Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112
prosba o sprawdzenie • programosy.pl

  • Ogłoszenie:

prosba o sprawdzenie

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

prosba o sprawdzenie

Postprzez Progressive 18 Kwi 2006, 22:04

reklama
witam, ostatnimy czasy zauwazylem ze komputer wolniej dziala, czesto sie zawiesza/zacina z tego wlasnie powodu prosze o sprawdzenie loga z ewido

Kod: Zaznacz wszystko
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on:         20:40:33, 2006-04-18
+ Report-Checksum:      CDE5EE64

+ Scan result:

   HKU\S-1-5-21-1085031214-507921405-1060284298-1003\Software\IST -> Adware.ISTBar : Cleaned with backup
   C:\Documents and Settings\VinceNT\Cookies\vincent@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
   C:\Documents and Settings\VinceNT\Cookies\vincent@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
   :mozilla.38:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
   :mozilla.51:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
   :mozilla.52:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
   :mozilla.55:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
   :mozilla.56:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
   :mozilla.61:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
   :mozilla.62:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
   :mozilla.66:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
   :mozilla.67:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
   :mozilla.69:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
   :mozilla.75:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.cenzura-spam : Cleaned with backup
   :mozilla.76:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup
   :mozilla.77:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup
   :mozilla.84:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
   :mozilla.95:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
   :mozilla.97:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
   :mozilla.98:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
   :mozilla.102:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
   :mozilla.117:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
   :mozilla.122:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
   :mozilla.123:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
   :mozilla.125:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
   :mozilla.127:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
   :mozilla.131:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup
   :mozilla.137:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Adocean : Cleaned with backup
   :mozilla.138:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Adocean : Cleaned with backup
   :mozilla.155:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
   :mozilla.156:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
   :mozilla.157:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
   :mozilla.158:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
   :mozilla.159:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
   :mozilla.165:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
   :mozilla.166:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
   :mozilla.167:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
   :mozilla.168:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
   :mozilla.169:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
   :mozilla.172:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Adocean : Cleaned with backup
   :mozilla.173:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Adocean : Cleaned with backup
   :mozilla.180:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Adocean : Cleaned with backup
   :mozilla.181:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Adocean : Cleaned with backup
   :mozilla.191:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
   :mozilla.192:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
   :mozilla.193:C:\Documents and Settings\VinceNT\Dane aplikacji\Mozilla\Firefox\Profiles\kskkniir.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
   C:\Documents and Settings\VinceNT\Pulpit\Gry\mp3_plugin.exe -> Downloader.IstBar : Cleaned with backup
   :mozilla.27:C:\Documents and Settings\Zybi\Dane aplikacji\Mozilla\Firefox\Profiles\mmp0zhtl.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
   :mozilla.28:C:\Documents and Settings\Zybi\Dane aplikacji\Mozilla\Firefox\Profiles\mmp0zhtl.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
   :mozilla.29:C:\Documents and Settings\Zybi\Dane aplikacji\Mozilla\Firefox\Profiles\mmp0zhtl.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
   :mozilla.33:C:\Documents and Settings\Zybi\Dane aplikacji\Mozilla\Firefox\Profiles\mmp0zhtl.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
   :mozilla.34:C:\Documents and Settings\Zybi\Dane aplikacji\Mozilla\Firefox\Profiles\mmp0zhtl.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
   D:\Pobrane\vba-beta3.zip/mp3_plugin.exe -> Downloader.IstBar : Cleaned with backup


::Report End


/// WIRUS

jeszcze mam pytanko, jaki wirus moze powodowac ze po wylaczeniu sie wygaszacza jak pojawia sie ekran powitalna (przelacza uzytkownika) przy probie logowanie nagle pojawia sie haslo na konto pomimo tego ze nigdy sie go nie zakladalo? po resecie jest ok. wiecie co to za wir/inny syf i jak go usunac?
Ostatnio edytowany przez Progressive, 18 Kwi 2006, 22:07, edytowano w sumie 1 raz
Progressive
~user
 
Posty: 3
Dołączenie: 18 Kwi 2006, 22:01



Postprzez jeff 18 Kwi 2006, 22:05

daj log z hijacka w tagach

http://forum.programosy.pl/hijackthis-gtobsuga-i-umieszczanie-loga-vt9452.html
jeff
 



Postprzez Progressive 18 Kwi 2006, 22:08

Kod: Zaznacz wszystko
Logfile of HijackThis v1.99.1
Scan saved at 20:50:25, on 2006-04-18
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\soundman.exe
C:\Program Files\Winamp\Winampa.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Konnekt\konnekt.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Winamp\winamp.exe
D:\Pobrane\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neostrada.pl
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada TP
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] -C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [Konnekt] "C:\Program Files\Konnekt\konnekt.exe" /autostart
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{52E57114-524A-4DD8-A86C-2E682A8081EB}: NameServer = 194.204.152.34 217.98.63.164
O17 - HKLM\System\CS1\Services\Tcpip\..\{52E57114-524A-4DD8-A86C-2E682A8081EB}: NameServer = 194.204.152.34 217.98.63.164
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - -C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

Progressive
~user
 
Posty: 3
Dołączenie: 18 Kwi 2006, 22:01



Postprzez SER 18 Kwi 2006, 22:43

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm


Wyłączasz Przywracanie Systemu, następnie wchodzisz w tryb awaryjny (F8 ) i usuwasz wpisy, a pogrubione pliki kasujesz ręcznie z dysku ;)
Pozdrawiam, SER :baseball:
Awatar użytkownika
SER
~user
 
Posty: 1665
Dołączenie: 11 Sty 2006, 20:40
Miejscowość: Wciśnij ALT+F4 aby uzyskać szczegółowe informacje ;-)
Pochwały: 204




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 22 gości