Dodaj do ulubionych

bardzo prosze o pomoc

IP: 217.153.221.* 19.10.05, 20:50
Logfile of HijackThis v1.99.1
Scan saved at 20:49:45, on 2005-10-19
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Winamp\Winampa.exe
C:\Program Files\D-Tools\daemon.exe
C:\WINDOWS\sachostx.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\System32\sachostb.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Sławko\Pulpit\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - Default URLSearchHook is missing
O2 - BHO: C:\WINDOWS\system32\st3.dll - {1B68470C-2DEF-493B-8A4A-
8E2D81BE4EA5} - C:\WINDOWS\system32\st3.dll
O2 - BHO: C:\WINDOWS\q1429546.dll - {7A7E6D97-B492-4884-9ABB-C31281DCC4F2} -
C:\WINDOWS\q1429546.dll (file missing)
O2 - BHO: C:\WINDOWS\adsldpbc.dll - {D7171221-2DE4-40D8-ABAE-4E0480CE5C2B} -
C:\WINDOWS\adsldpbc.dll (file missing)
O2 - BHO: Internet Explorer Web Content Catcher - {FFF4E223-7019-4ce7-BE03-
D7D3C8CCE884} - C:\Program Files\DNS\Catcher.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control
Panel\atiptaxx.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -
lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Bfdugicw] C:\Program Files\Wuzqdx\Rqhmt.exe
O4 - HKLM\..\Run: [MsUpdate] C:\Program Files\MsUpdate\MsUpdate.exe /auto
O4 - HKLM\..\Run: [MsMovies] C:\Program Files\MsMovies\MsMovies.exe /auto
O4 - HKLM\..\Run: [SysMemory manager] c:\windows\system32\mdms.exe
O4 - HKLM\..\Run: [updatedrweb_nt] C:\WINDOWS\System32\updatedrweb_nt.exe
O4 - HKLM\..\Run: [HostSrv] C:\WINDOWS\sachostx.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft
AntiSpyware\gcasServ.exe"
O4 - HKLM\..\RunServices: [updatedrweb_nt] C:\WINDOWS\System32
\updatedrweb_nt.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web
Folders\ibm00001.exe"
O4 - HKCU\..\Run: [updatedrweb_nt] C:\WINDOWS\System32\updatedrweb_nt.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office10\OSA.EXE
O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O15 - Trusted Zone: *.coolwebsearch.com
O15 - Trusted Zone: *.searchmeup.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120832597984
O20 - Winlogon Notify: st3 - C:\WINDOWS\system32\st3.dll
O20 - Winlogon Notify: style32 - C:\WINDOWS\q1429546.dll (file missing)
O20 - Winlogon Notify: tcpG4T - tcpG4T.dll (file missing)
O21 - SSODL: SysTray.Exys - {7368D5FC-6F5C-4f5b-B964-E67214F67852} -
C:\WINDOWS\System32\qmfhhjpl.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32
\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program
Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program
Files\ewido\security suite\ewidoguard.exe

Obserwuj wątek
    • browanx Re: bardzo prosze o pomoc 19.10.05, 21:29
      stary gdziesz ty był z tym kompem?
    • Gość: Kolobos Re: bardzo prosze o pomoc IP: *.warszawa.sdi.tpnet.pl 19.10.05, 21:42
      Zakoncz procesy:
      C:\WINDOWS\sachostx.exe
      C:\WINDOWS\System32\sachostb.exe

      W hijackthis:

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      c:\secure32.html <- usun plik.
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
      c:\secure32.html
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      c:\secure32.html
      R3 - Default URLSearchHook is missing
      O2 - BHO: C:\WINDOWS\system32\st3.dll - {1B68470C-2DEF-493B-8A4A-
      8E2D81BE4EA5} - C:\WINDOWS\system32\st3.dll <- usun plik
      O2 - BHO: C:\WINDOWS\q1429546.dll - {7A7E6D97-B492-4884-9ABB-C31281DCC4F2} -
      C:\WINDOWS\q1429546.dll (file missing)
      O2 - BHO: C:\WINDOWS\adsldpbc.dll - {D7171221-2DE4-40D8-ABAE-4E0480CE5C2B} -
      C:\WINDOWS\adsldpbc.dll (file missing)
      O2 - BHO: Internet Explorer Web Content Catcher - {FFF4E223-7019-4ce7-BE03-
      D7D3C8CCE884} - C:\Program Files\DNS\Catcher.dll <- usun katalog DNS.
      O4 - HKLM\..\Run: [Bfdugicw] C:\Program Files\Wuzqdx\Rqhmt.exe <- usun katalog
      Wuz..
      O4 - HKLM\..\Run: [MsUpdate] C:\Program Files\MsUpdate\MsUpdate.exe /auto
      O4 - HKLM\..\Run: [MsMovies] C:\Program Files\MsMovies\MsMovies.exe /auto
      O4 - HKLM\..\Run: [SysMemory manager] c:\windows\system32\mdms.exe <- usun plik
      + opis usuwania:
      securityresponse.symantec.com/avcenter/venc/data/trojan.repsamo.html
      O4 - HKLM\..\Run: [updatedrweb_nt] C:\WINDOWS\System32\updatedrweb_nt.exe
      O4 - HKLM\..\Run: [HostSrv] C:\WINDOWS\sachostx.exe <- usun plik
      O4 - HKLM\..\RunServices: [updatedrweb_nt] C:\WINDOWS\System32
      \updatedrweb_nt.exe
      O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web
      Folders\ibm00001.exe" <- usun plik, po usunieciu sciagnij i uruchom:
      www.kellys-korner-xp.com/regs_edits/exefix.reg
      O4 - HKCU\..\Run: [updatedrweb_nt] C:\WINDOWS\System32\updatedrweb_nt.exe <-
      usun plik
      O15 - Trusted Zone: *.coolwebsearch.com
      O15 - Trusted Zone: *.searchmeup.com
      O20 - Winlogon Notify: st3 - C:\WINDOWS\system32\st3.dll <- usun plik
      O20 - Winlogon Notify: style32 - C:\WINDOWS\q1429546.dll (file missing)
      O20 - Winlogon Notify: tcpG4T - tcpG4T.dll (file missing) <- opis usuwania
      tutaj:
      forum.gazeta.pl/forum/72,2.html?f=430&w=30500900&a=30506784
      O21 - SSODL: SysTray.Exys - {7368D5FC-6F5C-4f5b-B964-E67214F67852} -
      C:\WINDOWS\System32\qmfhhjpl.dll <- usun plik

      ewido odinstaluj i wklej nowy log.

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka