Virtual Bouncer i AdDestroyer

Witam!
Otóź głupia siostra przeglądała nie wiadomo jakie strony i po dłuźej walce udało mi się usunąć wiekoszość oprócz dwóch tytułowych.

Skanowałem kompa SpySweeperem, NAV04, Spybotem, Ad–Aware,Skanerem MKS online, CWShredderem.

Czy ktos zna moze jakis program ktory bankowo moje dwa problemy (prosze nie pisać nazw programów ktore znacie tylko same konkrety).

pozdrawiam

Zapodam jeszcze log z HiJacka:)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\WINDOWS\System32\winupdt.exe
C:\WINDOWS\system\eqaiaqaiqa.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\msdtc.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\PestPatrol\PestPatrol Corporate Edition v5\ppmc.exe
D:\HiJack\HijackThis.exe

R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.onet.pl/
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
O2 – BHO: (no name) – {016235BE–59D4–4CEB–ADD5–E2378282A1D9} – C:\Program Files\CxtPls\cxtpls.dll (file missing)
O2 – BHO: (no name) – {017C20C1–F86F–11D8–9B25–000ACD002AE3} – C:\WINDOWS\Helper101.dll (file missing)
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 – BHO: (no name) – {1D7E3B41–23CE–469B–BE1B–A64B877923E1} – C:\PROGRA~1\SEARCH~2\SEARCH~1.DLL (file missing)
O2 – BHO: MSW.cIExplorer – {4B57B77A–B130–4EB8–8CFB–42B880F6D311} – C:\Documents and Settings\All Users\Dane aplikacji\msw\MSW.dll
O2 – BHO: NAV Helper – {BDF3E430–B101–42AD–A544–FADC6B084872} – C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O2 – BHO: (no name) – {DA36F0D7–5007–40E3–ABA6–3239C3EC233D} – C:\Program Files\3b8w8hpa\3b8w8hpa.dll (file missing)
O3 – Toolbar: Norton AntiVirus – {42CDD1BF–3FFB–4238–8AD1–7859DF00B1D6} – C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O4 – HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 – HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 – HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 – HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 – HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 – HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exe
O4 – HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 – HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:\WINDOWS\System32\msjava.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:\WINDOWS\System32\msjava.dll
O15 – Trusted Zone: *.frame.crazywinnings.com
O15 – Trusted Zone: *.static.topconverting.com
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab

Odpowiedzi: 1

Smash:
prosze nie pisać nazw programów ktore znacie tylko same konkrety
Rece nie wystarcza zamiast programow ?

Usuwaj:


C:\WINDOWS\System32\winupdt.exe
C:\WINDOWS\system\eqaiaqaiqa.exe
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
O2 – BHO: (no name) – {016235BE–59D4–4CEB–ADD5–E2378282A1D9} – C:\Program Files\CxtPls\cxtpls.dll (file missing)
O2 – BHO: (no name) – {017C20C1–F86F–11D8–9B25–000ACD002AE3} – C:\WINDOWS\Helper101.dll (file missing)
O2 – BHO: (no name) – {1D7E3B41–23CE–469B–BE1B–A64B877923E1} – C:\PROGRA~1\SEARCH~2\SEARCH~1.DLL (file missing)
O2 – BHO: MSW.cIExplorer – {4B57B77A–B130–4EB8–8CFB–42B880F6D311} – C:\Documents and Settings\All Users\Dane aplikacji\msw\MSW.dll
O2 – BHO: (no name) – {DA36F0D7–5007–40E3–ABA6–3239C3EC233D} – C:\Program Files\3b8w8hpa\3b8w8hpa.dll (file missing)
O4 – HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exe
O15 – Trusted Zone: *.frame.crazywinnings.com
O15 – Trusted Zone: *.static.topconverting.com
EL NINO
Dodano
27.02.2005 20:21:48
Smash
Dodano:
27.02.2005 13:56:02
Komentarzy:
1
Strona 1 / 1