chomiki
Log kontrolny - OTL 24.05.10
Proszę o sprawdzenie log'a, trojanDownloader.Wigon.bs
Log kontrolny - 24.10.2008
moze ktos sprawdzic mi log?prosze
Log kontrolny 22.01.10
LOG Meczy mnie reklamiarz
Net zmulony - log
Prosze o sprawdzenie log-a
Log proszę o sprawdzenie
CZYTAC TO!
  • zanotowane.pl
  • doc.pisz.pl
  • pdf.pisz.pl
  • apv88.opx.pl

  • chomiki

    WITAM

    Mam pro¶be, co¶ mi komputer szwankuje avast wywala komunikat o trojanie Win32:small i nie moge go usun±ć, oto log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 02:11:35, on 2001-11-21
    Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\CyberLink\PCM4Everio\EverioService.exe
    C:\WINDOWS\system32\wind32.exe
    C:\WINDOWS\system32\n2ewma1xxsv234.exe
    C:\WINDOWS\system32\alt.exe.exe
    C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Windows\xpupdate.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\dllgh8jkd1q1.exe
    C:\WINDOWS\system32\dllgh8jkd1q5.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\vedxga1me4t1.exe
    C:\WINDOWS\system32\vedxg4am1et2.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\wscntfy.exe
    c:\sysihic.exe
    C:\WINDOWS\system32\dllgh8jkd1q1.exe
    C:\WINDOWS\system32\dllgh8jkd1q5.exe
    C:\WINDOWS\system32\vedxga1me4t1.exe
    C:\WINDOWS\system32\msupdtck.exe
    C:\Program Files\BitComet\BitComet.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wp.pl/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Ł±cza
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\vmware-ufad.exe,
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {247BE3C3-56F2-4828-9600-E2C73592BE86} - C:\WINDOWS\system32\datim.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [EverioService] "C:\Program Files\CyberLink\PCM4Everio\EverioService.exe"
    O4 - HKLM\..\Run: [System] C:\WINDOWS\system32\wind32.exe
    O4 - HKLM\..\Run: [SystemSv121] C:\WINDOWS\system32\n2ewma1xxsv2234.exe
    O4 - HKLM\..\Run: [PromoReg] C:\WINDOWS\system32\alt.exe.exe
    O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\adam\USTAWI~1\Temp\winlogon.exe
    O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
    O4 - HKCU\..\Run: [Service Pack 1] C:\WINDOWS\system32\vedxg6ame4.exe
    O4 - HKCU\..\Run: [mssdbsrv] C:\WINDOWS\system32\msupdtck.exe
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microso...b?1006298722901
    O17 - HKLM\System\CCS\Services\Tcpip\..\{23790EFB-279D-4A10-AE77-C79B23121104}: NameServer = 85.255.113.202,85.255.112.202
    O17 - HKLM\System\CCS\Services\Tcpip\..\{40BCB9C4-7415-41A8-92FA-46D60B4F038E}: NameServer = 85.255.113.202,85.255.112.202
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.202 85.255.112.202
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.202 85.255.112.202
    O20 - Winlogon Notify: WLCtrl32 - C:\WINDOWS\SYSTEM32\WLCtrl32.dll
    O21 - SSODL: zip - {3af3cdca-cf60-4513-81cb-30bbb3a87b96} - C:\WINDOWS\Installer\{3af3cdca-cf60-4513-81cb-30bbb3a87b96}\zip.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
    O23 - Service: Microsoft security update service (msupdate) - Unknown owner - c:\windows\system32\mssrv32.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O24 - Desktop Component 0: (no name) - http://www.travian3.pl/img/pl/t2/gallier.gif
    O24 - Desktop Component 1: (no name) - http://www.husaria.jest.pl/husik.gif

    --
    End of file - 10950 bytes

    Z góry dzięki za pomoc


    hm.. podejrzane pliki:
    C:\WINDOWS\system32\wind32.exe
    C:\WINDOWS\system32\n2ewma1xxsv234.exe
    C:\WINDOWS\system32\alt.exe.exe
    C:\Windows\xpupdate.exe
    C:\WINDOWS\system32\dllgh8jkd1q1.exe
    C:\WINDOWS\system32\dllgh8jkd1q5.exe
    C:\WINDOWS\system32\vedxga1me4t1.exe
    C:\WINDOWS\system32\vedxg4am1et2.exe
    c:\sysihic.exe
    C:\WINDOWS\system32\dllgh8jkd1q1.exe
    C:\WINDOWS\system32\dllgh8jkd1q5.exe
    C:\WINDOWS\system32\vedxga1me4t1.exe
    C:\WINDOWS\system32\msupdtck.exe
    O4 - HKLM\..\Run: [System] C:\WINDOWS\system32\wind32.exe
    O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\adam\USTAWI~1\Temp\winlogon.exe - fix
    O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe - fix
    Odniosłem wrażenie jakby kto¶ Ci porty skanował...
    porty skanował tzn??

