sprawdźcie mojego loga, proszę ;–)
Logfile of HijackThis v1.99.1
Scan saved at 11:03:15, on 05–02–22
Platform: Windows NT 4 SP6 (WinNT 4.00.1381)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINNTSystem32smss.exe
C:WINNTsystem32winlogon.exe
C:WINNTsystem32services.exe
C:WINNTsystem32lsass.exe
C:WINNTsystem32ionusb.exe
C:WINNTsystem32RpcSs.exe
C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:WINNTsystem32spoolss.exe
C:Program FilesSymantec AntiVirusDefWatch.exe
C:Program FilesExecutive SoftwareDiskeeperLiteDKService.exe
C:WINNTSystem32LexStart.Exe
c:winntsystem32pstores.exe
C:WINNTsystem32MSTask.exe
C:WINNTSystem32 ddeagnt.exe
C:Program FilesSymantec AntiVirusRtvscan.exe
C:WINNTExplorer.exe
C:WINNTSystem32SysTray.Exe
C:WINNTSystem32loadwc.exe
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:PROGRA~1SYMANT~2VPTray.exe
C:Program FilesYDPYdpDictWatch.exe
C:WINNTSystem32 undll32.exe
C:WINNTSystem32ddhelp.exe
C:Program FilesMaxthonMaxthon.exe
C:Program FilesGadu–Gadugg.exe
C:PROGRA~1Plus!MICROS~1iexplore.exe
C:Program FilesMicrosoft OfficeOfficeEXCEL.EXE
C:Program FilesOutlook ExpressMSIMN.EXE
C:PROGRA~1DAPDAP.EXE
C:Program FilesWinRARWinRAR.exe
E:DownloadHijackThis.exe
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
F2 – REG:system.ini: UserInit=userinit,nddeagnt.exe
O2 – BHO: DAPHelper Class – {0000CC75–ACF3–4cac–A0A9–DD3868E06852} – C:Program FilesDAPDAPBHO.dll
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINNTSystem32msdxm.ocx
O4 – HKLM..Run: [SystemTray] SysTray.Exe
O4 – HKLM..Run: [BrowserWebCheck] loadwc.exe
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINNTSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINNTSystem32NvMcTray.dll,NvTaskbarInit
O4 – HKLM..Run: [SchedulingAgent] mstinit.exe /logon
O4 – HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 – HKLM..Run: [vptray] C:PROGRA~1SYMANT~2VPTray.exe
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – Startup: Sygnaturka.lnk = C:Program FileseMuleOnlineSig.13.binonline.exe
O4 – Startup: Słownik YDP.lnk = C:Program FilesYDPYdpDictYdpDict.exe
O4 – Global Startup: Aktywacja Testera.lnk = C:Program FilesYDPYdpDictWatch.exe
O4 – Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOfficeOSA9.EXE
O8 – Extra context menu item: &Download with &DAP – C:PROGRA~1DAPdapextie.htm
O8 – Extra context menu item: Download &all with DAP – C:PROGRA~1DAPdapextie2.htm
O9 – Extra button: Run DAP – {669695BC–A811–4A9D–8CDF–BA8C795F261C} – C:PROGRA~1DAPDAP.EXE
O13 – WWW. Prefix: http://
O16 – DPF: komentator – http://sport.onet.pl/komentator.cab
O16 – DPF: Notowania ONET – http://www.pb.pl/notowania/applet/notowania.cab
O16 – DPF: {43A848AB–928D–43A0–8B8A–81D953E9F3EE} (XMLFileSaver Class) – https://www.brebrokers.pl/res/EPMXMLFILESAVERCOM.cab
O16 – DPF: {AFD8ED36–EA54–11D6–AC3F–00105ADCF632} (Ntw4 Control) – https://www.brebrokers.pl/res/ntw4.cab
O20 – Winlogon Notify: NavLogon – C:WINNTSystem32NavLogon.dll
O23 – Service: Symantec Event Manager (ccEvtMgr) – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
O23 – Service: Symantec Password Validation (ccPwdSvc) – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccPwdSvc.exe
O23 – Service: Symantec Settings Manager (ccSetMgr) – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
O23 – Service: Symantec AntiVirus Definition Watcher (DefWatch) – Symantec Corporation – C:Program FilesSymantec AntiVirusDefWatch.exe
O23 – Service: Diskeeper – Executive Software International, Inc. – C:Program FilesExecutive SoftwareDiskeeperLiteDKService.exe
O23 – Service: IONUSB (ionusb) – Inside Out Networks – C:WINNTsystem32ionusb.exe
O23 – Service: SAVRoam (SavRoam) – symantec – C:Program FilesSymantec AntiVirusSavRoam.exe
O23 – Service: Symantec Network Drivers Service (SNDSrvc) – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe
O23 – Service: Symantec AntiVirus – Symantec Corporation – C:Program FilesSymantec AntiVirusRtvscan.exe
Odpowiedzi: 1
Do usuniecia:
O13 – WWW. Prefix: http://
O16 – DPF: {43A848AB–928D–43A0–8B8A–81D953E9F3EE} (XMLFileSaver Class) – https://www.brebrokers.pl/res/EPMXMLFILESAVERCOM.cab
O16 – DPF: {AFD8ED36–EA54–11D6–AC3F–00105ADCF632} (Ntw4 Control) – https://www.brebrokers.pl/res/ntw4.cab
Strona 1 / 1