|
![]() |
#1 |
Registered User
Datum registracije: Nov 2006
Lokacija: DBK
Postovi: 15
|
![]() Ovako, tijekom dana, spojen na internet laptop je iako već spor jako usporio. Od podizanja, koje traje (pre)više minuta, pa do čudnih trzaja miša i trzanja i pucketanja zvučnika (iako je zvuk u intervalima potpuno čist) cca. svake 3 sekunde, što je izgleda isključivo softverski problem. Instalirao sam besplatnu verziju Bitdefendera koji je pronašao samo tri virusa (od kojih dva unutar direktorija Bitdefendera : hitthewa ). Ovakvo je stanje u task manageru: _____________________________ _____________________________ Processes Image Name User Name(prazna polja su ime mašine) explorer.exe taskmgr.exe locator.exe NETWORK SERVICE hpwmi.exe SYSTEM HPQTA~1.exe Skype.exe bdmcon.exe LVCOMSX.exe AlarmMe.exe rundll32.exe atiptaxx.exe SynTPEnh.exe realched.exe InCD.exe svchost.exe LOCAL SERVICE hpqwmiex.exe SYSTEM alg.exe LOCAL SERVICE svchost.exe NETWORK SERVICE asghost.exe ati2evxx.exe dllhost.exe SYSTEM bdss.exe SYSTEM xcommsvr.exe SYSTEM InCDsrv.exe SYSTEM svchost.exe SYSTEM svchost.exe NETWORK SERVICE svchost.exe SYSTEM ati2evxx.exe SYSTEM Issass.exe SYSTEM services.exe SYSTEM winlogon.exe SYSTEM csrss.exe SYSTEM svchost.exe LOCAL SERVICE svchost.exe SYSTEM wmiprvse.exe SYSTEM LVPrcSrv.exe SYSTEM spoolsv.exe SYSTEM smss.exe SYSTEM btwdins.exe SYSTEM BCMWLTRY.EXE SYSTEM WLTRYSVC.EXE SYSTEM System Idle Processes SYSTEM __________________________ __________________________ Valjda ovo pomogne, mislim da je neka vrsta dialera ili sl. ali vi vidite i pomozite. Nakon što sam napravio end task samo na ova dva locator.exe i svchost.exe (kojega ima previše upaljenih, ne znam zašto) Izbacio je odbrojavanje do shutdowna sa napomenom "The system is shutting down. Shutdown was initiated by NT AUTHORITY\SYSTEM". Je li to normalno ili ne. Molim Vašu pomoć |
![]() |
![]() |
![]() |
#2 |
Premium
Datum registracije: Feb 2006
Lokacija: Osijek
Postovi: 4,387
|
najbolje ti je format C:\ skeniraj komp s AVG anti-spyware, AD-aware, Spybot, Hijack this(log file pasteaj ovdje) samo 3 virusa ![]() što se tiče shutdowna, samo odi na sat i vrati ga par sati unatrag pa imaš fore |
![]() |
![]() |
|
|
Oglas
|
|
![]() |
#3 |
-------
Datum registracije: Aug 2005
Lokacija: -
Postovi: 7,568
|
Najprije pročisti i popravi sve kaj se da, a tek kad vidiš da nema pomoći - formatiraj. BitDefender slobodni makni. Nekolicina korisnih programčeka i linkova: EFRC RegMon RegCleaner Autoruns CCleaner Comodo Firewall Servisi: 1, 2, 3 HDTune Startup PerfectDisk Procesi |
![]() |
![]() |
![]() |
#4 |
Registered User
Datum registracije: Nov 2006
Lokacija: DBK
Postovi: 15
|
Evo Bitdefender izbrisan (btw, tih 9 Mb je brisalo cijelu minutu!) avg=0 virusa ad-Avare=37 problema rješenih ali nakon restarta, komp se palio nekih 15 min, nakon čega je ponovno izbacio: error loading C:\windows\system32\cgggrgn.dll i C:\windows\system32\drvxib.dll Onda sam ga hijackao pa kaže ovako: Logfile of HijackThis v1.99.1 Scan saved at 3:40:16, on 16.2.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\HPQ\IAM\bin\asghost.exe C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\svchost.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe C:\WINDOWS\system32\bcmntray.exe C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\MUSICA~1\mac.exe C:\Program Files\Alarm Me\AlarmMe.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe C:\PROGRA~1\HPQ\SHARED\HPQTOA~1.EXE C:\Program Files\HPQ\Shared\hpqwmi.exe C:\WINDOWS\system32\msiexec.exe C:\Documents and Settings\Stankovic\Desktop\avg\HijackThis.exe C:\WINDOWS\system32\mmc.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://v4.windowsupdate.microsoft.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Ajd na Net R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: HP Credential Manager for ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\HPQ\IAM\Bin\ItIeAddIN.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\bcmntray O4 - HKLM\..\Run: [tcomantidialerrun] C:\Program Files\T-Com Antidialer\T-Com Antidialer.exe O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\System32\drvxib.dll,startup O4 - HKLM\..\Run: [cgggrgn.dll] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\cgggrgn.dll,wqrem O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\SCROLL~1\MouseElf.EXE O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll,RegisterModule O4 - HKLM\..\Run: [Music Alarm Clock] C:\PROGRA~1\MUSICA~1\mac.exe O4 - HKLM\..\Run: [AlarmMe] "C:\Program Files\Alarm Me\AlarmMe.exe" "-h" O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - Global Startup: BlueSoleil.lnk = ? O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: I&zvoz u Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O20 - Winlogon Notify: OneCard - C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll O20 - Winlogon Notify: winepi32 - winepi32.dll (file missing) O21 - SSODL: cussers - {ff170564-36c8-43f7-9100-559e166405cf} - (no file) O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\Shared\hpqwmi.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe |
![]() |
![]() |
![]() |
#5 |
Banned
Datum registracije: May 2005
Lokacija: Online
Postovi: 2,404
|
Kratko i jasno, zaklao si ga : lol2 : Ne sa virusima nego sa pravom gomilom programa i cjelim čudom aktivnih servisa. Nosi to nekom da ti poisključuje šta ti ne treba ili format.... |
![]() |
![]() |
![]() |
#6 |
Premium
Datum registracije: Jan 2006
Lokacija: Zagreb
Postovi: 4,068
|
Najbolje da reinstaliraš ali ajd možeš još probat izbrisat ovo u Hijack-This-u: C:\PROGRA~1\MUSICA~1\mac.exe C:\Program Files\Alarm Me\AlarmMe.exe O4 - HKLM\..\Run: [cgggrgn.dll] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\cgggrgn.dll,wqrem O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [Music Alarm Clock] C:\PROGRA~1\MUSICA~1\mac.exe O4 - HKLM\..\Run: [AlarmMe] "C:\Program Files\Alarm Me\AlarmMe.exe" "-h" O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: I&zvoz u Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O20 - Winlogon Notify: winepi32 - winepi32.dll (file missing) O21 - SSODL: cussers - {ff170564-36c8-43f7-9100-559e166405cf} - (no file) Daj si sredi programe koji ti se pokreću prilikom bootanja, skini CCleaner (direct link) (već ti je McG dao link isto) i njime očisti komp od smeća, bespotrebnih registry ključeva i u njemu si sredi programe koji se pokreću sa startanjem Windowsa (izbornici lijevo u programu). I instaliraj si neki Firewall pod obavezno. EDIT: Ustvari makni još i ovo (nisu maliciozni servisi ali ti usporavaju komp bezveze) O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\SCROLL~1\MouseElf.EXE O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot Evo to je to. |
![]() |
![]() |
![]() |
#7 |
Registered User
Datum registracije: Nov 2006
Lokacija: DBK
Postovi: 15
|
Puno vam hvala, osjećaju se već neka poboljšalja, ali to je samo privremeno jer ću skoro morati pribjeći radikalnom rješenju koje ste predložili, a i meni se čini najbolje..: giljotin : Drone : : goood : |
![]() |
![]() |
|
|
Oglas
|
|
![]() |
|
|