Najdi forum

SP2 connection patcher

Tale program (SP2 connection patcher) imam instaliran v računalniku pa ne vem kaj je to in če lahko izbrišem?

Prilagam še HijackThis:

Logfile of HijackThis v1.99.0
Scan saved at 22:09:37, on 20.8.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\dai the flu\Desktop\HijackThis.exe

O2 – BHO: AcroIEHlprObj Class – {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} – C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O4 – HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 – HKLM\..\Run: [nod32kui] “C:\Program Files\Eset\nod32kui.exe” /WAITSERVICE
O4 – HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 – HKLM\..\Run: [nwiz] nwiz.exe /install
O4 – HKLM\..\Run: [AVGCtrl] “C:\Program Files\AVPersonal\AVGNT.EXE” /min
O4 – HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 – HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 – HKLM\..\Run: [CloneCDTray] “C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe” /s
O4 – HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 – HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
O4 – HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 – HKCU\..\Run: [MsnMsgr] “C:\Program Files\MSN Messenger\MsnMsgr.Exe” /background
O4 – HKCU\..\Run: [SP2 Connection Patcher] “C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe” -n=200
O4 – Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 – Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 – Extra context menu item: E&xport to Microsoft Excel – res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 – Extra button: (no name) – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 – Extra ‘Tools’ menuitem: Sun Java Console – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O16 – DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) – http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 – DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) – http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1123340697083
O16 – DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) – http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 – DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) – http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 – Service: AntiVir Service – H+BEDV Datentechnik GmbH – C:\Program Files\AVPersonal\AVGUARD.EXE
O23 – Service: AntiVir Update – H+BEDV Datentechnik GmbH, Germany – C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 – Service: NOD32 Kernel Service – Unknown – C:\Program Files\Eset\nod32krn.exe
O23 – Service: NVIDIA Display Driver Service – NVIDIA Corporation – C:\WINDOWS\system32\nvsvc32.exe

NAJLEPŠA VAM HVALA ZA POMOČ.

Changes limit of concurrent TCP connections of Windows Service Pack 2

to je pač del sp2, sicer teče kot servis, lahko ga pa ustaviš.
Po mojem pač to pusti pri miru 😉 pa bo.

lp

(\__/) Copy and paste bunny (='.'=) to help him gain (")_(") world domination

Ja samo SP2 imam naložene že ohoho časa tale program pa komaj dva dni. Zakaj?

Prav pa si instaliral(a) kakšne p2p programčke. sicer pa to pač odstrani pa bo..

(\__/) Copy and paste bunny (='.'=) to help him gain (")_(") world domination

Morda poglej lastnosti datoteke:

C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe

Na zavihku version poglej kdo je avtor tega programa. Moral bi biti Microsoft če je res del SP2, sicer je pa možno da kakšni trojanci in podobno zamenjajo original datoteke z svojo verzijo, ki počne potem kaj drugega.

Če tvoj log skopiraš sem:

http://www.hijackthis.de

vidiš še eno nasty zadevo:

O4 – HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
Nasty New Dot Net Spyware
Hit rate: 99 % (result)
Must be fixed!

Log HijacThis sem priložil. Je morda kaj za zbrisati (popraviti)?
Tisti SP2 connection patcher sem pa zbrisal. Sem pa res nekaj “mozgal” en P2P programček samo sem ga takoj zbrisal. Izgleda, da je to ostalo.

Forum je zaprt za komentiranje.

New Report

Close