Problem z Trojanem.Bho
Czy mógłby ktoś sprawdzić mój scan z Hijackthis!!!
Running processes:
F:WINDOWSSystem32smss.exe
F:WINDOWSsystem32winlogon.exe
F:WINDOWSsystem32services.exe
F:WINDOWSsystem32lsass.exe
F:WINDOWSsystem32svchost.exe
F:WINDOWSSystem32svchost.exe
F:WINDOWSExplorer.EXE
F:WINDOWSsystem32spoolsv.exe
F:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
F:WINDOWSSystem32P2P NetworkingP2P Networking.exe
F:Program FilesJavaj2re1.4.2_06injusched.exe
F:Program FilesWinFastWFTVFMWFWIZ.exe
F:Program FilesCommon FilesSymantec SharedccApp.exe
F:Programyfine readerAbbyyNewsReader.exe
F:WINDOWSsystem32 undll32.exe
F:Program FilesMessengermsmsgs.exe
F:WINDOWSSystem32driversCDAC11BA.EXE
F:ProgramyNorton AntiVirus avapsvc.exe
F:ProgramyNorton AntiVirusAdvToolsNPROTECT.EXE
F:WINDOWSSystem32 vsvc32.exe
F:WINDOWSSystem32svchost.exe
F:Program FilesCommon FilesSymantec SharedSecurity CenterSymWSC.exe
F:ProgramyGadu–Gadugg.exe
F:Program FilesInternet Exploreriexplore.exe
G:instalkihijackthisHijackThis.exe
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.onet.pl/
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 – BHO: My Search BHO – {014DA6C1–189F–421a–88CD–07CFE51CFF10} – F:Program FilesMySearchar1.binS4BAR.DLL
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – F:Program FilesAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll
O2 – BHO: URLLink Class – {4A2AACF3–ADF6–11D5–98A9–00E018981B9E} – F:Program FilesNewDotNet ewdotnet4_85.dll
O2 – BHO: F:WINDOWSlbbho.dll – {9D1925DA–A849–47A9–9CB9–F1D6E706F47E} – F:WINDOWSlbbho.dll
O2 – BHO: NAV Helper – {BDF3E430–B101–42AD–A544–FADC6B084872} – F:ProgramyNorton AntiVirusNavShExt.dll
O3 – Toolbar: Norton AntiVirus – {42CDD1BF–3FFB–4238–8AD1–7859DF00B1D6} – F:ProgramyNorton AntiVirusNavShExt.dll
O3 – Toolbar: My Search Bar – {014DA6C9–189F–421a–88CD–07CFE51CFF10} – F:Program FilesMySearchar1.binS4BAR.DLL
O4 – HKLM..Run: [P2P Networking] F:WINDOWSSystem32P2P NetworkingP2P Networking.exe /AUTOSTART
O4 – HKLM..Run: [SunJavaUpdateSched] F:Program FilesJavaj2re1.4.2_06injusched.exe
O4 – HKLM..Run: [WinFast Schedule] F:Program FilesWinFastWFTVFMWFWIZ.exe
O4 – HKLM..Run: [ccApp] "F:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 – HKLM..Run: [ccRegVfy] "F:Program FilesCommon FilesSymantec SharedccRegVfy.exe"
O4 – HKLM..Run: [Advanced Tools Check] F:ProgramyNORTON~1AdvToolsADVCHK.EXE
O4 – HKLM..Run: [FineReader7NewsReaderPro] "F:Programyfine readerAbbyyNewsReader.exe"
O4 – HKLM..Run: [New.net Startup] rundll32 F:PROGRA~1NEWDOT~1NEWDOT~1.DLL,NewDotNetStartup
O4 – HKCU..Run: [Gadu–Gadu] "F:ProgramyGadu–Gadugg.exe" /tray
O4 – HKCU..Run: [MSMSGS] "F:Program FilesMessengermsmsgs.exe" /background
O4 – Startup: PowerReg Scheduler.exe
O4 – Global Startup: Microsoft Office.lnk = F:Program FilesMicrosoft OfficeOfficeOSA9.EXE
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – (no file)
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – (no file)
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – F:Program FilesMessengermsmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – F:Program FilesMessengermsmsgs.exe
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O16 – DPF: {1D6711C8–7154–40BB–8380–3DEA45B69CBF} (Web P2P Installer) –
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
O17 – HKLMSystemCCSServicesTcpip..{5843A782–0FB0–43BC–87EE–2D39F63B8224}: NameServer = 192.168.33.254,194.204.159.1
O17 – HKLMSystemCS1ServicesTcpip..{5843A782–0FB0–43BC–87EE–2D39F63B8224}: NameServer = 192.168.33.254,194.204.159.1
Z gory dziekuje za pomoc !!!!!!
