problem z Netfind..zerknijcie w loga- proszę

IP: *.chello.pl 27.12.04, 02:02
witam...proszę pomóżcie mi jak możecie cały czas coś mi się włącza jako start-
page
dzieki za wszsyskie rady
oto mój log:Logfile of HijackThis v1.99.0
Scan saved at 02:02:43, on 04-12-27
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2614.3500)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\PANDA SOFTWARE\PANDA TITANIUM ANTIVIRUS 2004\PSIMSVC.EXE
C:\PROGRAM FILES\PANDA SOFTWARE\PANDA TITANIUM ANTIVIRUS 2004\APVXDWIN.EXE
C:\PROGRAM FILES\PANDA SOFTWARE\PANDA TITANIUM ANTIVIRUS 2004\WEBPROXY.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WINOA386.MOD
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
D:\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,Search =
http://www.nowfind.net/002/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://www.nowfind.net/002/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer,Search =
http://www.nowfind.net/002/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.nowfind.net/002/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.nowfind.net/002/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.nowfind.net/002/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.nowfind.net/002/index.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.gazeta.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://213.159.117.134/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.nowfind.net/002/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.nowfind.net/002/index.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.nowfind.net/002/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.nowfind.net/002/index.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.nowfind.net/002/index.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.nowfind.net/002/index.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.nowfind.net/002/index.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
http://213.159.117.134/index.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
http://213.159.117.134/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - Default URLSearchHook is missing
F1 - win.ini:
run=C:\WINDOWS\hpfsched.bat;C:\WINDOWS\hpfsched.exe;C:\WINDOWS\hpfsched.com;C:
\WINDOWS\hpfsched.scr;C:\WINDOWS\hpfsched.vbs;C:\WINDOWS\COMMAND\hpfsched.bat;
C:\WINDOWS\COMMAND\hpfsched.exe;C:\WINDOWS\COMMAND\hpfsched.com;C:\WINDOWS\COM
MAND\hpfsched.scr;C:\WINDOWS\COMMAND\hpfsched.vbs;C:\WINDOWS\SYSTEM\hpfsched.b
at;C:\WINDOWS\SYSTEM\hpfsched.exe;C:\WINDOWS\SYSTEM\hpfsched.com;C:\WINDOWS\SY
STEM\hpfsched.scr;C:\WINDOWS\SYSTEM\hpfsched.vbs
O1 - Hosts: 3466709097 sea.search.msn.com
O1 - Hosts: 3466709097 www.your.com your.com
O1 - Hosts: 3466709097 com.org
O1 - Hosts: 3466690378 ad.doubleclick.net
O1 - Hosts: 3466690378 view.atdmt.com
O1 - Hosts: 3466690378 click.atdmt.com
O1 - Hosts: 3466690378 leader.linkexchange.com
O2 - BHO: (no name) - {275636E4-A535-4668-9FF1-86DC0C62D446} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1
\SPYBOT~1\SDHELPER.DLL
O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B136188F5DEB} -
C:\WINDOWS\QUESTMOD.DLL (file missing)
O2 - BHO: Tubby - {9EAC0102-5E61-2312-BC2D-544243544243} -
C:\WINDOWS\SYSTEM\TBC.DLL
O2 - BHO: (no name) - {968D3B45-573D-11D9-9C29-00007C38F24F} -
C:\WINDOWS\SYSTEM\FCA.DLL (file missing)
O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} -
C:\PROGRAM FILES\SIDEFIND\SFBHO.DLL (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Search Toolbar - {9EAC0102-5E61-2312-BC2D-544243544243} -
C:\WINDOWS\SYSTEM\TBC.DLL
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Titanium
Antivirus 2004\APVXDWIN.EXE" /s
O4 - HKLM\..\RunServices: [PSIMSVC] "C:\Program Files\Panda Software\Panda
Titanium Antivirus 2004\PSIMSVC.exe"
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} -
C:\PROGRAM FILES\SIDEFIND\SIDEFIND.DLL (file missing)
O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npvmidi.dll
O13 - DefaultPrefix: http://nowfind.net/rand/gallery.php?url=
O13 - WWW Prefix: http://nowfind.net/rand/gallery.php?url=
O13 - Home Prefix: http://nowfind.net/rand/gallery.php?url=
O13 - Mosaic Prefix: http://nowfind.net/rand/gallery.php?url=
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O15 - Trusted Zone: *.slotch.com
O15 - Trusted Zone: *.blazefind.com
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.ysbweb.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted Zone: *.searchbarcash.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.slotch.com (HKLM)
O15 - Trusted Zone: *.flingstone.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.blazefind.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.ysbweb.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted IP range: 67.19.178.84
O15 - Trusted IP range: 67.19.178.84 (HKLM)
O16 - DPF: komentator - http://sport.onet.pl/komentator.cab
O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
http://skaner.mks.com.pl/SkanerOnline.cab
O16 - DPF: {5F874A6F-8B34-433D-BA4B-47AC91C0567F} (MailCfg Control) -
https://poczta.wp.pl/autoryzacja/mailcfg2.ocx
O16 - DPF: {631FF594-EC25-4CFF-B869-402DF294E1D6} (Instalator oprogramowania
Onet.pl) - http://slimak.onet.pl/_m/kamerzysta/OnetInstalator012s.ocx
O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} -
http://www.netvenda.com/sites/games-intl/pl/games4.cab
O18 - Filter: text/html - {6BED2220-57AA-11D9-9C29-0000CA3DE211} -
C:\WINDOWS\DANE APLIKACJI\MICROSOFT\INTERNET EXPLORER\V0.26.DAT
O18 - Filter: text/plain - {968D3B44-573D-11D9-9C29-0000137457D4} -
C:\WINDOWS\SYSTEM\FCA.DLL
O21 - SSODL: OLE Automation Module - {3F143C3A-1457-6CCA-03A7-7AA23B61E40F} -
(no file)
O21 - SSODL: DDE Module - {DABB03E9-AC0D-3740-E3E5-4B37C80837E5} -
C:\WINDOWS\SYSTEM\mtwirl.dll
O21 - SSODL: eplrr - {47EFF680-57A1-11D9-9C29-0000CA3DE211} -
C:\WINDOWS\SYSTEM\eplrr3.dll


