
logi
- Kod: Zaznacz wszystko
- Logfile of HijackThis v1.99.1
 Scan saved at 23:24:42, on 2006-12-01
 Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\LEXBCES.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
 C:\WINDOWS\System32\RunDll32.exe
 C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
 C:\Program Files\Mozilla Firefox 2 Beta 2\firefox.exe
 C:\Program Files\Gadu-Gadu\gg.exe
 D:\InStAlKi\HijackThis.exe
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/search/index.html?src=ssb
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com/pl/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
 R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL (file missing)
 R3 - URLSearchHook: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - (no file)
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {192c5b4a-3efd-40c7-9f99-c472deb8efc0} - C:\Program Files\Perfect Codec\isaddon.dll (file missing)
 O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1\FLASHGET\jccatch.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
 O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\PROGRA~1\FLASHGET\getflash.dll
 O2 - BHO: XBTP02634 - {F97DA966-F09D-4cab-BF29-75A0026986EA} - (no file)
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
 O3 - Toolbar: Protection Bar - {bf1ced2c-4b3f-4079-a330-864eda5a4cff} - C:\Program Files\Perfect Codec\iesplugin.dll (file missing)
 O3 - Toolbar: Steganos Internet Anonym - {00000000-5736-4205-0008-781cd0e19f00} - c:\program files\steganos internet anonym pro 7\siapro7iep.dll
 O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
 O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
 O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
 O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1045
 O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
 O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
 O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
 O4 - HKCU\..\Run: [Konnekt] "C:\Program Files\Konnekt\konnekt.exe" /autostart
 O4 - HKCU\..\Run: [AutoConnect] C:\Program Files\AutoConnect\AutoConnect.exe
 O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
 O4 - HKCU\..\Run: [PowerOff] "C:\Program Files\PowerOff\PowerOff.exe" /HIDE
 O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
 O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
 O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\eMule.exe -AutoStart
 O4 - Global Startup: ATI CATALYST – pasek zadań.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
 O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
 O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
 O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O8 - Extra context menu item: Ściągnij przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_link.htm
 O8 - Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_all.htm
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Ochrona WWW - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
 O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
 O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
 O17 - HKLM\System\CCS\Services\Tcpip\..\{152B9901-F943-4617-81DB-43293BE225F7}: NameServer = 194.204.152.34,213.76.136.98
 O17 - HKLM\System\CCS\Services\Tcpip\..\{8B15344E-AD93-440A-8577-6B70A3D489CB}: NameServer = 194.204.152.34 217.98.63.164
 O20 - Winlogon Notify: klogon - C:\WINDOWS\System32\klogon.dll
 O21 - SSODL: featherweed - {ab340860-fd81-4a65-b345-82eb77a66b5e} - C:\WINDOWS\System32\jbtazy.dll (file missing)
 O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
 O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
 O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
 O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
 O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
silent
- Kod: Zaznacz wszystko
- "Silent Runners.vbs", revision 49, http://www.silentrunners.org/
 Operating System: Windows XP
 Output limited to non-default values, except where indicated by "{++}"
 Startup items buried in registry:
 ---------------------------------
 HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
 "Konnekt" = ""C:\Program Files\Konnekt\konnekt.exe" /autostart" ["Stamina"]
 "AutoConnect" = "C:\Program Files\AutoConnect\AutoConnect.exe" [file not found]
 "Gadu-Gadu" = ""C:\Program Files\Gadu-Gadu\gg.exe" /tray" ["Gadu-Gadu S.A."]
 "PowerOff" = ""C:\Program Files\PowerOff\PowerOff.exe" /HIDE" [" "]
 "Skype" = ""C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized" ["Skype Technologies S.A."]
 "swg" = "C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe" ["Google Inc."]
 "eMuleAutoStart" = "C:\Program Files\eMule\eMule.exe -AutoStart" ["http://www.emule-project.net"]
 HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
 "ATICCC" = ""C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime" [null data]
 "Cmaudio" = "RunDll32 cmicnfg.cpl,CMICtrlWnd" [MS]
 "DAEMON Tools" = ""C:\Program Files\DAEMON Tools\daemon.exe" -lang 1045" ["DT Soft Ltd."]
 "CnxDslTaskBar" = ""C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"" ["Conexant Systems, Inc."]
 "QuickTime Task" = ""C:\WINDOWS\system32\qttask.exe" -atboottime" [file not found]
 "kav" = ""C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"" ["Kaspersky Lab"]
 "(Default)" = "(empty string)" [file not found]
 "!AVG Anti-Spyware" = ""C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized" ["Anti-Malware Development a.s."]
