Prosze o analize loga
Logfile of HijackThis v1.97.7
Scan saved at 13:24:58, on 2005–01–29
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.exe
C:WINDOWSSystem32Fmctrl.EXE
C:Program Filesone LabsoneAlarmzlclient.exe
C:Program FilesAdmilli ServiceAdmilliServ.exe
C:Program FilesWinampwinampa.exe
C:WINDOWSSystem32 ibs3.exe
C:Program FilesSpyFighterSpyFighterScanner.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesGadu–Gadugg.exe
C:Program FilesSkypePhoneSkype.exe
C:Program FilesAdmilli ServiceAdmilliKeep.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32ONELABSvsmon.exe
C:WINDOWSsystem32init32m.exe
C:WINDOWSSystem32wuauclt.exe
C:Program FilesInternet ExplorerIEXPLORE.EXE
E:InstalkiHijackThis.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://find–on–the–net.com/search.htm
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://web–searcher.info
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
F0 – system.ini: Shell=Explorer.exe init32m.exe
F2 – REG:system.ini: Shell=Explorer.exe init32m.exe
O2 – BHO: (no name) – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 5.0 CEReaderActiveXAcroIEHelper.ocx
O2 – BHO: (no name) – {2C5175A2–ADF3–4F57–AB70–BA90FD60A383} – C:Program FilesIESearchToolbarIESearchToolbar.dll
O2 – BHO: (no name) – {9896231A–C487–43A5–8369–6EC9B0A96CC0} – C:WINDOWSSystem32WStart.dll
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O3 – Toolbar: IE Search Toolbar – {EB381422–F797–4A98–A266–9DC490821907} – C:Program FilesIESearchToolbarIESearchToolbar.dll
O4 – HKLM..Run: [NeroCheck] C:WINDOWSSystem32NeroCheck.exe
O4 – HKLM..Run: [SystemTray] SysTray.Exe
O4 – HKLM..Run: [FmctrlTray] Fmctrl.EXE
O4 – HKLM..Run: [Zone Labs Client] "C:Program Filesone LabsoneAlarmzlclient.exe"
O4 – HKLM..Run: [Admilli Service] C:Program FilesAdmilli ServiceAdmilliServ.exe
O4 – HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe
O4 – HKLM..Run: [System32] "user32.exe" –user
O4 – HKLM..Run: [tibs3] C:WINDOWSSystem32 ibs3.exe
O4 – HKLM..Run: [ieexec.exe] ieexec.exe
O4 – HKLM..Run: [wuviewer] C:WINDOWSSystem32wuviewer.exe
O4 – HKLM..Run: [desktop] C:WINDOWSSystem32desktop.exe
O4 – HKLM..Run: [SpyFighterMonitor] "C:Program FilesSpyFighterSpyFighterScanner.exe" monitor
O4 – HKLM..RunServices: [wuviewer] C:WINDOWSSystem32wuviewer.exe
O4 – HKLM..RunServices: [desktop] C:WINDOWSSystem32desktop.exe
O4 – HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – HKCU..Run: [eMuleAutoStart] C:Program FileseMuleemule.exe –AutoStart
O4 – HKCU..Run: [wuviewer] C:WINDOWSSystem32wuviewer.exe
O4 – HKCU..Run: [desktop] C:WINDOWSSystem32desktop.exe
O4 – HKCU..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /nosplash /minimized
O4 – HKLM..RunOnce: [Srv32 spool service] C:WINDOWSSystem32spoolsrv32.exe
O4 – HKCU..RunOnce: [Srv32 spool service] C:WINDOWSSystem32spoolsrv32.exe
O4 – Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~1Office10EXCEL.EXE/3000
O9 – Extra button: Related (HKLM)
O9 – Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 – DPF: {15AD4789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://static.windupdates.com/cab/CDTInc/ie/bridge–c282.cab
O16 – DPF: {33564D57–0000–0010–8000–00AA00389B71} – http://download.microsoft.com/download/F/6/E/F6E491A6–77E1–4E20–9F5F–94901338C922/wmv9VCM.CAB
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
Scan saved at 13:24:58, on 2005–01–29
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.exe
C:WINDOWSSystem32Fmctrl.EXE
C:Program Filesone LabsoneAlarmzlclient.exe
C:Program FilesAdmilli ServiceAdmilliServ.exe
C:Program FilesWinampwinampa.exe
C:WINDOWSSystem32 ibs3.exe
C:Program FilesSpyFighterSpyFighterScanner.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesGadu–Gadugg.exe
C:Program FilesSkypePhoneSkype.exe
C:Program FilesAdmilli ServiceAdmilliKeep.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32ONELABSvsmon.exe
C:WINDOWSsystem32init32m.exe
C:WINDOWSSystem32wuauclt.exe
C:Program FilesInternet ExplorerIEXPLORE.EXE
E:InstalkiHijackThis.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://find–on–the–net.com/search.htm
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://web–searcher.info
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
F0 – system.ini: Shell=Explorer.exe init32m.exe
F2 – REG:system.ini: Shell=Explorer.exe init32m.exe
O2 – BHO: (no name) – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 5.0 CEReaderActiveXAcroIEHelper.ocx
O2 – BHO: (no name) – {2C5175A2–ADF3–4F57–AB70–BA90FD60A383} – C:Program FilesIESearchToolbarIESearchToolbar.dll
O2 – BHO: (no name) – {9896231A–C487–43A5–8369–6EC9B0A96CC0} – C:WINDOWSSystem32WStart.dll
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O3 – Toolbar: IE Search Toolbar – {EB381422–F797–4A98–A266–9DC490821907} – C:Program FilesIESearchToolbarIESearchToolbar.dll
O4 – HKLM..Run: [NeroCheck] C:WINDOWSSystem32NeroCheck.exe
O4 – HKLM..Run: [SystemTray] SysTray.Exe
O4 – HKLM..Run: [FmctrlTray] Fmctrl.EXE
O4 – HKLM..Run: [Zone Labs Client] "C:Program Filesone LabsoneAlarmzlclient.exe"
O4 – HKLM..Run: [Admilli Service] C:Program FilesAdmilli ServiceAdmilliServ.exe
O4 – HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe
O4 – HKLM..Run: [System32] "user32.exe" –user
O4 – HKLM..Run: [tibs3] C:WINDOWSSystem32 ibs3.exe
O4 – HKLM..Run: [ieexec.exe] ieexec.exe
O4 – HKLM..Run: [wuviewer] C:WINDOWSSystem32wuviewer.exe
O4 – HKLM..Run: [desktop] C:WINDOWSSystem32desktop.exe
O4 – HKLM..Run: [SpyFighterMonitor] "C:Program FilesSpyFighterSpyFighterScanner.exe" monitor
O4 – HKLM..RunServices: [wuviewer] C:WINDOWSSystem32wuviewer.exe
O4 – HKLM..RunServices: [desktop] C:WINDOWSSystem32desktop.exe
O4 – HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – HKCU..Run: [eMuleAutoStart] C:Program FileseMuleemule.exe –AutoStart
O4 – HKCU..Run: [wuviewer] C:WINDOWSSystem32wuviewer.exe
O4 – HKCU..Run: [desktop] C:WINDOWSSystem32desktop.exe
O4 – HKCU..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /nosplash /minimized
O4 – HKLM..RunOnce: [Srv32 spool service] C:WINDOWSSystem32spoolsrv32.exe
O4 – HKCU..RunOnce: [Srv32 spool service] C:WINDOWSSystem32spoolsrv32.exe
O4 – Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~1Office10EXCEL.EXE/3000
O9 – Extra button: Related (HKLM)
O9 – Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 – DPF: {15AD4789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://static.windupdates.com/cab/CDTInc/ie/bridge–c282.cab
O16 – DPF: {33564D57–0000–0010–8000–00AA00389B71} – http://download.microsoft.com/download/F/6/E/F6E491A6–77E1–4E20–9F5F–94901338C922/wmv9VCM.CAB
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
Odpowiedzi: 2
W zadnym wypadku
C:WINDOWSSystem32Fmctrl.EXE
poniewaz to Genius SM–Live Control Panel
Natomiast dodatkowo, bezwarunkowo:
C:Program FilesAdmilli ServiceAdmilliServ.exe
C:Program FilesAdmilli ServiceAdmilliKeep.exe
O2 – BHO: (no name) – {2C5175A2–ADF3–4F57–AB70–BA90FD60A383} – C:Program FilesIESearchToolbarIESearchToolbar.dll
O4 – HKLM..Run: [Admilli Service] C:Program FilesAdmilli ServiceAdmilliServ.exe
O4 – HKLM..RunOnce: [Srv32 spool service] C:WINDOWSSystem32spoolsrv32.exe
O4 – HKCU..RunOnce: [Srv32 spool service] C:WINDOWSSystem32spoolsrv32.exe
Kacper, znowu babol :P .
C:WINDOWSSystem32Fmctrl.EXE
poniewaz to Genius SM–Live Control Panel
Natomiast dodatkowo, bezwarunkowo:
C:Program FilesAdmilli ServiceAdmilliServ.exe
C:Program FilesAdmilli ServiceAdmilliKeep.exe
O2 – BHO: (no name) – {2C5175A2–ADF3–4F57–AB70–BA90FD60A383} – C:Program FilesIESearchToolbarIESearchToolbar.dll
O4 – HKLM..Run: [Admilli Service] C:Program FilesAdmilli ServiceAdmilliServ.exe
O4 – HKLM..RunOnce: [Srv32 spool service] C:WINDOWSSystem32spoolsrv32.exe
O4 – HKCU..RunOnce: [Srv32 spool service] C:WINDOWSSystem32spoolsrv32.exe
Kacper, znowu babol :P .
Usuń:
MKS On–Line
:arrow: http://skaner.mks.com.pl/
C:WINDOWSSystem32Fmctrl.EXE
C:WINDOWSSystem32 ibs3.exe
C:WINDOWSsystem32init32m.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://find–on–the–net.com/search.htm
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://web–searcher.info
F0 – system.ini: Shell=Explorer.exe init32m.exe
F2 – REG:system.ini: Shell=Explorer.exe init32m.exe
O2 – BHO: (no name) – {9896231A–C487–43A5–8369–6EC9B0A96CC0} – C:WINDOWSSystem32WStart.dll
O3 – Toolbar: IE Search Toolbar – {EB381422–F797–4A98–A266–9DC490821907} – C:Program FilesIESearchToolbarIESearchToolbar.dll
O4 – HKLM..Run: [System32] "user32.exe" –user
O4 – HKLM..Run: [tibs3] C:WINDOWSSystem32 ibs3.exe
O4 – HKLM..Run: [ieexec.exe] ieexec.exe
O4 – HKLM..Run: [wuviewer] C:WINDOWSSystem32wuviewer.exe
O4 – HKLM..Run: [desktop] C:WINDOWSSystem32desktop.exe
O4 – HKLM..RunServices: [wuviewer] C:WINDOWSSystem32wuviewer.exe
O4 – HKLM..RunServices: [desktop] C:WINDOWSSystem32desktop.exe
O4 – HKCU..Run: [wuviewer] C:WINDOWSSystem32wuviewer.exe
O4 – HKCU..Run: [desktop] C:WINDOWSSystem32desktop.exe
O9 – Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 – DPF: {15AD4789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://static.windupdates.com/cab/CDTInc/ie/bridge–c282.cab
MKS On–Line
:arrow: http://skaner.mks.com.pl/
Strona 1 / 1