    • netsec Re: HiJack Log 27.12.04, 10:35
      Zacznij od odinstalowania wszystkiego czego nie znasz w Dodaj/Usuń programy.
      Ściągnij nowy CWShredder 2.12 cwshredder.net/bin/CWShredder.exe
      Zamknij wszystkie okna Internet Explorer uruchom CWShredder i wykonaj FIX.
      Po tym uruchom komputer ponownie i wklej nowy log z HiJack.
      Czy Twoja Panda to jest pełna wersja, która się aktualizauje?
      Mam na myśli bazę wirusów.
      • Gość: Radekk Re: HiJack Log IP: *.chello.pl 27.12.04, 22:14
        zrobiłem tak jak chciałeś
        sciągnałem Shredera zrobiłem fix
        i to jest nowy log

        Moja POanda to jest darmowa wersja z ostatniego Komputer świat _niezbędnik
        12/2004
        a to jest mój logogfile of HijackThis v1.99.0
        Scan saved at 22:11:30, on 04-12-27
        Platform: Windows 98 SE (Win9x 4.10.2222A)
        MSIE: Internet Explorer v5.00 (5.00.2614.3500)

        Running processes:
        C:\WINDOWS\SYSTEM\KERNEL32.DLL
        C:\WINDOWS\SYSTEM\MSGSRV32.EXE
        C:\WINDOWS\SYSTEM\SPOOL32.EXE
        C:\WINDOWS\SYSTEM\MPREXE.EXE
        C:\WINDOWS\SYSTEM\mmtask.tsk
        C:\PROGRAM FILES\PANDA SOFTWARE\PANDA TITANIUM ANTIVIRUS 2004\PSIMSVC.EXE
        C:\WINDOWS\SYSTEM\DDHELP.EXE
        C:\WINDOWS\EXPLORER.EXE
        D:\HIJACKTHIS.EXE

        R1 - HKCU\Software\Microsoft\Internet Explorer,Search =
        http://www.nowfind.net/002/index.html
        R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
        http://www.nowfind.net/002/index.html
        R1 - HKLM\Software\Microsoft\Internet Explorer,Search =
        http://www.nowfind.net/002/index.html
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
        http://www.nowfind.net/002/index.html
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
        http://www.nowfind.net/002/index.html
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
        http://www.nowfind.net/002/index.html
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
        http://www.nowfind.net/002/index.html
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        http://www.nowfind.net/002/index.html
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
        http://www.nowfind.net/002/index.html
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
        http://www.nowfind.net/002/index.html
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
        http://www.nowfind.net/002/index.html
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        http://www.nowfind.net/002/index.html
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        http://www.nowfind.net/002/index.html
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        http://www.nowfind.net/002/index.html
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        http://www.nowfind.net/002/index.html
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
        R3 - Default URLSearchHook is missing
        F1 - win.ini:
        run=C:\WINDOWS\hpfsched.bat;C:\WINDOWS\hpfsched.exe;C:\WINDOWS\hpfsched.com;C:\W
        INDOWS\hpfsched.scr;C:\WINDOWS\hpfsched.vbs;C:\WINDOWS\COMMAND\hpfsched.bat;C:\W
        INDOWS\COMMAND\hpfsched.exe;C:\WINDOWS\COMMAND\hpfsched.com;C:\WINDOWS\COMMAND\h
        pfsched.scr;C:\WINDOWS\COMMAND\hpfsched.vbs;C:\WINDOWS\SYSTEM\hpfsched.bat;C:\WI
        NDOWS\SYSTEM\hpfsched.exe;C:\WINDOWS\SYSTEM\hpfsched.com;C:\WINDOWS\SYSTEM\hpfsc
        hed.scr;C:\WINDOWS\SYSTEM\hpfsched.vbs
        O2 - BHO: (no name) - {275636E4-A535-4668-9FF1-86DC0C62D446} - (no file)
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1
        \SPYBOT~1\SDHELPER.DLL
        O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B136188F5DEB} -
        C:\WINDOWS\QUESTMOD.DLL (file missing)
        O2 - BHO: Tubby - {9EAC0102-5E61-2312-BC2D-544243544243} -
        C:\WINDOWS\SYSTEM\TBC.DLL
        O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\PROGRAM
        FILES\SIDEFIND\SFBHO.DLL (file missing)
        O2 - BHO: (no name) - {695F49FB-582F-11D9-9C29-0000344C1EAE} -
        C:\WINDOWS\SYSTEM\NJA.DLL
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
        C:\WINDOWS\SYSTEM\MSDXM.OCX
        O3 - Toolbar: Search Toolbar - {9EAC0102-5E61-2312-BC2D-544243544243} -
        C:\WINDOWS\SYSTEM\TBC.DLL
        O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Titanium
        Antivirus 2004\APVXDWIN.EXE" /s
        O4 - HKLM\..\Run: [MSUpdSrv] msupdsrv.exe
        O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\SYSTEM\twink64.exe
        internat.dll,LoadKeyboardProfile
        O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\SYSTEM\tibs3.exe
        O4 - HKLM\..\RunServices: [PSIMSVC] "C:\Program Files\Panda Software\Panda
        Titanium Antivirus 2004\PSIMSVC.exe"
        O4 - HKCU\..\Run: [Eaua] C:\WINDOWS\Dane aplikacji\ooua.exe
        O4 - HKCU\..\RunServices: [Eaua] C:\WINDOWS\Dane aplikacji\ooua.exe
        O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} -
        C:\PROGRAM FILES\SIDEFIND\SIDEFIND.DLL (file missing)
        O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npvmidi.dll
        O13 - DefaultPrefix: http://nowfind.net/rand/gallery.php?url=
        O13 - WWW Prefix: http://nowfind.net/rand/gallery.php?url=
        O13 - Home Prefix: http://nowfind.net/rand/gallery.php?url=
        O13 - Mosaic Prefix: http://nowfind.net/rand/gallery.php?url=
        O14 - IERESET.INF: SEARCH_PAGE_URL=
        O14 - IERESET.INF: START_PAGE_URL=
        O15 - Trusted Zone: *.slotch.com
        O15 - Trusted Zone: *.xxxtoolbar.com
        O15 - Trusted Zone: *.blazefind.com
        O15 - Trusted Zone: *.windupdates.com
        O15 - Trusted Zone: *.searchmiracle.com
        O15 - Trusted Zone: *.searchbarcash.com
        O15 - Trusted Zone: *.skoobidoo.com
        O15 - Trusted Zone: *.my-internet.info
        O15 - Trusted Zone: *.flingstone.com
        O15 - Trusted Zone: *.mt-download.com
        O15 - Trusted Zone: *.clickspring.net
        O15 - Trusted Zone: *.ysbweb.com
        O15 - Trusted Zone: *.slotchbar.com
        O15 - Trusted Zone: *.iframedollars.biz
        O15 - Trusted Zone: *.windupdates.com (HKLM)
        O15 - Trusted Zone: *.searchbarcash.com (HKLM)
        O15 - Trusted Zone: *.searchmiracle.com (HKLM)
        O15 - Trusted Zone: *.skoobidoo.com (HKLM)
        O15 - Trusted Zone: *.my-internet.info (HKLM)
        O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
        O15 - Trusted Zone: *.slotch.com (HKLM)
        O15 - Trusted Zone: *.flingstone.com (HKLM)
        O15 - Trusted Zone: *.mt-download.com (HKLM)
        O15 - Trusted Zone: *.blazefind.com (HKLM)
        O15 - Trusted Zone: *.clickspring.net (HKLM)
        O15 - Trusted Zone: *.ysbweb.com (HKLM)
        O15 - Trusted Zone: *.slotchbar.com (HKLM)
        O15 - Trusted Zone: *.iframedollars.biz (HKLM)
        O15 - Trusted IP range: 67.19.185.246
        O15 - Trusted IP range: 67.19.185.246 (HKLM)
        O16 - DPF: komentator - http://sport.onet.pl/komentator.cab
        O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
        http://skaner.mks.com.pl/SkanerOnline.cab
        O16 - DPF: {5F874A6F-8B34-433D-BA4B-47AC91C0567F} (MailCfg Control) -
        https://poczta.wp.pl/autoryzacja/mailcfg2.ocx
        O16 - DPF: {631FF594-EC25-4CFF-B869-402DF294E1D6} (Instalator oprogramowania
        Onet.pl) - http://slimak.onet.pl/_m/kamerzysta/OnetInstalator012s.ocx
        O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} -
        http://www.netvenda.com/sites/games-intl/pl/games4.cab
        O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller
        Control) - http://www.mt-download.com/MediaTicketsInstaller.cab?refid=2732
        O16 - DPF: {C40F8F85-3FC3-4C0C-AD91-6A204FAAD59F} (UCInstall Class) -
        http://ultimatecleaner.com/install/UCInst.cab
        O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) -
        http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_adult.cab
        O18 - Filter: text/html - {695F49FA-582F-11D9-9C29-00005B00BB35} -
        C:\WINDOWS\SYSTEM\NJA.DLL
        O18 - Filter: text/plain - {695F49FA-582F-11D9-9C29-00005B00BB35} -
        C:\WINDOWS\SYSTEM\NJA.DLL
        O21 - SSODL: OLE Automation Module - {3F143C3A-1457-6CCA-03A7-7AA23B61E40F} -
        (no file)
        O21 - SSODL: DDE Module - {DABB03E9-AC0D-3740-E3E5-4B37C80837E5} -
        C:\WINDOWS\SYSTEM\mtwirl.dll
        O21 - SSODL: eplrr - {47EFF680-57A1-11D9-9C29-0000CA3DE211} -
        C:\WINDOWS\SYSTEM\eplrr3.dll


        • Gość: Radekk Re: HiJack Log IP: *.chello.pl 28.12.04, 22:02
          Netsec...jesteś moja ostatnia deska ratunku..pomóż plisss
          • netsec Re: HiJack Log 29.12.04, 09:13
            Zamknij wszystkie okna Internet Explorer’a.
            Uruchom ponownie HiJackThis wykonaj SCAN i zaznacz(haczykiem) te pozycje:


            R1 - HKCU\Software\Microsoft\Internet Explorer,Search =
            http://www.nowfind.net/002/index.html
            R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
            http://www.nowfind.net/002/index.html
            R1 - HKLM\Software\Microsoft\Internet Explorer,Search =
            http://www.nowfind.net/002/index.html
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
            http://www.nowfind.net/002/index.html
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
            http://www.nowfind.net/002/index.html
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
            http://www.nowfind.net/002/index.html
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
            http://www.nowfind.net/002/index.html
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
            http://www.nowfind.net/002/index.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
            http://www.nowfind.net/002/index.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
            http://www.nowfind.net/002/index.html
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
            http://www.nowfind.net/002/index.html
            R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            http://www.nowfind.net/002/index.html
            R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            http://www.nowfind.net/002/index.html
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            http://www.nowfind.net/002/index.html
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            http://www.nowfind.net/002/index.html
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
            R3 - Default URLSearchHook is missing
            F1 - win.ini:
            run=C:\WINDOWS\hpfsched.bat;C:\WINDOWS\hpfsched.exe;C:\WINDOWS\hpfsched.com;C:\W
            INDOWS\hpfsched.scr;C:\WINDOWS\hpfsched.vbs;C:\WINDOWS\COMMAND\hpfsched.bat;C:\W
            INDOWS\COMMAND\hpfsched.exe;C:\WINDOWS\COMMAND\hpfsched.com;C:\WINDOWS\COMMAND\h
            pfsched.scr;C:\WINDOWS\COMMAND\hpfsched.vbs;C:\WINDOWS\SYSTEM\hpfsched.bat;C:\WI
            NDOWS\SYSTEM\hpfsched.exe;C:\WINDOWS\SYSTEM\hpfsched.com;C:\WINDOWS\SYSTEM\hpfsc
            hed.scr;C:\WINDOWS\SYSTEM\hpfsched.vbs
            O2 - BHO: (no name) - {275636E4-A535-4668-9FF1-86DC0C62D446} - (no file)
            O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B136188F5DEB} -
            C:\WINDOWS\QUESTMOD.DLL (file missing)
            O2 - BHO: Tubby - {9EAC0102-5E61-2312-BC2D-544243544243} -
            C:\WINDOWS\SYSTEM\TBC.DLL
            O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\PROGRAM
            FILES\SIDEFIND\SFBHO.DLL (file missing)
            O2 - BHO: (no name) - {695F49FB-582F-11D9-9C29-0000344C1EAE} -
            C:\WINDOWS\SYSTEM\NJA.DLL
            O3 - Toolbar: Search Toolbar - {9EAC0102-5E61-2312-BC2D-544243544243} -
            C:\WINDOWS\SYSTEM\TBC.DLL
            O4 - HKLM\..\Run: [MSUpdSrv] msupdsrv.exe
            O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\SYSTEM\twink64.exe
            internat.dll,LoadKeyboardProfile
            O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\SYSTEM\tibs3.exe
            O4 - HKCU\..\Run: [Eaua] C:\WINDOWS\Dane aplikacji\ooua.exe
            O4 - HKCU\..\RunServices: [Eaua] C:\WINDOWS\Dane aplikacji\ooua.exe
            O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} -
            C:\PROGRAM FILES\SIDEFIND\SIDEFIND.DLL (file missing)
            O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npvmidi.dll
            O13 - DefaultPrefix: http://nowfind.net/rand/gallery.php?url=
            O13 - WWW Prefix: http://nowfind.net/rand/gallery.php?url=
            O13 - Home Prefix: http://nowfind.net/rand/gallery.php?url=
            O13 - Mosaic Prefix: http://nowfind.net/rand/gallery.php?url=
            O14 - IERESET.INF: SEARCH_PAGE_URL=
            O14 - IERESET.INF: START_PAGE_URL=
            O15 - Trusted Zone: *.slotch.com
            O15 - Trusted Zone: *.xxxtoolbar.com
            O15 - Trusted Zone: *.blazefind.com
            O15 - Trusted Zone: *.windupdates.com
            O15 - Trusted Zone: *.searchmiracle.com
            O15 - Trusted Zone: *.searchbarcash.com
            O15 - Trusted Zone: *.skoobidoo.com
            O15 - Trusted Zone: *.my-internet.info
            O15 - Trusted Zone: *.flingstone.com
            O15 - Trusted Zone: *.mt-download.com
            O15 - Trusted Zone: *.clickspring.net
            O15 - Trusted Zone: *.ysbweb.com
            O15 - Trusted Zone: *.slotchbar.com
            O15 - Trusted Zone: *.iframedollars.biz
            O15 - Trusted Zone: *.windupdates.com (HKLM)
            O15 - Trusted Zone: *.searchbarcash.com (HKLM)
            O15 - Trusted Zone: *.searchmiracle.com (HKLM)
            O15 - Trusted Zone: *.skoobidoo.com (HKLM)
            O15 - Trusted Zone: *.my-internet.info (HKLM)
            O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
            O15 - Trusted Zone: *.slotch.com (HKLM)
            O15 - Trusted Zone: *.flingstone.com (HKLM)
            O15 - Trusted Zone: *.mt-download.com (HKLM)
            O15 - Trusted Zone: *.blazefind.com (HKLM)
            O15 - Trusted Zone: *.clickspring.net (HKLM)
            O15 - Trusted Zone: *.ysbweb.com (HKLM)
            O15 - Trusted Zone: *.slotchbar.com (HKLM)
            O15 - Trusted Zone: *.iframedollars.biz (HKLM)
            O15 - Trusted IP range: 67.19.185.246
            O15 - Trusted IP range: 67.19.185.246 (HKLM)
            O16 - DPF: komentator - http://sport.onet.pl/komentator.cab
            O16 - DPF: {631FF594-EC25-4CFF-B869-402DF294E1D6} (Instalator oprogramowania
            Onet.pl) - http://slimak.onet.pl/_m/kamerzysta/OnetInstalator012s.ocx
            O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} -
            http://www.netvenda.com/sites/games-intl/pl/games4.cab
            O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller
            Control) - http://www.mt-download.com/MediaTicketsInstaller.cab?refid=2732
            O16 - DPF: {C40F8F85-3FC3-4C0C-AD91-6A204FAAD59F} (UCInstall Class) -
            http://ultimatecleaner.com/install/UCInst.cab
            O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) -
            http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_adult.cab
            O18 - Filter: text/html - {695F49FA-582F-11D9-9C29-00005B00BB35} -
            C:\WINDOWS\SYSTEM\NJA.DLL
            O18 - Filter: text/plain - {695F49FA-582F-11D9-9C29-00005B00BB35} -
            C:\WINDOWS\SYSTEM\NJA.DLL
            O21 - SSODL: OLE Automation Module - {3F143C3A-1457-6CCA-03A7-7AA23B61E40F} -
            (no file)
            O21 - SSODL: DDE Module - {DABB03E9-AC0D-3740-E3E5-4B37C80837E5} -
            C:\WINDOWS\SYSTEM\mtwirl.dll
            O21 - SSODL: eplrr - {47EFF680-57A1-11D9-9C29-0000CA3DE211} -
            C:\WINDOWS\SYSTEM\eplrr3.dll

            Po zaznaczeniu wykonaj FIX CHECKED i potwierdź TAK/OK.

            W Panel Sterowania => Opcje Internetowe usuń
            Tymczasowe pliki Internetowe (Wszystkie) i Cooki.

            Odinstaluj w Panelu sterowania Dodaj/Usuń programy, to czego nie znasz.

            Uruchom ponownie komputer i wklej nowy log z HJ.
            • Gość: Radekk Re: HiJack Log IP: *.chello.pl 29.12.04, 12:29
              zrobiłem to co mi napisałeś
              oto nowy logLogfile of HijackThis v1.99.0
              Scan saved at 12:31:02, on 04-12-29
              Platform: Windows 98 SE (Win9x 4.10.2222A)
              MSIE: Internet Explorer v5.00 (5.00.2614.3500)

              Running processes:
              C:\WINDOWS\SYSTEM\KERNEL32.DLL
              C:\WINDOWS\SYSTEM\MSGSRV32.EXE
              C:\WINDOWS\SYSTEM\MPREXE.EXE
              C:\WINDOWS\SYSTEM\mmtask.tsk
              C:\PROGRAM FILES\PANDA SOFTWARE\PANDA TITANIUM ANTIVIRUS 2004\PSIMSVC.EXE
              C:\WINDOWS\EXPLORER.EXE
              C:\PROGRAM FILES\PANDA SOFTWARE\PANDA TITANIUM ANTIVIRUS 2004\APVXDWIN.EXE
              C:\PROGRAM FILES\PANDA SOFTWARE\PANDA TITANIUM ANTIVIRUS 2004\WEBPROXY.EXE
              C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
              C:\WINDOWS\SYSTEM\DDHELP.EXE
              D:\HIJACKTHIS.EXE

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
              res://C:\WINDOWS\TEMP\sp.dll/sp.html
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
              www.nowfind.net/002/index.html
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
              res://C:\WINDOWS\TEMP\sp.dll/sp.html
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
              R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              about:blank
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              about:blank
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              O2 - BHO: (no name) - {CF424941-5994-11D9-9C29-0000CACDC258} -
              C:\WINDOWS\SYSTEM\NJA.DLL
              O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Titanium
              Antivirus 2004\APVXDWIN.EXE" /s
              O4 - HKLM\..\RunServices: [PSIMSVC] "C:\Program Files\Panda Software\Panda
              Titanium Antivirus 2004\PSIMSVC.exe"
              O14 - IERESET.INF: SEARCH_PAGE_URL=
              O14 - IERESET.INF: START_PAGE_URL=
              O15 - Trusted IP range: 67.19.185.246
              O15 - Trusted IP range: 67.19.185.246 (HKLM)
              O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
              skaner.mks.com.pl/SkanerOnline.cab
              O16 - DPF: {5F874A6F-8B34-433D-BA4B-47AC91C0567F} (MailCfg Control) -
              poczta.wp.pl/autoryzacja/mailcfg2.ocx
              O18 - Filter: text/html - {CF424940-5994-11D9-9C29-0000A58167C3} -
              C:\WINDOWS\SYSTEM\NJA.DLL
              O18 - Filter: text/plain - {CF424940-5994-11D9-9C29-0000A58167C3} -
              C:\WINDOWS\SYSTEM\NJA.DLL



Pełna wersja