Proszę o sprawdzenie Loga

Witam!!!

Logfile of HijackThis v1.99.1
Scan saved at 21:17:59, on 2005–05–16
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/System32/Ati2evxx.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/Ati2evxx.exe
C:/WINDOWS/system32/spoolsv.exe
C:/WINDOWS/Explorer.EXE
C:/Program Files/Alwil Software/Avast4/aswUpdSv.exe
C:/Program Files/Alwil Software/Avast4/ashServ.exe
C:/Program Files/Common Files/EPSON/EBAPI/SAgent2.exe
C:/WINDOWS/System32/svchost.exe
C:/Program Files/ATI Technologies/ATI Control Panel/atiptaxx.exe
C:/WINDOWS/System32/spool/DRIVERS/W32X86/3/E_S10IC2.EXE
C:/PROGRA~1/ALWILS~1/Avast4/ashDisp.exe
C:/spywarebegone/SpywareBeGone.exe
C:/Program Files/SAGEM/SAGEM F@st 800–840/dslmon.exe
C:/Program Files/Alwil Software/Avast4/ashMaiSv.exe
C:/Program Files/Alwil Software/Avast4/ashWebSv.exe
C:/Program Files/Spyware Doctor/swdoctor.exe
C:/WINDOWS/System32/devldr32.exe
C:/Program Files/Internet Explorer/iexplore.exe
C:/Documents and Settings/MAREK/Pulpit/HijackThis najnowszy.exe

R1 – HKCU/Software/Microsoft/Internet Explorer/Main,Search Page = http://www.onet.pl
R0 – HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.onet.pl/
R1 – HKCU/Software/Microsoft/Internet Connection Wizard,ShellNext = http://www.idg.pl/
R1 – HKCU/Software/Microsoft/Internet Explorer/Main,Window Title = Program Microsoft Internet Explorer dostarczony przez IDG.pl
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:/Program Files/Adobe/Acrobat 6.0 CE/Reader/ActiveX/AcroIEHelper.dll
O2 – BHO: PCTools Site Guard – {5C8B2A36–3DB1–42A4–A3CB–D426709BBFEB} – C:/PROGRA~1/SPYWAR~1/tools/iesdsg.dll
O2 – BHO: PCTools Browser Monitor – {B56A7D7D–6927–48C8–A975–17DF180C71AC} – C:/PROGRA~1/SPYWAR~1/tools/iesdpb.dll
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:/WINDOWS/System32/msdxm.ocx
O4 – HKLM/../Run: [AtiPTA] C:/Program Files/ATI Technologies/ATI Control Panel/atiptaxx.exe
O4 – HKLM/../Run: [EPSON Stylus C42 Series] C:/WINDOWS/System32/spool/DRIVERS/W32X86/3/E_S10IC2.EXE /P23 "EPSON Stylus C42 Series" /O6 "USB001" /M "Stylus C42"
O4 – HKLM/../Run: [Onet.pl AutoUpdate] "C:/Program Files/Common Files/Onet.pl/NewAutoUpdate.exe" /updateexetsr
O4 – HKLM/../Run: [avast!] C:/PROGRA~1/ALWILS~1/Avast4/ashDisp.exe
O4 – HKLM/../Run: [NeroCheck] C:/WINDOWS/System32/NeroCheck.exe
O4 – HKLM/../Run: [Repair Registry Pro] C:/Program Files/Repair Registry Pro/RepairRegistryPro.exe –s
O4 – HKLM/../Run: [adiras] adiras.exe
O4 – HKLM/../Run: [Windows Logon Application] C:/WINDOWS/System32/logon.exe
O4 – HKCU/../Run: [Spyware Begone] "C:/spywarebegone/SpywareBeGone.exe" –FastScan
O4 – Global Startup: Adobe Gamma Loader.lnk = C:/Program Files/Common Files/Adobe/Calibration/Adobe Gamma Loader.exe
O4 – Global Startup: DSLMON.lnk = C:/Program Files/SAGEM/SAGEM F@st 800–840/dslmon.exe
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:/PROGRA~1/MICROS~2/OFFICE11/EXCEL.EXE/3000
O9 – Extra button: Spyware Doctor – {2D663D1A–8670–49D9–A1A5–4C56B4E14E84} – C:/PROGRA~1/SPYWAR~1/tools/iesdpb.dll
O9 – Extra button: Badanie – {92780B25–18CC–41C8–B9BE–3C9C571A8263} – C:/PROGRA~1/MICROS~2/OFFICE11/REFIEBAR.DLL
O12 – Plugin for .spop: C:/Program Files/Internet Explorer/Plugins/NPDocBox.dll
O16 – DPF: {24311111–1111–1121–1111–111191113457} – file://c:/eied_s7.cab
O17 – HKLM/System/CCS/Services/Tcpip/../{B190ACAE–B78F–4FA7–B5F2–28FCAF0A20F6}: NameServer = 69.50.184.86 195.225.176.110
O23 – Service: avast! iAVS4 Control Service (aswUpdSv) – Unknown owner – C:/Program Files/Alwil Software/Avast4/aswUpdSv.exe
O23 – Service: Ati HotKey Poller – ATI Technologies Inc. – C:/WINDOWS/System32/Ati2evxx.exe
O23 – Service: ATI Smart – Unknown owner – C:/WINDOWS/system32/ati2sgag.exe
O23 – Service: Autodesk Licensing Service – Autodesk, Inc. – C:/Program Files/Common Files/Autodesk Shared/Service/AdskScSrv.exe
O23 – Service: avast! Antivirus – Unknown owner – C:/Program Files/Alwil Software/Avast4/ashServ.exe
O23 – Service: avast! Mail Scanner – Unknown owner – C:/Program Files/Alwil Software/Avast4/ashMaiSv.exe" /service (file missing)
O23 – Service: avast! Web Scanner – Unknown owner – C:/Program Files/Alwil Software/Avast4/ashWebSv.exe" /service (file missing)
O23 – Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) – SEIKO EPSON CORPORATION – C:/Program Files/Common Files/EPSON/EBAPI/SAgent2.exe

Dzięki :D

Odpowiedzi: 2

To co mialo wyleciec – wylecialo, ale został jeden mały smieciuch:
O2 – BHO: (no name) – {5C8B2A36–3DB1–42A4–A3CB–D426709BBFEB} – (no file)

Przypomnij sobie TEN temat, juz wtedy pisałem o tych fałszywych programach anty
Co do tych DNS–ów to na razie czekamy, a Ty pilnuj i od czasu do czasu sprawdzaj czy sie nie odtwarzają.
W razie czego trzeba bedzie wnikliwiej poszukać jakiegos krytego badziewia.
Bobi
Dodano
17.05.2005 00:41:00
Dzięki Ci Bobi !!!
Zrobiłem wszystko wg wskazówek i tak mi się wydaje, źe komp zbystrzał.
Czy mógłbyś jeszcze raz zerknąć na mojego nowego Loga ?
Z góry dziękuję :D

Logfile of HijackThis v1.99.1
Scan saved at 22:22:13, on 2005–05–16
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/System32/Ati2evxx.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/Ati2evxx.exe
C:/WINDOWS/Explorer.EXE
C:/WINDOWS/system32/spoolsv.exe
C:/Program Files/Alwil Software/Avast4/aswUpdSv.exe
C:/Program Files/Alwil Software/Avast4/ashServ.exe
C:/Program Files/Common Files/EPSON/EBAPI/SAgent2.exe
C:/WINDOWS/System32/svchost.exe
C:/Program Files/ATI Technologies/ATI Control Panel/atiptaxx.exe
C:/WINDOWS/System32/spool/DRIVERS/W32X86/3/E_S10IC2.EXE
C:/PROGRA~1/ALWILS~1/Avast4/ashDisp.exe
C:/Program Files/SAGEM/SAGEM F@st 800–840/dslmon.exe
C:/Program Files/Alwil Software/Avast4/ashWebSv.exe
C:/Program Files/Alwil Software/Avast4/ashMaiSv.exe
C:/Documents and Settings/MAREK/Pulpit/HijackThis najnowszy.exe

