Dodaj do ulubionych

BullsEye Network - pomocy

IP: *.neoplus.adsl.tpnet.pl 23.11.04, 19:17
Hej !

Prosze Was o pomoc poniewaz mam pewien problem z czyms co nazywa
sie "BullsEye Network". Usunalem juz wiele wpisow w Hijacku, ale w dalszym
ciagu robak ten mi sie odnawia. Mam nadzieje, ze pomozecie mi w usunieciu go.
Oto moj log z Hijacka.


Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\PROGRA~1\NEOSTR~1\CnxMon.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Programiki\Internet\Gadu-Gadu\gg.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NEOSTR~1\NeostradaTP.exe
C:\PROGRA~1\NEOSTR~1\ComComp.exe
C:\PROGRA~1\NEOSTR~1\Watch.exe
C:\Program Files\Norton AntiVirus\OPScan.exe
C:\Program Files\Programiki\Internet\Maxthon\Maxthon.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\BullsEye Network\bin\bargains.exe
C:\Documents and Settings\Hellrond\Pulpit\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada
TP
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - (no
file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no
file)
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - (no file)
O2 - BHO: brdg Class - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - (no file)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} -
C:\PROGRA~1\PROGRA~1\INTERNET\FLASHGET\jccatch.dll
O2 - BHO: CHungryBHO Object - {BCF96FB4-5F1B-497B-AECC-910304A55011} - (no
file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program
Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} -
C:\WINDOWS\System32\msbe.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} -
C:\PROGRA~1\PROGRA~1\INTERNET\FLASHGET\fgiebar.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Search Bar - {0A8CE102-FA03-4612-9BEE-7FE5452F4CB1} -
C:\WINDOWS\system32\srchbar.dll
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\NEOSTR~1\CnxMon.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program
Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05
\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec
Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [MSConfig]
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - Startup: Skrót do gg.lnk = C:\Program Files\Programiki\Internet\Gadu-
Gadu\gg.exe
O8 - Extra context menu item: Web Rebates - file://C:\Program
Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O8 - Extra context menu item: Ściągnij przy pomocy FlashGet'a - C:\Program
Files\Programiki\Internet\FlashGet\jc_link.htm
O8 - Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a -
C:\Program Files\Programiki\Internet\FlashGet\jc_all.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no
file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
00401C608501} - (no file)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-
00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} -
C:\PROGRA~1\PROGRA~1\INTERNET\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-
0050BA6940E3} - C:\PROGRA~1\PROGRA~1\INTERNET\FLASHGET\flashget.exe
O16 - DPF: {11111111-1111-1111-1111-111111113457} - file://c:\ied_s7m.cab
O16 - DPF: {11111111-1111-1111-1111-511111113457} - file://c:\x.cab
O16 - DPF: {11111111-1111-1111-1111-511111113458} - file://c:\x.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
public.windupdates.com/get_file.php?bt=ie&p=638c04efabf4090ab4c5fc024154ef69cf9247c4e1075281a08feba11106d93954c17e
e672280f19f68d33f6d9199b6b680ebc2a50847f30f0b8bb2a24ea33ea35f4:f992a2588cd0115
0ad693e854e5c9a60
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
skaner.mks.com.pl/SkanerOnline.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AF1B1422-026C-490D-89E7-
13CA08D0E486}: NameServer = 194.204.152.34 217.98.63.164
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} -
C:\WINDOWS\System32\vbsys2 (file missing)


Prosilbym tez o rady comam zrobic po pomyslnym usunieciu robaka, czy zostawil
on jakies trwale slady swojej obecnosci?

Pozdrawiam
Hellrond

Obserwuj wątek
    • Gość: piecyk gazowy Re: BullsEye Network - pomocy IP: *.tpnet.pl / *.tpnet.pl 23.11.04, 22:33
      Gość portalu: Hellrond napisał(a):

      Do wywalenia (wpisy oznaczone gwiazdką są poprawne, ale według mnie, można się
      ich również pozbyć):

      *> R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada
      > TP

      > O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - (no
      > file)

      > O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no
      > file)
      > O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - (no file)
      > O2 - BHO: brdg Class - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - (no file)

      > O2 - BHO: CHungryBHO Object - {BCF96FB4-5F1B-497B-AECC-910304A55011} - (no
      > file)

      > O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} -
      > C:\WINDOWS\System32\msbe.dll

      > O3 - Toolbar: Search Bar - {0A8CE102-FA03-4612-9BEE-7FE5452F4CB1} -
      > C:\WINDOWS\system32\srchbar.dll

      *> O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program
      > Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon

      *> O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05
      > \bin\jusched.exe

      *> O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec
      > Shared\Security Center\UsrPrmpt.exe
      > O4 - HKLM\..\Run: [MSConfig]
      > C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

      > O8 - Extra context menu item: Web Rebates - file://C:\Program
      > Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm

      > O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no
      > file)
      > O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
      > 00401C608501} - (no file)
      > O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
      > C:\WINDOWS\web\related.htm
      > O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-
      > 00aa003c157a} - C:\WINDOWS\web\related.htm

      > O16 - DPF: {11111111-1111-1111-1111-111111113457} - file://c:\ied_s7m.cab
      > O16 - DPF: {11111111-1111-1111-1111-511111113457} - file://c:\x.cab
      > O16 - DPF: {11111111-1111-1111-1111-511111113458} - file://c:\x.cab
      > O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
      > public.windupdates.com/get_file.php?
      bt=ie&p=638c04efabf4090ab4c5fc024154ef69cf9247c4e1075281a08feba11106d93954c17e
      > e672280f19f68d33f6d9199b6b680ebc2a50847f30f0b8bb2a24ea33ea35f4:f992a2588cd0115
      > 0ad693e854e5c9a60

      > O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} -
      > C:\WINDOWS\System32\vbsys2 (file missing)

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka