Dodaj do ulubionych

proszę o sparwdzenia loga

06.08.06, 20:59
Mam znowu problemy z kompem - już trochę usunęłam skanerami online: mks,
panda, bitdeender oraz enwiro i spybot, ale dalej pisze że mam jakieś spyware

Oto log

Logfile of HijackThis v1.99.1
Scan saved at 20:50:15, on 2006-08-06
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
D:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\CBA\pds.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
E:\instalki\hijackthis\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
D:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program
Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone
Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [dmcvp.exe] C:\WINDOWS\System32\dmcvp.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &
Destroy\TeaTimer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office10\OSA.EXE
O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %
windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 -
{85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file
missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-
00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {5A09E43F-A0A7-4ABF-AF80-11367CF1DC8F} (MainControl Class) -
mks.com.pl/skaner/SkanerOnline.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer
Class) - acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8B3BDA3F-97B3-4C3D-B389-
36FD4E49606D}: NameServer = 85.255.116.74,85.255.112.167
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.74
85.255.112.167
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.74
85.255.112.167
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.74
85.255.112.167
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O21 - SSODL: hubbsi - {7b1eeccd-0a6d-4ad5-8ac1-4af5722b3885} -
C:\WINDOWS\System32\vwlummc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec
Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec
Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. -
D:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINDOWS\System32
\CBA\pds.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program
Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC -
C:\WINDOWS\system32\ZONELABS\vsmon.exe

Obserwuj wątek
    • Gość: Kolobos Re: proszę o sparwdzenia loga IP: *.warszawa.sdi.tpnet.pl 06.08.06, 21:29
      > enwiro

      Coz to takiego? ;-) Gdzie masz ten spyware? Podaj nazwe pliku i lokalizacje.

      Zamknij porty w wwdc, nie uzywaj IE tylko Opere lub FF.

      Uzyj:
      downloads.subratam.org/Fixwareout.exe
      Log z usuwania wklej na forum.

      W hjt usun:
      O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
      O4 - HKLM\..\Run: [dmcvp.exe] C:\WINDOWS\System32\dmcvp.exe <- plik usun z
      dysku.
      O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
      C:\WINDOWS\web\related.htm
      O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-
      00aa003c157a} - C:\WINDOWS\web\related.htm
      O17 - HKLM\System\CCS\Services\Tcpip\..\{8B3BDA3F-97B3-4C3D-B389-
      36FD4E49606D}: NameServer = 85.255.116.74,85.255.112.167
      O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.74
      85.255.112.167
      O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.74
      85.255.112.167
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.74
      85.255.112.167
      O21 - SSODL: hubbsi - {7b1eeccd-0a6d-4ad5-8ac1-4af5722b3885} -
      C:\WINDOWS\System32\vwlummc.dll <- plik usun z dysku.
      • kobietaxyz Re: proszę o sparwdzenia loga 07.08.06, 22:09
        Szanowny Kolobosie, enwiro to oczywiście ewido - wszystkie działania zgodnei z
        tym co się już nauczyłam na tym forum.

        Po użyciu fixwareout otrzymałam


        Fixwareout ver 1.003
        Last edited 07/1/2006
        Post this report in the forums please

        Reg Entries that were deleted
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\swen
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\ogol
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\llun
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\owt
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\eerht
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\ruof
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\evif
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\daolnwodi
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\putesprpgd
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\onisacputes
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\eno
        ...

        Random Runs removed from HKLM
        "dmcvp.exe"=-
        ...

        PLEASE NOTE, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS
        LEAVE THEM ALONE.
        Example ipsec6.exe is legitimate

        »»»»» Search by size and names...

        »»»»» Misc files

        »»»»» Checking for older varients covered by the Rem3 tool

        »»»»»
        Search five digit cs, dm and jb files
        This WILL/CAN also list Legit Files, Submit them at Virustotal
        Other suspects
        Directory of C:\WINDOWS\system32
        {F8404DF8-FEB6-4EA4-B03A-E3D0622601A8}.exe
        {A3D0C44B-1EB4-4AAA-96DB-AE3A5BADFB34}.exe
        • kobietaxyz Re: proszę o sparwdzenia loga 07.08.06, 22:22
          C:\WINDOWS\System32\vwlummc.dll <- plik usun z dysku.

          tego ne moge usunąc bo wyskakuje, ze ten plik jest używany


          Nei wiem czy to coś pomoże, ale zamieszczam to piszę w Spybocie
          006-08-06 19:43:23 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:43:50 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:43:53 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:43:55 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:43:58 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:44:01 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:44:03 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:44:06 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:44:09 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:44:20 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:44:24 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:44:26 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:44:30 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:44:57 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:45:05 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:45:20 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:45:26 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:45:28 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:45:31 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:45:35 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:45:39 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:45:41 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:45:49 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:45:51 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:45:53 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:45:56 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:45:58 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:01 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:03 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:05 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:08 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:10 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:17 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:19 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:22 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:24 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:27 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:29 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:32 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:34 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:37 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:39 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:42 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:46 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:49 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:51 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:53 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:55 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:46:59 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:02 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:05 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:07 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:10 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:12 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:15 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:18 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:20 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:23 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:25 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:27 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:30 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:33 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:35 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:38 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:40 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:43 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:46 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:48 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:51 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:53 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:56 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:47:58 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:48:01 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:48:03 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:48:06 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:48:09 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:48:11 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-06 19:48:14 Encountered and terminated Smitfraud-C. in
          C:\WINDOWS\System32\isnotify.exe!
          2006-08-
          • kobietaxyz log po zmianach 07.08.06, 22:24
            a oto log po zmianach


            Logfile of HijackThis v1.99.1
            Scan saved at 22:22:27, on 2006-08-07
            Platform: Windows XP (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 (6.00.2600.0000)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\ZONELABS\vsmon.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
            C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Symantec AntiVirus\DefWatch.exe
            D:\Program Files\ewido anti-spyware 4.0\guard.exe
            C:\WINDOWS\System32\CBA\pds.exe
            C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
            C:\Program Files\Symantec AntiVirus\Rtvscan.exe
            C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
            C:\Program Files\Common Files\Symantec Shared\ccApp.exe
            C:\PROGRA~1\SYMANT~1\VPTray.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\WINDOWS\System32\wuauclt.exe
            E:\instalki\hijackthis\hijackthis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
            D:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program
            Files\Spybot - Search & Destroy\SDHelper.dll
            O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
            C:\WINDOWS\System32\msdxm.ocx
            O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone
            Labs\ZoneAlarm\zlclient.exe"
            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
            Shared\ccApp.exe"
            O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &
            Destroy\TeaTimer.exe
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
            Office\Office10\OSA.EXE
            O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
            res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%
            \bdoscandel.exe (file missing)
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 -
            {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
            O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
            O16 - DPF: {5A09E43F-A0A7-4ABF-AF80-11367CF1DC8F} (MainControl Class) -
            mks.com.pl/skaner/SkanerOnline.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
            download.bitdefender.com/resources/scan8/oscan8.cab
            O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
            acs.pandasoftware.com/activescan/as5free/asinst.cab
            O17 - HKLM\System\CCS\Services\Tcpip\..\{4AAF5DD8-F4DF-49E7-B603-2B699750FBA6}:
            NameServer = 85.255.116.74 85.255.112.167
            O17 - HKLM\System\CS1\Services\Tcpip\..\{4AAF5DD8-F4DF-49E7-B603-2B699750FBA6}:
            NameServer = 85.255.116.74 85.255.112.167
            O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
            C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
            O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation -
            C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -
            C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
            O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec
            Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
            O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. -
            D:\Program Files\ewido anti-spyware 4.0\guard.exe
            O23 - Service: Intel PDS - Intel® Corporation - C:\WINDOWS\System32\CBA\pds.exe
            O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program
            Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
            O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program
            Files\Symantec AntiVirus\Rtvscan.exe
            O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC -
            C:\WINDOWS\system32\ZONELABS\vsmon.exe

            • Gość: Kolobos Re: log po zmianach IP: *.warszawa.sdi.tpnet.pl 08.08.06, 18:09
              Do ksacji:
              O17 - HKLM\System\CCS\Services\Tcpip\..\{4AAF5DD8-F4DF-49E7-B603-2B699750FBA6}:
              NameServer = 85.255.116.74 85.255.112.167
              O17 - HKLM\System\CS1\Services\Tcpip\..\{4AAF5DD8-F4DF-49E7-B603-2B699750FBA6}:
              NameServer = 85.255.116.74 85.255.112.167
          • Gość: Kolobos Re: proszę o sparwdzenia loga IP: *.warszawa.sdi.tpnet.pl 08.08.06, 18:08
            Wiec uzyj killbox'a z opcja delete on reboot i usun:
            C:\WINDOWS\System32\vwlummc.dll
            lub Start->uruchom->regsvr32 /u C:\WINDOWS\System32\vwlummc.dll
            i dopiero usun.

            Usun z dysku jeszcze:
            z C:\WINDOWS\system32
            {F8404DF8-FEB6-4EA4-B03A-E3D0622601A8}.exe
            {A3D0C44B-1EB4-4AAA-96DB-AE3A5BADFB34}.exe
            isnotify.exe

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka