Jump to content

SUBIECTE NOI
« 1 / 5 »
RSS
Mezina familiei, Merida BigNine

The Tattooist of Auschwitz (2024)

Se poate recupera numar de telefo...

Upgrade de la MacBook Pro M1 cu 8...
 Ce tip de monitor am nevoie pt of...

Resoftare camera supraveghere

Cu ce va aparati de cainii agresi...

Nu imi platiti coletul cu cardul ...
 Exista vreun plan de terorizare p...

Schimbare adresa DNS IPv4 pe rout...

Recomandare Barebone

Monede JO 2024
 Suprasolicitare sistem electric

CIV auto import

Mutare in MOZAMBIC - pareri, expe...

Scoatere antifurt airtag de pe ha...
 

HijackThis - alexxx21a

- - - - -
  • Please log in to reply
50 replies to this topic

#37
alexxx21a

alexxx21a

    Junior Member

  • Grup: Members
  • Posts: 26
  • Înscris: 07.04.2010
Da am Avira , cel recomandat de voi . Cand am instalat windowsul am scos cablul de la net pana cand am instalat si antivirusul . Iar cand se blocheaza calculatorul si tot dau restarturi , cand incepe sa mearga atunci se deschide si umbrela acolo la iconita de la antivirus . Cand se tot blocheaza calculatorul inca nu apuca sa fie activ antivirusul ( nu se deschide umbrela )

#38
Official

Official

    Forzza ASA!

  • Grup: Senior Members
  • Posts: 3,327
  • Înscris: 27.03.2009
Pune un log HiJackThis. Stii cum, ca e al 3-lea :P

#39
alexxx21a

alexxx21a

    Junior Member

  • Grup: Members
  • Posts: 26
  • Înscris: 07.04.2010

Quote

Logfile of Trend Micro HiJackThis v2.0.4
Scan saved at 10:36:08 AM, on 9/15/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Documents and Settings\Fl0rYnAa\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\RunOnce: [IE8] rundll32 advpack.dll,LaunchINFSection IE8.INF,FirstUserStart (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [IE8] rundll32 advpack.dll,LaunchINFSection IE8.INF,FirstUserStart (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [IE8] rundll32 advpack.dll,LaunchINFSection IE8.INF,FirstUserStart (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [IE8] rundll32 advpack.dll,LaunchINFSection IE8.INF,FirstUserStart (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: CarbonPoker - {e4e8c758-34b4-44bb-8ef9-1f0786e81d2d} - C:\Documents and Settings\Fl0rYnAa\Start Menu\Programs\CarbonPoker\CarbonPoker.lnk (HKCU)
O17 - HKLM\System\CCS\Services\Tcpip\..\{241C2510-9839-4816-A317-365AB7F20270}: NameServer = 213.154.124.1 193.231.252.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{241C2510-9839-4816-A317-365AB7F20270}: NameServer = 213.154.124.1 193.231.252.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{241C2510-9839-4816-A317-365AB7F20270}: NameServer = 213.154.124.1 193.231.252.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 7113 bytes


#40
rootkit

rootkit

    Awake. Security DNA

  • Grup: Senior Members
  • Posts: 34,883
  • Înscris: 07.02.2007
Log-ul e curat.


Descarca

Dr.Web CureIt! 6.00.2

Scoate cablul de Internet, opreste protectia real-time(scutul) a antivirus-ului instalat pe PC si scaneaza full cu acest utilitar.

Initial, la rulare, Dr.Web CureIt! incepe un Express Scan. Apasa butonul Stop in dreapta cand acesta are culoarea verde.

Posted Image

Bifeaza apoi in stanga Complete Scan si asa in dreapta pe butonul verde Play.

Posted Image

La terminarea scanarii dezinfecteaza/sterge toate fisierele detectate.

Restart, activeaza protectia antivirus, conecteaza cablul de internet.

#41
alexxx21a

alexxx21a

    Junior Member

  • Grup: Members
  • Posts: 26
  • Înscris: 07.04.2010
am incercat sa fac treaba aceasta , dar dupa 1 ora si 53 d eminute de scanare s-a blocat calculatorul. La fel nu mai puteam msca mouse-ul , iar ledurile erau aprinse . Nu a gasit nici un virus nimic pana atunci.

Nu poate fi probleme de la vreo componenta a calculatorului sau ceva? Procesor , placa video/de baza HDD ?

#42
rootkit

rootkit

    Awake. Security DNA

  • Grup: Senior Members
  • Posts: 34,883
  • Înscris: 07.02.2007
Incearca scanarea in Safe Mode.

#43
alexxx21a

alexxx21a

    Junior Member

  • Grup: Members
  • Posts: 26
  • Înscris: 07.04.2010
Am incercat si in Safe Mode si la fel s-a intamplat , dupa aproximativ vreo 15 minute s-a blocat iarasi calculatorul.

#44
rootkit

rootkit

    Awake. Security DNA

  • Grup: Senior Members
  • Posts: 34,883
  • Înscris: 07.02.2007
Descarca Dr. Web Rescue CD:

ftp://ftp.drweb.com/pub/drweb/livecd/

Se arde pe un CD imaginea(recomand Active@ ISO Burner pentru ardere, daca folosesti altceva, selecteaza functia Burn Image)

http://www.softpedia...SO-Burner.shtml

[ http://www.softpedia.com/screenshots/Windows-Portable-Applications-Portable-Active-ISO-Burner_1.png - Pentru incarcare in pagina (embed) Click aici ]

Restart PC,bootezi de pe CD si scanezi.

#45
alexxx21a

alexxx21a

    Junior Member

  • Grup: Members
  • Posts: 26
  • Înscris: 07.04.2010
La fel s-a intamplat si asa . Si vreau doar sa mentionez ceva : la ATI .. pe la driverele instalate control panel ATi sua ce mai e pe acolo a scanat foarteee mult , iar in cele din urma s-a blocat si calculatorul

#46
alexxx21a

alexxx21a

    Junior Member

  • Grup: Members
  • Posts: 26
  • Înscris: 07.04.2010
Scuze de double-posting , dar nu a raspuns nimeni si vreau doar sa va intreb ceva de urgenta .
AM reinstalat windowsul pentru ca azi dimineata cand am pornit calculatorul se restarta una-intruna nu apuca sa intre in windows si se restarta , la fel si in safe Mode .


Vreau sa va intreb ce program imi trebuie sa fac un back-up sau cum se numeste , adica ce vreau sa spun , dupa ce am instalat windowsul si programele necesare sa fac acel back-up , astfel incat in cacul in care am nevoie sa instalez iarasi windowsul sa rulez doar acel program si sa o ia din punctul de unde am terminat cu windowsul si programele instalate.  Multumesc frumos !

#47
rootkit

rootkit

    Awake. Security DNA

  • Grup: Senior Members
  • Posts: 34,883
  • Înscris: 07.02.2007
Acronis True Image il recomand eu :)

#48
alexxx21a

alexxx21a

    Junior Member

  • Grup: Members
  • Posts: 26
  • Înscris: 07.04.2010
Mersi , si legat de problema asta alte solutii mai aveti ? :) .. sau sa ma indrumati spre o alta sectie daca ar fi problema din cauza unor componente sua ceva ?! :-??

#49
rootkit

rootkit

    Awake. Security DNA

  • Grup: Senior Members
  • Posts: 34,883
  • Înscris: 07.02.2007
Restart-urile nu sunt un semn bun. Ori e conflict de drivere ori e o componenta hardware ce genereaza problema.

#50
alexxx21a

alexxx21a

    Junior Member

  • Grup: Members
  • Posts: 26
  • Înscris: 07.04.2010
Mai am o intrebare  :)

Versiunea aceasta : Windows XP Service Pack 3 Build 5512 FINAL: Free Download  , care este disponibila la download de pe site-ul vostru este in regula ? e functionala ? Ca as vrea sa incerc poate si cu alte variante de windows .




PS : legat de blocarea calculatorului citeam prin sectiunea WINDOWS pe la un tip cum ca i s-ar fi blocat calculatorul si i s-a cerut un folder din C/windows/MINIDUMP sau ceva de genul ... poate fi pe acolo problema ?

Edited by alexxx21a, 20 September 2010 - 01:24.


#51
rootkit

rootkit

    Awake. Security DNA

  • Grup: Senior Members
  • Posts: 34,883
  • Înscris: 07.02.2007
Ala de pe Softpedia e doar Update, nu e Windows complet.

Anunturi

Bun venit pe Forumul Softpedia!

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Forumul Softpedia foloseste "cookies" pentru a imbunatati experienta utilizatorilor Accept
Pentru detalii si optiuni legate de cookies si datele personale, consultati Politica de utilizare cookies si Politica de confidentialitate