Dodaj do ulubionych

Chłopaki pomóżcie

IP: 217.153.84.* 23.03.05, 13:59
Mam chyba wirusa Start Page i nie mogę go usunąć. Jeśli chodzi o komputer jestem zupełnie zielona i proszę Was o pomoc. Czytałam na forum że trzeba wkleić jakiegoś loga więc go wklejam,tylko nie wiem czy dobrze to robię Mojego brata starszego nie ma i nie ma mi kto pomóc.

Oto log
Logfile of HijackThis v1.99.1
Scan saved at 13:53:51, on 2005-03-23
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\AVENGINE.EXE
C:\Program Files\Panda Software\Panda Antivirus Platinum\apvxdwin.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\pavProxy.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Opera\Opera.exe
C:\Documents and Settings\Krzysztof Komar\Pulpit\Ilona\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 0ml.net/cat
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = 1-se.com/srchasst.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\KRZYSZ~1\USTAWI~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.onet.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\KRZYSZ~1\USTAWI~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = ls0.net/srchasst.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = 0ml.net/searchasst.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = ls0.net/srchasst.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = 0ml.net/searchasst.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = 0ml.net/cat
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = 0ml.net/cat
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: (no name) - {0428FFC7-1931-45b7-95CB-3CBB919777E1} - (no file)
F3 - REG:win.ini: load=C:\YDPDict\watch.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet6_38.dll
O2 - BHO: (no name) - {5E2CC47F-E828-4759-8F2F-DEF2DB64FEAF} - C:\WINDOWS\system32\ogipl.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\system32\f98er24s8u.dll (file missing)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [Soundmx] \soundmx.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe
O4 - HKLM\..\Run: [Dial32] C:\WINDOWS\dl.exe
O4 - HKLM\..\Run: [Dial33] C:\WINDOWS\dlm.exe
O4 - HKLM\..\Run: [Upgrade Service] C:\WINDOWS\sxchost.exe
O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\fgnttimi.exe
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Antivirus Platinum\Inicio.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\KRZYSZ~1\USTAWI~1\Temp\se.dll,DllInstall
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Windows Internet Protocol] C:\WINDOWS\system32\winproc32.exe
O4 - HKCU\..\Run: [Spyware Begone] c:\freescan\freescan.exe -FastScan
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Web Search - C:\WINDOWS\ex.htm
O8 - Extra context menu item: Ściągnij przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_all.htm
O9 - Extra button: Microsoft® JavaScript® Console - {048FFF91-2D04-4DFB-B65A-444A8858C605} - C:\WINDOWS\System32\comdlg32.ocx
O9 - Extra 'Tools' menuitem: JavaScript Console - {048FFF91-2D04-4DFB-B65A-444A8858C605} - C:\WINDOWS\System32\comdlg32.ocx
O9 - Extra button: (no name) - {237AA178-C3BC-4f67-A8BB-D8BC14BA0B89} - C:\WINDOWS\System32\something.dll (file missing)
O9 - Extra button: (no name) - {869EE607-5376-486d-8DAC-EDC8E239AD5F} - C:\WINDOWS\System32\crt32_v2.dll
O9 - Extra button: (no name) - {BE2F2769-8A63-4bc7-8A99-06C2C4AD7B9B} - C:\WINDOWS\System32\crtv2_32.dll (file missing)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d
Obserwuj wątek
    • Gość: Kolobos Re: Chłopaki pomóżcie IP: *.warszawa.sdi.tpnet.pl 23.03.05, 14:03
      Nie zmiescil sie caly log, doklej brakujacy koniec.
      A co do Start Page to faktycznie masz to go powinno zalatwic:
      www.derbilk.de/SpSeHjfix_Beta7.zip
      Z tego co widze to masz tez innych "gosci" jak dokleisz log, to bedzie sie
      mozna nimi zajac, a najlepiej wklej nowy juz po uzyciu SpSeHjfix_Beta7
      • Gość: ania Re: Chłopaki pomóżcie IP: 217.153.84.* 23.03.05, 15:12
        wklejam to co poprzednio nie zostało wklejone

        O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra button: Microsoft® JavaScript® Console - {048FFF91-2D04-4DFB-B65A-444A8858C605} - C:\WINDOWS\System32\comdlg32.ocx (HKCU)
        O9 - Extra 'Tools' menuitem: JavaScript Console - {048FFF91-2D04-4DFB-B65A-444A8858C605} - C:\WINDOWS\System32\comdlg32.ocx (HKCU)
        O9 - Extra button: (no name) - {237AA178-C3BC-4f67-A8BB-D8BC14BA0B89} - C:\WINDOWS\System32\something.dll (file missing) (HKCU)
        O9 - Extra button: (no name) - {869EE607-5376-486d-8DAC-EDC8E239AD5F} - C:\WINDOWS\System32\crt32_v2.dll (HKCU)
        O9 - Extra button: (no name) - {BE2F2769-8A63-4bc7-8A99-06C2C4AD7B9B} - C:\WINDOWS\System32\crtv2_32.dll (file missing) (HKCU)
        O10 - Hijacked Internet access by New.Net
        O10 - Hijacked Internet access by New.Net
        O10 - Hijacked Internet access by New.Net
        O10 - Hijacked Internet access by New.Net
        O10 - Hijacked Internet access by New.Net
        O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
        O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
        O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
        O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - www.trojanscan.com/trojanscan/TDECntrl.CAB
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093250083027
        O16 - DPF: {67135BDA-6546-4426-BC94-BB5AF5005231} (GINCHECKERS Class) - gryonline.wp.pl/files/checkers_2_0_0_6.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - www.pandasoftware.com/activescan/as5/asinst.cab
        O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - www.ravantivirus.com/scan/ravonline.cab
        O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) - skaner.mks.com.pl/SkanerOnline.cab
        O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C4} (GINBILLARDT Class) - gryonline.wp.pl/files/billardt_2_0_0_6.cab
        O18 - Filter: text/html - {5B82B423-6747-49F3-B58C-11F6090E2EEA} - C:\WINDOWS\system32\ogipl.dll
        O18 - Filter: text/plain - {5B82B423-6747-49F3-B58C-11F6090E2EEA} - C:\WINDOWS\system32\ogipl.dll
        O20 - AppInit_DLLs: C:\WINDOWS\System32\sql.dll
        O21 - SSODL: Web Event Logger - {79FEACFF-FFCE-815E-A900-316290B5B738} - (no file)
        O23 - Service: Windows Update Service (muamgrd) - Unknown owner - C:\WINDOWS\System32\muamgrd.exe (file missing)
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
        O23 - Service: Panda Firewall Service (PAVFIRES) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
        O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe


        • Gość: Kolobos Re: Chłopaki pomóżcie IP: *.warszawa.sdi.tpnet.pl 23.03.05, 15:24
          Uzyj programu, ktory polecilem w poprzednim poscie, a co do loga to uruchom
          hijackthis i zaznacz te wpisy:

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
          0ml.net/cat
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = 1-
          se.com/srchasst.html
          (obfuscated)
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
          res://C:\DOCUME~1\KRZYSZ~1\USTAWI~1\Temp\se.dll/sp.html
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.onet.pl/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
          res://C:\DOCUME~1\KRZYSZ~1\USTAWI~1\Temp\se.dll/sp.html
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
          R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          about:blank
          R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          ls0.net/srchasst.html
          (obfuscated)
          R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) =
          0ml.net/searchasst.html
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          about:blank
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          ls0.net/srchasst.html
          (obfuscated)
          R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) =
          0ml.net/searchasst.html
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = 0ml.net/cat
          R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = 0ml.net/cat
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
          R3 - URLSearchHook: (no name) - {0428FFC7-1931-45b7-95CB-3CBB919777E1} - (no
          file)
          O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program
          Files\NewDotNet\newdotnet6_38.dll
          O2 - BHO: (no name) - {5E2CC47F-E828-4759-8F2F-DEF2DB64FEAF} -
          C:\WINDOWS\system32\ogipl.dll
          O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10000} -
          C:\WINDOWS\system32\f98er24s8u.dll (file missing)
          O4 - HKLM\..\Run: [Soundmx] \soundmx.exe
          To odinstaluj w dodaj-usun i zacznij uzywac jakiegos innego programu do p2p
          (eMule itp)
          O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P
          Networking.exe /AUTOSTART
          O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe
          O4 - HKLM\..\Run: [Dial32] C:\WINDOWS\dl.exe
          O4 - HKLM\..\Run: [Dial33] C:\WINDOWS\dlm.exe
          O4 - HKLM\..\Run: [Upgrade Service] C:\WINDOWS\sxchost.exe
          O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
          O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\fgnttimi.exe
          O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1
          \NEWDOT~1.DLL,NewDotNetStartup -s
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
          Files\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\KRZYSZ~1\USTAWI~1
          \Temp\se.dll,DllInstall
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [Windows Internet Protocol] C:\WINDOWS\system32\winproc32.exe
          Odinstaluj ten program w dodaj-usun:
          O4 - HKCU\..\Run: [Spyware Begone] c:\freescan\freescan.exe -FastScan
          O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
          Office\Office10\OSA.EXE
          O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
          res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
          O8 - Extra context menu item: Web Search - C:\WINDOWS\ex.htm
          O9 - Extra button: Microsoft® JavaScript® Console - {048FFF91-2D04-4DFB-B65A-
          444A8858C605} -
          C:\WINDOWS\System32\comdlg32.ocx
          O9 - Extra 'Tools' menuitem: JavaScript Console - {048FFF91-2D04-4DFB-B65A-
          444A8858C605} - C:\WINDOWS\System32\comdlg32.ocx
          O9 - Extra button: (no name) - {237AA178-C3BC-4f67-A8BB-D8BC14BA0B89} -
          C:\WINDOWS\System32\something.dll (file missing)
          O9 - Extra button: (no name) - {869EE607-5376-486d-8DAC-EDC8E239AD5F} -
          C:\WINDOWS\System32\crt32_v2.dll
          O9 - Extra button: (no name) - {BE2F2769-8A63-4bc7-8A99-06C2C4AD7B9B} -
          C:\WINDOWS\System32\crtv2_32.dll (file missing)
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
          C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-
          00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra button: Microsoft® JavaScript® Console - {048FFF91-2D04-4DFB-B65A-
          444A8858C605} -
          C:\WINDOWS\System32\comdlg32.ocx (HKCU)
          O9 - Extra 'Tools' menuitem: JavaScript Console - {048FFF91-2D04-4DFB-B65A-
          444A8858C605} - C:\WINDOWS\System32\comdlg32.ocx (HKCU)
          O9 - Extra button: (no name) - {237AA178-C3BC-4f67-A8BB-D8BC14BA0B89} -
          C:\WINDOWS\System32\something.dll (file missing) (HKCU)
          O9 - Extra button: (no name) - {869EE607-5376-486d-8DAC-EDC8E239AD5F} -
          C:\WINDOWS\System32\crt32_v2.dll (HKCU)
          O9 - Extra button: (no name) - {BE2F2769-8A63-4bc7-8A99-06C2C4AD7B9B} -
          C:\WINDOWS\System32\crtv2_32.dll (file missing) (HKCU)

          To ponizej napraw tym:
          www.cexx.org/LSPFix.exe
          O10 - Hijacked Internet access by New.Net
          O10 - Hijacked Internet access by New.Net
          O10 - Hijacked Internet access by New.Net
          O10 - Hijacked Internet access by New.Net
          O10 - Hijacked Internet access by New.Net
          O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
          O18 - Filter: text/html - {5B82B423-6747-49F3-B58C-11F6090E2EEA} -
          C:\WINDOWS\system32\ogipl.dll
          O18 - Filter: text/plain - {5B82B423-6747-49F3-B58C-11F6090E2EEA} -
          C:\WINDOWS\system32\ogipl.dll
          O20 - AppInit_DLLs: C:\WINDOWS\System32\sql.dll
          O21 - SSODL: Web Event Logger - {79FEACFF-FFCE-815E-A900-316290B5B738} - (no
          file)
          O23 - Service: Windows Update Service (muamgrd) - Unknown owner -
          C:\WINDOWS\System32\muamgrd.exe (file missing)

          I nacisnij Fix Checked, nastepnie uruchom ponownie komputer i wklej nowy log z
          hijackthis.
    • Gość: Ania Re: Chłopaki pomóżcie IP: 217.153.84.* 23.03.05, 15:17
      Kolobos dziękuję za pomoc, ale co mam zrobić z linkiem który mi podałeś .Tak jak mówiłam jestem z komputera zupełnie zielona
      • Gość: Kolobos Re: Chłopaki pomóżcie IP: *.warszawa.sdi.tpnet.pl 23.03.05, 15:26
        Muszisc sciagnac ten program, rozpakowac, uruchomic i nacisnac przycisk start
        disinfection
        Tak samo sciagnij LSPFix o ktorym napisalem tutaj:
        forum.gazeta.pl/forum/72,2.html?f=430&w=21999089&a=22003072
        I usun wpisy, ktore podalem :-)
        • netsec Re: Klobos, naprawa Winsock jest łatwiejsza :) 23.03.05, 16:11
          W przypadku systemu Windows XP z SP2 wytarczy do naprawy łańcucha Winsock
          przejść do menu 'START' wpisać w 'Uruchom' CMD kliknać OK.
          Dalej w oknie które się pojawi wpisujesz netsh winsock reset naciskasz ENTER.
          Po pojawianiu się napisu 'Pomyślnie zresetowano Winsock Catalog.
          Musisz ponownie uruchomi komputer, aby ukończyć resetowanie.'

          Restarujesz komp i tyle :)
        • Gość: Ania Re: Chłopaki pomóżcie IP: 217.153.84.* 23.03.05, 17:11
          Kolombos zrobiłam tak jak mówiłeś tylko nie wiem jak mam usunąc te wpisy tym programem LSPFix exe Należy może tego loga z Hijack wkleić do programu LSPFixi usunąć? Aha napisałes jeszcze żeby dwa wpisy z loga odinstalować ale jak to zrobić Oto log po tej operacji

          Logfile of HijackThis v1.99.1
          Scan saved at 16:57:48, on 2005-03-23
          Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\SYSTEM32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\ntvdm.exe
          C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE
          C:\Program Files\Winamp\winampa.exe
          C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
          C:\WINDOWS\system32\rundll32.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\WINDOWS\system32\RUNDLL32.EXE
          C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
          C:\WINDOWS\System32\nvsvc32.exe
          C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
          C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
          C:\Program Files\Panda Software\Panda Antivirus Platinum\AVENGINE.EXE
          C:\Program Files\Panda Software\Panda Antivirus Platinum\pavProxy.exe
          C:\Documents and Settings\Krzysztof Komar\Pulpit\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 0ml.net/cat
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.onet.pl/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
          R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
          R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = ls0.net/srchasst.html (obfuscated)
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = ls0.net/srchasst.html (obfuscated)
          F3 - REG:win.ini: load=C:\YDPDict\watch.exe
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
          O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
          O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
          O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
          O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Antivirus Platinum\Inicio.exe"
          O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE" /s
          O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
          O4 - HKLM\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
          O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s
          O4 - HKLM\..\Run: [Soundmx] \soundmx.exe
          O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
          O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe
          O4 - HKLM\..\Run: [Dial32] C:\WINDOWS\dl.exe
          O4 - HKLM\..\Run: [Dial33] C:\WINDOWS\dlm.exe
          O4 - HKLM\..\Run: [Upgrade Service] C:\WINDOWS\sxchost.exe
          O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
          O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\fgnttimi.exe
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\KRZYSZ~1\USTAWI~1\Temp\se.dll,DllInstall
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
          O4 - HKCU\..\Run: [Windows Internet Protocol] C:\WINDOWS\system32\winproc32.exe
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [Spyware Begone] c:\freescan\freescan.exe -FastScan
          O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
          O8 - Extra context menu item: Ściągnij przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_link.htm
          O8 - Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_all.htm
          O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
          O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
          O10 - Hijacked Internet access by New.Net
          O10 - Hijacked Internet access by New.Net
          O10 - Hijacked Internet access by New.Net
          O10 - Hijacked Internet access by New.Net
          O10 - Hijacked Internet access by New.Net
          O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
          O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
          O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
          O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - www.trojanscan.com/trojanscan/TDECntrl.CAB
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093250083027
          O16 - DPF: {67135BDA-6546-4426-BC94-BB5AF5005231} (GINCHECKERS Class) - gryonline.wp.pl/files/checkers_2_0_0_6.cab
          O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - www.pandasoftware.com/activescan/as5/asinst.cab
          O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - www.ravantivirus.com/scan/ravonline.cab
          O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) - skaner.mks.com.pl/SkanerOnline.cab
          O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C4} (GINBILLARDT Class) - gryonline.wp.pl/files/billardt_2_0_0_6.cab
          O18 - Filter: text/html - {D47A3C38-E797-4684-A040-0A505AA37C93} - C:\WINDOWS\system32\ogipl.dll
          O18 - Filter: text/plain - {D47A3C38-E797-4684-A040-0A505AA37C93} - C:\WINDOWS\system32\ogipl.dll
          O20 - AppInit_DLLs: C:\WINDOWS\System32\sql.dll
          O21 - SSODL: Web Event Logger - {79FEACFF-FFCE-815E-A900-316290B5B738} - (no file)
          O23 - Service: Windows Update Service (muamgrd) - Unknown owner - C:\WINDOWS\System32\muamgrd.exe (file missing)
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
          O23 - Service: Panda Firewall Service (PAVFIRES) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
          O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus Platin
          • Gość: Kolobos Re: Chłopaki pomóżcie IP: *.warszawa.sdi.tpnet.pl 23.03.05, 18:31
            Nie LSPFix to odzielny program, uruchom go i usun to co dotyczy newnet albo
            zrob tak jak napisal netsec:
            forum.gazeta.pl/forum/72,2.html?f=430&w=21999089&a=22004977
            Co do loga to jest lepiej ale dalej zostalo sporo, uruchom hijackthis i zaznacz
            te wpisy:

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
            0ml.net/cat
            R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            ls0.net/srchasst.html
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            ls0.net/srchasst.html
            O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1
            \NEWDOT~1.DLL,NewDotNetStartup -s
            O4 - HKLM\..\Run: [Soundmx] \soundmx.exe
            O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe
            O4 - HKLM\..\Run: [Dial32] C:\WINDOWS\dl.exe
            O4 - HKLM\..\Run: [Dial33] C:\WINDOWS\dlm.exe
            O4 - HKLM\..\Run: [Upgrade Service] C:\WINDOWS\sxchost.exe
            O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
            O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\fgnttimi.exe
            O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\KRZYSZ~1\USTAWI~1
            \Temp\se.dll,DllInstall
            O4 - HKCU\..\Run: [Windows Internet Protocol] C:\WINDOWS\system32\winproc32.exe
            Ten program odinstaluj, pisalem to juz wczesniej Panel Sterowania->Dodaj-Usun
            Programy, odszukaj go tam i odinstaluj:
            O4 - HKCU\..\Run: [Spyware Begone] c:\freescan\freescan.exe -FastScan
            O10 - Hijacked Internet access by New.Net <- juz napisalem na poczatku co z tym
            zrobic
            O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
            O18 - Filter: text/html - {D47A3C38-E797-4684-A040-0A505AA37C93} -
            C:\WINDOWS\system32\ogipl.dll
            O18 - Filter: text/plain - {D47A3C38-E797-4684-A040-0A505AA37C93} -
            C:\WINDOWS\system32\ogipl.dll
            O20 - AppInit_DLLs: C:\WINDOWS\System32\sql.dll
            O21 - SSODL: Web Event Logger - {79FEACFF-FFCE-815E-A900-316290B5B738} - (no
            file)
            O23 - Service: Windows Update Service (muamgrd) - Unknown owner -
            C:\WINDOWS\System32\muamgrd.exe (file missing)

            I Fix Checked, nastepnie uruchom ponownie i wklej nowy log, mam nadzieje, ze
            juz bedzie mniej ;-)
            • Gość: Ania Re: Chłopaki pomóżcie IP: 217.153.84.* 23.03.05, 19:18
              Nowy log
              Logfile of HijackThis v1.99.1
              Scan saved at 19:10:50, on 2005-03-23
              Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\SYSTEM32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\system32\ntvdm.exe
              C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE
              C:\Program Files\Winamp\winampa.exe
              C:\WINDOWS\system32\rundll32.exe
              C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
              C:\Program Files\Common Files\Real\Update_OB\realsched.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\WINDOWS\system32\RUNDLL32.EXE
              C:\Program Files\Messenger\msmsgs.exe
              C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
              C:\WINDOWS\System32\nvsvc32.exe
              C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
              C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
              C:\Program Files\Panda Software\Panda Antivirus Platinum\AVENGINE.EXE
              C:\Program Files\Panda Software\Panda Antivirus Platinum\pavProxy.exe
              C:\Program Files\Opera\Opera.exe
              C:\Documents and Settings\Krzysztof Komar\Pulpit\HijackThis.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 0ml.net/cat
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.onet.pl/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
              R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
              R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = ls0.net/srchasst.html (obfuscated)
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = ls0.net/srchasst.html (obfuscated)
              F3 - REG:win.ini: load=C:\YDPDict\watch.exe
              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
              O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
              O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
              O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
              O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
              O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Antivirus Platinum\Inicio.exe"
              O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE" /s
              O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
              O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s
              O4 - HKLM\..\Run: [Soundmx] \soundmx.exe
              O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
              O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe
              O4 - HKLM\..\Run: [Dial32] C:\WINDOWS\dl.exe
              O4 - HKLM\..\Run: [Dial33] C:\WINDOWS\dlm.exe
              O4 - HKLM\..\Run: [Upgrade Service] C:\WINDOWS\sxchost.exe
              O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
              O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\fgnttimi.exe
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\KRZYSZ~1\USTAWI~1\Temp\se.dll,DllInstall
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O4 - HKCU\..\Run: [Windows Internet Protocol] C:\WINDOWS\system32\winproc32.exe
              O4 - HKCU\..\Run: [Spyware Begone] c:\freescan\freescan.exe -FastScan
              O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
              O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
              O8 - Extra context menu item: Ściągnij przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_link.htm
              O8 - Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_all.htm
              O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
              O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
              O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
              O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
              O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - www.trojanscan.com/trojanscan/TDECntrl.CAB
              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093250083027
              O16 - DPF: {67135BDA-6546-4426-BC94-BB5AF5005231} (GINCHECKERS Class) - gryonline.wp.pl/files/checkers_2_0_0_6.cab
              O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - www.pandasoftware.com/activescan/as5/asinst.cab
              O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - www.ravantivirus.com/scan/ravonline.cab
              O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) - skaner.mks.com.pl/SkanerOnline.cab
              O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C4} (GINBILLARDT Class) - gryonline.wp.pl/files/billardt_2_0_0_6.cab
              O18 - Filter: text/html - {5FB4CF59-3667-44B8-B0A4-4C12014D7889} - C:\WINDOWS\system32\mgacoca.dll
              O20 - AppInit_DLLs: C:\WINDOWS\System32\sql.dll
              O21 - SSODL: Web Event Logger - {79FEACFF-FFCE-815E-A900-316290B5B738} - (no file)
              O23 - Service: Windows Update Service (muamgrd) - Unknown owner - C:\WINDOWS\System32\muamgrd.exe (file missing)
              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
              O23 - Service: Panda Firewall Service (PAVFIRES) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
              O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe

              Dalej natomiast nie wiem jak się obsługuje ten program LSP-Fix Po lewej stronie tabeli keep znajdują się jakieś pliki a prawa strona Remove jest pusta .Co mam zrobić
              • Gość: Kolobos Re: Chłopaki pomóżcie IP: *.warszawa.sdi.tpnet.pl 23.03.05, 19:34
                LSPFix nic nie pokazuje bo juz jest ok, przyjamniej to ;-)
                teraz czeka Cie zabawa z killbox'em bo widze ze wiekszosc wpisow wrocila czyli
                trzeba usunac pliki
                www.downloads.subratam.org/KillBox.zip
                rozpakuj uruchom, zaznacz remove on reboot i usun te wszystkie pliki :
                C:\Program Files\Common files\updmgr\updmgr.exe
                C:\WINDOWS\dl.exe
                C:\WINDOWS\dlm.exe
                C:\WINDOWS\sxchost.exe
                C:\WINDOWS\sysupd.exe
                C:\WINDOWS\System32\fgnttimi.exe
                C:\DOCUME~1\KRZYSZ~1\USTAWI~1\Temp\se.dll
                C:\WINDOWS\system32\winproc32.exe
                C:\WINDOWS\System32\sql.dll
                C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL
                soundmx.exe <- tego poszukaj w Szukaj plikow i folderow i wklej jego sciezke do
                killboxa


                • Gość: Ania Re: Chłopaki pomóżcie IP: 217.153.84.* 23.03.05, 20:54
                  Serdeczne dziękuję za pomoc Kolobos
                  • Gość: Ania Re: Chłopaki pomóżcie IP: 217.153.84.* 23.03.05, 21:38
                    Dlaczego nigdzie nie można znależć tych plików do usunięcia.Zrobiłam tak jak kazałeś ,szukałam i ich nie ma ,co mam zrobić
                    • Gość: Kolobos Re: Chłopaki pomóżcie IP: *.warszawa.sdi.tpnet.pl 23.03.05, 22:40
                      Bo sa ukryte, wklej do killbox'a juz gotowe sciezki np. C:\Program Files\Common
                      files\updmgr\updmgr.exe nie musisz szukac tych plikow.
                      Jezeli chcesz zeby je bylo widac to wejdz w Explorer->Narzedzia->Opcje Folderow-
                      >Widok-> i zaznacz tam Pokaz ukryte pliki i foldery oraz odznacz ukryj
                      chronione pliki systemu operacyjnego.
                • netsec Re: Kolobos 24.03.05, 08:39
                  Najpierw trzeba odinstalować programy które są zainstalowane w systemie np.
                  P2P Networking, New.Net i fałszywy Spyware Begone :)
                  W przeciwnym razie bijesz pianę -:)
                  • Gość: Kolobos Re: Kolobos IP: *.warszawa.sdi.tpnet.pl 24.03.05, 10:49
                    Przeciez juz dawno napisalem, autorce postu zeby je odinstalowala.Ale co ja
                    moge poradzic jak ona nie chce tego zrobic?
                    • Gość: Ania Re: Kolobos IP: 217.153.84.* 24.03.05, 11:54
                      Cześć to znowu ja.Próbowałam usunąć te pliki KiLLBoxem ale to chyba nic nie dało,Ty i kolega pisaliście że muszę coś usunąć ponieważ to nic nie da. W panelu sterowania dodaj usuń znalazłam P2P Networing natomiast pozostałych programów nie ma czyli NEW NET i fałszywy spyware Begone ,gdzie je mam znależć .Jeszcze mam pytanie czy jak usunę P2P Networing czy skasują mi sie dane które mam w programie emule i które ściagamNaprawdę jeśli chodzi o komputery to ja jestem zielona
                      to jest mój log teraz
                      Logfile of HijackThis v1.99.1
                      Scan saved at 11:54:00, on 2005-03-24
                      Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\SYSTEM32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\system32\ntvdm.exe
                      C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE
                      C:\Program Files\Winamp\winampa.exe
                      C:\WINDOWS\system32\rundll32.exe
                      C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
                      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\WINDOWS\system32\RUNDLL32.EXE
                      C:\Program Files\Messenger\msmsgs.exe
                      C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
                      C:\WINDOWS\System32\nvsvc32.exe
                      C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
                      C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
                      C:\Program Files\Panda Software\Panda Antivirus Platinum\AVENGINE.EXE
                      C:\Program Files\Panda Software\Panda Antivirus Platinum\pavProxy.exe
                      C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
                      C:\Program Files\Opera\Opera.exe
                      C:\WINDOWS\system32\rundll32.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Documents and Settings\Krzysztof Komar\Pulpit\HijackThis.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 0ml.net/cat
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\KRZYSZ~1\USTAWI~1\Temp\se.dll/sp.html
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\KRZYSZ~1\USTAWI~1\Temp\se.dll/sp.html
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = ls0.net/srchasst.html (obfuscated)
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = ls0.net/srchasst.html (obfuscated)
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
                      F3 - REG:win.ini: load=C:\YDPDict\watch.exe
                      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                      O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
                      O2 - BHO: (no name) - {F8D5DB90-9F83-49CF-BA1D-122CC694CF9F} - C:\WINDOWS\system32\djmlm.dll (file missing)
                      O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
                      O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                      O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Antivirus Platinum\Inicio.exe"
                      O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE" /s
                      O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                      O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s
                      O4 - HKLM\..\Run: [Soundmx] \soundmx.exe
                      O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
                      O4 - HKLM\..\Run: [Upgrade Service] C:\WINDOWS\sxchost.exe
                      O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\fgnttimi.exe
                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                      O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\KRZYSZ~1\USTAWI~1\Temp\se.dll,DllInstall
                      O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe
                      O4 - HKLM\..\Run: [Dial32] C:\WINDOWS\dl.exe
                      O4 - HKLM\..\Run: [Dial33] C:\WINDOWS\dlm.exe
                      O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
                      O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
                      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                      O4 - HKCU\..\Run: [Windows Internet Protocol] C:\WINDOWS\system32\winproc32.exe
                      O4 - HKCU\..\Run: [Spyware Begone] c:\freescan\freescan.exe -FastScan
                      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                      O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
                      O8 - Extra context menu item: Ściągnij przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_link.htm
                      O8 - Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_all.htm
                      O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
                      O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
                      O10 - Hijacked Internet access by New.Net
                      O10 - Hijacked Internet access by New.Net
                      O10 - Hijacked Internet access by New.Net
                      O10 - Hijacked Internet access by New.Net
                      O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
                      O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                      O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - www.trojanscan.com/trojanscan/TDECntrl.CAB
                      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093250083027
                      O16 - DPF: {67135BDA-6546-4426-BC94-BB5AF5005231} (GINCHECKERS Class) - gryonline.wp.pl/files/checkers_2_0_0_6.cab
                      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - www.pandasoftware.com/activescan/as5/asinst.cab
                      O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - www.ravantivirus.com/scan/ravonline.cab
                      O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) - skaner.mks.com.pl/SkanerOnline.cab
                      O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C4} (GINBILLARDT Class) - gryonline.wp.pl/files/billardt_2_0_0_6.cab
                      O18 - Filter: text/html - {0B88BC57-A061-48AE-A2CF-1A1220DF8352} - C:\WINDOWS\system32\djmlm.dll
                      O18 - Filter: text/plain - {0B88BC57-A061-48AE-A2CF-1A
                      • Gość: Kolobos Re: Kolobos IP: *.warszawa.sdi.tpnet.pl 24.03.05, 12:16
                        Log dalej wyglada strasznie ;-)
                        Znowu masz se.dll -> uzyj jeszcze raz SpSeHjfix_Beta7
                        LSPFix -> teraz zadziala ;-)
                        CWS Shredder -> cwshredder.net/bin/CWShredder.exe (uruchom po zamknieciu
                        okien przegladarki)
                        P2P Networing nie ma zwiazku z emule
                        Przeskanuj tez Panda caly dysk, najlepiej w trybie awaryjnym (naciskasz F8
                        podczas startu windowsa i wybierasz tryb awaryjny)

                        a dopiero pozniej usun te wpisy (zaznacz wszystkie w hijackthis i nacisnij Fix
                        Checked)

                        > R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
                        0ml.net/cat
                        > R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
                        res://C:\DOCUM
                        > E~1\KRZYSZ~1\USTAWI~1\Temp\se.dll/sp.html
                        > R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
                        > R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
                        res://C:\DOCUM
                        > E~1\KRZYSZ~1\USTAWI~1\Temp\se.dll/sp.html
                        > R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
                        > R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                        about:b
                        > lank
                        > R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        ls0.net/srchasst.html
                        (obfuscated)
                        > R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                        about:b
                        > lank
                        > R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        ls0.net/srchasst.html
                        (obfuscated)
                        > R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
                        > R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
                        > O2 - BHO: (no name) - {F8D5DB90-9F83-49CF-BA1D-122CC694CF9F} -
                        C:\WINDOWS\syste
                        > m32\djmlm.dll (file missing)
                        > O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32
                        \NvCpl.dll,NvStartup
                        > O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1
                        \NEWDOT~1.DLL,NewDotNetStartup -s
                        > O4 - HKLM\..\Run: [Soundmx] \soundmx.exe
                        > O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P
                        Networking.exe /AUTOSTART
                        > O4 - HKLM\..\Run: [Upgrade Service] C:\WINDOWS\sxchost.exe
                        > O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\fgnttimi.exe
                        > O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
                        Files\Real\Update_OB\realsched.exe" -osboot
                        > O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\KRZYSZ~1\USTAWI~1
                        \Temp\se.dll,DllInstall
                        > O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe
                        > O4 - HKLM\..\Run: [Dial32] C:\WINDOWS\dl.exe
                        > O4 - HKLM\..\Run: [Dial33] C:\WINDOWS\dlm.exe
                        > O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
                        > O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                        > O4 - HKCU\..\Run: [Windows Internet Protocol] C:\WINDOWS\system32
                        \winproc32.exe
                        > O4 - HKCU\..\Run: [Spyware Begone] c:\freescan\freescan.exe -FastScan
                        > O4 - Global Startup: PrecisionTime.lnk = C:\Program
                        Files\PrecisionTime\Precisi onTime.exe
                        > O10 - Hijacked Internet access by New.Net
                        > O10 - Hijacked Internet access by New.Net
                        > O10 - Hijacked Internet access by New.Net
                        > O10 - Hijacked Internet access by New.Net
                        > O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) -
                        www.trojanscan.com/trojanscan/TDECntrl.CAB
                        > O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) -
                        target="_blank

                        Upewnij sie, ze zaznaczylas wszystkie te wpisy.
                        • Gość: Ania Re: Kolobos IP: 217.153.84.* 24.03.05, 12:33
                          dokończony log
                          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093250083027
                          O16 - DPF: {67135BDA-6546-4426-BC94-BB5AF5005231} (GINCHECKERS Class) - gryonline.wp.pl/files/checkers_2_0_0_6.cab
                          O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - www.pandasoftware.com/activescan/as5/asinst.cab
                          O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - www.ravantivirus.com/scan/ravonline.cab
                          O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) - skaner.mks.com.pl/SkanerOnline.cab
                          O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C4} (GINBILLARDT Class) - gryonline.wp.pl/files/billardt_2_0_0_6.cab
                          O18 - Filter: text/html - {0B88BC57-A061-48AE-A2CF-1A1220DF8352} - C:\WINDOWS\system32\djmlm.dll
                          O18 - Filter: text/plain - {0B88BC57-A061-48AE-A2CF-1A1220DF8352} - C:\WINDOWS\system32\djmlm.dll
                          O20 - AppInit_DLLs: C:\WINDOWS\System32\sql.dll
                          O21 - SSODL: Web Event Logger - {79FEACFF-FFCE-815E-A900-316290B5B738} - (no file)
                          O23 - Service: Windows Update Service (muamgrd) - Unknown owner - C:\WINDOWS\System32\muamgrd.exe (file missing)
                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                          O23 - Service: Panda Firewall Service (PAVFIRES) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
                          O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe

                          • Gość: Kolobos Re: Kolobos IP: *.warszawa.sdi.tpnet.pl 24.03.05, 12:43
                            O18 - Filter: text/html - {0B88BC57-A061-48AE-A2CF-1A1220DF8352} -
                            C:\WINDOWS\system32\djmlm.dll
                            O18 - Filter: text/plain - {0B88BC57-A061-48AE-A2CF-1A1220DF8352} -
                            C:\WINDOWS\system32\djmlm.dll
                            O20 - AppInit_DLLs: C:\WINDOWS\System32\sql.dll
                            O21 - SSODL: Web Event Logger - {79FEACFF-FFCE-815E-A900-316290B5B738} - (no
                            file)
                            O23 - Service: Windows Update Service (muamgrd) - Unknown owner -
                            C:\WINDOWS\System32\muamgrd.exe (file missing)

                            Jeszcze to usun, razem z tamtym co wczesniej.
                      • Gość: Kolobos Re: Kolobos IP: *.warszawa.sdi.tpnet.pl 24.03.05, 12:17
                        Do tego caly log sie nie zmiescil, doklej koniec.
                        • Gość: Ania Re: Kolobos IP: 217.153.84.* 24.03.05, 12:39
                          Czy muszę odinstalowywać te programy o których pisałes i jak to zrobić
                          • Gość: Kolobos Re: Kolobos IP: *.warszawa.sdi.tpnet.pl 24.03.05, 12:45
                            Jakie? Masz odinstalowac P2P Networking z dodaj-usun programy oraz poszukac tam
                            spyware begone i tez odinstalowac, a takze New.Net.
                            A co do LSPFix itd to masz uzyc tych programow, a nie odinstalowac.
                            • Gość: Ania Re: Kolobos IP: 217.153.84.* 24.03.05, 13:10
                              Te dwa programy odinstalowałam czyli P2P Networing i New.Net ale nie mogę znależć pliku lub programu spyware begone,próbowałam aby komputer wyszukał tego pliku i go nie znalazł. Co mam zrobić
                              • Gość: Kolobos Re: Kolobos IP: *.warszawa.sdi.tpnet.pl 24.03.05, 13:24
                                No to nie szukaj narazie new.net rob wszystko dalej tak jak napisalem
                                wczesniej, uzyj programow ktore polecilem, na koniec wklej nowy log itd.

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka