Dodaj do ulubionych

Fałszywe linki z google

20.03.07, 16:13
Witam

Mój problem polega na tym, że kiedy klikam na jakiś link w google, prowadzi
mnie on zazwyczaj na strony cx.maxfiles.com, hrena.com, sestat.com itp.
Czasami powrót i ponowne kliknięcie prowadzi do poprawnej strony. Czasem
muszę wkleić cały adres aby dojść tam gdzie chcę.

Mam WinXP SP2 i IE 7.

Przeleciałem komputer parę razy Spybot Search & Destroy, mam na stałe
włączonego McAfee.

Uruchomiłem hijackthis i sprawdziłem log na www.hijack.de. Naprawiłem parę
(ok 5) wątpliwych linii, nie było tam żadnych poważnych alarmów

Macie może pomysł co to może być? Log z hijack wkleję jeżeli stwierdzicie że
jest potrzebny.
Obserwuj wątek
    • Gość: Kolobos Re: Fałszywe linki z google IP: *.escom.net.pl 20.03.07, 16:31
      Wklej log na forum.
      Uzyj tez: siri.urz.free.fr/Fix/SmitfraudFix_En.php zrob to co masz
      opisane pod "Clean" po uzyciu utworzy sie log, ktory wklej na forum.
      • larson Re: Fałszywe linki z google 20.03.07, 17:24
        DZIĘKI! Smitfraudfix pomógł!! Kolobos rulez.

        Może się to komuś przyda- log ze smitfraudfixa:

        SmitFraudFix v2.150

        Scan done at 16:42:38.73, 20/03/2007
        Run from C:\Installs\SmitfraudFix
        OS: Microsoft Windows XP [Wersja 5.1.2600] - Windows_NT
        The filesystem type is NTFS
        Fix run in safe mode

        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
        !!!Attention, following keys are not inevitably infected!!!

        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll

        »»»»»»»»»»»»»»»»»»»»»»»» Killing process


        »»»»»»»»»»»»»»»»»»»»»»»» hosts


        127.0.0.1 localhost

        »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

        GenericRenosFix by S!Ri


        »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


        »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
        !!!Attention, following keys are not inevitably infected!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
        "System"="kdlis.exe"

        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

        Registry Cleaning done.

        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
        !!!Attention, following keys are not inevitably infected!!!

        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll


        »»»»»»»»»»»»»»»»»»»»»»»» Reboot

        C:\WINDOWS\system32\kdlis.exe Deleted

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
        "System"=""


        »»»»»»»»»»»»»»»»»»»»»»»» End
        • Gość: Kolobos Re: Fałszywe linki z google IP: *.escom.net.pl 20.03.07, 18:12
          Jak chcesz to dla pewnosci wklej log z hijackthis na forum.
          Tutaj masz te przydatne narzedzie do usuwania WareOut (o ile w Twoim przypadku to bylo wlasnie to):
          downloads.subratam.org/Fixwareout.exe
          • larson Re: Fałszywe linki z google 20.03.07, 18:17
            Proszę bardzo:

            Logfile of HijackThis v1.99.1
            Scan saved at 16:26:51, on 20/03/2007
            Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16414)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Windows Defender\MsMpEng.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
            C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\WINDOWS\ATKKBService.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\Program Files\Exact Software\Event Manager\Bin\KS_Serv.exe
            C:\Program Files\Exact Software\Event Manager\bin\KS_Sched.exe
            C:\Program Files\Exact Software\Event Manager\bin\KS_DB.exe
            C:\Program Files\Exact Software\Event Manager\bin\KS_Email.exe
            C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            C:\Program Files\Exact Software\Event Manager\bin\KS_Report.exe
            C:\Program Files\Exact Software\Event Manager\bin\KS_Action.exe
            c:\program files\mcafee.com\agent\mcdetect.exe
            c:\PROGRA~1\mcafee.com\vso\mcshield.exe
            c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
            C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
            C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlservr.exe
            C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
            C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\wdfmgr.exe
            C:\Program Files\Exact Software\Event Manager\bin\idsmai32.exe
            C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
            C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\ATK0100\HControl.exe
            C:\WINDOWS\SOUNDMAN.EXE
            C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
            C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
            C:\WINDOWS\system32\hkcmd.exe
            C:\WINDOWS\system32\igfxpers.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Program Files\McAfee.com\VSO\oasclnt.exe
            C:\WINDOWS\ATK0100\ATKOSD.exe
            C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
            c:\progra~1\mcafee.com\vso\mcvsescn.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Skype\Phone\Skype.exe
            C:\Program Files\Skype\Plugin Manager\SkypePM.exe
            C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
            c:\progra~1\mcafee.com\vso\mcvsftsn.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
            C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
            C:\WINDOWS\system32\inetsrv\inetinfo.exe
            C:\WINDOWS\system32\dllhost.exe
            C:\WINDOWS\system32\ntvdm.exe
            C:\Program Files\Exact Software\bin\e4shell.exe
            C:\PROGRA~1\EXACTS~1\BIN\e4slash.exe
            C:\Installs\hijackthis_199\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
            go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
            go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
            go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
            go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
            go.microsoft.com/fwlink/?LinkId=69157
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-
            784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program
            Files\Spybot - Search & Destroy\SDHelper.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
            Files\Java\jre1.5.0_09\bin\ssv.dll
            O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} -
            c:\progra~1\mcafee.com\vso\mcvsshl.dll
            O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
            O4 - HKLM\..\Run: [Skrót do strony właściwości High Definition Audio]
            HDAShCut.exe
            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
            O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4
            Gear\BatteryLife.exe 1
            O4 - HKLM\..\Run: [IntelZeroConfig] C:\Program
            Files\Intel\Wireless\bin\ZCfgSvc.exe
            O4 - HKLM\..\Run: [IntelWireless] C:\Program
            Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
            O4 - HKLM\..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
            O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
            O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
            O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
            O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows
            Defender\MSASCui.exe" -hide
            O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1
            \McAfee.com\VSO\mcmnhdlr.exe" /checktask
            O4 - HKLM\..\Run: [VirusScan Online] C:\Program
            Files\McAfee.com\VSO\mcvsshld.exe
            O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
            O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
            O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
            O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1
            \McAfee.com\Shared\mcappins.exe /v=3 /cleanup
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program
            Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL
            Server\80\Tools\Binn\sqlmangr.exe
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1
            \MICROS~2\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
            C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
            00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
            C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
            C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-
            00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O11 - Options group: [INTERNATIONAL] International*
            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage
            Validation Tool) - go.microsoft.com/fwlink/?linkid=39204
            O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan
            Agent 6.6) - eu-housecall.trendmicro-
            europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
            O16 - DPF: {26774F3E-5F15-4883-8394-89146270A8C7}
            (SynergyOfficeAddin.Connect_Excel) -
            tomasz/Synergy/cab/SynergyOfficeAddin.CAB
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) -
            C:\Program Files\Yahoo!\Common\yinsthelper.dll
            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
            <a href="by103fd.bay103.hotm
            • Gość: Kolobos Re: Fałszywe linki z google IP: *.escom.net.pl 20.03.07, 18:24
              Limit forum zjadl koniec, doklej w nastepnym poscie.
              • larson Re: Fałszywe linki z google 20.03.07, 19:34
                OK, jadę dalej:

                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
                by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
                O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
                update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1130529807015
                O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment
                1.5.0) - javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586-
                jc.cab
                O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
                acs.pandasoftware.com/activescan/as5free/asinst.cab
                O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF}
                (MsnMessengerSetupDownloadControl Class) -
                messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                O16 - DPF: {BD324C84-E46E-11D3-83D0-00C04F4EB66B} (HTMLParser Class) -
                eportal.exact.nl/cab/ebcasp.cab
                O16 - DPF: {D30CA0FD-1CA0-11D4-AC78-006008A9A8BC} (WebBasedClientInstall
                Class) - sav.exactsoftware.com/webinst.cab
                O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) -
                www.bemowo.waw.pl:30/activex/AMC.cab
                O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex
                Control) - secure.logmein.com/activex/ractrl.cab?lmi=100
                O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1
                \COMMON~1\Skype\SKYPE4~1.DLL
                O20 - Winlogon Notify: !SASWinLogon - C:\Program
                Files\SUPERAntiSpyware\SASWINLO.DLL
                O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
                O20 - Winlogon Notify: IntelWireless - C:\Program
                Files\Intel\Wireless\Bin\LgNotify.dll
                O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
                O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner -
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER
                INC. - C:\WINDOWS\ATKKBService.exe
                O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil
                Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil
                Software\Avast4\ashMaiSv.exe" /service (file missing)
                O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil
                Software\Avast4\ashWebSv.exe" /service (file missing)
                O23 - Service: EvtEng - Intel Corporation - C:\Program
                Files\Intel\Wireless\Bin\EvtEng.exe
                O23 - Service: Exact Event Manager - Vineyardsoft Corporation - C:\Program
                Files\Exact Software\Event Manager\Bin\KS_Serv.exe
                O23 - Service: LightScribeService Direct Disc Labeling Service
                (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common
                Files\LightScribe\LSSrvc.exe
                O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1
                \LUCOMS~1.EXE
                O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program
                files\mcafee.com\agent\mcdetect.exe
                O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1
                \mcafee.com\vso\mcshield.exe
                O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1
                \mcafee.com\agent\mctskshd.exe
                O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee,
                Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
                O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program
                Files\Intel\Wireless\Bin\OProtSvc.exe
                O23 - Service: RegSrvc - Intel Corporation - C:\Program
                Files\Intel\Wireless\Bin\RegSrvc.exe
                O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation -
                C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common
                Files\PCSuite\Services\ServiceLayer.exe
                • Gość: Kolobos Re: Fałszywe linki z google IP: *.escom.net.pl 20.03.07, 20:21
                  Zostaw tylko jeden antywirus, drugi odinstaluj.
                  Defendera od MS tez wywal, jego skutecznosc jest tragiczna.
                  • larson Re: Fałszywe linki z google 29.03.07, 17:08
                    Dzięki, zastosowałem się do wskazówek, nie mam już Win defendera i Symanteca,
                    zastąpiłem to wszystko McAfee

                    Tylko jeszcze jedno pytanie, o tę linię z logu:

                    C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlservr.exe

                    www.hijackthis.de twierdzi że jest to "possibly nasty" bo zazwyczaj plik
                    znajduje się w innym katalogu.

                    Tylko ja nie mogę znaleźć ani takiego katalogu MI6841... (włączyłem również
                    ukryte foldery i plik), ani samego pliku sqlservr.exe nigdzie na dysku, oprócz
                    standardowej lokalizacji (\Microsoft SQL Server\MSSQL\Binn\). Co to może być?
                    • Gość: Kolobos Re: Fałszywe linki z google IP: *.escom.net.pl 29.03.07, 17:15
                      Zostaw to w spokoju.

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka