Sprawdzenie loga z Hijack This

IP: 217.149.242.* 22.11.05, 10:16
Logfile of HijackThis v1.99.1
Scan saved at 10:14:36, on 2005-11-22
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Kazaa Lite Rewolucja\kazaalite.kpp
C:\WINDOWS\EXPLORER.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Documents and Settings\KucharczykN\Pulpit\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
www.onet.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat 5.0 CE\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone
Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [RemoteControl] "C:\Program
Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [Skype] "C:\Program
Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office\OSA9.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage
Validation Tool) - go.microsoft.com/fwlink/?linkid=39204
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner -
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil
Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil
Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil
Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC -
C:\WINDOWS\system32\ZONELABS\vsmon.exe

    • neder Re: Sprawdzenie loga z Hijack This 22.11.05, 10:20
      wygląda ok
      pzdr
      • Gość: GawrychM Re: Sprawdzenie loga z Hijack This IP: 217.149.242.* 22.11.05, 10:27
        Może ktoś w takim razie może mi pomóc. Przy uruchamianiu praktycznie wszystkich
        gier dla dziecka pojawia się komunikat "Wystąpił problem z aplikacją
        Explorer.exe i zostanie ona zamknięta". Co jeszcze dziwniejsze jedyna gra w
        którą ja gram Fottball Manager uruchamia się bez problemu.
        Pozdrawiam
        • srull Re: Sprawdzenie loga z Hijack This 22.11.05, 19:51
          Ja Ci nie pomoge, podczepie sie pod watek, bo z tym zamykaniem sam tez mam
          czesto klopot. Oto moj log:

          Logfile of HijackThis v1.99.1
          Scan saved at 19:49:33, on 2005-11-22
          Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
          C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
          C:\Program Files\Norton AntiVirus\navapsvc.exe
          C:\Program Files\Norton Personal Firewall\NISUM.EXE
          C:\Program Files\Logitech\iTouch\iTouch.exe
          C:\Program Files\Common Files\Symantec Shared\ccApp.exe
          C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
          C:\Program Files\Norton Personal Firewall\IAMAPP.EXE
          C:\Program Files\Gadu-Gadu\gg.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Norton Personal Firewall\SymProxySvc.exe
          C:\Program Files\Norton Personal Firewall\NISSERV.EXE
          C:\Program Files\Norton Personal Firewall\ATRACK.EXE
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Documents and Settings\Piotr\Pulpit\HI JACK\hijackthis.com

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
          www.interia.pl/
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
          C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
          O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program
          Files\Norton AntiVirus\NavShExt.dll
          O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
          C:\Program Files\Norton AntiVirus\NavShExt.dll
          O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
          C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
          O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec
          Shared\ccRegVfy.exe"
          O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
          O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
          /Consumer
          O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Personal Firewall\IAMAPP.EXE
          O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
          O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
          O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
          res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O8 - Extra context menu item: Pobierz używając Download &Express'a - C:\Program
          Files\Download Express\Add_Url.htm
          O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
          C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
          C:\Program Files\Messenger\msmsgs.exe (file missing)
          O9 - Extra 'Tools' menuitem: Windows Messenger -
          {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          (file missing)
          O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) -
          www.cult3d.com/download/cult.cab
          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
          C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
          O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec
          Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
          O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program
          Files\Executive Software\DiskeeperWorkstation\DKService.exe
          O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec
          Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
          O23 - Service: Norton Personal Firewall Service (NISSERV) - Symantec Corporation
          - C:\Program Files\Norton Personal Firewall\NISSERV.EXE
          O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec
          Corporation - C:\Program Files\Norton Personal Firewall\NISUM.EXE
          O23 - Service: Norton Unerase Protection (NProtectService) - Symantec
          Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
          O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -
          C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
          O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation
          - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
          O23 - Service: Norton Personal Firewall Proxy Service (SymProxySvc) - Symantec
          Corporation - C:\Program Files\Norton Personal Firewall\SymProxySvc.exe
          O23 - Service: SymWMI Service (SymWSC) - Unknown owner - C:\Program Files\Common
          Files\Symantec Shared\Security Center\SymWSC.exe (file missing)
          • neder Re: Sprawdzenie loga z Hijack This 22.11.05, 22:20
            loga raczej nie podczepiaj do innych bo jak widac trudno Cię tu znaleźć ;)
            Log wygląda ok, ale powodów błędów z explorer.exe może być zapewne całe mnóstwo.
            Zobacz, czy jakiś proces nie obciąża Ci procesora, sprawdź temperatury
            (programem everest), być może też trzeba będzie sprawdzić pamięć programem
            memtest (link i opis w FAQ Forum Komputery). Zaglądałeś do podglądu zdarzeń
            (Panel Sterowania->Narzędzia Administracyjne?
            • srull Re: Sprawdzenie loga z Hijack This 23.11.05, 20:14
              Neder (bez siusiaka:)), dzieki. Z everestu juz korzystalem - wszystko OK, z
              podgladem zdarzen wlasnie sie zaznajamiam, do memtestu zabiore sie w wolnej
              chwilce (to chyba rzeczywiscie moze byc "to"). Dzieki raz jeszcze za "pomocna
              dlon".
Pełna wersja