Dodaj do ulubionych

bardzo proszę o pomoc

14.10.04, 16:26
Ostatnio bardzo spowolnił mi sie komputer:( Kursor dziwnie przesuwa strony, a
także foldery przesuwane są na ekranie jakby w spowolnionym tempie.Dodatkowo
internet się wolniej ładuje. Już nie wiem co robić... Zastanawiam się czy ma
to związek z jakimś wirusem. Dodam,że jestem kompletnym laikiem jeżeli chodzi
o komputery.


Logfile of HijackThis v1.97.7
Scan saved at 16:24:45, on 2004-10-14
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\windowsupdate.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
D:\programy\winamp5.0\Winamp\winampa.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\program files\altnet\points manager\points manager.exe
C:\Documents and Settings\Marzena\Moje dokumenty\Gadu-Gadu\gg.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\PROGRA~1\Altnet\DOWNLO~1\asm.exe
C:\PROGRA~1\Altnet\DOWNLO~1\adm4005.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\programy\icq\ICQLite\ICQLite.exe
D:\programy\winamp5.0\Winamp\Winamp.exe
D:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
searchmiracle.com/sp.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
www.onet.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: (no name) - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no
file)
O2 - BHO: (no name) - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} -
C:\WINDOWS\EliteToolBar\EliteToolBar version 53.dll (file missing)
O4 - HKLM\..\Run: [Windows Messenger] msmsgs.exe
O4 - HKLM\..\Run: [Windows Sound Manager] SndMon32.exe
O4 - HKLM\..\Run: [Microsoft Inet Xp..] teekids.exe
O4 - HKLM\..\Run:
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run]
windowsupdate.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05
\bin\jusched.exe
O4 - HKLM\..\Run: [ICQ Lite] D:\programy\icq\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [Windows Automation] mslaugh.exe
O4 - HKLM\..\Run: [WinampAgent] D:\programy\winamp5.0\Winamp\winampa.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P
Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [SearchUpgrader] C:\Program Files\Common
files\SearchUpgrader\SearchUpgrader.exe
O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points
manager\points manager.exe -s
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Trickler] "c:\documents and settings\marzena\ustawienia
lokalne\temp\fsg_4104.exe"
O4 - HKLM\..\RunServices: [Windows Messenger] msmsgs.exe
O4 - HKLM\..\RunServices: [Windows Sound Manager] SndMon32.exe
O4 - HKLM\..\RunServices:
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run]
windowsupdate.exe
O4 - HKCU\..\Run: [Windows Messenger] msmsgs.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Windows Sound Manager] SndMon32.exe
O4 - HKCU\..\Run:
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run]
windowsupdate.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Documents and Settings\Marzena\Moje
dokumenty\Gadu-Gadu\gg.exe" /tray
O4 - HKLM\..\RunOnce:
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run]
windowsupdate.exe
O4 - HKCU\..\RunOnce:
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run]
windowsupdate.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] D:\programy\icq\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: hp officejet 4100 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office\OSA9.EXE
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone
Labs\ZoneAlarm\zonealarm.exe
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: ICQ 4 (HKLM)
O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1097347601906
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility
Class) - security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
skaner.mks.com.pl/SkanerOnline.cab
Obserwuj wątek
    • kalinowski11 Re: bardzo proszę o pomoc 14.10.04, 16:46
      Witam .

      Dobrze by było zajrzeć poniżej :)

      www.windowsupdate.com/
      Do usunięcia :

      > R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
      > searchmiracle.com/sp.php
      > R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
      > searchmiracle.com/sp.php
      > R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
      > searchmiracle.com/sp.php
      > R3 - URLSearchHook: (no name) - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no
      > file)
      > O2 - BHO: (no name) - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} -
      > C:\WINDOWS\EliteToolBar\EliteToolBar version 53.dll (file missing)
      > O4 - HKLM\..\Run: [Windows Sound Manager] SndMon32.exe
      > O4 - HKLM\..\Run: [Microsoft Inet Xp..] teekids.exe
      > O4 - HKLM\..\Run: [Windows Automation] mslaugh.exe
      > O4 - HKLM\..\Run: [SearchUpgrader] C:\Program Files\Common
      > files\SearchUpgrader\SearchUpgrader.exe
      > O4 - HKLM\..\Run: [Trickler] "c:\documents and settings\marzena\ustawienia
      > lokalne\temp\fsg_4104.exe"
      > O4 - HKLM\..\RunServices: [Windows Sound Manager] SndMon32.exe

      A tego nie jestem pewien :

      > O4 - HKLM\..\Run:
      > [HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run]
      > windowsupdate.exe
      > O4 - HKLM\..\RunOnce:
      > [HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run]
      > windowsupdate.exe
      > O4 - HKCU\..\RunOnce:
      > [HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run]
      > windowsupdate.exe
      > O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -

      Ktoś z większym doświadczeniem pewnie wypatrzy coś jeszcze .
    • netsec Re: bardzo proszę o pomoc 14.10.04, 17:01
      Wklej ponownie log wykonany najnowszą wersją HiJackThis
      downloads.subratam.org/hijackthis.zip
      • marzena86 Re: bardzo proszę o pomoc 14.10.04, 17:05
        Logfile of HijackThis v1.98.2
        Scan saved at 17:05:25, on 2004-10-14
        Platform: Windows XP (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 (6.00.2600.0000)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\ZoneLabs\vsmon.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\System32\windowsupdate.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
        D:\programy\winamp5.0\Winamp\winampa.exe
        C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
        C:\program files\altnet\points manager\points manager.exe
        C:\Documents and Settings\Marzena\Moje dokumenty\Gadu-Gadu\gg.exe
        C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
        C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
        C:\PROGRA~1\Altnet\DOWNLO~1\asm.exe
        C:\PROGRA~1\Altnet\DOWNLO~1\adm4005.exe
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\WINDOWS\System32\wuauclt.exe
        C:\WINDOWS\System32\wuauclt.exe
        D:\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
        searchmiracle.com/sp.php
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
        searchmiracle.com/sp.php
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
        searchmiracle.com/sp.php
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        www.onet.pl/
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
        R3 - URLSearchHook: (no name) - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no
        file)
        O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} -
        C:\WINDOWS\EliteToolBar\EliteToolBar version 53.dll (file missing)
        O4 - HKLM\..\Run: [Windows Messenger] msmsgs.exe
        O4 - HKLM\..\Run: [Windows Sound Manager] SndMon32.exe
        O4 - HKLM\..\Run: [Microsoft Inet Xp..] teekids.exe
        O4 - HKLM\..\Run:
        [HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run]
        windowsupdate.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05
        \bin\jusched.exe
        O4 - HKLM\..\Run: [ICQ Lite] D:\programy\icq\ICQLite\ICQLite.exe -minimize
        O4 - HKLM\..\Run: [Windows Automation] mslaugh.exe
        O4 - HKLM\..\Run: [WinampAgent] D:\programy\winamp5.0\Winamp\winampa.exe
        O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P
        Networking.exe /AUTOSTART
        O4 - HKLM\..\Run: [SearchUpgrader] C:\Program Files\Common
        files\SearchUpgrader\SearchUpgrader.exe
        O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points
        manager\points manager.exe -s
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [Trickler] "c:\documents and settings\marzena\ustawienia
        lokalne\temp\fsg_4104.exe"
        O4 - HKLM\..\RunServices: [Windows Messenger] msmsgs.exe
        O4 - HKLM\..\RunServices: [Windows Sound Manager] SndMon32.exe
        O4 - HKLM\..\RunServices:
        [HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run]
        windowsupdate.exe
        O4 - HKLM\..\RunOnce:
        [HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run]
        windowsupdate.exe
        O4 - HKCU\..\Run: [Windows Messenger] msmsgs.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKCU\..\Run: [Windows Sound Manager] SndMon32.exe
        O4 - HKCU\..\Run:
        [HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run]
        windowsupdate.exe
        O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Documents and Settings\Marzena\Moje
        dokumenty\Gadu-Gadu\gg.exe" /tray
        O4 - HKCU\..\RunOnce:
        [HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run]
        windowsupdate.exe
        O4 - HKCU\..\RunOnce: [ICQ Lite] D:\programy\icq\ICQLite\ICQLite.exe -trayboot
        O4 - Global Startup: hp officejet 4100 series.lnk = ?
        O4 - Global Startup: hpoddt01.exe.lnk = ?
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
        Office\Office\OSA9.EXE
        O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone
        Labs\ZoneAlarm\zonealarm.exe
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no
        file)
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
        00401C608501} - (no file)
        O9 - Extra button: ICQ 4 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} -
        D:\programy\icq\ICQLite\ICQLite.exe
        O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} -
        D:\programy\icq\ICQLite\ICQLite.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
        C:\Program Files\Messenger\MSMSGS.EXE
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-
        00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
        O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
        v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1097347601906
        O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility
        Class) - security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
        O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
        skaner.mks.com.pl/SkanerOnline.cab

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka