severah
(Severah)
20 Sierpień 2006 11:56
#1
co pare minut rozłącza mi neostrade, zawiesza mi się komp, kiedy chce ściągnąć jakiś antywirus to po paru saekundach zamyka mi strony w necie z tymi programami, nie pozwala mi zainstalować żadnego antywirusa, czy firewalla bo po paru sekundach zamyka się okienko instalacji, pomocy!
Logfile of HijackThis v1.99.1 Scan saved at 13:49:25, on 2006-08-20 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: D:\WINDOWS\System32\smss.exe D:\WINDOWS\SYSTEM32\winlogon.exe D:\WINDOWS\system32\services.exe D:\WINDOWS\system32\lsass.exe D:\WINDOWS\system32\svchost.exe D:\WINDOWS\System32\svchost.exe D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe D:\WINDOWS\System32\xpjavams.exe D:\WINDOWS\system32\spoolsv.exe D:\WINDOWS\System32\nvsvc32.exe D:\WINDOWS\lsass.exe D:\PROGRA~1\Wanadoo\taskbaricon.exe D:\Program Files\Java\jre1.5.0_06\bin\jusched.exe D:\Program Files\Common Files\Symantec Shared\ccApp.exe D:\Program Files\iTunes\iTunesHelper.exe D:\Program Files\Common Files\AOL\1155921827\ee\AOLSoftware.exe D:\Program Files\iPod\bin\iPodService.exe D:\Program Files\SAGEM\SAGEM F@st 800-840\DSLMON.exe D:\WINDOWS\System32\rundll32.exe D:\Program Files\The Cleaner\tca.exe D:\Documents and Settings\Linda\Pulpit\zlsSetup_65_731_000_en.exe D:\DOCUME~1\Linda\USTAWI~1\Temp\GLB78.tmp D:\Documents and Settings\Linda\Pulpit\zlsSetup_65_731_000_en.exe D:\DOCUME~1\Linda\USTAWI~1\Temp\GLB82.tmp D:\Documents and Settings\Linda\Pulpit\ats2.exe D:\Documents and Settings\Linda\Pulpit\zlsSetup_65_731_000_en.exe D:\DOCUME~1\Linda\USTAWI~1\Temp\GLB9E.tmp D:\Documents and Settings\Linda\Pulpit\zlsSetup_65_731_000_en.exe D:\DOCUME~1\Linda\USTAWI~1\Temp\GLBA5.tmp D:\Documents and Settings\Linda\Pulpit\zlsSetup_65_731_000_en.exe D:\DOCUME~1\Linda\USTAWI~1\Temp\GLBB0.tmp D:\Documents and Settings\Linda\Pulpit\zlsSetup_65_731_000_en.exe D:\DOCUME~1\Linda\USTAWI~1\Temp\GLBB7.tmp D:\WINDOWS\system32\cleanmgr.exe D:\PROGRA~1\Wanadoo\EspaceWanadoo.exe D:\PROGRA~1\Wanadoo\ComComp.exe D:\PROGRA~1\Wanadoo\Watch.exe D:\Documents and Settings\Linda\Pulpit\zlsSetup_65_731_000_en.exe D:\DOCUME~1\Linda\USTAWI~1\Temp\GLBD4.tmp D:\Program Files\Mozilla Firefox\firefox.exe D:\WINDOWS\System32\cmd.exe D:\WINDOWS\System32\javanet.exe D:\WINDOWS\explorer.exe D:\WINDOWS\System32\msiexec.exe D:\Documents and Settings\Linda\Pulpit\zlsSetup_65_731_000_en.exe D:\DOCUME~1\Linda\USTAWI~1\Temp\GLB118.tmp D:\PROGRA~1\WINZIP\winzip32.exe D:\Documents and Settings\Linda\Ustawienia lokalne\Temp\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customi … earch.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/def … .yahoo.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada Plus wita Cie w Internecie R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza F2 - REG:system.ini: Shell=Explorer.exe xpjavams.exe F2 - REG:system.ini: UserInit=D:\WINDOWS\System32\userinit.exe,xpjavams.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - D:\PROGRA~1\TEXTware\QUICKF~1\PlugIns\IEHelp.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx O4 - HKLM…\Run: [WOOWATCH] D:\PROGRA~1\Wanadoo\Watch.exe O4 - HKLM…\Run: [WOOTASKBARICON] D:\PROGRA~1\Wanadoo\taskbaricon.exe O4 - HKLM…\Run: [sunJavaUpdateSched] D:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM…\Run: [nwiz] nwiz.exe /install O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM…\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM…\Run: [HPDJ Taskbar Utility] D:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe O4 - HKLM…\Run: [ccApp] “D:\Program Files\Common Files\Symantec Shared\ccApp.exe” O4 - HKLM…\Run: [adiras] adiras.exe O4 - HKLM…\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM…\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe O4 - HKLM…\Run: [QuickTime Task] “D:\Program Files\QuickTime\qttask.exe” -atboottime O4 - HKLM…\Run: [iTunesHelper] “D:\Program Files\iTunes\iTunesHelper.exe” O4 - HKLM…\Run: [HostManager] D:\Program Files\Common Files\AOL\1155921827\ee\AOLSoftware.exe O4 - HKLM…\Run: [iPHSend] D:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe O4 - HKLM…\Run: [TrojanScanner] D:\Program Files\Trojan Remover\Trjscan.exe O4 - HKLM…\Run: [tcactive] D:\Program Files\The Cleaner\tca.exe O4 - HKLM…\Run: [tcmonitor] D:\Program Files\The Cleaner\tcm.exe O4 - HKLM…\RunServices: [MS Java for Windows NT, XP & ME] xpjavams.exe O4 - HKLM…\RunServices: [MS Java for Windows XP & NT] javanet.exe O4 - HKLM…\RunOnce: [delfile] D:\delfiles.cmd O4 - HKCU…\Run: [ccleaner] “C:\Program Files\CCleaner\ccleaner.exe” /AUTO O4 - HKCU…\Run: [Aim6] “D:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe” /d locale=en-US ee://aol/imApp O4 - HKCU…\RunServices: [MS Java for Windows NT, XP & ME] xpjavams.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: DSLMON.lnk = D:\Program Files\SAGEM\SAGEM F@st 800-840\DSLMON.exe O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O15 - Trusted Zone: http://www.180searchassistant.com O15 - Trusted Zone: http://www.ang.pl O15 - Trusted Zone: http://www.bbc.co.uk O15 - Trusted Zone: poczta.gazeta.pl O15 - Trusted Zone: serwisy.gazeta.pl O15 - Trusted Zone: http://www.gazeta.pl O15 - Trusted Zone: http://www.neostrada.pl O15 - Trusted Zone: users.nethit.pl O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.c … st0401.cab O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab O16 - DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} (MainControl Class) - http://arcaonline.arcabit.com/ArcaOnline.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda … 0943663201 O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/house … hcImpl.cab O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/viru … ebscan.cab O16 - DPF: {AFD8ED36-EA54-11D6-AC3F-00105ADCF632} (Ntw4 Control) - https://epromak.millenniumdm.pl/res/ntw4.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMe … loader.cab O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/g … anager.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab O17 - HKLM\System\CCS\Services\Tcpip…{45409FE3-0C65-4B50-8612-5B04963A40C6}: NameServer = 194.204.152.34 217.98.63.164 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O21 - SSODL: UPnP Tray Monitor - {E61B5E20-DE35-11CF-9C87-1579005127ED} - D:\WINDOWS\SYSTEM32\msc.cpl O21 - SSODL: msp.cpl - {E21B5E20-DE35-11CF-9C87-157900512701} - D:\WINDOWS\SYSTEM32\msp.cpl O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe O23 - Service: Windows Genuine Advantage Registration Service (net32a) - Unknown owner - D:\WINDOWS\System32\net32a.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe O23 - Service: Microsoft sdk core (sdk) - Unknown owner - D:\WINDOWS\lsass.exe
Myszak
(Myszonus)
20 Sierpień 2006 17:50
#2
Start --> Uruchom --> cmd i wpisz :
F2 - REG:system.ini: Shell=Explorer.exe xpjavams.exe F2 - REG:system.ini: UserInit=D:\WINDOWS\System32\userinit.exe,xpjavams.exe O4 - HKLM…\RunServices: [MS Java for Windows NT, XP & ME] xpjavams.exe O4 - HKLM…\RunServices: [MS Java for Windows XP & NT] javanet.exe O4 - HKLM…\RunOnce: [delfile] D:\delfiles.cmd O4 - HKCU…\RunServices: [MS Java for Windows NT, XP & ME] xpjavams.exe O15 - Trusted Zone: http://www.180searchassistant.com O15 - Trusted Zone: users.nethit.pl O16 - DPF: {AFD8ED36-EA54-11D6-AC3F-00105ADCF632} (Ntw4 Control) - https://epromak.millenniumdm.pl/res/ntw4.cab O21 - SSODL: UPnP Tray Monitor - {E61B5E20-DE35-11CF-9C87-1579005127ED} - D:\WINDOWS\SYSTEM32\msc.cpl O21 - SSODL: msp.cpl - {E21B5E20-DE35-11CF-9C87-157900512701} - D:\WINDOWS\SYSTEM32\msp.cpl O23 - Service: Windows Genuine Advantage Registration Service (net32a) - Unknown owner - D:\WINDOWS\System32\net32a.exe O23 - Service: Microsoft sdk core (sdk) - Unknown owner - D:\WINDOWS\lsass.exe
Startujesz do trybu awaryjnego i wyłączasz przywracanie systemu.
Wpisy skasuj Hijackiem.
Użyj programu Killbox . Uruchamiasz zaznaczasz Delete on reboot, w polu full path of file wklej ścieżkę :
D:\WINDOWS\System32\xpjavams.exe
D:\WINDOWS\lsass.exe
D:\Documents and Settings\Linda\Pulpit\zlsSetup_65_731_000_en.exe
D:\Documents and Settings\Linda\Pulpit\ats2.exe
D:\WINDOWS\System32\javanet.exe
D:\WINDOWS\SYSTEM32\msc.cpl
D:\WINDOWS\SYSTEM32\msp.cpl
D:\WINDOWS\System32\net32a.exe
D:\WINDOWS\lsass.exe
Klikasz X i reset kompa. - reset dopiero po wklejeniu ostatniej ścieżki do Killboxa.
Daj log z Silent Runners – tu masz opis.
Update :
Start --> Uruchom --> SYSTEM.INI
Będziesz zapewne miał coś takiego :
Usuń xpjavams.exe (ma być tylko shell=explorer.exe)
severah
(Severah)
20 Sierpień 2006 22:49
#3
hej zrobiłam to co napisałeś, ale nie wiem czy wyszło
“Silent Runners.vbs”, revision 46, http://www.silentrunners.org/ Operating System: Windows XP Output limited to non-default values, except where indicated by “{++}” Startup items buried in registry: --------------------------------- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} “ccleaner” = ““C:\Program Files\CCleaner\ccleaner.exe” /AUTO” [“Piriform Ltd”] “Aim6” = ““D:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe” /d locale=en-US ee://aol/imApp” [“America Online, Inc.”] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} “WOOWATCH” = “D:\PROGRA~1\Wanadoo\Watch.exe” [“France Télécom R&D”] “WOOTASKBARICON” = “D:\PROGRA~1\Wanadoo\TaskbarIcon.exe” [“France Télécom R&D”] “SunJavaUpdateSched” = “D:\Program Files\Java\jre1.5.0_06\bin\jusched.exe” [“Sun Microsystems, Inc.”] “nwiz” = “nwiz.exe /install” [“NVIDIA Corporation”] “NvCplDaemon” = “RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup” [MS] “KernelFaultCheck” = “%systemroot%\system32\dumprep 0 -k” [MS] “HPDJ Taskbar Utility” = “D:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe” [“HP”] “ccApp” = ““D:\Program Files\Common Files\Symantec Shared\ccApp.exe”” [“Symantec Corporation”] “adiras” = “adiras.exe” [file not found] “NvMediaCenter” = “RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit” [MS] “NeroFilterCheck” = “D:\WINDOWS\system32\NeroCheck.exe” [“Ahead Software Gmbh”] “QuickTime Task” = ““D:\Program Files\QuickTime\qttask.exe” -atboottime” [“Apple Computer, Inc.”] “iTunesHelper” = ““D:\Program Files\iTunes\iTunesHelper.exe”” [“Apple Computer, Inc.”] “HostManager” = “D:\Program Files\Common Files\AOL\1155921827\ee\AOLSoftware.exe” [“America Online, Inc.”] “IPHSend” = “D:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe” [“America Online, Inc.”] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = (no title provided) -> {HKLM…CLSID} = “Adobe PDF Reader Link Helper” \InProcServer32(Default) = “D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll” [“Adobe Systems Incorporated”] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}(Default) = (no title provided) -> {HKLM…CLSID} = “SSVHelper Class” \InProcServer32(Default) = “D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll” [“Sun Microsystems, Inc.”] {C08DF07A-3E49-4E25-9AB0-D3882835F153}(Default) = (no title provided) -> {HKLM…CLSID} = “QUICKfind BHO Object” \InProcServer32(Default) = “D:\PROGRA~1\TEXTware\QUICKF~1\PlugIns\IEHelp.dll” [null data] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ “{88895560-9AA2-1069-930E-00AA0030EBC8}” = “Rozszerzenie ikony HyperTerminalu” -> {HKLM…CLSID} = “HyperTerminal Icon Ext” \InProcServer32(Default) = “D:\WINDOWS\System32\hticons.dll” [“Hilgraeve, Inc.”] “{e57ce731-33e8-4c51-8354-bb4de9d215d1}” = “Uniwersalne urządzenia Plug and Play” -> {HKLM…CLSID} = “Uniwersalne urządzenia Plug and Play” \InProcServer32(Default) = “D:\WINDOWS\System32\upnpui.dll” [MS] “{0006F045-0000-0000-C000-000000000046}” = “Microsoft Outlook Custom Icon Handler” -> {HKLM…CLSID} = “Rozszerzenie ikon plików programu Outlook” \InProcServer32(Default) = “D:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL” [MS] “{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}” = “Shell Extensions for RealOne Player” -> {HKLM…CLSID} = “RealOne Player Context Menu Class” \InProcServer32(Default) = “D:\Program Files\Real\RealPlayer\rpshell.dll” [“RealNetworks, Inc.”] “{E0D79304-84BE-11CE-9641-444553540000}” = “WinZip” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\PROGRA~1\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] “{E0D79305-84BE-11CE-9641-444553540000}” = “WinZip” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\PROGRA~1\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] “{E0D79306-84BE-11CE-9641-444553540000}” = “WinZip” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\PROGRA~1\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] “{E0D79307-84BE-11CE-9641-444553540000}” = “WinZip” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\PROGRA~1\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] “{1CDB2949-8F65-4355-8456-263E7C208A5D}” = “Desktop Explorer” -> {HKLM…CLSID} = “Desktop Explorer” \InProcServer32(Default) = “D:\WINDOWS\System32\nvshell.dll” [“NVIDIA Corporation”] “{1E9B04FB-F9E5-4718-997B-B8DA88302A47}” = “Desktop Explorer Menu” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “D:\WINDOWS\System32\nvshell.dll” [“NVIDIA Corporation”] “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” = “WinRAR shell extension” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “D:\Program Files\WinRAR\rarext.dll” [null data]
Myszak
(Myszonus)
20 Sierpień 2006 22:52
#4
Log jest ucięty. Poczekaj aż Silent wyświetli komunikat.
severah
(Severah)
21 Sierpień 2006 10:07
#5
dalej nie działa poprawnie
“Silent Runners.vbs”, revision 46, http://www.silentrunners.org/ Operating System: Windows XP Output limited to non-default values, except where indicated by “{++}” Startup items buried in registry: --------------------------------- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} “ccleaner” = ““C:\Program Files\CCleaner\ccleaner.exe” /AUTO” [“Piriform Ltd”] “Aim6” = ““D:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe” /d locale=en-US ee://aol/imApp” [“America Online, Inc.”] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} “WOOWATCH” = “D:\PROGRA~1\Wanadoo\Watch.exe” [“France Télécom R&D”] “WOOTASKBARICON” = “D:\PROGRA~1\Wanadoo\TaskbarIcon.exe” [“France Télécom R&D”] “SunJavaUpdateSched” = “D:\Program Files\Java\jre1.5.0_06\bin\jusched.exe” [“Sun Microsystems, Inc.”] “nwiz” = “nwiz.exe /install” [“NVIDIA Corporation”] “NvCplDaemon” = “RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup” [MS] “KernelFaultCheck” = “%systemroot%\system32\dumprep 0 -k” [MS] “HPDJ Taskbar Utility” = “D:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe” [“HP”] “ccApp” = ““D:\Program Files\Common Files\Symantec Shared\ccApp.exe”” [“Symantec Corporation”] “adiras” = “adiras.exe” [file not found] “NvMediaCenter” = “RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit” [MS] “NeroFilterCheck” = “D:\WINDOWS\system32\NeroCheck.exe” [“Ahead Software Gmbh”] “QuickTime Task” = ““D:\Program Files\QuickTime\qttask.exe” -atboottime” [“Apple Computer, Inc.”] “iTunesHelper” = ““D:\Program Files\iTunes\iTunesHelper.exe”” [“Apple Computer, Inc.”] “HostManager” = “D:\Program Files\Common Files\AOL\1155921827\ee\AOLSoftware.exe” [“America Online, Inc.”] “IPHSend” = “D:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe” [“America Online, Inc.”] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = (no title provided) -> {HKLM…CLSID} = “Adobe PDF Reader Link Helper” \InProcServer32(Default) = “D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll” [“Adobe Systems Incorporated”] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}(Default) = (no title provided) -> {HKLM…CLSID} = “SSVHelper Class” \InProcServer32(Default) = “D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll” [“Sun Microsystems, Inc.”] {C08DF07A-3E49-4E25-9AB0-D3882835F153}(Default) = (no title provided) -> {HKLM…CLSID} = “QUICKfind BHO Object” \InProcServer32(Default) = “D:\PROGRA~1\TEXTware\QUICKF~1\PlugIns\IEHelp.dll” [null data] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ “{88895560-9AA2-1069-930E-00AA0030EBC8}” = “Rozszerzenie ikony HyperTerminalu” -> {HKLM…CLSID} = “HyperTerminal Icon Ext” \InProcServer32(Default) = “D:\WINDOWS\System32\hticons.dll” [“Hilgraeve, Inc.”] “{e57ce731-33e8-4c51-8354-bb4de9d215d1}” = “Uniwersalne urządzenia Plug and Play” -> {HKLM…CLSID} = “Uniwersalne urządzenia Plug and Play” \InProcServer32(Default) = “D:\WINDOWS\System32\upnpui.dll” [MS] “{0006F045-0000-0000-C000-000000000046}” = “Microsoft Outlook Custom Icon Handler” -> {HKLM…CLSID} = “Rozszerzenie ikon plików programu Outlook” \InProcServer32(Default) = “D:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL” [MS] “{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}” = “Shell Extensions for RealOne Player” -> {HKLM…CLSID} = “RealOne Player Context Menu Class” \InProcServer32(Default) = “D:\Program Files\Real\RealPlayer\rpshell.dll” [“RealNetworks, Inc.”] “{E0D79304-84BE-11CE-9641-444553540000}” = “WinZip” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\PROGRA~1\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] “{E0D79305-84BE-11CE-9641-444553540000}” = “WinZip” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\PROGRA~1\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] “{E0D79306-84BE-11CE-9641-444553540000}” = “WinZip” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\PROGRA~1\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] “{E0D79307-84BE-11CE-9641-444553540000}” = “WinZip” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\PROGRA~1\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] “{1CDB2949-8F65-4355-8456-263E7C208A5D}” = “Desktop Explorer” -> {HKLM…CLSID} = “Desktop Explorer” \InProcServer32(Default) = “D:\WINDOWS\System32\nvshell.dll” [“NVIDIA Corporation”] “{1E9B04FB-F9E5-4718-997B-B8DA88302A47}” = “Desktop Explorer Menu” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “D:\WINDOWS\System32\nvshell.dll” [“NVIDIA Corporation”] “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” = “WinRAR shell extension” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “D:\Program Files\WinRAR\rarext.dll” [null data] “{640167b4-59b0-47a6-b335-a6b3c0695aea}” = “Portable Media Devices” -> {HKLM…CLSID} = “Portable Media Devices” \InProcServer32(Default) = “D:\WINDOWS\System32\Audiodev.dll” [MS] “{cc86590a-b60a-48e6-996b-41d25ed39a1e}” = “Portable Media Devices Menu” -> {HKLM…CLSID} = “Portable Media Devices Menu” \InProcServer32(Default) = “D:\WINDOWS\System32\Audiodev.dll” [MS] “{A70C977A-BF00-412C-90B7-034C51DA2439}” = “NvCpl DesktopContext Class” -> {HKLM…CLSID} = “DesktopContext Class” \InProcServer32(Default) = “D:\WINDOWS\System32\nvcpl.dll” [“NVIDIA Corporation”] “{FFB699E0-306A-11d3-8BD1-00104B6F7516}” = “Play on my TV helper” -> {HKLM…CLSID} = “NVIDIA CPL Extension” \InProcServer32(Default) = “D:\WINDOWS\System32\nvcpl.dll” [“NVIDIA Corporation”] “{1E9B04FB-F9E5-4718-997B-B8DA88302A48}” = “nView Desktop Context Menu” -> {HKLM…CLSID} = “nView Desktop Context Menu” \InProcServer32(Default) = “D:\WINDOWS\System32\nvshell.dll” [“NVIDIA Corporation”] “{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}” = “iTunes” -> {HKLM…CLSID} = “iTunes” \InProcServer32(Default) = “D:\Program Files\iTunes\iTunesMiniPlayer.dll” [“Apple Computer, Inc.”] “{B327765E-D724-4347-8B16-78AE18552FC3}” = “NeroDigitalIconHandler” -> {HKLM…CLSID} = “NeroDigitalIconHandler Class” \InProcServer32(Default) = “D:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll” [“Nero AG”] “{7F1CF152-04F8-453A-B34C-E609530A9DC8}” = “NeroDigitalPropSheetHandler” -> {HKLM…CLSID} = “NeroDigitalPropSheetHandler Class” \InProcServer32(Default) = “D:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll” [“Nero AG”] “{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}” = “Messenger Sharing Folders” -> {HKLM…CLSID} = “My Sharing Folders” \InProcServer32(Default) = “D:\Program Files\MSN Messenger\fsshext.8.0.0812.00.dll” [MS] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\ INFECTION WARNING! “Shell” = “Explorer.exe javanet.exe” [MS], [null data] INFECTION WARNING! “Userinit” = “D:\WINDOWS\System32\userinit.exe,javanet.exe” [MS], [null data] HKLM\Software\Classes\Folder\shellex\ColumnHandlers\ {7D4D6379-F301-4311-BEBA-E26EB0561882}(Default) = “NeroDigitalExt.NeroDigitalColumnHandler” -> {HKLM…CLSID} = “NeroDigitalColumnHandler Class” \InProcServer32(Default) = “D:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll” [“Nero AG”] {F9DB5320-233E-11D1-9F84-707F02C10627}(Default) = “PDF Column Info” -> {HKLM…CLSID} = “PDF Shell Extension” \InProcServer32(Default) = “D:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll” [“Adobe Systems, Inc.”] HKLM\Software\Classes*\shellex\ContextMenuHandlers\ WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “D:\Program Files\WinRAR\rarext.dll” [null data] WinZip(Default) = “{E0D79304-84BE-11CE-9641-444553540000}” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\PROGRA~1\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “D:\Program Files\WinRAR\rarext.dll” [null data] WinZip(Default) = “{E0D79304-84BE-11CE-9641-444553540000}” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\PROGRA~1\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “D:\Program Files\WinRAR\rarext.dll” [null data] WinZip(Default) = “{E0D79304-84BE-11CE-9641-444553540000}” -> {HKLM…CLSID} = “WinZip” \InProcServer32(Default) = “D:\PROGRA~1\WINZIP\WZSHLSTB.DLL” [“WinZip Computing, Inc.”] Active Desktop and Wallpaper: ----------------------------- Active Desktop is disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState HKCU\Control Panel\Desktop\ “Wallpaper” = “D:\Documents and Settings\Linda\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp” Startup items in “Linda” & “All Users” startup folders: ------------------------------------------------------- D:\Documents and Settings\All Users\Menu Start\Programy\Autostart “Adobe Reader Speed Launch” -> shortcut to: “D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe” [“Adobe Systems Incorporated”] “DSLMON” -> shortcut to: “D:\Program Files\SAGEM\SAGEM F@st 800-840\DSLMON.exe /W” [empty string] “Microsoft Office” -> shortcut to: “D:\Program Files\Microsoft Office\Office\OSA9.EXE -b -l” [MS] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] 000000000002\LibraryPath = “%SystemRoot%\System32\winrnr.dll” [MS] 000000000003\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15 %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05 Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ iPodService, iPodService, “D:\Program Files\iPod\bin\iPodService.exe” [“Apple Computer, Inc.”] NVIDIA Display Driver Service, NVSvc, “D:\WINDOWS\System32\nvsvc32.exe” [“NVIDIA Corporation”] Symantec Event Manager, ccEvtMgr, ““D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe”” [“Symantec Corporation”] Symantec Settings Manager, ccSetMgr, ““D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe”” [“Symantec Corporation”] Windows User Mode Driver Framework, UMWdf, “D:\WINDOWS\System32\wdfmgr.exe” [MS] Print Monitors: --------------- HKLM\System\CurrentControlSet\Control\Print\Monitors\ hpzsnt05\Driver = “hpzsnt05.dll” [“HP”] ---------- + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + The search for DESKTOP.INI DLL launch points on all local fixed drives took 477 seconds. + The search for all Registry CLSIDs containing dormant Explorer Bars took 545 seconds. ---------- (total run time: 2225 seconds)
Złączono Posta : 21.08.2006 (Pon) 21:05
hej, pomocy, ciągle mam ten sam problem