SafeGroup

Pełna wersja: Katalog system32 otwiera się o północy
Aktualnie przeglądasz uproszczoną wersję forum. Kliknij tutaj, by zobaczyć wersję z pełnym formatowaniem.
Stron: 1 2
Witam,

Od pewnego czasu, zawsze o północy, samoczynnie otwiera mi się katalog ''system32''.

Ponadto jakiś syf udaje Nortona i co jakiś czas sam się odpala próbując robić skanowanie. Nie przypominam sobie, żebym kiedykolwiek instalowała Nortona.

Dzięki za pomoc.

Kod:
Logfile of HijackThis v1.99.1
Scan saved at 22:16:42, on 2008-04-04
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
C:Program FilesAlwil SoftwareAvast4ashServ.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:Program FilesSystemGuards.comSystemGuardssgScheduleService.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe
C:Program FilesAlwil SoftwareAvast4ashWebSv.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:PROGRA~1ALWILS~1Avast4ashDisp.exe
C:Program FilesNokiaNokia Software LauncherNSLauncher.exe
C:Program FilesJavajre1.6.0_02binjusched.exe
C:Program FilesCommon FilesRealUpdate_OBrealsched.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesCommon FilesPCSuiteServicesServiceLayer.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe
C:Program FilesKodakKodak EasyShare softwarebinEasyShare.exe
C:Program FilesOperaOpera.exe
D:instalkiHJHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.onet.pl/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sp/*http://uk.search.yahoo.com/
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = 127.0.0.1
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:Program FilesWinamp Toolbarwinamptb.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:Program FilesBitComettoolsBitCometBHO_1.1.7.4.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:PROGRA~1Yahoo!Commonyiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_02binssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:Program FilesAskSBarbar1.binASKSBAR.DLL
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:Program FilesYahoo!browserYSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:Program FilesWinamp Toolbarwinamptb.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:Program FilesAskSBarbar1.binASKSBAR.DLL
O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe
O4 - HKLM..Run: [NSLauncher] C:Program FilesNokiaNokia Software LauncherNSLauncher.exe /startup
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.6.0_02binjusched.exe"
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeQTTask.exe" -atboottime
O4 - HKLM..Run: [Onet.pl AutoUpdate] "C:Program FilesCommon FilesOnet.plAutoUpdate.exe" /tsr
O4 - HKLM..Run: [System Guards] C:Program FilesSystemGuards.comSystemGuardsSysGuards.exe
O4 - HKLM..Run: [TkBellExe] "C:Program FilesCommon FilesRealUpdate_OBrealsched.exe"-osboot
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [AdobeUpdater] C:Program FilesCommon FilesAdobeUpdater5AdobeUpdater.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe
O4 - Global Startup: Oprogramowanie Kodak EasyShare.lnk = C:Program FilesKodakKodak EasyShare softwarebinEasyShare.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:Program FilesBitCometBitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:Program FilesBitCometBitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:Program FilesBitCometBitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Winamp Toolbar Search - C:Documents and SettingsAll UsersDane aplikacjiWinamp ToolbarieToolbarresourcesen-USlocalsearch.html
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_02binssv.dll
O9 - Extra ''Tools'' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_02binssv.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:Program FilesBitComettoolsBitCometBHO_1.1.7.4.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:PROGRA~1Yahoo!Commonyiesrvc.dll
O15 - Trusted Zone: http://www.mks.com.pl
O15 - Trusted Zone: http://bezpieczenstwo.onet.pl
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:Program FilesYahoo!commonyinsthelper.dll
O16 - DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} (MainControl Class) - http://slimak.onet.pl/_m/wirusy/ArcaOnline.cab
O16 - DPF: {5A09E43F-A0A7-4ABF-AF80-11367CF1DC8F} - http://mks.com.pl/skaner/SkanerOnline.cab
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} - http://www.mks.com.pl/skaner/SkanerOnline.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:WINDOWSsystem32WPDShServiceObj.dll
O23 - Service: Urządzenie mobilne Apple (Apple Mobile Device) - Apple, Inc. - C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:Program FilesAlwil SoftwareAvast4ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashWebSv.exe" /service (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:Program FilesSpyware Doctorsvcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:Program FilesSpyware Doctorswdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:Program FilesCommon FilesPCSuiteServicesServiceLayer.exe
O23 - Service: sgSchedulerService - Unknown owner - C:Program FilesSystemGuards.comSystemGuardssgScheduleService.exe
O23 - Service: YPCService - Yahoo! Inc. - C:WINDOWSsystem32YPCSER~1.EXE




Kod:
"Silent Runners.vbs", revision 56, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCUSoftwareMicrosoftWindowsCurrentVersionRun {++}
"ctfmon.exe" = "C:WINDOWSsystem32ctfmon.exe" [MS]
"AdobeUpdater" = "C:Program FilesCommon FilesAdobeUpdater5AdobeUpdater.exe" ["Adobe Systems Incorporated"]

HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun {++}
"avast!" = "C:PROGRA~1ALWILS~1Avast4ashDisp.exe" ["ALWIL Software"]
"NSLauncher" = "C:Program FilesNokiaNokia Software LauncherNSLauncher.exe /startup" [null data]
"Adobe Reader Speed Launcher" = ""C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"" ["Adobe Systems Incorporated"]
"SunJavaUpdateSched" = ""C:Program FilesJavajre1.6.0_02binjusched.exe"" ["Sun Microsystems, Inc."]
"QuickTime Task" = ""C:Program FilesQuickTimeQTTask.exe" -atboottime" ["Apple Inc."]
"Onet.pl AutoUpdate" = ""C:Program FilesCommon FilesOnet.plAutoUpdate.exe" /tsr" [file not found]
"System Guards" = "C:Program FilesSystemGuards.comSystemGuardsSysGuards.exe" ["SystemGuards.com"]
"TkBellExe" = ""C:Program FilesCommon FilesRealUpdate_OBrealsched.exe"-osboot" ["RealNetworks, Inc."]

HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects
{02478D38-C3F9-4EFB-9B51-7695ECA05670}(Default) = (no title provided)
-> {HKLM...CLSID} = "Yahoo! Toolbar Helper"
InProcServer32(Default) = "C:Program FilesYahoo!CompanionInstallscpn0yt.dll" ["Yahoo! Inc."]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = (no title provided)
-> {HKLM...CLSID} = "Adobe PDF Reader Link Helper"
InProcServer32(Default) = "C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll" ["Adobe Systems Incorporated"]
{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}(Default) = "Winamp Toolbar BHO"
-> {HKLM...CLSID} = "Winamp Toolbar BHO"
InProcServer32(Default) = "C:Program FilesWinamp Toolbarwinamptb.dll" ["AOL LLC"]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}(Default) = "BitComet ClickCapture"
-> {HKLM...CLSID} = "BitComet Helper"
InProcServer32(Default) = "C:Program FilesBitComettoolsBitCometBHO_1.1.7.4.dll" ["BitComet"]
{53707962-6F74-2D53-2644-206D7942484F}(Default) = (no title provided)
-> {HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "C:PROGRA~1SPYBOT~1SDHelper.dll" ["Safer Networking Limited"]
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}(Default) = (no title provided)
-> {HKLM...CLSID} = "Yahoo! IE Services Button"
InProcServer32(Default) = "C:PROGRA~1Yahoo!Commonyiesrvc.dll" ["Yahoo! Inc."]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}(Default) = (no title provided)
-> {HKLM...CLSID} = "SSVHelper Class"
InProcServer32(Default) = "C:Program FilesJavajre1.6.0_02binssv.dll" ["Sun Microsystems, Inc."]
{9030D464-4C02-4ABF-8ECC-5164760863C6}(Default) = (no title provided)
-> {HKLM...CLSID} = "Windows Live Sign-in Helper"
InProcServer32(Default) = "C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll" [MS]
{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}(Default) = "Ask Toolbar BHO"
-> {HKLM...CLSID} = "Ask Toolbar BHO"
InProcServer32(Default) = "C:Program FilesAskSBarbar1.binASKSBAR.DLL" ["Ask.com"]
{F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D}(Default) = (no title provided)
-> {HKLM...CLSID} = "SidebarAutoLaunch Class"
InProcServer32(Default) = "C:Program FilesYahoo!browserYSidebarIEBHO.dll" ["Yahoo! Inc."]

HKLMSOFTWAREMicrosoftWindowsCurrentVersionShell ExtensionsApproved
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
-> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
InProcServer32(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
InProcServer32(Default) = "C:WINDOWSSystem32hticons.dll" ["Hilgraeve, Inc."]
"{2F603045-309F-11CF-9774-0020AFD0CFF6}" = "Synaptics Control Panel"
-> {HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "C:Program FilesSynapticsSynTPSynTPCpl.dll" ["Synaptics, Inc."]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
-> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook"
InProcServer32(Default) = "C:Program FilesMicrosoft OfficeOffice10OLKFSTUB.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "C:Program FilesMicrosoft OfficeOffice10msohev.dll" [MS]
"{20082881-FC36-4E47-9A7A-644C95FF749F}" = "IntelliPoint Wireless Control Panel Property Page"
-> {HKLM...CLSID} = "Wireless Property Page"
InProcServer32(Default) = ""C:Program FilesMicrosoft IntelliPointipcplwir.dll"" [MS]
"{AF90F543-6A3A-4C1B-8B16-ECEC073E69BE}" = "IntelliPoint Wheel Control Panel Property Page"
-> {HKLM...CLSID} = "Wheel Property Page"
InProcServer32(Default) = ""C:Program FilesMicrosoft IntelliPointipcplwhl.dll"" [MS]
"{653DCCC2-13DB-45B2-A389-427885776CFE}" = "IntelliPoint Activities Control Panel Property Page"
-> {HKLM...CLSID} = "Activities Property Page"
InProcServer32(Default) = ""C:Program FilesMicrosoft IntelliPointipcplact.dll"" [MS]
"{124597D8-850A-41AE-849C-017A4FA99CA2}" = "IntelliPoint Buttons Control Panel Property Page"
-> {HKLM...CLSID} = "Buttons Property Page"
InProcServer32(Default) = ""C:Program FilesMicrosoft IntelliPointipcplbtn.dll"" [MS]
"{400CFEE2-39D0-46DC-96DF-E0BB5A4324B3}" = "My Labtec Pictures"
-> {HKLM...CLSID} = "My Labtec Pictures"
InProcServer32(Default) = "C:Program FilesLogitechVideoNamespc2.dll" ["Labtec Inc."]
"{E0D79300-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM...CLSID} = "WinZip"
InProcServer32(Default) = "C:PROGRA~1WinZipwzshlext.dll" [null data]
"{E0D79301-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM...CLSID} = "WinZip"
InProcServer32(Default) = "C:PROGRA~1WinZipwzshlext.dll" [null data]
"{E0D79302-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM...CLSID} = "WinZip"
InProcServer32(Default) = "C:PROGRA~1WinZipwzshlext.dll" [null data]
"{B327765E-D724-4347-8B16-78AE18552FC3}" = "NeroDigitalIconHandler"
-> {HKLM...CLSID} = "NeroDigitalIconHandler Class"
InProcServer32(Default) = "C:Program FilesCommon FilesAheadlibNeroDigitalExt.dll" ["Nero AG"]
"{7F1CF152-04F8-453A-B34C-E609530A9DC8}" = "NeroDigitalPropSheetHandler"
-> {HKLM...CLSID} = "NeroDigitalPropSheetHandler Class"
InProcServer32(Default) = "C:Program FilesCommon FilesAheadlibNeroDigitalExt.dll" ["Nero AG"]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {HKLM...CLSID} = "RealOne Player Context Menu Class"
InProcServer32(Default) = "C:Program FilesRealRealPlayerrpshell.dll" ["RealNetworks, Inc."]
"{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}" = "PowerISO"
-> {HKLM...CLSID} = "PowerISO"
InProcServer32(Default) = "C:Program FilesPowerISOPWRISOSH.DLL" ["PowerISO Computing, Inc."]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]
"{5464D816-CF16-4784-B9F3-75C0DB52B499}" = "Yahoo! Mail"
-> {HKLM...CLSID} = "YMailShellExt Class"
InProcServer32(Default) = "C:PROGRA~1Yahoo!Commonymmapi.dll" ["Yahoo! Inc."]
"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
-> {HKLM...CLSID} = "avast"
InProcServer32(Default) = "C:Program FilesAlwil SoftwareAvast4ashShell.dll" ["ALWIL Software"]
"{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"
-> {HKLM...CLSID} = "Moje foldery udostępniania"
InProcServer32(Default) = "C:Program FilesMSN Messengerfsshext.8.1.0178.00.dll" [MS]
"{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A}" = "PhoneBrowser"
-> {HKLM...CLSID} = "Nokia Phone Browser"
InProcServer32(Default) = "C:Program FilesNokiaNokia PC Suite 6PhoneBrowser.dll" ["Nokia"]

HKLMSOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad
"WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
-> {HKLM...CLSID} = "WPDShServiceObj Class"
InProcServer32(Default) = "C:WINDOWSsystem32WPDShServiceObj.dll" [MS]

HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotify
<<!>> AtiExtEventDLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]

HKLMSOFTWAREClassesFoldershellexColumnHandlers
{7D4D6379-F301-4311-BEBA-E26EB0561882}(Default) = "NeroDigitalExt.NeroDigitalColumnHandler"
-> {HKLM...CLSID} = "NeroDigitalColumnHandler Class"
InProcServer32(Default) = "C:Program FilesCommon FilesAheadlibNeroDigitalExt.dll" ["Nero AG"]
{F9DB5320-233E-11D1-9F84-707F02C10627}(Default) = "PDF Column Info"
-> {HKLM...CLSID} = "PDF Shell Extension"
InProcServer32(Default) = "C:Program FilesCommon FilesAdobeAcrobatActiveXPDFShell.dll" ["Adobe Systems, Inc."]

HKLMSOFTWAREClasses*shellexContextMenuHandlers
avast(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM...CLSID} = "avast"
InProcServer32(Default) = "C:Program FilesAlwil SoftwareAvast4ashShell.dll" ["ALWIL Software"]
PowerISO(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"
-> {HKLM...CLSID} = "PowerISO"
InProcServer32(Default) = "C:Program FilesPowerISOPWRISOSH.DLL" ["PowerISO Computing, Inc."]
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]
WinZip(Default) = "{E0D79300-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
InProcServer32(Default) = "C:PROGRA~1WinZipwzshlext.dll" [null data]
Yahoo! Mail(Default) = "{5464D816-CF16-4784-B9F3-75C0DB52B499}"
-> {HKLM...CLSID} = "YMailShellExt Class"
InProcServer32(Default) = "C:PROGRA~1Yahoo!Commonymmapi.dll" ["Yahoo! Inc."]

HKLMSOFTWAREClassesDirectoryshellexContextMenuHandlers
PowerISO(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"
-> {HKLM...CLSID} = "PowerISO"
InProcServer32(Default) = "C:Program FilesPowerISOPWRISOSH.DLL" ["PowerISO Computing, Inc."]
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]
WinZip(Default) = "{E0D79300-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
InProcServer32(Default) = "C:PROGRA~1WinZipwzshlext.dll" [null data]

HKLMSOFTWAREClassesFoldershellexContextMenuHandlers
avast(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM...CLSID} = "avast"
InProcServer32(Default) = "C:Program FilesAlwil SoftwareAvast4ashShell.dll" ["ALWIL Software"]
PowerISO(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"
-> {HKLM...CLSID} = "PowerISO"
InProcServer32(Default) = "C:Program FilesPowerISOPWRISOSH.DLL" ["PowerISO Computing, Inc."]
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]
WinZip(Default) = "{E0D79300-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
InProcServer32(Default) = "C:PROGRA~1WinZipwzshlext.dll" [null data]


Group Policies {GPedit.msc branch and setting}:
-----------------------------------------------

Note: detected settings may not have any effect.

HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystem

"shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop may be disabled at this entry:
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCUSoftwareMicrosoftInternet ExplorerDesktopGeneral
"Wallpaper" = "C:WINDOWSsystem32configsystemprofileUstawienia lokalneDane aplikacjiMicrosoftWallpaper1.bmp"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCUControl PanelDesktop
"Wallpaper" = "C:Documents and SettingsDominikaUstawienia lokalneDane aplikacjiMicrosoftWallpaper1.bmp"


Startup items in "Dominika" & "All Users" startup folders:
----------------------------------------------------------

C:Documents and SettingsAll UsersMenu StartProgramyAutostart
"KODAK Software Updater" -> shortcut to: "C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe" [null data]
"Oprogramowanie Kodak EasyShare" -> shortcut to: "C:Program FilesKodakKodak EasyShare softwarebinEasyShare.exe -hx" ["Eastman Kodak Company"]


Enabled Scheduled Tasks:
------------------------

"AppleSoftwareUpdate" -> launches: "C:Program FilesApple Software UpdateSoftwareUpdate.exe -task" ["Apple Inc."]
"Norton Security Scan" -> launches: "C:Program FilesNorton Security ScanNss.exe /scan-full /scheduled" ["Symantec Corporation"]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLMSYSTEMCurrentControlSetServicesWinsock2ParametersNameSpace_Catalog5Catalog_Entries {++}
000000000001LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]
000000000002LibraryPath = "%SystemRoot%System32winrnr.dll" [MS]
000000000003LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]

Transport Service Providers

HKLMSYSTEMCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_Entries {++}
0000000000##PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%system32mswsock.dll [MS], 01 - 03, 06 - 17
%SystemRoot%system32rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
------------------------------------

Toolbars

HKCUSoftwareMicrosoftInternet ExplorerToolbarWebBrowser
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
-> {HKLM...CLSID} = "Yahoo! Toolbar"
InProcServer32(Default) = "C:Program FilesYahoo!CompanionInstallscpn0yt.dll" ["Yahoo! Inc."]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"
-> {HKLM...CLSID} = "Winamp Toolbar"
InProcServer32(Default) = "C:Program FilesWinamp Toolbarwinamptb.dll" ["AOL LLC"]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"
-> {HKLM...CLSID} = "Ask Toolbar"
InProcServer32(Default) = "C:Program FilesAskSBarbar1.binASKSBAR.DLL" ["Ask.com"]

HKLMSOFTWAREMicrosoftInternet ExplorerToolbar
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = (no title provided)
-> {HKLM...CLSID} = "Yahoo! Toolbar"
InProcServer32(Default) = "C:Program FilesYahoo!CompanionInstallscpn0yt.dll" ["Yahoo! Inc."]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}" = "Winamp Toolbar"
-> {HKLM...CLSID} = "Winamp Toolbar"
InProcServer32(Default) = "C:Program FilesWinamp Toolbarwinamptb.dll" ["AOL LLC"]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}" = (no title provided)
-> {HKLM...CLSID} = "Ask Toolbar"
InProcServer32(Default) = "C:Program FilesAskSBarbar1.binASKSBAR.DLL" ["Ask.com"]

Explorer Bars

HKLMSOFTWAREMicrosoftInternet ExplorerExplorer Bars

HKLMSOFTWAREClassesCLSID{51085E3D-A958-42A2-A6BE-A6A9B0BAF276}(Default) = "BT Yahoo! Sidebar"
Implemented Categories{00021493-0000-0000-C000-000000000046} [vertical bar]
InProcServer32(Default) = "C:Program FilesYahoo!browserysidebarIE.dll" ["Yahoo! Inc."]

HKLMSOFTWAREClassesCLSID{E7A829CC-671F-4C3D-B590-8C0AEA72E6B2}(Default) = "BitComet Search"
Implemented Categories{00021493-0000-0000-C000-000000000046} [vertical bar]
InProcServer32(Default) = "C:Program FilesBitComettoolsBitCometBHO_1.1.7.4.dll" ["BitComet"]

Extensions (Tools menu items, main toolbar menu buttons)

HKLMSOFTWAREMicrosoftInternet ExplorerExtensions
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}"
-> {HKCU...CLSID} = "Java Plug-in 1.6.0_02"
InProcServer32(Default) = "C:Program FilesJavajre1.6.0_02binssv.dll" ["Sun Microsystems, Inc."]
-> {HKLM...CLSID} = "Java Plug-in 1.6.0_02"
InProcServer32(Default) = "C:Program FilesJavajre1.6.0_02binnpjpi160_02.dll" ["Sun Microsystems, Inc."]

{461CC20B-FB6E-4F16-8FE8-C29359DB100E}
"ButtonText" = "BitComet Search"

{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}
"ButtonText" = "BT Yahoo! Services"
"CLSIDExtension" = "{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}"
-> {HKLM...CLSID} = "Yahoo! IE Services Button"
InProcServer32(Default) = "C:PROGRA~1Yahoo!Commonyiesrvc.dll" ["Yahoo! Inc."]


Miscellaneous IE Hijack Points
------------------------------

HKCUSoftwareMicrosoftInternet ExplorerURLSearchHooks
<<H>> "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = (no title provided)
-> {HKLM...CLSID} = "Yahoo! Toolbar"
InProcServer32(Default) = "C:Program FilesYahoo!CompanionInstallscpn0yt.dll" ["Yahoo! Inc."]


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

Ati HotKey Poller, Ati HotKey Poller, "C:WINDOWSsystem32Ati2evxx.exe" ["ATI Technologies Inc."]
avast! Antivirus, avast! Antivirus, ""C:Program FilesAlwil SoftwareAvast4ashServ.exe"" ["ALWIL Software"]
avast! iAVS4 Control Service, aswUpdSv, ""C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe"" ["ALWIL Software"]
avast! Mail Scanner, avast! Mail Scanner, ""C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service" ["ALWIL Software"]
avast! Web Scanner, avast! Web Scanner, ""C:Program FilesAlwil SoftwareAvast4ashWebSv.exe" /service" ["ALWIL Software"]
Machine Debug Manager, MDM, ""C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE"" [MS]
ServiceLayer, ServiceLayer, ""C:Program FilesCommon FilesPCSuiteServicesServiceLayer.exe"" ["Nokia."]
sgSchedulerService, sgSchedulerService, "C:Program FilesSystemGuards.comSystemGuardssgScheduleService.exe" [null data]
Urządzenie mobilne Apple, Apple Mobile Device, ""C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe"" ["Apple, Inc."]


---------- (launch time: 2008-04-04 22:17:15)
<<!>>: Suspicious data at a malware launch point.
<<H>>: Suspicious data at a browser hijack point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 150 seconds.
---------- (total run time: 233 seconds)
Jeszcze raz wklejam logi, bo cośtam nie wyszło

Kod:
[ code]
Logfile of HijackThis v1.99.1
Scan saved at 22:16:42, on 2008-04-04
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
C:Program FilesAlwil SoftwareAvast4ashServ.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:Program FilesSystemGuards.comSystemGuardssgScheduleService.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe
C:Program FilesAlwil SoftwareAvast4ashWebSv.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:PROGRA~1ALWILS~1Avast4ashDisp.exe
C:Program FilesNokiaNokia Software LauncherNSLauncher.exe
C:Program FilesJavajre1.6.0_02binjusched.exe
C:Program FilesCommon FilesRealUpdate_OBrealsched.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesCommon FilesPCSuiteServicesServiceLayer.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe
C:Program FilesKodakKodak EasyShare softwarebinEasyShare.exe
C:Program FilesOperaOpera.exe
D:instalkiHJHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.onet.pl/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sp/*http://uk.search.yahoo.com/
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = 127.0.0.1
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:Program FilesWinamp Toolbarwinamptb.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:Program FilesBitComettoolsBitCometBHO_1.1.7.4.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:PROGRA~1Yahoo!Commonyiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_02binssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:Program FilesAskSBarbar1.binASKSBAR.DLL
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:Program FilesYahoo!browserYSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:Program FilesWinamp Toolbarwinamptb.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:Program FilesAskSBarbar1.binASKSBAR.DLL
O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe
O4 - HKLM..Run: [NSLauncher] C:Program FilesNokiaNokia Software LauncherNSLauncher.exe /startup
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.6.0_02binjusched.exe"
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeQTTask.exe" -atboottime
O4 - HKLM..Run: [Onet.pl AutoUpdate] "C:Program FilesCommon FilesOnet.plAutoUpdate.exe" /tsr
O4 - HKLM..Run: [System Guards] C:Program FilesSystemGuards.comSystemGuardsSysGuards.exe
O4 - HKLM..Run: [TkBellExe] "C:Program FilesCommon FilesRealUpdate_OBrealsched.exe"-osboot
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [AdobeUpdater] C:Program FilesCommon FilesAdobeUpdater5AdobeUpdater.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe
O4 - Global Startup: Oprogramowanie Kodak EasyShare.lnk = C:Program FilesKodakKodak EasyShare softwarebinEasyShare.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:Program FilesBitCometBitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:Program FilesBitCometBitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:Program FilesBitCometBitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Winamp Toolbar Search - C:Documents and SettingsAll UsersDane aplikacjiWinamp ToolbarieToolbarresourcesen-USlocalsearch.html
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_02binssv.dll
O9 - Extra ''Tools'' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_02binssv.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:Program FilesBitComettoolsBitCometBHO_1.1.7.4.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:PROGRA~1Yahoo!Commonyiesrvc.dll
O15 - Trusted Zone: http://www.mks.com.pl
O15 - Trusted Zone: http://bezpieczenstwo.onet.pl
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:Program FilesYahoo!commonyinsthelper.dll
O16 - DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} (MainControl Class) - http://slimak.onet.pl/_m/wirusy/ArcaOnline.cab
O16 - DPF: {5A09E43F-A0A7-4ABF-AF80-11367CF1DC8F} - http://mks.com.pl/skaner/SkanerOnline.cab
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} - http://www.mks.com.pl/skaner/SkanerOnline.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:WINDOWSsystem32WPDShServiceObj.dll
O23 - Service: Urządzenie mobilne Apple (Apple Mobile Device) - Apple, Inc. - C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:Program FilesAlwil SoftwareAvast4ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashWebSv.exe" /service (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:Program FilesSpyware Doctorsvcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:Program FilesSpyware Doctorswdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:Program FilesCommon FilesPCSuiteServicesServiceLayer.exe
O23 - Service: sgSchedulerService - Unknown owner - C:Program FilesSystemGuards.comSystemGuardssgScheduleService.exe
O23 - Service: YPCService - Yahoo! Inc. - C:WINDOWSsystem32YPCSER~1.EXE
[ /code]


[ code]
"Silent Runners.vbs", revision 56, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCUSoftwareMicrosoftWindowsCurrentVersionRun {++}
"ctfmon.exe" = "C:WINDOWSsystem32ctfmon.exe" [MS]
"AdobeUpdater" = "C:Program FilesCommon FilesAdobeUpdater5AdobeUpdater.exe" ["Adobe Systems Incorporated"]

HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun {++}
"avast!" = "C:PROGRA~1ALWILS~1Avast4ashDisp.exe" ["ALWIL Software"]
"NSLauncher" = "C:Program FilesNokiaNokia Software LauncherNSLauncher.exe /startup" [null data]
"Adobe Reader Speed Launcher" = ""C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"" ["Adobe Systems Incorporated"]
"SunJavaUpdateSched" = ""C:Program FilesJavajre1.6.0_02binjusched.exe"" ["Sun Microsystems, Inc."]
"QuickTime Task" = ""C:Program FilesQuickTimeQTTask.exe" -atboottime" ["Apple Inc."]
"Onet.pl AutoUpdate" = ""C:Program FilesCommon FilesOnet.plAutoUpdate.exe" /tsr" [file not found]
"System Guards" = "C:Program FilesSystemGuards.comSystemGuardsSysGuards.exe" ["SystemGuards.com"]
"TkBellExe" = ""C:Program FilesCommon FilesRealUpdate_OBrealsched.exe"-osboot" ["RealNetworks, Inc."]

HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects
{02478D38-C3F9-4EFB-9B51-7695ECA05670}(Default) = (no title provided)
-> {HKLM...CLSID} = "Yahoo! Toolbar Helper"
InProcServer32(Default) = "C:Program FilesYahoo!CompanionInstallscpn0yt.dll" ["Yahoo! Inc."]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = (no title provided)
-> {HKLM...CLSID} = "Adobe PDF Reader Link Helper"
InProcServer32(Default) = "C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll" ["Adobe Systems Incorporated"]
{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}(Default) = "Winamp Toolbar BHO"
-> {HKLM...CLSID} = "Winamp Toolbar BHO"
InProcServer32(Default) = "C:Program FilesWinamp Toolbarwinamptb.dll" ["AOL LLC"]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}(Default) = "BitComet ClickCapture"
-> {HKLM...CLSID} = "BitComet Helper"
InProcServer32(Default) = "C:Program FilesBitComettoolsBitCometBHO_1.1.7.4.dll" ["BitComet"]
{53707962-6F74-2D53-2644-206D7942484F}(Default) = (no title provided)
-> {HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "C:PROGRA~1SPYBOT~1SDHelper.dll" ["Safer Networking Limited"]
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}(Default) = (no title provided)
-> {HKLM...CLSID} = "Yahoo! IE Services Button"
InProcServer32(Default) = "C:PROGRA~1Yahoo!Commonyiesrvc.dll" ["Yahoo! Inc."]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}(Default) = (no title provided)
-> {HKLM...CLSID} = "SSVHelper Class"
InProcServer32(Default) = "C:Program FilesJavajre1.6.0_02binssv.dll" ["Sun Microsystems, Inc."]
{9030D464-4C02-4ABF-8ECC-5164760863C6}(Default) = (no title provided)
-> {HKLM...CLSID} = "Windows Live Sign-in Helper"
InProcServer32(Default) = "C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll" [MS]
{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}(Default) = "Ask Toolbar BHO"
-> {HKLM...CLSID} = "Ask Toolbar BHO"
InProcServer32(Default) = "C:Program FilesAskSBarbar1.binASKSBAR.DLL" ["Ask.com"]
{F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D}(Default) = (no title provided)
-> {HKLM...CLSID} = "SidebarAutoLaunch Class"
InProcServer32(Default) = "C:Program FilesYahoo!browserYSidebarIEBHO.dll" ["Yahoo! Inc."]

HKLMSOFTWAREMicrosoftWindowsCurrentVersionShell ExtensionsApproved
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
-> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
InProcServer32(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
InProcServer32(Default) = "C:WINDOWSSystem32hticons.dll" ["Hilgraeve, Inc."]
"{2F603045-309F-11CF-9774-0020AFD0CFF6}" = "Synaptics Control Panel"
-> {HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "C:Program FilesSynapticsSynTPSynTPCpl.dll" ["Synaptics, Inc."]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
-> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook"
InProcServer32(Default) = "C:Program FilesMicrosoft OfficeOffice10OLKFSTUB.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "C:Program FilesMicrosoft OfficeOffice10msohev.dll" [MS]
"{20082881-FC36-4E47-9A7A-644C95FF749F}" = "IntelliPoint Wireless Control Panel Property Page"
-> {HKLM...CLSID} = "Wireless Property Page"
InProcServer32(Default) = ""C:Program FilesMicrosoft IntelliPointipcplwir.dll"" [MS]
"{AF90F543-6A3A-4C1B-8B16-ECEC073E69BE}" = "IntelliPoint Wheel Control Panel Property Page"
-> {HKLM...CLSID} = "Wheel Property Page"
InProcServer32(Default) = ""C:Program FilesMicrosoft IntelliPointipcplwhl.dll"" [MS]
"{653DCCC2-13DB-45B2-A389-427885776CFE}" = "IntelliPoint Activities Control Panel Property Page"
-> {HKLM...CLSID} = "Activities Property Page"
InProcServer32(Default) = ""C:Program FilesMicrosoft IntelliPointipcplact.dll"" [MS]
"{124597D8-850A-41AE-849C-017A4FA99CA2}" = "IntelliPoint Buttons Control Panel Property Page"
-> {HKLM...CLSID} = "Buttons Property Page"
InProcServer32(Default) = ""C:Program FilesMicrosoft IntelliPointipcplbtn.dll"" [MS]
"{400CFEE2-39D0-46DC-96DF-E0BB5A4324B3}" = "My Labtec Pictures"
-> {HKLM...CLSID} = "My Labtec Pictures"
InProcServer32(Default) = "C:Program FilesLogitechVideoNamespc2.dll" ["Labtec Inc."]
"{E0D79300-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM...CLSID} = "WinZip"
InProcServer32(Default) = "C:PROGRA~1WinZipwzshlext.dll" [null data]
"{E0D79301-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM...CLSID} = "WinZip"
InProcServer32(Default) = "C:PROGRA~1WinZipwzshlext.dll" [null data]
"{E0D79302-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM...CLSID} = "WinZip"
InProcServer32(Default) = "C:PROGRA~1WinZipwzshlext.dll" [null data]
"{B327765E-D724-4347-8B16-78AE18552FC3}" = "NeroDigitalIconHandler"
-> {HKLM...CLSID} = "NeroDigitalIconHandler Class"
InProcServer32(Default) = "C:Program FilesCommon FilesAheadlibNeroDigitalExt.dll" ["Nero AG"]
"{7F1CF152-04F8-453A-B34C-E609530A9DC8}" = "NeroDigitalPropSheetHandler"
-> {HKLM...CLSID} = "NeroDigitalPropSheetHandler Class"
InProcServer32(Default) = "C:Program FilesCommon FilesAheadlibNeroDigitalExt.dll" ["Nero AG"]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {HKLM...CLSID} = "RealOne Player Context Menu Class"
InProcServer32(Default) = "C:Program FilesRealRealPlayerrpshell.dll" ["RealNetworks, Inc."]
"{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}" = "PowerISO"
-> {HKLM...CLSID} = "PowerISO"
InProcServer32(Default) = "C:Program FilesPowerISOPWRISOSH.DLL" ["PowerISO Computing, Inc."]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]
"{5464D816-CF16-4784-B9F3-75C0DB52B499}" = "Yahoo! Mail"
-> {HKLM...CLSID} = "YMailShellExt Class"
InProcServer32(Default) = "C:PROGRA~1Yahoo!Commonymmapi.dll" ["Yahoo! Inc."]
"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
-> {HKLM...CLSID} = "avast"
InProcServer32(Default) = "C:Program FilesAlwil SoftwareAvast4ashShell.dll" ["ALWIL Software"]
"{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"
-> {HKLM...CLSID} = "Moje foldery udostępniania"
InProcServer32(Default) = "C:Program FilesMSN Messengerfsshext.8.1.0178.00.dll" [MS]
"{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A}" = "PhoneBrowser"
-> {HKLM...CLSID} = "Nokia Phone Browser"
InProcServer32(Default) = "C:Program FilesNokiaNokia PC Suite 6PhoneBrowser.dll" ["Nokia"]

HKLMSOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad
"WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
-> {HKLM...CLSID} = "WPDShServiceObj Class"
InProcServer32(Default) = "C:WINDOWSsystem32WPDShServiceObj.dll" [MS]

HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotify
<<!>> AtiExtEventDLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]

HKLMSOFTWAREClassesFoldershellexColumnHandlers
{7D4D6379-F301-4311-BEBA-E26EB0561882}(Default) = "NeroDigitalExt.NeroDigitalColumnHandler"
-> {HKLM...CLSID} = "NeroDigitalColumnHandler Class"
InProcServer32(Default) = "C:Program FilesCommon FilesAheadlibNeroDigitalExt.dll" ["Nero AG"]
{F9DB5320-233E-11D1-9F84-707F02C10627}(Default) = "PDF Column Info"
-> {HKLM...CLSID} = "PDF Shell Extension"
InProcServer32(Default) = "C:Program FilesCommon FilesAdobeAcrobatActiveXPDFShell.dll" ["Adobe Systems, Inc."]

HKLMSOFTWAREClasses*shellexContextMenuHandlers
avast(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM...CLSID} = "avast"
InProcServer32(Default) = "C:Program FilesAlwil SoftwareAvast4ashShell.dll" ["ALWIL Software"]
PowerISO(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"
-> {HKLM...CLSID} = "PowerISO"
InProcServer32(Default) = "C:Program FilesPowerISOPWRISOSH.DLL" ["PowerISO Computing, Inc."]
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]
WinZip(Default) = "{E0D79300-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
InProcServer32(Default) = "C:PROGRA~1WinZipwzshlext.dll" [null data]
Yahoo! Mail(Default) = "{5464D816-CF16-4784-B9F3-75C0DB52B499}"
-> {HKLM...CLSID} = "YMailShellExt Class"
InProcServer32(Default) = "C:PROGRA~1Yahoo!Commonymmapi.dll" ["Yahoo! Inc."]

HKLMSOFTWAREClassesDirectoryshellexContextMenuHandlers
PowerISO(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"
-> {HKLM...CLSID} = "PowerISO"
InProcServer32(Default) = "C:Program FilesPowerISOPWRISOSH.DLL" ["PowerISO Computing, Inc."]
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]
WinZip(Default) = "{E0D79300-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
InProcServer32(Default) = "C:PROGRA~1WinZipwzshlext.dll" [null data]

HKLMSOFTWAREClassesFoldershellexContextMenuHandlers
avast(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM...CLSID} = "avast"
InProcServer32(Default) = "C:Program FilesAlwil SoftwareAvast4ashShell.dll" ["ALWIL Software"]
PowerISO(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"
-> {HKLM...CLSID} = "PowerISO"
InProcServer32(Default) = "C:Program FilesPowerISOPWRISOSH.DLL" ["PowerISO Computing, Inc."]
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]
WinZip(Default) = "{E0D79300-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
InProcServer32(Default) = "C:PROGRA~1WinZipwzshlext.dll" [null data]


Group Policies {GPedit.msc branch and setting}:
-----------------------------------------------

Note: detected settings may not have any effect.

HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystem

"shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop may be disabled at this entry:
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCUSoftwareMicrosoftInternet ExplorerDesktopGeneral
"Wallpaper" = "C:WINDOWSsystem32configsystemprofileUstawienia lokalneDane aplikacjiMicrosoftWallpaper1.bmp"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCUControl PanelDesktop
"Wallpaper" = "C:Documents and SettingsDominikaUstawienia lokalneDane aplikacjiMicrosoftWallpaper1.bmp"


Startup items in "Dominika" & "All Users" startup folders:
----------------------------------------------------------

C:Documents and SettingsAll UsersMenu StartProgramyAutostart
"KODAK Software Updater" -> shortcut to: "C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe" [null data]
"Oprogramowanie Kodak EasyShare" -> shortcut to: "C:Program FilesKodakKodak EasyShare softwarebinEasyShare.exe -hx" ["Eastman Kodak Company"]


Enabled Scheduled Tasks:
------------------------

"AppleSoftwareUpdate" -> launches: "C:Program FilesApple Software UpdateSoftwareUpdate.exe -task" ["Apple Inc."]
"Norton Security Scan" -> launches: "C:Program FilesNorton Security ScanNss.exe /scan-full /scheduled" ["Symantec Corporation"]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLMSYSTEMCurrentControlSetServicesWinsock2ParametersNameSpace_Catalog5Catalog_Entries {++}
000000000001LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]
000000000002LibraryPath = "%SystemRoot%System32winrnr.dll" [MS]
000000000003LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]

Transport Service Providers

HKLMSYSTEMCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_Entries {++}
0000000000##PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%system32mswsock.dll [MS], 01 - 03, 06 - 17
%SystemRoot%system32rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
------------------------------------

Toolbars

HKCUSoftwareMicrosoftInternet ExplorerToolbarWebBrowser
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
-> {HKLM...CLSID} = "Yahoo! Toolbar"
InProcServer32(Default) = "C:Program FilesYahoo!CompanionInstallscpn0yt.dll" ["Yahoo! Inc."]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"
-> {HKLM...CLSID} = "Winamp Toolbar"
InProcServer32(Default) = "C:Program FilesWinamp Toolbarwinamptb.dll" ["AOL LLC"]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"
-> {HKLM...CLSID} = "Ask Toolbar"
InProcServer32(Default) = "C:Program FilesAskSBarbar1.binASKSBAR.DLL" ["Ask.com"]

HKLMSOFTWAREMicrosoftInternet ExplorerToolbar
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = (no title provided)
-> {HKLM...CLSID} = "Yahoo! Toolbar"
InProcServer32(Default) = "C:Program FilesYahoo!CompanionInstallscpn0yt.dll" ["Yahoo! Inc."]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}" = "Winamp Toolbar"
-> {HKLM...CLSID} = "Winamp Toolbar"
InProcServer32(Default) = "C:Program FilesWinamp Toolbarwinamptb.dll" ["AOL LLC"]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}" = (no title provided)
-> {HKLM...CLSID} = "Ask Toolbar"
InProcServer32(Default) = "C:Program FilesAskSBarbar1.binASKSBAR.DLL" ["Ask.com"]

Explorer Bars

HKLMSOFTWAREMicrosoftInternet ExplorerExplorer Bars

HKLMSOFTWAREClassesCLSID{51085E3D-A958-42A2-A6BE-A6A9B0BAF276}(Default) = "BT Yahoo! Sidebar"
Implemented Categories{00021493-0000-0000-C000-000000000046} [vertical bar]
InProcServer32(Default) = "C:Program FilesYahoo!browserysidebarIE.dll" ["Yahoo! Inc."]

HKLMSOFTWAREClassesCLSID{E7A829CC-671F-4C3D-B590-8C0AEA72E6B2}(Default) = "BitComet Search"
Implemented Categories{00021493-0000-0000-C000-000000000046} [vertical bar]
InProcServer32(Default) = "C:Program FilesBitComettoolsBitCometBHO_1.1.7.4.dll" ["BitComet"]

Extensions (Tools menu items, main toolbar menu buttons)

HKLMSOFTWAREMicrosoftInternet ExplorerExtensions
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}"
-> {HKCU...CLSID} = "Java Plug-in 1.6.0_02"
InProcServer32(Default) = "C:Program FilesJavajre1.6.0_02binssv.dll" ["Sun Microsystems, Inc."]
-> {HKLM...CLSID} = "Java Plug-in 1.6.0_02"
InProcServer32(Default) = "C:Program FilesJavajre1.6.0_02binnpjpi160_02.dll" ["Sun Microsystems, Inc."]

{461CC20B-FB6E-4F16-8FE8-C29359DB100E}
"ButtonText" = "BitComet Search"

{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}
"ButtonText" = "BT Yahoo! Services"
"CLSIDExtension" = "{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}"
-> {HKLM...CLSID} = "Yahoo! IE Services Button"
InProcServer32(Default) = "C:PROGRA~1Yahoo!Commonyiesrvc.dll" ["Yahoo! Inc."]


Miscellaneous IE Hijack Points
------------------------------

HKCUSoftwareMicrosoftInternet ExplorerURLSearchHooks
<<H>> "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = (no title provided)
-> {HKLM...CLSID} = "Yahoo! Toolbar"
InProcServer32(Default) = "C:Program FilesYahoo!CompanionInstallscpn0yt.dll" ["Yahoo! Inc."]


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

Ati HotKey Poller, Ati HotKey Poller, "C:WINDOWSsystem32Ati2evxx.exe" ["ATI Technologies Inc."]
avast! Antivirus, avast! Antivirus, ""C:Program FilesAlwil SoftwareAvast4ashServ.exe"" ["ALWIL Software"]
avast! iAVS4 Control Service, aswUpdSv, ""C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe"" ["ALWIL Software"]
avast! Mail Scanner, avast! Mail Scanner, ""C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service" ["ALWIL Software"]
avast! Web Scanner, avast! Web Scanner, ""C:Program FilesAlwil SoftwareAvast4ashWebSv.exe" /service" ["ALWIL Software"]
Machine Debug Manager, MDM, ""C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE"" [MS]
ServiceLayer, ServiceLayer, ""C:Program FilesCommon FilesPCSuiteServicesServiceLayer.exe"" ["Nokia."]
sgSchedulerService, sgSchedulerService, "C:Program FilesSystemGuards.comSystemGuardssgScheduleService.exe" [null data]
Urządzenie mobilne Apple, Apple Mobile Device, ""C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe"" ["Apple, Inc."]


---------- (launch time: 2008-04-04 22:17:15)
<<!>>: Suspicious data at a malware launch point.
<<H>>: Suspicious data at a browser hijack point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 150 seconds.
---------- (total run time: 233 seconds)
[ /code]
Cytat: O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - CTonguerogram FilesAskSBarbar1.binASKSBAR.DLL
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - CTonguerogram Files AskSBar bar1.binASKSBAR.DLL
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)


Skasuj pogrubiony folder ręcznie z dysku w trybie awaryjnym i wyłączonym przywracaniem systemu, wpisy skasuj w hijacku.

Zastosuj

[Aby zobaczyć linki, zarejestruj się tutaj]

opcja nr 2

Po zabiegach dajesz nowe logi z hijacka,

[Aby zobaczyć linki, zarejestruj się tutaj]

oraz raport ze smitfraudfix
Dzięki Martinez,

Zrobiłam, jak radziłeś. Kupa syfu była.

Nowe logi po skanie:

Kod:
Logfile of HijackThis v1.99.1
Scan saved at 14:29:53, on 2008-04-05
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:Program FilesSystemGuards.comSystemGuardssgScheduleService.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:Program FilesNokiaNokia Software LauncherNSLauncher.exe
C:Program FilesJavajre1.6.0_02binjusched.exe
C:Program FilesCommon FilesRealUpdate_OBrealsched.exe
C:Program FilesCommon FilesPCSuiteServicesServiceLayer.exe
C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe
C:WINDOWSsystem32ctfmon.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe
C:Program FilesKodakKodak EasyShare softwarebinEasyShare.exe
C:Program FilesAdobeReader 8.0ReaderAcroRd32.exe
C:Program FilesOperaOpera.exe
D:instalkiHJHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.onet.pl/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sp/*http://uk.search.yahoo.com/
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = 127.0.0.1
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:Program FilesWinamp Toolbarwinamptb.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:Program FilesBitComettoolsBitCometBHO_1.1.7.4.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:PROGRA~1Yahoo!Commonyiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_02binssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:Program FilesAskSBarbar1.binASKSBAR.DLL
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:Program FilesYahoo!browserYSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:Program FilesWinamp Toolbarwinamptb.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:Program FilesAskSBarbar1.binASKSBAR.DLL
O4 - HKLM..Run: [NSLauncher] C:Program FilesNokiaNokia Software LauncherNSLauncher.exe /startup
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.6.0_02binjusched.exe"
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [Onet.pl AutoUpdate] "C:Program FilesCommon FilesOnet.plAutoUpdate.exe" /tsr
O4 - HKLM..Run: [System Guards] C:Program FilesSystemGuards.comSystemGuardsSysGuards.exe
O4 - HKLM..Run: [TkBellExe] "C:Program FilesCommon FilesRealUpdate_OBrealsched.exe"-osboot
O4 - HKLM..Run: [avgnt] "C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe" /min
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [AdobeUpdater] C:Program FilesCommon FilesAdobeUpdater5AdobeUpdater.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe
O4 - Global Startup: Oprogramowanie Kodak EasyShare.lnk = C:Program FilesKodakKodak EasyShare softwarebinEasyShare.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:Program FilesBitCometBitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:Program FilesBitCometBitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:Program FilesBitCometBitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Winamp Toolbar Search - C:Documents and SettingsAll UsersDane aplikacjiWinamp ToolbarieToolbarresourcesen-USlocalsearch.html
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_02binssv.dll
O9 - Extra ''Tools'' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_02binssv.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:Program FilesBitComettoolsBitCometBHO_1.1.7.4.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:PROGRA~1Yahoo!Commonyiesrvc.dll
O15 - Trusted Zone: http://www.mks.com.pl
O15 - Trusted Zone: http://bezpieczenstwo.onet.pl
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:Program FilesYahoo!commonyinsthelper.dll
O16 - DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} (MainControl Class) - http://slimak.onet.pl/_m/wirusy/ArcaOnline.cab
O16 - DPF: {5A09E43F-A0A7-4ABF-AF80-11367CF1DC8F} - http://mks.com.pl/skaner/SkanerOnline.cab
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} - http://www.mks.com.pl/skaner/SkanerOnline.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:WINDOWSsystem32WPDShServiceObj.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
O23 - Service: Urządzenie mobilne Apple (Apple Mobile Device) - Apple, Inc. - C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:Program FilesSpyware Doctorsvcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:Program FilesSpyware Doctorswdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:Program FilesCommon FilesPCSuiteServicesServiceLayer.exe
O23 - Service: sgSchedulerService - Unknown owner - C:Program FilesSystemGuards.comSystemGuardssgScheduleService.exe
O23 - Service: YPCService - Yahoo! Inc. - C:WINDOWSsystem32YPCSER~1.EXE


Kod:
"Silent Runners.vbs", revision 56, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCUSoftwareMicrosoftWindowsCurrentVersionRun {++}
"ctfmon.exe" = "C:WINDOWSsystem32ctfmon.exe" [MS]
"AdobeUpdater" = "C:Program FilesCommon FilesAdobeUpdater5AdobeUpdater.exe" ["Adobe Systems Incorporated"]

HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun {++}
"NSLauncher" = "C:Program FilesNokiaNokia Software LauncherNSLauncher.exe /startup" [null data]
"Adobe Reader Speed Launcher" = ""C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"" ["Adobe Systems Incorporated"]
"SunJavaUpdateSched" = ""C:Program FilesJavajre1.6.0_02binjusched.exe"" ["Sun Microsystems, Inc."]
"QuickTime Task" = ""C:Program FilesQuickTimeqttask.exe" -atboottime" ["Apple Inc."]
"Onet.pl AutoUpdate" = ""C:Program FilesCommon FilesOnet.plAutoUpdate.exe" /tsr" [file not found]
"System Guards" = "C:Program FilesSystemGuards.comSystemGuardsSysGuards.exe" ["SystemGuards.com"]
"TkBellExe" = ""C:Program FilesCommon FilesRealUpdate_OBrealsched.exe"-osboot" ["RealNetworks, Inc."]
"avgnt" = ""C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe" /min" ["Avira GmbH"]

HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects
{02478D38-C3F9-4EFB-9B51-7695ECA05670}(Default) = (no title provided)
-> {HKLM...CLSID} = "Yahoo! Toolbar Helper"
InProcServer32(Default) = "C:Program FilesYahoo!CompanionInstallscpn0yt.dll" ["Yahoo! Inc."]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = (no title provided)
-> {HKLM...CLSID} = "Adobe PDF Reader Link Helper"
InProcServer32(Default) = "C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll" ["Adobe Systems Incorporated"]
{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}(Default) = "Winamp Toolbar BHO"
-> {HKLM...CLSID} = "Winamp Toolbar BHO"
InProcServer32(Default) = "C:Program FilesWinamp Toolbarwinamptb.dll" ["AOL LLC"]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}(Default) = "BitComet ClickCapture"
-> {HKLM...CLSID} = "BitComet Helper"
InProcServer32(Default) = "C:Program FilesBitComettoolsBitCometBHO_1.1.7.4.dll" ["BitComet"]
{53707962-6F74-2D53-2644-206D7942484F}(Default) = (no title provided)
-> {HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "C:PROGRA~1SPYBOT~1SDHelper.dll" ["Safer Networking Limited"]
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}(Default) = (no title provided)
-> {HKLM...CLSID} = "Yahoo! IE Services Button"
InProcServer32(Default) = "C:PROGRA~1Yahoo!Commonyiesrvc.dll" ["Yahoo! Inc."]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}(Default) = (no title provided)
-> {HKLM...CLSID} = "SSVHelper Class"
InProcServer32(Default) = "C:Program FilesJavajre1.6.0_02binssv.dll" ["Sun Microsystems, Inc."]
{9030D464-4C02-4ABF-8ECC-5164760863C6}(Default) = (no title provided)
-> {HKLM...CLSID} = "Windows Live Sign-in Helper"
InProcServer32(Default) = "C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll" [MS]
{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}(Default) = "Ask Toolbar BHO"
-> {HKLM...CLSID} = "Ask Toolbar BHO"
InProcServer32(Default) = "C:Program FilesAskSBarbar1.binASKSBAR.DLL" ["Ask.com"]
{F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D}(Default) = (no title provided)
-> {HKLM...CLSID} = "SidebarAutoLaunch Class"
InProcServer32(Default) = "C:Program FilesYahoo!browserYSidebarIEBHO.dll" ["Yahoo! Inc."]

HKLMSOFTWAREMicrosoftWindowsCurrentVersionShell ExtensionsApproved
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
-> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
InProcServer32(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
InProcServer32(Default) = "C:WINDOWSSystem32hticons.dll" ["Hilgraeve, Inc."]
"{2F603045-309F-11CF-9774-0020AFD0CFF6}" = "Synaptics Control Panel"
-> {HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "C:Program FilesSynapticsSynTPSynTPCpl.dll" ["Synaptics, Inc."]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
-> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook"
InProcServer32(Default) = "C:Program FilesMicrosoft OfficeOffice10OLKFSTUB.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM...CLSID} = (no title provided)
InProcServer32(Default) = "C:Program FilesMicrosoft OfficeOffice10msohev.dll" [MS]
"{20082881-FC36-4E47-9A7A-644C95FF749F}" = "IntelliPoint Wireless Control Panel Property Page"
-> {HKLM...CLSID} = "Wireless Property Page"
InProcServer32(Default) = ""C:Program FilesMicrosoft IntelliPointipcplwir.dll"" [MS]
"{AF90F543-6A3A-4C1B-8B16-ECEC073E69BE}" = "IntelliPoint Wheel Control Panel Property Page"
-> {HKLM...CLSID} = "Wheel Property Page"
InProcServer32(Default) = ""C:Program FilesMicrosoft IntelliPointipcplwhl.dll"" [MS]
"{653DCCC2-13DB-45B2-A389-427885776CFE}" = "IntelliPoint Activities Control Panel Property Page"
-> {HKLM...CLSID} = "Activities Property Page"
InProcServer32(Default) = ""C:Program FilesMicrosoft IntelliPointipcplact.dll"" [MS]
"{124597D8-850A-41AE-849C-017A4FA99CA2}" = "IntelliPoint Buttons Control Panel Property Page"
-> {HKLM...CLSID} = "Buttons Property Page"
InProcServer32(Default) = ""C:Program FilesMicrosoft IntelliPointipcplbtn.dll"" [MS]
"{400CFEE2-39D0-46DC-96DF-E0BB5A4324B3}" = "My Labtec Pictures"
-> {HKLM...CLSID} = "My Labtec Pictures"
InProcServer32(Default) = "C:Program FilesLogitechVideoNamespc2.dll" ["Labtec Inc."]
"{E0D79300-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM...CLSID} = "WinZip"
InProcServer32(Default) = "C:PROGRA~1WinZipwzshlext.dll" [null data]
"{E0D79301-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM...CLSID} = "WinZip"
InProcServer32(Default) = "C:PROGRA~1WinZipwzshlext.dll" [null data]
"{E0D79302-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM...CLSID} = "WinZip"
InProcServer32(Default) = "C:PROGRA~1WinZipwzshlext.dll" [null data]
"{B327765E-D724-4347-8B16-78AE18552FC3}" = "NeroDigitalIconHandler"
-> {HKLM...CLSID} = "NeroDigitalIconHandler Class"
InProcServer32(Default) = "C:Program FilesCommon FilesAheadlibNeroDigitalExt.dll" ["Nero AG"]
"{7F1CF152-04F8-453A-B34C-E609530A9DC8}" = "NeroDigitalPropSheetHandler"
-> {HKLM...CLSID} = "NeroDigitalPropSheetHandler Class"
InProcServer32(Default) = "C:Program FilesCommon FilesAheadlibNeroDigitalExt.dll" ["Nero AG"]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {HKLM...CLSID} = "RealOne Player Context Menu Class"
InProcServer32(Default) = "C:Program FilesRealRealPlayerrpshell.dll" ["RealNetworks, Inc."]
"{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}" = "PowerISO"
-> {HKLM...CLSID} = "PowerISO"
InProcServer32(Default) = "C:Program FilesPowerISOPWRISOSH.DLL" ["PowerISO Computing, Inc."]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]
"{5464D816-CF16-4784-B9F3-75C0DB52B499}" = "Yahoo! Mail"
-> {HKLM...CLSID} = "YMailShellExt Class"
InProcServer32(Default) = "C:PROGRA~1Yahoo!Commonymmapi.dll" ["Yahoo! Inc."]
"{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"
-> {HKLM...CLSID} = "Moje foldery udostępniania"
InProcServer32(Default) = "C:Program FilesMSN Messengerfsshext.8.1.0178.00.dll" [MS]
"{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A}" = "PhoneBrowser"
-> {HKLM...CLSID} = "Nokia Phone Browser"
InProcServer32(Default) = "C:Program FilesNokiaNokia PC Suite 6PhoneBrowser.dll" ["Nokia"]
"{45AC2688-0253-4ED8-97DE-B5370FA7D48A}" = "Shell Extension for Malware scanning"
-> {HKLM...CLSID} = "Shell Extension for Malware scanning"
InProcServer32(Default) = "C:Program FilesAviraAntiVir PersonalEdition Classicshlext.dll" ["Avira GmbH"]

HKLMSOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad
"WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
-> {HKLM...CLSID} = "WPDShServiceObj Class"
InProcServer32(Default) = "C:WINDOWSsystem32WPDShServiceObj.dll" [MS]

HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotify
<<!>> AtiExtEventDLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]

HKLMSOFTWAREClassesFoldershellexColumnHandlers
{7D4D6379-F301-4311-BEBA-E26EB0561882}(Default) = "NeroDigitalExt.NeroDigitalColumnHandler"
-> {HKLM...CLSID} = "NeroDigitalColumnHandler Class"
InProcServer32(Default) = "C:Program FilesCommon FilesAheadlibNeroDigitalExt.dll" ["Nero AG"]
{F9DB5320-233E-11D1-9F84-707F02C10627}(Default) = "PDF Column Info"
-> {HKLM...CLSID} = "PDF Shell Extension"
InProcServer32(Default) = "C:Program FilesCommon FilesAdobeAcrobatActiveXPDFShell.dll" ["Adobe Systems, Inc."]

HKLMSOFTWAREClasses*shellexContextMenuHandlers
PowerISO(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"
-> {HKLM...CLSID} = "PowerISO"
InProcServer32(Default) = "C:Program FilesPowerISOPWRISOSH.DLL" ["PowerISO Computing, Inc."]
Shell Extension for Malware scanning(Default) = "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}"
-> {HKLM...CLSID} = "Shell Extension for Malware scanning"
InProcServer32(Default) = "C:Program FilesAviraAntiVir PersonalEdition Classicshlext.dll" ["Avira GmbH"]
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]
WinZip(Default) = "{E0D79300-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
InProcServer32(Default) = "C:PROGRA~1WinZipwzshlext.dll" [null data]
Yahoo! Mail(Default) = "{5464D816-CF16-4784-B9F3-75C0DB52B499}"
-> {HKLM...CLSID} = "YMailShellExt Class"
InProcServer32(Default) = "C:PROGRA~1Yahoo!Commonymmapi.dll" ["Yahoo! Inc."]

