Dodaj do ulubionych

hijack - log :-)

IP: *.neoplus.adsl.tpnet.pl 20.04.05, 18:43
Logfile of HijackThis v1.99.1
Scan saved at 17:23:39, on 2005-04-20
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\System32\P2P Networking\P2P Networking.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\winampa.exe
C:\WINNT\SOUNDMAN.EXE
C:\WINNT\System32\ctfmon.exe
C:\Program Files\iolo\System Mechanic 4 Professional\Search and Recover\DiskImageService.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Gadu-Gadu\Gadu-Gadu\gg.exe
C:\WINNT\System32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINNT\System32\wuauclt.exe
C:\Documents and Settings\AFFA\Pulpit\HijackThis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = www.hotbar.com/dyn/hotbar/3.0/sb_searchPageHome.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = www.onet.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
F3 - REG:win.ini: load=C:\YDPDict\watch.exe
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0 CE\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Hotbar - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - C:\Program Files\Hotbar\bin\4.5.1.0\HbHostIE.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Hotbar - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - C:\Program Files\Hotbar\bin\4.5.1.0\HbHostIE.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [P2P Networking] C:\WINNT\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points manager\points manager.exe -s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [WeatherOnTray] C:\Program Files\Hotbar\bin\4.5.1.0\WeatherOnTray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Hotbar] C:\Program Files\Hotbar\bin\4.5.1.0\HbInst.exe /Upgrade
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINNT\System32\ctfmon.exe
O4 - HKCU\..\Run: [Komunikator] C:\Program Files\Tlen.pl\tlen.exe
O4 - HKCU\..\Run: [Search and Recover Disk Image Service] "C:\Program Files\iolo\System Mechanic 4 Professional\Search and Recover\DiskImageService.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\Program Files\iolo\System Mechanic 4 Professional\PopupStopper.exe"
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\Gadu-Gadu\gg.exe" /tray
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - www.live365.com/players/play365.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - www2.incredimail.com/contents/setup/downloader/imloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CED35B02-504A-44EF-8A20-C31F38D73884}: NameServer = 194.204.159.1,194.204.152.34
O18 - Filter: text/html - {64C0FB1B-0E62-4631-B4E5-2B00343E1EC0} - C:\Documents and Settings\AFFA\Ustawienia lokalne\Dane aplikacji\microsoft\internet explorer\V0.26.dat
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: MkS_Vir Monitor (MksVirMonSvc) - Unknown owner - C:\Program Files\MKS\Bin\mksmonsv.exe (file missing)
O23 - Service: Usługa Auto Protect programu Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\Syste
Obserwuj wątek
    • Gość: Kolobos Re: hijack - log :-) IP: *.warszawa.sdi.tpnet.pl 20.04.05, 20:38
      Odinstaluj:
      P2P Networking
      Hotbar

      W hijackthis zaznacz te wpisy:

      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      www.hotbar.com/dyn/hotbar/3.0/sb_searchPageHome.htm
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program
      Files\MyWay\myBar\1.bin\MYBAR.DLL (file missing)
      O2 - BHO: Hotbar - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - C:\Program
      Files\Hotbar\bin\4.5.1.0\HbHostIE.dll (file missing)
      O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program
      Files\MyWay\myBar\1.bin\MYBAR.DLL (file missing)
      O3 - Toolbar: &Hotbar - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - C:\Program
      Files\Hotbar\bin\4.5.1.0\HbHostIE.dll (file missing)
      O4 - HKLM\..\Run: [P2P Networking] C:\WINNT\System32\P2P Networking\P2P
      Networking.exe /AUTOSTART
      O4 - HKLM\..\Run: [WeatherOnTray] C:\Program Files\Hotbar\bin\4.5.1.0
      \WeatherOnTray.exe
      O4 - HKLM\..\Run: [Hotbar] C:\Program Files\Hotbar\bin\4.5.1.0
      \HbInst.exe /Upgrade
      O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q
      O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
      O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) -
      launch.gamespyarcade.com/software/launch/alaunch.cab
      O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) -
      www.live365.com/players/play365.cab
      O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) -
      www2.incredimail.com/contents/setup/downloader/imloader.cab
      O18 - Filter: text/html - {64C0FB1B-0E62-4631-B4E5-2B00343E1EC0} - C:\Documents
      and Settings\AFFA\Ustawienia lokalne\Dane
      aplikacji\microsoft\internet explorer\V0.26.dat

      Fix Checked, a po resecie wklej nowy log i nie instaluj juz nigdy paskow
      pokazujacych pogode, super zegarow itp nic dobrego Ci z tego nie wyjdzie
      najlepiej na nic nie klikaj co wyskakuje na roznych dziwnych stronach.
      • Gość: marta Re: hijack - log :-) IP: *.neoplus.adsl.tpnet.pl 23.04.05, 09:55
        Logfile of HijackThis v1.99.1
        Scan saved at 09:47:46, on 2005-04-23
        Platform: Windows XP (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 (6.00.2600.0000)

        Running processes:
        C:\WINNT\System32\smss.exe
        C:\WINNT\system32\winlogon.exe
        C:\WINNT\system32\services.exe
        C:\WINNT\system32\lsass.exe
        C:\WINNT\system32\svchost.exe
        C:\WINNT\System32\svchost.exe
        C:\WINNT\Explorer.EXE
        C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
        C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
        C:\WINNT\system32\spoolsv.exe
        C:\WINNT\system32\ntvdm.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\Common Files\Symantec Shared\ccApp.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
        C:\Program Files\Winamp\winampa.exe
        C:\WINNT\SOUNDMAN.EXE
        C:\WINNT\System32\ctfmon.exe
        C:\Program Files\iolo\System Mechanic 4 Professional\Search and
        Recover\DiskImageService.exe
        C:\Program Files\Skype\Phone\Skype.exe
        C:\WINNT\System32\drivers\CDAC11BA.EXE
        C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
        C:\Program Files\Norton AntiVirus\navapsvc.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\WINNT\System32\nvsvc32.exe
        C:\WINNT\System32\svchost.exe
        C:\Program Files\Norton AntiVirus\SAVScan.exe
        C:\WINNT\System32\wuauclt.exe
        C:\WINNT\System32\wuauclt.exe
        C:\Program Files\Gadu-Gadu\Gadu-Gadu\gg.exe
        C:\Documents and Settings\AFFA\Pulpit\Nieużywane skróty
        pulpitu\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        www.onet.pl/
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
        www.onet.pl/
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
        F3 - REG:win.ini: load=C:\YDPDict\watch.exe
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
        - C:\Program Files\Adobe\Acrobat 5.0
        CE\Reader\ActiveX\AcroIEHelper.ocx
        O2 - BHO: Google Toolbar Helper -
        {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program
        files\google\googletoolbar2.dll
        O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} -
        C:\Program Files\Norton AntiVirus\NavShExt.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
        C:\WINNT\System32\msdxm.ocx
        O3 - Toolbar: Norton AntiVirus -
        {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton
        AntiVirus\NavShExt.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
        c:\program files\google\googletoolbar2.dll
        O4 - HKLM\..\Run: [Synchronization Manager]
        %SystemRoot%\system32\mobsync.exe /logon
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
        C:\WINNT\System32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points
        manager\points manager.exe -s
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
        Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
        Shared\ccApp.exe"
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
        Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common
        Files\Symantec Shared\Security Center\UsrPrmpt.exe
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINNT\System32\ctfmon.exe
        O4 - HKCU\..\Run: [Komunikator] C:\Program Files\Tlen.pl\tlen.exe
        O4 - HKCU\..\Run: [Search and Recover Disk Image Service] "C:\Program
        Files\iolo\System Mechanic 4 Professional\Search and
        Recover\DiskImageService.exe"
        O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe"
        /nosplash /minimized
        O4 - HKCU\..\Run: [System Mechanic Popup Stopper] "C:\Program
        Files\iolo\System Mechanic 4 Professional\PopupStopper.exe"
        O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program
        Files\Gadu-Gadu\Gadu-Gadu\gg.exe" /tray
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
        Office\Office10\OSA.EXE
        O8 - Extra context menu item: &Google Search - res://c:\program
        files\google\GoogleToolbar2.dll/cmsearch.html
        O8 - Extra context menu item: Backward Links - res://c:\program
        files\google\GoogleToolbar2.dll/cmbacklinks.html
        O8 - Extra context menu item: Cached Snapshot of Page -
        res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
        O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
        res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O8 - Extra context menu item: Similar Pages - res://c:\program
        files\google\GoogleToolbar2.dll/cmsimilar.html
        O8 - Extra context menu item: Translate into English -
        res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683}
        - C:\Program Files\Messenger\MSMSGS.EXE
        O9 - Extra 'Tools' menuitem: Windows Messenger -
        {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
        Files\Messenger\MSMSGS.EXE
        O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) -
        launch.gamespyarcade.com/software/launch/alaunch.cab
        O17 - HKLM\System\CCS\Services\Tcpip\..\{CED35B02-504A-44EF-8A20-C31F38D73884}:
        NameServer = 194.204.159.1,194.204.152.34
        O23 - Service: C-DillaCdaC11BA - Macrovision -
        C:\WINNT\System32\drivers\CDAC11BA.EXE
        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec
        Corporation - C:\Program Files\Common Files\Symantec
        Shared\ccEvtMgr.exe
        O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec
        Corporation - C:\Program Files\Common Files\Symantec
        Shared\ccPwdSvc.exe
        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec
        Corporation - C:\Program Files\Common Files\Symantec
        Shared\ccSetMgr.exe
        O23 - Service: MkS_Vir Monitor (MksVirMonSvc) - Unknown owner -
        C:\Program Files\MKS\Bin\mksmonsv.exe (file missing)
        O23 - Service: Usługa Auto Protect programu Norton AntiVirus
        (navapsvc) - Symantec Corporation - C:\Program Files\Norton
        AntiVirus\navapsvc.exe
        O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA
        Corporation - C:\WINNT\System32\nvsvc32.exe
        O23 - Service: SAVScan - Symantec Corporation - C:\Program
        Files\Norton AntiVirus\SAVScan.exe
        O23 - Service: ScriptBlocking Service (SBService) - Symantec
        Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec
        Corporation - C:\Program Files\Common Files\Symantec
        Shared\SNDSrvc.exe
        O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation -
        C:\Program Files\Common Files\Symantec Shared\Security
        Center\SymWSC.exe
        • Gość: Kolobos Re: hijack - log :-) IP: *.warszawa.sdi.tpnet.pl 23.04.05, 11:01
          Log wyglada ok, ale usun jeszcze to:

          O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) -
          launch.gamespyarcade.com/software/launch/alaunch.cab
          • Gość: marta Re: hijack - log :-) IP: *.neoplus.adsl.tpnet.pl 23.04.05, 13:07
            dziękuję za pomoc :-)

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka