Prosze o sprawdzenie loga

Witam....ja sprawdzilam loga tylko nie wiem czy to co mo HJ uznala za groźne naprawde musze usunać...o to ten log:

Logfile of HijackThis v1.99.1
Scan saved at 19:06:57, on 2006–03–22
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\ewido anti–malware\ewidoctrl.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Kaspersky Lab\Kaspersky Security Suite\Kaspersky Anti–Hacker\KAVPF.exe
C:\Documents and Settings\1\Pulpit\KAVPF.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\PROGRA~1\mozilla.org\Mozilla\Mozilla.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\1\Pulpit\HijackThis.exe

R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R0 – HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
F2 – REG:system.ini: Shell=explorer.exe
O2 – BHO: Yahoo! Toolbar Helper – {02478D38–C3F9–4EFB–9B51–7695ECA05670} – C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 – BHO: bho2gr Class – {31FF080D–12A3–439A–A2EF–4BA95A3148E8} – C:\Program Files\GetRight\xx2gr.dll
O2 – BHO: Burn4Free Toolbar Helper – {F8E5CA21–C27B–43e7–B2BE–4CA93C9F9A1F} – C:\Program Files\Burn4Free Toolbar\v2.0.0.4\Burn4Free_Toolbar.dll
O3 – Toolbar: Yahoo! Toolbar – {EF99BD32–C1FB–11D2–892F–0090271D4F88} – C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 – Toolbar: Burn4Free Toolbar – {70DE7956–479D–4eb7–8641–2B45774C350E} – C:\Program Files\Burn4Free Toolbar\v2.0.0.4\Burn4Free_Toolbar.dll
O4 – HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 – HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 – HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 – HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 – HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 – HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 – HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 – HKLM\..\Run: [Super X Desktop Version 3.4.0730] E:\Super X Desktop\SXDesk.exe
O4 – HKLM\..\Run: [Spik] C:\Program Files\Spik\Spik.exe –autostart
O4 – HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 – HKCU\..\Run: [Skype] "E:\Phone\Skype.exe" /nosplash /minimized
O4 – HKCU\..\Run: [Zegarynka] C:\Documents and Settings\1\Pulpit\zegarynka(dobreprogramy.pl)\Zegarynka.exe
O4 – HKCU\..\Run: [AQQ] C:\DOCUME~1\1\Pulpit\anii\AQQ\AQQ.exe
O4 – HKCU\..\Run: [Komunikator] C:\Program Files\Tlen.pl\tlen.exe
O4 – HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\mozilla.org\Mozilla\Mozilla.exe" –turbo
O4 – HKCU\..\Run: [Gadu–Gadu] "C:\PROGRA~1\GADU–G~1\GADU–G~1\gg.exe" /tray
O4 – Global Startup: Kaspersky Anti–Hacker.lnk = ?
O4 – Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 – Extra context menu item: Download with GetRight – C:\Program Files\GetRight\GRdownload.htm
O8 – Extra context menu item: Open with GetRight Browser – C:\Program Files\GetRight\GRbrowse.htm
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 – Extra button: eBay – Homepage – {EF79EAC5–3452–4E02–B8BD–BA4C89F1AC7A} – C:\Program Files\IrfanView\Ebay\Ebay.htm
O12 – Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 – Trusted Zone: http://arcaonline.arcabit.com
O15 – Trusted Zone: http://skaner.mks.com.pl
O15 – Trusted Zone: http://www.mks.com.pl
O16 – DPF: {17492023–C23A–453E–A040–C7C580BBF700} (Windows Genuine Advantage Validation Tool) – http://go.microsoft.com/fwlink/?linkid=39204
O16 – DPF: {18506D80–9B80–11D4–82C2–0080C8D7ED4A} (GameDesire Roulette) – http://67.15.101.3/g_bin/pl/roulette_2_0_0_15.cab
O16 – DPF: {3D8700FB–86A4–4CB4–B738–6F0FC016AC7D} (MainControl Class) – http://arcaonline.arcabit.com/ArcaOnline.cab
O16 – DPF: {41ACD49D–1974–791A–0981–AA9872721044} (Ganymede Board Games) – http://67.15.101.3/g_bin/pl/boards_2_0_0_22.cab
O16 – DPF: {4B4513E2–4E57–43DF–9496–FCD37E9DFA64} (GameDesire Sea Battle) – http://67.15.101.3/g_bin/pl/navy_2_0_0_20.cab
O16 – DPF: {5D86DDB5–BDF9–441B–9E9E–D4730F4EE499} (BDSCANONLINE Control) – http://www.bitdefender.com/scan8/oscan8.cab
O16 – DPF: {6414512B–B978–451D–A0D8–FCFDF33E833C} (WUWebControl Class) – http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1115899759040
O16 – DPF: {6E32070A–766D–4EE6–879C–DC1FA91D2FC3} (MUWebControl Class) – http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1122636889179
O16 – DPF: {74D05D43–3236–11D4–BDCD–00C04F9A3B61} (HouseCall Control) – http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 – DPF: {9A9307A0–7DA4–4DAF–B042–5009F29E09E1} (ActiveScan Installer Class) – http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
O16 – DPF: {EF791A6B–FC12–4C68–99EF–FB9E207A39E6} (McFreeScan Class) – http://download.mcafee.com/molbin/iss–loc/vso/en–us/tools/mcfscan/2,0,0,4608/mcfscan.cab
O17 – HKLM\System\CCS\Services\Tcpip\..\{0CE5E9B6–883C–4D69–8BF8–F50E3B926EB2}: NameServer = 10.1.88.1,194.204.159.1,194.204.152.34
O17 – HKLM\System\CS1\Services\Tcpip\..\{0CE5E9B6–883C–4D69–8BF8–F50E3B926EB2}: NameServer = 10.1.88.1,194.204.159.1,194.204.152.34
O17 – HKLM\System\CS2\Services\Tcpip\..\{0CE5E9B6–883C–4D69–8BF8–F50E3B926EB2}: NameServer = 10.1.88.1,194.204.159.1,194.204.152.34
O18 – Protocol: wpmsg – {2E0AC5A0–3597–11D6–B3ED–0001021DC1C3} – C:\Program Files\Spik\url_wpmsg.dll
O20 – Winlogon Notify: WgaLogon – C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 – Service: AVK Service (AVKService) – Unknown owner – C:\Program Files\AntiVirenKit 2006\AVKService.exe (file missing)
O23 – Service: Straźnik AVK (AVKWCtl) – Unknown owner – C:\Program Files\AntiVirenKit 2006\AVKWCtl.exe (file missing)
O23 – Service: Diskeeper – Diskeeper Corporation – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 – Service: ewido security suite control – ewido networks – C:\Program Files\ewido anti–malware\ewidoctrl.exe
O23 – Service: ewido security suite guard – ewido networks – C:\Program Files\ewido anti–malware\ewidoguard.exe
O23 – Service: InstallDriver Table Manager (IDriverT) – Macrovision Corporation – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 – Service: InCD Helper (InCDsrv) – Nero AG – C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 – Service: iPodService – Apple Computer, Inc. – C:\Program Files\iPod\bin\iPodService.exe
O23 – Service: kavsvc – Kaspersky Lab – C:\Program Files\Kaspersky Lab\Kaspersky Security Suite\Kaspersky Anti–Virus Personal\kavsvc.exe
O23 – Service: LightScribeService Direct Disc Labeling Service (LightScribeService) – Hewlett–Packard Company – C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 – Service: lxcg_device – Unknown owner – C:\WINDOWS\system32\lxcgcoms.exe

Odpowiedzi: 5

oki......dzieki za pomoc..:D
yvonna
Dodano
25.03.2006 16:00:20
Ok EL NINO no to się wyjaśniło. przyznaje się ze link który podałem źle przeanlizowałem. Ale jak to się mówi człowiek całe źycie się uczy a....... :wink:

Czyli wpisy zostają są OK
Wiewia
Dodano
24.03.2006 17:59:43
Pierdzielicie Panowie.
To IP sieci wewnetrznej. Najprawdopodobniej serwera, routera, czy czego co udostepnia net. Zadne holenderskie, czy majace zwiazek z iana.org i p2p.

Zreszta – skoro juz podaje sie linka wynikowego z ripe.net, nalezaloby doczytac rezultat szukania:

descr: Class A address space for private internets
EL NINO
Dodano
24.03.2006 01:33:27
Te wpisy mają coś wspólnego z http://www.iana.org/
i wiąźą się chyba z p2p.
k@@cor
Dodano
23.03.2006 22:53:33
F2 – REG:system.ini: Shell=explorer.exe


Było by tylko to do usunięcia

Ale..

O17 – HKLM\System\CCS\Services\Tcpip\..\{0CE5E9B6–883C–4D69–8BF8–F50E3B926EB2}: NameServer = 10.1.88.1,194.204.159.1,194.204.152.34
O17 – HKLM\System\CS1\Services\Tcpip\..\{0CE5E9B6–883C–4D69–8BF8–F50E3B926EB2}: NameServer = 10.1.88.1,194.204.159.1,194.204.152.34
O17 – HKLM\System\CS2\Services\Tcpip\..\{0CE5E9B6–883C–4D69–8BF8–F50E3B926EB2}: NameServer = 10.1.88.1,194.204.159.1,194.204.152.34


Dziwią mnie te wpisy zaznaczone niby są holenderskie http://www.ripe.net/fcgi–bin/whois?form_type=simple&full_query_string=&searchtext=10.1.88.1&do_search=Search

W jaki sposób łaczych się z netem ? Neostrada? (oczywiście narazie tego nie usuwasz)
Wiewia
Dodano
23.03.2006 21:26:16
yvonna
Dodano:
22.03.2006 20:11:37
Komentarzy:
5
Strona 1 / 1