Problem z otworzeniem plików/foldrów
Startup items buried in registry:
–––––––––––––––––––––––––––––––––
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"Gadu–Gadu" = ""C:\Program Files\Gadu–Gadu\gg.exe" /tray" ["sms–express.com"]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F–C8D7–4D59–B87D–784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{A5366673–E8CA–11D3–9CD9–0090271D075B}\(Default) = "IeCatch2 Class" [from CLSID]
–> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\FLASHGET\jccatch.dll" ["Amaze Soft"]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714–76d4–11d1–8b24–00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
–> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560–9AA2–1069–930E–00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{42042206–2D85–11D3–8CFF–005004838597}" = "Microsoft Office HTML Icon Handler"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
"{8FF88D21–7BD0–11D1–BFB7–00AA00262A11}" = "WinAce Archiver 2.11 Context Menu Shell Extension"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e–merge GmbH"]
"{8FF88D25–7BD0–11D1–BFB7–00AA00262A11}" = "WinAce Archiver 2.11 DragDrop Shell Extension"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e–merge GmbH"]
"{8FF88D27–7BD0–11D1–BFB7–00AA00262A11}" = "WinAce Archiver 2.11 Context Menu Shell Extension"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e–merge GmbH"]
"{8FF88D23–7BD0–11D1–BFB7–00AA00262A11}" = "WinAce Archiver 2.11 Property Sheet Shell Extension"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e–merge GmbH"]
"{B41DB860–8EE4–11D2–9906–E49FADC173CA}" = "WinRAR shell extension"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860–8EE4–11D2–9906–E49FADC173CA}"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
ZFAdd\(Default) = "{8FF88D27–7BD0–11D1–BFB7–00AA00262A11}"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e–merge GmbH"]
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860–8EE4–11D2–9906–E49FADC173CA}"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
ZFAdd\(Default) = "{8FF88D27–7BD0–11D1–BFB7–00AA00262A11}"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e–merge GmbH"]
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860–8EE4–11D2–9906–E49FADC173CA}"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
Active Desktop and Wallpaper:
–––––––––––––––––––––––––––––
Active Desktop is disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\!DZEJCOB\Dane aplikacji\Microsoft\Internet Explorer\Tapeta programu Internet Explorer.bmp"
Startup items in "!DZEJCOB" & "All Users" startup folders:
––––––––––––––––––––––––––––––––––––––––––––––––––––––––––
C:\Documents and Settings\!DZEJCOB\Menu Start\Programy\Autostart
"Ad–Watch SE Professional" –> shortcut to: "C:\Program Files\Lavasoft\Ad–Aware SE Professional\Ad–Watch.exe" ["Lavasoft Sweden"]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
"Microsoft Office" –> shortcut to: "C:\Program Files\Microsoft Office\Office10\OSA.EXE –b –l" [MS]
Winsock2 Service Provider DLLs:
–––––––––––––––––––––––––––––––
Namespace Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
Transport Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 – 03, 06 – 13
%SystemRoot%\system32\rsvpsp.dll [MS], 04 – 05
Toolbars, Explorer Bars, Extensions:
––––––––––––––––––––––––––––––––––––
Toolbars
HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{E0E899AB–F487–11D5–8D29–0050BA6940E3}" = "FlashGet Bar"
–> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\FLASHGET\fgiebar.dll" ["Amaze Soft"]
Extensions (Tools menu items, main toolbar menu buttons)
HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0–4FCB–11CF–AAA5–00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{08B0E5C0–4FCB–11CF–AAA5–00401C608501}"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\msjava.dll" [MS]
{D6E814A0–E0C5–11D4–8D29–0050BA6940E3}\
"ButtonText" = "FlashGet"
"MenuText" = "&FlashGet"
"Exec" = "C:\PROGRA~1\FLASHGET\flashget.exe" ["Amaze Soft"]
{FB5F1910–F110–11D2–BB9E–00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]
Running Services (Display Name, Service Name, Path {Service DLL}):
––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––
Machine Debug Manager, MDM, ""C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"" [MS]
SecuROM User Access Service (V7), UserAccess7, "C:\WINDOWS\system32\UAService7.exe" [null data]
––––––––––
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the –all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points and all Registry CLSIDs for dormant Explorer Bars,
use the –supp parameter or answer "Yes" at the first message box.
–––––––––– (total run time: 37 seconds, including 6 seconds for message boxes)
–––––––––––––––––––––––––––––––––
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"Gadu–Gadu" = ""C:\Program Files\Gadu–Gadu\gg.exe" /tray" ["sms–express.com"]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F–C8D7–4D59–B87D–784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{A5366673–E8CA–11D3–9CD9–0090271D075B}\(Default) = "IeCatch2 Class" [from CLSID]
–> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\FLASHGET\jccatch.dll" ["Amaze Soft"]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714–76d4–11d1–8b24–00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
–> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560–9AA2–1069–930E–00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{42042206–2D85–11D3–8CFF–005004838597}" = "Microsoft Office HTML Icon Handler"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
"{8FF88D21–7BD0–11D1–BFB7–00AA00262A11}" = "WinAce Archiver 2.11 Context Menu Shell Extension"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e–merge GmbH"]
"{8FF88D25–7BD0–11D1–BFB7–00AA00262A11}" = "WinAce Archiver 2.11 DragDrop Shell Extension"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e–merge GmbH"]
"{8FF88D27–7BD0–11D1–BFB7–00AA00262A11}" = "WinAce Archiver 2.11 Context Menu Shell Extension"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e–merge GmbH"]
"{8FF88D23–7BD0–11D1–BFB7–00AA00262A11}" = "WinAce Archiver 2.11 Property Sheet Shell Extension"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e–merge GmbH"]
"{B41DB860–8EE4–11D2–9906–E49FADC173CA}" = "WinRAR shell extension"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860–8EE4–11D2–9906–E49FADC173CA}"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
ZFAdd\(Default) = "{8FF88D27–7BD0–11D1–BFB7–00AA00262A11}"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e–merge GmbH"]
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860–8EE4–11D2–9906–E49FADC173CA}"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
ZFAdd\(Default) = "{8FF88D27–7BD0–11D1–BFB7–00AA00262A11}"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e–merge GmbH"]
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860–8EE4–11D2–9906–E49FADC173CA}"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
Active Desktop and Wallpaper:
–––––––––––––––––––––––––––––
Active Desktop is disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\!DZEJCOB\Dane aplikacji\Microsoft\Internet Explorer\Tapeta programu Internet Explorer.bmp"
Startup items in "!DZEJCOB" & "All Users" startup folders:
––––––––––––––––––––––––––––––––––––––––––––––––––––––––––
C:\Documents and Settings\!DZEJCOB\Menu Start\Programy\Autostart
"Ad–Watch SE Professional" –> shortcut to: "C:\Program Files\Lavasoft\Ad–Aware SE Professional\Ad–Watch.exe" ["Lavasoft Sweden"]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
"Microsoft Office" –> shortcut to: "C:\Program Files\Microsoft Office\Office10\OSA.EXE –b –l" [MS]
Winsock2 Service Provider DLLs:
–––––––––––––––––––––––––––––––
Namespace Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
Transport Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 – 03, 06 – 13
%SystemRoot%\system32\rsvpsp.dll [MS], 04 – 05
Toolbars, Explorer Bars, Extensions:
––––––––––––––––––––––––––––––––––––
Toolbars
HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{E0E899AB–F487–11D5–8D29–0050BA6940E3}" = "FlashGet Bar"
–> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\FLASHGET\fgiebar.dll" ["Amaze Soft"]
Extensions (Tools menu items, main toolbar menu buttons)
HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0–4FCB–11CF–AAA5–00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{08B0E5C0–4FCB–11CF–AAA5–00401C608501}"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\msjava.dll" [MS]
{D6E814A0–E0C5–11D4–8D29–0050BA6940E3}\
"ButtonText" = "FlashGet"
"MenuText" = "&FlashGet"
"Exec" = "C:\PROGRA~1\FLASHGET\flashget.exe" ["Amaze Soft"]
{FB5F1910–F110–11D2–BB9E–00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]
Running Services (Display Name, Service Name, Path {Service DLL}):
––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––
Machine Debug Manager, MDM, ""C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"" [MS]
SecuROM User Access Service (V7), UserAccess7, "C:\WINDOWS\system32\UAService7.exe" [null data]
––––––––––
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the –all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points and all Registry CLSIDs for dormant Explorer Bars,
use the –supp parameter or answer "Yes" at the first message box.
–––––––––– (total run time: 37 seconds, including 6 seconds for message boxes)
Odpowiedzi: 9
Poczekaj jak skrypt skończy produkowac log, pojawi się info. Dopiero wtedy wklej go do posta.
Zacznij uźywać przycisku zmień, bo następnym razem łączył juz nie będę, zacznę ciąć.
Zacznij uźywać przycisku zmień, bo następnym razem łączył juz nie będę, zacznę ciąć.
Poczekaj jak skrypt skończy produkowac log, pojawi się info. Dopiero wtedy wklej go do posta.
Zacznij uźywać przycisku zmień, bo następnym razem łączył juz nie będę, zacznę ciąć.
Zacznij uźywać przycisku zmień, bo następnym razem łączył juz nie będę, zacznę ciąć.
to oto chodzi??
Logfile of HijackThis v1.99.1
Scan saved at 12:58:25, on 2005–08–22
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/spoolsv.exe
C:/WINDOWS/Explorer.EXE
C:/Program Files\Gadu–Gadu\gg.exe
C:/Program Files/Lavasoft/Ad–Aware SE Professional/Ad–Watch.exe
C:/Program Files/Common Files/Microsoft Shared/VS7Debug/mdm.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/UAService7.exe
C:/WINDOWS/system32/ctfmon.exe
C:/WINDOWS/system32/javaw.exe
C:/Documents and Settings/!DZEJCOB/Pulpit/HijackThis.exe
R0 – HKCU/Software/Microsoft/Internet Explorer/Main,Start Page =
R0 – HKLM/Software/Microsoft/Internet Explorer/Main,Start Page =
R0 – HKLM/Software/Microsoft/Internet Explorer/Search,SearchAssistant =
R0 – HKLM/Software/Microsoft/Internet Explorer/Search,CustomizeSearch =
R0 – HKCU/Software/Microsoft/Internet Explorer/Main,Local Page =
R0 – HKLM/Software/Microsoft/Internet Explorer/Main,Local Page =
R0 – HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Łącza
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:/Program Files/Adobe/Acrobat 6.0 CE/Reader/ActiveX/AcroIEHelper.dll
O2 – BHO: IeCatch2 Class – {A5366673–E8CA–11D3–9CD9–0090271D075B} – C:/PROGRA~1/FLASHGET/jccatch.dll
O3 – Toolbar: FlashGet Bar – {E0E899AB–F487–11D5–8D29–0050BA6940E3} – C:/PROGRA~1/FLASHGET/fgiebar.dll
O4 – HKCU/../Run: [Gadu–Gadu] "C:/Program Files/Gadu–Gadu/gg.exe" /tray
O4 – Startup: Ad–Watch SE Professional.lnk = C:/Program Files/Lavasoft/Ad–Aware SE Professional/Ad–Watch.exe
O4 – Global Startup: Microsoft Office.lnk = C:/Program Files/Microsoft Office/Office10/OSA.EXE
O8 – Extra context menu item: Ściągnij przy pomocy FlashGet'a – C:/Program Files/FlashGet/jc_link.htm
O8 – Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a – C:/Program Files/FlashGet/jc_all.htm
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:/WINDOWS/System32/msjava.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:/WINDOWS/System32/msjava.dll
O9 – Extra button: FlashGet – {D6E814A0–E0C5–11d4–8D29–0050BA6940E3} – C:/PROGRA~1/FLASHGET/flashget.exe
O9 – Extra 'Tools' menuitem: &FlashGet – {D6E814A0–E0C5–11d4–8D29–0050BA6940E3} – C:/PROGRA~1/FLASHGET/flashget.exe
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:/Program Files/Messenger\msmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:/Program Files/Messenger/msmsgs.exe
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
O23 – Service: SecuROM User Access Service (V7) (UserAccess7) – Unknown owner – C:\WINDOWS\system32\UAService7.exe
Logfile of HijackThis v1.99.1
Scan saved at 12:58:25, on 2005–08–22
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/spoolsv.exe
C:/WINDOWS/Explorer.EXE
C:/Program Files\Gadu–Gadu\gg.exe
C:/Program Files/Lavasoft/Ad–Aware SE Professional/Ad–Watch.exe
C:/Program Files/Common Files/Microsoft Shared/VS7Debug/mdm.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/UAService7.exe
C:/WINDOWS/system32/ctfmon.exe
C:/WINDOWS/system32/javaw.exe
C:/Documents and Settings/!DZEJCOB/Pulpit/HijackThis.exe
R0 – HKCU/Software/Microsoft/Internet Explorer/Main,Start Page =
R0 – HKLM/Software/Microsoft/Internet Explorer/Main,Start Page =
R0 – HKLM/Software/Microsoft/Internet Explorer/Search,SearchAssistant =
R0 – HKLM/Software/Microsoft/Internet Explorer/Search,CustomizeSearch =
R0 – HKCU/Software/Microsoft/Internet Explorer/Main,Local Page =
R0 – HKLM/Software/Microsoft/Internet Explorer/Main,Local Page =
R0 – HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Łącza
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:/Program Files/Adobe/Acrobat 6.0 CE/Reader/ActiveX/AcroIEHelper.dll
O2 – BHO: IeCatch2 Class – {A5366673–E8CA–11D3–9CD9–0090271D075B} – C:/PROGRA~1/FLASHGET/jccatch.dll
O3 – Toolbar: FlashGet Bar – {E0E899AB–F487–11D5–8D29–0050BA6940E3} – C:/PROGRA~1/FLASHGET/fgiebar.dll
O4 – HKCU/../Run: [Gadu–Gadu] "C:/Program Files/Gadu–Gadu/gg.exe" /tray
O4 – Startup: Ad–Watch SE Professional.lnk = C:/Program Files/Lavasoft/Ad–Aware SE Professional/Ad–Watch.exe
O4 – Global Startup: Microsoft Office.lnk = C:/Program Files/Microsoft Office/Office10/OSA.EXE
O8 – Extra context menu item: Ściągnij przy pomocy FlashGet'a – C:/Program Files/FlashGet/jc_link.htm
O8 – Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a – C:/Program Files/FlashGet/jc_all.htm
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:/WINDOWS/System32/msjava.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:/WINDOWS/System32/msjava.dll
O9 – Extra button: FlashGet – {D6E814A0–E0C5–11d4–8D29–0050BA6940E3} – C:/PROGRA~1/FLASHGET/flashget.exe
O9 – Extra 'Tools' menuitem: &FlashGet – {D6E814A0–E0C5–11d4–8D29–0050BA6940E3} – C:/PROGRA~1/FLASHGET/flashget.exe
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:/Program Files/Messenger\msmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:/Program Files/Messenger/msmsgs.exe
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
O23 – Service: SecuROM User Access Service (V7) (UserAccess7) – Unknown owner – C:\WINDOWS\system32\UAService7.exe
Pokaź całość tego loga, bardziej jednak zalezy mi na logu z Silent Runners.
Opis i link masz w przyklejonym w bezpieczenstwie FAQ
P.S. Uźywaj przycisku ZMIEŃ
Opis i link masz w przyklejonym w bezpieczenstwie FAQ
P.S. Uźywaj przycisku ZMIEŃ
zrobiłem skana tym HijackThis i wyskoczyło od groma jakis wpisów?? niewiem czy to czasem nie jest zle??
np.
R0 – HKCU/Software/Microsoft/Internet Explorer/Main,Start Page =
R0 – HKLM/Software/Microsoft/Internet Explorer/Main,Start Page =
itp
to zle czy dobrze??
np.
R0 – HKCU/Software/Microsoft/Internet Explorer/Main,Start Page =
R0 – HKLM/Software/Microsoft/Internet Explorer/Main,Start Page =
itp
to zle czy dobrze??
??co??
Niewiem co to znaczy ale zainstalowałem inną przeglądarke (maxthon) i wszysto działa. :)
Niewiem co to znaczy ale zainstalowałem inną przeglądarke (maxthon) i wszysto działa. :)
Proces iexplore.exe w tasku zostaje zainicjowany ?
Rzuć logami z HijackThis i Silent Runners.
Jeśli to jest to co myśle to te programy to pokazą.
Rzuć logami z HijackThis i Silent Runners.
Jeśli to jest to co myśle to te programy to pokazą.
Dzięki bardzo z to !!
Tylko ze teraz mam problem z internet exsplorerem:( klikając 2 razy na ikonke jest brak reakcji, znaczy sie pokazuje sie klepsydra i zaraz znika a internet i tak sie nie otwiera
Tylko ze teraz mam problem z internet exsplorerem:( klikając 2 razy na ikonke jest brak reakcji, znaczy sie pokazuje sie klepsydra i zaraz znika a internet i tak sie nie otwiera
Dodaj do rejestru ten plik :arrow: (kliknij na niego dwukrotnie, na pytanie o scalenie z rejestrem odpowiedz twierdząco).
Strona 1 / 1