Dodaj do ulubionych

Proszę o pomoc

03.09.05, 23:29
Po pierwsze proszę o sprawdzenie loga:

Logfile of HijackThis v1.99.1
Scan saved at 23:09:45, on 05-09-03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\ATIPTAXX.EXE
C:\WINDOWS\POWERS.EXE
C:\WINDOWS\DSLAUNCH.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\PROGRAM FILES\MEDIA GATEWAY\MEDIAGATEWAY.EXE
C:\PROGRAM FILES\MICROSTAR\WLANUTILITY\WLANUTILITY.EXE
C:\PROGRAM FILES\ULEAD SYSTEMS\ULEAD PHOTO EXPRESS 2 SE\CALCHECK.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
C:\PROGRAM FILES\MICROSTAR\WLANUTILITY\WLAN_SERVICE.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\GAMES\ICYTOWER1.2\ICYTOWER.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\PULPIT\RóżNE\HIJACK THIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
www.google.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} -
C:\PROGRAM FILES\FLASHGET\JCCATCH.DLL
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-
0B27DDD11DB2} - C:\PROGRAM FILES\SPYWAREGUARD\DLPROTECT.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1
\SPYBOT~1\SDHELPER.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} -
C:\PROGRAM FILES\FLASHGET\FGIEBAR.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [PowerS] "C:\WINDOWS\PowerS.EXE"
O4 - HKLM\..\Run: [YAMAHA DS-XG Launcher] C:\WINDOWS\dslaunch.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [PE2CKFNT SE] C:\Program Files\Ulead Systems\Ulead Photo
Express 2 SE\ChkFont.exe
O4 - HKLM\..\Run: [Media Gateway] C:\PROGRAM FILES\MEDIA
GATEWAY\MEDIAGATEWAY.EXE
O4 - HKLM\..\Run: [InstaFinderK] C:\Program
Files\INSTAFINK\INSTAFINDERK_INST.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ATIPOLAB] ati2evxx.exe
O4 - Startup: WlanUtility.lnk = C:\Program
Files\MicroStar\WLANUtility\WlanUtility.exe
O4 - Startup: Photo Express Calendar Checker SE.lnk = C:\Program Files\Ulead
Systems\Ulead Photo Express 2 SE\CalCheck.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office\OSA9.EXE
O8 - Extra context menu item: Ściągnij przy pomocy FlashGet'a - C:\PROGRAM
FILES\FLASHGET\jc_link.htm
O8 - Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a -
C:\PROGRAM FILES\FLASHGET\jc_all.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} -
C:\PROGRAM FILES\FLASHGET\FLASHGET.EXE
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-
0050BA6940E3} - C:\PROGRAM FILES\FLASHGET\FLASHGET.EXE
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (Download Helper Class) -
activex.microgaming.com/DLhelper/version7/dlhelper.cab
O16 - DPF: {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} (IEHelperObject) -
eroscop.pl/avicodec.ocx
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer =
194.204.152.34,194.204.159.1

Poza tym mam taki problem, że jak skanuję system Spybotem to mi wyskakuje po
pewnym czasie takie coś:

Błąd podczas skanowania!: Xuron55 (Datei C:\WINDOWS\win.ini kann nicht
geöffnet werden. Proces nie może uzyskać dostępu do pliku
ponieważ jest on używany przez inny proces) ()

I jeszcze jedno: jak sobie poradzić z wirusem Downloader.Dyfica.3.AL? Co to
jest w ogóle? Z góry dzięki.
Obserwuj wątek
    • Gość: Kolobos Re: Proszę o pomoc IP: *.warszawa.sdi.tpnet.pl 03.09.05, 23:47
      Zainstaluj nowa wersje SpyBot'a i/lub poczytaj na stronie programu co zrobic z
      Xuron55 lub na google:
      www.google.pl/search?sourceid=navclient&hl=pl&ie=UTF-8&oe=UTF-8&q=Xuron55


      Zakoncz proces:
      C:\PROGRAM FILES\MEDIA GATEWAY\MEDIAGATEWAY.EXE
      I usun caly katalog Media Gateway


      W hijackthis:

      O4 - HKLM\..\Run: [Media Gateway] C:\PROGRAM FILES\MEDIA
      GATEWAY\MEDIAGATEWAY.EXE
      O4 - HKLM\..\Run: [InstaFinderK] C:\Program
      Files\INSTAFINK\INSTAFINDERK_INST.EXE <- odinstaluj i usun caly katalog
      O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (Download Helper Class) -
      activex.microgaming.com/DLhelper/version7/dlhelper.cab
      O16 - DPF: {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} (IEHelperObject) -
      eroscop.pl/avicodec.ocx


      W jakim pliku wykrywa Ci Downloader.Dyfica.3.AL ?
      • liessa Re: Proszę o pomoc 04.09.05, 13:29
        Log:

        Running processes:
        C:\WINDOWS\SYSTEM\KERNEL32.DLL
        C:\WINDOWS\SYSTEM\MSGSRV32.EXE
        C:\WINDOWS\SYSTEM\MPREXE.EXE
        C:\WINDOWS\SYSTEM\mmtask.tsk
        C:\WINDOWS\SYSTEM\MSTASK.EXE
        C:\WINDOWS\EXPLORER.EXE
        C:\WINDOWS\SYSTEM\INTERNAT.EXE
        C:\WINDOWS\TASKMON.EXE
        C:\WINDOWS\SYSTEM\SYSTRAY.EXE
        C:\WINDOWS\SYSTEM\ATIPTAXX.EXE
        C:\WINDOWS\POWERS.EXE
        C:\WINDOWS\DSLAUNCH.EXE
        C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
        C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
        C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
        C:\PROGRAM FILES\MICROSTAR\WLANUTILITY\WLANUTILITY.EXE
        C:\PROGRAM FILES\ULEAD SYSTEMS\ULEAD PHOTO EXPRESS 2 SE\CALCHECK.EXE
        C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
        C:\WINDOWS\SYSTEM\WMIEXE.EXE
        C:\PROGRAM FILES\MICROSTAR\WLANUTILITY\WLAN_SERVICE.EXE
        C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
        C:\PROGRAM FILES\GADU-GADU\GG.EXE
        C:\WINDOWS\SYSTEM\DDHELP.EXE
        C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
        C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
        C:\WINDOWS\RUNDLL32.EXE
        C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGVV.EXE
        C:\WINDOWS\PULPIT\RóżNE\HIJACK THIS\HIJACKTHIS.EXE

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        www.google.pl/
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
        O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRAM
        FILES\FLASHGET\JCCATCH.DLL
        O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-
        0B27DDD11DB2} - C:\PROGRAM FILES\SPYWAREGUARD\DLPROTECT.DLL
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
        C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1
        \SPYBOT~1\SDHELPER.DLL
        O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} -
        C:\PROGRAM FILES\FLASHGET\FGIEBAR.DLL
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
        C:\WINDOWS\SYSTEM\MSDXM.OCX
        O4 - HKLM\..\Run: [internat.exe] internat.exe
        O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
        O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
        O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
        O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe
        powrprof.dll,LoadCurrentPwrScheme
        O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
        O4 - HKLM\..\Run: [PowerS] "C:\WINDOWS\PowerS.EXE"
        O4 - HKLM\..\Run: [YAMAHA DS-XG Launcher] C:\WINDOWS\dslaunch.exe
        O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
        O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
        O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
        O4 - HKLM\..\Run: [PE2CKFNT SE] C:\Program Files\Ulead Systems\Ulead Photo
        Express 2 SE\ChkFont.exe
        O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe
        powrprof.dll,LoadCurrentPwrScheme
        O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
        O4 - HKLM\..\RunServices: [ATIPOLAB] ati2evxx.exe
        O4 - Startup: WlanUtility.lnk = C:\Program
        Files\MicroStar\WLANUtility\WlanUtility.exe
        O4 - Startup: Photo Express Calendar Checker SE.lnk = C:\Program Files\Ulead
        Systems\Ulead Photo Express 2 SE\CalCheck.exe
        O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
        O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
        Office\Office\OSA9.EXE
        O8 - Extra context menu item: Ściągnij przy pomocy FlashGet'a - C:\PROGRAM
        FILES\FLASHGET\jc_link.htm
        O8 - Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a -
        C:\PROGRAM FILES\FLASHGET\jc_all.htm
        O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} -
        C:\PROGRAM FILES\FLASHGET\FLASHGET.EXE
        O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-
        0050BA6940E3} - C:\PROGRAM FILES\FLASHGET\FLASHGET.EXE
        O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
        O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer =
        194.204.152.34,194.204.159.1

        A tego wirusa wykrywa w C:\TEMP\OPTIMIZE.EXE
        • Gość: Kolobos Re: Proszę o pomoc IP: *.warszawa.sdi.tpnet.pl 04.09.05, 14:02
          To go usun, po co go trzymasz na dysku?
          Log wyglada juz ok.

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka