
Prosze o sprawdzenie loga, co prawda nie mojego bo koleżanki ale coś mi sie wydaje że dużo ma syfu tutaj xD
Aha i chciałam podziękować Łukaszowi za pomoc w moim starym temacje z 'wirusikiem' o nazwie cwis.exe od tamtej pory zginął, przepadł i Kasik cieszy się urokami internetu xD <koniec offta log>
- Kod: Zaznacz wszystko
- Logfile of HijackThis v1.99.1
 Scan saved at 18:39:25, on 05-09-22
 Platform: Windows 98 SE (Win9x 4.10.2222A)
 MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
 Running processes:
 C:\WINDOWS\SYSTEM\KERNEL32.DLL
 C:\WINDOWS\SYSTEM\MSGSRV32.EXE
 C:\WINDOWS\SYSTEM\MPREXE.EXE
 C:\WINDOWS\SYSTEM\mmtask.tsk
 C:\WINDOWS\SYSTEM\MSTASK.EXE
 C:\WINDOWS\EXPLORER.EXE
 C:\WINDOWS\TASKMON.EXE
 C:\PROGRAM FILES\NEOSTRADA TP\TASKBARICON.EXE
 C:\WINDOWS\RUNDLL32.EXE
 C:\WINDOWS\SYSTEM\SYSTRAY.EXE
 C:\TEMP\SALM.EXE
 C:\WINDOWS\SYSTEM\05AKOI4U.EXE
 C:\PROGRAM FILES\INTERNET OPTIMIZER\OPTIMIZE.EXE
 C:\PROGRAM FILES\MEDIA GATEWAY\MEDIAGATEWAY.EXE
 C:\PROGRAM FILES\AJZGGMS\YMVSGU.EXE
 C:\PROGRAM FILES\SAGEM\SAGEM F@ST 800-840\DSLMON.EXE
 C:\WINDOWS\SYSTEM\WMIEXE.EXE
 C:\PROGRAM FILES\INTERNET OPTIMIZER\ACTALERT.EXE
 C:\PROGRAM FILES\NEOSTRADA TP\NEOSTRADATP.EXE
 C:\PROGRAM FILES\NEOSTRADA TP\COMCOMP.EXE
 C:\WINDOWS\SYSTEM\TAPISRV.EXE
 C:\PROGRAM FILES\NEOSTRADA TP\WATCH.EXE
 C:\WINDOWS\SYSTEM\DDHELP.EXE
 C:\PROGRAM FILES\GADU-GADU\GG.EXE
 C:\PROGRAM FILES\GADU-GADU\GG.EXE
 C:\WINDOWS\SYSTEM\RNAAPP.EXE
 C:\MOJE DOKUMENTY\AGA\HIJACKTHIS.EXE
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://szukaj.wp.pl
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ibiza-club.pl/
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada TP
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
 R3 - URLSearchHook: (no name) - _{08C06D61-F1F3-4799-86F8-BE1A89362C85} - (no file)
 O2 - BHO: C:\WINDOWS\LBBHO.DLL - {A303DCA0-0F06-11D9-A9A9-444553540000} - C:\WINDOWS\LBBHO.DLL
 O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet6_38.dll
 O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\NEM220.DLL
 O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\WSEM303.DLL
 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
 O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
 O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
 O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
 O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
 O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe
 O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
 O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
 O4 - HKLM\..\Run: [Zasobnik systemowy] SysTray.Exe
 O4 - HKLM\..\Run: [Kernel32] C:\WINDOWS\SYSTEM\Kernel.dll
 O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
 O4 - HKLM\..\Run: [wxcpit] C:\WINDOWS\wxcpit.exe
 O4 - HKLM\..\Run: [05akoi4u] C:\WINDOWS\SYSTEM\05akoi4u.exe
 O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
 O4 - HKLM\..\Run: [Media Gateway] C:\PROGRAM FILES\MEDIA GATEWAY\MEDIAGATEWAY.EXE
 O4 - HKLM\..\Run: [Peuvzpc] C:\PROGRAM FILES\AJZGGMS\YMVSGU.EXE
 O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
 O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
 O4 - HKCU\..\Run: [Gadu-Gadu] "C:\PROGRAM FILES\GADU-GADU\GG.EXE" /tray
 O4 - HKCU\..\Run: [Komunikator] C:\PROGRAM FILES\TLEN.PL\TLEN.EXE
 O4 - Startup: FOLDER.HTT
 O4 - Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
 O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
 O4 - Global Startup: FOLDER.HTT
 O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
 O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
 O10 - Hijacked Internet access by New.Net
 O10 - Hijacked Internet access by New.Net
 O10 - Hijacked Internet access by New.Net
 O10 - Hijacked Internet access by New.Net
 O10 - Hijacked Internet access by New.Net
 O16 - DPF: {261EE805-4893-45A3-8E9E-AD90914CB39A} (VacPro.internazionale_98_ver11) - http://www9.advnt01.com/dialer/internazionale_98_ver11.CAB


 
	
 
 