Problem XP

Witam problem z roznymi programami typu adware i nie tylko (kilkugodzinne posiedzenie mlodszego brata przy moim kompie :frowning: )

Mam problem z usunieciem kilki plikow np: G???.exe i plikow ktore nie maja sciezki dostepu .pomocy.

Log z HijackThis:

Logfile of HijackThis v1.97.7

Scan saved at 10:16:58, on 2005-02-19

Platform: Windows XP (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Tlen.pl\tlen.exe

C:\WINDOWS\System32\ctfmon.exe

C:\Program Files\F-Secure Anti-Virus\backweb\4476822\program\fsbwsys.exe

C:\Program Files\Kerio\Personal Firewall 3\kpf3.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Documents and Settings\PoroKaktus\Pulpit\HijackThis.exe

C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Microsoft Office\Office10\WINWORD.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.popupsearches.com/sidesearch.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.popupsearches.com/sidesearch.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.popupsearches.com/sidesearch.html

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.popupsearches.com/sidesearch.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.popupsearches.com/sidesearch.html

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {1D7E3B41-23CE-469B-BE1B-A64B877923E1} - C:\PROGRA~1\SEARCH~2\SEARCH~1.DLL

O2 - BHO: ohb - {4D568F0F-8AC9-40AB-88B7-415134C78777} - (no file)

O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll

O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll

O4 - HKLM…\Run: [jxthylur] C:\WINDOWS\System32\izwnsy.exe

O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM…\Run: [CloneCDTray] “C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe” /s

O4 - HKLM…\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe

O4 - HKLM…\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM…\Run: [nwiz] nwiz.exe /install

O4 - HKLM…\Run: [WebRebates0] C:\Program Files\Web_Rebates\WebRebates0.exe

O4 - HKCU…\Run: [Komunikator] C:\Program Files\Tlen.pl\tlen.exe

O4 - HKCU…\Run: [steam] D:\Valve\Steam\Steam.exe -silent

O4 - HKCU…\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe

O4 - HKCU…\Run: [Esil] C:\Documents and Settings\PoroKaktus\Dane aplikacji\g???.exe

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm

O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm

O9 - Extra button: FlashGet (HKLM)

O9 - Extra ‘Tools’ menuitem: &FlashGet (HKLM)

O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/rap … loader.cab

O16 - DPF: {07E9CDF4-20D2-46B1-B681-663968F527CE} - http://www.begin2search.com/toolbar/bar/winb2s32.cab

O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/Music … dge-c8.cab

O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shoc … tor/sw.cab

O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll

O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://host.cycore.net/plugins/windows/ … .0.228.cab

O16 - DPF: {3E339D3C-4B12-4E8C-A529-9CC4BEEAFD4F} (VacPro.russia_ver3) - http://advnt01.com/dialer/russia.CAB

O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://mapguide.procad.pl/download/mgaxctrl.cab

O16 - DPF: {7823A620-9DD9-11CF-A662-00AA00C066D2} (PopupMenu Object) - http://activex.microsoft.com/controls/i … iemenu.cab

O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://217.113.232.40/activex/AxisCamControl.cab

O16 - DPF: {AB8638BB-79E8-4E9D-ABF2-8F33054E3941} (Guesser Class) - http://czat.onet.pl/client/kalambury/NetPunGame1.dll

O16 - DPF: {AE609930-A6EB-4A78-B7DA-B3200705FEBD} (Mophun Control) - http://www.mophun.com/codebase/mophun.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash4/cabs/swflash.cab

O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) - http://skaner.mks.com.pl/SkanerOnline.cab

O16 - DPF: {FE4BBEA8-1EFD-4B8A-BD1B-341CCDBEEAA6} - http://ads.dealhelper.com/updates/DealHelperNew.cab

A oto log ze staru windows:

StartupList report, 2005-02-19, 10:17:36

StartupList version: 1.52

Started from : C:\Documents and Settings\PoroKaktus\Pulpit\HijackThis.EXE

Detected: Windows XP (WinNT 5.01.2600)

Detected: Internet Explorer v6.00 (6.00.2600.0000)

* Using default options

==================================================

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Tlen.pl\tlen.exe

C:\WINDOWS\System32\ctfmon.exe

C:\Program Files\F-Secure Anti-Virus\backweb\4476822\program\fsbwsys.exe

C:\Program Files\Kerio\Personal Firewall 3\kpf3.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Documents and Settings\PoroKaktus\Pulpit\HijackThis.exe

C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Microsoft Office\Office10\WINWORD.EXE

C:\WINDOWS\system32\NOTEPAD.EXE


Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]

UserInit = C:\WINDOWS\system32\userinit.exe,


Autorun entries from Registry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

jxthylur = C:\WINDOWS\System32\izwnsy.exe

NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

CloneCDTray = “C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe” /s

WinampAgent = C:\Program Files\Winamp\winampa.exe

NeroFilterCheck = C:\WINDOWS\system32\NeroCheck.exe

nwiz = nwiz.exe /install

WebRebates0 = C:\Program Files\Web_Rebates\WebRebates0.exe


Autorun entries from Registry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Komunikator = C:\Program Files\Tlen.pl\tlen.exe

Steam = D:\Valve\Steam\Steam.exe -silent

CTFMON.EXE = C:\WINDOWS\System32\ctfmon.exe

MSMsgSvc =

Esil = C:\Documents and Settings\PoroKaktus\Dane aplikacji\g???.exe


Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*

SCRNSAVE.EXE=*INI section not found*

drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe

SCRNSAVE.EXE=*Registry value not found*

drivers=*Registry value not found*

Policies Shell key:

HKCU…\Policies: Shell=*Registry key not found*

HKLM…\Policies: Shell=*Registry value not found*


Enumerating Browser Helper Objects:

(no name) - C:\PROGRA~1\SEARCH~2\SEARCH~1.DLL - {1D7E3B41-23CE-469B-BE1B-A64B877923E1}

ohb - (no file) - {4D568F0F-8AC9-40AB-88B7-415134C78777}

(no name) - C:\PROGRA~1\FlashGet\jccatch.dll - {A5366673-E8CA-11D3-9CD9-0090271D075B}


Enumerating Download Program Files:

[RaptisoftGameLoader]

CODEBASE = http://www.miniclip.com/hamsterball/rap … loader.cab

OSD = C:\WINDOWS\Downloaded Program Files\OSD28E7.OSD

[{07E9CDF4-20D2-46B1-B681-663968F527CE}]

CODEBASE = http://www.begin2search.com/toolbar/bar/winb2s32.cab

[{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}]

InProcServer32 = C:\WINDOWS\Downloaded Program Files\AdToolsX.dll

CODEBASE = http://static.windupdates.com/cab/Music … dge-c8.cab

[shockwave ActiveX Control]

InProcServer32 = C:\WINDOWS\system32\Macromed\Director\SwDir.dll

CODEBASE = http://download.macromedia.com/pub/shoc … tor/sw.cab

[CR64Loader Object]

InProcServer32 = C:\WINDOWS\Downloaded Program Files\miniclipGameLoader.dll

CODEBASE = http://www.miniclip.com/platypus/miniclipGameLoader.dll

[Cult3D ActiveX Player]

InProcServer32 = C:\WINDOWS\System32\Cult3D\IECult.dll

CODEBASE = http://host.cycore.net/plugins/windows/ … .0.228.cab

[VacPro.russia_ver3]

InProcServer32 = C:\WINDOWS\Downloaded Program Files\russia.ocx

CODEBASE = http://advnt01.com/dialer/russia.CAB

[Autodesk MapGuide ActiveX Control]

InProcServer32 = C:\WINDOWS\Downloaded Program Files\MgAxCtrl.dll

CODEBASE = http://mapguide.procad.pl/download/mgaxctrl.cab

[PopupMenu Object]

InProcServer32 = C:\WINDOWS\Downloaded Program Files\iemenu.ocx

CODEBASE = http://activex.microsoft.com/controls/i … iemenu.cab

[CamImage Class]

InProcServer32 = C:\WINDOWS\Downloaded Program Files\AxisCamControl.ocx

CODEBASE = http://217.113.232.40/activex/AxisCamControl.cab

[Guesser Class]

InProcServer32 = C:\WINDOWS\Downloaded Program Files\NetPunGame1.dll

CODEBASE = http://czat.onet.pl/client/kalambury/NetPunGame1.dll

[Mophun Control]

InProcServer32 = C:\WINDOWS\DOWNLO~1\mophun.ocx

CODEBASE = http://www.mophun.com/codebase/mophun.cab

[shockwave Flash Object]

InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocx

CODEBASE = http://active.macromedia.com/flash4/cabs/swflash.cab

[MainControl Class]

InProcServer32 = C:\WINDOWS\System32\SkanerOnline.dll

CODEBASE = http://skaner.mks.com.pl/SkanerOnline.cab

[{FE4BBEA8-1EFD-4B8A-BD1B-341CCDBEEAA6}]

CODEBASE = http://ads.dealhelper.com/updates/DealHelperNew.cab


Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll

CDBurn: C:\WINDOWS\system32\SHELL32.dll

WebCheck: C:\WINDOWS\System32\webcheck.dll

SysTray: C:\WINDOWS\System32\stobject.dll


End of report, 6 377 bytes

Report generated in 0,046 seconds

Command line options:

/verbose - to add additional info on each section

/complete - to include empty sections and unsuspicious data

/full - to include several rarely-important sections

/force9x - to include Win9x-only startups even if running on WinNT

/forcent - to include WinNT-only startups even if running on Win9x

/forceall - to include all Win9x and WinNT startups, regardless of platform

/history - to list version history only

Dzieki za odpowiedz pozdrawiam.

WoW :o , masz zdolnego brata :stuck_out_tongue:

Kasujesz

Potem skan AntiVirem, Ad-Awarem, SpyBotem i Polecam winstalowanie SP2 :stuck_out_tongue:

Wklej loga z

HijackThis 1.99

Wedle zyczenia v1.99.1

Logfile of HijackThis v1.99.1

Scan saved at 13:35:31, on 2005-02-19

Platform: Windows XP (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Tlen.pl\tlen.exe

C:\WINDOWS\System32\ctfmon.exe

C:\Program Files\F-Secure Anti-Virus\backweb\4476822\program\fsbwsys.exe

C:\Program Files\Kerio\Personal Firewall 3\kpf3.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\WINDOWS\System32\svchost.exe

E:\eMule\emule.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Documents and Settings\PoroKaktus\Pulpit\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {4D568F0F-8AC9-40AB-88B7-415134C78777} - (no file)

O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll

O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll

O4 - HKLM…\Run: [jxthylur] C:\WINDOWS\System32\izwnsy.exe

O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM…\Run: [CloneCDTray] “C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe” /s

O4 - HKLM…\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe

O4 - HKLM…\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM…\Run: [nwiz] nwiz.exe /install

O4 - HKCU…\Run: [Komunikator] C:\Program Files\Tlen.pl\tlen.exe

O4 - HKCU…\Run: [steam] D:\Valve\Steam\Steam.exe -silent

O4 - HKCU…\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe

O4 - HKCU…\Run: [Esil] C:\Documents and Settings\PoroKaktus\Dane aplikacji\g???.exe

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm

O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm

O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe

O9 - Extra ‘Tools’ menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe

O15 - Trusted Zone: *.05p.com (HKLM)

O15 - Trusted Zone: *.clickspring.net (HKLM)

O15 - Trusted Zone: *.mt-download.com (HKLM)

O15 - Trusted Zone: *.my-internet.info (HKLM)

O15 - Trusted Zone: *.scoobidoo.com (HKLM)

O15 - Trusted Zone: *.searchmiracle.com (HKLM)

O15 - Trusted IP range: 206.161.125.149

O15 - Trusted IP range: 206.161.125.149 (HKLM)

O15 - ProtocolDefaults: ‘http’ protocol is in My Computer Zone, should be Internet Zone

O15 - ProtocolDefaults: ‘http’ protocol is in My Computer Zone, should be Internet Zone (HKLM)

O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/rap … loader.cab

O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll

O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://host.cycore.net/plugins/windows/ … .0.228.cab

O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://mapguide.procad.pl/download/mgaxctrl.cab

O16 - DPF: {7823A620-9DD9-11CF-A662-00AA00C066D2} (PopupMenu Object) - http://activex.microsoft.com/controls/i … iemenu.cab

O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://217.113.232.40/activex/AxisCamControl.cab

O16 - DPF: {AB8638BB-79E8-4E9D-ABF2-8F33054E3941} (Guesser Class) - http://czat.onet.pl/client/kalambury/NetPunGame1.dll

O16 - DPF: {AE609930-A6EB-4A78-B7DA-B3200705FEBD} (Mophun Control) - http://www.mophun.com/codebase/mophun.cab

O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) - http://skaner.mks.com.pl/SkanerOnline.cab

O23 - Service: F-Secure Anti-Virus 2005 (BackWeb Plug-in - 4476822) - Unknown owner - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE

O23 - Service: F-Secure Gatekeeper Handler Starter - Unknown owner - C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsgk32st.exe (file missing)

O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Anti-Virus\backweb\4476822\program\fsbwsys.exe

O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - Unknown owner - C:\Program Files\F-Secure Anti-Virus\FWES\Program\fsdfwd.exe (file missing)

O23 - Service: F-Secure Management Agent (FSMA) - Unknown owner - C:\Program Files\F-Secure Anti-Virus\Common\FSMA32.EXE (file missing)

O23 - Service: Kerio Personal Firewall 3 (KPF3) - Unknown owner - C:\Program Files\Kerio\Personal Firewall 3\kpf3.exe

O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - C:\WINDOWS\System32\wdfmgr.exe (file missing)

STARTUP LOG :

StartupList report, 2005-02-19, 13:37:04

StartupList version: 1.52.2

Started from : C:\Documents and Settings\PoroKaktus\Pulpit\HijackThis.EXE

Detected: Windows XP (WinNT 5.01.2600)

Detected: Internet Explorer v6.00 (6.00.2600.0000)

* Using default options

==================================================

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Tlen.pl\tlen.exe

C:\WINDOWS\System32\ctfmon.exe

C:\Program Files\F-Secure Anti-Virus\backweb\4476822\program\fsbwsys.exe

C:\Program Files\Kerio\Personal Firewall 3\kpf3.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\WINDOWS\System32\svchost.exe

E:\eMule\emule.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Documents and Settings\PoroKaktus\Pulpit\HijackThis.exe


Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]

UserInit = C:\WINDOWS\system32\userinit.exe,


Autorun entries from Registry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

jxthylur = C:\WINDOWS\System32\izwnsy.exe

NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

CloneCDTray = “C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe” /s

WinampAgent = C:\Program Files\Winamp\winampa.exe

NeroFilterCheck = C:\WINDOWS\system32\NeroCheck.exe

nwiz = nwiz.exe /install


Autorun entries from Registry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Komunikator = C:\Program Files\Tlen.pl\tlen.exe

Steam = D:\Valve\Steam\Steam.exe -silent

CTFMON.EXE = C:\WINDOWS\System32\ctfmon.exe

MSMsgSvc =

Esil = C:\Documents and Settings\PoroKaktus\Dane aplikacji\g???.exe


Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*

SCRNSAVE.EXE=*INI section not found*

drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe

SCRNSAVE.EXE=*Registry value not found*

drivers=*Registry value not found*

Policies Shell key:

HKCU…\Policies: Shell=*Registry key not found*

HKLM…\Policies: Shell=*Registry value not found*


Enumerating Browser Helper Objects:

(no name) - (no file) - {4D568F0F-8AC9-40AB-88B7-415134C78777}

(no name) - C:\PROGRA~1\FlashGet\jccatch.dll - {A5366673-E8CA-11D3-9CD9-0090271D075B}


Enumerating Download Program Files:

[RaptisoftGameLoader]

CODEBASE = http://www.miniclip.com/hamsterball/rap … loader.cab

OSD = C:\WINDOWS\Downloaded Program Files\OSD28E7.OSD

[shockwave ActiveX Control]

InProcServer32 = C:\WINDOWS\system32\Macromed\Director\SwDir.dll

CODEBASE = http://download.macromedia.com/pub/shoc … tor/sw.cab

[CR64Loader Object]

InProcServer32 = C:\WINDOWS\Downloaded Program Files\miniclipGameLoader.dll

CODEBASE = http://www.miniclip.com/platypus/miniclipGameLoader.dll

[Cult3D ActiveX Player]

InProcServer32 = C:\WINDOWS\System32\Cult3D\IECult.dll

CODEBASE = http://host.cycore.net/plugins/windows/ … .0.228.cab

[Autodesk MapGuide ActiveX Control]

InProcServer32 = C:\WINDOWS\Downloaded Program Files\MgAxCtrl.dll

CODEBASE = http://mapguide.procad.pl/download/mgaxctrl.cab

[PopupMenu Object]

InProcServer32 = C:\WINDOWS\Downloaded Program Files\iemenu.ocx

CODEBASE = http://activex.microsoft.com/controls/i … iemenu.cab

[CamImage Class]

InProcServer32 = C:\WINDOWS\Downloaded Program Files\AxisCamControl.ocx

CODEBASE = http://217.113.232.40/activex/AxisCamControl.cab

[Guesser Class]

InProcServer32 = C:\WINDOWS\Downloaded Program Files\NetPunGame1.dll

CODEBASE = http://czat.onet.pl/client/kalambury/NetPunGame1.dll

[Mophun Control]

InProcServer32 = C:\WINDOWS\DOWNLO~1\mophun.ocx

CODEBASE = http://www.mophun.com/codebase/mophun.cab

[shockwave Flash Object]

InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocx

CODEBASE = http://active.macromedia.com/flash4/cabs/swflash.cab

[MainControl Class]

InProcServer32 = C:\WINDOWS\System32\SkanerOnline.dll

CODEBASE = http://skaner.mks.com.pl/SkanerOnline.cab


Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll

CDBurn: C:\WINDOWS\system32\SHELL32.dll

WebCheck: C:\WINDOWS\System32\webcheck.dll

SysTray: C:\WINDOWS\System32\stobject.dll


End of report, 5 542 bytes

Report generated in 0,125 seconds

Command line options:

/verbose - to add additional info on each section

/complete - to include empty sections and unsuspicious data

/full - to include several rarely-important sections

/force9x - to include Win9x-only startups even if running on WinNT

/forcent - to include WinNT-only startups even if running on Win9x

/forceall - to include all Win9x and WinNT startups, regardless of platform

/history - to list version history only

ps.co to nwiz.exe i g??? .exe i gkst.exe

ps2. jak uruchamiam msconfig w akladce uruchamianie mam cala czysta linie tzn nie widac jaki tam proces siedzi. Spoko no nie? :stuck_out_tongue:

Instaluj Service Pack 2

Usuwasz;

R3 - Default URLSearchHook is missing


   	O2 - BHO: (no name) - {4D568F0F-8AC9-40AB-88B7-415134C78777} - (no file)

O4 - HKLM\..\Run: [jxthylur] C:\WINDOWS\System32\izwnsy.exe

O15 - Trusted Zone: *.05p.com (HKLM)

O15 - Trusted Zone: *.clickspring.net (HKLM)

O15 - Trusted Zone: *.mt-download.com (HKLM)

O15 - Trusted Zone: *.my-internet.info (HKLM)

O15 - Trusted Zone: *.scoobidoo.com (HKLM)

O15 - Trusted Zone: *.searchmiracle.com (HKLM)

O15 - Trusted IP range: 206.161.125.149

O15 - Trusted IP range: 206.161.125.149 (HKLM)

O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone

O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM) 

   	O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab

O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll

 	O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://mapguide.procad.pl/download/mgaxctrl.cab

 	O16 - DPF: {AE609930-A6EB-4A78-B7DA-B3200705FEBD} (Mophun Control) - http://www.mophun.com/codebase/mophun.cab

   	O23 - Service: F-Secure Gatekeeper Handler Starter - Unknown owner - C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsgk32st.exe (file missing)

   	O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - Unknown owner - C:\Program Files\F-Secure Anti-Virus\FWES\Program\fsdfwd.exe (file missing)

   	O23 - Service: F-Secure Management Agent (FSMA) - Unknown owner - C:\Program Files\F-Secure Anti-Virus\Common\FSMA32.EXE (file missing)

O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - C:\WINDOWS\System32\wdfmgr.exe (file missing)

Wszystko to w trybie awaryjnym F8. Radzę zmienić przeglądarkę na http://www.firefox.pl

Potem na nowo log. Zainstaluj firewall

Start=>Uruchom=>Wpisz polecenie msconfig=>Zakładka Uruchamianie i odchacz:

winamp

NeroCheck

Możesz wyłączyć CTFMON.EXE: Panel sterowania => Opcje regionalne=> Języki => Szczegóły => Zaawansowane => zaznaczasz wyłącz zaawansowane usługi tekstowe

A co to jest i jak to usunac?