Forumi
Home Pravila i pomoć Članovi Kalendar Današnji postovi


Povratak   PC Ekspert Forum > Računala > Problemi > Softverski problemi
Ime
Lozinka

Odgovori
 
Uređivanje
Staro 09.05.2005., 16:22   #1
acer
Whatever :)
Moj komp
 
acer's Avatar
 
Datum registracije: Nov 2002
Lokacija: Rijeka,Bulevard
Postovi: 1,751
Dekstop Hijacker

Imam jedan problem u firmi.Na jednom kompu ne mogu promijenit wallpaper.
U atachmentu je slika poruke.
Imali netko ideju kako to ukloniti?
Evo i HijackThis loga:

Logfile of HijackThis v1.99.1
Scan saved at 16:29:11, on 09/05/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\msdtc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Billionton\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\mqsvc.exe
C:\WINDOWS\System32\CCM\CcmExec.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\system32\proquota.exe
C:\WINDOWS\System32\mqtgsvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\taskswitch.exe
C:\WINDOWS\System32\bthcli.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\System32\baseman.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Billionton\Bluetooth Software\BTTray.exe
C:\Program Files\WordWeb\wweb32.exe
C:\PROGRA~1\BILLIO~1\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\ScreenPrint32 v3\ScreenPrint32.exe
E:\hijackthis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://bacheca
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://bacheca
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://bacheca
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe
O4 - HKLM\..\Run: [7stj3nO] bthcli.exe
O4 - HKLM\..\Run: [Disk Keeper] C:\WINDOWS\System32\Services\{5595B9AC-1AA3-4E11-9914-7441D4C14217}\SECURITY.EXE
O4 - HKLM\..\Run: [ScreenPrint32] C:\Program Files\ScreenPrint32 v3\ScreenPrint32.exe -startup
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [MB2tRhi2R] baseman.exe
O4 - HKCU\..\Run: [SpywareNo] C:\Program Files\SpywareNo\SpywareNo.exe
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: AutoCAD LT Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: BTTray.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O14 - IERESET.INF: START_PAGE_URL=http://bacheca
O15 - Trusted Zone: http://collaboration.saipem.pri
O15 - Trusted Zone: http://ibis.saipem.pri
O15 - Trusted Zone: http://rikm.saipem.pri
O15 - Trusted Zone: http://sharepoint.saipem.pri
O15 - Trusted Zone: http://weld.saipem.pri
O15 - Trusted Zone: http://collaboration.saipem.pri (HKLM)
O15 - Trusted Zone: http://ibis.saipem.pri (HKLM)
O15 - Trusted Zone: http://rikm.saipem.pri (HKLM)
O15 - Trusted Zone: http://sharepoint.saipem.pri (HKLM)
O15 - Trusted Zone: http://weld.saipem.pri (HKLM)
O15 - Trusted IP range: http://10.150.101.20
O15 - Trusted IP range: http://10.150.101.20 (HKLM)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1093695268544
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = saipem.pri
O17 - HKLM\Software\..\Telephony: DomainName = saipem.pri
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = saipem.pri
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bluetooth Service (btwdins) - Unknown owner - C:\Program Files\Billionton\Bluetooth Software\bin\btwdins.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
__________________



GIGABYTE B450 AORUS PRO
Fractal Design Define XL R2
Chieftec A-80, CTG-750C, 750W
AMD Ryzen 5 3600
Be Quiet Dark Rock Pro 4
Asus Nvidia GTX 1060 OC Edition, 3GB
Avermedia Live Gamer HD Lite
GEIL Evo Spear AMD GASB416GB3200C16ADC, DDR4 3200MHz, kit 2x8GB
Kingston NVMe M.2, 1TB
LG BH16NS55 Bluray writer
LG GGW-H20L Bluray writer
27" Philips
Brother HL-2240
Das Keyboard 4 Professional, MX brown
Logitech mouse G402
Scanner HP Photosmart G3010
Cambridge Audio DacMagic 100
Scythe SDAR-2100 + Scythe Kro Craft Speaker SCBKS-1000
Windows 10 PRO x64




Zadnje izmijenjeno od: acer. 21.02.2006. u 13:43.
acer je offline   Reply With Quote
Staro 12.05.2005., 19:52   #2
Costa
Moderator
 
Costa's Avatar
 
Datum registracije: Aug 2003
Lokacija: Zagreb
Postovi: 3,193
Kod tebe mi je malo bed jer je racunalo od firme pa ne znam za ove trusted stvari da li je to admin postavio i da li je tko korisno uopce?
Uglanom budi oprezan, BTW hijackthis po defaultu radi backup tako da sve sto sredis mozes i vratiti.

Izgasi:
C:\WINDOWS\system32\proquota.exe
C:\WINDOWS\System32\bthcli.exe
C:\WINDOWS\System32\baseman.exe

Evo sto je meni sumnjivo:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://bacheca
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://bacheca
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://bacheca
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [7stj3nO] bthcli.exe
O4 - HKLM\..\Run: [Disk Keeper] C:\WINDOWS\System32\Services\{5595B9AC-1AA3-4E11-9914-7441D4C14217}\SECURITY.EXE
O4 - HKCU\..\Run: [MB2tRhi2R] baseman.exe
O4 - HKCU\..\Run: [SpywareNo] C:\Program Files\SpywareNo\SpywareNo.exe
O4 - Global Startup: BTTray.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O14 - IERESET.INF: START_PAGE_URL=http://bacheca
O15 - Trusted Zone: http://collaboration.saipem.pri
O15 - Trusted Zone: http://ibis.saipem.pri
O15 - Trusted Zone: http://rikm.saipem.pri
O15 - Trusted Zone: http://sharepoint.saipem.pri
O15 - Trusted Zone: http://weld.saipem.pri
O15 - Trusted Zone: http://collaboration.saipem.pri (HKLM)
O15 - Trusted Zone: http://ibis.saipem.pri (HKLM)
O15 - Trusted Zone: http://rikm.saipem.pri (HKLM)
O15 - Trusted Zone: http://sharepoint.saipem.pri (HKLM)
O15 - Trusted Zone: http://weld.saipem.pri (HKLM)
O15 - Trusted IP range: http://10.150.101.20
O15 - Trusted IP range: http://10.150.101.20 (HKLM)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = saipem.pri
O17 - HKLM\Software\..\Telephony: DomainName = saipem.pri
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = saipem.pri
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
Costa je offline   Reply With Quote
Oglasni prostor
Oglas
 
Oglas
Staro 13.05.2005., 09:12   #3
acer
Whatever :)
Moj komp
 
acer's Avatar
 
Datum registracije: Nov 2002
Lokacija: Rijeka,Bulevard
Postovi: 1,751
Uspio sam riješiti,morao sam nešto izbrisati u registriju i sad je ok
__________________



GIGABYTE B450 AORUS PRO
Fractal Design Define XL R2
Chieftec A-80, CTG-750C, 750W
AMD Ryzen 5 3600
Be Quiet Dark Rock Pro 4
Asus Nvidia GTX 1060 OC Edition, 3GB
Avermedia Live Gamer HD Lite
GEIL Evo Spear AMD GASB416GB3200C16ADC, DDR4 3200MHz, kit 2x8GB
Kingston NVMe M.2, 1TB
LG BH16NS55 Bluray writer
LG GGW-H20L Bluray writer
27" Philips
Brother HL-2240
Das Keyboard 4 Professional, MX brown
Logitech mouse G402
Scanner HP Photosmart G3010
Cambridge Audio DacMagic 100
Scythe SDAR-2100 + Scythe Kro Craft Speaker SCBKS-1000
Windows 10 PRO x64



acer je offline   Reply With Quote
Staro 02.06.2005., 19:18   #4
spawn
Premium
Moj komp
 
spawn's Avatar
 
Datum registracije: Aug 2004
Lokacija: Istra
Postovi: 8,379
A sta si to izbrisao u registriju? I meni se desilo slicno....
Hvala
spawn je offline   Reply With Quote
Staro 02.06.2005., 19:29   #5
acer
Whatever :)
Moj komp
 
acer's Avatar
 
Datum registracije: Nov 2002
Lokacija: Rijeka,Bulevard
Postovi: 1,751
E sad da me ubiješ ne mogu se sjetiti.
Potraži u registriju poruku koja ti je na ekranu,pa probaj izbrisati.
__________________



GIGABYTE B450 AORUS PRO
Fractal Design Define XL R2
Chieftec A-80, CTG-750C, 750W
AMD Ryzen 5 3600
Be Quiet Dark Rock Pro 4
Asus Nvidia GTX 1060 OC Edition, 3GB
Avermedia Live Gamer HD Lite
GEIL Evo Spear AMD GASB416GB3200C16ADC, DDR4 3200MHz, kit 2x8GB
Kingston NVMe M.2, 1TB
LG BH16NS55 Bluray writer
LG GGW-H20L Bluray writer
27" Philips
Brother HL-2240
Das Keyboard 4 Professional, MX brown
Logitech mouse G402
Scanner HP Photosmart G3010
Cambridge Audio DacMagic 100
Scythe SDAR-2100 + Scythe Kro Craft Speaker SCBKS-1000
Windows 10 PRO x64



acer je offline   Reply With Quote
Oglasni prostor
Oglas
 
Oglas
Odgovori



Pravila postanja
Vi ne možete otvarati nove teme
Vi ne možete pisati odgovore
Vi ne možete uploadati priloge
Vi ne možete uređivati svoje poruke

BB code je Uključeno
Smajlići su Uključeno
[IMG] kod je Uključeno
HTML je Isključeno

Idi na