Prośba o sprawdzenie LOGA
A wiec mam problem z explorer.exe zaimuje 80%cpu ,tnie mi jak ogladam TV skanowalem NOD32 ale nic niewykryl moze tu cos jest nietak moze ktos pomoc zgory dziekuje:)
Logfile of HijackThis v1.99.0
Scan saved at 15:20:24, on 2005–02–06
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
F:WINDOWSSystem32smss.exe
F:WINDOWSsystem32winlogon.exe
F:WINDOWSsystem32services.exe
F:WINDOWSsystem32lsass.exe
F:WINDOWSsystem32svchost.exe
F:WINDOWSSystem32svchost.exe
F:WINDOWSsystem32spoolsv.exe
F:WINDOWSExplorer.EXE
F:Program FilesEset od32krn.exe
F:WINDOWSSystem32 vsvc32.exe
F:Program FilesJavaj2re1.4.2_06injusched.exe
F:Program FilesWinampwinampa.exe
F:Program FilescFoscFosDNT.exe
F:Program FilesThomsonSpeedTouch USBDragdiag.exe
F:Program FilesEset od32kui.exe
F:WINDOWSSystem32ctfmon.exe
F:Program FilesAutoConnectAutoConnect.exe
F:Program FilesMessengermsmsgs.exe
F:Program FilesKWORLDMpegTV Station PCITVRemoteCtl.exe
F:Program FilesJavaj2re1.4.2_06injavaw.exe
F:WINDOWSSystem32wuauclt.exe
F:Program FilesOperaopera.exe
F:Program FilesEset od32.exe
F:WINDOWSsystem32osk.exe
F:WINDOWSsystem32MSSWCHX.EXE
C:HijackThis.exe
C:HijackThis.exe
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R3 – URLSearchHook: Search Class – {08C06D61–F1F3–4799–86F8–BE1A89362C85} – F:PROGRA~1NEOSTR~1SEARCH~1.DLL (file missing)
O3 – Toolbar: (no name) – {E0E899AB–F487–11D5–8D29–0050BA6940E3} – (no file)
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – F:WINDOWSSystem32msdxm.ocx
O4 – HKLM..Run: [SiSUSBRG] F:WINDOWSSiSUSBrg.exe
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE F:WINDOWSSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [SunJavaUpdateSched] F:Program FilesJavaj2re1.4.2_06injusched.exe
O4 – HKLM..Run: [NeroCheck] F:WINDOWSSystem32NeroCheck.exe
O4 – HKLM..Run: [WinampAgent] F:Program FilesWinampwinampa.exe
O4 – HKLM..Run: [NvMediaCenter] RUNDLL32.EXE F:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit
O4 – HKLM..Run: [TRM] F:documents and settingshubsonustawienia lokalne empTRM.exe
O4 – HKLM..Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 – HKLM..Run: [Overnet] F:Program FilesOverneteDonkey2000.exe –t
O4 – HKLM..Run: [Resume copy] copyfstq.exe /startup
O4 – HKLM..Run: [cFosDNT] F:Program FilescFoscFosDNT.exe
O4 – HKLM..Run: [SpeedTouch USB Diagnostics] "F:Program FilesThomsonSpeedTouch USBDragdiag.exe" /icon
O4 – HKLM..Run: [nod32kui] "F:Program FilesEset od32kui.exe" /WAITSERVICE
O4 – HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 –k
O4 – HKCU..Run: [CTFMON.EXE] F:WINDOWSSystem32ctfmon.exe
O4 – HKCU..Run: [AutoConnect] F:Program FilesAutoConnectAutoConnect.exe
O4 – HKCU..Run: [MSMSGS] "F:Program FilesMessengermsmsgs.exe" /background
O4 – Startup: PartMetBackup.lnk = F:Program FilesJavaj2re1.4.2_06injavaw.exe
O4 – Global Startup: Adobe Gamma Loader.lnk = F:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O4 – Global Startup: MpegTV Station PCITV Remote Control.lnk = F:Program FilesKWORLDMpegTV Station PCITVRemoteCtl.exe
O4 – Global Startup: Microsoft Office.lnk = F:Program FilesMicrosoft OfficeOffice10OSA.EXE
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – F:Program FilesJavaj2re1.4.2_06in pjpi142_06.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – F:Program FilesJavaj2re1.4.2_06in pjpi142_06.dll
O16 – DPF: {6414512B–B978–451D–A0D8–FCFDF33E833C} (WUWebControl Class) – http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1100616530607
O17 – HKLMSystemCCSServicesTcpip..{8AA67871–267B–43AC–9F82–33EC6097DE7F}: NameServer = 194.204.152.34 217.98.63.164
O23 – Service: ISEXEng – Unknown – F:WINDOWSSystem32angelex.exe (file missing)
O23 – Service: NOD32 Kernel Service – Unknown – F:Program FilesEset od32krn.exe
O23 – Service: NVIDIA Display Driver Service – NVIDIA Corporation – F:WINDOWSSystem32 vsvc32.exe
Logfile of HijackThis v1.99.0
Scan saved at 15:20:24, on 2005–02–06
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
F:WINDOWSSystem32smss.exe
F:WINDOWSsystem32winlogon.exe
F:WINDOWSsystem32services.exe
F:WINDOWSsystem32lsass.exe
F:WINDOWSsystem32svchost.exe
F:WINDOWSSystem32svchost.exe
F:WINDOWSsystem32spoolsv.exe
F:WINDOWSExplorer.EXE
F:Program FilesEset od32krn.exe
F:WINDOWSSystem32 vsvc32.exe
F:Program FilesJavaj2re1.4.2_06injusched.exe
F:Program FilesWinampwinampa.exe
F:Program FilescFoscFosDNT.exe
F:Program FilesThomsonSpeedTouch USBDragdiag.exe
F:Program FilesEset od32kui.exe
F:WINDOWSSystem32ctfmon.exe
F:Program FilesAutoConnectAutoConnect.exe
F:Program FilesMessengermsmsgs.exe
F:Program FilesKWORLDMpegTV Station PCITVRemoteCtl.exe
F:Program FilesJavaj2re1.4.2_06injavaw.exe
F:WINDOWSSystem32wuauclt.exe
F:Program FilesOperaopera.exe
F:Program FilesEset od32.exe
F:WINDOWSsystem32osk.exe
F:WINDOWSsystem32MSSWCHX.EXE
C:HijackThis.exe
C:HijackThis.exe
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R3 – URLSearchHook: Search Class – {08C06D61–F1F3–4799–86F8–BE1A89362C85} – F:PROGRA~1NEOSTR~1SEARCH~1.DLL (file missing)
O3 – Toolbar: (no name) – {E0E899AB–F487–11D5–8D29–0050BA6940E3} – (no file)
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – F:WINDOWSSystem32msdxm.ocx
O4 – HKLM..Run: [SiSUSBRG] F:WINDOWSSiSUSBrg.exe
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE F:WINDOWSSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [SunJavaUpdateSched] F:Program FilesJavaj2re1.4.2_06injusched.exe
O4 – HKLM..Run: [NeroCheck] F:WINDOWSSystem32NeroCheck.exe
O4 – HKLM..Run: [WinampAgent] F:Program FilesWinampwinampa.exe
O4 – HKLM..Run: [NvMediaCenter] RUNDLL32.EXE F:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit
O4 – HKLM..Run: [TRM] F:documents and settingshubsonustawienia lokalne empTRM.exe
O4 – HKLM..Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 – HKLM..Run: [Overnet] F:Program FilesOverneteDonkey2000.exe –t
O4 – HKLM..Run: [Resume copy] copyfstq.exe /startup
O4 – HKLM..Run: [cFosDNT] F:Program FilescFoscFosDNT.exe
O4 – HKLM..Run: [SpeedTouch USB Diagnostics] "F:Program FilesThomsonSpeedTouch USBDragdiag.exe" /icon
O4 – HKLM..Run: [nod32kui] "F:Program FilesEset od32kui.exe" /WAITSERVICE
O4 – HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 –k
O4 – HKCU..Run: [CTFMON.EXE] F:WINDOWSSystem32ctfmon.exe
O4 – HKCU..Run: [AutoConnect] F:Program FilesAutoConnectAutoConnect.exe
O4 – HKCU..Run: [MSMSGS] "F:Program FilesMessengermsmsgs.exe" /background
O4 – Startup: PartMetBackup.lnk = F:Program FilesJavaj2re1.4.2_06injavaw.exe
O4 – Global Startup: Adobe Gamma Loader.lnk = F:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O4 – Global Startup: MpegTV Station PCITV Remote Control.lnk = F:Program FilesKWORLDMpegTV Station PCITVRemoteCtl.exe
O4 – Global Startup: Microsoft Office.lnk = F:Program FilesMicrosoft OfficeOffice10OSA.EXE
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – F:Program FilesJavaj2re1.4.2_06in pjpi142_06.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – F:Program FilesJavaj2re1.4.2_06in pjpi142_06.dll
O16 – DPF: {6414512B–B978–451D–A0D8–FCFDF33E833C} (WUWebControl Class) – http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1100616530607
O17 – HKLMSystemCCSServicesTcpip..{8AA67871–267B–43AC–9F82–33EC6097DE7F}: NameServer = 194.204.152.34 217.98.63.164
O23 – Service: ISEXEng – Unknown – F:WINDOWSSystem32angelex.exe (file missing)
O23 – Service: NOD32 Kernel Service – Unknown – F:Program FilesEset od32krn.exe
O23 – Service: NVIDIA Display Driver Service – NVIDIA Corporation – F:WINDOWSSystem32 vsvc32.exe
Odpowiedzi: 1
Te dwa pliki sa z tych "podejrzanych".
F:WINDOWSsystem32osk.exe
F:WINDOWSsystem32MSSWCHX.EXE
R3 – URLSearchHook: Search Class – {08C06D61–F1F3–4799–86F8–BE1A89362C85} – F:PROGRA~1NEOSTR~1SEARCH~1.DLL (file missing)
O3 – Toolbar: (no name) – {E0E899AB–F487–11D5–8D29–0050BA6940E3} – (no file)
O4 – HKLM..Run: [TRM] F:documents and settingshubsonustawienia lokalne empTRM.exe
O4 – HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 –k
O23 – Service: ISEXEng – Unknown – F:WINDOWSSystem32angelex.exe (file missing)
F:WINDOWSsystem32osk.exe
F:WINDOWSsystem32MSSWCHX.EXE
R3 – URLSearchHook: Search Class – {08C06D61–F1F3–4799–86F8–BE1A89362C85} – F:PROGRA~1NEOSTR~1SEARCH~1.DLL (file missing)
O3 – Toolbar: (no name) – {E0E899AB–F487–11D5–8D29–0050BA6940E3} – (no file)
O4 – HKLM..Run: [TRM] F:documents and settingshubsonustawienia lokalne empTRM.exe
O4 – HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 –k
O23 – Service: ISEXEng – Unknown – F:WINDOWSSystem32angelex.exe (file missing)
Strona 1 / 1