POMÓŻECIE !!!! Chybamam wirusa :(:(

IP: *.neoplus.adsl.tpnet.pl 05.02.05, 22:57
Słuchajcie nie mogę otwierać niektórych Witryn ( zwłaszcza tych głownych np.
wp,onet,pf itp.) ponieważ pojawia mi się napisa Access Blocked - Virus
Warning. No to ja sprytnie skanuje komputer antywirusem ( norton antivirus) i
co i nic :/ :/ :/
Proszę was pomóżcie - strasznie mnie to irytuje ...:)
Albo chociaż zapodajcie link z którego można sciagnąć jakiegoś porządego
antyvirusa.

Z góry WIELKIE dzieki
pozdrawiam
Axel
    • Gość: piecyk gazowy Re: POMÓŻECIE !!!! Chybamam wirusa :(:( IP: *.tpnet.pl / *.tpnet.pl 05.02.05, 23:01
      forum.gazeta.pl/forum/72,2.html?f=430&w=20286061&a=20286267
      • Gość: Blondyn Dzieki Bardzo PIecyk Gazowy !! IP: *.neoplus.adsl.tpnet.pl 06.02.05, 01:56
        Tak to wygląda :

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.ex e
        C:\WINDOWS\system32\services.ex e
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
        C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
        C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\Grisoft\AVG7\avgams vr.exe
        C:\PROGRA~1\Grisoft\AVG7\avgups vc.exe
        C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
        C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
        C:\WINDOWS\System32\nvsvc32.exe
        C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Winamp\winampa.exe
        C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
        C:\Program Files\Microsoft Works\WksSb.exe
        C:\Program Files\Hewlett-Packard\Toolbox2. 0\Apache Tomcat 4.0
        \webapps\Toolbox\StatusClient\S tatusClient.exe
        C:\Program Files\Common Files\Symantec Shared\ccApp.exe
        C:\Program Files\MSN Apps\Updater\01.02.3000.1001\pl -pl\msnappau.exe
        C:\WINDOWS\System32\qttask.exe
        C:\Program Files\CyberLink\PowerDVD\PDVDSe rv.exe
        C:\Program Files\Windows AdStatus\WinStat.exe
        C:\temp\salm.exe
        C:\Program Files\Web_Rebates\WebRebates0.e xe
        C:\PROGRA~1\Grisoft\AVG7\avgcc. exe
        C:\Program Files\Windows AdStatus\WinStatKeep.exe
        C:\PROGRA~1\Grisoft\AVG7\avgemc .exe
        C:\Program Files\Neostrada TP\NeostradaTP.exe
        C:\WINDOWS\System32\ctfmon.exe
        C:\Program Files\Gadu-Gadu\gg.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\Program Files\Sony Corporation\Picture Package\Picture Package
        Menu\SonyTray.exe
        C:\Program Files\Sony Corporation\Picture Package\Picture Package
        Applications\Residence.exe
        C:\Program Files\WinZip\WZQKPICK.EXE
        C:\Program Files\Hewlett-Packard\Toolbox2. 0\Javasoft\JRE\1.3.1\bin\javaw. exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\Program Files\Neostrada TP\ComComp.exe
        C:\Program Files\Neostrada TP\Watch.exe
        C:\Program Files\Web_Rebates\WebRebates1.e xe
        C:\WINDOWS\System32\wuauclt.exe
        C:\Program Files\eMule\emule.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Documents and Settings\NTT\Moje dokumenty\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Interne t Explorer\Main,Search Bar =
        szukaj.wp.pl
        R0 - HKCU\Software\Microsoft\Interne t Explorer\Main,Start Page =
        www.onet.pl
        R0 - HKLM\Software\Microsoft\Interne t Explorer\Main,Start Page =
        default.home
        R1 - HKCU\Software\Microsoft\Interne t Explorer\Main,Window Title = Neostrada TP
        R0 - HKCU\Software\Microsoft\Interne t Explorer\Toolbar,LinksFolderNam e = Łącza
        R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89 362C85} -
        C:\PROGRA~1\NEOSTR~1\SEARCH~1.D LL
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D 6BE0B3} -
        C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper .ocx
        O2 - BHO: (no name) - {1D7E3B41-23CE-469B-BE1B-A64B87 7923E1} - C:\PROGRA~1
        \SEARCH~1\SEARCH~3.DLL
        O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF3 6AF6E4} - C:\Program Files\MSN
        Apps\ST\01.02.3000.1002\en-xu\s tmain.dll
        O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF 1699E1} - C:\Program
        Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
        O2 - BHO: VDOMP Class - {A0ED918D-B8E6-4c3d-BD15-1DB1AE 9A5DD3} -
        C:\WINDOWS\wtlbass32.dll (file missing)
        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4 FF55D0} - C:\Program
        Files\MSN Apps\MSN Toolbar\01.02.3000.1001\pl-pl\m sntb.dll
        O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B 084872} - C:\Program
        Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9 082467} -
        C:\WINDOWS\System32\msdxm.ocx
        O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A 5676A7} -
        C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
        O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF 00B1D6} -
        C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4 FF55D0} - C:\Program
        Files\MSN Apps\MSN Toolbar\01.02.3000.1001\pl-pl\m sntb.dll
        O3 - Toolbar: SToolbar - {0E1230F8-EA50-42A9-983C-D22ABC 2EED3B} -
        C:\WINDOWS\stoolbd.dll
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32
        \NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32
        \NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program
        Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
        O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
        O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft
        Works\WksSb.exe /AllUsers
        O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft
        Works\WkDetect.exe
        O4 - HKLM\..\Run: [StatusClient] C:\Program Files\Hewlett-Packard\Toolbox2. 0
        \Apache Tomcat 4.0\webapps\Toolbox\StatusClien t\StatusClient.exe /auto
        O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2. 0
        \hpbpsttp.exe
        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
        Shared\ccApp.exe"
        O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet
        Security\UrlLstCk.exe
        O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.e xe
        O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001
        \pl-pl\msnappau.exe"
        O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
        O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe
        O4 - HKLM\..\Run: [RemoteControl] "C:\Program
        Files\CyberLink\PowerDVD\PDVDSe rv.exe"
        O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec
        Shared\Security Center\UsrPrmpt.exe
        O4 - HKLM\..\Run: [Windows AdStatus] C:\Program Files\Windows
        AdStatus\WinStat.exe
        O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
        O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.e xe"
        O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc. exe /STARTUP
        O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc .exe
        O4 - HKLM\..\Run: [dypofej] C:\WINDOWS\dypofej.exe
        O4 - HKLM\..\Run: [WOOKIT] C:\Program Files\Neostrada TP\NeostradaTP.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
        O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN
        Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [CTFMONSS] C:\WINDOWS\System32\CTFMONSS.EX E
        O4 - HKCU\..\Run: [CSRSSW] C:\WINDOWS\System32\CSRSSW.EXE
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
        Office\Office\OSA9.EXE
        O4 - Global Startup: Picture Package Menu.lnk = ?
        O4 - Global Startup: Picture Package VCD Maker.lnk = ?
        O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program
        Files\WinZip\WZQKPICK.EXE
        O8 - Extra context menu item: Web Rebates - file://C:\Program
        Files\Web_Rebates\Sy1150\Tp1150 \scri1150a.htm
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C 608501} -
        C:\WINDOWS\System32\msjava.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
        00401C608501} - C:\WINDOWS\System32\msjava.dll
        O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa00 3c157a} -
        C:\WINDOWS\web\related.htm
        O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-
        00aa003c157a} - C:\WINDOWS\web\related.htm
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F 795683} -
        C:\Program F
        • Gość: xyxźż Re: Dzieki Bardzo PIecyk Gazowy !! IP: *.neoplus.adsl.tpnet.pl 06.02.05, 02:34
          to nie jest cały log-nie zmieścił Ci się
        • Gość: piecyk gazowy Re: Dzieki Bardzo PIecyk Gazowy !! IP: *.tpnet.pl / *.tpnet.pl 06.02.05, 10:52
          Zaznacz poniższe pozycje i wciśnij Fix Checked:

          O2 - BHO: (no name) - {1D7E3B41-23CE-469B-BE1B-A64B87 7923E1} - C:\PROGRA~1
          \SEARCH~1\SEARCH~3.DLL
          O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF3 6AF6E4} - C:\Program Files\MSN
          Apps\ST\01.02.3000.1002\en-xu\s tmain.dll

          O2 - BHO: VDOMP Class - {A0ED918D-B8E6-4c3d-BD15-1DB1AE 9A5DD3} -
          C:\WINDOWS\wtlbass32.dll (file missing)
          O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4 FF55D0} - C:\Program
          Files\MSN Apps\MSN Toolbar\01.02.3000.1001\pl-pl\m sntb.dll

          O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4 FF55D0} - C:\Program
          Files\MSN Apps\MSN Toolbar\01.02.3000.1001\pl-pl\m sntb.dll
          O3 - Toolbar: SToolbar - {0E1230F8-EA50-42A9-983C-D22ABC 2EED3B} -
          C:\WINDOWS\stoolbd.dll

          O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001
          \pl-pl\msnappau.exe"

          O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe

          O4 - HKLM\..\Run: [Windows AdStatus] C:\Program Files\Windows
          AdStatus\WinStat.exe
          O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
          O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.e xe"

          O4 - HKLM\..\Run: [dypofej] C:\WINDOWS\dypofej.exe

          O4 - HKCU\..\Run: [CTFMONSS] C:\WINDOWS\System32\CTFMONSS.EX E
          O4 - HKCU\..\Run: [CSRSSW] C:\WINDOWS\System32\CSRSSW.EXE

          O8 - Extra context menu item: Web Rebates - file://C:\Program
          Files\Web_Rebates\Sy1150\Tp1150 \scri1150a.htm

          O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa00 3c157a} -
          C:\WINDOWS\web\related.htm
          O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-
          00aa003c157a} - C:\WINDOWS\web\related.htm

          Odinstaluj jeden program antywirusowy i wklej nowego loga.
Pełna wersja