prośba o sprawdzenie loga

witam, proszę o pomoc w sprawdzeniu loga

Logfile of HijackThis v1.99.0
Scan saved at 13:03:01, on 2005–02–06
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32RunDll32.exe
C:PROGRA~1A4TechMouseAmoumain.exe
C:WINDOWSsystem32d5k.exe
C:Program FilesHotbarin4.5.1.0WeatherOnTray.exe
C:WINDOWSw32dlli.exe
C:Program FilesHPHP Software UpdateHPWuSchd2.exe
C:Program FilesHPhpcoretechhpcmpmgr.exe
C:WINDOWSSystem32 ?skmgr.exe
C:Program FilesHPDigital Imaginginhpqtra08.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesHPDigital Imaginginhpqgalry.exe
C:WINDOWSSystem32wuauclt.exe
C:WINDOWSSystem32wuauclt.exe
C:PROGRA~1WinZipwinzip32.exe
C:DOCUME~1SYLWIAUSTAWI~1TempHijackThis.exe

R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:DOCUME~1SYLWIAUSTAWI~1Tempsp.dll/sp.html
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.onet.pl/
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:DOCUME~1SYLWIAUSTAWI~1Tempsp.dll/sp.html
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page_bak = http://www.onet.pl/
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R3 – URLSearchHook: (no name) – _{CFBFAE00–17A6–11D0–99CB–00C04FD64497} – (no file)
O1 – Hosts: 205.134.176.246 adserver.gadu–gadu.pl
O1 – Hosts: 205.134.176.246 onet.hit.gemius.pl
O1 – Hosts: 205.134.176.246 i.wp.pl
O1 – Hosts: 205.134.176.246 hit.gemius.pl
O2 – BHO: BHObj Class – {00000010–6F7D–442C–93E3–4A4827C2E4C8} – C:WINDOWS em220.dll (file missing)
O2 – BHO: LocalNRDObj Class – {00320615–B6C2–40A6–8F99–F1C52D674FAD} – C:WINDOWSlocalNRD.dll (file missing)
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O2 – BHO: (no name) – {3DFD3572–BF46–5AEF–D103–645505802867} – C:WINDOWSSystem32onmlr.dll
O2 – BHO: BAHelper Class – {A3FDD654–A057–4971–9844–4ED8E67DBBB8} – C:Program FilesSideFindsfbho.dll (file missing)
O2 – BHO: Hotbar – {B195B3B3–8A05–11D3–97A4–0004ACA6948E} – C:Program FilesHotbarin4.5.1.0HbHostIE.dll (file missing)
O2 – BHO: QUICKfind BHO Object – {C08DF07A–3E49–4E25–9AB0–D3882835F153} – C:PROGRA~1TEXTwareQUICKF~1PlugInsIEHelp.dll
O2 – BHO: IEHlprObj Class – {CE7C3CF0–4B15–11D1–ABED–709549C10001} – C:WINDOWSsystem32iemonit.dll
O3 – Toolbar: &Hotbar – {B195B3B3–8A05–11D3–97A4–0004ACA6948E} – C:Program FilesHotbarin4.5.1.0HbHostIE.dll (file missing)
O3 – Toolbar: ISTbar – {5F1ABCDB–A875–46c1–8345–B72A4567E486} – C:Program FilesISTbaristbar.dll (file missing)
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O4 – HKLM..Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 – HKLM..Run: [WheelMouse] C:PROGRA~1A4TechMouseAmoumain.exe
O4 – HKLM..Run: [Internet Explorer Library] C:WINDOWSsystem32ieupdates.exe
O4 – HKLM..Run: [d5k] C:WINDOWSsystem32d5k.exe
O4 – HKLM..Run: [windows auto update] msblast.exe
O4 – HKLM..Run: [b5210f343de2f9e0266322c77fa1770c] C:Program FilesInternet Explorer5210f343de2f9e0266322c77fa1770c.exe
O4 – HKLM..Run: [ICQ Net] C:WINDOWSwinlogon.exe –stealth
O4 – HKLM..Run: [WeatherOnTray] C:Program FilesHotbarin4.5.1.0WeatherOnTray.exe
O4 – HKLM..Run: [Win32 Configuration] videosd32.exe
O4 – HKLM..Run: [Printer] C:WINDOWSw32dlli.exe
O4 – HKLM..Run: [Windows Timer Update] phqghume.exe
O4 – HKLM..Run: [Internet Optimizer] "C:Program FilesInternet Optimizeroptimize.exe"
O4 – HKLM..Run: [dzwokdnsv] C:WINDOWSSystem32mtohkn.exe
O4 – HKLM..Run: [sais] c:program files180solutionssais.exe
O4 – HKLM..Run: [hqhmf] C:WINDOWShqhmf.exe
O4 – HKLM..Run: [FireWire Driver] samx.exe
O4 – HKLM..Run: [Hotbar] C:Program FilesHotbarin4.5.1.0HbInst.exe /Upgrade
O4 – HKLM..Run: [Windows AdTools] C:Program FilesWindows AdToolsWinAdTools.exe
O4 – HKLM..Run: [ScManager] scman.exe
O4 – HKLM..Run: [HP Software Update] "C:Program FilesHPHP Software UpdateHPWuSchd2.exe"
O4 – HKLM..Run: [HP Component Manager] "C:Program FilesHPhpcoretechhpcmpmgr.exe"
O4 – HKLM..Run: [Windows Update AutoUpdate Client Product] wuauct.exe
O4 – HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 –k
O4 – HKLM..Run: [Microsoft Help System] mshelp32.exe
O4 – HKLM..Run: [NOD32POP3] "C:Program FilesEsetpop3scan.exe" /uninstall
O4 – HKLM..RunServices: [Win32 Configuration] videosd32.exe
O4 – HKLM..RunServices: [Windows Timer Update] phqghume.exe
O4 – HKLM..RunServices: [FireWire Driver] samx.exe
O4 – HKLM..RunServices: [ScManager] scman.exe
O4 – HKLM..RunServices: [Windows Update AutoUpdate Client Product] wuauct.exe
O4 – HKLM..RunServices: [Microsoft Help System] mshelp32.exe
O4 – HKCU..Run: [Komunikator] C:Documents and SettingsSYLWIAPulpit len.exe
O4 – HKCU..Run: [Win32 Configuration] videosd32.exe
O4 – HKCU..Run: [Windows Timer Update] phqghume.exe
O4 – HKCU..Run: [FireWire Driver] samx.exe
O4 – HKCU..Run: [Uits] C:Documents and SettingsSYLWIADane aplikacji ual.exe
O4 – HKCU..Run: [ScManager] scman.exe
O4 – HKCU..Run: [Ifhbnyjc] C:WINDOWSSystem32 ?skmgr.exe
O4 – HKCU..Run: [Microsoft Help System] mshelp32.exe
O4 – HKCU..RunServices: [Microsoft Help System] mshelp32.exe
O4 – Global Startup: HP Digital Imaging Monitor.lnk = C:Program FilesHPDigital Imaginginhpqtra08.exe
O4 – Global Startup: HP Image Zone – szybkie uruchamianie.lnk = C:Program FilesHPDigital Imaginginhpqthb08.exe
O4 – Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOfficeOSA9.EXE
O9 – Extra button: SideFind – {10E42047–DEB9–4535–A118–B3F6EC39B807} – C:Program FilesSideFindsidefind.dll (file missing)
O9 – Extra button: Related – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:WINDOWSweb elated.htm
O9 – Extra 'Tools' menuitem: Show &Related Links – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:WINDOWSweb elated.htm
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 – DPF: {6414512B–B978–451D–A0D8–FCFDF33E833C} (WUWebControl Class) – http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1104949245882
O18 – Protocol: cetihpz – {CF184AD3–CDCB–4168–A3F7–8E447D129300} – C:Program FilesHPhpcoretechcomphpuiprot.dll
O18 – Protocol: textwareilluminatorbase – {CE5CD329–1650–414A–8DB0–4CBF72FAED87} – C:WINDOWSSystem32 extwareilluminatorbaseProtocol.dll
O21 – SSODL: Web Event Logger – {79FEACFF–FFCE–815E–A900–316290B5B738} – C:WINDOWSSystem32Behfakig.dll (file missing)
O23 – Service: Pml Driver HPZ12 – HP – C:WINDOWSSystem32HPZipm12.exe

Odpowiedzi: 1

Smiecia poteznie duźo

Wylacz przywracanie

Zakoncz procesy w tasku albo od razu odpal w awaryjnym i usuwaj:
d5k.exe
WeatherOnTray.exe
w32dlli.exe
t?skmgr.exe

Usun z dysku (najpierw kaz systemowi pokazac pliki ukryte i moze rowniez systemowe):
onmlr.dll
C:Program FilesSideFind
C:Program FilesHotbar
iemonit.dll
C:Program FilesISTbar
ieupdates.exe
d5k.exe
msblast.exe
b5210f343de2f9e0266322c77fa1770c.exe
winlogon.exe >> systemowy jest w system32, usun z innej lokalizacji
videosd32.exe
w32dlli.exe
phqghume.exe
C:Program FilesInternet Optimizer
mtohkn.exe
c:program files180solutions
hqhmf.exe
samx.exe
C:Program FilesWindows AdTools
scman.exe
wuauct.exe >> systemowy jest w system32
mshelp32.exe
rual.exe
t?skmgr.exe

Oproznij Tempa



FIX:
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:DOCUME~1SYLWIAUSTAWI~1Tempsp.dll/sp.html
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.onet.pl/
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:DOCUME~1SYLWIAUSTAWI~1Tempsp.dll/sp.html
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page_bak = http://www.onet.pl/
R3 – URLSearchHook: (no name) – _{CFBFAE00–17A6–11D0–99CB–00C04FD64497} – (no file)
O1 – Hosts: 205.134.176.246 adserver.gadu–gadu.pl
O1 – Hosts: 205.134.176.246 onet.hit.gemius.pl
O1 – Hosts: 205.134.176.246 i.wp.pl
O1 – Hosts: 205.134.176.246 hit.gemius.pl
O2 – BHO: BHObj Class – {00000010–6F7D–442C–93E3–4A4827C2E4C8} – C:WINDOWS em220.dll (file missing)
O2 – BHO: LocalNRDObj Class – {00320615–B6C2–40A6–8F99–F1C52D674FAD} – C:WINDOWSlocalNRD.dll (file missing)
O2 – BHO: (no name) – {3DFD3572–BF46–5AEF–D103–645505802867} – C:WINDOWSSystem32onmlr.dll
O2 – BHO: BAHelper Class – {A3FDD654–A057–4971–9844–4ED8E67DBBB8} – C:Program FilesSideFindsfbho.dll (file missing)
O2 – BHO: Hotbar – {B195B3B3–8A05–11D3–97A4–0004ACA6948E} – C:Program FilesHotbarin4.5.1.0HbHostIE.dll (file missing)
O2 – BHO: IEHlprObj Class – {CE7C3CF0–4B15–11D1–ABED–709549C10001} – C:WINDOWSsystem32iemonit.dll
O3 – Toolbar: &Hotbar – {B195B3B3–8A05–11D3–97A4–0004ACA6948E} – C:Program FilesHotbarin4.5.1.0HbHostIE.dll (file missing)
O3 – Toolbar: ISTbar – {5F1ABCDB–A875–46c1–8345–B72A4567E486} – C:Program FilesISTbaristbar.dll (file missing)
O4 – HKLM..Run: [Internet Explorer Library] C:WINDOWSsystem32ieupdates.exe
O4 – HKLM..Run: [d5k] C:WINDOWSsystem32d5k.exe
O4 – HKLM..Run: [windows auto update] msblast.exe
O4 – HKLM..Run: [b5210f343de2f9e0266322c77fa1770c] C:Program FilesInternet Explorer5210f343de2f9e0266322c77fa1770c.exe
O4 – HKLM..Run: [ICQ Net] C:WINDOWSwinlogon.exe –stealth
O4 – HKLM..Run: [WeatherOnTray] C:Program FilesHotbarin4.5.1.0WeatherOnTray.exe
O4 – HKLM..Run: [Win32 Configuration] videosd32.exe
O4 – HKLM..Run: [Printer] C:WINDOWSw32dlli.exe
O4 – HKLM..Run: [Windows Timer Update] phqghume.exe
O4 – HKLM..Run: [Internet Optimizer] "C:Program FilesInternet Optimizeroptimize.exe"
O4 – HKLM..Run: [dzwokdnsv] C:WINDOWSSystem32mtohkn.exe
O4 – HKLM..Run: [sais] c:program files180solutionssais.exe
O4 – HKLM..Run: [hqhmf] C:WINDOWShqhmf.exe
O4 – HKLM..Run: [FireWire Driver] samx.exe
O4 – HKLM..Run: [Hotbar] C:Program FilesHotbarin4.5.1.0HbInst.exe /Upgrade
O4 – HKLM..Run: [Windows AdTools] C:Program FilesWindows AdToolsWinAdTools.exe
O4 – HKLM..Run: [ScManager] scman.exe
O4 – HKLM..RunServices: [Windows Update AutoUpdate Client Product] wuauct.exe
O4 – HKLM..Run: [Windows Update AutoUpdate Client Product] wuauct.exe
O4 – HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 –k
O4 – HKLM..Run: [Microsoft Help System] mshelp32.exe
O4 – HKLM..RunServices: [Win32 Configuration] videosd32.exe
O4 – HKLM..RunServices: [Windows Timer Update] phqghume.exe
O4 – HKLM..RunServices: [FireWire Driver] samx.exe
O4 – HKLM..RunServices: [ScManager] scman.exe
O4 – HKLM..RunServices: [Microsoft Help System] mshelp32.exe
O4 – HKCU..Run: [Win32 Configuration] videosd32.exe
O4 – HKCU..Run: [Windows Timer Update] phqghume.exe
O4 – HKCU..Run: [FireWire Driver] samx.exe
O4 – HKCU..Run: [Uits] C:Documents and SettingsSYLWIADane aplikacji ual.exe
O4 – HKCU..Run: [ScManager] scman.exe
O4 – HKCU..Run: [Ifhbnyjc] C:WINDOWSSystem32 ?skmgr.exe
O4 – HKCU..Run: [Microsoft Help System] mshelp32.exe
O4 – HKCU..RunServices: [Microsoft Help System] mshelp32.exe
O9 – Extra button: SideFind – {10E42047–DEB9–4535–A118–B3F6EC39B807} – C:Program FilesSideFindsidefind.dll (file missing)
O9 – Extra button: Related – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:WINDOWSweb elated.htm
O9 – Extra 'Tools' menuitem: Show &Related Links – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:WINDOWSweb elated.htm
O21 – SSODL: Web Event Logger – {79FEACFF–FFCE–815E–A900–316290B5B738} – C:WINDOWSSystem32Behfakig.dll (file missing)


Jakbys nie mogła znalezc niektorych plikow to sciagnij CopyLock i wklep sciezki do plikow

Znasz to: ??
O18 – Protocol: textwareilluminatorbase – {CE5CD329–1650–414A–8DB0–4CBF72FAED87} – C:WINDOWSSystem32 extwareilluminatorbaseProtocol.dll


Na koniec po wszystkim podaj nowy log
Bobi
Dodano
06.02.2005 14:46:15
sylwia
Dodano:
06.02.2005 14:03:28
Komentarzy:
1
Strona 1 / 1