Zablokowana partycja


(Matnis5) #1

Witam.

Po zainstalowaniu na partycji D-KIS(trial) została ona praktycznie zablokowana gdyż próby zainstalowania na niej cokolwiek lub usunięcia z niej folderu kończy się komunikatem :Odmowa dostępu.Nie można usunąć folderu.Trudno postawić diagnozę dlaczego tak się dzieje-zaczynam więc od logów.

Logfile of HijackThis v1.99.1

Scan saved at 21:21:39, on 2007-03-25

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16414)


Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

D:\avp.exe

C:\Program Files\UPHClean\uphclean.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\ALCWZRD.EXE

C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe

C:\WINDOWS\Dit.exe

C:\WINDOWS\system32\igfxtray.exe

C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

C:\WINDOWS\SOUNDMAN.EXE

D:\avp.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Internet Explorer\iexplore.exe

E:\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wp.pl

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll

O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE

O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s

O4 - HKLM\..\Run: [Dit] Dit.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [ISUSPM Startup] "c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" -startup

O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [AVP] "D:\avp.exe"

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: Dodaj do blokowanych banerów - D:\ie_banner_deny.htm

O9 - Extra button: Statystyki ochrony WWW - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\scieplugin.dll

O11 - Options group: [INTERNATIONAL] International*

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O20 - AppInit_DLLs: D:\adialhk.dll

O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll

O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Kaspersky Lab - D:\avp.exe

O23 - Service: O&O Defrag (OODefrag) - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - E:\prog.przysp\TU\WinStylerThemeSvc.exe


[code]

http://www.silentrunners.org/Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by "{++}" Startup items buried in registry: --------------------------------- HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++} "AlcWzrd" = "ALCWZRD.EXE" ["RealTek Semicoductor Corp."] "CloneCDTray" = ""C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s" ["SlySoft, Inc."] "Dit" = "Dit.exe" ["ICSI Technology Ltd."] "HotKeysCmds" = "C:\WINDOWS\system32\hkcmd.exe" ["Intel Corporation"] "IgfxTray" = "C:\WINDOWS\system32\igfxtray.exe" ["Intel Corporation"] "ISUSPM Startup" = ""c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" -startup" ["InstallShield Software Corporation"] "ISUSScheduler" = ""C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start" ["InstallShield Software Corporation"] "NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"] "SoundMan" = "SOUNDMAN.EXE" ["Realtek Semiconductor Corp."] "AVP" = ""D:\avp.exe"" ["Kaspersky Lab"] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = (no title provided) -> {HKLM...CLSID} = "AcroIEHlprObj Class" \InProcServer32(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"] {53707962-6F74-2D53-2644-206D7942484F}(Default) = (no title provided) -> {HKLM...CLSID} = (no title provided) \InProcServer32(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}(Default) = (no title provided) -> {HKLM...CLSID} = "SSVHelper Class" \InProcServer32(Default) = "C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll" ["Sun Microsystems, Inc."] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu" -> {HKLM...CLSID} = "HyperTerminal Icon Ext" \InProcServer32(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."] "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler" -> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook" \InProcServer32(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS] "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension" -> {HKLM...CLSID} = "WinRAR" \InProcServer32(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] "{00DF1F20-0849-A4D1-0239-00D0AF3E9CB0}" = "TuneUp Shredder Shell Context Menu Extension" -> {HKCU...CLSID} = "TuneUp Shredder Shell Context Menu Extension" \InProcServer32(Default) = ""E:\prog.przysp\TU\sdshelex.dll"" ["TuneUp Software GmbH"] "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu" -> {HKLM...CLSID} = "Portable Media Devices Menu" \InProcServer32(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS] "{EFA24E62-B078-11d0-89E4-00C04FC9E26E}" = "History Band" -> {HKLM...CLSID} = "History Band" \InProcServer32(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS] "{e57ce731-33e8-4c51-8354-bb4de9d215d1}" = "Uniwersalne urządzenia Plug and Play" -> {HKLM...CLSID} = "Uniwersalne urządzenia Plug and Play" \InProcServer32(Default) = "C:\WINDOWS\system32\upnpui.dll" [MS] "{363E9C24-C4C3-4116-81A4-6D86B459CBE3}" = "Pointstone Shredder Context Menu Shell Extension" -> {HKLM...CLSID} = "Pointstone Shredder Context Menu Shell Extension" \InProcServer32(Default) = "C:\PROGRA~1\COMMON~1\POINTS~1\Shredder\SDShlExt.dll" ["Pointstone Software, LLC"] "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}" = "UnlockerShellExtension" -> {HKLM...CLSID} = "UnlockerShellExtension" \InProcServer32(Default) = "E:\Niezbędnik\Unlocker\UnlockerCOM.dll" [null data] "{85E0B171-04FA-11D1-B7DA-00A0C90348D6}" = "Statystyki ochrony WWW" -> {HKLM...CLSID} = "Statystyki ochrony WWW" \InProcServer32(Default) = "D:\scieplugin.dll" ["Kaspersky Lab"] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\ <> "AppInit_DLLs" = "D:\adialhk.dll" ["Kaspersky Lab"] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ <> igfxcui\DLLName = "igfxsrvc.dll" ["Intel Corporation"] <> klogon\DLLName = "C:\WINDOWS\system32\klogon.dll" ["Kaspersky Lab"] HKLM\Software\Classes\Folder\shellex\ColumnHandlers\ {F9DB5320-233E-11D1-9F84-707F02C10627}(Default) = "PDF Column Info" -> {HKLM...CLSID} = "PDF Shell Extension" \InProcServer32(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."] HKLM\Software\Classes*\shellex\ContextMenuHandlers\ Kaspersky Anti-Virus(Default) = "{dd230880-495a-11d1-b064-008048ec2fc5}" -> {HKLM...CLSID} = (no title provided) \InProcServer32(Default) = "D:\ShellEx.dll" ["Kaspersky Lab"] Pointstone Shredder(Default) = "{363E9C24-C4C3-4116-81A4-6D86B459CBE3}" -> {HKLM...CLSID} = "Pointstone Shredder Context Menu Shell Extension" \InProcServer32(Default) = "C:\PROGRA~1\COMMON~1\POINTS~1\Shredder\SDShlExt.dll" ["Pointstone Software, LLC"] WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM...CLSID} = "WinRAR" \InProcServer32(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ Pointstone Shredder(Default) = "{363E9C24-C4C3-4116-81A4-6D86B459CBE3}" -> {HKLM...CLSID} = "Pointstone Shredder Context Menu Shell Extension" \InProcServer32(Default) = "C:\PROGRA~1\COMMON~1\POINTS~1\Shredder\SDShlExt.dll" ["Pointstone Software, LLC"] WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM...CLSID} = "WinRAR" \InProcServer32(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ Kaspersky Anti-Virus(Default) = "{dd230880-495a-11d1-b064-008048ec2fc5}" -> {HKLM...CLSID} = (no title provided) \InProcServer32(Default) = "D:\ShellEx.dll" ["Kaspersky Lab"] UnlockerShellExtension(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}" -> {HKLM...CLSID} = "UnlockerShellExtension" \InProcServer32(Default) = "E:\Niezbędnik\Unlocker\UnlockerCOM.dll" [null data] WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM...CLSID} = "WinRAR" \InProcServer32(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] HKLM\Software\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\ UnlockerShellExtension(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}" -> {HKLM...CLSID} = "UnlockerShellExtension" \InProcServer32(Default) = "E:\Niezbędnik\Unlocker\UnlockerCOM.dll" [null data] Group Policies {policy setting}: -------------------------------- Note: detected settings may not have any effect. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ "NoBandCustomize" = (REG_DWORD) hex:0x00000000 {Disable customizing browser toolbars} "NoToolbarCustomize" = (REG_DWORD) hex:0x00000000 {Disable customizing browser toolbar buttons} "NoActiveDesktop" = (REG_DWORD) hex:0x00000000 {Disable Active Desktop} "ClassicShell" = (REG_DWORD) hex:0x00000000 {Enable Classic Shell / Turn on Classic Shell} "ForceActiveDesktopOn" = (REG_DWORD) hex:0x00000000 {Enable Active Desktop} "NoCDBurning" = (REG_DWORD) hex:0x00000001 {unrecognized setting} "LinkResolveIgnoreLinkInfo" = (REG_DWORD) hex:0x00000000 {unrecognized setting} HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ "NoBandCustomize" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "NoToolbarCustomize" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "NoCDBurning" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "LinkResolveIgnoreLinkInfo" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "NoResolveSearch" = (REG_DWORD) hex:0x00000001 {unrecognized setting} HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\ "DisableTaskMgr" = (REG_DWORD) hex:0x00000000 {Remove Task Manager} "DisableRegistryTools" = (REG_DWORD) hex:0x00000000 {Prevent access to registry editing tools} HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\ "proxy" = (REG_SZ) 1 {Disable changing proxy settings} "Homepage" = (REG_DWORD) hex:0x00000000 {Disable changing home page settings} HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel\ "HomePage" = (REG_DWORD) hex:0x00000000 {Disable changing home page settings} "Cache" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "History" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "Colors" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "links" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "Fonts" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "Languages" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "Accessibility" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "Ratings" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "Certificates" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "FormSuggest" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "FormSuggest Passwords" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "Profiles" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "Connection Settings" = (REG_DWORD) hex:0x00000000 {Disable changing connection settings} "Connwiz Admin Lock" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "Proxy" = (REG_DWORD) hex:0x00000000 {Disable changing proxy settings} "Messaging" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "ResetWebSettings" = (REG_DWORD) hex:0x00000000 {Disable the Reset Web Settings feature} "Check_If_Default" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "Advanced" = (REG_DWORD) hex:0x00000000 {Disable changing Advanced page settings} HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\ "NoSplash" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "NoJITSetup" = (REG_DWORD) hex:0x00000000 {unrecognized setting} HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\ "NoSplash" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "NoJITSetup" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "NoUpdateCheck" = (REG_DWORD) hex:0x00000001 {unrecognized setting} HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\ "NoBrowserClose" = (REG_DWORD) hex:0x00000000 {unrecognized setting} HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions\ "NoBrowserSaveAs" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "NoFileNew" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "NoBrowserClose" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "NoFileOpen" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "NoTheaterMode" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "NoViewSource" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "NoFavorites" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "NoAddingChannels" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "NoBrowserOptions" = (REG_DWORD) hex:0x00000000 {Tools menu: Disable Internet Options... menu option} "NoBrowserContextMenu" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "NoOpeninNewWnd" = (REG_DWORD) hex:0x00000000 {unrecognized setting} HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\ "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001 {Shutdown: Allow system to be shut down without having to log on} "undockwithoutlogon" = (REG_DWORD) hex:0x00000001 {Devices: Allow undock without having to log on} "SynchronousMachineGroupPolicy" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "SynchronousUserGroupPolicy" = (REG_DWORD) hex:0x00000000 {unrecognized setting} "EnableLUA" = (REG_DWORD) hex:0x00000001 {User Account Control: Run All Administrators In Admin Approval Mode} Active Desktop and Wallpaper: ----------------------------- Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState Displayed if Active Desktop enabled and wallpaper not set by Group Policy: HKCU\Software\Microsoft\Internet Explorer\Desktop\General\ "Wallpaper" = "%APPDATA%\Microsoft\Internet Explorer\Tapeta programu Internet Explorer.bmp" Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ "Wallpaper" = "C:\Documents and Settings\Właściciel\Dane aplikacji\Microsoft\Internet Explorer\Tapeta programu Internet Explorer.bmp" Enabled Screen Saver: --------------------- HKCU\Control Panel\Desktop\ "SCRNSAVE.EXE" = "C:\WINDOWS\system32\ss3dfo.scr" [MS] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] 000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS] 000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 13 %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05 Toolbars, Explorer Bars, Extensions: ------------------------------------ Explorer Bars HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\ HKLM\Software\Classes\CLSID{85E0B171-04FA-11D1-B7DA-00A0C90348D6}(Default) = "Statystyki ochrony WWW" Implemented Categories{00021493-0000-0000-C000-000000000046}\ [vertical bar] InProcServer32(Default) = "D:\scieplugin.dll" ["Kaspersky Lab"] Extensions (Tools menu items, main toolbar menu buttons) HKLM\Software\Microsoft\Internet Explorer\Extensions\ {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}\ "ButtonText" = "Statystyki ochrony WWW" Miscellaneous IE Hijack Points ------------------------------ HKLM\Software\Microsoft\Internet Explorer\AboutURLs\ <> "TuneUp" = "file://C|/Documents and Settings/All Users/Dane aplikacji/TuneUp Software/Common/base.css" [file not found] <> "PhishingSite" = "res://nctb.dll/phishingsite.htm" [file not found] Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ Kaspersky Internet Security 6.0, AVP, "D:\avp.exe -r" ["Kaspersky Lab"] User Profile Hive Cleanup, UPHClean, "C:\Program Files\UPHClean\uphclean.exe" [MS] Print Monitors: --------------- HKLM\System\CurrentControlSet\Control\Print\Monitors\ hpzsnt10\Driver = "hpzsnt10.dll" ["HP"] ---------- <>: Suspicious data at a malware launch point. <>: Suspicious data at a browser hijack point. + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + The search for DESKTOP.INI DLL launch points on all local fixed drives took 47 seconds. ---------- (total run time: 94 seconds)

"Silent Runners.vbs", revision R50,


(adam9870) #2

Oba logi czyste.

Czy sam ustawiałeś te restrykcje? Jeśli nie to usuń HJT.

Poczytaj o przejmowaniu uprawnień:

http://www.strefabezpieczenstwa.pl/topics1/381.htm


(Matnis5) #3

Nie bardzo już pamiętam czy te restrykcje ustawiałem sam ale chyba tak.

Jak je usunę to chyba nic się nie stanie?

Za sprawdzenie logów i poradę co dalej robić wielkie dzięki.

Pozdrawiam.


(Gutek) #4

Nic się nie stanie :wink: