Dodaj do ulubionych

WLLoginproxy.exe

IP: *.adsl.inetia.pl 07.05.07, 09:51
Nie moge sie pozbyć tego procesu. Podaję log z silent runner.

"Silent Runners.vbs", revision 46, www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"SpeedTouch USB Diagnostics" = ""C:\Program Files\Thomson\SpeedTouch
USB\Dragdiag.exe" /icon" ["THOMSON Telecom Belgium"]
"SunJavaUpdateSched" = ""C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe""
["Sun Microsystems, Inc."]
"BDMCon" = ""C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg"
["SOFTWIN S.R.L."]
"BDAgent" = ""C:\Program Files\Softwin\BitDefender10\bdagent.exe"" ["SOFTWIN
S.R.L."]
"NvCplDaemon" = ""RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
-> {HKLM...CLSID} = "AcroIEHlprObj Class"
\InProcServer32\(Default) = "C:\Program Files\Acrobat 6.0.1
\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{22BF413B-C6D2-4d91-82A9-A0F997BA588C}\(Default) = "Skype add-on (mastermind)"
-> {HKLM...CLSID} = "Skype add-on (mastermind)"
\InProcServer32\(Default) = "C:\PROGRA~1
\Skype\Phone\IEPlugin\SKYPEI~1.DLL" ["Skype Technologies S.A."]
{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}\(Default) = (no title provided)
-> {HKLM...CLSID} = "MEGAUPLOADTOOLBAR"
\InProcServer32\(Default) = "C:\PROGRA~1\MEGAUP~1
\MEGAUP~1.DLL" ["MegaUpload"]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
-> {HKLM...CLSID} = "SSVHelper Class"
\InProcServer32\(Default) = "C:\Program
Files\Java\jre1.5.0_10\bin\ssv.dll" ["Sun Microsystems, Inc."]
{9030D464-4C02-4ABF-8ECC-5164760863C6}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Windows Live Sign-in Helper"
\InProcServer32\(Default) = "C:\Program Files\Common
Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll" [MS]
{AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Google Toolbar Helper"
\InProcServer32\(Default) = "c:\windows\downloaded program
files\googletoolbar_pl_4.0.1601-big.dll" ["Google Inc."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "C:\WINDOWS\system32
\hticons.dll" ["Hilgraeve, Inc."]
"{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
-> {HKLM...CLSID} = "DesktopContext Class"
\InProcServer32\(Default) = "C:\WINDOWS\system32
\nvcpl.dll" ["NVIDIA Corporation"]
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
-> {HKLM...CLSID} = "NVIDIA CPL Extension"
\InProcServer32\(Default) = "C:\WINDOWS\system32
\nvcpl.dll" ["NVIDIA Corporation"]
"{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
-> {HKLM...CLSID} = "Desktop Explorer"
\InProcServer32\(Default) = "C:\WINDOWS\system32
\nvshell.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32
\nvshell.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"
-> {HKLM...CLSID} = "nView Desktop Context Menu"
\InProcServer32\(Default) = "C:\WINDOWS\system32
\nvshell.dll" ["NVIDIA Corporation"]
"{B327765E-D724-4347-8B16-78AE18552FC3}" = "NeroDigitalIconHandler"
-> {HKLM...CLSID} = "NeroDigitalIconHandler Class"
\InProcServer32\(Default) = "C:\Program Files\Common
Files\Ahead\lib\NeroDigitalExt.dll" ["Nero AG"]
"{7F1CF152-04F8-453A-B34C-E609530A9DC8}" = "NeroDigitalPropSheetHandler"
-> {HKLM...CLSID} = "NeroDigitalPropSheetHandler Class"
\InProcServer32\(Default) = "C:\Program Files\Common
Files\Ahead\lib\NeroDigitalExt.dll" ["Nero AG"]
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes"
-> {HKLM...CLSID} = "iTunes"
\InProcServer32\(Default) = "C:\Program
Files\QuickTime\iTunesMiniPlayer.dll" ["Apple Computer, Inc."]
"{7A4097B2-6022-4670-995F-DA363EBF947F}" = "Custom shell context menu
extension"
-> {HKLM...CLSID} = "Custom shell context menu extension"
\InProcServer32\(Default) = "C:\WINDOWS\system32
\shctxex.dll" [empty string]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program
Files\WinRAR\rarext.dll" [null data]
"{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"
-> {HKLM...CLSID} = "Moje foldery udostępniania"
\InProcServer32\(Default) = "C:\Program Files\MSN
Messenger\fsshext.8.1.0178.00.dll" [MS]

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\
INFECTION WARNING! "AppInit_DLLs" = "sockspy.dll" [null data]

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
"System" = (value not set)

HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
{7D4D6379-F301-4311-BEBA-E26EB0561882}\(Default)
= "NeroDigitalExt.NeroDigitalColumnHandler"
-> {HKLM...CLSID} = "NeroDigitalColumnHandler Class"
\InProcServer32\(Default) = "C:\Program Files\Common
Files\Ahead\lib\NeroDigitalExt.dll" ["Nero AG"]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
Custom shell context menu extension\(Default) = "{7A4097B2-6022-4670-995F-
DA363EBF947F}"
-> {HKLM...CLSID} = "Custom shell context menu extension"
\InProcServer32\(Default) = "C:\WINDOWS\system32
\shctxex.dll" [empty string]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program
Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
Custom shell context menu extension\(Default) = "{7A4097B2-6022-4670-995F-
DA363EBF947F}"
-> {HKLM...CLSID} = "Custom shell context menu extension"
\InProcServer32\(Default) = "C:\WINDOWS\system32
\shctxex.dll" [empty string]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program
Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program
Files\WinRAR\rarext.dll" [null data]


Active Desktop and Wallpaper:
-----------------------------

Active Desktop is disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\Sebek\Ustawienia lokalne\Dane
aplikacji\Microsoft\Wallpaper1.bmp"


Enabled Screen Saver:
---------------------

HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\system32\logon.scr" [MS]


Startup items in "Sebek" & "All Users" startup folders:
-------------------------------------------------------

C:\Documents and Settings\Sebek\Menu Start\Programy\Autostart
"DriveCrypt" -> shortcut to: "C:\Program Files\DriveCrypt\DriveCrypt.exe"
["Secustar"]


Winsock2 Service Provider DLLs:
--------------------------
Obserwuj wątek
    • Gość: Ytek Re: WLLoginproxy.exe dalszy ciag IP: *.adsl.inetia.pl 07.05.07, 09:53
      Winsock2 Service Provider DLLs:
      -------------------------------

      Namespace Service Providers

      HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5
      \Catalog_Entries\ {++}
      000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
      000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
      000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

      Transport Service Providers

      HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9
      \Catalog_Entries\ {++}
      0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
      %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 17
      %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


      Toolbars, Explorer Bars, Extensions:
      ------------------------------------

      Toolbars

      HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
      "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
      -> {HKLM...CLSID} = "&Google"
      \InProcServer32\(Default) = "c:\windows\downloaded program
      files\googletoolbar_pl_4.0.1601-big.dll" ["Google Inc."]
      "{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}"
      -> {HKLM...CLSID} = "MEGAUPLOADTOOLBAR"
      \InProcServer32\(Default) = "C:\PROGRA~1\MEGAUP~1
      \MEGAUP~1.DLL" ["MegaUpload"]

      HKLM\Software\Microsoft\Internet Explorer\Toolbar\
      "{6932D140-ABC4-4073-A44C-D4A541665E35}" = "ImageShack Toolbar"
      -> {HKLM...CLSID} = "ImageShack Toolbar"
      \InProcServer32\(Default)
      = "C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll" ["ImageShack Corp."]
      "{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}" = (no title provided)
      -> {HKLM...CLSID} = "MEGAUPLOADTOOLBAR"
      \InProcServer32\(Default) = "C:\PROGRA~1\MEGAUP~1
      \MEGAUP~1.DLL" ["MegaUpload"]
      "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)
      -> {HKLM...CLSID} = "&Google"
      \InProcServer32\(Default) = "c:\windows\downloaded program
      files\googletoolbar_pl_4.0.1601-big.dll" ["Google Inc."]

      Extensions (Tools menu items, main toolbar menu buttons)

      HKLM\Software\Microsoft\Internet Explorer\Extensions\
      {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
      "MenuText" = "Sun Java Console"
      "CLSIDExtension" = "{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}"
      -> {HKCU...CLSID} = "Java Plug-in 1.5.0_10"
      \InProcServer32\(Default) = "C:\Program
      Files\Java\jre1.5.0_10\bin\ssv.dll" ["Sun Microsystems, Inc."]
      -> {HKLM...CLSID} = "Java Plug-in 1.5.0_10"
      \InProcServer32\(Default) = "C:\Program
      Files\Java\jre1.5.0_10\bin\npjpi150_10.dll" ["Sun Microsystems, Inc."]

      {215940F1-E7E0-4801-BEE3-44D045534106}\
      "ButtonText" = "Wyslij SMS'a"
      "Script" = "C:\Program Files\Common Files\moje.js" [null data]

      {35980F6E-A258-4E50-953D-813BB8556899}\
      "ButtonText" = "WellGet"
      "Exec" = "C:\Program Files\WellGet\WellGet.exe" [empty string]

      {77BF5300-1474-4EC7-9980-D32B190E9B07}\
      "ButtonText" = "Skype"
      "CLSIDExtension" = "{77BF5300-1474-4EC7-9980-D32B190E9B07}"
      -> {HKLM...CLSID} = "Skype add-on (button)"
      \InProcServer32\(Default) = "C:\PROGRA~1
      \Skype\Phone\IEPlugin\SKYPEI~1.DLL" ["Skype Technologies S.A."]

      {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A}\
      "ButtonText" = "eBay - Homepage"
      "CLSIDExtension" = "{1FBA04EE-3024-11D2-8F1F-0000F87ABD16}"
      -> {HKLM...CLSID} = "Toolbar Extension for Executable"
      \InProcServer32\(Default) = "C:\WINDOWS\system32
      \shdocvw.dll" [MS]
      "Exec" = "C:\Program Files\IrfanView\Ebay\Ebay.htm" [null data]

      {FB5F1910-F110-11D2-BB9E-00C04F795683}\
      "ButtonText" = "Messenger"
      "MenuText" = "Windows Messenger"
      "Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]


      Running Services (Display Name, Service Name, Path {Service DLL}):
      ------------------------------------------------------------------

      BitDefender Communicator, XCOMM, ""C:\Program Files\Common
      Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service" ["Softwin"]
      BitDefender Desktop Update Service, LIVESRV, ""C:\Program Files\Common
      Files\Softwin\BitDefender Update Service\livesrv.exe" /service" ["SOFTWIN
      S.R.L."]
      BitDefender Scan Server, bdss, ""C:\Program Files\Common
      Files\Softwin\BitDefender Scan Server\bdss.exe" /service" [null data]
      BitDefender Virus Shield, VSSERV, ""C:\Program Files\Softwin\BitDefender10
      \vsserv.exe" /service" ["SOFTWIN S.R.L."]
      DriveCrypt Service, DriveCryptService, "C:\Program
      Files\DriveCrypt\DcrServ.exe" [null data]
      NVIDIA Display Driver Service, NVSvc, "C:\WINDOWS\system32\nvsvc32.exe"
      ["NVIDIA Corporation"]
      Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]


      ----------
      + This report excludes default entries except where indicated.
      + To see *everywhere* the script checks and *everything* it finds,
      launch it from a command prompt or a shortcut with the -all parameter.
      + To search all directories of local fixed drives for DESKTOP.INI
      DLL launch points and all Registry CLSIDs for dormant Explorer Bars,
      use the -supp parameter or answer "No" at the first message box.
      --------
    • Gość: Ytek Re: WLLoginproxy.exe a tu hjt IP: *.adsl.inetia.pl 07.05.07, 09:54
      Logfile of HijackThis v1.99.1
      Scan saved at 09:53:29, on 2007-05-07
      Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\DriveCrypt\DcrServ.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
      C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
      C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
      C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
      C:\Program Files\Softwin\BitDefender10\vsserv.exe
      C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
      C:\Program Files\Softwin\BitDefender10\bdmcon.exe
      C:\Program Files\Softwin\BitDefender10\bdagent.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\Total Commander\TOTALCMD.EXE
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\WINDOWS\system32\NOTEPAD.EXE
      E:\Sebek\Instalki\HiJackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      www.dict.pl/plen
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
      C:\Program Files\Acrobat 6.0.1\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} -
      C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
      O2 - BHO: MEGAUPLOADTOOLBAR - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} -
      C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
      Files\Java\jre1.5.0_10\bin\ssv.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} -
      C:\Program Files\Common Files\Microsoft Shared\Windows
      Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
      c:\windows\downloaded program files\googletoolbar_pl_4.0.1601-big.dll
      O3 - Toolbar: ImageShack Toolbar - {6932D140-ABC4-4073-A44C-D4A541665E35} -
      C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll
      O3 - Toolbar: MEGAUPLOADTOOLBAR - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} -
      C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
      c:\windows\downloaded program files\googletoolbar_pl_4.0.1601-big.dll
      O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program
      Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10
      \bin\jusched.exe"
      O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10
      \bdmcon.exe" /reg
      O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
      O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32
      \NvCpl.dll,NvStartup
      O4 - Startup: DriveCrypt.lnk = C:\Program Files\DriveCrypt\DriveCrypt.exe
      O8 - Extra context menu item: &Ściągnij wszystko za pomocą WellGeta -
      C:\Program Files\WellGet\nxall.htm
      O8 - Extra context menu item: Ściągnij za pomocą &WellGeta - C:\Program
      Files\WellGet\nxcatch.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
      C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
      00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
      O9 - Extra button: Wyslij SMS'a - {215940F1-E7E0-4801-BEE3-44D045534106} -
      C:\Program Files\Common Files\moje.js
      O9 - Extra button: WellGet - {35980F6E-A258-4E50-953D-813BB8556899} -
      C:\Program Files\WellGet\WellGet.exe
      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1
      \Skype\Phone\IEPlugin\SKYPEI~1.DLL
      O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} -
      C:\Program Files\IrfanView\Ebay\Ebay.htm
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
      C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-
      00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O15 - Trusted Zone: toolbar.imageshack.us
      O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
      messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
      O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
      messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
      O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
      messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
      O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) -
      toolbar.imageshack.us/toolbar/ImageShackToolbar.cab
      O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} -
      toolbar1.google.com/data/pl/big/1.1.62-big/GoogleNav.cab
      O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
      messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
      messenger.zone.msn.com/binary/ZIntro.cab47946.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{37DCA4E9-8971-4F97-A8C4-DCA3B7BF4517}:
      NameServer = 213.241.79.37 83.238.255.76
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1
      \MSNMES~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1
      \MSNMES~1\MSGRAP~1.DLL
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program
      Files\Skype\Plugin Manager\Skype4COM.dll
      O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program
      Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file
      missing)
      O23 - Service: DriveCrypt Service (DriveCryptService) - Unknown owner -
      C:\Program Files\DriveCrypt\DcrServ.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program
      Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner -
      C:\Program Files\Common Files\Softwin\BitDefender Update
      Service\livesrv.exe" /service (file missing)
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
      C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program
      Files\Softwin\BitDefender10\vsserv.exe" /service (file missing)
      O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program
      Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service
      (file missing)

      • Gość: Kolobos Re: WLLoginproxy.exe a tu hjt IP: *.escom.net.pl 07.05.07, 10:01
        Po co te logi? Przeciez to proces MS, wystarczy uzyc google:
        www.liutilities.com/products/wintaskspro/processlibrary/wlloginproxy/
        • Gość: Ytek Re: WLLoginproxy.exe IP: *.adsl.inetia.pl 07.05.07, 10:08
          Ale nie mialem nigdy tego procesu wiec pomyslalem ze to jakis trojan. Co to za
          proces bo nie miałem go wcześniej? (na polskich stronach nie moglem znaleść
          strony i procesach)
          • Gość: Ytek Re: WLLoginproxy.exe IP: *.adsl.inetia.pl 07.05.07, 10:10
            aha wczoraj gmer wykrył mi rootkity stąd też moje obawy.
            • Gość: Kolobos Re: WLLoginproxy.exe IP: *.escom.net.pl 07.05.07, 10:26
              Jakie? Opis tego pliku masz na stronie ktora podalem.

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka