Prosze o sprawdzenie loga !

IP: *.chello.pl 11.04.06, 00:30
Witam
Problemem jest przekierowanie adresów na jakieś gó..ane wyszukiwarki gdy
otwieram wyniki z googla.
Oto log:

Logfile of HijackThis v1.99.1
Scan saved at 00:12:59, on 2006-04-11
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\csrss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
E:\WINDOWS\system32\RUNDLL32.EXE
E:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exe
E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
E:\uzytki\Spyware Doctor\swdoctor.exe
E:\WINDOWS\system32\CTsvcCDA.exe
E:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2
\bin\apache.exe
E:\Program Files\Norton AntiVirus\navapsvc.exe
E:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
E:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
E:\WINDOWS\system32\nvsvc32.exe
E:\WINDOWS\system32\MsPMSPSv.exe
E:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
E:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2
\bin\apache.exe
E:\WINDOWS\System32\alg.exe
E:\Program Files\Gadu-Gadu\gg.exe
E:\WINDOWS\system32\ping.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Program Files\Windows Media Player\wmplayer.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\download\spyware\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
www.onet.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} -
E:\uzytki\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -
E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} -
E:\uzytki\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Program
Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
E:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [nTrayFw] E:\Program Files\NVIDIA
Corporation\NetworkAccessManager\bin\nTrayFw.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32
\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32
\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CTSysVol] E:\Program Files\Creative\SBAudigy LS\Surround
Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] E:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [RemoteControl] "E:\Program
Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_06
\bin\jusched.exe
O4 - HKCU\..\Run: [Spyware Doctor] "E:\uzytki\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [Malware Sweeper] E:\uzytki\MalwareSweeper.com\Malware
Sweeper\MalSwep.exe /STARTUP
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} -
E:\uzytki\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
www.mks.com.pl/skaner/SkanerOnline.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EE2E4476-163A-425F-B0A3-
88A40C0B0BE0}: NameServer = 85.255.114.61,85.255.112.60
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd -
E:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown
owner - E:\Program Files\NVIDIA

Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown
owner - E:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache

Group\Apache2\bin\apache.exe" -k runservice (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec
Corporation - E:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - E:\Program
Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - E:\Program
Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
E:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -
E:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division
Software - E:\Program Files\Alcohol Soft\Alcohol

120\StarWind\StarWindService.exe
    • Gość: k Re: Prosze o sprawdzenie loga ! IP: *.warszawa.sdi.tpnet.pl 11.04.06, 01:11
      Usun:
      O17 - HKLM\System\CCS\Services\Tcpip\..\{EE2E4476-163A-425F-B0A3-
      88A40C0B0BE0}: NameServer = 85.255.114.61,85.255.112.60

      Nastepnie ustaw dns'y jakie zaleca Twoj dostawca netu.
      • Gość: Llorand niestety... IP: *.chello.pl 11.04.06, 02:13
        Niestety problem nie znikł mimo iż zmieniłem dns na ten od mojego dostawcy
        (chello): 62.179.1.60, 62.179.1.61
        W dalszym ciągu przekierowuje mnie :/
        Oto nowy log:

        Logfile of HijackThis v1.99.1
        Scan saved at 02:05:22, on 2006-04-11
        Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        E:\WINDOWS\System32\smss.exe
        E:\WINDOWS\system32\csrss.exe
        E:\WINDOWS\system32\winlogon.exe
        E:\WINDOWS\system32\services.exe
        E:\WINDOWS\system32\lsass.exe
        E:\WINDOWS\system32\svchost.exe
        E:\WINDOWS\system32\svchost.exe
        E:\WINDOWS\System32\svchost.exe
        E:\WINDOWS\system32\svchost.exe
        E:\WINDOWS\system32\svchost.exe
        E:\WINDOWS\Explorer.EXE
        E:\WINDOWS\system32\spoolsv.exe
        E:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
        E:\WINDOWS\system32\RUNDLL32.EXE
        E:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exe
        E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
        E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
        E:\Program Files\Internet Explorer\iexplore.exe
        E:\uzytki\Spyware Doctor\swdoctor.exe
        E:\WINDOWS\system32\CTsvcCDA.exe
        E:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2
        \bin\apache.exe
        E:\Program Files\Norton AntiVirus\navapsvc.exe
        E:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
        E:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
        E:\WINDOWS\system32\nvsvc32.exe
        E:\WINDOWS\system32\MsPMSPSv.exe
        E:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
        E:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2
        \bin\apache.exe
        E:\WINDOWS\System32\alg.exe
        E:\Program Files\Internet Explorer\IEXPLORE.EXE
        E:\WINDOWS\system32\wuauclt.exe
        E:\WINDOWS\system32\wbem\wmiprvse.exe
        E:\download\spyware\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        www.onet.pl/
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
        O1 - Hosts: localhost 127.0.0.1
        O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} -
        E:\uzytki\SPYWAR~1\tools\iesdsg.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program
        Files\Java\jre1.5.0_06\bin\ssv.dll
        O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} -
        E:\uzytki\SPYWAR~1\tools\iesdpb.dll
        O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Program
        Files\Norton AntiVirus\NavShExt.dll
        O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
        E:\Program Files\Norton AntiVirus\NavShExt.dll
        O4 - HKLM\..\Run: [nTrayFw] E:\Program Files\NVIDIA
        Corporation\NetworkAccessManager\bin\nTrayFw.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32
        \NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32
        \NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [CTSysVol] E:\Program Files\Creative\SBAudigy LS\Surround
        Mixer\CTSysVol.exe /r
        O4 - HKLM\..\Run: [UpdReg] E:\WINDOWS\UpdReg.EXE
        O4 - HKLM\..\Run: [RemoteControl] "E:\Program
        Files\CyberLink\PowerDVD\PDVDServ.exe"
        O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_06
        \bin\jusched.exe
        O4 - HKLM\..\Run: [dflnl.exe] E:\WINDOWS\system32\dflnl.exe
        O4 - HKCU\..\Run: [Spyware Doctor] "E:\uzytki\Spyware Doctor\swdoctor.exe" /Q
        O4 - HKCU\..\Run: [Malware Sweeper] E:\uzytki\MalwareSweeper.com\Malware
        Sweeper\MalSwep.exe /STARTUP
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
        E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
        00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
        O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} -
        E:\uzytki\SPYWAR~1\tools\iesdpb.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
        E:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-
        00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
        O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
        O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
        O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
        O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
        O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
        O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
        O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
        O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
        O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
        O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
        O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
        O10 - Unknown file in Winsock LSP: e:\windows\system32\nvappfilter.dll
        O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
        www.mks.com.pl/skaner/SkanerOnline.cab
        O17 - HKLM\System\CCS\Services\Tcpip\..\{EE2E4476-163A-425F-B0A3-88A40C0B0BE0}:
        NameServer = 62.179.1.60,62.179.1.61
        O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd -
        E:\WINDOWS\system32\CTsvcCDA.exe
        O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner -
        E:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
        O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner -
        E:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2
        \bin\apache.exe" -k runservice (file missing)
        O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec
        Corporation - E:\Program Files\Norton AntiVirus\navapsvc.exe
        O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - E:\Program Files\NVIDIA
        Corporation\NetworkAccessManager\bin\nSvcIp.exe
        O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - E:\Program
        Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
        E:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -
        E:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
        O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division
        Software - E:\Program Files\Alcohol Soft\Alcohol 120
        \StarWind\StarWindService.exe
        • Gość: k Re: niestety... IP: *.warszawa.sdi.tpnet.pl 11.04.06, 10:00
          O4 - HKLM\..\Run: [dflnl.exe] E:\WINDOWS\system32\dflnl.exe <- usun plik
          O4 - HKCU\..\Run: [Malware Sweeper] E:\uzytki\MalwareSweeper.com\Malware
          Sweeper\MalSwep.exe /STARTUP <- odinstaluj i usun katalog.

          Do tego zrob skan przy pomocy ewido.
          • Gość: Llorand Nie pomogło :/ n/t IP: *.chello.pl 11.04.06, 19:26
            • kolobos Re: Nie pomogło :/ n/t 12.04.06, 00:28
              Zobacz moze:
              www.searchengines.pl/phpbb203/index.php?s=d763d930af0af06d0451cb7b3e83d564&showtopic=47691
            • Gość: Antek Re: Nie pomogło :/ n/t IP: *.acn.waw.pl 12.04.06, 01:07
              Podejrzyj %windir%\system32\drivers\etc\hosts i zobacz czy jest cos poza linia
              127.0.0.1 localhost (linie zaczynajace sie od # pomin).
    • Gość: Llorand Thx IP: *.chello.pl 12.04.06, 02:13
      Chyba się udało usunąć gada! Wszytkim dziękuje za pomoc. :)
Pełna wersja