Symantec wysyla setki wiadomosci
Mam nortona internet security 2005 w tym antyvirus auto protect lecz mam z nim problemy. Ostatnio wlacza mi sie scanowanie wysylanych e–maili tylko ze ja ich nie wysylam :roll: ??? Rozumiem ze mozna wylaczyc skanowanie wysylanych e–maili, ale ja nie chce tego wylaczac. Prosze o pomoc w rozwiazaniu tego problemu dolaczam zdjecie na ktorym widac co sie dzieje :idea: .[/list]
Odpowiedzi: 18
OT: 2
Ten Logitech Desktop Messenger mu tych 018 nawalił jak się łaczył i sprawdzał aktualizacje.
Poza tym klikało się po fajnych stronach bez gumki to i syf się ma :wink:
Ten Logitech Desktop Messenger mu tych 018 nawalił jak się łaczył i sprawdzał aktualizacje.
Poza tym klikało się po fajnych stronach bez gumki to i syf się ma :wink:
OT: Nie wierze ze Norton tyle tego przepuscil
Pewnie instalowałes go po fakcie i na dodatek nie wykonałes skanowania przedinstalacyjnego
Pewnie instalowałes go po fakcie i na dodatek nie wykonałes skanowania przedinstalacyjnego
Jezu jaki ty miałeś syf na kompie, martinmarshall... nawet ja takiego nie miałem :mrgreen:
Sciagnij uninstaller'a do NewNet'a
Odpal go
Pozniej ptaszek (V) i fix checked przy tych 3 pozycjach
C:WINDOWSmultimpp.dll
Znajdz ten plik i usun go a pozniej sfixuj przez HJT
PS: Nie dziwie sie ze wysylal maile na prawo i lewo przy takiej ilosci syfu :roll:
Odpal go
Pozniej ptaszek (V) i fix checked przy tych 3 pozycjach
C:WINDOWSmultimpp.dll
Znajdz ten plik i usun go a pozniej sfixuj przez HJT
PS: Nie dziwie sie ze wysylal maile na prawo i lewo przy takiej ilosci syfu :roll:
Powidzcie mi jeszcze jak mam to usunac gdzie mam wejsc ???
HKCUSoftwareMicrosoftInternet Explorer,SearchURL = http://www.isearch.com/index.php?app=SE&affjump=1&affiliate=ODQ6NTo5&Terms=
O10 – Hijacked Internet access by New.Net
O16 – DPF: {15AD4789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://static.windupdates.com/cab/DownloadsUnlimited/ie/bridge–c11.cab
a z tymi
O2 – BHO: MultiMPPObj Class – {002EB272–2590–4693–B166–FBD5D9B6FEA6} – C:WINDOWSmultimpp.dll
mam je calkowicie skasowac tak ???
HKCUSoftwareMicrosoftInternet Explorer,SearchURL = http://www.isearch.com/index.php?app=SE&affjump=1&affiliate=ODQ6NTo5&Terms=
O10 – Hijacked Internet access by New.Net
O16 – DPF: {15AD4789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://static.windupdates.com/cab/DownloadsUnlimited/ie/bridge–c11.cab
a z tymi
O2 – BHO: MultiMPPObj Class – {002EB272–2590–4693–B166–FBD5D9B6FEA6} – C:WINDOWSmultimpp.dll
mam je calkowicie skasowac tak ???
Dziekowa za pomoc, wiry juz usuniete a reszte sie zrobi (mam nadzieje) :lol: Wielkie dzieki
Wyłącz przywracanie systemu,
Uruchom PC w trybie awaryjnym,
Zakoncz aktywne procesy z listy niźej wyszukaj je i usuń.
Napraw i zwróć uwagę co napisałem w nawiasach.
Jeśli odinstalujesz LogitechDesktopMessenger.exe sprawdz czy w lokalizacji znajduje się BWPlugProtocol–8876480.dll jak tak to usuń.
Dalej Fix ( jeśli ponownie będzie w logu ).
Nie wnikam w szczegóły, ale IMO przeszedłeś sam siebie z takim syfem.
Update 1.
Uzyj Spybot`a i innych Spy/Adware skanerów to usuną częsć dupereli.
Będzie Tobie łatwiej blank`i usuwać ( no file ).
Update 2 :
Nie łaź po dupach jak nie potrafisz.
Usuń Internet Temporary Files to pozbedziesz się ByteVerify i inych z Internet Temp.
Uruchom PC w trybie awaryjnym,
Zakoncz aktywne procesy z listy niźej wyszukaj je i usuń.
Napraw i zwróć uwagę co napisałem w nawiasach.
C:WINDOWSSystem32leqhvb.exe
C:WINDOWSsystem32svhost32.exe
C:Program FilesWindows ControlAdWinCtlAd.exe
C:Program FilesLogitechDesktop Messenger8876480ProgramLogitechDesktopMessenger.exe ( nie potrzebne bo tylko burdel robi odinstaluj )
C:PROGRA~1COMMON~1 sa sm2.exe
R1 – HKCUSoftwareMicrosoftInternet Explorer,SearchURL = http://www.isearch.com/index.php?app=SE&affjump=1&affiliate=ODQ6NTo5&Terms=
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.isearch.com/index.php?app=SE&affjump=1&affiliate=ODQ6NTo5&Terms=
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.isearch.com/index.php?app=SE&affjump=1&affiliate=ODQ6NTo5&Terms=
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://www.isearch.com/index.php?app=SE&affjump=1&affiliate=ODQ6NTo5&Terms=
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://www.isearch.com/index.php?app=SE&affjump=1&affiliate=ODQ6NTo5&Terms=
R3 – URLSearchHook: (no name) – {1C78AB3F–A857–482e–80C0–3A1E5238A565} – (no file)
O2 – BHO: MultiMPPObj Class – {002EB272–2590–4693–B166–FBD5D9B6FEA6} – C:WINDOWSmultimpp.dll
O2 – BHO: ohb – {086CEFD5–A88D–4981–8915–D51F04360ED1} – C:WINDOWSsystem32winhot32.dll
O2 – BHO: Search Relevancy – {1D7E3B41–23CE–469B–BE1B–A64B877923E1} – C:PROGRA~1SEARCH~1SEARCH~2.DLL
O2 – BHO: URLLink Class – {4A2AACF3–ADF6–11D5–98A9–00E018981B9E} – C:Program FilesNewDotNet ewdotnet6_38
O2 – BHO: C:WINDOWSlbbho.dll – {5EA9EBB6–D0F0–4B70–B3E9–3BAA9C69B721} – C:WINDOWSlbbho.dll
O2 – BHO: QUICKfind BHO Object – {C08DF07A–3E49–4E25–9AB0–D3882835F153} – C:PROGRA~1TEXTwareQUICKF~1PlugInsIEHelp.dll
O2 – BHO: Saristar – {C68AE9C0–0909–4DDC–B661–C1AFB9F5AE50} – C:WINDOWSsystem32saristar.dll
O3 – Toolbar: HotSearchBar.com Bar – {8B224779–3B0E–4FEA–8AE1–B66C20DD840F} – C:WINDOWSsystem32winhot32.dll
O4 – HKLM..Run: [uajbbvl] C:WINDOWSSystem32leqhvb.exe
O4 – HKLM..Run: [conscorr] C:WINDOWSconscorr.exe
O4 – HKLM..Run: [New.net Startup] rundll32 C:PROGRA~1NEWDOT~1NEWDOT~2.DLL,NewDotNetStartup–s
O4 – HKLM..Run: [UsbD] C:WINDOWSsystem32svhost32.exe
O4 – HKLM..Run: [Windows ControlAd] C:Program FilesWindows ControlAdWinCtlAd.exe
O4 – HKLM..Run: [version] C:WINDOWSsystem32II22.exe
O4 – HKLM..Run: [pyzih] C:WINDOWSpyzih.exe
O4 – HKCU..Run: [LDM] C:Program FilesLogitechDesktop Messenger8876480ProgramLogitechDesktopMessenger.exe ( usuń ten automatyczny Update Logitech`a )
O4 – HKCU..Run: [Tsa2] C:PROGRA~1COMMON~1 sa sm2.exe
O8 – Extra context menu item: &iSearch The Web – res://C:WINDOWSsystem32 oolbar.dll/SEARCH.HTML
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O16 – DPF: {11111111–1111–1111–1111–111111111732} – file://c:progra~1pl.exe
O16 – DPF: {11111111–1111–1111–1111–111111113457} – file://c:explorer.cab
O16 – DPF: {15AD4789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://static.windupdates.com/cab/DownloadsUnlimited/ie/bridge–c11.cab
O16 – DPF: {1C78AB3F–A857–482E–80C0–3A1E5238A565} – http://toolbar.isearch.com/general/drm.cab
O16 – DPF: {771A1334–6B08–4A6B–AEDC–CF994BA2CEBE} (Installer Class) – http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab
O16 – DPF: {99802379–7362–40E2–9D28–8A3B9AF880B7} (iiittt Class) – http://hotsearchbar.com/toolbar2/winhot32.cab
Jeśli odinstalujesz LogitechDesktopMessenger.exe sprawdz czy w lokalizacji znajduje się BWPlugProtocol–8876480.dll jak tak to usuń.
Dalej Fix ( jeśli ponownie będzie w logu ).
O18 – Protocol: bw+0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw+0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw–0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw–0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw00 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw00s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw10 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw10s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw20 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw20s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw30 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw30s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw40 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw40s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw50 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw50s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw60 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw60s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw70 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw70s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw80 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw80s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw90 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw90s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwa0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwa0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwb0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwb0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwc0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwc0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwd0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwd0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwe0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwe0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwf0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwf0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwfile–8876480 – {9462A756–7B47–47BC–8C80–C34B9B80B32B} – C:Program FilesLogitechDesktop Messenger8876480ProgramGAPlugProtocol–8876480.dll
O18 – Protocol: bwg0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwg0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwh0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwh0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwi0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwi0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwj0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwj0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwk0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwk0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwl0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwl0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwm0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwm0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwn0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwn0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwo0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwo0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwp0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwp0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwq0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwq0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwr0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwr0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bws0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bws0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwt0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwt0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwu0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwu0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwv0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwv0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bww0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bww0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwx0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwx0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwy0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwy0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwz0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwz0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: offline–8876480 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: textwareilluminatorbase – {CE5CD329–1650–414A–8DB0–4CBF72FAED87} – C:WINDOWSsystem32 extwareilluminatorbaseProtocol.dll
O23 – Service: Win32 Wmls Driver – Unknown – C:WINDOWSSystem32winitr32.exe (file missing)
Nie wnikam w szczegóły, ale IMO przeszedłeś sam siebie z takim syfem.
Update 1.
Uzyj Spybot`a i innych Spy/Adware skanerów to usuną częsć dupereli.
Będzie Tobie łatwiej blank`i usuwać ( no file ).
Update 2 :
Nie łaź po dupach jak nie potrafisz.
Usuń Internet Temporary Files to pozbedziesz się ByteVerify i inych z Internet Temp.
dawno nie widzielem czegos takiego :roll:
Czyscisz czasam i system itd ?
Czyscisz czasam i system itd ?
Zdarzenie Status Lokalizacja
Virus:Trj/Downloader.NL Nie wyleczalny System operacyjny
Virus:Exploit/ByteVerify Nie wyleczalny C:Documents and SettingsWitold MarcinApplication DataSunJavaDeploymentcachejavapiv1.0fileDummy.class–400b01a8–2a0215ec.class
Virus:Exploit/ByteVerify Nie wyleczalny C:Documents and SettingsWitold MarcinApplication DataSunJavaDeploymentcachejavapiv1.0fileGummy.class–673366f0–7913880f.class
Virus:Exploit/ByteVerify Nie wyleczalny C:Documents and SettingsWitold MarcinApplication DataSunJavaDeploymentcachejavapiv1.0jarar3.jar–4966bd13–7643d2d4.zip[Gummy.class]
Virus:Exploit/ByteVerify Nie wyleczalny C:Documents and SettingsWitold MarcinApplication DataSunJavaDeploymentcachejavapiv1.0jararchive.jar–2880d2c3–4dd5f813.zip[BlackBox.class]
Virus:Exploit/ByteVerify Nie wyleczalny C:Documents and SettingsWitold MarcinApplication DataSunJavaDeploymentcachejavapiv1.0jararchive.jar–2880d2c3–4dd5f813.zip[VBUG.class]
Virus:Exploit/ByteVerify Nie wyleczalny C:Documents and SettingsWitold MarcinApplication DataSunJavaDeploymentcachejavapiv1.0jararchive.jar–2880d2c3–4dd5f813.zip[Dummy.class]
Virus:Trj/StartPage.JU Nie wyleczalny C:Documents and SettingsWitold MarcinApplication DataSunJavaDeploymentcachejavapiv1.0jararchive.jar–2880d2c3–4dd5f813.zip[Beyond.class]
Virus:W32/Gaobot.gen.worm Nie wyleczalny C:WINDOWSsystem32lssrv.exe
Virus:Trj/Downloader.NL Nie wyleczalny C:WINDOWSsystem32winhot32.dll
no i co mam zrobic ??? :roll: wyniki skanowania online
Virus:Trj/Downloader.NL Nie wyleczalny System operacyjny
Virus:Exploit/ByteVerify Nie wyleczalny C:Documents and SettingsWitold MarcinApplication DataSunJavaDeploymentcachejavapiv1.0fileDummy.class–400b01a8–2a0215ec.class
Virus:Exploit/ByteVerify Nie wyleczalny C:Documents and SettingsWitold MarcinApplication DataSunJavaDeploymentcachejavapiv1.0fileGummy.class–673366f0–7913880f.class
Virus:Exploit/ByteVerify Nie wyleczalny C:Documents and SettingsWitold MarcinApplication DataSunJavaDeploymentcachejavapiv1.0jarar3.jar–4966bd13–7643d2d4.zip[Gummy.class]
Virus:Exploit/ByteVerify Nie wyleczalny C:Documents and SettingsWitold MarcinApplication DataSunJavaDeploymentcachejavapiv1.0jararchive.jar–2880d2c3–4dd5f813.zip[BlackBox.class]
Virus:Exploit/ByteVerify Nie wyleczalny C:Documents and SettingsWitold MarcinApplication DataSunJavaDeploymentcachejavapiv1.0jararchive.jar–2880d2c3–4dd5f813.zip[VBUG.class]
Virus:Exploit/ByteVerify Nie wyleczalny C:Documents and SettingsWitold MarcinApplication DataSunJavaDeploymentcachejavapiv1.0jararchive.jar–2880d2c3–4dd5f813.zip[Dummy.class]
Virus:Trj/StartPage.JU Nie wyleczalny C:Documents and SettingsWitold MarcinApplication DataSunJavaDeploymentcachejavapiv1.0jararchive.jar–2880d2c3–4dd5f813.zip[Beyond.class]
Virus:W32/Gaobot.gen.worm Nie wyleczalny C:WINDOWSsystem32lssrv.exe
Virus:Trj/Downloader.NL Nie wyleczalny C:WINDOWSsystem32winhot32.dll
no i co mam zrobic ??? :roll: wyniki skanowania online
Logfile of HijackThis v1.99.0
Scan saved at 12:34:08, on 2004–12–19
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesTGTSoftStyleXPStyleXPService.exe
C:Program FilesCommon FilesSymantec SharedccProxy.exe
C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
C:Program FilesNorton Internet SecurityISSVC.exe
C:WINDOWSExplorer.EXE
C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe
C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exe
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:Program FilesNorton Internet SecurityNorton AntiVirus avapsvc.exe
C:WINDOWSSystem32 vsvc32.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedCCPD–LCsymlcsvc.exe
C:Program FilesAlcatelSpeedTouch USBDragdiag.exe
C:PROGRA~1WanadooTaskbarIcon.exe
C:PROGRA~1LogitechMOUSEW~1SYSTEMEM_EXEC.EXE
C:Program FilesD–Toolsdaemon.exe
C:Program FilesJavaj2re1.4.2_05injusched.exe
C:WINDOWSSystem32leqhvb.exe
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:WINDOWSsystem32 undll32.exe
C:Program FilesCommon FilesRealUpdate_OB ealsched.exe
C:Program FilesWinampwinampa.exe
C:Program FilesQuickTimeqttask.exe
C:WINDOWSsystem32svhost32.exe
C:Program FilesWindows ControlAdWinCtlAd.exe
C:Program FilesPestPatrolPPControl.exe
C:PROGRA~1PESTPA~1PPMemCheck.exe
C:PROGRA~1PESTPA~1CookiePatrol.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesLogitechDesktop Messenger8876480ProgramLogitechDesktopMessenger.exe
C:WINDOWSsystem32RUNDLL32.EXE
C:Program FilesWindows ControlAdWinCtlAdAlt.exe
C:PROGRA~1COMMON~1 sa sm2.exe
C:WINDOWSsystem32ctfmon.exe
C:WINDOWSsystem32 undll32.exe
C:Program FilesWanadooEspaceWanadoo.exe
C:Program FilesWanadooComComp.exe
C:Program FilesWanadooWatch.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
C:WINDOWSsystem32NOTEPAD.EXE
C:Program FilesWinRARWinRAR.exe
C:DOCUME~1WITOLD~1LOCALS~1TempRar$EX00.640HijackThis.exe
R1 – HKCUSoftwareMicrosoftInternet Explorer,SearchURL = http://www.isearch.com/index.php?app=SE&affjump=1&affiliate=ODQ6NTo5&Terms=
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.isearch.com/index.php?app=SE&affjump=1&affiliate=ODQ6NTo5&Terms=
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.isearch.com/index.php?app=SE&affjump=1&affiliate=ODQ6NTo5&Terms=
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.neostrada.pl
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://www.isearch.com/index.php?app=SE&affjump=1&affiliate=ODQ6NTo5&Terms=
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://www.isearch.com/index.php?app=SE&affjump=1&affiliate=ODQ6NTo5&Terms=
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page_bak = http://www.neostrada.pl
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Neostrada Plus wita Cie w Internecie
R3 – URLSearchHook: (no name) – {1C78AB3F–A857–482e–80C0–3A1E5238A565} – (no file)
O2 – BHO: MultiMPPObj Class – {002EB272–2590–4693–B166–FBD5D9B6FEA6} – C:WINDOWSmultimpp.dll
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll
O2 – BHO: ohb – {086CEFD5–A88D–4981–8915–D51F04360ED1} – C:WINDOWSsystem32winhot32.dll
O2 – BHO: Search Relevancy – {1D7E3B41–23CE–469B–BE1B–A64B877923E1} – C:PROGRA~1SEARCH~1SEARCH~2.DLL
O2 – BHO: URLLink Class – {4A2AACF3–ADF6–11D5–98A9–00E018981B9E} – C:Program FilesNewDotNet ewdotnet6_38.dll
O2 – BHO: (no name) – {53707962–6F74–2D53–2644–206D7942484F} – C:Program FilesSpybot – Search & DestroySDHelper.dll
O2 – BHO: C:WINDOWSlbbho.dll – {5EA9EBB6–D0F0–4B70–B3E9–3BAA9C69B721} – C:WINDOWSlbbho.dll
O2 – BHO: Norton Internet Security – {9ECB9560–04F9–4bbc–943D–298DDF1699E1} – C:Program FilesCommon FilesSymantec SharedAdBlockingNISShExt.dll
O2 – BHO: NAV Helper – {BDF3E430–B101–42AD–A544–FADC6B084872} – C:Program FilesNorton Internet SecurityNorton AntiVirusNavShExt.dll
O2 – BHO: QUICKfind BHO Object – {C08DF07A–3E49–4E25–9AB0–D3882835F153} – C:PROGRA~1TEXTwareQUICKF~1PlugInsIEHelp.dll
O2 – BHO: TGTSoft Explorer Toolbar Changer – {C333CF63–767F–4831–94AC–E683D962C63C} – C:Program FilesTGTSoftStyleXPTGT_BHO.dll
O2 – BHO: Saristar – {C68AE9C0–0909–4DDC–B661–C1AFB9F5AE50} – C:WINDOWSsystem32saristar.dll
O3 – Toolbar: Norton Internet Security – {0B53EAC3–8D69–4b9e–9B19–A37C9A5676A7} – C:Program FilesCommon FilesSymantec SharedAdBlockingNISShExt.dll
O3 – Toolbar: Norton AntiVirus – {42CDD1BF–3FFB–4238–8AD1–7859DF00B1D6} – C:Program FilesNorton Internet SecurityNorton AntiVirusNavShExt.dll
O3 – Toolbar: HotSearchBar.com Bar – {8B224779–3B0E–4FEA–8AE1–B66C20DD840F} – C:WINDOWSsystem32winhot32.dll
O4 – HKLM..Run: [SpeedTouch USB Diagnostics] "C:Program FilesAlcatelSpeedTouch USBDragdiag.exe" /icon
O4 – HKLM..Run: [WOOWATCH] C:PROGRA~1WanadooWatch.exe
O4 – HKLM..Run: [WOOTASKBARICON] C:PROGRA~1WanadooTaskbarIcon.exe
O4 – HKLM..Run: [EM_EXEC] C:PROGRA~1LogitechMOUSEW~1SYSTEMEM_EXEC.EXE
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [DAEMON Tools–1033] "C:Program FilesD–Toolsdaemon.exe" –lang 1033
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_05injusched.exe
O4 – HKLM..Run: [uajbbvl] C:WINDOWSSystem32leqhvb.exe
O4 – HKLM..Run: [conscorr] C:WINDOWSconscorr.exe
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 – HKLM..Run: [Symantec NetDriver Monitor] C:PROGRA~1SYMNET~1SNDMon.exe
O4 – HKLM..Run: [New.net Startup] rundll32 C:PROGRA~1NEWDOT~1NEWDOT~2.DLL,NewDotNetStartup –s
O4 – HKLM..Run: [TkBellExe] "C:Program FilesCommon FilesRealUpdate_OB ealsched.exe" –osboot
O4 – HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe
O4 – HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" –atboottime
O4 – HKLM..Run: [UsbD] C:WINDOWSsystem32svhost32.exe
O4 – HKLM..Run: [Windows ControlAd] C:Program FilesWindows ControlAdWinCtlAd.exe
O4 – HKLM..Run: [version] C:WINDOWSsystem32II22.exe
O4 – HKLM..Run: [pyzih] C:WINDOWSpyzih.exe
O4 – HKLM..Run: [PestPatrol Control Center] C:Program FilesPestPatrolPPControl.exe
O4 – HKLM..Run: [PPMemCheck] C:PROGRA~1PESTPA~1PPMemCheck.exe
O4 – HKLM..Run: [CookiePatrol] C:PROGRA~1PESTPA~1CookiePatrol.exe
O4 – HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 – HKCU..Run: [LDM] C:Program FilesLogitechDesktop Messenger8876480ProgramLogitechDesktopMessenger.exe
O4 – HKCU..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NVMCTRAY.DLL,NvTaskbarInit
O4 – HKCU..Run: [STYLEXP] C:Program FilesTGTSoftStyleXPStyleXP.exe –Hide
O4 – HKCU..Run: [Tsa2] C:PROGRA~1COMMON~1 sa sm2.exe
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – HKCU..Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 – HKCU..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /nosplash /minimized
O4 – HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 – Startup: iMesh.lnk = C:Program FilesiMeshClientiMeshClient.exe
O4 – Startup: PowerReg Scheduler.exe
O4 – Global Startup: Logitech Desktop Messenger.lnk = C:Program FilesLogitechDesktop Messenger8876480ProgramLDMConf.exe
O8 – Extra context menu item: &iSearch The Web – res://C:WINDOWSsystem32 oolbar.dll/SEARCH.HTML
O8 – Extra context menu item: &NeoTrace It! – C:PROGRA~1NEOTRA~1NTXcontext.htm
O8 – Extra context menu item: E&xport to Microsoft Excel – res://C:PROGRA~1OFFICE11EXCEL.EXE/3000
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:WINDOWSSystem32msjava.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:WINDOWSSystem32msjava.dll
O9 – Extra button: Research – {92780B25–18CC–41C8–B9BE–3C9C571A8263} – C:PROGRA~1OFFICE11REFIEBAR.DLL
O9 – Extra button: Researcher – {9455301C–CF6B–11D3–A266–00C04F689C50} – C:Program FilesCommon FilesMicrosoft SharedEncarta ResearcherEROPROJ.DLL
O9 – Extra button: (no name) – {B205A35E–1FC4–4CE3–818B–899DBBB3388C} – C:Program FilesCommon FilesMicrosoft SharedEncarta Search BarENCSBAR.DLL
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O9 – Extra button: NeoTrace It! – {9885224C–1217–4c5f–83C2–00002E6CEF2B} – C:PROGRA~1NEOTRA~1NTXtoolbar.htm (file missing) (HKCU)
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O16 – DPF: {11111111–1111–1111–1111–111111111732} – file://c:progra~1pl.exe
O16 – DPF: {11111111–1111–1111–1111–111111113457} – file://c:explorer.cab
O16 – DPF: {15AD4789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://static.windupdates.com/cab/DownloadsUnlimited/ie/bridge–c11.cab
O16 – DPF: {1C78AB3F–A857–482E–80C0–3A1E5238A565} – http://toolbar.isearch.com/general/drm.cab
O16 – DPF: {6414512B–B978–451D–A0D8–FCFDF33E833C} (WUWebControl Class) – http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1095884666453
O16 – DPF: {644E432F–49D3–41A1–8DD5–E099162EEEC5} (Symantec RuFSI Utility Class) – http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 – DPF: {771A1334–6B08–4A6B–AEDC–CF994BA2CEBE} (Installer Class) – http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab
O16 – DPF: {99802379–7362–40E2–9D28–8A3B9AF880B7} (iiittt Class) – http://hotsearchbar.com/toolbar2/winhot32.cab
O16 – DPF: {9A9307A0–7DA4–4DAF–B042–5009F29E09E1} (ActiveScan Installer Class) – http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 – HKLMSystemCCSServicesTcpip..{A4126E98–258D–4FB1–9222–7CD578950E91}: NameServer = 194.204.152.34 217.98.63.164
O18 – Protocol: bw+0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw+0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw–0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw–0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw00 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw00s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw10 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw10s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw20 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw20s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw30 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw30s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw40 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw40s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw50 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw50s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw60 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw60s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw70 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw70s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw80 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw80s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw90 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw90s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwa0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwa0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwb0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwb0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwc0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwc0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwd0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwd0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwe0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwe0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwf0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwf0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwfile–8876480 – {9462A756–7B47–47BC–8C80–C34B9B80B32B} – C:Program FilesLogitechDesktop Messenger8876480ProgramGAPlugProtocol–8876480.dll
O18 – Protocol: bwg0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwg0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwh0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwh0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwi0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwi0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwj0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwj0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwk0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwk0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwl0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwl0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwm0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwm0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwn0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwn0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwo0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwo0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwp0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwp0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwq0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwq0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwr0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwr0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bws0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bws0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwt0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwt0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwu0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwu0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwv0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwv0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bww0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bww0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwx0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwx0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwy0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwy0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwz0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwz0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: offline–8876480 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: textwareilluminatorbase – {CE5CD329–1650–414A–8DB0–4CBF72FAED87} – C:WINDOWSsystem32 extwareilluminatorbaseProtocol.dll
O23 – Service: Symantec Event Manager – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
O23 – Service: Symantec Network Proxy – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccProxy.exe
O23 – Service: Symantec Password Validation – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccPwdSvc.exe
O23 – Service: Symantec Settings Manager – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
O23 – Service: ISSvc – Symantec Corporation – C:Program FilesNorton Internet SecurityISSVC.exe
O23 – Service: Win32 Wmls Driver – Unknown – C:WINDOWSSystem32winitr32.exe (file missing)
O23 – Service: Norton AntiVirus Auto–Protect Service – Symantec Corporation – C:Program FilesNorton Internet SecurityNorton AntiVirus avapsvc.exe
O23 – Service: NVIDIA Driver Helper Service – NVIDIA Corporation – C:WINDOWSSystem32 vsvc32.exe
O23 – Service: SAVScan – Symantec Corporation – C:Program FilesNorton Internet SecurityNorton AntiVirusSAVScan.exe
O23 – Service: ScriptBlocking Service – Symantec Corporation – C:PROGRA~1COMMON~1SYMANT~1SCRIPT~1SBServ.exe
O23 – Service: Symantec Network Drivers Service – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe
O23 – Service: Symantec SPBBCSvc – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exe
O23 – Service: StyleXPService – Unknown – C:Program FilesTGTSoftStyleXPStyleXPService.exe
O23 – Service: Symantec Core LC – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedCCPD–LCsymlcsvc.exe
O23 – Service: SymWMI Service – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedSecurity CenterSymWSC.exe
O23 – Service: TuneUp WinStyler Theme Service – TuneUp Software GmbH – C:Program FilesTuneUp Utilities 2004WinStylerThemeSvc.exe
[/img]
Scan saved at 12:34:08, on 2004–12–19
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesTGTSoftStyleXPStyleXPService.exe
C:Program FilesCommon FilesSymantec SharedccProxy.exe
C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
C:Program FilesNorton Internet SecurityISSVC.exe
C:WINDOWSExplorer.EXE
C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe
C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exe
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:Program FilesNorton Internet SecurityNorton AntiVirus avapsvc.exe
C:WINDOWSSystem32 vsvc32.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedCCPD–LCsymlcsvc.exe
C:Program FilesAlcatelSpeedTouch USBDragdiag.exe
C:PROGRA~1WanadooTaskbarIcon.exe
C:PROGRA~1LogitechMOUSEW~1SYSTEMEM_EXEC.EXE
C:Program FilesD–Toolsdaemon.exe
C:Program FilesJavaj2re1.4.2_05injusched.exe
C:WINDOWSSystem32leqhvb.exe
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:WINDOWSsystem32 undll32.exe
C:Program FilesCommon FilesRealUpdate_OB ealsched.exe
C:Program FilesWinampwinampa.exe
C:Program FilesQuickTimeqttask.exe
C:WINDOWSsystem32svhost32.exe
C:Program FilesWindows ControlAdWinCtlAd.exe
C:Program FilesPestPatrolPPControl.exe
C:PROGRA~1PESTPA~1PPMemCheck.exe
C:PROGRA~1PESTPA~1CookiePatrol.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesLogitechDesktop Messenger8876480ProgramLogitechDesktopMessenger.exe
C:WINDOWSsystem32RUNDLL32.EXE
C:Program FilesWindows ControlAdWinCtlAdAlt.exe
C:PROGRA~1COMMON~1 sa sm2.exe
C:WINDOWSsystem32ctfmon.exe
C:WINDOWSsystem32 undll32.exe
C:Program FilesWanadooEspaceWanadoo.exe
C:Program FilesWanadooComComp.exe
C:Program FilesWanadooWatch.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
C:WINDOWSsystem32NOTEPAD.EXE
C:Program FilesWinRARWinRAR.exe
C:DOCUME~1WITOLD~1LOCALS~1TempRar$EX00.640HijackThis.exe
R1 – HKCUSoftwareMicrosoftInternet Explorer,SearchURL = http://www.isearch.com/index.php?app=SE&affjump=1&affiliate=ODQ6NTo5&Terms=
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.isearch.com/index.php?app=SE&affjump=1&affiliate=ODQ6NTo5&Terms=
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.isearch.com/index.php?app=SE&affjump=1&affiliate=ODQ6NTo5&Terms=
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.neostrada.pl
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://www.isearch.com/index.php?app=SE&affjump=1&affiliate=ODQ6NTo5&Terms=
R0 – HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://www.isearch.com/index.php?app=SE&affjump=1&affiliate=ODQ6NTo5&Terms=
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page_bak = http://www.neostrada.pl
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Neostrada Plus wita Cie w Internecie
R3 – URLSearchHook: (no name) – {1C78AB3F–A857–482e–80C0–3A1E5238A565} – (no file)
O2 – BHO: MultiMPPObj Class – {002EB272–2590–4693–B166–FBD5D9B6FEA6} – C:WINDOWSmultimpp.dll
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll
O2 – BHO: ohb – {086CEFD5–A88D–4981–8915–D51F04360ED1} – C:WINDOWSsystem32winhot32.dll
O2 – BHO: Search Relevancy – {1D7E3B41–23CE–469B–BE1B–A64B877923E1} – C:PROGRA~1SEARCH~1SEARCH~2.DLL
O2 – BHO: URLLink Class – {4A2AACF3–ADF6–11D5–98A9–00E018981B9E} – C:Program FilesNewDotNet ewdotnet6_38.dll
O2 – BHO: (no name) – {53707962–6F74–2D53–2644–206D7942484F} – C:Program FilesSpybot – Search & DestroySDHelper.dll
O2 – BHO: C:WINDOWSlbbho.dll – {5EA9EBB6–D0F0–4B70–B3E9–3BAA9C69B721} – C:WINDOWSlbbho.dll
O2 – BHO: Norton Internet Security – {9ECB9560–04F9–4bbc–943D–298DDF1699E1} – C:Program FilesCommon FilesSymantec SharedAdBlockingNISShExt.dll
O2 – BHO: NAV Helper – {BDF3E430–B101–42AD–A544–FADC6B084872} – C:Program FilesNorton Internet SecurityNorton AntiVirusNavShExt.dll
O2 – BHO: QUICKfind BHO Object – {C08DF07A–3E49–4E25–9AB0–D3882835F153} – C:PROGRA~1TEXTwareQUICKF~1PlugInsIEHelp.dll
O2 – BHO: TGTSoft Explorer Toolbar Changer – {C333CF63–767F–4831–94AC–E683D962C63C} – C:Program FilesTGTSoftStyleXPTGT_BHO.dll
O2 – BHO: Saristar – {C68AE9C0–0909–4DDC–B661–C1AFB9F5AE50} – C:WINDOWSsystem32saristar.dll
O3 – Toolbar: Norton Internet Security – {0B53EAC3–8D69–4b9e–9B19–A37C9A5676A7} – C:Program FilesCommon FilesSymantec SharedAdBlockingNISShExt.dll
O3 – Toolbar: Norton AntiVirus – {42CDD1BF–3FFB–4238–8AD1–7859DF00B1D6} – C:Program FilesNorton Internet SecurityNorton AntiVirusNavShExt.dll
O3 – Toolbar: HotSearchBar.com Bar – {8B224779–3B0E–4FEA–8AE1–B66C20DD840F} – C:WINDOWSsystem32winhot32.dll
O4 – HKLM..Run: [SpeedTouch USB Diagnostics] "C:Program FilesAlcatelSpeedTouch USBDragdiag.exe" /icon
O4 – HKLM..Run: [WOOWATCH] C:PROGRA~1WanadooWatch.exe
O4 – HKLM..Run: [WOOTASKBARICON] C:PROGRA~1WanadooTaskbarIcon.exe
O4 – HKLM..Run: [EM_EXEC] C:PROGRA~1LogitechMOUSEW~1SYSTEMEM_EXEC.EXE
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [DAEMON Tools–1033] "C:Program FilesD–Toolsdaemon.exe" –lang 1033
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_05injusched.exe
O4 – HKLM..Run: [uajbbvl] C:WINDOWSSystem32leqhvb.exe
O4 – HKLM..Run: [conscorr] C:WINDOWSconscorr.exe
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 – HKLM..Run: [Symantec NetDriver Monitor] C:PROGRA~1SYMNET~1SNDMon.exe
O4 – HKLM..Run: [New.net Startup] rundll32 C:PROGRA~1NEWDOT~1NEWDOT~2.DLL,NewDotNetStartup –s
O4 – HKLM..Run: [TkBellExe] "C:Program FilesCommon FilesRealUpdate_OB ealsched.exe" –osboot
O4 – HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe
O4 – HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" –atboottime
O4 – HKLM..Run: [UsbD] C:WINDOWSsystem32svhost32.exe
O4 – HKLM..Run: [Windows ControlAd] C:Program FilesWindows ControlAdWinCtlAd.exe
O4 – HKLM..Run: [version] C:WINDOWSsystem32II22.exe
O4 – HKLM..Run: [pyzih] C:WINDOWSpyzih.exe
O4 – HKLM..Run: [PestPatrol Control Center] C:Program FilesPestPatrolPPControl.exe
O4 – HKLM..Run: [PPMemCheck] C:PROGRA~1PESTPA~1PPMemCheck.exe
O4 – HKLM..Run: [CookiePatrol] C:PROGRA~1PESTPA~1CookiePatrol.exe
O4 – HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 – HKCU..Run: [LDM] C:Program FilesLogitechDesktop Messenger8876480ProgramLogitechDesktopMessenger.exe
O4 – HKCU..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NVMCTRAY.DLL,NvTaskbarInit
O4 – HKCU..Run: [STYLEXP] C:Program FilesTGTSoftStyleXPStyleXP.exe –Hide
O4 – HKCU..Run: [Tsa2] C:PROGRA~1COMMON~1 sa sm2.exe
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – HKCU..Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 – HKCU..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /nosplash /minimized
O4 – HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 – Startup: iMesh.lnk = C:Program FilesiMeshClientiMeshClient.exe
O4 – Startup: PowerReg Scheduler.exe
O4 – Global Startup: Logitech Desktop Messenger.lnk = C:Program FilesLogitechDesktop Messenger8876480ProgramLDMConf.exe
O8 – Extra context menu item: &iSearch The Web – res://C:WINDOWSsystem32 oolbar.dll/SEARCH.HTML
O8 – Extra context menu item: &NeoTrace It! – C:PROGRA~1NEOTRA~1NTXcontext.htm
O8 – Extra context menu item: E&xport to Microsoft Excel – res://C:PROGRA~1OFFICE11EXCEL.EXE/3000
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:WINDOWSSystem32msjava.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:WINDOWSSystem32msjava.dll
O9 – Extra button: Research – {92780B25–18CC–41C8–B9BE–3C9C571A8263} – C:PROGRA~1OFFICE11REFIEBAR.DLL
O9 – Extra button: Researcher – {9455301C–CF6B–11D3–A266–00C04F689C50} – C:Program FilesCommon FilesMicrosoft SharedEncarta ResearcherEROPROJ.DLL
O9 – Extra button: (no name) – {B205A35E–1FC4–4CE3–818B–899DBBB3388C} – C:Program FilesCommon FilesMicrosoft SharedEncarta Search BarENCSBAR.DLL
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O9 – Extra button: NeoTrace It! – {9885224C–1217–4c5f–83C2–00002E6CEF2B} – C:PROGRA~1NEOTRA~1NTXtoolbar.htm (file missing) (HKCU)
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O10 – Hijacked Internet access by New.Net
O16 – DPF: {11111111–1111–1111–1111–111111111732} – file://c:progra~1pl.exe
O16 – DPF: {11111111–1111–1111–1111–111111113457} – file://c:explorer.cab
O16 – DPF: {15AD4789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://static.windupdates.com/cab/DownloadsUnlimited/ie/bridge–c11.cab
O16 – DPF: {1C78AB3F–A857–482E–80C0–3A1E5238A565} – http://toolbar.isearch.com/general/drm.cab
O16 – DPF: {6414512B–B978–451D–A0D8–FCFDF33E833C} (WUWebControl Class) – http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1095884666453
O16 – DPF: {644E432F–49D3–41A1–8DD5–E099162EEEC5} (Symantec RuFSI Utility Class) – http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 – DPF: {771A1334–6B08–4A6B–AEDC–CF994BA2CEBE} (Installer Class) – http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab
O16 – DPF: {99802379–7362–40E2–9D28–8A3B9AF880B7} (iiittt Class) – http://hotsearchbar.com/toolbar2/winhot32.cab
O16 – DPF: {9A9307A0–7DA4–4DAF–B042–5009F29E09E1} (ActiveScan Installer Class) – http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 – HKLMSystemCCSServicesTcpip..{A4126E98–258D–4FB1–9222–7CD578950E91}: NameServer = 194.204.152.34 217.98.63.164
O18 – Protocol: bw+0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw+0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw–0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw–0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw00 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw00s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw10 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw10s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw20 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw20s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw30 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw30s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw40 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw40s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw50 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw50s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw60 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw60s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw70 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw70s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw80 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw80s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw90 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bw90s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwa0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwa0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwb0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwb0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwc0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwc0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwd0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwd0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwe0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwe0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwf0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwf0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwfile–8876480 – {9462A756–7B47–47BC–8C80–C34B9B80B32B} – C:Program FilesLogitechDesktop Messenger8876480ProgramGAPlugProtocol–8876480.dll
O18 – Protocol: bwg0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwg0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwh0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwh0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwi0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwi0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwj0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwj0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwk0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwk0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwl0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwl0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwm0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwm0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwn0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwn0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwo0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwo0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwp0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwp0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwq0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwq0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwr0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwr0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bws0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bws0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwt0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwt0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwu0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwu0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwv0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwv0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bww0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bww0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwx0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwx0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwy0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwy0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwz0 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: bwz0s – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: offline–8876480 – {44100D48–5F62–49A4–9236–4407C58AC4D6} – C:Program FilesLogitechDesktop Messenger8876480ProgramBWPlugProtocol–8876480.dll
O18 – Protocol: textwareilluminatorbase – {CE5CD329–1650–414A–8DB0–4CBF72FAED87} – C:WINDOWSsystem32 extwareilluminatorbaseProtocol.dll
O23 – Service: Symantec Event Manager – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
O23 – Service: Symantec Network Proxy – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccProxy.exe
O23 – Service: Symantec Password Validation – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccPwdSvc.exe
O23 – Service: Symantec Settings Manager – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
O23 – Service: ISSvc – Symantec Corporation – C:Program FilesNorton Internet SecurityISSVC.exe
O23 – Service: Win32 Wmls Driver – Unknown – C:WINDOWSSystem32winitr32.exe (file missing)
O23 – Service: Norton AntiVirus Auto–Protect Service – Symantec Corporation – C:Program FilesNorton Internet SecurityNorton AntiVirus avapsvc.exe
O23 – Service: NVIDIA Driver Helper Service – NVIDIA Corporation – C:WINDOWSSystem32 vsvc32.exe
O23 – Service: SAVScan – Symantec Corporation – C:Program FilesNorton Internet SecurityNorton AntiVirusSAVScan.exe
O23 – Service: ScriptBlocking Service – Symantec Corporation – C:PROGRA~1COMMON~1SYMANT~1SCRIPT~1SBServ.exe
O23 – Service: Symantec Network Drivers Service – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe
O23 – Service: Symantec SPBBCSvc – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exe
O23 – Service: StyleXPService – Unknown – C:Program FilesTGTSoftStyleXPStyleXPService.exe
O23 – Service: Symantec Core LC – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedCCPD–LCsymlcsvc.exe
O23 – Service: SymWMI Service – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedSecurity CenterSymWSC.exe
O23 – Service: TuneUp WinStyler Theme Service – TuneUp Software GmbH – C:Program FilesTuneUp Utilities 2004WinStylerThemeSvc.exe
[/img]
martinmarshall:Bobi robert co mam zrobic ?? bo jestem lama i trzeba wytlumaczyc mi :roll:
http://www.centrumxp.pl/forum/viewtopic.php?t=19974
Ile jeszcze razy :evil:
Bobi robert co mam zrobic ?? bo jestem lama i trzeba wytlumaczyc mi :roll:
Wyglada na to ze cos z Twojego komputera zrobilo sobie baze do rozsylania spamu czy innego syfu (lewe zalczniki)
Wklej log z HijackThis
Wklej log z HijackThis
Jak narazie znalozlo 7 wirow tylko nie wiem czy je skasuje
http://www.komputerswiat.pl/biznes/skaner/skaner.html
tutaj klikasz dalej i wykonujesz instrukcje, później powinieneś mieć normalne menu skanowania, jak w antywirze, ustawiasz opcje automatycznego leczenia plików, klikasz cały komputer czy jakoś tak, i uruchamiasz skanowanie
tutaj klikasz dalej i wykonujesz instrukcje, później powinieneś mieć normalne menu skanowania, jak w antywirze, ustawiasz opcje automatycznego leczenia plików, klikasz cały komputer czy jakoś tak, i uruchamiasz skanowanie
A JAK TO ZROBIC ???
uźyj scanera on–line... moźe robak wyłącza albo ogranicza niektóre funkcje antywirów...
Przy skanowaniu nie znajduje zadanych wirow :cry:
Strona 1 / 1