Dodaj do ulubionych

pomocy!!dialer-jak sie go pozbyc??????????????????

IP: *.net.pl / 62.148.88.* 08.01.05, 16:20
ilekroc go usune uruchamia sie znowu !!!!przeskanowalam dysk programem spybot
i wiekszosc "syfu" zostala usunieta ale ten dialer ciagle wraca!!!!bardzo
prosze o pomoc.....
Obserwuj wątek
    • Gość: piecyk gazowy Re: pomocy!!dialer-jak sie go pozbyc????????????? IP: *.tpnet.pl / *.tpnet.pl 08.01.05, 17:45
      forum.gazeta.pl/forum/72,2.html?f=430&w=19211751&a=19235610
      • Gość: yhy Re: pomocy!!dialer-jak sie go pozbyc????????????? IP: *.net.pl / 62.148.88.* 08.01.05, 18:19
        Logfile of HijackThis v1.99.0
        Scan saved at 18:19:27, on 2005-01-08
        Platform: Windows ME (Win9x 4.90.3000)
        MSIE: Internet Explorer v5.50 (5.50.4134.0100)

        Running processes:
        C:\WINDOWS\SYSTEM\KERNEL32.DLL
        C:\WINDOWS\SYSTEM\MSGSRV32.EXE
        C:\WINDOWS\SYSTEM\SPOOL32.EXE
        C:\WINDOWS\SYSTEM\MPREXE.EXE
        C:\WINDOWS\SYSTEM\MSTASK.EXE
        C:\WINDOWS\SYSTEM\mmtask.tsk
        C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
        C:\WINDOWS\EXPLORER.EXE
        C:\WINDOWS\RUNDLL32.EXE
        C:\WINDOWS\SYSTEM\INTERNAT.EXE
        C:\WINDOWS\TASKMON.EXE
        C:\WINDOWS\SYSTEM\SYSTRAY.EXE
        C:\WINDOWS\SYSTEM\CMD32.EXE
        C:\PROGRAM FILES\DESKAD SERVICE\DESKADSERV.EXE
        C:\PROGRAM FILES\180SOLUTIONS\SAIS.EXE
        C:\WINDOWS\SYSTEM\FPPDIS2A.EXE
        C:\PROGRAM FILES\GADU-GADU\GG.EXE
        C:\WINDOWS\DANE APLIKACJI\MMDE.EXE
        C:\WINDOWS\SYSTEM\XEXWSIKX.EXE
        C:\PROGRAM FILES\DESKAD SERVICE\DESKADKEEP.EXE
        C:\PROGRAM FILES\D-LINK AIRPLUS\AIRPLUS.EXE
        C:\WINDOWS\SYSTEM\WMIEXE.EXE
        C:\WINDOWS\SYSTEM\TAPISRV.EXE
        C:\WINDOWS\SYSTEM\IZXCZXCR.EXE
        C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
        C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
        C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
        C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
        C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
        C:\WINDOWS\TEMP\SA3311.TMP.EXE
        C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
        C:\WINDOWS\SYSTEM\RNAAPP.EXE
        C:\WINDOWS\SYSTEM\DDHELP.EXE
        C:\WINDOWS\PULPIT\HIJACKTHIS.EXE

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
        about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
        about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
        about:NavigationFailure
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
        about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        about:NavigationFailure
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        about:NavigationFailure
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
        R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no
        file)
        O1 - Hosts: 69.20.16.183 ieautosearch
        O1 - Hosts: 69.20.16.183 ieautosearch
        O1 - Hosts: 69.20.16.183 ieautosearch
        O1 - Hosts: 69.20.16.183 search.netscape.com
        O1 - Hosts: 69.20.16.183 auto.search.msn.com
        O1 - Hosts: 69.20.16.183 ieautosearch
        O2 - BHO: (no name) - {952747F3-36C3-4757-B006-C40DD7D3F5FB} -
        C:\WINDOWS\SYSTEM\BDOJFD.DLL
        O3 - Toolbar: @msdxmLC.dll,-1@1045,&Radio - {8E718888-423F-11D2-876E-
        00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
        O3 - Toolbar: (no name) - {7DBCACBE-AD3A-442D-AEA9-7D36D7453AC6} - (no file)
        O4 - HKLM\..\Run: [internat.exe] internat.exe
        O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
        O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
        O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
        O4 - HKLM\..\Run: [Windows Millennium Edition Intro Video] C:\WINDOWS\Applic~1
        \Micros~1\Intro\content.hta
        O4 - HKLM\..\Run: [SelfHostUtil] C:\WINDOWS\selfhost.exe /L
        O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
        O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe
        powrprof.dll,LoadCurrentPwrScheme
        O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye
        Network\bin\bargains.exe
        O4 - HKLM\..\Run: [RegisterDropHandler] C:\Program
        Files\ScannerU\TBRIDGE\BIN\RegisterDropHandler.exe
        O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\SYSTEM\cmd32.exe
        internat.dll,LoadKeyboardProfile
        O4 - HKLM\..\Run: [DeskAd Service] C:\PROGRAM FILES\DESKAD
        SERVICE\DESKADSERV.EXE
        O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
        O4 - HKLM\..\Run: [ezalct] C:\WINDOWS\ezalct.exe
        O4 - HKLM\..\Run: [Tsl] C:\PROGRA~1\COMMON~1\TSA\tsl.exe
        O4 - HKLM\..\RunServices: [HiberMonitor] C:\WINDOWS\HCount.exe
        O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe
        powrprof.dll,LoadCurrentPwrScheme
        O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
        O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
        O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\Program
        Files\ScannerU\TBRIDGE\BIN\RegisterDropHandler.exe
        O4 - HKCU\..\Run: [pdfFactory Pro Dispatcher v2] C:\WINDOWS\SYSTEM\fppdis2a.exe
        O4 - HKCU\..\Run: [Gadu-Gadu] "C:\PROGRAM FILES\GADU-GADU\GG.EXE" /tray
        O4 - HKCU\..\Run: [Cdwt] C:\WINDOWS\Dane aplikacji\mmde.exe
        O4 - HKCU\..\Run: [Nscw] C:\WINDOWS\SYSTEM\xexwsikx.exe
        O4 - HKCU\..\Run: [Spyware Begone] C:\FREESCAN\FREESCAN.EXE -FastScan
        O4 - Startup: D-Link AirPlus.lnk = C:\Program Files\D-Link AirPlus\AirPlus.exe
        O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10
        \OSA.EXE
        O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
        res://C:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
        O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
        C:\WINDOWS\web\related.htm
        O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-
        00aa003c157a} - C:\WINDOWS\web\related.htm
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
        C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
        O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-
        00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
        O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} -
        C:\PROGRAM FILES\SIDEFIND\SIDEFIND.DLL (file missing)
        O15 - Trusted Zone: *.windupdates.com
        O15 - Trusted Zone: *.searchmiracle.com
        O15 - Trusted Zone: *.searchbarcash.com
        O15 - Trusted Zone: *.skoobidoo.com
        O15 - Trusted Zone: *.my-internet.info
        O15 - Trusted Zone: *.flingstone.com
        O15 - Trusted Zone: *.mt-download.com
        O15 - Trusted Zone: *.clickspring.net
        O15 - Trusted Zone: *.ysbweb.com
        O15 - Trusted Zone: *.slotchbar.com
        O15 - Trusted Zone: *.slotch.com
        O15 - Trusted Zone: *.xxxtoolbar.com
        O15 - Trusted Zone: *.blazefind.com
        O15 - Trusted Zone: *.windupdates.com (HKLM)
        O15 - Trusted Zone: *.searchbarcash.com (HKLM)
        O15 - Trusted Zone: *.searchmiracle.com (HKLM)
        O15 - Trusted Zone: *.skoobidoo.com (HKLM)
        O15 - Trusted Zone: *.my-internet.info (HKLM)
        O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
        O15 - Trusted Zone: *.slotch.com (HKLM)
        O15 - Trusted Zone: *.flingstone.com (HKLM)
        O15 - Trusted Zone: *.mt-download.com (HKLM)
        O15 - Trusted Zone: *.blazefind.com (HKLM)
        O15 - Trusted Zone: *.clickspring.net (HKLM)
        O15 - Trusted Zone: *.ysbweb.com (HKLM)
        O15 - Trusted Zone: *.slotchbar.com (HKLM)
        O15 - Trusted IP range: 67.19.185.246
        O15 - Trusted IP range: 67.19.185.246 (HKLM)
        O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) -
        67.19.185.246/i/8/loader2.ocx
        O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller
        Control) - www.mt-download.com/MediaTicketsInstaller.cab?refid=3548
        O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
        static.windupdates.com/cab/ClickYesToContinue/ie/bridge-c18.cab
        O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) -
        www.xxxtoolbar.com/ist/softwares/v4.0/0006_adult.cab
        O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = 123
        O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer =
        195.114.161.61,195.114.181.131
        O18 - Filter: text/html - {83507693-21BE-453A-857D-E06CB6D886FE} -
        C:\WINDOWS\SYSTEM\BDOJFD.DLL
        O18 - Filter: text/plain - {83507693-21BE-453A-857D-E06CB6D886FE} -
        C:\WINDOWS\SYSTEM\BDOJFD.DLL
        • Gość: piecyk gazowy Re: pomocy!!dialer-jak sie go pozbyc????????????? IP: *.tpnet.pl / *.tpnet.pl 08.01.05, 18:48
          Będzie ciężko. Wejdź najpierw do Panelu sterowania -> Dodaj/usuń programy i
          odinstaluj (jeśli się da):
          - BullsEye Network,
          - 180solutions,
          - DESKAD SERVICE.

