Re: może ktoś spojrzy - chyba coś złapałem...

Autor: tomasz:) <antyspam.CUT._at_buziaczek.pl>
Data: Thu 12 Jun 2008 - 17:22:59 MET DST
Message-ID: <48513F53.9070300@buziaczek.pl>
Content-Type: text/plain; charset=ISO-8859-2; format=flowed

Przepraszam - post się nie pojawił, a sprawa poważna...

> Witam,
>
> prośba o pomoc. COŚ cały czas resetuje eksplotera (2 razy na minutę).
> potem na chilę pojawia sie okienko "Ustawineia spersonalizowane" i
> peoces się włącza.
>
> poniżej Logi hijackthis - sytuazja bardzo utrudniająca funkcjonowanie...
>
> pozdrawiam,
>
> Logfile of Trend Micro HijackThis v2.0.2
> Scan saved at 15:13:49, on 2008-06-12
> Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
> MSIE: Internet Explorer v7.00 (7.00.6000.16674)
> Boot mode: Normal
>
> Running processes:
> C:\WINDOWS\System32\smss.exe
> C:\WINDOWS\system32\winlogon.exe
> C:\WINDOWS\system32\services.exe
> C:\WINDOWS\system32\lsass.exe
> C:\WINDOWS\system32\svchost.exe
> C:\WINDOWS\System32\svchost.exe
> C:\WINDOWS\system32\spoolsv.exe
> C:\Program Files\Bonjour\mDNSResponder.exe
> C:\Program Files\ESET Smart Security\ekrn.exe
> C:\PROGRA~1\NVIDIA\NETWOR~1\Apache Group\Apache2\bin\apache.exe
> C:\Program Files\LogMeIn\x86\RaMaint.exe
> C:\Program Files\LogMeIn\x86\LogMeIn.exe
> C:\PROGRA~1\NVIDIA\NETWOR~1\Apache Group\Apache2\bin\apache.exe
> C:\PROGRA~1\NVIDIA\NETWOR~1\bin\nSvcLog.exe
> C:\WINDOWS\system32\nvsvc32.exe
> C:\Program Files\Sandboxie\SbieSvc.exe
> C:\Program Files\Common Files\VMware\VMware Virtual Image
> Editing\vmount2.exe
> C:\WINDOWS\system32\vmnat.exe
> C:\Program Files\VNC4\WinVNC4.exe
> C:\PROGRA~1\NVIDIA\NETWOR~1\bin\nSvcAppFlt.exe
> C:\PROGRA~1\NVIDIA\NETWOR~1\bin\nSvcIp.exe
> C:\Program Files\VMware\vmware-authd.exe
> C:\WINDOWS\system32\vmnetdhcp.exe
> C:\WINDOWS\system32\nvraidservice.exe
> C:\WINDOWS\system32\RUNDLL32.EXE
> C:\Program Files\Analog Devices\Core\smax4pnp.exe
> C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
> C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
> C:\Program Files\ESET Smart Security\egui.exe
> C:\Program Files\VMware\hqtray.exe
> C:\WINDOWS\system32\wbem\unsecapp.exe
> C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
> C:\Program Files\Maxtor\MSS Backup\maxbackservice.exe
> C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
> C:\Program Files\Maxtor\ManagerApp\msssort.exe
> C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
> C:\Program Files\Skype\Phone\Skype.exe
> C:\WINDOWS\system32\ctfmon.exe
> C:\Program Files\Picasa2\PicasaMediaDetector.exe
> C:\Program Files\Sandboxie\SbieCtrl.exe
> C:\Program Files\Gadu-Gadu\gg.exe
> C:\WINDOWS\system32\svchost.exe
> C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
> C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
> C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
> C:\Program Files\Skype\Plugin Manager\skypePM.exe
> C:\WINDOWS\system32\taskmgr.exe
> C:\Program Files\Firefox\firefox.exe
> C:\Program Files\HijackThis\HijackThis.exe
> C:\WINDOWS\system32\NOTEPAD.EXE
> C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
> C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
> C:\Program Files\Mozilla Thunderbird\thunderbird.exe
> C:\WINDOWS\explorer.exe
>
> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
> http://go.microsoft.com/fwlink/?LinkId=69157
> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
> http://go.microsoft.com/fwlink/?LinkId=54896
> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
> http://go.microsoft.com/fwlink/?LinkId=54896
> R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
> http://go.microsoft.com/fwlink/?LinkId=69157
> R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
> Settings,ProxyOverride = *.local
> R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
> Łącza
> O2 - BHO: Adobe PDF Reader Link Helper -
> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common
> Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
> O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} -
> C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
> O3 - Toolbar: Megaupload Toolbar -
> {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
> O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
> O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
> C:\WINDOWS\system32\NvCpl.dll,NvStartup
> O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
> O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
> C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
> O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog
> Devices\Core\smax4pnp.exe
> O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog
> Devices\SoundMAX\Smax4.exe" /tray
> O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program
> Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
> O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
> Files\Java\jre1.5.0_06\bin\jusched.exe
> O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET Smart Security\egui.exe"
> /hide /waitservice
> O4 - HKLM\..\Run: [VMware hqtray] "C:\Program Files\VMware\hqtray.exe"
> O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program
> Files\LogMeIn\x86\LogMeInSystray.exe"
> O4 - HKLM\..\Run: [InfraDrive Carbosign] "C:\Program
> Files\Carbosign\Carbosign.exe"
> O4 - HKLM\..\Run: [InfraDrive Carbosign Updates] "C:\Program
> Files\Carbosign\Carbosign.exe" -u
> O4 - HKLM\..\Run: [MaxBackSchedule] "C:\Program Files\Maxtor\MSS
> Backup\maxbackservice.exe"
> O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch
> Status\maxmenumgr.exe"
> O4 - HKLM\..\Run: [mssSort] "C:\Program
> Files\Maxtor\ManagerApp\msssort.exe"
> O4 - HKCU\..\Run: [TaskSwitchXP] C:\Program
> Files\TaskSwitchXP\TaskSwitchXP.exe
> O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe"
> /nosplash /minimized
> O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
> O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program
> Files\Picasa2\PicasaMediaDetector.exe
> O4 - HKCU\..\Run: [SandboxieControl] "C:\Program
> Files\Sandboxie\SbieCtrl.exe"
> O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
> O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
> (User 'SYSTEM')
> O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
> (User 'Default user')
> O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat
> 2\TransBar\TransBar.exe
> O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat
> 2\UberIcon\UberIcon Manager.exe
> O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat
> 2\YzShadow\YzShadow.exe
> O4 - Global Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista
> Inspirat 2\RocketDock\RocketDock.exe
> O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
> res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
> O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
> C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
> O9 - Extra 'Tools' menuitem: Sun Java Console -
> {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
> Files\Java\jre1.6.0_05\bin\ssv.dll
> O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
> C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
> O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -
> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
> O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -
> {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network
> Diagnostic\xpnetdiag.exe
> O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
> C:\Program Files\Messenger\msmsgs.exe
> O9 - Extra 'Tools' menuitem: Windows Messenger -
> {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
> Files\Messenger\msmsgs.exe
> O17 -
> HKLM\System\CCS\Services\Tcpip\..\{7D0F9656-7E34-4924-8444-CB9DD9DAF4CF}:
> NameServer = 217.8.168.244,157.25.5.18
> O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -
> C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
> O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##
> (Bonjour Service) - Apple Computer, Inc. - C:\Program
> Files\Bonjour\mDNSResponder.exe
> O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program
> Files\ESET Smart Security\EHttpSrv.exe
> O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET Smart
> Security\ekrn.exe
> O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. -
> C:\Program Files\Common Files\Macrovision Shared\FLEXnet
> Publisher\FNPLicensingService.exe
> O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown
> owner - C:\PROGRA~1\NVIDIA\NETWOR~1\bin\nSvcAppFlt.exe
> O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache
> Software Foundation - C:\PROGRA~1\NVIDIA\NETWOR~1\Apache
> Group\Apache2\bin\apache.exe
> O23 - Service: Google Updater Service (gusvc) - Google - C:\Program
> Files\Google\Common\Google Updater\GoogleUpdaterService.exe
> O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. -
> C:\Program Files\LogMeIn\x86\RaMaint.exe
> O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program
> Files\LogMeIn\x86\LogMeIn.exe
> O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation -
> C:\PROGRA~1\NVIDIA\NETWOR~1\bin\nSvcIp.exe
> O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation
> - C:\PROGRA~1\NVIDIA\NETWOR~1\bin\nSvcLog.exe
> O23 - Service: NVIDIA-OMEGA Display Driver Service (NVSvc) - NVIDIA
> Corporation - C:\WINDOWS\system32\nvsvc32.exe
> O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program
> Files\Sandboxie\SbieSvc.exe
> O23 - Service: VMware Authorization Service (VMAuthdService) - VMware,
> Inc. - C:\Program Files\VMware\vmware-authd.exe
> O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. -
> C:\WINDOWS\system32\vmnetdhcp.exe
> O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware,
> Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image
> Editing\vmount2.exe
> O23 - Service: VMware NAT Service - VMware, Inc. -
> C:\WINDOWS\system32\vmnat.exe
> O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. -
> C:\Program Files\VNC4\WinVNC4.exe
>
Received on Thu Jun 12 17:25:03 2008

To archiwum zostało wygenerowane przez hypermail 2.1.8 : Thu 12 Jun 2008 - 17:42:01 MET DST