Proszę o sprawdzenie loga

A gdzie został zapisany? N apulpicie z dopiskiem FIX.REG

Na pulpicie. Być może, że coś zrobiłam źle!

No to w trybie awaryjnym kliknij 2 razy na FIX.REG i nowy og z silenta - link wyżej

“Silent Runners.vbs”, revision 41, http://www.silentrunners.org/

Operating System: Windows XP SP2

Output limited to non-default values, except where indicated by “{++}”

Startup items buried in registry:


HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}

“CTFMON.EXE” = “C:\WINDOWS\system32\ctfmon.exe” [MS]

“MSMSGS” = ““C:\Program Files\Messenger\msmsgs.exe” /background” [MS]

“NvMediaCenter” = “RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit” [MS]

“Firewall Pro” = “C:\Program Files\Play\PC Tools 2005\Firewall Pro 2005\fwpro.exe” [“Aktywni.pl”]

“Gadu-Gadu” = ““C:\Program Files\Gadu-Gadu\gg.exe” /tray” [“Gadu-Gadu Sp. z oo”]

“Komunikator” = “C:\Program Files\Tlen.pl\tlen.exe” [null data]

“Shell” = ““C:\DOCUME~1\Jacek\USTAWI~1\Temp\\svi00001.exe”” [null data]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}

“NvCplDaemon” = “RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup” [MS]

“nwiz” = “nwiz.exe /install” [“NVIDIA Corporation”]

“avast!” = “C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [null data]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\

“{42071714-76d4-11d1-8b24-00a0c9068ff3}” = “Rozszerzenie CPL kadrowania wyświetlania”

-> {CLSID}\InProcServer32(Default) = “deskpan.dll” [file not found]

“{88895560-9AA2-1069-930E-00AA0030EBC8}” = “Rozszerzenie ikony HyperTerminalu”

-> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\system32\hticons.dll” [“Hilgraeve, Inc.”]

“{59850401-6664-101B-B21C-00AA004BA90B}” = “Microsoft Office Binder Unbind”

-> {CLSID}\InProcServer32(Default) = “C:\PROGRA~1\MICROS~2\Office\1045\UNBIND.DLL” [MS]

“{0006F045-0000-0000-C000-000000000046}” = “Microsoft Outlook Custom Icon Handler”

-> {CLSID}\InProcServer32(Default) = “C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL” [MS]

“{472083B0-C522-11CF-8763-00608CC02F24}” = “avast”

-> {CLSID}\InProcServer32(Default) = “C:\Program Files\Alwil Software\Avast4\ashShell.dll” [“ALWIL Software”]

“{1CDB2949-8F65-4355-8456-263E7C208A5D}” = “Desktop Explorer”

-> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\System32\nvshell.dll” [“NVIDIA Corporation”]

“{1E9B04FB-F9E5-4718-997B-B8DA88302A47}” = “Desktop Explorer Menu”

-> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\System32\nvshell.dll” [“NVIDIA Corporation”]

“{640167b4-59b0-47a6-b335-a6b3c0695aea}” = “Portable Media Devices”

-> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\System32\Audiodev.dll” [MS]

“{cc86590a-b60a-48e6-996b-41d25ed39a1e}” = “Portable Media Devices Menu”

-> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\System32\Audiodev.dll” [MS]

“{B41DB860-8EE4-11D2-9906-E49FADC173CA}” = “WinRAR shell extension”

-> {CLSID}\InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data]

“{C3DC52A2-C349-489F-B9E5-DA32863454DD}” = (no title provided)

-> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\system32\ajsnds.dll” [file not found]

“{6A087B9F-F0BD-4D72-A638-935B1D636CEF}” = (no title provided)

-> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\system32\kpdhela2.dll” [file not found]

“{70170ACA-F31C-490B-8EA5-946D5B6A23BF}” = (no title provided)

-> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\system32\olmanage.dll” [file not found]

“{1DEDE2E2-018A-416A-BE51-1C17A944F259}” = (no title provided)

-> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\system32\lurmonui.dll” [file not found]

“{76CE142D-0940-4C63-A860-109A6C9F6339}” = (no title provided)

-> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\system32\jssh400.dll” [file not found]

“{60217129-7845-4AEA-B064-8C5A9F94FA28}” = (no title provided)

-> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\system32\msc40loc.dll” [file not found]

“{527F5D21-0B4F-458B-86DE-3FBF9310D77C}” = (no title provided)

-> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\system32\mbimg32.dll” [file not found]

“{B3419F1C-4C52-4E19-830E-C667377BA27C}” = (no title provided)

-> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\system32\nbdeapi.dll” [file not found]

“{38B672EC-4E4A-44AA-9C1C-E6FE28F4AE4C}” = (no title provided)

-> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\system32\DYAO36.DLL” [file not found]

“{314D2587-1F00-4326-8C87-EB60796C69A2}” = (no title provided)

-> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\system32\mtl_mtf.dll” [null data]

“{9339543F-317E-46DD-B31B-FD266898AE71}” = (no title provided)

-> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\system32\jkdw400.dll” [null data]

“{4449FBFE-549B-4758-9349-5C1D0083BC77}” = (no title provided)

-> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\system32\easadu.dll” [null data]

“{D9190FFD-6231-40A3-8795-759E62759FE4}” = (no title provided)

-> {CLSID}\InProcServer32(Default) = “C:\WINDOWS\system32\mcuni11.dll” [null data]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\

INFECTION WARNING! Explorer\DLLName = “C:\WINDOWS\system32\enlsl1371.dll” [null data]

HKLM\Software\Classes*\shellex\ContextMenuHandlers\

avast(Default) = “{472083B0-C522-11CF-8763-00608CC02F24}”

-> {CLSID}\InProcServer32(Default) = “C:\Program Files\Alwil Software\Avast4\ashShell.dll” [“ALWIL Software”]

WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}”

-> {CLSID}\InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\

WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}”

-> {CLSID}\InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\

avast(Default) = “{472083B0-C522-11CF-8763-00608CC02F24}”

-> {CLSID}\InProcServer32(Default) = “C:\Program Files\Alwil Software\Avast4\ashShell.dll” [“ALWIL Software”]

WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}”

-> {CLSID}\InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data]

Active Desktop and Wallpaper:


Active Desktop is disabled at this entry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

HKCU\Control Panel\Desktop\

“Wallpaper” = “C:\WINDOWS\web\wallpaper\Idylla.bmp”

Enabled Screen Saver:


HKCU\Control Panel\Desktop\

“SCRNSAVE.EXE” = “C:\WINDOWS\System32\logon.scr” [MS]

Kliknęłam 2 razy pokazał sie komunikat czy chce dodac do rejestru, nacisnęłam OK nie wiem czy dobrze

Extra super zrobiłeś, ale jeszcze jeden fix trzeba zrobić.

Otwórz Notatnik i wklej w nim to:

Plik >>> Zapisz jako >>> Zmień rozszerzenie z TXT na Wszystkie pliki >>> Zapisz pod nazwą FIX.REG

Przejście do trybu awaryjnego Windows i uruchomienie pliku FIX.REG.

I powinno być Ok

Oczyść jeszcze w trybie awaryjnym TEMP

Wielkie dzięki za pomoc! :smiley:

Kolega oczyścił mi dysk , myślę, że teraz mam wszystko ok!

Tylko pytanko: Co jaki czas powinno się sprawdzać loga?

Żeby mieć pewność , że wszystko jest w porządku?

Jeszcze raz DZIĘKI! !!

Proponuje Ewido

http://www.searchengines.pl/phpbb203/lo … 16762.html oraz od czasu do czasu Scanery online - przeleć kompa i Ok

Pomyśl o porządnym antywirusie i firewall-u - zobacz TUTAJ