prosze zebyscie mi sprawdzili loga
Logfile of HijackThis v1.99.1
Scan saved at 18:52:55, on 2005–07–29
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS2\System32\smss.exe
C:\WINDOWS2\system32\winlogon.exe
C:\WINDOWS2\system32\services.exe
C:\WINDOWS2\system32\lsass.exe
C:\WINDOWS2\system32\svchost.exe
C:\WINDOWS2\system32\spoolsv.exe
C:\PROGRA~1\F–Secure\BackWeb\7681197\Program\SERVIC~1.EXE
C:\Program Files\F–Secure\Anti–Virus\fsgk32st.exe
C:\Program Files\F–Secure\Anti–Virus\FSGK32.EXE
C:\Program Files\F–Secure\BackWeb\7681197\program\fsbwsys.exe
C:\Program Files\F–Secure\Common\FSMA32.EXE
C:\Program Files\F–Secure\Anti–Virus\fssm32.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\F–Secure\Common\FSMB32.EXE
C:\Program Files\F–Secure\Common\FCH32.EXE
C:\WINDOWS2\Explorer.EXE
C:\Program Files\F–Secure\Anti–Virus\fsqh.exe
C:\Program Files\F–Secure\Common\FAMEH32.EXE
C:\Program Files\F–Secure\Anti–Virus\fsrw.exe
C:\WINDOWS2\System32\Fmctrl.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\F–Secure\Common\FSM32.EXE
D:\Programy\java\bin\jusched.exe
C:\WINDOWS2\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Gadu–Gadu\gg.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\F–Secure\BackWeb\7681197\program\F–Secure Automatic Update.exe
C:\Program Files\F–Secure\Anti–Virus\fsav32.exe
C:\Program Files\Avant Browser\avant.exe
C:\WINDOWS2\System32\svchost.exe
C:\Program Files\F–Secure\Common\FNRB32.EXE
C:\Program Files\F–Secure\Common\FIH32.EXE
C:\Program Files\F–Secure\FWES\Program\fsdfwd.exe
C:\PROGRA~1\F–Secure\ANTI–S~1\fsaw.exe
C:\Program Files\F–Secure\FSGUI\fsguidll.exe
C:\Documents and Settings\kamil.KAMILOSKI\Pulpit\HijackThis.exe
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\KAMIL~1.KAM\USTAWI~1\Temp\se.dll/spage.html
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 – HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 – BHO: (no name) – {A5366673–E8CA–11D3–9CD9–0090271D075B} – (no file)
O2 – BHO: Google Toolbar Helper – {AA58ED58–01DD–4d91–8333–CF10577473F7} – c:\program files\google\googletoolbar2.dll
O3 – Toolbar: &Google – {2318C2B1–4965–11d4–9B18–009027A5CD4F} – c:\program files\google\googletoolbar2.dll
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:\WINDOWS2\System32\msdxm.ocx
O4 – HKLM\..\Run: [SystemTray] SysTray.Exe
O4 – HKLM\..\Run: [FmctrlTray] Fmctrl.EXE
O4 – HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 – HKLM\..\Run: [F–Secure Manager] "C:\Program Files\F–Secure\Common\FSM32.EXE" /splash
O4 – HKLM\..\Run: [F–Secure TNB] "C:\Program Files\F–Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 – HKLM\..\Run: [SunJavaUpdateSched] D:\Programy\java\bin\jusched.exe
O4 – HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 –k
O4 – HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS2\System32\ctfmon.exe
O4 – HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 – HKCU\..\Run: [Gadu–Gadu] "C:\Program Files\Gadu–Gadu\gg.exe" /tray
O4 – Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 – Global Startup: F–Secure Automatic Update.lnk = C:\Program Files\F–Secure\BackWeb\7681197\program\F–Secure Automatic Update.exe
O8 – Extra context menu item: &Block this popup – C:\Program Files\F–Secure\Anti–Spyware\blockpopups.htm
O8 – Extra context menu item: &Google Search – res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 – Extra context menu item: Backward Links – res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 – Extra context menu item: Blokuj wszystkie obrazy z tego serwera – C:\Program Files\Avant Browser\AddAllToADBlackList.htm
O8 – Extra context menu item: Cached Snapshot of Page – res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 – Extra context menu item: Dodaj do listy blokowanych reklam – C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:\PROGRA~1\MIC233~1\OFFICE11\EXCEL.EXE/3000
O8 – Extra context menu item: Otwórz wszystkie adresy z tej strony... – C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 – Extra context menu item: Podświetl – C:\Program Files\Avant Browser\Highlight.htm
O8 – Extra context menu item: Similar Pages – res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 – Extra context menu item: Szukaj – C:\Program Files\Avant Browser\Search.htm
O8 – Extra context menu item: Translate into English – res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 – Extra context menu item: Ściągnij przy pomocy FlashGet'a – D:\Programy\FlashGet\jc_link.htm
O8 – Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a – D:\Programy\FlashGet\jc_all.htm
O9 – Extra button: IE Shield – {300DB664–75B5–47c0–8B45–A44ACCF73C00} – C:\Program Files\F–Secure\Anti–Spyware\ieshield.dll
O9 – Extra 'Tools' menuitem: IE Shield... – {300DB664–75B5–47c0–8B45–A44ACCF73C00} – C:\Program Files\F–Secure\Anti–Spyware\ieshield.dll
O9 – Extra button: Badanie – {92780B25–18CC–41C8–B9BE–3C9C571A8263} – C:\PROGRA~1\MIC233~1\OFFICE11\REFIEBAR.DLL
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O16 – DPF: {15AD6789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://static.windupdates.com/cab/MediaAccessVerisign/ie/Bridge–c139.cab
O16 – DPF: {FDDBE2B8–6602–4AD8–946D–94C5A32FA6C5} (GameDesire Snooker) – http://67.15.101.3/g_bin/pl/snooker_2_0_0_22.cab
O23 – Service: F–Secure Automatic Update (BackWeb Plug–in – 7681197) – F–Secure Automatic Update – C:\PROGRA~1\F–Secure\BackWeb\7681197\Program\SERVIC~1.EXE
O23 – Service: FSGKHS (F–Secure Gatekeeper Handler Starter) – F–Secure Corp. – C:\Program Files\F–Secure\Anti–Virus\fsgk32st.exe
O23 – Service: F–Secure Network Request Broker – F–Secure Corporation – C:\Program Files\F–Secure\Common\FNRB32.EXE
O23 – Service: fsbwsys – F–Secure Corp. – C:\Program Files\F–Secure\BackWeb\7681197\program\fsbwsys.exe
O23 – Service: F–Secure Anti–Virus Firewall Daemon (FSDFWD) – F–Secure Corporation – C:\Program Files\F–Secure\FWES\Program\fsdfwd.exe
O23 – Service: F–Secure Management Agent (FSMA) – F–Secure Corporation – C:\Program Files\F–Secure\Common\FSMA32.EXE
Scan saved at 18:52:55, on 2005–07–29
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS2\System32\smss.exe
C:\WINDOWS2\system32\winlogon.exe
C:\WINDOWS2\system32\services.exe
C:\WINDOWS2\system32\lsass.exe
C:\WINDOWS2\system32\svchost.exe
C:\WINDOWS2\system32\spoolsv.exe
C:\PROGRA~1\F–Secure\BackWeb\7681197\Program\SERVIC~1.EXE
C:\Program Files\F–Secure\Anti–Virus\fsgk32st.exe
C:\Program Files\F–Secure\Anti–Virus\FSGK32.EXE
C:\Program Files\F–Secure\BackWeb\7681197\program\fsbwsys.exe
C:\Program Files\F–Secure\Common\FSMA32.EXE
C:\Program Files\F–Secure\Anti–Virus\fssm32.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\F–Secure\Common\FSMB32.EXE
C:\Program Files\F–Secure\Common\FCH32.EXE
C:\WINDOWS2\Explorer.EXE
C:\Program Files\F–Secure\Anti–Virus\fsqh.exe
C:\Program Files\F–Secure\Common\FAMEH32.EXE
C:\Program Files\F–Secure\Anti–Virus\fsrw.exe
C:\WINDOWS2\System32\Fmctrl.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\F–Secure\Common\FSM32.EXE
D:\Programy\java\bin\jusched.exe
C:\WINDOWS2\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Gadu–Gadu\gg.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\F–Secure\BackWeb\7681197\program\F–Secure Automatic Update.exe
C:\Program Files\F–Secure\Anti–Virus\fsav32.exe
C:\Program Files\Avant Browser\avant.exe
C:\WINDOWS2\System32\svchost.exe
C:\Program Files\F–Secure\Common\FNRB32.EXE
C:\Program Files\F–Secure\Common\FIH32.EXE
C:\Program Files\F–Secure\FWES\Program\fsdfwd.exe
C:\PROGRA~1\F–Secure\ANTI–S~1\fsaw.exe
C:\Program Files\F–Secure\FSGUI\fsguidll.exe
C:\Documents and Settings\kamil.KAMILOSKI\Pulpit\HijackThis.exe
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\KAMIL~1.KAM\USTAWI~1\Temp\se.dll/spage.html
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 – HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 – BHO: (no name) – {A5366673–E8CA–11D3–9CD9–0090271D075B} – (no file)
O2 – BHO: Google Toolbar Helper – {AA58ED58–01DD–4d91–8333–CF10577473F7} – c:\program files\google\googletoolbar2.dll
O3 – Toolbar: &Google – {2318C2B1–4965–11d4–9B18–009027A5CD4F} – c:\program files\google\googletoolbar2.dll
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:\WINDOWS2\System32\msdxm.ocx
O4 – HKLM\..\Run: [SystemTray] SysTray.Exe
O4 – HKLM\..\Run: [FmctrlTray] Fmctrl.EXE
O4 – HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 – HKLM\..\Run: [F–Secure Manager] "C:\Program Files\F–Secure\Common\FSM32.EXE" /splash
O4 – HKLM\..\Run: [F–Secure TNB] "C:\Program Files\F–Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 – HKLM\..\Run: [SunJavaUpdateSched] D:\Programy\java\bin\jusched.exe
O4 – HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 –k
O4 – HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS2\System32\ctfmon.exe
O4 – HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 – HKCU\..\Run: [Gadu–Gadu] "C:\Program Files\Gadu–Gadu\gg.exe" /tray
O4 – Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 – Global Startup: F–Secure Automatic Update.lnk = C:\Program Files\F–Secure\BackWeb\7681197\program\F–Secure Automatic Update.exe
O8 – Extra context menu item: &Block this popup – C:\Program Files\F–Secure\Anti–Spyware\blockpopups.htm
O8 – Extra context menu item: &Google Search – res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 – Extra context menu item: Backward Links – res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 – Extra context menu item: Blokuj wszystkie obrazy z tego serwera – C:\Program Files\Avant Browser\AddAllToADBlackList.htm
O8 – Extra context menu item: Cached Snapshot of Page – res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 – Extra context menu item: Dodaj do listy blokowanych reklam – C:\Program Files\Avant Browser\AddToADBlackList.htm
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:\PROGRA~1\MIC233~1\OFFICE11\EXCEL.EXE/3000
O8 – Extra context menu item: Otwórz wszystkie adresy z tej strony... – C:\Program Files\Avant Browser\OpenAllLinks.htm
O8 – Extra context menu item: Podświetl – C:\Program Files\Avant Browser\Highlight.htm
O8 – Extra context menu item: Similar Pages – res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 – Extra context menu item: Szukaj – C:\Program Files\Avant Browser\Search.htm
O8 – Extra context menu item: Translate into English – res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 – Extra context menu item: Ściągnij przy pomocy FlashGet'a – D:\Programy\FlashGet\jc_link.htm
O8 – Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a – D:\Programy\FlashGet\jc_all.htm
O9 – Extra button: IE Shield – {300DB664–75B5–47c0–8B45–A44ACCF73C00} – C:\Program Files\F–Secure\Anti–Spyware\ieshield.dll
O9 – Extra 'Tools' menuitem: IE Shield... – {300DB664–75B5–47c0–8B45–A44ACCF73C00} – C:\Program Files\F–Secure\Anti–Spyware\ieshield.dll
O9 – Extra button: Badanie – {92780B25–18CC–41C8–B9BE–3C9C571A8263} – C:\PROGRA~1\MIC233~1\OFFICE11\REFIEBAR.DLL
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O16 – DPF: {15AD6789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://static.windupdates.com/cab/MediaAccessVerisign/ie/Bridge–c139.cab
O16 – DPF: {FDDBE2B8–6602–4AD8–946D–94C5A32FA6C5} (GameDesire Snooker) – http://67.15.101.3/g_bin/pl/snooker_2_0_0_22.cab
O23 – Service: F–Secure Automatic Update (BackWeb Plug–in – 7681197) – F–Secure Automatic Update – C:\PROGRA~1\F–Secure\BackWeb\7681197\Program\SERVIC~1.EXE
O23 – Service: FSGKHS (F–Secure Gatekeeper Handler Starter) – F–Secure Corp. – C:\Program Files\F–Secure\Anti–Virus\fsgk32st.exe
O23 – Service: F–Secure Network Request Broker – F–Secure Corporation – C:\Program Files\F–Secure\Common\FNRB32.EXE
O23 – Service: fsbwsys – F–Secure Corp. – C:\Program Files\F–Secure\BackWeb\7681197\program\fsbwsys.exe
O23 – Service: F–Secure Anti–Virus Firewall Daemon (FSDFWD) – F–Secure Corporation – C:\Program Files\F–Secure\FWES\Program\fsdfwd.exe
O23 – Service: F–Secure Management Agent (FSMA) – F–Secure Corporation – C:\Program Files\F–Secure\Common\FSMA32.EXE
Odpowiedzi: 3
Nie usuwaj O10 z LSP. To biblioteka f–secure.
O2 rowniez nie. To FlashGet a on u Ciebie chodzi.
Wejdz do przyklejonego tu tematu FAQ, sciagnij i zastosuj fixa na se.dll
Pokaz pozniej log.
Teraz usun tylko O16 –> static.windupdates...
O2 rowniez nie. To FlashGet a on u Ciebie chodzi.
Wejdz do przyklejonego tu tematu FAQ, sciagnij i zastosuj fixa na se.dll
Pokaz pozniej log.
Teraz usun tylko O16 –> static.windupdates...
tylko nie wiem czy ktos teraz napisze... ;/
wiesz nie znam sie za bardzo i poczekaj aź ktoś z adminów Ci odpisze ale ja usunąłbym
to
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
i chyba jeszcze to
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\KAMIL~1.KAM\USTAWI~1\Temp\se.dll/spage.html
O2 – BHO: (no name) – {A5366673–E8CA–11D3–9CD9–0090271D075B} – (no file)
ale powtarzam poczekaj aź ktoś jeszcze napiszę
chcę tylko zobaczyć czy dobrze wzkazałem
to
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
O10 – Unknown file in Winsock LSP: c:\program files\f–secure\fsps\program\fslsp.dll
i chyba jeszcze to
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\KAMIL~1.KAM\USTAWI~1\Temp\se.dll/spage.html
O2 – BHO: (no name) – {A5366673–E8CA–11D3–9CD9–0090271D075B} – (no file)
ale powtarzam poczekaj aź ktoś jeszcze napiszę
chcę tylko zobaczyć czy dobrze wzkazałem
Strona 1 / 1