Dodaj do ulubionych

prosze o sprawdzenie loga

16.08.05, 01:34
Logfile of HijackThis v1.99.1
Scan saved at 02:42:27, on 2000-01-01
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVirenKit\AVKService.exe
C:\Program Files\AntiVirenKit\AVKWCtl.exe
C:\Program Files\G DATA\AVK ManagementServer\gdnss.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Pawel.PAWEL-
M0OI73XJY\Desktop\hijakcthis\hijackthis.com
C:\Documents and Settings\Pawel.PAWEL-
M0OI73XJY\Desktop\hijakcthis\hijackthis.com
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
195.95.218.172/index.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
195.95.218.172/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
195.95.218.172/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
195.95.218.172/index.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
195.95.218.172/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
195.95.218.172/index.php
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyServer = w3cache.sgh.waw.pl:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Loader Class - {2E246FAE-8420-11D9-870D-000C2917DE7F} -
C:\WINDOWS\SYSTEM\Loader.dll
O2 - BHO: (no name) - {78364D99-A640-4ddf-B91A-67EFF8373045} -
C:\WINDOWS\system32\appwiz.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SmartFix] "C:\Program Files\SmartFix\smartfix.exe"
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [S3hotkey] S3hotkey.exe
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint
Manager\ViewMgr.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32
\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11
\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [SysMemory manager] c:\windows\system32\mdms.exe
O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\System32\paytime.exe
O4 - HKLM\..\Run: [ms2] C:\WINDOWS\ms2.exe
O4 - HKLM\..\Run: [Internet Explorer] c:\Program Files\Internet
Explorer\shttps\http.exe
O4 - HKLM\..\Run: [Yggn] C:\WINDOWS\System32\ierfyzwnqmeko.exe
O4 - HKLM\..\Run: [secboot] C:\WINDOWS\System32\mszx23.exe !!
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program
Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\System32\paytime.exe
O4 - HKCU\..\Run: [ms2] C:\WINDOWS\ms2.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search -
kc.bar.need2find.com/KC/menusearch.html?p=KC
O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-
00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .tiff: C:\Program Files\Internet
Explorer\PLUGINS\npqtplugin5.dll
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) -
h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?946763476794
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) -
h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O20 - Winlogon Notify: drct16 - C:\WINDOWS\SYSTEM32\drct16.dll
O20 - Winlogon Notify: tcpG4T - C:\WINDOWS\SYSTEM32\tcpG4T.dll
O23 - Service: AVK Service (AVKService) - Unknown owner - C:\Program
Files\AntiVirenKit\AVKService.exe
O23 - Service: AVK Monitor (AVKWCtl) - Unknown owner - C:\Program
Files\AntiVirenKit\AVKWCtl.exe
O23 - Service: AVK Management Server (GDNSS) - Unknown owner - C:\Program
Files\G DATA\AVK ManagementServer\gdnss.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe

Obserwuj wątek
    • Gość: tata1959 Re: prosze o sprawdzenie loga IP: *.neoplus.adsl.tpnet.pl 16.08.05, 19:57
      witaj
      tak...pamiętaj!! sam log to jeszcze nie wszystko,proszę opis co się dzieje,ale
      generalnie to masz poważny problem bo masz między innymi fałszywą tapetę
      SpySheriff ,ale tu jest jak dla mnie za mało możliwości edycyjnych.
      zapraszam na www.searchengines.pl/phpbb203/index.php?showforum=99

      pozdrawiam

      .
      • oneway5 Re: prosze o sprawdzenie loga 19.08.05, 19:02
        Witam,

        Loga puscilem na forum bedac w pelnej panice... ale wlasnie dzieki Twoim postom
        na forum udalo mi sie odratowac kompa. Co prawda zeby z tego wyjsc troche
        pojecia o komputerach trzeba miec i co wazne drugi komp podlaczony do sieci...
        Moj zainfekowany byl w takim stanie, ze totalnie nic nie dzialalo. Udalo sie
        jednak za n-ta proba zainstalowac hijacka i jeszcze przed usunieciem haxedoor'a
        (najgorszy syf do usuniecia - tak przynajmniej wiesc gminna niesie) pozbylem
        sie falszywej tapety. Dzieki tata1959 i mam nadzieje ze to forum pomoze wielu w
        walce z wirami!
        Pozdrawiam,
        K.

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka