27.12.2006, 18:28
czesc wszystkim dzisiaj zaprezentuje moj nowu produkt (to nie reklama pamersów) przejde do rzeczy cos mi sie dzieje z gg albo z mojim netem:shock:jak do kogos pisze to nie odpowiada a jeszcze przedwczoraj reinstalowałęm gg:?i czyszciłem rejestr Jv16tools
z tego co pamietamto wchodziłem na taki link cos w tym stylu hsqvyrpzeh.info
jak narazie poprubuje poskanować jakimis skanerami online.
wrzuce loga z Hijacka :
Tutaj z silenta :
dodam jeszcze ze nawet infobot mi nie odpowiada w gg:oops:a i jeszcze muli mi okropnie firefox ale to moze z powodu małej ilosci ram dlatego urzywam IE ;/ ale w link wchodziłem firefoxem ;]dodatkowe informacje dotyczace tego linku (hsqvyrpzeh.info/?ifccab.jpg nie wbijac nawet jak wyśle komuś...)- to ma ustawiona jedna osoba u mnie na gg jako opis ?? lecz jest właśnie problem w tym ze do niego niemoge napsać poprostu niedocierają wiadomosci.
z góry dzieki
z tego co pamietamto wchodziłem na taki link cos w tym stylu hsqvyrpzeh.info
jak narazie poprubuje poskanować jakimis skanerami online.
wrzuce loga z Hijacka :
Cytat: Logfile of HijackThis v1.99.1
Scan saved at 17:45:29, on 2006-12-27
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32atievxx.exe
Crogram FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
Crogram FilesLClockLClock.exe
C:WINDOWSsystem32ctfmon.exe
C:WINDOWSsystem32wscntfy.exe
Crogram FilesWinampwinamp.exe
Crogram FilesGadu-Gadugg.exe
Crogram FilesWinRARWinRAR.exe
COCUME~1KompUSTAWI~1TempRar$EX01.184HijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =[Aby zobaczyć linki, zarejestruj się tutaj]
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Ĺącza
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - Crogram FilesFlashGetJccatch.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - Crogram FilesBitComettoolsBitCometBHO.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - CROGRA~1MEGAUP~1MEGAUP~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - Crogram FilesJavajre1.5.0_09binssv.dll
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - Crogram FilesFlashGetgetflash.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - CROGRA~1MEGAUP~1MEGAUP~1.DLL
O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - Crogram FilesFlashGetfgiebar.dll
O4 - HKLM..Run: [LClock]Crogram FilesLClockLClock.exe
O4 - HKCU..Run: [ctfmon.exe]C:WINDOWSsystem32ctfmon.exe
O8 - Extra context menu item: &Ĺciągnij przy pomocy FlashGet''a - Crogram FilesFlashGetjc_link.htm
O8 - Extra context menu item: &Ĺciągnij wszystko przy pomocy FlashGet''a - Crogram FilesFlashGetjc_all.htm
O8 - Extra context menu item: Download all links using BitComet -[Aby zobaczyć linki, zarejestruj się tutaj]
FilesBitCometBitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet -[Aby zobaczyć linki, zarejestruj się tutaj]
FilesBitCometBitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet -[Aby zobaczyć linki, zarejestruj się tutaj]
FilesBitCometBitComet.exe/AddLink.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel -[Aby zobaczyć linki, zarejestruj się tutaj]
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Crogram FilesJavajre1.5.0_09binssv.dll
O9 - Extra ''Tools'' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Crogram FilesJavajre1.5.0_09binssv.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - CROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - CROGRA~1FlashGetflashget.exe
O9 - Extra ''Tools'' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - CROGRA~1FlashGetflashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Crogram FilesMessengermsmsgs.exe
O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Crogram FilesMessengermsmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -[Aby zobaczyć linki, zarejestruj się tutaj]
O17 - HKLMSystemCCSServicesTcpip..{DB45CA7F-A440-41A7-AB08-7D3E6A11CE6D}: NameServer = 194.204.152.34,194.204.159.1
Tutaj z silenta :
Cytat: "Silent Runners.vbs", revision 46,[Aby zobaczyć linki, zarejestruj się tutaj]
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCUSOFTWAREMicrosoftWindowsCurrentVersionRun {++}
"ctfmon.exe" = "C:WINDOWSsystem32ctfmon.exe" [MS]
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun {++}
"LClock" = "Crogram FilesLClockLClock.exe" [null data]
HKLMSoftwareMicrosoftActive SetupInstalled Components
>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}(Default) = "Outlook Express"
StubPath = "C:WINDOWSsystem32shmgrate.exe OCInstallUserConfigOE" [MS]
HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}(Default) = (no title provided)
-> {HKLM...CLSID} = "IeCatch5 Class"
InProcServer32(Default) = "Crogram FilesFlashGetJccatch.dll" ["FlashGet"]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}(Default) = "BitComet ClickCapture"
-> {HKLM...CLSID} = "BitComet Helper"
InProcServer32(Default) = "Crogram FilesBitComettoolsBitCometBHO.dll" ["BitComet"]
{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}(Default) = (no title provided)
-> {HKLM...CLSID} = "Megaupload Toolbar"
InProcServer32(Default) = "CROGRA~1MEGAUP~1MEGAUP~1.DLL" ["MegaUpload"]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}(Default) = (no title provided)
-> {HKLM...CLSID} = "SSVHelper Class"
InProcServer32(Default) = "Crogram FilesJavajre1.5.0_09binssv.dll" ["Sun Microsystems, Inc."]
{F156768E-81EF-470C-9057-481BA8380DBA}(Default) = (no title provided)
-> {HKLM...CLSID} = "gFlash Class"
InProcServer32(Default) = "Crogram FilesFlashGetgetflash.dll" [empty string]
HKLMSoftwareMicrosoftWindowsCurrentVersionShell ExtensionsApproved
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
-> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
InProcServer32(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
InProcServer32(Default) = "C:WINDOWSsystem32hticons.dll" ["Hilgraeve, Inc."]
"{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler"
-> {HKLM...CLSID} = "Microsoft Office Outlook"
InProcServer32(Default) = "CROGRA~1MICROS~2OFFICE11MLSHEXT.DLL" [MS]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler"
-> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook"
InProcServer32(Default) = "CROGRA~1MICROS~2OFFICE11OLKFSTUB.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "Crogram FilesMicrosoft OfficeOFFICE11msohev.dll" [MS]
"{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
-> {HKLM...CLSID} = "Portable Media Devices"
InProcServer32(Default) = "C:WINDOWSsystem32Audiodev.dll" [MS]
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
-> {HKLM...CLSID} = "Portable Media Devices Menu"
InProcServer32(Default) = "C:WINDOWSsystem32Audiodev.dll" [MS]
"{21569614-B795-46b1-85F4-E737A8DC09AD}" = "Shell Search Band"
-> {HKLM...CLSID} = "Shell Search Band"
InProcServer32(Default) = "C:WINDOWSsystem32browseui.dll" [MS]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "Crogram FilesWinRARrarext.dll" [null data]
HKLMSoftwareClassesPROTOCOLSFilter
INFECTION WARNING! text/xmlCLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"
-> {HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "Crogram FilesCommon FilesMicrosoft SharedOFFICE11MSOXMLMF.DLL" [MS]
HKLMSoftwareClasses*shellexContextMenuHandlers
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "Crogram FilesWinRARrarext.dll" [null data]
HKLMSoftwareClassesDirectoryshellexContextMenuHandlers
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "Crogram FilesWinRARrarext.dll" [null data]
HKLMSoftwareClassesFoldershellexContextMenuHandlers
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "Crogram FilesWinRARrarext.dll" [null data]
Active Desktop and Wallpaper:
-----------------------------
Active Desktop is disabled at this entry:
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShellState
HKCUControl PanelDesktop
"Wallpaper" = "Cocuments and SettingsKompUstawienia lokalneDane aplikacjiMicrosoftWallpaper1.bmp"
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLMSystemCurrentControlSetServicesWinsock2ParametersNameSpace_Catalog5Catalog_Entries {++}
000000000001LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]
000000000002LibraryPath = "%SystemRoot%System32winrnr.dll" [MS]
000000000003LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]
Transport Service Providers
HKLMSystemCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_Entries {++}
0000000000##PackedCatalogItem (contains) DLL [Company Name] , (at) ## range:
%SystemRoot%system32mswsock.dll [MS] , 01 - 04, 07 - 14
%SystemRoot%system32rsvpsp.dll [MS] , 05 - 06
Toolbars, Explorer Bars, Extensions:
------------------------------------
Toolbars
HKCUSoftwareMicrosoftInternet ExplorerToolbarWebBrowser
"{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}"
-> {HKLM...CLSID} = "Megaupload Toolbar"
InProcServer32(Default) = "CROGRA~1MEGAUP~1MEGAUP~1.DLL" ["MegaUpload"]
HKLMSoftwareMicrosoftInternet ExplorerToolbar
"{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}" = (no title provided)
-> {HKLM...CLSID} = "Megaupload Toolbar"
InProcServer32(Default) = "CROGRA~1MEGAUP~1MEGAUP~1.DLL" ["MegaUpload"]
"{E0E899AB-F487-11D5-8D29-0050BA6940E3}" = "FlashGet"
-> {HKLM...CLSID} = "FlashGet"
InProcServer32(Default) = "Crogram FilesFlashGetfgiebar.dll" ["Amaze Soft"]
Extensions (Tools menu items, main toolbar menu buttons)
HKLMSoftwareMicrosoftInternet ExplorerExtensions
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}"
-> {HKCU...CLSID} = "Java Plug-in 1.5.0_09"
InProcServer32(Default) = "Crogram FilesJavajre1.5.0_09binssv.dll" ["Sun Microsystems, Inc."]
-> {HKLM...CLSID} = "Java Plug-in 1.5.0_09"
InProcServer32(Default) = "Crogram FilesJavajre1.5.0_09binnpjpi150_09.dll" ["Sun Microsystems, Inc."]
{92780B25-18CC-41C8-B9BE-3C9C571A8263}
"ButtonText" = "Badanie"
{D6E814A0-E0C5-11D4-8D29-0050BA6940E3}
"ButtonText" = "FlashGet"
"MenuText" = "FlashGet"
"Exec" = "CROGRA~1FlashGetflashget.exe" ["FlashGet.com"]
{FB5F1910-F110-11D2-BB9E-00C04F795683}
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "Crogram FilesMessengermsmsgs.exe" [MS]
Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------
Ati HotKey Poller, Ati HotKey Poller, "C:WINDOWSsystem32atievxx.exe" [MS]
Machine Debug Manager, MDM, ""Crogram FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE"" [MS]
Windows User Mode Driver Framework, UMWdf, "C:WINDOWSsystem32wdfmgr.exe" [MS]
Print Monitors:
---------------
HKLMSystemCurrentControlSetControlPrintMonitors
Microsoft Document Imaging Writer MonitorDriver = "mdimon.dll" [MS]
----------
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points and all Registry CLSIDs for dormant Explorer Bars,
use the -supp parameter or answer "No" at the first message box.
---------- (total run time: 71 seconds, including 5 seconds for message boxes)
dodam jeszcze ze nawet infobot mi nie odpowiada w gg:oops:a i jeszcze muli mi okropnie firefox ale to moze z powodu małej ilosci ram dlatego urzywam IE ;/ ale w link wchodziłem firefoxem ;]dodatkowe informacje dotyczace tego linku (hsqvyrpzeh.info/?ifccab.jpg nie wbijac nawet jak wyśle komuś...)- to ma ustawiona jedna osoba u mnie na gg jako opis ?? lecz jest właśnie problem w tym ze do niego niemoge napsać poprostu niedocierają wiadomosci.
z góry dzieki