Dodaj do ulubionych

prosba o sprawdzenie loga

IP: *.c31.msk.pl 23.03.06, 21:36
nalapalam jakiegos badziewa,probowalam sama to pousuwac i chyba popsulam
sobie jescze bardziej bo mi sie samorestartuje zaraz jak mi sie widnows
zaladuje,prosze o pomoc,dziękuje,oto log:
Logfile of HijackThis v1.99.1
Scan saved at 21:31:05, on 2006-03-23
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\gadu z 17.01.06\Gadu-Gadu\gg.exe
C:\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - Default URLSearchHook is missing
F3 - REG:win.ini: run=C:\WINDOWS\inet20003\services.exe
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} -
C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [LXCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86
\3\LXCFtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -
lang 1033
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [ABmenu] C:\Program Files\ArcaVir\Bin\ABmenu.exe
O4 - HKLM\..\Run: [ABREGMON] C:\Program Files\ArcaVir\Bin\ABregmon.exe
O4 - HKLM\..\Run: [MKS_MENU] C:\Program Files\MKS\Bin\mks_menu.exe
O4 - HKLM\..\Run: [Odkurzacz-MCD] C:\Program Files\Odkurzacz 10.1
Pro\odk_mcd.exe
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inet20003\services.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Gadu-Gadu] "D:\gadu z 17.01.06\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [Komunikator] D:\fol tlen\tlen.exe
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inet20003\services.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program
Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program
Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Download All by FlashGet - C:\Program
Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program
Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} -
C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-
0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1119253612588
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer
Class) - acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
skaner.mks.com.pl/SkanerOnline.cab
O20 - Winlogon Notify: avpe32 - C:\WINDOWS\SYSTEM32\avpe32.dll
O20 - Winlogon Notify: Extensions - C:\WINDOWS\system32\s088lalu1dq8.dll
O23 - Service: Workstation NetLogon Service ( 11Fßä#·şÄÖ`I) - Unknown owner -
C:\WINDOWS\system32\msgh.exe (file missing)
O23 - Service: ArcaBit NetMonitor (ABNetMon) - ArcaBit sp. z o.o. -
C:\Program Files\ArcaVir\Bin\NetMonSv.exe
O23 - Service: ArcaVir Monitor (ArcaMonSvc) - ArcaBit - C:\Program
Files\ArcaVir\Bin\avmonsv.exe
O23 - Service: ArcaScan - ArcaBit - C:\Program Files\ArcaVir\Bin\ArcaScan.exe
O23 - Service: arcaserv - ArcaBit Sp. z o. o. - C:\Program
Files\ArcaVir\bin\arcaserv.exe
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program
Files\Ahead\InCD\InCDsrv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program
Files\TGTSoft\StyleXP\StyleXPService.exe

Obserwuj wątek
    • Gość: k Re: prosba o sprawdzenie loga IP: *.warszawa.sdi.tpnet.pl 24.03.06, 01:50
      Opisy usuwania look2me itd w przyklejonym poscie.

      W hijackthis usun:
      R3 - Default URLSearchHook is missing
      F3 - REG:win.ini: run=C:\WINDOWS\inet20003\services.exe
      O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inet20003\services.exe
      O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inet20003\services.exe <- usun katalog
      inet20003
      O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll <- jezeli juz
      nie uzywasz Internet Download Manager to usun w lspfix idmmbc.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

      O20 - Winlogon Notify: avpe32 - C:\WINDOWS\SYSTEM32\avpe32.dll <- opis usuwania
      tutaj:
      www.searchengines.pl/phpbb203/index.php?showtopic=6745&st=0&p=129742&#entry129742
      O20 - Winlogon Notify: Extensions - C:\WINDOWS\system32\s088lalu1dq8.dll <-
      look2me
      O23 - Service: Workstation NetLogon Service ( 11Fßä#·şÄÖ`I) - Unknown owner -
      C:\WINDOWS\system32\msgh.exe (file missing) <- usluga do kasacji.

      Zrob skan tym co wszyscy.

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka