Pomocy robak z karty pamieci

Witam,

po powrocie z urlopu przywiozlem jakies wirusy na karcie pamieci, ktore mi prawdopodobnie wgrali w sklepie fotograficznym podczas przegrywania zdjec na CD. Obecnie komputer mi sie wylacza i jest mega wolny. Prosze o sprawdzenie czy wszystko. Dzieki. PS: nie znam sie za bardzo na komputerach.

Logfile of HijackThis v1.99.1

Scan saved at 11:52:01, on 2008-03-23

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe

C:\WINDOWS\system32\cisvc.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\Program Files\ESET\ESET Smart Security\ekrn.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\SOUNDMAN.EXE

C:\WINDOWS\ehome\ehtray.exe

C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

C:\WINDOWS\system32\umonit.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\WINDOWS\system32\LVCOMSX.EXE

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\QuickTime\QTTask.exe

C:\Program Files\ESET\ESET Smart Security\egui.exe

C:\WINDOWS\eHome\ehmsas.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe

C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

C:\WINDOWS\system32\cidaemon.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Documents and Settings\Romek\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bph.pl/pl

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

F2 - REG:system.ini: Shell=Explorer.exe,service.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O4 - HKLM…\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM…\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

O4 - HKLM…\Run: [ATICCC] “C:\Program Files\ATI Technologies\ATI.ACE\cli.exe” runtime -Delay

O4 - HKLM…\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg

O4 - HKLM…\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM…\Run: [uMonit] C:\WINDOWS\system32\umonit.exe

O4 - HKLM…\Run: [WooCnxMon] C:\PROGRA~1\Neostrada TP\CnxMon.exe

O4 - HKLM…\Run: [iTunesHelper] “C:\Program Files\iTunes\iTunesHelper.exe”

O4 - HKLM…\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE

O4 - HKLM…\Run: [TkBellExe] “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot

O4 - HKLM…\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,BluetoothAuthenticationAgent

O4 - HKLM…\Run: [QuickTime Task] “C:\Program Files\QuickTime\QTTask.exe” -atboottime

O4 - HKLM…\Run: [egui] “C:\Program Files\ESET\ESET Smart Security\egui.exe” /hide /waitservice

O4 - HKLM…\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKCU…\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU…\Run: [MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background

O4 - HKCU…\Run: [Dancer] “C:\Program Files\Windows Plus\Dancer\Dancer.exe”

O4 - HKCU…\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe

O4 - HKCU…\Run: [MsnMsgr] “C:\Program Files\MSN Messenger\MsnMsgr.Exe” /background

O4 - Global Startup: BlueSoleil.lnk = ?

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: START_PAGE_URL=http://www.vobis.pl/

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab

O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab

O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar … vSniff.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab

O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab

O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab

O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab

O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar … /cabsa.cab

O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab

O16 - DPF: {92ECE6FA-AC2E-4042-BFAE-0C8608E52A43} (SignActivX Control) - https://www.bph.pl/pi/components/SignActivX.cab

O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-l … cfscan.cab

O17 - HKLM\System\CCS\Services\Tcpip…{3D3AB371-171D-41E1-81F2-F03F45153900}: NameServer = 194.204.152.34 217.98.63.164

O18 - Protocol: bw+0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw+0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw-0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw-0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw00 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw00s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw10 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw10s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw20 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw20s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw30 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw30s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw40 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw40s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw50 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw50s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw60 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw60s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw70 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw70s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw80 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw80s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw90 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw90s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwa0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwa0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwb0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwb0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwc0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwc0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwd0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwd0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwe0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwe0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwf0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwf0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O18 - Protocol: bwg0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwg0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwh0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwh0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwi0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwi0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwj0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwj0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwk0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwk0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwl0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwl0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwm0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwm0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwn0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwn0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwo0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwo0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwp0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwp0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwq0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwq0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwr0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwr0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bws0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bws0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwt0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwt0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwu0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwu0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwv0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwv0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bww0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bww0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwx0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwx0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwy0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwy0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwz0 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwz0s - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: offline-8876480 - {A3DB0F5D-CBB7-462D-8B9F-375355D05F4F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe

O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe

O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe (file missing)

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

Zasady wklejania logów na forum - http://forum.dobreprogramy.pl/viewtopic.php?f=16&t=213350

Wpis zafixuj w HijacThis czyli zaptaszkuj i kliknij w Fix Checked .

Podaj log z ComboFix’a :arrow: http://download.bleepingcomputer.com/sUBs/ComboFix.exe.

Możesz jeszcze usunąć Desktop Messenger z C:\Program Files\Logitech\ Desktop Messenger jeśli nie używasz .

Dziękuję za szybka odpowiedz.

chciałbym wkleić loga tak jak to jest opisane, ale nie mogę otworzyć strony…wklej.org (komunikat: połączenie zostało zresetowane… a może robię coś źle?

wykonałem, a Desktop Messenger nie reaguje na usuwanie…

poniżej log z ComboFix’a:

ComboFix 08-03-22.3 - Romek 2008-03-23 16:41:21.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.569 [GMT 1:00]

Running from: C:\Documents and Settings\Romek\Desktop\ComboFix.exe

* Created a new restore point

* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

C:\WINDOWS\hosts

C:\WINDOWS\system32\pskill.exe

.

((((((((((((((((((((((((( Files Created from 2008-02-23 to 2008-03-23 )))))))))))))))))))))))))))))))

.

2008-03-31 14:41 . 2008-03-31 14:41

2008-03-28 15:17 . 2008-02-26 03:50 54,156 --ah----- C:\WINDOWS\QTFont.qfn

2008-03-28 15:17 . 2008-03-28 15:17 1,409 --a------ C:\WINDOWS\QTFont.for

2008-03-28 15:16 . 2008-03-28 15:16

2008-03-28 15:16 . 2008-03-28 15:16

2008-03-23 16:34 . 2008-03-23 16:34

2008-03-23 16:34 . 2008-03-23 16:34 16,384 --a----t- C:\Temp\Perflib_Perfdata_d24.dat

2008-03-23 16:34 . 2008-03-23 16:34 16,384 --a----t- C:\Temp\Perflib_Perfdata_d1c.dat

2008-03-23 16:34 . 2008-03-23 16:34 16,384 --a----t- C:\Temp\Perflib_Perfdata_970.dat

2008-03-22 20:07 . 2008-03-22 20:07 16,384 --a----t- C:\Temp\Perflib_Perfdata_d64.dat

2008-03-22 20:07 . 2008-03-22 20:07 16,384 --a----t- C:\Temp\Perflib_Perfdata_d58.dat

2008-03-22 20:07 . 2008-03-22 20:07 16,384 --a----t- C:\Temp\Perflib_Perfdata_988.dat

2008-03-21 19:54 . 2008-03-21 19:54 1,374 --a------ C:\WINDOWS\system32\wpa.bak

2008-03-20 20:35 . 2008-03-20 20:35 16,384 --a----t- C:\Temp\Perflib_Perfdata_d44.dat

2008-03-20 20:25 . 2008-03-21 19:54 8,192 --a------ C:\WINDOWS\system32\sdpsrv.dll

2008-03-20 01:23 . 2008-03-20 01:23 16,384 --a----t- C:\Temp\Perflib_Perfdata_634.dat

2008-02-26 16:49 . 2008-02-26 16:49

2008-02-24 13:25 . 2008-02-24 13:25 16,384 --a----t- C:\Temp\Perflib_Perfdata_740.dat

2008-02-23 03:36 . 2008-03-23 00:23

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-04-04 09:59 --------- d-----w C:\Documents and Settings\Romek\Application Data\Wireshark

2008-04-03 23:41 --------- d-----w C:\Program Files\Wireshark

2008-04-03 23:40 --------- d-----w C:\Program Files\WinPcap

2008-04-01 16:24 --------- d-----w C:\Program Files\Gadu-Gadu

2008-03-28 14:18 --------- d-----w C:\Program Files\QuickTime

2008-03-28 14:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer

2008-03-26 12:03 --------- d-----w C:\Documents and Settings\Romek\Application Data\MyPhoneExplorer

2008-03-22 21:39 --------- d-----w C:\Documents and Settings\Romek\Application Data\Skype

2008-02-27 09:04 --------- d-----w C:\Program Files\Symantec

2008-02-26 01:02 --------- d-----w C:\Documents and Settings\Romek\Application Data\U3

2008-02-26 00:55 --------- d-----w C:\Program Files\eMule

2008-02-22 02:42 --------- d-----w C:\Documents and Settings\Romek\Application Data\ESET

2008-02-22 02:41 --------- d-----w C:\Program Files\ESET

2008-02-22 02:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET

2008-02-22 02:37 --------- d-----w C:\Program Files\Common Files\Symantec Shared

2008-02-22 02:35 --------- d-----w C:\Program Files\CCleaner

2008-02-22 02:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec

2008-02-22 02:34 --------- d-----w C:\Program Files\Yahoo!

2008-02-22 02:32 --------- d-----w C:\Documents and Settings\Romek\Application Data\Symantec

2006-03-05 23:55 338 ----a-w C:\Program Files\Neostrada

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-10 13:00 15360]

“MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2004-10-13 17:24 1694208]

“Dancer”=“C:\Program Files\Windows Plus\Dancer\Dancer.exe” []

“LDM”=“C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe” []

“MsnMsgr”=“C:\Program Files\MSN Messenger\MsnMsgr.exe” []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

“SoundMan”=“SOUNDMAN.EXE” [2005-12-14 18:06 577536 C:\WINDOWS\SOUNDMAN.EXE]

“ehTray”=“C:\WINDOWS\ehome\ehtray.exe” [2005-08-05 13:56 64512]

“ATICCC”=“C:\Program Files\ATI Technologies\ATI.ACE\cli.exe” [2005-08-12 14:43 45056]

“PinnacleDriverCheck”=“C:\WINDOWS\system32\PSDrvCheck.exe” [2004-03-10 15:26 406016]

“NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 10:50 155648]

“UMonit”=“C:\WINDOWS\system32\umonit.exe” [2004-05-11 14:34 53248]

“WooCnxMon”=“C:\PROGRA~1\Neostrada TP\CnxMon.exe” [2003-10-16 18:07 24576]

“NWEReboot”="" []

“iTunesHelper”=“C:\Program Files\iTunes\iTunesHelper.exe” [2006-02-23 15:45 278528]

“LVCOMSX”=“C:\WINDOWS\system32\LVCOMSX.EXE” [2005-07-19 16:32 221184]

“TkBellExe”=“C:\Program Files\Common Files\Real\Update_OB\realsched.exe” [2006-06-19 12:11 180269]

“BluetoothAuthenticationAgent”=“bthprops.cpl” [2004-08-10 13:00 110592 C:\WINDOWS\system32\bthprops.cpl]

“QuickTime Task”=“C:\Program Files\QuickTime\QTTask.exe” [2008-01-10 15:27 385024]

“egui”=“C:\Program Files\ESET\ESET Smart Security\egui.exe” [2007-11-23 21:51 1410304]

[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-10 13:00 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\

BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2006-12-06 23:43:42 1183744]

Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 19:05:56 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

“InstallVisualStyle”= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles

“InstallTheme”= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

“AntiVirusDisableNotify”=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

“DisableMonitoring”=dword:00000001

[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

“EnableFirewall”= 0 (0x0)

[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

“%windir%\system32\sessmgr.exe”=

“C:\Program Files\iTunes\iTunes.exe”=

“C:\Program Files\Messenger\msmsgs.exe”=

“C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe”=

“C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe”=

“C:\Program Files\LimeWire\LimeWire.exe”=

“%windir%\Network Diagnostic\xpnetdiag.exe”=

“C:\Program Files\Skype\Phone\Skype.exe”=

R3 fixustor;fixustor;C:\WINDOWS\system32\drivers\fixustor.sys [2004-05-11 15:38]

S2 PavProc;Panda Process Protection Driver;C:\WINDOWS\system32\DRIVERS\PavProc.sys []

S3 pmxdrv;pmxdrv;C:\WINDOWS\system32\drivers\pmxdrv.sys []

S3 ProcAPI;ProcAPI;C:\Documents and Settings\Administrator\Desktop\Intel Frequency Display\ProcAPI.sys []

S3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;C:\WINDOWS\system32\DRIVERS\WlanBZXP.sys [2005-12-22 14:45]

S3 ULI5261XP;ULi M526X Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN51.SYS [2005-03-22 20:36]

S3 ZDCndis5;ZDCndis5 Protocol Driver;C:\WINDOWS\system32\ZDCndis5.SYS []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{5a3cfebd-542f-11dc-9a16-000e50ae5fee}]

\Shell\AutoRun\command - G:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{a0c3f950-a79f-11da-ba1f-00138f729a1c}]

\Shell\AutoRun\command - cmd /Q /K autorun.cmd

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{c4c262a1-04b5-11dc-99ee-000e50ae5fee}]

\Shell\AutoRun\command - G:\setupSNK.exe

.

**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-03-23 16:43:25

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

UMonit = C:\WINDOWS\system32\umonit.exe?s?B\Vid_08???Pid_6803???c?9&PID5238???B?O???w???s?l???|p??|???m??|C??w???c?B$?|???w???w*?,???c???w???s???T???~?s???s???s???

scanning hidden files …

scan completed successfully

hidden files: 0

**************************************************************************

.

Completion time: 2008-03-23 16:43:59

ComboFix-quarantined-files.txt 2008-03-23 15:43:55

.

2008-03-20 08:20:25 — E O F —

start >> uruchom >> cmd

sc stop PavProc

sc stop pmxdrv

sc stop ProcAPI

sc stop ZDCndis5

sc delete PavProc

sc delete pmxdrv

sc delete ProcAPI

sc delete ZDCndis5

otwórz notatnik i wklej

zapisz jako plik.reg >> wszystkie pliki >> scal z rejestrem >> restart

b57f17008275c957m.jpg

powstanie plik o takiej ikonie

062aec4c9b51c033m.jpg

w który dwa razy klikniesz potwierdzisz chęć dodania do rejestru potem restart

:slight_smile:

Zmiana zasad wklejania logów na forum - viewtopic.php?f=16&t=213350

Witaj Leon

dziękuję za odpowiedź. Niestety jako, że jestem laikiem nie rozumiem wszystkiego o czym napisales. Potrafię wejść w cmd, ale nie wiem co tam wpisywać i jak dokładnie to robić. To mam wpisać?:

i co znaczy “scal z registrem”?

pozdrawiam

Tak to masz wpisać

po każdej komendzie Enter

obejrzyj obrazki i podpisy pod nimi

:slight_smile: