Dodaj do ulubionych

prosze o sprawdzenie loga

13.02.05, 00:48
StartupList report, 2005-02-12, 23:52:52
StartupList version: 1.52.2
Started from : C:\Documents and Settings\Luqas\Pulpit\HijackThis.EXE
Detected: Windows XP Dodatek SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
e:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\PROGRA~1\PANASO~1\REMOTE~1\kmentsrv.exe
E:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
E:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WISPTIS.EXE
E:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
E:\Program Files\Microsoft AntiSpyware\gcasServ.exe
E:\Mozila FireFox\firefox.exe
C:\Documents and Settings\Luqas\Pulpit\stinger.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Luqas\Pulpit\HijackThis.exe

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
Symantec NetDriver Monitor = C:\PROGRA~1\SYMNET~1\SNDMon.exe
BluetoothAuthenticationAgent = rundll32.exe
bthprops.cpl,,BluetoothAuthenticationAgent
gcasServ = "E:\Program Files\Microsoft AntiSpyware\gcasServ.exe"

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Browser Helper Objects:

(no name) - E:\Program Files\Adobe\Acrobat 6.0
CE\Reader\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - E:\Program Files\Norton AntiVirus\NavShExt.dll -
{BDF3E430-B101-42AD-A544-FADC6B084872}

--------------------------------------------------

Enumerating Task Scheduler jobs:

Norton AntiVirus - Skanuj komputer - Luqas.job
Symantec NetDetect.job

--------------------------------------------------

Enumerating Download Program Files:

[{33564D57-0000-0010-8000-00AA00389B71}]
CODEBASE =
download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
[MainControl Class]
InProcServer32 = C:\WINDOWS\system32\SkanerOnline.dll
CODEBASE = skaner.mks.com.pl/SkanerOnline.cab

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #5: C:\WINDOWS\system32\wshbth.dll

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll

--------------------------------------------------
End of report, 4 753 bytes
Report generated in 0,050 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Obserwuj wątek
    • m.gregor Re: prosze o sprawdzenie loga 13.02.05, 00:53
      Wklej normalnego z HiJackThis.
      • ggreg Re: prosze o sprawdzenie loga czy ten jest dobry? 13.02.05, 01:07
        Logfile of HijackThis v1.99.0
        Scan saved at 23:21:09, on 2005-02-12
        Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        e:\Program Files\Ahead\InCD\InCDsrv.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Common Files\Symantec Shared\ccApp.exe
        C:\WINDOWS\system32\rundll32.exe
        C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
        C:\PROGRA~1\PANASO~1\REMOTE~1\kmentsrv.exe
        E:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
        C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
        C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
        C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
        C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
        E:\Program Files\Norton AntiVirus\navapsvc.exe
        C:\WINDOWS\system32\devldr32.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\mmc.exe
        C:\WINDOWS\system32\DfrgNtfs.exe
        C:\WINDOWS\system32\DfrgNtfs.exe
        C:\WINDOWS\system32\DfrgNtfs.exe
        C:\WINDOWS\System32\WISPTIS.EXE
        E:\Mozila FireFox\firefox.exe
        E:\PROGRA~1\NORTON~1\navw32.exe
        e:\Program Files\PowerArchiver\POWERARC.EXE
        C:\DOCUME~1\Luqas\USTAWI~1\Temp\_PA85\HijackThis.exe
        C:\Program Files\Messenger\msmsgs.exe

        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
        E:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
        O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Program
        Files\Norton AntiVirus\NavShExt.dll
        O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
        E:\Program Files\Norton AntiVirus\NavShExt.dll
        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
        O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
        O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe
        bthprops.cpl,,BluetoothAuthenticationAgent
        O8 - Extra context menu item: &Add animation to IncrediMail Style Box -
        D:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
        O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
        skaner.mks.com.pl/SkanerOnline.cab
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. -
        C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program
        Files\Common Files\Symantec Shared\ccEvtMgr.exe
        O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program
        Files\Common Files\Symantec Shared\ccPwdSvc.exe
        O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program
        Files\Common Files\Symantec Shared\ccSetMgr.exe
        O23 - Service: InCD Helper - Ahead Software AG - e:\Program
        Files\Ahead\InCD\InCDsrv.exe
        O23 - Service: KME Remote Server - Unknown -
        C:\PROGRA~1\PANASO~1\REMOTE~1\kmentsrv.exe
        O23 - Service: Norton AntiVirus Auto-Protect Service - Symantec Corporation -
        E:\Program Files\Norton AntiVirus\navapsvc.exe
        O23 - Service: Norton AntiVirus Firewall Monitor Service - Symantec Corporation
        - E:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
        O23 - Service: SAVScan - Symantec Corporation - E:\Program Files\Norton
        AntiVirus\SAVScan.exe
        O23 - Service: ScriptBlocking Service - Symantec Corporation -
        C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
        O23 - Service: Symantec Network Drivers Service - Symantec Corporation -
        C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
        O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program
        Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
        O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common
        Files\Symantec Shared\CCPD-LC\symlcsvc.exe

        • m.gregor Jak dla mnie czysto n/t 13.02.05, 11:26

          • ggreg Re: Jak dla mnie czysto n/t 13.02.05, 11:48
            Dzieki bardzo pozdrawiam

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka