
proszę o sprawdzenie logów;)
HiJackThiS
- Kod: Zaznacz wszystko
- Logfile of HijackThis v1.99.1
 Scan saved at 19:24:32, on 2006-09-13
 Platform: Windows XP (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 (6.00.2600.0000)
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\csrss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\explorer.exe
 C:\WINDOWS\System32\nvsvc32.exe
 C:\WINDOWS\System32\wdfmgr.exe
 C:\WINDOWS\System32\RUNDLL32.EXE
 C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00003.exe
 C:\WINDOWS\System32\cmd32.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\Skype\Phone\Skype.exe
 C:\Program Files\Gadu-Gadu\gg.exe
 C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
 C:\winstall.exe
 C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00003.exe
 C:\WINDOWS\System32\z14.exe
 C:\DOCUME~1\LONTMM~1\USTAWI~1\Temp\msn.exe
 C:\Program Files\Common Files\Microsoft Shared\Web Folders\_ibm00005.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe
 C:\WINDOWS\System32\WScript.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\WINDOWS\System32\wbem\wmiprvse.exe
 C:\WINDOWS\System32\dwwin.exe
 C:\Documents and Settings\Lont MMMS\Pulpit\HijackThis.exe
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
 R3 - Default URLSearchHook is missing
 F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe"
 O1 - Hosts: localhost 127.0.0.1
 O2 - BHO: Acrobat IE Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE083} - C:\WINDOWS\system\ctldlg32.dll
 O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\System32\{65679DC4-35E3-496D-ADBF-FC9ADDCA5801}.dll (file missing)
 O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
 O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL
 O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\System32\{65679DC4-35E3-496D-ADBF-FC9ADDCA5801}.dll (file missing)
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
 O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [windows auto update] msblast.exe
 O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\System32\cmd32.exe internat.dll,LoadKeyboardProfile
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
 O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
 O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
 O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
 O16 - DPF: {2A781DED-C22D-4153-9812-CEA98A32981C} (GameDesire Makao) - http://67.15.101.3/g_bin/pl/cardsmakao_2_0_0_24.cab
 O16 - DPF: {70B410C0-BADA-11D4-8308-0080C8D7ED4A} (GameDesire Bridge) - http://67.15.101.3/g_bin/eng/bridge_2_0_0_20.cab
 O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} (GameDesire Poker Games) - http://67.15.101.3/g_bin/eng/poker_2_0_0_43.cab
 O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) - http://67.15.101.3/g_bin/pl/billard8_2_0_0_28.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{421950AC-BF2B-43AF-8611-AE39297C430F}: NameServer = 85.255.114.196,85.255.112.149
 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.196 85.255.112.149
 O17 - HKLM\System\CS1\Services\Tcpip\..\{421950AC-BF2B-43AF-8611-AE39297C430F}: NameServer = 85.255.114.196,85.255.112.149
 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.114.196 85.255.112.149
 O17 - HKLM\System\CS2\Services\Tcpip\..\{421950AC-BF2B-43AF-8611-AE39297C430F}: NameServer = 85.255.114.196,85.255.112.149
 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.196 85.255.112.149
 O23 - Service: Microsoft ASPI Manager (aspi113210) - Unknown owner - C:\WINDOWS\System32\aspi13779.exe (file missing)
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
I Silent oczywiście:
- Kod: Zaznacz wszystko
- "Silent Runners.vbs", revision 46, http://www.silentrunners.org/
 Operating System: Windows XP
 Output limited to non-default values, except where indicated by "{++}"
 Startup items buried in registry:
 ---------------------------------
 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
 "MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [MS]
 "Skype" = ""C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized" ["Skype Technologies S.A."]
 "Gadu-Gadu" = ""C:\Program Files\Gadu-Gadu\gg.exe" /tray" ["Gadu-Gadu Sp. z oo"]
 "swg" = "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe" ["Google Inc."]
 "Windows installer" = "C:\winstall.exe" [null data]
 "taskdir" = "C:\WINDOWS\System32\taskdir.exe" [null data]
 "shell" = ""C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe"" [null data]
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
 "NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup" [MS]
 "nwiz" = "nwiz.exe /install" ["NVIDIA Corporation"]
 "NvMediaCenter" = "RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit" [MS]
 "CloneCDElbyCDFL" = ""C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL" ["Elaborate Bytes AG"]
 "CloneCDTray" = ""C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"" ["Elaborate Bytes AG"]
 "NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
 "SunJavaUpdateSched" = "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" ["Sun Microsystems, Inc."]
 "windows auto update" = "msblast.exe" [file not found]
 "ControlPanel" = "C:\WINDOWS\System32\cmd32.exe internat.dll,LoadKeyboardProfile" [null data]
 "dmqel.exe" = "C:\WINDOWS\System32\dmqel.exe" [file not found]
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
 {06849E9F-C8D7-4D59-B87D-784B7D6BE083}\(Default) = "Acrobat IE Helper"
 -> {HKLM...CLSID} = (no title provided)
 \InProcServer32\(Default) = "C:\WINDOWS\system\ctldlg32.dll" [null data]
 {08BEC6AA-49FC-4379-3587-4B21E286C19E}\(Default) = (no title provided)
 -> {HKLM...CLSID} = "SearchToolbar"
 \InProcServer32\(Default) = "C:\WINDOWS\System32\{65679DC4-35E3-496D-ADBF-FC9ADDCA5801}.dll" [file not found]
 {37B85A21-692B-4205-9CAD-2626E4993404}\(Default) = "My Global Search Bar BHO"
 -> {HKLM...CLSID} = "My Global Search Bar BHO"
 \InProcServer32\(Default) = "C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL" ["My Global Search"]
 {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
 -> {HKLM...CLSID} = "SSVHelper Class"
 \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll" ["Sun Microsystems, Inc."]
 {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
 -> {HKLM...CLSID} = "Google Toolbar Helper"
 \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]
 HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
 "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
 -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
 \InProcServer32\(Default) = "deskpan.dll" [file not found]
 "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
 -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
 \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
 "{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
 -> {HKLM...CLSID} = "DesktopContext Class"
 \InProcServer32\(Default) = "C:\WINDOWS\System32\nvcpl.dll" ["NVIDIA Corporation"]
 "{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
 -> {HKLM...CLSID} = "NVIDIA CPL Extension"
 \InProcServer32\(Default) = "C:\WINDOWS\System32\nvcpl.dll" ["NVIDIA Corporation"]
 "{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
 -> {HKLM...CLSID} = "Desktop Explorer"
 \InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
 "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
 -> {HKLM...CLSID} = (no title provided)
 \InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
 "{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"
 -> {HKLM...CLSID} = "nView Desktop Context Menu"
 \InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
 "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 "{32020A01-506E-484D-A2A8-BE3CF17601C3}" = "AlcoholShellEx"
 -> {HKLM...CLSID} = "AlcoholShellEx"
 \InProcServer32\(Default) = "C:\PROGRA~1\ALCOHO~1\ALCOHO~1\AXShlEx.dll" ["Alcohol Soft Development Team"]
 "{0E6C58A9-F592-4862-B35F-CA45E24003B3}" = "CloneCD"
 -> {HKLM...CLSID} = "CloneCD Shell Extension"
 \InProcServer32\(Default) = "C:\Program Files\Elaborate Bytes\CloneCD\ElbyVCDShell.dll" ["Elaborate Bytes"]
 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
 INFECTION WARNING! "Shell" = "explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe"" [MS], [file not found], [file not found], [file not found], [file not found], [file not found]
 INFECTION WARNING! "System" = "cspxl.exe" [null data]
 HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 Group Policies [Description] {enabled Group Policy setting}:
 ------------------------------------------------------------
 HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
 HIJACK WARNING! "ForceActiveDesktopOn"=dword:00000001
 [enables Active Desktop and prevents disabling it]
 {User Configuration|Administrative Templates|Desktop|Active Desktop|
 Enable Active Desktop}
 "Wallpaper" = (value not set)
 [disables the Display Properties|Desktop (tab) (except the "Customize
 Desktop..." button); selects wallpaper if Active Desktop is enabled]
 {User Configuration|Administrative Templates|Desktop|Active Desktop|
 Active Desktop Wallpaper|Wallpaper Name:}
 Active Desktop and Wallpaper:
 -----------------------------
 Active Desktop enabled via Group Policy.
 Wallpaper selected via Group Policy.
 Enabled Screen Saver:
 ---------------------
 HKCU\Control Panel\Desktop\
 HKCU\Software\Microsoft\Internet Explorer\Desktop\Components\0\
 "SCRNSAVE.EXE" = "C:\WINDOWS\System32\logon.scr" [MS]
Silentem tylko tyle idzie zrobić bo potem wyskakuje jakiś bład i nie skanuje dalej
 
				

 
	

 
	



 
	

