Dodaj do ulubionych

prosze o sprawdzenie loga

IP: *.autocom.pl 23.10.06, 22:51
Logfile of HijackThis v1.99.1
Scan saved at 10:48:04 PM, on 10/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Borland\InterBase\bin\ibguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\Borland\InterBase\bin\ibserver.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\TOSHIBA\IVP\ISM\pinger.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\COMMON~1\SEMBLY~1\winspool.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Documents and Settings\Kubus Puchatek\Desktop\hijackthis\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
www.gazeta.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
go.microsoft.com/fwlink/?LinkId=69157
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat
7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} -
C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -
C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:\program files\google\googletoolbar3.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} -
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} -
C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program
Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming
Utility\SmoothView.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog
Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog
Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [Pinger] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [IntelWireless] C:\Program
Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [Notebook Maximizer] C:\Program Files\Notebook
Maximizer\maximizer_startup.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe"
-atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat
7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec
Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
/Consumer
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG
Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [VoipBuster] "C:\Program
Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash
/minimized
O4 - HKCU\..\Run: [swg] C:\Program
Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Eprc] "C:\PROGRA~1\COMMON~1\SEMBLY~1\winspool.exe" -vt yazb
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
Files\Adobe\Calibration\Adobe G
Obserwuj wątek
    • Gość: mirr Re: prosze o sprawdzenie loga IP: *.autocom.pl 23.10.06, 23:14
      mialem problem z jakims g... programikiem o nazwie OIN. Zostal niby wywalony
      przy pomocy specjalnego deinstalatora odnalezionego w sieci. Niby jest ok, ale
      od czasu do czasu znow pojawiaja sie jakies dziwne okienka
    • Gość: Kolobos Re: prosze o sprawdzenie loga IP: *.escom.net.pl 24.10.06, 00:55
      Na poczatek skan przy pomocy ewido.

      W menadzerze zadan zakoncz:
      C:\PROGRA~1\COMMON~1\SEMBLY~1\winspool.exe

      W hjt usun:
      R3 - Default URLSearchHook is missing
      O4 - HKCU\..\Run: [Eprc] "C:\PROGRA~1\COMMON~1\SEMBLY~1\winspool.exe" -vt yazb <- plik usun z dysku.

      Log sie nie zmiescil, a wiec doklej reszte od:
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
      Files\Adobe\Calibration\Adobe G

      (tylko nie probuj znowu wklejac calosci...)
      • Gość: mirr Re: prosze o sprawdzenie loga IP: *.autocom.pl 24.10.06, 03:19
        ok, tutaj jest reszta

        O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program
        Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
        O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1
        \MICROS~2\OFFICE11\EXCEL.EXE/3000
        O8 - Extra context menu item: Konwertuj do Adobe PDF - res://C:\Program
        Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
        O8 - Extra context menu item: Konwertuj miejsce docelowe lacza do Adobe PDF -
        res://C:\Program Files\Adobe\Acrobat 7.0
        \Acrobat\AcroIEFavClient.dll/AcroIECapture.html
        O8 - Extra context menu item: Konwertuj miejsce docelowe lacza do istniejacego
        pliku PDF - res://C:\Program Files\Adobe\Acrobat 7.0
        \Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
        O8 - Extra context menu item: Konwertuj wybrane lacza do Adobe PDF -
        res://C:\Program Files\Adobe\Acrobat 7.0
        \Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
        O8 - Extra context menu item: Konwertuj zaznaczenie do Adobe PDF -
        res://C:\Program Files\Adobe\Acrobat 7.0
        \Acrobat\AcroIEFavClient.dll/AcroIECapture.html
        O8 - Extra context menu item: Konwertuj zaznaczenie do istniejacego pliku PDF -
        res://C:\Program Files\Adobe\Acrobat 7.0
        \Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
        C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
        00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
        O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
        C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no
        file)
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%
        \Network Diagnostic\xpnetdiag.exe (file missing)
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-
        f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
        C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-
        00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O11 - Options group: [INTERNATIONAL] International*
        O14 - IERESET.INF: START_PAGE_URL=www.toshibadirect.com/dpdstart
        O15 - Trusted Zone: www.mks.com.pl
        O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
        www.kaspersky.pl/resources/virusscanner/kavwebscan_unicode.cab
        O16 - DPF: {5A09E43F-A0A7-4ABF-AF80-11367CF1DC8F} (MainControl Class) -
        mks.com.pl/skaner/SkanerOnline.cab
        O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner
        3.0) - support.f-secure.com/ols/fscax.cab
        O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
        O20 - Winlogon Notify: IntelWireless - C:\Program
        Files\Intel\Wireless\Bin\LgNotify.dll
        O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
        O20 - Winlogon Notify: winhco32 - winhco32.dll (file missing)
        O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common
        Files\Adobe Systems Shared\Service\Adobelmsvc.exe
        O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. -
        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32
        \drivers\CDAC11BA.EXE
        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
        C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
        O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec
        Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
        O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program
        Files\TOSHIBA\ConfigFree\CFSvcs.exe
        O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. -
        C:\WINDOWS\system32\DVDRAMSV.exe
        O23 - Service: EvtEng - Intel Corporation - C:\Program
        Files\Intel\Wireless\Bin\EvtEng.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision
        Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32
        \IDriverT.exe
        O23 - Service: InterBase Guardian (InterBaseGuardian) - Inprise Corporation -
        C:\Program Files\Borland\InterBase\bin\ibguard.exe
        O23 - Service: InterBase Server (InterBaseServer) - Inprise Corporation -
        C:\Program Files\Borland\InterBase\bin\ibserver.exe
        O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. -
        C:\WINDOWS\system32\LEXBCES.EXE
        O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec
        Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
        O23 - Service: Norton Unerase Protection (NProtectService) - Symantec
        Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
        O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program
        Files\Intel\Wireless\Bin\OProtSvc.exe
        O23 - Service: RegSrvc - Intel Corporation - C:\Program
        Files\Intel\Wireless\Bin\RegSrvc.exe
        O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation -
        C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
        O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -
        C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec
        Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
        O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) -
        Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
        O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
        O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program
        Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
        O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. -
        C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
        O23 - Service: Ç-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32
        \DRIVERS\CDANTSRV.EXE

        • Gość: Kolobos Re: prosze o sprawdzenie loga IP: *.escom.net.pl 24.10.06, 10:20
          Zostaw tylko JEDEN antyvirus, a wiec albo norton albo avg.

          W hjt usun:
          O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no
          file)
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%
          \Network Diagnostic\xpnetdiag.exe (file missing)
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-
          f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
          O20 - Winlogon Notify: winhco32 - winhco32.dll (file missing)

          Uzyj tez:
          siri.urz.free.fr/Fix/SmitfraudFix_En.php (robisz to co masz pod "Clean").
          • Gość: mirr Re: log po usunieciu wg zalecen IP: *.autocom.pl 24.10.06, 12:33
            Logfile of HijackThis v1.99.1
            Scan saved at 12:30:03 PM, on 10/24/2006
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.5730.0011)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
            C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
            C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
            C:\WINDOWS\system32\LEXBCES.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\system32\LEXPPS.EXE
            C:\WINDOWS\system32\drivers\CDAC11BA.EXE
            C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
            C:\WINDOWS\system32\DVDRAMSV.exe
            C:\Program Files\Borland\InterBase\bin\ibguard.exe
            C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
            C:\Program Files\Norton AntiVirus\navapsvc.exe
            C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
            C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
            C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
            C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
            C:\WINDOWS\system32\svchost.exe
            c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
            C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
            C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
            C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
            C:\Program Files\Borland\InterBase\bin\ibserver.exe
            C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
            C:\WINDOWS\Explorer.EXE
            C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
            C:\WINDOWS\system32\igfxtray.exe
            C:\WINDOWS\system32\hkcmd.exe
            C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
            C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
            C:\Program Files\ltmoh\Ltmoh.exe
            C:\WINDOWS\AGRSMMSG.exe
            C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
            C:\Program Files\Toshiba\Tvs\TvsTray.exe
            C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
            C:\WINDOWS\system32\dla\tfswctrl.exe
            C:\WINDOWS\system32\TPSMain.exe
            C:\WINDOWS\system32\TPSBattM.exe
            C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
            C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
            C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
            C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
            C:\Program Files\TOSHIBA\ConfigFree\CFXFER.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
            C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
            C:\Program Files\Common Files\Symantec Shared\ccApp.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
            C:\Program Files\Skype\Phone\Skype.exe
            C:\WINDOWS\system32\RAMASST.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\TOSHIBA\IVP\ISM\ivpsvmgr.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            C:\Documents and Settings\Kubus Puchatek\Desktop\hijackthis\hijackthis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
            www.gazeta.pl/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
            go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
            go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
            go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
            go.microsoft.com/fwlink/?LinkId=69157
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
            - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} -
            C:\WINDOWS\system32\dla\tfswshx.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
            Files\Java\jre1.5.0_06\bin\ssv.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
            c:\program files\google\googletoolbar3.dll
            O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} -
            C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
            O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program
            Files\Norton AntiVirus\NavShExt.dll
            O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program
            Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
            O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
            C:\Program Files\Norton AntiVirus\NavShExt.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
            files\google\googletoolbar3.dll
            O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
            O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
            O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
            O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
            O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
            O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
            O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming
            Utility\SmoothView.exe
            O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
            O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog
            Devices\SoundMAX\SMax4PNP.exe
            O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
            /tray
            O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
            O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
            O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
            O4 - HKLM\..\Run: [Pinger] C:\TOSHIBA\IVP\ISM\pinger.exe /run
            O4 - HKLM\..\Run: [IntelWireless] C:\Program
            Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
            O4 - HKLM\..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
            O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
            O4 - HKLM\..\Run: [Notebook Maximizer] C:\Program Files\Notebook
            Maximizer\maximizer_startup.exe
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe"
            -atboottime
            O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
            Files\Java\jre1.5.0_06\bin\jusched.exe
            O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat
            7.0\Distillr\Acrotray.exe"
            O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
            O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec
            Shared\ccRegVfy.exe
            O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
            O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
            /Consumer
            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware
            7.5\avgas.exe" /minimized
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKCU\..\Run: [VoipBuster] "C:\Program
            Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized
            O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash
            /minimized
            O4 - HKCU\..\Run: [swg] C:\Program
            Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
            O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
            O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
            Files\Adobe\Calibration\Adobe Gamma Loader.exe
            O4
            • Gość: mirr Re: log po usunieciu wg zalecen IP: *.autocom.pl 24.10.06, 12:38
              tutaj jest reszta
              nie mam 2 antywirusow, AVG to tylko anty spyware


              O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program
              Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
              O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
              O8 - Extra context menu item: E&xport to Microsoft Excel -
              res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
              O8 - Extra context menu item: Konwertuj do Adobe PDF - res://C:\Program
              Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
              O8 - Extra context menu item: Konwertuj miejsce docelowe lacza do Adobe PDF -
              res://C:\Program Files\Adobe\Acrobat
              7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
              O8 - Extra context menu item: Konwertuj miejsce docelowe lacza do istniejacego
              pliku PDF - res://C:\Program Files\Adobe\Acrobat
              7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
              O8 - Extra context menu item: Konwertuj wybrane lacza do Adobe PDF -
              res://C:\Program Files\Adobe\Acrobat
              7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
              O8 - Extra context menu item: Konwertuj zaznaczenie do Adobe PDF -
              res://C:\Program Files\Adobe\Acrobat
              7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
              O8 - Extra context menu item: Konwertuj zaznaczenie do istniejacego pliku PDF -
              res://C:\Program Files\Adobe\Acrobat
              7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
              C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Sun Java Console -
              {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
              Files\Java\jre1.5.0_06\bin\ssv.dll
              O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
              C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
              C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger -
              {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O11 - Options group: [INTERNATIONAL] International*
              O14 - IERESET.INF: START_PAGE_URL=www.toshibadirect.com/dpdstart
              O15 - Trusted Zone: www.mks.com.pl
              O16 - DPF: {5A09E43F-A0A7-4ABF-AF80-11367CF1DC8F} (MainControl Class) -
              mks.com.pl/skaner/SkanerOnline.cab
              O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0)
              - support.f-secure.com/ols/fscax.cab
              O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
              O20 - Winlogon Notify: IntelWireless - C:\Program
              Files\Intel\Wireless\Bin\LgNotify.dll
              O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
              O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common
              Files\Adobe Systems Shared\Service\Adobelmsvc.exe
              O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. -
              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd -
              C:\WINDOWS\system32\drivers\CDAC11BA.EXE
              O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
              C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
              O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec
              Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
              O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program
              Files\TOSHIBA\ConfigFree\CFSvcs.exe
              O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. -
              C:\WINDOWS\system32\DVDRAMSV.exe
              O23 - Service: EvtEng - Intel Corporation - C:\Program
              Files\Intel\Wireless\Bin\EvtEng.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation
              - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: InterBase Guardian (InterBaseGuardian) - Inprise Corporation -
              C:\Program Files\Borland\InterBase\bin\ibguard.exe
              O23 - Service: InterBase Server (InterBaseServer) - Inprise Corporation -
              C:\Program Files\Borland\InterBase\bin\ibserver.exe
              O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. -
              C:\WINDOWS\system32\LEXBCES.EXE
              O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec
              Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
              O23 - Service: Norton Unerase Protection (NProtectService) - Symantec
              Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
              O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program
              Files\Intel\Wireless\Bin\OProtSvc.exe
              O23 - Service: RegSrvc - Intel Corporation - C:\Program
              Files\Intel\Wireless\Bin\RegSrvc.exe
              O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation -
              C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
              O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -
              C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
              O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation
              - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
              O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) -
              Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
              O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
              O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program
              Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
              O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. -
              C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
              O23 - Service: Ç-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE

              • Gość: Kolobos Re: log po usunieciu wg zalecen IP: *.escom.net.pl 24.10.06, 15:12
                Log wyglada juz ok.

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka