Forumi
Home Pravila i pomoć Članovi Kalendar Današnji postovi


Povratak   PC Ekspert Forum > Računala > Problemi > Softverski problemi
Ime
Lozinka

Odgovori
 
Uređivanje
Staro 14.08.2005., 21:37   #1
MRKONJA
M.U.P.
 
MRKONJA's Avatar
 
Datum registracije: Sep 2004
Lokacija: Zagreb
Postovi: 2,277
Hijack this log

Molim majstora Costu da baci oko.Hvala

Logfile of HijackThis v1.98.0
Scan saved at TRENUTNO JE: 9:38:41 , on 14.8.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp WinStyler\WinStylerThemeSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE
C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\Fast.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\AVENGINE.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\pavProxy.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\OUTLAWZ\Desktop\HijackThis\HijackThis.exe

F0 - system.ini: Shell=
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [BackgroundSwitcher] C:\WINDOWS\system32\bgswitch.exe
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Antivirus Platinum\Inicio.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{69984F47-1F22-43F7-A5ED-0119BA323A3E}: NameServer = 195.29.150.3 195.29.150.4
__________________



Abit AX8 VIA k8t890//Venice 3000@2250//1x1gb PQI//POV 7600gs silent//Seagate 7200.10 250gb(16mb//sata)//Hitachi 7k160 120gb@mobile kučište//Seagate 7200.7 200gb
//Samsung SH-w163A//Seasonic S-12 380w//Sharkoon silvation



MRKONJA je offline   Reply With Quote
Staro 14.08.2005., 23:44   #2
Costa
Moderator
 
Costa's Avatar
 
Datum registracije: Aug 2003
Lokacija: Zagreb
Postovi: 3,193
Sve ti je u redu.
Costa je offline   Reply With Quote
Oglasni prostor
Oglas
 
Oglas
Staro 14.08.2005., 23:49   #3
MRKONJA
M.U.P.
 
MRKONJA's Avatar
 
Datum registracije: Sep 2004
Lokacija: Zagreb
Postovi: 2,277
Al spybot mi pronalazi navexcel websearch i kad ga makne nakon restarta je opet tamo.
__________________



Abit AX8 VIA k8t890//Venice 3000@2250//1x1gb PQI//POV 7600gs silent//Seagate 7200.10 250gb(16mb//sata)//Hitachi 7k160 120gb@mobile kučište//Seagate 7200.7 200gb
//Samsung SH-w163A//Seasonic S-12 380w//Sharkoon silvation



MRKONJA je offline   Reply With Quote
Staro 15.08.2005., 00:02   #4
Costa
Moderator
 
Costa's Avatar
 
Datum registracije: Aug 2003
Lokacija: Zagreb
Postovi: 3,193
Koje fileove ti izlista kao zarazene?

Ovdje imaju upute za rucno uklanjanje:
http://www.scanspyware.net/info/NavExcel.htm

Daj napravi scan zadnjom verzijom HijackThisa:
http://www.merijn.org/files/hijackthis.zip
Costa je offline   Reply With Quote
Staro 15.08.2005., 00:06   #5
MRKONJA
M.U.P.
 
MRKONJA's Avatar
 
Datum registracije: Sep 2004
Lokacija: Zagreb
Postovi: 2,277
Izlista samo navexcel websearch.
Update je napravljen prije pola sata.
ogfile of HijackThis v1.99.1
Scan saved at TRENUTNO JE: 12:08:42 , on 15.8.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp WinStyler\WinStylerThemeSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE
C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\AVENGINE.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\Fast.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\pavProxy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\PowerArchiver\POWERARC.EXE
C:\DOCUME~1\OUTLAWZ\LOCALS~1\Temp\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [BackgroundSwitcher] C:\WINDOWS\system32\bgswitch.exe
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Antivirus Platinum\Inicio.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{69984F47-1F22-43F7-A5ED-0119BA323A3E}: NameServer = 195.29.150.3 195.29.150.4
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Panda Firewall Service (PAVFIRES) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
O23 - Service: RadClock - Unknown owner - C:\WINDOWS\system32\RadClock.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp WinStyler\WinStylerThemeSvc.exe
__________________



Abit AX8 VIA k8t890//Venice 3000@2250//1x1gb PQI//POV 7600gs silent//Seagate 7200.10 250gb(16mb//sata)//Hitachi 7k160 120gb@mobile kučište//Seagate 7200.7 200gb
//Samsung SH-w163A//Seasonic S-12 380w//Sharkoon silvation



MRKONJA je offline   Reply With Quote
Staro 15.08.2005., 00:16   #6
Costa
Moderator
 
Costa's Avatar
 
Datum registracije: Aug 2003
Lokacija: Zagreb
Postovi: 3,193
S logom je sve u redu. Pogledaj onaj link za rucno uklanjanje pa vidi imas li ista od toga na kompu.
Costa je offline   Reply With Quote
Staro 15.08.2005., 00:30   #7
MRKONJA
M.U.P.
 
MRKONJA's Avatar
 
Datum registracije: Sep 2004
Lokacija: Zagreb
Postovi: 2,277
Nema ništa. Ima samo u add/remove programs i kad ga hoću maknut ništa se ne desi,al ga spybot nakon što je očistio opet nađe:confused:
__________________



Abit AX8 VIA k8t890//Venice 3000@2250//1x1gb PQI//POV 7600gs silent//Seagate 7200.10 250gb(16mb//sata)//Hitachi 7k160 120gb@mobile kučište//Seagate 7200.7 200gb
//Samsung SH-w163A//Seasonic S-12 380w//Sharkoon silvation



MRKONJA je offline   Reply With Quote
Staro 15.08.2005., 08:55   #8
Costa
Moderator
 
Costa's Avatar
 
Datum registracije: Aug 2003
Lokacija: Zagreb
Postovi: 3,193
Probaj ga rucno maknuti iz Add/Remove liste

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Costa je offline   Reply With Quote
Staro 15.08.2005., 14:32   #9
MRKONJA
M.U.P.
 
MRKONJA's Avatar
 
Datum registracije: Sep 2004
Lokacija: Zagreb
Postovi: 2,277
To ga je skroz maknulo. Hvala
__________________



Abit AX8 VIA k8t890//Venice 3000@2250//1x1gb PQI//POV 7600gs silent//Seagate 7200.10 250gb(16mb//sata)//Hitachi 7k160 120gb@mobile kučište//Seagate 7200.7 200gb
//Samsung SH-w163A//Seasonic S-12 380w//Sharkoon silvation



MRKONJA je offline   Reply With Quote
Oglasni prostor
Oglas
 
Oglas
Odgovori



Pravila postanja
Vi ne možete otvarati nove teme
Vi ne možete pisati odgovore
Vi ne možete uploadati priloge
Vi ne možete uređivati svoje poruke

BB code je Uključeno
Smajlići su Uključeno
[IMG] kod je Uključeno
HTML je Isključeno

Idi na