mazāku kapitāla

Magazine
Go Back   Computer Sulas > Computer Software > Vīrusu, spiegprogrammatūru un drošība

Register


 Default 

Please help-dators darbojas ļoti lēni, vīrusu?




Reply
 
Thread Tools
  #1  
Old Marts 26, 2008, 15:42
New Member Group
 
Default Please help-dators darbojas ļoti lēni, vīrusu?

HELLO - manu datoru, jo pēdējo dienu laikā ir sagatavojusi un vadījusi tiešām lēni, man ir beigušies Spybot, viņi atrada bunch of stuff un acīmredzot vaļā no tā -, bet tagad mans dators joprojām ir lēns .. Please help ... Šeit ir mana HJT log failu ...
  #2  
Old Marts 26, 2008, 15:43
New Member Group
 
Default Please help-dators darbojas ļoti lēni, vīrusu?

Logfile of HijackThis v1.99.1
Scan saglabāts 6:47:29 gada 3/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running procesiem:
C: \ WINDOWS \ System32 \ Smss.exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ Program Files \ Alwil Software \ Avast4 \ aswUpdSv.exe
C: \ Program Files \ Alwil Software \ Avast4 \ ashServ.exe
C: \ WINDOWS \ system32 \ Spoolsv.exe
C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe
C: \ Program Files \ Common Files \ Microsoft Shared \ VS7DEBUG \ MDM.EXE
C: \ WINDOWS \ System32 \ nvsvc32.exe
C: \ WINDOWS \ system32 \ PRISMSVC.EXE
C: \ WINDOWS \ System32 \ svchost.exe
C: \ Program Files \ Alwil Software \ Avast4 \ ashMaiSv.exe
C: \ Program Files \ Alwil Software \ Avast4 \ ashWebSv.exe
C: \ Windows \ Explorer.exe
C: \ WINDOWS \ system32 \ PRISMSVR.EXE
C: \ WINDOWS \ ALCXMNTR.EXE
C: \ WINDOWS \ LTMSG.exe
C: \ WINDOWS \ System32 \ spool \ drivers \ W32X86 \ 3 \ E_FATI9 FA.EXE
C: \ PROGRA ~ 1 \ ALWILS ~ 1 \ Avast4 \ ashDisp.exe
C: \ Program Files \ QuickTime \ QTTask.exe
C: \ Program Files \ iTunes \ iTunesHelper.exe
C: \ Program Files \ Adobe \ Adobe Photoshop Lightroom 1,2 \ apdproxy.exe
C: \ WINDOWS \ system32 \ ctfmon.exe
C: \ Program Files \ BitTorrent \ bittorrent.exe
C: \ Program Files \ Spybot - Search & Destroy \ TeaTimer.exe
C: \ WINDOWS \ system32 \ rundll32.exe
C: \ Program Files \ Dell Wireless \ PRISMCFG.exe
C: \ Program Files \ limewire \ LimeWire.exe
C: \ Program Files \ Stardock \ ObjectDock \ ObjectDock.exe
C: \ Program Files \ Mozilla Firefox \ firefox.exe
C: \ Program Files \ iPod \ bin \ iPodService.exe
C: \ Documents and Settings \ Neven \ Desktop \ sniper.exe

R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Search Bar = http://red.clientapps.yahoo.com/cust...search/ie.html
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.finderg.com
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Bar = http://red.clientapps.yahoo.com/cust...search/ie.html
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU \ Software \ Microsoft \ Internet Connection Wizard, ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Adobe \ Acrobat 7,0 \ ActiveX \ AcroIEHelper.dll
O2 - BHO: Spybot-S & D IE Protection - (53.707.962-6F74-2D53-2.644-206D7942484F) - C: \ Program Files \ Spybot - Search & Destroy \ SDHelper.dll
O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll
O4 - HKLM \ .. \ Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM \ .. \ Run: [NvCplDaemon] RUNDLL32.EXE C: \ WINDOWS \ System32 \ NvCpl.dll, NvStartup
O4 - HKLM \ .. \ Run: [nwiz] nwiz.exe / installquiet / keeploaded / nodetect
O4 - HKLM \ .. \ Run: [LTMSG] LTMSG.exe 7
O4 - HKLM \ .. \ Run: [EPSON Stylus Photo R320 Series] C: \ WINDOWS \ System32 \ spool \ drivers \ W32X86 \ 3 \ E_FATI9 FA.EXE / P30 "EPSON Stylus Photo R320 Series" / O6 "USB002" / M "Stylus Photo R320"
O4 - HKLM \ .. \ Run: [ProfileWatcher] C: \ Program Files \ ProfileWatcher \ profilewatcher.exe
O4 - HKLM \ .. \ Run: [Avast!] C: \ PROGRA ~ 1 \ ALWILS ~ 1 \ Avast4 \ ashDisp.exe
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ QTTask.exe"-atboottime
O4 - HKLM \ .. \ Run: [iTunesHelper] "C: \ Program Files \ iTunes \ iTunesHelper.exe"
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.6.0_02 \ bin \ jusched.exe"
O4 - HKLM \ .. \ Run: [Adobe Photo Downloader] "C: \ Program Files \ Adobe \ Adobe Photoshop Lightroom 1,2 \ apdproxy.exe"
O4 - HKCU \ .. \ Run: [Yahoo! Peidžeri] C: \ PROGRA ~ 1 \ Yahoo! \ MESSEN ~ 1 \ ypager.exe-kluss
O4 - HKCU \ .. \ Run: [ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe
O4 - HKCU \ .. \ Run: [BitTorrent] "C: \ Program Files \ BitTorrent \ bittorrent.exe" - force_start_minimized
O4 - HKCU \ .. \ Run: [SpybotSD TeaTimer] C: \ Program Files \ Spybot - Search & Destroy \ TeaTimer.exe
O4 - Startup: limewire On Startup.lnk = C: \ Program Files \ limewire \ LimeWire.exe
O4 - Startup: Stardock ObjectDock.lnk = C: \ Program Files \ Stardock \ ObjectDock \ ObjectDock.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C: \ Program Files \ Adobe \ Acrobat 7,0 \ Reader \ reader_sl.exe
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk =?
Ø8 - ārpus konteksta menu item: & Search -? P = ZK
Ø8 - ārpus konteksta menu item: E & ksportēt uz Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ Micros ~ 2 \ Office11 \ EXCEL.EXE/3000
Ø9 - Extra button: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll
Ø9 - Extra 'Tools' MENUITEM: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll
Ø9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ Micros ~ 2 \ Office11 \ REFIEBAR.DLL
Ø9 - Extra button: (no name) - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ Program Files \ Spybot - Search & Destroy \ SDHelper.dll
Ø9 - Extra 'Tools' MENUITEM: Spybot - Search & & Destroy Configuration - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ Program Files \ Spybot - Search & Destroy \ SDHelper.dll
Ø9 - Extra button: PokerStars.net - (FA9B9510-9FCB-4ca0-818C-5D0987B47C4D) - C: \ Program Files \ PokerStars.NET \ PokerStarsUpdate.exe
Ø9 - Extra button: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
Ø9 - Extra 'Tools' MENUITEM: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
Ø11 - grupā Opcijas: [INTERNATIONAL] International *
Ø16 - DPF: (200B3EE9-7.242-4EFD-B1E4-D97EE825BA53) (VerifyGMN klase) -- http://h20270.www2.hp.com/ediags/gmn...taller_gmn.cab
Ø16 - DPF: (30.528.230-99f7-4bb4-88d8-fa1d4f56a2ab) --
Ø16 - DPF: (6414512B-B978-451D-A0D8-FCFDF33E833C) (WUWebControl klase) -- http://update.microsoft.com/windowsu...?1162589752500
Ø16 - DPF: (6E32070A-766D-4EE6-879C-DC1FA91D2FC3) (MUWebControl klase) -- http://update.microsoft.com/microsof...?1162829153500
Ø16 - DPF: (AB86CE53-AC9F-449F-9.399-D8ABCA09EC09) (Get_ActiveX Control) -- https: / / h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx
Ø16 - DPF: (D18F962A-3.722-4B59-B08D-28BB9EB2281E) (PhotosCtrl klase) -- http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
Ø16 - DPF: (D27CDB6E-AE6D-11CF-96B8-444.553.540.000) (Shockwave Flash Object) -- http://fpdownload2.macromedia.com/ge...sh/swflash.cab
Ø20 - Winlogon Paziņot: PRISMAPI.DLL - C: \ WINDOWS \ SYSTEM32 \ PRISMAPI.DLL
Ø20 - Winlogon Paziņot: PRISMGNA.DLL - C: \ WINDOWS \ SYSTEM32 \ PRISMGNA.DLL
Ø20 - Winlogon Paziņot: WgaLogon - C: \ WINDOWS \ SYSTEM32 \ WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C: \ Program Files \ Common Files \ Adobe Systems Shared \ Service \ Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc - C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe
O23 - Service: Avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C: \ Program Files \ Alwil Software \ Avast4 \ aswUpdSv.exe
O23 - Service: Avast! Antivirus - ALWIL Software - C: \ Program Files \ Alwil Software \ Avast4 \ ashServ.exe
O23 - Service: Avast! Mail Scanner - Unknown īpašnieks - C: \ Program Files \ Alwil Software \ Avast4 \ ashMaiSv.exe "/ service (file missing)
O23 - Service: Avast! Web Scanner - Unknown īpašnieks - C: \ Program Files \ Alwil Software \ Avast4 \ ashWebSv.exe "/ service (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd - C: \ Program Files \ Common Files \ Macrovision Shared \ FLEXnet Publisher \ FNPLicensingService.exe
O23 - Service: hpdj - Unknown īpašnieks - C: \ DOCUME ~ 1 \ Īpašnieks \ Lokālie ~ 1 \ Temp \ hpdj.exe (file missing)
O23 - Service: iPod Service - Apple Inc - C: \ Program Files \ iPod \ bin \ iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C: \ WINDOWS \ System32 \ nvsvc32.exe
O23 - Service: PRISMSVC - Conexant Systems, Inc - C: \ WINDOWS \ system32 \ PRISMSVC.EXE
  #3  
Old Marts 26, 2008, 16:35
Moderator Group
 
Default Please help-dators darbojas ļoti lēni, vīrusu?

Jums ir kādas malware norādot žurnālā. Lūdzu, dodieties ŠEIT un do CCleaner, Superantispyware un MBAM skenēšanu. Post žurnālus, kad pabeigta līdz ar jaunu HijackThis log. Pārliecinieties, ne palaist HijackThis tikai pēc citu skenē, ir pilnīgi un dators ir jāatsāk.

Atzīmēt Ir ierosināts, lai dotos uz Pievienot / noņemt programmas un atinstalēt ProfileWatcher.

Quote:
ProfileWatcher:
Infiltrātu jūsu myspace kontu un nosūta reklāmas visās Jūsu draugu komentāri lapā.
__________________

  #4  
Old 2 aprīlis 2008, 15:10
New Member Group
 
Default Please help-dators darbojas ļoti lēni, vīrusu?

Tas ir Malwarebytes log
Attached Files
File Type: txt mbam-log-3-28-2008 (19-53-55). txt (2.2 KB, 5 viedokļi)
  #5  
Old 2 aprīlis 2008, 15:11
New Member Group
 
Default Please help-dators darbojas ļoti lēni, vīrusu?

tas HijackThis log
Logfile of HijackThis v1.99.1
Scan saglabāts 6:16:51 gada 4/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running procesiem:
C: \ WINDOWS \ System32 \ Smss.exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ Program Files \ Alwil Software \ Avast4 \ aswUpdSv.exe
C: \ Program Files \ Alwil Software \ Avast4 \ ashServ.exe
C: \ WINDOWS \ system32 \ Spoolsv.exe
C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe
C: \ Program Files \ Common Files \ Microsoft Shared \ VS7DEBUG \ MDM.EXE
C: \ WINDOWS \ System32 \ nvsvc32.exe
C: \ WINDOWS \ system32 \ PRISMSVC.EXE
C: \ WINDOWS \ System32 \ svchost.exe
C: \ Program Files \ Alwil Software \ Avast4 \ ashMaiSv.exe
C: \ Program Files \ Alwil Software \ Avast4 \ ashWebSv.exe
C: \ Windows \ Explorer.exe
C: \ WINDOWS \ system32 \ PRISMSVR.EXE
C: \ WINDOWS \ ALCXMNTR.EXE
C: \ WINDOWS \ LTMSG.exe
C: \ WINDOWS \ System32 \ spool \ drivers \ W32X86 \ 3 \ E_FATI9 FA.EXE
C: \ PROGRA ~ 1 \ ALWILS ~ 1 \ Avast4 \ ashDisp.exe
C: \ Program Files \ QuickTime \ QTTask.exe
C: \ Program Files \ iTunes \ iTunesHelper.exe
C: \ Program Files \ Adobe \ Adobe Photoshop Lightroom 1,2 \ apdproxy.exe
C: \ WINDOWS \ system32 \ ctfmon.exe
C: \ WINDOWS \ system32 \ rundll32.exe
C: \ Program Files \ Dell Wireless \ PRISMCFG.exe
C: \ Program Files \ limewire \ LimeWire.exe
C: \ Program Files \ iPod \ bin \ iPodService.exe
C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe
C: \ Program Files \ Mozilla Firefox \ firefox.exe
C: \ Documents and Settings \ Neven \ Desktop \ sniper.exe

R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Search Bar = http://red.clientapps.yahoo.com/cust...search/ie.html
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.finderg.com
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Bar = http://red.clientapps.yahoo.com/cust...search/ie.html
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU \ Software \ Microsoft \ Internet Connection Wizard, ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R3 - URLSearchHook: Yahoo! Toolbar - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ Program Files \ Yahoo! \ Companion \ installs \ CPN \ yt.dll
O2 - BHO: Yahoo! Toolbar Helper - (02478D38-C3F9-4EFB-9B51-7695ECA05670) - C: \ Program Files \ Yahoo! \ Companion \ installs \ CPN \ yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Adobe \ Acrobat 7,0 \ ActiveX \ AcroIEHelper.dll
O2 - BHO: Spybot-S & D IE Protection - (53.707.962-6F74-2D53-2.644-206D7942484F) - C: \ Program Files \ Spybot - Search & Destroy \ SDHelper.dll
O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll
O3 - Toolbar: Yahoo! Toolbar - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ Program Files \ Yahoo! \ Companion \ installs \ CPN \ yt.dll
O4 - HKLM \ .. \ Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM \ .. \ Run: [NvCplDaemon] RUNDLL32.EXE C: \ WINDOWS \ System32 \ NvCpl.dll, NvStartup
O4 - HKLM \ .. \ Run: [nwiz] nwiz.exe / installquiet / keeploaded / nodetect
O4 - HKLM \ .. \ Run: [LTMSG] LTMSG.exe 7
O4 - HKLM \ .. \ Run: [EPSON Stylus Photo R320 Series] C: \ WINDOWS \ System32 \ spool \ drivers \ W32X86 \ 3 \ E_FATI9 FA.EXE / P30 "EPSON Stylus Photo R320 Series" / O6 "USB002" / M "Stylus Photo R320"
O4 - HKLM \ .. \ Run: [ProfileWatcher] C: \ Program Files \ ProfileWatcher \ profilewatcher.exe
O4 - HKLM \ .. \ Run: [Avast!] C: \ PROGRA ~ 1 \ ALWILS ~ 1 \ Avast4 \ ashDisp.exe
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ QTTask.exe"-atboottime
O4 - HKLM \ .. \ Run: [iTunesHelper] "C: \ Program Files \ iTunes \ iTunesHelper.exe"
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.6.0_02 \ bin \ jusched.exe"
O4 - HKLM \ .. \ Run: [Adobe Photo Downloader] "C: \ Program Files \ Adobe \ Adobe Photoshop Lightroom 1,2 \ apdproxy.exe"
O4 - HKCU \ .. \ Run: [Yahoo! Peidžeri] C: \ PROGRA ~ 1 \ Yahoo! \ MESSEN ~ 1 \ ypager.exe-kluss
O4 - HKCU \ .. \ Run: [ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe
O4 - HKCU \ .. \ Run: [BitTorrent] "C: \ Program Files \ BitTorrent \ bittorrent.exe" - force_start_minimized
O4 - HKCU \ .. \ Run: [SpybotSD TeaTimer] C: \ Program Files \ Spybot - Search & Destroy \ TeaTimer.exe
O4 - HKCU \ .. \ Run: [SUPERAntiSpyware] C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe
O4 - Startup: limewire On Startup.lnk = C: \ Program Files \ limewire \ LimeWire.exe
O4 - Startup: Stardock ObjectDock.lnk = C: \ Program Files \ Stardock \ ObjectDock \ ObjectDock.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C: \ Program Files \ Adobe \ Acrobat 7,0 \ Reader \ reader_sl.exe
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk =?
Ø8 - ārpus konteksta menu item: & Search -? P = ZK
Ø8 - ārpus konteksta menu item: E & ksportēt uz Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ Micros ~ 2 \ Office11 \ EXCEL.EXE/3000
Ø9 - Extra button: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll
Ø9 - Extra 'Tools' MENUITEM: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll
Ø9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ Micros ~ 2 \ Office11 \ REFIEBAR.DLL
Ø9 - Extra button: (no name) - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ Program Files \ Spybot - Search & Destroy \ SDHelper.dll
Ø9 - Extra 'Tools' MENUITEM: Spybot - Search & & Destroy Configuration - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ Program Files \ Spybot - Search & Destroy \ SDHelper.dll
Ø9 - Extra button: PokerStars.net - (FA9B9510-9FCB-4ca0-818C-5D0987B47C4D) - C: \ Program Files \ PokerStars.NET \ PokerStarsUpdate.exe
Ø9 - Extra button: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
Ø9 - Extra 'Tools' MENUITEM: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
Ø11 - grupā Opcijas: [INTERNATIONAL] International *
Ø16 - DPF: (200B3EE9-7.242-4EFD-B1E4-D97EE825BA53) (VerifyGMN klase) -- http://h20270.www2.hp.com/ediags/gmn...taller_gmn.cab
Ø16 - DPF: (30.528.230-99f7-4bb4-88d8-fa1d4f56a2ab) (YInstStarter klase) - C: \ Program Files \ Yahoo! \ Common \ yinsthelper.dll
Ø16 - DPF: (6414512B-B978-451D-A0D8-FCFDF33E833C) (WUWebControl klase) -- http://update.microsoft.com/windowsu...?1162589752500
Ø16 - DPF: (6E32070A-766D-4EE6-879C-DC1FA91D2FC3) (MUWebControl klase) -- http://update.microsoft.com/microsof...?1162829153500
Ø16 - DPF: (AB86CE53-AC9F-449F-9.399-D8ABCA09EC09) (Get_ActiveX Control) -- https: / / h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx
Ø16 - DPF: (D18F962A-3.722-4B59-B08D-28BB9EB2281E) (PhotosCtrl klase) -- http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
Ø16 - DPF: (D27CDB6E-AE6D-11CF-96B8-444.553.540.000) (Shockwave Flash Object) -- http://fpdownload2.macromedia.com/ge...sh/swflash.cab
Ø20 - Winlogon Paziņot:! SASWinLogon - C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.dll
Ø20 - Winlogon Paziņot: PRISMAPI.DLL - C: \ WINDOWS \ SYSTEM32 \ PRISMAPI.DLL
Ø20 - Winlogon Paziņot: PRISMGNA.DLL - C: \ WINDOWS \ SYSTEM32 \ PRISMGNA.DLL
Ø20 - Winlogon Paziņot: WgaLogon - C: \ WINDOWS \ SYSTEM32 \ WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C: \ Program Files \ Common Files \ Adobe Systems Shared \ Service \ Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc - C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe
O23 - Service: Avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C: \ Program Files \ Alwil Software \ Avast4 \ aswUpdSv.exe
O23 - Service: Avast! Antivirus - ALWIL Software - C: \ Program Files \ Alwil Software \ Avast4 \ ashServ.exe
O23 - Service: Avast! Mail Scanner - Unknown īpašnieks - C: \ Program Files \ Alwil Software \ Avast4 \ ashMaiSv.exe "/ service (file missing)
O23 - Service: Avast! Web Scanner - Unknown īpašnieks - C: \ Program Files \ Alwil Software \ Avast4 \ ashWebSv.exe "/ service (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd - C: \ Program Files \ Common Files \ Macrovision Shared \ FLEXnet Publisher \ FNPLicensingService.exe
O23 - Service: hpdj - Unknown īpašnieks - C: \ DOCUME ~ 1 \ Īpašnieks \ Lokālie ~ 1 \ Temp \ hpdj.exe (file missing)
O23 - Service: iPod Service - Apple Inc - C: \ Program Files \ iPod \ bin \ iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C: \ WINDOWS \ System32 \ nvsvc32.exe
O23 - Service: PRISMSVC - Conexant Systems, Inc - C: \ WINDOWS \ system32 \ PRISMSVC.EXE
  #6  
Old 2 aprīlis 2008, 15:13
New Member Group
 
Default Please help-dators darbojas ļoti lēni, vīrusu?

un tas ir superantispyware log --- Es zinu, tu dzirdi tas daudz - bet jūs patiešām lifesaver thank you very much ----

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 03/28/2008 at 08:37

Application Version: 4.0.1154

Core Noteikumi Database Version: 3426
Trace Noteikumi Database Version: 1418

Scan type: Complete Scan
Kopā Scan Time: 00:42:44

Atmiņas vienības skenēts: 515
Memory draudiem detected: 0
Reģistra vienības skenēts: 5.073
Reģistrs draudiem detected: 0
File preces skenēts: 15.903
File draudiem detected: 0


mans dators joprojām ir lēns - nē, jo skenē izmaiņas ...
  #7  
Old 2 aprīlis 2008, 15:20
Moderator Group
 
Default Please help-dators darbojas ļoti lēni, vīrusu?

Mums ir nepieciešams palaist jaudīgāku skenēšanu. Tā neveiks ļoti ilgi.

Lūdzu, lejupielādējiet Combofix ar subs no vienas no saitēm.
(Try visi trīs, ja nepieciešams)Svarīgi! Combofix.exe Jābūt saglabāt un ilga no Desktop.
  • Aizveriet visas atvērtās interneta pārlūkprogrammas. (Firefox, Internet Explorer uc) pirms uzsākt Combofix.
  • Svarīgi! Laiku sakropļot jūsu antivīruss, script bloķēšana un visiem antispyware reāllaika aizsardzību pirms veic skenēšanu.
    • Click šo saiti redzēt sarakstu drošības programmas, kas ir invalīdi un to, kā pārtraukt to darbību.
    • Ja jūsu valsts nav sarakstā, un jūs nezināt, kā atspējot, lūdzu, jautājiet.
  • Brīdinājums: Combofix atvieno datoru no interneta. Savienojums tiek automātiski atjaunots pirms Combofix pabeidz palaist.
  • Dubultklikšķi combofix.exe un sekojiet norādījumiem.
    • Izvēlieties Jā, lai akceptētu atrunas.[
  • Kad pabeigts, tas rada log for you.
  • Dienests, log jūsu nākamo atbildi.
Brīdinājums: Nav mouseclick combofix loga kamēr tas darbojas. Tas var izraisīt to stall
  • Ja Combofix nokļūst grūtībās, un to beidz priekšlaicīgi, savienojumu var manuāli atjaunoja restartējot datoru.
  • Svarīgi: Atcerieties, ka jauna aktivizētu jūsu antivīrusu un antispyware, pirms atjaunot saikni ar internetu.
__________________

  #8  
Old 2 aprīlis 2008, 15:38
New Member Group
 
Default Please help-dators darbojas ļoti lēni, vīrusu?

Šeit ir combofix log
Attached Files
File Type: txt ComboFix.txt (8.7 KB, 8 viedokļi)
  #9  
Old 2 aprīlis 2008, 15:57
Moderator Group
 
Default Please help-dators darbojas ļoti lēni, vīrusu?

Open HijackThis un izvēlieties Vai sistēmas skenēšanu tikai pēc tam notiek atzīmi blakus šīm enteies.

R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.finderg.com
Ø8 - ārpus konteksta menu item: & Search -? P = ZK

Aizveriet visus logus, izņemot HijackThis un noklikšķiniet uz Labot pārbaudīt.

----------

Lūdzu, apskatiet F-Secure Online Scanner

Piezīme: Šajā Scanner darbojas ar Internet Explorer Tikai!
  • Ritiniet līdz apakšā lapu un noklikšķiniet uz Sākt skenēšanu pogu. Logs pop up.
  • Ļauj ActiveX kontrole ir instalēta jūsu datorā, noklikšķiniet uz Akceptēt pogas
  • Click Full System Scan un ļauj komponentu lejupielādēt un skenēšanu, lai to pabeigtu.
  • Ja malware tiek konstatēts, pārbaudiet Iesniegt paraugu F-Secure pēc tam izvēlieties Automātiskā tīrīšana
  • Tīrot ir finitished, noklikšķiniet uz Parādīt ziņojumu (tas atvērs Internet Explorer logu, kas satur ziņojumu)
  • Izcelt un Copy (CTRL + C) pilnīgs ziņojums, un Paste (CTRL + V), jaunu atbildi uz šo ziņu
    • Ja automātiskā tīrīšana ar iesniegtu paraugus uzkaras, noklikšķiniet uz Atcelt, Tad New Scan
  • Kad tīrīšana opcija ir iesniegts Neatķeksējiet Iesniegt paraugu F-Secure
  • Click Automātiskā tīrīšana
  • Tīrot ir finitished, noklikšķiniet uz Rādīt ziņojumu (tas būs atvērts Internet Explorer logu, kas satur ziņojumu)
  • Izcelt un Copy (CTRL + C) pilnīgs ziņojums, un Paste (CTRL + V), jaunu atbildi uz šo amatu.

Šī scan var būt ilgu laiku, tāpēc, lūdzu, esiet pacietīgi
__________________

  #10  
Old 2 aprīlis 2008, 17:41
New Member Group
 
Default Please help-dators darbojas ļoti lēni, vīrusu?

Skenēšanas Ziņojums

Wednesday, April 02, 2008 19:19:08-20:30:00

Computer name: Neven-MS8XDAEE4
Scanning tips: Scan sistēmas ļaunprātīgu programmatūru, rootkit
Target: C: \

Rezultāts: 1 malware atrasts

Tracking Cookie (spyware)
  • Sistēma
Statistika

Skenēts:
  • Faili: 39.253
  • Sistēma: 3.397
  • Netiek skenēti: 22
Darbības:
  • Dezinficēts: 0
  • Pārdēvēta: 0
  • Svītro: 0
  • None: 1
  • Publicēts: 0
Faili netiek skenēti:
  • C: \ PAGEFILE.SYS
  • C: \ WINDOWS \ SYSTEM32 \ CONFIG \ DEFAULT
  • C: \ WINDOWS \ SYSTEM32 \ CONFIG \ SAM
  • C: \ WINDOWS \ SYSTEM32 \ CONFIG \ Security
  • C: \ WINDOWS \ SYSTEM32 \ CONFIG \ SOFTWARE
  • C: \ WINDOWS \ SYSTEM32 \ CONFIG \ SYSTEM
  • C: \ WINDOWS \ $ NTUNINSTALLKB835732 $ \ CALLCONT.DLL
  • C: \ WINDOWS \ $ NTUNINSTALLKB835732 $ \ GDI32.DLL
  • C: \ WINDOWS \ $ NTUNINSTALLKB835732 $ \ H323.TSP
  • C: \ WINDOWS \ $ NTUNINSTALLKB835732 $ \ H323MSP.DLL
  • C: \ WINDOWS \ $ NTUNINSTALLKB835732 $ \ HELPCTR.EXE
  • C: \ WINDOWS \ $ NTUNINSTALLKB835732 $ \ IPNATHLP.DLL
  • C: \ WINDOWS \ $ NTUNINSTALLKB835732 $ \ LSASRV.DLL
  • C: \ WINDOWS \ $ NTUNINSTALLKB835732 $ \ MF3216.DLL
  • C: \ WINDOWS \ $ NTUNINSTALLKB835732 $ \ MSASN1.DLL
  • C: \ WINDOWS \ $ NTUNINSTALLKB835732 $ \ MSGINA.DLL
  • C: \ WINDOWS \ $ NTUNINSTALLKB835732 $ \ MST120.DLL
  • C: \ WINDOWS \ $ NTUNINSTALLKB835732 $ \ NETAPI32.DLL
  • C: \ WINDOWS \ $ NTUNINSTALLKB835732 $ \ NMCOM.DLL
  • C: \ WINDOWS \ $ NTUNINSTALLKB835732 $ \ RTCDLL.DLL
  • C: \ WINDOWS \ $ NTUNINSTALLKB835732 $ \ SCHANNEL.DLL
  • C: \ Documents and Settings \ Neven \ LOCAL SETTINGS \ temp \ HSPERFDATA_NEVEN \ 2.636
Options

Skenēšanas dzinēji:
  • F-Secure USS: 2.30.0
  • F-Secure Hydra: 2.8.8110, 2008/04/02
  • F-Secure AVP: 7.0.171, 2008/04/02
  • F-Secure Pegasus: 1.20.0, 2008/02/28
  • F-Secure Blacklight: 1.0.64
Skenēšanas opcijas:
  • Scan noteikts faili: COM EXE SYS ov? BIN SCR DLL SHS HTM HTML htt VBS JS INF VXD DO? XL? RTF CPL Wiz HTA PP? PWZ P? T MSO PIF. ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC wsh VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML ĶTR SHB LNK WSF (* PDF ZL? XML ZIP XXX ANI AVB BAT CMD JPG LSP MAP MHT MIF PHP POT SWF WMF NWS TAR
  • Izmantot uzlaboto heiristiku
  • Copyright © 1998-2007 Product support |Nosūtīt vīrusa paraugs F-Secure

    F-Secure neuzņemas nekādu atbildību par materiāla izveidotas vai publicē trešās puses, F-Secure World Wide Web lapās ir saite. Ja vien jūs neesat skaidri norādīts citādi, iesniedzot materiālu, lai kādu no mūsu serveriem, piemēram, pa e-pastu vai, izmantojot mūsu F-Secure's CGI E-pasts, jūs piekrītat, ka materiāls jūs rīcībā var publicēt F-Secure pasaule Wide lapas vai cietās kopijas publikācijas. Jūs sasniegsiet F-Secure sabiedrības tīmekļa vietnē, noklikšķinot uz uzsvēra saites. Vienlaikus rīkojoties, jūsu pieeja ir pieteicies uz mūsu privāto piekļūt statistikai ar savu domēna name.This informācija netiks sniegta trešām personām. Jūs piekrītat neveikt pasākumus pret mums saistībā ar materiālu, kas jums iesniegt. Ja vien jūs neesat skaidri norādīts citādi, iesniedzot materiālu, jūs garantējat, ka F-Secure var būt jebkuras koncepcijas, kas aprakstītas to F-Secure produktiem / publications bez atbildības.
Reply

Register

Bookmarks

Similar Threads
Pavediens Thread Starter Forums Replies Last Post
Datoru, kurā darbojas ļoti lēni curlysmith General Hardware Čats 5 12 septembris 2009 02:48
Problēma ar datoru darbojas lēni nolaupīt log pls palīdzēt antbann Vīrusu, spiegprogrammatūru un drošība 6 5 novembris 2008 07:28
Man ir labas drošību? Un mana datora darbojas lēni. paudashlake Vīrusu, spiegprogrammatūru un drošība 13 18 oktobris 2008 12:02
Datoru, kurā darbojas lēni / zils sreen christine154 Vīrusu, spiegprogrammatūru un drošība 1 22 augusts 2008 08:56
Datoru, kurā darbojas lēni antbann Vīrusu, spiegprogrammatūru un drošība 10 23 marts 2008 12:21
Thread Tools




Arabic Bulgarian Chinese (Simplified) Chinese (Traditional) Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Thai Turkish Ukrainian

Copyright © 2006 - 2009 Computer Sulas.

Powered by vBulletin ® Copyright © 2000 - 2009 Jelsoft Enterprises Ltd SEO līdz 2009 vBSEO ©, Crawlability, Inc