Gość: ???????? IP: *.neoplus.adsl.tpnet.pl 03.05.05, 22:03 Czy to mozliwe ze cos samo zainstalowalo mi sie z neta jak mnie nie bylo w domu i kopm byl nie uzywany wracam a tam 10 jakis programow w pasku i cos tam clik me ?????????????pomocy Odpowiedz Link Zgłoś czytaj wygodnie posty
Gość: ???????????? Re: mala IP: *.neoplus.adsl.tpnet.pl 03.05.05, 22:06 C:\WINDOWS\system32\poland.exe -R miedzy innymi cos takiego co to :( Odpowiedz Link Zgłoś
Gość: Kolobos Re: mala IP: *.warszawa.sdi.tpnet.pl 03.05.05, 22:10 Napewno sie samo nie zainstalowalo, ktos korzystal pewnie z komputera jak Cie nie bylo i zainstalowal. Wklej log z hijackthis: www.spychecker.com/program/hijackthis.html Odpowiedz Link Zgłoś
Gość: ?????????? Re: mala IP: *.neoplus.adsl.tpnet.pl 03.05.05, 22:18 Logfile of HijackThis v1.99.1 Scan saved at 22:16:56, on 2005-05-03 Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\WINDOWS\System32\userinit32.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Norton Internet Security\ISSVC.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe C:\Program Files\D-Tools\daemon.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\System32\nmc32.exe C:\temp\salm.exe C:\WINDOWS\System32\csrci.exe C:\WINDOWS\System32\ctfmon.exe C:\WINDOWS\System32\RUNDLL32.EXE C:\Program Files\Tlen.pl\tlen.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Messenger\msmsgs.exe C:\Documents and Settings\KrzysieK\Pulpit\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.pl/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza F3 - REG:win.ini: run= F to jest log prosze sprawdz go Odpowiedz Link Zgłoś
Gość: ????????? Re: mala IP: *.neoplus.adsl.tpnet.pl 03.05.05, 22:24 salm.exe i cos 180 assistans Odpowiedz Link Zgłoś
Gość: Kolobos Re: mala IP: *.warszawa.sdi.tpnet.pl 03.05.05, 22:46 Wklej cala zawartosc log'a, a nie tylko kawalek. Odpowiedz Link Zgłoś
Gość: ?????????????? Re: mala IP: *.neoplus.adsl.tpnet.pl 03.05.05, 23:18 Logfile of HijackThis v1.99.1 Scan saved at 22:16:56, on 2005-05-03 Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\WINDOWS\System32\userinit32.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Norton Internet Security\ISSVC.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe C:\Program Files\D-Tools\daemon.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\System32\nmc32.exe C:\temp\salm.exe C:\WINDOWS\System32\csrci.exe C:\WINDOWS\System32\ctfmon.exe C:\WINDOWS\System32\RUNDLL32.EXE C:\Program Files\Tlen.pl\tlen.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Messenger\msmsgs.exe C:\Documents and Settings\KrzysieK\Pulpit\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.pl/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza F3 - REG:win.ini: run= F2 - REG:system.ini: UserInit=userinit.exe,userinit32.exe O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll O2 - BHO: &EliteSideBar - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - C:\WINDOWS\EliteSideBar\EliteSideBar 08.dll O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32 \NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03 \bin\jusched.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1 \SNDMon.exe /Consumer O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" - lang 1045 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [Microsoft MCT64 Center] nmc32.exe O4 - HKLM\..\Run: [salm] c:\temp\salm.exe O4 - HKLM\..\Run: [AhPMafD] C:\WINDOWS\dbjsugr.exe O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitebsu32.exe O4 - HKLM\..\Run: [HELPER] C:\WINDOWS\System32\poland.exe -N O4 - HKLM\..\Run: [WinNTunit] csrci.exe O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe O4 - HKLM\..\RunServices: [Microsoft MCT64 Center] nmc32.exe O4 - HKLM\..\RunServices: [WinNTunit] csrci.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32 \NVMCTRAY.DLL,NvTaskbarInit O4 - HKCU\..\Run: [Komunikator] C:\Program Files\Tlen.pl\tlen.exe O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [Microsoft MCT64 Center] nmc32.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5- 00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O15 - Trusted Zone: ny.contentmatch.net (HKLM) O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} (GINBOARDS Class) - 67.15.101.3/g_bin/pl/boards_2_0_0_20.cab O16 - DPF: {92ECE6FA-AC2E-4042-BFAE-0C8608E52A43} (SignActivX Control) - www.bph.pl/pi/components/SignActivX.cab O16 - DPF: {AC120B1D-9411-4111-AF52-118052D85D45} (GameDesire Darts Games) - 67.15.101.3/g_bin/pl/darts_2_0_0_29.cab O16 - DPF: {BFA1F11D-3121-AFE1-4112-983219421AEF} (GameDesire 1Player Word Games) - 67.15.101.3/g_bin/pl/wordssingle_2_0_0_34.cab O16 - DPF: {E23FABEE-12E3-33DA-DA12-195DAC123984} (GameDesire Mahjong) - 67.15.101.3/g_bin/pl/mahjong_2_0_0_18.cab O16 - DPF: {E95CF138-A587-4C54-8175-3AD80997CB14} (GINSOCCER Class) - 67.15.101.3/g_bin/pl/soccer_2_0_0_8.cab O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) - 67.15.101.3/g_bin/pl/billard8_2_0_0_21.cab O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C5} (GameDesire Snooker) - 67.15.101.3/g_bin/pl/snooker_2_0_0_22.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{31CB2C0C-9019-40E5-B0B2-608EBFE7A23E}: NameServer = 194.204.152.34 217.98.63.164 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common File Odpowiedz Link Zgłoś
Gość: Kolobos Re: mala IP: *.warszawa.sdi.tpnet.pl 03.05.05, 23:37 Na poczatek uzyj tego: www.simplytech.it/ETRemover/ETRemoverV120.zip W hijackthis zaznacz te wpisy: F3 - REG:win.ini: run= F2 - REG:system.ini: UserInit=userinit.exe,userinit32.exe O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll O2 - BHO: &EliteSideBar - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - C:\WINDOWS\EliteSideBar\EliteSideBar 08.dll O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll O4 - HKLM\..\Run: [Microsoft MCT64 Center] nmc32.exe O4 - HKLM\..\Run: [salm] c:\temp\salm.exe O4 - HKLM\..\Run: [AhPMafD] C:\WINDOWS\dbjsugr.exe O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitebsu32.exe O4 - HKLM\..\Run: [HELPER] C:\WINDOWS\System32\poland.exe -N O4 - HKLM\..\Run: [WinNTunit] csrci.exe O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe O4 - HKLM\..\RunServices: [Microsoft MCT64 Center] nmc32.exe O4 - HKLM\..\RunServices: [WinNTunit] csrci.exe O4 - HKCU\..\Run: [Microsoft MCT64 Center] nmc32.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O15 - Trusted Zone: ny.contentmatch.net (HKLM) O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab I Fix Checked, nastepnie sciagnij: www.downloads.subratam.org/KillBox.zip Rozpakuj, zaznacz Delete file on reboot wklej sciezke do pliku (sam/a nie szukaj tylko wklejaj gotowa) i naciskaj czerwony przycik ale na pytanie o reset odpowiadaj nie i tak zrob z tymi plikami: C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll C:\WINDOWS\EliteSideBar\EliteSideBar 08.dll C:\WINDOWS\System32\poland.exe C:\WINDOWS\System32\userinit32.exe C:\WINDOWS\System32\csrci.exe C:\WINDOWS\dbjsugr.exe C:\Program Files\Power Scan\powerscan.exe <- po resecie usun caly katalog Power Scan C:\windows\system32\elitebsu32.exe C:\WINDOWS\System32\nmc32.exe Nastepnie uruchom ponownie komputer i wklej nowy log z hijackthis, zainstaluj tez: www.safer-networking.org/pl/mirrors/index.html <- SpyBot S&D -> przeskanuj i wlacz ochrone przegladarki www.javacoolsoftware.com/spywareblaster.html <- SpywareBlaster -> wlacz ochrone przegladarki www.wilderssecurity.net/spywareguard.html <- SpywareGuard Odpowiedz Link Zgłoś
Gość: ????????? Re: mala IP: *.neoplus.adsl.tpnet.pl 04.05.05, 00:09 dziekuje zrobie tak a mam pytanie co to jest co usunelam i skad to sie wzielo czy to cos zlego prosze odpisz mi Odpowiedz Link Zgłoś
Gość: Kolobos Re: mala IP: *.warszawa.sdi.tpnet.pl 04.05.05, 00:15 Robaki, trojany, spyware same smiecie ale nic grozneg, wzielo sie stad, ze ktos kliknal w jakies okienko na jakiejs stronie (i to nawet pare razy ;-)) i zainstalowal. Odpowiedz Link Zgłoś
Gość: ?????????? Re: mala IP: *.neoplus.adsl.tpnet.pl 04.05.05, 00:18 na jakiej stronie czy np to sa te strony o jakich mysle ??? Odpowiedz Link Zgłoś