Net strasznie zamula


(4d!666) #1

Witam mam problem z internetem... Na moim kompie net chodzi normalnie(transfer max. 50-60kb/s)lecz u mojego ojca strasznie muli, strony wolno się wczytują i ściąga mu z transferem 5-10kb/s(ma windows 2000)Mamy razem neta przez kabel DSL :stuck_out_tongue: Wklejam log z Hijackthis:

Logfile of HijackThis v1.99.1

Scan saved at 21:07:37, on 2007-05-30

Platform: Windows 2000 SP4 (WinNT 5.00.2195)

MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)


Running processes:

D:\WINNT\System32\smss.exe

D:\WINNT\system32\winlogon.exe

D:\WINNT\system32\services.exe

D:\WINNT\system32\lsass.exe

D:\WINNT\system32\svchost.exe

D:\WINNT\system32\spoolsv.exe

D:\WINNT\system32\svchost.exe

D:\WINNT\system32\regsvc.exe

D:\WINNT\system32\MSTask.exe

D:\WINNT\system32\stisvc.exe

D:\WINNT\System32\WBEM\WinMgmt.exe

D:\WINNT\system32\svchost.exe

D:\WINNT\Explorer.EXE

D:\Program Files\Kerio\Personal Firewall\PERSFW.EXE

D:\WINNT\system32\wuauclt.exe

D:\Program Files\Kerio\Personal Firewall\PERSFW.EXE

D:\Program Files\Mozilla Firefox\firefox.exe

D:\Documents and Settings\NTX\Pulpit\hijackthis\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://bossa.pl/notowania/wykresy/

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza

F2 - REG:system.ini: UserInit=D:\WINNT\system32\userinit.exe,C:\WINNT\system32\userinit.exe,

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)

O2 - BHO: (no name) - {1a1ddc19-5893-43ab-a73f-f41a0f34d115} - D:\Program Files\Video ActiveX Object\isaddon.dll (file missing)

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - D:\Program Files\BitComet\tools\BitCometBHO.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\system32\msdxm.ocx

O3 - Toolbar: Protection Bar - {5d4831e0-5a7c-4a46-afd5-a79ab8ce36c2} - D:\Program Files\Video ActiveX Object\iesplugin.dll (file missing)

O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon

O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe

O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [BearShare] "D:\Program Files\BearShare\BearShare.exe" /pause

O4 - HKLM\..\Run: [NeroCheck] D:\WINNT\system32\\NeroCheck.exe

O4 - HKLM\..\Run: [S7UB Start] "D:\Siemens\Common\S7ubtoox\s7ubtstx.exe" -StartDB

O4 - HKCU\..\Run: [internat.exe] internat.exe

O4 - Startup: Firewall Engine.lnk = C:\Program Files\Kerio\Personal Firewall\PERSFW.EXE

O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE

O8 - Extra context menu item: Download all links using BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Download all videos using BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddVideo.htm

O8 - Extra context menu item: Download link using &BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddLink.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{A11B2147-C0F5-40A0-AAE8-1044C19876D3}: NameServer = 62.179.1.60,62.179.1.61

O21 - SSODL: flammei - {9d635a36-6b3c-4146-8625-f3aaf507bbf8} - D:\WINNT\system32\vcehaeb.dll

O23 - Service: Ati HotKey Poller - Unknown owner - D:\WINNT\system32\Ati2evxx.exe

O23 - Service: Usługa administracyjna Menedżera dysków logicznych (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe

O23 - Service: Pml Driver HPZ12 - HP - D:\WINNT\system32\HPZipm12.exe

Mam nadzieje ,że mi pomożecie :wink:


(qrczak13) #2

Zastosuj SimtFraudFix, opcja 2 w trybie awaryjnym.

Daj nowy log z HJT + SilentRunners oraz zawartość pliku c:\rapport.txt


(4d!666) #3

HJT:

Logfile of HijackThis v1.99.1

Scan saved at 21:41:37, on 2007-05-30

Platform: Windows 2000 SP4 (WinNT 5.00.2195)

MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)


Running processes:

D:\WINNT\System32\smss.exe

D:\WINNT\system32\winlogon.exe

D:\WINNT\system32\services.exe

D:\WINNT\system32\lsass.exe

D:\WINNT\system32\svchost.exe

D:\WINNT\system32\spoolsv.exe

D:\WINNT\system32\svchost.exe

D:\WINNT\system32\regsvc.exe

D:\WINNT\system32\MSTask.exe

D:\WINNT\system32\stisvc.exe

D:\WINNT\System32\WBEM\WinMgmt.exe

D:\WINNT\system32\svchost.exe

D:\WINNT\Explorer.EXE

D:\WINNT\system32\atiptaxx.exe

D:\WINNT\system32\internat.exe

D:\Program Files\Kerio\Personal Firewall\PERSFW.EXE

D:\Program Files\Mozilla Firefox\firefox.exe

D:\WINNT\system32\wuauclt.exe

D:\Documents and Settings\NTX\Pulpit\hijackthis\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = D:\windows\system32\blank.htm

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = D:\windows\system32\blank.htm

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza

F2 - REG:system.ini: UserInit=D:\WINNT\system32\userinit.exe,C:\WINNT\system32\userinit.exe,

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - D:\Program Files\BitComet\tools\BitCometBHO.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\system32\msdxm.ocx

O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon

O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe

O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [BearShare] "D:\Program Files\BearShare\BearShare.exe" /pause

O4 - HKLM\..\Run: [NeroCheck] D:\WINNT\system32\\NeroCheck.exe

O4 - HKLM\..\Run: [S7UB Start] "D:\Siemens\Common\S7ubtoox\s7ubtstx.exe" -StartDB

O4 - HKCU\..\Run: [internat.exe] internat.exe

O4 - Startup: Firewall Engine.lnk = C:\Program Files\Kerio\Personal Firewall\PERSFW.EXE

O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE

O8 - Extra context menu item: Download all links using BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Download all videos using BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddVideo.htm

O8 - Extra context menu item: Download link using &BitComet - res://D:\Program Files\BitComet\BitComet.exe/AddLink.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{A11B2147-C0F5-40A0-AAE8-1044C19876D3}: NameServer = 62.179.1.60,62.179.1.61

O23 - Service: Ati HotKey Poller - Unknown owner - D:\WINNT\system32\Ati2evxx.exe

O23 - Service: Usługa administracyjna Menedżera dysków logicznych (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe

O23 - Service: Pml Driver HPZ12 - HP - D:\WINNT\system32\HPZipm12.exe

rapport.txt

SmitFraudFix v2.189


Scan done at 21:38:15,29, —r 2007-05-30

Run from D:\Documents and Settings\NTX\Pulpit\SmitfraudFix\SmitfraudFix

OS: Microsoft Windows 2000 [Wersja 5.00.2195] - Windows_NT

The filesystem type is NTFS

Fix run in normal mode


»»»»»»»»»»»»»»»»»»»»»»»» Process


D:\WINNT\System32\smss.exe

D:\WINNT\system32\winlogon.exe

D:\WINNT\system32\services.exe

D:\WINNT\system32\lsass.exe

D:\WINNT\system32\svchost.exe

D:\WINNT\system32\spoolsv.exe

D:\WINNT\system32\svchost.exe

D:\WINNT\system32\regsvc.exe

D:\WINNT\system32\MSTask.exe

D:\WINNT\system32\stisvc.exe

D:\WINNT\System32\WBEM\WinMgmt.exe

D:\WINNT\system32\svchost.exe

D:\WINNT\Explorer.EXE

D:\WINNT\system32\atiptaxx.exe

D:\WINNT\system32\internat.exe

D:\Program Files\Kerio\Personal Firewall\PERSFW.EXE

D:\Program Files\Mozilla Firefox\firefox.exe

D:\WINNT\system32\wuauclt.exe

D:\WINNT\system32\cmd.exe


»»»»»»»»»»»»»»»»»»»»»»»» hosts



»»»»»»»»»»»»»»»»»»»»»»»» D:\



»»»»»»»»»»»»»»»»»»»»»»»» D:\WINNT



»»»»»»»»»»»»»»»»»»»»»»»» D:\WINNT\system



»»»»»»»»»»»»»»»»»»»»»»»» D:\WINNT\Web



»»»»»»»»»»»»»»»»»»»»»»»» D:\WINNT\system32



»»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\NTX



»»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\NTX\Application Data



»»»»»»»»»»»»»»»»»»»»»»»» Start Menu



»»»»»»»»»»»»»»»»»»»»»»»» D:\DOCUME~1\NTX\Ulubione



»»»»»»»»»»»»»»»»»»»»»»»» Desktop



»»»»»»»»»»»»»»»»»»»»»»»» D:\Program Files 



»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys



»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components




»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!Attention, following keys are not inevitably infected!


SrchSTS.exe by S!Ri

Search SharedTaskScheduler's .dll



»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!Attention, following keys are not inevitably infected!


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"=""



»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!Attention, following keys are not inevitably infected!


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

"System"=""



»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32-xpdt




»»»»»»»»»»»»»»»»»»»»»»»» DNS


Description: 3Com EtherLink PCI

DNS Server Search Order: 62.179.1.62

DNS Server Search Order: 62.179.1.63


Description: Winbond W89C840(A) 100M PCI Adapter.

DNS Server Search Order: 62.179.1.60

DNS Server Search Order: 62.179.1.61


HKLM\SYSTEM\CCS\Services\Tcpip\..\{675BA368-83FF-4C20-9228-028099BAFA94}: DhcpNameServer=62.179.1.62 62.179.1.63

HKLM\SYSTEM\CCS\Services\Tcpip\..\{A11B2147-C0F5-40A0-AAE8-1044C19876D3}: NameServer=62.179.1.60,62.179.1.61

HKLM\SYSTEM\CS1\Services\Tcpip\..\{675BA368-83FF-4C20-9228-028099BAFA94}: DhcpNameServer=62.179.1.62 62.179.1.63

HKLM\SYSTEM\CS1\Services\Tcpip\..\{A11B2147-C0F5-40A0-AAE8-1044C19876D3}: NameServer=62.179.1.60,62.179.1.61

HKLM\SYSTEM\CS2\Services\Tcpip\..\{675BA368-83FF-4C20-9228-028099BAFA94}: DhcpNameServer=62.179.1.62 62.179.1.63

HKLM\SYSTEM\CS2\Services\Tcpip\..\{A11B2147-C0F5-40A0-AAE8-1044C19876D3}: NameServer=62.179.1.60,62.179.1.61

HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=62.179.1.62 62.179.1.63

HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=62.179.1.62 62.179.1.63

HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=62.179.1.62 62.179.1.63



»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection



»»»»»»»»»»»»»»»»»»»»»»»» End


[/code]


ST

[code]"Silent Runners.vbs", revision R50, http://www.silentrunners.org/ Operating System: Windows 2000 Output limited to non-default values, except where indicated by "{++}" Startup items buried in registry: --------------------------------- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} "internat.exe" = "internat.exe" [MS] HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++} "Synchronization Manager" = "mobsync.exe /logon" [MS] "AtiPTA" = "atiptaxx.exe" ["ATI Technologies, Inc."] "SunJavaUpdateSched" = "D:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" ["Sun Microsystems, Inc."] "HP Software Update" = "D:\Program Files\HP\HP Software Update\HPWuSchd2.exe" ["Hewlett-Packard Development Company, L.P."] "BearShare" = ""D:\Program Files\BearShare\BearShare.exe" /pause" [file not found] "NeroCheck" = "D:\WINNT\system32\NeroCheck.exe" ["Ahead Software Gmbh"] "S7UB Start" = ""D:\Siemens\Common\S7ubtoox\s7ubtstx.exe" -StartDB" ["SIEMENS AG"] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}(Default) = "BitComet ClickCapture" -> {HKLM...CLSID} = "BitComet Helper" \InProcServer32(Default) = "D:\Program Files\BitComet\tools\BitCometBHO.dll" ["BitComet"] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}(Default) = (no title provided) -> {HKLM...CLSID} = "SSVHelper Class" \InProcServer32(Default) = "D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll" ["Sun Microsystems, Inc."] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania" -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania" \InProcServer32(Default) = "deskpan.dll" [file not found] "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu" -> {HKLM...CLSID} = "HyperTerminal Icon Ext" \InProcServer32(Default) = "D:\WINNT\system32\hticons.dll" ["Hilgraeve, Inc."] "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}" = "Pasek eksploratora" -> {HKLM...CLSID} = "Explorer Band" \InProcServer32(Default) = "D:\WINNT\system32\browseui.dll" [MS] "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension" -> {HKLM...CLSID} = "WinRAR" \InProcServer32(Default) = "D:\Program Files\WinRAR\rarext.dll" [null data] "{EE75AC21-B24F-11d3-BA80-00C0CA16AA37}" = "Siemens Device" -> {HKLM...CLSID} = "Siemens Device" \InProcServer32(Default) = "D:\Program Files\Mobile Phone Manager\bin\PhoneExplorer.dll" [empty string] "{EE75AC22-B24F-11d3-BA80-00C0CA16AA37}" = "Siemens Device ContextMenuHandler" -> {HKLM...CLSID} = "Siemens Device ContextMenuHandler" \InProcServer32(Default) = "D:\Program Files\Mobile Phone Manager\bin\PhoneExplorer.dll" [empty string] "{EE75AC23-B24F-11d3-BA80-00C0CA16AA37}" = "Siemens Device PropertySheetHandlers" -> {HKLM...CLSID} = "Siemens Device PropertySheetHandler" \InProcServer32(Default) = "D:\Program Files\Mobile Phone Manager\bin\PhoneExplorer.dll" [empty string] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ <> "Userinit" = "D:\WINNT\system32\userinit.exe,C:\WINNT\system32\userinit.exe," [MS], [file not found] HKLM\Software\Classes*\shellex\ContextMenuHandlers\ WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM...CLSID} = "WinRAR" \InProcServer32(Default) = "D:\Program Files\WinRAR\rarext.dll" [null data] HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM...CLSID} = "WinRAR" \InProcServer32(Default) = "D:\Program Files\WinRAR\rarext.dll" [null data] HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM...CLSID} = "WinRAR" \InProcServer32(Default) = "D:\Program Files\WinRAR\rarext.dll" [null data] Group Policies {GPedit.msc branch and setting}: ----------------------------------------------- Note: detected settings may not have any effect. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ "CDRAutoRun" = (REG_DWORD) hex:0x00000000 {unrecognized setting} HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\ "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Shutdown: Allow system to be shut down without having to log on} Active Desktop and Wallpaper: ----------------------------- Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState Startup items in "NTX" & "All Users" startup folders: ----------------------------------------------------- D:\Documents and Settings\NTX\Menu Start\Programy\Autostart "Firewall Engine" -> shortcut to: "D:\Program Files\Kerio\Personal Firewall\PERSFW.EXE" ["Kerio Technologies"] D:\Documents and Settings\All Users\Menu Start\Programy\Autostart "HP Digital Imaging Monitor" -> shortcut to: "D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" ["Hewlett-Packard Development Company, L.P."] "Microsoft Office" -> shortcut to: "D:\Program Files\Microsoft Office\Office\OSA9.EXE -b -l" [MS] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = "%SystemRoot%\System32\rnr20.dll" [MS] 000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS] Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\msafd.dll [MS], 01 - 03, 06 - 13 %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05 Toolbars, Explorer Bars, Extensions: ------------------------------------ Extensions (Tools menu items, main toolbar menu buttons) HKLM\Software\Microsoft\Internet Explorer\Extensions\ {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ "MenuText" = "Sun Java Console" "CLSIDExtension" = "{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}" -> {HKCU...CLSID} = "Java Plug-in" \InProcServer32(Default) = "D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll" ["Sun Microsystems, Inc."] -> {HKLM...CLSID} = "Java Plug-in 1.5.0_06" \InProcServer32(Default) = "D:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll" ["Sun Microsystems, Inc."] Miscellaneous IE Hijack Points ------------------------------ D:\WINNT\INF\IERESET.INF (used to "Reset Web Settings") Missing lines (compared with English-language version): [DeleteAutosearch.reg]: 1 line Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ System zdarzeń COM+, EventSystem, "D:\WINNT\system32\svchost.exe -k netsvcs" {"D:\WINNT\system32\es.dll" [null data]} Print Monitors: --------------- HKLM\System\CurrentControlSet\Control\Print\Monitors\ HP Standard TCP/IP Port\Driver = "HpTcpMon.dll" ["Hewlett Packard"] PCL hpz3l054\Driver = "hpz3l054.dll" ["Hewlett-Packard Company"] ---------- <>: Suspicious data at a malware launch point. + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + To search all directories of local fixed drives for DESKTOP.INI DLL launch points, use the -supp parameter or answer "No" at the first message box and "Yes" at the second message box. ---------- (total run time: 44 seconds, including 18 seconds for message boxes)

Dodam ,że download wciąż jest taki sam :frowning: Upload jest normalny :stuck_out_tongue: Any ideas? :wink:


(Joan Sunshine) #4

usun wpisy


(4d!666) #5

Ale ze mnie n00b :smiley: Już wiem o co chodzi :stuck_out_tongue: Przekroczyłem poprostu miesięczny limit pobierania w chello(10gb:/)dlatego net tak mi spowolnił :slight_smile: Na przyszłość polecam dla użytkowników chello stronę: http://licznik.upc.pl/ 8) Anyway thx za pomoc usunełem troche syfu z kompa =]