class_sick 3 Report post Posted August 26, 2007 salambaru2 nie pc slalu jer auto restart.dah try guna PAV dgn KAV.biler buat full scan,dia separuh jln,pastu restart balik pc nie.tiap2 kali masuk windows,KAV akan sound awal2 suruh buat full scan,tp biler scan jer,separuh jln,pc restart.dr start awal pakai KAV,xpernah run full scan. biler dah restart balik,windows akan kuarkan error mcm kat bwh nieapa kaitan dgn IP?time xguna tenet pun dia auto restart gak.time guna tenet pun dia restart gak.kdang2 sampai off sendri pc nie.pastu baru2 nie perasan ader beberapa files kat drive E yg xbese aku jumpa.satu lg nak tnya,cuba tgk pic kat bwh nie.task manager mmg icon dia mcm tu ker?pastu yg nircmd.exe tu pebendanyer?satu lg,Dit.exe tu apa yer?file windows gak ker?sbb tgk date dia created baru beberapa hr yg lepas.nie logfile nyer.Logfile of Trend Micro HijackThis v2.0.0 (BETA)Scan saved at 2:05:14 AM, on 8/25/2007Platform: Windows XP SP2 (WinNT 5.01.2600)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exeC:\WINDOWS\system32\nvsvc32.exeC:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exeC:\Program Files\Yahoo!\Messenger\ymsgr_tray.exeC:\WINDOWS\system32\wscntfy.exeC:\Program Files\Winamp\winamp.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Mozilla Firefox\firefox.exeG:\file\Hafiz\Software\HiJackThis_v2.exeO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dllO2 - BHO: IEHlprObj Class - {CD4C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\BP Go!Zilla v4.1\GoIEHlp.dllO4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quietO8 - Extra context menu item: Download with Go!Zilla - file://C:\Program Files\BP Go!Zilla v4.1\download-with-gozilla.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dllO9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLLO9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exeO9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO17 - HKLM\System\CCS\Services\Tcpip\..\{8296EFFC-62EE-40D9-A114-687DDE6D9B2A}: NameServer = 192.168.1.1,192.168.1.2O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dllO22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dllO23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exeO23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: wampapache - Apache Software Foundation - c:\wamp\apache2\bin\Apache.exeO23 - Service: wampmysqld - Unknown owner - c:\wamp\mysql\bin\mysqld-nt.exe--End of file - 3757 bytesapa yg aku perasan, O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup nie slalu jer muncul time startup.benda nie ape yer?nak tanya,lepas guna PAV,adakah dia otomatik akanreset balik foler option kita kpd Do Not Show Hidden Files And Folders?ok.tu jer kot buat masa nie.thanks Quote Share this post Link to post Share on other sites
Mr.Fahizi 0 Report post Posted August 26, 2007 fixed kan yang ni : O2 - BHO: IEHlprObj Class - {CD4C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\BP Go!Zilla v4.1\GoIEHlp.dllmasalah pc ko restart masa tgh scan tu .. mgkin datang dari masalah hardware pc ko kot... scan dalam safemode dah try ?? Quote Share this post Link to post Share on other sites