

Logfile of HijackThis v1.99.1
Scan saved at 22:44:21, on 2006-02-11
Platform: Windows XP Dodatek SP2
(WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2
(6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common
Files\Microsoft
Shared\VS7Debug\mdm.exe
C:\Program Files\Analog
Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI
Technologies\ATI.ACE\cli.exe
C:\PROGRA~1\WANADOO\TaskbarIcon.e
xe
C:\Program Files\DAP\DAP.EXE
C:\Program Files\ATI
Technologies\ATI.ACE\CLI.exe
C:\Program Files\SAGEM\SAGEM F@st
800-840\dslmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\My Downloads\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet
Explorer\Main,Start Page =
http://www.neostrada.pl/
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Window Title =
Neostrada Plus wita Cie w Internecie
R0 - HKCU\Software\Microsoft\Internet
Explorer\Toolbar,LinksFolderName =
Łącza
O2 - BHO: AcroIEHlprObj Class -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0
B3} - C:\Program Files\Adobe\Acrobat
7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet Toolbar Helper -
{6A373B7E-496E-424f-A9BE-486A5E9AB01
8} - C:\Program Files\BitComet
Toolbar\v2.0.0.1\BitComet_Toolbar.dll
O2 - BHO: NAV Helper -
{BDF3E430-B101-42AD-A544-FADC6B0848
72} - C:\Program Files\Norton
AntiVirus\NavShExt.dll (file missing)
O3 - Toolbar: BitComet Toolbar -
{2E608F70-C430-4bc5-96F6-608E02EBA5B
2} - C:\Program Files\BitComet
Toolbar\v2.0.0.1\BitComet_Toolbar.dll
O3 - Toolbar: Norton AntiVirus -
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1
D6} - C:\Program Files\Norton
AntiVirus\NavShExt.dll (file missing)
O4 - HKLM\..\Run: [ATIPTA] C:\Program
Files\ATI Technologies\ATI Control
Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program
Files\ATI Technologies\ATI.ACE\cli.exe"
runtime
O4 - HKLM\..\Run: [NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WOOWATCH]
C:\PROGRA~1\WANADOO\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON]
C:\PROGRA~1\WANADOO\TaskbarIcon.e
xe
O4 - HKLM\..\Run:
[DownloadAccelerator] "C:\Program
Files\DAP\DAP.EXE" /STARTUP
O4 - HKLM\..\Run: [MSConfig]
C:\WINDOWS\PCHealth\HelpCtr\Binaries
\MSConfig.exe /auto
O4 - Global Startup: ATI CATALYST –
pasek zadań.lnk = C:\Program Files\ATI
Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: DSLMON.lnk =
C:\Program Files\SAGEM\SAGEM F@st
800-840\dslmon.exe
O8 - Extra context menu item: &Clean
Traces - C:\Program Files\DAP\Privacy
Package\dapcleanerie.htm
O8 - Extra context menu item:
&Download with &DAP - C:\Program
Files\DAP\dapextie.htm
O8 - Extra context menu item:
Download &all with DAP - C:\Program
Files\DAP\dapextie2.htm
O9 - Extra button: Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F79568
3} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows
Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F79568
3} - C:\Program
Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://skaner.mks.com.pl
O16 - DPF:
{E7544C6C-CFD6-43EA-B4E9-360CEE20BD
F7} (MainControl Class) -
http://www.mks.com.pl/skaner/SkanerO
nline.cab
O18 - Protocol: ms-help -
{314111C7-A502-11D2-BBCA-00C04F8EC2
94} - C:\Program Files\Common
Files\Microsoft Shared\Help\hxds.dll
O23 - Service: Ati HotKey Poller - ATI
Technologies Inc. -
C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown
owner -
C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table
Manager (IDriverT) - Macrovision
Corporation - C:\Program Files\Common
Files\InstallShield\Driver\1050\Intel
32\IDriverT.exe
O23 - Service: MkS_Vir Monitor
(MksVirMonSvc) - Unknown owner -
C:\Program
Files\MKS\Bin\mksmonsv.exe (file
missing)
O23 - Service: SAVScan - Unknown
owner - C:\Program Files\Norton
AntiVirus\SAVScan.exe (file missing)
O23 - Service: SoundMAX Agent Service
(SoundMAX Agent Service (default)) -
Analog Devices, Inc. - C:\Program
Files\Analog
Devices\SoundMAX\SMAgent.exe