Zwracam sie z uprzejmą prośbą o pomoc bo sam nie jestem w stanie sobie poradzić.
1. Zadomowił się u mnie Win32:Trojan-gen. {Other} i co kilka minut avast o tym komunikuje - usunięcie nic nie daje. Umiejscawia sie w róznych plikach, ostatnio w C:\WINDOWS\swuzz.dll.
2. W ostatnim czasie komputer bardzo "spowolniał" ok. 10-krotnie, szczególnie podczas ściągania plików.
To te najbardziej uprzykrzające niedogodności, z innymi może uda mi się żyć.
Ponieważ jestem mocno zaawansowany wiekowo i język czy też slang komputerowy jest mi obcy, uprzejmie proszę o przedstawienie sposobu postepowania w formie dla przedszkolaków (łopatologicznie).
Z góry serdecznie dziękuję za każda udzieloną formę pomocy.
Poniżej przedstawiam swój log, bo pewnie będzie niezbędny.
- Kod: Zaznacz wszystko
Logfile of HijackThis v1.99.1
Scan saved at 10:48:42, on 2006-02-10
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\appsr.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\setrysvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\semwltry.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Sony Ericsson\Wireless Manager\GCXXManager.exe
C:\WINDOWS\system32\sdkyy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\Abc\USTAWI~1\Temp\Katalog tymczasowy 5 dla hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\swuzz.dll/sp.html#21044%resultposition.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\swuzz.dll/sp.html#21044%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\swuzz.dll/sp.html#21044%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\swuzz.dll/sp.html#21044%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\swuzz.dll/sp.html#21044%resultposition.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\swuzz.dll/sp.html#21044%resultposition.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\swuzz.dll/sp.html#21044%resultposition.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2EE72B4F-E40E-EFB8-15AA-4EB5AE709679} - (no file)
O2 - BHO: (no name) - {43E92535-41C0-42A6-6DD1-EC22B7AA19CC} - (no file)
O2 - BHO: (no name) - {66EF3492-6791-E464-2878-82061A226166} - (no file)
O2 - BHO: (no name) - {7561BD5A-4319-21D1-6A49-CBCE972E06E8} - (no file)
O2 - BHO: (no name) - {882631A5-5AE7-4F3B-DA2D-18C71F0FDF23} - (no file)
O2 - BHO: (no name) - {8C8EAD04-425B-319C-5458-9026C339B635} - (no file)
O2 - BHO: (no name) - {A49D52A9-DE08-47DE-6764-86D278A7683C} - (no file)
O2 - BHO: Class - {B13C0965-868F-283A-5E4E-C1B07A643E7A} - C:\WINDOWS\croj32.dll
O2 - BHO: (no name) - {BEFD1E91-36B1-6755-D849-210CC3AF2625} - (no file)
O2 - BHO: (no name) - {EC236CC0-5AF7-7707-E395-50D819B1C42A} - (no file)
O2 - BHO: (no name) - {F24066EC-902B-5FD0-38BE-FCBA8F762791} - (no file)
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [GCXX-Manager-Class] "C:\Program Files\Sony Ericsson\Wireless Manager\GCXXManager.exe" -startup
O4 - HKLM\..\Run: [winpv32.exe] C:\WINDOWS\winpv32.exe
O4 - HKLM\..\Run: [apibd.exe] C:\WINDOWS\apibd.exe
O4 - HKLM\..\Run: [syswt32.exe] C:\WINDOWS\system32\syswt32.exe
O4 - HKLM\..\Run: [appgi.exe] C:\WINDOWS\system32\appgi.exe
O4 - HKLM\..\Run: [d3cf32.exe] C:\WINDOWS\d3cf32.exe
O4 - HKLM\..\Run: [sysme32.exe] C:\WINDOWS\system32\sysme32.exe
O4 - HKLM\..\Run: [cras32.exe] C:\WINDOWS\system32\cras32.exe
O4 - HKLM\..\Run: [winij.exe] C:\WINDOWS\system32\winij.exe
O4 - HKLM\..\Run: [sdkdx32.exe] C:\WINDOWS\sdkdx32.exe
O4 - HKLM\..\Run: [ntkk32.exe] C:\WINDOWS\system32\ntkk32.exe
O4 - HKLM\..\Run: [sdkyy.exe] C:\WINDOWS\system32\sdkyy.exe
O4 - HKLM\..\Run: [apimc.exe] C:\WINDOWS\apimc.exe
O4 - HKLM\..\Run: [sdkte.exe] C:\WINDOWS\sdkte.exe
O4 - HKLM\..\Run: [mfcil32.exe] C:\WINDOWS\mfcil32.exe
O4 - HKLM\..\Run: [addjx32.exe] C:\WINDOWS\system32\addjx32.exe
O4 - HKLM\..\Run: [iprs32.exe] C:\WINDOWS\system32\iprs32.exe
O4 - HKLM\..\Run: [crjc32.exe] C:\WINDOWS\crjc32.exe
O4 - HKLM\..\Run: [sysrt32.exe] C:\WINDOWS\sysrt32.exe
O4 - HKLM\..\Run: [crst.exe] C:\WINDOWS\system32\crst.exe
O4 - HKLM\..\Run: [javapt.exe] C:\WINDOWS\javapt.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {18506D80-9B80-11D4-82C2-0080C8D7ED4A} (GameDesire Roulette) - http://67.15.101.3/g_bin/pl/roulette_2_0_0_17.cab
O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} (GameDesire Poker Games) - http://67.15.101.3/g_bin/pl/poker_2_0_0_39.cab
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) - http://67.15.101.3/g_bin/pl/billard8_2_0_0_24.cab
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C4} (GameDesire Pool Training) - http://67.15.101.3/g_bin/pl/billardt_2_0_0_23.cab
O23 - Service: Network Security Service ( 11Fßä#·şÄÖ`I) - Unknown owner - C:\WINDOWS\appsr.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Sony Ericsson Wireless LAN Tray Service (setrysvc) - Unknown owner - C:\WINDOWS\System32\setrysvc.exe
O23 - Service: SmartFinder Uninstall (SmartFinder_Uninstall) - Unknown owner - D:\SFUninstaller.exe" service (file missing)