Dodaj do ulubionych

Log do sprawdzenia

IP: *.adsl.inetia.pl 08.12.06, 18:40
Kolobos prosze sprawdz tego loga bo mi wykrywa trojana clickera, net mi sie
rozłącza co chwile (modem) ja w tym logu nic nie widze sprawdź go...

Logfile of HijackThis v1.99.1
Scan saved at 18:35:06, on 2006-12-08
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\DriveCrypt\DcrServ.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Softwin\BitDefender10\bdagent.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\DriveCrypt\DriveCrypt.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Softwin\BitDefender10\bdmcon.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\Program Files\Softwin\BitDefender10\bdlite.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Sebek\Pulpit\Instalki\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
www.dict.pl/plen
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Acrobat 6.0.1\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} -
C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} -
C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -
C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
C:\WINDOWS\Downloaded Program Files\googlenav.dll
O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} -
C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} -
C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [NVRTCLK] C:\WINDOWS\system32\NVRTCLK\NVRTClk.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32
\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32
\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program
Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-
Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09
\bin\jusched.exe"
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10
\bdmcon.exe" /reg
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10
\bdagent.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-
88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DriveCrypt Startup] c:\Program
Files\DriveCrypt\DriveCrypt.exe /WS
O8 - Extra context menu item: &Google Search - res://C:\WINDOWS\Downloaded
Program Files\googlenav.dll/cmsearch.html
O8 - Extra context menu item: &Ściągnij wszystko za pomocą WellGeta -
C:\Program Files\WellGet\nxall.htm
O8 - Extra context menu item: Backward &Links - res://C:\WINDOWS\Downloaded
Program Files\googlenav.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page -
res://C:\WINDOWS\Downloaded Program Files\googlenav.dll/cmcache.html
O8 - Extra context menu item: Post Image to Blog -
res://C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Si&milar Pages - res://C:\WINDOWS\Downloaded
Program Files\googlenav.dll/cmsimilar.html
O8 - Extra context menu item: Tag This Image -
res://C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Upload All Images to ImageShack -
res://C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack -
res://C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll/5001
O8 - Extra context menu item: Ściągnij za pomocą &WellGeta - C:\Program
Files\WellGet\nxcatch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: WellGet - {35980F6E-A258-4E50-953D-813BB8556899} -
C:\Program Files\WellGet\WellGet.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} -
C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} -
C:\Program Files\IrfanView\Ebay\Ebay.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: toolbar.imageshack.us
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient
Class) -
messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) -
toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} (Google Activate) -
toolbar1.google.com/data/pl/big/1.1.62-big/GoogleNav.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient
Class) -
messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) -
www.systemrequirementslab.com/sysreqlab.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{37DCA4E9-8971-4F97-A8C4-
DCA3B7BF4517}: NameServer = 213.241.79.37 195.114.181.130
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1
\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4D
Obserwuj wątek
    • Gość: Ytek Re: Log do sprawdzenia IP: *.adsl.inetia.pl 08.12.06, 18:41
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. -
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program
      Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file
      missing)
      O23 - Service: DriveCrypt Service (DriveCryptService) - Unknown owner -
      C:\Program Files\DriveCrypt\DcrServ.exe
      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner -
      C:\Program Files\Common Files\Softwin\BitDefender Update
      Service\livesrv.exe" /service (file missing)
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
      C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. -
      C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
      O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program
      Files\Softwin\BitDefender10\vsserv.exe" /service (file missing)
      O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program
      Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service
      (file missing)
      • Gość: Kolobos Re: Log do sprawdzenia IP: *.escom.net.pl 08.12.06, 20:11
        Po co zakladasz juz trzeci watek? Nie mogles pisac caly czas w jednym?
        Log jest ok.

        > wykrywa trojana clickera

        W jakim pliku?

        > net mi sie rozłącza co chwile (modem)

        To nie ma zwiazku z log'iem, jak rozumiem chodzi o modem dsl? Jezeli tak to winny jest raczej uslugodawca.
        • Gość: Ytek Re: Log do sprawdzenia IP: *.adsl.inetia.pl 08.12.06, 22:30
          Ano to ---> img163.imageshack.us/img163/3376/tonn3.png
          • Gość: Ytek Re: Log do sprawdzenia IP: *.adsl.inetia.pl 08.12.06, 22:34
            I teraz jeszcze to img146.imageshack.us/img146/7628/itoix0.jpg
            a log wpożądku wiec co jest ?
          • Gość: Kolobos Re: Log do sprawdzenia IP: *.escom.net.pl 08.12.06, 22:42
            Wklej log z silentrunners oraz log z gmera z zakladki rootkit (log z gmera wyslij mi na maila).
            Plik C:\WINDOWS\System32\usbpda.dll usun przy pomocy killbox'a.
            • Gość: Ytek Re: Log do sprawdzenia IP: *.adsl.inetia.pl 08.12.06, 22:58
              "Silent Runners.vbs", revision 46, www.silentrunners.org/
              Operating System: Windows XP SP2
              Output limited to non-default values, except where indicated by "{++}"


              Startup items buried in registry:
              ---------------------------------

              HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
              "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" = ""C:\Program Files\Common
              Files\Ahead\Lib\NMBgMonitor.exe"" ["Nero AG"]
              "DriveCrypt Startup" = "c:\Program Files\DriveCrypt\DriveCrypt.exe /WS"
              ["Secustar"]

              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
              "NVRTCLK" = "C:\WINDOWS\system32\NVRTCLK\NVRTClk.exe" [empty string]
              "NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup" [MS]
              "nwiz" = "nwiz.exe /install" ["NVIDIA Corporation"]
              "NvMediaCenter" = "RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit"
              [MS]
              "SpeedTouch USB Diagnostics" = ""C:\Program Files\Thomson\SpeedTouch
              USB\Dragdiag.exe" /icon" ["THOMSON Telecom Belgium"]
              "!AVG Anti-Spyware" = ""C:\Program Files\Grisoft\AVG Anti-Spyware 7.5
              \avgas.exe" /minimized" ["Anti-Malware Development a.s."]
              "SunJavaUpdateSched" = ""C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe""
              ["Sun Microsystems, Inc."]
              "BDMCon" = ""C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg" ["SOFTWIN
              S.R.L."]
              "BDAgent" = ""C:\Program Files\Softwin\BitDefender10\bdagent.exe"" ["SOFTWIN
              S.R.L."]

              HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
              {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
              -> {HKLM...CLSID} = "AcroIEHlprObj Class"
              \InProcServer32\(Default) = "C:\Program Files\Acrobat 6.0.1
              \Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
              {22BF413B-C6D2-4d91-82A9-A0F997BA588C}\(Default) = "Skype add-on (mastermind)"
              -> {HKLM...CLSID} = "Skype add-on (mastermind)"
              \InProcServer32\(Default) = "C:\PROGRA~1
              \Skype\Phone\IEPlugin\SKYPEI~1.DLL" ["Skype Technologies S.A."]
              {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}\(Default) = (no title provided)
              -> {HKLM...CLSID} = "Megaupload Toolbar"
              \InProcServer32\(Default) = "C:\PROGRA~1\MEGAUP~1
              \MEGAUP~1.DLL" ["MegaUpload"]
              {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
              -> {HKLM...CLSID} = "SSVHelper Class"
              \InProcServer32\(Default) = "C:\Program
              Files\Java\jre1.5.0_09\bin\ssv.dll" ["Sun Microsystems, Inc."]

              HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
              "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania
              wyświetlania"
              -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
              \InProcServer32\(Default) = "deskpan.dll" [file not found]
              "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
              -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
              \InProcServer32\(Default) = "C:\WINDOWS\system32
              \hticons.dll" ["Hilgraeve, Inc."]
              "{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
              -> {HKLM...CLSID} = "DesktopContext Class"
              \InProcServer32\(Default) = "C:\WINDOWS\system32\nvcpl.dll"
              ["NVIDIA Corporation"]
              "{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
              -> {HKLM...CLSID} = "NVIDIA CPL Extension"
              \InProcServer32\(Default) = "C:\WINDOWS\system32\nvcpl.dll"
              ["NVIDIA Corporation"]
              "{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
              -> {HKLM...CLSID} = "Desktop Explorer"
              \InProcServer32\(Default) = "C:\WINDOWS\system32
              \nvshell.dll" ["NVIDIA Corporation"]
              "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
              -> {HKLM...CLSID} = (no title provided)
              \InProcServer32\(Default) = "C:\WINDOWS\system32
              \nvshell.dll" ["NVIDIA Corporation"]
              "{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"
              -> {HKLM...CLSID} = "nView Desktop Context Menu"
              \InProcServer32\(Default) = "C:\WINDOWS\system32
              \nvshell.dll" ["NVIDIA Corporation"]
              "{7850a720-705f-11d0-a9eb-0080488625e5}" = "BestCrypt Shell Extension"
              -> {HKLM...CLSID} = "BestCrypt Shell Extension"
              \InProcServer32\(Default) = "BCShExt.dll" ["Jetico, Inc."]
              "{B327765E-D724-4347-8B16-78AE18552FC3}" = "NeroDigitalIconHandler"
              -> {HKLM...CLSID} = "NeroDigitalIconHandler Class"
              \InProcServer32\(Default) = "C:\Program Files\Common
              Files\Ahead\lib\NeroDigitalExt.dll" ["Nero AG"]
              "{7F1CF152-04F8-453A-B34C-E609530A9DC8}" = "NeroDigitalPropSheetHandler"
              -> {HKLM...CLSID} = "NeroDigitalPropSheetHandler Class"
              \InProcServer32\(Default) = "C:\Program Files\Common
              Files\Ahead\lib\NeroDigitalExt.dll" ["Nero AG"]
              "{32020A01-506E-484D-A2A8-BE3CF17601C3}" = "AlcoholShellEx"
              -> {HKLM...CLSID} = "AlcoholShellEx"
              \InProcServer32\(Default) = "C:\PROGRA~1\ALCOHO~1\ALCOHO~1
              \AXShlEx.dll" [file not found]
              "{73B24247-042E-4EF5-ADC2-42F62E6FD654}" = "ICQ Lite Shell Extension"
              -> {HKLM...CLSID} = "MCLiteShellExt Class"
              \InProcServer32\(Default) = "C:\Program
              Files\ICQLite\ICQLiteShell.dll" [file not found]
              "{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes"
              -> {HKLM...CLSID} = "iTunes"
              \InProcServer32\(Default) = "C:\Program
              Files\QuickTime\iTunesMiniPlayer.dll" ["Apple Computer, Inc."]
              "{7A4097B2-6022-4670-995F-DA363EBF947F}" = "Custom shell context menu extension"
              -> {HKLM...CLSID} = "Custom shell context menu extension"
              \InProcServer32\(Default) = "C:\WINDOWS\system32
              \shctxex.dll" [empty string]
              "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
              -> {HKLM...CLSID} = "WinRAR"
              \InProcServer32\(Default) = "C:\Program
              Files\WinRAR\rarext.dll" [null data]

              HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
              INFECTION WARNING! "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" = "AVG Anti-Spyware
              7.5"
              -> {HKLM...CLSID} = "CShellExecuteHookImpl Object"
              \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG
              Anti-Spyware 7.5\shellexecutehook.dll" ["Anti-Malware Development a.s."]

              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\
              INFECTION WARNING! "AppInit_DLLs" = "sockspy.dll" [null data]

              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
              "System" = (value not set)

              HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
              {7D4D6379-F301-4311-BEBA-E26EB0561882}\(Default)
              = "NeroDigitalExt.NeroDigitalColumnHandler"
              -> {HKLM...CLSID} = "NeroDigitalColumnHandler Class"
              \InProcServer32\(Default) = "C:\Program Files\Common
              Files\Ahead\lib\NeroDigitalExt.dll" ["Nero AG"]

              HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
              AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
              -> {HKLM...CLSID} = "CContextScan Object"
              \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG
              Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."]
              BCShellMenu\(Default) = "{7850a720-705f-11d0-a9eb-0080488625e5}"
              -> {HKLM...CLSID} = "BestCrypt Shell Extension"
              \InProcServer32\(Default) = "BCShExt.dll" ["Jetico, Inc."]
              Custom shell context menu extension\(Default) = "{7A4097B2-6022-4670-995F-
              DA363EBF947F}"
              -> {HKLM...CLSID} = "Custom shell context menu extension"
              \InProcServer32\(Default) = "C:\WINDOWS\system32
              \shctxex.dll" [empty string]
              ICQLiteMenu\(Default) = "{73B24247-042E-4EF5-ADC2-42F62E6FD654}"
              -> {HKLM...CLSID} = "MCLiteShellExt Class"
              \InProcServer32\(Default) = "C:\Program
              Files\ICQLite\ICQLiteShell.dll" [file not found]
              WinRAR\(Default) = "{B41DB
              • Gość: Ytek Re: Log do sprawdzenia IP: *.adsl.inetia.pl 08.12.06, 22:59
                ICQLiteMenu\(Default) = "{73B24247-042E-4EF5-ADC2-42F62E6FD654}"
                -> {HKLM...CLSID} = "MCLiteShellExt Class"
                \InProcServer32\(Default) = "C:\Program
                Files\ICQLite\ICQLiteShell.dll" [file not found]
                WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                -> {HKLM...CLSID} = "WinRAR"
                \InProcServer32\(Default) = "C:\Program
                Files\WinRAR\rarext.dll" [null data]

                HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
                BCShellMenu\(Default) = "{7850a720-705f-11d0-a9eb-0080488625e5}"
                -> {HKLM...CLSID} = "BestCrypt Shell Extension"
                \InProcServer32\(Default) = "BCShExt.dll" ["Jetico, Inc."]
                WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                -> {HKLM...CLSID} = "WinRAR"
                \InProcServer32\(Default) = "C:\Program
                Files\WinRAR\rarext.dll" [null data]


                Active Desktop and Wallpaper:
                -----------------------------

                Active Desktop is disabled at this entry:
                HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

                HKCU\Control Panel\Desktop\
                "Wallpaper" = "C:\Documents and Settings\Sebek\Ustawienia lokalne\Dane
                aplikacji\Microsoft\Wallpaper1.bmp"


                Winsock2 Service Provider DLLs:
                -------------------------------

                Namespace Service Providers

                HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5
                \Catalog_Entries\ {++}
                000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
                000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
                000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

                Transport Service Providers

                HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9
                \Catalog_Entries\ {++}
                0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
                %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15
                %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


                Toolbars, Explorer Bars, Extensions:
                ------------------------------------

                Toolbars

                HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
                "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
                -> {HKLM...CLSID} = "&Google"
                \InProcServer32\(Default) = "C:\WINDOWS\Downloaded Program
                Files\googlenav.dll" ["Google Inc."]
                "{37B85A29-692B-4205-9CAD-2626E4993404}"
                -> {HKLM...CLSID} = "My Global Search Bar"
                \InProcServer32\(Default) = "C:\Program
                Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL" [file not found]
                "{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}"
                -> {HKLM...CLSID} = "Megaupload Toolbar"
                \InProcServer32\(Default) = "C:\PROGRA~1\MEGAUP~1
                \MEGAUP~1.DLL" ["MegaUpload"]

