
oto mój log:
- Kod: Zaznacz wszystko
Logfile of HijackThis v1.99.1
Scan saved at 11:32:23, on 2005-11-27
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/System32/Ati2evxx.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/spoolsv.exe
C:/WINDOWS/system32/Ati2evxx.exe
C:/WINDOWS/Explorer.EXE
C:/WINDOWS/SOUNDMAN.EXE
C:/Program Files/Winamp/winampa.exe
C:/Program Files/AVPersonal/AVGNT.EXE
C:/Program Files/Java/j2re1.4.2_04/bin/jusched.exe
C:/WINDOWS/System32/ctfmon.exe
C:/Program Files/Java/j2re1.4.2_04/bin/jucheck.exe
C:/Program Files/Gadu-Gadu/gg.exe
C:/Program Files/AVPersonal/AVGUARD.EXE
C:/Program Files/AVPersonal/AVWUPSRV.EXE
C:/WINDOWS/tool2.exe
C:/WINDOWS/System32/paytime.exe
C:/Documents and Settings/marcin/Pulpit/HijackThis.exe
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = c:/secure32.html
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = c:/secure32.html
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = c:/secure32.html
R0 - HKLM/Software/Microsoft/Internet Explorer/Main,Start Page = c:/secure32.html
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Local Page = c:/secure32.html
R0 - HKLM/Software/Microsoft/Internet Explorer/Main,Local Page = c:/secure32.html
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:/Program Files/Adobe/Acrobat 7.0/ActiveX/AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O4 - HKLM/../Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM/../Run: [ATICCC] "C:/Program Files/ATI Technologies/ATI.ACE/cli.exe" runtime
O4 - HKLM/../Run: [WinampAgent] C:/Program Files/Winamp/winampa.exe
O4 - HKLM/../Run: [AVGCtrl] "C:/Program Files/AVPersonal/AVGNT.EXE" /min
O4 - HKLM/../Run: [SunJavaUpdateSched] C:/Program Files/Java/j2re1.4.2_04/bin/jusched.exe
O4 - HKLM/../Run: [PayTime] C:/WINDOWS/System32/paytime.exe
O4 - HKLM/../RunOnce: [data] cmd /C DEL C:/WINDOWS/WindUp.exe
O4 - HKLM/../RunOnce: [win] svc.exe
O4 - HKCU/../Run: [CTFMON.EXE] C:/WINDOWS/System32/ctfmon.exe
O4 - HKCU/../Run: [MSMSGS] "C:/Program Files/Messenger/msmsgs.exe" /background
O4 - HKCU/../Run: [Gadu-Gadu] "C:/Program Files/Gadu-Gadu/gg.exe" /tray
O4 - HKCU/../Run: [Windows installer] C:/winstall.exe
O4 - HKCU/../Run: [PayTime] C:/WINDOWS/System32/paytime.exe
O4 - HKCU/../RunOnce: [data] cmd /C DEL C:/WINDOWS/WindUp.exe
O4 - HKCU/../RunOnce: [win] svc.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:/Program Files/ATI Technologies/ATI.ACE/CLI.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:/Program Files/Adobe/Acrobat 7.0/Reader/reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:/Program Files/Java/j2re1.4.2_04/bin/npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:/Program Files/Java/j2re1.4.2_04/bin/npjpi142_04.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:/WINDOWS/web/related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:/WINDOWS/web/related.htm
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:/Program Files/AVPersonal/AVGUARD.EXE
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:/WINDOWS/System32/Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:/WINDOWS/system32/ati2sgag.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:/Program Files/AVPersonal/AVWUPSRV.EXE[code][/code]