Dodaj do ulubionych

mam wirusa

IP: *.246.jawnet.pl 14.10.05, 18:34
Co chwilę zacina mi się komputer.Lecz antywirus nic nie wykrywa.Proszę
zobaczcie na to

Logfile of HijackThis v1.99.1
Scan saved at 18:27:11, on 05-10-14
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2614.3500)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\MKS\BIN\NETMONSV.EXE
C:\PROGRAM FILES\COMMON FILES\EPSON\EBAPI\SAGENT2.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\MKS\BIN\MKS_MENU.EXE
C:\PROGRAM FILES\MKS\BIN\MKS_MON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\SYSTEM\E_S10IC2.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\A4TECH\MOUSE\AMOUMAIN.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\PROGRAM FILES\PWN\DEFINICJE\BIN\STARTER.EXE
C:\WINDOWS\ANVSHELL.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\SLYSOFT\CLONECD\CLONECDTRAY.EXE
C:\PROGRAM FILES\GADU-GADU\GG.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\DESKTOP ARCHITECT\DATRAY.EXE
C:\PROGRAM FILES\MKS\BIN\MKS_SCAN.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\DC++\DCPLUSPLUS.EXE
C:\WINDOWS\PULPIT\PROGRAMY\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
www.google.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
www.eu.microsoft.com/poland/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [internat.exe] internat.exe
Obserwuj wątek
    • Gość: Kolobos Re: mam wirusa IP: *.warszawa.sdi.tpnet.pl 14.10.05, 18:50
      Komputer sie moze zawieszac, a nie zacinac ;-)
      Wklej caly log.
      Chyba nie uzywasz tego IE 5.0? :>
      • Gość: abc Re: mam wirusa IP: *.246.jawnet.pl 14.10.05, 18:55
        Ja urzywam mozille.org

        Logfile of HijackThis v1.99.1
        Scan saved at 18:27:11, on 05-10-14
        Platform: Windows 98 SE (Win9x 4.10.2222A)
        MSIE: Internet Explorer v5.00 (5.00.2614.3500)

        Running processes:
        C:\WINDOWS\SYSTEM\KERNEL32.DLL
        C:\WINDOWS\SYSTEM\MSGSRV32.EXE
        C:\WINDOWS\SYSTEM\MPREXE.EXE
        C:\PROGRAM FILES\MKS\BIN\NETMONSV.EXE
        C:\PROGRAM FILES\COMMON FILES\EPSON\EBAPI\SAGENT2.EXE
        C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
        C:\WINDOWS\SYSTEM\MSTASK.EXE
        C:\WINDOWS\SYSTEM\mmtask.tsk
        C:\WINDOWS\EXPLORER.EXE
        C:\WINDOWS\SYSTEM\INTERNAT.EXE
        C:\WINDOWS\TASKMON.EXE
        C:\WINDOWS\SYSTEM\SYSTRAY.EXE
        C:\PROGRAM FILES\MKS\BIN\MKS_MENU.EXE
        C:\PROGRAM FILES\MKS\BIN\MKS_MON.EXE
        C:\WINDOWS\SYSTEM\QTTASK.EXE
        C:\WINDOWS\SYSTEM\E_S10IC2.EXE
        C:\WINDOWS\SYSTEM\STIMON.EXE
        C:\WINDOWS\SYSTEM\SPOOL32.EXE
        C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
        C:\PROGRAM FILES\A4TECH\MOUSE\AMOUMAIN.EXE
        C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
        C:\PROGRAM FILES\PWN\DEFINICJE\BIN\STARTER.EXE
        C:\WINDOWS\ANVSHELL.EXE
        C:\WINDOWS\SYSTEM\DDHELP.EXE
        C:\PROGRAM FILES\SLYSOFT\CLONECD\CLONECDTRAY.EXE
        C:\PROGRAM FILES\GADU-GADU\GG.EXE
        C:\WINDOWS\RunDLL.exe
        C:\PROGRAM FILES\DESKTOP ARCHITECT\DATRAY.EXE
        C:\PROGRAM FILES\MKS\BIN\MKS_SCAN.EXE
        C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
        C:\WINDOWS\SYSTEM\WMIEXE.EXE
        C:\PROGRAM FILES\DC++\DCPLUSPLUS.EXE
        C:\WINDOWS\PULPIT\PROGRAMY\HIJACKTHIS\HIJACKTHIS.EXE

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        www.google.pl/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
        www.eu.microsoft.com/poland/
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
        C:\WINDOWS\SYSTEM\MSDXM.OCX
        O4 - HKLM\..\Run: [internat.exe] internat.exe
        O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
        O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
        O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
        O4 - HKLM\..\Run: [OWCCardbusTray] ocbtray.exe
        O4 - HKLM\..\Run: [MKS_MENU] C:\Program Files\MKS\Bin\mks_menu.exe
        O4 - HKLM\..\Run: [MKS_MON] C:\Program Files\MKS\Bin\mks_mon.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
        O4 - HKLM\..\Run: [EPSON Stylus C42 Series] C:\WINDOWS\SYSTEM\E_S10IC2.EXE /P23
        "EPSON Stylus C42 Series" /O5 "LPT1:" /M "Stylus C42"
        O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
        O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone
        Labs\ZoneAlarm\zlclient.exe
        O4 - HKLM\..\Run: [PE2CKFNT SE] C:\Program Files\Ulead Systems\Ulead Photo
        Express 2 SE\ChkFont.exe
        O4 - HKLM\..\Run: [WheelMouse] C:\PROGRA~1\A4TECH\MOUSE\AMOUMAIN.EXE
        O4 - HKLM\..\Run: [Zasobnik systemowy] SysTray.Exe
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKLM\..\Run: [DemonStarter] C:\Program Files\PWN\Definicje\Bin\Starter.exe
        O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
        O4 - HKLM\..\Run: [anvshell] anvshell.exe
        O4 - HKLM\..\Run: [LiveNote] livenote.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [wpkontakt] C:\Program Files\Wirtualna
        Polska\wpkontakt\wpkontakt.exe -autostart
        O4 - HKLM\..\Run: [CloneCDTray] "C:\Program
        Files\SlySoft\CloneCD\CloneCDTray.exe" /s
        O4 - HKLM\..\RunServices: [MksMailService] C:\PROGRAM FILES\MKS\BIN\NETMONSV.EXE
        O4 - HKLM\..\RunServices: [SAgent2ExePath] C:\Program Files\Common
        Files\EPSON\EBAPI\SAgent2.exe
        O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
        O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe
        powrprof.dll,LoadCurrentPwrScheme
        O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\SYSTEM\mstask.exe
        O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program
        Files\mozilla.org\Mozilla\Mozilla.exe" -turbo
        O4 - HKCU\..\Run: [Gadu-Gadu] "C:\PROGRAM FILES\GADU-GADU\GG.EXE" /tray
        O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL
        deskcp16.dll,QUICKRES_RUNDLLENTRY
        O4 - HKCU\..\Run: [Desktop Architect] "C:\PROGRAM FILES\DESKTOP
        ARCHITECT\DATRAY.EXE" -S
        O4 - HKCU\..\Run: [NBJ] "C:\PROGRAM FILES\AHEAD\NERO BACKITUP\NBJ.EXE"
        O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common
        Files\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Startup: Uruchamianie pakietu Office.lnk = C:\Program Files\Microsoft
        Office\Office\OSA.EXE
        O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft
        Office\Office\FINDFAST.EXE
        O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
        C:\WINDOWS\web\related.htm
        O9 - Extra 'Tools' menuitem: Show &Related Links -
        {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
        C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console -
        {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
        Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O14 - IERESET.INF: SEARCH_PAGE_URL=
        O14 - IERESET.INF: START_PAGE_URL=
        O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) -
        67.15.101.3/g_bin/pl/billard8_2_0_0_23.cab
        O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
        skaner.mks.com.pl/SkanerOnline.cab
        O18 - Protocol: wpmsg - {2E0AC5A0-3597-11D6-B3ED-0001021DC1C3} - C:\PROGRAM
        FILES\WIRTUALNA POLSKA\WPKONTAKT\URL_WPMSG.DLL

        • Gość: Kolobos Re: mam wirusa IP: *.warszawa.sdi.tpnet.pl 14.10.05, 19:06
          Ale uzywasz przez samo ż

          Usun z autostartu Microsoft Find Fast
          Log jest ok wiec idz sobie do dzialu Komputer i tam napisz ze sie wiesza i
          opisz co dokladnie sie dzieje.

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka