Awaria systemu

witam,
regularnie, co kilka chwil, system konczy wiekszosc dzialajacych procesow, zamyka okna, wylacza sie tez explorer,
w dzienniku zdarzen pojawiaja sie takie hasla:
Usługa Usługi IPSEC zakończyła działanie; wystąpił następujący błąd:
Zamierzana operacja nie jest obsługiwana dla typu obiektu, do którego się odwołała.


Nie moźna załadować następujących sterowników startu rozruchowego lub systemowego:
SAVRTPEL


Nie moźna uruchomić usługi ScriptBlocking Service z powodu następującego błędu:
System nie moźe odnaleźć określonej ścieźki.


Usługa Klient DHCP zaleźy od usługi SYMTDI, której nie moźna uruchomić z powodu następującego błędu:
Nie moźna odnaleźć określonego pliku.

tu log z hijacka:
Logfile of HijackThis v1.99.1
Scan saved at 11:41:06, on 2005–11–08
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\SYSTEM32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\SYSTEM32\Userinit.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Winamp\winampa.exe
E:\Program Files\GigaByte\VGA Utility Manager\G–VGA.exe
F:\PDVD\PDVDServ.exe
E:\Program Files\HP\hpcoretech\hpcmpmgr.exe
E:\Program Files\Hewlett–Packard\HP Software Update\HPWuSchd2.exe
E:\Program Files\iTunes\iTunesHelper.exe
E:\Program Files\QuickTime\qttask.exe
E:\windows\system32\mdms.exe
E:\Program Files\Tlen.pl\tlen.exe
D:\Gadu–Gadu\gg.exe
E:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
E:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
E:\WINDOWS\System32\inetsrv\inetinfo.exe
E:\WINDOWS\System32\nvsvc32.exe
E:\WINDOWS\System32\devldr32.exe
E:\WINDOWS\System32\tcpsvcs.exe
E:\WINDOWS\System32\snmp.exe
E:\Program Files\Common Files\Symantec Shared\CCPD–LC\symlcsvc.exe
E:\Program Files\iPod\bin\iPodService.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Program Files\Spybot – Search & Destroy\SpybotSD.exe
E:\WINDOWS\system32\mmc.exe
E:\NBGCleanRE\NBGCleanRE.exe
E:\WINDOWS\explorer.exe
E:\hijackthis_199\HijackThis.exe

R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://onet.pl/
O2 – BHO: IeCatch2 Class – {A5366673–E8CA–11D3–9CD9–0090271D075B} – E:\PROGRA~1\FLASHGET\jccatch.dll
O4 – HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 – HKLM\..\Run: [WinampAgent] E:\Program Files\Winamp\winampa.exe
O4 – HKLM\..\Run: [PathNvidiaTV] E:\Program Files\Gigabyte\Nvidia\patchnvidiaTVout.exe
O4 – HKLM\..\Run: [VGAUtil] E:\Program Files\GigaByte\VGA Utility Manager\G–VGA.exe
O4 – HKLM\..\Run: [RemoteControl] F:\PDVD\PDVDServ.exe
O4 – HKLM\..\Run: [HP Component Manager] "E:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 – HKLM\..\Run: [HP Software Update] "E:\Program Files\Hewlett–Packard\HP Software Update\HPWuSchd2.exe"
O4 – HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
O4 – HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" –atboottime
O4 – HKLM\..\Run: [SysMemory manager] e:\windows\system32\mdms.exe
O4 – HKCU\..\Run: [Komunikator] E:\Program Files\Tlen.pl\tlen.exe
O4 – HKCU\..\Run: [Gadu–Gadu] "D:\Gadu–Gadu\gg.exe" /tray
O4 – Global Startup: InterVideo WinCinema Manager.lnk = E:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 – Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 – Global Startup: Adobe Gamma Loader.lnk = E:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 – Extra context menu item: &Google Search – res://E:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 – Extra context menu item: Backward &Links – res://E:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 – Extra context menu item: Cac&hed Snapshot of Page – res://E:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 – Extra context menu item: Download All by FlashGet – E:\Program Files\FlashGet\jc_all.htm
O8 – Extra context menu item: Download using FlashGet – E:\Program Files\FlashGet\jc_link.htm
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 – Extra context menu item: Si&milar Pages – res://E:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 – Extra context menu item: Translate into English – res://E:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 – Extra button: Related – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – E:\WINDOWS\web\related.htm
O9 – Extra 'Tools' menuitem: Show &Related Links – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – E:\WINDOWS\web\related.htm
O9 – Extra button: FlashGet – {D6E814A0–E0C5–11d4–8D29–0050BA6940E3} – E:\PROGRA~1\FLASHGET\flashget.exe
O9 – Extra 'Tools' menuitem: &FlashGet – {D6E814A0–E0C5–11d4–8D29–0050BA6940E3} – E:\PROGRA~1\FLASHGET\flashget.exe
O16 – DPF: komentator – http://sport.onet.pl/komentator.cab
O16 – DPF: {0A5FD7C5–A45C–49FC–ADB5–9952547D5715} (Creative Software AutoUpdate) – http://www.creative.com/su/ocx/15009/CTSUEng.cab
O16 – DPF: {6414512B–B978–451D–A0D8–FCFDF33E833C} (WUWebControl Class) – http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1122827411078
O16 – DPF: {644E432F–49D3–41A1–8DD5–E099162EEEC5} (Symantec RuFSI Utility Class) – http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
O16 – DPF: {EF791A6B–FC12–4C68–99EF–FB9E207A39E6} (McFreeScan Class) – http://download.mcafee.com/molbin/iss–loc/vso/en–us/tools/mcfscan/2,0,0,4598/mcfscan.cab
O16 – DPF: {F6ACF75C–C32C–447B–9BEF–46B766368D29} (Creative Software AutoUpdate Support Package) – http://www.creative.com/su/ocx/15010/CTPID.cab
O17 – HKLM\System\CCS\Services\Tcpip\..\{7DA1394A–657F–4AA5–8CDA–FC48EE0F6940}: NameServer = 194.146.252.5,213.134.128.19
O20 – Winlogon Notify: mcfG7A – mcfG7A.dll (file missing)
O23 – Service: Symantec Event Manager (ccEvtMgr) – Unknown owner – E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (file missing)
O23 – Service: Symantec Password Validation (ccPwdSvc) – Unknown owner – E:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (file missing)
O23 – Service: Symantec Settings Manager (ccSetMgr) – Symantec Corporation – E:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 – Service: InstallDriver Table Manager (IDriverT) – Macrovision Corporation – E:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 – Service: iPodService – Apple Computer, Inc. – E:\Program Files\iPod\bin\iPodService.exe
O23 – Service: Norton AntiVirus Auto Protect Service (navapsvc) – Unknown owner – E:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
O23 – Service: NVIDIA Display Driver Service (NVSvc) – NVIDIA Corporation – E:\WINDOWS\System32\nvsvc32.exe
O23 – Service: ScriptBlocking Service (SBService) – Unknown owner – E:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe (file missing)
O23 – Service: Symantec Core LC – Symantec Corporation – E:\Program Files\Common Files\Symantec Shared\CCPD–LC\symlcsvc.exe
O23 – Service: SymWMI Service (SymWSC) – Unknown owner – E:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (file missing)
O23 – Service: Network Security Service (__NS_Service_3) – Unknown owner – E:\WINDOWS\ipzr32.exe (file missing)

nie wiem, co robic...
pzdr
przemek

Odpowiedzi: 1

Nie dziwnota, w logu na szybko:

Repsamo:
O4 – HKLM\..\Run: [SysMemory manager] e:\windows\system32\mdms.exe


Haxdoor.AK
O20 – Winlogon Notify: mcfG7A – mcfG7A.dll (file missing)


Trojan.Agent najprawdopodobniej:
O23 – Service: Network Security Service (__NS_Service_3) – Unknown owner – E:\WINDOWS\ipzr32.exe (file missing)


Ostatni to jeszcze pamiątka z ostatniego odrobaczania.
Bobi
Dodano
08.11.2005 17:08:47
wielkaradosc
Dodano:
08.11.2005 12:49:40
Komentarzy:
1
Strona 1 / 1