
chodzi o to ze w czasie surfowania po necie wyswietla sie mnóstwo reklam
oraz pojawił sie dziwny pasek wyszukiwania w firefox`ie oraz obok zegara systemowego
- Kod: Zaznacz wszystko
- Logfile of HijackThis v1.99.1
 Scan saved at 21:57:33, on 2006-09-30
 Platform: Windows XP (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 (6.00.2600.0000)
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\csrss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\System32\directxbt.exe
 C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
 C:\PROGRA~1\NEOSTR~1\CnxMon.exe
 C:\WINDOWS\System32\alg.exe
 D:\programy\AutoConnect\AutoConnect.exe
 D:\programy\Gadu-Gadu\gg.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Program Files\Network Monitor\netmon.exe
 C:\WINDOWS\WHh4\command.exe
 C:\WINDOWS\explorer.exe
 C:\WINDOWS\System32\rundll32.exe
 C:\WINDOWS\System32\WScript.exe
 C:\WINDOWS\System32\wbem\wmiprvse.exe
 C:\WINDOWS\System32\wbem\wmiprvse.exe
 C:\Documents and Settings\Administrator\Pulpit\HijackThis.exe
 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada TP
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
 R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL
 R3 - URLSearchHook: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
 O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL
 O4 - HKLM\..\Run: [Microsoft Directxsp] directxbt.exe
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe
 O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\NEOSTR~1\CnxMon.exe
 O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe
 O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
 O4 - HKLM\..\Run: [ouu2609d] RUNDLL32.EXE w0061f71.dll,n 005260980000000a0061f71
 O4 - HKLM\..\RunServices: [Microsoft Security Monitor Process] mssmp.exe
 O4 - HKLM\..\RunServices: [Microsoft Security] C:\WINDOWS\System32\drivers\mssc.exe
 O4 - HKLM\..\RunServices: [msvcc25] svcchost.exe
 O4 - HKLM\..\RunServices: [mysvcig38] mysvcc.exe
 O4 - HKLM\..\RunServices: [Microsoft explorer Update] internal.exe
 O4 - HKLM\..\RunServices: [Microsoft Directxsp] directxbt.exe
 O4 - HKCU\..\Run: [AutoConnect] D:\programy\AutoConnect\AutoConnect.exe
 O4 - HKCU\..\Run: [Microsoft Directxsp] directxbt.exe
 O4 - HKCU\..\RunServices: [Microsoft Directxsp] directxbt.exe
 O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
 O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
 O17 - HKLM\System\CCS\Services\Tcpip\..\{485AC8C5-7429-404E-A3D3-243A8CF2C095}: NameServer = 194.204.152.34 217.98.63.164
 O20 - Winlogon Notify: Extensions - C:\WINDOWS\system32\wsvdmoe.dll
 O20 - Winlogon Notify: policies - C:\WINDOWS\system32\omjsel.dll
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\WINDOWS\System32\nvsvc32.exe (file missing)
- Kod: Zaznacz wszystko
- "Silent Runners.vbs", revision 48, http://www.silentrunners.org/
 Operating System: Windows XP
 Output limited to non-default values, except where indicated by "{++}"
 Startup items buried in registry:
 ---------------------------------
 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
 "AutoConnect" = "D:\programy\AutoConnect\AutoConnect.exe" ["http://autoconnect.prv.pl"]
 "Microsoft Directxsp" = "directxbt.exe" [null data]
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
 "Microsoft Directxsp" = "directxbt.exe" [null data]
 "NeroFilterCheck" = "C:\WINDOWS\System32\NeroCheck.exe" ["Ahead Software Gmbh"]
 "WooCnxMon" = "C:\PROGRA~1\NEOSTR~1\CnxMon.exe" [empty string]
 "WOOWATCH" = "C:\PROGRA~1\NEOSTR~1\Watch.exe" ["France Télécom R&D"]
 "WOOTASKBARICON" = "C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe" ["France Télécom R&D"]
 "ouu2609d" = "RUNDLL32.EXE w0061f71.dll,n 005260980000000a0061f71" [MS]
 HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
 "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
 -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
 \InProcServer32\(Default) = "deskpan.dll" [file not found]
 "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
 -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
 \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
 "{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
 -> {HKLM...CLSID} = "DesktopContext Class"
 \InProcServer32\(Default) = "C:\WINDOWS\System32\nvcpl.dll" ["NVIDIA Corporation"]
 "{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
 -> {HKLM...CLSID} = "NVIDIA CPL Extension"
 \InProcServer32\(Default) = "C:\WINDOWS\System32\nvcpl.dll" ["NVIDIA Corporation"]
 "{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
 -> {HKLM...CLSID} = "Desktop Explorer"
 \InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
 "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
 -> {HKLM...CLSID} = (no title provided)
 \InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
 "{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"
 -> {HKLM...CLSID} = "nView Desktop Context Menu"
 \InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
 "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 "{B327765E-D724-4347-8B16-78AE18552FC3}" = "NeroDigitalIconHandler"
 -> {HKLM...CLSID} = "NeroDigitalIconHandler Class"
 \InProcServer32\(Default) = "C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll" [file not found]
 "{7F1CF152-04F8-453A-B34C-E609530A9DC8}" = "NeroDigitalPropSheetHandler"
 -> {HKLM...CLSID} = "NeroDigitalPropSheetHandler Class"
 \InProcServer32\(Default) = "C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll" [file not found]
 "{3B98E21C-E776-4407-BDE9-75AE109D5EFC}" = (no title provided)
 -> {HKLM...CLSID} = (no title provided)
 \InProcServer32\(Default) = "C:\WINDOWS\system32\wsvdmoe.dll" [null data]
 "{687759EA-5D37-4B47-BBDC-8D6AA2A29CDA}" = (no title provided)
 -> {HKLM...CLSID} = (no title provided)
 \InProcServer32\(Default) = "C:\WINDOWS\system32\omjsel.dll" [null data]
 HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
 INFECTION WARNING! Extensions\DLLName = "C:\WINDOWS\system32\wsvdmoe.dll" [null data]
 INFECTION WARNING! policies\DLLName = "C:\WINDOWS\system32\omjsel.dll" [null data]
 HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
 {7D4D6379-F301-4311-BEBA-E26EB0561882}\(Default) = "NeroDigitalExt.NeroDigitalColumnHandler"
 -> {HKLM...CLSID} = "NeroDigitalColumnHandler Class"
 \InProcServer32\(Default) = "C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll" [file not found]
 HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 XPTools\(Default) = "{23F2DE6C-2C3F-4F95-B16A-56714C6FAAF4}"
 -> {HKLM...CLSID} = "Context Menu Shell Extension"
 \InProcServer32\(Default) = "C:\WINDOWS\System32\context.dll" ["SuperLogix"]
 HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 XPTools\(Default) = "{23F2DE6C-2C3F-4F95-B16A-56714C6FAAF4}"
 -> {HKLM...CLSID} = "Context Menu Shell Extension"
 \InProcServer32\(Default) = "C:\WINDOWS\System32\context.dll" ["SuperLogix"]
 Active Desktop and Wallpaper:
 -----------------------------
 Active Desktop is disabled at this entry:
 HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
 HKCU\Control Panel\Desktop\
 "Wallpaper" = "C:\WINDOWS\web\wallpaper\Idylla.bmp"
 Enabled Screen Saver:
 ---------------------
 HKCU\Control Panel\Desktop\
 "SCRNSAVE.EXE" = "C:\WINDOWS\System32\logon.scr" [MS]
 Winsock2 Service Provider DLLs:
 -------------------------------
 Namespace Service Providers
 HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
 000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
 000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
 000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
 Transport Service Providers
 HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
 %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15
 %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05
 Toolbars, Explorer Bars, Extensions:
 ------------------------------------
 Toolbars
 HKLM\Software\Microsoft\Internet Explorer\Toolbar\
 "{37B85A29-692B-4205-9CAD-2626E4993404}" = (no title provided)
 -> {HKLM...CLSID} = "My Global Search Bar"
 \InProcServer32\(Default) = "C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL" ["My Global Search"]
 Explorer Bars
 Dormant Explorer Bars in "View, Explorer Bar" menu
 HKLM\Software\Classes\CLSID\{01002DB2-8170-4D9B-A8B1-DDC9DD114E03}\(Default) = "Volet Wanadoo"
 Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
 InProcServer32\(Default) = "C:\PROGRA~1\NEOSTR~1\audience\audience.dll" [empty string]
 HKLM\Software\Classes\CLSID\{3BAF4A27-C764-4E1A-A6F4-62F7A7E5E51C}\(Default) = "ToolBand Class"
 Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
 InProcServer32\(Default) = "C:\PROGRA~1\NEOSTR~1\audience\audience.dll" [empty string]
 HKLM\Software\Classes\CLSID\{5BF498C0-931E-4A4F-B33F-456D07137EAA}\(Default) = "Volet Wanadoo"
 Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
 InProcServer32\(Default) = "C:\PROGRA~1\NEOSTR~1\audience\audience.dll" [empty string]
 Miscellaneous IE Hijack Points
 ------------------------------
 HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\
 Missing lines (compared with English-language version):
 "{08C06D61-F1F3-4799-86F8-BE1A89362C85}" = (no title provided)
 -> {HKLM...CLSID} = "Search Class"
 \InProcServer32\(Default) = "C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL" [empty string]
 "{A8B28872-3324-4CD2-8AA3-7D555C872D96}" = (no title provided)
 -> {HKLM...CLSID} = "DeskbarBHO"
 \InProcServer32\(Default) = "C:\Program Files\Deskbar\deskbar.dll" ["Deskbar"]
 Running Services (Display Name, Service Name, Path {Service DLL}):
 ------------------------------------------------------------------
 Command Service, cmdService, "C:\WINDOWS\WHh4\command.exe" [null data]
 Network Monitor, Network Monitor, "C:\Program Files\Network Monitor\netmon.exe service" [null data]
 ----------
 + This report excludes default entries except where indicated.
 + To see *everywhere* the script checks and *everything* it finds,
 launch it from a command prompt or a shortcut with the -all parameter.
 + The search for DESKTOP.INI DLL launch points on all local fixed drives
 took 15 seconds.
 + The search for all Registry CLSIDs containing dormant Explorer Bars
 took 15 seconds.
 ---------- (total run time: 92 seconds)


 
	

 
	


