Neostrada cały czas mi wysyła –prosze o pomoc.

Cały czas cos mi wysyła i odbiera z netu.Jakis program mcafee32. Podaje scan HijackThis. Co wykasować.


Logfile of HijackThis v1.97.7
Scan saved at 22:21:11, on 2005–02–25
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.exe
C:WINDOWSSystem32RUNDLL32.EXE
C:WINDOWSSystem32CTHELPER.EXE
C:WINDOWSSystem32ctfmon.exe
C:Program FilesAVERTV2KQuickTV.exe
C:Program FilesLogitechMouseWaresystemem_exec.exe
C:Program FilesKerioPersonal Firewall 4kpf4ss.exe
C:WINDOWSSystem32 vsvc32.exe
C:Program FilesKerioPersonal Firewall 4kpf4gui.exe
C:WINDOWSSystem32mcafee32.exe
C:Program FilesKerioPersonal Firewall 4kpf4gui.exe
C:Program FilesOperaOpera.exe
C:Program Files otalcmdTOTALCMD.EXE
D:Uzytkiapora KerioHijackHijackThis.exe

R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.onet.pl/
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
F0 – system.ini: Shell=Explorer.exe mcafee32.exe
F2 – REG:system.ini: Shell=Explorer.exe mcafee32.exe
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit
O4 – HKLM..Run: [UpdReg] C:WINDOWSUpdreg.exe
O4 – HKLM..Run: [CTStartup] C:Program FilesCreativeSplash ScreenCTEaxSpl.EXE /run
O4 – HKLM..Run: [Jet Detection] C:Program FilesCreativeSBAudigyPROGRAMADGJDet.exe
O4 – HKLM..Run: [Logitech Utility] Logi_MwX.Exe
O4 – HKLM..Run: [CTHelper] CTHELPER.EXE
O4 – HKLM..Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 – HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 – Global Startup: QuickTV.lnk = C:Program FilesAVERTV2KQuickTV.exe
O16 – DPF: {6414512B–B978–451D–A0D8–FCFDF33E833C} (WUWebControl Class) – http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1109356037187
O17 – HKLMSystemCCSServicesTcpip..{B2866A4F–52D4–4DE6–A2FD–D1B125A149E7}: NameServer = 194.204.152.34 217.98.63.164

Dziekuje za pomoc.

Odpowiedzi: 1

Wylacz przywracanie systemu

Zakoncz proces i usun plik:
mcafee32.exe

FIX:
F0 – system.ini: Shell=Explorer.exe mcafee32.exe
F2 – REG:system.ini: Shell=Explorer.exe mcafee32.exe

Przeszukaj rejestr i usun wszystko co w nazwie bedzie miało mcafee32.exe
Poszukaj rowniez navprotect.exe
Bobi
Dodano
26.02.2005 00:13:26
  • wodzu-4 31.08.2006 15:07:06

    <p>Witam Mam od kilku dni ten sam problem ale mimo zasatosowaniu r&oacute;znego typu rad ciągle nie mogę sobie poradzić. Neostrada cały czas mi coś wysyła i przezto mam strasznie mały transfer.</p><p>Moze to coś pomoże w zbadaniu co jest nie tak: </p><p>Logfile of HijackThis v1.99.1<br />Scan saved at 12:22:57, on 2006-08-31<br />Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)<br />MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)</p><p>Running processes:<br />C:\WINDOWS\System32\smss.exe<br />C:\WINDOWS\system32\winlogon.exe<br />C:\WINDOWS\system32\services.exe<br />C:\WINDOWS\system32\lsass.exe<br />C:\WINDOWS\system32\svchost.exe<br />C:\WINDOWS\System32\svchost.exe<br />C:\WINDOWS\system32\spoolsv.exe<br />C:\Program Files\MKS\Bin\NetMonSV.exe<br />C:\Program Files\MKS\Bin\mksmonsv.exe<br />C:\WINDOWS\System32\nvsvc32.exe<br />C:\WINDOWS\System32\svchost.exe<br />C:\WINDOWS\Explorer.EXE<br />C:\WINDOWS\System32\devldr32.exe<br />C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />C:\Program Files\MKS\Bin\mks_menu.exe<br />C:\Program Files\MKS\Bin\ABregmon.exe<br />C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe<br />C:\Program Files\MKS\Bin\mks_scan.exe<br />C:\WINDOWS\System32\taskmgr.exe<br />C:\Program Files\Tlen.pl\tlen.exe<br />C:\Program Files\Opera\Opera.exe<br />C:\Documents and Settings\wodzu\Pulpit\hijackthis\HijackThis.exe</p><p>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <br />R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza<br />R3 - Default URLSearchHook is missing<br />F2 - REG:system.ini: UserInit=userinit.exe<br />O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll<br />O2 - BHO: (no name) - {1da7dbe8-c51b-4ae4-bc6e-21863349b0b4} - C:\Program Files\IntCodec\isaddon.dll (file missing)<br />O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />O2 - BHO: (no name) - {B6F1A4CB-DADD-4D0C-BDFC-E945647302C1} - c:\system.dll (file missing)<br />O3 - Toolbar: &amp;Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx<br />O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br />O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;&nbsp; -osboot<br />O4 - HKLM\..\Run: [MKS_MENU] C:\Program Files\MKS\Bin\mks_menu.exe<br />O4 - HKLM\..\Run: [ABREGMON] C:\Program Files\MKS\Bin\ABregmon.exe<br />O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] &quot;C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe&quot; /icon<br />O4 - HKLM\..\Run: [RemoteControl] &quot;C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe&quot;<br />O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup<br />O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit<br />O4 - HKLM\..\RunServices: [stonedrv] c:\windows\system32\stonedrv.exe<br />O4 - HKCU\..\Run: [Komunikator] &quot;C:\Program Files\Tlen.pl\tlen.exe&quot; --confdir=home<br />O4 - HKCU\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe<br />O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE<br />O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />O9 - Extra &#39;Tools&#39; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />O15 - Trusted Zone: <a href="http://click.getmirar.com/">http://click.getmirar.com</a> (HKLM)<br />O15 - Trusted Zone: <a href="http://click.mirarsearch.com/">http://click.mirarsearch.com</a> (HKLM)<br />O15 - Trusted Zone: <a href="http://redirect.mirarsearch.com/">http://redirect.mirarsearch.com</a> (HKLM)<br />O15 - Trusted Zone: <a href="http://www.mirarsearch.com/">http://www.mirarsearch.com</a> (HKLM)<br />O16 - DPF: {33331111-1111-1111-1111-611111193423} - <br />O16 - DPF: {33331111-1111-1111-1111-611111193429} - <br />O16 - DPF: {33331111-1111-1111-1111-611111193457} - <a>file://c:\ex.cab</a><br />O16 - DPF: {33331111-1111-1111-1111-611111193458} - <a>file://c:\ex.cab</a><br />O16 - DPF: {33331111-1111-1111-1111-615111193427} - <br />O16 - DPF: {33331111-1111-1111-1111-622221193458} - <a>file://c:\ex.cab</a><br />O16 - DPF: {33331111-1131-1111-1111-611111193428} - <br />O16 - DPF: {43331111-1111-1111-1111-611111195622} - <br />O16 - DPF: {64311111-1111-1121-1111-111191113457} - <a>file://c:\eied_s7.cab</a><br />O17 - HKLM\System\CCS\Services\Tcpip\..\{89050E03-7203-403E-80C0-E48DC3F8F495}: NameServer = 194.204.152.34 217.98.63.164<br />O20 - AppInit_DLLs:&nbsp; C:\WINDOWS\System32\rundll32.dll<br />O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - C:\WINDOWS\System32\vbsys2.dll<br />O23 - Service: ArcaBit NetMonitor (ABNetMon) - ArcaBit sp. z o.o. - C:\Program Files\MKS\Bin\NetMonSV.exe<br />O23 - Service: MS Software Shadow Download Provider (dnlsvc) - Unknown owner - C:\DOCUME~1\wodzu\USTAWI~1\Temp\dnlsvc.exe (file missing)<br />O23 - Service: MkSUpdateInt - MkS Sp. z o. o. - C:\Program Files\MKS\bin\MkSUpdateInt.exe<br />O23 - Service: MkS_Vir Monitor (MksVirMonSvc) - Unknown owner - C:\Program Files\MKS\Bin\mksmonsv.exe<br />O23 - Service: MkS_Scan - Unknown owner - C:\Program Files\MKS\Bin\mks_scan.exe<br />O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe</p><p>Prosze o pomoc bo już sam nie wiem co robić a nie mam czasu ani ochoty zeby bawić sie w foematowanie dysku</p>

  • Żółty 31.08.2006 15:12:21

    W dziale Bezpieczeństwo jest instrukcja jak sobie loga sprawdzić - zajrzyj tam i najpierw sprawdź samodzielnie (a masz trochę syf&oacute;w). Jak skończysz to wrzuć loga kontrolnego. Jak będziesz miał wątpliwości lub sobie nie będziesz z czymś radził&nbsp; to pisz.<br />

  • wodzu-4 07.09.2006 13:11:27

    <p>Witam ponownie</p><p>Zrobiłem dokładnie tak jak opisane w dziale &quot;bezpieczeństwo&quot; I wydawało mnie sie że coś to pomogło bo było kilka dni spokoju. NIestety od dziś jest znowu to samo, z taką r&oacute;żnicą ze po sprawdzeniu loga analizator twierdzi ze wszysko jest już OK ale komp cały czas coś wysyła. </p><p>Oto obecny stan zeczy</p><p>Logfile of HijackThis v1.99.1<br />Scan saved at 11:00:36, on 2006-09-07<br />Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)<br />MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)</p><p>Running processes:<br />C:\WINDOWS\System32\smss.exe<br />C:\WINDOWS\system32\winlogon.exe<br />C:\WINDOWS\system32\services.exe<br />C:\WINDOWS\system32\lsass.exe<br />C:\WINDOWS\system32\svchost.exe<br />C:\WINDOWS\System32\svchost.exe<br />C:\WINDOWS\system32\spoolsv.exe<br />C:\Program Files\MKS\Bin\NetMonSV.exe<br />C:\Program Files\MKS\Bin\mksmonsv.exe<br />C:\WINDOWS\System32\nvsvc32.exe<br />C:\WINDOWS\System32\svchost.exe<br />C:\WINDOWS\Explorer.EXE<br />C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />C:\WINDOWS\System32\devldr32.exe<br />C:\Program Files\MKS\Bin\mks_menu.exe<br />C:\Program Files\MKS\Bin\ABregmon.exe<br />C:\WINDOWS\System32\taskmgr.exe<br />C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe<br />C:\Program Files\MKS\Bin\mks_scan.exe<br />C:\Program Files\Internet Explorer\iexplore.exe<br />C:\Documents and Settings\wodzu\Pulpit\hijackthis\HijackThis.exe</p><p>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <br />R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza<br />F2 - REG:system.ini: UserInit=userinit.exe<br />O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll<br />O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />O3 - Toolbar: &amp;Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx<br />O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br />O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;&nbsp; -osboot<br />O4 - HKLM\..\Run: [MKS_MENU] C:\Program Files\MKS\Bin\mks_menu.exe<br />O4 - HKLM\..\Run: [ABREGMON] C:\Program Files\MKS\Bin\ABregmon.exe<br />O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] &quot;C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe&quot; /icon<br />O4 - HKLM\..\Run: [RemoteControl] &quot;C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe&quot;<br />O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup<br />O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit<br />O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe<br />O4 - HKCU\..\Run: [Komunikator] &quot;C:\Program Files\Tlen.pl\tlen.exe&quot; --confdir=home<br />O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE<br />O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />O9 - Extra &#39;Tools&#39; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />O15 - Trusted Zone: <a href="http://click.getmirar.com/">http://click.getmirar.com</a> (HKLM)<br />O15 - Trusted Zone: <a href="http://click.mirarsearch.com/">http://click.mirarsearch.com</a> (HKLM)<br />O15 - Trusted Zone: <a href="http://redirect.mirarsearch.com/">http://redirect.mirarsearch.com</a> (HKLM)<br />O15 - Trusted Zone: <a href="http://www.mirarsearch.com/">http://www.mirarsearch.com</a> (HKLM)<br />O17 - HKLM\System\CCS\Services\Tcpip\..\{89050E03-7203-403E-80C0-E48DC3F8F495}: NameServer = 194.204.152.34 217.98.63.164<br />O23 - Service: ArcaBit NetMonitor (ABNetMon) - ArcaBit sp. z o.o. - C:\Program Files\MKS\Bin\NetMonSV.exe<br />O23 - Service: MS Software Shadow Download Provider (dnlsvc) - Unknown owner - C:\DOCUME~1\wodzu\USTAWI~1\Temp\dnlsvc.exe (file missing)<br />O23 - Service: MkSUpdateInt - MkS Sp. z o. o. - C:\Program Files\MKS\bin\MkSUpdateInt.exe<br />O23 - Service: MkS_Vir Monitor (MksVirMonSvc) - Unknown owner - C:\Program Files\MKS\Bin\mksmonsv.exe<br />O23 - Service: MkS_Scan - Unknown owner - C:\Program Files\MKS\Bin\mks_scan.exe<br />O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe</p><p>&nbsp;</p>

  • Seeker 07.09.2006 13:59:03

    <p>to jeszce wywal</p><p>O17 - HKLM\System\CCS\Services\Tcpip\..\{89050E03-7203-403E-80C0-E48DC3F8F495}: NameServer = 194.204.152.34 217.98.63.164</p><p>-chyba że znasz ten adres i z nim jakieś wymiany plik&oacute;w robicie<br /></p><p>O wylaczeniu przywracania pamiętałeś? To mogło spowodować że problem powr&oacute;cił</p>

  • EL NINO 07.09.2006 14:30:48

    <BLOCKQUOTE><div><img src="http://portal.centrumxp.pl/Themes/default/images/icon-quote.gif"> <strong>Seeker:</strong></div><div><p>to jeszce wywal</p><p>O17 - HKLM\System\CCS\Services\Tcpip\..\{89050E03-7203-403E-80C0-E48DC3F8F495}: NameServer = 194.204.152.34 217.98.63.164</p></div></BLOCKQUOTE>Seeker, toz to tepsniane DNSy. <br /><br />wodzu, nie usuwaj tego.<br /><br />Pozbadz sie uslugi:<br />O23 - Service: MS Software Shadow Download Provider (dnlsvc) - Unknown owner - C:\DOCUME~1\wodzu\USTAWI~1\Temp\dnlsvc.exe (file missing)<br />To trojan. Z Uruchom &quot;services.msc&quot;, wyszukaj usluge&nbsp;MS Software Shadow Download Provider (dnlsvc), wylacz, uruchaianie ustaw na &quot;wylaczone&quot;. Wyszukaj&nbsp;na&nbsp;dysku plik dnlsvc.exe i usun.<br />Pozniej wywolaj z Uruchom &quot;cmd&quot; i wykonaj:<br />sc delete&nbsp;dnlsvc <br /> <br />

  • Seeker 07.09.2006 14:37:03

    <BLOCKQUOTE><div><img src="http://portal.centrumxp.pl/Themes/default/images/icon-quote.gif"> <strong>EL NINO:</strong></div><div><BLOCKQUOTE><div><img src="http://portal.centrumxp.pl/Themes/default/images/icon-quote.gif"> <strong>Seeker:</strong></div><div> <p>to jeszce wywal</p><p>O17 - HKLM\System\CCS\Services\Tcpip\..\{89050E03-7203-403E-80C0-E48DC3F8F495}: NameServer = 194.204.152.34 217.98.63.164</p><p></div></BLOCKQUOTE>Seeker, toz to tepsniane DNSy.&nbsp;<br /><br /></div></BLOCKQUOTE></p><p>Taaak? nie używam , ,<img src="http://portal.centrumxp.pl/emoticons/emotion-4.gif" alt="Stick out tongue" /></p><p>&nbsp;a bo mnie się pomylyło&nbsp; z takim jednym <img src="http://portal.centrumxp.pl/emoticons/emotion-10.gif" alt="Embarrassed" /> <img src="http://portal.centrumxp.pl/emoticons/emotion-2.gif" alt="Big Smile" /></p>

  • EL NINO 07.09.2006 14:39:18

    <BLOCKQUOTE><div><img src="http://portal.centrumxp.pl/Themes/default/images/icon-quote.gif"> <strong>Seeker:</strong></div><div>Taaak? nie używam , ,<img src="http://portal.centrumxp.pl/emoticons/emotion-4.gif" alt="Stick out tongue" /></div></BLOCKQUOTE>W Twoim wieku to nawet nie jest wskazane<img src="http://portal.centrumxp.pl/emoticons/emotion-4.gif" alt="Stick out tongue" />.

  • wodzu-4 07.09.2006 15:11:17

    <p>Witam Zrobiłem wszystko dokłądnie tak ja napisane ale niestety to też nic nie pomogło. Neostrada dalej coś wysyła. </p><p>Oto najnowszy log</p><p>Logfile of HijackThis v1.99.1<br />Scan saved at 13:10:28, on 2006-09-07<br />Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)<br />MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)</p><p>Running processes:<br />C:\WINDOWS\System32\smss.exe<br />C:\WINDOWS\system32\winlogon.exe<br />C:\WINDOWS\system32\services.exe<br />C:\WINDOWS\system32\lsass.exe<br />C:\WINDOWS\system32\svchost.exe<br />C:\WINDOWS\System32\svchost.exe<br />C:\WINDOWS\system32\spoolsv.exe<br />C:\Program Files\MKS\Bin\NetMonSV.exe<br />C:\Program Files\MKS\Bin\mksmonsv.exe<br />C:\WINDOWS\System32\nvsvc32.exe<br />C:\WINDOWS\System32\svchost.exe<br />C:\WINDOWS\Explorer.EXE<br />C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />C:\WINDOWS\System32\devldr32.exe<br />C:\WINDOWS\System32\taskmgr.exe<br />C:\Program Files\MKS\Bin\mks_menu.exe<br />C:\Program Files\MKS\Bin\ABregmon.exe<br />C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe<br />C:\Program Files\MKS\Bin\mks_scan.exe<br />C:\Program Files\Internet Explorer\iexplore.exe<br />C:\WINDOWS\system32\mmc.exe<br />C:\Documents and Settings\wodzu\Pulpit\hijackthis\HijackThis.exe</p><p>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <br />R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza<br />F2 - REG:system.ini: UserInit=userinit.exe<br />O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll<br />O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />O3 - Toolbar: &amp;Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx<br />O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br />O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;&nbsp; -osboot<br />O4 - HKLM\..\Run: [MKS_MENU] C:\Program Files\MKS\Bin\mks_menu.exe<br />O4 - HKLM\..\Run: [ABREGMON] C:\Program Files\MKS\Bin\ABregmon.exe<br />O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] &quot;C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe&quot; /icon<br />O4 - HKLM\..\Run: [RemoteControl] &quot;C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe&quot;<br />O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup<br />O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit<br />O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe<br />O4 - HKCU\..\Run: [Komunikator] &quot;C:\Program Files\Tlen.pl\tlen.exe&quot; --confdir=home<br />O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE<br />O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />O9 - Extra &#39;Tools&#39; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />O15 - Trusted Zone: <a href="http://click.getmirar.com/">http://click.getmirar.com</a> (HKLM)<br />O15 - Trusted Zone: <a href="http://click.mirarsearch.com/">http://click.mirarsearch.com</a> (HKLM)<br />O15 - Trusted Zone: <a href="http://redirect.mirarsearch.com/">http://redirect.mirarsearch.com</a> (HKLM)<br />O15 - Trusted Zone: <a href="http://www.mirarsearch.com/">http://www.mirarsearch.com</a> (HKLM)<br />O17 - HKLM\System\CCS\Services\Tcpip\..\{89050E03-7203-403E-80C0-E48DC3F8F495}: NameServer = 194.204.152.34 217.98.63.164<br />O23 - Service: ArcaBit NetMonitor (ABNetMon) - ArcaBit sp. z o.o. - C:\Program Files\MKS\Bin\NetMonSV.exe<br />O23 - Service: MkSUpdateInt - MkS Sp. z o. o. - C:\Program Files\MKS\bin\MkSUpdateInt.exe<br />O23 - Service: MkS_Vir Monitor (MksVirMonSvc) - Unknown owner - C:\Program Files\MKS\Bin\mksmonsv.exe<br />O23 - Service: MkS_Scan - Unknown owner - C:\Program Files\MKS\Bin\mks_scan.exe<br />O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe</p><p>&nbsp;</p>

  • EL NINO 08.09.2006 12:23:42

    wodzu, dwie sprawy:<br /><br />1.&nbsp;Wszystkie wpisy&nbsp;(4&nbsp;sztuki)&nbsp;O15&nbsp;z&nbsp;&quot;mirarsearch.com&quot;&nbsp;-&nbsp;czy&nbsp;masz&nbsp;stamtad&nbsp;jakis&nbsp;Toolbar&nbsp;?&nbsp;Bo&nbsp;jesli&nbsp;nie,&nbsp;trzeba&nbsp;czyscic.<br /><a href="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453078818" target="_blank">http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453078818</a>&nbsp;na dole strony w okienkach znajdziesz nazwy plikow, wpisow w rejestrze.<br /><br />2.&nbsp;Czy&nbsp;podczas&nbsp;robienia&nbsp;loga&nbsp;korzystales&nbsp;z&nbsp;przystawki&nbsp;MMC&nbsp;?&nbsp;-&gt;&nbsp;C:\WINDOWS\system32\mmc.exe<br /> Jesli nie, bylaby to&nbsp;prawdopodobnie Nimda i oczywiscie na to tez jest lekarstwo -&gt;<a href="http://www.kaspersky.pl/services.html?s=faq&amp;s_faq=details&amp;category_id=3&amp;details_id=29" target="_blank"> http://www.kaspersky.pl/services.html?s=faq&amp;s_faq=details&amp;category_id=3&amp;details_id=29</a><br />

  • wodzu-4 08.09.2006 17:59:15

    <p>Witam</p><p>Zrobiłem wszystko dokładnie tak jak opisane i nic sie niepoprawiło. Powiem wiecej jest chyab nawet gorzej bo zwiększył się transfer wysyłanych. Otworzenie tej strony zajeło mi około 10 min. Ja już sam nie wiem co jest i gdzie jeszcze mozna tego szukać.</p><p>Oto najnowszy log</p><p>Logfile of HijackThis v1.99.1<br />Scan saved at 15:58:23, on 2006-09-08<br />Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)<br />MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)</p><p>Running processes:<br />C:\WINDOWS\System32\smss.exe<br />C:\WINDOWS\system32\winlogon.exe<br />C:\WINDOWS\system32\services.exe<br />C:\WINDOWS\system32\lsass.exe<br />C:\WINDOWS\system32\svchost.exe<br />C:\WINDOWS\System32\svchost.exe<br />C:\WINDOWS\system32\spoolsv.exe<br />C:\Program Files\MKS\Bin\NetMonSV.exe<br />C:\Program Files\MKS\Bin\mksmonsv.exe<br />C:\WINDOWS\System32\nvsvc32.exe<br />C:\WINDOWS\System32\svchost.exe<br />C:\WINDOWS\Explorer.EXE<br />C:\WINDOWS\System32\taskmgr.exe<br />C:\WINDOWS\System32\devldr32.exe<br />C:\Program Files\Common Files\Real\Update_OB\realsched.exe<br />C:\Program Files\MKS\Bin\mks_menu.exe<br />C:\Program Files\MKS\Bin\mks_scan.exe<br />C:\Program Files\MKS\Bin\ABregmon.exe<br />C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe<br />C:\Program Files\Internet Explorer\iexplore.exe<br />C:\Documents and Settings\wodzu\Pulpit\hijackthis\HijackThis.exe</p><p>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <br />R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza<br />F2 - REG:system.ini: UserInit=userinit.exe<br />O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll<br />O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br />O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />O3 - Toolbar: &amp;Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx<br />O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe<br />O4 - HKLM\..\Run: [TkBellExe] &quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;&nbsp; -osboot<br />O4 - HKLM\..\Run: [MKS_MENU] C:\Program Files\MKS\Bin\mks_menu.exe<br />O4 - HKLM\..\Run: [ABREGMON] C:\Program Files\MKS\Bin\ABregmon.exe<br />O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] &quot;C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe&quot; /icon<br />O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup<br />O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br />O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit<br />O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe<br />O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto<br />O4 - HKCU\..\Run: [Komunikator] &quot;C:\Program Files\Tlen.pl\tlen.exe&quot; --confdir=home<br />O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE<br />O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br />O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />O9 - Extra &#39;Tools&#39; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br />O17 - HKLM\System\CCS\Services\Tcpip\..\{89050E03-7203-403E-80C0-E48DC3F8F495}: NameServer = 194.204.152.34 217.98.63.164<br />O23 - Service: ArcaBit NetMonitor (ABNetMon) - ArcaBit sp. z o.o. - C:\Program Files\MKS\Bin\NetMonSV.exe<br />O23 - Service: MkSUpdateInt - MkS Sp. z o. o. - C:\Program Files\MKS\bin\MkSUpdateInt.exe<br />O23 - Service: MkS_Vir Monitor (MksVirMonSvc) - Unknown owner - C:\Program Files\MKS\Bin\mksmonsv.exe<br />O23 - Service: MkS_Scan - Unknown owner - C:\Program Files\MKS\Bin\mks_scan.exe<br />O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe</p><p>&nbsp;</p>

  • Żółty 08.09.2006 18:35:10

    <p>Ściągnij i zr&oacute;b loga Silent Runners. Loga pokaż.<br /></p>

  • wodzu-4 08.09.2006 19:31:22

    <p>Oto log z Silent Runners Nie wiem czy kompletny czy nie ale moze coś pomoże</p><p>&quot;Silent Runners.vbs&quot;, revision 48, <a href="http://www.silentrunners.org/">http://www.silentrunners.org/</a><br />Operating System: Windows XP<br />Output limited to non-default values, except where indicated by &quot;{++}&quot;</p><p><br />Startup items buried in registry:<br />---------------------------------</p><p>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}<br />&quot;Komunikator&quot; = &quot;&quot;C:\Program Files\Tlen.pl\tlen.exe&quot; --confdir=home&quot; [&quot;o2.pl Sp. z o.o.&quot;]</p><p>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ {++}<br />&quot;DriverLoad&quot; = (empty string)<br />&quot;DriverCheck&quot; = (empty string)<br />&quot;SystemDriverLoad&quot; = (empty string)<br />&quot;Winhost&quot; = (empty string)<br />&quot;Winhost1&quot; = (empty string)<br />&quot;Winhost2&quot; = (empty string)<br />&quot;Winhost3&quot; = (empty string)<br />&quot;Winhost4&quot; = (empty string)<br />&quot;SystemDriver&quot; = &quot;c:\DriverLoad\windrv.exe&quot; [file not found]<br />&quot;FDriver&quot; = &quot;c:\DriverLoad\windrv.exe&quot; [file not found]<br />&quot;ADriver&quot; = &quot;c:\DriverLoad\windrv.exe&quot; [file not found]<br />&quot;CDriver&quot; = &quot;c:\DriverLoad\windrv.exe&quot; [file not found]<br />&quot;DDriver&quot; = &quot;c:\DriverLoad\windrv.exe&quot; [file not found]</p><p>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}<br />&quot;NeroFilterCheck&quot; = &quot;C:\WINDOWS\system32\NeroCheck.exe&quot; [&quot;Ahead Software Gmbh&quot;]<br />&quot;TkBellExe&quot; = &quot;&quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;&nbsp; -osboot&quot; [&quot;RealNetworks, Inc.&quot;]<br />&quot;MKS_MENU&quot; = &quot;C:\Program Files\MKS\Bin\mks_menu.exe&quot; [&quot;MKS Sp. z o.o.&quot;]<br />&quot;ABREGMON&quot; = &quot;C:\Program Files\MKS\Bin\ABregmon.exe&quot; [&quot;ArcaBit&quot;]<br />&quot;SpeedTouch USB Diagnostics&quot; = &quot;&quot;C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe&quot; /icon&quot; [&quot;THOMSON multimedia&quot;]<br />&quot;NvCplDaemon&quot; = &quot;RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup&quot; [MS]<br />&quot;nwiz&quot; = &quot;nwiz.exe /install&quot; [&quot;NVIDIA Corporation&quot;]<br />&quot;NvMediaCenter&quot; = &quot;RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit&quot; [MS]<br />&quot;TrojanScanner&quot; = &quot;C:\Program Files\Trojan Remover\Trjscan.exe&quot; [&quot;Simply Super Software&quot;]<br />&quot;MSConfig&quot; = &quot;C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto&quot; [MS]</p><p>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\<br />{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;AcroIEHlprObj Class&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll&quot; [&quot;Adobe Systems Incorporated&quot;]<br />{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)<br />&nbsp; -&gt; {HKLM...CLSID} = (no title provided)<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\PROGRA~1\SPYBOT~1\SDHelper.dll&quot; [&quot;Safer Networking Limited&quot;]<br />{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;SSVHelper Class&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll&quot; [&quot;Sun Microsystems, Inc.&quot;]</p><p>HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\<br />&quot;{42071714-76d4-11d1-8b24-00a0c9068ff3}&quot; = &quot;Rozszerzenie CPL kadrowania wyświetlania&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;Rozszerzenie CPL kadrowania wyświetlania&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;deskpan.dll&quot; [file not found]<br />&quot;{88895560-9AA2-1069-930E-00AA0030EBC8}&quot; = &quot;Rozszerzenie ikony HyperTerminalu&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;HyperTerminal Icon Ext&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\WINDOWS\System32\hticons.dll&quot; [&quot;Hilgraeve, Inc.&quot;]<br /></p>

