x-kom hosting

PROBLEM Z INTERNETEM !!

player**
utworzono
utworzono

Mam uciążliwy problem z internetem (TP). W zasobniku systemowym zawsze podczasz połączenia z netem widnieją 2 komputerki, oraz (w moim przypadku) zielona ikonka świadcząca o gotowości modemu. Komputerki świecą sie zazwyczaj gdy coś pobieram, a gdy nie - to nie. Niestety przez ostatnie 2 tyg świecą się cały czas a gdy na nie klikne to widzę, że coś cały czs wysyłam, tylko nie wiem komu i w jaki sposób ?? :/ przy tym strasznie muli mi IE, oraz inne aplikacje. proszę o pomoc.>@@@!!!!

Aqui
komentarz
komentarz

Moze masz jakiegos szkodnika..

Wklej logi z Hijackthis i Silentrunners

opis--> http://www.pcboard.pl/viewtopic.php?t=13

player**
komentarz
komentarz

Logfile of HijackThis v1.99.1

Scan saved at 18:52:35, on 2007-02-26

Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:

C:WINDOWSSystem32smss.exe

C:WINDOWSsystem32winlogon.exe

C:WINDOWSsystem32services.exe

C:WINDOWSsystem32lsass.exe

C:WINDOWSsystem32svchost.exe

C:WINDOWSSystem32svchost.exe

C:WINDOWSExplorer.EXE

C:WINDOWSsystem32spoolsv.exe

C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

C:Program FilesAlwil SoftwareAvast4ashServ.exe

C:WINDOWSSystem32svchost.exe

C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe

C:Program FilesAlwil SoftwareAvast4ashWebSv.exe

C:WINDOWSSystem32flushdns.exe

C:PROGRA~1NEOSTR~1CnxMon.exe

C:PROGRA~1NEOSTR~1TaskbarIcon.exe

C:PROGRA~1ALWILS~1Avast4ashDisp.exe

C:WINDOWSSystem32mysvcc.exe

C:WINDOWSsystem32srvc.exe

C:WINDOWSSystem32ctfmon.exe

C:Program FilesSAGEMSAGEM F@st 800-840dslmon.exe

C:WINDOWSSystem32devldr32.exe

C:WINDOWSSystem32urdvxc.exe

C:Program FilesInternet ExplorerIEXPLORE.EXE

C:Program FilesGadu-Gadugg.exe

C:Program FilesWinampwinamp.exe

C:Documents and SettingsPawełek.MALINOWS-CSEUI8PulpithijackthisHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Neostrada TP

R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza

R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:PROGRA~1NEOSTR~1SEARCH~1.DLL

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:Program FilesSpybot - Search & DestroySDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_11binssv.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx

O3 - Toolbar: (no name) - {37B85A29-692B-4205-9CAD-2626E4993404} - (no file)

O4 - HKLM..Run: [WooCnxMon] C:PROGRA~1NEOSTR~1CnxMon.exe

O4 - HKLM..Run: [WOOWATCH] C:PROGRA~1NEOSTR~1Watch.exe

O4 - HKLM..Run: [WOOTASKBARICON] C:PROGRA~1NEOSTR~1TaskbarIcon.exe

O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe

O4 - HKLM..Run: [mysvcig38] mysvcc.exe

O4 - HKLM..Run: [symantec Antivirus professional] flushdns.exe

O4 - HKLM..Run: [johnj315] C:WINDOWSsystem32srvc.exe

O4 - HKLM..RunServices: [mysvcig38] mysvcc.exe

O4 - HKLM..RunServices: [symantec Antivirus professional] flushdns.exe

O4 - HKLM..RunOnce: [symantec Antivirus professional] flushdns.exe

O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe

O4 - HKCU..Run: [AutoConnect] C:Program FilesAutoConnectAutoConnect.exe

O4 - HKCU..Run: [symantec Antivirus professional] flushdns.exe

O4 - HKCU..Run: [johnj315] C:WINDOWSsystem32srvc.exe

O4 - HKCU..RunOnce: [symantec Antivirus professional] flushdns.exe

O4 - Global Startup: DSLMON.lnk = C:Program FilesSAGEMSAGEM F@st 800-840dslmon.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_11binssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_11binssv.dll

O12 - Plugin for .pdf: C:Program FilesInternet ExplorerPLUGINSnppdf32.dll

O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} (Ganymede Board Games) - http://67.15.101.3/g_bin/pl/boards_2_0_0_31.cab

O16 - DPF: {AC120B1D-9411-4111-AF52-118052D85D45} (GameDesire Darts Games) - http://67.15.101.3/g_bin/pl/darts_2_0_0_37.cab

O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C4} (GameDesire Pool Training) - http://67.15.101.3/g_bin/pl/billardt_2_0_0_29.cab

O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C5} (GameDesire Snooker) - http://67.15.101.3/g_bin/pl/snooker_2_0_0_29.cab

O17 - HKLMSystemCCSServicesTcpip..{FC12C3F3-9EE0-47BE-AD29-4E843984F419}: NameServer = 194.204.159.1 217.98.63.164

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe

O23 - Service: avast! Antivirus - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashWebSv.exe" /service (file missing)

O23 - Service: Network Windows Service (MSWindows) - Unknown owner - C:WINDOWSSystem32urdvxc.exe" /service (file missing)

[ Dodano: 2007-02-26, 19:55 ]

"Silent Runners.vbs", revision R50, http://www.silentrunners.org/

Operating System: Windows XP

Output limited to non-default values, except where indicated by "{++}"

Startup items buried in registry:

---------------------------------

HKCUSoftwareMicrosoftWindowsCurrentVersionRun {++}

"CTFMON.EXE" = "C:WINDOWSSystem32ctfmon.exe" [MS]

"AutoConnect" = "C:Program FilesAutoConnectAutoConnect.exe" [file not found]

"Symantec Antivirus professional" = "flushdns.exe" [null data]

"johnj315" = "C:WINDOWSsystem32srvc.exe" [null data]

HKCUSoftwareMicrosoftWindowsCurrentVersionRunOnce {++}

"Symantec Antivirus professional" = "flushdns.exe" [null data]

HKLMSoftwareMicrosoftWindowsCurrentVersionRun {++}

"WooCnxMon" = "C:PROGRA~1NEOSTR~1CnxMon.exe" [empty string]

"WOOWATCH" = "C:PROGRA~1NEOSTR~1Watch.exe" ["France Télécom R&D"]

"WOOTASKBARICON" = "C:PROGRA~1NEOSTR~1TaskbarIcon.exe" ["France Télécom R&D"]

"avast!" = "C:PROGRA~1ALWILS~1Avast4ashDisp.exe" [null data]

"mysvcig38" = "mysvcc.exe" [null data]

"Symantec Antivirus professional" = "flushdns.exe" [null data]

"johnj315" = "C:WINDOWSsystem32srvc.exe" [null data]

HKLMSoftwareMicrosoftWindowsCurrentVersionRunOnce {++}

"Symantec Antivirus professional" = "flushdns.exe" [null data]

HKLMSoftwareMicrosoftActive SetupInstalled Components

{306D6C21-C1B6-4629-986C-E59E1875B8AF}(Default) = (no title provided)

StubPath = ""C:WINDOWSSystem32rundll32.exe" "C:Program FilesMessengermsgsc.dll",ShowIconsUser" [MS]

HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects

{53707962-6F74-2D53-2644-206D7942484F}(Default) = (no title provided)

-> {HKLM...CLSID} = (no title provided)

InProcServer32(Default) = "C:Program FilesSpybot - Search & DestroySDHelper.dll" ["Safer Networking Limited"]

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}(Default) = (no title provided)

-> {HKLM...CLSID} = "SSVHelper Class"

InProcServer32(Default) = "C:Program FilesJavajre1.5.0_11binssv.dll" ["Sun Microsystems, Inc."]

HKLMSoftwareMicrosoftWindowsCurrentVersionShell ExtensionsApproved

"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"

-> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"

InProcServer32(Default) = "deskpan.dll" [file not found]

"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"

-> {HKLM...CLSID} = "HyperTerminal Icon Ext"

InProcServer32(Default) = "C:WINDOWSSystem32hticons.dll" ["Hilgraeve, Inc."]

"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"

-> {HKLM...CLSID} = "avast"

InProcServer32(Default) = "C:Program FilesAlwil SoftwareAvast4ashShell.dll" ["ALWIL Software"]

HKLMSoftwareClasses*shellexContextMenuHandlers

avast(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"

-> {HKLM...CLSID} = "avast"

InProcServer32(Default) = "C:Program FilesAlwil SoftwareAvast4ashShell.dll" ["ALWIL Software"]

HKLMSoftwareClassesFoldershellexContextMenuHandlers

avast(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"

-> {HKLM...CLSID} = "avast"

InProcServer32(Default) = "C:Program FilesAlwil SoftwareAvast4ashShell.dll" ["ALWIL Software"]

Group Policies {GPedit.msc branch and setting}:

-----------------------------------------------

Note: detected settings may not have any effect.

HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem

"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001

{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|

Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) hex:0x00000001

{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|

Devices: Allow undock without having to log on}

Active Desktop and Wallpaper:

-----------------------------

Active Desktop may be disabled at this entry:

HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:

HKCUSoftwareMicrosoftInternet ExplorerDesktopGeneral

"Wallpaper" = "D:DOKUMENTYLMwallp.bmp"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:

HKCUControl PanelDesktop

"Wallpaper" = "D:DOKUMENTYLMwallp.bmp"

Enabled Screen Saver:

---------------------

HKCUControl PanelDesktop

"SCRNSAVE.EXE" = "C:WINDOWSSystem32logon.scr" [MS]

Startup items in "Pawełek" & "All Users" startup folders:

---------------------------------------------------------

C:Documents and SettingsAll Users.WINDOWSMenu StartProgramyAutostart

"DSLMON" -> shortcut to: "C:Program FilesSAGEMSAGEM F@st 800-840dslmon.exe /W" [empty string]

Winsock2 Service Provider DLLs:

-------------------------------

Namespace Service Providers

HKLMSystemCurrentControlSetServicesWinsock2ParametersNameSpace_Catalog5Catalog_E

tries {++}

000000000001LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]

000000000002LibraryPath = "%SystemRoot%System32winrnr.dll" [MS]

000000000003LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]

Transport Service Providers

HKLMSystemCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_En

ries {++}

0000000000##PackedCatalogItem (contains) DLL [Company Name], (at) ## range:

%SystemRoot%system32mswsock.dll [MS], 01 - 03, 06 - 15

%SystemRoot%system32rsvpsp.dll [MS], 04 - 05

Toolbars, Explorer Bars, Extensions:

------------------------------------

Explorer Bars

HKLMSoftwareMicrosoftInternet ExplorerExplorer Bars

HKLMSoftwareClassesCLSID{01002DB2-8170-4D9B-A8B1-DDC9DD114E03}(Default) = "Volet Wanadoo"

Implemented Categories{00021494-0000-0000-C000-000000000046} [horizontal bar]

InProcServer32(Default) = "C:PROGRA~1NEOSTR~1audienceaudience.dll" [empty string]

HKLMSoftwareClassesCLSID{3BAF4A27-C764-4E1A-A6F4-62F7A7E5E51C}(Default) = "ToolBand Class"

Implemented Categories{00021494-0000-0000-C000-000000000046} [horizontal bar]

InProcServer32(Default) = "C:PROGRA~1NEOSTR~1audienceaudience.dll" [empty string]

HKLMSoftwareClassesCLSID{5BF498C0-931E-4A4F-B33F-456D07137EAA}(Default) = "Volet Wanadoo"

Implemented Categories{00021494-0000-0000-C000-000000000046} [horizontal bar]

InProcServer32(Default) = "C:PROGRA~1NEOSTR~1audienceaudience.dll" [empty string]

Extensions (Tools menu items, main toolbar menu buttons)

HKLMSoftwareMicrosoftInternet ExplorerExtensions

{08B0E5C0-4FCB-11CF-AAA5-00401C608501}

"MenuText" = "Sun Java Console"

"CLSIDExtension" = "{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}"

-> {HKCU...CLSID} = "Java Plug-in 1.5.0_11"

InProcServer32(Default) = "C:Program FilesJavajre1.5.0_11binssv.dll" ["Sun Microsystems, Inc."]

-> {HKLM...CLSID} = "Java Plug-in 1.5.0_11"

InProcServer32(Default) = "C:Program FilesJavajre1.5.0_11binnpjpi150_11.dll" ["Sun Microsystems, Inc."]

Miscellaneous IE Hijack Points

------------------------------

HKCUSoftwareMicrosoftInternet ExplorerURLSearchHooks

<<H>> "{08C06D61-F1F3-4799-86F8-BE1A89362C85}" = (no title provided)

-> {HKLM...CLSID} = "Search Class"

InProcServer32(Default) = "C:PROGRA~1NEOSTR~1SEARCH~1.DLL" [empty string]

Running Services (Display Name, Service Name, Path {Service DLL}):

------------------------------------------------------------------

avast! Antivirus, avast! Antivirus, ""C:Program FilesAlwil SoftwareAvast4ashServ.exe"" [null data]

avast! iAVS4 Control Service, aswUpdSv, ""C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe"" [null data]

avast! Mail Scanner, avast! Mail Scanner, ""C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service" ["ALWIL Software"]

avast! Web Scanner, avast! Web Scanner, ""C:Program FilesAlwil SoftwareAvast4ashWebSv.exe" /service" ["ALWIL Software"]

Network Windows Service, MSWindows, ""C:WINDOWSSystem32urdvxc.exe" /service" [null data]

Symantec Antivirus professional, Symantec Antivirus professional, ""C:WINDOWSSystem32flushdns.exe" -netsvcs" [null data]

Print Monitors:

---------------

HKLMSystemCurrentControlSetControlPrintMonitors

hpzsnt07Driver = "hpzsnt07.dll" ["HP"]

----------

<<H>>: Suspicious data at a browser hijack point.

+ This report excludes default entries except where indicated.

+ To see *everywhere* the script checks and *everything* it finds,

launch it from a command prompt or a shortcut with the -all parameter.

+ The search for DESKTOP.INI DLL launch points on all local fixed drives

took 1748 seconds.

---------- (total run time: 2635 seconds)

Aqui
komentarz
komentarz

Jest syf..

www.ewido.net <---Przeskanuj i wywal wszystko

Dodatkowo uzyj SmitFraudFix opcja nr 2

opis--> http://www.pcboard.pl/viewtopic.php?t=14

player**
komentarz
komentarz

Miałem kiedyś program bodajże Microsoft XP-Antyspy taka ikonka jak by tablicy do strzelania z łuku:P i wiem że on usuwał mi te problemu ale teraz nigdzie nie mogę go znaleźć. Proszę o www jeśli by ktoś wiedział.

Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!

Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.

×
×
  • Dodaj nową pozycję...

Powiadomienie o plikach cookie

Strona wykorzystuje pliki cookies w celu prawidłowego świadczenia usług i wygody użytkowników. Warunki przechowywania i dostępu do plików cookies możesz zmienić w ustawieniach przeglądarki.