
W Operze wyskakuje MI:
This object has been blocked.
A w IE:
Dostęp do strony zabroniony!
Nie wiem czy to jest wirus czy źle zkonfigurowany ZA.
Jaka funkcja w ZA odpowiada za to?!


[ Dodano: Dzisiaj o 18:35 ]
ps... log z HJ mam czysty...
The firewall has blocked Internet acces to your computer (HTTP) from 81.190.77.8 (TCP Port 1248) [TPC Flags; S].
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:21, on 2007-12-07
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\RTHDCPL.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Flashget Catch Url Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Alcohol Toolbar Helper - {52D06F97-5511-43FA-8FDA-C481864FD26E} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Alcohol Toolbar - {4C4E7CDB-5BFC-4D74-83E2-8AE659B7EDA2} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Ratlerek.lnk = C:\WINDOWS\RTHDCPL.exe
O8 - Extra context menu item: &Ściągnij przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &Ściągnij wszystko przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Add to AMV Convert Tool... - E:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: Add to AMV Converter... - E:\Program Files\MP3 Player Utilities 4.09\AMVConverter\grab.html
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - E:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O16 - DPF: {4B4513E2-4E57-43DF-9496-FCD37E9DFA64} (GameDesire Sea Battle) - http://67.15.101.3/g_bin/pl/navy_2_0_0_29.cab
O16 - DPF: {65D72393-E210-4A2A-B8E0-10AC45986770} (GWebInstallControl Object) - http://megapanel.gem.pl/WebInstaller.dll
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} (GameDesire Poker Games) - http://67.15.101.3/g_bin/pl/poker_2_0_0_48.cab
O16 - DPF: {AB8638BB-79E8-4E9D-ABF2-8F33054E3941} (Guesser Class) - http://czat.onet.pl/client/kalambury/NetPunGame1.dll
O16 - DPF: {BFA1F11D-3121-AFE1-4112-894323212DAC} (GameDesire Word Games) - http://67.15.101.3/g_bin/pl/words_2_0_0_51.cab
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) - http://67.15.101.3/g_bin/pl/billard8_2_0_0_35.cab
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C5} (GameDesire Snooker) - http://67.15.101.3/g_bin/pl/snooker_2_0_0_29.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 6082 bytes
ComboFix 07-11-19.4 - Admin 2007-12-05 19:27:44.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.210 [GMT 1:00]
Running from: C:\Documents and Settings\Admin\Pulpit\LOGI ITP\ComboFix2.exe
.
((((((((((((((((((((((((( Files Created from 2007-11-05 to 2007-12-05 )))))))))))))))))))))))))))))))
.
2007-12-05 21:06 <DIR> d-------- C:\Documents and Settings\Admin\Dane aplikacji\7soft
2007-12-04 21:48 152,576 -ra------ C:\WINDOWS\system32\drivers\LV532AV.SYS
2007-11-28 17:47 <DIR> d-------- C:\Documents and Settings\Admin\Dane aplikacji\FileZilla
2007-11-28 17:37 18,944 --a------ C:\WINDOWS\eraser.exe
2007-11-27 16:08 <DIR> d-------- C:\WINDOWS\ERUNT
2007-11-23 21:03 <DIR> d-------- C:\Program Files\kRk Software
2007-11-19 16:15 <DIR> d-------- C:\Program Files\Monte Cristo
2007-11-19 15:44 <DIR> d-------- C:\WINDOWS\system32\hdined32.nls.{00021401-0000-0000-C000-000000000046}
2007-11-08 17:43 <DIR> d-------- C:\Program Files\Game_Maker7
2007-11-06 17:27 <DIR> d-------- C:\Program Files\bobyte
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-07 13:11 --------- d-----w C:\Documents and Settings\Admin\Dane aplikacji\Draco Organizer
2007-12-07 00:25 --------- d-----w C:\Program Files\eMule
2007-12-06 20:27 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2007-12-06 20:27 409,600 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2007-12-05 18:48 --------- d-----w C:\Program Files\FlashGet
2007-12-04 16:38 --------- d-----w C:\Program Files\CamStudio
2007-12-02 15:30 --------- d-----w C:\Program Files\sXe Injected
2007-11-24 14:31 392,856 ----a-w C:\Documents and Settings\Admin\Dane aplikacji\GDIPFONTCACHEV1.DAT
2007-11-19 17:01 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-10 10:06 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\FLEXnet
2007-11-10 08:43 --------- d-----w C:\Documents and Settings\Admin\Dane aplikacji\Tlen.pl
2007-11-03 11:35 --------- d-----w C:\Documents and Settings\Admin\Dane aplikacji\Notepad++
2007-11-03 11:33 --------- d-----w C:\Program Files\Notepad++
2007-11-03 10:24 --------- d-----w C:\Documents and Settings\Admin\Dane aplikacji\PHP Designer 2007
2007-10-28 21:49 --------- d-----w C:\Program Files\SystemRequirementsLab
2007-10-24 15:53 --------- d-----w C:\Program Files\Just BASIC v1.01
2007-10-24 15:11 --------- d-----w C:\Program Files\createinstall free
2007-10-22 15:03 --------- d-----w C:\Program Files\_AOE
2007-10-18 16:55 --------- d-----w C:\Program Files\Gadu-Gadu
2007-10-14 08:46 --------- d---a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2007-10-07 13:44 60,416 ----a-w C:\WINDOWS\system32\drivers\dg^mwswc.sys
2007-08-11 20:57 4 ----a-w C:\Program Files\2007-08-11 22_55.gps.bin
2007-08-11 20:56 0 ----a-w C:\Program Files\2007-08-11 22_55.gps
2007-08-08 14:47 44 ----a-w C:\Documents and Settings\Admin\ipspace.dat
2007-08-08 14:47 4,411 ----a-w C:\Documents and Settings\Admin\serverlist.dat
2007-08-08 14:47 2 ----a-w C:\Documents and Settings\Admin\filter.dat
2007-03-31 15:20 868 --sha-w C:\WINDOWS\system32\regnessem_nsm.dat
.
((((((((((((((((((((((((((((( snapshot@2007-11-19_19.20.36.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2003-12-31 22:58:00 33,792 ----a-w C:\WINDOWS\system32\CMDLGDE.DLL
+ 2003-12-31 22:58:00 35,328 ----a-w C:\WINDOWS\system32\DBGRDDE.DLL
+ 2003-12-31 22:58:00 32,768 ----a-w C:\WINDOWS\system32\DBLSTDE.DLL
+ 2005-02-08 18:51:32 69,632 ----a-w C:\WINDOWS\system32\EIrDaComm.dll
+ 2003-12-31 22:58:00 42,496 ----a-w C:\WINDOWS\system32\FLXGDDE.DLL
+ 2003-12-31 22:58:00 26,896 ----a-w C:\WINDOWS\system32\hh.exe
+ 2001-05-24 09:20:38 544,256 ----a-w C:\WINDOWS\system32\janGraphics.dll
+ 2003-12-31 22:58:00 34,816 ----a-w C:\WINDOWS\system32\MCIDE.DLL
+ 2003-12-31 22:58:00 64,512 ----a-w C:\WINDOWS\system32\MSCC2DE.DLL
+ 2003-12-31 22:58:00 158,208 ----a-w C:\WINDOWS\system32\MSCMCDE.DLL
+ 2003-12-31 22:58:00 14,336 ----a-w C:\WINDOWS\system32\MSCOMDE.DLL
- 1997-03-18 22:00:00 134,416 ------w C:\WINDOWS\system32\MSJINT35.DLL
+ 2003-12-31 22:58:00 148,240 ----a-w C:\WINDOWS\system32\MSJINT35.DLL
- 1997-03-18 22:00:00 24,336 ------w C:\WINDOWS\system32\MSJTER35.DLL
+ 2003-12-31 22:58:00 24,848 ----a-w C:\WINDOWS\system32\MSJTER35.DLL
- 1997-03-18 22:00:00 251,664 ----a-w C:\WINDOWS\system32\MSRD2X35.DLL
+ 2003-12-31 22:58:00 252,176 ----a-w C:\WINDOWS\system32\MSRD2X35.DLL
+ 2003-12-31 22:58:00 36,352 ----a-w C:\WINDOWS\system32\RCHTXDE.DLL
+ 2003-12-31 22:58:00 28,672 ----a-w C:\WINDOWS\system32\SmartMenuXP.dll
+ 2001-04-27 13:11:00 24,576 ----a-w C:\WINDOWS\system32\SmartSubClass.dll
+ 2003-12-31 22:58:00 89,360 ----a-w C:\WINDOWS\system32\VB5DB.DLL
+ 2003-12-31 22:58:00 125,712 ----a-w C:\WINDOWS\system32\VB6DE.DLL
- 2007-11-27 15:01:13 6,896,533 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware.dat
+ 2007-12-06 15:02:12 7,060,547 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware.dat
+ 2007-12-07 15:58:45 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_1f0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:44]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-08 23:02]
"Lexmark 1200 Series"="C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" [2006-07-13 06:33]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-03 23:44 C:\WINDOWS\system32\rundll32.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:44]
C:\Documents and Settings\Admin\Menu Start\Programy\Autostart\
Ratlerek.lnk - C:\WINDOWS\RTHDCPL.exe [2006-11-08 22:51:22]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
2005-08-09 13:28 1961984 --------- C:\Program Files\Ahead\Nero BackItUp\NBJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.8472\GoogleToolbarNotifier.exe
R1 drwebnet;SpIDer Guard boot hook driver for Windows NT;C:\WINDOWS\system32\drivers\drwebnet.sys
R2 Vcs;Vcs support;\??\C:\WINDOWS\system32\Drivers\Vcs.sys
S2 SPIDER;SpIDer FS Monitor for Windows NT;\??\C:\Program Files\DrWeb\spider.sys
S3 C-Dilla;C-Dilla;\??\C:\WINDOWS\system32\drivers\CDANT.SYS
S3 ddsxeiservice;ddsxeiservice2;\??\C:\Program Files\sXe Injected\ddsxei.sys
S3 GVCplDrv;GVCplDrv;C:\WINDOWS\system32\drivers\GVCplDrv.sys
S3 PID_0920;Logitech QuickCam Express(PID_0920);C:\WINDOWS\system32\DRIVERS\LV532AV.SYS
S3 RivaTuner32;RivaTuner32;\??\e:\Program Files\RivaTuner v2.01\RivaTuner32.sys
S4 spidernt;SpIDer Guard for Windows NT;C:\Program Files\DrWeb\SpiderNT.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-05 19:48:42
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\poof]
.
Completion time: 2007-12-05 19:50:39
C:\ComboFix-quarantined-files.txt ... 2007-09-11 15:19
C:\ComboFix2.txt ... 2007-11-19 19:21
C:\ComboFix3.txt ... 2007-11-02 09:18
.
--- E O F ---
]Kiedy
S2 SPIDER;SpIDer FS Monitor for Windows NT;\??\C:\Program Files\DrWeb\spider.sys
dj_disc napisał(a):JESCZE NIE POKAZUJE ANIMACJI GIF I SKRYPTÓW JAVA!!!!
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 28 gości