Oglądasz wypowiedzi znalezione dla frazy: Microsoft Spyware





Temat: Prośba o sprawdzenie loga
Prośba o sprawdzenie loga
Prosze sprawdzić .Nie wszystko jest w porządku.

Logfile of HijackThis v1.97.7
Scan saved at 16:09:31, on 2005-04-13
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe
C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exe
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSGtwatch.exe
C:WINDOWSgtwatch.exe
F:Program filesmobile PhoneToolsWatchDog.exe
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:Program FilesNorton AntiVirus avapsvc.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesNorton AntiVirusIWPNPFMntor.exe
C:WINDOWSSystem32 vsvc32.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe
C:Program FilesTlen.pl len.exe
E:emuleemule.exe
C:Program FilesInternet Exploreriexplore.exe
D:HijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
www.wp.pl/
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet
Settings,ProxyServer = w3cache.daminet.pl:8080
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program
FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:Program
FilesSpybot - Search & DestroySDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:Program
FilesNorton AntiVirusNavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:WINDOWSSystem32msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
C:Program FilesNorton AntiVirusNavShExt.dll
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32
NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [] C:WINDOWSGtwatch.exe
O4 - HKLM..Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM..Run: [Gtwatch] C:WINDOWSgtwatch.exe
O4 - HKLM..Run: [NeroCheck] C:WINDOWSSystem32\NeroCheck.exe
O4 - HKLM..Run: [HPDJ Taskbar Utility] C:WINDOWSSystem32
spooldriversw32x863hpztsb03.exe
O4 - HKLM..Run: [WatchDog] F:Program filesmobile PhoneToolsWatchDog.exe
O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec
SharedccApp.exe"
O4 - HKLM..Run: [SSC_UserPrompt] C:Program FilesCommon FilesSymantec
SharedSecurity CenterUsrPrmpt.exe
O4 - HKLM..Run: [Symantec NetDriver Monitor] C:PROGRA~1SYMNET~1SNDMon.exe
O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft
OfficeOffice10OSA.EXE
O4 - Global Startup: Ulead Photo Express 3.0 SE Calendar Checker.lnk =
C:Program FilesUlead SystemsUlead Photo Express 3.0 SECalCheck.exe
O4 - Global Startup: Watch.lnk = C:WINDOWS wain_32A6U16KWATCH.exe
O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Microsoft AntiSpyware helper (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper (HKCU)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
skaner.mks.com.pl/SkanerOnline.cab
O17 - HKLMSystemCCSServicesTcpip..{1C3740F4-E723-401D-8E9B-
885862A8026C}: NameServer = 82.139.13.226
O17 - HKLMSystemCS1ServicesTcpip..{1C3740F4-E723-401D-8E9B-
885862A8026C}: NameServer = 82.139.13.226
O17 - HKLMSystemCS2ServicesTcpip..{1C3740F4-E723-401D-8E9B-
885862A8026C}: NameServer = 82.139.13.226

Przeczytaj wszystkie posty z tego wątku



Temat: SPYWARE _POMOCY!!!!!!!!!!!!!!!!!
Najpierw przeskanuj tym:
cwshredder.net/bin/CWShredder.exe <- CWS Shredder

Odinstaluj: MySearch,PCTools, Spyware Doctor, RegFreeze

Do tego o ile dobrze widze masz dwa antyvirusy, a wiec odinstaluj jeden chociaz
oba to zamulacze systemu wiec wywal najlepiej oba i zainstaluj avast + kerio :-)

> R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
> res://C:WINDOWSsystem32shdocpl.dll/security.htm#subID=MPV;401
> R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
> www.vobis.pl/
> R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
> www.makemesearch.com/?said=382
> R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
> res://shdocpl.dll/asst.htm
> R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
> O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - C:Program
> FilesMySearchar1.binS4BAR.DLL
> O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} -
> C:PROGRA~1SPYWAR~2 oolsiesdsg.dll
> O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} -
> C:PROGRA~1SPYWAR~2 oolsiesdpb.dll
> O2 - BHO: Cls - {CF021F40-3E14-23A5-CBA2-7173706D8274} - C:WINDOWSSystem32
> spm8274.dll
> O3 - Toolbar: SuperBar - {2DBDB463-84E1-458A-8ED4-E98F4CEE09C2} - C:Program
> FilesSUPERBARSUPERBAR.dll (file missing)
> O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
> O4 - HKLM..Run: [lsasss.exe] C:WINDOWSlsasss.exe
> O4 - HKLM..Run: [levur] C:WINDOWSlevur.exe
> O4 - HKLM..Run: [FastStart] C:WINDOWSsystem32svcnut.exe home
> O4 - HKLM..RunOnce: [Local runole service] C:WINDOWSSystem32srvc32.exe
> O4 - HKLM..RunOnce: [Srv32 spool service] C:WINDOWSSystem32spoolsrv32.exe
> O4 - HKCU..Run: [Spyware Doctor] "C:Program FilesSpyware
> Doctorswdoctor.exe" /Q
> O4 - HKCU..RunOnce: [Local runole service] C:WINDOWSSystem32srvc32.exe
> O4 - HKCU..RunOnce: [Srv32 spool service] C:WINDOWSSystem32spoolsrv32.exe
> O4 - Startup: RegFreeze.lnk = C:Program FilesRegFreeze egfreeze.exe
> O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} -
> C:PROGRA~1SPYWAR~2 oolsiesdpb.dll
> O9 - Extra button: Search and Remove Spyware - {CDB280E8-BE43-4128-8A5A-
> 3FCD094E2D88} - C:Program FilesRegFreeze fsearchhandler.dll
> O9 - Extra 'Tools' menuitem: Search and Remove Spyware - {CDB280E8-BE43-4128-
> 8A5A-3FCD094E2D88} - C:Program FilesRegFreeze fsearchhandler.dll
> O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {8171C6FC-F6F9-
> 4499-9DF4-A005F3385E22} - (no file) (HKCU)
> O14 - IERESET.INF: START_PAGE_URL=www.vobis.pl/

Fix Checked i wklej nowy log z hijackthis.
Przeczytaj wszystkie posty z tego wątku



Temat: trojan
trojan
pokazuje się napisa na pulpicie...(pulpit jest niebieski)

a fatal erro in EI has occured at 0028: c0011e36 in vxd vmm (01)00010e36.
Error was caused by trojan-spy.html.smitfraud.c


Logfile of HijackThis v1.99.1
Scan saved at 16:23:50, on 2005-04-27
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:PROGRA~1AGNITUMOUTPOS~1.0outpost.exe
C:WINDOWSsvchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32 undll32.exe
C:Program FilesGadu-Gadugg.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:WINDOWSSystem32devldr32.exe
C:DOCUME~1MareckiUSTAWI~1Tempupdate.tmp
C:Program FilesFlashGetflashget.exe
C:DownloadsHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar =
res://C:DOCUME~1MareckiUSTAWI~1Tempse.dll/spage.html
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar =
res://C:DOCUME~1MareckiUSTAWI~1Tempse.dll/spage.html
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = about:blank
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
about:blank
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
about:blank
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet
Settings,ProxyOverride = 127.0.0.1
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 - BHO: (no name) - {035749F7-79F5-485C-98C6-C92C783ADBF1} - (no file)
O2 - BHO: (no name) - {26CBADF4-0150-4B6F-9A82-9F1B1B5DFA73} -
C:WINDOWSSystem32ikbc.dll
O2 - BHO: (no name) - {6A64C6C7-FF52-4F89-BC20-16979F845E11} - (no file)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} -
C:PROGRA~1FLASHGETjccatch.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:WINDOWSSystem32msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} -
C:PROGRA~1FLASHGETfgiebar.dll
O4 - HKLM..Run: [Outpost Firewall] C:PROGRA~1AGNITUMOUTPOS~1.0
outpost.exe /waitservice
O4 - HKLM..Run: [TrojanScanner] C:Program FilesTrojan RemoverTrjscan.exe
O4 - HKLM..Run: [sp] rundll32 C:DOCUME~1MareckiUSTAWI~1
Tempse.dll,DllInstall
O4 - HKLM..Run: [MKS_MENU] C:Program FilesMKSBinmks_menu.exe
O8 - Extra context menu item: Download All by FlashGet - C:Program
FilesFlashGetjc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:Program
FilesFlashGetjc_link.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
C:WINDOWSweb elated.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-
00aa003c157a} - C:WINDOWSweb elated.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} -
C:PROGRA~1FLASHGETflashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-
0050BA6940E3} - C:PROGRA~1FLASHGETflashget.exe
O9 - Extra button: Microsoft AntiSpyware helper - {471E3BEB-5EBC-4C1D-90AA-
8D1AAAF81FD9} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {471E3BEB-5EBC-
4C1D-90AA-8D1AAAF81FD9} - (no file) (HKCU)
O16 - DPF: {11311111-1111-1111-1111-111111111157} -
file://C:RecycledQ330995.exe
O17 - HKLMSystemCCSServicesTcpip..{DC85E18D-B55A-4756-A3BB-
F0AE03FC1B19}: NameServer = 192.168.0.1
O18 - Filter: text/html - {E556A7EE-B2FA-4784-86C7-6F0D0F67F0DD} -
C:WINDOWSSystem32ikbc.dll
O18 - Filter: text/plain - {E556A7EE-B2FA-4784-86C7-6F0D0F67F0DD} -
C:WINDOWSSystem32ikbc.dll
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum -
C:PROGRA~1AGNITUMOUTPOS~1.0outpost.exe

Przeczytaj wszystkie posty z tego wątku



Temat: Bardzo Prosze o sprawdzenie loga hijackthis !!!
Na poczatk usun iSearch "Desktop Search" tak jak masz w opisie tutaj:
www.searchengines.pl/phpbb203/index.php?showtopic=12510&st=0&p=109496&#entry135478

Nastepnie usun Backdoor.Haxdoor tak jak masz podane tutaj:
www.searchengines.pl/phpbb203/index.php?showtopic=12510&st=0&p=109496&#entry132561

Jak juz to wszystko zrobisz to w hijackthis wybierz scan only i zaznacz te
wpisy:

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
81.222.131.49/index.php
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
81.222.131.49/index.php
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
81.222.131.49/index.php
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
81.222.131.49/index.php
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
81.222.131.49/index.php
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no
file)
O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} -
C:WINDOWSBolger.dll
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} -
C:WINDOWSisrvssysupd.dll (file missing)
O2 - BHO: (no name) - {A0269420-A638-4509-889C-8FC3CC85DA7E} -
C:WINDOWSdrexinit.dll (file missing)
O3 - Toolbar: (no name) - {44BE0690-5429-47f0-85BB-3FFD8020233E} - (no file)
O4 - HKLM..Run: [Media Pass] C:Program FilesMedia PassMediaPassK.exe
O4 - HKLM..Run: [gah95on6] C:WINDOWSSystem32gah95on6.exe
O4 - HKLM..Run: [Windows Update] C:WINDOWSms1.exe
O4 - HKLM..Run: [Desktop Search] C:WINDOWSisrvsdesktop.exe
O4 - HKLM..Run: [ffis] C:WINDOWSisrvsffisearch.exe
O4 - HKCU..Run: [PayTime] C:WINDOWSSystem32paytime.exe
O9 - Extra button: Microsoft AntiSpyware helper - {7CFDB64D-9514-4861-8188-
4D2B7FBF9A1C} - C:WINDOWSSystem32wldr.dll (file missing)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7CFDB64D-9514-
4861-8188-4D2B7FBF9A1C} - C:WINDOWSSystem32wldr.dll (file missing)
O9 - Extra button: Microsoft AntiSpyware helper - {7CFDB64D-9514-4861-8188-
4D2B7FBF9A1C} - C:WINDOWSSystem32wldr.dll (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7CFDB64D-9514-
4861-8188-4D2B7FBF9A1C} - C:WINDOWSSystem32wldr.dll (file missing) (HKCU)
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} -
C:WINDOWSisrvsmfiltis.dll
O20 - Winlogon Notify: drct16 - C:WINDOWSSYSTEM32drct16.dll

I Fix Checked i sciagnij KillBox:
www.downloads.subratam.org/KillBox.zip
Rozpakuj, zaznacz Delete file on reboot wklej sciezke do pliku (sam nie szukaj
tylko wklejaj gotowa) i naciskaj czerwony przycik ale na pytanie o reset
odpowiadaj nie i tak zrob z tymi plikami:
C:WINDOWSBolger.dll
C:Program FilesMedia PassMediaPassK.exe
C:WINDOWSSystem32gah95on6.exe
C:WINDOWSSYSTEM32drct16.dll
C:WINDOWSisrvsmfiltis.dll
C:WINDOWSSystem32paytime.exe

Chociaz polowy juz nie powinno byc jak usuniesz wszystko zgodnie z dwoma
opisami podanym na poczatku.Po resecie wklej nowy log z hijackthis bo pewnie
cos zostanie.

Przeczytaj wszystkie posty z tego wątku



Temat: Kolejny log hijacks do sprawdzenia
Log mie zmieścił się cały.


Start do trybu awaryjnego:

usuwasz (poprzez dodaj/usun programy)
- 180 SearchAssistant
- BULLSEYE NETWORK
- SearchAccelerator
- CXTPLS
- SECURITY IGUARD


potem szukasz i usuwasz:
> IENUTILW.EXE -> z C:WINDOWSSYSTEM
> ENUBG.EXE -> z C:WINDOWSSYSTEM
> paytime.exe -> z C:WINDOWSSYSTEM
ap9h4qmo.exe -> z C:WINDOWSSYSTEM

uruchamiasz HJ wybierasz "do a system scan only" i zaznaczasz
> R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
> 81.222.131.49/index.php
> R1 - HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) =
> keyword.netscape.com/keyword/%s
> R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
> 81.222.131.49/index.php
> R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
> 81.222.131.49/index.php
> O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} -
> C:WINDOWSNEM220.DLL (file missing)
> O2 - BHO: (no name) - {A0269420-A638-4509-889C-8FC3CC85DA7E} -
> C:WINDOWSDREXINIT.DLL
> O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:PROGRAM
> FILESCXTPLSCXTPLS.DLL
> O2 - BHO: (no name) - {9414B321-799B-2366-E1D8-52C0CE965D93} -
> C:WINDOWSSYSTEMUUVDR.DLL
> O3 - Toolbar: @msdxmLC.dll,-1@1045,&Radio -
> {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSYSTEMMSDXM.OCX
> O3 - Toolbar: UCmore XP - The Search Accelerator -
> {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:PROGRAM
> FILESTHESEARCHACCELERATORUCMTSAIE.DLL
> O4 - HKLM..Run: [TkBellExe] "C:Program FilesCommon
> FilesRealUpdate_OB ealsched.exe" -osboot
> O4 - HKLM..Run: [QuickTime Task] "C:WINDOWSSYSTEMQTTASK.EXE" -atboottime
> O4 - HKLM..Run: [sac] c:program files180searchassistantsac.exe
> O4 - HKLM..Run: [BullsEye Network] C:Program FilesBullsEye
> Networkinargains.exe
> O4 - HKLM..Run: [op8g36j] IENUTILW.EXE
> O4 - HKLM..Run: [AutoLoaderEnvoloAutoUpdater]
> "C:WINDOWSTEMP~COMPOUNDINST0AUTO_UPDATE_LOADER.EXE" /HideUninstall
> /HideDir /PC=CP.AMS /ShowLegalNote=nonbranded
> O4 - HKLM..Run: [Security iGuard] C:PROGRAM FILESSECURITY IGUARDSECURITY
> IGUARD.EXE
> O4 - HKLM..Run: [PayTime] C:WINDOWSSYSTEMpaytime.exe
> > O4 - HKLM..Run: [Service Host]
> C:WINDOWSSYSTEMServices{8756B060-BF4E-11D9-A139-00111E0010F3}SVCHOST.EXE
> O4 - HKLM..Run: [ap9h4qmo] C:WINDOWSSYSTEMap9h4qmo.exe
> O4 - HKLM..Run: [AutoUpdater] "c:Program FilesAutoUpdateAutoUpdate.exe"
> O4 - HKCU..Run: [ZErmRWHnj] ENUBG.EXE
> O4 - HKCU..Run: [PayTime] C:WINDOWSSYSTEMpaytime.exe
> O4 - Startup: Microsoft Office.lnk = C:Program FilesMicrosoft
> OfficeOfficeOSA9.EXE -> nieszkodliwe ale zbedne
> O4 - Startup: Watch.lnk = C:WINDOWSTWAIN_32a4s2_600watch.exe
> > O9 - Extra 'Tools' menuitem: Show &Related Links -
> {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSweb elated.htm
> O9 - Extra button: Microsoft AntiSpyware helper -
> {B90977A0-BF4E-11D9-A139-00111E0010F3} - (no file) (HKCU)
> O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper -
> {B90977A0-BF4E-11D9-A139-00111E0010F3} - (no file) (HKCU)
> > O15 - Trusted Zone: *.windupdates.com
> O15 - Trusted Zone: *.searchmiracle.com
> O15 - Trusted Zone: *.my-internet.info
> O15 - Trusted Zone: *.flingstone.com
> O15 - Trusted Zone: *.blazefind.com
> O15 - Trusted Zone: *.clickspring.net
> O15 - Trusted Zone: *.ysbweb.com
> O15 - Trusted Zone: *.slotchbar.com
> O15 - Trusted Zone: *.windupdates.com (HKLM)
> O15 - Trusted Zone: *.searchbarcash.com (HKLM)
> O15 - Trusted Zone: *.searchmiracle.com (HKLM)
> O15 - Trusted Zone: *.skoobidoo.com (HKLM)
> O15 - Trusted Zone: *.my-internet.info (HKLM)
> O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
> O15 - Trusted Zone: *.slotch.com (HKLM)
> O15 - Trusted Zone: *.flingstone.com (HKLM)
> O15 - Trusted Zone: *.mt-download.com (HKLM)
> O15 - Trusted Zone: *.blazefind.com (HKLM)
> O15 - Trusted IP range: 81.222.131.59
> O15 - Trusted IP range: 81.222.131.59 (HKLM)

i Fix Checked. restart i wklej nowy log.
Przeczytaj wszystkie posty z tego wątku
  • zanotowane.pl
  • doc.pisz.pl
  • pdf.pisz.pl
  • erfly06132.opx.pl



  • Strona 3 z 3 • Zostało wyszukane 186 wypowiedzi • 1, 2, 3

    © 2009 Najlepszy miesiąc kawalerski w Polsce !!! - Ceske - Sjezdovky .cz. Design downloaded from free website templates