Dodaj do ulubionych

prośba o sprawdzenie log

IP: *.neoplus.adsl.tpnet.pl 18.12.05, 19:43
Logfile of HijackThis v1.99.1
Scan saved at 19:35:39, on 2005-12-18
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
F:\WINDOWS\explorer.exe
F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Norton AntiVirus\navapsvc.exe
F:\Program Files\Norton AntiVirus\SAVScan.exe
F:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
F:\Program Files\Common Files\Symantec Shared\ccApp.exe
F:\Program Files\Microsoft AntiSpyware\gcasServ.exe
F:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
F:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
F:\Program Files\BearShare\BearShare.exe
F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
F:\Program Files\Tlen.pl\tlen.exe
F:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
F:\Program Files\TBONBin\tbon.exe
F:\Program Files\Desktop Sidebar\dsidebar.exe
F:\Program Files\Messenger\msmsgs.exe
F:\Program Files\Outlook Express\msimn.exe
F:\Program Files\Gadu-Gadu\gg.exe
F:\Program Files\Winamp\Winamp.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\Program Files\WinRAR\WinRAR.exe
F:\DOCUME~1\Dom\USTAWI~1\Temp\Rar$EX06.641\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
www.wp.pl/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
www.wp.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} -
F:\Program Files\MyWebSearch\SrchAstt\4.bin\MWSSRCAS.DLL
F2 - REG:system.ini: Shell=explorer.exe
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-
5838F569A31D} - F:\Program Files\MyWebSearch\SrchAstt\4.bin\MWSSRCAS.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - F:\Program
Files\MyWebSearch\bar\4.bin\MWSBAR.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - F:\Program
Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
F:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common Files\Symantec
Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] F:\PROGRA~1\SYMNET~1
\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [System32] "user32.exe" -user
O4 - HKLM\..\Run: [gcasServ] "F:\Program Files\Microsoft
AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] F:\Program Files\Java\jre1.5.0_04
\bin\jusched.exe
O4 - HKLM\..\Run: [AntyVirKS] f:\windows\avks.exe ukrt
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] F:\PROGRA~1\MYWEBS~1
\bar\4.bin\mwsoemon.exe
O4 - HKLM\..\Run: [BearShare] "F:\Program
Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [P2P Networking] F:\WINDOWS\system32\P2P Networking\P2P
Networking.exe /AUTOSTART
O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search &
Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Komunikator] F:\Program Files\Tlen.pl\tlen.exe
O4 - HKCU\..\Run: [tbon] F:\Program Files\TBONBin\tbon.exe /r
O4 - HKCU\..\Run: [SIDEBAR] "F:\Program Files\Desktop Sidebar\dsidebar.exe"
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] F:\PROGRA~1\MYWEBS~1
\bar\4.bin\mwsoemon.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = F:\Program
Files\MyWebSearch\bar\4.bin\MWSOEMON.EXE
O4 - Global Startup: MyWebSearch Email Plugin.lnk = F:\Program
Files\MyWebSearch\bar\4.bin\MWSOEMON.EXE
O8 - Extra context menu item: &Search -
bar.mywebsearch.com/menusearch.html?p=ZC
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-
51FB2220DF80} - F:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-
479e-9411-51FB2220DF80} - F:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9085316E-42BA-11D4-BAA3-0080C8D7ED4A} (GameDesire JungleHunter) -
67.15.101.3/g_bin/pl/hunter_2_0_0_17.cab
O16 - DPF: {A9ED6AA2-D9D4-4D71-9586-E293E2E3580B} (GameDesire
Marbles&Diamonds&Runes) - 67.15.101.3/g_bin/pl/marbles_2_0_0_22.cab
O16 - DPF: {AD7013FF-1D9A-4F36-94A6-3CD408A663F9} (GameDesire BreakOut) -
67.15.101.3/g_bin/pl/breakout_2_0_0_19.cab
O16 - DPF: {BFA1F11D-3121-AFE1-4112-894323212DAC} (GameDesire Word Games) -
67.15.101.3/g_bin/pl/words_2_0_0_36.cab
O16 - DPF: {BFA1F11D-3121-AFE1-4112-983219421AEF} (GameDesire 1Player Word
Games) - 67.15.101.3/g_bin/pl/wordssingle_2_0_0_34.cab
O16 - DPF: {E23FABEE-12E3-33DA-DA12-195DAC123984} (GameDesire Mahjong) -
67.15.101.3/g_bin/pl/mahjong_2_0_0_20.cab
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) -
67.15.101.3/g_bin/pl/billard8_2_0_0_24.cab
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C5} (GameDesire Snooker) -
67.15.101.3/g_bin/pl/snooker_2_0_0_24.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec
Corporation - F:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -
F:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Usługa Auto Protect programu Norton AntiVirus (navapsvc) -
Symantec Corporation - F:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - F:\Program Files\Norton
AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -
F:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec
Corporation - F:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - F:\Program
Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Obserwuj wątek
    • Gość: k Re: prośba o sprawdzenie log IP: *.warszawa.sdi.tpnet.pl 18.12.05, 19:51
      Odinstaluj nortona i zainstaluj avast.
      Przeskanuj system przy pomocy ewido, a po przeskanowaniu odinstaluj.

      W menadzerze zadan zakoncz:
      F:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
      F:\Program Files\TBONBin\tbon.exe

      W hijackthis usun:

      R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} -
      F:\Program Files\MyWebSearch\SrchAstt\4.bin\MWSSRCAS.DLL
      O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-
      5838F569A31D} - F:\Program Files\MyWebSearch\SrchAstt\4.bin\MWSSRCAS.DLL
      O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - F:\Program
      Files\MyWebSearch\bar\4.bin\MWSBAR.DLL
      O4 - HKLM\..\Run: [System32] "user32.exe" -user <- usun plik
      O4 - HKLM\..\Run: [AntyVirKS] f:\windows\avks.exe ukrt <- usun plik
      O4 - HKLM\..\Run: [MyWebSearch Email Plugin] F:\PROGRA~1\MYWEBS~1
      \bar\4.bin\mwsoemon.exe
      O4 - HKLM\..\Run: [P2P Networking] F:\WINDOWS\system32\P2P Networking\P2P
      Networking.exe /AUTOSTART <- usun katalog p2p networking
      O4 - HKCU\..\Run: [tbon] F:\Program Files\TBONBin\tbon.exe /r <- usun katalog
      TBONBin
      O4 - HKCU\..\Run: [MyWebSearch Email Plugin] F:\PROGRA~1\MYWEBS~1
      \bar\4.bin\mwsoemon.exe
      O4 - Startup: MyWebSearch Email Plugin.lnk = F:\Program
      Files\MyWebSearch\bar\4.bin\MWSOEMON.EXE
      O4 - Global Startup: MyWebSearch Email Plugin.lnk = F:\Program
      Files\MyWebSearch\bar\4.bin\MWSOEMON.EXE <- odinstaluj i usun caly katalog
      MyWebSearch
      O8 - Extra context menu item: &Search -
      bar.mywebsearch.com/menusearch.html?p=ZC

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka