player** utworzono 26 lutego 2007 utworzono 26 lutego 2007 Mam uciążliwy problem z internetem (TP). W zasobniku systemowym zawsze podczasz połączenia z netem widnieją 2 komputerki, oraz (w moim przypadku) zielona ikonka świadcząca o gotowości modemu. Komputerki świecą sie zazwyczaj gdy coś pobieram, a gdy nie - to nie. Niestety przez ostatnie 2 tyg świecą się cały czas a gdy na nie klikne to widzę, że coś cały czs wysyłam, tylko nie wiem komu i w jaki sposób ?? :/ przy tym strasznie muli mi IE, oraz inne aplikacje. proszę o pomoc.>@@@!!!!
Aqui komentarz 26 lutego 2007 komentarz 26 lutego 2007 Moze masz jakiegos szkodnika.. Wklej logi z Hijackthis i Silentrunners opis--> http://www.pcboard.pl/viewtopic.php?t=13
player** komentarz 26 lutego 2007 Autor komentarz 26 lutego 2007 Logfile of HijackThis v1.99.1 Scan saved at 18:52:35, on 2007-02-26 Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:WINDOWSSystem32smss.exe C:WINDOWSsystem32winlogon.exe C:WINDOWSsystem32services.exe C:WINDOWSsystem32lsass.exe C:WINDOWSsystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSExplorer.EXE C:WINDOWSsystem32spoolsv.exe C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe C:Program FilesAlwil SoftwareAvast4ashServ.exe C:WINDOWSSystem32svchost.exe C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe C:Program FilesAlwil SoftwareAvast4ashWebSv.exe C:WINDOWSSystem32flushdns.exe C:PROGRA~1NEOSTR~1CnxMon.exe C:PROGRA~1NEOSTR~1TaskbarIcon.exe C:PROGRA~1ALWILS~1Avast4ashDisp.exe C:WINDOWSSystem32mysvcc.exe C:WINDOWSsystem32srvc.exe C:WINDOWSSystem32ctfmon.exe C:Program FilesSAGEMSAGEM F@st 800-840dslmon.exe C:WINDOWSSystem32devldr32.exe C:WINDOWSSystem32urdvxc.exe C:Program FilesInternet ExplorerIEXPLORE.EXE C:Program FilesGadu-Gadugg.exe C:Program FilesWinampwinamp.exe C:Documents and SettingsPawełek.MALINOWS-CSEUI8PulpithijackthisHijackThis.exe R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/ R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Neostrada TP R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:PROGRA~1NEOSTR~1SEARCH~1.DLL O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:Program FilesSpybot - Search & DestroySDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_11binssv.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx O3 - Toolbar: (no name) - {37B85A29-692B-4205-9CAD-2626E4993404} - (no file) O4 - HKLM..Run: [WooCnxMon] C:PROGRA~1NEOSTR~1CnxMon.exe O4 - HKLM..Run: [WOOWATCH] C:PROGRA~1NEOSTR~1Watch.exe O4 - HKLM..Run: [WOOTASKBARICON] C:PROGRA~1NEOSTR~1TaskbarIcon.exe O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe O4 - HKLM..Run: [mysvcig38] mysvcc.exe O4 - HKLM..Run: [symantec Antivirus professional] flushdns.exe O4 - HKLM..Run: [johnj315] C:WINDOWSsystem32srvc.exe O4 - HKLM..RunServices: [mysvcig38] mysvcc.exe O4 - HKLM..RunServices: [symantec Antivirus professional] flushdns.exe O4 - HKLM..RunOnce: [symantec Antivirus professional] flushdns.exe O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe O4 - HKCU..Run: [AutoConnect] C:Program FilesAutoConnectAutoConnect.exe O4 - HKCU..Run: [symantec Antivirus professional] flushdns.exe O4 - HKCU..Run: [johnj315] C:WINDOWSsystem32srvc.exe O4 - HKCU..RunOnce: [symantec Antivirus professional] flushdns.exe O4 - Global Startup: DSLMON.lnk = C:Program FilesSAGEMSAGEM F@st 800-840dslmon.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_11binssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_11binssv.dll O12 - Plugin for .pdf: C:Program FilesInternet ExplorerPLUGINSnppdf32.dll O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} (Ganymede Board Games) - http://67.15.101.3/g_bin/pl/boards_2_0_0_31.cab O16 - DPF: {AC120B1D-9411-4111-AF52-118052D85D45} (GameDesire Darts Games) - http://67.15.101.3/g_bin/pl/darts_2_0_0_37.cab O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C4} (GameDesire Pool Training) - http://67.15.101.3/g_bin/pl/billardt_2_0_0_29.cab O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C5} (GameDesire Snooker) - http://67.15.101.3/g_bin/pl/snooker_2_0_0_29.cab O17 - HKLMSystemCCSServicesTcpip..{FC12C3F3-9EE0-47BE-AD29-4E843984F419}: NameServer = 194.204.159.1 217.98.63.164 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:Program FilesAlwil SoftwareAvast4ashWebSv.exe" /service (file missing) O23 - Service: Network Windows Service (MSWindows) - Unknown owner - C:WINDOWSSystem32urdvxc.exe" /service (file missing) [ Dodano: 2007-02-26, 19:55 ] "Silent Runners.vbs", revision R50, http://www.silentrunners.org/ Operating System: Windows XP Output limited to non-default values, except where indicated by "{++}" Startup items buried in registry: --------------------------------- HKCUSoftwareMicrosoftWindowsCurrentVersionRun {++} "CTFMON.EXE" = "C:WINDOWSSystem32ctfmon.exe" [MS] "AutoConnect" = "C:Program FilesAutoConnectAutoConnect.exe" [file not found] "Symantec Antivirus professional" = "flushdns.exe" [null data] "johnj315" = "C:WINDOWSsystem32srvc.exe" [null data] HKCUSoftwareMicrosoftWindowsCurrentVersionRunOnce {++} "Symantec Antivirus professional" = "flushdns.exe" [null data] HKLMSoftwareMicrosoftWindowsCurrentVersionRun {++} "WooCnxMon" = "C:PROGRA~1NEOSTR~1CnxMon.exe" [empty string] "WOOWATCH" = "C:PROGRA~1NEOSTR~1Watch.exe" ["France Télécom R&D"] "WOOTASKBARICON" = "C:PROGRA~1NEOSTR~1TaskbarIcon.exe" ["France Télécom R&D"] "avast!" = "C:PROGRA~1ALWILS~1Avast4ashDisp.exe" [null data] "mysvcig38" = "mysvcc.exe" [null data] "Symantec Antivirus professional" = "flushdns.exe" [null data] "johnj315" = "C:WINDOWSsystem32srvc.exe" [null data] HKLMSoftwareMicrosoftWindowsCurrentVersionRunOnce {++} "Symantec Antivirus professional" = "flushdns.exe" [null data] HKLMSoftwareMicrosoftActive SetupInstalled Components {306D6C21-C1B6-4629-986C-E59E1875B8AF}(Default) = (no title provided) StubPath = ""C:WINDOWSSystem32rundll32.exe" "C:Program FilesMessengermsgsc.dll",ShowIconsUser" [MS] HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects {53707962-6F74-2D53-2644-206D7942484F}(Default) = (no title provided) -> {HKLM...CLSID} = (no title provided) InProcServer32(Default) = "C:Program FilesSpybot - Search & DestroySDHelper.dll" ["Safer Networking Limited"] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}(Default) = (no title provided) -> {HKLM...CLSID} = "SSVHelper Class" InProcServer32(Default) = "C:Program FilesJavajre1.5.0_11binssv.dll" ["Sun Microsystems, Inc."] HKLMSoftwareMicrosoftWindowsCurrentVersionShell ExtensionsApproved "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania" -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania" InProcServer32(Default) = "deskpan.dll" [file not found] "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu" -> {HKLM...CLSID} = "HyperTerminal Icon Ext" InProcServer32(Default) = "C:WINDOWSSystem32hticons.dll" ["Hilgraeve, Inc."] "{472083B0-C522-11CF-8763-00608CC02F24}" = "avast" -> {HKLM...CLSID} = "avast" InProcServer32(Default) = "C:Program FilesAlwil SoftwareAvast4ashShell.dll" ["ALWIL Software"] HKLMSoftwareClasses*shellexContextMenuHandlers avast(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}" -> {HKLM...CLSID} = "avast" InProcServer32(Default) = "C:Program FilesAlwil SoftwareAvast4ashShell.dll" ["ALWIL Software"] HKLMSoftwareClassesFoldershellexContextMenuHandlers avast(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}" -> {HKLM...CLSID} = "avast" InProcServer32(Default) = "C:Program FilesAlwil SoftwareAvast4ashShell.dll" ["ALWIL Software"] Group Policies {GPedit.msc branch and setting}: ----------------------------------------------- Note: detected settings may not have any effect. HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Shutdown: Allow system to be shut down without having to log on} "undockwithoutlogon" = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Devices: Allow undock without having to log on} Active Desktop and Wallpaper: ----------------------------- Active Desktop may be disabled at this entry: HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShellState Displayed if Active Desktop enabled and wallpaper not set by Group Policy: HKCUSoftwareMicrosoftInternet ExplorerDesktopGeneral "Wallpaper" = "D:DOKUMENTYLMwallp.bmp" Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCUControl PanelDesktop "Wallpaper" = "D:DOKUMENTYLMwallp.bmp" Enabled Screen Saver: --------------------- HKCUControl PanelDesktop "SCRNSAVE.EXE" = "C:WINDOWSSystem32logon.scr" [MS] Startup items in "Pawełek" & "All Users" startup folders: --------------------------------------------------------- C:Documents and SettingsAll Users.WINDOWSMenu StartProgramyAutostart "DSLMON" -> shortcut to: "C:Program FilesSAGEMSAGEM F@st 800-840dslmon.exe /W" [empty string] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLMSystemCurrentControlSetServicesWinsock2ParametersNameSpace_Catalog5Catalog_E tries {++} 000000000001LibraryPath = "%SystemRoot%System32mswsock.dll" [MS] 000000000002LibraryPath = "%SystemRoot%System32winrnr.dll" [MS] 000000000003LibraryPath = "%SystemRoot%System32mswsock.dll" [MS] Transport Service Providers HKLMSystemCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_En ries {++} 0000000000##PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%system32mswsock.dll [MS], 01 - 03, 06 - 15 %SystemRoot%system32rsvpsp.dll [MS], 04 - 05 Toolbars, Explorer Bars, Extensions: ------------------------------------ Explorer Bars HKLMSoftwareMicrosoftInternet ExplorerExplorer Bars HKLMSoftwareClassesCLSID{01002DB2-8170-4D9B-A8B1-DDC9DD114E03}(Default) = "Volet Wanadoo" Implemented Categories{00021494-0000-0000-C000-000000000046} [horizontal bar] InProcServer32(Default) = "C:PROGRA~1NEOSTR~1audienceaudience.dll" [empty string] HKLMSoftwareClassesCLSID{3BAF4A27-C764-4E1A-A6F4-62F7A7E5E51C}(Default) = "ToolBand Class" Implemented Categories{00021494-0000-0000-C000-000000000046} [horizontal bar] InProcServer32(Default) = "C:PROGRA~1NEOSTR~1audienceaudience.dll" [empty string] HKLMSoftwareClassesCLSID{5BF498C0-931E-4A4F-B33F-456D07137EAA}(Default) = "Volet Wanadoo" Implemented Categories{00021494-0000-0000-C000-000000000046} [horizontal bar] InProcServer32(Default) = "C:PROGRA~1NEOSTR~1audienceaudience.dll" [empty string] Extensions (Tools menu items, main toolbar menu buttons) HKLMSoftwareMicrosoftInternet ExplorerExtensions {08B0E5C0-4FCB-11CF-AAA5-00401C608501} "MenuText" = "Sun Java Console" "CLSIDExtension" = "{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}" -> {HKCU...CLSID} = "Java Plug-in 1.5.0_11" InProcServer32(Default) = "C:Program FilesJavajre1.5.0_11binssv.dll" ["Sun Microsystems, Inc."] -> {HKLM...CLSID} = "Java Plug-in 1.5.0_11" InProcServer32(Default) = "C:Program FilesJavajre1.5.0_11binnpjpi150_11.dll" ["Sun Microsystems, Inc."] Miscellaneous IE Hijack Points ------------------------------ HKCUSoftwareMicrosoftInternet ExplorerURLSearchHooks <<H>> "{08C06D61-F1F3-4799-86F8-BE1A89362C85}" = (no title provided) -> {HKLM...CLSID} = "Search Class" InProcServer32(Default) = "C:PROGRA~1NEOSTR~1SEARCH~1.DLL" [empty string] Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ avast! Antivirus, avast! Antivirus, ""C:Program FilesAlwil SoftwareAvast4ashServ.exe"" [null data] avast! iAVS4 Control Service, aswUpdSv, ""C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe"" [null data] avast! Mail Scanner, avast! Mail Scanner, ""C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe" /service" ["ALWIL Software"] avast! Web Scanner, avast! Web Scanner, ""C:Program FilesAlwil SoftwareAvast4ashWebSv.exe" /service" ["ALWIL Software"] Network Windows Service, MSWindows, ""C:WINDOWSSystem32urdvxc.exe" /service" [null data] Symantec Antivirus professional, Symantec Antivirus professional, ""C:WINDOWSSystem32flushdns.exe" -netsvcs" [null data] Print Monitors: --------------- HKLMSystemCurrentControlSetControlPrintMonitors hpzsnt07Driver = "hpzsnt07.dll" ["HP"] ---------- <<H>>: Suspicious data at a browser hijack point. + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + The search for DESKTOP.INI DLL launch points on all local fixed drives took 1748 seconds. ---------- (total run time: 2635 seconds)
Aqui komentarz 27 lutego 2007 komentarz 27 lutego 2007 Jest syf.. www.ewido.net <---Przeskanuj i wywal wszystko Dodatkowo uzyj SmitFraudFix opcja nr 2 opis--> http://www.pcboard.pl/viewtopic.php?t=14
player** komentarz 27 lutego 2007 Autor komentarz 27 lutego 2007 Miałem kiedyś program bodajże Microsoft XP-Antyspy taka ikonka jak by tablicy do strzelania z łuku:P i wiem że on usuwał mi te problemu ale teraz nigdzie nie mogę go znaleźć. Proszę o www jeśli by ktoś wiedział.
Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!
Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.