| Author |
Message
|
El Diablo Poziom 18

Joined: 30 Jul 2004 Posts: 469 Location: Wrocław
|
#1
08 Dec 2005 14:03 NAV2006 i scanning message |
|
|
|
witam, mam taki problem z norton av 2006 ze ciagle na ekran wyskakuja mi powiadomienia o skanowaniu wiadomosci jest ich dziesiatki, a poczte odbieram tylko przez www i nie wiem gdzie to wylaczyc.
wyglada to tak:
| Description: |
|
| Filesize: |
83.36 KB |

|
|
|
| Back to top |
|
 |
Robert B Poziom 24

Joined: 12 Jun 2003 Posts: 5772 Location: Warszawa
|
#2
09 Dec 2005 01:42 NAV2006 i scanning message |
|
|
|
Zlituj się! Z tego mamy coś przeczytać??? Zrzuć okno a nie cały pulpit!
|
|
| Back to top |
|
 |
El Diablo Poziom 18

Joined: 30 Jul 2004 Posts: 469 Location: Wrocław
|
#3
10 Dec 2005 17:55 Re: NAV2006 i scanning message |
|
|
|
sorki chcialem zebys zobaczyl m/w jak to wyglada, a wiadomosci maja miedzy innymi taka postac:
| Description: |
|
| Filesize: |
24.26 KB |

|
|
|
| Back to top |
|
 |
Robert B Poziom 24

Joined: 12 Jun 2003 Posts: 5772 Location: Warszawa
|
#4
11 Dec 2005 23:05 NAV2006 i scanning message |
|
|
|
Zrobiłeś co każą?
|
|
| Back to top |
|
 |
Google

|
#
11 Dec 2005 23:05 |
|
|
|
|
|
| Back to top |
|
 |
jankolo Poziom 26

Joined: 10 Jan 2005 Posts: 28261 Location: Łódź
|
#5
11 Dec 2005 23:20 Re: NAV2006 i scanning message |
|
|
|
El Diablo, jeżeli to jest screen z Twojego komputera, to wskazuje on dowodnie iż rozsyłasz pocztę z reklamami p...graficznymi, czyli jesteś SPAMEREM! Jeżeli tego nie robisz świadomie, to masz exploita w komputerze. Wklej na forum log z hijackthis.
|
|
| Back to top |
|
 |
El Diablo Poziom 18

Joined: 30 Jul 2004 Posts: 469 Location: Wrocław
|
#6
16 Dec 2005 15:24 NAV2006 i scanning message |
|
|
|
ja nawet nie mam skonfigurowanego outlooka !!
czy o to chodzi ?
Logfile of HijackThis v1.99.1
Scan saved at 15:30:00, on 2005-12-16
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Programy\RivaTuner v2.0 RC 15.6\RivaTuner.exe
C:\WINDOWS\System32\realmon.exe
C:\Program Files\Common files\VPN Network\IPSecMon.exe
C:\Programy\DAEMON Tools4\daemon.exe
C:\Program Files\SHA256\secure.exe
C:\WINDOWS\System32\MSNav32.exe
C:\WINDOWS\System32\fwwmon.exe
C:\WINDOWS\System32\MSFW2.exe
C:\Programy\QuickTime 6\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Programy\SlySoft\AnyDVD\AnyDVD.exe
C:\WINDOWS\system32\Kaspersky Lab\Kaspersky On-line Scanner\data\Patches\Nowy folder\myspy\svhosts.exe
C:\Programy\Restore Desktop\RestoreDesktop.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programy\Norton AntiVirus 2006\navapsvc.exe
C:\Programy\Norton AntiVirus 2006\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Programy\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\master.XXX-5COWPGC5PMB\Pulpit\hijackthis1.99.1\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.onet.pl/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = .: DEPECHE MODE :.
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = netcache.interia.pl:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programy\Acrobat\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Programy\Norton AntiVirus 2006\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Programy\Norton AntiVirus 2006\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Services Pack 2] usbdriver.exe
O4 - HKLM\..\Run: [RivaTuner] "C:\Programy\RivaTuner v2.0 RC 15.6\RivaTuner.exe" /T
O4 - HKLM\..\Run: [eTrust Realtime Monitor] C:\WINDOWS\System32\realmon.exe /start
O4 - HKLM\..\Run: [Recguard] C:\Program Files\HP\recguard.exe
O4 - HKLM\..\Run: [IPSecMon] C:\Program Files\Common files\VPN Network\IPSecMon.exe /vpncheck
O4 - HKLM\..\Run: [FoolProof] C:\Program Files\SmartStuff\fpwinldr.exe /load
O4 - HKLM\..\Run: [Microsoft Reg] wuamgrnd32.exe
O4 - HKLM\..\Run: [TermAgent] C:\WINDOWS\System32\deskconn.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programy\DAEMON Tools4\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SHA256] C:\Program Files\SHA256\secure.exe
O4 - HKLM\..\Run: [AdsBlocker] C:\Program Files\AdsBlocker\stopAds.exe
O4 - HKLM\..\Run: [REAL] C:\Program Files\REAL\realjbox.exe
O4 - HKLM\..\Run: [Apvxdwin] C:\WINDOWS\System32\APVXDWIN.EXE
O4 - HKLM\..\Run: [MSAntiVirus] C:\WINDOWS\System32\MSNav32.exe
O4 - HKLM\..\Run: [FWWMON.EXE] C:\WINDOWS\System32\fwwmon.exe
O4 - HKLM\..\Run: [Windows Update AutoUpdate Client] C:\WINDOWS\System32\winupd\wuauclt.exe
O4 - HKLM\..\Run: [MSFireWall2] C:\WINDOWS\System32\MSFW2.exe
O4 - HKLM\..\Run: [DSB] C:\Program Files\DSB\dsb.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programy\QuickTime 6\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] "C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe"
O4 - HKLM\..\Run: [AnyDVD] C:\Programy\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [msservice] C:\WINDOWS\system32\Kaspersky Lab\Kaspersky On-line Scanner\data\Patches\Nowy folder\myspy\svhosts.exe
O4 - HKLM\..\RunServices: [Services Pack 2] usbdriver.exe
O4 - HKLM\..\RunServices: [Microsoft Reg] wuamgrnd32.exe
O4 - HKLM\..\RunServices: [Microsoft Internet Explorer] lEXPLORE.EXE
O4 - HKCU\..\Run: [RestoreDesktop] C:\Programy\Restore Desktop\RestoreDesktop.exe
O4 - HKCU\..\Run: [Skype] "C:\Programy\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Programy\Gadu-Gadu\GG.EXE" /tray
O4 - HKCU\..\RunServices: [Services Pack 2] usbdriver.exe
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\Programy\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Pobierz z &BitSpirit - C:\Programy\BitSpirit\bsurl.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://kaspersky.pl/resources/virusscanner/kavwebscan_unicode.cab
O16 - DPF: {631FF594-EC25-4CFF-B869-402DF294E1D6} (Instalator oprogramowania Onet.pl) - http://slimak.onet.pl/_m/kamerzysta/OnetInstalator012s.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1133651381903
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: awtqo - awtqo.dll (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Hardware Clock Driver (hwclock) - Conexant - (no file)
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Programy\Norton AntiVirus 2006\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Programy\Norton AntiVirus 2006\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Programy\Norton AntiVirus 2006\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programy\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
|
|
| Back to top |
|
 |
jankolo Poziom 26

Joined: 10 Jan 2005 Posts: 28261 Location: Łódź
|
|
| Back to top |
|
 |
Google

|
#
16 Dec 2005 23:10 |
|
|
|
|
|
| Back to top |
|
 |
Robert B Poziom 24

Joined: 12 Jun 2003 Posts: 5772 Location: Warszawa
|
#8
17 Dec 2005 01:12 NAV2006 i scanning message |
|
|
|
Np. to pachnie mi lewizną:
O4 - HKLM\..\Run: [Services Pack 2] usbdriver.exe
O4 - HKLM\..\Run: [SHA256] C:\Program Files\SHA256\secure.exe
Sporo innych też. Odinstaluj też jednego antywirusa. Co za dużo to niezdrowo.
Wyobrażam sobie po tym listingu jak wolno chodzi Twój komputer.
|
|
| Back to top |
|
 |
El Diablo Poziom 18

Joined: 30 Jul 2004 Posts: 469 Location: Wrocław
|
#9
17 Dec 2005 17:12 NAV2006 i scanning message |
|
|
|
mam tylko nortona a moze chodzi ci o kaspersky online scaner ?
robert B to co napisales to mam usunac ?
jankolo po czym sadzisz ze to trojan ?[/b]
|
|
| Back to top |
|
 |
jankolo Poziom 26

Joined: 10 Jan 2005 Posts: 28261 Location: Łódź
|
#10
17 Dec 2005 20:32 Re: NAV2006 i scanning message |
|
|
|
| El Diablo wrote: |
| po czym sadzisz ze to rtojan ? |
Po tym: C:\WINDOWS\System32\fwwmon.exe
|
|
| Back to top |
|
 |
paweliw Poziom 24

Joined: 24 Apr 2003 Posts: 4482 Location: Bydgoszcz
|
#11
17 Dec 2005 22:30 Re: NAV2006 i scanning message |
|
|
|
Jakby powiedział gość z Seksmisji "niezły bajzel tutaj widzę"
Brak uaktualnienia IE ! Wypadałoby to zmienić !
Wyłącz Przywracanie systemu w XP.
Użyj Windows Worms Doors Cleanera http://www.firewallleaktester.com/wwdc.htm zmień znaczki z disable na enable, i reset komputera.
Przeskanuj tym: http://www.microsoft.com/downloads/details.aspx?FamilyId=321CD7A2-6A57-4C57-A8BD-DBF62EDA9671 i usuń wszystko co znajdzie.
Odpal komputer w trybie awaryjnym bez dostępu do internetu.
Zakończ procesy:
C:\Program Files\SHA256\secure.exe
C:\WINDOWS\System32\MSNav32.exe
C:\WINDOWS\System32\fwwmon.exe
C:\WINDOWS\System32\MSFW2.exe
Jeżeli świadomie nie instalowałeś My Spy i Restore Desktop to również:
C:\WINDOWS\system32\Kaspersky Lab\Kaspersky On-line Scanner\data\Patches\Nowy folder\myspy\svhosts.exe
C:\Programy\Restore Desktop\RestoreDesktop.exe
Zaznacz wskazane wpisy kliknij Fix checked i skasuj z dysku pliki i foldery, które podkreśliłem na czerwono:
O4 - HKLM\..\Run: [Services Pack 2] usbdriver.exe
O4 - HKLM\..\Run: [Microsoft Reg] wuamgrnd32.exe
O4 - HKLM\..\Run: [TermAgent] C:\WINDOWS\System32\deskconn.exe
O4 - HKLM\..\Run: [SHA256] C:\Program Files\SHA256\secure.exe
O4 - HKLM\..\Run: [FWWMON.EXE] C:\WINDOWS\System32\fwwmon.exe
O4 - HKLM\..\Run: [Windows Update AutoUpdate Client] C:\WINDOWS\System32\winupd\wuauclt.exe
O4 - HKLM\..\Run: [MSFireWall2] C:\WINDOWS\System32\[/color]MSFW2.exe[/color=red]
O4 - HKLM\..\Run: [DSB] C:\Program Files\DSB\dsb.exe
O4 - HKLM\..\Run: [msservice] C:\WINDOWS\system32\Kaspersky Lab\Kaspersky On-line Scanner\data\Patches\Nowy folder\myspy\svhosts.exe <-usuń plik jak nie instalowałeś My Spy
O4 - HKLM\..\RunServices: [Services Pack 2] usbdriver.exe
O4 - HKLM\..\RunServices: [Microsoft Reg] wuamgrnd32.exe
O4 - HKLM\..\RunServices: [Microsoft Internet Explorer] [/color]lEXPLORE.EXE[/color=red]
O4 - HKCU\..\Run: [RestoreDesktop] C:\Programy\Restore Desktop\RestoreDesktop.exe <-usuń plik jak nie instalowałeś restore Desktop
O4 - HKCU\..\RunServices: [Services Pack 2] usbdriver.exe
O20 - Winlogon Notify: awtqo - awtqo.dll (file missing)
O23 - Service: Hardware Clock Driver (hwclock) - Conexant - (no file)
Na koniec wklej nowy log.
Sorry za red ale znaczniki mi się porypały :cry:
|
|
| Back to top |
|
 |
El Diablo Poziom 18

Joined: 30 Jul 2004 Posts: 469 Location: Wrocław
|
#12
18 Dec 2005 21:45 NAV2006 i scanning message |
|
|
|
Logfile of HijackThis v1.99.1
Scan saved at 21:37:44, on 2005-12-18
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Programy\RivaTuner v2.0 RC 15.6\RivaTuner.exe
C:\Programy\DAEMON Tools4\daemon.exe
C:\Program Files\AdsBlocker\stopAds.exe
C:\Programy\QuickTime 6\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Programy\SlySoft\AnyDVD\AnyDVD.exe
C:\WINDOWS\system32\Kaspersky Lab\Kaspersky On-line Scanner\data\Patches\Nowy folder\myspy\svhosts.exe
C:\Programy\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programy\Restore Desktop\RestoreDesktop.exe
C:\Programy\Skype\Phone\Skype.exe
C:\Programy\Gadu-Gadu\GG.EXE
C:\Programy\Microsoft AntiSpyware\gcasDtServ.exe
C:\Programy\Norton AntiVirus 2006\navapsvc.exe
C:\Programy\Norton AntiVirus 2006\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Programy\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\master.XXX-5COWPGC5PMB\Pulpit\hijackthis1.99.1\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = .: DEPECHE MODE :.
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = netcache.interia.pl:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programy\Acrobat\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Programy\Norton AntiVirus 2006\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Programy\Norton AntiVirus 2006\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RivaTuner] "C:\Programy\RivaTuner v2.0 RC 15.6\RivaTuner.exe" /T
O4 - HKLM\..\Run: [eTrust Realtime Monitor] C:\WINDOWS\System32\realmon.exe /start
O4 - HKLM\..\Run: [Recguard] C:\Program Files\HP\recguard.exe
O4 - HKLM\..\Run: [IPSecMon] C:\Program Files\Common files\VPN Network\IPSecMon.exe /vpncheck
O4 - HKLM\..\Run: [FoolProof] C:\Program Files\SmartStuff\fpwinldr.exe /load
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Programy\DAEMON Tools4\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [AdsBlocker] C:\Program Files\AdsBlocker\stopAds.exe
O4 - HKLM\..\Run: [REAL] C:\Program Files\REAL\realjbox.exe
O4 - HKLM\..\Run: [Apvxdwin] C:\WINDOWS\System32\APVXDWIN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programy\QuickTime 6\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] "C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe"
O4 - HKLM\..\Run: [AnyDVD] C:\Programy\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Programy\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [msservice] C:\WINDOWS\system32\Kaspersky Lab\Kaspersky On-line Scanner\data\Patches\Nowy folder\myspy\svhosts.exe
O4 - HKCU\..\Run: [RestoreDesktop] C:\Programy\Restore Desktop\RestoreDesktop.exe
O4 - HKCU\..\Run: [Skype] "C:\Programy\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Programy\Gadu-Gadu\GG.EXE" /tray
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\Programy\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Pobierz z &BitSpirit - C:\Programy\BitSpirit\bsurl.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://kaspersky.pl/resources/virusscanner/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1133651381903
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Hardware Clock Driver (hwclock) - Conexant - (no file)
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Programy\Norton AntiVirus 2006\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Programy\Norton AntiVirus 2006\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Programy\Norton AntiVirus 2006\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programy\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
|
|
| Back to top |
|
 |
paweliw Poziom 24

Joined: 24 Apr 2003 Posts: 4482 Location: Bydgoszcz
|
#13
21 Dec 2005 00:12 Re: NAV2006 i scanning message |
|
|
|
Sorry, że tak późno ale żona w szpitalu ...
Jest już dużo lepiej niż było ale jeszcze nie idealnie.
W dalszym ciągu brak uaktualnienia IE !
Rozumiem że świadomie korzystasz (poprzednio o to pytałem) z:
C:\WINDOWS\system32\Kaspersky Lab\Kaspersky On-line Scanner\data\Patches\Nowy folder\myspy\svhosts.exe
C:\Programy\Restore Desktop\RestoreDesktop.exe
C:\Program Files\AdsBlocker\stopAds.exe
Fix w hijackthis:
O23 - Service: Hardware Clock Driver (hwclock) - Conexant - (no file)
Jak fix nie pomoże to:
Start ->Uruchom wpisz cmd [enter]
W nowym oknie "dosa" wpisz: sc delete hwclock [enter] i restart komputera.
|
|
| Back to top |
|
 |
El Diablo Poziom 18

Joined: 30 Jul 2004 Posts: 469 Location: Wrocław
|
#14
21 Dec 2005 12:10 NAV2006 i scanning message |
|
|
|
swiadomie kozystam z restore desktop i myspy
a stopAds.exe ? nie wiem co to, a windows update nie uaktualnia IE ? czy to jakos inaczej trza zrobic ?
aha no i zauwazylem ze co jakis czas instaluje mi sie jakis energy plugins, pierw wyskakuje puste okno i jest exit i agree daje exit i chwile potem instaluje sie plugin...
|
|
| Back to top |
|
 |
Google

|
#
21 Dec 2005 12:10 |
|
|
|
|
|
| Back to top |
|
 |
paweliw Poziom 24

Joined: 24 Apr 2003 Posts: 4482 Location: Bydgoszcz
|
|
| Back to top |
|
 |
El Diablo Poziom 18

Joined: 30 Jul 2004 Posts: 469 Location: Wrocław
|
#16
26 Dec 2005 22:13 NAV2006 i scanning message |
|
|
|
energy plugins... jeszcze nie wiem moze z chatem na onecie ? ja nie ale zona uskutecznia bajere na nim ale jeszcze sie przyjze a co do tych denerwujacych okienek spamowych jak z tematu to pomoglo to co radziliscie, dzieki...
o stopAds przeczytalem i usunalem ten wpis ale nie wiem czy to usuwa go z systemu bo np. gify dalej sie nie ruszaja...
|
|
| Back to top |
|
 |