Logfile of Browser Hijack Recover(BHR) v2.2 http://www.browser-hijack.com/ Log created on 2007-10-21 18:26:44 Microsoft Windows XP Professional Dodatek Service Pack 2 (Build 2600) Internet Explorer v6.0.2900.2180 Update Versions: ;SP2; [Process Manager] - [Process] D:\WINDOWS\System32\smss.exe D:\WINDOWS\system32\csrss.exe D:\WINDOWS\system32\winlogon.exe D:\WINDOWS\system32\services.exe D:\WINDOWS\system32\lsass.exe D:\WINDOWS\system32\Ati2evxx.exe D:\WINDOWS\system32\svchost.exe D:\WINDOWS\system32\svchost.exe D:\WINDOWS\System32\svchost.exe D:\WINDOWS\system32\svchost.exe D:\WINDOWS\system32\svchost.exe D:\WINDOWS\system32\Ati2evxx.exe D:\WINDOWS\system32\spoolsv.exe D:\WINDOWS\RTHDCPL.EXE D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE C:\Program Files\Gadu-Gadu\gg.exe D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe D:\WINDOWS\system32\wdfmgr.exe D:\WINDOWS\System32\alg.exe D:\Program Files\Mozilla Firefox\firefox.exe D:\WINDOWS\explorer.exe C:\Program Files\WinRAR.exe C:\Program Files\WinRAR.exe C:\Program Files\Browser Hijack Recover\bhr.exe [IE Options] - [Normal] R0 - HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/windows/ie_intl/en/start/ R0 - HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main,Window Title = [IE Options] - [IE Menu] [IE Options] - [Internet Options] [IE Options] - [IE Search Hooks] R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - D:\WINDOWS\system32\shdocvw.dll [IE Add-Ons] - [Toolbars] [IE Add-Ons] - [Explorer Bars] [IE Add-Ons] - [Context Menu] O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\OFFICE11\EXCEL.EXE/3000 [IE Add-Ons] - [BHOs] [IE Add-Ons] - [Tools Menu] O9 - Extra "Tool" Menu Item: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe [IE Add-Ons] - [Tools Button] O9 - Extra Button: Statystyki dla ochrony WWW - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll O9 - Extra Button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\OFFICE11\REFIEBAR.DLL O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe [System Options] [StartUp] 04 - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Gadu-Gadu = C:\Program Files\Gadu-Gadu\gg.exe" /tray