                HKLM\Software\Microsoft\Internet Explorer\Toolbar\
                "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)
                -> {HKLM...CLSID} = "&Google"
                \InProcServer32\(Default) = "C:\WINDOWS\Downloaded Program
                Files\googlenav.dll" ["Google Inc."]
                "{6932D140-ABC4-4073-A44C-D4A541665E35}" = "ImageShack Toolbar"
                -> {HKLM...CLSID} = "ImageShack Toolbar"
                \InProcServer32\(Default)
                = "C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll" ["ImageShack Corp."]
                "{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}" = (no title provided)
                -> {HKLM...CLSID} = "Megaupload Toolbar"
                \InProcServer32\(Default) = "C:\PROGRA~1\MEGAUP~1
                \MEGAUP~1.DLL" ["MegaUpload"]

                Extensions (Tools menu items, main toolbar menu buttons)

                HKLM\Software\Microsoft\Internet Explorer\Extensions\
                {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
                "MenuText" = "Sun Java Console"
                "CLSIDExtension" = "{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}"
                -> {HKCU...CLSID} = "Java Plug-in 1.5.0_09"
                \InProcServer32\(Default) = "C:\Program
                Files\Java\jre1.5.0_09\bin\ssv.dll" ["Sun Microsystems, Inc."]
                -> {HKLM...CLSID} = "Java Plug-in 1.5.0_09"
                \InProcServer32\(Default) = "C:\Program
                Files\Java\jre1.5.0_09\bin\npjpi150_09.dll" ["Sun Microsystems, Inc."]

                {35980F6E-A258-4E50-953D-813BB8556899}\
                "ButtonText" = "WellGet"
                "Exec" = "C:\Program Files\WellGet\WellGet.exe" [empty string]

                {77BF5300-1474-4EC7-9980-D32B190E9B07}\
                "ButtonText" = "Skype"
                "CLSIDExtension" = "{77BF5300-1474-4EC7-9980-D32B190E9B07}"
                -> {HKLM...CLSID} = "Skype add-on (button)"
                \InProcServer32\(Default) = "C:\PROGRA~1
                \Skype\Phone\IEPlugin\SKYPEI~1.DLL" ["Skype Technologies S.A."]

                {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A}\
                "ButtonText" = "eBay - Homepage"
                "CLSIDExtension" = "{1FBA04EE-3024-11D2-8F1F-0000F87ABD16}"
                -> {HKLM...CLSID} = "Toolbar Extension for Executable"
                \InProcServer32\(Default) = "C:\WINDOWS\system32
                \shdocvw.dll" [MS]
                "Exec" = "C:\Program Files\IrfanView\Ebay\Ebay.htm" [null data]

                {FB5F1910-F110-11D2-BB9E-00C04F795683}\
                "ButtonText" = "Messenger"
                "MenuText" = "Windows Messenger"
                "Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]


                Running Services (Display Name, Service Name, Path {Service DLL}):
                ------------------------------------------------------------------

                AVG Anti-Spyware Guard, AVG Anti-Spyware Guard, "C:\Program Files\Grisoft\AVG
                Anti-Spyware 7.5\guard.exe" ["Anti-Malware Development a.s."]
                BitDefender Communicator, XCOMM, ""C:\Program Files\Common
                Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service" ["Softwin"]
                BitDefender Desktop Update Service, LIVESRV, ""C:\Program Files\Common
                Files\Softwin\BitDefender Update Service\livesrv.exe" /service" ["SOFTWIN
                S.R.L."]
                BitDefender Scan Server, bdss, ""C:\Program Files\Common
                Files\Softwin\BitDefender Scan Server\bdss.exe" /service" [null data]
                BitDefender Virus Shield, VSSERV, ""C:\Program Files\Softwin\BitDefender10
                \vsserv.exe" /service" ["SOFTWIN S.R.L."]
                DriveCrypt Service, DriveCryptService, "C:\Program
                Files\DriveCrypt\DcrServ.exe" [null data]
                NVIDIA Display Driver Service, NVSvc, "C:\WINDOWS\system32\nvsvc32.exe"
                ["NVIDIA Corporation"]
                Ulead Burning Helper, UleadBurningHelper, "C:\Program Files\Common Files\Ulead
                Systems\DVD\ULCDRSvr.exe" ["Ulead Systems, Inc."]
                USB Data Adapter, Usbpda, "C:\WINDOWS\System32\svchost.exe -k netsvcs"
                {"C:\WINDOWS\System32\usbpda.dll" [file not found]}
                Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]


                ----------
                + This report excludes default entries except where indicated.
                + To see *everywhere* the script checks and *everything* it finds,
                launch it from a command prompt or a shortcut with the -all parameter.
                + To search all directories of local fixed drives for DESKTOP.INI
                DLL launch points and all Registry CLSIDs for dormant Explorer Bars,
                use the -supp parameter or answer "No" at the first message box.
                --------
                • Gość: Kolobos Re: Log do sprawdzenia IP: *.escom.net.pl 08.12.06, 23:10
                  Start->Uruchom->sc stop Usbpda
                  oraz: sc delete Usbpda

                  Uruchm tez regedit, przedz do:
                  HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ i usun tam:
                  "{37B85A29-692B-4205-9CAD-2626E4993404}"


                  Ps. Czekam na log z gmera.
                  • Gość: Ytek Re: Log do sprawdzenia IP: *.adsl.inetia.pl 08.12.06, 23:19
                    log w toku coś długo idzie wybrałem dokładniejszy skan chyba dobrze
                    • Gość: Ytek Re: Log do sprawdzenia IP: *.adsl.inetia.pl 08.12.06, 23:34
                      wysłałem pierwszy skan nie wiem czemu ale dokładny skan sie zawiesza
                      • Gość: Ytek Re: Log do sprawdzenia IP: *.adsl.inetia.pl 09.12.06, 01:14
                        jak sie usuwa z gmera ?? klikam prawym i mam zablokowane opcje
                        • Gość: Kolobos Re: Log do sprawdzenia IP: *.escom.net.pl 09.12.06, 01:33
                          Poczytaj np:
                          forum.gazeta.pl/forum/72,2.html?f=430&w=38051058&a=46101173
                          • Gość: Ytek Re: Log do sprawdzenia IP: *.adsl.inetia.pl 09.12.06, 01:56
                            uf no chyba wszystko ok gmer nic nie wykrywa...hmm tak myśle i chyba najlepiej
                            tym gmerem skanowac to lepsze od logów hjt...
                            dużo chodze po necie dlatego tak często łapie pskudztwa...ale zbieram
                            doświadczenie w elimincji tego wszystkiego...
                            • Gość: Kolobos Re: Log do sprawdzenia IP: *.escom.net.pl 09.12.06, 10:04
                              Juz Ci to chyba pisalem ale napisze jeszcze raz: ZMIEN PRZEGLADARKE NA OPERE i nie bedziesz mial żadnych problemow z robakami (chyba, ze sam je sciagniesz i uruchomisz).
                              • Gość: Ytek Re: Log do sprawdzenia IP: *.adsl.inetia.pl 09.12.06, 11:28
                                ale pozamykałem porty nie powinney sie przedostawac ;/
                                tak zmienie na opere ale pewnie trzeba ją jakoś skofigurować i ustawić
                                • Gość: Kolobos Re: Log do sprawdzenia IP: *.escom.net.pl 09.12.06, 11:34
                                  Nie trzeba, chociaz warto. Jest po polsku wiec nie bedziesz mial problemu.
                                  • Gość: Ytek Re: Log do sprawdzenia IP: *.adsl.inetia.pl 09.12.06, 14:10
                                    jakies opcje dotyczace coockies nie wiem co ustawiac zabardzo to w coockies są robaki ?
                                    • Gość: Kolobos Re: Log do sprawdzenia IP: *.escom.net.pl 09.12.06, 14:44
                                      Nie ma, zainstaluj Opere i uzywaj.
                                      • Gość: Ytek Ok mam ja IP: *.adsl.inetia.pl 09.12.06, 22:50
                                        ale net mi rozłącza co jakiś czas...moj kolega ma tego samego operatora i ma
                                        ok....czytalem na necie ze to moze sprawka wirusa ale przciesz dopiero
                                        czysciliśmy

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka