mala

IP: *.neoplus.adsl.tpnet.pl 03.05.05, 22:03
Czy to mozliwe ze cos samo zainstalowalo mi sie z neta jak mnie nie bylo w
domu i kopm byl nie uzywany wracam a tam 10 jakis programow w pasku i cos tam
clik me ?????????????pomocy
    • Gość: ???????????? Re: mala IP: *.neoplus.adsl.tpnet.pl 03.05.05, 22:06
      C:\WINDOWS\system32\poland.exe -R miedzy innymi cos takiego co to :(
      • Gość: Kolobos Re: mala IP: *.warszawa.sdi.tpnet.pl 03.05.05, 22:10
        Napewno sie samo nie zainstalowalo, ktos korzystal pewnie z komputera jak Cie
        nie bylo i zainstalowal.
        Wklej log z hijackthis:
        www.spychecker.com/program/hijackthis.html
        • Gość: ?????????? Re: mala IP: *.neoplus.adsl.tpnet.pl 03.05.05, 22:18
          Logfile of HijackThis v1.99.1
          Scan saved at 22:16:56, on 2005-05-03
          Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
          C:\WINDOWS\System32\userinit32.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
          C:\Program Files\Norton Internet Security\ISSVC.exe
          C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
          C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
          C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
          C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
          C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
          C:\Program Files\D-Tools\daemon.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\Program Files\Common Files\Symantec Shared\ccApp.exe
          C:\WINDOWS\System32\nmc32.exe
          C:\temp\salm.exe
          C:\WINDOWS\System32\csrci.exe
          C:\WINDOWS\System32\ctfmon.exe
          C:\WINDOWS\System32\RUNDLL32.EXE
          C:\Program Files\Tlen.pl\tlen.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
          C:\WINDOWS\System32\nvsvc32.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Skype\Phone\Skype.exe
          C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
          C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Documents and Settings\KrzysieK\Pulpit\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
          www.google.pl/
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft
          Internet Explorer
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
          F3 - REG:win.ini: run=
          F




          to jest log prosze sprawdz go
    • Gość: ????????? Re: mala IP: *.neoplus.adsl.tpnet.pl 03.05.05, 22:24
      salm.exe i cos 180 assistans
      • Gość: Kolobos Re: mala IP: *.warszawa.sdi.tpnet.pl 03.05.05, 22:46
        Wklej cala zawartosc log'a, a nie tylko kawalek.
    • Gość: ?????????????? Re: mala IP: *.neoplus.adsl.tpnet.pl 03.05.05, 23:18
      Logfile of HijackThis v1.99.1
      Scan saved at 22:16:56, on 2005-05-03
      Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
      C:\WINDOWS\System32\userinit32.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      C:\Program Files\Norton Internet Security\ISSVC.exe
      C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
      C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
      C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      C:\Program Files\D-Tools\daemon.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      C:\WINDOWS\System32\nmc32.exe
      C:\temp\salm.exe
      C:\WINDOWS\System32\csrci.exe
      C:\WINDOWS\System32\ctfmon.exe
      C:\WINDOWS\System32\RUNDLL32.EXE
      C:\Program Files\Tlen.pl\tlen.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
      C:\WINDOWS\System32\nvsvc32.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
      C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Documents and Settings\KrzysieK\Pulpit\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      www.google.pl/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft
      Internet Explorer
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
      F3 - REG:win.ini: run=
      F2 - REG:system.ini: UserInit=userinit.exe,userinit32.exe
      O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} -
      C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll
      O2 - BHO: &EliteSideBar - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} -
      C:\WINDOWS\EliteSideBar\EliteSideBar 08.dll
      O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} -
      C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32
      \NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program
      Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
      O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec
      Shared\Security Center\UsrPrmpt.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03
      \bin\jusched.exe
      O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1
      \SNDMon.exe /Consumer
      O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -
      lang 1045
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
      Shared\ccApp.exe"
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [Microsoft MCT64 Center] nmc32.exe
      O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
      O4 - HKLM\..\Run: [AhPMafD] C:\WINDOWS\dbjsugr.exe
      O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitebsu32.exe
      O4 - HKLM\..\Run: [HELPER] C:\WINDOWS\System32\poland.exe -N
      O4 - HKLM\..\Run: [WinNTunit] csrci.exe
      O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe
      O4 - HKLM\..\RunServices: [Microsoft MCT64 Center] nmc32.exe
      O4 - HKLM\..\RunServices: [WinNTunit] csrci.exe
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
      O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32
      \NVMCTRAY.DLL,NvTaskbarInit
      O4 - HKCU\..\Run: [Komunikator] C:\Program Files\Tlen.pl\tlen.exe
      O4 - HKCU\..\Run: [Skype] "C:\Program
      Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - HKCU\..\Run: [Microsoft MCT64 Center] nmc32.exe
      O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
      O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
      res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
      C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
      00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
      C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O15 - Trusted Zone: ny.contentmatch.net (HKLM)
      O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
      O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} (GINBOARDS Class) -
      67.15.101.3/g_bin/pl/boards_2_0_0_20.cab
      O16 - DPF: {92ECE6FA-AC2E-4042-BFAE-0C8608E52A43} (SignActivX Control) -
      www.bph.pl/pi/components/SignActivX.cab
      O16 - DPF: {AC120B1D-9411-4111-AF52-118052D85D45} (GameDesire Darts Games) -
      67.15.101.3/g_bin/pl/darts_2_0_0_29.cab
      O16 - DPF: {BFA1F11D-3121-AFE1-4112-983219421AEF} (GameDesire 1Player Word
      Games) - 67.15.101.3/g_bin/pl/wordssingle_2_0_0_34.cab
      O16 - DPF: {E23FABEE-12E3-33DA-DA12-195DAC123984} (GameDesire Mahjong) -
      67.15.101.3/g_bin/pl/mahjong_2_0_0_18.cab
      O16 - DPF: {E95CF138-A587-4C54-8175-3AD80997CB14} (GINSOCCER Class) -
      67.15.101.3/g_bin/pl/soccer_2_0_0_8.cab
      O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) -
      67.15.101.3/g_bin/pl/billard8_2_0_0_21.cab
      O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C5} (GameDesire Snooker) -
      67.15.101.3/g_bin/pl/snooker_2_0_0_22.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{31CB2C0C-9019-40E5-B0B2-608EBFE7A23E}:
      NameServer = 194.204.152.34 217.98.63.164
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
      C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation -
      C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation -
      C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -
      C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton
      Internet Security\ISSVC.exe
      O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec
      Corporation - C:\Program Files\Norton Internet Security\Norton
      AntiVirus\navapsvc.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
      C:\WINDOWS\System32\nvsvc32.exe
      O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton
      Internet Security\Norton AntiVirus\SAVScan.exe
      O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -
      C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec
      Corporation - C:\Program Files\Common File
      • Gość: Kolobos Re: mala IP: *.warszawa.sdi.tpnet.pl 03.05.05, 23:37
        Na poczatek uzyj tego:
        www.simplytech.it/ETRemover/ETRemoverV120.zip
        W hijackthis zaznacz te wpisy:

        F3 - REG:win.ini: run=
        F2 - REG:system.ini: UserInit=userinit.exe,userinit32.exe
        O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} -
        C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll
        O2 - BHO: &EliteSideBar - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} -
        C:\WINDOWS\EliteSideBar\EliteSideBar 08.dll
        O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} -
        C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll
        O4 - HKLM\..\Run: [Microsoft MCT64 Center] nmc32.exe
        O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
        O4 - HKLM\..\Run: [AhPMafD] C:\WINDOWS\dbjsugr.exe
        O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitebsu32.exe
        O4 - HKLM\..\Run: [HELPER] C:\WINDOWS\System32\poland.exe -N
        O4 - HKLM\..\Run: [WinNTunit] csrci.exe
        O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe
        O4 - HKLM\..\RunServices: [Microsoft MCT64 Center] nmc32.exe
        O4 - HKLM\..\RunServices: [WinNTunit] csrci.exe
        O4 - HKCU\..\Run: [Microsoft MCT64 Center] nmc32.exe
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
        O15 - Trusted Zone: ny.contentmatch.net (HKLM)
        O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab

        I Fix Checked, nastepnie sciagnij:
        www.downloads.subratam.org/KillBox.zip
        Rozpakuj, zaznacz Delete file on reboot wklej sciezke do pliku (sam/a nie
        szukaj tylko wklejaj gotowa) i naciskaj czerwony przycik ale na pytanie o reset
        odpowiadaj nie i tak zrob z tymi plikami:

        C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll
        C:\WINDOWS\EliteSideBar\EliteSideBar 08.dll
        C:\WINDOWS\System32\poland.exe
        C:\WINDOWS\System32\userinit32.exe
        C:\WINDOWS\System32\csrci.exe
        C:\WINDOWS\dbjsugr.exe
        C:\Program Files\Power Scan\powerscan.exe <- po resecie usun caly katalog Power
        Scan
        C:\windows\system32\elitebsu32.exe
        C:\WINDOWS\System32\nmc32.exe

        Nastepnie uruchom ponownie komputer i wklej nowy log z hijackthis, zainstaluj
        tez:
        www.safer-networking.org/pl/mirrors/index.html <- SpyBot S&D ->
        przeskanuj i wlacz ochrone przegladarki
        www.javacoolsoftware.com/spywareblaster.html <- SpywareBlaster -> wlacz
        ochrone przegladarki
        www.wilderssecurity.net/spywareguard.html <- SpywareGuard
    • Gość: ????????? Re: mala IP: *.neoplus.adsl.tpnet.pl 04.05.05, 00:09
      dziekuje zrobie tak a mam pytanie co to jest co usunelam i skad to sie wzielo
      czy to cos zlego prosze odpisz mi
      • Gość: Kolobos Re: mala IP: *.warszawa.sdi.tpnet.pl 04.05.05, 00:15
        Robaki, trojany, spyware same smiecie ale nic grozneg, wzielo sie stad, ze ktos
        kliknal w jakies okienko na jakiejs stronie (i to nawet pare razy ;-)) i
        zainstalowal.
        • Gość: ?????????? Re: mala IP: *.neoplus.adsl.tpnet.pl 04.05.05, 00:18
          na jakiej stronie czy np to sa te strony o jakich mysle ???
Pełna wersja