sprawdzenie log– a
Czy ktoś moźe sprawdzić mój log?
Logfile of HijackThis v1.99.0
Scan saved at 14:58:48, on 2005–01–17
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSSystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:PROGRA~1A4TechMouseAmoumain.exe
C:PROGRA~1PESTPA~1PPMemCheck.exe
C:PROGRA~1PESTPA~1PPControl.exe
C:WINDOWSsystem32NVATray.exe
C:PROGRA~1PESTPA~1CookiePatrol.exe
C:PROGRA~1ALWILS~1Avast4ashDisp.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesGadu–Gadugg.exe
C:Program FilesOpenOffice.org1.1.0programsoffice.exe
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
C:Program FilesRainlendarRainlendar.exe
C:Program FilesAlwil SoftwareAvast4ashServ.exe
c:progra~1intern~1iexplore.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe
C:Program FilesRainlendarRainlendar.exe
C:Documents and SettingswozimexPulpitHijackThis.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.iqazbcronslaocjvjxvxgicdo.net/2c6WpdU9f_0y3ItHmmr__imyR1vuFRBOckKpwckYnCC2yqD_CqnLHuhhdncJCGM_.html
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.shell.com.pl/
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R3 – URLSearchHook: (no name) – {1C78AB3F–A857–482e–80C0–3A1E5238A565} – (no file)
F2 – REG:system.ini: Shell=
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll
O2 – BHO: (no name) – {2532C553–8D80–C7D6–963F–468C6CE172EB} – C:PROGRA~1MATHTI~1filmshim.exe (file missing)
O2 – BHO: (no name) – {53707962–6F74–2D53–2644–206D7942484F} – C:PROGRA~1SPYBOT~1SDHelper.dll
O2 – BHO: Google Toolbar Helper – {AA58ED58–01DD–4d91–8333–CF10577473F7} – c:program filesgooglegoogletoolbar1.dll
O3 – Toolbar: &Google – {2318C2B1–4965–11d4–9B18–009027A5CD4F} – c:program filesgooglegoogletoolbar1.dll
O4 – HKLM..Run: [APVXDWIN] "C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004APVXDWIN.EXE" /s
O4 – HKLM..Run: [WheelMouse] C:PROGRA~1A4TechMouseAmoumain.exe
O4 – HKLM..Run: [PPMemCheck] C:PROGRA~1PESTPA~1PPMemCheck.exe
O4 – HKLM..Run: [Platform Atom Pile Mags] C:Documents and SettingsAll UsersDane aplikacjideletestyleplatformatomurnbits.exe
O4 – HKLM..Run: [PestPatrol Control Center] C:PROGRA~1PESTPA~1PPControl.exe
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [NVIDIA nForce APU1 Utilities] NVATray.exe
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 – HKLM..Run: [HPDJ Taskbar Utility] C:WINDOWSSystem32spooldriversw32x863hpztsb08.exe
O4 – HKLM..Run: [CookiePatrol] C:PROGRA~1PESTPA~1CookiePatrol.exe
O4 – HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe
O4 – HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 – HKCU..Run: [Komunikator] C:Program FilesTlen.pl len.exe
O4 – HKCU..Run: [idle web] C:DOCUME~1wozimexDANEAP~1playmailPoll flap.exe
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – Startup: OpenOffice.org 1.1.0.lnk = C:Program FilesOpenOffice.org1.1.0programquickstart.exe
O4 – Startup: Rainlendar.lnk = C:Program FilesRainlendarRainlendar.exe
O8 – Extra context menu item: &Google Search – res://c:program filesgoogleGoogleToolbar1.dll/cmsearch.html
O8 – Extra context menu item: Backward Links – res://c:program filesgoogleGoogleToolbar1.dll/cmbacklinks.html
O8 – Extra context menu item: Cached Snapshot of Page – res://c:program filesgoogleGoogleToolbar1.dll/cmcache.html
O8 – Extra context menu item: Similar Pages – res://c:program filesgoogleGoogleToolbar1.dll/cmsimilar.html
O8 – Extra context menu item: Translate into English – res://c:program filesgoogleGoogleToolbar1.dll/cmtrans.html
O9 – Extra button: (no name) – {CD67F990–D8E9–11d2–98FE–00C0F0318AFE} – (no file)
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O13 – Home Prefix:
O13 – Mosaic Prefix:
O13 – FTP Prefix:
O13 – Gopher Prefix:
