

Logfile of HijackThis v1.99.1
Scan saved at 20:57:03, on 2005-05-18
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\qttask.exe
D:\WINDOWS\System32\MSDNSD32.exe
D:\WINDOWS\System32\win32bootcfg.exe
C:\Programy\AutoConnect\AutoConnect.exe
C:\Programy\Tlen\tlen.exe
D:\WINDOWS\System32\MSDNSD32.exe
D:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
D:\WINDOWS\System32\wdfmgr.exe
D:\WINDOWS\system32\cmd.exe
D:\WINDOWS\system32\p.exe
D:\Program Files\Registry Defragmentation\RegManServ.exe
D:\WINDOWS\wupdmgr.exe
D:\WINDOWS\osaupd.exe
c:\defender21.exe
c:\keyboard21.exe
c:\ryaqhktk.exe
c:\Program Files\sbrshx.exe
D:\WINDOWS\EXPLORER.EXE
D:\WINDOWS\System32\rundll32.exe
D:\WINDOWS\System32\CROSOF~1.NET\mshta.exe
D:\PROGRA~1\COMMON~1\wzow\wzowm.exe
D:\PROGRA~1\COMMON~1\wzow\wzowa.exe
c:\ffej.exe
D:\Program Files\Network Monitor\netmon.exe
D:\WINDOWS\IGNGa2E\command.exe
D:\WINDOWS\System32\0mcamcap.exe
D:\WINDOWS\System32\TheMatrixHasYou.exe
D:\Documents and Settings\cFka\Dane aplikacji\?icrosoft.NET\?vchost.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINDOWS\System32\winsrv32.exe
C:\Programy\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada TP
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - D:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL
R3 - URLSearchHook: (no name) - {35B93A8F-A76D-D2CF-3D20-F96A6DD88B99} - D:\WINDOWS\System32\wwr.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {35B93A8F-A76D-D2CF-3D20-F96A6DD88B99} - D:\WINDOWS\System32\wwr.dll
O2 - BHO: winapi32.MyBHO - {B52CCF85-726D-471C-B72C-CA9F104C5B98} - D:\WINDOWS\System32\winapi32.dll
O3 - Toolbar: Search - {a19ef336-01d4-48e6-926a-fe7e1c747aed} - D:\WINDOWS\System32\azesearch4.ocx
O4 - HKLM\..\Run: [autoclk] autoclk.exe
O4 - HKLM\..\Run: [WOOWATCH] D:\PROGRA~1\NEOSTR~1\Watch.exe
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Programy\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
O4 - HKLM\..\Run: [QuickTime Task] "D:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Odkurzacz-MCD] C:\Programy\Odkurzacz 10.1 Pro\odk_mcd.exe
O4 - HKLM\..\Run: [MS Domain Name Server Deamon] MSDNSD32.exe
O4 - HKLM\..\Run: [Windows Core Kernel Update] D:\WINDOWS\System32\win32bootcfg.exe
O4 - HKLM\..\Run: [defender] c:\\defender21.exe
O4 - HKLM\..\Run: [keyboard] c:\\keyboard21.exe
O4 - HKLM\..\Run: [SysTray] c:\Program Files\sbrshx.exe
O4 - HKLM\..\Run: [newname] c:\\newname21.exe
O4 - HKLM\..\Run: [aefbf15b.exe] D:\WINDOWS\System32\aefbf15b.exe
O4 - HKLM\..\Run: [0mcamcap] D:\WINDOWS\System32\0mcamcap.exe
O4 - HKLM\..\RunServices: [MS Domain Name Server Deamon] MSDNSD32.exe
O4 - HKLM\..\RunServices: [msconfig38] mssvcc.exe
O4 - HKLM\..\RunServices: [0mcamcap] D:\WINDOWS\System32\0mcamcap.exe
O4 - HKCU\..\Run: [AutoConnect] C:\Programy\AutoConnect\AutoConnect.exe
O4 - HKCU\..\Run: [Komunikator] C:\Programy\Tlen\tlen.exe
O4 - HKCU\..\Run: [MS Domain Name Server Deamon] MSDNSD32.exe
O4 - HKCU\..\Run: [shell] "D:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [Iwsi] "D:\WINDOWS\System32\CROSOF~1.NET\mshta.exe" -vt yazr
O4 - HKCU\..\Run: [wzow] D:\PROGRA~1\COMMON~1\wzow\wzowm.exe
O4 - HKCU\..\Run: [aefbf15b.exe] D:\Documents and Settings\cFka\Ustawienia lokalne\Dane aplikacji\aefbf15b.exe
O4 - HKCU\..\Run: [0mcamcap] D:\WINDOWS\System32\0mcamcap.exe
O4 - HKCU\..\Run: [Gjkuiav] D:\Documents and Settings\cFka\Dane aplikacji\?icrosoft.NET\?vchost.exe
O4 - Global Startup: DSLMON.lnk = D:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: &Google Search - res://d:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://d:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://d:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://d:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://d:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://d:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Ściągnij przy pomocy FlashGet'a - C:\Programy\FlashGet\jc_link.htm
O8 - Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a - C:\Programy\FlashGet\jc_all.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRAMY\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRAMY\FLASHGET\flashget.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} - http://www.azebar.com/1/sux.cab
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool- http://67.15.101.3/g_bin/pl/billard8_2_0_0_24.cab
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C3} (GameDesire Pool 14) - http://67.15.101.3/g_bin/pl/billard14_2_0_0_24.cab
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C5} (GameDesire Snooker) - http://67.15.101.3/g_bin/pl/snooker_2_0_0_24.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4EFC4139-8CD4-403F-9C5D-4C5464C4D2E7}: NameServer = 194.204.152.34 217.98.63.164
O20 - Winlogon Notify: mmxeroxk - D:\WINDOWS\SYSTEM32\mmxeroxk.dll
O20 - Winlogon Notify: Run - D:\WINDOWS\system32\lPprxy.dll
O23 - Service: Command Service (cmdService) - Unknown owner - D:\WINDOWS\IGNGa2E\command.exe
O23 - Service: Usługa Kaspersky Anti-Virus (kavsvc) - Kaspersky Lab - C:\Programy\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
O23 - Service: Network Monitor - Unknown owner - D:\Program Files\Network Monitor\netmon.exe
O23 - Service: Registry Management Service (RegManServ) - Unknown owner - D:\Program Files\Registry Defragmentation\RegManServ.exe
O23 - Service: Win32 Kernel Update (Win32Kernel) - Unknown owner - D:\WINDOWS\win32host.exe (file missing)
skanowalem kompa poprzez ad-aware, rowniez rejestr poprzez RegCleaner!