mam wirusa

IP: *.neoplus.adsl.tpnet.pl 17.04.05, 01:03
ktory caly czas wraca stale po uruchomieniu komputera avast go wywala. Pomoze
ktos co mam dac logi z hijack?
    • Gość: Kolobos Re: mam wirusa IP: *.icm.edu.pl / *.icm.edu.pl 17.04.05, 01:52
      Po co pytasz? Wklej log i juz.
      • Gość: mydelko Re: mam wirusa IP: *.neoplus.adsl.tpnet.pl 17.04.05, 11:49
        No bo ja sie na komputerach znam jak na kosmosie, oto logi

        Logfile of HijackThis v1.99.1
        Scan saved at 11:48:45, on 05-04-17
        Platform: Windows 98 SE (Win9x 4.10.2222A)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\SYSTEM\KERNEL32.DLL
        C:\WINDOWS\SYSTEM\MSGSRV32.EXE
        C:\WINDOWS\SYSTEM\MPREXE.EXE
        C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
        C:\WINDOWS\SYSTEM\MSTASK.EXE
        C:\WINDOWS\SYSTEM\mmtask.tsk
        C:\WINDOWS\EXPLORER.EXE
        C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
        C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
        C:\PROGRAM FILES\MEDIA ACCESS\MEDIAACCK.EXE
        C:\PROGRAM FILES\MEDIA ACCESS\MEDIAACCESS.EXE
        C:\WINDOWS\SYSTEM\RPCSS.EXE
        C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
        C:\WINDOWS\SYSTEM\DDHELP.EXE
        C:\PROGRAM FILES\EMULE.DE\EMULE.EXE
        C:\WINDOWS\PULPIT\HIJACKTHIS.EXE

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
        www.onet.pl
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        www.onet.pl/
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = www.onet.pl
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program
        Files\Spybot - Search & Destroy\SDHelper.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
        C:\WINDOWS\SYSTEM\MSDXM.OCX
        O4 - HKLM\..\Run: [avast! Web Scanner] C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE
        O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\AVAST4\ashmaisv.exe
        O4 - HKLM\..\Run: [Media Access] C:\PROGRAM FILES\MEDIA ACCESS\MediaAccK.exe
        O4 - HKLM\..\Run: [klczyv] C:\WINDOWS\klczyv.exe
        O4 - HKLM\..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4
        \ashServ.exe
        O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
        O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
        C:\WINDOWS\web\related.htm
        O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-
        00aa003c157a} - C:\WINDOWS\web\related.htm
        O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
        O15 - Trusted Zone: *.finefind.nettraffic2cash.biz
        O15 - Trusted IP range: 213.159.117.202

        jeszcze jedno - komputer chodzi raczej wolno, moze jakies niepotrzebne programy
        powywalac?
        • Gość: Kolobos Re: mam wirusa IP: *.warszawa.sdi.tpnet.pl 17.04.05, 11:52
          Wklej caly log bo z tego co wiedze to tylko kawalek, a nie calosc.
          • Gość: mydelko Re: mam wirusa IP: *.neoplus.adsl.tpnet.pl 17.04.05, 12:06
            Logfile of HijackThis v1.99.1
            Scan saved at 12:06:11, on 05-04-17
            Platform: Windows 98 SE (Win9x 4.10.2222A)
            MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

            Running processes:
            C:\WINDOWS\SYSTEM\KERNEL32.DLL
            C:\WINDOWS\SYSTEM\MSGSRV32.EXE
            C:\WINDOWS\SYSTEM\MPREXE.EXE
            C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
            C:\WINDOWS\SYSTEM\MSTASK.EXE
            C:\WINDOWS\SYSTEM\mmtask.tsk
            C:\WINDOWS\EXPLORER.EXE
            C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
            C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
            C:\PROGRAM FILES\MEDIA ACCESS\MEDIAACCK.EXE
            C:\PROGRAM FILES\MEDIA ACCESS\MEDIAACCESS.EXE
            C:\WINDOWS\SYSTEM\RPCSS.EXE
            C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
            C:\WINDOWS\SYSTEM\DDHELP.EXE
            C:\PROGRAM FILES\EMULE.DE\EMULE.EXE
            C:\WINDOWS\SYSTEM\RNAAPP.EXE
            C:\WINDOWS\SYSTEM\TAPISRV.EXE
            C:\WINDOWS\PULPIT\HIJACKTHIS.EXE

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
            www.onet.pl
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
            www.onet.pl/
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = www.onet.pl
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program
            Files\Spybot - Search & Destroy\SDHelper.dll
            O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
            C:\WINDOWS\SYSTEM\MSDXM.OCX
            O4 - HKLM\..\Run: [avast! Web Scanner] C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE
            O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\AVAST4\ashmaisv.exe
            O4 - HKLM\..\Run: [Media Access] C:\PROGRAM FILES\MEDIA ACCESS\MediaAccK.exe
            O4 - HKLM\..\Run: [klczyv] C:\WINDOWS\klczyv.exe
            O4 - HKLM\..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4
            \ashServ.exe
            O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
            O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
            C:\WINDOWS\web\related.htm
            O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-
            00aa003c157a} - C:\WINDOWS\web\related.htm
            O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
            O15 - Trusted Zone: *.finefind.nettraffic2cash.biz
            O15 - Trusted IP range: 213.159.117.202

            to na 100% calosc, moze wiec avast sie z tym uporal?
            • Gość: Kolobos Re: mam wirusa IP: *.warszawa.sdi.tpnet.pl 17.04.05, 12:26
              Uruchom hijackthis wybierz tylko scan i zaznacz te wpisy:

              > O4 - HKLM\..\Run: [Media Access] C:\PROGRAM FILES\MEDIA ACCESS\MediaAccK.exe
              > O4 - HKLM\..\Run: [klczyv] C:\WINDOWS\klczyv.exe
              > O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
              > C:\WINDOWS\web\related.htm
              > O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-
              > 00aa003c157a} - C:\WINDOWS\web\related.htm
              > O15 - Trusted Zone: *.finefind.nettraffic2cash.biz
              > O15 - Trusted IP range: 213.159.117.202

              I Fix Checked, zainstaluj tez:
              www.safer-networking.org/pl/mirrors/index.html <- SpyBot S&D
              www.javacoolsoftware.com/spywareblaster.html <- SpywareBlaster
              W obu wlacz ochrone przegladarki.
              Pomysl tez o firewall'u:
              www.kerio.com/us/kpf_home.html
              Po resecie usun plik:
              C:\WINDOWS\klczyv.exe
              oraz caly katalog:
              C:\PROGRAM FILES\MEDIA ACCESS\

              I wklej nowy log, napisz tez gdzie znajduje tego virusa i co to za virus?
Pełna wersja