  • Żółty 08.09.2006 19:37:09

    Nie jest kompletny ten log. Zr&oacute;b go jeszcze raz - poczekaj na komunikat o zakończeniu.<br />

  • wodzu-4 08.09.2006 19:44:20

    Czekałem około 10 min i nic się nie pojawiło. Spr&oacute;buje zrobić jeszcze raz i poczekam dł&oacute;żej

  • wodzu-4 08.09.2006 20:24:55

    <p>Czekałem 30 min i nic nie wyskoczyłe Ale w logu jest jakby wiecej informacji</p><p>&quot;Silent Runners.vbs&quot;, revision 48, <a href="http://www.silentrunners.org/">http://www.silentrunners.org/</a><br />Operating System: Windows XP<br />Output limited to non-default values, except where indicated by &quot;{++}&quot;</p><p><br />Startup items buried in registry:<br />---------------------------------</p><p>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}<br />&quot;Komunikator&quot; = &quot;&quot;C:\Program Files\Tlen.pl\tlen.exe&quot; --confdir=home&quot; [&quot;o2.pl Sp. z o.o.&quot;]</p><p>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ {++}<br />&quot;DriverLoad&quot; = (empty string)<br />&quot;DriverCheck&quot; = (empty string)<br />&quot;SystemDriverLoad&quot; = (empty string)<br />&quot;Winhost&quot; = (empty string)<br />&quot;Winhost1&quot; = (empty string)<br />&quot;Winhost2&quot; = (empty string)<br />&quot;Winhost3&quot; = (empty string)<br />&quot;Winhost4&quot; = (empty string)<br />&quot;SystemDriver&quot; = &quot;c:\DriverLoad\windrv.exe&quot; [file not found]<br />&quot;FDriver&quot; = &quot;c:\DriverLoad\windrv.exe&quot; [file not found]<br />&quot;ADriver&quot; = &quot;c:\DriverLoad\windrv.exe&quot; [file not found]<br />&quot;CDriver&quot; = &quot;c:\DriverLoad\windrv.exe&quot; [file not found]<br />&quot;DDriver&quot; = &quot;c:\DriverLoad\windrv.exe&quot; [file not found]</p><p>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}<br />&quot;NeroFilterCheck&quot; = &quot;C:\WINDOWS\system32\NeroCheck.exe&quot; [&quot;Ahead Software Gmbh&quot;]<br />&quot;TkBellExe&quot; = &quot;&quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;&nbsp; -osboot&quot; [&quot;RealNetworks, Inc.&quot;]<br />&quot;MKS_MENU&quot; = &quot;C:\Program Files\MKS\Bin\mks_menu.exe&quot; [&quot;MKS Sp. z o.o.&quot;]<br />&quot;ABREGMON&quot; = &quot;C:\Program Files\MKS\Bin\ABregmon.exe&quot; [&quot;ArcaBit&quot;]<br />&quot;SpeedTouch USB Diagnostics&quot; = &quot;&quot;C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe&quot; /icon&quot; [&quot;THOMSON multimedia&quot;]<br />&quot;NvCplDaemon&quot; = &quot;RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup&quot; [MS]<br />&quot;nwiz&quot; = &quot;nwiz.exe /install&quot; [&quot;NVIDIA Corporation&quot;]<br />&quot;NvMediaCenter&quot; = &quot;RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit&quot; [MS]<br />&quot;TrojanScanner&quot; = &quot;C:\Program Files\Trojan Remover\Trjscan.exe&quot; [&quot;Simply Super Software&quot;]</p><p>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\<br />{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;AcroIEHlprObj Class&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll&quot; [&quot;Adobe Systems Incorporated&quot;]<br />{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)<br />&nbsp; -&gt; {HKLM...CLSID} = (no title provided)<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\PROGRA~1\SPYBOT~1\SDHelper.dll&quot; [&quot;Safer Networking Limited&quot;]<br />{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;SSVHelper Class&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll&quot; [&quot;Sun Microsystems, Inc.&quot;]</p><p>HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\<br />&quot;{42071714-76d4-11d1-8b24-00a0c9068ff3}&quot; = &quot;Rozszerzenie CPL kadrowania wyświetlania&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;Rozszerzenie CPL kadrowania wyświetlania&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;deskpan.dll&quot; [file not found]<br />&quot;{88895560-9AA2-1069-930E-00AA0030EBC8}&quot; = &quot;Rozszerzenie ikony HyperTerminalu&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;HyperTerminal Icon Ext&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\WINDOWS\System32\hticons.dll&quot; [&quot;Hilgraeve, Inc.&quot;]<br />&quot;{B41DB860-8EE4-11D2-9906-E49FADC173CA}&quot; = &quot;WinRAR shell extension&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;WinRAR&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\WinRAR\rarext.dll&quot; [null data]<br />&quot;{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}&quot; = &quot;Shell Extensions for RealOne Player&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;RealOne Player Context Menu Class&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\Real\RealPlayer\rpshell.dll&quot; [&quot;RealNetworks, Inc.&quot;]<br />&quot;{A70C977A-BF00-412C-90B7-034C51DA2439}&quot; = &quot;NvCpl DesktopContext Class&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;DesktopContext Class&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\WINDOWS\System32\nvcpl.dll&quot; [&quot;NVIDIA Corporation&quot;]<br />&quot;{FFB699E0-306A-11d3-8BD1-00104B6F7516}&quot; = &quot;Play on my TV helper&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;NVIDIA CPL Extension&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\WINDOWS\System32\nvcpl.dll&quot; [&quot;NVIDIA Corporation&quot;]<br />&quot;{1CDB2949-8F65-4355-8456-263E7C208A5D}&quot; = &quot;Desktop Explorer&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;Desktop Explorer&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\WINDOWS\System32\nvshell.dll&quot; [&quot;NVIDIA Corporation&quot;]<br />&quot;{1E9B04FB-F9E5-4718-997B-B8DA88302A47}&quot; = &quot;Desktop Explorer Menu&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = (no title provided)<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\WINDOWS\System32\nvshell.dll&quot; [&quot;NVIDIA Corporation&quot;]<br />&quot;{1E9B04FB-F9E5-4718-997B-B8DA88302A48}&quot; = &quot;nView Desktop Context Menu&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;nView Desktop Context Menu&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\WINDOWS\System32\nvshell.dll&quot; [&quot;NVIDIA Corporation&quot;]<br />&quot;{52B87208-9CCF-42C9-B88E-069281105805}&quot; = &quot;Trojan Remover Shell Extension&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;Trojan Remover Shell Extension&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\PROGRA~1\TROJAN~1\Trshlex.dll&quot; [&quot;Simply Super Software&quot;]</p><p>HKLM\Software\Classes\*\shellex\ContextMenuHandlers\<br />MkS_Vir\(Default) = &quot;{CC4245C0-D511-11D0-8918-444553540000}&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;MkS_Vir Shell Extension&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\MKS\Bin\MkSShell.dll&quot; [null data]<br />Trojan Remover\(Default) = &quot;{52B87208-9CCF-42C9-B88E-069281105805}&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;Trojan Remover Shell Extension&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\PROGRA~1\TROJAN~1\Trshlex.dll&quot; [&quot;Simply Super Software&quot;]<br />WinRAR\(Default) = &quot;{B41DB860-8EE4-11D2-9906-E49FADC173CA}&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;WinRAR&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\WinRAR\rarext.dll&quot; [null data]</p><p>HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\<br />WinRAR\(Default) = &quot;{B41DB860-8EE4-11D2-9906-E49FADC173CA}&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;WinRAR&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\WinRAR\rarext.dll&quot; [null data]</p><p>HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\<br />MkS_Vir\(Default) = &quot;{CC4245C0-D511-11D0-8918-444553540000}&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;MkS_Vir Shell Extension&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\MKS\Bin\MkSShell.dll&quot; [null data]<br />Trojan Remover\(Default) = &quot;{52B87208-9CCF-42C9-B88E-069281105805}&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;Trojan Remover Shell Extension&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\PROGRA~1\TROJAN~1\Trshlex.dll&quot; [&quot;Simply Super Software&quot;]<br />WinRAR\(Default) = &quot;{B41DB860-8EE4-11D2-9906-E49FADC173CA}&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;WinRAR&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\WinRAR\rarext.dll&quot; [null data]</p><p><br />Active Desktop and Wallpaper:<br />-----------------------------</p><p>Active Desktop is disabled at this entry:<br />HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState</p><p>HKCU\Control Panel\Desktop\<br />&quot;Wallpaper&quot; = &quot;C:\Documents and Settings\wodzu\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp&quot;</p><p><br />Enabled Screen Saver:<br />---------------------</p><p>HKCU\Control Panel\Desktop\<br />&quot;SCRNSAVE.EXE&quot; = &quot;C:\WINDOWS\System32\logon.scr&quot; [MS]</p><p><br />Startup items in &quot;wodzu&quot; &amp; &quot;All Users&quot; startup folders:<br />-------------------------------------------------------</p><p>C:\Documents and Settings\All Users\Menu Start\Programy\Autostart<br />&quot;Microsoft Office&quot; -&gt; shortcut to: &quot;C:\Program Files\Microsoft Office\Office\OSA9.EXE -b -l&quot; [MS]<br />&quot;Adobe Gamma Loader&quot; -&gt; shortcut to: &quot;C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe&quot; [&quot;Adobe Systems, Inc.&quot;]</p><p><br />Winsock2 Service Provider DLLs:<br />-------------------------------</p><p>Namespace Service Providers</p><p>HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}<br />000000000001\LibraryPath = &quot;%SystemRoot%\System32\mswsock.dll&quot; [MS]<br />000000000002\LibraryPath = &quot;%SystemRoot%\System32\winrnr.dll&quot; [MS]<br />000000000003\LibraryPath = &quot;%SystemRoot%\System32\mswsock.dll&quot; [MS]</p><p>Transport Service Providers</p><p>HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}<br />0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:<br />%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 17<br />%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05</p><p><br />Toolbars, Explorer Bars, Extensions:<br />------------------------------------</p><p>Extensions (Tools menu items, main toolbar menu buttons)</p><p>HKLM\Software\Microsoft\Internet Explorer\Extensions\<br />{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\<br />&quot;MenuText&quot; = &quot;Sun Java Console&quot;<br /></p>

  • hommini 09.09.2006 22:09:36

    U mnie bylo tak samo. Pomogla instalacja firewalla. Konkretnie Outposta.

  • wodzu-4 10.09.2006 01:32:45

    Zainstalowałem ten program co radził mi &quot;hommini&quot; ale mam z nim małe problemy. Albo blokuje mi sieć że nic nie działa albo mogę go wyłaczyć i wtedy i tak neostrada cały czas wysyła obciążając sieć.<br />No a co do loga z Silent Runners to znowu czekałem około 30 min i żadnego komunikatu nie było. Ja już sam nie wiem co jeszcze mozę być Jeśli ktoś ma jeszcze jakiś pomysła to BARDZO PROSZE pomocy bo jeśli nie to skończy sie na formacie :(<br />

  • wodzu-4 10.09.2006 22:47:25

    <p>Witam</p><p>Chyba wreszcie udało mnie sie zrobić tego loga w Silent Runners. Oto on:</p><p>&quot;Silent Runners.vbs&quot;, revision 48, <a href="http://www.silentrunners.org/">http://www.silentrunners.org/</a><br />Operating System: Windows XP<br />Output limited to non-default values, except where indicated by &quot;{++}&quot;</p><p><br />Startup items buried in registry:<br />---------------------------------</p><p>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}<br />&quot;Komunikator&quot; = &quot;&quot;C:\Program Files\Tlen.pl\tlen.exe&quot; --confdir=home&quot; [&quot;o2.pl Sp. z o.o.&quot;]</p><p>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ {++}<br />&quot;DriverLoad&quot; = (empty string)<br />&quot;DriverCheck&quot; = (empty string)<br />&quot;SystemDriverLoad&quot; = (empty string)<br />&quot;Winhost&quot; = (empty string)<br />&quot;Winhost1&quot; = (empty string)<br />&quot;Winhost2&quot; = (empty string)<br />&quot;Winhost3&quot; = (empty string)<br />&quot;Winhost4&quot; = (empty string)<br />&quot;SystemDriver&quot; = &quot;c:\DriverLoad\windrv.exe&quot; [file not found]<br />&quot;FDriver&quot; = &quot;c:\DriverLoad\windrv.exe&quot; [file not found]<br />&quot;ADriver&quot; = &quot;c:\DriverLoad\windrv.exe&quot; [file not found]<br />&quot;CDriver&quot; = &quot;c:\DriverLoad\windrv.exe&quot; [file not found]<br />&quot;DDriver&quot; = &quot;c:\DriverLoad\windrv.exe&quot; [file not found]</p><p>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}<br />&quot;NeroFilterCheck&quot; = &quot;C:\WINDOWS\system32\NeroCheck.exe&quot; [&quot;Ahead Software Gmbh&quot;]<br />&quot;TkBellExe&quot; = &quot;&quot;C:\Program Files\Common Files\Real\Update_OB\realsched.exe&quot;&nbsp; -osboot&quot; [&quot;RealNetworks, Inc.&quot;]<br />&quot;MKS_MENU&quot; = &quot;C:\Program Files\MKS\Bin\mks_menu.exe&quot; [&quot;MKS Sp. z o.o.&quot;]<br />&quot;ABREGMON&quot; = &quot;C:\Program Files\MKS\Bin\ABregmon.exe&quot; [&quot;ArcaBit&quot;]<br />&quot;SpeedTouch USB Diagnostics&quot; = &quot;&quot;C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe&quot; /icon&quot; [&quot;THOMSON multimedia&quot;]<br />&quot;NvCplDaemon&quot; = &quot;RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup&quot; [MS]<br />&quot;nwiz&quot; = &quot;nwiz.exe /install&quot; [&quot;NVIDIA Corporation&quot;]<br />&quot;NvMediaCenter&quot; = &quot;RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit&quot; [MS]<br />&quot;Outpost Firewall&quot; = &quot;C:\PROGRA~1\AGNITUM\OUTPOS~1.0\outpost.exe /waitservice&quot; [&quot;Agnitum Ltd.&quot;]<br />&quot;OutpostFeedBack&quot; = &quot;C:\PROGRA~1\AGNITUM\OUTPOS~1.0\feedback.exe /dump:os_startup&quot; [&quot;Agnitum Ltd.&quot;]</p><p>HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\<br />{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;AcroIEHlprObj Class&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll&quot; [&quot;Adobe Systems Incorporated&quot;]<br />{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)<br />&nbsp; -&gt; {HKLM...CLSID} = (no title provided)<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\PROGRA~1\SPYBOT~1\SDHelper.dll&quot; [&quot;Safer Networking Limited&quot;]<br />{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;SSVHelper Class&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll&quot; [&quot;Sun Microsystems, Inc.&quot;]</p><p>HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\<br />&quot;{42071714-76d4-11d1-8b24-00a0c9068ff3}&quot; = &quot;Rozszerzenie CPL kadrowania wyświetlania&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;Rozszerzenie CPL kadrowania wyświetlania&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;deskpan.dll&quot; [file not found]<br />&quot;{88895560-9AA2-1069-930E-00AA0030EBC8}&quot; = &quot;Rozszerzenie ikony HyperTerminalu&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;HyperTerminal Icon Ext&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\WINDOWS\System32\hticons.dll&quot; [&quot;Hilgraeve, Inc.&quot;]<br />&quot;{B41DB860-8EE4-11D2-9906-E49FADC173CA}&quot; = &quot;WinRAR shell extension&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;WinRAR&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\WinRAR\rarext.dll&quot; [null data]<br />&quot;{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}&quot; = &quot;Shell Extensions for RealOne Player&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;RealOne Player Context Menu Class&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\Real\RealPlayer\rpshell.dll&quot; [&quot;RealNetworks, Inc.&quot;]<br />&quot;{A70C977A-BF00-412C-90B7-034C51DA2439}&quot; = &quot;NvCpl DesktopContext Class&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;DesktopContext Class&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\WINDOWS\System32\nvcpl.dll&quot; [&quot;NVIDIA Corporation&quot;]<br />&quot;{FFB699E0-306A-11d3-8BD1-00104B6F7516}&quot; = &quot;Play on my TV helper&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;NVIDIA CPL Extension&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\WINDOWS\System32\nvcpl.dll&quot; [&quot;NVIDIA Corporation&quot;]<br />&quot;{1CDB2949-8F65-4355-8456-263E7C208A5D}&quot; = &quot;Desktop Explorer&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;Desktop Explorer&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\WINDOWS\System32\nvshell.dll&quot; [&quot;NVIDIA Corporation&quot;]<br />&quot;{1E9B04FB-F9E5-4718-997B-B8DA88302A47}&quot; = &quot;Desktop Explorer Menu&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = (no title provided)<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\WINDOWS\System32\nvshell.dll&quot; [&quot;NVIDIA Corporation&quot;]<br />&quot;{1E9B04FB-F9E5-4718-997B-B8DA88302A48}&quot; = &quot;nView Desktop Context Menu&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;nView Desktop Context Menu&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\WINDOWS\System32\nvshell.dll&quot; [&quot;NVIDIA Corporation&quot;]<br />&quot;{52B87208-9CCF-42C9-B88E-069281105805}&quot; = &quot;Trojan Remover Shell Extension&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;Trojan Remover Shell Extension&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\PROGRA~1\TROJAN~1\Trshlex.dll&quot; [&quot;Simply Super Software&quot;]</p><p>HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\<br />INFECTION WARNING! &quot;AppInit_DLLs&quot; = &quot; C:\PROGRA~1\AGNITUM\OUTPOS~1.0\wl_hook.dll&quot; [&quot;Agnitum Ltd.&quot;]</p><p>HKLM\Software\Classes\*\shellex\ContextMenuHandlers\<br />ASW\(Default) = &quot;{33C9E362-3EDA-4930-8AFE-5DA39A8BB77A}&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;Outpost.ASWShellExt Component&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\PROGRA~1\AGNITUM\OUTPOS~1.0\op_shell.dll&quot; [&quot;Agnitum Ltd.&quot;]<br />MkS_Vir\(Default) = &quot;{CC4245C0-D511-11D0-8918-444553540000}&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;MkS_Vir Shell Extension&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\MKS\Bin\MkSShell.dll&quot; [null data]<br />Trojan Remover\(Default) = &quot;{52B87208-9CCF-42C9-B88E-069281105805}&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;Trojan Remover Shell Extension&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\PROGRA~1\TROJAN~1\Trshlex.dll&quot; [&quot;Simply Super Software&quot;]<br />WinRAR\(Default) = &quot;{B41DB860-8EE4-11D2-9906-E49FADC173CA}&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;WinRAR&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\WinRAR\rarext.dll&quot; [null data]</p><p>HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\<br />ASW\(Default) = &quot;{33C9E362-3EDA-4930-8AFE-5DA39A8BB77A}&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;Outpost.ASWShellExt Component&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\PROGRA~1\AGNITUM\OUTPOS~1.0\op_shell.dll&quot; [&quot;Agnitum Ltd.&quot;]<br />WinRAR\(Default) = &quot;{B41DB860-8EE4-11D2-9906-E49FADC173CA}&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;WinRAR&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\WinRAR\rarext.dll&quot; [null data]</p><p>HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\<br />ASW\(Default) = &quot;{33C9E362-3EDA-4930-8AFE-5DA39A8BB77A}&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;Outpost.ASWShellExt Component&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\PROGRA~1\AGNITUM\OUTPOS~1.0\op_shell.dll&quot; [&quot;Agnitum Ltd.&quot;]<br />MkS_Vir\(Default) = &quot;{CC4245C0-D511-11D0-8918-444553540000}&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;MkS_Vir Shell Extension&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\MKS\Bin\MkSShell.dll&quot; [null data]<br />Trojan Remover\(Default) = &quot;{52B87208-9CCF-42C9-B88E-069281105805}&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;Trojan Remover Shell Extension&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\PROGRA~1\TROJAN~1\Trshlex.dll&quot; [&quot;Simply Super Software&quot;]<br />WinRAR\(Default) = &quot;{B41DB860-8EE4-11D2-9906-E49FADC173CA}&quot;<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;WinRAR&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\WinRAR\rarext.dll&quot; [null data]</p><p><br />Active Desktop and Wallpaper:<br />-----------------------------</p><p>Active Desktop is disabled at this entry:<br />HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState</p><p>HKCU\Control Panel\Desktop\<br />&quot;Wallpaper&quot; = &quot;C:\Documents and Settings\wodzu\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp&quot;</p><p><br />Enabled Screen Saver:<br />---------------------</p><p>HKCU\Control Panel\Desktop\<br />&quot;SCRNSAVE.EXE&quot; = &quot;C:\WINDOWS\System32\logon.scr&quot; [MS]</p><p><br />Startup items in &quot;wodzu&quot; &amp; &quot;All Users&quot; startup folders:<br />-------------------------------------------------------</p><p>C:\Documents and Settings\All Users\Menu Start\Programy\Autostart<br />&quot;Microsoft Office&quot; -&gt; shortcut to: &quot;C:\Program Files\Microsoft Office\Office\OSA9.EXE -b -l&quot; [MS]<br />&quot;Adobe Gamma Loader&quot; -&gt; shortcut to: &quot;C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe&quot; [&quot;Adobe Systems, Inc.&quot;]</p><p><br />Winsock2 Service Provider DLLs:<br />-------------------------------</p><p>Namespace Service Providers</p><p>HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}<br />000000000001\LibraryPath = &quot;%SystemRoot%\System32\mswsock.dll&quot; [MS]<br />000000000002\LibraryPath = &quot;%SystemRoot%\System32\winrnr.dll&quot; [MS]<br />000000000003\LibraryPath = &quot;%SystemRoot%\System32\mswsock.dll&quot; [MS]</p><p>Transport Service Providers</p><p>HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}<br />0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:<br />%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 17<br />%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05</p><p><br />Toolbars, Explorer Bars, Extensions:<br />------------------------------------</p><p>Explorer Bars</p><p>Dormant Explorer Bars in &quot;View, Explorer Bar&quot; menu</p><p>HKLM\Software\Classes\CLSID\{A1A7E22D-1587-4230-8F16-081C68D21448}\(Default) = &quot;Szybkie dostosowywanie programu&quot;<br />Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]<br />InProcServer32\(Default) = &quot;C:\PROGRA~1\AGNITUM\OUTPOS~1.0\Plugins\BrowserBar\ie_bar.dll&quot; [&quot;Agnitum Ltd.&quot;]</p><p>HKLM\Software\Classes\CLSID\{A2595F37-48D0-46A1-9B51-478591A97764}\(Default) = &quot;Protection Bar&quot;<br />Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]<br />InProcServer32\(Default) = &quot;C:\Program Files\IntCodec\iesplugin.dll&quot; [file not found]</p><p>Extensions (Tools menu items, main toolbar menu buttons)</p><p>HKLM\Software\Microsoft\Internet Explorer\Extensions\<br />{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\<br />&quot;MenuText&quot; = &quot;Sun Java Console&quot;<br />&quot;CLSIDExtension&quot; = &quot;{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}&quot;<br />&nbsp; -&gt; {HKCU...CLSID} = &quot;Java Plug-in&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll&quot; [&quot;Sun Microsystems, Inc.&quot;]<br />&nbsp; -&gt; {HKLM...CLSID} = &quot;Java Plug-in 1.5.0_06&quot;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \InProcServer32\(Default) = &quot;C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll&quot; [&quot;Sun Microsystems, Inc.&quot;]</p><p>{44627E97-789B-40D4-B5C2-58BD171129A1}\<br />&quot;ButtonText&quot; = &quot;Szybkie dostosowywanie programu Outpost Firewall Pro&quot;</p><p><br />Running Services (Display Name, Service Name, Path {Service DLL}):<br />------------------------------------------------------------------</p><p>ArcaBit NetMonitor, ABNetMon, &quot;C:\Program Files\MKS\Bin\NetMonSV.exe&quot; [&quot;ArcaBit sp. z o.o.&quot;]<br />MkS_Scan, MkS_Scan, &quot;C:\Program Files\MKS\Bin\mks_scan.exe&quot; [empty string]<br />MkS_Vir Monitor, MksVirMonSvc, &quot;C:\Program Files\MKS\Bin\mksmonsv.exe&quot; [empty string]<br />NVIDIA Display Driver Service, NVSvc, &quot;C:\WINDOWS\System32\nvsvc32.exe&quot; [&quot;NVIDIA Corporation&quot;]</p><p><br />----------<br />+ This report excludes default entries except where indicated.<br />+ To see *everywhere* the script checks and *everything* it finds,<br />&nbsp; launch it from a command prompt or a shortcut with the -all parameter.<br />+ The search for DESKTOP.INI DLL launch points on all local fixed drives<br />&nbsp; took 350 seconds.<br />+ The search for all Registry CLSIDs containing dormant Explorer Bars<br />&nbsp; took 832 seconds.<br />---------- (total run time: 2792 seconds)<br /></p>

  • wodzu-4 16.09.2006 23:18:36

    Fajnie że juz tydzień czekam na jaką kolwiek odpowiedź a tutaj nic a nic. Nawe nikt nieodwazyła się napisać że nie wie co zrobić. Najlepiej to zostawić człowieka samego z problemem. WIELKIE DZIĘKI ZA BRAK POMOCY

  • De Niro 18.09.2006 13:11:11

    <p><BLOCKQUOTE><div>F2 - REG:system.ini: UserInit=userinit.exe</div></BLOCKQUOTE></p><p>ten wpis r&oacute;wnież należy usunąć&nbsp;&nbsp;&nbsp; &nbsp;</p>

  • wodzu-4 18.09.2006 15:37:25

    Witam ponownie<br />Zrobiłem zgodnie za poradą De Niro ale niestety problem cały czas zostaje bez zmiany :( <br />

Rejter
Dodano:
25.02.2005 23:22:55
Komentarzy:
1
Strona 1 / 1