Problem z NIS 2006PL
Po zainstalowaniu Nortona Internet Security 2006, pobraniu aktualizacji przez Live Update zaczynaja sie schody..
Program prosi o wykonanie pelnego skanowania systemu. Prosze bardzo. Po jakims czasie jednak (nieokreslonym, czasem minuta czasem 5, czasem juz wierce sie niecierpliwie, ze wlasnie konczy)wyskakuje blad! :(
"Wystapil problem z aplikacja Norton Antivirus Scanner Module i zostanie ona zamknieta"
Sygnatura bledu : AppName: navw32.exe AppVer: 12.1.0.20 ModName: msls31.dll ModVer: 3.10.349.0 Offset: 00002cd7
Z dziennika zdarzen : Aplikacja powodująca błąd navw32.exe, wersja 12.1.0.20, moduł powodujący błąd msls31.dll, wersja 3.10.349.0, adres błędu 0x00002cd7.
Co smieszniejsze, po instalacji NIS wystepuje tez ten sam blad z Internet Explorerem , w aplikacji iexplore.exe
Bardzo prosze o pilna pomoc
PS. Juz przezyje tego IE, uzywam glownie firefoxa. Ale pomozcie mi prosze przeskanowac system do konca aby co chwila nie wyskakiwalo cholerne przypomnienie o potrzebie dokonania skanowania :(
Program prosi o wykonanie pelnego skanowania systemu. Prosze bardzo. Po jakims czasie jednak (nieokreslonym, czasem minuta czasem 5, czasem juz wierce sie niecierpliwie, ze wlasnie konczy)wyskakuje blad! :(
"Wystapil problem z aplikacja Norton Antivirus Scanner Module i zostanie ona zamknieta"
Sygnatura bledu : AppName: navw32.exe AppVer: 12.1.0.20 ModName: msls31.dll ModVer: 3.10.349.0 Offset: 00002cd7
Z dziennika zdarzen : Aplikacja powodująca błąd navw32.exe, wersja 12.1.0.20, moduł powodujący błąd msls31.dll, wersja 3.10.349.0, adres błędu 0x00002cd7.
Co smieszniejsze, po instalacji NIS wystepuje tez ten sam blad z Internet Explorerem , w aplikacji iexplore.exe
Bardzo prosze o pilna pomoc
PS. Juz przezyje tego IE, uzywam glownie firefoxa. Ale pomozcie mi prosze przeskanowac system do konca aby co chwila nie wyskakiwalo cholerne przypomnienie o potrzebie dokonania skanowania :(
Odpowiedzi: 13
Podmienialem juz ten plik z konsoli odzyskiwania i nie pomoglo:) Sprobuje jeszcze drugiej metody jaka byles uprzejmy podac, ale jak nadmienilem kilka postow wyzej, po zainstalowaniu IE 7.0 w dziwnych okolicznosciach przyrody problem zniknal, a przynajmniej tak mi sie wydaje.
Naprawde wierzysz w te bzdury ?szzzzz:Poprostu moze miec za salbego kompa na Nortona i wyskakuja mu te bledy...!!
orsoniasty, odszukaj plik msls31.dll, zamien mu rozszerzenie na .old i w jego miejsce wypakuj z plyty XP nowa kopie. Byc moze biblioteka jest uszkodzona ?
Mozesz ja rowniez zarejestrowac przez Uruchom:
regsvr32 c:\windows\system32\msls31.dll
Ta biblioteka uzywana jest przez IE i Worda – wspiera Unicode, jak mozna przeczytac w necie.
szzzzz:Poprostu moze miec za salbego kompa na Nortona i wyskakuja mu te bledy...!!
AsRock P4VT8+ , PIV 3.0 s478, 1x256(333) + 1x512(400) DDR, Caviar 80gb, Radeon 9550 128mb. Sys Win Xp Prof.+sp2.
Poprostu moze miec za salbego kompa na Nortona i wyskakuja mu te bledy...!!
Pary ze trzy kubiki. Biala, bez zapachu, ulatnia sie do gory. 2,5 hektopaskala.szzzzz:Podaj Parometry twojego kompa.!
Co bedzie nastepne ? Data urodzin ?
Podaj Parometry twojego kompa.!
szzzzz:Zamies Loga Silent Ruuners.!
To cholernie dlugie, ale prosze bardzo:
"Silent Runners.vbs", revision 43, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non–default values, except where indicated by "{++}"
Startup items buried in registry:
–––––––––––––––––––––––––––––––––
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
"Gadu–Gadu" = ""C:\Program Files\Gadu–Gadu\gg.exe" /tray" ["Gadu–Gadu Sp. z oo"]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"Cmaudio" = "RunDll32 cmicnfg.cpl,CMICtrlWnd" [MS]
"ccApp" = ""C:\Program Files\Common Files\Symantec Shared\ccApp.exe"" ["Symantec Corporation"]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F–C8D7–4D59–B87D–784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx" [empty string]
{9ECB9560–04F9–4bbc–943D–298DDF1699E1}\(Default) = "Norton Internet Security 2006"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"]
{A8F38D8D–E480–4D52–B7A2–731BB6995FDD}\(Default) = "NAV Helper"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714–76d4–11d1–8b24–00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
–> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560–9AA2–1069–930E–00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{30D02401–6A81–11d0–8274–00C04FD5AE38}" = "IE Search Band"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{E7E4BC40–E76A–11CE–A9BB–00AA004AE837}" = "Shell DocObject Viewer"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{FBF23B40–E3F0–101B–8488–00AA003E56F8}" = "InternetShortcut"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{3C374A40–BAE4–11CF–BF7D–00AA006946EE}" = "Microsoft Url History Service"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{FF393560–C2A7–11CF–BFF4–444553540000}" = "History"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{7BD29E00–76C1–11CF–9DD0–00A0C9034933}" = "Temporary Internet Files"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{7BD29E01–76C1–11CF–9DD0–00A0C9034933}" = "Temporary Internet Files"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{CFBFAE00–17A6–11D0–99CB–00C04FD64497}" = "Microsoft Url Search Hook"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{3DC7A020–0ACD–11CF–A9BB–00AA004AE837}" = "The Internet"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{871C5380–42A0–1069–A2EA–08002B30309D}" = "Internet Name Space"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{B41DB860–8EE4–11D2–9906–E49FADC173CA}" = "WinRAR shell extension"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
"{32020A01–506E–484D–A2A8–BE3CF17601C3}" = "AlcoholShellEx"
–> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\ALCOHO~1\ALCOHO~1\AXShlEx.dll" ["Alcohol Soft Development Team"]
"{21569614–B795–46b1–85F4–E737A8DC09AD}" = "Shell Search Band"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{0D6D4F41–2994–4ba0–8FEF–620E43CD2812}" = "IE Microsoft Internet Toolbar"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{73CFD649–CD48–4fd8–A272–2070EA56526B}" = "IE BandProxy"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{07C45BB1–4A8C–4642–A1F5–237E7215FF66}" = "IE Microsoft BrowserBand"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{43886CD5–6529–41c4–A707–7B3C92C05E68}" = "IE Navigation Bar"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{C4EC38BD–4E9E–4b5e–935A–D1BFF237D980}" = "Explorer Travel Band"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{6D8BB3D3–9D87–4a91–AB56–4F30CFFEFE9F}" = "Explorer Search Band"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{F83DAC1C–9BB9–4f2b–B619–09819DA81B0E}" = "IE Registry Tree Options Utility"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{DE011590–0531–4804–9C9C–3FEDC7E6E5C8}" = "IE &Address"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{7E48925F–FF5C–47fa–A99A–F5912A10623B}" = "IE Address EditBox"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{3028902F–6374–48b2–8DC6–9725E775B926}" = "IE AutoComplete"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{98FF6D4B–6387–4b0a–8FBD–C5C4BB17B4F8}" = "IE MRU AutoComplete List"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{FDE7673D–2E19–4145–8376–BBD58C4BC7BA}" = "IE Custom MRU AutoCompleted List"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{6038EF75–ABFC–4e59–AB6F–12D397F6568D}" = "IE Microsoft History AutoComplete List"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{9D958C62–3954–4b44–8FAB–C4670C1DB4C2}" = "IE Microsoft Shell Folder AutoComplete List"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{B31C5FAE–961F–415b–BAF0–E697A5178B94}" = "IE Microsoft Multiple AutoComplete List Container"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{E6EE9AAC–F76B–4947–8260–A9F136138E11}" = "IE Shell Band Site Menu"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{7EDC7DE1–DD42–457a–8B36–B422F8E94E14}" = "IE Shell DeskBar"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{BFAD62EE–9D54–4b2a–BF3B–76F90697BD2A}" = "IE Shell Rebar BandSite"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{FAC3CBF6–8697–43d0–BAB9–DCD1FCE19D75}" = "IE User Assist"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{F0353E1D–FEEC–474e–A984–1E5C6865E380}" = "IE Global Folder Settings"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{4B78D326–D922–44f9–AF2A–07805C2A3560}" = "IE Menu Band"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{6CF48EF8–44CD–45d2–8832–A16EA016311B}" = "IE IShellFolderBand"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{F2CF5485–4E02–4f68–819C–B92DE9277049}" = "&Links"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{DBC04CF4–BE36–4f53–9C48–2D3625CA7694}" = "IE Thumbnail Image"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{1C1EDB47–CE22–4bbb–B608–77B48F83C823}" = "IE Fade Task"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{6B4ECC4F–16D1–4474–94AB–5A763F2A54AE}" = "IE Tracking Shell Menu"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{44C76ECD–F7FA–411c–9929–1B77BA77F524}" = "IE Menu Site"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{205D7A97–F16D–4691–86EF–F3075DCCA57D}" = "IE Menu Desk Bar"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{482A7CB3–2EDF–4595–A315–A5244F1E96E6}" = "IE Search Control"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{0B1818A2–EA07–4a55–AF57–1F410EBD21D3}" = "Favorites Band"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{BC476F4C–D9D7–4100–8D4E–E043F6DEC409}" = "Microsoft Browser Architecture"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\
INFECTION WARNING! "{553858A7–4922–4e7e–B1C1–97140C1C16EF}" = "IE Component Categories cache daemon"
–> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
INFECTION WARNING! AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D–699D–49B2–BE16–7F82CB4C59CA}"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
WinRAR\(Default) = "{B41DB860–8EE4–11D2–9906–E49FADC173CA}"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860–8EE4–11D2–9906–E49FADC173CA}"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D–699D–49B2–BE16–7F82CB4C59CA}"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
WinRAR\(Default) = "{B41DB860–8EE4–11D2–9906–E49FADC173CA}"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
Active Desktop and Wallpaper:
–––––––––––––––––––––––––––––
Active Desktop is disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\Andrzej\Dane aplikacji\Mozilla\Firefox\Tapeta pulpitu.bmp"
Enabled Screen Saver:
–––––––––––––––––––––
HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\System32\logon.scr" [MS]
Enabled Scheduled Tasks:
––––––––––––––––––––––––
"Norton AntiVirus – Uruchom pełne skanowanie systemu – Andrzej" –> launches: "C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe /TASK:"C:\Documents and Settings\All Users\Dane aplikacji\Symantec\Norton AntiVirus\Tasks\mycomp.sca"" ["Symantec Corporation"]
"Symantec NetDetect" –> launches: "C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE" ["Symantec Corporation"]
Winsock2 Service Provider DLLs:
–––––––––––––––––––––––––––––––
Namespace Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
Transport Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 – 03, 06 – 13
%SystemRoot%\system32\rsvpsp.dll [MS], 04 – 05
Toolbars, Explorer Bars, Extensions:
––––––––––––––––––––––––––––––––––––
Toolbars
HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
"{C4069E3A–68F1–403E–B40E–20066696354B}" = "Norton AntiVirus" [from CLSID]
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{0B53EAC3–8D69–4B9E–9B19–A37C9A5676A7}" = "Norton Internet Security 2006" [from CLSID]
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"]
HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{0B53EAC3–8D69–4B9E–9B19–A37C9A5676A7}" = "Norton Internet Security 2006"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"]
"{C4069E3A–68F1–403E–B40E–20066696354B}" = "Norton AntiVirus"
–> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
Extensions (Tools menu items, main toolbar menu buttons)
HKLM\Software\Microsoft\Internet Explorer\Extensions\
{FB5F1910–F110–11D2–BB9E–00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]
Miscellaneous IE Hijack Points
––––––––––––––––––––––––––––––
C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")
Added lines (compared with English–language version):
[Strings]: START_PAGE_URL="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
[Strings]: MS_START_PAGE_URL="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
Missing lines (compared with English–language version):
[Strings]: 2 lines
HKLM\Software\Microsoft\Internet Explorer\AboutURLs\
HIJACK WARNING! "NavigationFailure" = "res://ieframe.dll/navcancl.htm" [MS]
HIJACK WARNING! "DesktopItemNavigationFailure" = "res://ieframe.dll/navcancl.htm" [MS]
HIJACK WARNING! "NavigationCanceled" = "res://ieframe.dll/navcancl.htm" [MS]
HIJACK WARNING! "OfflineInformation" = "res://ieframe.dll/offcancl.htm" [MS]
HIJACK WARNING! "PostNotCached" = "res://ieframe.dll/repost.htm" [MS]
HIJACK WARNING! "NoAdd–ons" = "res://ieframe.dll/noaddon.htm" [MS]
HIJACK WARNING! "NoAdd–onsInfo" = "res://ieframe.dll/noaddoninfo.htm" [MS]
HIJACK WARNING! "SecurityRisk" = "res://ieframe.dll/securityatrisk.htm" [MS]
Running Services (Display Name, Service Name, Path {Service DLL}):
––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––––
Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\System32\Ati2evxx.exe" ["ATI Technologies Inc."]
PCTEL Speaker Phone, Pctspk, "C:\WINDOWS\system32\pctspk.exe" ["PCtel, Inc."]
StarWind iSCSI Service, StarWindService, "C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe" ["Rocket Division Software"]
Symantec Core LC, Symantec Core LC, ""C:\Program Files\Common Files\Symantec Shared\CCPD–LC\symlcsvc.exe"" ["Symantec Corporation"]
Symantec Event Manager, ccEvtMgr, ""C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"" ["Symantec Corporation"]
Symantec Network Drivers Service, SNDSrvc, ""C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"" ["Symantec Corporation"]
Symantec Network Proxy, ccProxy, ""C:\Program Files\Common Files\Symantec Shared\ccProxy.exe"" ["Symantec Corporation"]
Symantec Settings Manager, ccSetMgr, ""C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"" ["Symantec Corporation"]
Symantec SPBBCSvc, SPBBCSvc, ""C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"" ["Symantec Corporation"]
Usługa Auto–Protect programu Norton AntiVirus, navapsvc, ""C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe"" ["Symantec Corporation"]
Usługa Norton Protection Center, NSCService, ""C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE"" ["Symantec Corporation"]
––––––––––
Mysle, ze zadnych syfow nie powinienem miec. NIS gryzie sie widocznie z dana konfiguracja systemowa(a ze tylko u mnie – magia). Jak mowilem po zainstalowaniu IE 7.0 , glupio to brzmi ale zaczal chyba dzialac – a przynajmniej skanowanie wykonal tym razem ;–)
Zamies Loga Silent Ruuners.!
Hmm moze to i niedorzeczne, ale po zainstalowaniu IE 7.0 Beta .. wszystko dziala bez zarzutu :D
Przynajmniej na pierwszy rzut oka.
Przynajmniej na pierwszy rzut oka.
Przeinstalowalem. Bez zmian :(
Log czysty...
A co do błędu to spróbuj przeinstalować Nortona.
A co do błędu to spróbuj przeinstalować Nortona.
szzzzz:Prosze o Loga z Hijack'a tu jak narazie wystepuja bledy wiec niczego stwierdzic nie morzna.!
Mnie to nic nie mowi :) ale prosze uprzejmnie :
Logfile of HijackThis v1.99.1
Scan saved at 05:55:33, on 2006–02–07
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD–LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Gadu–Gadu\gg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\navw32.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Andrzej\Pulpit\HijackThis.exe
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://onet.pl/
R1 – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = w3cache.tpnet.pl:8080
R0 – HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 – BHO: Norton Internet Security 2006 – {9ECB9560–04F9–4bbc–943D–298DDF1699E1} – C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 – BHO: NAV Helper – {A8F38D8D–E480–4D52–B7A2–731BB6995FDD} – C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 – Toolbar: Norton Internet Security 2006 – {0B53EAC3–8D69–4b9e–9B19–A37C9A5676A7} – C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 – Toolbar: Norton AntiVirus – {C4069E3A–68F1–403E–B40E–20066696354B} – C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 – HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 – HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 – HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 – HKCU\..\Run: [Gadu–Gadu] "C:\Program Files\Gadu–Gadu\gg.exe" /tray
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
O12 – Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 – HKLM\System\CCS\Services\Tcpip\..\{0AD3AF31–3D43–40C0–A532–1B5FF6069B82}: NameServer = 80.51.89.5,80.51.89.2
O23 – Service: Ati HotKey Poller – ATI Technologies Inc. – C:\WINDOWS\System32\Ati2evxx.exe
O23 – Service: ATI Smart – Unknown owner – C:\WINDOWS\system32\ati2sgag.exe
O23 – Service: Symantec Event Manager (ccEvtMgr) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 – Service: Symantec Internet Security Password Validation (ccISPwdSvc) – Symantec Corporation – C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 – Service: Symantec Network Proxy (ccProxy) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 – Service: Symantec Settings Manager (ccSetMgr) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 – Service: COM Host (comHost) – Symantec Corporation – C:\Program Files\Norton Internet Security\comHost.exe
O23 – Service: Usługa Auto–Protect programu Norton AntiVirus (navapsvc) – Symantec Corporation – C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 – Service: Usługa Norton Protection Center (NSCService) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 – Service: PCTEL Speaker Phone (Pctspk) – PCtel, Inc. – C:\WINDOWS\system32\pctspk.exe
O23 – Service: Symantec AVScan (SAVScan) – Symantec Corporation – C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 – Service: Symantec Network Drivers Service (SNDSrvc) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 – Service: Symantec SPBBCSvc (SPBBCSvc) – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 – Service: StarWind iSCSI Service (StarWindService) – Rocket Division Software – C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 – Service: Symantec Core LC – Symantec Corporation – C:\Program Files\Common Files\Symantec Shared\CCPD–LC\symlcsvc.exe
Prosze o Loga z Hijack'a tu jak narazie wystepuja bledy wiec niczego stwierdzic nie morzna.!
Strona 1 / 1