Proszę o sprawdzenie loga

Logfile of HijackThis v1.99.1
Scan saved at 14:22:19, on 2005–04–20
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\program files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\Program Files\lotus\notes\ntmulti.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\NWTRAY.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Winamp\winampa.exe
C:\Windows\Pbm.exe
C:\Windows\System32\Services\{ADF7D696–916B–4878–9D4B–63A57C8642C9}\SVCHOST.EXE
C:\Windows\System32\winldra.exe
C:\Windows\System32\icasServ.exe
C:\Windows\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Gadu–Gadu\gg.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\ivo\UniSpiker\unispiker.exe
C:\Program Files\Kalendarz XP\Kalendarz.exe
C:\Windows\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\Katalog tymczasowy 1 dla hijackthis.zip\HijackThis.exe

R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://81.222.131.49/index.php
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ipcons.biz/index.php?id=186
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://81.222.131.49/index.php
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://81.222.131.49/index.php
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://81.222.131.49/index.php
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://81.222.131.49/index.php
R0 – HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 – Default URLSearchHook is missing
O2 – BHO: (no name) – {1027E318–4049–4862–8D64–25535B0494B6} – (no file)
O2 – BHO: (no name) – {8C39FA75–AEEC–48E1–AE8A–9F1806E2DD07} – (no file)
O2 – BHO: Google Toolbar Helper – {AA58ED58–01DD–4d91–8333–CF10577473F7} – c:\program files\google\googletoolbar2.dll
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:\Windows\System32\msdxm.ocx
O3 – Toolbar: &Google – {2318C2B1–4965–11d4–9B18–009027A5CD4F} – c:\program files\google\googletoolbar2.dll
O4 – HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 – HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 – HKLM\..\Run: [ControlPanel] C:\Windows\System32\twink64.exe internat.dll,LoadKeyboardProfile
O4 – HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe"
O4 – HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 – HKLM\..\Run: [AntyVirK] c:\windows\antyvirk.exe ukrt
O4 – HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 –k
O4 – HKLM\..\Run: [PayTime] C:\Windows\System32\paytime.exe
O4 – HKLM\..\Run: [Dik] C:\Windows\Pbm.exe
O4 – HKLM\..\Run: [atipatxx] C:\Windows\System32\atipatxx.exe
O4 – HKLM\..\Run: [Service Host] C:\Windows\System32\Services\{ADF7D696–916B–4878–9D4B–63A57C8642C9}\SVCHOST.EXE
O4 – HKLM\..\Run: [load32] C:\Windows\System32\winldra.exe
O4 – HKLM\..\Run: [Uqs] C:\Windows\Vun.exe
O4 – HKLM\..\Run: [Rqh] C:\Windows\Eug.exe
O4 – HKLM\..\Run: [Ahl] C:\Windows\System32\Nka.exe
O4 – HKLM\..\Run: [Cqj] C:\Windows\Cdp.exe
O4 – HKLM\..\Run: [Jmq] C:\Windows\System32\Qte.exe
O4 – HKLM\..\Run: [Ncj] C:\Windows\System32\Vej.exe
O4 – HKLM\..\Run: [Mrm] C:\Windows\Gfp.exe
O4 – HKLM\..\Run: [Hju] C:\Windows\System32\Jcj.exe
O4 – HKLM\..\Run: [Efh] C:\Windows\Vbe.exe
O4 – HKLM\..\Run: [Ssn] C:\Windows\Hoq.exe
O4 – HKLM\..\Run: [Prk] C:\Windows\Bsb.exe
O4 – HKLM\..\Run: [Gcu] C:\Windows\System32\Tnf.exe
O4 – HKLM\..\Run: [Msd] C:\Windows\System32\Msb.exe
O4 – HKLM\..\Run: [icasServ] C:\Windows\System32\icasServ.exe
O4 – HKLM\..\Run: [Cmb] C:\Windows\System32\Uce.exe
O4 – HKLM\..\Run: [Svk] C:\Windows\System32\Ojd.exe
O4 – HKLM\..\Run: [Epu] C:\Windows\Tjm.exe
O4 – HKLM\..\Run: [Gdg] C:\Windows\System32\Tbk.exe
O4 – HKLM\..\Run: [Nbp] C:\Windows\Eug.exe
O4 – HKLM\..\Run: [Hol] C:\Windows\System32\Rfu.exe
O4 – HKLM\..\Run: [Ddq] C:\Windows\Tcr.exe
O4 – HKLM\..\Run: [Qcq] C:\Windows\Jlp.exe
O4 – HKLM\..\Run: [Opm] C:\Windows\Urr.exe
O4 – HKLM\..\Run: [Ihv] C:\Windows\Ndn.exe
O4 – HKLM\..\Run: [Jum] C:\Windows\Fjg.exe
O4 – HKLM\..\Run: [Geg] C:\Windows\Dht.exe
O4 – HKLM\..\Run: [Mpm] C:\Windows\System32\Mfp.exe
O4 – HKLM\..\Run: [Tru] C:\Windows\System32\Vnj.exe
O4 – HKLM\..\Run: [Jcr] C:\Windows\System32\Qcl.exe
O4 – HKLM\..\Run: [Cct] C:\Windows\Epg.exe
O4 – HKLM\..\Run: [Dai] C:\Windows\System32\Scj.exe
O4 – HKLM\..\Run: [Vbm] C:\Windows\System32\Ian.exe
O4 – HKLM\..\Run: [Lrc] C:\Windows\Uql.exe
O4 – HKLM\..\Run: [Khi] C:\Windows\System32\Dvn.exe
O4 – HKLM\..\Run: [Vov] C:\Windows\System32\Kjp.exe
O4 – HKLM\..\Run: [Bku] C:\Windows\System32\Gnj.exe
O4 – HKLM\..\Run: [Ams] C:\Windows\System32\Sva.exe
O4 – HKLM\..\Run: [Rji] C:\Windows\System32\Tnp.exe
O4 – HKLM\..\Run: [Gqn] C:\Windows\System32\Vgq.exe
O4 – HKLM\..\Run: [Cia] C:\Windows\Fjk.exe
O4 – HKLM\..\Run: [Oqs] C:\Windows\Mdg.exe
O4 – HKLM\..\Run: [Disk Keeper] C:\Windows\System32\Services\{ADF7D696–916B–4878–9D4B–63A57C8642C9}\SECURITY.EXE
O4 – HKLM\..\Run: [Bhl] C:\Windows\System32\Gst.exe
O4 – HKLM\..\RunServices: [atipatxx] C:\Windows\System32\atipatxx.exe
O4 – HKCU\..\Run: [CTFMON.EXE] C:\Windows\System32\ctfmon.exe
O4 – HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 – HKCU\..\Run: [Spyware Begone] c:\freescan\freescan.exe –FastScan
O4 – HKCU\..\Run: [Spyware Vanisher] c:\spywarevanisher–free\FreeScanner.exe –FastScan
O4 – HKCU\..\Run: [Gadu–Gadu] "C:\Program Files\Gadu–Gadu\gg.exe" /tray
O4 – HKCU\..\Run: [PayTime] C:\Windows\System32\paytime.exe
O4 – HKCU\..\Run: [Dik] C:\Windows\Pbm.exe
O4 – HKCU\..\Run: [atipatxx] C:\Windows\System32\atipatxx.exe
O4 – HKCU\..\Run: [Uqs] C:\Windows\Vun.exe
O4 – HKCU\..\Run: [Rqh] C:\Windows\Eug.exe
O4 – HKCU\..\Run: [Ahl] C:\Windows\System32\Nka.exe
O4 – HKCU\..\Run: [Cqj] C:\Windows\Cdp.exe
O4 – HKCU\..\Run: [Jmq] C:\Windows\System32\Qte.exe
O4 – HKCU\..\Run: [Ncj] C:\Windows\System32\Vej.exe
O4 – HKCU\..\Run: [Mrm] C:\Windows\Gfp.exe
O4 – HKCU\..\Run: [Hju] C:\Windows\System32\Jcj.exe
O4 – HKCU\..\Run: [Efh] C:\Windows\Vbe.exe
O4 – HKCU\..\Run: [Ssn] C:\Windows\Hoq.exe
O4 – HKCU\..\Run: [Prk] C:\Windows\Bsb.exe
O4 – HKCU\..\Run: [Gcu] C:\Windows\System32\Tnf.exe
O4 – HKCU\..\Run: [Msd] C:\Windows\System32\Msb.exe
O4 – HKCU\..\Run: [Cmb] C:\Windows\System32\Uce.exe
O4 – HKCU\..\Run: [Svk] C:\Windows\System32\Ojd.exe
O4 – HKCU\..\Run: [Epu] C:\Windows\Tjm.exe
O4 – HKCU\..\Run: [Gdg] C:\Windows\System32\Tbk.exe
O4 – HKCU\..\Run: [Nbp] C:\Windows\Eug.exe
O4 – HKCU\..\Run: [Hol] C:\Windows\System32\Rfu.exe
O4 – HKCU\..\Run: [Ddq] C:\Windows\Tcr.exe
O4 – HKCU\..\Run: [Qcq] C:\Windows\Jlp.exe
O4 – HKCU\..\Run: [Opm] C:\Windows\Urr.exe
O4 – HKCU\..\Run: [Ihv] C:\Windows\Ndn.exe
O4 – HKCU\..\Run: [Jum] C:\Windows\Fjg.exe
O4 – HKCU\..\Run: [Geg] C:\Windows\Dht.exe
O4 – HKCU\..\Run: [Mpm] C:\Windows\System32\Mfp.exe
O4 – HKCU\..\Run: [Tru] C:\Windows\System32\Vnj.exe
O4 – HKCU\..\Run: [Jcr] C:\Windows\System32\Qcl.exe
O4 – HKCU\..\Run: [Cct] C:\Windows\Epg.exe
O4 – HKCU\..\Run: [Dai] C:\Windows\System32\Scj.exe
O4 – HKCU\..\Run: [Vbm] C:\Windows\System32\Ian.exe
O4 – HKCU\..\Run: [Lrc] C:\Windows\Uql.exe
O4 – HKCU\..\Run: [Khi] C:\Windows\System32\Dvn.exe
O4 – HKCU\..\Run: [Vov] C:\Windows\System32\Kjp.exe
O4 – HKCU\..\Run: [Bku] C:\Windows\System32\Gnj.exe
O4 – HKCU\..\Run: [Ams] C:\Windows\System32\Sva.exe
O4 – HKCU\..\Run: [Rji] C:\Windows\System32\Tnp.exe
O4 – HKCU\..\Run: [Gqn] C:\Windows\System32\Vgq.exe
O4 – HKCU\..\Run: [Cia] C:\Windows\Fjk.exe
O4 – HKCU\..\Run: [Oqs] C:\Windows\Mdg.exe
O4 – HKCU\..\Run: [Bhl] C:\Windows\System32\Gst.exe
O4 – Startup: UniSpiker.lnk = ?
O4 – Global Startup: Kalendarz XP.lnk = C:\Program Files\Kalendarz XP\Start.exe
O4 – Global Startup: Rejestracja poprzez WWW.lnk = C:\WINDOWS\winhlp32.exe
O4 – Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 – Extra context menu item: &Google Search – res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 – Extra context menu item: Backward Links – res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 – Extra context menu item: Cached Snapshot of Page – res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 – Extra context menu item: Similar Pages – res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 – Extra context menu item: Translate into English – res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:\Program Files\Messenger\MSMSGS.EXE
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:\Program Files\Messenger\MSMSGS.EXE
O12 – Plugin for .au: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 – Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 – Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 – Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O14 – IERESET.INF: START_PAGE_URL=http://www.freeserve.net/
O15 – Trusted Zone: *.skoobidoo.com
O15 – Trusted Zone: *.slotchbar.com
O15 – Trusted Zone: *.windupdates.com
O15 – Trusted Zone: *.skoobidoo.com (HKLM)
O15 – Trusted Zone: *.slotchbar.com (HKLM)
O15 – Trusted Zone: *.windupdates.com (HKLM)
O15 – Trusted IP range: 67.19.185.246
O15 – ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O16 – DPF: {0585238B–9CA6–4CCB–A9B2–FE4BA495E880} (AXWebMon Control) – http://www.magiccam.pl/demo/AXWebMonProj1.cab
O16 – DPF: {15AD6789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://static.windupdates.com/cab/6247971CanadaInc/ie/bridge–c11.cab
O16 – DPF: {6414512B–B978–451D–A0D8–FCFDF33E833C} (WUWebControl Class) – http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1101805727359
O16 – DPF: {9A9307A0–7DA4–4DAF–B042–5009F29E09E1} (ActiveScan Installer Class) – http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
O20 – Winlogon Notify: NavLogon – C:\Windows\System32\NavLogon.dll
O20 – Winlogon Notify: ntfs32 – C:\Windows\SYSTEM32\ntfs32.dll
O21 – SSODL: anUXozuPwRX – {346F984A–9EC5–32E0–3817–80B463CDCEF7} – C:\Windows\System32\bvloh.dll
O23 – Service: DefWatch – Symantec Corporation – C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 – Service: Provides three management service (FreeBSD) – Unknown owner – C:\Windows\System32\dev32.exe (file missing)
O23 – Service: Multi–user Cleanup Service – Unknown owner – C:\Program Files\lotus\notes\ntmulti.exe
O23 – Service: Klient Symantec AntiVirus (Norton AntiVirus Server) – Symantec Corporation – C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe

Odpowiedzi: 6

A zaznaczyłes pokazywanie w systemie plików ukrytych i systemowych ??
Odinstalowywałes go z dodaj/usun programy ??
Moze akurat przy odinstalowywaniu katalog sam usunał, ale dla pewnosci wpisz sciezke do niego w programie Pocket Killbox.

Ktore wpisy powracają ?? Te z trzema literami w nazwie ??
Jesli tak to pewnie dlatego, ze niedokładnie pliki usuwasz albo robisz to na raty.
Nie ma na raty, startujesz do awaryjnego i wszystkie musza wyleciec w kosmos. Jesli ich nie widać to wskaz pliki Killboxowi, zreszta wszystko masz w temacie który linkowałem.
Bobi
Dodano
22.04.2005 15:46:56
Nie mogę odnaleźć w Program Files folderu WebHancer.
Resztę usuwam ale znowu wraca :cry:
ArturoG
Dodano
22.04.2005 12:28:04
Nowy log, w ktorym zostalo to co bylo.

Poczawszy od svchosta w \Services\{ADF7D696–916B–4878–9D4B– 63A57C8642C9}, poprzez strone startowa, litanie plikow w Run ktorych nazwa to trzy_literki.exe, do whSurvey.exe, SECURITY.EXE z \Services\{ADF7D696– 916B–4878–9D4B–63A57C8642C9}.

Wyczysc to jeszcze, lacznie z plikami.
EL NINO
Dodano
21.04.2005 14:39:46
W miarę moźliwości starałem się dostosować do zaleceń i po tym wszystkim nowy log

Logfile of HijackThis v1.99.1
Scan saved at 10:24:37, on 2005–04–21
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\program files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\Program Files\lotus\notes\ntmulti.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\NWTRAY.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Winamp\winampa.exe
C:\Windows\Nen.exe
C:\Windows\System32\Services\{ADF7D696–916B–4878–9D4B–63A57C8642C9}\SVCHOST.EXE
C:\Windows\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Gadu–Gadu\gg.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Windows\System32\wuauclt.exe
C:\Program Files\ivo\UniSpiker\unispiker.exe
C:\Program Files\Kalendarz XP\Kalendarz.exe
C:\Documents and Settings\Administrator\Ustawienia lokalne\Temp\Katalog tymczasowy 5 dla hijackthis.zip\HijackThis.exe

R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ipcons.biz/index.php?id=186
R0 – HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 – BHO: Google Toolbar Helper – {AA58ED58–01DD–4d91–8333–CF10577473F7} – c:\program files\google\googletoolbar2.dll
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:\Windows\System32\msdxm.ocx
O3 – Toolbar: &Google – {2318C2B1–4965–11d4–9B18–009027A5CD4F} – c:\program files\google\googletoolbar2.dll
O4 – HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 – HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 – HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe"
O4 – HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 – HKLM\..\Run: [Uqs] C:\Windows\Vun.exe
O4 – HKLM\..\Run: [Rqh] C:\Windows\Eug.exe
O4 – HKLM\..\Run: [Ahl] C:\Windows\System32\Nka.exe
O4 – HKLM\..\Run: [Cqj] C:\Windows\Cdp.exe
O4 – HKLM\..\Run: [Jmq] C:\Windows\System32\Qte.exe
O4 – HKLM\..\Run: [Ncj] C:\Windows\System32\Vej.exe
O4 – HKLM\..\Run: [Mrm] C:\Windows\Gfp.exe
O4 – HKLM\..\Run: [Hju] C:\Windows\System32\Jcj.exe
O4 – HKLM\..\Run: [Efh] C:\Windows\Vbe.exe
O4 – HKLM\..\Run: [Ssn] C:\Windows\Hoq.exe
O4 – HKLM\..\Run: [Prk] C:\Windows\Bsb.exe
O4 – HKLM\..\Run: [Gcu] C:\Windows\System32\Tnf.exe
O4 – HKLM\..\Run: [Msd] C:\Windows\System32\Msb.exe
O4 – HKLM\..\Run: [Cmb] C:\Windows\System32\Uce.exe
O4 – HKLM\..\Run: [Svk] C:\Windows\System32\Ojd.exe
O4 – HKLM\..\Run: [Epu] C:\Windows\Tjm.exe
O4 – HKLM\..\Run: [Gdg] C:\Windows\System32\Tbk.exe
O4 – HKLM\..\Run: [Nbp] C:\Windows\Eug.exe
O4 – HKLM\..\Run: [Hol] C:\Windows\System32\Rfu.exe
O4 – HKLM\..\Run: [Ddq] C:\Windows\Tcr.exe
O4 – HKLM\..\Run: [Qcq] C:\Windows\Jlp.exe
O4 – HKLM\..\Run: [Opm] C:\Windows\Urr.exe
O4 – HKLM\..\Run: [Ihv] C:\Windows\Ndn.exe
O4 – HKLM\..\Run: [Jum] C:\Windows\Fjg.exe
O4 – HKLM\..\Run: [Geg] C:\Windows\Dht.exe
O4 – HKLM\..\Run: [Mpm] C:\Windows\System32\Mfp.exe
O4 – HKLM\..\Run: [Tru] C:\Windows\System32\Vnj.exe
O4 – HKLM\..\Run: [Jcr] C:\Windows\System32\Qcl.exe
O4 – HKLM\..\Run: [Cct] C:\Windows\Epg.exe
O4 – HKLM\..\Run: [Dai] C:\Windows\System32\Scj.exe
O4 – HKLM\..\Run: [Vbm] C:\Windows\System32\Ian.exe
O4 – HKLM\..\Run: [Lrc] C:\Windows\Uql.exe
O4 – HKLM\..\Run: [Khi] C:\Windows\System32\Dvn.exe
O4 – HKLM\..\Run: [Vov] C:\Windows\System32\Kjp.exe
O4 – HKLM\..\Run: [Bku] C:\Windows\System32\Gnj.exe
O4 – HKLM\..\Run: [Ams] C:\Windows\System32\Sva.exe
O4 – HKLM\..\Run: [Rji] C:\Windows\System32\Tnp.exe
O4 – HKLM\..\Run: [Gqn] C:\Windows\System32\Vgq.exe
O4 – HKLM\..\Run: [Cia] C:\Windows\Fjk.exe
O4 – HKLM\..\Run: [Oqs] C:\Windows\Mdg.exe
O4 – HKLM\..\Run: [Bhl] C:\Windows\System32\Gst.exe
O4 – HKLM\..\Run: [Pch] C:\Windows\Nen.exe
O4 – HKLM\..\Run: [Gej] C:\Windows\System32\Klq.exe
O4 – HKLM\..\Run: [Rlf] C:\Windows\Ial.exe
O4 – HKLM\..\Run: [Inu] C:\Windows\Bsk.exe
O4 – HKLM\..\Run: [Pfm] C:\Windows\Vuv.exe
O4 – HKLM\..\Run: [Vsl] C:\Windows\System32\Rjo.exe
O4 – HKLM\..\Run: [Elb] C:\Windows\System32\Ivf.exe
O4 – HKLM\..\Run: [Arl] C:\Windows\Qes.exe
O4 – HKLM\..\Run: [Qna] C:\Windows\System32\Bch.exe
O4 – HKLM\..\Run: [Ilf] C:\Windows\Qaa.exe
O4 – HKLM\..\Run: [Vdj] C:\Windows\Qcf.exe
O4 – HKLM\..\Run: [Kid] C:\Windows\Jcv.exe
O4 – HKLM\..\Run: [Vcv] C:\Windows\Cbu.exe
O4 – HKLM\..\Run: [Pje] C:\Windows\System32\Ipf.exe
O4 – HKLM\..\Run: [Adv] C:\Windows\System32\Hit.exe
O4 – HKLM\..\Run: [Qmr] C:\Windows\Sqs.exe
O4 – HKLM\..\Run: [Utj] C:\Windows\Ffg.exe
O4 – HKLM\..\Run: [Service Host] C:\Windows\System32\Services\{ADF7D696–916B–4878–9D4B–63A57C8642C9}\SVCHOST.EXE
O4 – HKLM\..\Run: [Evg] C:\Windows\Enk.exe
O4 – HKLM\..\Run: [Hin] C:\Windows\Pkl.exe
O4 – HKLM\..\Run: [Fbh] C:\Windows\Jgl.exe
O4 – HKLM\..\Run: [Pbu] C:\Windows\Ghr.exe
O4 – HKLM\..\Run: [Disk Keeper] C:\Windows\System32\Services\{ADF7D696–916B–4878–9D4B–63A57C8642C9}\SECURITY.EXE
O4 – HKCU\..\Run: [CTFMON.EXE] C:\Windows\System32\ctfmon.exe
O4 – HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 – HKCU\..\Run: [Spyware Begone] c:\freescan\freescan.exe –FastScan
O4 – HKCU\..\Run: [Spyware Vanisher] c:\spywarevanisher–free\FreeScanner.exe –FastScan
O4 – HKCU\..\Run: [Gadu–Gadu] "C:\Program Files\Gadu–Gadu\gg.exe" /tray
O4 – HKCU\..\Run: [Dik] C:\Windows\Pbm.exe
O4 – HKCU\..\Run: [Uqs] C:\Windows\Vun.exe
O4 – HKCU\..\Run: [Rqh] C:\Windows\Eug.exe
O4 – HKCU\..\Run: [Ahl] C:\Windows\System32\Nka.exe
O4 – HKCU\..\Run: [Cqj] C:\Windows\Cdp.exe
O4 – HKCU\..\Run: [Jmq] C:\Windows\System32\Qte.exe
O4 – HKCU\..\Run: [Ncj] C:\Windows\System32\Vej.exe
O4 – HKCU\..\Run: [Mrm] C:\Windows\Gfp.exe
O4 – HKCU\..\Run: [Hju] C:\Windows\System32\Jcj.exe
O4 – HKCU\..\Run: [Efh] C:\Windows\Vbe.exe
O4 – HKCU\..\Run: [Ssn] C:\Windows\Hoq.exe
O4 – HKCU\..\Run: [Prk] C:\Windows\Bsb.exe
O4 – HKCU\..\Run: [Gcu] C:\Windows\System32\Tnf.exe
O4 – HKCU\..\Run: [Msd] C:\Windows\System32\Msb.exe
O4 – HKCU\..\Run: [Cmb] C:\Windows\System32\Uce.exe
O4 – HKCU\..\Run: [Svk] C:\Windows\System32\Ojd.exe
O4 – HKCU\..\Run: [Epu] C:\Windows\Tjm.exe
O4 – HKCU\..\Run: [Gdg] C:\Windows\System32\Tbk.exe
O4 – HKCU\..\Run: [Nbp] C:\Windows\Eug.exe
O4 – HKCU\..\Run: [Hol] C:\Windows\System32\Rfu.exe
O4 – HKCU\..\Run: [Ddq] C:\Windows\Tcr.exe
O4 – HKCU\..\Run: [Qcq] C:\Windows\Jlp.exe
O4 – HKCU\..\Run: [Opm] C:\Windows\Urr.exe
O4 – HKCU\..\Run: [Ihv] C:\Windows\Ndn.exe
O4 – HKCU\..\Run: [Jum] C:\Windows\Fjg.exe
O4 – HKCU\..\Run: [Geg] C:\Windows\Dht.exe
O4 – HKCU\..\Run: [Mpm] C:\Windows\System32\Mfp.exe
O4 – HKCU\..\Run: [Tru] C:\Windows\System32\Vnj.exe
O4 – HKCU\..\Run: [Jcr] C:\Windows\System32\Qcl.exe
O4 – HKCU\..\Run: [Cct] C:\Windows\Epg.exe
O4 – HKCU\..\Run: [Dai] C:\Windows\System32\Scj.exe
O4 – HKCU\..\Run: [Vbm] C:\Windows\System32\Ian.exe
O4 – HKCU\..\Run: [Lrc] C:\Windows\Uql.exe
O4 – HKCU\..\Run: [Khi] C:\Windows\System32\Dvn.exe
O4 – HKCU\..\Run: [Vov] C:\Windows\System32\Kjp.exe
O4 – HKCU\..\Run: [Bku] C:\Windows\System32\Gnj.exe
O4 – HKCU\..\Run: [Ams] C:\Windows\System32\Sva.exe
O4 – HKCU\..\Run: [Rji] C:\Windows\System32\Tnp.exe
O4 – HKCU\..\Run: [Gqn] C:\Windows\System32\Vgq.exe
O4 – HKCU\..\Run: [Cia] C:\Windows\Fjk.exe
O4 – HKCU\..\Run: [Oqs] C:\Windows\Mdg.exe
O4 – HKCU\..\Run: [Bhl] C:\Windows\System32\Gst.exe
O4 – HKCU\..\Run: [Pch] C:\Windows\Nen.exe
O4 – HKCU\..\Run: [Gej] C:\Windows\System32\Klq.exe
O4 – HKCU\..\Run: [Rlf] C:\Windows\Ial.exe
O4 – HKCU\..\Run: [Inu] C:\Windows\Bsk.exe
O4 – HKCU\..\Run: [Pfm] C:\Windows\Vuv.exe
O4 – HKCU\..\Run: [Vsl] C:\Windows\System32\Rjo.exe
O4 – HKCU\..\Run: [Elb] C:\Windows\System32\Ivf.exe
O4 – HKCU\..\Run: [Arl] C:\Windows\Qes.exe
O4 – HKCU\..\Run: [Qna] C:\Windows\System32\Bch.exe
O4 – HKCU\..\Run: [Ilf] C:\Windows\Qaa.exe
O4 – HKCU\..\Run: [Vdj] C:\Windows\Qcf.exe
O4 – HKCU\..\Run: [Kid] C:\Windows\Jcv.exe
O4 – HKCU\..\Run: [Vcv] C:\Windows\Cbu.exe
O4 – HKCU\..\Run: [Pje] C:\Windows\System32\Ipf.exe
O4 – HKCU\..\Run: [Adv] C:\Windows\System32\Hit.exe
O4 – HKCU\..\Run: [Qmr] C:\Windows\Sqs.exe
O4 – HKCU\..\Run: [Utj] C:\Windows\Ffg.exe
O4 – HKCU\..\Run: [Evg] C:\Windows\Enk.exe
O4 – HKCU\..\Run: [Hin] C:\Windows\Pkl.exe
O4 – HKCU\..\Run: [Fbh] C:\Windows\Jgl.exe
O4 – HKCU\..\Run: [Pbu] C:\Windows\Ghr.exe
O4 – Startup: UniSpiker.lnk = ?
O4 – Global Startup: Kalendarz XP.lnk = C:\Program Files\Kalendarz XP\Start.exe
O4 – Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 – Extra context menu item: &Google Search – res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 – Extra context menu item: Backward Links – res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 – Extra context menu item: Cached Snapshot of Page – res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 – Extra context menu item: Similar Pages – res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 – Extra context menu item: Translate into English – res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:\Program Files\Messenger\MSMSGS.EXE
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:\Program Files\Messenger\MSMSGS.EXE
O12 – Plugin for .au: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 – Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 – Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 – Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 – DPF: {6414512B–B978–451D–A0D8–FCFDF33E833C} (WUWebControl Class) – http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1101805727359
O16 – DPF: {9A9307A0–7DA4–4DAF–B042–5009F29E09E1} (ActiveScan Installer Class) – http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
O21 – SSODL: anUXozuPwRX – {346F984A–9EC5–32E0–3817–80B463CDCEF7} – C:\Windows\System32\bvloh.dll
O23 – Service: DefWatch – Symantec Corporation – C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 – Service: Provides three management service (FreeBSD) – Unknown owner – C:\Windows\System32\dev32.exe (file missing)
O23 – Service: Multi–user Cleanup Service – Unknown owner – C:\Program Files\lotus\notes\ntmulti.exe
O23 – Service: Klient Symantec AntiVirus (Norton AntiVirus Server) – Symantec Corporation – C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
ArturoG
Dodano
21.04.2005 12:26:37
Co znaczy źe wpisy i pliki naja wylecieć , w jaki sposób je usunąć? Proszę o wyrozumiałość i wytłumaczenie jak dla laika. Z góry dziękuję
ArturoG
Dodano
21.04.2005 10:42:05
Mamy poteznie duzo smiecia i to roznej masci