 "WinampAgent" = "C:\Program Files\Winamp\winampa.exe" [null data]
 HKLM\Software\Microsoft\Active Setup\Installed Components\
 >{26923b43-4d38-484f-9b9e-de460746276c}\(Default) = "Internet Explorer"
 \StubPath = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigIE" [MS]
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
 {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
 -> {HKLM...CLSID} = "AcroIEHlprObj Class"
 \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
 {192c5b4a-3efd-40c7-9f99-c472deb8efc0}\(Default) = (no title provided)
 -> {HKLM...CLSID} = (no title provided)
 \InProcServer32\(Default) = "C:\Program Files\Perfect Codec\isaddon.dll" [file not found]
 {2F364306-AA45-47B5-9F9D-39A8B94E7EF7}\(Default) = (no title provided)
 -> {HKLM...CLSID} = "IeCatch5 Class"
 \InProcServer32\(Default) = "C:\PROGRA~1\FLASHGET\jccatch.dll" ["FlashGet"]
 {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
 -> {HKLM...CLSID} = "SSVHelper Class"
 \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll" ["Sun Microsystems, Inc."]
 {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
 -> {HKLM...CLSID} = "Google Toolbar Helper"
 \InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."]
 {F156768E-81EF-470C-9057-481BA8380DBA}\(Default) = (no title provided)
 -> {HKLM...CLSID} = "gFlash Class"
 \InProcServer32\(Default) = "C:\PROGRA~1\FLASHGET\getflash.dll" [null data]
 HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
 "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
 -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
 \InProcServer32\(Default) = "deskpan.dll" [file not found]
 "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
 -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
 \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
 "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
 -> {HKLM...CLSID} = (no title provided)
 \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\OFFICE11\msohev.dll" [MS]
 "{5E2121EE-0300-11D4-8D3B-444553540000}" = "Catalyst Context Menu extension"
 -> {HKLM...CLSID} = "SimpleShlExt Class"
 \InProcServer32\(Default) = "C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll" [empty string]
 "{B089FE88-FB52-11d3-BDF1-0050DA34150D}" = "NOD32 Context Menu Shell Extension"
 -> {HKLM...CLSID} = "NOD32 Context Menu Shell Extension"
 \InProcServer32\(Default) = "C:\Program Files\Eset\nodshex.dll" [file not found]
 "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
 -> {HKLM...CLSID} = "RealOne Player Context Menu Class"
 \InProcServer32\(Default) = "C:\Program Files\ACE Mega CoDecS Pack\SystemS\RealMedia\rpshell.dll" ["RealNetworks, Inc."]
 "{85E0B171-04FA-11D1-B7DA-00A0C90348D6}" = "Ochrona WWW"
 -> {HKLM...CLSID} = "Ochrona WWW"
 \InProcServer32\(Default) = "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll" ["Kaspersky Lab"]
 "{00000000-5736-4205-0100-781cd0e19f00}" = "Steganos Internet Anonym Pro 7"
 -> {HKLM...CLSID} = "Steganos Internet Anonym Pro 7"
 \InProcServer32\(Default) = "c:\program files\steganos internet anonym pro 7\siapro7se.dll" [null data]
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\
 <<!>> "{ab340860-fd81-4a65-b345-82eb77a66b5e}" = "featherweed"
 -> {HKLM...CLSID} = (no title provided)
 \InProcServer32\(Default) = "C:\WINDOWS\System32\jbtazy.dll" [file not found]
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
 <<!>> "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" = "AVG Anti-Spyware 7.5"
 -> {HKLM...CLSID} = "CShellExecuteHookImpl Object"
 \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" ["Anti-Malware Development a.s."]
 HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
 "featherweed" = "{ab340860-fd81-4a65-b345-82eb77a66b5e}"
 -> {HKLM...CLSID} = (no title provided)
 \InProcServer32\(Default) = "C:\WINDOWS\System32\jbtazy.dll" [file not found]
 HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
 <<!>> AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]
 <<!>> klogon\DLLName = "C:\WINDOWS\System32\klogon.dll" ["Kaspersky Lab"]
 HKLM\Software\Classes\PROTOCOLS\Filter\
 <<!>> text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"
 -> {HKLM...CLSID} = (no title provided)
 \InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS]
 HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
 {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
 -> {HKLM...CLSID} = "PDF Shell Extension"
 \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]
 HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
 AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
 -> {HKLM...CLSID} = "CContextScan Object"
 \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."]
 Kaspersky Anti-Virus\(Default) = "{dd230880-495a-11d1-b064-008048ec2fc5}"
 -> {HKLM...CLSID} = (no title provided)
 \InProcServer32\(Default) = "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\shellex.dll" ["Kaspersky Lab"]
 NOD32 Context Menu Shell Extension\(Default) = "{B089FE88-FB52-11d3-BDF1-0050DA34150D}"
 -> {HKLM...CLSID} = "NOD32 Context Menu Shell Extension"
 \InProcServer32\(Default) = "C:\Program Files\Eset\nodshex.dll" [file not found]
 Steganos Internet Anonym Pro 7\(Default) = "{00000000-5736-4205-0100-781cd0e19f00}"
 -> {HKLM...CLSID} = "Steganos Internet Anonym Pro 7"
 \InProcServer32\(Default) = "c:\program files\steganos internet anonym pro 7\siapro7se.dll" [null data]
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
 AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
 -> {HKLM...CLSID} = "CContextScan Object"
 \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."]
 Steganos Internet Anonym Pro 7\(Default) = "{00000000-5736-4205-0100-781cd0e19f00}"
 -> {HKLM...CLSID} = "Steganos Internet Anonym Pro 7"
 \InProcServer32\(Default) = "c:\program files\steganos internet anonym pro 7\siapro7se.dll" [null data]
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
 Kaspersky Anti-Virus\(Default) = "{dd230880-495a-11d1-b064-008048ec2fc5}"
 -> {HKLM...CLSID} = (no title provided)
 \InProcServer32\(Default) = "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\shellex.dll" ["Kaspersky Lab"]
 NOD32 Context Menu Shell Extension\(Default) = "{B089FE88-FB52-11d3-BDF1-0050DA34150D}"
 -> {HKLM...CLSID} = "NOD32 Context Menu Shell Extension"
 \InProcServer32\(Default) = "C:\Program Files\Eset\nodshex.dll" [file not found]
 WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
 -> {HKLM...CLSID} = "WinRAR"
 \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
 Group Policies {GPedit.msc branch and setting}:
 -----------------------------------------------
 Note: detected settings may not have any effect.
 HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\
 "DisableRegistryTools" = (REG_DWORD) hex:0x00000000
 {User Configuration|Administrative Templates|System|
 Prevent access to registry editing tools}
 HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\
 "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
 Shutdown: Allow system to be shut down without having to log on}
 "undockwithoutlogon" = (REG_DWORD) hex:0x00000001
 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
 Devices: Allow undock without having to log on}
 Active Desktop and Wallpaper:
 -----------------------------
 Active Desktop may be enabled at this entry:
 HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
 Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
 HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
 "Wallpaper" = "C:\Documents and Settings\Administrator\Pulpit\ninjatext(3).gif"
 Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
 HKCU\Control Panel\Desktop\
 "Wallpaper" = "C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"
 Enabled Screen Saver:
 ---------------------
 HKCU\Control Panel\Desktop\
 "SCRNSAVE.EXE" = "C:\WINDOWS\System32\ssmarque.scr" [MS]
 Startup items in "Administrator" & "All Users" startup folders:
 ---------------------------------------------------------------
 C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
 "ATI CATALYST – pasek zadań" -> shortcut to: "C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe SystemTray" [null data]
 Winsock2 Service Provider DLLs:
 -------------------------------
 Namespace Service Providers
 HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
 000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
 000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
 000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
 Transport Service Providers
 HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
 C:\Program Files\Secure Surfing Engine\sselsp.dll [null data], 01 - 03, 23
 C:\WINDOWS\System32\imon.dll ["Eset "], 04 - 08, 22
 %SystemRoot%\system32\mswsock.dll [MS], 09 - 11, 14 - 21
 %SystemRoot%\system32\rsvpsp.dll [MS], 12 - 13
 Toolbars, Explorer Bars, Extensions:
 ------------------------------------
 Toolbars
 HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
 "{BF1CED2C-4B3F-4079-A330-864EDA5A4CFF}"
 -> {HKLM...CLSID} = "Protection Bar"
 \InProcServer32\(Default) = "C:\Program Files\Perfect Codec\iesplugin.dll" [file not found]
 "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
 -> {HKLM...CLSID} = "&Google"
 \InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."]
 HKLM\Software\Microsoft\Internet Explorer\Toolbar\
 "{BF1CED2C-4B3F-4079-A330-864EDA5A4CFF}" = (no title provided)
 -> {HKLM...CLSID} = "Protection Bar"
 \InProcServer32\(Default) = "C:\Program Files\Perfect Codec\iesplugin.dll" [file not found]
 "{00000000-5736-4205-0008-781CD0E19F00}" = (no title provided)
 -> {HKLM...CLSID} = "Steganos Internet Anonym"
 \InProcServer32\(Default) = "c:\program files\steganos internet anonym pro 7\siapro7iep.dll" [null data]
 "{E0E899AB-F487-11D5-8D29-0050BA6940E3}" = "FlashGet Bar"
 -> {HKLM...CLSID} = "FlashGet Bar"
 \InProcServer32\(Default) = "C:\PROGRA~1\FLASHGET\fgiebar.dll" ["Amaze Soft"]
 "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)
 -> {HKLM...CLSID} = "&Google"
 \InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."]
 Explorer Bars
 HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\
 HKLM\Software\Classes\CLSID\{00000000-5736-4205-0009-781CD0E19F00}\(Default) = "Prywatna lista ulubionych Steganos"
 Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
 InProcServer32\(Default) = "c:\program files\steganos internet anonym pro 7\siapro7iep.dll" [null data]
 HKLM\Software\Classes\CLSID\{85E0B171-04FA-11D1-B7DA-00A0C90348D6}\(Default) = "Ochrona WWW"
 Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
 InProcServer32\(Default) = "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll" ["Kaspersky Lab"]
 HKLM\Software\Classes\CLSID\{BF1CED2C-4B3F-4079-A330-864EDA5A4CFF}\(Default) = "Protection Bar"
 Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
 InProcServer32\(Default) = "C:\Program Files\Perfect Codec\iesplugin.dll" [file not found]
 HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Badanie"
 Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
 InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL" [MS]
 Extensions (Tools menu items, main toolbar menu buttons)
 HKLM\Software\Microsoft\Internet Explorer\Extensions\
 {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
 "MenuText" = "Sun Java Console"
 "CLSIDExtension" = "{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}"
 -> {HKCU...CLSID} = "Java Plug-in"
 \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll" ["Sun Microsystems, Inc."]
 -> {HKLM...CLSID} = "Java Plug-in 1.5.0_06"
 \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll" ["Sun Microsystems, Inc."]
 {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}\
 "ButtonText" = "Ochrona WWW"
 {92780B25-18CC-41C8-B9BE-3C9C571A8263}\
 "ButtonText" = "Badanie"
 {D6E814A0-E0C5-11D4-8D29-0050BA6940E3}\
 "ButtonText" = "FlashGet"
 "MenuText" = "&FlashGet"
 "Exec" = "C:\PROGRA~1\FLASHGET\flashget.exe" ["FlashGet.com"]
 Miscellaneous IE Hijack Points
 ------------------------------
 HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\
 <<H>> "{08C06D61-F1F3-4799-86F8-BE1A89362C85}" = (no title provided)
 -> {HKLM...CLSID} = "Search Class"
 \InProcServer32\(Default) = "C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL" [file not found]
 Running Services (Display Name, Service Name, Path {Service DLL}):
 ------------------------------------------------------------------
 AVG Anti-Spyware Guard, AVG Anti-Spyware Guard, "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe" ["Anti-Malware Development a.s."]
 LexBce Server, LexBceS, "C:\WINDOWS\system32\LEXBCES.EXE" ["Lexmark International, Inc."]
 Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\System32\wdfmgr.exe" [MS]
 Print Monitors:
 ---------------
 HKLM\System\CurrentControlSet\Control\Print\Monitors\
 Lexmark Network Port\Driver = "LEXLMPM.DLL" ["Lexmark International, Inc."]
 Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS]
 ----------
 <<!>>: Suspicious data at a malware launch point.
 <<H>>: Suspicious data at a browser hijack point.
 + This report excludes default entries except where indicated.
 + To see *everywhere* the script checks and *everything* it finds,
 launch it from a command prompt or a shortcut with the -all parameter.
 + To search all directories of local fixed drives for DESKTOP.INI
 DLL launch points, use the -supp parameter or answer "No" at the
 first message box and "Yes" at the second message box.
 ---------- (total run time: 1202 seconds, including 6 seconds for message boxes)

 
	







 ( programy z autostartu )
 ( programy z autostartu ) 
