Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.

HiackThis - Log fajl... pomoc!

[es] :: Zaštita :: HiackThis - Log fajl... pomoc!

[ Pregleda: 1541 | Odgovora: 7 ] > FB > Twit

Postavi temu Odgovori

Autor

Pretraga teme: Traži
Markiranje Štampanje RSS

zemunac83

Član broj: 118525
Poruke: 7
*.187.eunet.yu.



Profil

icon HiackThis - Log fajl... pomoc!13.11.2006. u 00:58 - pre 213 meseci
Bio bih izuzetno zahvalan ako mi neko moze pomoci oko HijackThis log fajla! Unapred zahvalan!


Logfile of HijackThis v1.99.1
Scan saved at 1:43:41, on 13.11.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ATKKBService.exe
C:\Program Files\TECOM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Raxco\PerfectDisk\PDSched.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Marina\Local Settings\Temp\autoruns.exe
C:\Documents and Settings\Marina\Local Settings\Temp\procexp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Marina\Local Settings\Temp\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/sear...ZVu8ccHJvpz3t6hUcs5mSv1JHXMA56
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\smax4.exe" /tray
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\TECOM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\TECOM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\TECOM\Bluetooth Software\btsendto_ie.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{F9BC14C8-C198-487F-905F-142B581120A5}: NameServer = 194.247.192.33 194.247.192.1
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\TECOM\Bluetooth Software\bin\btwdins.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe

 
Odgovor na temu

Jbyn4e

Član broj: 422
Poruke: 6049
*.ptt.yu.



+257 Profil

icon Re: HiackThis - Log fajl... pomoc!13.11.2006. u 09:48 - pre 213 meseci
To ti je HjackThis! log fajl na Windows XP SP2 . Jel dovoljno pomoci? &:)

Sta te KONKRETNO zanima, tj. oko cega ti je potrebna pomoc? Ovako nema smisla to sto si pitao...



Kad sve ostalo zakaže, pročitaj uputstvo...
 
Odgovor na temu

nicr

Član broj: 47862
Poruke: 577
*.teol.net.



Profil

icon Re: HiackThis - Log fajl... pomoc!13.11.2006. u 10:29 - pre 213 meseci

Valjda ga zanima, sta moze(treba) bisati... Ja nevidim razloge za neku brigu,...mada bi ja pola toga pobrisao. Ma preventive radi.


 
Odgovor na temu

zemunac83

Član broj: 118525
Poruke: 7
*.86.eunet.yu.



Profil

icon Re: HiackThis - Log fajl... pomoc!13.11.2006. u 13:04 - pre 213 meseci
Da, zanima me sta treba da brisem!
A takodje, nasao sam na nekim opisima procesa da sui ova dva trojanci:
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe

Al ne mogu nikako da oh obrisem.


 
Odgovor na temu

Jbyn4e

Član broj: 422
Poruke: 6049
*.ptt.yu.



+257 Profil

icon Re: HiackThis - Log fajl... pomoc!13.11.2006. u 13:17 - pre 213 meseci
Ti su MOZDA virusi (ima neki koji zamene ove fajlove), ali su generalno:
Citat:

Process File: ctfmon or ctfmon.exe
Process Name: Alternative User Input Services

Description:
ctfmon.exe is a process belonging to Microsoft Office Suite. It activates the Alternative User Input Text Input Processor (TIP) and the
Microsoft Office XP Language Bar. This program is a non-essential system process, but should not be terminated unless suspected to be causing problems.

(sa http://www.liutilities.com/pro...askspro/processlibrary/ctfmon/)
i
Citat:

Process File: msnmsgr.exe
Process Name: MSN Messenger
Description: msnmsgr.exe is the main executable for MSN Messenger, which is bundled with Windows and Microsoft Office. It provides online chat, an file sharing capabilities.

(sa http://www.liutilities.com/pro...skspro/processlibrary/msnmsgr/)

Ja bih se vise brinuo oko ovoga:
Citat:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/sear...ZVu8ccHJvpz3t6hUcs5mSv1JHXMA56

i onih yahoo toolbar-a i slicno...

Medju ostalim procesima je generalno visak par komada koji ne moraju da rade non stop...

Kad sve ostalo zakaže, pročitaj uputstvo...
 
Odgovor na temu

zemunac83

Član broj: 118525
Poruke: 7
*.86.eunet.yu.



Profil

icon Re: HiackThis - Log fajl... pomoc!13.11.2006. u 14:06 - pre 213 meseci
A mene zanima kako da trajno blokiram neke od tih procesa.
Jer ja ih obrisem, ali se oni svaki put ponovo pojave, iako mi je system restore iskljucen.
Probao sam i sa Autorunsom i sa Process Explorerom al se uvek vrate
 
Odgovor na temu

aco murija

Član broj: 112932
Poruke: 89
*.dynamic.sbb.co.yu.



Profil

icon Re: HiackThis - Log fajl... pomoc!13.11.2006. u 14:37 - pre 213 meseci
Idesh:
Start/Run/ ukucash >msconfig< pa u Services zatvorish ono shto volesh al da znaesh shta je sta - podrazumeva se.
Istina je da neke greshke ako napravis mož i da ispravish al neki put kada zabrljash mora iz Safe - moda...
 
Odgovor na temu

zemunac83

Član broj: 118525
Poruke: 7
*.70.eunet.yu.



Profil

icon Re: HiackThis - Log fajl... pomoc!13.11.2006. u 23:16 - pre 212 meseci
Probao sam i tako... i odcekirao sam sve fajlove koje ne zelim... ali mi se pojedini uvek vracaju!
 
Odgovor na temu

[es] :: Zaštita :: HiackThis - Log fajl... pomoc!

[ Pregleda: 1541 | Odgovora: 7 ] > FB > Twit

Postavi temu Odgovori

Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.