Jump to content
Sign in to follow this  
dekzorro

Pasai Processes La Ni...

Recommended Posts

aku dpti terlalu byk item (application) kat processes XP yg aku guna. aku nak post kat sini, tp x tau cara nak copy list tu... ader cara nak copy tak..

lps tu baru bole kemuka solan seterusnya. dry.gif

satu lagi..baru² ni pc aku teruk kena trojan, spyware dan ntah aper bendo lagi. terutam IE aku.. asyik about:blank jeee...

korang ader tip tak camner aku settle masalah ni..secara manual.

Edited by dekzorro

Share this post


Link to post
Share on other sites

snap image or bukak system Information, file export as txt. than search part yg state pasal Running Task under Software Enviroment. copy and paste.

kalau bigginer, pakai Hijact This (iam not supporting this tools, Please ask C-Fu for help regarding Hijact This).

Share this post


Link to post
Share on other sites

ok...nie dia processes kat pc aku...

System Information report written at: 03/12/05 21:28:55

system idle process

system

smss.exe

csrss.exe

winlogon.exe

lsass.exe

svchost.exe

svchost.exe

svchost.exe

svchost.exe

svchost.exe

spoolsv.exe

inetinfo.exe

inorpc.exe

inort.exe

inotask.exe

snmp.exe

alg.exe

explorer.exe

rundll32.exe

ituneshelper.exe

qttask.exe

msmsgs.exe

ipodservice.exe

dllhost.exe

dllhost.exe

msdtc.exe

rainlendar.exe

objectdock.exe

itunes.exe

svchost.exe

firefox.exe

helpctr.exe

helpsvc.exe

wmiprvse.exe

bole tak korang tlg inform aku peranan file yg ader tu... ader tak yg bahaya.. jika bahaya camne nak buang..

tima kacih krn sanggup membantu kpd anda² yg sudi membantu. rolleyes.gif

Share this post


Link to post
Share on other sites

kene spyware? try ikut care bawah nie...

sila check ngan spyware software like TMIS 2005

microsoft antispyware

spyblaster

hijackthis

lavasoft

spybot

1. Gunakan Spybot .. ( download definition yang terkini )

2. Adware SE-Personal (hanya dari Lavasoft) (download definition yang terkini)

3. Delete cookies dan file lama.

4. Check object dalam internet option dan pastikan ya adalah dari company2 yang

dikenali .

5. Gunakan perisian seperti firewall dan pop up blocker untuk langkah tambahan

6. Boleh juga delete secara manual pada registry....

Share this post


Link to post
Share on other sites

aku dpti terlalu byk item (application) kat processes XP yg aku guna. aku nak post kat sini, tp x tau cara nak copy list tu... ader cara nak copy tak..

lps tu baru bole kemuka solan seterusnya. dry.gif

satu lagi..baru² ni pc aku teruk kena trojan, spyware dan ntah aper bendo lagi. terutam IE aku.. asyik about:blank jeee...

korang ader tip tak camner aku settle masalah ni..secara manual.

kau guna win xp sp1 lagi kee??

aku syor kau guna win xp sp2 laa plak

sbb security dia lebih baik sikit dari yg lain...

klu nak mudah jgn guna IE

guna je browser lain

cam Opera ke,firefox ke...

okk??

cool.gif

Share this post


Link to post
Share on other sites

ok...nie dia processes kat pc aku...

System Information report written at: 03/12/05 21:28:55

system idle process

system

smss.exe

csrss.exe

winlogon.exe

lsass.exe

svchost.exe

svchost.exe

svchost.exe

svchost.exe

svchost.exe

spoolsv.exe

inetinfo.exe

inorpc.exe

inort.exe

inotask.exe

snmp.exe

alg.exe

explorer.exe

rundll32.exe

ituneshelper.exe

qttask.exe

msmsgs.exe

ipodservice.exe

dllhost.exe

dllhost.exe

msdtc.exe

rainlendar.exe

objectdock.exe

itunes.exe

svchost.exe

firefox.exe

helpctr.exe

helpsvc.exe

wmiprvse.exe

bole tak korang tlg inform aku peranan file yg ader tu... ader tak yg bahaya.. jika bahaya camne nak buang..

tima kacih krn sanggup membantu kpd anda² yg sudi membantu. rolleyes.gif

Keterangan Isass.

Process File: isass.exe

Process Name: Optix.Pro virus

Virus: No ( Remove )

Trojan: Yes ( Remove )

Spyware: No ( Remove )

Security Risk (0-5): 4

Agak bahaya jugak Isaaa nie. baik remove cepat

Share this post


Link to post
Share on other sites

Keterangan Isass.

Process File: isass.exe

Process Name: Optix.Pro virus

Virus: No ( Remove )

Trojan: Yes ( Remove )

Spyware: No ( Remove )

Security Risk (0-5):  4

Agak bahaya jugak Isaaa nie. baik remove cepat

remove la kalo terer smile.gif

http://www.processlibrary.com/directory/fi...lsass/index.php

start/administrative tool/services. disabled + stop je mane process yg tak guna dari running masa start pc.

Share this post


Link to post
Share on other sites

ONGBOK, tengok betul2, tu bukan ke LSASS. Servis windows XP. cara aku, aku carik executable tu nad tengok properties dia, sapo buat, bila execute tu masuk dalam system. kalau lain macam je aku delete.

Share this post


Link to post
Share on other sites

C-FU.....where are you? C-Fu lah expert bab2 spyware nie....aku rasa aku leh comment....tapi aku rasa lebih baik C-fu yang handle....ko try PM C-FU....

All the Best!

Share this post


Link to post
Share on other sites

asik-asik C-Fu.. benci..

Keterangan Isass.

Process File: isass.exe

Process Name: Optix.Pro virus

I bukan L. social engineering. smile.gif

Share this post


Link to post
Share on other sites

system idle process

system

smss.exe

csrss.exe

winlogon.exe

lsass.exe

svchost.exe

svchost.exe

kau tengok post asal dia, tu I ke L, aku nampak cam L je.

----------------------%--------------------------------------

compare bentuk L or kau claim I tu ngan image aku snap ni, mana yg more than 75% equal.

user posted image

Edited by mus3na

Share this post


Link to post
Share on other sites

aku dpti terlalu byk item (application) kat processes XP yg aku guna. aku nak post kat sini, tp x tau cara nak copy list tu... ader cara nak copy tak..

lps tu baru bole kemuka solan seterusnya. dry.gif

satu lagi..baru² ni pc aku teruk kena trojan, spyware dan ntah aper bendo lagi. terutam IE aku.. asyik about:blank jeee...

korang ader tip tak camner aku settle masalah ni..secara manual.

hm...IE dah kene hijack! try ikut care aku sat(post #4)......kalau kau gune hijackthis tu...lepas scan tu kau boleh pastekan kau punye log file kat sini....aku nak tgk sat.....

Share this post


Link to post
Share on other sites

kau guna win xp sp1 lagi kee??

aku syor kau guna win xp sp2 laa plak

sbb security dia lebih baik sikit dari yg lain...

klu nak mudah jgn guna IE

guna je browser lain

cam Opera ke,firefox ke...

okk??

cool.gif

yg aku skang ni SP2.. same je, aku kene teruk oooo..manjang keluar popup..

sebenarnye aku sedang mencari kaedah utk buang masalah ni cara manual... baru kite tau apr yg di ubahnye.

aku dah jumpa satu: trojan.digit; yg utk kacau IE, ko punye default page bole jadi about:blank (ngan aku² blank). tapi tak semua tips yg aku jumpa utk trojan nie berjaya. kat tempat aku keje ni ramai kene (aku la tu). aku tak nak format pc, nampak sgt tak terrorrx (hehehe). aku dok search utk pdm link file, registry dan mcm² laie.

Edited by dekzorro

Share this post


Link to post
Share on other sites

nak download manual? leh je.

first kene tau samada program tu tengah running. second, kene tau camner program tu leh tetibe run bile ko start, dengan check semua tempat2 startup. tu pasal ramai orang suruh gune hijackthis.

download hijackthis (google kalo taktau kat mane), pastu boh file hijackthis.exe kat dalam satu folder baru (kene buat), scan and save log, pastu copy log dan paste kat sini. meh ako bagitau camner ko nak delete satu2.

Share this post


Link to post
Share on other sites

ye bebeh... ini dia filelog suda mari..

Logfile of HijackThis v1.99.1

Scan saved at 5:07:57 PM, on 3/13/2005

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\QuickTime\qttask.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Rainlendar\Rainlendar.exe

C:\Program Files\Stardock\ObjectDock\ObjectDock.exe

C:\WINDOWS\system32\inetsrv\inetinfo.exe

C:\Program Files\CA\eTrust\Antivirus\InoRpc.exe

C:\Program Files\CA\eTrust\Antivirus\InoRT.exe

C:\Program Files\CA\eTrust\Antivirus\InoTask.exe

C:\WINDOWS\System32\snmp.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\WINDOWS\system32\dllhost.exe

C:\Program Files\iTunes\iTunes.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\WINDOWS\system32\taskmgr.exe

C:\Program Files\XoftSpy\XoftSpy.exe

C:\WINDOWS\system32\notepad.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = 1

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = 1

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {7FE89029-04FE-4517-96BE-65ABDFD2A7DF} - C:\WINDOWS\system32\bmli.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll,DllInstall

O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - Startup: Rainlendar.lnk = C:\Program Files\Rainlendar\Rainlendar.exe

O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe

O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html

O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm

O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html

O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html

O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html

O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm

O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {B24F0664-7DDA-40B6-B38C-A4FD68DE8685} (CentraDownloaderCtl Class) - http://202.187.24.88/main/Install/en/US/CentraDownloader.cab

O18 - Filter: text/html - {CE61487E-007E-4CB8-A8A8-0B5F48DE086C} - C:\WINDOWS\system32\bmli.dll

O18 - Filter: text/plain - {CE61487E-007E-4CB8-A8A8-0B5F48DE086C} - C:\WINDOWS\system32\bmli.dll

O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll

O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust\Antivirus\InoRpc.exe

O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust\Antivirus\InoRT.exe

O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust\Antivirus\InoTask.exe

O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

sorry.. nie je the best edit yg aku bole buat..harap² tak poning la ye. tq semua

Share this post


Link to post
Share on other sites

benda yg kene fix:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/sp.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = 1

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = 1

O2 - BHO: (no name) - {7FE89029-04FE-4517-96BE-65ABDFD2A7DF} - C:\WINDOWS\system32\bmli.dll

O16 - DPF: {B24F0664-7DDA-40B6-B38C-A4FD68DE8685} (CentraDownloaderCtl Class) - http://202.187.24.88/main/Install/en/US/CentraDownloader.cab

O18 - Filter: text/html - {CE61487E-007E-4CB8-A8A8-0B5F48DE086C} - C:\WINDOWS\system32\bmli.dll

O18 - Filter: text/plain - {CE61487E-007E-4CB8-A8A8-0B5F48DE086C} - C:\WINDOWS\system32\bmli.dll

Share this post


Link to post
Share on other sites

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/sp.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = 1

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = 1

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

O2 - BHO: (no name) - {7FE89029-04FE-4517-96BE-65ABDFD2A7DF} - C:\WINDOWS\system32\bmli.dll

O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll,DllInstall

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O16 - DPF: {B24F0664-7DDA-40B6-B38C-A4FD68DE8685} (CentraDownloaderCtl Class) - http://202.187.24.88/main/Install/en/US/CentraDownloader.cab

O18 - Filter: text/html - {CE61487E-007E-4CB8-A8A8-0B5F48DE086C} - C:\WINDOWS\system32\bmli.dll

O18 - Filter: text/plain - {CE61487E-007E-4CB8-A8A8-0B5F48DE086C} - C:\WINDOWS\system32\bmli.dll

pastikan sebelum fix, ko cube untuk unregister file2 .dll tu dengan pegi start>run>cmd

pastu taip regsvr32 /u namafail.dll cam bmli.dll, se.dll tu.

DAN, tutup SEMUA window pasal kalo tak hijackthis takkan menjadi untuk fix.

pastu restart, dan cube carik file2 .dll kat atas tu dan delete kalo still ade.

pasni bagi logfile hijackthis terbaru. bile sume dah ok, ako rekomen ko buat step kat bawah.

download spybot. http://www.safer-networking.org/en/index.html

download, UPDATE, pastu scan. fix, pastu restart. pastu scan balik, takut2 ade problem balik. kalau problem tu asyik kluar balik, pegi terus ke step hijackthis kat bawah.

lepas dah update semua, bukak balik spybot. pegi menu mode>advanced mode. kat menu kiri, pegi tools. checkkan semua, so semua setting boleh kite set.

then kat menu kiri, pegi spybot>immunize. klik immunize, dan klik enable permanent blocking of bad addresses... dan block all pages silently.

pastu gi Tools>IE Tweaks. lock hosts file. kalo nak lock IE start page pon elok gak.

pastu gi Tools>Hosts file. add spybot hosts file.

pastu gi Tools>Resident. Checkkan option SDHelper.

Edited by C-Fu

Share this post


Link to post
Share on other sites

rajin eh C-Fu track satu2 log tu.. KOHKOHKOHKOHKOHKOH.. smile.gif

hehehe baguslah kalau dia rajin nak tolong...daripada dia post tak tentu hala atau ada yang melalut tak tentu pasal...

Share this post


Link to post
Share on other sites

bio le die. die tengah bangge tu FINALLY bilangan pos die lebeh dari ako

Share this post


Link to post
Share on other sites

pos balik log hijackthis terbaru just nak make sure pc ko dah ok.

also, dari hijackthis log die tu yang ako tengok running process die tulis L, bukan I la.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
Sign in to follow this  

×
×
  • Create New...