Elektroda.pl
Elektroda.pl
X

Wyszukiwarki naszych partnerów

Wyszukaj w ofercie 200 tys. produktów TME
Europejski lider sprzedaży techniki i elektroniki.
Proszę, dodaj wyjątek elektroda.pl do Adblock.
Dzięki temu, że oglądasz reklamy, wspierasz portal i użytkowników.

problem z wyskakiwaniem co chwile stron internetowych

psychol1986 23 Maj 2007 12:16 1905 9
  • #2 23 Maj 2007 12:21
    beatacc
    Poziom 22  

    Napisz jakim programem to skanowałeś, bo jestem pewna, że wszystkiego nie usunąłeś.



    Miłego dnia - Beata

  • #3 23 Maj 2007 12:24
    Kolobos
    Spec od komputerów

    Wklej log z hijackthis.

  • #4 23 Maj 2007 13:23
    psychol1986
    Poziom 9  

    Pierw przeskanowalem programem zerospywere czy cos takiego a potem spywere doctor oto logo hijackthis:
    Logfile of HijackThis v1.99.1
    Scan saved at 13:22:15, on 2007-05-23
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Spyware Doctor\svcntaux.exe
    C:\Program Files\Spyware Doctor\swdsvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Java\j2re1.4.2_14\bin\jusched.exe
    C:\Program Files\Spyware Doctor\SDTrayApp.exe
    C:\Program Files\Common Files\{80D61EE4-077C-1045-1208-040412210030}\Update.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Gadu-Gadu\gg.exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\Winamp\winamp.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: (no name) - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_14\bin\jusched.exe"
    O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_14\bin\npjpi142_14.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_14\bin\npjpi142_14.dll
    O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
    O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

  • #5 23 Maj 2007 13:30
    Kolobos
    Spec od komputerów

    Zamknij porty przy pomocy wwdc.exe

    W menadzerze zadan zakoncz:
    C:\Program Files\Common Files\{80D61EE4-077C-1045-1208-040412210030}\Update.exe
    Katalog {80.. usun z dysku.

    W hjt usun:
    O3 - Toolbar: (no name) - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    Do tego skan:
    http://www.superantispyware.com/downloads/SUPERAntiSpyware.exe

    Wklej tez w zalaczniku log z:
    http://www.techsupportforum.com/sectools/Deckard/dss.exe

  • #6 23 Maj 2007 15:03
    psychol1986
    Poziom 9  

    wykonalem wsyztskie operacje przesylam skan z tego programu
    Deckard's System Scanner v20070426.43
    Run by Administrator on 2007-05-23 at 14:52:38
    Computer is in Normal Mode.
    --------------------------------------------------------------------------------

    -- System Restore --------------------------------------------------------------

    Successfully created a Deckard's System Scanner Restore Point.


    -- Last 5 Restore Point(s) --
    5: 2007-05-23 12:52:41 UTC - RP45 - Deckard's System Scanner Restore Point
    4: 2007-05-23 12:08:04 UTC - RP44 - Installed SUPERAntiSpyware Free Edition
    3: 2007-05-23 05:10:35 UTC - RP43 - Punkt kontrolny systemu
    2: 2007-05-22 04:52:53 UTC - RP42 - Punkt kontrolny systemu
    1: 2007-05-21 04:42:52 UTC - RP41 - Punkt kontrolny systemu


    Backed up registry hives.

    Performed disk cleanup.


    -- HijackThis (run as Administrator.exe) ---------------------------------------

    Logfile of HijackThis v1.99.1
    Scan saved at 14:54:50, on 2007-05-23
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Java\j2re1.4.2_14\bin\jusched.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Gadu-Gadu\gg.exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Administrator\Pulpit\dss.exe
    C:\Program Files\WinRAR\WinRAR.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
    C:\PROGRA~1\HIJACK~1\Administrator.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_14\bin\jusched.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray




    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_14\bin\npjpi142_14.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_14\bin\npjpi142_14.dll
    O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
    O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe


    -- HijackThis Fixed Entries (C:\PROGRA~1\HIJACK~1\backups\) --------------------

    backup-20070523-134138-347 O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    backup-20070523-134138-430 O3 - Toolbar: (no name) - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
    backup-20070523-134138-818 O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    -- File Associations -----------------------------------------------------------

    .cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL %1,%*
    .cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser %1,%*


    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

    R0 viamraid - c:\windows\system32\drivers\viamraid.sys <Not Verified; VIA Technologies inc,.ltd; VIA RAID driver>
    R1 core - c:\windows\system32\drivers\core.sys
    R1 PQNTDrv - c:\windows\system32\drivers\pqntdrv.sys
    R1 SASDIFSV - c:\program files\superantispyware\sasdifsv.sys
    R1 SASKUTIL - c:\program files\superantispyware\saskutil.sys
    R3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>


    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

    All services whitelisted.


    -- Files created between 2007-04-23 and 2007-05-23 -----------------------------

    2007-05-23 14:08:04 0 d-------- C:\Program Files\SUPERAntiSpyware
    2007-05-23 14:07:54 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
    2007-05-23 12:16:50 0 d-------- C:\Program Files\Spyware Doctor
    2007-05-23 12:01:30 0 d-------- C:\Program Files\Skype
    2007-05-23 12:01:29 0 d-------- C:\Program Files\Common Files\Skype
    2007-05-22 22:55:57 0 d-------- C:\WINDOWS\System32\zslfiles
    2007-05-22 22:52:30 0 d-------- C:\Program Files\FBM Software
    2007-05-22 16:39:54 0 d-------- C:\WINDOWS\pss
    2007-05-22 16:10:44 0 d-------- C:\Program Files\W?nSxS
    2007-05-22 16:10:20 0 d-------- C:\Program Files\Common Files\M?crosoft
    2007-05-22 13:42:29 72320 --a------ C:\WINDOWS\System32\drivers\core.sys
    2007-05-22 13:25:36 0 d---s---- C:\WINDOWS\System32\Microsoft
    2007-05-22 13:23:59 0 d-------- C:\Program Files\Common Files\{30D61EE4-077C-1045-1208-040412210030}
    2007-05-22 13:22:52 0 d-------- C:\Program Files\WinZix
    2007-05-17 19:17:34 0 d--hs---- C:\WINDOWS\ftpcache
    2007-05-17 19:17:28 368912 --a------ C:\WINDOWS\System32\vbar332.dll <Not Verified; Microsoft Corporation; Microsoft Visual Basic for Applications>
    2007-05-16 09:59:52 0 d-------- C:\Program Files\KONAMI
    2007-05-15 18:09:24 0 d-------- C:\Program Files\PC Inspector File Recovery
    2007-05-15 18:02:10 98304 --a------ C:\WINDOWS\System32\CmdLineExt.dll <Not Verified; Sony DADC Austria AG.; >
    2007-05-15 17:59:10 0 d-------- C:\Program Files\DAEMON Tools
    2007-05-14 20:08:08 682232 --a------ C:\WINDOWS\System32\drivers\sptd.sys
    2007-05-11 15:36:12 0 d-------- C:\corel
    2007-05-10 17:09:03 0 d-------- C:\Program Files\ExpressLotto
    2007-05-10 12:23:28 0 d-------- C:\Program Files\Codemasters
    2007-05-09 15:28:45 0 d-------- C:\Program Files\Common Files\Borland Shared
    2007-05-09 15:28:02 0 d-------- C:\Program Files\Borland
    2007-05-08 15:46:13 0 d-------- C:\Program Files\Common Files\Java
    2007-05-08 15:35:37 0 d-------- C:\WINDOWS\System32\appmgmt
    2007-05-08 15:33:13 0 d-------- C:\Program Files\Winamp
    2007-05-08 15:04:25 0 d-------- C:\WINDOWS\Sun
    2007-05-08 15:03:04 0 d-------- C:\Program Files\Java
    2007-05-08 12:30:21 0 d-------- C:\Games
    2007-05-07 19:56:19 0 d-------- C:\Program Files\VideoLAN
    2007-05-07 19:56:09 0 d-------- C:\Program Files\Vplayer
    2007-05-07 19:53:44 0 d-------- C:\Program Files\Media Player Classic
    2007-05-07 19:53:43 0 d-------- C:\Program Files\Real Alternative
    2007-05-07 15:25:41 0 d-------- C:\Program Files\Common Files\Adobe
    2007-05-07 15:19:43 4 --a------ C:\WINDOWS\System32\proc1795523372.bin
    2007-05-06 23:08:38 0 d-------- C:\Program Files\XP Codec Pack
    2007-05-06 22:09:17 0 d-------- C:\Program Files\uTorrent
    2007-05-06 16:12:51 1262956 -----n--- C:\WINDOWS\System32\XMNT2001.EXE
    2007-05-06 16:12:51 3252 -----n--- C:\WINDOWS\System32\drivers\PQNTDRV.SYS
    2007-05-06 16:12:45 0 d-------- C:\Program Files\PowerQuest
    2007-05-06 16:07:34 0 d--hs---- C:\WINDOWS\CSC
    2007-05-06 16:00:32 0 d-------- C:\Program Files\BitComet
    2007-05-06 15:54:52 0 d-------- C:\WINDOWS\SHELLNEW
    2007-05-06 15:54:50 0 d-------- C:\Program Files\Microsoft.NET
    2007-05-06 15:50:44 0 dr-h----- C:\MSOCache
    2007-05-06 15:46:18 1777 --a------ C:\WINDOWS\mozver.dat
    2007-05-06 13:07:40 0 d-------- C:\Program Files\Gadu-Gadu
    2007-05-06 13:06:28 0 --a------ C:\WINDOWS\nsreg.dat
    2007-05-06 11:56:08 997888 --a------ C:\WINDOWS\System32\wmvdmoe2.dll <Not Verified; Microsoft Corporation; Microsoft&reg; Windows Media Services>
    2007-05-06 11:56:08 892416 --a------ C:\WINDOWS\System32\wmspdmoe.dll <Not Verified; Microsoft Corporation; Microsoft&reg; Windows Media Services>
    2007-05-06 11:56:08 1111040 --a------ C:\WINDOWS\System32\wmsdmoe2.dll <Not Verified; Microsoft Corporation; Microsoft&reg; Windows Media Services>
    2007-05-06 11:55:19 106496 --a------ C:\WINDOWS\System32\TwnLib20.dll <Not Verified; Pegasus Software; TWNLIB20>
    2007-05-06 11:55:14 471040 -----n--- C:\WINDOWS\System32\ImagXRA7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
    2007-05-06 11:55:13 262144 -----n--- C:\WINDOWS\System32\ImagXR7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
    2007-05-06 11:55:13 1568768 -----n--- C:\WINDOWS\System32\ImagX7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
    2007-05-06 11:55:12 155648 --a------ C:\WINDOWS\System32\NeroCheck.exe <Not Verified; Ahead Software Gmbh; Ahead Software Gmbh NeroCheck>
    2007-05-06 11:55:06 0 d-------- C:\Program Files\Common Files\Ahead
    2007-05-06 11:55:04 0 d-------- C:\Program Files\Ahead
    2007-05-06 11:51:12 0 d-------- C:\WUTemp
    2007-05-06 11:28:49 38160 --a------ C:\WINDOWS\System32\LMRTREND.dll <Not Verified; Microsoft Corporation; Microsoft&reg; Windows(TM) Operating System>
    2007-05-06 11:28:48 182032 --a------ C:\WINDOWS\System32\dxtmsft3.dll <Not Verified; Microsoft Corporation; Microsoft&reg; Windows(TM) Operating System>
    2007-05-06 11:28:47 63488 --a------ C:\WINDOWS\System32\unam4ie.exe <Not Verified; Microsoft Corporation; DirectShow>
    2007-05-06 11:28:46 10240 --a------ C:\WINDOWS\System32\vidx16.dll
    2007-05-06 11:28:46 194320 --a------ C:\WINDOWS\System32\qcut.dll <Not Verified; Microsoft Corporation; DirectShow>
    2007-05-06 11:28:45 4608 --a------ C:\WINDOWS\System32\w95inf32.dll <Not Verified; Microsoft Corporation; Microsoft&reg; Plus! for Windows&reg; 95>
    2007-05-06 11:28:45 2272 --a------ C:\WINDOWS\System32\w95inf16.dll <Not Verified; Microsoft Corporation; Microsoft&reg; Plus! for Windows&reg; 95>
    2007-05-06 11:28:44 73728 -----n--- C:\WINDOWS\system\CMedia.dll
    2007-05-06 11:28:40 0 d-------- C:\Program Files\PCI Audio Applications
    2007-05-06 11:28:18 306688 --a------ C:\WINDOWS\IsUninst.exe <Not Verified; InstallShield Software Corporation; InstallShield&reg; unInstaller>
    2007-05-06 11:28:08 0 d-------- C:\WINDOWS\OemDir
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\WinSxS
    2007-05-06 11:28:05 0 dr------- C:\WINDOWS\Web
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\twain_32
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\system32
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\wins
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\wbem
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\usmt
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\spool
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\ShellExt
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\Setup
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\ras
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\oobe
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\npp
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\mui
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\inetsrv
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\IME
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\icsxml
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\ias
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\export
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\drivers
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\drivers\etc
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\drivers\disdn
    2007-05-06 11:28:05 0 dr-hs--c- C:\WINDOWS\System32\dllcache
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\dhcp
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\config
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\3com_dmi
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\3076
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\2052
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\1054
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\1045
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\1042
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\1041
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\1037
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\1033
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\1031
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\1028
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\System32\1025
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\system
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\security
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\Resources
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\repair
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\mui
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\msapps
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\msagent
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\Media
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\java
    2007-05-06 11:28:05 0 d--h----- C:\WINDOWS\inf
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\ime
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\Help
    2007-05-06 11:28:05 0 dr--s---- C:\WINDOWS\Fonts
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\Driver Cache
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\Debug
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\Cursors
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\Connection Wizard
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\Config
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\AppPatch
    2007-05-06 11:28:05 0 d-------- C:\WINDOWS\addins
    2007-05-06 11:23:36 0 d-------- C:\Program Files\C-Media
    2007-05-06 11:16:10 0 d-------- C:\WINDOWS\RegisteredPackages
    2007-05-06 11:15:39 1703936 --a------ C:\WINDOWS\System32\d3d9.dll <Not Verified; Microsoft Corporation; Microsoft&reg; Windows&reg; Operating System>
    2007-05-06 11:15:38 1769472 --a------ C:\WINDOWS\System32\dxdiagn.dll <Not Verified; Microsoft Corporation; Microsoft&reg; Windows&reg; Operating System>
    2007-05-06 11:14:24 0 d-------- C:\WINDOWS\System32\URTTemp
    2007-05-06 11:13:28 516096 -----n--- C:\WINDOWS\System32\ati2sgag.exe <Not Verified; ; ATI Smart>
    2007-05-06 11:13:25 307200 -ra------ C:\WINDOWS\System32\atiiiexx.dll <Not Verified; ATI Technologies Inc.; ATI Display Driver Utilities>
    2007-05-06 11:13:22 104373 -ra------ C:\WINDOWS\System32\atiicdxx.dat
    2007-05-06 11:13:19 0 d-------- C:\WINDOWS\System32\ReinstallBackups
    2007-05-06 11:13:06 0 d-------- C:\Program Files\ATI Technologies
    2007-05-06 11:12:59 0 d--h----- C:\Program Files\InstallShield Installation Information
    2007-05-06 11:12:16 0 d-------- C:\Program Files\Common Files\InstallShield
    2007-05-06 11:08:15 0 d--hs---- C:\WINDOWS\Installer
    2007-05-06 11:07:58 0 d--hs---- C:\System Volume Information
    2007-05-06 11:07:49 0 d-------- C:\WINDOWS\Prefetch
    2007-05-06 11:04:38 0 d-------- C:\WINDOWS\System32\xircom
    2007-05-06 11:04:38 0 d-------- C:\Program Files\microsoft frontpage
    2007-05-06 11:04:22 0 -rahs---- C:\MSDOS.SYS
    2007-05-06 11:04:22 0 -rahs---- C:\IO.SYS
    2007-05-06 11:04:22 0 --a------ C:\CONFIG.SYS
    2007-05-06 11:04:22 0 --a------ C:\AUTOEXEC.BAT
    2007-05-06 11:03:40 0 dr------- C:\WINDOWS\Offline Web Pages
    2007-05-06 11:03:40 0 d---s---- C:\WINDOWS\Downloaded Program Files
    2007-05-06 11:03:23 0 d-------- C:\WINDOWS\srchasst
    2007-05-06 11:03:13 0 d-------- C:\WINDOWS\System32\Macromed
    2007-05-06 11:03:13 0 d-------- C:\WINDOWS\System32\DirectX
    2007-05-06 11:02:58 0 d-------- C:\Program Files\Movie Maker
    2007-05-06 11:02:24 0 d-------- C:\WINDOWS\System32\Restore
    2007-05-06 11:02:17 0 d-------- C:\WINDOWS\PCHEALTH
    2007-05-06 11:02:09 0 d---s---- C:\WINDOWS\Tasks
    2007-05-06 11:02:05 0 d-------- C:\Program Files\Common Files\MSSoap
    2007-05-06 11:01:37 21856 --a------ C:\WINDOWS\System32\emptyregdb.dat
    2007-05-06 11:01:34 0 d-------- C:\WINDOWS\Registration
    2007-05-06 11:01:31 0 d--h----- C:\Program Files\WindowsUpdate
    2007-05-06 11:01:31 0 d-------- C:\Program Files\Usługi online
    2007-05-06 11:01:28 0 d-------- C:\Program Files\Messenger
    2007-05-06 11:01:18 0 d-------- C:\Program Files\MSN Gaming Zone
    2007-05-06 11:01:05 0 d-------- C:\Program Files\Windows NT
    2007-05-06 11:00:49 0 d-------- C:\WINDOWS\System32\MsDtc
    2007-05-06 11:00:46 0 d-------- C:\WINDOWS\System32\Com
    2007-05-06 10:36:28 0 d-------- C:\Program Files\Common Files\ODBC
    2007-05-06 10:36:25 0 d-------- C:\Program Files\Common Files\SpeechEngines
    2007-05-06 10:36:24 0 dr------- C:\Program Files
    2007-05-06 10:35:52 0 d-------- C:\WINDOWS\System32\CatRoot2
    2007-05-06 10:35:52 0 d-------- C:\WINDOWS\System32\CatRoot
    2007-05-06 10:35:35 0 d-------- C:\Documents and Settings


    -- Find3M Report ---------------------------------------------------------------

    2007-05-23 14:08:04 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\SUPERAntiSpyware.com
    2007-05-23 13:04:11 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Skype
    2007-05-23 12:19:53 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\uTorrent
    2007-05-23 12:16:50 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\PC Tools
    2007-05-08 15:30:30 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Gadu-Gadu
    2007-05-08 15:04:25 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Sun
    2007-05-07 22:58:11 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\vlc
    2007-05-07 19:53:43 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Real
    2007-05-07 17:19:34 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\AdobeUM
    2007-05-07 15:26:12 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Adobe
    2007-05-07 15:19:43 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\GanymedeNet
    2007-05-06 13:06:43 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Talkback
    2007-05-06 13:06:26 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla
    2007-05-06 11:21:40 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Help
    2007-05-06 11:15:41 435978 --a------ C:\WINDOWS\System32\perfh015.dat
    2007-05-06 11:15:41 67078 --a------ C:\WINDOWS\System32\perfc015.dat
    2007-05-06 11:15:18 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Macromedia
    2007-05-06 11:08:13 0 d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Identities
    2007-05-06 10:36:02 62 --ahs---- C:\Documents and Settings\Administrator\Dane aplikacji\desktop.ini


    -- Registry Dump ---------------------------------------------------------------

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
    "ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
    "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\j2re1.4.2_14\\bin\\jusched.exe\""

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
    "CTFMON.EXE"="C:\\WINDOWS\\System32\\ctfmon.exe"
    "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
    "Gadu-Gadu"="\"C:\\Program Files\\Gadu-Gadu\\gg.exe\" /tray"
    "DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
    "SUPERAntiSpyware"="C:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
    "CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
    "{80D61EE4-077C-1045-1208-040412210030}"="\"C:\\Program Files\\Common Files\\{80D61EE4-077C-1045-1208-040412210030}\\Update.exe\" mc-110-12-0002239"

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\Run]
    "{80D61EE4-077C-1045-1208-040412210030}"="\"C:\\Program Files\\Common Files\\{80D61EE4-077C-1045-1208-040412210030}\\Update.exe\" mc-110-12-0002239"
    "{80D61EE4-077D-1045-1208-040412210030}"="\"C:\\Program Files\\Common Files\\{80D61EE4-077D-1045-1208-040412210030}\\Update.exe\" mc-110-12-0002239"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon

    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
    Authentication Packages REG_MULTI_SZ msv1_0\0\0
    Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
    Notification Packages REG_MULTI_SZ scecli\0\0

    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdauxservice
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdcoreservice

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk]
    "path"="C:\\Documents and Settings\\All Users\\Menu Start\\Programy\\Autostart\\Adobe Reader Speed Launch.lnk"
    "backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
    "location"="Common Startup"
    "command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
    "item"="Adobe Reader Speed Launch"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C-Media Mixer]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="Mixer"
    "hkey"="HKLM"
    "command"="Mixer.exe /startup"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\idol readme bone cash]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="Transpoll"
    "hkey"="HKLM"
    "command"="C:\\Documents and Settings\\All Users\\Dane aplikacji\\activeliteidolreadme\\Transpoll.exe"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Iijqeawp]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="j?vaw"
    "hkey"="HKCU"
    "command"="\"C:\\Program Files\\W?nSxS\\j?vaw.exe\""
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IpWins]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="ipwins"
    "hkey"="HKCU"
    "command"="C:\\Program Files\\Ipwindows\\ipwins.exe"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="NeroCheck"
    "hkey"="HKLM"
    "command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sixth Wave]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="LOVE NEW DENT"
    "hkey"="HKCU"
    "command"="C:\\DOCUME~1\\ADMINI~1\\DANEAP~1\\PLUSWI~1\\LOVE NEW DENT.exe"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Synchronization Manager]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="mobsync"
    "hkey"="HKLM"
    "command"="%SystemRoot%\\system32\\mobsync.exe /logon"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\webHancer Agent]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="whagent"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\webHancer\\Programs\\whagent.exe"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "Client IP-IPX"=dword:00000002
    "ATI Smart"=dword:00000002

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
    LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
    NetworkService REG_MULTI_SZ DnsCache\0\0
    rpcss REG_MULTI_SZ RpcSs\0\0
    imgsvc REG_MULTI_SZ StiSvc\0\0
    termsvcs REG_MULTI_SZ TermService\0\0



    -- Hosts -----------------------------------------------------------------------

    127.0.0.1 bin.errorprotector.com ## added by CiD
    127.0.0.1 br.errorsafe.com ## added by CiD
    127.0.0.1 br.winantivirus.com ## added by CiD
    127.0.0.1 br.winfixer.com ## added by CiD
    127.0.0.1 cdn.drivecleaner.com ## added by CiD
    127.0.0.1 cdn.errorsafe.com ## added by CiD
    127.0.0.1 cdn.winsoftware.com ## added by CiD
    127.0.0.1 de.errorsafe.com ## added by CiD
    127.0.0.1 de.winantivirus.com ## added by CiD
    127.0.0.1 download.cdn.drivecleaner.com ## added by CiD

    60 more entries in hosts file.


    -- End of Deckard's System Scanner: finished at 2007-05-23 at 14:55:37 ---------

    Dodano po 6 [minuty]:

    a i jeszcze to :
    Deckard's System Scanner v20070426.43
    Extra logfile - please post this as an attachment with your post.
    --------------------------------------------------------------------------------

    -- System Information ----------------------------------------------------------

    Microsoft Windows XP Professional (build 2600)
    Architecture: X86; Language: Polish

    CPU 0: AMD Athlon(tm) XP 2600+
    Percentage of Memory in Use: 37%
    Physical Memory (total/avail): 1023.48 MiB / 641.78 MiB
    Pagefile Memory (total/avail): 2462.07 MiB / 2216.19 MiB
    Virtual Memory (total/avail): 2047.88 MiB / 1974.04 MiB

    A: is Removable (No Media)
    C: is Fixed (NTFS) - 37.06 GiB total, 28.62 GiB free.
    D: is CDROM (No Media)
    E: is CDROM (UDF)
    F: is Fixed (FAT32) - 74.51 GiB total, 2.85 GiB free.
    H: is Fixed (NTFS) - 195.82 GiB total, 187.01 GiB free.
    I: is CDROM (No Media)


    -- Security Center -------------------------------------------------------------

    AUState says computer is in an unknown state.
    Windows Internal Firewall is enabled.


    -- Environment Variables -------------------------------------------------------

    ALLUSERSPROFILE=C:\Documents and Settings\All Users
    APPDATA=C:\Documents and Settings\Administrator\Dane aplikacji
    CLIENTNAME=Console
    CommonProgramFiles=C:\Program Files\Common Files
    COMPUTERNAME=KOMP
    ComSpec=C:\WINDOWS\system32\cmd.exe
    HOMEDRIVE=C:
    HOMEPATH=\Documents and Settings\Administrator
    LOGONSERVER=\\KOMP
    NUMBER_OF_PROCESSORS=1
    OS=Windows_NT
    Path=C:\Program Files\Mozilla Firefox;C:\PROGRA~1\Borland\CBUILD~1\Bin;C:\PROGRA~1\Borland\CBUILD~1\Projects\Bpl;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\Mozilla Firefox
    PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    PROCESSOR_ARCHITECTURE=x86
    PROCESSOR_IDENTIFIER=x86 Family 6 Model 10 Stepping 0, AuthenticAMD
    PROCESSOR_LEVEL=6
    PROCESSOR_REVISION=0a00
    ProgramFiles=C:\Program Files
    PROMPT=$P$G
    SESSIONNAME=Console
    SystemDrive=C:
    SystemRoot=C:\WINDOWS
    TEMP=C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp
    TMP=C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp
    USERDOMAIN=KOMP
    USERNAME=Administrator
    USERPROFILE=C:\Documents and Settings\Administrator
    windir=C:\WINDOWS


    -- User Profiles ---------------------------------------------------------------

    Administrator (admin)


    -- Add/Remove Programs ---------------------------------------------------------

    --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    Adobe Flash Player 9 ActiveX --> C:\WINDOWS\System32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlock
    Adobe Reader 7.0 - Polish --> MsiExec.exe /I{AC76BA86-7AD7-1045-7B44-A70000000000}
    ATI Display Driver --> rundll32 C:\WINDOWS\System32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
    ATI HydraVision --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}\setup.exe"
    &micro;Torrent --> "C:\Program Files\uTorrent\uninstall.exe"
    BitComet 0.62 --> C:\Program Files\BitComet\uninst.exe
    Borland C++Builder 6 --> MsiExec.exe /I{2864C41B-EF2D-4640-95A2-526276524519}
    Gadu-Gadu 7.7 --> C:\Program Files\Gadu-Gadu\Setup.exe
    Heroia Mu Online Client --> C:\Games\HeroiaMu\Uninstal.exe
    HijackThis 1.99.1 --> C:\Program Files\HijackThis\HijackThis.exe /uninstall
    hp deskjet 5100 series --> rundll32 hpzcon08.dll,VendorJettison hp deskjet 5100 series
    Java 2 Runtime Environment, SE v1.4.2_14 --> MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142140}
    Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110415-6000-11D3-8CFE-0150048383C9}
    Mozilla Firefox (2.0.0.3) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    Narzędzie Software Uninstall Utility firmy ATI --> C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
    Nero OEM --> C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
    Panel sterowania ATI --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
    PC Inspector File Recovery --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0DD140D3-9563-481E-AA75-BA457CBDAEF2}\Setup.exe" -l0x9
    PCI Audio Applications --> C:\Program Files\PCI Audio Applications\Bin\Uninstall.exe
    PCI Audio Driver --> cmuninst.exe
    PowerQuest PartitionMagic 7.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1E5007FA-DA5E-4EDD-BDE5-14D128D66887}\Setup.exe"
    Pro Evolution Soccer 6 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{EBB794ED-D282-4334-92FB-254481EFF514} /l1045
    Race Driver --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{8E309767-4214-4A04-AB88-FE86155FC151} /l1033
    Real Alternative 1.51 --> "C:\Program Files\Real Alternative\unins000.exe"
    Skype™ 3.2 --> MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
    Spyware Doctor 5.0 --> C:\Program Files\Spyware Doctor\unins000.exe
    SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
    VideoLAN VLC media player 0.8.4 --> C:\Program Files\VideoLAN\VLC\uninstall.exe
    Vplayer --> MsiExec.exe /I{A05BE20E-6510-44BC-95ED-6E6D730407D3}
    Winamp (remove only) --> "C:\Program Files\Winamp\UninstWA.exe"
    WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
    WinZip --> "C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
    WinZix version 1.0 --> "C:\Program Files\WinZix\unins000.exe"
    XP Codec Pack --> C:\Program Files\XP Codec Pack\Uninstall.exe


    -- End of Deckard's System Scanner: finished at 2007-05-23 at 14:55:37 ---------

    niestety okna nadal wyskakuja:/

  • #7 23 Maj 2007 17:25
    Kolobos
    Spec od komputerów

    Przeciez pisalem wklej w ZALACZNIKU! To chyba dla was za trudne..

    > niestety okna nadal wyskakuja:/

    Zainstalowales trojany to wyskakuja.
    Do tego nie usunales katalogu ktory podalem do kasacji.

    Uzyj: http://siri.urz.free.fr/Fix/SmitfraudFix_En.php wybierasz opcje 2.

    (Jezeli czegos z tego nie bedzie to nie usuwasz)
    W msconfig wlacz ta usluge: Client IP-IPX

    Start->Uruchom->cmd
    i tam:
    sc stop "core"
    sc delete "core"
    sc stop "Client IP-IPX"
    sc delete "Client IP-IPX"
    del c:\windows\system32\drivers\core.sys

    Trojanow nie wylacza sie w msconfig tylko usuwa!

    Uruchom regedit i przedz do:
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\
    usuwasz tam:
    idol readme bone cash
    Iijqeawp
    IpWins
    Sixth Wave
    webHancer Agent

    Nastepnie przechodzisz do:
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run
    i usuwasz tam:
    "{80D61EE4-077C-1045-1208-040412210030}"
    To samo w:
    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\Run]
    kasacja:
    "{80D61EE4-077C-1045-1208-040412210030}"
    "{80D61EE4-077D-1045-1208-040412210030}"

    Z dysku usuwasz te pliki katalogi:
    C:\WINDOWS\System32\zslfiles
    C:\Program Files\W?nSxS
    C:\Program Files\Common Files\M?crosoft
    C:\Program Files\Common Files\{30D61EE4-077C-1045-1208-040412210030}

    Tylko nie pomyl nazw! W razie problemow uzyj killbox z zaznaczona opcja delete on reboot.
    Po wszystkim wklej nowy log z dss ale tym razem wysil sie bardziej i wklej w zalaczniku.

  • #8 23 Maj 2007 23:13
    psychol1986
    Poziom 9  

    Sorry ale robilem to w pospiechu niemoglem wykonac 3 operacji mianowicie:
    sc stop "Client IP-IPX"
    sc delete "Client IP-IPX"
    del c:\windows\system32\drivers\core.sys

    pisze cos takiego open service failed reszte wykonalem teraz juz zalanczam w zalaczniku wyniki loga z dss

  • #9 23 Maj 2007 23:33
    Kolobos
    Spec od komputerów

    Pewnie, ze nie mogles skoro nie chce Ci sie czytac tego co napisalem. Masz wlaczyc ta usluge w msconfig tam gdzie ja wylaczyles i dopiero usuwac.

    Nie usunales w:
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
    tego: "idol readme bone cash"

    Dlaczego?

    Do tego ten plik miales usunac:
    C:\WINDOWS\System32\drivers\core.sys
    W razie problemow uzyj killbox z zaznaczona opcja delete on reboot.

  • #10 24 Maj 2007 22:05
    psychol1986
    Poziom 9  

    Wykonalem ta operacje z usunieciem tego folderu ale nadal niemoge
    sc stop "Client IP-IPX"
    sc delete "Client IP-IPX"

    wlaczylem w msconfig wszystko co wylaczylem wczesniej i nic niedalo:/ w zalaczniku przesylam nastepny log z dss

    Proszę niezwłocznie poprawić WSZYSTKIE błedy w swoich postach!
    [jankolo]

 Szukaj w ofercie
Zamknij 
Wyszukaj w ofercie 200 tys. produktów TME