Poproszę o sprawdzenie loga
witam,
cos mi spowalnia kompa, chyba jakas franca sie zgniezdzila.... poprosze o podpowiedz, czy cos zlapalem:
Logfile of HijackThis v1.99.1
Scan saved at 08:52:05, on 2005–02–21
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesPanda SoftwarePavShldpavprsrv.exe
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004Pavsrv51.exe
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004PsImSvc.exe
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004AVENGINE.EXE
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32igfxtray.exe
C:WINDOWSSystem32hkcmd.exe
C:PROGRA~1QUANTA~1QtEwLMng.EXE
C:Program FilesSynapticsSynTPSynTPLpr.exe
C:Program FilesSynapticsSynTPSynTPEnh.exe
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004APVXDWIN.EXE
C:Program FilesCommon FilesNokiaNCLToolsNclTray.exe
C:Program FilesJavaj2re1.4.2_06injusched.exe
C:Program FilesMicrosoft AntiSpywaregcasServ.exe
C:Program FilesWindows AdStatusWinStat.exe
C:WINDOWSSystem32ctfmon.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesWindows AdStatusWinStatKeep.exe
C:PROGRA~1COMMON~1NokiaServicesSERVIC~1.EXE
C:Program FilesMicrosoft AntiSpywaregcasDtServ.exe
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004WebProxy.exe
C:Program FilesOutlook Expressmsimn.exe
C:WINDOWSSystem32wuauclt.exe
C:Program Files otalcmdTOTALCMD.EXE
C:Program FilesGrabItGrabIt.exe
C:Program FilesSoulseekslsk.exe
C:Program FilesMicrosoft OfficeOFFICE11WINWORD.EXE
c:1HijackThis.exe
C:Program FilesCrazy BrowserCrazy Browser.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.google.pl
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.google.pl
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.google.pl
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.google.pl
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/
R1 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = proxy.provider.pl:8080
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
F2 – REG:system.ini: UserInit=C:WINDOWSsystem32userinit.exe,C:WINDOWSTSI32 sircusr.exe
O1 – Hosts file is located at: C:WINDOWS sdbhosts
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O4 – HKLM..Run: [IgfxTray] C:WINDOWSSystem32igfxtray.exe
O4 – HKLM..Run: [HotKeysCmds] C:WINDOWSSystem32hkcmd.exe
O4 – HKLM..Run: [QtEwLMng] C:PROGRA~1QUANTA~1QtEwLMng.EXE
O4 – HKLM..Run: [SynTPLpr] C:Program FilesSynapticsSynTPSynTPLpr.exe
O4 – HKLM..Run: [SynTPEnh] C:Program FilesSynapticsSynTPSynTPEnh.exe
O4 – HKLM..Run: [NeroCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [APVXDWIN] "C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004APVXDWIN.EXE" /s
O4 – HKLM..Run: [Nokia Tray Application] C:Program FilesCommon FilesNokiaNCLToolsNclTray.exe
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_06injusched.exe
O4 – HKLM..Run: [gcasServ] "C:Program FilesMicrosoft AntiSpywaregcasServ.exe"
O4 – HKLM..Run: [Windows AdStatus] C:Program FilesWindows AdStatusWinStat.exe
O4 – HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 – HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O8 – Extra context menu item: Pobierz uźywając Download &Express'a – C:Program FilesDownload ExpressAdd_Url.htm
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:Program FilesJavaj2re1.4.2_06in pjpi142_06.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:Program FilesJavaj2re1.4.2_06in pjpi142_06.dll
O9 – Extra button: Badanie – {92780B25–18CC–41C8–B9BE–3C9C571A8263} – C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O9 – Extra button: Related – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:WINDOWSweb elated.htm
O9 – Extra 'Tools' menuitem: Show &Related Links – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:WINDOWSweb elated.htm
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 – DPF: {15AD4789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://static.windupdates.com/cab/CDTInc/ie/bridge–c282.cab
O17 – HKLMSystemCCSServicesTcpip..{04467041–CD17–4357–B20D–528A05025A69}: NameServer = 212.244.130.1,212.244.130.2
O17 – HKLMSystemCCSServicesTcpip..{8F94AAAC–8B15–4FC3–91BF–1AC1F28B00CF}: NameServer = 212.244.130.1,212.244.130.2
O17 – HKLMSystemCS1ServicesTcpip..{04467041–CD17–4357–B20D–528A05025A69}: NameServer = 212.244.130.1,212.244.130.2
O20 – Winlogon Notify: igfxcui – C:WINDOWSSYSTEM32igfxsrvc.dll
O23 – Service: Panda Process Protection Service (PavPrSrv) – Panda Software – C:Program FilesCommon FilesPanda SoftwarePavShldpavprsrv.exe
O23 – Service: Panda anti–virus service (PAVSRV) – Panda Software – C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004Pavsrv51.exe
O23 – Service: Panda IManager Service (PSIMSVC) – Panda Software Internacional – C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004PsImSvc.exe
cos mi spowalnia kompa, chyba jakas franca sie zgniezdzila.... poprosze o podpowiedz, czy cos zlapalem:
Logfile of HijackThis v1.99.1
Scan saved at 08:52:05, on 2005–02–21
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesPanda SoftwarePavShldpavprsrv.exe
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004Pavsrv51.exe
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004PsImSvc.exe
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004AVENGINE.EXE
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32igfxtray.exe
C:WINDOWSSystem32hkcmd.exe
C:PROGRA~1QUANTA~1QtEwLMng.EXE
C:Program FilesSynapticsSynTPSynTPLpr.exe
C:Program FilesSynapticsSynTPSynTPEnh.exe
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004APVXDWIN.EXE
C:Program FilesCommon FilesNokiaNCLToolsNclTray.exe
C:Program FilesJavaj2re1.4.2_06injusched.exe
C:Program FilesMicrosoft AntiSpywaregcasServ.exe
C:Program FilesWindows AdStatusWinStat.exe
C:WINDOWSSystem32ctfmon.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesWindows AdStatusWinStatKeep.exe
C:PROGRA~1COMMON~1NokiaServicesSERVIC~1.EXE
C:Program FilesMicrosoft AntiSpywaregcasDtServ.exe
C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004WebProxy.exe
C:Program FilesOutlook Expressmsimn.exe
C:WINDOWSSystem32wuauclt.exe
C:Program Files otalcmdTOTALCMD.EXE
C:Program FilesGrabItGrabIt.exe
C:Program FilesSoulseekslsk.exe
C:Program FilesMicrosoft OfficeOFFICE11WINWORD.EXE
c:1HijackThis.exe
C:Program FilesCrazy BrowserCrazy Browser.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.google.pl
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.google.pl
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.google.pl
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.google.pl
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/
R1 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = proxy.provider.pl:8080
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
F2 – REG:system.ini: UserInit=C:WINDOWSsystem32userinit.exe,C:WINDOWSTSI32 sircusr.exe
O1 – Hosts file is located at: C:WINDOWS sdbhosts
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O4 – HKLM..Run: [IgfxTray] C:WINDOWSSystem32igfxtray.exe
O4 – HKLM..Run: [HotKeysCmds] C:WINDOWSSystem32hkcmd.exe
O4 – HKLM..Run: [QtEwLMng] C:PROGRA~1QUANTA~1QtEwLMng.EXE
O4 – HKLM..Run: [SynTPLpr] C:Program FilesSynapticsSynTPSynTPLpr.exe
O4 – HKLM..Run: [SynTPEnh] C:Program FilesSynapticsSynTPSynTPEnh.exe
O4 – HKLM..Run: [NeroCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [APVXDWIN] "C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004APVXDWIN.EXE" /s
O4 – HKLM..Run: [Nokia Tray Application] C:Program FilesCommon FilesNokiaNCLToolsNclTray.exe
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_06injusched.exe
O4 – HKLM..Run: [gcasServ] "C:Program FilesMicrosoft AntiSpywaregcasServ.exe"
O4 – HKLM..Run: [Windows AdStatus] C:Program FilesWindows AdStatusWinStat.exe
O4 – HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 – HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O8 – Extra context menu item: Pobierz uźywając Download &Express'a – C:Program FilesDownload ExpressAdd_Url.htm
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:Program FilesJavaj2re1.4.2_06in pjpi142_06.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:Program FilesJavaj2re1.4.2_06in pjpi142_06.dll
O9 – Extra button: Badanie – {92780B25–18CC–41C8–B9BE–3C9C571A8263} – C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O9 – Extra button: Related – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:WINDOWSweb elated.htm
O9 – Extra 'Tools' menuitem: Show &Related Links – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:WINDOWSweb elated.htm
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 – DPF: {15AD4789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://static.windupdates.com/cab/CDTInc/ie/bridge–c282.cab
O17 – HKLMSystemCCSServicesTcpip..{04467041–CD17–4357–B20D–528A05025A69}: NameServer = 212.244.130.1,212.244.130.2
O17 – HKLMSystemCCSServicesTcpip..{8F94AAAC–8B15–4FC3–91BF–1AC1F28B00CF}: NameServer = 212.244.130.1,212.244.130.2
O17 – HKLMSystemCS1ServicesTcpip..{04467041–CD17–4357–B20D–528A05025A69}: NameServer = 212.244.130.1,212.244.130.2
O20 – Winlogon Notify: igfxcui – C:WINDOWSSYSTEM32igfxsrvc.dll
O23 – Service: Panda Process Protection Service (PavPrSrv) – Panda Software – C:Program FilesCommon FilesPanda SoftwarePavShldpavprsrv.exe
O23 – Service: Panda anti–virus service (PAVSRV) – Panda Software – C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004Pavsrv51.exe
O23 – Service: Panda IManager Service (PSIMSVC) – Panda Software Internacional – C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004PsImSvc.exe
Odpowiedzi: 17
no niestety to chyba problem hardwerowy
Pozdrówko
Mirek
Pozdrówko
Mirek
Wróblewski:Jestem pełen podziwu dla wiedzy jaką przedstawiasz i czasu jaki poświęcasz,
powiem krótko
Dzięki Mistrzu
Pozdrówko
Mirek
No nie przesadzaj :P
Tylko kurna nie pisz ze Ci sie PS/2 naprawiło :wink:
Wróblewski:Jestem pełen podziwu dla wiedzy jaką przedstawiasz i czasu jaki poświęcasz,
powiem krótko
Dzięki Mistrzu
Pozdrówko
Mirek
No nie przesadzaj :P
Tylko kurna nie pisz ze Ci sie PS/2 naprawiło :wink:
Jestem pełen podziwu dla wiedzy jaką przedstawiasz i czasu jaki poświęcasz,
powiem krótko
Dzięki Mistrzu
Pozdrówko
Mirek
powiem krótko
Dzięki Mistrzu
Pozdrówko
Mirek
Jestem pełen podziwu dla wiedzy jaką przedstawiasz i czasu jaki poświęcasz,
powiem krótko
Dzięki Mistrzu
Pozdrówko
Mirek
powiem krótko
Dzięki Mistrzu
Pozdrówko
Mirek
Log juz czysty tylko go troche poszatkowało.
"Bobi_robert" wydaje mi się źe wszystko wykonałem proszę o ponowne sprawdzenie:
Logfile of HijackThis v1.99.1
Scan saved at 20:03:26, on 2005–02–21
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
D:WINDOWSSystem32smss.exe
D:WINDOWSsystem32winlogon.exe
D:WINDOWSsystem32services.exe
D:WINDOWSsystem32lsass.exe
D:WINDOWSsystem32svchost.exe
D:WINDOWSSystem32svchost.exe
D:WINDOWSExplorer.EXE
D:WINDOWSsystem32spoolsv.exe
D:Program FilesWinFastWFTVFMWFWIZ.exe
D:WINDOWSSystem32WF2K.EXE
D:Program FilesiTunesiTunesHelper.exe
D:Program FilesQuickTimeqttask.exe
F:Video DownloadsGadu–Gadugg.exe
C:Kalendarz XPKalendarz.exe
D:Program FilesSkypePhoneSkype.exe
D:Program FilesAVPersonalAVWUPSRV.EXE
D:WINDOWSSystem32inetsrvinetinfo.exe
D:WINDOWSSystem32 vsvc32.exe
D:WINDOWSSystem32 cpsvcs.exe
D:WINDOWSSystem32svchost.exe
D:Program FilesiPodiniPodService.exe
D:WINDOWSSystem32wuauclt.exe
C:ProgDVBProgDVB.exe
C:HiackhijackthisHijackThis.exe
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3}
– c:program filesReaderActiveXAcroIEHelper.ocx
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} –
D:WINDOWSSystem32msdxm.ocx
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon
initialize
O4 – HKLM..Run: [WinFast Schedule] D:Program
FilesWinFastWFTVFMWFWIZ.exe
O4 – HKLM..Run: [WinFast2KLoadDefault] rundll32.exe
wf2kcpl.dll,DllLoadDefaultSettings
O4 – HKLM..Run: [WinFast_2K] D:WINDOWSSystem32WF2K.EXE
O4 – HKLM..Run: [iTunesHelper] D:Program
FilesiTunesiTunesHelper.exe
O4 – HKLM..Run: [QuickTime Task] "D:Program
FilesQuickTimeqttask.exe" –atboottime
O4 – HKCU..Run: [SIDEBAR] "D:Program FilesDesktop
Sidebardsidebar.exe"
O4 – HKCU..Run: [Gadu–Gadu] "F:Video DownloadsGadu–Gadugg.exe"
/tray
O4 – HKCU..Run: [CursorXP] D:Program FilesCursorXPCursorXP.exe
O4 – Startup: Kalendarz.exe.lnk = C:Kalendarz XPKalendarz.exe
O9 – Extra button: eBay – Homepage –
{EF79EAC5–3452–4E02–B8BD–BA4C89F1AC7A} – D:Program
FilesIrfanViewEbayEbay.htm
O12 – Plugin for .spop: D:Program FilesInternet
ExplorerPluginsNPDocBox.dll
O17 –
HKLMSystemCCSServicesTcpip..{99689AD6–A180–4F62–82F6–CF213F34E12D
}: NameServer = 194.204.159.1,194.204.152.34
O23 – Service: AntiVir Update (AVWUpSrv) – H+BEDV Datentechnik GmbH,
Germany – D:Program FilesAVPersonalAVWUPSRV.EXE
O23 – Service: Symantec Password Validation (ccPwdSvc) – Symantec
Corporation – D:Program FilesCommon FilesSymantec
SharedccPwdSvc.exe
O23 – Service: iPod Service (iPodService) – Apple Computer, Inc. –
D:Program FilesiPodiniPodService.exe
O23 – Service: Leadtek Driver Helper Service (NVSvc) – NVIDIA
Corporation – D:WINDOWSSystem32 vsvc32.exe
Pozdrówko
Mirek
Logfile of HijackThis v1.99.1
Scan saved at 20:03:26, on 2005–02–21
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
D:WINDOWSSystem32smss.exe
D:WINDOWSsystem32winlogon.exe
D:WINDOWSsystem32services.exe
D:WINDOWSsystem32lsass.exe
D:WINDOWSsystem32svchost.exe
D:WINDOWSSystem32svchost.exe
D:WINDOWSExplorer.EXE
D:WINDOWSsystem32spoolsv.exe
D:Program FilesWinFastWFTVFMWFWIZ.exe
D:WINDOWSSystem32WF2K.EXE
D:Program FilesiTunesiTunesHelper.exe
D:Program FilesQuickTimeqttask.exe
F:Video DownloadsGadu–Gadugg.exe
C:Kalendarz XPKalendarz.exe
D:Program FilesSkypePhoneSkype.exe
D:Program FilesAVPersonalAVWUPSRV.EXE
D:WINDOWSSystem32inetsrvinetinfo.exe
D:WINDOWSSystem32 vsvc32.exe
D:WINDOWSSystem32 cpsvcs.exe
D:WINDOWSSystem32svchost.exe
D:Program FilesiPodiniPodService.exe
D:WINDOWSSystem32wuauclt.exe
C:ProgDVBProgDVB.exe
C:HiackhijackthisHijackThis.exe
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3}
– c:program filesReaderActiveXAcroIEHelper.ocx
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} –
D:WINDOWSSystem32msdxm.ocx
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon
initialize
O4 – HKLM..Run: [WinFast Schedule] D:Program
FilesWinFastWFTVFMWFWIZ.exe
O4 – HKLM..Run: [WinFast2KLoadDefault] rundll32.exe
wf2kcpl.dll,DllLoadDefaultSettings
O4 – HKLM..Run: [WinFast_2K] D:WINDOWSSystem32WF2K.EXE
O4 – HKLM..Run: [iTunesHelper] D:Program
FilesiTunesiTunesHelper.exe
O4 – HKLM..Run: [QuickTime Task] "D:Program
FilesQuickTimeqttask.exe" –atboottime
O4 – HKCU..Run: [SIDEBAR] "D:Program FilesDesktop
Sidebardsidebar.exe"
O4 – HKCU..Run: [Gadu–Gadu] "F:Video DownloadsGadu–Gadugg.exe"
/tray
O4 – HKCU..Run: [CursorXP] D:Program FilesCursorXPCursorXP.exe
O4 – Startup: Kalendarz.exe.lnk = C:Kalendarz XPKalendarz.exe
O9 – Extra button: eBay – Homepage –
{EF79EAC5–3452–4E02–B8BD–BA4C89F1AC7A} – D:Program
FilesIrfanViewEbayEbay.htm
O12 – Plugin for .spop: D:Program FilesInternet
ExplorerPluginsNPDocBox.dll
O17 –
HKLMSystemCCSServicesTcpip..{99689AD6–A180–4F62–82F6–CF213F34E12D
}: NameServer = 194.204.159.1,194.204.152.34
O23 – Service: AntiVir Update (AVWUpSrv) – H+BEDV Datentechnik GmbH,
Germany – D:Program FilesAVPersonalAVWUPSRV.EXE
O23 – Service: Symantec Password Validation (ccPwdSvc) – Symantec
Corporation – D:Program FilesCommon FilesSymantec
SharedccPwdSvc.exe
O23 – Service: iPod Service (iPodService) – Apple Computer, Inc. –
D:Program FilesiPodiniPodService.exe
O23 – Service: Leadtek Driver Helper Service (NVSvc) – NVIDIA
Corporation – D:WINDOWSSystem32 vsvc32.exe
Pozdrówko
Mirek
Raczej jakiś wirus "albo co" z początku jest klawiatura ale później gdzieś znika. Wirusów ani szpiegów nie wykryto a mimo to coś się dzieje, stąd wcześniej załączyłem Logfile of HijackThis
Pozdrówko
Mirek
Pozdrówko
Mirek
Moze ten PS/2 sie spalilo na plycie :?: Albo jakis wirusek, trojan :?:
Wróblewski:Podstawowy problem mojego kompa to zanikanie lub wręcz brak portu PS2 klawiatury
I co wykoszenie paru wpisow w HJT sprawe załątwi ??
Ten program to nie panaceum na wszelkie dolegliwosci
Nie mniej jednak trojana CWS about:blank masz
Wylacz przywracanie
Oproznij Temp
FIX:
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://D:DOCUME~1MIROSŁAWUSTAWI~1Tempse.dll/sp.html
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank
O9 – Extra button: Related – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – D:WINDOWSweb elated.htm (file missing)
O9 – Extra 'Tools' menuitem: Show &Related Links – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – D:WINDOWSweb elated.htm (file missing)
Witam. Proszę o sprawdzenie loga. Podstawowy problem mojego kompa to zanikanie lub wręcz brak portu PS2 klawiatury
Logfile of HijackThis v1.99.1
Scan saved at 14:37:51, on 2005–02–21
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
D:WINDOWSSystem32smss.exe
D:WINDOWSsystem32winlogon.exe
D:WINDOWSsystem32services.exe
D:WINDOWSsystem32lsass.exe
D:WINDOWSsystem32svchost.exe
D:WINDOWSSystem32svchost.exe
D:WINDOWSsystem32spoolsv.exe
D:WINDOWSExplorer.EXE
D:Program FilesWinFastWFTVFMWFWIZ.exe
D:WINDOWSSystem32WF2K.EXE
D:Program FilesiTunesiTunesHelper.exe
D:Program FilesQuickTimeqttask.exe
F:Video DownloadsGadu–Gadugg.exe
C:Kalendarz XPKalendarz.exe
D:Program FilesSkypePhoneSkype.exe
D:Program FilesAVPersonalAVWUPSRV.EXE
D:WINDOWSSystem32inetsrvinetinfo.exe
D:WINDOWSSystem32 vsvc32.exe
D:WINDOWSSystem32 cpsvcs.exe
D:WINDOWSSystem32svchost.exe
D:Program FilesiPodiniPodService.exe
D:WINDOWSSystem32wuauclt.exe
C:HiackhijackthisHijackThis.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://D:DOCUME~1MIROSŁAWUSTAWI~1Tempse.dll/sp.html
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – c:program filesReaderActiveXAcroIEHelper.ocx
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – D:WINDOWSSystem32msdxm.ocx
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 – HKLM..Run: [WinFast Schedule] D:Program FilesWinFastWFTVFMWFWIZ.exe
O4 – HKLM..Run: [WinFast2KLoadDefault] rundll32.exe wf2kcpl.dll,DllLoadDefaultSettings
O4 – HKLM..Run: [WinFast_2K] D:WINDOWSSystem32WF2K.EXE
O4 – HKLM..Run: [iTunesHelper] D:Program FilesiTunesiTunesHelper.exe
O4 – HKLM..Run: [QuickTime Task] "D:Program FilesQuickTimeqttask.exe" –atboottime
O4 – HKCU..Run: [SIDEBAR] "D:Program FilesDesktop Sidebardsidebar.exe"
O4 – HKCU..Run: [Gadu–Gadu] "F:Video DownloadsGadu–Gadugg.exe" /tray
O4 – HKCU..Run: [CursorXP] D:Program FilesCursorXPCursorXP.exe
O4 – Startup: Kalendarz.exe.lnk = C:Kalendarz XPKalendarz.exe
O9 – Extra button: Related – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – D:WINDOWSweb elated.htm (file missing)
O9 – Extra 'Tools' menuitem: Show &Related Links – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – D:WINDOWSweb elated.htm (file missing)
O9 – Extra button: eBay – Homepage – {EF79EAC5–3452–4E02–B8BD–BA4C89F1AC7A} – D:Program FilesIrfanViewEbayEbay.htm
O12 – Plugin for .spop: D:Program FilesInternet ExplorerPluginsNPDocBox.dll
O17 – HKLMSystemCCSServicesTcpip..{99689AD6–A180–4F62–82F6–CF213F34E12D}: NameServer = 194.204.159.1,194.204.152.34
O23 – Service: AntiVir Update (AVWUpSrv) – H+BEDV Datentechnik GmbH, Germany – D:Program FilesAVPersonalAVWUPSRV.EXE
O23 – Service: Symantec Password Validation (ccPwdSvc) – Symantec Corporation – D:Program FilesCommon FilesSymantec SharedccPwdSvc.exe
O23 – Service: iPod Service (iPodService) – Apple Computer, Inc. – D:Program FilesiPodiniPodService.exe
O23 – Service: Leadtek Driver Helper Service (NVSvc) – NVIDIA Corporation – D:WINDOWSSystem32 vsvc32.exe
Poniewaź tak głęboko sięgam w system pierwszy raz proszę o źyczliwość
Pozdrówko
Logfile of HijackThis v1.99.1
Scan saved at 14:37:51, on 2005–02–21
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
D:WINDOWSSystem32smss.exe
D:WINDOWSsystem32winlogon.exe
D:WINDOWSsystem32services.exe
D:WINDOWSsystem32lsass.exe
D:WINDOWSsystem32svchost.exe
D:WINDOWSSystem32svchost.exe
D:WINDOWSsystem32spoolsv.exe
D:WINDOWSExplorer.EXE
D:Program FilesWinFastWFTVFMWFWIZ.exe
D:WINDOWSSystem32WF2K.EXE
D:Program FilesiTunesiTunesHelper.exe
D:Program FilesQuickTimeqttask.exe
F:Video DownloadsGadu–Gadugg.exe
C:Kalendarz XPKalendarz.exe
D:Program FilesSkypePhoneSkype.exe
D:Program FilesAVPersonalAVWUPSRV.EXE
D:WINDOWSSystem32inetsrvinetinfo.exe
D:WINDOWSSystem32 vsvc32.exe
D:WINDOWSSystem32 cpsvcs.exe
D:WINDOWSSystem32svchost.exe
D:Program FilesiPodiniPodService.exe
D:WINDOWSSystem32wuauclt.exe
C:HiackhijackthisHijackThis.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://D:DOCUME~1MIROSŁAWUSTAWI~1Tempse.dll/sp.html
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – c:program filesReaderActiveXAcroIEHelper.ocx
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – D:WINDOWSSystem32msdxm.ocx
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 – HKLM..Run: [WinFast Schedule] D:Program FilesWinFastWFTVFMWFWIZ.exe
O4 – HKLM..Run: [WinFast2KLoadDefault] rundll32.exe wf2kcpl.dll,DllLoadDefaultSettings
O4 – HKLM..Run: [WinFast_2K] D:WINDOWSSystem32WF2K.EXE
O4 – HKLM..Run: [iTunesHelper] D:Program FilesiTunesiTunesHelper.exe
O4 – HKLM..Run: [QuickTime Task] "D:Program FilesQuickTimeqttask.exe" –atboottime
O4 – HKCU..Run: [SIDEBAR] "D:Program FilesDesktop Sidebardsidebar.exe"
O4 – HKCU..Run: [Gadu–Gadu] "F:Video DownloadsGadu–Gadugg.exe" /tray
O4 – HKCU..Run: [CursorXP] D:Program FilesCursorXPCursorXP.exe
O4 – Startup: Kalendarz.exe.lnk = C:Kalendarz XPKalendarz.exe
O9 – Extra button: Related – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – D:WINDOWSweb elated.htm (file missing)
O9 – Extra 'Tools' menuitem: Show &Related Links – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – D:WINDOWSweb elated.htm (file missing)
O9 – Extra button: eBay – Homepage – {EF79EAC5–3452–4E02–B8BD–BA4C89F1AC7A} – D:Program FilesIrfanViewEbayEbay.htm
O12 – Plugin for .spop: D:Program FilesInternet ExplorerPluginsNPDocBox.dll
O17 – HKLMSystemCCSServicesTcpip..{99689AD6–A180–4F62–82F6–CF213F34E12D}: NameServer = 194.204.159.1,194.204.152.34
O23 – Service: AntiVir Update (AVWUpSrv) – H+BEDV Datentechnik GmbH, Germany – D:Program FilesAVPersonalAVWUPSRV.EXE
O23 – Service: Symantec Password Validation (ccPwdSvc) – Symantec Corporation – D:Program FilesCommon FilesSymantec SharedccPwdSvc.exe
O23 – Service: iPod Service (iPodService) – Apple Computer, Inc. – D:Program FilesiPodiniPodService.exe
O23 – Service: Leadtek Driver Helper Service (NVSvc) – NVIDIA Corporation – D:WINDOWSSystem32 vsvc32.exe
Poniewaź tak głęboko sięgam w system pierwszy raz proszę o źyczliwość
Pozdrówko
Log czysty ;)
Witam :!:
Prośba o sprawdzenie loga :)
Logfile of HijackThis v1.99.0
Scan saved at 15:29:34, on 2005–02–21
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32 askswitch.exe
C:Program FilesMicrosoft AntiSpywaregcasServ.exe
C:Program FilesAVPersonalAVGNT.EXE
C:Program FilesMicrosoft AntiSpywaregcasDtServ.exe
C:Program FilesStardockObjectDockObjectDock.exe
C:Program FilesAVPersonalAVGUARD.EXE
C:Program FilesAVPersonalAVWUPSRV.EXE
C:WINDOWSSystem32 vsvc32.exe
C:WINDOWSSystem32Fast.exe
C:Program FilesGadu–Gadugg.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesMicrosoft OfficeOFFICE11OUTLOOK.EXE
C:Program FilesMicrosoft OfficeOFFICE11WINWORD.EXE
C:Program FilesInternet Exploreriexplore.exe
D:ProgramyhijackthisHijackThis.exe
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/
R1 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = proxy.satfilm.net.pl:8080
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [CoolSwitch] C:WINDOWSSystem32 askswitch.exe
O4 – HKLM..Run: [gcasServ] "C:Program FilesMicrosoft AntiSpywaregcasServ.exe"
O4 – HKLM..Run: [AVGCtrl] C:Program FilesAVPersonalAVGNT.EXE /min
O4 – Startup: Stardock ObjectDock.lnk = C:Program FilesStardockObjectDockObjectDock.exe
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 – DPF: {17492023–C23A–453E–A040–C7C580BBF700} (Windows Genuine Advantage Validation Tool) – http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O18 – Protocol: cetihpz – {CF184AD3–CDCB–4168–A3F7–8E447D129300} – C:Program FilesHPhpcoretechcomphpuiprot.dll
O23 – Service: AntiVir Service – H+BEDV Datentechnik GmbH – C:Program FilesAVPersonalAVGUARD.EXE
O23 – Service: AntiVir Update – H+BEDV Datentechnik GmbH, Germany – C:Program FilesAVPersonalAVWUPSRV.EXE
O23 – Service: NVIDIA Display Driver Service – NVIDIA Corporation – C:WINDOWSSystem32 vsvc32.exe
Prośba o sprawdzenie loga :)
Logfile of HijackThis v1.99.0
Scan saved at 15:29:34, on 2005–02–21
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32 askswitch.exe
C:Program FilesMicrosoft AntiSpywaregcasServ.exe
C:Program FilesAVPersonalAVGNT.EXE
C:Program FilesMicrosoft AntiSpywaregcasDtServ.exe
C:Program FilesStardockObjectDockObjectDock.exe
C:Program FilesAVPersonalAVGUARD.EXE
C:Program FilesAVPersonalAVWUPSRV.EXE
C:WINDOWSSystem32 vsvc32.exe
C:WINDOWSSystem32Fast.exe
C:Program FilesGadu–Gadugg.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesMicrosoft OfficeOFFICE11OUTLOOK.EXE
C:Program FilesMicrosoft OfficeOFFICE11WINWORD.EXE
C:Program FilesInternet Exploreriexplore.exe
D:ProgramyhijackthisHijackThis.exe
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/
R1 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = proxy.satfilm.net.pl:8080
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [CoolSwitch] C:WINDOWSSystem32 askswitch.exe
O4 – HKLM..Run: [gcasServ] "C:Program FilesMicrosoft AntiSpywaregcasServ.exe"
O4 – HKLM..Run: [AVGCtrl] C:Program FilesAVPersonalAVGNT.EXE /min
O4 – Startup: Stardock ObjectDock.lnk = C:Program FilesStardockObjectDockObjectDock.exe
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 – DPF: {17492023–C23A–453E–A040–C7C580BBF700} (Windows Genuine Advantage Validation Tool) – http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O18 – Protocol: cetihpz – {CF184AD3–CDCB–4168–A3F7–8E447D129300} – C:Program FilesHPhpcoretechcomphpuiprot.dll
O23 – Service: AntiVir Service – H+BEDV Datentechnik GmbH – C:Program FilesAVPersonalAVGUARD.EXE
O23 – Service: AntiVir Update – H+BEDV Datentechnik GmbH, Germany – C:Program FilesAVPersonalAVWUPSRV.EXE
O23 – Service: NVIDIA Display Driver Service – NVIDIA Corporation – C:WINDOWSSystem32 vsvc32.exe
nie, to bodajze admin w firmie ;)
Jesli sam instalowales i jest Ci potrzebny, to nie usuwaj.
Przy okazji:
Ty ustawiales ...proxy.provider.pl:8080 ?
Przy okazji:
Ty ustawiales ...proxy.provider.pl:8080 ?
Coz to za program:
C:PROGRA~1QUANTA~1QtEwLMng.EXE
O4 – HKLM..Run: [QtEwLMng] C:PROGRA~1QUANTA~1QtEwLMng.EXE
to chyba do klawiatury jakis badziew........ wywalic?
i dzieki za re
C:PROGRA~1QUANTA~1QtEwLMng.EXE
O4 – HKLM..Run: [QtEwLMng] C:PROGRA~1QUANTA~1QtEwLMng.EXE
to chyba do klawiatury jakis badziew........ wywalic?
i dzieki za re
Usuwasz:
Coz to za program:
C:PROGRA~1QUANTA~1QtEwLMng.EXE
O4 – HKLM..Run: [QtEwLMng] C:PROGRA~1QUANTA~1QtEwLMng.EXE
Uzywasz jakichs badziewi do "optymalizacji" neta ?
F2 – REG:system.ini: UserInit=C:WINDOWSsystem32userinit.exe,C:WINDOWSTSI32 sircusr.exe
C:Program FilesWindows AdStatusWinStat.exe
C:Program FilesWindows AdStatusWinStatKeep.exe
O1 – Hosts file is located at: C:WINDOWS sdbhosts
O4 – HKLM..Run: [Windows AdStatus] C:Program FilesWindows AdStatusWinStat.exe
O9 – Extra button: Related – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:WINDOWSweb elated.htm
O9 – Extra 'Tools' menuitem: Show &Related Links – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:WINDOWSweb elated.htm
O16 – DPF: {15AD4789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://static.windupdates.com/cab/CDTInc/ie/bridge–c282.cab
Coz to za program:
C:PROGRA~1QUANTA~1QtEwLMng.EXE
O4 – HKLM..Run: [QtEwLMng] C:PROGRA~1QUANTA~1QtEwLMng.EXE
Uzywasz jakichs badziewi do "optymalizacji" neta ?
F2 – REG:system.ini: UserInit=C:WINDOWSsystem32userinit.exe,C:WINDOWSTSI32 sircusr.exe
Strona 1 / 1