Running processes:
F:WINDOWSSystem32smss.exe
F:WINDOWSsystem32winlogon.exe
F:WINDOWSsystem32services.exe
F:WINDOWSsystem32lsass.exe
F:WINDOWSsystem32svchost.exe
F:WINDOWSSystem32svchost.exe
F:WINDOWSExplorer.EXE
F:WINDOWSsystem32spoolsv.exe
F:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
F:WINDOWSSystem32P2P NetworkingP2P Networking.exe
F:Program FilesJavaj2re1.4.2_06injusched.exe
F:Program FilesWinFastWFTVFMWFWIZ.exe
F:Program FilesCommon FilesSymantec SharedccApp.exe
F:Programyfine readerAbbyyNewsReader.exe
F:WINDOWSsystem32 undll32.exe
F:Program FilesMessengermsmsgs.exe
F:WINDOWSSystem32driversCDAC11BA.EXE
F:ProgramyNorton AntiVirus avapsvc.exe
F:ProgramyNorton AntiVirusAdvToolsNPROTECT.EXE
F:WINDOWSSystem32 vsvc32.exe
F:WINDOWSSystem32svchost.exe
F:Program FilesCommon FilesSymantec SharedSecurity CenterSymWSC.exe
F:ProgramyGadu–Gadugg.exe
F:Program FilesInternet Exploreriexplore.exe
G:instalkihijackthisHijackThis.exe
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.onet.pl/
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 – BHO: My Search BHO – {014DA6C1–189F–421a–88CD–07CFE51CFF10} – F:Program FilesMySearchar1.binS4BAR.DLL
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – F:Program FilesAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll
O2 – BHO: URLLink Class – {4A2AACF3–ADF6–11D5–98A9–00E018981B9E} – F:Program FilesNewDotNet ewdotnet4_85.dll
O2 – BHO: F:WINDOWSlbbho.dll – {9D1925DA–A849–47A9–9CB9–F1D6E706F47E} – F:WINDOWSlbbho.dll
O2 – BHO: NAV Helper – {BDF3E430–B101–42AD–A544–FADC6B084872} – F:ProgramyNorton AntiVirusNavShExt.dll
O3 – Toolbar: Norton AntiVirus – {42CDD1BF–3FFB–4238–8AD1–7859DF00B1D6} – F:ProgramyNorton AntiVirusNavShExt.dll
O3 – Toolbar: My Search Bar – {014DA6C9–189F–421a–88CD–07CFE51CFF10} – F:Program FilesMySearchar1.binS4BAR.DLL
O4 – HKLM..Run: [P2P Networking] F:WINDOWSSystem32P2P NetworkingP2P Networking.exe /AUTOSTART
O4 – HKLM..Run: [SunJavaUpdateSched] F:Program FilesJavaj2re1.4.2_06injusched.exe
O4 – HKLM..Run: [WinFast Schedule] F:Program FilesWinFastWFTVFMWFWIZ.exe
O4 – HKLM..Run: [ccApp] "F:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 – HKLM..Run: [ccRegVfy] "F:Program FilesCommon FilesSymantec SharedccRegVfy.exe"
O4 – HKLM..Run: [Advanced Tools Check] F:ProgramyNORTON~1AdvToolsADVCHK.EXE
O4 – HKLM..Run: [FineReader7NewsReaderPro] "F:Programyfine readerAbbyyNewsReader.exe"
O4 – HKLM..Run: [New.net Startup] rundll32 F:PROGRA~1NEWDOT~1NEWDOT~1.DLL,NewDotNetStartup
O4 – HKCU..Run: [Gadu–Gadu] "F:ProgramyGadu–Gadugg.exe" /tray
O4 – HKCU..Run: [MSMSGS] "F:Program FilesMessengermsmsgs.exe" /background
O4 – Startup: PowerReg Scheduler.exe
O4 – Global Startup: Microsoft Office.lnk = F:Program FilesMicrosoft OfficeOfficeOSA9.EXE
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – (no file)
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – (no file)
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – F:Program FilesMessengermsmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – F:Program FilesMessengermsmsgs.exe
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O16 – DPF: {1D6711C8–7154–40BB–8380–3DEA45B69CBF} (Web P2P Installer) –
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
O17 – HKLMSystemCCSServicesTcpip..{5843A782–0FB0–43BC–87EE–2D39F63B8224}: NameServer = 192.168.33.254,194.204.159.1
O17 – HKLMSystemCS1ServicesTcpip..{5843A782–0FB0–43BC–87EE–2D39F63B8224}: NameServer = 192.168.33.254,194.204.159.1
Z gory dziekuje za pomoc !!!!!!
Odpowiedzi: 1
Prosilem zeby nie zamieszczac logow w przyklejonym temacie.
Link do narzedzia odinstalowujacego "new dot" znajdziesz w tym dziale. Usun z loga i dysku:
F:WINDOWSSystem32P2P NetworkingP2P Networking.exe
O2 – BHO: My Search BHO – {014DA6C1–189F–421a–88CD–07CFE51CFF10} – F:Program FilesMySearchar1.binS4BAR.DLL
O2 – BHO: URLLink Class – {4A2AACF3–ADF6–11D5–98A9–00E018981B9E} – F:Program FilesNewDotNet ewdotnet4_85.dll
O2 – BHO: F:WINDOWSlbbho.dll – {9D1925DA–A849–47A9–9CB9–F1D6E706F47E} – F:WINDOWSlbbho.dll
O3 – Toolbar: My Search Bar – {014DA6C9–189F–421a–88CD–07CFE51CFF10} – F:Program FilesMySearchar1.binS4BAR.DLL
O4 – HKLM..Run: [P2P Networking] F:WINDOWSSystem32P2P NetworkingP2P Networking.exe /AUTOSTART
O4 – HKLM..Run: [New.net Startup] rundll32 F:PROGRA~1NEWDOT~1NEWDOT~1.DLL,NewDotNetStartup
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – (no file)
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – (no file)
O9 – Extra 'Tools' menuitem: Windows Messenger –
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O16 – DPF: {1D6711C8–7154–40BB–8380–3DEA45B69CBF} (Web P2P Installer) –
Jesli nie Ty instalowales Messengera w Program Files, rowniez usun to co ponizej. Domyslnie powinien znajdowac sie w windowsSystem32
F:Program FilesMessengermsmsgs.exe
{FB5F1910–F110–11d2–BB9E–00C04F795683} – F:Program FilesMessengermsmsgs.exe
Wroc to tempo:
jednak z XP msmsgs.exe jest wlasnie w tym miejscu.
Link do narzedzia odinstalowujacego "new dot" znajdziesz w tym dziale. Usun z loga i dysku:
F:WINDOWSSystem32P2P NetworkingP2P Networking.exe
O2 – BHO: My Search BHO – {014DA6C1–189F–421a–88CD–07CFE51CFF10} – F:Program FilesMySearchar1.binS4BAR.DLL
O2 – BHO: URLLink Class – {4A2AACF3–ADF6–11D5–98A9–00E018981B9E} – F:Program FilesNewDotNet ewdotnet4_85.dll
O2 – BHO: F:WINDOWSlbbho.dll – {9D1925DA–A849–47A9–9CB9–F1D6E706F47E} – F:WINDOWSlbbho.dll
O3 – Toolbar: My Search Bar – {014DA6C9–189F–421a–88CD–07CFE51CFF10} – F:Program FilesMySearchar1.binS4BAR.DLL
O4 – HKLM..Run: [P2P Networking] F:WINDOWSSystem32P2P NetworkingP2P Networking.exe /AUTOSTART
O4 – HKLM..Run: [New.net Startup] rundll32 F:PROGRA~1NEWDOT~1NEWDOT~1.DLL,NewDotNetStartup
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – (no file)
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – (no file)
O9 – Extra 'Tools' menuitem: Windows Messenger –
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O16 – DPF: {1D6711C8–7154–40BB–8380–3DEA45B69CBF} (Web P2P Installer) –
Jesli nie Ty instalowales Messengera w Program Files, rowniez usun to co ponizej. Domyslnie powinien znajdowac sie w windowsSystem32
F:Program FilesMessengermsmsgs.exe
{FB5F1910–F110–11d2–BB9E–00C04F795683} – F:Program FilesMessengermsmsgs.exe
Wroc to tempo:
jednak z XP msmsgs.exe jest wlasnie w tym miejscu.
Strona 1 / 1