PROSZE O SPRAWDZENIE LOGA

IP: *.e-wro.net.pl 13.01.06, 15:45
mam problem z wirusami (a raczej z trojanami) bo avast je wykrywa, ale nie
może ich usunąć: "win 32 Trojan-gen", "Win32:SpyBotA-3230", "Win32:Hidewnd"
i "Win32:Rbot-ARL"
Prosze o sprawdzenie loga i powoiedzenie czyy już mam sformatować dysk..


Logfile of HijackThis v1.99.1
Scan saved at 15:32:29, on 2006-01-13
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvraidservice.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
D:\Programy\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\System32\grplscd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\iobuw.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\System32\wuamgr0.exe
C:\WINDOWS\System32\MSNplus.pif
C:\WINDOWS\System32\ctfmon.exe
D:\Programy\Gadu-Gadu\gg.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
d:\Programy\Alwil Software\Avast4\aswUpdSv.exe
d:\Programy\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\axdcfasb.exe
C:\Program Files\iPod\bin\iPodService.exe
d:\Programy\Alwil Software\Avast4\ashWebSv.exe
d:\Programy\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Programy\Mistrz Bo\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
gazeta.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\System32\nvraidservice.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control
Panel\atiptaxx.exe
O4 - HKLM\..\Run: [avast!] d:\Programy\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Virtual CD v6] grplscd.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -
atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [Diam prosessor] iobuw.exe
O4 - HKLM\..\Run: [REGEDIT] C:\WINDOWS\System32\system Drive\zlip25.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05
\bin\jusched.exe
O4 - HKLM\..\Run: [Microsoft Machine] wuamgr0.exe
O4 - HKLM\..\Run: [WinDLL (svchost.dll)] rundll32.exe C:\WINDOWS\System32
\svchost.dll,start
O4 - HKLM\..\Run: [MSN Messenger] MSNplus.pif
O4 - HKLM\..\RunServices: [Virtual CD v6] grplscd.exe
O4 - HKLM\..\RunServices: [Diam prosessor] iobuw.exe
O4 - HKLM\..\RunServices: [Microsoft Machine] wuamgr0.exe
O4 - HKLM\..\RunServices: [MSN Messenger] MSNplus.pif
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Gadu-Gadu] "D:\Programy\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-
88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [REGEDIT] C:\WINDOWS\System32\system Drive\zlip25.exe
O4 - HKCU\..\Run: [Microsoft Machine] wuamgr0.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O12 - Plugin for .spop: C:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner -
d:\Programy\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32
\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - Unknown owner - d:\Programy\Alwil
Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - d:\Programy\Alwil
Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - d:\Programy\Alwil
Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision
Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32
\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program
Files\iPod\bin\iPodService.exe
O23 - Service: sdktemp - Unknown owner - C:\WINDOWS\axdcfasb.exe
    • Gość: mmx Re: PROSZE O SPRAWDZENIE LOGA IP: *.acn.waw.pl 13.01.06, 15:51
      Przede wszystkim zaktualizuj najpierw system.
    • Gość: MistrzBo Re: PROSZE O SPRAWDZENIE LOGA IP: *.e-wro.net.pl 13.01.06, 16:25
      zaktualizowałem, lecz miałem problem z zainstalowaniem Narzędzia Usługi
      inteligentnego transferu w tle (BITS) 2.0 (KB842773. Oto log jaki teraz
      zrobiłem:


      Logfile of HijackThis v1.99.1
      Scan saved at 16:23:16, on 2006-01-13
      Platform: Windows XP (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 (6.00.2600.0000)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\System32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\System32\nvraidservice.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      D:\Programy\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\System32\grplscd.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\WINDOWS\System32\iobuw.exe
      C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
      C:\WINDOWS\System32\wuamgr0.exe
      C:\WINDOWS\System32\MSNplus.pif
      C:\WINDOWS\System32\ctfmon.exe
      C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
      d:\Programy\Alwil Software\Avast4\aswUpdSv.exe
      d:\Programy\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\axdcfasb.exe
      C:\Program Files\iPod\bin\iPodService.exe
      d:\Programy\Alwil Software\Avast4\ashWebSv.exe
      d:\Programy\Alwil Software\Avast4\ashMaiSv.exe
      C:\WINDOWS\System32\wbem\unsecapp.exe
      C:\WINDOWS\system32\cmd.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\WINDOWS\System32\wuauclt.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      D:\Programy\Mistrz Bo\hijackthis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      gazeta.pl/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
      C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
      C:\WINDOWS\System32\msdxm.ocx
      O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\System32\nvraidservice.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control
      Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [avast!] d:\Programy\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [Virtual CD v6] grplscd.exe
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -
      atboottime
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe
      O4 - HKLM\..\Run: [Diam prosessor] iobuw.exe
      O4 - HKLM\..\Run: [REGEDIT] C:\WINDOWS\System32\system Drive\zlip25.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05
      \bin\jusched.exe
      O4 - HKLM\..\Run: [Microsoft Machine] wuamgr0.exe
      O4 - HKLM\..\Run: [WinDLL (svchost.dll)] rundll32.exe C:\WINDOWS\System32
      \svchost.dll,start
      O4 - HKLM\..\Run: [MSN Messenger] MSNplus.pif
      O4 - HKLM\..\RunServices: [Virtual CD v6] grplscd.exe
      O4 - HKLM\..\RunServices: [Diam prosessor] iobuw.exe
      O4 - HKLM\..\RunServices: [Microsoft Machine] wuamgr0.exe
      O4 - HKLM\..\RunServices: [MSN Messenger] MSNplus.pif
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [Gadu-Gadu] "D:\Programy\Gadu-Gadu\gg.exe" /tray
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-
      88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [REGEDIT] C:\WINDOWS\System32\system Drive\zlip25.exe
      O4 - HKCU\..\Run: [Microsoft Machine] wuamgr0.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
      Office\Office\OSA9.EXE
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
      C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
      00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
      O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
      update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1137164302764
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner -
      d:\Programy\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32
      \Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: avast! Antivirus - Unknown owner - d:\Programy\Alwil
      Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - Unknown owner - d:\Programy\Alwil
      Software\Avast4\ashMaiSv.exe" /service (file missing)
      O23 - Service: avast! Web Scanner - Unknown owner - d:\Programy\Alwil
      Software\Avast4\ashWebSv.exe" /service (file missing)
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision
      Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32
      \IDriverT.exe
      O23 - Service: iPodService - Apple Computer, Inc. - C:\Program
      Files\iPod\bin\iPodService.exe
      O23 - Service: sdktemp - Unknown owner - C:\WINDOWS\axdcfasb.exe

      • Gość: mmx Re: PROSZE O SPRAWDZENIE LOGA IP: *.acn.waw.pl 13.01.06, 16:33
        > zaktualizowałem, lecz miałem problem z zainstalowaniem Narzędzia Usługi
        > inteligentnego transferu w tle (BITS) 2.0 (KB842773.

        Czyli nic nie zaktualizowales bo nowsze poprawki wymagaja wlasnie
        zainstalowania BITS. W dalszym ciagu masz system bez poprawek czy chociazby SP1.
        • Gość: gość Re: PROSZE O SPRAWDZENIE LOGA IP: *.neoplus.adsl.tpnet.pl 13.01.06, 18:51
          robaki ci zjadają kompa zapraszam tu
          www.tncsystem.info/forum/viewforum.php?f=6
Pełna wersja