Forumi
Home Pravila i pomoć Članovi Kalendar Današnji postovi


Povratak   PC Ekspert Forum > Računala > Problemi > Softverski problemi
Ime
Lozinka

Odgovori
 
Uređivanje
Staro 21.10.2005., 12:18   #1
atha
Moderator
Moj komp
 
atha's Avatar
 
Datum registracije: Jan 2005
Lokacija: Rijeka
Postovi: 9,067
hijack this log for costa

ja sam skinuo ono sto sam mislio da treba, samo me josh zanima sto ti mislis i treba li jos sto rijeshiti.

zahvaljujem costa.

C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\hidserv.exe
C:\Tivoli\lcf\bin\w32-ix86\mrt\LCFD.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\OraTool6\bin\wdblsnr.exe
C:\OraTool6\bin\ifsrv60.exe
C:\OraTool6\bin\ifweb60.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Sophos\Remote Management System\AutoUpdateAgentNT.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\WINNT\RCSERV.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe
C:\WINNT\system32\wm.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\Explorer.EXE
C:\Tivoli\lcf\bin\w32-ix86\mrt\lcfep.exe
C:\WINNT\system32\dpmw32.exe
C:\WINNT\system32\NWTRAY.EXE
C:\WINNT\system32\Smtray.exe
C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Lotus\Notes\nminder.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Lotus\Notes\naldaemn.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Documents and Settings\IgorTom\Desktop\CWShredder.exe
C:\Documents and Settings\IgorTom\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vl2
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://vl2
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://vl2
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://vl2/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://vl2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://vl2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://vl2
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://vl2
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://vl2
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://vl2
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.int.lenac.hr:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = vl2;vl5;172.16;;<local>
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [lcfep] "C:\Tivoli\lcf\bin\w32-ix86\mrt\lcfep.exe"
O4 - HKLM\..\Run: [NDPS] C:\WINNT\system32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [Smapp] Smtray.exe
O4 - HKLM\..\Run: [IMONTRAY] C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [Comparator Fast] "C:\Program Files\Interdesigner Software\Comparator Fast\ComparatorFast.exe" /STARTUP
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Notes Minder.lnk = C:\Lotus\Notes\nminder.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O16 - DPF: {02E09B2E-2A03-4572-9291-69900C068564} (LCSim Control) - http://www.learnitcorp.com/cabs/lcsim.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?link...67&clcid=0x409
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - http://www-306.ibm.com/pc/support/IbmEgath.cab
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {E9472078-EBA7-4885-8768-80ACF6F94553} (ClientSetup.RunSetup) - https://mojportal.htmobile.hr/manager/ClientSetup.CAB
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = int.lenac.hr
O17 - HKLM\System\CCS\Services\Tcpip\..\{89E36E56-039E-4E1B-B3A1-5CFE84EF1A09}: NameServer = 172.16.1.10,172.16.1.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{EA6EE805-8A47-47CC-A5CE-9ED843A3385A}: NameServer = 172.16.1.10,172.16.1.4
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = int.lenac.hr
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = int.lenac.hr,lenac.hr
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = int.lenac.hr
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = int.lenac.hr,lenac.hr
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = int.lenac.hr,lenac.hr
O20 - Winlogon Notify: Extensions - C:\WINNT\system32\mndtcui.dll
O23 - Service: CWShredder Service - Trend Micro Incorporated - C:\Documents and Settings\IgorTom\Desktop\CWShredder.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Intel(R) Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe
O23 - Service: Tivoli Endpoint (lcfd) - Unknown owner - C:\Tivoli\lcf\bin\w32-ix86\mrt\LCFD.EXE
O23 - Service: Oracle WebDb Listener - Unknown owner - C:\OraTool6\bin\wdblsnr.exe
O23 - Service: OracleClientCache80 - Unknown owner - C:\OraTool6\BIN\ONRSD80.EXE
O23 - Service: Oracle Forms Server [Forms60Server] (OracleFormsServer-Forms60Server) - Oracle Corporation - C:\OraTool6\bin\ifsrv60.exe
O23 - Service: Oracle Reports Server [Rep60_IN-MARIO1] (OracleReportServer-Rep60_IN-MARIO1) - Oracle Corp - C:\OraTool6\bin\rwmts60.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos Agent - Unknown owner - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe" -service -name Agent (file missing)
O23 - Service: Sophos AutoUpdate Agent - Unknown owner - C:\Program Files\Sophos\Remote Management System\AutoUpdateAgentNT.exe" -service -name ALC (file missing)
O23 - Service: Sophos AutoUpdate Service - Sophos plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Message Router - Unknown owner - C:\Program Files\Sophos\Remote Management System\RouterNT.exe" -service -name Router -ORBListenEndpoints iiop://:8193/ssl_port=8194 (file missing)
O23 - Service: Tivoli Remote Control Service (TME10RC) - Unknown owner - C:\WINNT\RCSERV.EXE
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)
O23 - Service: Novell Workstation Manager (WM) - Novell, Inc. - C:\WINNT\system32\wm.exe
__________________
___________
Just atha
x
atha je offline   Reply With Quote
Staro 23.10.2005., 23:58   #2
Costa
Moderator
 
Costa's Avatar
 
Datum registracije: Aug 2003
Lokacija: Zagreb
Postovi: 3,193
Sve ti je OK, ali mozes počistiti one stavke kod kojih piše (file missing).
Costa je offline   Reply With Quote
Oglasni prostor
Oglas
 
Oglas
Staro 24.10.2005., 11:01   #3
atha
Moderator
Moj komp
 
atha's Avatar
 
Datum registracije: Jan 2005
Lokacija: Rijeka
Postovi: 9,067
ok, hvala costa. neki trojanchek mi je uletio, ali ipak su posljedice bile prevelike, tako da sam jutros formatirao. a i bilo je vrijeme za ciscenje, ovo je samo bio dodatni razlog.
__________________
___________
Just atha
x
atha je offline   Reply With Quote
Oglasni prostor
Oglas
 
Oglas
Odgovori



Pravila postanja
Vi ne možete otvarati nove teme
Vi ne možete pisati odgovore
Vi ne možete uploadati priloge
Vi ne možete uređivati svoje poruke

BB code je Uključeno
Smajlići su Uključeno
[IMG] kod je Uključeno
HTML je Isključeno

Idi na