Dodaj do ulubionych

prosze o sprawdzenie loga

IP: *.nyc.res.rr.com 11.12.05, 03:24
wyskakuja niechciane reklamy typu:winfixer
2005,oidnaserver,screenserver/christmas/,oferty roznych produktow.komputer
spowolnial.Programy spybot i spy sweeper wykryly duzo szkodnikow ktore
usunieto ale w dalszy ciagu popups wyskakuja.Bardzo prosze o instrukcje.
moj log:Logfile of HijackThis v1.99.1
Scan saved at 7:50:04 PM, on 12/10/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\COMPAQ\INTERNET\ISDBDC.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\MCTOOL.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\ptsnoop.exe
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\COMPAQ\CPQINET\CPQINET.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\PROGRAM FILES\ODOC\MEOH.EXE
C:\WINDOWS\SYSTEM\QUHD.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\EAUSBKBD.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\YZK31AJY\HIJACKTHIS[1].EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
desktop.presario.net/scripts/redirectors/presario/deskredir.dll?s=consumer&LC=0409&c=1c00
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
www.rr.com/html/index.cfm?p=16&m=92
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
search.presario.net/scripts/redirectors/presario/srchredir.dll?c=1c00&s=searchbar&LC=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft
Internet Explorer provided by Roadrunner
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = 127.0.0.1;<local>
O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} -
C:\WINDOWS\SYSTEM\NZDD.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [VsecomrEXE] C:\Program Files\Network Associates\McAfee
VirusScan\VSEcomR.EXE
O4 - HKLM\..\Run: [VsStatEXE] C:\Program Files\Network Associates\McAfee
VirusScan\VSSTAT.EXE /SHOWWARNING
O4 - HKLM\..\Run: [CPQInet] c:\compaq\CPQInet\CpqInet.exe
O4 - HKLM\..\Run: [cpqns] c:\compaq\cpqinet\cpqnpcss.exe
O4 - HKLM\..\Run: [CompaqPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [LVComs] c:\windows\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [Vshwin32EXE] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE
VIRUSSCAN\VSHWIN32.EXE
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\realplay.exe
SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [isdbdc] c:\compaq\internet\isdbdc.exe
O4 - HKLM\..\RunServices: [Vshwin32EXE] C:\PROGRAM FILES\NETWORK
ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKCU\..\Run: [Wsea] "C:\Program Files\odoc\meoh.exe" -vt ndrv
O4 - HKCU\..\Run: [Vey] C:\WINDOWS\SYSTEM\quhd.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box -
C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O9 - Extra button: Translate - {06FE5D05-8F11-11d2-804F-00105A133818} -
search.presario.net/scripts/redirectors/presario/srchredir.dll?
s=avbabelfish&c=1c00&lc=0409 (file missing)
O9 - Extra 'Tools' menuitem: AV &Translate - {06FE5D05-8F11-11d2-804F-
00105A133818} -
search.presario.net/scripts/redirectors/presario/srchredir.dll?
s=avbabelfish&c=1c00&lc=0409 (file missing)
O9 - Extra button: (no name) - {06FE5D02-8F11-11d2-804F-00105A133818} -
search.presario.net/scripts/redirectors/presario/srchredir.dll?
s=avlinksearch&c=1c00&lc=0409 (file missing)
O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL - {06FE5D02-8F11-
11d2-804F-00105A133818} -
search.presario.net/scripts/redirectors/presario/srchredir.dll?
s=avlinksearch&c=1c00&lc=0409 (file missing)
O9 - Extra button: (no name) - {06FE5D03-8F11-11d2-804F-00105A133818} -
search.presario.net/scripts/redirectors/presario/srchredir.dll?
s=avhostsearch&c=1c00&lc=0409 (file missing)
O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host - {06FE5D03-8F11-
11d2-804F-00105A133818} -
search.presario.net/scripts/redirectors/presario/srchredir.dll?
s=avhostsearch&c=1c00&lc=0409 (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program
Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} -
C:\Program Files\ICQ\ICQ.exe
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .swf: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin7.dll
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager
Class) - www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab

Obserwuj wątek
    • Gość: k Re: prosze o sprawdzenie loga IP: *.warszawa.sdi.tpnet.pl 11.12.05, 16:59
      Usun w hijackthis:

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
      desktop.presario.net/scripts/redirectors/presario/deskredir.dll?
      s=consumer&LC=0409&c=1c00
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
      about:blank
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      www.rr.com/html/index.cfm?p=16&m=92
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
      search.presario.net/scripts/redirectors/presario/srchredir.dll?
      c=1c00&s=searchbar&LC=0409
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      about:blank
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft
      Internet Explorer provided by Roadrunner
      O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} -
      C:\WINDOWS\SYSTEM\NZDD.DLL <- usun plik
      O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe <- usun plik
      O4 - HKCU\..\Run: [Wsea] "C:\Program Files\odoc\meoh.exe" -vt ndrv <- usun
      katalog odoc
      O4 - HKCU\..\Run: [Vey] C:\WINDOWS\SYSTEM\quhd.exe <- usun plik
      O9 - Extra button: Translate - {06FE5D05-8F11-11d2-804F-00105A133818} -
      search.presario.net/scripts/redirectors/presario/srchredir.dll?
      s=avbabelfish&c=1c00&lc=0409 (file missing)
      O9 - Extra 'Tools' menuitem: AV &Translate - {06FE5D05-8F11-11d2-804F-
      00105A133818} -
      search.presario.net/scripts/redirectors/presario/srchredir.dll?
      s=avbabelfish&c=1c00&lc=0409 (file missing)
      O9 - Extra button: (no name) - {06FE5D02-8F11-11d2-804F-00105A133818} -
      search.presario.net/scripts/redirectors/presario/srchredir.dll?
      s=avlinksearch&c=1c00&lc=0409 (file missing)
      O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL - {06FE5D02-8F11-
      11d2-804F-00105A133818} -
      search.presario.net/scripts/redirectors/presario/srchredir.dll?
      s=avlinksearch&c=1c00&lc=0409 (file missing)
      O9 - Extra button: (no name) - {06FE5D03-8F11-11d2-804F-00105A133818} -
      search.presario.net/scripts/redirectors/presario/srchredir.dll?
      s=avhostsearch&c=1c00&lc=0409 (file missing)
      O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host - {06FE5D03-8F11-
      11d2-804F-00105A133818} -
      search.presario.net/scripts/redirectors/presario/srchredir.dll?
      s=avhostsearch&c=1c00&lc=0409 (file missing)

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka