Dodaj do ulubionych

Strasznie muli komputer

IP: *.neoplus.adsl.tpnet.pl 04.05.06, 16:32
Hej!
Strasznie muli komputer, prosze o sprawdzenie log

Logfile of HijackThis v1.99.1
Scan saved at 16:27:40, on 2006-05-04
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\explorer.exe
F:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
F:\Program Files\Alwil Software\Avast4\ashServ.exe
F:\Program Files\Microsoft AntiSpyware\gcasServ.exe
F:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
F:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
F:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
F:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
F:\WINDOWS\system32\wuauclt.exe
F:\Program Files\Alwil Software\Avast4\ashWebSv.exe
F:\WINDOWS\system32\wscntfy.exe
F:\DOCUME~1\Dom\USTAWI~1\Temp\Katalog tymczasowy 4 dla
hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.wp.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
F2 - REG:system.ini: Shell=explorer.exe
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O4 - HKLM\..\Run: [gcasServ] "F:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] F:\Program
Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [BearShare] "F:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [System32] "user32.exe" -user
O4 - HKLM\..\Run: [AntyVirKS] f:\windows\avks.exe ukrt
O4 - HKLM\..\Run: [MyWebSearch Email Plugin]
F:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common Files\Symantec
Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] F:\PROGRA~1\SYMNET~1\SNDMon.exe
/Consumer
O4 - HKLM\..\Run: [P2P Networking] F:\WINDOWS\system32\P2P Networking\P2P
Networking.exe /AUTOSTART
O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search &
Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin]
F:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
O4 - HKCU\..\Run: [SIDEBAR] "F:\Program Files\Desktop Sidebar\dsidebar.exe"
O4 - HKCU\..\Run: [Komunikator] F:\Program Files\Tlen.pl\tlen.exe
O4 - HKCU\..\Run: [tbon] F:\Program Files\TBONBin\tbon.exe /r
O8 - Extra context menu item: &Search -
bar.mywebsearch.com/menusearch.html?p=ZC
O8 - Extra context menu item: Translate into English - res://F:\Program
Files\Google\googletoolbar.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
F:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program
Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Subscribe in Desktop Sidebar -
{09FE188B-6E85-479e-9411-51FB2220DF80} - F:\Program Files\Desktop
Sidebar\sbhelp.dll (file missing)
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar -
{09FE188B-6E85-479e-9411-51FB2220DF80} - F:\Program Files\Desktop
Sidebar\sbhelp.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9085316E-42BA-11D4-BAA3-0080C8D7ED4A} (GameDesire JungleHunter) -
67.15.101.3/g_bin/pl/hunter_2_0_0_17.cab
O16 - DPF: {A9ED6AA2-D9D4-4D71-9586-E293E2E3580B} (GameDesire
Marbles&Diamonds&Runes) - 67.15.101.3/g_bin/pl/marbles_2_0_0_22.cab
O16 - DPF: {AD7013FF-1D9A-4F36-94A6-3CD408A663F9} (GameDesire BreakOut) -
67.15.101.3/g_bin/pl/breakout_2_0_0_19.cab
O16 - DPF: {BFA1F11D-3121-AFE1-4112-894323212DAC} (GameDesire Word Games) -
67.15.101.3/g_bin/pl/words_2_0_0_36.cab
O16 - DPF: {BFA1F11D-3121-AFE1-4112-983219421AEF} (GameDesire 1Player Word
Games) - 67.15.101.3/g_bin/pl/wordssingle_2_0_0_34.cab
O16 - DPF: {E23FABEE-12E3-33DA-DA12-195DAC123984} (GameDesire Mahjong) -
67.15.101.3/g_bin/pl/mahjong_2_0_0_20.cab
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) -
67.15.101.3/g_bin/pl/billard8_2_0_0_24.cab
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C5} (GameDesire Snooker) -
67.15.101.3/g_bin/pl/snooker_2_0_0_24.cab
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner -
F:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - F:\Program Files\Alwil
Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - F:\Program Files\Alwil
Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - F:\Program Files\Alwil
Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - F:\Program
Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Obserwuj wątek
    • Gość: k Re: Strasznie muli komputer IP: *.warszawa.sdi.tpnet.pl 04.05.06, 17:00
      W menadzerze zadan zakoncz:
      F:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe

      W hjt usun:
      O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
      O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
      O4 - HKLM\..\Run: [System32] "user32.exe" -user <- usun plik z dysku
      O4 - HKLM\..\Run: [AntyVirKS] f:\windows\avks.exe ukrt <- usun plik z dysku
      O4 - HKLM\..\Run: [MyWebSearch Email Plugin]
      F:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
      O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common
      Files\SymantecShared\ccApp.exe"
      O4 - HKLM\..\Run: [Symantec NetDriver Monitor] F:\PROGRA~1\SYMNET~1
      \SNDMon.exe /Consumer
      O4 - HKLM\..\Run: [P2P Networking] F:\WINDOWS\system32\P2P Networking\P2P
      Networking.exe /AUTOSTART <- usun katalog P2P Networking
      O4 - HKCU\..\Run: [MyWebSearch Email Plugin]
      F:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe <- odinstaluj i usun katalog
      Mybwebs~1
      O4 - HKCU\..\Run: [tbon] F:\Program Files\TBONBin\tbon.exe /r <- usun katalog
      TBONBin
      O8 - Extra context menu item: &Search -
      bar.mywebsearch.com/menusearch.html?p=ZC
      O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)

      Do tego przeskanuj system przy pomocy ewido.

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka