Cześć!
O to mój problem… i jak tego mam sie pozbyc?
Logfile of HijackThis v1.98.2
Scan saved at 18:37:07, on 2004-11-15
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
F:\Programy\Programy antywirusowe\Avast! (antivir)\aswUpdSv.exe
F:\Programy\Programy antywirusowe\Avast! (antivir)\ashServ.exe
D:\WINDOWS\System32\CTsvcCDA.EXE
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\MsPMSPSv.exe
D:\WINDOWS\Explorer.EXE
F:\Program Files\Winamp\winampa.exe
D:\WINDOWS\LiveChatut.exe
D:\Program Files\Creative\ShareDLL\CtNotify.exe
F:\Program Files\Creative\SBLive\Program\CTAvTray.EXE
D:\Program Files\Windows AdControl\WinAdCtl.exe
F:\Programy\PROGRA~2\AVAST!~1\ashDisp.exe
D:\WINDOWS\System32\ctfmon.exe
D:\Program Files\Windows AdControl\WinAdAlt.exe
D:\Program Files\Creative\ShareDLL\MediaDet.Exe
F:\Programy\kursory\CursorXP.exe
F:\Programy\BitComet\BitComet.exe
F:\Programy\Gadu-Gadu\gg.exe
F:\Program Files\BearShare\BearShare.exe
F:\Program Files\BearShare\BearShare.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\Pobrane\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchcentral.cc/search.php?v=4&aff=2492
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchcentral.cc/index.php?v=4&aff=2492
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.web–search.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.onet.pl/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: StartBHO Class - {30192F8D-0958-44E6-B54D-331FD39AC959} - D:\WINDOWS\Downloaded Program Files\CONFLICT.1\webdlg32.dll
O1 - Hosts file is located at: D:\WINDOWS\nsdb\hosts
O1 - Hosts: 82.179.166.164 lender-search.com
O1 - Hosts: 82.179.166.165 hot-searches.com
O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - D:\WINDOWS\localNRD.dll (file missing)
O2 - BHO: NavErrRedir Class - {0199DF25-9820-4bd5-9FEE-5A765AB4371E} - D:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: StartBHO Class - {30192F8D-0958-44E6-B54D-331FD39AC959} - D:\WINDOWS\Downloaded Program Files\CONFLICT.1\webdlg32.dll
O3 - Toolbar: (no name) - {5F1ABCDB-A875-46c1-8345-B72A4567E486} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Search Bar - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - D:\WINDOWS\Downloaded Program Files\CONFLICT.1\webdlg32.dll
O4 - HKLM…\Run: [Gainward] D:\WINDOWS\TBPanel.exe /A
O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM…\Run: [nwiz] nwiz.exe /install
O4 - HKLM…\Run: [WinampAgent] f:\Program Files\Winamp\winampa.exe
O4 - HKLM…\Run: [bearShare] “F:\Program Files\BearShare\BearShare.exe” /pause
O4 - HKLM…\Run: [updReg] D:\WINDOWS\Updreg.exe
O4 - HKLM…\Run: [AHQInit] f:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM…\Run: [bwbktmv] D:\WINDOWS\bwbktmv.exe
O4 - HKLM…\Run: [LiveChatut] D:\WINDOWS\LiveChatut.exe
O4 - HKLM…\Run: [iST Service] D:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM…\Run: [Disc Detector] D:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM…\Run: [AudioHQ] f:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM…\Run: [CTAvTray] F:\Program Files\Creative\SBLive\Program\CTAvTray.EXE
O4 - HKLM…\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM…\Run: [Windows AdControl] D:\Program Files\Windows AdControl\WinAdCtl.exe
O4 - HKLM…\Run: [avast!] F:\Programy\PROGRA~2\AVAST!~1\ashDisp.exe
O4 - HKLM…\RunOnce: [tlc] D:\WINDOWS\update13.js
O4 - HKLM…\RunOnce: [CTAVTray] f:\Program Files\Creative\SBLive\Program\CTAvStub.EXE EAX.AVI
O4 - HKLM…\RunOnce: [installShieldSetup] D:\PROGRA~1\INSTAL~1{9FD12~1\setup.exe -rebootD:\PROGRA~1\INSTAL~1{9FD12~1\reboot.ini -l0x9
O4 - HKCU…\Run: [CTFMON.EXE] D:\WINDOWS\System32\ctfmon.exe
O4 - HKCU…\Run: [MSMSGS] “D:\Program Files\Messenger\msmsgs.exe” /background
O4 - HKCU…\Run: [Gadu-Gadu] “F:\Programy\Gadu-Gadu\gg.exe” /tray
O4 - HKCU…\Run: [CursorXP] F:\Programy\kursory\CursorXP.exe
O4 - HKCU…\Run: [skype] “D:\Program Files\Skype\Skype.exe” /nosplash /minimized
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
O9 - Extra ‘Tools’ menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
O9 - Extra button: Search cracks at CrackSpider.NET - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - http://crackspider.net/ie/btn.php (file missing) (HKCU)
O9 - Extra ‘Tools’ menuitem: Search cracks at CrackSpider.NET - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - http://crackspider.net/ie/btn.php (file missing) (HKCU)
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:\foo.mht! http://82.179.166.130/e9xr2.chm::/file.exe
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file. … 78c1291781
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v … 9586454359
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O18 - Filter: text/html - {4F7681E5-6CAF-478D-9CB8-4CA593BEE7FB} - D:\WINDOWS\System32\xplugin.dll
Dzieki za wszelką pomoc