          Potem w HijackThis zaznacz poniższe pozycje i wciśnij Fix Checked:

          > R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
          > about:NavigationFailure
          > R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
          > about:NavigationFailure
          > R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
          > about:NavigationFailure
          > R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
          > about:NavigationFailure
          > R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          > about:NavigationFailure
          > R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          > about:NavigationFailure
          > R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
          > R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

          > R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no
          > file)
          > O1 - Hosts: 69.20.16.183 ieautosearch
          > O1 - Hosts: 69.20.16.183 ieautosearch
          > O1 - Hosts: 69.20.16.183 ieautosearch
          > O1 - Hosts: 69.20.16.183 search.netscape.com
          > O1 - Hosts: 69.20.16.183 auto.search.msn.com
          > O1 - Hosts: 69.20.16.183 ieautosearch
          > O2 - BHO: (no name) - {952747F3-36C3-4757-B006-C40DD7D3F5FB} -
          > C:\WINDOWS\SYSTEM\BDOJFD.DLL
          > O3 - Toolbar: @msdxmLC.dll,-1@1045,&Radio - {8E718888-423F-11D2-876E-
          > 00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
          > O3 - Toolbar: (no name) - {7DBCACBE-AD3A-442D-AEA9-7D36D7453AC6} - (no file)

          > O4 - HKLM\..\Run: [Windows Millennium Edition Intro Video] C:\WINDOWS\Applic~1
          > \Micros~1\Intro\content.hta
          > O4 - HKLM\..\Run: [SelfHostUtil] C:\WINDOWS\selfhost.exe /L

          > O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye
          > Network\bin\bargains.exe

          > O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\SYSTEM\cmd32.exe
          > internat.dll,LoadKeyboardProfile
          > O4 - HKLM\..\Run: [DeskAd Service] C:\PROGRAM FILES\DESKAD
          > SERVICE\DESKADSERV.EXE
          > O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
          > O4 - HKLM\..\Run: [ezalct] C:\WINDOWS\ezalct.exe
          > O4 - HKLM\..\Run: [Tsl] C:\PROGRA~1\COMMON~1\TSA\tsl.exe
          > O4 - HKLM\..\RunServices: [HiberMonitor] C:\WINDOWS\HCount.exe

          > O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\Program
          > Files\ScannerU\TBRIDGE\BIN\RegisterDropHandler.exe
          > O4 - HKCU\..\Run: [pdfFactory Pro Dispatcher v2]
          C:\WINDOWS\SYSTEM\fppdis2a.exe

          > O4 - HKCU\..\Run: [Cdwt] C:\WINDOWS\Dane aplikacji\mmde.exe
          > O4 - HKCU\..\Run: [Nscw] C:\WINDOWS\SYSTEM\xexwsikx.exe
          > O4 - HKCU\..\Run: [Spyware Begone] C:\FREESCAN\FREESCAN.EXE -FastScan

          > O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} -
          > C:\PROGRAM FILES\SIDEFIND\SIDEFIND.DLL (file missing)
          > O15 - Trusted Zone: *.windupdates.com
          > O15 - Trusted Zone: *.searchmiracle.com
          > O15 - Trusted Zone: *.searchbarcash.com
          > O15 - Trusted Zone: *.skoobidoo.com
          > O15 - Trusted Zone: *.my-internet.info
          > O15 - Trusted Zone: *.flingstone.com
          > O15 - Trusted Zone: *.mt-download.com
          > O15 - Trusted Zone: *.clickspring.net
          > O15 - Trusted Zone: *.ysbweb.com
          > O15 - Trusted Zone: *.slotchbar.com
          > O15 - Trusted Zone: *.slotch.com
          > O15 - Trusted Zone: *.xxxtoolbar.com
          > O15 - Trusted Zone: *.blazefind.com
          > O15 - Trusted Zone: *.windupdates.com (HKLM)
          > O15 - Trusted Zone: *.searchbarcash.com (HKLM)
          > O15 - Trusted Zone: *.searchmiracle.com (HKLM)
          > O15 - Trusted Zone: *.skoobidoo.com (HKLM)
          > O15 - Trusted Zone: *.my-internet.info (HKLM)
          > O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
          > O15 - Trusted Zone: *.slotch.com (HKLM)
          > O15 - Trusted Zone: *.flingstone.com (HKLM)
          > O15 - Trusted Zone: *.mt-download.com (HKLM)
          > O15 - Trusted Zone: *.blazefind.com (HKLM)
          > O15 - Trusted Zone: *.clickspring.net (HKLM)
          > O15 - Trusted Zone: *.ysbweb.com (HKLM)
          > O15 - Trusted Zone: *.slotchbar.com (HKLM)
          > O15 - Trusted IP range: 67.19.185.246
          > O15 - Trusted IP range: 67.19.185.246 (HKLM)
          > O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) -
          > 67.19.185.246/i/8/loader2.ocx
          > O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller
          > Control) - www.mt-download.com/MediaTicketsInstaller.cab?refid=3548
          > O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
          > static.windupdates.com/cab/ClickYesToContinue/ie/bridge-c18.cab
          > O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) -
          > www.xxxtoolbar.com/ist/softwares/v4.0/0006_adult.cab

          > O18 - Filter: text/html - {83507693-21BE-453A-857D-E06CB6D886FE} -
          > C:\WINDOWS\SYSTEM\BDOJFD.DLL
          > O18 - Filter: text/plain - {83507693-21BE-453A-857D-E06CB6D886FE} -
          > C:\WINDOWS\SYSTEM\BDOJFD.DLL
          • Gość: p Re: pomocy!!dialer-jak sie go pozbyc????????????? IP: *.tpnet.pl / *.tpnet.pl 08.01.05, 18:53
          • Gość: piecyk gazowy Re: pomocy!!dialer-jak sie go pozbyc????????????? IP: *.tpnet.pl / *.tpnet.pl 08.01.05, 18:53
            www.searchengines.pl/phpbb203/index.php?showtopic=12510&st=0&p=109496&#entry109496
          • Gość: yhy Re: pomocy!!dialer-jak sie go pozbyc????????????? IP: *.net.pl / 62.148.88.* 08.01.05, 19:39
            zrobilam tak ale po ponownym wlaczeniu kompa:
            Logfile of HijackThis v1.99.0
            Scan saved at 19:37:14, on 2005-01-08
            Platform: Windows ME (Win9x 4.90.3000)
            MSIE: Internet Explorer v5.50 (5.50.4134.0100)

            Running processes:
            C:\WINDOWS\SYSTEM\KERNEL32.DLL
            C:\WINDOWS\SYSTEM\MSGSRV32.EXE
            C:\WINDOWS\SYSTEM\mmtask.tsk
            C:\WINDOWS\SYSTEM\MPREXE.EXE
            C:\WINDOWS\SYSTEM\MSTASK.EXE
            C:\WINDOWS\EXPLORER.EXE
            C:\WINDOWS\RUNDLL32.EXE
            C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
            C:\WINDOWS\SYSTEM\CMD32.EXE
            C:\PROGRAM FILES\DESKAD SERVICE\DESKADSERV.EXE
            C:\PROGRAM FILES\GADU-GADU\GG.EXE
            C:\WINDOWS\DANE APLIKACJI\MMDE.EXE
            C:\PROGRAM FILES\DESKAD SERVICE\DESKADKEEP.EXE
            C:\PROGRAM FILES\D-LINK AIRPLUS\AIRPLUS.EXE
            C:\WINDOWS\SYSTEM\IZXCZXCR.EXE
            C:\WINDOWS\SYSTEM\RNAAPP.EXE
            C:\WINDOWS\SYSTEM\TAPISRV.EXE
            C:\WINDOWS\PULPIT\HIJACKTHIS.EXE

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
            file://C:\WINDOWS\TEMP\sp.html
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
            file://C:\WINDOWS\TEMP\sp.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
            file://C:\WINDOWS\TEMP\sp.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
            file://C:\WINDOWS\TEMP\sp.html
            R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            file://C:\WINDOWS\TEMP\sp.html
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            file://C:\WINDOWS\TEMP\sp.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
            O1 - Hosts: 69.20.16.183 ieautosearch
            O1 - Hosts: 69.20.16.183 auto.search.msn.com
            O1 - Hosts: 69.20.16.183 search.netscape.com
            O2 - BHO: (no name) - {87DBABFF-CDB0-44EA-9F90-84902BF0CC81} -
            C:\WINDOWS\SYSTEM\ODJCBAA.DLL
            O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
            O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe
            powrprof.dll,LoadCurrentPwrScheme
            O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\SYSTEM\cmd32.exe
            internat.dll,LoadKeyboardProfile
            O4 - HKLM\..\Run: [DeskAd Service] C:\PROGRAM FILES\DESKAD
            SERVICE\DESKADSERV.EXE
            O4 - HKLM\..\RunServices: [HiberMonitor] C:\WINDOWS\HCount.exe
            O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe
            powrprof.dll,LoadCurrentPwrScheme
            O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
            O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
            O4 - HKCU\..\Run: [Gadu-Gadu] "C:\PROGRAM FILES\GADU-GADU\GG.EXE" /tray
            O4 - HKCU\..\Run: [Cdwt] C:\WINDOWS\Dane aplikacji\mmde.exe
            O4 - HKCU\..\RunServices: [Gadu-Gadu] "C:\PROGRAM FILES\GADU-GADU\GG.EXE" /tray
            O4 - HKCU\..\RunServices: [Cdwt] C:\WINDOWS\Dane aplikacji\mmde.exe
            O4 - Startup: D-Link AirPlus.lnk = C:\Program Files\D-Link AirPlus\AirPlus.exe
            O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10
            \OSA.EXE
            O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
            res://C:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
            O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
            C:\WINDOWS\web\related.htm
            O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-
            00aa003c157a} - C:\WINDOWS\web\related.htm
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
            C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
            O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-
            00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
            O15 - Trusted Zone: *.windupdates.com
            O15 - Trusted Zone: *.searchmiracle.com
            O15 - Trusted Zone: *.searchbarcash.com
            O15 - Trusted Zone: *.skoobidoo.com
            O15 - Trusted Zone: *.my-internet.info
            O15 - Trusted Zone: *.xxxtoolbar.com
            O15 - Trusted Zone: *.slotch.com
            O15 - Trusted Zone: *.flingstone.com
            O15 - Trusted Zone: *.mt-download.com
            O15 - Trusted Zone: *.blazefind.com
            O15 - Trusted Zone: *.clickspring.net
            O15 - Trusted Zone: *.ysbweb.com
            O15 - Trusted Zone: *.slotchbar.com
            O15 - Trusted Zone: *.windupdates.com (HKLM)
            O15 - Trusted Zone: *.searchbarcash.com (HKLM)
            O15 - Trusted Zone: *.searchmiracle.com (HKLM)
            O15 - Trusted Zone: *.skoobidoo.com (HKLM)
            O15 - Trusted Zone: *.my-internet.info (HKLM)
            O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
            O15 - Trusted Zone: *.slotch.com (HKLM)
            O15 - Trusted Zone: *.flingstone.com (HKLM)
            O15 - Trusted Zone: *.mt-download.com (HKLM)
            O15 - Trusted Zone: *.blazefind.com (HKLM)
            O15 - Trusted Zone: *.clickspring.net (HKLM)
            O15 - Trusted Zone: *.ysbweb.com (HKLM)
            O15 - Trusted Zone: *.slotchbar.com (HKLM)
            O15 - Trusted IP range: 67.19.185.246
            O15 - Trusted IP range: 67.19.185.246 (HKLM)
            O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) -
            www.xxxtoolbar.com/ist/softwares/v4.0/0006_adult.cab
            O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
            static.windupdates.com/cab/ClickYesToContinue/ie/bridge-c18.cab
            O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) -
            67.19.185.246/i/8/loader2.ocx
            O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller
            Control) - www.mt-download.com/MediaTicketsInstaller.cab?refid=3548
            O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = 123
            O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer =
            195.114.161.61,195.114.181.131
            O18 - Filter: text/html - {506FA66D-1473-4FBC-864C-61331F5BE69F} -
            C:\WINDOWS\SYSTEM\ODJCBAA.DLL
            O18 - Filter: text/plain - {506FA66D-1473-4FBC-864C-61331F5BE69F} -
            C:\WINDOWS\SYSTEM\ODJCBAA.DLL


            a to wynik po skanowaniu SpyBot:
            ISTbar.Slotch: Tracking cookie (Internet Explorer: KASIA) (Cookie, nothing done)


            Common hijacker: Przeadresowanie hosta (Przeadresowanie hosta, nothing done)


            Common hijacker: Przeadresowanie hosta (Przeadresowanie hosta, nothing done)


            DSO Exploit: Data source object exploit (Zmiany rejestru, nothing done)
            HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet
            Settings\Zones\0\1004!=W=3

            IGetNet: Przeadresowanie hosta (Przeadresowanie hosta, nothing done)


            TIBS: Program directory (Katalog, nothing done)
            C:\Program Files\WebSiteViewer\

            TIBS: User settings (Klucz rejestru, nothing done)
            HKEY_USERS\.DEFAULT\Software\WebSiteViewer

            WebDialer: Settings (Dane rejestru, nothing done)
            HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\HOMEOldSP


            -
            • Gość: piecyk gazowy Re: pomocy!!dialer-jak sie go pozbyc????????????? IP: *.tpnet.pl / *.tpnet.pl 08.01.05, 19:55
              Spróbuj tym przy zamkniętej przeglądarce:
              cwshredder.net/bin/CWSInstall.exe
              • Gość: yhy Re: pomocy!!dialer-jak sie go pozbyc????????????? IP: *.net.pl / 62.148.88.* 08.01.05, 22:11
                naprawde nie da sie z tym nic wiecej
                zrobic????????????????????????????????????????????????????????????????
            • Gość: piecyk gazowy SpyBot IP: *.tpnet.pl / *.tpnet.pl 08.01.05, 19:56
              A w SpyBot nie możesz tego usuąć?
              • Gość: yhy Re: SpyBot IP: *.net.pl / 62.148.88.* 08.01.05, 20:08
                cwshreder pisze ze nic nie wykryl a w SpyBot niby to sie usuwa ale po ponownym
                wlaczniu kompa wszystko wraca!!
                • Gość: piecyk gazowy Re: SpyBot IP: *.tpnet.pl / *.tpnet.pl 08.01.05, 22:17
                  Spróbuj wyłączyć przywracanie systemu
                  www.gdata.pl/pl/support/avk12_pyt7.html
                  i przeskanuj jeszcze raz.
                  • Gość: yhy Re: SpyBot IP: *.net.pl / 62.148.88.* 08.01.05, 22:38
                    mialam juz to wylaczone wczesniej....:/
    • Gość: yhy Re: pomocy!!dialer-jak sie go pozbyc????????????? IP: *.net.pl / 62.148.88.* 08.01.05, 18:32
      i cio mam teraz z tym zrobic???????pomocyyyy;]
      • Gość: Toudi Re: pomocy!!dialer-jak sie go pozbyc????????????? IP: *.neoplus.adsl.tpnet.pl 08.01.05, 22:15
        Ja mam identytczny problem, Panda 2005 i Konektor TP nic nie wykrywają a w Dial-
        Upie non stop mi się zmienia numer dostępowy! Pozostaje mi tylko format.
        • Gość: piecyk gazowy @Toudi IP: *.tpnet.pl / *.tpnet.pl 09.01.05, 14:31
          forum.gazeta.pl/forum/72,2.html?f=299&w=19028470
    • Gość: fdsa Re: pomocy!!dialer-jak sie go pozbyc????????????? IP: *.katowice.msk.pl / 62.233.244.* 09.01.05, 19:35
      znasz nazwę? Nie da się go wywalić z rejestru?? (start-uruchom-"regedit" -
      znajdź - usuwasz wpis) Tylko przedtem zrób kopię rejestru !!!!!!! (eksportuj
      rejestr)

      A firewall??
      Może Zone Alarm go wykryje i nie pozwoli na przełączenie? (www.zonelabs.com -
      bodajże)

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka