Dodaj do ulubionych

Virus alert pojawil sie na pasku -co poczac ?

IP: *.cable.ubr03.gill.blueyonder.co.uk 22.05.06, 21:49
...wiec na pasku obok zegara pojawil sie komunikat VIRUSA ALERT z migajaca
ikonka . a przy tym komunikat , CRITICAL SYSTEM ERROR , USE ANTIMALWARE
SOFTWARE TO CLEAN AND PROTEC YOUR SYSTEM.
co mam poczac ?
Obserwuj wątek
    • Gość: klon Re: Virus alert pojawil sie na pasku -co poczac ? IP: *.cable.ubr03.gill.blueyonder.co.uk 22.05.06, 21:58
      ....moze log powie cos wiecej na temat tego dziwnego problemu;

      Logfile of HijackThis v1.99.1
      Scan saved at 20:56:30, on 22/05/2006
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
      C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      C:\Program Files\Norton Internet Security\ISSVC.exe
      C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
      C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      C:\Program Files\Gizmo Project\mDNSResponder.exe
      C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
      C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
      C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\atmclk.exe
      C:\WINDOWS\system32\dcomcfg.exe
      C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
      C:\Program Files\D-Tools\daemon.exe
      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\Program Files\MSN Messenger\MsnMsgr.Exe
      C:\program files\voipstunt.com\voipstunt\voipstunt.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
      C:\Program Files\SJLabs\SJphone\SJphone.exe
      C:\Program Files\RALINK\RT2500 USB Wireless LAN
      Card\Installer\WINXP\RaConfig2500USB.exe
      C:\WINDOWS\system32\msiexec.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\MalwareWipe\MalwareWipe.exe
      C:\Program Files\MalwareWipe\MalwareWipe.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Documents and Settings\tomasz1\Desktop\HijackThis.exe

      R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} -
      C:\Program Files\ICQToolbar\toolbaru.dll
      O2 - BHO: Nothing - {f79fd28e-36ee-4989-aa61-9dd8e30a82fa} - C:\WINDOWS\system32
      \hp865A.tmp
      O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-
      A37C9A5676A7} - C:\Program Files\Common Files\Symantec
      Shared\AdBlocking\NISShExt.dll (file missing)
      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
      C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} -
      C:\Program Files\ICQToolbar\toolbaru.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
      files\google\googletoolbar1.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} -
      C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
      O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -
      lang 1033
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
      Shared\ccApp.exe"
      O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
      Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -
      atboottime
      O4 - HKLM\..\Run: [MalwareWipe] C:\Program Files\MalwareWipe\MalwareWipe.exe /h
      O4 - HKCU\..\Run: [Skype] "C:\Program
      Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN
      Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [VoipStunt] "C:\program
      files\voipstunt.com\voipstunt\voipstunt.exe" -nosplash -minimized
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program
      Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: BTTray.lnk = ?
      O4 - Global Startup: HaloNet Softphone.lnk = ?
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
      Office\Office10\OSA.EXE
      O4 - Global Startup: RaConfig2500USB.lnk = C:\Program Files\RALINK\RT2500 USB
      Wireless LAN Card\Installer\WINXP\RaConfig2500USB.exe
      O8 - Extra context menu item: &Google Search - res://c:\program
      files\google\GoogleToolbar1.dll/cmsearch.html
      O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program
      Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
      O8 - Extra context menu item: &Translate English Word - res://c:\program
      files\google\GoogleToolbar1.dll/cmwordtrans.html
      O8 - Extra context menu item: Backward Links - res://c:\program
      files\google\GoogleToolbar1.dll/cmbacklinks.html
      O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program
      files\google\GoogleToolbar1.dll/cmcache.html
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1
      \MICROS~2\Office10\EXCEL.EXE/3000
      O8 - Extra context menu item: Send To &Bluetooth - C:\Program
      Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
      O8 - Extra context menu item: Similar Pages - res://c:\program
      files\google\GoogleToolbar1.dll/cmsimilar.html
      O8 - Extra context menu item: Translate Page into English - res://c:\program
      files\google\GoogleToolbar1.dll/cmtrans.html
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
      C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
      00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
      C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} -
      C:\Program Files\ICQLite\ICQLite.exe
      O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} -
      C:\Program Files\ICQLite\ICQLite.exe
      O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} -
      C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-
      5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
      C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-
      00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
      O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) -
      www.cult3d.com/download/cult.cab
      O16 - DPF: {631FF594-EC25-4CFF-B869-402DF294E1D6} (Instalator oprogramowania
      Onet.pl) - slimak.onet.pl/_m/kamerzysta/OnetInstalator012s.ocx
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF}
      (MsnMessengerSetupDownloadControl Class) -
      messenger.msn.com/download/MsnMessengerSetupDownloader.cab
      O18 - Protocol: Festoon - (no CLSID) - (no file)
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1
      \MSNMES~1\msgrapp.dll" (file missing)
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1
      \MSNMES~1\msgrapp.dll" (file missing)
      O18 - Protocol: vskype - (no CLSID) - (no file)
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
      O23 - Service: Automatic LiveUpdat
      • Gość: k Re: Virus alert pojawil sie na pasku -co poczac ? IP: *.warszawa.sdi.tpnet.pl 22.05.06, 22:04
        Odinstaluj: Yahoo! Toolbar
        Uzyj: siri.urz.free.fr/Fix/SmitfraudFix_En.php

        Zakoncz:
        C:\WINDOWS\system32\atmclk.exe
        C:\WINDOWS\system32\dcomcfg.exe
        C:\Program Files\MalwareWipe\MalwareWipe.exe <- usun katalog MalwareWipe
        C:\Program Files\MalwareWipe\MalwareWipe.exe

        W hjt usun:
        O2 - BHO: Nothing - {f79fd28e-36ee-4989-aa61-9dd8e30a82fa} - C:\WINDOWS\system32
        \hp865A.tmp
        O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-
        A37C9A5676A7} - C:\Program Files\Common Files\Symantec
        Shared\AdBlocking\NISShExt.dll (file missing)
        O4 - HKLM\..\Run: [MalwareWipe] C:\Program Files\MalwareWipe\MalwareWipe.exe /h
        O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) -
        www.cult3d.com/download/cult.cab
        O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

        Doklej reszte od:
        O23 - Service: Automatic LiveUpdat

        Do tego zrob skan przy pomocy ewido.
        • Gość: klon Re: Virus alert pojawil sie na pasku -co poczac ? IP: *.cable.ubr03.gill.blueyonder.co.uk 22.05.06, 22:06
          ...reszta od 023

          O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation -
          C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Gizmo
          Project\mDNSResponder.exe
          O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program
          Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
          C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
          O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation -
          C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
          O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation -
          C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
          O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -
          C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
          O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program
          Files\TOSHIBA\ConfigFree\CFSvcs.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision
          Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32
          \IDriverT.exe
          O23 - Service: iPodService - Apple Computer, Inc. - C:\Program
          Files\iPod\bin\iPodService.exe
          O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton
          Internet Security\ISSVC.exe
          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1
          \LUCOMS~1.EXE
          O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec
          Corporation - C:\Program Files\Norton Internet Security\Norton
          AntiVirus\navapsvc.exe
          O23 - Service: O&O Defrag (OODefrag) - O&O Software GmbH - C:\WINDOWS\system32
          \oodag.exe
          O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton
          Internet Security\Norton AntiVirus\SAVScan.exe
          O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -
          C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
          O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec
          Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
          O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program
          Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
          O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program
          Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
          O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp
          Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
          • Gość: klon Re: Virus alert pojawil sie na pasku -co poczac ? IP: *.cable.ubr03.gill.blueyonder.co.uk 22.05.06, 22:24
            ...a to raport ze skanowania smitfraud

            SmitFraudFix v2.45

            Scan done at 21:20:45.92, 22/05/2006
            Run from C:\Documents and Settings\tomasz1\Desktop\SmitfraudFix\SmitfraudFix
            OS: Microsoft Windows XP [Version 5.1.2600]

            »»»»»»»»»»»»»»»»»»»»»»»» C:\


            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

            C:\WINDOWS\system32\atmclk.exe FOUND !
            C:\WINDOWS\system32\dcomcfg.exe FOUND !
            C:\WINDOWS\system32\hp????.tmp FOUND !
            C:\WINDOWS\system32\ld????.tmp FOUND !
            C:\WINDOWS\system32\ot.ico FOUND !
            C:\WINDOWS\system32\regperf.exe FOUND !
            C:\WINDOWS\system32\simpole.tlb FOUND !
            C:\WINDOWS\system32\stdole3.tlb FOUND !
            C:\WINDOWS\system32\1024\ FOUND !

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\tomasz1\Application Data

            C:\Documents and Settings\tomasz1\Application Data\Microsoft\Internet
            Explorer\Quick Launch\MalwareWipe 4.1.lnk FOUND !

            »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

            C:\DOCUME~1\tomasz1\STARTM~1\MalwareWipe 4.1.lnk FOUND !
            C:\DOCUME~1\tomasz1\STARTM~1\Programs\MalwareWipe FOUND !
            C:\DOCUME~1\tomasz1\STARTM~1\Programs\SpyFalcon FOUND !

            »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\tomasz1\FAVORI~1

            C:\DOCUME~1\tomasz1\FAVORI~1\Antivirus Test Online.url FOUND !

            »»»»»»»»»»»»»»»»»»»»»»»» Desktop

            C:\DOCUME~1\tomasz1\Desktop\MalwareWipe.lnk FOUND !

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

            C:\Program Files\MalwareWipe\ FOUND !

            »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


            »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
            "Source"="About:Home"
            "SubscribedURL"="About:Home"
            "FriendlyName"="My Current Home Page"


            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
            !!!Attention, following keys are not inevitably infected!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTas
            kScheduler]
            "{89aef01d-d237-49c7-84dc-4e1904c1fd31}"="AutoDisc Ware"

            [HKEY_CLASSES_ROOT\CLSID\{89aef01d-d237-49c7-84dc-4e1904c1fd31}\InProcServer32]
            @="C:\WINDOWS\system32\sbnudh.dll"

            [HKEY_CURRENT_USER\Software\Classes\CLSID\{89aef01d-d237-49c7-84dc-4e1904c1fd31}
            \InProcServer32]
            @="C:\WINDOWS\system32\sbnudh.dll"


            »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


            »»»»»»»»»»»»»»»»»»»»»»»» End

            • Gość: klon Re: Virus alert pojawil sie na pasku -co poczac ? IP: *.cable.ubr03.gill.blueyonder.co.uk 22.05.06, 22:58
              ...mam problem , banalny.........nie wiem jak wejsc w safe mode , nie wiem jak
              odszukac i zakonczyc wymienione wczesniej programy.......
              a ta migajaco na czerwono ikonka VIRUS tylko stresuje
              • Gość: k Re: Virus alert pojawil sie na pasku -co poczac ? IP: *.warszawa.sdi.tpnet.pl 22.05.06, 23:28
                Nie miales skanowac tylko usunac, a wiec na podanej stronie wykonujesz to co
                masz pod "Clean:", a nie "Search:".
                Jak to nie wiesz jak wlaczyc safe mode (tryb awaryjny), przeciez na stronie
                masz podane:
                "before the Windows icon appears, tap the F8 key continually"
                Wiec nacisnij F8 przy starcie systemu i wlacz.
                • Gość: klon Re: Virus alert pojawil sie na pasku -co poczac ? IP: *.cable.ubr03.gill.blueyonder.co.uk 23.05.06, 01:30
                  dziekuje za pomoc ,
                  postapilem zgodnie zw wskazowkai i czerwone ostrzezenie virusa na pasku znikl.
                  zamiescilem obecny log,
                  jeszcze raz dzieki.......


                  Logfile of HijackThis v1.99.1
                  Scan saved at 00:28:26, on 23/05/2006
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                  C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                  C:\Program Files\Norton Internet Security\ISSVC.exe
                  C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                  C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                  C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  C:\Program Files\Gizmo Project\mDNSResponder.exe
                  C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
                  C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                  C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                  C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
                  C:\Program Files\D-Tools\daemon.exe
                  C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                  C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                  C:\Program Files\MSN Messenger\MsnMsgr.Exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                  C:\Program Files\SJLabs\SJphone\SJphone.exe
                  C:\Program Files\RALINK\RT2500 USB Wireless LAN
                  Card\Installer\WINXP\RaConfig2500USB.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Skype\Phone\Skype.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\rundll32.exe
                  C:\WINDOWS\explorer.exe
                  C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
                  C:\Program Files\Messenger\msmsgs.exe
                  C:\Documents and Settings\tomasz1\Desktop\HijackThis.exe

                  R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} -
                  C:\Program Files\ICQToolbar\toolbaru.dll
                  O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
                  C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
                  files\google\googletoolbar1.dll
                  O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
                  O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -
                  lang 1033
                  O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
                  Shared\ccApp.exe"
                  O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
                  Files\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -
                  atboottime
                  O4 - HKCU\..\Run: [Skype] "C:\Program
                  Files\Skype\Phone\Skype.exe" /nosplash /minimized
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN
                  Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [VoipStunt] "C:\program
                  files\voipstunt.com\voipstunt\voipstunt.exe" -nosplash -minimized
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program
                  Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                  O4 - Global Startup: BTTray.lnk = ?
                  O4 - Global Startup: HaloNet Softphone.lnk = ?
                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
                  Office\Office10\OSA.EXE
                  O4 - Global Startup: RaConfig2500USB.lnk = C:\Program Files\RALINK\RT2500 USB
                  Wireless LAN Card\Installer\WINXP\RaConfig2500USB.exe
                  O8 - Extra context menu item: &Google Search - res://c:\program
                  files\google\GoogleToolbar1.dll/cmsearch.html
                  O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program
                  Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
                  O8 - Extra context menu item: &Translate English Word - res://c:\program
                  files\google\GoogleToolbar1.dll/cmwordtrans.html
                  O8 - Extra context menu item: Backward Links - res://c:\program
                  files\google\GoogleToolbar1.dll/cmbacklinks.html
                  O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program
                  files\google\GoogleToolbar1.dll/cmcache.html
                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1
                  \MICROS~2\Office10\EXCEL.EXE/3000
                  O8 - Extra context menu item: Send To &Bluetooth - C:\Program
                  Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                  O8 - Extra context menu item: Similar Pages - res://c:\program
                  files\google\GoogleToolbar1.dll/cmsimilar.html
                  O8 - Extra context menu item: Translate Page into English - res://c:\program
                  files\google\GoogleToolbar1.dll/cmtrans.html
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
                  C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
                  00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
                  C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} -
                  C:\Program Files\ICQLite\ICQLite.exe
                  O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} -
                  C:\Program Files\ICQLite\ICQLite.exe
                  O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} -
                  C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                  O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-
                  5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
                  C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-
                  00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                  O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -
                  download.ewido.net/ewidoOnlineScan.cab
                  O16 - DPF: {631FF594-EC25-4CFF-B869-402DF294E1D6} (Instalator oprogramowania
                  Onet.pl) - slimak.onet.pl/_m/kamerzysta/OnetInstalator012s.ocx
                  O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF}
                  (MsnMessengerSetupDownloadControl Class) -
                  messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                  O18 - Protocol: Festoon - (no CLSID) - (no file)
                  O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1
                  \MSNMES~1\msgrapp.dll" (file missing)
                  O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1
                  \MSNMES~1\msgrapp.dll" (file missing)
                  O18 - Protocol: vskype - (no CLSID) - (no file)
                  O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                  O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                  O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation -
                  C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Gizmo
                  Project\mDNSResponder.exe
                  O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program
                  Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
                  O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
                  C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                  O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation -
                  C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                  O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation -
                  C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
                  O23 -
                  • Gość: klon Re: Virus alert pojawil sie na pasku -co poczac ? IP: *.cable.ubr03.gill.blueyonder.co.uk 23.05.06, 01:33
                    cd...023

                    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation -
                    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                    O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Gizmo
                    Project\mDNSResponder.exe
                    O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program
                    Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
                    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
                    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation -
                    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation -
                    C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
                    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -
                    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program
                    Files\TOSHIBA\ConfigFree\CFSvcs.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision
                    Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32
                    \IDriverT.exe
                    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program
                    Files\iPod\bin\iPodService.exe
                    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton
                    Internet Security\ISSVC.exe
                    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1
                    \LUCOMS~1.EXE
                    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec
                    Corporation - C:\Program Files\Norton Internet Security\Norton
                    AntiVirus\navapsvc.exe
                    O23 - Service: O&O Defrag (OODefrag) - O&O Software GmbH - C:\WINDOWS\system32
                    \oodag.exe
                    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton
                    Internet Security\Norton AntiVirus\SAVScan.exe
                    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -
                    C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
                    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec
                    Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program
                    Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program
                    Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                    O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp
                    Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe

                    • Gość: k Re: Virus alert pojawil sie na pasku -co poczac ? IP: *.warszawa.sdi.tpnet.pl 23.05.06, 11:22
                      Nowy log nie jest potrzebny.
    • Gość: pumiczek Ten sam problem - pomocy :(( IP: *.neoplus.adsl.tpnet.pl 24.05.06, 07:21
      Mam ten sam problem a dodatkowo wyskakują jakies nagle stronki z gołymi babami
      prosze jesli ktos moze mi pomoc o sprawdzenie mojego loga:
      Logfile of HijackThis v1.99.1
      Scan saved at 13:23:02, on 2006-05-17
      Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
      C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\Norton AntiVirus\navapsvc.exe
      C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
      C:\PROGRA~1\P2PNET~1\P2PNET~1.EXE
      C:\Program Files\Serwer wydruków graficznych dla CDN Klasyka\RpWinKla.exe
      C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
      C:\WINDOWS\system32\atmclk.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\DOCUME~1\Andrzej\USTAWI~1\Temp\Katalog tymczasowy 1 dla
      hijackthis.zip\HijackThis.exe
      C:\Program Files\Messenger\msmsgs.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      www.infudex.pl/
      O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program
      Files\Norton AntiVirus\NavShExt.dll
      O2 - BHO: Nothing - {f79fd28e-36ee-4989-aa61-9dd8e30a82fa} - C:\WINDOWS\system32
      \hp4A54.tmp
      O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} -
      C:\Program Files\Norton AntiVirus\NavShExt.dll
      O4 - HKLM\..\Run: [ABBYY Community Agent] C:\Program Files\ABBYY FineReader 5.0
      Pro\CAgent.exe
      O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-
      Packard\HP Share-to-Web\hpgs2wnd.exe
      O4 - HKLM\..\Run: [MediaPipe] "C:\Program Files\MediaPipe\MediaPipe.exe" /H
      O4 - HKLM\..\Run: [MediaPipe P2P Loader] "C:\Program
      Files\p2pnetworks\mpp2pl.exe" /H
      O4 - HKLM\..\Run: [MediaPipeTrayIcon] "C:\Program Files\MediaPipe\MPTray.exe" /H
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
      Shared\ccApp.exe"
      O4 - HKLM\..\Run: [BHR4.1] C:\Program Files\Zamaan's Software\Browser Hijack
      Retaliator 4.1\BHR4.1.exe
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [taskdir] C:\WINDOWS\system32\taskdir.exe
      O4 - HKCU\..\Run: [PestTrap] C:\Program Files\PestTrap\PestTrap.exe
      O4 - Global Startup: Serwer wydruków graficznych dla CDN Klasyka.lnk = ?
      O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
      res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
      C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
      C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-
      00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {1F831FAC-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) -
      file://C:\Program Files\AutoCAD LT 2002 Plk\InstFred.ocx
      O16 - DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} (MainControl Class) -
      arcaonline.arcabit.com/ArcaOnline.cab
      O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday) -
      file://C:\Program Files\AutoCAD LT 2002 Plk\AcDcToday.ocx
      O16 - DPF: {AE56372C-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) -
      file://C:\Program Files\AutoCAD LT 2002 Plk\InstBanr.ocx
      O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
      www.mks.com.pl/skaner/SkanerOnline.cab
      O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) -
      file://C:\Program Files\AutoCAD LT 2002 Plk\AcPreview.ocx
      O17 - HKLM\System\CCS\Services\Tcpip\..\{CEA1D52D-1283-4219-8436-08D779207B60}:
      NameServer = 192.168.0.1
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
      C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -
      C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      O23 - Service: Usługa Auto-Protect programu Norton AntiVirus (navapsvc) -
      Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
      O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec
      Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
      O23 - Service: Usługa Norton Protection Center (NSCService) - Symantec
      Corporation - C:\Program Files\Common Files\Symantec Shared\Security
      Console\NSCSRVCE.EXE
      O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program
      Files\Norton AntiVirus\SAVScan.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec
      Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common
      Files\Symantec Shared\SPBBC\SPBBCSvc.exe
      O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program
      Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

      • Gość: k Re: Ten sam problem - pomocy :(( IP: *.warszawa.sdi.tpnet.pl 24.05.06, 09:58
        Przeciez rozwiaznie masz w tym watku wiec go przeczytaj.

        W hjt usun:
        O2 - BHO: Nothing - {f79fd28e-36ee-4989-aa61-9dd8e30a82fa} - C:\WINDOWS\system32
        \hp4A54.tmp
        O4 - HKLM\..\Run: [MediaPipe] "C:\Program Files\MediaPipe\MediaPipe.exe" /H <-
        odinstaluj i usun katalog MediaPipe.
        O4 - HKLM\..\Run: [MediaPipe P2P Loader] "C:\Program
        Files\p2pnetworks\mpp2pl.exe" /H
        O4 - HKLM\..\Run: [MediaPipeTrayIcon] "C:\Program Files\MediaPipe\MPTray.exe" /H
        O4 - HKCU\..\Run: [taskdir] C:\WINDOWS\system32\taskdir.exe <- usun plik.
        O4 - HKCU\..\Run: [PestTrap] C:\Program Files\PestTrap\PestTrap.exe <- usun
        katalog PestTrap.

        Do tego skan ewido.

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka