe)
Systemprozess fr Desktop und Taskleiste.


C:\WINDOWS\system32\LEXBCES.EXE
Safe. running process. (LEXBCES.EXE)
Lexmark LexBce Service


C:\WINDOWS\system32\spoolsv.exe
Safe. This entry was classified from our visitors as good.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
C:\WINDOWS\system32\LEXPPS.EXE
Safe. This entry was classified from our visitors as good.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
C:\Program Files\Kaspersky Lab\Kaspersky Anti–Virus Personal Pro\avpcc.exe
Safe. running process. (avpcc.exe)
Kaspersky–Control–Center

Possibly nasty! According to our database this process runs normally in c:\programme\kaspersky lab\kaspersky anti–virus for workstation\! Check if you know this process and arrange a viruscheck where required.
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
Safe. running process. (jusched.exe)
Java Runtime


C:\Program Files\Kaspersky Lab\Kaspersky Anti–Hacker\KAVPF.exe
Safe. running process. (KAVPF.exe)
Kaspersky Anti–Hacker


C:\Program Files\Kaspersky Lab\Kaspersky Anti–Virus Personal Pro\avpcc.exe
Safe. running process. (avpcc.exe)
Kaspersky–Control–Center

Possibly nasty! According to our database this process runs normally in c:\programme\kaspersky lab\kaspersky anti–virus for workstation\! Check if you know this process and arrange a viruscheck where required.
C:\Program Files\Kaspersky Lab\Kaspersky Anti–Virus Personal Pro\avpm.exe
Safe. running process. (avpm.exe)
Kaspersky(/Escan)–Antivirus–Monitor

Possibly nasty! According to our database this process runs normally in c:\programme\kaspersky lab\kaspersky anti–virus for workstation\! Check if you know this process and arrange a viruscheck where required.
C:\WINDOWS\system32\nvsvc32.exe
Safe. This entry was classified from our visitors as good.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
C:\Program Files\Spyware Doctor\sdhelp.exe
Safe. running process. (sdhelp.exe)
Spyware Doctor


C:\WINDOWS\system32\svchost.exe
Safe. This entry was classified from our visitors as good.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
C:\WINDOWS\system32\wdfmgr.exe
Safe. running process. (wdfmgr.exe)



C:\WINDOWS\system32\wscntfy.exe
Safe. running process. (wscntfy.exe)
Windows XP Securitycenter (Service Pack 2)


C:\WINDOWS\System32\alg.exe
Safe. This entry was classified from our visitors as good.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
C:\Program Files\Kaspersky Lab\Kaspersky Anti–Virus Personal Pro\Avp32.exe
Safe. running process. (Avp32.exe)
Kaspersky–Antivirus–Scanner

Possibly nasty! According to our database this process runs normally in c:\archivos de programa\kaspersky lab\kaspersky anti–virus personal pro\! Check if you know this process and arrange a viruscheck where required.
C:\Program Files\Kaspersky Lab\Kaspersky Anti–Virus Personal Pro\Avp32.exe
Safe. running process. (Avp32.exe)
Kaspersky–Antivirus–Scanner

Possibly nasty! According to our database this process runs normally in c:\archivos de programa\kaspersky lab\kaspersky anti–virus personal pro\! Check if you know this process and arrange a viruscheck where required.
D:\Gadu–Gadu\gg.exe
Safe. running process. (gg.exe)
Polish language Instant Messaging client
Not dangerous, but unnecessary.

C:\Program Files\Outlook Express\msimn.exe
Safe. running process. (msimn.exe)
Outlook Express


C:\Program Files\Messenger\msmsgs.exe
Safe. running process. (msmsgs.exe)
MSN Messenger


D:\Gadu–Gadu\gg.exe
Safe. running process. (gg.exe)
Polish language Instant Messaging client
Not dangerous, but unnecessary.

C:\Program Files\Internet Explorer\iexplore.exe
Safe. running process. (iexplore.exe)
Internet Explorer – Wir empfehlen einen sichereren alternativen Browser zu verwenden. (z.B. Firefox)


C:\PROGRA~1\WinZip\winzip32.exe
Safe. running process. (winzip32.exe)



C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\HijackThis.exe
Safe. running process. (HijackThis.exe)
Tool, mit dem sie dieses Logfile erzeugt haben. Das Programm sollte so angelegt sein ! C:\Programme\HijackThis\HijackThis.exe
Remember that Hijackthis must be run in an own folder. Only if Hijackthis run in an own folder it will create backups!
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
Safe. This page has been identified as safe.

R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
Safe. This page has been identified as safe.

R0 – HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
Safe.

R3 – Default URLSearchHook is missing
Nasty This entry was classified from our visitors as bad.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
F2 – REG:system.ini: Shell=Explorer.exe
Unknown the following information has been found about this entry: .
Unknown application.
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
Safe. Entries found in this registry zone are potentially nasty. This application ([06849E9F–C8D7–4D59–B87D–784B7D6BE0B3] – Result: 06849E9F–C8D7–4D59–B87D–784B7D6BE0B3) has been checked. Hit rate: 100,00%

O2 – BHO: (no name) – {196B9CB5–4C83–46F7–9B06–9672ECD9D99B} – C:\WINDOWS\system32\winbrume.dll
Unknown Entries found in this registry zone are potentially nasty. This application ([196B9CB5–4C83–46F7–9B06–9672ECD9D99B] – Result: ) has been checked. Hit rate: 0,00%
Unknown application.
O2 – BHO: (no name) – {53707962–6F74–2D53–2644–206D7942484F} – C:\PROGRA~1\SPYBOT~1\SDHelper.dll
Safe. This entry was classified from our visitors as good.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
O2 – BHO: PCTools Site Guard – {5C8B2A36–3DB1–42A4–A3CB–D426709BBFEB} – C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
Safe. Entries found in this registry zone are potentially nasty. This application ([5C8B2A36–3DB1–42A4–A3CB–D426709BBFEB] – Result: 5C8B2A36–3DB1–42A4–A3CB–D426709BBFEB) has been checked. Hit rate: 100,00%

O2 – BHO: SSVHelper Class – {761497BB–D6F0–462C–B6EB–D4DAF1D92D43} – C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
Safe. This entry was classified from our visitors as good.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
O2 – BHO: PCTools Browser Monitor – {B56A7D7D–6927–48C8–A975–17DF180C71AC} – C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
Safe. Entries found in this registry zone are potentially nasty. This application ([B56A7D7D–6927–48C8–A975–17DF180C71AC] – Result: B56A7D7D–6927–48C8–A975–17DF180C71AC) has been checked. Hit rate: 100,00%

O4 – HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
Safe. Nvidia TrayIcon
Hit rate: 100,00 % (result)

O4 – HKLM\..\Run: [nwiz] nwiz.exe /install
Safe. This entry was classified from our visitors as good.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
O4 – HKLM\..\Run: [OfficeGuard RegChecker] "C:\Program Files\Kaspersky Lab\Kaspersky Anti–Virus Personal Pro\ogrc.exe"
Safe. Kaspersky Labs anti–virus
Hit rate: 100,00 % (result)

O4 – HKLM\..\Run: [AVPCC] "C:\Program Files\Kaspersky Lab\Kaspersky Anti–Virus Personal Pro\avpcc.exe" /wait
Safe. O4 – HKLM..Run: [AVPCC] "C:Program FilesKaspersky LabKaspersky Anti–Virus Personal Proavpcc.exe" /wait
Hit rate: 100,00 % (result)

O4 – HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
Safe. Java von Sun
Hit rate: 100,00 % (result)

O4 – HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
Safe. This entry was classified from our visitors as good.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
O4 – Global Startup: Kaspersky Anti–Hacker.lnk = ?
Safe. Kaspersky Anti–Hacker
Hit rate: 95,65 % (result)

The entry is unnecessary and can be fixed.
O8 – Extra context menu item: &Search – http://bar.mywebsearch.com/menusearch.html?p=ZNfox000
Nasty The entry &Search has been identified as nasty.

O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Safe. The entry E&ksport do programu Microsoft Excel has been identified as safe.
If the entry 'E&ksport do programu Microsoft Excel ' is not needed anymore, it should be fixed.
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
Safe. The entry has been identified as safe.
If the entry '' is not needed anymore, it should be fixed.
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
Safe. The entry Sun Java Console has been identified as safe.
If the entry 'Sun Java Console ' is not needed anymore, it should be fixed.
O9 – Extra button: Spyware Doctor – {2D663D1A–8670–49D9–A1A5–4C56B4E14E84} – C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
Safe. The entry Spyware Doctor has been identified as safe.
If the entry 'Spyware Doctor ' is not needed anymore, it should be fixed.
O9 – Extra button: Badanie – {92780B25–18CC–41C8–B9BE–3C9C571A8263} – C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
Safe. The entry Badanie has been identified as safe.
If the entry 'Badanie ' is not needed anymore, it should be fixed.
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
Safe. The entry Messenger has been identified as safe.
If the entry 'Messenger ' is not needed anymore, it should be fixed.
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
Safe. The entry Windows Messenger has been identified as safe.
If the entry 'Windows Messenger ' is not needed anymore, it should be fixed.
O15 – Trusted Zone: http://www.mks.com.pl
Safe. If you did not add these pages to your trusted pages, they should be fixed.

O16 – DPF: {0EB0E74A–2A76–4AB3–A7FB–9BD8C29F7F75} (CKAVWebScan Object) – http://www.kaspersky.com/downloads/kws/kavwebscan_unicode.cab
Safe. This entry has been identified as safe.

O16 – DPF: {17492023–C23A–453E–A040–C7C580BBF700} (Windows Genuine Advantage Validation Tool) – http://go.microsoft.com/fwlink/?linkid=39204
Safe. This entry was classified from our visitors as good.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
O16 – DPF: {2BC66F54–93A8–11D3–BEB6–00105AA9B6AE} (Symantec AntiVirus scanner) – http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
Safe. This entry has been identified as safe.

O16 – DPF: {31B7EB4E–8B4B–11D1–A789–00A0CC6651A8} (Cult3D ActiveX Player) – http://host.cycore.net/plugins/windows/ie/Cult3D_IE_5.3.0.228.cab
Safe. This entry has been identified as safe.

O16 – DPF: {6414512B–B978–451D–A0D8–FCFDF33E833C} (WUWebControl Class) – http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_ site.cab?1102958186334
Safe. This entry has been identified as safe.

O16 – DPF: {644E432F–49D3–41A1–8DD5–E099162EEEC5} (Symantec RuFSI Utility Class) – http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
Safe. This entry has been identified as safe.

O16 – DPF: {80DD2229–B8E4–4C77–B72F–F22972D723EA} (AvxScanOnline Control) – http://www.bitdefender.com/scan/Msie/bitdefender.cab
Safe. This entry has been identified as safe.

O16 – DPF: {A3009861–330C–4E10–822B–39D16EC8829D} (CRAVOnline Object) – http://www.ravantivirus.com/scan/ravonline.cab
Safe. This entry has been identified as safe.

O16 – DPF: {A6916797–7ABD–4F07–93AE–098B6F543129} (CO2Player Class) – http://www.lemontv.pl/lmctrlp.cab
Possibly nasty Unknown ActiveX–Objects, or ActiveX–Objects from unknown sites should always be fixed. If the name of the ActiveX–Object or the URL contains the words 'dialer', 'casino', 'free plugin' etc, it should be fixed!
Check if you know this site and fix it if you do not.
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://www.mks.com.pl/skaner/SkanerOnline.cab
Safe. This entry was classified from our visitors as good.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
O20 – Winlogon Notify: WRNotifier – WRLogonNTF.dll (file missing)
Safe. This entry was classified from our visitors as good.
Click on the stars and look at the comments from our visitors, to see, why the entry was classified in such a way.
O23 – Service: AVP Control Centre Service (AVPCC) – Unknown owner – C:\Program Files\Kaspersky Lab\Kaspersky Anti–Virus Personal Pro\avpcc.exe" /service (file missing)
Safe. These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.
This service (avpcc.exe) was identified as a good one.
O23 – Service: KAV Monitor Service (KAVMonitorService) – Unknown owner – C:\Program Files\Kaspersky Lab\Kaspersky Anti–Virus Personal Pro\avpm.exe" /service (file missing)
Safe. These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.
This service (avpm.exe) was identified as a good one.
O23 – Service: LexBce Server (LexBceS) – Lexmark International, Inc. – C:\WINDOWS\system32\LEXBCES.EXE
Safe. These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.
This service (LEXBCES.EXE) was identified as a good one.
O23 – Service: NVIDIA Driver Helper Service (NVSvc) – NVIDIA Corporation – C:\WINDOWS\system32\nvsvc32.exe
Safe. These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.
This service (nvsvc32.exe) was identified as a good one.
O23 – Service: PC Tools Spyware Doctor (SDhelper) – PC Tools Research Pty Ltd – C:\Program Files\Spyware Doctor\sdhelp.exe
Safe. These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it.
This service (sdhelp.exe) was identified as a good one.


This log has been checked automatically.
Check your log file automatically at www.hijackthis.de.
reksio50
Dodano
25.04.2006 19:27:48
Po co wogole te pytanie czy moźesz przesłać... My chyba mamy tobie pomóc, a nie prosić o pomoc, log z hijacka to przewaźnie podstawa... :?
garret.
Dodano
25.04.2006 18:08:26
sprawdziłem log z hi jacka były trzy wpisy z zonkiem usunąłem je i dalej jest to samo. zainstalowałem jeszcze Spybot – Search & Destroy znalazł jakieś zonki ale to teź nic nie dało. log moge przesłać bo mam go zapisanego
reksio50
Dodano
25.04.2006 17:49:06
Czy na innych przeglądarkach masz równieź ten sam problem? Zainstaluj operę lub firefoxa (osobiście uźywam i polecam to drugie) i wtedy sprawdź czy takowe reklamy są wyświetlane... Jeźeli nie to masz odpowiedź (spyware). Coś nie chce mi się wieźyć, źe ad–aware lub spybot niczego nie wykrywa... Sprawdź tak jak wyźej polecano Hj'em i skasuj wpisy wg. instrukcji w przyklejonym temacie. Sądze, źe są to podpięte badziewia do IE w stylu Spysheriff or smthg.
garret.
Dodano
25.04.2006 17:11:02
reksio50:
Niestety kolejne skanowanie ad–aware nic nie dało dalej są te reklamy i przekierowania moźe ktoś ma jakiś pomysł
a sprzawdzales log z hi jacka wg przklejonego tematu ?
gieras
Dodano
25.04.2006 17:07:17
Niestety kolejne skanowanie ad–aware nic nie dało dalej są te reklamy i przekierowania moźe ktoś ma jakiś pomysł
reksio50
Dodano
25.04.2006 16:36:39
to jest na 100% spyware. Na stronie banku nie ma takich reklam... i nie moźe być. Pobierz sobie jakiś program np: Lavasoft Ad–aware, Spyboot lub Windows Defender i usuń to dziadostwo, które najprawdopodobnie cię szpieguje :)
Qper
Dodano
24.04.2006 10:26:34
hmmm, teź takie reklamy wszędzie spotykam, ale to chyba nie wir...
domin45670
Dodano
24.04.2006 03:06:20
reksio50
Dodano:
24.04.2006 00:44:59
Komentarzy:
10
Strona 1 / 1