ďťż
chomiki Niespodziewnie zniknął menadżer zadań... winamp Nowy komputer Co to za przekaĹşnik? PROBLEM Z ZAPALANIEM [tapeta] Moja pierwsza tapeta w ps :D niepodlaczone przewody chyba do turbiny prosze o sprawdzenie loga Problemy z usunieciem Pandy Platinum (demo). Wentylator chĹodnicy - problem inny niĹź wszystkie... |
chomikiod kilku dni nie moge uruchomic menadzera zadań pojawia mi się tylko ikonka koło zegarka,Logfile of HijackThis v1.99.1 Scan saved at 22:43:38, on 2006-02-20 Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: D:\WINDOWS\System32\smss.exe D:\WINDOWS\system32\winlogon.exe D:\WINDOWS\system32\services.exe D:\WINDOWS\system32\lsass.exe D:\WINDOWS\system32\svchost.exe D:\WINDOWS\System32\svchost.exe D:\WINDOWS\system32\LEXBCES.EXE D:\WINDOWS\system32\spoolsv.exe D:\WINDOWS\system32\LEXPPS.EXE D:\WINDOWS\system32\nvsvc32.exe D:\WINDOWS\Explorer.EXE D:\WINDOWS\SOUNDMAN.EXE D:\WINDOWS\system32\RUNDLL32.EXE D:\WINDOWS\system32\ctfmon.exe D:\Program Files\Messenger\msmsgs.exe D:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe D:\Program Files\Tlen.pl\tlen.exe D:\Program Files\Winamp\winamp.exe D:\Program Files\Outlook Express\msimn.exe D:\Program Files\Internet Explorer\iexplore.exe D:\Documents and Settings\ja.HEYAH-3CD7F5E67\Pulpit\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.onet.pl/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = ERROR R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza O4 - HKLM\..\Run: [KAVPersonal50] "D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [PinnacleDriverCheck] D:\WINDOWS\system32\PSDrvCheck.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [MKS_MENU] D:\Program Files\MKS\Bin\mks_menu.exe O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ares] "C:\Program files\Ares\Ares.exe" -h O4 - Global Startup: DSLMON.lnk = D:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe O4 - Global Startup: Kaspersky Anti-Hacker.lnk = D:\Program Files\Kaspersky Lab\Kaspersky Security Suite\Kaspersky Anti-Hacker\KAVPF.exe O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .pdf: D:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll O15 - Trusted Zone: www.mks.com.pl O16 - DPF: {37A49D66-2735-4BB9-8503-82BA5E2333D0} (MailCfg Control) - http://poczta.wp.pl/d015/mailcfg.ocx O16 - DPF: {831FDD16-0C5C-11D2-A9FC-0000F8754DA1} - http://activex.microsoft....b6/MSComCtl.cab O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab O16 - DPF: {F9043C88-F6F2-101A-A3C9-08002B2F49FB} - http://activex.microsoft....b6/ComDlg32.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{CAB5BE12-86E0-466C-A513-D55C37B4F392}: NameServer = 194.204.152.34 217.98.63.164 O23 - Service: kavsvc - Kaspersky Lab - D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - D:\WINDOWS\system32\LEXBCES.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe Coś mi się nie podoba. Masz dwa antyvirusy Kaspersky i MKS Bo wpis MKS'a jest w autostarcie ale jego usług już nie widać ... Spróbuj tego: http://gromat.srcom.info/...10b89eeb57fcc9a Co do loga: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = ERROR R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit Więcej nic podejrzanego tutaj nie widzę. Komputer skanowałeś avast!'em, AVG, spybot'em, ad-aware'em w trybie awaryjnym? Co do loga: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = ERROR R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit Więcej nic podejrzanego tutaj nie widzę. Komputer skanowałeś avast!'em, AVG, spybot'em, ad-aware'em w trybie awaryjnym? nebeu - te wpisy nie są szkodliwe - NvMcTray.dll jest od sterów NVidii, R1 samemu się ustawia, a R0 jest od paska IE. mam kasperskiego który podczas skanu nic nie wykrył, ale później zrobiłem skana ad-ware tez nic, potem mks on-line który wykrył jednego trojana, a i jeszcze przed samym skanem wcieło mi 2,5 tys. mp3 Masz wiruysy miałem jednego, fix nie pomógł, dalej mam tylko ikone Polecam skaner on-line pandy. Jeszcze niegdy mnie nie zawiódł. Szukaj na stronie domowej pandy. Klika się chyba "panda active scan", jeśli dobrze pamiętam. Później trzeba wybrać swój kraj i wpisać adres e-mail. Jeszcze się chyba wybierało czy używasz tego w firmie czy w domu. miałem jednego, fix nie pomógł, dalej mam tylko ikone Ściągnij Silent Runners, wygeneruj nim loga i wrzuć tego loga tutaj. skanowałem pando ze złym wynikiem tza jeszcze 2 wirusy, ten log: "Silent Runners.vbs", revision 43, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by "{++}" Startup items buried in registry: --------------------------------- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} "CTFMON.EXE" = "D:\WINDOWS\system32\ctfmon.exe" [MS] "MSMSGS" = ""D:\Program Files\Messenger\msmsgs.exe" /background" [MS] "ares" = ""C:\Program files\Ares\Ares.exe" -h" ["Ares Development Group"] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} "SoundMan" = "SOUNDMAN.EXE" ["Realtek Semiconductor Corp."] "NvCplDaemon" = "RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup" [MS] "nwiz" = "nwiz.exe /install" ["NVIDIA Corporation"] "PinnacleDriverCheck" = "D:\WINDOWS\system32\PSDrvCheck.exe" [empty string] "NvMediaCenter" = "RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit" [MS] "APVXDWIN" = ""D:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\APVXDWIN.EXE" /s" ["Panda Software International"] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania" {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found] "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu" {CLSID}\InProcServer32\(Default) = "D:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."] "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension" {CLSID}\InProcServer32\(Default) = "D:\Program Files\WinRAR\rarext.dll" [null data] "{21569614-B795-46b1-85F4-E737A8DC09AD}" = "Shell Search Band" {CLSID}\InProcServer32\(Default) = "D:\WINDOWS\system32\browseui.dll" [MS] "{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class" {CLSID}\InProcServer32\(Default) = "D:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"] "{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer" {CLSID}\InProcServer32\(Default) = "D:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"] "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu" {CLSID}\InProcServer32\(Default) = "D:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"] "{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu" {CLSID}\InProcServer32\(Default) = "D:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"] "{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler" {CLSID}\InProcServer32\(Default) = "D:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL" [MS] "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler" {CLSID}\InProcServer32\(Default) = "D:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL" [MS] "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler" {CLSID}\InProcServer32\(Default) = "D:\Program Files\Microsoft Office\OFFICE11\msohev.dll" [MS] "{F5D92341-0A64-11D0-9956-0000E8096023}" = "CD Copy Shell Extension" {CLSID}\InProcServer32\(Default) = "D:\WINDOWS\system32\Shellext\CDWshext.dll" ["Pinnacle Systems, Inc."] "{F5D92342-0A64-11D0-9956-0000E8096023}" = "CD Wizard Shell Extension" {CLSID}\InProcServer32\(Default) = "D:\WINDOWS\system32\Shellext\CDWshext.dll" ["Pinnacle Systems, Inc."] "{F5D92344-0A64-11D0-9956-0000E8096023}" = "InstantWrite Shellextension" {CLSID}\InProcServer32\(Default) = "D:\WINDOWS\system32\ShellExt\iwshex.dll" ["VOB Computersysteme GmbH"] "{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper" {CLSID}\InProcServer32\(Default) = "D:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"] "{65756541-C65C-11CD-0000-4B656E696100}" = "Panda Antivirus" {CLSID}\InProcServer32\(Default) = "D:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\ShellTit.DLL" ["Panda Software International"] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ INFECTION WARNING! avldr\DLLName = "avldr.dll" ["Panda Software"] HKLM\Software\Classes\PROTOCOLS\Filter\ INFECTION WARNING! text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}" {CLSID}\InProcServer32\(Default) = "D:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS] HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ Panda Antivirus\(Default) = "{65756541-C65C-11CD-0000-4B656E696100}" {CLSID}\InProcServer32\(Default) = "D:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\ShellTit.DLL" ["Panda Software International"] WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" {CLSID}\InProcServer32\(Default) = "D:\Program Files\WinRAR\rarext.dll" [null data] HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" {CLSID}\InProcServer32\(Default) = "D:\Program Files\WinRAR\rarext.dll" [null data] HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ Panda Antivirus\(Default) = "{65756541-C65C-11CD-0000-4B656E696100}" {CLSID}\InProcServer32\(Default) = "D:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\ShellTit.DLL" ["Panda Software International"] WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" {CLSID}\InProcServer32\(Default) = "D:\Program Files\WinRAR\rarext.dll" [null data] Active Desktop and Wallpaper: ----------------------------- Active Desktop is disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState HKCU\Control Panel\Desktop\ "Wallpaper" = "D:\Documents and Settings\ja.HEYAH-3CD7F5E67\Moje dokumenty\Moje obrazy\cfdsaf.bmp" Startup items in "ja" & "All Users" startup folders: ---------------------------------------------------- D:\Documents and Settings\All Users.WINDOWS\Menu Start\Programy\Autostart "DSLMON" shortcut to: "D:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe" [empty string] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] 000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS] 000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: D:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\pavlsp.dll ["Panda Software "], 01 - 03, 19 %SystemRoot%\system32\mswsock.dll [MS], 04 - 06, 09 - 18 %SystemRoot%\system32\rsvpsp.dll [MS], 07 - 08 Toolbars, Explorer Bars, Extensions: ------------------------------------ Explorer Bars HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\ {FF059E31-CC5A-4E2E-BF3B-96E929D65503}\ = "&Badanie" [from CLSID] {CLSID}\InProcServer32\(Default) = "D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL" [MS] Extensions (Tools menu items, main toolbar menu buttons) HKLM\Software\Microsoft\Internet Explorer\Extensions\ {92780B25-18CC-41C8-B9BE-3C9C571A8263}\ "ButtonText" = "Badanie" {FB5F1910-F110-11D2-BB9E-00C04F795683}\ "ButtonText" = "Messenger" "MenuText" = "Windows Messenger" "Exec" = "D:\Program Files\Messenger\msmsgs.exe" [MS] Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ LexBce Server, LexBceS, "D:\WINDOWS\system32\LEXBCES.EXE" ["Lexmark International, Inc."] NVIDIA Display Driver Service, NVSvc, "D:\WINDOWS\system32\nvsvc32.exe" ["NVIDIA Corporation"] Panda anti-virus service, PAVSRV, ""D:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\pavsrv51.exe"" ["Panda Software"] Panda Function Service, PAVFNSVR, ""D:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\PavFnSvr.exe"" ["Panda Software"] Panda IManager Service, PSIMSVC, ""D:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\PsImSvc.exe"" ["Panda Software Internacional"] Panda Network Manager, PNMSRV, ""d:\program files\panda software\panda titanium 2006 antivirus + antispyware\firewall\PNMSRV.EXE"" ["Panda Software"] Panda Process Protection Service, PavPrSrv, ""D:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe"" ["Panda Software"] Panda TPSrv, TPSrv, ""D:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\TPSrv.exe"" ["Panda Software"] Windows User Mode Driver Framework, UMWdf, "D:\WINDOWS\system32\wdfmgr.exe" [MS] Print Monitors: --------------- HKLM\System\CurrentControlSet\Control\Print\Monitors\ Lexmark Network Port\Driver = "LEXLMPM.DLL" ["Lexmark International, Inc."] Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS] ---------- + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + To search all directories of local fixed drives for DESKTOP.INI DLL launch points and all Registry CLSIDs for dormant Explorer Bars, use the -supp parameter or answer "No" at the first message box. ---------- (total run time: 106 seconds, including 13 seconds for message boxes) W logach nie widać niczego specjalnego poza aresem - to Twój program Spróbuj za pomocą Hijackowego Process managera zabić ten program i sprawdź czy zadziała. Panda jakie pliki wskazała jako wirusy I jaką ich nazwę podała W logach nie widać niczego specjalnego poza aresem - to Twój program Spróbuj za pomocą Hijackowego Process managera zabić ten program i sprawdź czy zadziała. Panda jakie pliki wskazała jako wirusy I jaką ich nazwę podała Ares to prog do ściągania z p2p . panda wykryła wirusy: Exploit/LSASS, i kilka prodramów szpiegujących, a Ares jest mojm p2p No to odp. prosta usuń to. |
||||
Wszelkie Prawa ZastrzeĹźone! chomiki Design by SZABLONY.maniak.pl. | |||||