Zobacz pojedynczy post
stary 30-10-2007, 00:24   #558
Misza
Użytkownik Forum
 
Misza's Avatar
 
Data dołączenia: 30 06 2005
Lokacja: -+*≡☼SZWECJA☼≡*+-
Wpisy bloga: 3

Posty: 1,324
Domyślny

Ściągałem raz jeden program do zmiany IP przez proxy, nie działał. Od tamtego czasu nie mogę usunąć pliku, a mam go na pulpicie, cham go szpeci. Próbowałem już trybu awaryjnego, kilku file deleterów, ale nic to nie dało. Jak coś to zamieszczam logi z Hijackthis.
Ukryty tekst:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:06:40, on 2007-10-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss*****
C:\WINDOWS\system32\winlogon*****
C:\WINDOWS\system32\services*****
C:\WINDOWS\system32\lsass*****
C:\WINDOWS\system32\svchost*****
C:\WINDOWS\System32\svchost*****
D:\Program\Alwil Software\Avast4\aswUpdSv*****
C:\WINDOWS\Explorer*****
D:\Program\Alwil Software\Avast4\ashServ*****
C:\WINDOWS\system32\RunDll32*****
C:\WINDOWS\system32\RunDLL32*****
D:\Program\Winamp\winampa*****
D:\Program\ALWILS~1\Avast4\ashDisp*****
D:\Program\SONICS~1\SsAAD*****
C:\Program\Java\jre1.6.0_02\bin\jusched*****
C:\WINDOWS\vVX1000*****
C:\WINDOWS\system32\ctfmon*****
D:\Program\WapSter\AQQ\AQQ*****
D:\Program\Steam\Steam*****
C:\WINDOWS\system32\spoolsv*****
C:\Program\Microsoft LifeCam\MSCamSvc*****
C:\WINDOWS\system32\nvsvc32*****
C:\WINDOWS\system32\PnkBstrA*****
D:\Program\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE*****
C:\WINDOWS\system32\svchost*****
D:\Program\Alwil Software\Avast4\ashMaiSv*****
D:\Program\Alwil Software\Avast4\ashWebSv*****
D:\Program\Xfire\xfire*****
C:\Program\MSN Messenger\usnsvc*****
D:\Program\Mozilla Firefox\firefox*****
D:\Program\Trend Micro\HijackThis\HijackThis*****

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\Program\Adobe Reader\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Alcohol Toolbar Helper - {8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489} - C:\Program\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
O3 - Toolbar: Alcohol Toolbar - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - C:\Program\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
O4 - HKLM\..\Run: [C6501Sound] RunDll32 c6501.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32***** C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz***** /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32***** NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] D:\Program\Winamp\winampa*****
O4 - HKLM\..\Run: [avast!] D:\Program\ALWILS~1\Avast4\ashDisp*****
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9 CE***** /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [SsAAD*****] D:\Program\SONICS~1\SsAAD*****
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program\QuickTime\QTTask*****" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_02\bin\jusched*****"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000*****
O4 - HKCU\..\Run: [CTFMON*****] C:\WINDOWS\system32\ctfmon*****
O4 - HKCU\..\Run: [AQQ] D:\Program\WapSter\AQQ\AQQ*****
O4 - HKCU\..\Run: [Steam] "D:\Program\Steam\Steam*****" -silent
O4 - HKUS\S-1-5-19\..\Run: [CTFMON*****] C:\WINDOWS\system32\CTFMON***** (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON*****] C:\WINDOWS\system32\CTFMON***** (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON*****] C:\WINDOWS\system32\CTFMON***** (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON*****] C:\WINDOWS\system32\CTFMON***** (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = D:\Program\Microsoft Office\Office\OSA9*****
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program\ICQ6\ICQ*****
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program\ICQ6\ICQ*****
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs*****
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs*****
O12 - Plugin for .spop: C:\Program\Internet Explorer\Plugins\NPDocBox.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program\DELADE~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Program\Alwil Software\Avast4\aswUpdSv*****
O23 - Service: avast! Antivirus - ALWIL Software - D:\Program\Alwil Software\Avast4\ashServ*****
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program\Alwil Software\Avast4\ashMaiSv*****
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program\Alwil Software\Avast4\ashWebSv*****
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program\Delade filer\Sony Shared\AVLib\MSCSPTISRV*****
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32*****
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program\Delade filer\Sony Shared\AVLib\PACSPTISVR*****
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA*****
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program\Delade filer\Sony Shared\AVLib\SPTISRV*****
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program\Delade filer\Sony Shared\AVLib\SSScsiSV*****
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Program\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE*****

--
End of file - 5781 bytes

Nie wiem, czy logi coś dadzą, ale może przy okazji znajdzie się tutaj coś szkodliwego. ;p
__________________
HELIUM~
Misza jest offline   Odpowiedz z Cytatem