
- Kod: Zaznacz wszystko
- Logfile of HijackThis v1.99.1
 Scan saved at 16:06:45, on 2005-12-05
 Platform: Windows XP (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 (6.00.2600.0000)
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\inet20003\services.exe
 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 C:\windows\system32\mdms.exe
 C:\Program Files\Internet Explorer\IEXPLORE.EXE
 C:\Program Files\Gadu-Gadu\gg.exe
 C:\Program Files\eMule\emule.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
 C:\Program Files\Alwil Software\Avast4\ashServ.exe
 C:\WINDOWS\System32\nvsvc32.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
 C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
 C:\WINDOWS\system32\cmd.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Documents and Settings\Pytoo\Pulpit\HijackThis.exe
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://194.63.135.88:8000/listen.pls
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
 F3 - REG:win.ini: run=C:\WINDOWS\inet20003\services.exe
 O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: HBO Class - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - C:\WINDOWS\inet20003\3.00.11.dll
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
 O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
 O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [NVRTCLK] C:\WINDOWS\System32\NVRTCLK\NVRTClk.exe
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [Lexmark 5200 series] "C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe"
 O4 - HKLM\..\Run: [Microsoft Visual SourceSafe] oojovek.exe
 O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
 O4 - HKLM\..\Run: [update] update.exe
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [bxproxy] C:\WINDOWS\bxproxy.exe
 O4 - HKLM\..\Run: [SysMemory manager] c:\windows\system32\mdms.exe
 O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inet20003\services.exe
 O4 - HKLM\..\Run: [Outpost Center] C:\WINDOWS\System32\outpstd.exe
 O4 - HKLM\..\RunServices: [Microsoft Visual SourceSafe] oojovek.exe
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
 O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
 O4 - HKCU\..\Run: [bxproxy] C:\WINDOWS\bxproxy.exe
 O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inet20003\services.exe
 O4 - HKCU\..\Run: [System] C:\WINDOWS\svchost.exe
 O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O8 - Extra context menu item: Download all by Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
 O8 - Extra context menu item: Download by Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
 O8 - Extra context menu item: Download selected by Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
 O8 - Extra context menu item: Download web site by Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
 O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
 O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
 O10 - Broken Internet access because of LSP provider 'mswsck2.dll' missing
 O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) - http://67.15.101.3/g_bin/pl/billard8_2_0_0_24.cab
 O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C5} (GameDesire Snooker) - http://67.15.101.3/g_bin/pl/snooker_2_0_0_24.cab
 O20 - Winlogon Notify: logon032 - C:\WINDOWS\SYSTEM32\logon032.dll
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
 O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
 O23 - Service: lxbt_device - Lexmark International, Inc. - C:\WINDOWS\System32\lxbtcoms.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
prubowalem sciagnac emule ionix nagle komp zlapal laga zresetowalem i na internecie explorer widnieje :
- Kod: Zaznacz wszystko
- Detected SPYware! System error #384
 __________________________________________________________________________
 
 Your IP address is xxx.xxx.xxx.xx. Using this address a remote computer has gained anaccess to your computer and probably is collecting the information about the sites you've visited and the files contained in the folder Temporary Internet Files. Attention! Ask for help or install the software for deleting secret information about the sites you visited.
 
 __________________________________________________________________________
 
 Your computer is full of evidences!
 
 ISP of transmission: EC
 Your IP address: xxx.xxx.xxx.xx
 They know you're using: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; FDM)
 Your computer is: Windows XP
 Risk status for further investigation: VERY HIGH RISK
 
 
 
 
 To protect from the Spyware - click here
 To prevent information transmission - click here
 To delete the history of your activity, click here
Adresy ip wykasowane dla bezpieczeństwa
[ Dodano: Dzisiaj o 16:47 ]
prosze was pomozcie:(


 
	
 
 

 
 
 - http://67.15.101.3/g_bin/pl/billard8_2_0_0_24.cab
 - http://67.15.101.3/g_bin/pl/billard8_2_0_0_24.cab 
  
