Prosze o analize loga :(

Witam wszystkich forumowiczow, prosze was panowie , panie o analize loga z mojego biednego sprzetu, chyba tu cos tego za duzo jak na normalne dzialanie systemu :(((


Logfile of HijackThis v1.99.0
Scan saved at 2:10:37 PM, on 12/23/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSSYSTEM32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:Program FilesPanda SoftwarePanda Antivirus PlatinumFirewallPavFires.exe
C:WINDOWSinet10055services.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE
C:WINDOWSsystem32syscfg32.exe
C:WINDOWSSystem32spooldriversw32x863hpztsb10.exe
C:Program FilesHewlett–PackardHP Software UpdateHPWuSchd2.exe
C:Program FilesHPhpcoretechhpcmpmgr.exe
C:WINDOWSSystem32zxcvbnm.exe
C:WINDOWSSystem32ctfmon.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesTlen.pl len.exe
C:Program FilesiISystem WiperSystemWiper.exe
C:Program FilesPanda SoftwarePanda Antivirus Platinumpavsrv51.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumAVENGINE.EXE
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32devldr32.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumpavProxy.exe
C:WINDOWSSystem32wuauclt.exe
C:Program FilesSkypePhoneSkype.exe
C:Program FilesWebSiteViewer9248448temp.exe
C:Program FilesWebSiteViewer125013.exe
C:Documents and SettingsAnetaDesktopHijackThis.exe

R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.searchportal.info/10055/
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page = c:WINDOWSPCHEALTHHELPCTRSystempanelslank.htm
F3 – REG:win.ini: run=C:WINDOWSinet10055services.exe
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll
O2 – BHO: CCHelper – {0CF0B8EE–6596–11D5–A98E–0003470BB48E} – C:Program FilesPanicwarePop–Up Stopper ProCCHelper.dll
O2 – BHO: PK IE Plugin – {1E1B2879–88FF–11D3–8D96–D7ACAC95951A} – C:WINDOWSSystem32XCVBN~2.DLL
O2 – BHO: (no name) – {5321E378–FFAD–4999–8C62–03CA8155F0B3} – (no file)
O2 – BHO: (no name) – {7B55BB05–0B4D–44fd–81A6–B136188F5DEB} – C:WINDOWSquestmod.dll
O2 – BHO: NAV Helper – {BDF3E430–B101–42AD–A544–FADC6B084872} – C:Program FilesNorton AntiVirusNavShExt.dll
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O3 – Toolbar: Norton AntiVirus – {42CDD1BF–3FFB–4238–8AD1–7859DF00B1D6} – C:Program FilesNorton AntiVirusNavShExt.dll
O3 – Toolbar: Pa&nicware Pop–Up Stopper Pro – {B1E741E7–1E77–40D4–9FD8–51949B9CCBD0} – C:Program FilesPanicwarePop–Up Stopper Propopuppro.dll
O4 – HKLM..Run: [NeroCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [SCANINICIO] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumInicio.exe"
O4 – HKLM..Run: [APVXDWIN] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE" /s
O4 – HKLM..Run: [Configuration Loader] C:WINDOWSsystem32syscfg32.exe
O4 – HKLM..Run: [LoadManageProfile] c:windowsvhost.exe
O4 – HKLM..Run: [xp_system] C:WINDOWSinet10055services.exe
O4 – HKLM..Run: [HPDJ Taskbar Utility] C:WINDOWSSystem32spooldriversw32x863hpztsb10.exe
O4 – HKLM..Run: [HP Software Update] "C:Program FilesHewlett–PackardHP Software UpdateHPWuSchd2.exe"
O4 – HKLM..Run: [HP Component Manager] "C:Program FilesHPhpcoretechhpcmpmgr.exe"
O4 – HKCU..Run: [ctfmon.exe] C:WINDOWSSystem32ctfmon.exe
O4 – HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 – HKCU..Run: [svchost32] C:WINDOWSsvchost32.exe
O4 – HKCU..Run: [Komunikator] C:Program FilesTlen.pl len.exe
O4 – HKCU..Run: [iIWiper] C:Program FilesiISystem WiperSystemWiper.exe m
O4 – HKCU..Run: [xp_system] C:WINDOWSinet10055services.exe
O8 – Extra context menu item: E&xport to Microsoft Excel – res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O9 – Extra button: Research – {92780B25–18CC–41C8–B9BE–3C9C571A8263} – C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O12 – Plugin for .mid: C:Program FilesInternet ExplorerPLUGINS pqtplugin.dll
O12 – Plugin for .mov: C:Program FilesInternet ExplorerPLUGINS pqtplugin.dll
O12 – Plugin for .wav: C:Program FilesInternet ExplorerPLUGINS pqtplugin.dll
O16 – DPF: {31B7EB4E–8B4B–11D1–A789–00A0CC6651A8} (Cult3D ActiveX Player) – http://www.cult3d.com/download/cult.cab
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O18 – Protocol: cetihpz – {CF184AD3–CDCB–4168–A3F7–8E447D129300} – C:Program FilesHPhpcoretechcomphpuiprot.dll
O23 – Service: Norton Internet Security Service – Unknown – C:Program FilesNorton Internet SecurityNISSERV.EXE (file missing)
O23 – Service: Norton Internet Security Accounts Manager – Unknown – C:Program FilesNorton Internet SecurityNISUM.EXE (file missing)
O23 – Service: Panda Firewall Service – Unknown – C:Program FilesPanda SoftwarePanda Antivirus PlatinumFirewallPavFires.exe
O23 – Service: Panda anti–virus service – Unknown – C:Program FilesPanda SoftwarePanda Antivirus Platinumpavsrv51.exe
O23 – Service: Norton Internet Security Proxy Service – Unknown – C:Program FilesNorton Internet SecuritySymProxySvc.exe (file missing)

Odpowiedzi: 1

Wiec od poczatku, sporo tego

Wylacz przywracanie systemu

Zakoncz prcesy w tasku (alt+ctrl+del):
services.exe >> uruchomiony ale nie przez system :!:
syscfg32.exe (Kwbot.S)
zxcvbnm.exe
9248448temp.exe
125013.exe

Usun z dysku:
C:WINDOWSinet10055
syscfg32.exe
zxcvbnm.exe
ZXCVBN~2.DLL
questmod.dll
svchost32.exe
C:Program FilesWebSiteViewer
vhost.exe

Fix checked:
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.searchportal.info/10055/
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page = c:WINDOWSPCHEALTHHELPCTRSystempanelslank.htm
F3 – REG:win.ini: run=C:WINDOWSinet10055services.exe
O2 – BHO: PK IE Plugin – {1E1B2879–88FF–11D3–8D96–D7ACAC95951A} – C:WINDOWSSystem32XCVBN~2.DLL
O2 – BHO: (no name) – {5321E378–FFAD–4999–8C62–03CA8155F0B3} – (no file)
O2 – BHO: (no name) – {7B55BB05–0B4D–44fd–81A6–B136188F5DEB} – C:WINDOWSquestmod.dll
O4 – HKLM..Run: [Configuration Loader] C:WINDOWSsystem32syscfg32.exe
O4 – HKLM..Run: [LoadManageProfile] c:windowsvhost.exe
O4 – HKLM..Run: [xp_system] C:WINDOWSinet10055services.exe
O4 – HKCU..Run: [svchost32] C:WINDOWSsvchost32.exe
O4 – HKCU..Run: [xp_system] C:WINDOWSinet10055services.exe
O23 – Service: Norton Internet Security Service – Unknown – C:Program FilesNorton Internet SecurityNISSERV.EXE (file missing)
O23 – Service: Norton Internet Security Accounts Manager – Unknown – C:Program FilesNorton Internet SecurityNISUM.EXE (file missing)
O23 – Service: Norton Internet Security Proxy Service – Unknown – C:Program FilesNorton Internet SecuritySymProxySvc.exe (file missing)
Bobi
Dodano
23.12.2004 21:38:00
aneta
Dodano:
23.12.2004 21:19:30
Komentarzy:
1
Strona 1 / 1