Sprawdzenie loga – proźba
log nie mój ale kumpel prosi o sprawdzenie:
A sprawdzicie mi Zupełnie nie wiem o co w tym chodzi
oto log:
Logfile of HijackThis v1.99.1
Scan saved at 14:21:12, on 2005–02–18
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSSystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSOUNDMAN.EXE
C:Program FilesKaspersky LabKaspersky Anti–Virus Personal Proavpcc.exe
D:Javainjusched.exe
D:ProgramyFree NotesFreeNotes.exe
C:Program FilesKaspersky LabKaspersky Anti–Virus Personal Proavpcc.exe
C:Program FilesNorton SystemWorksNorton GhostGhostStartService.exe
C:Program FilesKaspersky LabKaspersky Anti–Virus Personal Proavpm.exe
C:Program FilesCommon FilesMicrosoft SharedVS7Debugmdm.exe
C:PROGRA~1MCAFEE.COMPERSON~1MPFSERVICE.exe
D:ProgramyBitCometBitComet.exe
C:PROGRA~1NORTON~1NORTON~1SPEEDD~1NOPDB.EXE
C:WINDOWSSystem32svchost.exe
C:Documents and SettingsWin XpDane aplikacjiMap MakerMMManager.exe
C:Program FilesCommon FilesSymantec SharedCCPD–LCsymlcsvc.exe
C:PROGRA~1MCAFEE.COMPERSON~1MPFAGENT.EXE
D:ProgramyGadu–Gadugg.exe
C:PROGRA~1MCAFEE.COMPERSON~1MpfTray.exe
D:ProgramyMozilla Firefoxfirefox.exe
C:Documents and SettingsWin XpPulpithijackthis_199HijackThis.exe
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.piespekinczyk.republika.pl/
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O1 – Hosts: 127.0.0.3 www.greg–tut.com
O1 – Hosts: 127.0.0.3 nylonsexy.com
O1 – Hosts: 127.0.0.3 www.nylonsexy.com
O1 – Hosts: 127.0.0.3 vparivalka.com
O1 – Hosts: 127.0.0.3 www.vparivalka.comtoescrowpay.com
O1 – Hosts: 127.0.0.3 www.awmdabest.com
O1 – Hosts: 127.0.0.3 www.sexfiles.nu
O1 – Hosts: 127.0.0.3 awmdabest.com
O1 – Hosts: 127.0.0.3 sexfiles.nu
O1 – Hosts: 127.0.0.3 allforadult.com
O1 – Hosts: 127.0.0.3 www.allforadult.com
O1 – Hosts: 127.0.0.3 www.iframe.biz
O1 – Hosts: 127.0.0.3 iframe.biz
O1 – Hosts: 127.0.0.3 www.newiframe.biz
O1 – Hosts: 127.0.0.3 newiframe.biz
O1 – Hosts: 127.0.0.3 www.vesbiz.biz
O1 – Hosts: 127.0.0.3 vesbiz.biz
O1 – Hosts: 127.0.0.3 www.pizdato.biz
O1 – Hosts: 127.0.0.3 pizdato.biz
O1 – Hosts: 127.0.0.3 www.aaasexypics.com
O1 – Hosts: 127.0.0.3 aaasexypics.com
O1 – Hosts: 127.0.0.3 www.virgin–tgp.net
O1 – Hosts: 127.0.0.3 virgin–tgp.net
O1 – Hosts: 127.0.0.3 www.awmcash.biz
O1 – Hosts: 127.0.0.3 awmcash.biz
O1 – Hosts: 127.0.0.3 buldog–stats.com
O1 – Hosts: 127.0.0.3 www.buldog–stats.com
O1 – Hosts: 127.0.0.3 fregat.drocherway.com
O1 – Hosts: 127.0.0.3 slutmania.biz
O1 – Hosts: 127.0.0.3 www.slutmania.biz
O1 – Hosts: 127.0.0.3 toolbarpartner.com
O1 – Hosts: 127.0.0.3 www.toolbarpartner.com
O1 – Hosts: 127.0.0.3 www.megapornix.com
O1 – Hosts: 127.0.0.3 megapornix.com
O1 – Hosts: 127.0.0.3 www.sp2fucked.biz
O1 – Hosts: 127.0.0.3 sp2fucked.biz
O1 – Hosts: 127.0.0.3 greg–tut.com
O1 – Hosts: http://213.159.117.203/dkprogs/hosts.txt
O2 – BHO: Yahoo! Companion BHO – {02478D38–C3F9–4efb–9B51–7695ECA05670} – C:Program FilesYahoo!CompanionInstallscpnycomp5_5_7_0.dll
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll
O2 – BHO: IeCatch2 Class – {A5366673–E8CA–11D3–9CD9–0090271D075B} – D:PROGRAMYFLASHGETjccatch.dll
O3 – Toolbar: FlashGet Bar – {E0E899AB–F487–11D5–8D29–0050BA6940E3} – D:PROGRAMYFLASHGETfgiebar.dll
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O3 – Toolbar: Yahoo! Companion – {EF99BD32–C1FB–11D2–892F–0090271D4F88} – C:Program FilesYahoo!CompanionInstallscpnycomp5_5_7_0.dll
O4 – HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 – HKLM..Run: [OfficeGuard RegChecker] "C:Program FilesKaspersky LabKaspersky Anti–Virus Personal Proogrc.exe"
O4 – HKLM..Run: [AVPCC] "C:Program FilesKaspersky LabKaspersky Anti–Virus Personal Proavpcc.exe" /wait
O4 – HKLM..Run: [FineReader7NewsReaderPro] C:Program FilesABBYY FineReader 7.0 Professional EditionAbbyyNewsReader.exe
O4 – HKLM..Run: [SunJavaUpdateSched] D:Javainjusched.exe
O4 – HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 –k
O4 – HKCU..Run: [Free Notes] "D:ProgramyFree NotesFreeNotes.exe"
O4 – HKCU..Run: [Gadu–Gadu] "D:ProgramyGadu–Gadugg.exe" /tray
O4 – HKCU..Run: [BitComet] "D:ProgramyBitCometBitComet.exe"
O4 – HKCU..Run: [Komunikator] D:ProgramyTlen len.exe
O4 – Startup: SunClock5.lnk = C:Documents and SettingsWin XpDane aplikacjiMap MakerMMManager.exe
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O8 – Extra context menu item: Ściągnij przy pomocy FlashGet'a – D:ProgramyFlashGetjc_link.htm
O8 – Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a – D:ProgramyFlashGetjc_all.htm
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:WINDOWSSystem32msjava.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:WINDOWSSystem32msjava.dll
O9 – Extra button: Badanie – {92780B25–18CC–41C8–B9BE–3C9C571A8263} – C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O9 – Extra button: FlashGet – {D6E814A0–E0C5–11d4–8D29–0050BA6940E3} – D:PROGRAMYFLASHGETflashget.exe
O9 – Extra 'Tools' menuitem: &FlashGet – {D6E814A0–E0C5–11d4–8D29–0050BA6940E3} – D:PROGRAMYFLASHGETflashget.exe
O20 – Winlogon Notify: WB – D:PROGRAMYWINDOW~1fastload.dll
O23 – Service: Ati HotKey Poller – Unknown owner – C:WINDOWSSystem32Ati2evxx.exe
O23 – Service: ATI Smart – Unknown owner – C:WINDOWSsystem32ati2sgag.exe
O23 – Service: AVP Control Centre Service (AVPCC) – Unknown owner – C:Program FilesKaspersky LabKaspersky Anti–Virus Personal Proavpcc.exe" /service (file missing)
O23 – Service: GhostStartService – Symantec Corporation – C:Program FilesNorton SystemWorksNorton GhostGhostStartService.exe
O23 – Service: KAV Monitor Service (KAVMonitorService) – Unknown owner – C:Program FilesKaspersky LabKaspersky Anti–Virus Personal Proavpm.exe" /service (file missing)
O23 – Service: McAfee Personal Firewall Service (MpfService) – McAfee Corporation – C:PROGRA~1MCAFEE.COMPERSON~1MPFSERVICE.exe
O23 – Service: Speed Disk service – Symantec Corporation – C:PROGRA~1NORTON~1NORTON~1SPEEDD~1NOPDB.EXE
O23 – Service: Symantec Core LC – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedCCPD–LCsymlcsvc.exe
Odpowiedzi: 1
W tych wszyskich wpisach w pliku hosts w lokalizacji
C:WINDOWSsystem32driversetc
Zamaist 3 na koncu zmienia na 1 czyli 127.0.0.1
Natomiast ta linjike:
O1 – Hosts: http://213.159.117.203/dkprogs/hosts.txt
modyfikuje do tej posatci:
127.0.0.1 http://213.159.117.203
Modyfikacje przeprowadza otwierajac np w notatniku
FIX:
O4 – HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 –k
(KAVMonitorService) – Unknown owner – C:Program FilesKaspersky LabKaspersky Anti–Virus Personal Proavpm.exe" /service (file missing)
Wpisy od Kaspersky tez mozna usunac bo juz go nie ma
C:WINDOWSsystem32driversetc
Zamaist 3 na koncu zmienia na 1 czyli 127.0.0.1
O1 – Hosts: 127.0.0.3 www.greg–tut.com
O1 – Hosts: 127.0.0.3 nylonsexy.com
O1 – Hosts: 127.0.0.3 www.nylonsexy.com
O1 – Hosts: 127.0.0.3 vparivalka.com
O1 – Hosts: 127.0.0.3 www.vparivalka.comtoescrowpay.com
O1 – Hosts: 127.0.0.3 www.awmdabest.com
O1 – Hosts: 127.0.0.3 www.sexfiles.nu
O1 – Hosts: 127.0.0.3 awmdabest.com
O1 – Hosts: 127.0.0.3 sexfiles.nu
O1 – Hosts: 127.0.0.3 allforadult.com
O1 – Hosts: 127.0.0.3 www.allforadult.com
O1 – Hosts: 127.0.0.3 www.iframe.biz
O1 – Hosts: 127.0.0.3 iframe.biz
O1 – Hosts: 127.0.0.3 www.newiframe.biz
O1 – Hosts: 127.0.0.3 newiframe.biz
O1 – Hosts: 127.0.0.3 www.vesbiz.biz
O1 – Hosts: 127.0.0.3 vesbiz.biz
O1 – Hosts: 127.0.0.3 www.Pamela.biz
O1 – Hosts: 127.0.0.3 Pamela.biz
O1 – Hosts: 127.0.0.3 www.aaasexypics.com
O1 – Hosts: 127.0.0.3 aaasexypics.com
O1 – Hosts: 127.0.0.3 www.virgin–tgp.net
O1 – Hosts: 127.0.0.3 virgin–tgp.net
O1 – Hosts: 127.0.0.3 www.awmcash.biz
O1 – Hosts: 127.0.0.3 awmcash.biz
O1 – Hosts: 127.0.0.3 buldog–stats.com
O1 – Hosts: 127.0.0.3 www.buldog–stats.com
O1 – Hosts: 127.0.0.3 fregat.drocherway.com
O1 – Hosts: 127.0.0.3 slutmania.biz
O1 – Hosts: 127.0.0.3 www.slutmania.biz
O1 – Hosts: 127.0.0.3 toolbarpartner.com
O1 – Hosts: 127.0.0.3 www.toolbarpartner.com
O1 – Hosts: 127.0.0.3 www.megapornix.com
O1 – Hosts: 127.0.0.3 megapornix.com
O1 – Hosts: 127.0.0.3 www.sp2fucked.biz
O1 – Hosts: 127.0.0.3 sp2fucked.biz
O1 – Hosts: 127.0.0.3 greg–tut.com
Natomiast ta linjike:
O1 – Hosts: http://213.159.117.203/dkprogs/hosts.txt
modyfikuje do tej posatci:
127.0.0.1 http://213.159.117.203
Modyfikacje przeprowadza otwierajac np w notatniku
FIX:
O4 – HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 –k
(KAVMonitorService) – Unknown owner – C:Program FilesKaspersky LabKaspersky Anti–Virus Personal Proavpm.exe" /service (file missing)
Wpisy od Kaspersky tez mozna usunac bo juz go nie ma
Strona 1 / 1