Prośba o sprawdzenie loga

Dzięki :D

Logfile of HijackThis v1.99.0
Scan saved at 23:21:15, on 02/12/2005
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32 tvdm.exe
C:WINDOWSTBPanel.exe
C:Program FilesMKSBinmks_mail.exe
C:WINDOWSSOUNDMAN.EXE
C:PROGRA~1VIRTUA~1SystemVCDPlay.exe
C:WINDOWSsystem32RUNDLL32.EXE
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:Program Filesone LabsoneAlarmzlclient.exe
C:Program FilesWinampwinampa.exe
C:Program FilesCommon FilesCMEIICMESys.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesGadu–Gadugg.exe
C:Program FilesCommon FilesGMTGMT.exe
C:Program FilesMSIPC Alert 4PCAlert4.exe
C:WINDOWSSYSTEM32GEARSEC.EXE
C:Program FilesCommon FilesMicrosoft SharedVS7Debugmdm.exe
C:Program FilesMKSBinmksmonsv.exe
C:Program FilesVirtual CD v4SystemVCDTray.exe
C:Program FilesNorton AntiVirus avapsvc.exe
C:WINDOWSSystem32 vsvc32.exe
C:Program FilesNorton AntiVirusSAVScan.exe
C:WINDOWSSystem32 cpsvcs.exe
C:WINDOWSSystem32snmp.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesVirtual CD v4Systemvcdsecs.exe
C:WINDOWSsystem32oneLabsvsmon.exe
C:Program FilesCommon FilesSymantec SharedSecurity CenterSymWSC.exe
C:Program FilesMKSBinmks_scan.exe
C:WINDOWSexplorer.exe
E:HijackThis.exe
C:Program FilesInternet Exploreriexplore.exe
F:START.EXE
d:Program FilesInterActive VisionInterior Architect 3DInterior Architect 3D.exe
E:HijackThis.exe
C:Program FilesMessengermsmsgs.exe

R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
F3 – REG:win.ini: load=C:YDPDictwatch.exe
O2 – BHO: InstaFinderK – {4E7BD74F–2B8D–469E–90F0–F66AB581A933} – C:PROGRA~1INSTAF~1INSTAF~1.DLL
O3 – Toolbar: Norton AntiVirus – {42CDD1BF–3FFB–4238–8AD1–7859DF00B1D6} – C:Program FilesNorton AntiVirusNavShExt.dll
O4 – HKLM..Run: [HPDJ Taskbar Utility] C:WINDOWSSystem32spooldriversw32x863hpztsb04.exe
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [Gainward] C:WINDOWSTBPanel.exe /A
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [MailScanner] C:Program FilesMKSBinmks_mail.exe
O4 – HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 – HKLM..Run: [VCDPlayer] C:PROGRA~1VIRTUA~1SystemVCDPlay.exe
O4 – HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit
O4 – HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 – HKLM..Run: [NAV CfgWiz] C:Program FilesCommon FilesSymantec SharedCfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 – HKLM..Run: [Zone Labs Client] "C:Program Filesone LabsoneAlarmzlclient.exe"
O4 – HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe
O4 – HKLM..Run: [CMESys] "C:Program FilesCommon FilesCMEIICMESys.exe"
O4 – HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – Global Startup: GStartup.lnk = C:Program FilesCommon FilesGMTGMT.exe
O4 – Global Startup: Menu mks_vir.lnk = C:Program FilesMKSBinmks_menu.exe
O4 – Global Startup: PC Alert 4.lnk = C:Program FilesMSIPC Alert 4PCAlert4.exe
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O12 – Plugin for .pdf: C:Program FilesInternet ExplorerPLUGINS ppdf32.dll
O16 – DPF: {27527D31–447B–11D5–A46E–0001023B4289} (CoGSManager Class) – http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O23 – Service: Symantec Event Manager – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
O23 – Service: Symantec Password Validation – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccPwdSvc.exe
O23 – Service: Symantec Settings Manager – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
O23 – Service: GEARSecurity – GEAR Software – C:WINDOWSSYSTEM32GEARSEC.EXE
O23 – Service: MkSUpdateInt – MkS Sp. z o. o. – C:Program FilesMKSinMkSUpdateInt.exe
O23 – Service: MkS_Vir Monitor – Unknown – C:Program FilesMKSBinmksmonsv.exe
O23 – Service: MkS_Scan – Unknown – C:Program FilesMKSBinmks_scan.exe
O23 – Service: Usługa Auto Protect programu Norton AntiVirus – Symantec Corporation – C:Program FilesNorton AntiVirus avapsvc.exe
O23 – Service: NVIDIA Display Driver Service – NVIDIA Corporation – C:WINDOWSSystem32 vsvc32.exe
O23 – Service: SAVScan – Symantec Corporation – C:Program FilesNorton AntiVirusSAVScan.exe
O23 – Service: ScriptBlocking Service – Symantec Corporation – C:PROGRA~1COMMON~1SYMANT~1SCRIPT~1SBServ.exe
O23 – Service: SymWMI Service – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedSecurity CenterSymWSC.exe
O23 – Service: Virtual CD v4 Security service – H+H Software GmbH – C:Program FilesVirtual CD v4Systemvcdsecs.exe
O23 – Service: TrueVector Internet Monitor – Zone Labs Inc. – C:WINDOWSsystem32oneLabsvsmon.exe




a i na koniec jescze takie pytanko, czy korzystanie z kazyy jest bezpieczne ?

Pozdrawiam

Odpowiedzi: 7

Dzięki i polecam się na przyszłość :–)
jackuc
Dodano
13.02.2005 21:53:07
Log czysty ;–)
Mrówek
Dodano
13.02.2005 02:57:45
Dzięki za pomoc
Oto log po operacjach , które zrobiłem

Logfile of HijackThis v1.99.0
Scan saved at 01:30:48, on 02/13/2005
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32 tvdm.exe
C:WINDOWSTBPanel.exe
C:Program FilesMKSBinmks_mail.exe
C:WINDOWSSOUNDMAN.EXE
C:PROGRA~1VIRTUA~1SystemVCDPlay.exe
C:WINDOWSsystem32RUNDLL32.EXE
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:Program Filesone LabsoneAlarmzlclient.exe
C:Program FilesWinampwinampa.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesGadu–Gadugg.exe
C:Program FilesMSIPC Alert 4PCAlert4.exe
C:WINDOWSSYSTEM32GEARSEC.EXE
C:Program FilesCommon FilesMicrosoft SharedVS7Debugmdm.exe
C:Program FilesVirtual CD v4SystemVCDTray.exe
C:Program FilesMKSBinmksmonsv.exe
C:Program FilesNorton AntiVirus avapsvc.exe
C:WINDOWSSystem32 vsvc32.exe
C:Program FilesNorton AntiVirusSAVScan.exe
C:WINDOWSSystem32 cpsvcs.exe
C:WINDOWSSystem32snmp.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesVirtual CD v4Systemvcdsecs.exe
C:WINDOWSsystem32oneLabsvsmon.exe
C:Program FilesCommon FilesSymantec SharedSecurity CenterSymWSC.exe
C:Program FilesMKSBinmks_scan.exe
C:Program FilesInternet Exploreriexplore.exe
E:HijackThis.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesMessengermsmsgs.exe

R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
F3 – REG:win.ini: load=C:YDPDictwatch.exe
O3 – Toolbar: Norton AntiVirus – {42CDD1BF–3FFB–4238–8AD1–7859DF00B1D6} – C:Program FilesNorton AntiVirusNavShExt.dll
O4 – HKLM..Run: [HPDJ Taskbar Utility] C:WINDOWSSystem32spooldriversw32x863hpztsb04.exe
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [Gainward] C:WINDOWSTBPanel.exe /A
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [MailScanner] C:Program FilesMKSBinmks_mail.exe
O4 – HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 – HKLM..Run: [VCDPlayer] C:PROGRA~1VIRTUA~1SystemVCDPlay.exe
O4 – HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit
O4 – HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 – HKLM..Run: [NAV CfgWiz] C:Program FilesCommon FilesSymantec SharedCfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 – HKLM..Run: [Zone Labs Client] "C:Program Filesone LabsoneAlarmzlclient.exe"
O4 – HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe
O4 – HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – Global Startup: Menu mks_vir.lnk = C:Program FilesMKSBinmks_menu.exe
O4 – Global Startup: PC Alert 4.lnk = C:Program FilesMSIPC Alert 4PCAlert4.exe
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O12 – Plugin for .pdf: C:Program FilesInternet ExplorerPLUGINS ppdf32.dll
O16 – DPF: {27527D31–447B–11D5–A46E–0001023B4289} (CoGSManager Class) – http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O23 – Service: Symantec Event Manager – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
O23 – Service: Symantec Password Validation – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccPwdSvc.exe
O23 – Service: Symantec Settings Manager – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
O23 – Service: GEARSecurity – GEAR Software – C:WINDOWSSYSTEM32GEARSEC.EXE
O23 – Service: MkSUpdateInt – MkS Sp. z o. o. – C:Program FilesMKSinMkSUpdateInt.exe
O23 – Service: MkS_Vir Monitor – Unknown – C:Program FilesMKSBinmksmonsv.exe
O23 – Service: MkS_Scan – Unknown – C:Program FilesMKSBinmks_scan.exe
O23 – Service: Usługa Auto Protect programu Norton AntiVirus – Symantec Corporation – C:Program FilesNorton AntiVirus avapsvc.exe
O23 – Service: NVIDIA Display Driver Service – NVIDIA Corporation – C:WINDOWSSystem32 vsvc32.exe
O23 – Service: SAVScan – Symantec Corporation – C:Program FilesNorton AntiVirusSAVScan.exe
O23 – Service: ScriptBlocking Service – Symantec Corporation – C:PROGRA~1COMMON~1SYMANT~1SCRIPT~1SBServ.exe
O23 – Service: SymWMI Service – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedSecurity CenterSymWSC.exe
O23 – Service: Virtual CD v4 Security service – H+H Software GmbH – C:Program FilesVirtual CD v4Systemvcdsecs.exe
O23 – Service: TrueVector Internet Monitor – Zone Labs Inc. – C:WINDOWSsystem32oneLabsvsmon.exe

Pozdrawiam
jackuc
Dodano
13.02.2005 02:36:09
Bobi_robert:
Mrówek:
3. Usuń wpisy(zaznaczasz wpisy poodane przeze mnie i zaznaczasz "Fix Checked"):


O2 – BHO: InstaFinderK – {4E7BD74F–2B8D–469E–90F0–F66AB581A933} – C:PROGRA~1INSTAF~1INSTAF~1.DLL

O4 – HKLM..Run: [CMESys] "C:Program FilesCommon FilesCMEIICMESys.exe"

Do tego jeszcze to: O4 – Global Startup: GStartup.lnk = C:Program FilesCommon FilesGMTGMT.exe


aha... zapomniało mi się ;–)
Mrówek
Dodano
13.02.2005 00:58:12
Mrówek:
3. Usuń wpisy(zaznaczasz wpisy poodane przeze mnie i zaznaczasz "Fix Checked"):


O2 – BHO: InstaFinderK – {4E7BD74F–2B8D–469E–90F0–F66AB581A933} – C:PROGRA~1INSTAF~1INSTAF~1.DLL

O4 – HKLM..Run: [CMESys] "C:Program FilesCommon FilesCMEIICMESys.exe"

Do tego jeszcze to: O4 – Global Startup: GStartup.lnk = C:Program FilesCommon FilesGMTGMT.exe
Bobi
Dodano
13.02.2005 00:56:35
EL NINO:
Oprocz cmesys i gmt nic nie ma.

Przez Kazaa naciagniesz gowna do kompa.


Zgadza się ;–)
1. Odinstaluj Kazaa Media Desktop, a następnie usuń foldery:
C:Program FilesCommon FilesGMT
C:Program FilesCommon FilesCMEII

2. Wejdź pod:
Mój Komputer–> Panel Sterowania–> Opcje Folderów–> zakłądka "Widok"–> zaznacz "Pokaź ukryte pliki i foldery"–> Naciśnij "OK'.

3. Wejdź pod folder:
C:Documents And SettingsNAZWA_UŻYTKOWNIKAUstawienia Lokalne
i Opróźnij foldery
TEMP
Temporary Internet Files
(UWAGA!! Nie usuwaj ich. Tylko opróźnij. Usunięcie ich moźe spowodować nieprawidłową pracę przeglądarki Internet Explorer i Systemu Windows XP).

3. Usuń wpisy(zaznaczasz wpisy poodane przeze mnie i zaznaczasz "Fix Checked"):


O2 – BHO: InstaFinderK – {4E7BD74F–2B8D–469E–90F0–F66AB581A933} – C:PROGRA~1INSTAF~1INSTAF~1.DLL

O4 – HKLM..Run: [CMESys] "C:Program FilesCommon FilesCMEIICMESys.exe"

O4 – Global Startup: GStartup.lnk = C:Program FilesCommon FilesGMTGMT.exe


4. Skanujesz Ad–Aware SE by pozbyć się innego syfu, który z pewnością masz na dysku ;–)

Pozdrawiam
Mrówek
Dodano
13.02.2005 00:38:16
Oprocz cmesys i gmt nic nie ma.

Przez Kazaa naciagniesz gowna do kompa.
EL NINO
Dodano
13.02.2005 00:26:50
jackuc
Dodano:
13.02.2005 00:22:08
Komentarzy:
7
Strona 1 / 1