Dodaj do ulubionych

smitfraud-c czy ktoś może pomoc

IP: *.echostar.pl 17.10.05, 19:40
elooo, na pocz powiem czym dysponuje na kompie-Kerio PF, Ad Aware SE, Spyware
Blaster, Avast Antivir i Spybot Search&Destroy. Ten ostatni czyli Spybot
wywalił mi, żę mam smitfraud-c. Tylko, że nie może sobie z nim poradzić jak
wybieram opcję "fix selected problems" i nie za bardzo wiem jak go wywalić.
Jeśli ktoś może coś poradzić to proszę o info.
Obserwuj wątek
    • neder Re: smitfraud-c czy ktoś może pomoc 17.10.05, 19:45
      wklej log z HijackThis
      pzdr
      • Gość: songo Re: smitfraud-c czy ktoś może pomoc IP: *.echostar.pl 17.10.05, 19:49
        Logfile of HijackThis v1.99.1
        Scan saved at 19:47:05, on 2005-10-17
        Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Anvshell.exe
        C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
        C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
        C:\WINDOWS\System32\RUNDLL32.EXE
        C:\Program Files\D-Tools\daemon.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
        C:\WINDOWS\System32\ctfmon.exe
        C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
        C:\WINDOWS\System32\nvsvc32.exe
        C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
        C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        www.google.pl/
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
        C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
        C:\PROGRA~1\SPYBOT~2\SDHelper.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
        C:\WINDOWS\System32\msdxm.ocx
        O4 - HKLM\..\Run: [Anvshell] C:\WINDOWS\Anvshell.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
        O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
        O4 - HKLM\..\Run: [HPDJ Taskbar Utility]
        C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
        O4 - HKLM\..\Run: [LANChatPro] C:\Program Files\LANChat Pro\LANChat.exe /q
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
        C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"
        -lang 1033
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe"
        -atboottime
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
        Files\Java\jre1.5.0_02\bin\jusched.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
        O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program
        Files\InterVideo\Common\Bin\WinCinemaMgr.exe
        O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
        res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
        C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console -
        {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
        Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
        O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
        O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International
        Setup Player) - www.napster.com/client/isetup.cab
        O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
        skaner.mks.com.pl/SkanerOnline.cab
        O16 - DPF: {F5D98C43-DB16-11CF-8ECA-0000C0FD59C7} (ActiveCGM Control) -
        sit.glogow.pl/MAPKA/ACGM/acgm.cab
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner -
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil
        Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil
        Software\Avast4\ashMaiSv.exe" /service (file missing)
        O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil
        Software\Avast4\ashWebSv.exe" /service (file missing)
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation
        - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies -
        C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
        C:\WINDOWS\System32\nvsvc32.exe
        O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) -
        Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
        • Gość: Kolobos Re: smitfraud-c czy ktoś może pomoc IP: *.warszawa.sdi.tpnet.pl 17.10.05, 21:08
          Log wyglada ok, naprawa tapety tutaj:
          www.searchengines.pl/phpbb203/index.php?showtopic=31936
          • Gość: songo Re: smitfraud-c czy ktoś może pomoc-do Kolobos IP: *.echostar.pl 17.10.05, 21:35
            no właśnie tylko że ja nie mam żadnej wyskakującej tapety???!!!???, wogólnie nic
            misię nie dzieje z kompem tylko po skanowaniu Spybot'em wywaliło mi że mam taki
            niechciany bonusik w kompie.

            A z tym nic nie dzianiem się z kompem to nie do końca jest tak, bo od wczoraj
            jak pierwszy raz przeskanowałem kompa to zaczęła się dziwna sprawa tzn. net mam
            przez kablówkę ale od wczoraj co jakiś czas siada mi połączenie po pewnym czasie
            nieużywania kompa, a nigdy wcześniej się to nie działo i dlatego to zauważyłem
            bo wcześniej było wszystlo ok???? czy to ma coś wspólnego z tym
            Smitfraud-C???????????????
            • Gość: Kolobos Re: smitfraud-c czy ktoś może pomoc-do Kolobos IP: *.warszawa.sdi.tpnet.pl 17.10.05, 22:36
              Zaloguj sie jako administrator i przeskanuj tym:
              download.microsoft.com/download/8/1/5/815d2d60-49b5-44dc-ae35-fca2f2c6f0cc/MicrosoftAntiSpywareInstall.exe

              download.ewido.net/ewido-setup.exe <- zrob update przed skanowaniem, po
              przeskanowaniu odinstaluj.

              • Gość: songo Re: smitfraud-c czy ktoś może pomoc-do Kolobos IP: *.echostar.pl 18.10.05, 19:18
                zrobiłem tak jak napisałeś, ściągnąłem co trzeba, zrobiłem update,
                przeskanowałem, powyrzucałem, zrestartowałem kompa i... jak sprawdzam tym
                Spybot'em to nadal mi wywala że znalazł smitfraud-c.
                wiec nie wiem co dalej z tym fantem zrobić?????????????????
                no i proszę o pomoc
                • Gość: Kolobos Re: smitfraud-c czy ktoś może pomoc-do Kolobos IP: *.warszawa.sdi.tpnet.pl 18.10.05, 19:25
                  Zaloguj sie jako administrator i przeskanuj jeszcze raz wszystkim.
                  Gdzie Ci to wykrywa? Jakis plik czy wpis w rejestrze czy co?
                  • Gość: songo Re: smitfraud-c czy ktoś może pomoc-do Kolobos IP: *.echostar.pl 18.10.05, 22:37
                    właśnie już skanowałem jako administrator, a co do tego gdzie to jest to może
                    log ze Spybot'a poniżej-jesli to cos pomoze:

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\www.niger.ru\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\www.6o9.com\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\webpidor.biz\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\visitfriend.net\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\veryeasysearch.com\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\v-224.com\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\tracking.allposters.com\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\terra.hcworld.com\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\s2.kav.cc\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\s13.remove.cc\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\rf104.com\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\new.8ad.com\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\msnprotection.com\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\meetyourfriend.biz\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\makechoice.com\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\love-catalog.net\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\letgohome.com\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\greg-tut.com\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\ga31.com\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\fuck-fuck.org\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\free-spy-cam.net\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\fast-look.com\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\ewizard.cc\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\e-finder.cc\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\dl.ad-ware.cc\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\datingforlove.org\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\crl.thawte.com\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\cc20foreva.com\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\bin.wordsx.cc\*!=W=4

                    Smitfraud-C.: User settings (Registry change, nothing done)

                    HKEY_USERS\S-1-5-21-1214440339-2025429265-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet
                    Settings\ZoneMap\Domains\adulthell.com\*!=W=4


                    -
                    • Gość: Kolobos Re: smitfraud-c czy ktoś może pomoc-do Kolobos IP: *.warszawa.sdi.tpnet.pl 18.10.05, 23:09
                      Dziwne, masz najnowszy spybot oraz bazy do niego? Wlaczyles w nim blokowanie
                      zlych stron? To co wkleiles jest ok z tego co widze i nie powinno tego
                      wykrywac, ale jak Ci to bardzo przeszkadza to usun te wpisy z rejestru.

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka