29.04.07, 23:53
Sygnalizuje mi takie coś:

This problem was caused by Win32/Nuwar.N!sys, a known computer virus.

Win32/Nuwar.N!sys is also known by the following names:

* Win32/Vxidl.B
* Troj/Dorf-Fam
* Trojan.Peacomm
* TROJ_SMALL.EDW


Nie moge tego usunąć. Prosze o pomoc. Tylko w przystępnym języku...
Obserwuj wątek
    • Gość: Kolobos Re: Wirus IP: *.escom.net.pl 30.04.07, 07:21
      Co Ci to wyswietla?
      Wklej log z hijackthis.
      • james_bond007 Re: Wirus 30.04.07, 20:45
        Co jakiś czas resetuje mi komputer, po włączeniu i wysłaniu błędu łaczy ze
        stroną Microsoftu, gdzie pojawia się taki komunikat.

        Logfile of Trend Micro HijackThis v2.0.0 (BETA)
        Scan saved at 20:41:43, on 2007-04-30
        Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\savedump.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\tmrsrv32.exe
        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        C:\WINDOWS\System32\nvsvc32.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\RUNDLL32.EXE
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
        C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
        C:\Program Files\Messenger\MSMSGS.EXE
        C:\Program Files\Gadu-Gadu\gg.exe
        C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
        C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
        C:\WINDOWS\System32\wuauclt.exe
        C:\Documents and Settings\M\Pulpit\Nowy folder (13)\HiJackThis_v2.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        forum.gazeta.pl/forum/0,0.html
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
        - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} -
        E:\Marek\FlashGet\jccatch.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
        Files\Java\jre1.5.0_11\bin\ssv.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
        C:\WINDOWS\System32\msdxm.ocx
        O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} -
        E:\Marek\FlashGet\fgiebar.dll
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
        C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe"
        -atboottime
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program
        Files\Java\jre1.5.0_11\bin\jusched.exe"
        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop
        Album Starter Edition\3.0\Apps\apdproxy.exe"
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
        O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User
        'USŁUGA LOKALNA')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User
        'USŁUGA SIECIOWA')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User
        'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User
        'Default user')
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
        Office\Office\OSA9.EXE
        O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program
        Files\Adobe\Reader 8.0\Reader\reader_sl.exe
        O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program
        Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
        O8 - Extra context menu item: Download All by FlashGet -
        E:\Marek\FlashGet\jc_all.htm
        O8 - Extra context menu item: Download using FlashGet -
        E:\Marek\FlashGet\jc_link.htm
        O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
        res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
        C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console -
        {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
        Files\Java\jre1.5.0_11\bin\ssv.dll
        O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
        C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} -
        E:\Marek\FlashGet\flashget.exe
        O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3}
        - E:\Marek\FlashGet\flashget.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
        C:\Program Files\Messenger\MSMSGS.EXE
        O9 - Extra 'Tools' menuitem: Windows Messenger -
        {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
        O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
        O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center
        Base Module) -
        cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
        update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125305614679
        O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) -
        www.mks.com.pl/skaner/SkanerOnline.cab
        O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) -
        www.acclaim.com/cabs/acclaim_v5.cab
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
        update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1177874312062
        O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) -
        gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
        O17 - HKLM\System\CCS\Services\Tcpip\..\{9D62C150-5B4B-406D-BFC2-8CDA7D41A688}:
        NameServer = 194.204.152.34,194.204.159.1
        O20 - Winlogon Notify: A3dxq - C:\WINDOWS\System32\a3dxx.dll
        O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All
        Users\Dokumenty\Settings\winsys2f.dll
        O21 - SSODL: wcZAsSS - {3437D863-9E9D-72C9-4A82-473663B1EF03} -
        C:\WINDOWS\System32\xqrd.dll
        O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. -
        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
        C:\WINDOWS\System32\nvsvc32.exe

        --
        End of file - 6187 bytes
        • Gość: Kolobos Re: Wirus IP: *.escom.net.pl 30.04.07, 20:55
          Jezeli uzywasz Outlook'a to przestan i zmien go na Thunderbird'a, listy z trojanami w zlaczniku sie kasuje, a nie otwiera.

          Zamknij porty przy pomocy wwdc.exe

          W menadzerze zadan zakoncz:
          C:\WINDOWS\system32\tmrsrv32.exe
          Plik usun z dysku.

          W hjt usun:
          O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) -
          gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
          O20 - Winlogon Notify: A3dxq - C:\WINDOWS\System32\a3dxx.dll
          O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All
          Users\Dokumenty\Settings\winsys2f.dll
          O21 - SSODL: wcZAsSS - {3437D863-9E9D-72C9-4A82-473663B1EF03} -
          C:\WINDOWS\System32\xqrd.dll

          Pliki usun z dysku, w razie problemow przy pomocy killbox'a, na koniec skan tym:
          www.pandasoftware.com/activescan/pol/activescan_principal.htm
          www.spywareinfo.com/xscan.php
          www.bitdefender.com/scan8/ie.html
        • vko123 Re: Wirus 01.05.07, 10:51
          Dokładnie nie otwiera sie załączników a po drugie sam antyspyware to za mało.
          Jak używasz juz AVG Anti-Spyware to przydałaby sie druga "noga"- antywirus tego
          samego producenta AVG Anti-Virus Free www.avgpolska.pl/avg_free.html
          oraz buty do ochrony stóp czyli firewall. Może być Kerio, Zone Alarm, Ashampo itd.

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka