Dodaj do ulubionych

Prosze o analize loga....

IP: *.puchaczy.waw.pl / *.puchaczy.waw.pl 26.11.05, 22:33
Ogolnie wyskauja mi stronki www i nie wiem co z tym zrobic :/

Logfile of HijackThis v1.99.1
Scan saved at 22:30:16, on 2005-11-26
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\AntiVirenKit\AVKService.exe
C:\Program Files\AntiVirenKit\AVKWCtl.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Lexmark 5200 series\lxbtbmon.exe
C:\Program Files\Shareaza\Shareaza.exe
C:\PROGRA~1\COMMON~1\ooro\oorom.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\BitTorrent\btdownloadgui.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Majkel\USTAWI~1\Temp\Rar$EX00.484\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Super Ad Blocker Toolbar - {B4B3001E-0F56-4E51-8250-
BDE11547EC55} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\sabtb.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [Lexmark 5200 series] "C:\Program Files\Lexmark 5200
series\lxbtbmgr.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SysMemory manager] c:\windows\system32\mdms.exe
O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\System32\paytime.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Update] msconfg.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web
Folders\ibm00001.exe"
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\System32\paytime.exe
O4 - HKCU\..\Run: [klop] C:\WINDOWS\E.tmp
O4 - HKCU\..\Run: [ooro] C:\PROGRA~1\COMMON~1\ooro\oorom.exe
O4 - HKCU\..\Run: [AVKBar] "C:\Program Files\AntiVirenKit\AVKBar.exe"
O4 - HKCU\..\Run: [SuperAdBlocker] C:\Program Files\SuperAdBlocker.com\Super
Ad Blocker\SAdBlock.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program
Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office10\OSA.EXE
O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
skaner.mks.com.pl/SkanerOnline.cab
O20 - Winlogon Notify: CSCSettings - C:\WINDOWS\system32\m2julc191f.dll
O20 - Winlogon Notify: SABWinLogon - C:\Program
Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL
O21 - SSODL: SysTray.Excn2 - {1722ECFF-4356-4f5b-B534-E67294FE75E9} -
C:\WINDOWS\System32\lndcdcjc.dll (file missing)
O21 - SSODL: SysTray.Exsn - {2368D1FC-2F5C-4f1b-B124-E67214FC78E2} -
C:\WINDOWS\System32\mbknapho.dll (file missing)
O23 - Service: AVK Service (AVKService) - Unknown owner - C:\Program
Files\AntiVirenKit\AVKService.exe
O23 - Service: Strażnik AVK (AVKWCtl) - Unknown owner - C:\Program
Files\AntiVirenKit\AVKWCtl.exe
O23 - Service: lxbt_device - Lexmark International, Inc. - C:\WINDOWS\System32
\lxbtcoms.exe
O23 - Service: Super Ad Blocker Service (SABSVC) - SuperAdBlocker.com -
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE



Obserwuj wątek
    • Gość: k Re: Prosze o analize loga.... IP: *.warszawa.sdi.tpnet.pl 27.11.05, 08:47
      Masz piracki windows! Zmien przegladarke na Opere (znajdziesz na google) i nie
      uzywaj wiecej IE!
      Zamknij porty tym:
      www.firewallleaktester.com/tools/wwdc.exe
      Zakoncz proces:
      C:\PROGRA~1\COMMON~1\ooro\oorom.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
      c:\secure32.html
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      c:\secure32.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
      c:\secure32.html
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
      c:\secure32.html
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      c:\secure32.html
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      c:\secure32.html <- usun plik
      O4 - HKLM\..\Run: [SysMemory manager] c:\windows\system32\mdms.exe <- opis
      usuwania tutaj:
      www.searchengines.pl/phpbb203/index.php?showtopic=12510&pid=188758&mode=threaded&show=&st=30&#entry188758
      O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\System32\paytime.exe
      O4 - HKCU\..\Run: [Microsoft Update] msconfg.exe <- usun plik
      O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web
      Folders\ibm00001.exe" <- usun katalog
      O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe <- usun plik
      O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\System32\paytime.exe <- usun plik
      O4 - HKCU\..\Run: [klop] C:\WINDOWS\E.tmp <- usun plik
      O4 - HKCU\..\Run: [ooro] C:\PROGRA~1\COMMON~1\ooro\oorom.exe <- usun katalog
      ooro
      O20 - Winlogon Notify: CSCSettings - C:\WINDOWS\system32\m2julc191f.dll <-
      uninstaller do look2me masz tutaj:
      www.pchell.com/support/look2me.shtml jakby nie zadzialal to:
      forum.gazeta.pl/forum/72,2.html?f=430&w=32586630&a=32593198
      O21 - SSODL: SysTray.Excn2 - {1722ECFF-4356-4f5b-B534-E67294FE75E9} -
      C:\WINDOWS\System32\lndcdcjc.dll (file missing)
      O21 - SSODL: SysTray.Exsn - {2368D1FC-2F5C-4f1b-B124-E67214FC78E2} -
      C:\WINDOWS\System32\mbknapho.dll (file missing)

      Na koniec skan tym:
      download.ewido.net/ewido-setup.exe <- zrob update przed skanowaniem, po
      przeskanowaniu odinstaluj.

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka