
- Kod: Zaznacz wszystko
- Logfile of HijackThis v1.99.1
 Scan saved at 23:06:23, on 2005-07-23
 Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
 C:\Program Files\Alwil Software\Avast4\ashServ.exe
 D:\Program Files\Gene6 FTP Server\G6FTPSERVER.EXE
 D:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
 C:\WINDOWS\soundman.exe
 C:\WINDOWS\system32\rundll32.exe
 C:\Program Files\AutoConnect\AutoConnect.exe
 C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
 C:\Program Files\EnhanceKeyboard\kb_2k.exe
 C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
 C:\WINDOWS\system32\nvsvc32.exe
 C:\WINDOWS\system32\tcpsvcs.exe
 D:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
 D:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Program Files\Gadu-Gadu\gg.exe
 C:\Program Files\Winamp\winamp.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Documents and Settings\Dom\Pulpit\HijackThis.exe
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.antydialer.pl/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\WINDOWS\pchealth\helpctr\System\panels\blank.htm
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\WINDOWS\pchealth\helpctr\System\panels\blank.htm
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
 O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet6_38.dll
 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
 O4 - HKLM\..\Run: [SoundMan] soundman.exe
 O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s
 O4 - HKCU\..\Run: [AutoConnect] C:\Program Files\AutoConnect\AutoConnect.exe
 O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
 O4 - Startup: VoipBuster.lnk = C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
 O4 - Global Startup: enhanced keyboard driver.lnk = ?
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
 O10 - Hijacked Internet access by New.Net
 O10 - Hijacked Internet access by New.Net
 O10 - Hijacked Internet access by New.Net
 O10 - Hijacked Internet access by New.Net
 O10 - Hijacked Internet access by New.Net
 O17 - HKLM\System\CCS\Services\Tcpip\..\{5023EC1A-E748-429B-8131-68776AD49019}: NameServer = 194.204.152.34 217.98.63.164
 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
 O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
 O23 - Service: Gene6 FTP Server (G6FTPServer) - Gene6 - D:\Program Files\Gene6 FTP Server\G6FTPSERVER.EXE
 O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - D:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Wiem, że to to napewno syf:
- Kod: Zaznacz wszystko
- O10 - Hijacked Internet access by New.Net
 O10 - Hijacked Internet access by New.Net
 O10 - Hijacked Internet access by New.Net
 O10 - Hijacked Internet access by New.Net
 O10 - Hijacked Internet access by New.Net
Ale nie moge tego usunąć
wyłączyłem przywracanie systemu, i włączam tryb awaryjny
zaznaczam te pozycje daje fix checked
najpierw mi wywaliło takie cos:
 
No to odpalam spybota, pobieram najnowsze aktualizacje skanuje, nic nie wykryło, później jakos nie wywalało tego komunikatu niby usuwało, ale jak dałem ponownie scan to dalej to było.
Macie jakies pomysły??


 
	