skaczacy ping

Logfile of HijackThis v1.99.1
Scan saved at 20:16:19, on 2005–10–14
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\logonui.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\TBPanel.exe
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Gadu–Gadu\gg.exe
C:\program files\steam\steam.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\Pavsrv51.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PsImSvc.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\AVENGINE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\das\Ustawienia lokalne\Temp\Katalog tymczasowy 1 dla hijackthis_199.zip\HijackThis.exe

R0 – HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:\WINDOWS\System32\msdxm.ocx
O4 – HKLM\..\Run: [Gainward] C:\WINDOWS\TBPanel.exe /A
O4 – HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 – HKLM\..\Run: [nwiz] nwiz.exe /install
O4 – HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 – HKLM\..\Run: [CmiRemoveDir] C:\WINDOWS\CMIRMR~1.EXE
O4 – HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 – HKLM\..\Run: [Rundll16] RUNDLL16.EXE
O4 – HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\APVXDWIN.EXE" /s
O4 – HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 – HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 – HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 – HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 – HKCU\..\Run: [Gadu–Gadu] "C:\Program Files\Gadu–Gadu\gg.exe" /tray
O4 – HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" –silent
O4 – Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 – Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O18 – Protocol: bw+0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw+0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw–0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw–0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw00 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw00s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw10 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw10s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw20 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw20s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw30 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw30s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw40 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw40s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw50 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw50s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw60 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw60s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw70 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw70s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw80 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw80s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw90 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bw90s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwa0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwa0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwb0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwb0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwc0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwc0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwd0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwd0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwe0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwe0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwf0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwf0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwfile–8876480 – {9462A756–7B47–47BC–8C80–C34B9B80B32B} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol–8876480.dll
O18 – Protocol: bwg0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwg0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwh0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwh0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwi0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwi0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwj0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwj0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwk0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwk0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwl0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwl0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwm0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwm0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwn0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwn0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwo0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwo0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwp0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwp0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwq0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwq0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwr0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwr0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bws0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bws0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwt0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwt0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwu0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwu0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwv0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwv0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bww0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bww0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwx0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwx0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwy0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwy0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwz0 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: bwz0s – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O18 – Protocol: offline–8876480 – {A6C565A6–1151–44BD–A4D7–782A50FF3CF2} – C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol–8876480.dll
O23 – Service: NVIDIA Display Driver Service (NVSvc) – NVIDIA Corporation – C:\WINDOWS\System32\nvsvc32.exe
O23 – Service: Panda Process Protection Service (PavPrSrv) – Panda Software – C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 – Service: Panda anti–virus service (PAVSRV) – Panda Software – C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\Pavsrv51.exe
O23 – Service: Power Manager (PowerManager) – Unknown owner – C:\WINDOWS\svchost.exe (file missing)
O23 – Service: Panda IManager Service (PSIMSVC) – Panda Software Internacional – C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PsImSvc.exe

Odpowiedzi: 1

avogadro, w logu widać syfiastą usługę PowerManager i plik svchost.exe w C:\WINDOWS
Wiersz poleceń otwierasz i wpisujesz:
sc stop PowerManager
sc delete PowerManager
Plik w podanej lokalizacji usuwasz z dysku, prawdziwy jest w system32 – ten zostaje.
Do tego odinstaluj Desktop Messengera od Logitecha.
Rozwiń swoją wypowiedź nt. tego pingu bo sam log to o kant dupy rozbić moźna, bez konkretów rozmowy nie ma.
Chcesz sobie sprawdzić log kontrolnie skorzystaj na przyszłość z analizatora, nie zawracaj głowy.
Bobi
Dodano
14.10.2005 22:50:21
avogadro
Dodano:
14.10.2005 22:23:26
Komentarzy:
1
Strona 1 / 1