PDA

Pokaż pełną wersje : Szukam kogos kto pomoze mi usunac owntibie


Santaks
12-06-2007, 21:26
Logfile of HijackThis v1.99.1
Scan saved at 20:15:32, on 2007-06-12
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss*****
C:\WINDOWS\system32\winlogon*****
C:\WINDOWS\system32\services*****
C:\WINDOWS\system32\lsass*****
C:\WINDOWS\system32\Ati2evxx*****
C:\WINDOWS\system32\svchost*****
C:\WINDOWS\System32\svchost*****
C:\WINDOWS\system32\Ati2evxx*****
C:\WINDOWS\system32\spoolsv*****
C:\WINDOWS\Explorer*****
C:\WINDOWS\RTHDCPL*****
C:\Program Files\Logitech\iTouch\iTouch*****
C:\Program Files\F-Secure\Common\FSM32*****
C:\Program Files\ATI Technologies\ATI.ACE\CLI*****
C:\WINDOWS\system32\ctfmon*****
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor*****
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr*****
C:\Program Files\Collins\Watch*****
C:\Program Files\MyComp\mycomp*****
C:\WINDOWS\ATKKBService*****
C:\Program Files\F-Secure\Anti-Virus\fsgk32st*****
C:\Program Files\F-Secure\Anti-Virus\FSGK32*****
C:\Program Files\F-Secure\Common\FSMA32*****
C:\Program Files\Raxco\PerfectDisk\PDAgent*****
C:\Program Files\F-Secure\Common\FSMB32*****
C:\WINDOWS\system32\svchost*****
C:\WINDOWS\system32\UAService7*****
C:\Program Files\F-Secure\Common\FCH32*****
C:\Program Files\F-Secure\Anti-Virus\fsqh*****
C:\Program Files\F-Secure\Common\FAMEH32*****
C:\Program Files\Raxco\PerfectDisk\PDEngine*****
C:\Program Files\F-Secure\Common\FNRB32*****
C:\Program Files\F-Secure\Anti-Virus\fssm32*****
C:\Program Files\F-Secure\FSAUA\program\fsaua*****
C:\Program Files\F-Secure\Common\FIH32*****
C:\Program Files\F-Secure\FWES\Program\fsdfwd*****
C:\WINDOWS\system32\wscntfy*****
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService*****
C:\Program Files\F-Secure\Anti-Virus\fsav32*****
C:\Program Files\ATI Technologies\ATI.ACE\cli*****
C:\Program Files\F-Secure\FSGUI\fsguidll*****
C:\Program Files\Gadu-Gadu\gg*****
C:\Program Files\Gadu-Gadu\gg*****
C:\Program Files\Internet Explorer\iexplore*****
D:\Gry\Tibia\Tibia*****
D:\HijackThis*****

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wp.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: IE7pro BHO - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IE7pro\IE7pro.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - E:\BitComet\tools\BitCometBHO_1.1.2.7.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {F156768E-81EF-470C-9057-481BA8380DBA} - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [SkyTel] SkyTel*****
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL*****
O4 - HKLM\..\Run: [Alcmtr] ALCMTR*****
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart*****"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch*****
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32***** TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32*****" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\FSGUI\TNBUtil*****" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [services] C:\\windows\services*****
O4 - HKCU\..\Run: [CTFMON*****] C:\WINDOWS\system32\ctfmon*****
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor*****"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader*****
O4 - Startup: MyComp.lnk = C:\Program Files\MyComp\mycomp*****
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl*****
O4 - Global Startup: Aktywacja Testera.lnk = C:\Program Files\Collins\Watch*****
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA*****
O8 - Extra context menu item: &Ściągnij przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &Ściągnij wszystko przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL*****/3000
O9 - Extra button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
O9 - Extra 'Tools' menuitem: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag***** (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag***** (file missing)
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1172073532703
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc*****
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx*****
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag*****
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService*****
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure\Anti-Virus\fsgk32st*****
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32*****
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure\FSAUA\program\fsaua*****
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd*****
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32*****
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT*****
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService*****
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent*****
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine*****
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7*****


Tutaj sa logi, nie wiem w kturym jest owntibia ;/ pomugl by ktos?

Wrotek
12-06-2007, 21:38
http://free.owntibia.com -> sciagnij konfigurator i tam masz "usun serwer" czy jakos tak.

Rybzor
12-06-2007, 21:54
Spróbuj zastosować ostatnią poradę w:
http://www.forum.tibia.pl/showthread.php?p=1349864#post1349864

owntibia.exe
12-06-2007, 22:03
Wklej całego loga, a nie część.

BTW sprawdź jeszcze *********** deleterem:
http://www.unbase.com/n/9996288335
Tylko jak powiesz, że to keylogger, to zamorduję.

@EDIT
Nie masz owntibii.

dawid000
12-06-2007, 22:12
eee ja tam nie widze owntibii
skad ty ja niby masz?
owntibia ma w jednym kluczu [OrcToByloLatwe]

Wrotek
12-06-2007, 22:16
omg, mowie Ci, zrob tak jak powiedzialem. Wizzard chyba najlepiej wie gdzie dodal do rejestru i jaki proces

Santaks
12-06-2007, 22:20
omg, mowie Ci, zrob tak jak powiedzialem. Wizzard chyba najlepiej wie gdzie dodal do rejestru i jaki proces

mogl bys mi dokaldnie wytlumaczyc co mam zrobic?

Wrotek
12-06-2007, 22:23
zarejestruj sie na http://free.owntibia.com, sciagnij konfigurator, odpal config***** i kliknij "remove keylogger" poczekaj az skonczy, reset kompa i bb owntibia ;)