O16 – DPF: {205FF73B–CA67–11D5–99DD–444553540000} (CInstall Class) – http://www.spywarestormer.com/files2/Install.cab
O16 – DPF: {2F0D1DA3–F3E4–4C67–BB5C–5AFD70C1A4A5} (UDConnect Class) – http://03.sharedsource.org/html/UDConn_5.2.1.1.cab
O16 – DPF: {9A9307A0–7DA4–4DAF–B042–5009F29E09E1} (ActiveScan Installer Class) –
O16 – DPF: {A3009861–330C–4E10–822B–39D16EC8829D} (CRAVOnline Object) – http://www.ravantivirus.com/scan/ravonline.cab
O17 – HKLMSystemCCSServicesTcpip..{5881969F–0643–4A80–B0A7–453E4D2D3435}: NameServer = 212.244.88.3,212.244.88.24
O23 – Service: avast! iAVS4 Control Service – Unknown – C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
O23 – Service: avast! Antivirus – Unknown – C:Program FilesAlwil SoftwareAvast4ashServ.exe
O23 – Service: avast! Mail Scanner – ALWIL Software – C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe
Logfile of HijackThis v1.99.0
Scan saved at 14:58:48, on 2005–01–17
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSSystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:PROGRA~1A4TechMouseAmoumain.exe
C:PROGRA~1PESTPA~1PPMemCheck.exe
C:PROGRA~1PESTPA~1PPControl.exe
C:WINDOWSsystem32NVATray.exe
C:PROGRA~1PESTPA~1CookiePatrol.exe
C:PROGRA~1ALWILS~1Avast4ashDisp.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesGadu–Gadugg.exe
C:Program FilesOpenOffice.org1.1.0programsoffice.exe
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
C:Program FilesRainlendarRainlendar.exe
C:Program FilesAlwil SoftwareAvast4ashServ.exe
c:progra~1intern~1iexplore.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe
C:Program FilesRainlendarRainlendar.exe
C:Documents and SettingswozimexPulpitHijackThis.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.iqazbcronslaocjvjxvxgicdo.net/2c6WpdU9f_0y3ItHmmr__imyR1vuFRBOckKpwckYnCC2yqD_CqnLHuhhdncJCGM_.html
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.shell.com.pl/
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R3 – URLSearchHook: (no name) – {1C78AB3F–A857–482e–80C0–3A1E5238A565} – (no file)
F2 – REG:system.ini: Shell=
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll
O2 – BHO: (no name) – {2532C553–8D80–C7D6–963F–468C6CE172EB} – C:PROGRA~1MATHTI~1filmshim.exe (file missing)
O2 – BHO: (no name) – {53707962–6F74–2D53–2644–206D7942484F} – C:PROGRA~1SPYBOT~1SDHelper.dll
O2 – BHO: Google Toolbar Helper – {AA58ED58–01DD–4d91–8333–CF10577473F7} – c:program filesgooglegoogletoolbar1.dll
O3 – Toolbar: &Google – {2318C2B1–4965–11d4–9B18–009027A5CD4F} – c:program filesgooglegoogletoolbar1.dll
O4 – HKLM..Run: [APVXDWIN] "C:Program FilesPanda SoftwarePanda Titanium Antivirus 2004APVXDWIN.EXE" /s
O4 – HKLM..Run: [WheelMouse] C:PROGRA~1A4TechMouseAmoumain.exe
O4 – HKLM..Run: [PPMemCheck] C:PROGRA~1PESTPA~1PPMemCheck.exe
O4 – HKLM..Run: [Platform Atom Pile Mags] C:Documents and SettingsAll UsersDane aplikacjideletestyleplatformatomurnbits.exe
O4 – HKLM..Run: [PestPatrol Control Center] C:PROGRA~1PESTPA~1PPControl.exe
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [NVIDIA nForce APU1 Utilities] NVATray.exe
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 – HKLM..Run: [HPDJ Taskbar Utility] C:WINDOWSSystem32spooldriversw32x863hpztsb08.exe
O4 – HKLM..Run: [CookiePatrol] C:PROGRA~1PESTPA~1CookiePatrol.exe
O4 – HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe
O4 – HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 – HKCU..Run: [Komunikator] C:Program FilesTlen.pl len.exe
O4 – HKCU..Run: [idle web] C:DOCUME~1wozimexDANEAP~1playmailPoll flap.exe
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – Startup: OpenOffice.org 1.1.0.lnk = C:Program FilesOpenOffice.org1.1.0programquickstart.exe
O4 – Startup: Rainlendar.lnk = C:Program FilesRainlendarRainlendar.exe
O8 – Extra context menu item: &Google Search – res://c:program filesgoogleGoogleToolbar1.dll/cmsearch.html
O8 – Extra context menu item: Backward Links – res://c:program filesgoogleGoogleToolbar1.dll/cmbacklinks.html
O8 – Extra context menu item: Cached Snapshot of Page – res://c:program filesgoogleGoogleToolbar1.dll/cmcache.html
O8 – Extra context menu item: Similar Pages – res://c:program filesgoogleGoogleToolbar1.dll/cmsimilar.html
O8 – Extra context menu item: Translate into English – res://c:program filesgoogleGoogleToolbar1.dll/cmtrans.html
O9 – Extra button: (no name) – {CD67F990–D8E9–11d2–98FE–00C0F0318AFE} – (no file)
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O13 – Home Prefix:
O13 – Mosaic Prefix:
O13 – FTP Prefix:
O13 – Gopher Prefix:
O16 – DPF: {205FF73B–CA67–11D5–99DD–444553540000} (CInstall Class) – http://www.spywarestormer.com/files2/Install.cab
O16 – DPF: {2F0D1DA3–F3E4–4C67–BB5C–5AFD70C1A4A5} (UDConnect Class) – http://03.sharedsource.org/html/UDConn_5.2.1.1.cab
O16 – DPF: {9A9307A0–7DA4–4DAF–B042–5009F29E09E1} (ActiveScan Installer Class) –
O16 – DPF: {A3009861–330C–4E10–822B–39D16EC8829D} (CRAVOnline Object) – http://www.ravantivirus.com/scan/ravonline.cab
O17 – HKLMSystemCCSServicesTcpip..{5881969F–0643–4A80–B0A7–453E4D2D3435}: NameServer = 212.244.88.3,212.244.88.24
O23 – Service: avast! iAVS4 Control Service – Unknown – C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
O23 – Service: avast! Antivirus – Unknown – C:Program FilesAlwil SoftwareAvast4ashServ.exe
O23 – Service: avast! Mail Scanner – ALWIL Software – C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe
Odpowiedzi: 5
dzięki juź jest ok!!!!!!
Jesli nie znasz i nie wiesz co to za programy, zerknij do Dodaj/usun i uninstall. Jesli nie bedzie, usun w HiJacku.
Jesli nie znasz i nie wiesz co to za programy, zerknij do Dodaj/usun i uninstall. Jesli nie bedzie, usun w HiJacku.
dzięki!!! a tych exeków nie znam
Usuwasz:
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.iqazbcronslaocjvjxvxgicdo.net/2c6WpdU9f_0y3ItHmmr__imyR1vuFRBOckKpwckYnCC2yqD_CqnLHuhhdncJCGM_.html
R3 – URLSearchHook: (no name) – {1C78AB3F–A857–482e–80C0–3A1E5238A565} – (no file)
F2 – REG:system.ini: Shell=
O2 – BHO: (no name) – {2532C553–8D80–C7D6–963F–468C6CE172EB} – C:PROGRA~1MATHTI~1filmshim.exe (file missing)
O9 – Extra button: (no name) – {CD67F990–D8E9–11d2–98FE–00C0F0318AFE} – (no file)
O13 – Home Prefix:
O13 – Mosaic Prefix:
O13 – FTP Prefix:
O13 – Gopher Prefix:
O16 – DPF: {9A9307A0–7DA4–4DAF–B042–5009F29E09E1} (ActiveScan Installer Class) –
Znasz te exeki ?
O4 – HKLM..Run: [Platform Atom Pile Mags] C:Documents and SettingsAll UsersDane aplikacjideletestyleplatformatomurnbits.exe
O4 – HKCU..Run: [idle web] C:DOCUME~1wozimexDANEAP~1playmailPoll flap.exe
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.iqazbcronslaocjvjxvxgicdo.net/2c6WpdU9f_0y3ItHmmr__imyR1vuFRBOckKpwckYnCC2yqD_CqnLHuhhdncJCGM_.html
R3 – URLSearchHook: (no name) – {1C78AB3F–A857–482e–80C0–3A1E5238A565} – (no file)
F2 – REG:system.ini: Shell=
O2 – BHO: (no name) – {2532C553–8D80–C7D6–963F–468C6CE172EB} – C:PROGRA~1MATHTI~1filmshim.exe (file missing)
O9 – Extra button: (no name) – {CD67F990–D8E9–11d2–98FE–00C0F0318AFE} – (no file)
O13 – Home Prefix:
O13 – Mosaic Prefix:
O13 – FTP Prefix:
O13 – Gopher Prefix:
O16 – DPF: {9A9307A0–7DA4–4DAF–B042–5009F29E09E1} (ActiveScan Installer Class) –
Znasz te exeki ?
O4 – HKLM..Run: [Platform Atom Pile Mags] C:Documents and SettingsAll UsersDane aplikacjideletestyleplatformatomurnbits.exe
O4 – HKCU..Run: [idle web] C:DOCUME~1wozimexDANEAP~1playmailPoll flap.exe
Strona 1 / 1