Sprawdzcie LOGA !!

Logfile of HijackThis v1.99.0
Scan saved at 13:51:44, on 2005–02–13
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:Program FilesPanda SoftwarePanda Antivirus TitaniumAPVXDWIN.EXE
C:WINDOWSsystem32gah95on6.exe
C:Program FilesJavajre1.5.0_01injusched.exe
C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe
C:WINDOWSsystem32 undll32.exe
C:WINDOWSsystem32 vsvc32.exe
C:WINDOWSsystem32pavsrv.exe
C:WINDOWSsystem32AVENGINE.EXE
C:Program FilesPanda SoftwarePanda Antivirus TitaniumpavProxy.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
E:ystryMP3hijackthisHijackThis.exe

R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:DOCUME~1plusgsmUSTAWI~1Tempse.dll/sp.html
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:DOCUME~1plusgsmUSTAWI~1Tempse.dll/sp.html
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 – URLSearchHook: (no name) – {87766247–311C–43B4–8499–3D5FEC94A183} – (no file)
O2 – BHO: (no name) – {00000010–6F7D–442C–93E3–4A4827C2E4C8} – (no file)
O2 – BHO: InstaFinderK – {4E7BD74F–2B8D–469E–90F0–F66AB581A933} – C:PROGRA~1INSTAF~1INSTAF~1.DLL
O2 – BHO: (no name) – {96C43FF5–508B–46C4–9B08–BBCD5000934F} – C:WINDOWSsystem32jbkm.dll
O2 – BHO: IeCatch2 Class – {A5366673–E8CA–11D3–9CD9–0090271D075B} – C:PROGRA~1FlashGetjccatch.dll
O3 – Toolbar: FlashGet Bar – {E0E899AB–F487–11D5–8D29–0050BA6940E3} – C:PROGRA~1FlashGetfgiebar.dll
O4 – HKLM..Run: [APVXDWIN] "C:Program FilesPanda SoftwarePanda Antivirus TitaniumAPVXDWIN.EXE" /s
O4 – HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 –k
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit
O4 – HKLM..Run: [CloneCDElbyCDFL] "C:Program FilesElaborate BytesCloneCDElbyCheck.exe" /L ElbyCDFL
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [Windows AdStatus] C:Program FilesWindows AdStatusWinStat.exe
O4 – HKLM..Run: [gah95on6] C:WINDOWSsystem32gah95on6.exe
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavajre1.5.0_01injusched.exe
O4 – HKLM..Run: [ISUSPM Startup] C:PROGRA~1COMMON~1INSTAL~1UPDATE~1isuspm.exe –startup
O4 – HKLM..Run: [ISUSScheduler] "C:Program FilesCommon FilesInstallShieldUpdateServiceissch.exe" –start
O4 – HKLM..Run: [sp] rundll32 C:DOCUME~1plusgsmUSTAWI~1Tempse.dll,DllInstall
O4 – Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOfficeOSA9.EXE
O8 – Extra context menu item: Ściągnij przy pomocy FlashGet'a – C:Program FilesFlashGetjc_link.htm
O8 – Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a – C:Program FilesFlashGetjc_all.htm
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:Program FilesJavajre1.5.0_01in pjpi150_01.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:Program FilesJavajre1.5.0_01in pjpi150_01.dll
O9 – Extra button: FlashGet – {D6E814A0–E0C5–11d4–8D29–0050BA6940E3} – C:PROGRA~1FlashGetflashget.exe
O9 – Extra 'Tools' menuitem: &FlashGet – {D6E814A0–E0C5–11d4–8D29–0050BA6940E3} – C:PROGRA~1FlashGetflashget.exe
O12 – Plugin for .mp3: C:Program FilesInternet ExplorerPLUGINS pqtplugin3.dll
O12 – Plugin for .mpg: C:Program FilesInternet ExplorerPLUGINS pqtplugin3.dll
O12 – Plugin for .png: C:Program FilesInternet ExplorerPLUGINS pqtplugin4.dll
O17 – HKLMSystemCCSServicesTcpip..{4A013AD6–BA2A–4915–8278–24EA7092B2D7}: NameServer = 195.114.161.61,195.114.181.130
O18 – Filter: text/html – {DDF8016A–3C49–48B3–8BDC–F7DFBADCA2AD} – C:WINDOWSsystem32jbkm.dll
O18 – Filter: text/plain – {DDF8016A–3C49–48B3–8BDC–F7DFBADCA2AD} – C:WINDOWSsystem32jbkm.dll
O23 – Service: NVIDIA Display Driver Service – NVIDIA Corporation – C:WINDOWSsystem32 vsvc32.exe
O23 – Service: Panda anti–virus service – Unknown – pavsrv.exe (file missing)

Odpowiedzi: 2

Dodam jeszcze ze to rowniez wylatuje:
O4 – HKLM..Run: [sp] rundll32 C:DOCUME~1plusgsmUSTAWI~1Tempse.dll,DllInstall
Razem z innymi Tempami
Bobi
Dodano
13.02.2005 16:42:16
Wylaczasz przywracanie. Konczysz w menedzerze zadan te procesy:
gah95on6.exe
WinStat.exe
i usuwasz je wraz z odpowiadajacymi im katalogami
Dlle wyrejestrowujesz przed usunieciem (regsvr32 /u C:WINDOWSsystem32jbkm.dll) i INSTAF~1.DLL
Na koniec fixujesz ponizsze pozycje:

C:WINDOWSsystem32gah95on6.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:DOCUME~1plusgsmUSTAWI~1Tempse.dll/sp.html
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:DOCUME~1plusgsmUSTAWI~1Tempse.dll/sp.html
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank
R1 – HKLMSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 – URLSearchHook: (no name) – {87766247–311C–43B4–8499–3D5FEC94A183} – (no file)
O2 – BHO: (no name) – {00000010–6F7D–442C–93E3–4A4827C2E4C8} – (no file)
O2 – BHO: InstaFinderK – {4E7BD74F–2B8D–469E–90F0–F66AB581A933} – C:PROGRA~1INSTAF~1INSTAF~1.DLL
O2 – BHO: (no name) – {96C43FF5–508B–46C4–9B08–BBCD5000934F} – C:WINDOWSsystem32jbkm.dll
O4 – HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 –k
O4 – HKLM..Run: [Windows AdStatus] C:Program FilesWindows AdStatusWinStat.exe
O4 – HKLM..Run: [gah95on6] C:WINDOWSsystem32gah95on6.exe
O18 – Filter: text/html – {DDF8016A–3C49–48B3–8BDC–F7DFBADCA2AD} – C:WINDOWSsystem32jbkm.dll
O18 – Filter: text/plain – {DDF8016A–3C49–48B3–8BDC–F7DFBADCA2AD} – C:WINDOWSsystem32jbkm.dll
O23 – Service: Panda anti–virus service – Unknown – pavsrv.exe (file missing)
wins
Dodano
13.02.2005 15:47:42
bystry77
Dodano:
13.02.2005 14:54:24
Komentarzy:
2
Strona 1 / 1