Forumi
Home Pravila i pomoć Članovi Kalendar Današnji postovi


Povratak   PC Ekspert Forum > Računala > Problemi > Softverski problemi
Ime
Lozinka

Odgovori
 
Uređivanje
Staro 15.02.2007., 21:25   #1
Imperator
Registered User
 
Imperator's Avatar
 
Datum registracije: Nov 2006
Lokacija: DBK
Postovi: 15
Question Sporo funkcioniranje sistema

Ovako, tijekom dana, spojen na internet laptop je iako već spor jako usporio.
Od podizanja, koje traje (pre)više minuta, pa do čudnih trzaja miša i trzanja i pucketanja zvučnika (iako je zvuk u intervalima potpuno čist) cca. svake 3 sekunde, što je izgleda isključivo softverski problem. Instalirao sam besplatnu verziju Bitdefendera koji je pronašao samo tri virusa (od kojih dva unutar direktorija Bitdefendera : hitthewa ).
Ovakvo je stanje u task manageru:
_____________________________
_____________________________
Processes
Image Name User Name(prazna polja su ime mašine)



explorer.exe
taskmgr.exe
locator.exe NETWORK SERVICE
hpwmi.exe SYSTEM
HPQTA~1.exe
Skype.exe
bdmcon.exe
LVCOMSX.exe
AlarmMe.exe
rundll32.exe
atiptaxx.exe
SynTPEnh.exe
realched.exe
InCD.exe
svchost.exe LOCAL SERVICE
hpqwmiex.exe SYSTEM
alg.exe LOCAL SERVICE
svchost.exe NETWORK SERVICE
asghost.exe
ati2evxx.exe
dllhost.exe SYSTEM
bdss.exe SYSTEM
xcommsvr.exe SYSTEM
InCDsrv.exe SYSTEM
svchost.exe SYSTEM
svchost.exe NETWORK SERVICE
svchost.exe SYSTEM
ati2evxx.exe SYSTEM
Issass.exe SYSTEM
services.exe SYSTEM
winlogon.exe SYSTEM
csrss.exe SYSTEM
svchost.exe LOCAL SERVICE
svchost.exe SYSTEM
wmiprvse.exe SYSTEM
LVPrcSrv.exe SYSTEM
spoolsv.exe SYSTEM
smss.exe SYSTEM
btwdins.exe SYSTEM
BCMWLTRY.EXE SYSTEM
WLTRYSVC.EXE SYSTEM
System Idle Processes SYSTEM
__________________________
__________________________

Valjda ovo pomogne, mislim da je neka vrsta dialera ili sl. ali vi vidite i pomozite.
Nakon što sam napravio end task samo na ova dva locator.exe i svchost.exe (kojega ima previše upaljenih, ne znam zašto) Izbacio je odbrojavanje do shutdowna sa napomenom "The system is shutting down. Shutdown was initiated by NT AUTHORITY\SYSTEM". Je li to normalno ili ne.
Molim Vašu pomoć
Imperator je offline   Reply With Quote
Staro 15.02.2007., 22:33   #2
Buger
Premium
Moj komp
 
Datum registracije: Feb 2006
Lokacija: Osijek
Postovi: 4,387
najbolje ti je format C:\

skeniraj komp s AVG anti-spyware, AD-aware, Spybot, Hijack this(log file pasteaj ovdje)

samo 3 virusa

što se tiče shutdowna, samo odi na sat i vrati ga par sati unatrag pa imaš fore
Buger je offline   Reply With Quote
Oglasni prostor
Oglas
 
Oglas
Staro 15.02.2007., 23:33   #3
McG
-------
 
Datum registracije: Aug 2005
Lokacija: -
Postovi: 7,568
Najprije pročisti i popravi sve kaj se da, a tek kad vidiš da nema pomoći - formatiraj.
BitDefender slobodni makni.
Nekolicina korisnih programčeka i linkova:
EFRC
RegMon
RegCleaner
Autoruns
CCleaner
Comodo Firewall
Servisi: 1, 2, 3
HDTune
Startup
PerfectDisk
Procesi
McG je offline   Reply With Quote
Staro 16.02.2007., 03:48   #4
Imperator
Registered User
 
Imperator's Avatar
 
Datum registracije: Nov 2006
Lokacija: DBK
Postovi: 15
Evo
Bitdefender izbrisan (btw, tih 9 Mb je brisalo cijelu minutu!)
avg=0 virusa
ad-Avare=37 problema rješenih
ali nakon restarta, komp se palio nekih 15 min, nakon čega je ponovno izbacio:
error loading C:\windows\system32\cgggrgn.dll i
C:\windows\system32\drvxib.dll
Onda sam ga hijackao pa kaže ovako:

Logfile of HijackThis v1.99.1
Scan saved at 3:40:16, on 16.2.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\HPQ\IAM\bin\asghost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\bcmntray.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\MUSICA~1\mac.exe
C:\Program Files\Alarm Me\AlarmMe.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\PROGRA~1\HPQ\SHARED\HPQTOA~1.EXE
C:\Program Files\HPQ\Shared\hpqwmi.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Stankovic\Desktop\avg\HijackThis.exe
C:\WINDOWS\system32\mmc.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://v4.windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Ajd na Net
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: HP Credential Manager for ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\HPQ\IAM\Bin\ItIeAddIN.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\bcmntray
O4 - HKLM\..\Run: [tcomantidialerrun] C:\Program Files\T-Com Antidialer\T-Com Antidialer.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\System32\drvxib.dll,startup
O4 - HKLM\..\Run: [cgggrgn.dll] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\cgggrgn.dll,wqrem
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\SCROLL~1\MouseElf.EXE
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll,RegisterModule
O4 - HKLM\..\Run: [Music Alarm Clock] C:\PROGRA~1\MUSICA~1\mac.exe
O4 - HKLM\..\Run: [AlarmMe] "C:\Program Files\Alarm Me\AlarmMe.exe" "-h"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: BlueSoleil.lnk = ?
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: I&zvoz u Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O20 - Winlogon Notify: OneCard - C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll
O20 - Winlogon Notify: winepi32 - winepi32.dll (file missing)
O21 - SSODL: cussers - {ff170564-36c8-43f7-9100-559e166405cf} - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\Shared\hpqwmi.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
Imperator je offline   Reply With Quote
Staro 16.02.2007., 04:38   #5
stuc
Banned
 
stuc's Avatar
 
Datum registracije: May 2005
Lokacija: Online
Postovi: 2,404
Kratko i jasno, zaklao si ga : lol2 :

Ne sa virusima nego sa pravom gomilom programa i cjelim čudom aktivnih servisa.
Nosi to nekom da ti poisključuje šta ti ne treba ili format....
stuc je offline   Reply With Quote
Staro 16.02.2007., 15:17   #6
tutix
Premium
Moj komp
 
tutix's Avatar
 
Datum registracije: Jan 2006
Lokacija: Zagreb
Postovi: 4,068
Najbolje da reinstaliraš ali ajd možeš još probat izbrisat ovo u Hijack-This-u:

C:\PROGRA~1\MUSICA~1\mac.exe
C:\Program Files\Alarm Me\AlarmMe.exe
O4 - HKLM\..\Run: [cgggrgn.dll] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\cgggrgn.dll,wqrem
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Music Alarm Clock] C:\PROGRA~1\MUSICA~1\mac.exe
O4 - HKLM\..\Run: [AlarmMe] "C:\Program Files\Alarm Me\AlarmMe.exe" "-h"
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: I&zvoz u Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O20 - Winlogon Notify: winepi32 - winepi32.dll (file missing)
O21 - SSODL: cussers - {ff170564-36c8-43f7-9100-559e166405cf} - (no file)

Daj si sredi programe koji ti se pokreću prilikom bootanja, skini CCleaner (direct link) (već ti je McG dao link isto) i njime očisti komp od smeća, bespotrebnih registry ključeva i u njemu si sredi programe koji se pokreću sa startanjem Windowsa (izbornici lijevo u programu).

I instaliraj si neki Firewall pod obavezno.

EDIT: Ustvari makni još i ovo (nisu maliciozni servisi ali ti usporavaju komp bezveze)

O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\SCROLL~1\MouseElf.EXE
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

Evo to je to.
tutix je offline   Reply With Quote
Staro 16.02.2007., 17:10   #7
Imperator
Registered User
 
Imperator's Avatar
 
Datum registracije: Nov 2006
Lokacija: DBK
Postovi: 15
Puno vam hvala, osjećaju se već neka poboljšalja, ali to je samo privremeno jer ću skoro morati pribjeći radikalnom rješenju koje ste predložili, a i meni se čini najbolje..: giljotin : Drone : : goood :
Imperator je offline   Reply With Quote
Oglasni prostor
Oglas
 
Oglas
Odgovori



Pravila postanja
Vi ne možete otvarati nove teme
Vi ne možete pisati odgovore
Vi ne možete uploadati priloge
Vi ne možete uređivati svoje poruke

BB code je Uključeno
Smajlići su Uključeno
[IMG] kod je Uključeno
HTML je Isključeno

Idi na