Oglądasz wypowiedzi znalezione dla frazy: Microsoft Find
Temat: Co jest grane ?
Co jest grane ?
Dobra opisze krotko po pierwsze zweza mi sie ekran po szerokosci z obu stro i
co jakis czas rozszeza i tak w kolko. Po drugie wyskakuje mi stronka z
jakimis wygaszaczmi albo tapetami a nazywa sie screesarver za chiny nie moge
znalesc gdzie sie to umiejscowilo. W logu jest na koncu Truset IP range i tu
jest adres ip Linkey Network russia itd. i nie moge tego wywalic z pozycji
Hijacka.
Oto log :
Logfile of HijackThis v1.99.1
Scan saved at 16:25:07, on 05-12-18
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2614.3500)
Running processes:
C:WINDOWSSYSTEMKERNEL32.DLL
C:WINDOWSSYSTEMMSGSRV32.EXE
C:WINDOWSSYSTEMMPREXE.EXE
C:WINDOWSSYSTEMmmtask.tsk
C:WINDOWSSYSTEMMSTASK.EXE
C:PROGRAM FILESANTIVIRAL TOOLKIT PROAVPCC.EXE
C:WINDOWSEXPLORER.EXE
C:WINDOWSTASKMON.EXE
C:WINDOWSSYSTEMSYSTRAY.EXE
C:PROGRAM FILESHEWLETT-PACKARDDIGITAL IMAGINGUNLOADHPQCMON.EXE
C:PROGRAM FILESHEWLETT-PACKARDHP SHARE-TO-WEBHPGS2WND.EXE
C:PROGRAM FILESANTIVIRAL TOOLKIT PROAVPCC.EXE
C:PROGRAM FILESADAPTECDIRECTCDDIRECTCD.EXE
C:PROGRAM FILESADAPTECEASY CD CREATOR 4CREATECDCREATECD.EXE
E:MOJA DUPAGADU-GADUGG.EXE
C:PROGRAM FILESHEWLETT-PACKARDHP SHARE-TO-WEBHPGS2WNF.EXE
C:PROGRAM FILESMICROSOFT OFFICEOFFICEFINDFAST.EXE
C:PROGRAM FILESMICROSOFT OFFICEOFFICEOSA.EXE
C:PROGRAM FILESANTIVIRAL TOOLKIT PROAVPM.EXE
C:WINDOWSSYSTEMWMIEXE.EXE
C:PROGRAM FILESINTERNET EXPLORERIEXPLORE.EXE
C:WINDOWSSYSTEMFTE.EXE
C:WINDOWSSYSTEMPSTORES.EXE
C:WINDOWSSYSTEMDDHELP.EXE
C:WINDOWSPULPITHIJACKTHISHIJACKTHIS.EXE
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
www.gazeta.pl/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
www.eu.microsoft.com/poland/
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 - BHO: (no name) - {C6626970-A1C5-8E10-B51D-8E7AECC55092} -
C:WINDOWSSYSTEMUWD.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:PROGRAM FILESADOBEACROBAT 5.0 CEREADERACTIVEXACROIEHELPER.OCX
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:WINDOWSSYSTEMMSDXM.OCX
O4 - HKLM..Run: [TaskMonitor] C:WINDOWS askmon.exe
O4 - HKLM..Run: [SystemTray] SysTray.Exe
O4 - HKLM..Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..Run: [OWCCardbusTray] ocbtray.exe
O4 - HKLM..Run: [CamMonitor] C:Program FilesHewlett-PackardDigital
Imaging\Unloadhpqcmon.exe
O4 - HKLM..Run: [Share-to-Web Namespace Daemon] C:Program FilesHewlett-
PackardHP Share-to-Webhpgs2wnd.exe
O4 - HKLM..Run: [AVPCC] C:Program FilesAntiViral Toolkit Proavpcc.exe
O4 - HKLM..Run: [Adaptec DirectCD] C:PROGRA~1ADAPTECDIRECTCDDIRECTCD.EXE
O4 - HKLM..Run: [CreateCD] C:PROGRA~1ADAPTECEASYCD~1
CREATECDCREATECD.EXE -r
O4 - HKLM..RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..RunServices: [SchedulingAgent] C:WINDOWSSYSTEMmstask.exe
O4 - HKLM..RunServices: [AVPCC Service] C:Program FilesAntiViral Toolkit
Proavpcc.exe
O4 - HKCU..Run: [Gadu-Gadu] "E:MOJA DUPAGADU-GADUGG.EXE" /tray
O4 - Startup:
Microsoft Find Fast.lnk = C:Program FilesMicrosoft
OfficeOfficeFINDFAST.EXE
O4 - Startup: Uruchamianie pakietu Office.lnk = C:Program FilesMicrosoft
OfficeOfficeOSA.EXE
O6 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present
O12 - Plugin for .pdf: C:PROGRA~1INTERN~1PLUGINS
ppdf32.dll
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O15 - Trusted IP range: 213.159.117.202 (HKLM)
Przeczytaj wszystkie posty z tego wątku
Temat: baaardzo proszę o sprawdzenie loga
baaardzo proszę o sprawdzenie loga
Logfile of HijackThis v1.99.1
Scan saved at 21:14:59, on 2006-02-02
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSYSTEMKERNEL32.DLL
C:WINDOWSSYSTEMMSGSRV32.EXE
C:WINDOWSSYSTEMmmtask.tsk
C:WINDOWSSYSTEMMPREXE.EXE
C:WINDOWSSYSTEMMSTASK.EXE
C:WINDOWSSYSTEMONELABSVSMON.EXE
C:WINDOWSSYSTEMKB891711KB891711.EXE
C:WINDOWSEXPLORER.EXE
C:WINDOWSTASKMON.EXE
C:WINDOWSSYSTEMSYSTRAY.EXE
C:WINDOWSRUNDLL32.EXE
C:PROGRAM FILESALCATELSPEEDTOUCH USBDRAGDIAG.EXE
C:PROGRAM FILESWANADOOTASKBARICON.EXE
C:WINDOWSSYSTEMWMIEXE.EXE
C:PROGRAM FILESONE LABSONEALARMONEALARM.EXE
C:PROGRAM FILESMICROSOFT OFFICEOFFICEOSA.EXE
C:PROGRAM FILESMICROSOFT OFFICEOFFICEFINDFAST.EXE
C:PROGRAM FILESONE LABSONEALARMONEALARM.GID
C:WINDOWSSYSTEMDDHELP.EXE
C:WINDOWSSYSTEMRESTORESTMGR.EXE
C:PROGRAM FILESWANADOOESPACEWANADOO.EXE
C:PROGRAM FILESWANADOOCOMCOMP.EXE
C:WINDOWSSYSTEMTAPISRV.EXE
C:PROGRAM FILESWANADOOWATCH.EXE
C:WINDOWSSYSTEMRNAAPP.EXE
C:WINDOWSPULPITHIJACKTHISHIJACKTHIS.EXE
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar =
szukaj.wp.pl
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
www.wp.pl
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Neostrada
Plus wita Cie w Internecie
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:WINDOWSSYSTEMMSDXM.OCX
O4 - HKLM..Run: [ScanRegistry] C:WINDOWSscanregw.exe /autorun
O4 - HKLM..Run: [TaskMonitor] C:WINDOWS askmon.exe
O4 - HKLM..Run: [PCHealth] C:WINDOWSPCHealthSupportPCHSchd.exe -s
O4 - HKLM..Run: [SystemTray] SysTray.Exe
O4 - HKLM..Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE
C:WINDOWSSYSTEMNvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE
C:WINDOWSSYSTEMNvMcTray.dll,NvTaskbarInit
O4 - HKLM..Run: [SpeedTouch USB Diagnostics] "C:Program
FilesAlcatelSpeedTouch USBDragdiag.exe" /icon
O4 - HKLM..Run: [WOOWATCH] C:PROGRA~1WANADOOWatch.exe
O4 - HKLM..Run: [WOOTASKBARICON] C:PROGRA~1WANADOOTaskbarIcon.exe
O4 - HKLM..RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM..RunServices: [*StateMgr] C:WINDOWSSystemRestoreStateMgr.exe
O4 - HKLM..RunServices: [TrueVector] C:WINDOWSSYSTEMONELABSVSMON.EXE -
service
O4 - HKLM..RunServices: [KB891711] C:WINDOWSSYSTEMKB891711KB891711.EXE
O4 - HKCU..Run: [ccleaner] "C:PROGRAM FILESCCLEANERCCLEANER.exe" /AUTO
O4 - Startup: Uruchamianie pakietu Office.lnk = C:Program FilesMicrosoft
OfficeOfficeOSA.EXE
O4 - Startup:
Microsoft Find Fast.lnk = C:Program FilesMicrosoft
OfficeOfficeFINDFAST.EXE
O4 - Global Startup: ZoneAlarm.lnk = C:Program Filesone
LabsoneAlarmzonealarm.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:PROGRA~1MESSEN~1MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:PROGRA~1MESSEN~1MSMSGS.EXE
Przeczytaj wszystkie posty z tego wątku
Temat: prośba o sprawdzenie loga
Skan i usuwanie wszystkiego tym:
download.microsoft.com/download/8/1/5/815d2d60-49b5-44dc-ae35-fca2f2c6f0cc/MicrosoftAntiSpywareInstall.exe
download.ewido.net/ewido-setup.exe <- zrob update przed skanowaniem, po
przeskanowaniu odinstaluj.
Zamknij porty tym:
www.firewallleaktester.com/tools/wwdc.exe
W hijackthis:
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
195.95.218.172/index.php
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
195.95.218.172/index.php
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
195.95.218.172/index.php
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
195.95.218.172/index.php
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
195.95.218.172/index.php
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
195.95.218.172/index.php
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {78364D99-A640-4ddf-B91A-67EFF8373045} -
C:WINDOWSsystem32appwiz.dll <- kasujesz
O4 - HKLM..Run: [Starting up] wvsvc.exe
O4 - HKLM..Run: [SysMemory manager] c:windowssystem32mdms.exe opis
usuwania tutaj:
securityresponse.symantec.com/avcenter/venc/data/trojan.repsamo.html
O4 - HKLM..Run: [Internet Explorer] c:Program FilesInternet
Explorershttpshttp.exe
O4 - HKLM..Run: [ms1] C:WINDOWSms1.exe
O4 - HKLM..RunServices: [Starting up] wvsvc.exe
O4 - HKCU..Run: [Starting up] wvsvc.exe <- kasujesz plik
O4 - HKCU..Run: [ms1] C:WINDOWSms1.exe <- kasujesz plik
O4 - Global Startup:
Microsoft Find Fast.lnk = C:Program FilesMicrosoft
OfficeOfficeFINDFAST.EXE <- usun z autostartu
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) -
www.errorguard.com/installation/Install.cab
O20 - Winlogon Notify: drct16 - C:WINDOWSSYSTEM32drct16.dll <- i jak zwykle
to samo:
Backdoor.Haxdoor wariant D.
www.searchengines.pl/phpbb203/index.php?showtopic=12510&st=30&p=109496entry132561
O20 - Winlogon Notify: tcpG4T - C:WINDOWSSYSTEM32 cpG4T.dll
www.sophos.com/virusinfo/analyses/trojhaxdoorag.html <- tutaj masz
podane co i gdzie usunac.
O21 - SSODL: SysTray.Excn - {1722ECFF-4356-4f5b-B534-E67294FE75E9} -
C:WINDOWSSystem32aneagpqm.dll (file missing)
O21 - SSODL: SysTray.Exsh - {1768ECFC-4F5C-4f5b-B134-D67294FC78E9} -
C:WINDOWSSystem32jkbaqbmk.dll (file missing)
O21 - SSODL: Internet Explorer - {F28A40D7-AD0E-034A-C651-5F0ED76232E6} -
C:WINDOWSSystem32Mgapmj32.dll (file missing)
Jak juz wszystko usuniesz i naprawisz to wklej nowy log.
Przeczytaj wszystkie posty z tego wątku
Temat: Log z hijackthis, spysheriff... Proszę o pomoc!
Log z hijackthis, spysheriff... Proszę o pomoc!
Witam!
Oto mój log z hijackthis - coś tam już usuwałem ale nie wiem czy jest OK.
Proszę o pomoc i wskazówki jak usunąć SpySheriffa. Niby usunąłem go już z
kompa ale dalej coś jest nie tak. Pojawiają mi się ciągle monity o blokowaniu
trojanów.
Z góry dzięki
LOG:
Logfile of HijackThis v1.99.1
Scan saved at 21:11:28, on 2005-09-20
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:Program FilesMKSBinmks_menu.exe
C:Program FilesD-Toolsdaemon.exe
C:WINDOWSSystem32ctfmon.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesTlen.pl len.exe
C:winstall.exe
C:WINDOWS ool2.exe
C:Program FilesMicrosoft OfficeOfficeFINDFAST.EXE
C:Program FilesMicrosoft OfficeOfficeOSA.EXE
C:Program FilesMKSBinNetMonSv.exe
C:Program FilesMKSBinmksmonsv.exe
C:Program FilesMKSBinmks_scan.exe
C:WINDOWSSystem32wuauclt.exe
C:Documents and SettingsSylkaPulpithijackthisHijackThis.exe
C:Documents and SettingsSylkaPulpithijackthisHijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:WINDOWSSystem32msdxm.ocx
O4 - HKLM..Run: [MKS_MENU] C:Program FilesMKSBinmks_menu.exe
O4 - HKLM..Run: [SiSUSBRG] C:WINDOWSSiSUSBrg.exe
O4 - HKLM..Run: [DAEMON Tools-1033] "C:Program FilesD-Toolsdaemon.exe" -
lang 1033
O4 - HKLM..Run: [MSConfig]
C:WINDOWSPCHealthHelpCtrBinariesMSConfig.exe /auto
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 - HKCU..Run: [Komunikator] C:Program FilesTlen.pl len.exe
O4 - Global Startup:
Microsoft Find Fast.lnk = C:Program FilesMicrosoft
OfficeOfficeFINDFAST.EXE
O4 - Global Startup: Uruchamianie pakietu Office.lnk = C:Program
FilesMicrosoft OfficeOfficeOSA.EXE
O12 - Plugin for .spop: C:Program FilesInternet
ExplorerPluginsNPDocBox.dll
O23 - Service: MkS Net Monitor (MksNetMon) - Unknown owner - C:Program
FilesMKSBinNetMonSv.exe
O23 - Service: MkSUpdateInt - MkS Sp. z o. o. - C:Program
FilesMKSinMkSUpdateInt.exe
O23 - Service: MkS_Vir Monitor (MksVirMonSvc) - Unknown owner - C:Program
FilesMKSBinmksmonsv.exe
O23 - Service: MkS_Scan - Unknown owner - C:Program
FilesMKSBinmks_scan.exe
Przeczytaj wszystkie posty z tego wątku
Temat: CoolWWWSearch, trek blue error nuker
ja mam podobny problem z tym ze jak robie scan Spybotem to mi wykrywa tego
NUKERA i nie moge go usunac,jka robie scan hijackthis to nic mi na czerwono nie
wyskakuje. do tego mam jeszcze jakiegos CoolWWWSearch.SearchKlick i tez za
pomoca Apybota nie daje rady tego usunac. ponizej wklejam log z hijackthis moze
pomozecie.dzieki
Logfile of HijackThis v1.99.1
Scan saved at 13:34:35, on 2005-10-09
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
C:Program FilesAlwil SoftwareAvast4ashServ.exe
C:WINDOWSsystem32
vsvc32.exe
C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe
C:Program FilesAlwil SoftwareAvast4ashWebSv.exe
C:WINDOWSSOUNDMAN.EXE
C:Program FilesCyberLinkPowerDVDPDVDServ.exe
C:Program FilesJavajre1.5.0_04injusched.exe
C:PROGRA~1ALWILS~1Avast4ashDisp.exe
C:Program FilesWinampwinampa.exe
C:WINDOWSwinds32.exe
C:Program FilesSkypePhoneSkype.exe
C:Program FilesMicrosoft OfficeOfficeFINDFAST.EXE
C:WINDOWSsystem32mstw.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesSpybot - Search & DestroySpybotSD.exe
C:Documents and SettingsKarolPulpithijackthisHijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = about:blank
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = about:blank
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = about:blank
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = about:blank
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:Program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:PROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO: Class - {9114249C-F5E5-36A3-4480-169B869E0556} - C:WINDOWSsdkar.dll
O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE
C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit
O4 - HKLM..Run: [RemoteControl] "C:Program FilesCyberLinkPowerDVDPDVDServ.exe"
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [SunJavaUpdateSched] C:Program
FilesJavajre1.5.0_04injusched.exe
O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe
O4 - HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe
O4 - HKLM..Run: [winds32.exe] C:WINDOWSwinds32.exe
O4 - HKCU..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /nosplash
/minimized
O4 - Startup: ubisoft register.lnk = C:Program FilesUbi SoftRegisterschedule.exe
O4 - Global Startup:
Microsoft Find Fast.lnk = C:Program FilesMicrosoft
OfficeOfficeFINDFAST.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:Program FilesJavajre1.5.0_04in
pjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program
FilesJavajre1.5.0_04in
pjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
skaner.mks.com.pl/SkanerOnline.cab
O23 - Service: Network Security Service ( 11Fßä#·şÄÖ`I) - Unknown owner -
C:WINDOWSsystem32mstw.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner -
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:Program FilesAlwil
SoftwareAvast4ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:Program FilesAlwil
SoftwareAvast4ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:Program FilesAlwil
SoftwareAvast4ashWebSv.exe" /service (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
C:WINDOWSsystem32
vsvc32.exe
moze jakies dodatkowe instrukcje na maila: kaol@go2.pl
ponadto juz mi explorer wogole nie dziala, tak jakby go wywalilo.
Przeczytaj wszystkie posty z tego wątku
Temat: proszęo sprawdzenie loga
proszęo sprawdzenie loga
Logfile of HijackThis v1.99.1
Scan saved at 14:54:30, on 2006-04-03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSYSTEMKERNEL32.DLL
C:WINDOWSSYSTEMMSGSRV32.EXE
C:WINDOWSSYSTEMMPREXE.EXE
C:WINDOWSSYSTEMMSTASK.EXE
C:WINDOWSSYSTEMONELABSVSMON.EXE
C:WINDOWSSYSTEMONELABSMINILOG.EXE
C:WINDOWSSYSTEMmmtask.tsk
C:WINDOWSEXPLORER.EXE
C:WINDOWSSYSTEMINTERNAT.EXE
C:WINDOWSTASKMON.EXE
C:PROGRAM FILESEWAN-SOFTEWAN-SYSTEM SERWERBINFBGUARD.EXE
C:WINDOWSSYSTEMLVCOMSX.EXE
C:WINDOWSSYSTEMSYSTRAY.EXE
C:WINDOWSSYSTEMSTIMON.EXE
C:PROGRAM FILESONE LABSONEALARMONEALARM.EXE
C:PROGRAM FILESMICROSOFT OFFICEOFFICEFINDFAST.EXE
C:PROGRAM FILESEWAN-SOFTEWAN-SYSTEM SERWERBINFBSERVER.EXE
C:WINDOWSSYSTEMWMIEXE.EXE
C:PROGRAM FILESMOZILLA FIREFOXFIREFOX.EXE
C:PROGRAM FILESOUTLOOK EXPRESSMSIMN.EXE
C:WINDOWSSYSTEMPSTORES.EXE
C:WINDOWSSYSTEMDDHELP.EXE
D:PROGRAMY DLA CZARKAHIJACKTHISHIJACKTHIS.EXE
C:WINDOWSSYSTEMSPOOL32.EXE
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
www.eu.microsoft.com/poland/
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet
Settings,ProxyOverride = localhost;<local>
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:PROGRAM FILESADOBEACROBAT 5.0READERACTIVEXACROIEHELPER.OCX
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:WINDOWSSYSTEMMSDXM.OCX
O4 - HKLM..Run: [internat.exe] internat.exe
O4 - HKLM..Run: [ScanRegistry] C:WINDOWSscanregw.exe /autorun
O4 - HKLM..Run: [TaskMonitor] C:WINDOWS askmon.exe
O4 - HKLM..Run: [SystemTray] SysTray.Exe
O4 - HKLM..Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..Run: [FirebirdGuardian] C:Program FilesEWAN-SoftEWAN-System
SERWERinfbguard.exe
O4 - HKLM..Run: [LVCOMSX] C:WINDOWSSYSTEMLVCOMSX.EXE
O4 - HKLM..Run: [Zasobnik systemowy] SysTray.Exe
O4 - HKLM..Run: [StillImageMonitor] C:WINDOWSSYSTEMSTIMON.EXE
O4 - HKLM..Run: [mdac_runonce] C:WINDOWSSYSTEM
unonce.exe
O4 - HKLM..RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM..RunServices: [TrueVector] C:WINDOWSSYSTEMONELABSVSMON.EXE
-service
O4 - HKLM..RunServices: [MiniLog] C:WINDOWSSYSTEMONELABSMINILOG.EXE
-service
O4 - Startup:
Microsoft Find Fast.lnk = C:Program FilesMicrosoft
OfficeOfficeFINDFAST.EXE
O4 - Global Startup: ZoneAlarm.lnk = C:Program Filesone
LabsoneAlarmzonealarm.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:Program FilesJavajre1.5.0_01in
pjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program
FilesJavajre1.5.0_01in
pjpi150_01.dll
O12 - Plugin for .spop: C:PROGRA~1INTERN~1PluginsNPDocBox.dll
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
skaner.mks.com.pl/SkanerOnline.cab
Przeczytaj wszystkie posty z tego wątku
Temat: BARDZO proszę o przejrzenia loga...
BARDZO proszę o przejrzenia loga...
Witam
Od paru dni mam problem z przeglądarką. Co parę minut nie reaguje ona na nic
(nie można klikać w odnośniki ani wprowadzać danych). Trwa to parę sekund i
jest to strasznie irytujące... Na dodatek wyłączanie, lub przełączanie okienek
przeglądarki trwa ZAWSZE parę sekund. Czym to może być spowodowane?
Bardzo proszę o odpowiedź
Logfile of HijackThis v1.99.1
Scan saved at 13:56:47, on 06-05-09
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSYSTEMKERNEL32.DLL
C:WINDOWSSYSTEMMSGSRV32.EXE
C:WINDOWSSYSTEMMPREXE.EXE
C:WINDOWSSYSTEMMSTASK.EXE
C:WINDOWSSYSTEMmmtask.tsk
C:WINDOWSEXPLORER.EXE
C:WINDOWSSYSTEMINTERNAT.EXE
C:WINDOWSTASKMON.EXE
C:WINDOWSSYSTEMSYSTRAY.EXE
C:PROGRAM FILESBROWSER MOUSEMOUSE32A.EXE
C:PROGRAM FILESOFFICE KEYBOARDKBDAP32A.EXE
C:PROGRAM FILESD-TOOLSDAEMON.EXE
C:WINDOWSSYSTEMQTTASK.EXE
D:GADU-GADUGG.EXE
D:GRYOOFFICEFINDFAST.EXE
D:GRYOOFFICEOSA.EXE
C:WINDOWSSYSTEMWMIEXE.EXE
C:WINDOWSSYSTEMDDHELP.EXE
C:PROGRAM FILESMOZILLA.ORGMOZILLAMOZILLA.EXE
C:WINDOWSPULPITHIJACKTHISHIJACKTHIS.EXE
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
www.eu.microsoft.com/poland/
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:PROGRAM
FILESFLASHGETJCCATCH.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:PROGRAM FILESADOBEACROBAT 6.0READERACTIVEXACROIEHELPER.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -
F:Program Filesjavainssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:WINDOWSSYSTEMMSDXM.OCX
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} -
C:PROGRAM FILESFLASHGETFGIEBAR.DLL
O4 - HKLM..Run: [internat.exe] internat.exe
O4 - HKLM..Run: [ScanRegistry] C:WINDOWSscanregw.exe /autorun
O4 - HKLM..Run: [TaskMonitor] C:WINDOWS askmon.exe
O4 - HKLM..Run: [SystemTray] SysTray.ExE
O4 - HKLM..Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..Run: [Zasobnik systemowy] SysTray.Exe
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSYSTEMNvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE
C:WINDOWSSYSTEMNvMcTray.dll,NvTaskbarInit
O4 - HKLM..Run: [EnsoniqMixer] starter.exe
O4 - HKLM..Run: [FLMOFFICE4DMOUSE] C:Program FilesBrowser MOUSEmouse32a.exe
O4 - HKLM..Run: [FLMK08KB] C:Program FilesOffice KeyboardKbdAp32A.exe
O4 - HKLM..Run: [DAEMON Tools-1033] "C:Program FilesD-Toolsdaemon.exe"
-lang 1033
O4 - HKLM..Run: [QuickTime Task] "C:WINDOWSSYSTEMQTTASK.EXE" -atboottime
O4 - HKLM..Run: [WINSYS] C:WINDOWSSYSTEMWINSYS.EXE
O4 - HKLM..RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU..Run: [Mozilla Quick Launch] "C:Program
Filesmozilla.orgMozillaMozilla.exe" -turbo
O4 - HKCU..Run: [EdHTML] C:PROGRAM FILESBINBOYEDHTMLV5.0EdHTML.exe /none
O4 - HKCU..Run: [Gadu-Gadu] "D:GADU-GADUGG.EXE" /tray
O4 - Startup:
Microsoft Find Fast.lnk = D:gryoOfficeFINDFAST.EXE
O4 - Startup: Uruchamianie pakietu Office.lnk = D:gryoOfficeOSA.EXE
O8 - Extra context menu item: Download using FlashGet - C:PROGRAM
FILESFLASHGETjc_link.htm
O8 - Extra context menu item: Download All by FlashGet - C:PROGRAM
FILESFLASHGETjc_all.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} -
C:PROGRAM FILESFLASHGETFLASHGET.EXE
O9 - Extra 'Tools' menuitem: &FlashGet -
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:PROGRAM FILESFLASHGETFLASHGET.EXE
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
www.mks.com.pl/skaner/SkanerOnline.cab
Przeczytaj wszystkie posty z tego wątku
Temat: mam wirusa
Ja urzywam mozille.org
Logfile of HijackThis v1.99.1
Scan saved at 18:27:11, on 05-10-14
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2614.3500)
Running processes:
C:WINDOWSSYSTEMKERNEL32.DLL
C:WINDOWSSYSTEMMSGSRV32.EXE
C:WINDOWSSYSTEMMPREXE.EXE
C:PROGRAM FILESMKSBINNETMONSV.EXE
C:PROGRAM FILESCOMMON FILESEPSONEBAPISAGENT2.EXE
C:WINDOWSSYSTEMONELABSVSMON.EXE
C:WINDOWSSYSTEMMSTASK.EXE
C:WINDOWSSYSTEMmmtask.tsk
C:WINDOWSEXPLORER.EXE
C:WINDOWSSYSTEMINTERNAT.EXE
C:WINDOWSTASKMON.EXE
C:WINDOWSSYSTEMSYSTRAY.EXE
C:PROGRAM FILESMKSBINMKS_MENU.EXE
C:PROGRAM FILESMKSBINMKS_MON.EXE
C:WINDOWSSYSTEMQTTASK.EXE
C:WINDOWSSYSTEME_S10IC2.EXE
C:WINDOWSSYSTEMSTIMON.EXE
C:WINDOWSSYSTEMSPOOL32.EXE
C:PROGRAM FILESONE LABSONEALARMLCLIENT.EXE
C:PROGRAM FILESA4TECHMOUSEAMOUMAIN.EXE
C:PROGRAM FILESWINAMPWINAMPA.EXE
C:PROGRAM FILESPWNDEFINICJEBINSTARTER.EXE
C:WINDOWSANVSHELL.EXE
C:WINDOWSSYSTEMDDHELP.EXE
C:PROGRAM FILESSLYSOFTCLONECDCLONECDTRAY.EXE
C:PROGRAM FILESGADU-GADUGG.EXE
C:WINDOWSRunDLL.exe
C:PROGRAM FILESDESKTOP ARCHITECTDATRAY.EXE
C:PROGRAM FILESMKSBINMKS_SCAN.EXE
C:PROGRAM FILESMICROSOFT OFFICEOFFICEOSA.EXE
C:WINDOWSSYSTEMWMIEXE.EXE
C:PROGRAM FILESDC++DCPLUSPLUS.EXE
C:WINDOWSPULPITPROGRAMYHIJACKTHISHIJACKTHIS.EXE
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = about:blank
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
www.google.pl/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
www.eu.microsoft.com/poland/
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = about:blank
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:WINDOWSSYSTEMMSDXM.OCX
O4 - HKLM..Run: [internat.exe] internat.exe
O4 - HKLM..Run: [ScanRegistry] C:WINDOWSscanregw.exe /autorun
O4 - HKLM..Run: [TaskMonitor] C:WINDOWS askmon.exe
O4 - HKLM..Run: [SystemTray] SysTray.Exe
O4 - HKLM..Run: [OWCCardbusTray] ocbtray.exe
O4 - HKLM..Run: [MKS_MENU] C:Program FilesMKSBinmks_menu.exe
O4 - HKLM..Run: [MKS_MON] C:Program FilesMKSBinmks_mon.exe
O4 - HKLM..Run: [QuickTime Task] "C:WINDOWSSYSTEMQTTASK.EXE" -atboottime
O4 - HKLM..Run: [EPSON Stylus C42 Series] C:WINDOWSSYSTEME_S10IC2.EXE /P23
"EPSON Stylus C42 Series" /O5 "LPT1:" /M "Stylus C42"
O4 - HKLM..Run: [StillImageMonitor] C:WINDOWSSYSTEMSTIMON.EXE
O4 - HKLM..Run: [Zone Labs Client] C:Program Filesone
LabsoneAlarmzlclient.exe
O4 - HKLM..Run: [PE2CKFNT SE] C:Program FilesUlead SystemsUlead Photo
Express 2 SEChkFont.exe
O4 - HKLM..Run: [WheelMouse] C:PROGRA~1A4TECHMOUSEAMOUMAIN.EXE
O4 - HKLM..Run: [Zasobnik systemowy] SysTray.Exe
O4 - HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe
O4 - HKLM..Run: [DemonStarter] C:Program FilesPWNDefinicjeBinStarter.exe
O4 - HKLM..Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..Run: [anvshell] anvshell.exe
O4 - HKLM..Run: [LiveNote] livenote.exe
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSYSTEMNvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [wpkontakt] C:Program FilesWirtualna
Polskawpkontaktwpkontakt.exe -autostart
O4 - HKLM..Run: [CloneCDTray] "C:Program
FilesSlySoftCloneCDCloneCDTray.exe" /s
O4 - HKLM..RunServices: [MksMailService] C:PROGRAM FILESMKSBINNETMONSV.EXE
O4 - HKLM..RunServices: [SAgent2ExePath] C:Program FilesCommon
FilesEPSONEBAPISAgent2.exe
O4 - HKLM..RunServices: [TrueVector] C:WINDOWSSYSTEMONELABSVSMON.EXE -service
O4 - HKLM..RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..RunServices: [SchedulingAgent] C:WINDOWSSYSTEMmstask.exe
O4 - HKCU..Run: [Mozilla Quick Launch] "C:Program
Filesmozilla.orgMozillaMozilla.exe" -turbo
O4 - HKCU..Run: [Gadu-Gadu] "C:PROGRAM FILESGADU-GADUGG.EXE" /tray
O4 - HKCU..Run: [Taskbar Display Controls] RunDLL
deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU..Run: [Desktop Architect] "C:PROGRAM FILESDESKTOP
ARCHITECTDATRAY.EXE" -S
O4 - HKCU..Run: [NBJ] "C:PROGRAM FILESAHEADNERO BACKITUPNBJ.EXE"
O4 - Startup: Adobe Gamma Loader.exe.lnk = C:Program FilesCommon
FilesAdobeCalibrationAdobe Gamma Loader.exe
O4 - Startup: Uruchamianie pakietu Office.lnk = C:Program FilesMicrosoft
OfficeOfficeOSA.EXE
O4 - Startup:
Microsoft Find Fast.lnk = C:Program FilesMicrosoft
OfficeOfficeFINDFAST.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
C:WINDOWSweb
elated.htm
O9 - Extra 'Tools' menuitem: Show &Related Links -
{c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSweb
elated.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:Program FilesJavajre1.5.0_04in
pjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program
FilesJavajre1.5.0_04in
pjpi150_04.dll
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) -
67.15.101.3/g_bin/pl/billard8_2_0_0_23.cab
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
skaner.mks.com.pl/SkanerOnline.cab
O18 - Protocol: wpmsg - {2E0AC5A0-3597-11D6-B3ED-0001021DC1C3} - C:PROGRAM
FILESWIRTUALNA POLSKAWPKONTAKTURL_WPMSG.DLL
Przeczytaj wszystkie posty z tego wątku
Temat: Trojan.Agent.Ay
dzieki wielkie;)))))
czy możesz sprawdzić logo z mojego drugiego komutera?
próbowałam sprawdzić go pandą, przerwał stwierdzając błąd w
pliku VCACHE(04)+oooo1386
błąd: OE:0028:CO04EA22
Logfile of HijackThis v1.99.1
Scan saved at 13:08:13, on 2005-10-26
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0100)
Running processes:
C:WINDOWSSYSTEMKERNEL32.DLL
C:WINDOWSSYSTEMMSGSRV32.EXE
C:WINDOWSSYSTEMMPREXE.EXE
C:WINDOWSSYSTEMMSTASK.EXE
C:PROGRAM FILESCOMMON FILESSYMANTEC SHAREDCCEVTMGR.EXE
C:PROGRAM FILESNORTON SYSTEMWORKSNORTON CLEANSWEEPCSINJECT.EXE
C:PROGRAM FILESNORTON SYSTEMWORKSNORTON UTILITIESNPROTECT.EXE
C:PROGRAM FILESCOMMON FILESSYMANTEC SHAREDSYMTRAY.EXE
C:PROGRAM FILESNORTON SYSTEMWORKSNORTON GHOSTGHOSTSTARTSERVICE.EXE
C:WINDOWSSYSTEMmmtask.tsk
C:WINDOWSSYSTEMRESTORESTMGR.EXE
C:WINDOWSEXPLORER.EXE
C:MEDIA95VI_GRM.EXE
C:WINDOWSptsnoop.exe
C:WINDOWSSYSTEMINTERNAT.EXE
C:WINDOWSTASKMON.EXE
C:WINDOWSSYSTEMSYSTRAY.EXE
C:PROGRAM FILESSCANJETPRECISIONSCANLTHPPWRSAV.EXE
C:PROGRAM FILESCOMMON FILESSYMANTEC SHAREDCCAPP.EXE
C:PROGRAM FILESNORTON SYSTEMWORKSNORTON GHOSTGHOSTSTARTTRAYAPP.EXE
C:WINDOWSSYSTEMWMIEXE.EXE
C:PROGRAM FILESMICROSOFT OFFICEOFFICEFINDFAST.EXE
C:PROGRAM FILESNORTON SYSTEMWORKSNORTON CLEANSWEEPCSINSM32.EXE
C:Program FilesNorton SystemWorksNorton CleanSweepMonwow.exe
C:WINDOWSSYSTEMDDHELP.EXE
C:WINDOWSPULPITHIJACKTHISHIJACKTHIS.EXE
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
www.onet.pl/
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
F1 - win.ini: load=C:MEDIA95vi_grm.exe ptsnoop.exe
F1 - win.ini: run=hpfsched
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:PROGRAM FILESADOBEACROBAT 5.0 CEREADERACTIVEXACROIEHELPER.OCX
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:Program
FilesNorton SystemWorksNorton AntiVirusNavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1045,&Radio - {8E718888-423F-11D2-876E-
00A0C9082467} - C:WINDOWSSYSTEMMSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
C:Program FilesNorton SystemWorksNorton AntiVirusNavShExt.dll
O4 - HKLM..Run: [internat.exe] internat.exe
O4 - HKLM..Run: [TaskMonitor] C:WINDOWS askmon.exe
O4 - HKLM..Run: [PCHealth] C:WINDOWSPCHealthSupportPCHSchd.exe -s
O4 - HKLM..Run: [SystemTray] SysTray.Exe
O4 - HKLM..Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..Run: [hppwrsav] C:PROGRAM
FILESSCANJETPrecisionScanLThppwrsav.exe
O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec
SharedccApp.exe"
O4 - HKLM..Run: [ccRegVfy] "C:Program FilesCommon FilesSymantec
SharedccRegVfy.exe"
O4 - HKLM..Run: [GhostStartTrayApp] C:Program FilesNorton
SystemWorksNorton GhostGhostStartTrayApp.exe
O4 - HKLM..Run: [ScanRegistry] C:WINDOWSscanregw.exe /autorun
O4 - HKLM..Run: [NPROTECT] C:Program FilesNorton SystemWorksNorton
UtilitiesNPROTECT.EXE
O4 - HKLM..Run: [Symantec NetDriver Monitor] C:PROGRA~1SYMNET~1
SNDMON.EXE /Consumer
O4 - HKLM..RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM..RunServices: [*StateMgr] C:WINDOWSSystemRestoreStateMgr.exe
O4 - HKLM..RunServices: [ccEvtMgr] "C:Program FilesCommon FilesSymantec
SharedccEvtMgr.exe"
O4 - HKLM..RunServices: [ScriptBlocking] "C:Program FilesCommon
FilesSymantec SharedScript BlockingSBServ.exe" -reg
O4 - HKLM..RunServices: [CSINJECT.EXE] C:Program FilesNorton
SystemWorksNorton CleanSweepCSINJECT.EXE
O4 - HKLM..RunServices: [NPROTECT] C:Program FilesNorton SystemWorksNorton
UtilitiesNPROTECT.EXE
O4 - HKLM..RunServices: [SymTray - Norton SystemWorks] C:Program
FilesCommon FilesSymantec SharedSymTray.exe "Norton SystemWorks"
O4 - HKLM..RunServices: [GhostStartService] C:PROGRAM FILESNORTON
SYSTEMWORKSNORTON GHOSTGHOSTSTARTSERVICE.EXE
O4 - Startup:
Microsoft Find Fast.lnk = C:Program FilesMicrosoft
OfficeOfficeFINDFAST.EXE
O4 - Startup: CleanSweep Smart Sweep-Internet Sweep.lnk = C:Program
FilesNorton SystemWorksNorton CleanSweepcsinsm32.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
C:WINDOWSweb
elated.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-
00aa003c157a} - C:WINDOWSweb
elated.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:PROGRA~1MESSEN~1MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:PROGRA~1MESSEN~1MSMSGS.EXE
O9 - Extra button: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} -
C:Program FilesFree SurferFS20.exe
O9 - Extra 'Tools' menuitem: Free Surfer - {AFC3FA82-AD07-45cd-8B57-
983435B9899E} - C:Program FilesFree SurferFS20.exe
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX
Control) -
www.modgik.lodz.pl/Mapa_01/mgaxctrl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
acs.pandasoftware.com/activescan/as5free/asinst.cab
często włącza mu się tryb awaryjny i coś jest nie tak ze sterownikami, tyle
wiem.
Przeczytaj wszystkie posty z tego wątku
zanotowane.pldoc.pisz.plpdf.pisz.plerfly06132.opx.pl
Strona
4 z
4 • Zostało wyszukane 119 wypowiedzi •
1,
2,
3,
4