    porty skanował tzn??
    Szukał otwartej furtki do twojich danych.
    A to:



    http://pl.wikipedia.org/wiki/Skanowanie_portów

    skasuj totalem, jak by sie nie dało to killbox wszystko co na czerwono zanznacze

    http://pl.wikipedia.org/wiki/Skanowanie_portów

    skasuj totalem, jak by sie nie dało to killbox wszystko co na czerwono zanznacze
    fix i kasujesz
    C:\WINDOWS\system32\wind32.exe
    C:\Windows\xpupdate.exe
    C:\WINDOWS\system32\dllgh8jkd1q1.exe
    C:\WINDOWS\system32\dllgh8jkd1q5.exe
    C:\WINDOWS\system32\vedxga1me4t1.exe
    C:\WINDOWS\system32\vedxg4am1et2.exe

    Tego całe google nie zna, I ja tez… jesli nie znasz to tak samo fix i usuń
    c:\sysihic.exe
    fix
    C:\WINDOWS\system32\dllgh8jkd1q1.exe
    C:\WINDOWS\system32\dllgh8jkd1q1.exe
    C:\WINDOWS\system32\dllgh8jkd1q5.exe
    C:\WINDOWS\system32\vedxga1me4t1.exe
    C:\WINDOWS\system32\msupdtck.exe

    Fix
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    O1 - Hosts: 124.217.252.77 www.bravesentry.com
    O1 - Hosts: 124.217.252.77 bravesentry.com
    O1 - Hosts: 124.217.252.78 secure.isoftpay.com
    FIX
    O2 - BHO: (no name) - {247BE3C3-56F2-4828-9600-E2C73592BE86} - C:\WINDOWS\system32\datim.dll
    O4 - HKLM\..\Run: [System] C:\WINDOWS\system32\wind32.exe
    O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\adam\USTAWI~1\Temp\winlogon.exe
    O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
    O4 - HKCU\..\Run: [Service Pack 1] C:\WINDOWS\system32\vedxg6ame4.exe
    O4 - HKCU\..\Run: [mssdbsrv] C:\WINDOWS\system32\msupdtck.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{23790EFB-279D-4A10-AE77-C79B23121104}: NameServer = 85.255.113.202,85.255.112.202
    O17 - HKLM\System\CCS\Services\Tcpip\..\{40BCB9C4-7415-41A8-92FA-46D60B4F038E}: NameServer = 85.255.113.202,85.255.112.202
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.202 85.255.112.202
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.202 85.255.112.202
    O20 - Winlogon Notify: WLCtrl32 - C:\WINDOWS\SYSTEM32\WLCtrl32.dll
    O24 - Desktop Component 0: (no name) - http://www.travian3.pl/img/pl/t2/gallier.gif
    O24 - Desktop Component 1: (no name) - http://www.husaria.jest.pl/husik.gif

    Nie znam tego, ale i tak zakładam że syf
    O4 - HKLM\..\Run: [SystemSv121] C:\WINDOWS\system32\[color=darkred]n2ewma1xxsv2234.exe
    O4 - HKLM\..\Run: [PromoReg] C:\WINDOWS\system32\alt.exe.exe
    O23 - Service: Microsoft security update service (msupdate) - Unknown owner - c:\windows\system32\mssrv32.exe

    ja piernicze, tyle syfu naraz niegdy na oczy nie widziałem... weĽ to pokasuj i porestarcie jeszcze raz trzeba sprawdzić, bo na raz to napewno sie cos przeoczyło

    rekord
  • zanotowane.pl
  • doc.pisz.pl
  • pdf.pisz.pl
  • mandragora32.opx.pl
  • 
    Wszelkie Prawa ZastrzeĹĽone! chomiki Design by SZABLONY.maniak.pl.