HKLMSOFTWAREClassesDirectoryshellexContextMenuHandlers
PowerISO(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"
-> {HKLM...CLSID} = "PowerISO"
InProcServer32(Default) = "C:Program FilesPowerISOPWRISOSH.DLL" ["PowerISO Computing, Inc."]
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]
WinZip(Default) = "{E0D79300-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
InProcServer32(Default) = "C:PROGRA~1WinZipwzshlext.dll" [null data]

HKLMSOFTWAREClassesFoldershellexContextMenuHandlers
PowerISO(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"
-> {HKLM...CLSID} = "PowerISO"
InProcServer32(Default) = "C:Program FilesPowerISOPWRISOSH.DLL" ["PowerISO Computing, Inc."]
Shell Extension for Malware scanning(Default) = "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}"
-> {HKLM...CLSID} = "Shell Extension for Malware scanning"
InProcServer32(Default) = "C:Program FilesAviraAntiVir PersonalEdition Classicshlext.dll" ["Avira GmbH"]
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]
WinZip(Default) = "{E0D79300-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
InProcServer32(Default) = "C:PROGRA~1WinZipwzshlext.dll" [null data]


Group Policies {GPedit.msc branch and setting}:
-----------------------------------------------

Note: detected settings may not have any effect.

HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesSystem

"shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) dword:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop may be disabled at this entry:
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCUSoftwareMicrosoftInternet ExplorerDesktopGeneral
"Wallpaper" = "C:WINDOWSsystem32configsystemprofileUstawienia lokalneDane aplikacjiMicrosoftWallpaper1.bmp"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCUControl PanelDesktop
"Wallpaper" = "C:Documents and SettingsDominikaUstawienia lokalneDane aplikacjiMicrosoftWallpaper1.bmp"


Startup items in "Dominika" & "All Users" startup folders:
----------------------------------------------------------

C:Documents and SettingsAll UsersMenu StartProgramyAutostart
"KODAK Software Updater" -> shortcut to: "C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe" [null data]
"Oprogramowanie Kodak EasyShare" -> shortcut to: "C:Program FilesKodakKodak EasyShare softwarebinEasyShare.exe -hx" ["Eastman Kodak Company"]


Enabled Scheduled Tasks:
------------------------

"AppleSoftwareUpdate" -> launches: "C:Program FilesApple Software UpdateSoftwareUpdate.exe -task" ["Apple Inc."]
"Norton Security Scan" -> launches: "C:Program FilesNorton Security ScanNss.exe /scan-full /scheduled" ["Symantec Corporation"]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLMSYSTEMCurrentControlSetServicesWinsock2ParametersNameSpace_Catalog5Catalog_Entries {++}
000000000001LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]
000000000002LibraryPath = "%SystemRoot%System32winrnr.dll" [MS]
000000000003LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]

Transport Service Providers

HKLMSYSTEMCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_Entries {++}
0000000000##PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%system32mswsock.dll [MS], 01 - 03, 06 - 17
%SystemRoot%system32rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
------------------------------------

Toolbars

HKCUSoftwareMicrosoftInternet ExplorerToolbarWebBrowser
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
-> {HKLM...CLSID} = "Yahoo! Toolbar"
InProcServer32(Default) = "C:Program FilesYahoo!CompanionInstallscpn0yt.dll" ["Yahoo! Inc."]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"
-> {HKLM...CLSID} = "Winamp Toolbar"
InProcServer32(Default) = "C:Program FilesWinamp Toolbarwinamptb.dll" ["AOL LLC"]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"
-> {HKLM...CLSID} = "Ask Toolbar"
InProcServer32(Default) = "C:Program FilesAskSBarbar1.binASKSBAR.DLL" ["Ask.com"]

HKLMSOFTWAREMicrosoftInternet ExplorerToolbar
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = (no title provided)
-> {HKLM...CLSID} = "Yahoo! Toolbar"
InProcServer32(Default) = "C:Program FilesYahoo!CompanionInstallscpn0yt.dll" ["Yahoo! Inc."]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}" = "Winamp Toolbar"
-> {HKLM...CLSID} = "Winamp Toolbar"
InProcServer32(Default) = "C:Program FilesWinamp Toolbarwinamptb.dll" ["AOL LLC"]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}" = (no title provided)
-> {HKLM...CLSID} = "Ask Toolbar"
InProcServer32(Default) = "C:Program FilesAskSBarbar1.binASKSBAR.DLL" ["Ask.com"]

Explorer Bars

HKLMSOFTWAREMicrosoftInternet ExplorerExplorer Bars

HKLMSOFTWAREClassesCLSID{51085E3D-A958-42A2-A6BE-A6A9B0BAF276}(Default) = "BT Yahoo! Sidebar"
Implemented Categories{00021493-0000-0000-C000-000000000046} [vertical bar]
InProcServer32(Default) = "C:Program FilesYahoo!browserysidebarIE.dll" ["Yahoo! Inc."]

HKLMSOFTWAREClassesCLSID{E7A829CC-671F-4C3D-B590-8C0AEA72E6B2}(Default) = "BitComet Search"
Implemented Categories{00021493-0000-0000-C000-000000000046} [vertical bar]
InProcServer32(Default) = "C:Program FilesBitComettoolsBitCometBHO_1.1.7.4.dll" ["BitComet"]

Extensions (Tools menu items, main toolbar menu buttons)

HKLMSOFTWAREMicrosoftInternet ExplorerExtensions
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}"
-> {HKCU...CLSID} = "Java Plug-in 1.6.0_02"
InProcServer32(Default) = "C:Program FilesJavajre1.6.0_02binssv.dll" ["Sun Microsystems, Inc."]
-> {HKLM...CLSID} = "Java Plug-in 1.6.0_02"
InProcServer32(Default) = "C:Program FilesJavajre1.6.0_02binnpjpi160_02.dll" ["Sun Microsystems, Inc."]

{461CC20B-FB6E-4F16-8FE8-C29359DB100E}
"ButtonText" = "BitComet Search"

{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}
"ButtonText" = "BT Yahoo! Services"
"CLSIDExtension" = "{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}"
-> {HKLM...CLSID} = "Yahoo! IE Services Button"
InProcServer32(Default) = "C:PROGRA~1Yahoo!Commonyiesrvc.dll" ["Yahoo! Inc."]


Miscellaneous IE Hijack Points
------------------------------

HKCUSoftwareMicrosoftInternet ExplorerURLSearchHooks
<<H>> "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = "*_" (unwritable string)
-> {HKLM...CLSID} = "Yahoo! Toolbar"
InProcServer32(Default) = "C:Program FilesYahoo!CompanionInstallscpn0yt.dll" ["Yahoo! Inc."]


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

AntiVir PersonalEdition Classic Guard, AntiVirService, ""C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe"" ["Avira GmbH"]
AntiVir PersonalEdition Classic Scheduler, AntiVirScheduler, ""C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe"" ["Avira GmbH"]
Ati HotKey Poller, Ati HotKey Poller, "C:WINDOWSsystem32Ati2evxx.exe" ["ATI Technologies Inc."]
Machine Debug Manager, MDM, ""C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE"" [MS]
ServiceLayer, ServiceLayer, ""C:Program FilesCommon FilesPCSuiteServicesServiceLayer.exe"" ["Nokia."]
sgSchedulerService, sgSchedulerService, "C:Program FilesSystemGuards.comSystemGuardssgScheduleService.exe" [null data]
Urządzenie mobilne Apple, Apple Mobile Device, ""C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe"" ["Apple, Inc."]


---------- (launch time: 2008-04-05 14:30:10)
<<!>>: Suspicious data at a malware launch point.
<<H>>: Suspicious data at a browser hijack point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 136 seconds.
---------- (total run time: 202 seconds)
Cytat: O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - CTonguerogram FilesAskSBarbar1.binASKSBAR.DLL
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - CTonguerogram Files AskSBar bar1.binASKSBAR.DLL
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)


Skasuj pogrubiony folder ręcznie z dysku w trybie awaryjnym i wyłączonym przywracaniem systemu, wpisy skasuj w hijacku.

Zastosuj

[Aby zobaczyć linki, zarejestruj się tutaj]

opcja nr 2

Po zabiegach dajesz nowe logi z hijacka,

[Aby zobaczyć linki, zarejestruj się tutaj]

oraz raport ze smitfraudfix
bodek napisał(a):Zastosuj

[Aby zobaczyć linki, zarejestruj się tutaj]

opcja nr 2


Czy powyższą czynność mam wykonać również w awaryjnym?
Dominatrix napisał(a):
bodek napisał(a):Zastosuj

[Aby zobaczyć linki, zarejestruj się tutaj]

opcja nr 2


Czy powyższą czynność mam wykonać również w awaryjnym?


Tak
Kod:
Logfile of HijackThis v1.99.1
Scan saved at 21:35:09, on 2008-04-05
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:Program FilesNokiaNokia Software LauncherNSLauncher.exe
C:Program FilesJavajre1.6.0_02binjusched.exe
C:Program FilesCommon FilesRealUpdate_OBrealsched.exe
C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:Program FilesSystemGuards.comSystemGuardssgScheduleService.exe
C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe
C:Program FilesKodakKodak EasyShare softwarebinEasyShare.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesPCSuiteServicesServiceLayer.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesOperaOpera.exe
D:instalkiHJHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.onet.pl/
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = 127.0.0.1
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:Program FilesWinamp Toolbarwinamptb.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:Program FilesBitComettoolsBitCometBHO_1.1.7.4.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:PROGRA~1Yahoo!Commonyiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_02binssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:Program FilesYahoo!browserYSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:Program FilesWinamp Toolbarwinamptb.dll
O4 - HKLM..Run: [NSLauncher] C:Program FilesNokiaNokia Software LauncherNSLauncher.exe /startup
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.6.0_02binjusched.exe"
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [Onet.pl AutoUpdate] "C:Program FilesCommon FilesOnet.plAutoUpdate.exe" /tsr
O4 - HKLM..Run: [System Guards] C:Program FilesSystemGuards.comSystemGuardsSysGuards.exe
O4 - HKLM..Run: [TkBellExe] "C:Program FilesCommon FilesRealUpdate_OBrealsched.exe"-osboot
O4 - HKLM..Run: [avgnt] "C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe" /min
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [AdobeUpdater] C:Program FilesCommon FilesAdobeUpdater5AdobeUpdater.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe
O4 - Global Startup: Oprogramowanie Kodak EasyShare.lnk = C:Program FilesKodakKodak EasyShare softwarebinEasyShare.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:Program FilesBitCometBitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:Program FilesBitCometBitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:Program FilesBitCometBitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Winamp Toolbar Search - C:Documents and SettingsAll UsersDane aplikacjiWinamp ToolbarieToolbarresourcesen-USlocalsearch.html
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_02binssv.dll
O9 - Extra ''Tools'' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_02binssv.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:Program FilesBitComettoolsBitCometBHO_1.1.7.4.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:PROGRA~1Yahoo!Commonyiesrvc.dll
O15 - Trusted Zone: http://www.mks.com.pl
O15 - Trusted Zone: http://bezpieczenstwo.onet.pl
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:Program FilesYahoo!commonyinsthelper.dll
O16 - DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} (MainControl Class) - http://slimak.onet.pl/_m/wirusy/ArcaOnline.cab
O16 - DPF: {5A09E43F-A0A7-4ABF-AF80-11367CF1DC8F} - http://mks.com.pl/skaner/SkanerOnline.cab
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} - http://www.mks.com.pl/skaner/SkanerOnline.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:WINDOWSsystem32WPDShServiceObj.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
O23 - Service: Urządzenie mobilne Apple (Apple Mobile Device) - Apple, Inc. - C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:Program FilesSpyware Doctorsvcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:Program FilesSpyware Doctorswdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:Program FilesCommon FilesPCSuiteServicesServiceLayer.exe
O23 - Service: sgSchedulerService - Unknown owner - C:Program FilesSystemGuards.comSystemGuardssgScheduleService.exe
O23 - Service: YPCService - Yahoo! Inc. - C:WINDOWSsystem32YPCSER~1.EXE


Kod:
ComboFix 08-04-04.1 - Dominika 2008-04-05 21:38:01.1 - NTFSx86
Microsoft Windows XP Professional5.1.2600.2.1250.1.1045.18.97 [GMT 1:00]
Running from: D:instalkiCombofixComboFix.exe

[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.

((((((((((((((((((((((((( Files Created from 2008-03-05 to 2008-04-05)))))))))))))))))))))))))))))))
.

2008-04-05 20:44 . 2008-04-05 21:16    2,546    --a------    C:WINDOWSsystem32tmp.reg
2008-04-05 19:01 . 2006-02-08 10:05    <DIR>    d--h-----    C:Documents and SettingsAdministratorUstawienia lokalne
2008-04-05 19:01 . 2006-02-08 10:05    <DIR>    d--------    C:Documents and SettingsAdministratorUlubione
2008-04-05 19:01 . 2006-02-08 11:15    <DIR>    d--h-----    C:Documents and SettingsAdministratorSzablony
2008-04-05 19:01 . 2006-02-08 10:05    <DIR>    d--------    C:Documents and SettingsAdministratorPulpit
2008-04-05 19:01 . 2006-02-08 10:05    <DIR>    d--------    C:Documents and SettingsAdministratorMoje dokumenty
2008-04-05 19:01 . 2006-02-08 10:05    <DIR>    dr-------    C:Documents and SettingsAdministratorMenu Start
2008-04-05 19:01 . 2007-10-05 00:05    <DIR>    dr-h-----    C:Documents and SettingsAdministratorDane aplikacji
2008-04-05 11:40 . 2008-04-05 11:40    <DIR>    d--------    C:Program FilesAvira
2008-04-05 11:40 . 2008-04-05 11:40    <DIR>    d--------    C:Documents and SettingsAll UsersDane aplikacjiAvira
2008-03-21 14:14 . 2008-03-21 14:15    <DIR>    d--------    C:Program FilesOpera
2008-03-18 18:34 . 2008-03-18 18:34    172    --ah-----    C:sqmnoopt05.sqm
2008-03-18 18:34 . 2008-03-18 18:34    172    --ah-----    C:sqmdata05.sqm
2008-03-18 18:18 . 2008-03-18 18:18    268    --ah-----    C:sqmdata04.sqm
2008-03-18 18:18 . 2008-03-18 18:18    244    --ah-----    C:sqmnoopt04.sqm
2008-03-16 06:43 . 2008-03-16 06:53    <DIR>    d--------    C:Program FilesFlashGet
2008-03-16 06:43 . 2006-04-20 12:51    359,808    --a------    C:WINDOWSsystem32driverstcpip.sys.flg
2008-03-16 05:49 . 2008-03-16 05:50    4,932,385    --a------    C:TempFreeYouTubeToiPodConverter.exe
2008-03-05 18:07 . 2008-03-16 05:51    <DIR>    d--------    C:Program FilesDVDVideoSoft
2008-03-05 18:06 . 2008-03-05 18:07    7,219,355    --a------    C:TempFreeVideoToiPodConverter.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-04 14:47    ---------    d-----w    C:Program FileseMule
2008-04-04 14:00    ---------    d-----w    C:Program FilesNorton Security Scan
2008-03-30 14:11    ---------    d-----w    C:Documents and SettingsDominikaDane aplikacjiSkype
2008-03-16 04:51    ---------    d-----w    C:Program FilesCommon FilesDVDVideoSoft
2008-03-14 21:18    ---------    d-----w    C:Program FilesWindows Media Connect 2
2008-03-02 10:15    ---------    d-----w    C:Program FilesCommon FilesSymantec Shared
2008-02-23 22:05    ---------    d-----w    C:Program FilesCommon FilesReal
2008-02-16 16:20    ---------    d-----w    C:Program FilesSystemGuards.com
2008-02-16 15:37    ---------    d-----w    C:Program FilesMediafour
2008-02-16 06:03    ---------    d-----w    C:Documents and SettingsDominikaDane aplikacjiWinamp
2008-02-16 05:50    ---------    d-----w    C:Program FilesWinamp Toolbar
2008-02-16 05:50    ---------    d-----w    C:Documents and SettingsAll UsersDane aplikacjiWinamp Toolbar
2008-02-16 05:31    ---------    d-----w    C:Program FilesWinamp
2008-02-06 19:20    ---------    d-----w    C:Program FilesSopCast
2008-02-06 19:18    ---------    d-----w    C:Documents and SettingsDominikaDane aplikacjiSopCast
2007-12-21 16:39    34,624    ----a-w    C:Documents and SettingsDominikaDane aplikacjiGDIPFONTCACHEV1.DAT
2006-02-08 10:47    0    ----a-w    C:Documents and SettingsDominikaDane aplikacjiwklnhst.dat
2004-10-01 14:00    40,960    ----a-w    C:Program FilesUninstall_CDS.exe
2006-09-11 12:19    14    --sh--w    C:WINDOWSmswtpdxp.dll
2006-09-23 16:35    21    --sh--w    C:WINDOWSprwttrxp.dll
2006-09-11 12:19    21    --sh--w    C:WINDOWSsystem32dpwttaxp.dll
2006-09-11 12:19    14    --sh--w    C:WINDOWSsystem32mswtpaxp.dll
2006-09-23 16:35    2    --sh--w    C:WINDOWSsystem32verwttxp.dll
.

------- Sigcheck -------

2006-01-13 18:073604485562cc0a47b2aef06d3417b733f3c195    C:WINDOWS$hf_mig$KB913446SP2QFEtcpip.sys
2006-04-20 13:18360576b2220c618b42a2212a59d91ebd6fc4b4    C:WINDOWS$hf_mig$KB917953SP2QFEtcpip.sys
2001-08-18 07:24327168e7774698bb0d14b0710a9a31e209f9b6    C:WINDOWS$NtServicePackUninstall$tcpip.sys
2004-08-03 23:143590409f4b36614a0fc234525ba224957de55c    C:WINDOWS$NtUninstallKB913446$tcpip.sys
2006-01-13 03:28359808583e063fdc888ca30d05c2724b0d7ef4    C:WINDOWS$NtUninstallKB917953$tcpip.sys
2004-08-03 23:143590409f4b36614a0fc234525ba224957de55c    C:WINDOWSServicePackFilesi386tcpip.sys
2006-04-20 12:513598081dbf125862891817f374f407626967f4    C:WINDOWSsystem32dllcachetcpip.sys
2006-04-20 12:51359808b4e29943b4b04bd5e7381546848e6669    C:WINDOWSsystem32driverstcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE~Browser Helper Objects{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-12-13 17:49    1185120    --a------    C:Program FilesWinamp Toolbarwinamptb.dll

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= "C:Program FilesWinamp Toolbarwinamptb.dll" [2007-12-13 17:49 1185120]

[HKEY_CLASSES_ROOTclsid{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOTWINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOTTypeLib{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOTWINAMPTB.AOLToolBand]

[HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerToolbarWebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:Program FilesWinamp Toolbarwinamptb.dll [2007-12-13 17:49 1185120]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:Program FilesAskSBarbar1.binASKSBAR.DLL [ ]

[HKEY_CLASSES_ROOTclsid{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOTWINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOTTypeLib{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOTWINAMPTB.AOLToolBand]

[HKEY_CLASSES_ROOTclsid{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]

[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"ctfmon.exe"="C:WINDOWSsystem32ctfmon.exe" [2004-08-04 00:44 15360]
"AdobeUpdater"="C:Program FilesCommon FilesAdobeUpdater5AdobeUpdater.exe" [2007-03-01 10:37 2321600]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"NSLauncher"="C:Program FilesNokiaNokia Software LauncherNSLauncher.exe" [2006-11-28 01:12 2658304]
"Adobe Reader Speed Launcher"="C:Program FilesAdobeReader 8.0ReaderReader_sl.exe" [2007-05-11 03:06 40048]
"SunJavaUpdateSched"="C:Program FilesJavajre1.6.0_02binjusched.exe" [2007-07-12 04:00 132496]
"QuickTime Task"="C:Program FilesQuickTimeqttask.exe" [2007-12-11 11:56 286720]
"Onet.pl AutoUpdate"="C:Program FilesCommon FilesOnet.plAutoUpdate.exe" [ ]
"System Guards"="C:Program FilesSystemGuards.comSystemGuardsSysGuards.exe" [2007-11-08 17:07 638976]
"TkBellExe"="C:Program FilesCommon FilesRealUpdate_OBrealsched.exe" [2008-02-23 23:04 185896]
"avgnt"="C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe" [2008-04-05 12:00 249896]

[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="C:WINDOWSSystem32CTFMON.EXE" [2004-08-04 00:44 15360]

C:Documents and SettingsAll UsersMenu StartProgramyAutostart
KODAK Software Updater.lnk - C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe [2004-02-13 15:12:08 16423]
Oprogramowanie Kodak EasyShare.lnk - C:Program FilesKodakKodak EasyShare softwarebinEasyShare.exe [2007-02-20 06:10:26 282624]

[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversiondrivers32]
"VIDC.I420"= lvcodec2.dll
"msacm.divxa32"= DivXa32.acm
"MSVideo"= vfwwdm32.dll
"MSVideo8"= VfWWDM32.dll
"VIDC.WMV3"= wmv9vcm.dll

[HKLM~startupfolderC:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk]
path=C:Documents and SettingsAll UsersMenu StartProgramyAutostartAdobe Reader Speed Launch.lnk
backup=C:WINDOWSpssAdobe Reader Speed Launch.lnkCommon Startup

[HKLM~startupfolderC:^Documents and Settings^All Users^Menu Start^Programy^Autostart^BT Broadband Desktop Help.lnk]
path=C:Documents and SettingsAll UsersMenu StartProgramyAutostartBT Broadband Desktop Help.lnk
backup=C:WINDOWSpssBT Broadband Desktop Help.lnkCommon Startup

[HKLM~startupfolderC:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Microsoft Office.lnk]
path=C:Documents and SettingsAll UsersMenu StartProgramyAutostartMicrosoft Office.lnk
backup=C:WINDOWSpssMicrosoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregavast!]
C:PROGRA~1ALWILS~1Avast4ashDisp.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregBgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2005-09-03 15:18 94208 C:Program FilesCommon FilesAheadlibNMBgMonitor.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregbtbb_wcm_McciTrayApp]
--a------ 2005-12-29 11:22 543232 C:Program Filesbtbb_wcmMcciTrayApp.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregctfmon.exe]
--a------ 2004-08-04 00:44 15360 C:WINDOWSsystem32ctfmon.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregeyeBeam SIP Client]
--a------ 2006-07-31 20:00 19857408 C:Program FilesBT Broadband Talk SoftphoneBTSoftphone.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregIntelliPoint]
--a------ 2005-03-24 00:26 217088 C:Program FilesMicrosoft IntelliPointpoint32.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregiut75]
c:windowssystem32driversuzcx.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregLogitechVideoRepair]
--a------ 2005-01-19 11:45 458752 C:Program FilesLogitechVideoISStart.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregLogitechVideoTray]
--a------ 2005-01-19 11:39 217088 C:Program FilesLogitechVideoLogiTray.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregLVCOMSX]
--a------ 2005-01-19 11:05 221184 C:WINDOWSsystem32LVCOMSX.EXE

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregMotive SmartBridge]
--a------ 2006-02-06 18:52 462935 C:PROGRA~1BTHOME~1HelpSMARTB~1BTHelpNotifier.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:WINDOWSsystem32NeroCheck.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregPadTouch]
--a------ 2004-11-17 10:56 1077327 C:Program FilesTOSHIBATouch and LaunchPadExe.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregPCSuiteTrayApplication]
--a------ 2006-06-15 12:36 229376 C:PROGRA~1NokiaNOKIAP~1LAUNCH~1.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregRemoteControl]
--a------ 2003-12-08 17:35 32768 C:Program FilesCyberLink DVD SolutionPowerDVDPDVDServ.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSmcService]
C:PROGRA~1SygateSPFsmc.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSunJavaUpdateSched]
--a------ 2005-11-10 14:03 36975 C:Program FilesJavajre1.5.0_06binjusched.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregswg]
C:Program FilesGoogleGoogleToolbarNotifier1.2.1128.5462GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSynTPEnh]
--a------ 2004-10-08 16:43 688218 C:Program FilesSynapticsSynTPSynTPEnh.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSynTPLpr]
--a------ 2004-10-08 16:44 98394 C:Program FilesSynapticsSynTPSynTPLpr.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregTkBellExe]
--a------ 2008-02-23 23:04 185896 C:Program FilesCommon FilesRealUpdate_OBrealsched.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregYahoo! Pager]
--a------ 2005-08-31 17:11 2478080 C:PROGRA~1Yahoo!MESSEN~1ypager.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregYBrowser]
--a------ 2006-07-21 16:19 129536 C:PROGRA~1Yahoo!browserybrwicon.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\system32\sessmgr.exe"=
"C:\Program Files\Gadu-Gadu\gg.exe"=
"C:\Program Files\eMule\emule.exe"=
"C:\WINDOWS\system32\dpvsetup.exe"=
"C:\WINDOWS\system32\rundll32.exe"=
"C:\Program Files\BitComet\BitComet.exe"=
"C:\Program Files\Opera\Opera.exe"=
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe"=
"C:\Program Files\Yahoo!\Messenger\ypager.exe"=
"C:\Program Files\Yahoo!\Messenger\YServer.exe"=
"C:\Documents and Settings\Dominika\Dane aplikacji\SopCast\adv\SopAdver.exe"=
"C:\Program Files\MSN Messenger\msnmsgr.exe"=
"C:\Program Files\MSN Messenger\livecall.exe"=
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe"=
"C:\Program Files\SopCast\adv\SopAdver.exe"=
"C:\Program Files\SopCast\SopCast.exe"=
"C:\Program Files\Skype\Phone\Skype.exe"=

[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileGloballyOpenPortsList]
"13029:TCP"= 13029:TCP:BitComet 13029 TCP
"13029:UDP"= 13029:UDP:BitComet 13029 UDP

R2 sgSchedulerService;sgSchedulerService;C:Program FilesSystemGuards.comSystemGuardssgScheduleService.exe [2007-09-04 12:44]
S3 SER120;OTI Serial port driver;C:WINDOWSsystem32DRIVERSSER120.sys [2005-03-22 03:03]

[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{dc844044-d5a3-11dc-a8fe-00c09ff9d3e0}]
ShellAutoRuncommand - wd_windows_toolssetup.exe

*Newly Created Service* - CATCHME
.
Contents of the ''Scheduled Tasks'' folder
"2008-04-05 11:29:37 C:WINDOWSTasksAppleSoftwareUpdate.job"
- C:Program FilesApple Software UpdateSoftwareUpdate.exe
"2008-04-04 14:00:30 C:WINDOWSTasksNorton Security Scan.job"
- C:Program FilesNorton Security ScanNss.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-05 21:42:35
Windows 5.1.2600 Dodatek Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-04-05 21:44:41
ComboFix-quarantined-files.txt2008-04-05 20:43:44
Pre-Run: 1,667,145,728 bajtów wolnych
Post-Run: 1,651,007,488 bajtów wolnych


Kod:
SmitFraudFix v2.309

Scan done at 21:16:31,68, 2008-04-05
Run from D:instalkiSmitfraudfixNowy folder
OS: Microsoft Windows XP [Wersja 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler''s .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» VACFix

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri''s WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLMSYSTEMCCSServicesTcpip..{1B5E788E-C8AF-4EA7-8116-99278630458A}: DhcpNameServer=192.168.1.254


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler''s .dll


»»»»»»»»»»»»»»»»»»»»»»»» End
Do wykonania w trybie awaryjnym i wyłączonym przywracaniem systemu.

Otwórz notatnik i wklej w nim to:

Cytat:
file::
C:sqmnoopt05.sqm
C:sqmdata05.sqm
C:sqmdata04.sqm
C:sqmnoopt04.sqm
C:WINDOWSmswtpdxp.dll
C:WINDOWSprwttrxp.dll
C:WINDOWSsystem32dpwttaxp.dll
C:WINDOWSsystem32mswtpaxp.dll
C:WINDOWSsystem32verwttxp.dll
CGrinocuments and SettingsDominikaDane aplikacjiwklnhst.dat

folder::
CTonguerogram FilesSystemGuards.com

registry::
[HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerToolbarWebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"=-
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"System Guards"=-
[-HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregiut75]
[-HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{dc844044-d5a3-11dc-a8fe-00c09ff9d3e0}]

driver::
sgSchedulerService


plik>zapisz jako...> CFScript . Przeciągnij i upuść plik CFScript na ikonkę Combofixa i rozpocznie się proces usuwania podczas którego wystąpi reset komputera.

Pobierz program

[Aby zobaczyć linki, zarejestruj się tutaj]



* Dwuklik na SDFix.exe następnie program wypakuje się na dysk systemowy (standardowo C:SDFix)
* Zrestartuj komputer i wejdź do trybu awaryjnego (klawisz F8 przed bootem Windowsa)
* Wejdź do folderu z SDFix kliknij dwa razy na plik RunThis.bat
* Wciśnij Ynastąpi proces usuwania.
* Kiedy usuwanie się ukończy wciśnij dowolny klawisz (Any Key). Nastąpi restart komputera.
* Po restarcie SDFix uruchomi się ponownie, żeby dokończyć proces usuwania kiedy pojawi się w oknie programu Finished, wciśnij dowolny klawisz do zakończenia scryptu i załadowania ikon na pulpicie.
* Pokaż Report.txt znajdujący się w folderze SDFix.

Po zabiegach dajesz nowy log z hijacka log z

[Aby zobaczyć linki, zarejestruj się tutaj]

bodek napisał(a):Do wykonania w trybie awaryjnym i wyłączonym przywracaniem systemu.

Otwórz notatnik i wklej w nim to:

Cytat:
file::
C:sqmnoopt05.sqm
C:sqmdata05.sqm
C:sqmdata04.sqm
C:sqmnoopt04.sqm
C:WINDOWSmswtpdxp.dll
C:WINDOWSprwttrxp.dll
C:WINDOWSsystem32dpwttaxp.dll
C:WINDOWSsystem32mswtpaxp.dll
C:WINDOWSsystem32verwttxp.dll
CGrinocuments and SettingsDominikaDane aplikacjiwklnhst.dat

folder::
CTonguerogram FilesSystemGuards.com

registry::
[HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerToolbarWebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"=-
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"System Guards"=-
[-HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregiut75]
[-HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{dc844044-d5a3-11dc-a8fe-00c09ff9d3e0}]

driver::
sgSchedulerService


Awaryjny z obsługą sieci, czy lepiej bez?
Lepiej bez obsługi sieci
Kod:
Logfile of HijackThis v1.99.1
Scan saved at 12:22, on 2008-04-07
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32wscntfy.exe
C:WINDOWSsystem32notepad.exe
C:Program FilesNokiaNokia Software LauncherNSLauncher.exe
C:Program FilesAdobeReader 8.0ReaderReader_sl.exe
C:Program FilesCommon FilesRealUpdate_OBrealsched.exe
C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe
C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe
C:Program FilesKodakKodak EasyShare softwarebinEasyShare.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesCommon FilesPCSuiteServicesServiceLayer.exe
C:Program FilesOperaOpera.exe
D:instalkiHJHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.onet.pl/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = 127.0.0.1
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:Program FilesWinamp Toolbarwinamptb.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:Program FilesBitComettoolsBitCometBHO_1.1.7.4.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:PROGRA~1Yahoo!Commonyiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_02binssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:Program FilesYahoo!browserYSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpn0yt.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:Program FilesWinamp Toolbarwinamptb.dll
O4 - HKLM..Run: [NSLauncher] C:Program FilesNokiaNokia Software LauncherNSLauncher.exe /startup
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [Onet.pl AutoUpdate] "C:Program FilesCommon FilesOnet.plAutoUpdate.exe" /tsr
O4 - HKLM..Run: [TkBellExe] "C:Program FilesCommon FilesRealUpdate_OBrealsched.exe"-osboot
O4 - HKLM..Run: [avgnt] "C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe" /min
O4 - HKCU..Run: [AdobeUpdater] C:Program FilesCommon FilesAdobeUpdater5AdobeUpdater.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe
O4 - Global Startup: Oprogramowanie Kodak EasyShare.lnk = C:Program FilesKodakKodak EasyShare softwarebinEasyShare.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:Program FilesBitCometBitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:Program FilesBitCometBitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:Program FilesBitCometBitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Winamp Toolbar Search - C:Documents and SettingsAll UsersDane aplikacjiWinamp ToolbarieToolbarresourcesen-USlocalsearch.html
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_02binssv.dll
O9 - Extra ''Tools'' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_02binssv.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:Program FilesBitComettoolsBitCometBHO_1.1.7.4.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:PROGRA~1Yahoo!Commonyiesrvc.dll
O15 - Trusted Zone: http://www.mks.com.pl
O15 - Trusted Zone: http://bezpieczenstwo.onet.pl
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:Program FilesYahoo!commonyinsthelper.dll
O16 - DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} (MainControl Class) - http://slimak.onet.pl/_m/wirusy/ArcaOnline.cab
O16 - DPF: {5A09E43F-A0A7-4ABF-AF80-11367CF1DC8F} - http://mks.com.pl/skaner/SkanerOnline.cab
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} - http://www.mks.com.pl/skaner/SkanerOnline.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:WINDOWSsystem32WPDShServiceObj.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
O23 - Service: Urządzenie mobilne Apple (Apple Mobile Device) - Apple, Inc. - C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:Program FilesSpyware Doctorsvcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:Program FilesSpyware Doctorswdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:Program FilesCommon FilesPCSuiteServicesServiceLayer.exe
O23 - Service: YPCService - Yahoo! Inc. - C:WINDOWSsystem32YPCSER~1.EXE






Kod:
[b]SDFix: Version 1.167 [/b]
Run by Administrator on 2008-04-07 at 12:06

Microsoft Windows XP [Wersja 5.1.2600]
Running From: C:SDFix

[b]Checking Services [/b]:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting


[b]Checking Files [/b]:

Trojan Files Found:

C:WINDOWSSYSTEM32CLAUTH1.DLL - Deleted
C:WINDOWSSYSTEM32CLAUTH2.DLL - Deleted
C:WINDOWSSYSTEM32NSPRS.DLL - Deleted
C:WINDOWSSYSTEM32SERAUTH1.DLL - Deleted
C:WINDOWSSYSTEM32SERAUTH2.DLL - Deleted
C:WINDOWSSYSTEM32SSPRS.DLL - Deleted





Removing Temp Files

[b]ADS Check [/b]:



[b]Final Check [/b]:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-07 12:13:56
Windows 5.1.2600 Dodatek Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesEventlogApplicationESENT]
"EventMessageFile"=str(2):"c:windowssystem32ESENT.dll"
"CategoryMessageFile"=str(2):"c:windowssystem32ESENT.dll"
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessptdCfg]
"s0"=dword:f35c113a
"s1"=dword:daefce56
"s2"=dword:8215b947
"h0"=dword:00000001

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessptdCfg19659239224E364682FA4BAF72C53EA4]
"p0"="C:Program FilesDAEMON Tools"
"h0"=dword:00000000
"khjeh"=hex:50,3f,78,5c,63,d9,29,cc,75,74,05,4f,46,a3,85,4c,a0,01,d0,7d,08,..

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessptdCfg19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,34,5c,07,6f,65,5b,72,ce,44,e2,b7,b4,48,68,af,33,da,..
"khjeh"=hex:2a,8b,01,d0,e0,6d,17,06,27,e8,b7,77,e2,e0,d9,25,bf,6a,36,c5,a8,..

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessptdCfg19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:75,fa,9b,fd,ed,87,b3,cb,38,a9,49,b7,b5,f6,8b,ce,2f,a0,87,4d,8e,..

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessptdCfg19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:30,c1,d7,2f,e0,15,60,37,40,72,93,ce,d8,65,bf,41,fb,0f,8b,8d,67,..

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessptdCfg19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:e6,8c,6d,cf,1f,6a,7d,c5,74,5e,7e,a5,5e,ab,ab,05,94,6b,9f,01,05,..

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessptdCfg19659239224E364682FA4BAF72C53EA4\00000001\0Jf43]
"khjeh"=hex:e6,57,b1,b4,da,e9,09,ae,da,35,e9,57,8a,6d,90,b9,4e,34,4e,6c,e4,..
[HKEY_LOCAL_MACHINESYSTEMControlSet003ServicessptdCfg19659239224E364682FA4BAF72C53EA4]
"p0"="C:Program FilesDAEMON Tools"
"h0"=dword:00000000
"khjeh"=hex:50,3f,78,5c,63,d9,29,cc,75,74,05,4f,46,a3,85,4c,a0,01,d0,7d,08,..

[HKEY_LOCAL_MACHINESYSTEMControlSet003ServicessptdCfg19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,34,5c,07,6f,65,5b,72,ce,44,e2,b7,b4,48,68,af,33,da,..
"khjeh"=hex:2a,8b,01,d0,e0,6d,17,06,27,e8,b7,77,e2,e0,d9,25,bf,6a,36,c5,a8,..

[HKEY_LOCAL_MACHINESYSTEMControlSet003ServicessptdCfg19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:75,fa,9b,fd,ed,87,b3,cb,38,a9,49,b7,b5,f6,8b,ce,2f,a0,87,4d,8e,..

[HKEY_LOCAL_MACHINESYSTEMControlSet003ServicessptdCfg19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:30,c1,d7,2f,e0,15,60,37,40,72,93,ce,d8,65,bf,41,fb,0f,8b,8d,67,..

[HKEY_LOCAL_MACHINESYSTEMControlSet003ServicessptdCfg19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:e6,8c,6d,cf,1f,6a,7d,c5,74,5e,7e,a5,5e,ab,ab,05,94,6b,9f,01,05,..

[HKEY_LOCAL_MACHINESYSTEMControlSet003ServicessptdCfg19659239224E364682FA4BAF72C53EA4\00000001\0Jf43]
"khjeh"=hex:e6,57,b1,b4,da,e9,09,ae,da,35,e9,57,8a,6d,90,b9,4e,34,4e,6c,e4,..

scanning hidden registry entries ...

[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerMenuOrderFavoritesA151c]
"Order"=hex:08,00,00,00,02,00,00,00,0c,00,00,00,01,00,00,00,00,00,00,00

scanning hidden files ...


scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1


[b]Remaining Services [/b]:



Authorized Application Key Export:

[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Gadu-Gadu\gg.exe"="C:\Program Files\Gadu-Gadu\gg.exe:*:Enabled:Gadu-Gadu - program glowny"
"C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Uruchamia plik DLL jako aplikacj©"
"C:\Program Files\BitComet\BitComet.exe"="C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
"C:\Program Files\Opera\Opera.exe"="C:\Program Files\Opera\Opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe"="C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare"
"C:\Program Files\Yahoo!\Messenger\ypager.exe"="C:\Program Files\Yahoo!\Messenger\ypager.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\Documents and Settings\Dominika\Dane aplikacji\SopCast\adv\SopAdver.exe"="C:\Documents and Settings\Dominika\Dane aplikacji\SopCast\adv\SopAdver.exe:*:Disabled:SopCast Adver"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe"="C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Disabled:Kodak Software Updater"
"C:\Program Files\SopCast\adv\SopAdver.exe"="C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver"
"C:\Program Files\SopCast\SopCast.exe"="C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

[b]Remaining Files [/b]:


File Backups: - C:SDFixbackupsbackups.zip

[b]Files with Hidden Attributes [/b]:

Sun2 Apr 2006 4,348 ..SH. --- "C:Documents and SettingsAll UsersDRMDRMv1.bak"
Thu 21 Feb 2008 392 A..H. --- "C:Program FilesInterActualInterActual PlayeritiB2.tmp"
Sat7 Jul 2007 0 A.SH. --- "C:Documents and SettingsAll UsersDRMCacheIndiv01.tmp"
Mon1 Dec 2003 0 A.SHR --- "C:Documents and SettingsDominikaMoje dokumentydyskietka startowadyskietkaEBD.SYS"

[b]Finished![/b]





Kod:
ComboFix 08-04-04.1 - Administrator 2008-04-07 11:23:50.2 - NTFSx86 MINIMAL
Microsoft Windows XP Professional5.1.2600.2.1250.1.1045.18.281 [GMT 1:00]
Running from: D:instalkiCombofixComboFix.exe
Command switches used :: D:instalkiCombofixCFScript.txt

[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]

FILE ::
C:Documents and SettingsDominikaDane aplikacjiwklnhst.dat
C:sqmdata04.sqm
C:sqmdata05.sqm
C:sqmnoopt04.sqm
C:sqmnoopt05.sqm
C:WINDOWSmswtpdxp.dll
C:WINDOWSprwttrxp.dll
C:WINDOWSsystem32dpwttaxp.dll
C:WINDOWSsystem32mswtpaxp.dll
C:WINDOWSsystem32verwttxp.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:Documents and SettingsDominikaUstawienia lokalneTemporary Internet Files
C:Program FilesSystemGuards.com
C:Program FilesSystemGuards.comSystemGuardsAntiSpyware.dll
C:Program FilesSystemGuards.comSystemGuardsantispyware.swf
C:Program FilesSystemGuards.comSystemGuardsAPIHook9x.dll
C:Program FilesSystemGuards.comSystemGuardsAPIHookxp.dll
C:Program FilesSystemGuards.comSystemGuardsBrowse.swf
C:Program FilesSystemGuards.comSystemGuardsClose.swf
C:Program FilesSystemGuards.comSystemGuardsEnglish.ini
C:Program FilesSystemGuards.comSystemGuardsfirewall.swf
C:Program FilesSystemGuards.comSystemGuardsGuards.swf
C:Program FilesSystemGuards.comSystemGuardsHardDiskCleaner.dll
C:Program FilesSystemGuards.comSystemGuardsHelp.chm
C:Program FilesSystemGuards.comSystemGuardsHookFunc.dll
C:Program FilesSystemGuards.comSystemGuardsHookSetup.dll
C:Program FilesSystemGuards.comSystemGuardsHookSetup.lib
C:Program FilesSystemGuards.comSystemGuardsMain.swf
C:Program FilesSystemGuards.comSystemGuardsmessage.swf
C:Program FilesSystemGuards.comSystemGuardsRegCleaner.dll
C:Program FilesSystemGuards.comSystemGuardsSAlert.swf
C:Program FilesSystemGuards.comSystemGuardsscanning.swf
C:Program FilesSystemGuards.comSystemGuardsschedule.swf
C:Program FilesSystemGuards.comSystemGuardssgScheduleService.exe
C:Program FilesSystemGuards.comSystemGuardssgScheduleService.log
C:Program FilesSystemGuards.comSystemGuardssgShredder.dll
C:Program FilesSystemGuards.comSystemGuardsshredder.swf
C:Program FilesSystemGuards.comSystemGuardsstartup manger.swf
C:Program FilesSystemGuards.comSystemGuardsStartupManager.dll
C:Program FilesSystemGuards.comSystemGuardsSysCleaner.dll
C:Program FilesSystemGuards.comSystemGuardsSysGuards.exe
C:Program FilesSystemGuards.comSystemGuardssystem optimizer.swf
C:Program FilesSystemGuards.comSystemGuardsSystemCleaner.swf
C:Program FilesSystemGuards.comSystemGuardsSystemGuards.ini
C:Program FilesSystemGuards.comSystemGuardsSystemOptimizer.dll
C:Program FilesSystemGuards.comSystemGuardsTaskstasks.ini
C:Program FilesSystemGuards.comSystemGuardsunins000.dat
C:Program FilesSystemGuards.comSystemGuardsunins000.exe
C:Program FilesSystemGuards.comSystemGuardsUpdate DBupdate.cli
C:Program FilesSystemGuards.comSystemGuardsUpdate DBupdate.exe
C:Program FilesSystemGuards.comSystemGuardsupdate.cli
C:Program FilesSystemGuards.comSystemGuardsupdate.exe
C:Program FilesSystemGuards.comSystemGuardswizard.swf
C:sqmdata04.sqm
C:sqmdata05.sqm
C:sqmnoopt04.sqm
C:sqmnoopt05.sqm
C:WINDOWSmswtpdxp.dll
C:WINDOWSprwttrxp.dll
C:WINDOWSsystem32dpwttaxp.dll
C:WINDOWSsystem32mswtpaxp.dll
C:WINDOWSsystem32verwttxp.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------Legacy_sgSchedulerService
-------sgSchedulerService


((((((((((((((((((((((((( Files Created from 2008-03-07 to 2008-04-07)))))))))))))))))))))))))))))))
.

2008-04-05 20:44 . 2008-04-05 21:16    2,546    --a------    C:WINDOWSsystem32tmp.reg
2008-04-05 19:01 . 2008-04-05 21:44    <DIR>    d--h-----    C:Documents and SettingsAdministratorUstawienia lokalne
2008-04-05 19:01 . 2006-02-08 10:05    <DIR>    d--------    C:Documents and SettingsAdministratorUlubione
2008-04-05 19:01 . 2006-02-08 11:15    <DIR>    d--h-----    C:Documents and SettingsAdministratorSzablony
2008-04-05 19:01 . 2008-04-07 11:23    <DIR>    d--------    C:Documents and SettingsAdministratorPulpit
2008-04-05 19:01 . 2006-02-08 10:05    <DIR>    d--------    C:Documents and SettingsAdministratorMoje dokumenty
2008-04-05 19:01 . 2006-02-08 10:05    <DIR>    dr-------    C:Documents and SettingsAdministratorMenu Start
2008-04-05 19:01 . 2007-10-05 00:05    <DIR>    dr-h-----    C:Documents and SettingsAdministratorDane aplikacji
2008-04-05 11:40 . 2008-04-05 11:40    <DIR>    d--------    C:Program FilesAvira
2008-04-05 11:40 . 2008-04-05 11:40    <DIR>    d--------    C:Documents and SettingsAll UsersDane aplikacjiAvira
2008-03-21 14:14 . 2008-03-21 14:15    <DIR>    d--------    C:Program FilesOpera
2008-03-16 06:43 . 2008-03-16 06:53    <DIR>    d--------    C:Program FilesFlashGet
2008-03-16 06:43 . 2006-04-20 12:51    359,808    --a------    C:WINDOWSsystem32driverstcpip.sys.flg
2008-03-16 05:49 . 2008-03-16 05:50    4,932,385    --a------    C:TempFreeYouTubeToiPodConverter.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-06 14:23    ---------    d-----w    C:Documents and SettingsDominikaDane aplikacjiSkype
2008-04-04 14:47    ---------    d-----w    C:Program FileseMule
2008-04-04 14:00    ---------    d-----w    C:Program FilesNorton Security Scan
2008-03-16 04:51    ---------    d-----w    C:Program FilesDVDVideoSoft
2008-03-16 04:51    ---------    d-----w    C:Program FilesCommon FilesDVDVideoSoft
2008-03-14 21:18    ---------    d-----w    C:Program FilesWindows Media Connect 2
2008-03-02 10:15    ---------    d-----w    C:Program FilesCommon FilesSymantec Shared
2008-02-23 22:05    ---------    d-----w    C:Program FilesCommon FilesReal
2008-02-16 15:37    ---------    d-----w    C:Program FilesMediafour
2008-02-16 06:03    ---------    d-----w    C:Documents and SettingsDominikaDane aplikacjiWinamp
2008-02-16 05:50    ---------    d-----w    C:Program FilesWinamp Toolbar
2008-02-16 05:50    ---------    d-----w    C:Documents and SettingsAll UsersDane aplikacjiWinamp Toolbar
2008-02-16 05:31    ---------    d-----w    C:Program FilesWinamp
2007-12-21 16:39    34,624    ----a-w    C:Documents and SettingsDominikaDane aplikacjiGDIPFONTCACHEV1.DAT
2006-02-08 10:47    0    ----a-w    C:Documents and SettingsDominikaDane aplikacjiwklnhst.dat
2004-10-01 14:00    40,960    ----a-w    C:Program FilesUninstall_CDS.exe
.

------- Sigcheck -------

2006-01-13 18:073604485562cc0a47b2aef06d3417b733f3c195    C:WINDOWS$hf_mig$KB913446SP2QFEtcpip.sys
2006-04-20 13:18360576b2220c618b42a2212a59d91ebd6fc4b4    C:WINDOWS$hf_mig$KB917953SP2QFEtcpip.sys
2001-08-18 07:24327168e7774698bb0d14b0710a9a31e209f9b6    C:WINDOWS$NtServicePackUninstall$tcpip.sys
2004-08-03 23:143590409f4b36614a0fc234525ba224957de55c    C:WINDOWS$NtUninstallKB913446$tcpip.sys
2006-01-13 03:28359808583e063fdc888ca30d05c2724b0d7ef4    C:WINDOWS$NtUninstallKB917953$tcpip.sys
2004-08-03 23:143590409f4b36614a0fc234525ba224957de55c    C:WINDOWSServicePackFilesi386tcpip.sys
2006-04-20 12:513598081dbf125862891817f374f407626967f4    C:WINDOWSsystem32dllcachetcpip.sys
2006-04-20 12:51359808b4e29943b4b04bd5e7381546848e6669    C:WINDOWSsystem32driverstcpip.sys
.
((((((((((((((((((((((((((((( snapshot@2008-04-05_21.43.31,76 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 19:02:28    163,328    ----a-w    C:WINDOWSerdntsubsERDNT.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE~Browser Helper Objects{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-12-13 17:49    1185120    --a------    C:Program FilesWinamp Toolbarwinamptb.dll

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= "C:Program FilesWinamp Toolbarwinamptb.dll" [2007-12-13 17:49 1185120]

[HKEY_CLASSES_ROOTclsid{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOTWINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOTTypeLib{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOTWINAMPTB.AOLToolBand]

[HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerToolbarWebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:Program FilesWinamp Toolbarwinamptb.dll [2007-12-13 17:49 1185120]

[HKEY_CLASSES_ROOTclsid{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOTWINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOTTypeLib{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOTWINAMPTB.AOLToolBand]

[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"AdobeUpdater"="C:Program FilesCommon FilesAdobeUpdater5AdobeUpdater.exe" [2007-03-01 10:37 2321600]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"NSLauncher"="C:Program FilesNokiaNokia Software LauncherNSLauncher.exe" [2006-11-28 01:12 2658304]
"Adobe Reader Speed Launcher"="C:Program FilesAdobeReader 8.0ReaderReader_sl.exe" [2007-05-11 03:06 40048]
"QuickTime Task"="C:Program FilesQuickTimeqttask.exe" [2007-12-11 11:56 286720]
"Onet.pl AutoUpdate"="C:Program FilesCommon FilesOnet.plAutoUpdate.exe" [ ]
"TkBellExe"="C:Program FilesCommon FilesRealUpdate_OBrealsched.exe" [2008-02-23 23:04 185896]
"avgnt"="C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe" [2008-04-05 12:00 249896]

[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="C:WINDOWSSystem32CTFMON.EXE" [2004-08-04 00:44 15360]

C:Documents and SettingsAll UsersMenu StartProgramyAutostart
KODAK Software Updater.lnk - C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe [2004-02-13 15:12:08 16423]
Oprogramowanie Kodak EasyShare.lnk - C:Program FilesKodakKodak EasyShare softwarebinEasyShare.exe [2007-02-20 06:10:26 282624]

[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversiondrivers32]
"VIDC.I420"= lvcodec2.dll
"msacm.divxa32"= DivXa32.acm
"MSVideo"= vfwwdm32.dll
"MSVideo8"= VfWWDM32.dll
"VIDC.WMV3"= wmv9vcm.dll

[HKLM~startupfolderC:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk]
path=C:Documents and SettingsAll UsersMenu StartProgramyAutostartAdobe Reader Speed Launch.lnk
backup=C:WINDOWSpssAdobe Reader Speed Launch.lnkCommon Startup

[HKLM~startupfolderC:^Documents and Settings^All Users^Menu Start^Programy^Autostart^BT Broadband Desktop Help.lnk]
path=C:Documents and SettingsAll UsersMenu StartProgramyAutostartBT Broadband Desktop Help.lnk
backup=C:WINDOWSpssBT Broadband Desktop Help.lnkCommon Startup

[HKLM~startupfolderC:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Microsoft Office.lnk]
path=C:Documents and SettingsAll UsersMenu StartProgramyAutostartMicrosoft Office.lnk
backup=C:WINDOWSpssMicrosoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregavast!]
C:PROGRA~1ALWILS~1Avast4ashDisp.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregBgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2005-09-03 15:18 94208 C:Program FilesCommon FilesAheadlibNMBgMonitor.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregbtbb_wcm_McciTrayApp]
--a------ 2005-12-29 11:22 543232 C:Program Filesbtbb_wcmMcciTrayApp.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregctfmon.exe]
--a------ 2004-08-04 00:44 15360 C:WINDOWSsystem32ctfmon.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregeyeBeam SIP Client]
--a------ 2006-07-31 20:00 19857408 C:Program FilesBT Broadband Talk SoftphoneBTSoftphone.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregIntelliPoint]
--a------ 2005-03-24 00:26 217088 C:Program FilesMicrosoft IntelliPointpoint32.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregLogitechVideoRepair]
--a------ 2005-01-19 11:45 458752 C:Program FilesLogitechVideoISStart.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregLogitechVideoTray]
--a------ 2005-01-19 11:39 217088 C:Program FilesLogitechVideoLogiTray.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregLVCOMSX]
--a------ 2005-01-19 11:05 221184 C:WINDOWSsystem32LVCOMSX.EXE

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregMotive SmartBridge]
--a------ 2006-02-06 18:52 462935 C:PROGRA~1BTHOME~1HelpSMARTB~1BTHelpNotifier.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:WINDOWSsystem32NeroCheck.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregPadTouch]
--a------ 2004-11-17 10:56 1077327 C:Program FilesTOSHIBATouch and LaunchPadExe.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregPCSuiteTrayApplication]
--a------ 2006-06-15 12:36 229376 C:PROGRA~1NokiaNOKIAP~1LAUNCH~1.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregRemoteControl]
--a------ 2003-12-08 17:35 32768 C:Program FilesCyberLink DVD SolutionPowerDVDPDVDServ.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSmcService]
C:PROGRA~1SygateSPFsmc.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSunJavaUpdateSched]
--a------ 2005-11-10 14:03 36975 C:Program FilesJavajre1.5.0_06binjusched.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregswg]
C:Program FilesGoogleGoogleToolbarNotifier1.2.1128.5462GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSynTPEnh]
--a------ 2004-10-08 16:43 688218 C:Program FilesSynapticsSynTPSynTPEnh.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSynTPLpr]
--a------ 2004-10-08 16:44 98394 C:Program FilesSynapticsSynTPSynTPLpr.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregTkBellExe]
--a------ 2008-02-23 23:04 185896 C:Program FilesCommon FilesRealUpdate_OBrealsched.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregYahoo! Pager]
--a------ 2005-08-31 17:11 2478080 C:PROGRA~1Yahoo!MESSEN~1ypager.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregYBrowser]
--a------ 2006-07-21 16:19 129536 C:PROGRA~1Yahoo!browserybrwicon.exe

[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\system32\sessmgr.exe"=
"C:\Program Files\Gadu-Gadu\gg.exe"=
"C:\Program Files\eMule\emule.exe"=
"C:\WINDOWS\system32\dpvsetup.exe"=
"C:\WINDOWS\system32\rundll32.exe"=
"C:\Program Files\BitComet\BitComet.exe"=
"C:\Program Files\Opera\Opera.exe"=
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe"=
"C:\Program Files\Yahoo!\Messenger\ypager.exe"=
"C:\Program Files\Yahoo!\Messenger\YServer.exe"=
"C:\Documents and Settings\Dominika\Dane aplikacji\SopCast\adv\SopAdver.exe"=
"C:\Program Files\MSN Messenger\msnmsgr.exe"=
"C:\Program Files\MSN Messenger\livecall.exe"=
"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe"=
"C:\Program Files\SopCast\adv\SopAdver.exe"=
"C:\Program Files\SopCast\SopCast.exe"=
"C:\Program Files\Skype\Phone\Skype.exe"=

[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileGloballyOpenPortsList]
"13029:TCP"= 13029:TCP:BitComet 13029 TCP
"13029:UDP"= 13029:UDP:BitComet 13029 UDP

S3 SER120;OTI Serial port driver;C:WINDOWSsystem32DRIVERSSER120.sys [2005-03-22 03:03]

[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{dc844044-d5a3-11dc-a8fe-00c09ff9d3e0}]
ShellAutoRuncommand - wd_windows_toolssetup.exe

.
Contents of the ''Scheduled Tasks'' folder
"2008-04-05 11:29:37 C:WINDOWSTasksAppleSoftwareUpdate.job"
- C:Program FilesApple Software UpdateSoftwareUpdate.exe
"2008-04-04 14:00:30 C:WINDOWSTasksNorton Security Scan.job"
- C:Program FilesNorton Security ScanNss.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-07 11:36:12
Windows 5.1.2600 Dodatek Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:WINDOWSsystem32Ati2evxx.exe
C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
C:Program FilesCommon FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:WINDOWSsystem32Ati2evxx.exe
C:Program FilesCommon FilesPCSuiteServicesServiceLayer.exe
.
**************************************************************************
.
Completion time: 2008-04-07 11:40:27 - machine was rebooted [Dominika]
ComboFix-quarantined-files.txt2008-04-07 10:39:58
ComboFix2.txt2008-04-05 20:44:42
Pre-Run: 484,519,936 bajtów wolnych
Post-Run: 352,403,456 bajt˘w wolnych
Cytat: CGrinocuments and SettingsDominikaDane aplikacjiwklnhst.dat


Usuń ten plik ręcznie z dysku w trybie awaryjnym i wyłączonym przywracaniem systemu.

Otwórz notatnik i wklej w nim to:

Cytat: Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{dc844044-d5a3-11dc-a8fe-00c09ff9d3e0}]


Plik>zapisz jako...>zmień rozszerzenie na: wszystkie pliki>zapisz pod nazwą FIX.REG
Odpal plikFIX.REG w trybie awaryjnym i wyłączonym przywracaniem systemu. Po zabiegach dajesz nowe logi
bodek napisał(a):
Cytat: CGrinocuments and SettingsDominikaDane aplikacjiwklnhst.dat


Usuń ten plik ręcznie z dysku w trybie awaryjnym i wyłączonym przywracaniem systemu.


Nie da rady.
Pod profilem ''Administrator'' wyskakuje odmowa dostępu, gdy próbuję otworzyć katalog ''Dominika''. Pod profilem ''Dominika'', w katalogu ''user data'', w ogóle nie ma, lub nie widać pliku wklnhst.dat. W normalnym trybie również nie widać tego pliku.
Dominatrix napisał(a):
bodek napisał(a):
Cytat: CGrinocuments and SettingsDominikaDane aplikacjiwklnhst.dat


Usuń ten plik ręcznie z dysku w trybie awaryjnym i wyłączonym przywracaniem systemu.


Nie da rady.
Pod profilem ''Administrator'' wyskakuje odmowa dostępu, gdy próbuję otworzyć katalog ''Dominika''. Pod profilem ''Dominika'', w katalogu ''user data'', w ogóle nie ma, lub nie widać pliku wklnhst.dat. W normalnym trybie również nie widać tego pliku.


Nie widać bo jest ukryty Cool

Panel sterowania -> Opcje folderów -> Widok -> Pokaż ukryte pliki i foldery -> OKSmile
Dzięki Lisie Smile
Od wczoraj próbuję wkleić nowy log, ale za każdym razem, gdy wciskam ''Odpowiedz'' wyskakuje mi taki błąd:

''''Internal Server Error
The server encountered an internal error or misconfiguration and was unable to complete your request.''''
Może załącznikiem da radę?
W logu z hijacka czysto. Poproszę jeszcze o log z

[Aby zobaczyć linki, zarejestruj się tutaj]

Załącznik
Stron: 1 2