Dodaj do ulubionych

Prosze o sprawdzenie loga

IP: *.neoplus.adsl.tpnet.pl 10.02.06, 11:10
Logfile of HijackThis v1.99.1
Scan saved at 09:39:22, on 06-02-10
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\WANADOO\TASKBARICON.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\PROGRAM FILES\MEDIA ACCESS\MEDIAACCK.EXE
C:\PROGRAM FILES\VVSN\VVSN.EXE
C:\PROGRAM FILES\MEDIA ACCESS\MEDIAACCESS.EXE
C:\WINDOWS\WINSYSBAN7.EXE
C:\WINDOWS\SYSTEM\ABJZ.EXE
C:\PROGRAM FILES\ODAO\IEAW.EXE
C:\WINSTALL.EXE
C:\PROGRAM FILES\SAGEM\SAGEM F@ST 800-840\DSLMON.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\LOADWC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGWB.DAT
C:\PROGRAM FILES\WANADOO\ESPACEWANADOO.EXE
C:\PROGRAM FILES\WANADOO\COMCOMP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\WANADOO\WATCH.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\PROGRAM FILES\MYIE2\MYIE.EXE
C:\WINDOWS\TEMP\WIN1011.TMP.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\WINRAR\WINRAR.EXE
C:\WINDOWS\TEMP\RAR$EX00.541\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
about:NavigationFailure
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada
Plus wita Cie w Internecie
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: (no name) - {991C0141-EFA3-EF51-D10B-BF3EC2227597} -
C:\WINDOWS\SYSTEM\OTAFML.DLL
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no
file)
F1 - win.ini: run=hpfsched
O1 - Hosts: 127.0.0.5 makethemcry.com
O1 - Hosts: 127.0.0.5 loudcash.com
O1 - Hosts: 127.0.0.5 iframestat.com
O1 - Hosts: 127.0.0.5 toolbarpartner.com
O1 - Hosts: 127.0.0.5 hqcash.com
O1 - Hosts: 127.0.0.5 verybigcash.com
O1 - Hosts: 127.0.0.5 makethemcry.com
O1 - Hosts: 127.0.0.5 moviepartnership.com
O1 - Hosts: 127.0.0.5 callmachine.com
O1 - Hosts: 127.0.0.5 regcash.com
O1 - Hosts: 127.0.0.5 toolbarpartner.com
O1 - Hosts: 127.0.0.5 klikrevenue.com
O1 - Hosts: 127.0.0.5 p2dll.com
O1 - Hosts: 127.0.0.5 t73.com
O1 - Hosts: 127.0.0.5 www.makethemcry.com
O1 - Hosts: 127.0.0.5 www.loudcash.com
O1 - Hosts: 127.0.0.5 www.iframestat.com
O1 - Hosts: 127.0.0.5 www.toolbarpartner.com
O1 - Hosts: 127.0.0.5 www.hqcash.com
O1 - Hosts: 127.0.0.5 www.verybigcash.com
O1 - Hosts: 127.0.0.5 www.makethemcry.com
O1 - Hosts: 127.0.0.5 www.moviepartnership.com
O1 - Hosts: 127.0.0.5 www.callmachine.com
O1 - Hosts: 127.0.0.5 www.regcash.com
O1 - Hosts: 127.0.0.5 www.toolbarpartner.com
O1 - Hosts: 127.0.0.5 www.klikrevenue.com
O1 - Hosts: 127.0.0.5 www.p2dll.com
O1 - Hosts: 127.0.0.5 www.t73.com.0.0.5 www.megapornix.com
O1 - Hosts: 127.0.0.5 megapornix.com
O1 - Hosts: 127.0.0.5 www.sp2fucked.biz
O1 - Hosts: 127.0.0.5 sp2fucked.biz
O1 - Hosts: 127.0.0.5 greg-tut.com
O1 - Hosts: 127.0.0.5 www.greg-tut.com
O1 - Hosts: 127.0.0.5 nylonsexy.com
O1 - Hosts: 127.0.0.5 www.nylonsexy.com
O1 - Hosts: 127.0.0.5 vparivalka.com
O1 - Hosts: 127.0.0.5 www.vparivalka.com
O1 - Hosts: 127.0.0.5 iframeprofit.com
O1 - Hosts: 127.0.0.5 www.iframeprofit.com
O1 - Hosts: 127.0.0.5 topsearch10.com
O1 - Hosts: 127.0.0.5 www.topsearch10.com
O1 - Hosts: 127.0.0.5 statscash.biz
O1 - Hosts: 127.0.0.5 www.statscash.biz
O1 - Hosts: 127.0.0.5 vxiframe.biz
O1 - Hosts: 127.0.0.5 www.vxiframe.biz
O1 - Hosts: 127.0.0.5 crazy-toolbar.com
O1 - Hosts: 127.0.0.5 www.crazy-toolbar.com
O1 - Hosts: 127.0.0.5 topcash.biz
O1 - Hosts: 127.0.0.5 www.topcash.biz
O1 - Hosts: 127.0.0.5 loadcash.biz
O1 - Hosts: 127.0.0.5 www.loadcash.biz
O1 - Hosts: 127.0.0.5 txiframe.biz
O1 - Hosts: 127.0.0.5 www.txiframe.biz
O1 - Hosts: 127.0.0.5 procounter.biz
O1 - Hosts: 127.0.0.5 www.procounter.biz
O1 - Hosts: 127.0.0.5 advadmin.biz
O1 - Hosts: 127.0.0.5 www.advadmin.biz
O1 - Hosts: 127.0.0.5 trafficbest.net
O1 - Hosts: 127.0.0.5 www.trafficbest.net
O1 - Hosts: 127.0.0.5 besthvac.com
O1 - Hosts: 127.0.0.5 www.besthvac.com
O1 - Hosts: 127.0.0.5 traff4.com
O1 - Hosts: 127.0.0.5 www.traff4.com
O1 - Hosts: 127.0.0.5 ambush-script.com
O1 - Hosts: 127.0.0.5 www.ambush-script.com
O1 - Hosts: 127.0.0.5 beehappyy.biz
O1 - Hosts: 127.0.0.5 www.beehappyy.biz
O1 - Hosts: 127.0.0.5 tracktraff.cc
O1 - Hosts: 127.0.0.5 www.tracktraff.cc
O1 - Hosts: 127.0.0.5 allcount.net
O1 - Hosts: 127.0.0.5 www.allcount.net
O1 - Hosts: 127.0.0.5 onedayoffer.biz
O1 - Hosts: 127.0.0.5 www.onedayoffer.biz27.0.0.1 classic.adlink.de
O3 - Toolbar: (no name) - {6b95678d-30a4-4ff8-a72f-4208340c1f7f} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-
3FFD8020233E} - C:\PROGRAM FILES\THESEARCHACCELERATOR\UCMTSAIE.DLL
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [autoclk] autoclk.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\WANADOO\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\WANADOO\TaskbarIcon.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\PROGRAM FILES\WINAMP\WINAMPa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [KAZAA] "D:\KAZAA LITE REWOLUCJA\KPP.EXE" "D:\KAZAA LITE
REWOLUCJA\KAZAALITE.KPP" /SYSTRAY
O4 - HKLM\..\Run: [SunServer] C:\PROGRAM FILES\SUNB
Obserwuj wątek
    • Gość: Ash Prosze o sprawdzenie loga\ciąg dalszy loga IP: *.neoplus.adsl.tpnet.pl 10.02.06, 11:26
      O4 - HKLM\..\Run: [SunServer] C:\PROGRAM FILES\SUNBELT
      SOFTWARE\COUNTERSPY\CONSUMER\sunserver.exe
      O4 - HKLM\..\Run: [Media Access] C:\PROGRAM FILES\MEDIA ACCESS\MediaAccK.exe
      O4 - HKLM\..\Run: [VVSN] C:\PROGRAM FILES\VVSN\VVSN.EXE
      O4 - HKLM\..\Run: [winsysupd] C:\WINDOWS\WINSYSUPD7.exe
      O4 - HKLM\..\Run: [winzmc32] rundll32 winzmc32.dll,run
      O4 - HKLM\..\Run: [gimmygames] C:\WINDOWS\GIMMYGAMES.exe
      O4 - HKLM\..\Run: [winsysban] C:\WINDOWS\WINSYSBAN7.exe
      O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe
      powrprof.dll,LoadCurrentPwrScheme
      O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
      O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
      O4 - HKCU\..\Run: [Qisyflnp] C:\WINDOWS\SYSTEM\abjz.exe
      O4 - HKCU\..\Run: [Gadu-Gadu] "E:\GADU-GADU\GG.EXE" /tray
      O4 - HKCU\..\Run: [Oewt] "C:\Program Files\odao\ieaw.exe" -vt ndrv
      O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
      O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
      Office\Office\OSA9.EXE
      O4 - Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
      O4 - Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
      Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O15 - Trusted Zone: *.windupdates.com
      O15 - Trusted Zone: *.searchmiracle.com
      O15 - Trusted Zone: *.skoobidoo.com
      O15 - Trusted Zone: *.ysbweb.com
      O15 - Trusted Zone: *.slotchbar.com
      O15 - Trusted Zone: *.iframedollars.biz
      O15 - Trusted Zone: *.windupdates.com (HKLM)
      O15 - Trusted Zone: *.searchmiracle.com (HKLM)
      O15 - Trusted Zone: *.skoobidoo.com (HKLM)
      O15 - Trusted Zone: *.ysbweb.com (HKLM)
      O15 - Trusted Zone: *.slotchbar.com (HKLM)
      O15 - Trusted Zone: *.iframedollars.biz (HKLM)
      O15 - Trusted IP range: 213.159.117.202
      O15 - Trusted IP range: 213.159.117.202 (HKLM)
      O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
      bezpieczenstwo.onet.pl/skaner/SkanerOnline.cab
      O16 - DPF: RaptisoftGameLoader -
      www.miniclip.com/hamsterball/raptisoftgameloader.cab
      O18 - Filter: text/plain - {4A4B576B-3FE7-4A21-8B8C-7A7B333C52FA} -
      C:\WINDOWS\SYSTEM\JCKI.DLL
      O21 - SSODL: Web Event Logger - {7CFBACFF-EE01-1231-ABDD-416592E5D639} - (no
      file)
      • kolobos Re: Prosze o sprawdzenie loga\ciąg dalszy loga 10.02.06, 11:48
        Ogladajac taki log mozna dojsc do wniosku, ze komputery jednak nie powinny byc
        dostepne dla wszystkich...

        Alt+ctrl+del i zakoncz:
        C:\PROGRAM FILES\MEDIA ACCESS\MEDIAACCK.EXE
        C:\PROGRAM FILES\VVSN\VVSN.EXE
        C:\PROGRAM FILES\MEDIA ACCESS\MEDIAACCESS.EXE
        C:\WINDOWS\WINSYSBAN7.EXE
        C:\WINDOWS\SYSTEM\ABJZ.EXE
        C:\PROGRAM FILES\ODAO\IEAW.EXE
        C:\WINSTALL.EXE

        W hijackthis usun:
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
        c:\secure32.html
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
        searchbar.findthewebsiteyouneed.com
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
        searchbar.findthewebsiteyouneed.com
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
        searchbar.findthewebsiteyouneed.com
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        www.findthewebsiteyouneed.com
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
        c:\secure32.html
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
        about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
        searchbar.findthewebsiteyouneed.com
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
        c:\secure32.html
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        about:NavigationFailure
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        searchbar.findthewebsiteyouneed.com
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        c:\secure32.html
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
        c:\secure32.html
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada
        Plus wita Cie w Internecie
        R3 - URLSearchHook: (no name) - {991C0141-EFA3-EF51-D10B-BF3EC2227597} -
        C:\WINDOWS\SYSTEM\OTAFML.DLL
        R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no
        file)
        O1 - Hosts: 127.0.0.5 makethemcry.com
        O1 - Hosts: 127.0.0.5 loudcash.com
        O1 - Hosts: 127.0.0.5 iframestat.com
        O1 - Hosts: 127.0.0.5 toolbarpartner.com
        O1 - Hosts: 127.0.0.5 hqcash.com
        O1 - Hosts: 127.0.0.5 verybigcash.com
        O1 - Hosts: 127.0.0.5 makethemcry.com
        O1 - Hosts: 127.0.0.5 moviepartnership.com
        O1 - Hosts: 127.0.0.5 callmachine.com
        O1 - Hosts: 127.0.0.5 regcash.com
        O1 - Hosts: 127.0.0.5 toolbarpartner.com
        O1 - Hosts: 127.0.0.5 klikrevenue.com
        O1 - Hosts: 127.0.0.5 p2dll.com
        O1 - Hosts: 127.0.0.5 t73.com
        O1 - Hosts: 127.0.0.5 www.makethemcry.com
        O1 - Hosts: 127.0.0.5 www.loudcash.com
        O1 - Hosts: 127.0.0.5 www.iframestat.com
        O1 - Hosts: 127.0.0.5 www.toolbarpartner.com
        O1 - Hosts: 127.0.0.5 www.hqcash.com
        O1 - Hosts: 127.0.0.5 www.verybigcash.com
        O1 - Hosts: 127.0.0.5 www.makethemcry.com
        O1 - Hosts: 127.0.0.5 www.moviepartnership.com
        O1 - Hosts: 127.0.0.5 www.callmachine.com
        O1 - Hosts: 127.0.0.5 www.regcash.com
        O1 - Hosts: 127.0.0.5 www.toolbarpartner.com
        O1 - Hosts: 127.0.0.5 www.klikrevenue.com
        O1 - Hosts: 127.0.0.5 www.p2dll.com
        O1 - Hosts: 127.0.0.5 www.t73.com.0.0.5 www.megapornix.com
        O1 - Hosts: 127.0.0.5 megapornix.com
        O1 - Hosts: 127.0.0.5 www.sp2fucked.biz
        O1 - Hosts: 127.0.0.5 sp2fucked.biz
        O1 - Hosts: 127.0.0.5 greg-tut.com
        O1 - Hosts: 127.0.0.5 www.greg-tut.com
        O1 - Hosts: 127.0.0.5 nylonsexy.com
        O1 - Hosts: 127.0.0.5 www.nylonsexy.com
        O1 - Hosts: 127.0.0.5 vparivalka.com
        O1 - Hosts: 127.0.0.5 www.vparivalka.com
        O1 - Hosts: 127.0.0.5 iframeprofit.com
        O1 - Hosts: 127.0.0.5 www.iframeprofit.com
        O1 - Hosts: 127.0.0.5 topsearch10.com
        O1 - Hosts: 127.0.0.5 www.topsearch10.com
        O1 - Hosts: 127.0.0.5 statscash.biz
        O1 - Hosts: 127.0.0.5 www.statscash.biz
        O1 - Hosts: 127.0.0.5 vxiframe.biz
        O1 - Hosts: 127.0.0.5 www.vxiframe.biz
        O1 - Hosts: 127.0.0.5 crazy-toolbar.com
        O1 - Hosts: 127.0.0.5 www.crazy-toolbar.com
        O1 - Hosts: 127.0.0.5 topcash.biz
        O1 - Hosts: 127.0.0.5 www.topcash.biz
        O1 - Hosts: 127.0.0.5 loadcash.biz
        O1 - Hosts: 127.0.0.5 www.loadcash.biz
        O1 - Hosts: 127.0.0.5 txiframe.biz
        O1 - Hosts: 127.0.0.5 www.txiframe.biz
        O1 - Hosts: 127.0.0.5 procounter.biz
        O1 - Hosts: 127.0.0.5 www.procounter.biz
        O1 - Hosts: 127.0.0.5 advadmin.biz
        O1 - Hosts: 127.0.0.5 www.advadmin.biz
        O1 - Hosts: 127.0.0.5 trafficbest.net
        O1 - Hosts: 127.0.0.5 www.trafficbest.net
        O1 - Hosts: 127.0.0.5 besthvac.com
        O1 - Hosts: 127.0.0.5 www.besthvac.com
        O1 - Hosts: 127.0.0.5 traff4.com
        O1 - Hosts: 127.0.0.5 www.traff4.com
        O1 - Hosts: 127.0.0.5 ambush-script.com
        O1 - Hosts: 127.0.0.5 www.ambush-script.com
        O1 - Hosts: 127.0.0.5 beehappyy.biz
        O1 - Hosts: 127.0.0.5 www.beehappyy.biz
        O1 - Hosts: 127.0.0.5 tracktraff.cc
        O1 - Hosts: 127.0.0.5 www.tracktraff.cc
        O1 - Hosts: 127.0.0.5 allcount.net
        O1 - Hosts: 127.0.0.5 www.allcount.net
        O1 - Hosts: 127.0.0.5 onedayoffer.biz
        O1 - Hosts: 127.0.0.5 www.onedayoffer.biz27.0.0.1 classic.adlink.de
        O3 - Toolbar: (no name) - {6b95678d-30a4-4ff8-a72f-4208340c1f7f} - (no file)
        O3 - Toolbar: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-
        3FFD8020233E} - C:\PROGRAM FILES\THESEARCHACCELERATOR\UCMTSAIE.DLL <- usun
        katalog zawierajacy.
        O4 - HKLM\..\Run: [Media Access] C:\PROGRAM FILES\MEDIA ACCESS\MediaAccK.exe <-
        to samo tutaj
        O4 - HKLM\..\Run: [VVSN] C:\PROGRAM FILES\VVSN\VVSN.EXE <- i tutaj
        O4 - HKLM\..\Run: [winsysupd] C:\WINDOWS\WINSYSUPD7.exe <- usun plik
        O4 - HKLM\..\Run: [winzmc32] rundll32 winzmc32.dll,run <- usun plik winzmc32.dll
        O4 - HKLM\..\Run: [gimmygames] C:\WINDOWS\GIMMYGAMES.exe <- usun plik
        O4 - HKLM\..\Run: [winsysban] C:\WINDOWS\WINSYSBAN7.exe <- i ten
        O4 - HKCU\..\Run: [Qisyflnp] C:\WINDOWS\SYSTEM\abjz.exe
        O4 - HKCU\..\Run: [Oewt] "C:\Program Files\odao\ieaw.exe" -vt ndrv <- katalog
        odao
        O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe <- i ten
        O15 - Trusted Zone: *.windupdates.com
        O15 - Trusted Zone: *.searchmiracle.com
        O15 - Trusted Zone: *.skoobidoo.com
        O15 - Trusted Zone: *.ysbweb.com
        O15 - Trusted Zone: *.slotchbar.com
        O15 - Trusted Zone: *.iframedollars.biz
        O15 - Trusted Zone: *.windupdates.com (HKLM)
        O15 - Trusted Zone: *.searchmiracle.com (HKLM)
        O15 - Trusted Zone: *.skoobidoo.com (HKLM)
        O15 - Trusted Zone: *.ysbweb.com (HKLM)
        O15 - Trusted Zone: *.slotchbar.com (HKLM)
        O15 - Trusted Zone: *.iframedollars.biz (HKLM)
        O15 - Trusted IP range: 213.159.117.202
        O15 - Trusted IP range: 213.159.117.202 (HKLM)
        O16 - DPF: RaptisoftGameLoader -
        www.miniclip.com/hamsterball/raptisoftgameloader.cab
        O18 - Filter: text/plain - {4A4B576B-3FE7-4A21-8B8C-7A7B333C52FA} -
        C:\WINDOWS\SYSTEM\JCKI.DLL <- i ten
        O21 - SSODL: Web Event Logger - {7CFBACFF-EE01-1231-ABDD-416592E5D639} - (no
        file)

        Zrob skan:
        ftp://download.hirekmedia.hu/ssfsetup1_0.exe <- zrob update przed skanowaniem,
        po przeskanowaniu odinstaluj.

        Po wszystkim wklej nowy log i nie instaluj wiecej spywareu.

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka