Hijack nie POMAGA !!!!

IP: 80.51.228.* 10.12.04, 14:55
witam - mam taki log:
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} -
c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97
Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program
Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1
\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

Niestety jak usuwam pierwsze wpisy z Hosts to one i tak mi zaraz ponownie
pojawiaja sie. W wyniku tego co jakis czas otwiera mi sie IE z jakimis
stronkami.

Prosze o pomoc
Dzieki
    • m.gregor Re: Hijack nie POMAGA !!!! 10.12.04, 22:37
      A gdzie reszta?
      • Gość: aarek Re: Hijack nie POMAGA !!!! IP: 80.51.228.* 10.12.04, 22:45
      • Gość: aarek Re: Hijack nie POMAGA !!!! IP: 80.51.228.* 10.12.04, 22:45
        o to chodzi?:

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\S24EvMon.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\ZCfgSvc.exe
        C:\Program Files\AVPersonal\AVGUARD.EXE
        C:\Program Files\AVPersonal\AVWUPSRV.EXE
        C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
        c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\System32\rundll32.exe
        C:\WINDOWS\System32\hkcmd.exe
        C:\WINDOWS\System32\00THotkey.exe
        C:\WINDOWS\System32\TFNF5.exe
        C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
        C:\WINDOWS\System32\RegSrvc.exe
        C:\Program Files\Apoint2K\Apoint.exe
        C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
        C:\WINDOWS\System32\TPSMain.exe
        C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
        C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
        C:\WINDOWS\System32\TPSBattM.exe
        C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
        C:\Program Files\Apoint2K\Apntex.exe
        c:\progra~1\mcafee.com\vso\mcvsescn.exe
        c:\program files\mcafee.com\agent\mcagent.exe
        C:\Program Files\AVPersonal\AVGNT.EXE
        C:\WINDOWS\System32\ctfmon.exe
        C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
        C:\Program Files\Gadu-Gadu\gg.exe
        C:\Program Files\Messenger\msmsgs.exe
        c:\PROGRA~1\mcafee.com\vso\mcshield.exe
        c:\progra~1\mcafee.com\vso\mcvsftsn.exe
        C:\WINDOWS\System32\1XConfig.exe
        C:\WINDOWS\System32\wuauclt.exe
        C:\Program Files\The Bat!\thebat.exe
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\PROGRA~1\DAP\DAP.EXE
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Documents and Settings\adamos\Pulpit\hi\HijackThis.exe
        • kalinowski11 Re: Hijack nie POMAGA !!!! 10.12.04, 22:51
          Cały , łącznie z nagłówkiem ... od dechy do dechy :)
          • Gość: aarek Re: Hijack nie POMAGA !!!! IP: 80.51.228.* 11.12.04, 00:13
            Logfile of HijackThis v1.97.3
            Scan saved at 14:53:41, on 2004-12-10
            Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\S24EvMon.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\system32\ZCfgSvc.exe
            C:\Program Files\AVPersonal\AVGUARD.EXE
            C:\Program Files\AVPersonal\AVWUPSRV.EXE
            C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
            c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\System32\rundll32.exe
            C:\WINDOWS\System32\hkcmd.exe
            C:\WINDOWS\System32\00THotkey.exe
            C:\WINDOWS\System32\TFNF5.exe
            C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
            C:\WINDOWS\System32\RegSrvc.exe
            C:\Program Files\Apoint2K\Apoint.exe
            C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
            C:\WINDOWS\System32\TPSMain.exe
            C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
            C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
            C:\WINDOWS\System32\TPSBattM.exe
            C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
            C:\Program Files\Apoint2K\Apntex.exe
            c:\progra~1\mcafee.com\vso\mcvsescn.exe
            c:\program files\mcafee.com\agent\mcagent.exe
            C:\Program Files\AVPersonal\AVGNT.EXE
            C:\WINDOWS\System32\ctfmon.exe
            C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
            C:\Program Files\Gadu-Gadu\gg.exe
            C:\Program Files\Messenger\msmsgs.exe
            c:\PROGRA~1\mcafee.com\vso\mcshield.exe
            c:\progra~1\mcafee.com\vso\mcvsftsn.exe
            C:\WINDOWS\System32\1XConfig.exe
            C:\WINDOWS\System32\wuauclt.exe
            C:\Program Files\The Bat!\thebat.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\PROGRA~1\DAP\DAP.EXE
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Documents and Settings\adamos\Pulpit\hi\HijackThis.exe

            O1 - Hosts: 69.20.16.183 search.netscape.com
            O1 - Hosts: 69.20.16.183 search.netscape.com
            O1 - Hosts: 69.20.16.183 search.netscape.com
            O1 - Hosts: 69.20.16.183 auto.search.msn.com
            O1 - Hosts: 69.20.16.183 ieautosearch
            O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} -
            c:\progra~1\mcafee.com\vso\mcvsshl.dll
            O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
            O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
            O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
            O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
            O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97
            Audio Drivers\stacmon.exe
            O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
            O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
            O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
            O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
            O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
            O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program
            Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
            O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1
            \mcafee.com\vso\mcmnhdlr.exe" /checktask
            O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
            O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
            O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
            O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
            O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
            O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
            download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Pełna wersja