Zaczynasz od wylaczenia przywracania systemu
Wylaczasz procesy:
Pbm.exe
SVCHOST.EXE (uruchomiony przez usera nie przez system)
winldra.exe (Backdoor.Win32.Dumador.az)
icasServ.exe (–||–)

O4 – HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe"

Odinstaluj z dodaj/usun
Sciagnij LSP–FIX, uruchom go, zaznacz "I know what I'm doing", przenies strzałką do prawego ona pliki webHancera, kliknij Finish
Teraz reset i po resecie usuwasz cały katalog z Program Files

Załaczasz pokazywanie plikow ukrytych i systemowych

Wszystkie wymienione nizej pliki i wpisy maja wyleciec
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://81.222.131.49/index.php
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ipcons.biz/index.php?id=186
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://81.222.131.49/index.php
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://81.222.131.49/index.php
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://81.222.131.49/index.php
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://81.222.131.49/index.php
R3 – Default URLSearchHook is missing
O2 – BHO: (no name) – {1027E318–4049–4862–8D64–25535B0494B6} – (no file)
O2 – BHO: (no name) – {8C39FA75–AEEC–48E1–AE8A–9F1806E2DD07} – (no file)
O4 – HKLM\..\Run: [ControlPanel] C:\Windows\System32\twink64.exe internat.dll,LoadKeyboardProfile
O4 – HKLM\..\Run: [AntyVirK] c:\windows\antyvirk.exe ukrt
O4 – HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 –k
O4 – HKLM\..\Run: [PayTime] C:\Windows\System32\paytime.exe
O4 – HKLM\..\Run: [Dik] C:\Windows\Pbm.exe
O4 – HKLM\..\Run: [atipatxx] C:\Windows\System32\atipatxx.exe
O4 – HKLM\..\Run: [Service Host] C:\Windows\System32\Services\{ADF7D696–916B–4878–9D4B–63A57C8642C9}\SVCHOST.EXE
O4 – HKLM\..\Run: [load32] C:\Windows\System32\winldra.exe
O4 – HKLM\..\Run: [icasServ] C:\Windows\System32\icasServ.exe
O4 – HKLM\..\Run: [Disk Keeper] C:\Windows\System32\Services\{ADF7D696–916B–4878–9D4B–63A57C8642C9}\SECURITY.EXE
O4 – HKLM\..\RunServices: [atipatxx] C:\Windows\System32\atipatxx.exe
O4 – HKCU\..\Run: [PayTime] C:\Windows\System32\paytime.exe
O4 – HKCU\..\Run: [atipatxx] C:\Windows\System32\atipatxx.exe
O4 – Global Startup: Rejestracja poprzez WWW.lnk = C:\WINDOWS\winhlp32.exe
O14 – IERESET.INF: START_PAGE_URL=http://www.freeserve.net/
O15 – Trusted Zone: *.skoobidoo.com
O15 – Trusted Zone: *.slotchbar.com
O15 – Trusted Zone: *.windupdates.com
O15 – Trusted Zone: *.skoobidoo.com (HKLM)
O15 – Trusted Zone: *.slotchbar.com (HKLM)
O15 – Trusted Zone: *.windupdates.com (HKLM)
O15 – Trusted IP range: 67.19.185.246
O15 – ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O16 – DPF: {0585238B–9CA6–4CCB–A9B2–FE4BA495E880} (AXWebMon Control) – http://www.magiccam.pl/demo/AXWebMonProj1.cab
O16 – DPF: {15AD6789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://static.windupdates.com/cab/6247971CanadaInc/ie/bridge–c11.cab
O20 – Winlogon Notify: NavLogon – C:\Windows\System32\NavLogon.dll
O20 – Winlogon Notify: ntfs32 – C:\Windows\SYSTEM32\ntfs32.dll
O21 – SSODL: anUXozuPwRX – {346F984A–9EC5–32E0–3817–80B463CDCEF7} – C:\Windows\System32\bvloh.dll


O23 – Service: Provides three management service (FreeBSD) – Unknown owner – C:\Windows\System32\dev32.exe (file missing)

Usuwanie
O4 – HKLM\..\Run: [Dik] C:\Windows\Pbm.exe
O4 – HKLM\..\Run: [Bhl] C:\Windows\System32\Gst.exe
O4 – HKCU\..\Run: [Dik] C:\Windows\Pbm.exe
O4 – HKLM\..\Run: [Uqs] C:\Windows\Vun.exe
O4 – HKLM\..\Run: [Rqh] C:\Windows\Eug.exe
O4 – HKLM\..\Run: [Ahl] C:\Windows\System32\Nka.exe
O4 – HKLM\..\Run: [Cqj] C:\Windows\Cdp.exe
O4 – HKLM\..\Run: [Jmq] C:\Windows\System32\Qte.exe
O4 – HKLM\..\Run: [Ncj] C:\Windows\System32\Vej.exe
O4 – HKLM\..\Run: [Mrm] C:\Windows\Gfp.exe
O4 – HKLM\..\Run: [Hju] C:\Windows\System32\Jcj.exe
O4 – HKLM\..\Run: [Efh] C:\Windows\Vbe.exe
O4 – HKLM\..\Run: [Ssn] C:\Windows\Hoq.exe
O4 – HKLM\..\Run: [Prk] C:\Windows\Bsb.exe
O4 – HKLM\..\Run: [Gcu] C:\Windows\System32\Tnf.exe
O4 – HKLM\..\Run: [Msd] C:\Windows\System32\Msb.exe
O4 – HKLM\..\Run: [Cmb] C:\Windows\System32\Uce.exe
O4 – HKLM\..\Run: [Svk] C:\Windows\System32\Ojd.exe
O4 – HKLM\..\Run: [Epu] C:\Windows\Tjm.exe
O4 – HKLM\..\Run: [Gdg] C:\Windows\System32\Tbk.exe
O4 – HKLM\..\Run: [Nbp] C:\Windows\Eug.exe
O4 – HKLM\..\Run: [Hol] C:\Windows\System32\Rfu.exe
O4 – HKLM\..\Run: [Ddq] C:\Windows\Tcr.exe
O4 – HKLM\..\Run: [Qcq] C:\Windows\Jlp.exe
O4 – HKLM\..\Run: [Opm] C:\Windows\Urr.exe
O4 – HKLM\..\Run: [Ihv] C:\Windows\Ndn.exe
O4 – HKLM\..\Run: [Jum] C:\Windows\Fjg.exe
O4 – HKLM\..\Run: [Geg] C:\Windows\Dht.exe
O4 – HKLM\..\Run: [Mpm] C:\Windows\System32\Mfp.exe
O4 – HKLM\..\Run: [Tru] C:\Windows\System32\Vnj.exe
O4 – HKLM\..\Run: [Jcr] C:\Windows\System32\Qcl.exe
O4 – HKLM\..\Run: [Cct] C:\Windows\Epg.exe
O4 – HKLM\..\Run: [Dai] C:\Windows\System32\Scj.exe
O4 – HKLM\..\Run: [Vbm] C:\Windows\System32\Ian.exe
O4 – HKLM\..\Run: [Lrc] C:\Windows\Uql.exe
O4 – HKLM\..\Run: [Khi] C:\Windows\System32\Dvn.exe
O4 – HKLM\..\Run: [Vov] C:\Windows\System32\Kjp.exe
O4 – HKLM\..\Run: [Bku] C:\Windows\System32\Gnj.exe
O4 – HKLM\..\Run: [Ams] C:\Windows\System32\Sva.exe
O4 – HKLM\..\Run: [Rji] C:\Windows\System32\Tnp.exe
O4 – HKLM\..\Run: [Gqn] C:\Windows\System32\Vgq.exe
O4 – HKLM\..\Run: [Cia] C:\Windows\Fjk.exe
O4 – HKLM\..\Run: [Oqs] C:\Windows\Mdg.exe
04 – HKCU\..\Run: [Uqs] C:\Windows\Vun.exe
O4 – HKCU\..\Run: [Rqh] C:\Windows\Eug.exe
O4 – HKCU\..\Run: [Ahl] C:\Windows\System32\Nka.exe
O4 – HKCU\..\Run: [Cqj] C:\Windows\Cdp.exe
O4 – HKCU\..\Run: [Jmq] C:\Windows\System32\Qte.exe
O4 – HKCU\..\Run: [Ncj] C:\Windows\System32\Vej.exe
O4 – HKCU\..\Run: [Mrm] C:\Windows\Gfp.exe
O4 – HKCU\..\Run: [Hju] C:\Windows\System32\Jcj.exe
O4 – HKCU\..\Run: [Efh] C:\Windows\Vbe.exe
O4 – HKCU\..\Run: [Ssn] C:\Windows\Hoq.exe
O4 – HKCU\..\Run: [Prk] C:\Windows\Bsb.exe
O4 – HKCU\..\Run: [Gcu] C:\Windows\System32\Tnf.exe
O4 – HKCU\..\Run: [Msd] C:\Windows\System32\Msb.exe
O4 – HKCU\..\Run: [Cmb] C:\Windows\System32\Uce.exe
O4 – HKCU\..\Run: [Svk] C:\Windows\System32\Ojd.exe
O4 – HKCU\..\Run: [Epu] C:\Windows\Tjm.exe
O4 – HKCU\..\Run: [Gdg] C:\Windows\System32\Tbk.exe
O4 – HKCU\..\Run: [Nbp] C:\Windows\Eug.exe
O4 – HKCU\..\Run: [Hol] C:\Windows\System32\Rfu.exe
O4 – HKCU\..\Run: [Ddq] C:\Windows\Tcr.exe
O4 – HKCU\..\Run: [Qcq] C:\Windows\Jlp.exe
O4 – HKCU\..\Run: [Opm] C:\Windows\Urr.exe
O4 – HKCU\..\Run: [Ihv] C:\Windows\Ndn.exe
O4 – HKCU\..\Run: [Jum] C:\Windows\Fjg.exe
O4 – HKCU\..\Run: [Geg] C:\Windows\Dht.exe
O4 – HKCU\..\Run: [Mpm] C:\Windows\System32\Mfp.exe
O4 – HKCU\..\Run: [Tru] C:\Windows\System32\Vnj.exe
O4 – HKCU\..\Run: [Jcr] C:\Windows\System32\Qcl.exe
O4 – HKCU\..\Run: [Cct] C:\Windows\Epg.exe
O4 – HKCU\..\Run: [Dai] C:\Windows\System32\Scj.exe
O4 – HKCU\..\Run: [Vbm] C:\Windows\System32\Ian.exe
O4 – HKCU\..\Run: [Lrc] C:\Windows\Uql.exe
O4 – HKCU\..\Run: [Khi] C:\Windows\System32\Dvn.exe
O4 – HKCU\..\Run: [Vov] C:\Windows\System32\Kjp.exe
O4 – HKCU\..\Run: [Bku] C:\Windows\System32\Gnj.exe
O4 – HKCU\..\Run: [Ams] C:\Windows\System32\Sva.exe
O4 – HKCU\..\Run: [Rji] C:\Windows\System32\Tnp.exe
O4 – HKCU\..\Run: [Gqn] C:\Windows\System32\Vgq.exe
O4 – HKCU\..\Run: [Cia] C:\Windows\Fjk.exe
O4 – HKCU\..\Run: [Oqs] C:\Windows\Mdg.exe
O4 – HKCU\..\Run: [Bhl] C:\Windows\System32\Gst.exe

http://forum.centrumxp.pl/viewtopic.php?t=33126
O4 – HKCU\..\Run: [Spyware Begone] c:\freescan\freescan.exe –FastScan
O4 – HKCU\..\Run: [Spyware Vanisher] c:\spywarevanisher–free\FreeScanner.exe –FastScan

Odinstalować oba gówna i katalogi powywalać
O23 – Service: Klient Symantec AntiVirus (Norton AntiVirus Server) – Symantec Corporation – C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe

Cos mi sie zdaje ze Nortona juz dawno nie ma – FIX.

Zainstaluj antywirusa, Avasta chociaźby.
Zajrzyj czaem na Windows Update, bo widze ze raczej tam nigdy nie byłes.
Bobi
Dodano
20.04.2005 18:26:57
ArturoG
Dodano:
20.04.2005 16:28:43
Komentarzy:
6
Strona 1 / 1