
- Kod: Zaznacz wszystko
- [code]witam.na kompie teściowej po starcie na wp pojawia sie komunikat od mikrosoft internet explorer<warningDetected SPYware! System error #384
 __________________________________________________________________________
 
 Your IP address is 80.50.58.154. Using this address a remote computer has gained anaccess to your computer and probably is collecting the information about the sites you've visited and the files contained in the folder Temporary Internet Files. Attention! Ask for help or install the software for deleting secret information about the sites you visited.
 
 __________________________________________________________________________
 
 Your computer is full of evidences!
 
 ISP of transmission: 58
 Your IP address: 80.50.58.154
 They know you're using: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
 Your computer is: Windows XP
 Risk status for further investigation: VERY HIGH RISK
 
 
 
 
 To protect from the Spyware - click here
 To prevent information transmission - click here
 To delete the history of your activity, click here
 
 tutaj log
 Logfile of HijackThis v1.99.1
 Scan saved at 20:37:10, on 2006-06-10
 Platform: Windows XP (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 (6.00.2600.0000)
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 C:\Program Files\Alwil Software\Avast4\ashServ.exe
 C:\Program Files\Winamp\winampa.exe
 C:\Program Files\gswrdiw.exe
 C:\WINDOWS\System32\ctfmon.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\Skype\Phone\Skype.exe
 C:\Program Files\Gadu-Gadu\gg.exe
 C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.21 V1.10\WlanCU.exe
 C:\Program Files\Internet Explorer\IEXPLORE.EXE
 C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
 C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
 C:\WINDOWS\System32\wuauclt.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Documents and Settings\aha\Ustawienia lokalne\Temp\Katalog tymczasowy 9 dla hijackthis.zip\HijackThis.exe
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.find.fm/?aid=2343
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
 O4 - HKLM\..\Run: [SysTray] C:\Program Files\gswrdiw.exe
 O4 - HKLM\..\RunOnce: [aswAhAScr.dll] C:\PROGRA~1\ALWILS~1\Avast4\ASWREG~1.EXE "C:\Program Files\Alwil Software\Avast4\AhAScr.dll"
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
 O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe"
 O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
 O4 - Global Startup: Wireless Configuration Utility.lnk = C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.21 V1.10\WlanCU.exe
 O16 - DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} (MainControl Class) - http://arcaonline.arcabit.com/ArcaOnline.cab
 O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) - http://skaner.mks.com.pl/SkanerOnline.cab
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
 O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
 O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe[/code][code][/code]

 
	


 
	 
 



