
- Kod: Zaznacz wszystko
- Logfile of HijackThis v1.99.1
 Scan saved at 21:25:43, on 2006-02-09
 Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\SYSTEM32\winlogon.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\MKS\Bin\NetMonSV.exe
 C:\Program Files\MKS\Bin\mksmonsv.exe
 C:\WINDOWS\System32\nvsvc32.exe
 C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
 C:\WINDOWS\explorer.exe
 C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
 C:\WINDOWS\inet20003\winlogon.exe
 C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
 C:\PROGRA~1\NEOSTR~1\CnxMon.exe
 C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
 C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
 C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
 C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
 C:\WINDOWS\SM1BG.EXE
 C:\Program Files\MKS\Bin\mks_menu.exe
 C:\Program Files\MKS\Bin\ABregmon.exe
 C:\Program Files\D-Tools\daemon.exe
 C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
 C:\Program Files\MKS\Bin\mks_scan.exe
 C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
 C:\Program Files\Neostrada TP\NeostradaTP.exe
 C:\Program Files\Neostrada TP\ComComp.exe
 C:\Program Files\Neostrada TP\Watch.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\WINDOWS\system32\j?vaw.exe
 C:\WINDOWS\inet20003\mm4.exe
 C:\WINDOWS\System32\dllcache\IExplore.exe
 C:\WINDOWS\System32\dllcache\IExplore.exe
 C:\DOCUME~1\SADOWS~1\USTAWI~1\Temp\!update.exe
 C:\Program Files\bsal\traa.exe
 C:\WINDOWS\System32\dllcache\IExplore.exe
 C:\WINDOWS\System32\dllcache\IExplore.exe
 C:\Documents and Settings\Sadowski Bartłomiej\Pulpit\Programy\HijackThis.exe
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://szukaj.wp.pl
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neostrada.pl
 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.wp.pl/
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada TP
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
 R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL
 R3 - URLSearchHook: (no name) - {CD467844-ECAE-E103-D10E-BB3EC2222797} - C:\WINDOWS\System32\nwazbuc.dll
 R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
 F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
 F3 - REG:win.ini: run=C:\WINDOWS\inet20003\winlogon.exe
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
 O2 - BHO: HBO Class - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - C:\WINDOWS\inet20003\3.01.00.dll (file missing)
 O2 - BHO: (no name) - {CD467844-ECAE-E103-D10E-BB3EC2222797} - C:\WINDOWS\System32\nwazbuc.dll
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [Resume copy] copyfstq.exe /startup
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [WheelMouse] C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
 O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\NEOSTR~1\CnxMon.exe
 O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
 O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe
 O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
 O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
 O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
 O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
 O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
 O4 - HKLM\..\Run: [HostSrv] C:\WINDOWS\sachostx.exe
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [MKS_MENU] C:\Program Files\MKS\Bin\mks_menu.exe
 O4 - HKLM\..\Run: [ABREGMON] C:\Program Files\MKS\Bin\ABregmon.exe
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
 O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inet20003\winlogon.exe
 O4 - HKCU\..\Run: [Mouse Meter] C:\PROGRA~1\MOUSEM~1\MOUSEM~1.EXE
 O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
 O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inet20003\winlogon.exe
 O4 - HKCU\..\Run: [Eatb] "C:\Program Files\bsal\traa.exe" -vt mt
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
 O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
 O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab
 O16 - DPF: {631FF594-EC25-4CFF-B869-402DF294E1D6} (Instalator oprogramowania Onet.pl) - http://slimak.onet.pl/_m/kamerzysta/OnetInstalator012s.ocx
 O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab?refid=5071
 O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) - http://67.15.101.3/g_bin/pl/billard8_2_0_0_23.cab
 O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C5} (GameDesire Snooker) - http://67.15.101.3/g_bin/pl/snooker_2_0_0_24.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{1FAF3DEF-BC5A-4863-96B2-4F00AD071ECB}: NameServer = 194.204.152.34 217.98.63.164
 O20 - AppInit_DLLs: C:\WINDOWS\System32\tmp_26g.dll
 O20 - Winlogon Notify: winhoo32 - C:\WINDOWS\SYSTEM32\winhoo32.dll
 O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
 O23 - Service: ArcaBit NetMonitor (ABNetMon) - ArcaBit sp. z o.o. - C:\Program Files\MKS\Bin\NetMonSV.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: MkSUpdateInt - MkS Sp. z o. o. - C:\Program Files\MKS\bin\MkSUpdateInt.exe
 O23 - Service: MkS_Vir Monitor (MksVirMonSvc) - Unknown owner - C:\Program Files\MKS\Bin\mksmonsv.exe
 O23 - Service: MkS_Scan - Unknown owner - C:\Program Files\MKS\Bin\mks_scan.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
 O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
- Kod: Zaznacz wszystko
- "Silent Runners.vbs", revision 41, http://www.silentrunners.org/
 Operating System: Windows XP
 Output limited to non-default values, except where indicated by "{++}"
 Startup items buried in registry:
 ---------------------------------
 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
 "Mouse Meter" = "C:\PROGRA~1\MOUSEM~1\MOUSEM~1.EXE" [file not found]
 "Gadu-Gadu" = ""C:\Program Files\Gadu-Gadu\gg.exe" /tray" ["Gadu-Gadu Sp. z oo"]
 "xp_system" = "C:\WINDOWS\inet20003\winlogon.exe" [null data]
 "Eatb" = ""C:\Program Files\bsal\traa.exe" -vt mt" [null data]
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
 "NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup" [MS]
 "nwiz" = "nwiz.exe /install" ["NVIDIA Corporation"]
 "Resume copy" = "copyfstq.exe /startup" [null data]
 "NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
 "WheelMouse" = "C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe" ["A4Tech Co.,Ltd."]
 "KernelFaultCheck" = "C:\WINDOWS\system32\dumprep 0 -k" [MS]
 "WooCnxMon" = "C:\PROGRA~1\NEOSTR~1\CnxMon.exe" [empty string]
 "SpeedTouch USB Diagnostics" = ""C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon" ["THOMSON Telecom Belgium"]
 "WOOWATCH" = "C:\PROGRA~1\NEOSTR~1\Watch.exe" ["France Télécom R&D"]
 "WOOTASKBARICON" = "C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe" ["France Télécom R&D"]
 "SunJavaUpdateSched" = "C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe" ["Sun Microsystems, Inc."]
 "HP Software Update" = "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" ["Hewlett-Packard Co."]
 "HP Component Manager" = ""C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"" ["Hewlett-Packard Company"]
 "HPDJ Taskbar Utility" = "C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe" ["HP"]
 "SM1BG" = "C:\WINDOWS\SM1BG.EXE" ["Cypress Semiconductor"]
 "HostSrv" = "C:\WINDOWS\sachostx.exe" [file not found]
 "NvMediaCenter" = "RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit" [MS]
 "MKS_MENU" = "C:\Program Files\MKS\Bin\mks_menu.exe" ["MKS Sp. z o.o."]
 "ABREGMON" = "C:\Program Files\MKS\Bin\ABregmon.exe" ["ArcaBit"]
 "QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
 "DAEMON Tools-1033" = ""C:\Program Files\D-Tools\daemon.exe" -lang 1033" ["DAEMON'S HOME"]
 "PCSuiteTrayApplication" = "C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray" ["Nokia"]
 "xp_system" = "C:\WINDOWS\inet20003\winlogon.exe" [null data]
 HKLM\Software\Microsoft\Active Setup\Installed Components\
 {306D6C21-C1B6-4629-986C-E59E1875B8AF}\(Default) = (no title provided)
 \StubPath = ""C:\WINDOWS\System32\rundll32.exe" "C:\Program Files\Messenger\msgsc.dll",ShowIconsUser" [MS]
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
 {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx" [empty string]
 {5321E378-FFAD-4999-8C62-03CA8155F0B3}\(Default) = "HBO Class" [from CLSID]
 -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\inet20003\3.01.00.dll" [file not found]
 {CD467844-ECAE-E103-D10E-BB3EC2222797}\(Default) = (no title provided)
 -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nwazbuc.dll" [null data]
 HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
 "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
 -> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
 "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
 -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
 "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" = "WebCheck"
 -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\xp9152.dll" [null data]
 "{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
 -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvcpl.dll" ["NVIDIA Corporation"]
 "{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
 -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
 "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
 -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
 "{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"
 -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
 "{A4D78B20-6E05-1069-8758-4E73FD83DEAD}" = "QCopy"
 -> {CLSID}\InProcServer32\(Default) = "dropcpyr.dll" [null data]
 "{59850401-6664-101B-B21C-00AA004BA90B}" = "Microsoft Office Binder Unbind"
 -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\1045\UNBIND.DLL" [MS]
 "{32020A01-506E-484D-A2A8-BE3CF17601C3}" = "AlcoholShellEx"
 -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\ALCOHO~1\ALCOHO~1\AXShlEx.dll" ["Alcohol Soft Development Team"]
 "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 "{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
 -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Audiodev.dll" [MS]
 "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
 -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Audiodev.dll" [MS]
 "{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
 -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvcpl.dll" ["NVIDIA Corporation"]
 "{7C9D5882-CB4A-4090-96C8-430BFE8B795B}" = "Webroot Spy Sweeper Context Menu Integration"
 -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll" ["Webroot Software, Inc."]
 "{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A}" = "PhoneBrowser"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll" ["Nokia"]
 "{C0C4375A-5B72-4efe-929D-3B848C3A1E91}" = "Message View"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Nokia\Nokia PC Suite 6\MessageView.dll" ["Nokia"]
 HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
 "WebCheck" = "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
 -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\xp9152.dll" [null data]
 HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\
 INFECTION WARNING! "run" = "C:\WINDOWS\inet20003\winlogon.exe" [null data]
 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\
 INFECTION WARNING! "AppInit_DLLs" = "C:\WINDOWS\System32\tmp_26g.dll" [null data]
 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
 INFECTION WARNING! "Shell" = "explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"" [MS], [file not found], [file not found], [file not found], [file not found], [file not found]
 HKLM\System\CurrentControlSet\Control\Session Manager\
 INFECTION WARNING! "BootExecute" = "autocheck autochk * SsiEfr.e" [file not found], [MS], [file not found], [file not found]
 HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
 INFECTION WARNING! winhoo32\DLLName = "winhoo32.dll" [null data]
 INFECTION WARNING! WRNotifier\DLLName = "WRLogonNTF.dll" ["Webroot Software, Inc."]
 HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
 MkS_Vir\(Default) = "{CC4245C0-D511-11D0-8918-444553540000}"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\MKS\Bin\MkSShell.dll" [null data]
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 WinUHA\(Default) = "{095177B8-8097-4D32-9081-A8949C47020E}"
 -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WinUHA\SHELLW~1.DLL" [null data]
 HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
 MkS_Vir\(Default) = "{CC4245C0-D511-11D0-8918-444553540000}"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\MKS\Bin\MkSShell.dll" [null data]
 SpySweeper\(Default) = "{7C9D5882-CB4A-4090-96C8-430BFE8B795B}"
 -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll" ["Webroot Software, Inc."]
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 WinUHA\(Default) = "{095177B8-8097-4D32-9081-A8949C47020E}"
 -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WinUHA\SHELLW~1.DLL" [null data]
 Active Desktop and Wallpaper:
 -----------------------------
 Active Desktop is disabled at this entry:
 HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
 HKCU\Control Panel\Desktop\
 "Wallpaper" = "C:\Documents and Settings\Sadowski Bartłomiej\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"
 Enabled Screen Saver:
 ---------------------
 HKCU\Control Panel\Desktop\
 "SCRNSAVE.EXE" = "C:\WINDOWS\System32\logon.scr" [MS]
 Startup items in "Sadowski Bartłomiej" & "All Users" startup folders:
 ---------------------------------------------------------------------
 C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
 "Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office\OSA9.EXE -b -l" [MS]
 "Adobe Gamma Loader" -> shortcut to: "C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe" ["Adobe Systems, Inc."]
 Enabled Scheduled Tasks:
 ------------------------
 "MkSUpdate" -> launches: "C:\Program Files\MKS\bin\mks_upd.exe Task" ["MkS Sp. z o. o."]
 Winsock2 Service Provider DLLs:
 -------------------------------
 Namespace Service Providers
 HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
 000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
 000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
 000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
 Transport Service Providers
 HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
 %SystemRoot%\system32\mswsock.dll [MS], 01 - 04, 07 - 18
 %SystemRoot%\system32\rsvpsp.dll [MS], 05 - 06
 Toolbars, Explorer Bars, Extensions:
 ------------------------------------
 Explorer Bars
 Dormant Explorer Bars in "View, Explorer Bar" menu
 HKLM\Software\Classes\CLSID\{01002DB2-8170-4D9B-A8B1-DDC9DD114E03}\ = "Volet Wanadoo"
 Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
 InProcServer32\(Default) = "C:\PROGRA~1\NEOSTR~1\audience\audience.dll" [empty string]
 HKLM\Software\Classes\CLSID\{3BAF4A27-C764-4E1A-A6F4-62F7A7E5E51C}\ = "ToolBand Class"
 Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
 InProcServer32\(Default) = "C:\PROGRA~1\NEOSTR~1\audience\audience.dll" [empty string]
 HKLM\Software\Classes\CLSID\{5BF498C0-931E-4A4F-B33F-456D07137EAA}\ = "Volet Wanadoo"
 Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
 InProcServer32\(Default) = "C:\PROGRA~1\NEOSTR~1\audience\audience.dll" [empty string]
 Extensions (Tools menu items, main toolbar menu buttons)
 HKLM\Software\Microsoft\Internet Explorer\Extensions\
 {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
 "MenuText" = "Sun Java Console"
 "CLSIDExtension" = "{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll" ["Sun Microsystems, Inc."]
 Miscellaneous IE Hijack Points
 ------------------------------
 HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\
 Missing lines (compared with English-language version):
 "{08C06D61-F1F3-4799-86F8-BE1A89362C85}" = "Search Class" [from CLSID]
 -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL" [empty string]
 "{CD467844-ECAE-E103-D10E-BB3EC2222797}" = (no title provided)
 -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nwazbuc.dll" [null data]
 Running Services (Display Name, Service Name, Path {Service DLL}):
 ------------------------------------------------------------------
 ArcaBit NetMonitor, ABNetMon, "C:\Program Files\MKS\Bin\NetMonSV.exe" ["ArcaBit sp. z o.o."]
 MkS_Scan, MkS_Scan, "C:\Program Files\MKS\Bin\mks_scan.exe" [empty string]
 MkS_Vir Monitor, MksVirMonSvc, "C:\Program Files\MKS\Bin\mksmonsv.exe" [empty string]
 NVIDIA Display Driver Service, NVSvc, "C:\WINDOWS\System32\nvsvc32.exe" ["NVIDIA Corporation"]
 Ulead Burning Helper, UleadBurningHelper, "C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe" ["Ulead Systems, Inc."]
 Webroot Spy Sweeper Engine, svcWRSSSDK, "C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe" ["Webroot Software, Inc."]
 Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\System32\wdfmgr.exe" [MS]
 Print Monitors:
 ---------------
 HKLM\System\CurrentControlSet\Control\Print\Monitors\
 hpzlnt09\Driver = "hpzlnt09.dll" ["HP"]
 Monitor języka PJL\Driver = "PJLMON.DLL" [MS]
 ----------
 + This report excludes default entries except where indicated.
 + To see *everywhere* the script checks and *everything* it finds,
 launch it from a command prompt or a shortcut with the -all parameter.
 + The search for DESKTOP.INI DLL launch points on all local fixed drives
 took 81 seconds.
 + The search for all Registry CLSIDs containing dormant Explorer Bars
 took 47 seconds.
 ---------- (total run time: 318 seconds)


 
	
 
  
	
 
	