R1 – HKCU/Software/Microsoft/Internet Explorer/Main,Search Page = http://www.onet.pl
R0 – HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.onet.pl/
R1 – HKCU/Software/Microsoft/Internet Connection Wizard,ShellNext = http://www.idg.pl/
R1 – HKCU/Software/Microsoft/Internet Explorer/Main,Window Title = Program Microsoft Internet Explorer dostarczony przez IDG.pl
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:/Program Files/Adobe/Acrobat 6.0 CE/Reader/ActiveX/AcroIEHelper.dll
O2 – BHO: (no name) – {5C8B2A36–3DB1–42A4–A3CB–D426709BBFEB} – (no file)
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:/WINDOWS/System32/msdxm.ocx
O4 – HKLM/../Run: [AtiPTA] C:/Program Files/ATI Technologies/ATI Control Panel/atiptaxx.exe
O4 – HKLM/../Run: [EPSON Stylus C42 Series] C:/WINDOWS/System32/spool/DRIVERS/W32X86/3/E_S10IC2.EXE /P23 "EPSON Stylus C42 Series" /O6 "USB001" /M "Stylus C42"
O4 – HKLM/../Run: [Onet.pl AutoUpdate] "C:/Program Files/Common Files/Onet.pl/NewAutoUpdate.exe" /updateexetsr
O4 – HKLM/../Run: [avast!] C:/PROGRA~1/ALWILS~1/Avast4/ashDisp.exe
O4 – HKLM/../Run: [NeroCheck] C:/WINDOWS/System32/NeroCheck.exe
O4 – HKLM/../Run: [Repair Registry Pro] C:/Program Files/Repair Registry Pro/RepairRegistryPro.exe –s
O4 – HKLM/../Run: [adiras] adiras.exe
O4 – Global Startup: Adobe Gamma Loader.lnk = C:/Program Files/Common Files/Adobe/Calibration/Adobe Gamma Loader.exe
O4 – Global Startup: DSLMON.lnk = C:/Program Files/SAGEM/SAGEM F@st 800–840/dslmon.exe
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:/PROGRA~1/MICROS~2/OFFICE11/EXCEL.EXE/3000
O9 – Extra button: Badanie – {92780B25–18CC–41C8–B9BE–3C9C571A8263} – C:/PROGRA~1/MICROS~2/OFFICE11/REFIEBAR.DLL
O12 – Plugin for .spop: C:/Program Files/Internet Explorer/Plugins/NPDocBox.dll
O16 – DPF: {9A9307A0–7DA4–4DAF–B042–5009F29E09E1} (ActiveScan Installer Class) – http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 – Service: avast! iAVS4 Control Service (aswUpdSv) – Unknown owner – C:/Program Files/Alwil Software/Avast4/aswUpdSv.exe
O23 – Service: Ati HotKey Poller – ATI Technologies Inc. – C:/WINDOWS/System32/Ati2evxx.exe
O23 – Service: ATI Smart – Unknown owner – C:/WINDOWS/system32/ati2sgag.exe
O23 – Service: Autodesk Licensing Service – Autodesk, Inc. – C:/Program Files/Common Files/Autodesk Shared/Service/AdskScSrv.exe
O23 – Service: avast! Antivirus – Unknown owner – C:/Program Files/Alwil Software/Avast4/ashServ.exe
O23 – Service: avast! Mail Scanner – Unknown owner – C:/Program Files/Alwil Software/Avast4/ashMaiSv.exe" /service (file missing)
O23 – Service: avast! Web Scanner – Unknown owner – C:/Program Files/Alwil Software/Avast4/ashWebSv.exe" /service (file missing)
O23 – Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) – SEIKO EPSON CORPORATION – C:/Program Files/Common Files/EPSON/EBAPI/SAgent2.exe

Pozdrowienia
Marek2
Dodano
17.05.2005 00:29:32
Marek2
Dodano:
16.05.2005 23:22:53
Komentarzy:
2
Strona 1 / 1