szukam... tyle że jak ten komunikat wcisnę to ładuje mi stronkę spyaxa 
 [ Dodano: Dzisiaj o 0:39 ]
 [ Dodano: Dzisiaj o 0:39 ]coś nie może znaleść...  czy jest jeszce jakaś propozycja ?? 
heh ile ja sie tu naucze  
 [ Dodano: Dzisiaj o 10:13 ]
 [ Dodano: Dzisiaj o 10:13 ]nadal jest to samo .. włączam kompa i cholerstwo sie już samo instaluje.... 
[ Dodano: Dzisiaj o 10:35 ]zrobiłem wszystko od początku
włączyłem awaryjne
usunołem  HijackThis tą linię z spyaxe
odinstalowałem spy axe z panelu ster.
zrobiłem regedit
w killboxie nie znalazł takiego pliku 
[ Dodano: Dzisiaj o 10:37 ]jeszcze raaz przesyłam logi
- Kod: Zaznacz wszystko
- Logfile of HijackThis v1.99.1
 Scan saved at 09:24:21, on 2005-12-29
 Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\mozilla.org\Mozilla\mozilla.exe
 C:\PROGRA~1\ACDSYS~1\ACDSEE~1\ACDSee.exe
 C:\DOCUME~1\Dom\USTAWI~1\Temp\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.interia.pl/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
 O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [C-Media Echo Control] C:\Program Files\PCI Audio Applications\Bin\EchoCtrl.exe
 O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
 O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
 O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
 O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
 O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
 O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
 O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 
- Kod: Zaznacz wszystko
- "Silent Runners.vbs", revision 41, http://www.silentrunners.org/
 Operating System: Windows XP SP2
 Output limited to non-default values, except where indicated by "{++}"
 
 
 Startup items buried in registry:
 ---------------------------------
 
 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
 "Gadu-Gadu" = ""C:\Program Files\Gadu-Gadu\gg.exe" /tray" ["Gadu-Gadu Sp. z oo"]
 
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
 "ATIPTA" = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" ["ATI Technologies, Inc."]
 "C-Media Echo Control" = "C:\Program Files\PCI Audio Applications\Bin\EchoCtrl.exe" [empty string]
 "C-Media Mixer" = "Mixer.exe /startup" ["C-Media Electronic Inc. (www.cmedia.com.tw)"]
 "avast!" = "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [null data]
 "AVG7_CC" = "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP" ["GRISOFT, s.r.o."]
 "AVG7_EMC" = "C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe" ["GRISOFT, s.r.o."]
 "MSConfig" = "C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto" [MS]
 
 HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
 "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
 -> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
 "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
 -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
 "{59850401-6664-101B-B21C-00AA004BA90B}" = "Microsoft Office Binder Unbind"
 -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\1045\UNBIND.DLL" [MS]
 "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
 -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS]
 "{32020A01-506E-484D-A2A8-BE3CF17601C3}" = "AlcoholShellEx"
 -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\ALCOHO~1\ALCOHO~1\AXShlEx.dll" ["Alcohol Soft Development Team"]
 "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 "{2E9FFF5C-4375-494d-951F-098BAA42239E}" = "Spy Emergency Extension"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Spy Emergency 2005\SpyEmergencyExt.dll" [file not found]
 "{21569614-B795-46b1-85F4-E737A8DC09AD}" = "Shell Search Band"
 -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
 "{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
 "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
 "{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
 
 HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
 INFECTION WARNING! AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]
 
 HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
 avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
 AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
 SpyEmergency\(Default) = "{2E9FFF5C-4375-494d-951F-098BAA42239E}"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Spy Emergency 2005\SpyEmergencyExt.dll" [file not found]
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 
 HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
 SpyEmergency\(Default) = "{2E9FFF5C-4375-494d-951F-098BAA42239E}"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Spy Emergency 2005\SpyEmergencyExt.dll" [file not found]
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 
 HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
 avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
 AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
 SpyEmergency\(Default) = "{2E9FFF5C-4375-494d-951F-098BAA42239E}"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Spy Emergency 2005\SpyEmergencyExt.dll" [file not found]
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 
 
 Active Desktop and Wallpaper:
 -----------------------------
 
 Active Desktop is disabled at this entry:
 HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
 
 HKCU\Control Panel\Desktop\
 "Wallpaper" = "C:\WINDOWS\ACD Wallpaper.bmp"
 
 
 Enabled Screen Saver:
 ---------------------
 
 HKCU\Control Panel\Desktop\
 "SCRNSAVE.EXE" = "C:\WINDOWS\System32\logon.scr" [MS]
 
 
 Winsock2 Service Provider DLLs:
 -------------------------------
 
 Namespace Service Providers
 
 HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
 000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
 000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
 000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
 
 Transport Service Providers
 
 HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
 %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 11
 %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05
 
 
 Toolbars, Explorer Bars, Extensions:
 ------------------------------------
 
 Extensions (Tools menu items, main toolbar menu buttons)
 
 HKLM\Software\Microsoft\Internet Explorer\Extensions\
 {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
 "MenuText" = "Sun Java Console"
 "CLSIDExtension" = "{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}"
 -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll" ["Sun Microsystems, Inc."]
 
 {FB5F1910-F110-11D2-BB9E-00C04F795683}\
 "ButtonText" = "Messenger"
 "MenuText" = "Windows Messenger"
 "Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]
 
 
 All Non-Disabled Services (Display Name, Service Name, Path {Service DLL}):
 ---------------------------------------------------------------------------
 
 Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\system32\Ati2evxx.exe" ["ATI Technologies Inc."]
 ATI Smart, ATI Smart, "C:\WINDOWS\system32\ati2sgag.exe" [empty string]
 avast! Antivirus, avast! Antivirus, ""C:\Program Files\Alwil Software\Avast4\ashServ.exe"" [null data]
 avast! iAVS4 Control Service, aswUpdSv, ""C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"" [null data]
 avast! Mail Scanner, avast! Mail Scanner, ""C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service" ["ALWIL Software"]
 avast! Web Scanner, avast! Web Scanner, ""C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service" ["ALWIL Software"]
 AVG7 Alert Manager Server, Avg7Alrt, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe" ["GRISOFT, s.r.o."]
 AVG7 Update Service, Avg7UpdSvc, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe" ["GRISOFT, s.r.o."]
 HTTP SSL, HTTPFilter, "C:\WINDOWS\System32\svchost.exe -k HTTPFilter" {"C:\WINDOWS\System32\w3ssl.dll" [MS]}
 Karta wydajności WMI, WmiApSrv, "C:\WINDOWS\System32\wbem\wmiapsrv.exe" [MS]
 LexBce Server, LexBceS, "C:\WINDOWS\system32\LEXBCES.EXE" ["Lexmark International, Inc."]
 Macromedia Licensing Service, Macromedia Licensing Service, ""C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe"" [null data]
 StarWind iSCSI Service, StarWindService, "C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe" ["Rocket Division Software"]
 Usługa administracyjna Menedżera dysków logicznych, dmadmin, "C:\WINDOWS\System32\dmadmin.exe /com" ["Microsoft Corp., Veritas Software"]
 Usługa dostarczania sieci, xmlprov, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\xmlprov.dll" [MS]}
 Usługa numeru seryjnego multimediów przenośnych, WmdmPmSN, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\mspmsnsv.dll" [MS]}
 
 
 Print Monitors:
 ---------------
 
 HKLM\System\CurrentControlSet\Control\Print\Monitors\
 Lexmark Network Port\Driver = "LEXLMPM.DLL" ["Lexmark International, Inc."]
 OLFax Ports\Driver = "OLFMNT40.DLL" [MS]
 
 
 ----------
 + This report excludes default entries except where indicated.
 + To see *everywhere* the script checks and *everything* it finds,
 launch it from a command prompt or a shortcut with the -all parameter.
 + The search for DESKTOP.INI DLL launch points on all local fixed drives
 took 154 seconds.
 + The search for all Registry CLSIDs containing dormant Explorer Bars
 took 46 seconds.
 ---------- (total run time: 258 seconds)
 
[ Dodano: Dzisiaj o 10:44 ]po restarcie znowu sam sie zainstalował   
 
   
  
  już nie daje rady
pewnie czeka mnie format  
 
   [ Dodano: Dzisiaj o 15:06 ]
 [ Dodano: Dzisiaj o 15:06 ]widzę że nikt mi nie pomoże z tym cholerstwem 
