pomozcie bardzo prosze. co jest nie tak

23.05.05, 13:29
Logfile of HijackThis v1.99.1
Scan saved at 13:28:22, on 2005-05-23
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\wail\Pulpit\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
www.specialgoods.info/ad/ad0422/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
res://C:\DOCUME~1\wail\USTAWI~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} -
C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2EBABBBF-7747-4A01-932C-174B3DEA9C16} -
C:\WINDOWS\System32\pncj.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} -
C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32
\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02
\bin\jusched.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32
\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100
Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [SVCHOSŇ.EXE] SVCHOSŇ.EXE $$
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Spyware Begone] C:\Program Files\spyware
begone\freescan.exe -FastScan
O4 - Global Startup: True Internet Color Icon.lnk = C:\Program Files\E-
Color\True Internet Color\TICIcon.exe
O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Softsun Flashplayer - C:\Program
Files\Softsun\Softsun Flashplayer\config\getmovie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Softsun Flashplayer - {745DBD89-EE6C-4787-B874-
5400497CBD2D} - C:\Program Files\Softsun\Softsun
Flashplayer\config\getmovie.htm
O9 - Extra 'Tools' menuitem: &Softsun Flashplayer - {745DBD89-EE6C-4787-B874-
5400497CBD2D} - C:\Program Files\Softsun\Softsun
Flashplayer\config\getmovie.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1109416652717
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) -
www.windowsecurity.com/trojanscan/axscan.cab
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
skaner.mks.com.pl/SkanerOnline.cab
O20 - Winlogon Notify: f3dsl - lsd_f3.dll (file missing)
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH -
C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany -
C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. -
C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program
Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) -
Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    • Gość: Kolobos Re: pomozcie bardzo prosze. co jest nie tak IP: *.warszawa.sdi.tpnet.pl 23.05.05, 15:13
      Najpierw to:
      www.trojaner-info.de/files/SpSeHjfix112.exe
      W hijackthis to:

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      www.specialgoods.info/ad/ad0422/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
      res://C:\DOCUME~1\wail\USTAWI~1\Temp\se.dll/sp.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      about:blank
      O2 - BHO: (no name) - {2EBABBBF-7747-4A01-932C-174B3DEA9C16} -
      C:\WINDOWS\System32\pncj.dll (file missing)
      O4 - HKLM\..\Run: [SVCHOSŇ.EXE] SVCHOSŇ.EXE $$
      O20 - Winlogon Notify: f3dsl - lsd_f3.dll (file missing)

      www.downloads.subratam.org/KillBox.zip
      Killbox'em kasujesz to z opcja delete on reboot:

      C:\Windows\system32\SVCHOSŇ.EXE
      C:\DOCUME~1\wail\USTAWI~1\Temp\se.dll

      Po resecie wklejasz nowy log z hijackthis.

      • inter1981 Re: pomozcie bardzo prosze. co jest nie tak 23.05.05, 15:44
        Logfile of HijackThis v1.99.1
        Scan saved at 15:38:57, on 2005-05-23
        Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\LEXBCES.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\LEXPPS.EXE
        C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
        C:\Program Files\AVPersonal\AVGNT.EXE
        C:\WINDOWS\System32\ctfmon.exe
        C:\Program Files\AVPersonal\AVGUARD.EXE
        C:\Program Files\AVPersonal\AVWUPSRV.EXE
        C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
        C:\WINDOWS\System32\nvsvc32.exe
        C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\wuauclt.exe
        C:\Documents and Settings\wail\Pulpit\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        www.specialgoods.info/ad/ad0422/
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
        O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} -
        C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
        C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
        C:\WINDOWS\System32\msdxm.ocx
        O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} -
        C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32
        \NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02
        \bin\jusched.exe
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32
        \NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100
        Series\lxbkbmgr.exe"
        O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
        O4 - HKCU\..\Run: [Spyware Begone] C:\Program Files\spyware
        begone\freescan.exe -FastScan
        O4 - HKCU\..\Run: [HijackThis startup scan] C:\Documents and
        Settings\wail\Pulpit\HijackThis.exe /startupscan
        O4 - Global Startup: True Internet Color Icon.lnk = C:\Program Files\E-
        Color\True Internet Color\TICIcon.exe
        O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
        res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
        O8 - Extra context menu item: Softsun Flashplayer - C:\Program
        Files\Softsun\Softsun Flashplayer\config\getmovie.htm
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
        C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
        00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
        O9 - Extra button: Softsun Flashplayer - {745DBD89-EE6C-4787-B874-
        5400497CBD2D} - C:\Program Files\Softsun\Softsun Flashplayer\config\getmovie.htm
        O9 - Extra 'Tools' menuitem: &Softsun Flashplayer - {745DBD89-EE6C-4787-B874-
        5400497CBD2D} - C:\Program Files\Softsun\Softsun Flashplayer\config\getmovie.htm
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
        v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1109416652717
        O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) -
        www.windowsecurity.com/trojanscan/axscan.cab
        O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
        skaner.mks.com.pl/SkanerOnline.cab
        O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH -
        C:\Program Files\AVPersonal\AVGUARD.EXE
        O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany -
        C:\Program Files\AVPersonal\AVWUPSRV.EXE
        O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. -
        C:\WINDOWS\system32\LEXBCES.EXE
        O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program
        Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
        C:\WINDOWS\System32\nvsvc32.exe
        O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) -
        Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

        • Gość: Kolobos Re: pomozcie bardzo prosze. co jest nie tak IP: *.warszawa.sdi.tpnet.pl 23.05.05, 15:57
          Usun ten plik:
          C:\WINDOWS\System32\param32.dll
          Przy pomocy killbox'a.

          Nastepnie uruchom regedit:
          Start->Uruchom->regedit
          Przejdz do:
          Hkey_Local_Machine\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTask
          Scheduler\
          i usun tam ten klucz:
          "{D56A1203-1452-EBA1-7294-EE3377770000}" = "Interlinking Memory Support"

          O ile taki masz jak nie to zrob export calej galezi
          Hkey_Local_Machine\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTask
          Scheduler\

          I wklej na forum jej zawartosc.

          Na koniec kasujesz:
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
          www.specialgoods.info/ad/ad0422/

          • inter1981 Re: pomozcie bardzo prosze. co jest nie tak 23.05.05, 16:47
            WIELKIE DZIEKI :):):) NARAZIE WSZYSTKO JEST OK
Pełna wersja