
zaczne od tego ze jestem dopiero uzytkownikiem kompa dlatego prosze o wyrozumialosc
 . "Mily" pan wyslal mi na gadu-gadu link do stronki no i ja go otworzylam...wiem, glupia d... ze mnie no ale na bledach trzeba sie uczyc.
. "Mily" pan wyslal mi na gadu-gadu link do stronki no i ja go otworzylam...wiem, glupia d... ze mnie no ale na bledach trzeba sie uczyc.
a oto moj log
- Kod: Zaznacz wszystko
- Logfile of HijackThis v1.99.1
 Scan saved at 16:51:32, on 2005-11-11
 Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\AVPersonal\AVGUARD.EXE
 C:\Program Files\AVPersonal\AVWUPSRV.EXE
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Program Files\Winamp\winampa.exe
 C:\PROGRA~1\NEOSTR~1\CnxMon.exe
 C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
 C:\Program Files\AVPersonal\AVGNT.EXE
 C:\windows\system32\mdms.exe
 C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
 C:\WINDOWS\system32\paytime.exe
 C:\WINDOWS\system32\RUNDLL32.EXE
 C:\winstall.exe
 C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
 C:\WINDOWS\tool2.exe
 C:\Program Files\OpenOffice.org1.1.3\program\soffice.exe
 C:\PROGRA~1\NEOSTR~1\NeostradaTP.exe
 C:\PROGRA~1\NEOSTR~1\ComComp.exe
 C:\PROGRA~1\NEOSTR~1\Watch.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
 C:\WINDOWS\system32\sysvcs.exe
 C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
 C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
 C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
 C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
 C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
 C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
 C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
 C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
 C:\WINDOWS\explorer.exe
 C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
 C:\DOCUME~1\aa\USTAWI~1\Temp\Katalog tymczasowy 1 dla hijackthis.zip\HijackThis.exe
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada TP
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
 R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL
 F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
 O1 - Hosts: 127.0.0.5 n-glx.s-redirect.com
 O1 - Hosts: 127.0.0.5 x.full-tgp.net
 O1 - Hosts: 127.0.0.5 counter.cenzura-spam.com
 O1 - Hosts: 127.0.0.5 autoescrowpay.com
 O1 - Hosts: 127.0.0.5 www.autoescrowpay.com
 O1 - Hosts: 127.0.0.5 www.awmdabest.com
 O1 - Hosts: 127.0.0.5 www.cenzura-spam.nu
 O1 - Hosts: 127.0.0.5 awmdabest.com
 O1 - Hosts: 127.0.0.5 cenzura-spam.nu
 O1 - Hosts: 127.0.0.5 allforadult.com
 O1 - Hosts: 127.0.0.5 www.allforadult.com
 O1 - Hosts: 127.0.0.5 www.iframe.biz
 O1 - Hosts: 127.0.0.5 iframe.biz
 O1 - Hosts: 127.0.0.5 www.newiframe.biz
 O1 - Hosts: 127.0.0.5 newiframe.biz
 O1 - Hosts: 127.0.0.5 www.vesbiz.biz
 O1 - Hosts: 127.0.0.5 vesbiz.biz
 O1 - Hosts: 127.0.0.5 www.cenzura!.biz
 O1 - Hosts: 127.0.0.5 cenzura!.biz
 O1 - Hosts: 127.0.0.5 www.awmcash.biz
 O1 - Hosts: 127.0.0.5 awmcash.biz
 O1 - Hosts: 127.0.0.5 buldog-stats.com
 O1 - Hosts: 127.0.0.5 www.buldog-stats.com
 O1 - Hosts: 127.0.0.5 fregat.drocherway.com
 O1 - Hosts: 127.0.0.5 slutmania.biz
 O1 - Hosts: 127.0.0.5 www.slutmania.biz
 O1 - Hosts: 127.0.0.5 toolbarpartner.com
 O1 - Hosts: 127.0.0.5 www.toolbarpartner.com
 O1 - Hosts: 127.0.0.5 www.megapornix.com
 O1 - Hosts: 127.0.0.5 megapornix.com
 O1 - Hosts: 127.0.0.5 www.sp2fucked.biz
 O1 - Hosts: 127.0.0.5 sp2fucked.biz
 O1 - Hosts: 127.0.0.5 greg-tut.com
 O1 - Hosts: 127.0.0.5 www.greg-tut.com
 O1 - Hosts: 127.0.0.5 nylonsexy.com
 O1 - Hosts: 127.0.0.5 www.nylonsexy.com
 O1 - Hosts: 127.0.0.5 vparivalka.com
 O1 - Hosts: 127.0.0.5 www.vparivalka.com
 O1 - Hosts: 127.0.0.5 iframeprofit.com
 O1 - Hosts: 127.0.0.5 www.iframeprofit.com
 O1 - Hosts: 127.0.0.5 topsearch10.com
 O1 - Hosts: 127.0.0.5 www.topsearch10.com
 O1 - Hosts: 127.0.0.5 statscash.biz
 O1 - Hosts: 127.0.0.5 www.statscash.biz
 O1 - Hosts: 127.0.0.5 vxiframe.biz
 O1 - Hosts: 127.0.0.5 www.vxiframe.biz
 O1 - Hosts: 127.0.0.5 crazy-toolbar.com
 O1 - Hosts: 127.0.0.5 www.crazy-toolbar.com
 O1 - Hosts: 127.0.0.5 topcash.biz
 O1 - Hosts: 127.0.0.5 www.topcash.biz
 O1 - Hosts: 127.0.0.5 loadcash.biz
 O1 - Hosts: 127.0.0.5 www.loadcash.biz
 O1 - Hosts: 127.0.0.5 txiframe.biz
 O1 - Hosts: 127.0.0.5 www.txiframe.biz
 O1 - Hosts: 127.0.0.5 procounter.biz
 O1 - Hosts: 127.0.0.5 www.procounter.biz
 O1 - Hosts: 127.0.0.5 advadmin.biz
 O1 - Hosts: 127.0.0.5 www.advadmin.biz
 O1 - Hosts: 127.0.0.5 trafficbest.net
 O1 - Hosts: 127.0.0.5 www.trafficbest.net
 O1 - Hosts: 127.0.0.5 besthvac.com
 O1 - Hosts: 127.0.0.5 www.besthvac.com
 O1 - Hosts: 127.0.0.5 traff4.com
 O1 - Hosts: 127.0.0.5 www.traff4.com
 O1 - Hosts: 127.0.0.5 ambush-script.com
 O1 - Hosts: 127.0.0.5 www.ambush-script.com
 O1 - Hosts: 127.0.0.5 beehappyy.biz
 O1 - Hosts: 127.0.0.5 www.beehappyy.biz
 O1 - Hosts: 127.0.0.5 tracktraff.cc
 O1 - Hosts: 127.0.0.5 www.tracktraff.cc
 O1 - Hosts: 127.0.0.5 allcount.net
 O1 - Hosts: 127.0.0.5 www.allcount.net
 O1 - Hosts: 127.0.0.5 onedayoffer.biz
 O1 - Hosts: 127.0.0.5 www.onedayoffer.biz
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
 O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
 O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\NEOSTR~1\CnxMon.exe
 O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe
 O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
 O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
 O4 - HKLM\..\Run: [SysMemory manager] c:\windows\system32\mdms.exe
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
 O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
 O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [aupd] C:\WINDOWS\system32\sysvcs.exe
 O4 - Startup: OpenOffice.org 1.1.3.lnk = C:\Program Files\OpenOffice.org1.1.3\program\quickstart.exe
 O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O17 - HKLM\System\CCS\Services\Tcpip\..\{6BAD17F9-3D68-40FE-9C32-07EFE9319907}: NameServer = 194.204.152.34 217.98.63.164
 O20 - Winlogon Notify: nuclabdll - C:\WINDOWS\SYSTEM32\nuclabdll.dll
 O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
 O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
bardzo prosze o pomoc
pozdrawiam

 
	
 
  
  
 
 po zabiegu nowe logi
  po zabiegu nowe logi