![]() |
| | #1 (permalink) | ||
| Virus sau ?
sal all, de fiecare data cand instalez windows`ul, imi da acest msg si la kaspersky si la nod32, este virus sau ?, daca il sterg imi va da erroare si la aprindere si la stingerea pc`ului, ce sa fac ?
__________________ DualCore X2 4400+<>Gigabyte G-Power Lite Cooler <>Mb M2A-VM Asus<>Power Color ATI Radeon X800 Series256/256<>Kingmax 1x2Gb 800Mhz+2x1Gb OCZ Gold 800Mhz<>WD 300Gb SATA<>Asus Drw-2014L1T<>LC Power 550W<>Raidmax Smilodon<>DELL P1130<>Logitech Z-5500 Last edited by Preotu*; 03-07-2008 at 19:12.. | |||
|
| | #2 (permalink) | ||
|
nu e virus... dar ar trebui sa fii atent la ce soft folosesti... mai demult spre ex. era o versiune "DivX Gain Bundle" a carui licenta era gratuita daca acceptai sa instalezi si adware/spyware-ul inclus (tot GATOR). probabil ai instalat vreun program de genul asta ce contine adware. mai degraba rezolvi problema asta cu un anti-spyware (SUPERAntiSpyware, Spybot Search & Destroy, Ad-Aware SE etc). o alta idee ar fi sa dezinstalezi programul vinovat (daca-l descoperi) si astfel va fi probabil eliminat si spyware-ul cu care venise.
__________________ I dream, I dream I’m floating on the surface of my own life, watching it unfold, observing it, I’m the outsider looking in... Last edited by Unbreakable; 03-07-2008 at 19:36.. | |||
|
| | #4 (permalink) | ||
|
vin si eu cu o problema. Pe un sistem cu Windows Vista Home Premium, Kaspersky antivirus 2009 updatat pana acum 2 saptamani si cu Windows Defender activat, imi apare "eroarea" din imaginea de mai jos NUMAI cand deschid Windows Explorer sau Internet Explorer (versiunea 7). Cert e ca m-am captusit cu "ceva", dar nu stiu cum si cu ce anume. Regulile securitatii de bun simt se aplica, adica folosesc Firefox, Windows actualizat, nu vizitez pagini web cu pr0n gratis, nu primesc poze cu "Britney_dezbracata.jpg.exe" s.a.m.d.. Indiferent daca accept sau nu, automat se deschide o pagina web pe care Firefox-ul o blocheaza. Nu gasesc dracovenia asta deloc. Am dat scan cu Kaspersky si cu Windows Defender, dar nu au gasit nimic. M-am uitat si in Process Explorer sa vad daca apare ceva suspect, iar in HijackThis nu am vazut nimic suspect. Pun totusi si log-ul HjacThis, poate mie imi scapa ceva. Astept cateva sugestii. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 1:36:19, on 03/08/2008 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Program Files\ASUS\AASP\1.00.52\aaCenter.exe C:\Windows\Explorer.EXE D:\Software\Network & Internet\NetLimiter 2 Pro\NLClient.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Windows\System32\rundll32.exe D:\Software\Securitate\Kaspersky\avp.exe D:\Software\Unelte\DAEMON Tools Lite\daemon.exe C:\Windows\system32\wbem\unsecapp.exe D:\Software\Network & Internet\Thunderbird\thunderbird.exe D:\Software\Network & Internet\Firefox\firefox.exe D:\Software\Unelte\totalcmd\TOTALCMD.EXE D:\Software\Unelte\FastStone Capture\FSCapture.exe C:\Windows\system32\DllHost.exe D:\Software\Securitate\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - D:\Software\Securitate\Kaspersky\ievkbd.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - D:\Software\Network & Internet\Free Download Manager\iefdm2.dll O2 - BHO: IE.Filter - {F65E955E-26C0-42FF-8EE2-443A05EA286A} - C:\Windows\system32\IE_FIL~1.DLL O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [AVP] "D:\Software\Securitate\Kaspersky\avp.exe" O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Software\Unelte\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [Messenger (Yahoo!)] "D:\Software\Network & Internet\Yahoo! Messenger\Messenger\YahooMessenger.exe" -quiet O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "D:\Software\Unelte\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "D:\Software\Unelte\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user') O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Software\Securitate\Kaspersky\SCIEPlgn.dll O13 - Gopher Prefix: O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: D:\Software\SECURI~1\KASPER~1\mzvkbd.dll O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - D:\Software\Securitate\Kaspersky\avp.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: NetLimiter (nlsvc) - Locktime Software - D:\Software\Network & Internet\NetLimiter 2 Pro\nlsvc.exe O23 - Service: NMSAccessU - Unknown owner - D:\Software\Unelte\CDBurnerXP\NMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- End of file - 5908 bytes
__________________ Do you know the difference between an error and a mistake? Anyone can make an error. But that error does not become a mistake until you refuse to correct it. | |||
|
| | #5 (permalink) | ||
| Registered User Join Date: Apr 2005 Location: Bucuresti |
am avut aceeasi problema la serviciu pe un calc. si la o scanare on-line cu kaspersky mi-a raportat infectat un fisier din \windows\system32\, ceva de genul "aol_???.dll" ("?" - vine de la ce nu-mi mai amintesc din numele fisierului) vezi si tu pe acolo, ar trebui sa fie singurul cu nume apropiat... sterge-l manual si restarteaza... mie imi pare suspect si procesul de mai jos din quote "AOLAcsd.exe"... bafta! Quote:
| ||
|
| | #6 (permalink) | ||
|
SeikQ, deschide Hijackthis cu click drepta - Run as administrator, bifeaza O2 - BHO: IE.Filter - {F65E955E-26C0-42FF-8EE2-443A05EA286A} - C:\Windows\system32\IE_FIL~1.DLL si asasa fixed checked. Descarca FixIEDef, laseaza tot cu Run as administrator si lasa-l sa scaneze- http://www.malwareteks.com/FixIEDef.php#Download Dupa ce termina mai posteaza un log de Hijackthis! | |||
|
| | #7 (permalink) | ||
|
adybyron - procesul respectiv e AOL pe care il am instalat de ceva timp si nu mi-a facut probleme Johny Quest - am facut asa cum ai spus si se pare ca respectiva "eroare" nu mai apare. FixIEDef nu a raportat nimic. In fine, mai jos log-ul HijackThis C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Windows\System32\rundll32.exe D:\Software\Securitate\Kaspersky\avp.exe D:\Software\Unelte\DAEMON Tools Lite\daemon.exe C:\Windows\system32\wbem\unsecapp.exe D:\Software\Network & Internet\Yahoo! Messenger\Messenger\ymsgr_tray.exe C:\FixIEDef.exe C:\Windows\explorer.exe D:\Software\Securitate\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - D:\Software\Securitate\Kaspersky\ievkbd.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - D:\Software\Network & Internet\Free Download Manager\iefdm2.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [AVP] "D:\Software\Securitate\Kaspersky\avp.exe" O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Software\Unelte\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [Messenger (Yahoo!)] "D:\Software\Network & Internet\Yahoo! Messenger\Messenger\YahooMessenger.exe" -quiet O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "D:\Software\Unelte\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "D:\Software\Unelte\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user') O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Software\Securitate\Kaspersky\SCIEPlgn.dll O13 - Gopher Prefix: O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: D:\Software\SECURI~1\KASPER~1\mzvkbd.dll O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - D:\Software\Securitate\Kaspersky\avp.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: NetLimiter (nlsvc) - Locktime Software - D:\Software\Network & Internet\NetLimiter 2 Pro\nlsvc.exe O23 - Service: NMSAccessU - Unknown owner - D:\Software\Unelte\CDBurnerXP\NMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- End of file - 5664 bytes
__________________ Do you know the difference between an error and a mistake? Anyone can make an error. But that error does not become a mistake until you refuse to correct it. | |||
|
| | #8 (permalink) | ||
|
Ciudat, ar fi trebuit sa-l vada FixIEDef. Deschide HijacktThis!, bifeaza O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) si apasa fixed checked. Descarca Pocket Killbox, deschide-l cu drept de administrator la path scrie C:\Windows\system32\IE_FIL~1.DLL si apasa delete file. Poti apoi sa stergi folderul C:\!KillBox | |||
|
| | #11 (permalink) | ||
|
Bun. Am revenit. Am descarcat Pocket Killbox, dar nu-mi porneste. apare o eroare "component 'MSCOMCTL.OCX' or one of its dependencies not correctly registered: a file is missing or invalid". In fine, banuiesc ca acest program trebuia sa stearga fisierul IE_FIL.dll. M-am uitat in directorul system32, iar acel fisier nu apare acolo. Probabil hijackThis l-a sters, pt. ca "mesajul" acela stresant nu mai apare.
__________________ Do you know the difference between an error and a mistake? Anyone can make an error. But that error does not become a mistake until you refuse to correct it. | |||
|
| Advertisment | |
![]() |
|
| Thread Tools | |
| |