prośba o sprawdzenie loga

Logfile of HijackThis v1.99.0
Scan saved at 20:09:24, on 2005–04–20
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


Logfile of HijackThis v1.97.7
Scan saved at 17:26:31, on 2005–04–21
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
d:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\SOUNDMAN.EXE
d:\Program Files\Alwil Software\Avast4\ashServ.exe
D:\Program Files\Winamp\winampa.exe
D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\ET4\et4Tray.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SAGEM\SAGEM F@st 800–840\dslmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\wscntfy.exe
d:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
d:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\sesmgr.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Adobe\Acrobat 4.0\Reader\AcroRd32.exe
C:\Program Files\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Tlen.pl\tlen.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\DOM\Pulpit\pliki\HijackThis.exe

R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://szukaj.wp.pl
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neostrada.pl
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada Plus wita Cie w Internecie
R0 – HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 – URLSearchHook: (no name) – {59548858–BDB1–69C7–1A7B–2309F5AFFA61} – panel_its.dll (file missing)
O2 – BHO: (no name) – {A5366673–E8CA–11D3–9CD9–0090271D075B} – D:\PROGRA~1\FlashGet\jccatch.dll
O2 – BHO: (no name) – {AA58ED58–01DD–4d91–8333–CF10577473F7} – c:\program files\google\googletoolbar2.dll
O2 – BHO: (no name) – {C1326F34–3D2A–4295–80E7–8D93D4F5A974} – C:\WINDOWS\System32\spmvp.dll
O3 – Toolbar: FlashGet Bar – {E0E899AB–F487–11D5–8D29–0050BA6940E3} – D:\PROGRA~1\FlashGet\fgiebar.dll
O3 – Toolbar: &Google – {2318C2B1–4965–11d4–9B18–009027A5CD4F} – c:\program files\google\googletoolbar2.dll
O4 – HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 – HKLM\..\Run: [nwiz] nwiz.exe /install
O4 – HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 – HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 – HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 – HKLM\..\Run: [WinampAgent] d:\Program Files\Winamp\winampa.exe
O4 – HKLM\..\Run: [avast!] d:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 – HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 – HKLM\..\Run: [EasyTuneIV] C:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\ET4\et4Tray.exe
O4 – HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 – HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 – HKLM\..\Run: [stuffmon] new32.exe
O4 – HKLM\..\Run: [StatusCheck] driver32.exe
O4 – HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 – HKCU\..\Run: [Gadu–Gadu] d:\Program Files\Gadu–Gadu\powergg.exe /tray
O4 – HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 – HKCU\..\Run: [pizda] driver64.exe
O4 – HKCU\..\Run: [WTFCTF] Uint32.exe
O4 – Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 – Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800–840\dslmon.exe
O4 – Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 – HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 – Extra context menu item: &Google Search – res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 – Extra context menu item: Backward Links – res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 – Extra context menu item: Cached Snapshot of Page – res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 – Extra context menu item: Similar Pages – res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 – Extra context menu item: Translate into English – res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 – Extra context menu item: Ściągnij przy pomocy FlashGet'a – D:\Program Files\FlashGet\jc_link.htm
O8 – Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a – D:\Program Files\FlashGet\jc_all.htm
O9 – Extra button: FlashGet (HKLM)
O9 – Extra 'Tools' menuitem: &FlashGet (HKLM)
O9 – Extra button: Messenger (HKLM)
O9 – Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 – DPF: {15AD6789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://static.windupdates.com/cab/CDT/ie/bridge–c6.cab
O16 – DPF: {9A9307A0–7DA4–4DAF–B042–5009F29E09E1} (ActiveScan Installer Class) – http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 – HKLM\System\CCS\Services\Tcpip\..\{1F71C7CC–7B2E–4BF3–9079–6F76D8083E85}: NameServer = 69.50.176.156,195.225.176.31
O17 – HKLM\System\CCS\Services\Tcpip\..\{737649E2–6783–412A–8CE0–25F093827A2F}: NameServer = 194.204.152.34 217.98.63.164
O17 – HKLM\System\CS1\Services\Tcpip\..\{1F71C7CC–7B2E–4BF3–9079–6F76D8083E85}: NameServer = 69.50.176.156,195.225.176.31






Dzieki z góry. Pozdro.
P.S– juz jest cały

Odpowiedzi: 5

dzięki za pomoc
ATC
Dodano
23.04.2005 13:00:38
Bobi_robert:
...sciagnij sobie nowsza wersje programu...
Tia. Kraniki, dywaniki, zimne wode osobno, cieple wode tez osobno :mrgreen: . Niedawno logi podawala jeszcze starsza wersja i tez bylo git :wink: .


Wylacz proces/y, usun pliki z dysku (ukryte i systemowe), z HJ wpisy:

C:\WINDOWS\system32\sesmgr.exe

R3 – URLSearchHook: (no name) – {59548858–BDB1–69C7–1A7B–2309F5AFFA61} – panel_its.dll (file missing)
O2 – BHO: (no name) – {C1326F34–3D2A–4295–80E7–8D93D4F5A974} – C:\WINDOWS\System32\spmvp.dll
O4 – HKLM\..\Run: [stuffmon] new32.exe
O4 – HKLM\..\Run: [StatusCheck] driver32.exe
O4 – HKCU\..\Run: [Pamela] driver64.exe
O4 – HKCU\..\Run: [WTFCTF] Uint32.exe
O6 – HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 – DPF: {15AD6789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://static.windupdates.com/cab/CDT/ie/bridge–c6.cab
O17 – HKLM\System\CCS\Services\Tcpip\..\{1F71C7CC–7B2E–4BF3–9079–6F76D8083E85}: NameServer = 69.50.176.156,195.225.176.31
O17 – HKLM\System\CS1\Services\Tcpip\..\{1F71C7CC–7B2E–4BF3–9079–6F76D8083E85}: NameServer = 69.50.176.156,195.225.176.31


Nie pomyl tych ostatnich wpisow i nie wywalaj tego:
O17 – HKLM\System\CCS\Services\Tcpip\..\{737649E2–6783–412A–8CE0–25F093827A2F}: NameServer = 194.204.152.34 217.98.63.164
EL NINO
Dodano
21.04.2005 21:37:36
Narazie nic sciagnij sobie nowsza wersje programu i zmien jeszcze raz :wink:
Bobi
Dodano
21.04.2005 19:31:48
gotowe. Co trzeba sfiksować? :wink:
ATC
Dodano
21.04.2005 19:29:04
Wyedytuj swojego posta i wklej caly log.

Wczesniej odinstaluj Media Access i usun jego folder z Program files. Pozbadz sie rowniez plikow:
C:\WINDOWS\system32\dmsadmins.exe
C:\WINDOWS\system32\qwinnta.exe
C:\WINDOWS\system32\sesmgr.exe
EL NINO
Dodano
20.04.2005 22:15:19
ATC
Dodano:
20.04.2005 22:09:58
Komentarzy:
5
Strona 1 / 1