Prośba o sprawdzenie loga

IP: *.citysat.com.pl 03.01.09, 02:30
Witam ! W ostatnim czasie strasznie mi komputer "muli" przy starcie.
Logi z Hijacka mam takie :
SmitfraudFixLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:11:25, on 2009-01-03
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\SOUNDMAN.EXE
D:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009
\avp.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
D:\Program Files\Eraser\eraser.exe
D:\Program Files\a-squared Free\a2service.exe
D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009
\avp.exe
D:\Program Files\ewido anti-spyware 4.0\guard.exe
D:\WINDOWS\System32\svchost.exe
D:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
D:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL
= go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL = go.microsoft.com/fwlink/?
LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet
Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} -
D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009
\ievkbd.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] D:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] D:\PROGRA~1\Nokia\NOKIAP~1
\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [AVP] "D:\Program Files\Kaspersky Lab\Kaspersky
Internet Security 2009\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "D:\Program
Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AlcoholAutomount] "D:\Program Files\Alcohol
Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [PcSync] D:\Program Files\Nokia\Nokia PC Suite 6
\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [Gadu-Gadu] "D:\Program Files\Gadu-
Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [Eraser] D:\Program Files\Eraser\eraser.exe -hide
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32
\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32
\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = D:\Program
Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Dodaj do listy blokowanych banerów -
D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009
\ie_banner_deny.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Statystyki ochrony WWW - {1F460357-8A94-4D71-9CA3-
AA4ACF32ED8E} - D:\Program Files\Kaspersky Lab\Kaspersky Internet
Security 2009\SCIEPlgn.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-
f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-
4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-
BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan
Control) - downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C} (AOL Pictures
Uploader Class) -
o.aolcdn.com/pictures/ap/Resources/v2.14/cab/aolpPlugins.10.6.0.8.cab
O16 - DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} (MainControl
Class) - slimak.onet.pl/_m/wirusy/ArcaOnline.cab
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline
Class) - www.mks.com.pl/skaner/SkanerOnline.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan
Installer Class) -
acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash
Object) -
fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH -
D:\Program Files\a-squared Free\a2service.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab -
D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009
\avp.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware
Development a.s. - D:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: ServiceLayer - Nokia. - D:\Program Files\Common
Files\PCSuite\Services\ServiceLayer.exe

--
End of file - 5280 bytes
    • Gość: Kolobos Re: Prośba o sprawdzenie loga IP: *.escom.net.pl 03.01.09, 02:51
      Czytanie nie jest chyba takie trudne? forum.gazeta.pl/forum/72,2.html?f=430&w=76799955 daj log z combofix oraz hjt, oba na wklej i podaj link.
      • Gość: jarek1976 Re: Prośba o sprawdzenie loga IP: *.citysat.com.pl 03.01.09, 09:52
        Przepraszam nie doczytałem wklejam
        link:httpwklej.org/id/34397/
        • Gość: Kolobos Re: Prośba o sprawdzenie loga IP: *.escom.net.pl 03.01.09, 16:34
          Wszystko wyglada ok, wylacz tylko zbedne programy w msconfig, zakladka uruchamianie.
Pełna wersja