Po zainstalowaniu pacza do gry cos nie tak.

Witam.
Zainstalowalem sobie pacza w ver 1.5 do gry call of duty.
Jednak po zainstalowaniu przestaly dzialac strony (Mozilla Firefox i IE nie dzialaja).
Po ponownym uruchomieniu systemu komputer odpala sie ok. 5 minut, a przy tym nie wlacza sie firewall i anty wirus ( Norton Internet Security 2004).
Chwile pozniej wywala okienko z wylaczaniem systemu i jest odliczanie (minuta). Pisze tam cos o usludze RPC.
Wydaje sie jak jakis worm, ale objawy sa inne.
Nie moge sobie z tym poradzic.
W trybie awaryjnym z obsluga sieci komputer takze bardzo dlugo sie odpala.


WinXP SP2
Prosze o rady.

pozdrawiam.

Odpowiedzi: 4

Ok, poradzilem juz sobie
Zastanowila mnie ta linijka
O10 – Broken Internet access because of LSP provider 'xfire_lsp_10650.dll' missing

Xfire byl razem z patchem 1.5 do call of duty.
Program podobny go GameSpy na multi

odinstalowalem to i normalnie sie opalil system.

Dziwna sprawa, ze tak program zareagowal.

Dzieki.

Pozdr.
Sznaps
Dodano
18.12.2004 16:31:55
Udalo mi sie zrobic log
jednak BootVis'a nie moge cos odpalic caly czas mam "preparing to install"


Logfile of HijackThis v1.99.0
Scan saved at 14:32:04, on 2004–12–18
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedccProxy.exe
C:WINDOWSsystem32 vsvc32.exe
C:Program FilesNorton Internet Security ProfessionalNorton AntiVirusSAVScan.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32 askmgr.exe
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:Program FilesDU MeterDUMeter.exe
C:Program FilesJavaj2re1.4.2_05injusched.exe
C:DOCUME~1SznapsUSTAWI~1TempKatalog tymczasowy 1 dla hijackthis.zipHijackThis.exe

R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://google.pl/
R1 – HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 – BHO: (no name) – {53707962–6F74–2D53–2644–206D7942484F} – C:PROGRA~1SPYBOT~1SDHelper.dll
O2 – BHO: Web assistant – {9ECB9560–04F9–4bbc–943D–298DDF1699E1} – C:Program FilesCommon FilesSymantec SharedAdBlockingNISShExt.dll
O2 – BHO: NAV Helper – {BDF3E430–B101–42AD–A544–FADC6B084872} – C:Program FilesNorton Internet Security ProfessionalNorton AntiVirusNavShExt.dll
O3 – Toolbar: Web assistant – {0B53EAC3–8D69–4b9e–9B19–A37C9A5676A7} – C:Program FilesCommon FilesSymantec SharedAdBlockingNISShExt.dll
O3 – Toolbar: Norton AntiVirus – {42CDD1BF–3FFB–4238–8AD1–7859DF00B1D6} – C:Program FilesNorton Internet Security ProfessionalNorton AntiVirusNavShExt.dll
O4 – HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 – HKLM..Run: [URLLSTCK.exe] C:Program FilesNorton Internet Security ProfessionalUrlLstCk.exe
O4 – HKLM..Run: [Advanced Tools Check] C:PROGRA~1NORTON~1NORTON~1AdvToolsADVCHK.EXE
O4 – HKLM..Run: [DU Meter] C:Program FilesDU MeterDUMeter.exe
O4 – HKLM..Run: [Symantec NetDriver Monitor] C:PROGRA~1SYMNET~1SNDMon.exe
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_05injusched.exe
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [TrojanScanner] C:Program FilesTrojan RemoverTrjscan.exe
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:Program FilesJavaj2re1.4.2_05in pjpi142_05.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:Program FilesJavaj2re1.4.2_05in pjpi142_05.dll
O9 – Extra button: Messenger – {4528BBE0–4E08–11D5–AD55–00010333D0AD} – C:Program FilesYahoo!Messengeryhexbmes0521.dll
O9 – Extra 'Tools' menuitem: Yahoo! Messenger – {4528BBE0–4E08–11D5–AD55–00010333D0AD} – C:Program FilesYahoo!Messengeryhexbmes0521.dll
O9 – Extra button: ICQ 4 – {B863453A–26C3–4e1f–A54D–A2CD196348E9} – C:Program FilesICQLiteICQLite.exe
O9 – Extra 'Tools' menuitem: ICQ Lite – {B863453A–26C3–4e1f–A54D–A2CD196348E9} – C:Program FilesICQLiteICQLite.exe
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O10 – Broken Internet access because of LSP provider 'xfire_lsp_10650.dll' missing
O16 – DPF: {6414512B–B978–451D–A0D8–FCFDF33E833C} (WUWebControl Class) – http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1099330544808
O23 – Service: Symantec Event Manager – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
O23 – Service: Symantec Network Proxy – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccProxy.exe
O23 – Service: Symantec Password Validation – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccPwdSvc.exe
O23 – Service: Symantec Settings Manager – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedccSetMgr.exe
O23 – Service: Norton AntiVirus Auto Protect Service – Symantec Corporation – C:Program FilesNorton Internet Security ProfessionalNorton AntiVirus avapsvc.exe
O23 – Service: Norton Unerase Protection – Symantec Corporation – C:Program FilesNorton Internet Security ProfessionalNorton AntiVirusAdvToolsNPROTECT.EXE
O23 – Service: NVIDIA Display Driver Service – NVIDIA Corporation – C:WINDOWSsystem32 vsvc32.exe
O23 – Service: SAVScan – Symantec Corporation – C:Program FilesNorton Internet Security ProfessionalNorton AntiVirusSAVScan.exe
O23 – Service: ScriptBlocking Service – Symantec Corporation – C:PROGRA~1COMMON~1SYMANT~1SCRIPT~1SBServ.exe
O23 – Service: Symantec Network Drivers Service – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedSNDSrvc.exe
O23 – Service: Symantec Core LC – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedCCPD–LCsymlcsvc.exe
O23 – Service: SymWMI Service – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedSecurity CenterSymWSC.exe
Sznaps
Dodano
18.12.2004 15:42:19
OK, juz sciagam
nie wiem tylko czy zdaze to zainstalowac tam.
Przed chwila posciagalem rozne removal tool'e dla sassera, worma, mydooma
wrzucilem na inny hd i podlaczylem go
Okazalo sie, ze nie moge teraz nawet odpalic trybu awaryjnego.
Na szczescie mam jakiegos rupiecia i moge na net wchodzic.

Za chwile dam znac jak to wyglada.
pozdr i dzieki za odp.
Sznaps
Dodano
18.12.2004 15:14:22
Sciagnij BootVis–a i sprawdzaj co sie laduje
Wklej log z Hijack This'a
Bobi
Dodano
18.12.2004 14:55:02
Sznaps
Dodano:
18.12.2004 14:44:10
Komentarzy:
4
Strona 1 / 1