Dodaj do ulubionych

log z hijackthis

IP: *.aster.pl / *.aster.pl 22.07.05, 18:06
Logfile of HijackThis v1.99.1
Scan saved at 18:04:43, on 2005-07-22
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\Navnt\navapsvc.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Navnt\alertsvc.exe
C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
C:\WINNT\system32\internat.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Start Page Bodyguard\Start Page Bodyguard.exe
C:\Program Files\Navnt\navapw32.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\TextBridge Classic 2.0\Ereg\REMIND32.EXE
C:\WINNT\twain_32\CIS600X\WATCH.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\piotrek\Pulpit\antytrojany\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
www.jimbutt.com/stuffs/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
google.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,AutoConfigURL = www.astercity.net/acc_ssl.pac
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h
O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0
\Bin\REGIST~1.EXE
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINNT\System32\PSDrvCheck.exe -
CheckReg
O4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exe
O4 - HKLM\..\Run: [NAV DefAlert] C:\PROGRA~1\Navnt\defalert.exe
O4 - HKLM\..\Run: [zSPGuard] c:\program files\pjw\spguard\spguard.exe /s
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0
\Bin\REGIST~1.EXE
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy
Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [Start Page Bodyguard] C:\Program Files\Start Page
Bodyguard\Start Page Bodyguard.exe
O4 - Startup: reminder-ScanSoft Product Registration.lnk = C:\Program
Files\TextBridge Classic 2.0\Ereg\REMIND32.EXE
O4 - Startup: Watch.lnk = C:\WINNT\twain_32\CIS600X\WATCH.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Autoochrona programu Norton AntiVirus.lnk = C:\Program
Files\Navnt\navapw32.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program
Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
skaner.mks.com.pl/SkanerOnline.cab
O23 - Service: Usługa administracyjna Menedżera dysków logicznych (dmadmin) -
VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Alarm NAV (NAV Alert) - Symantec Corporation - C:\PROGRA~1
\Navnt\alertsvc.exe
O23 - Service: Autoochrona programu NAV (NAV Auto-Protect) - Symantec
Corporation - C:\PROGRA~1\Navnt\navapsvc.exe
O23 - Service: Norton Scheduler (Norton Program Scheduler) - Symantec
Corporation - C:\PROGRA~1\Navnt\npssvc.exe

aha system win2000
dzięki za pomoc
Obserwuj wątek
    • Gość: Kolobos Re: log z hijackthis IP: *.warszawa.sdi.tpnet.pl 22.07.05, 18:51
      System widac w logu ;-) Tylko czemu SP2 zamiast SP4 (albo to cos udajace SP5?)

      Instalujesz i skanujesz system, a nastpenie usuwasz wszystko co znajdzie:
      download.microsoft.com/download/8/1/5/815d2d60-49b5-44dc-ae35-fca2f2c6f0cc/MicrosoftAntiSpywareInstall.exe

      W hijackthis kasujesz:
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      www.jimbutt.com/stuffs/

      Wpisujesz w Start->Uruchom:

      regsvr32 /u systr.dll
      lub:
      regsvr32 /u param32.dll

      I kasujesz plik z dysku (masz tylko jeden z nich).

      Jak chcesz to poczytaj tutaj:
      www.searchengines.pl/phpbb203/index.php?showtopic=12510&st=15&#entry58793
      Masz tam napisane co w rejestrze skasowac.


Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka