Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu - svchost.exe vytížen na 100%

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Rengen
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 16 dub 2007 18:39

Prosím o kontrolu logu - svchost.exe vytížen na 100%

#1 Příspěvek od Rengen »

Prosím o kontrolu logu. Proces svchost je pernamentně vytížen na 100%.

Díky za pomoc.

Logfile of random's system information tool 1.06 (written by random/random)
Run by Gustav at 2010-02-27 20:43:12
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 5 GB (7%) free of 76 GB
Total RAM: 767 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:43:49, on 27.2.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Documents and Settings\Gustav\Dokumenty\Stažené soubory\RSIT.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\trend micro\Gustav.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: winesm32.exe
O8 - Extra context menu item: &Search - ?p=ZCfox000(2)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 1736495328
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

--
End of file - 4292 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class - C:\PROGRA~1\ICQTOO~1\toolbaru.dll [2006-12-25 701952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 501400]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bron-Spizaetus]
C:\WINDOWS\ShellNew\sempalong.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
C:\Program Files\ICQLite\ICQLite.exe -minimize []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2004-10-13 1694208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEXPRESS]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe [2007-02-04 79400]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2007-06-29 286720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe /systray /nologon []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2003-08-15 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-10-25 210472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe [2007-03-14 83608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tok-Cirrhatus]
C:\Documents and Settings\Gustav\Local Settings\Data aplikací\smss.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\READER~1.0\Reader\READER~1.EXE [2009-02-27 35696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Synchronizer.lnk]
C:\PROGRA~1\Adobe\READER~1.0\Reader\ADOBEC~1.EXE [2009-02-27 542096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~2\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Gustav^Nabídka Start^Programy^Po spuštění^Empty.pif]
C:\Documents and Settings\Gustav\Nabídka Start\Programy\Po spuštění\Empty.pif []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Gustav^Nabídka Start^Programy^Po spuštění^winesm32.exe]
C:\Documents and Settings\Gustav\Nabídka Start\Programy\Po spuštění\winesm32.exe [2004-08-17 29184]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mnmsrvc"=3

C:\Documents and Settings\Gustav\Nabídka Start\Programy\Po spuštění
winesm32.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableCMD"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoFolderOptions"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQLite\ICQLite.exe"="C:\Program Files\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite"
"C:\Program Files\Azureus\Azureus.exe"="C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\Program Files\TightVNC\WinVNC.exe"="C:\Program Files\TightVNC\WinVNC.exe:*:Enabled:TightVNC Win32 Server"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2010-02-27 20:04:25 ----D---- C:\_OTM
2010-02-27 19:52:49 ----D---- C:\Program Files\trend micro
2010-02-27 19:52:43 ----D---- C:\rsit
2010-02-27 18:37:52 ----A---- C:\WINDOWS\wininit.ini
2010-02-27 17:02:47 ----HDC---- C:\WINDOWS\$NtUninstallKB952011$
2010-02-27 16:15:05 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-02-27 16:15:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-02-27 16:14:51 ----D---- C:\WINDOWS\system32\CatRoot_bak
2010-02-27 16:07:32 ----D---- C:\c87b35079303a7086c
2010-02-27 14:30:20 ----A---- C:\Program Files\Uninstall Fun Web Products.dll
2010-02-27 13:03:19 ----A---- C:\WINDOWS\system32\reboot.txt
2010-02-27 12:58:47 ----SHD---- C:\Config.Msi
2010-02-08 12:31:19 ----D---- C:\Documents and Settings\All Users\Data aplikací\FarmFrenzy3_Arctica

======List of files/folders modified in the last 1 months======

2010-02-27 20:41:51 ----D---- C:\WINDOWS\Temp
2010-02-27 20:20:46 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-27 20:02:18 ----SH---- C:\boot.ini
2010-02-27 20:02:18 ----A---- C:\WINDOWS\win.ini
2010-02-27 20:02:18 ----A---- C:\WINDOWS\system.ini
2010-02-27 19:52:49 ----RD---- C:\Program Files
2010-02-27 19:50:33 ----D---- C:\WINDOWS
2010-02-27 19:48:31 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-27 19:24:20 ----D---- C:\WINDOWS\system32\CatRoot
2010-02-27 17:09:03 ----HD---- C:\WINDOWS\inf
2010-02-27 17:04:57 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-27 17:04:53 ----D---- C:\WINDOWS\system32\drivers
2010-02-27 17:04:52 ----D---- C:\WINDOWS\system32
2010-02-27 16:52:49 ----D---- C:\Program Files\Google
2010-02-27 16:14:48 ----D---- C:\WINDOWS\Debug
2010-02-27 14:52:06 ----D---- C:\Program Files\Mozilla Firefox
2010-02-27 14:49:51 ----D---- C:\Program Files\BSPlayer
2010-02-27 14:49:19 ----SHD---- C:\WINDOWS\Installer
2010-02-27 14:46:29 ----D---- C:\WINDOWS\Downloaded Installations
2010-02-27 14:45:58 ----D---- C:\Program Files\Adobe
2010-02-27 14:44:23 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-27 14:43:48 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-02-27 14:31:03 ----D---- C:\Program Files\nLite
2010-02-27 14:30:41 ----D---- C:\Program Files\Mv2Player
2010-02-27 14:30:09 ----D---- C:\Program Files\Internet Explorer
2010-02-27 13:04:57 ----D---- C:\Program Files\Hewlett-Packard
2010-02-27 13:00:42 ----A---- C:\WINDOWS\hpdj3600.ini
2010-02-27 12:53:52 ----D---- C:\Program Files\Common Files\InstallShield
2010-02-27 12:53:47 ----D---- C:\WINDOWS\Prefetch
2010-02-27 12:41:34 ----D---- C:\Program Files\CCleaner
2010-02-20 21:38:40 ----D---- C:\Documents and Settings\Gustav\Data aplikací\Azureus
2010-02-20 10:11:51 ----D---- C:\Program Files\Azureus
2010-02-17 20:15:33 ----D---- C:\Program Files\ICQ6.5

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2004-08-17 41216]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2003-08-14 404736]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2003-08-21 462940]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\WINDOWS\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 25856]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-04 20480]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 NTACCESS;NTACCESS; \??\D:\NTACCESS.sys []
S3 s916bus;Sony Ericsson Device 916 driver (WDM); C:\WINDOWS\system32\DRIVERS\s916bus.sys [2007-11-02 83496]
S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s916mdfl.sys [2007-11-02 15016]
S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s916mdm.sys [2007-11-02 109992]
S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s916mgmt.sys [2007-11-02 103976]
S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s916obex.sys [2007-11-02 100008]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\D:\NTGLM7X.sys []
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM); C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 58320]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter; C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 8304]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers; C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 94000]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2001-02-23 270336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-22 136120]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 hpdj3600;hpdj3600; C:\DOCUME~1\Gustav\LOCALS~1\Temp\hpdj3600.exe [2003-03-11 266240]

-----------------EOF-----------------

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Prosím o kontrolu logu - svchost.exe vytížen na 100%

#2 Příspěvek od Caroprd111 »

Zdravím :)

Na logu se pracuje, prosím o strpení.
Obrázek

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Prosím o kontrolu logu - svchost.exe vytížen na 100%

#3 Příspěvek od Caroprd111 »

Obrázek Podle návodu http://www.viry.cz/forum/viewtopic.php?f=15&t=72743 aplikujte tento skript.

Kód: Vybrat vše

:reg
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bron-Spizaetus]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tok-Cirrhatus]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Gustav^Nabídka Start^Programy^Po spuštění^winesm32.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Gustav^Nabídka Start^Programy^Po spuštění^Empty.pif]

:files
C:\Documents and Settings\Gustav\Nabídka Start\Programy\Po spuštění\Empty.pif
C:\Documents and Settings\Gustav\Nabídka Start\Programy\Po spuštění\winesm32.exe
C:\WINDOWS\ShellNew\sempalong.exe
C:\Documents and Settings\Gustav\Local Settings\Data aplikací\smss.exe

:commands
[EmptyTemp]
[Reboot]

Obrázek Doporučuji odinstalovat:
C:\Program Files\Azureus\Azureus.exe

P2P sítě a jejich klienti jsou potenciálním bezpečnostním rizikem, prakticky neustále jsou zdrojem virů, zbytečně se vystavujete riziku.
Obrázek

Rengen
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 16 dub 2007 18:39

Re: Prosím o kontrolu logu - svchost.exe vytížen na 100%

#4 Příspěvek od Rengen »

Perfektní, vše funguje, jak má :)
Zasílám nějakou dárcovskou sms na podporu fóra.

Díky moc


All processes killed
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bron-Spizaetus\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tok-Cirrhatus\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Gustav^Nabídka Start^Programy^Po spuštění^winesm32.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Gustav^Nabídka Start^Programy^Po spuštění^Empty.pif\ deleted successfully.
========== FILES ==========
File/Folder C:\Documents and Settings\Gustav\Nabídka Start\Programy\Po spuštění\Empty.pif not found.
C:\Documents and Settings\Gustav\Nabídka Start\Programy\Po spuštění\winesm32.exe moved successfully.
File/Folder C:\WINDOWS\ShellNew\sempalong.exe not found.
File/Folder C:\Documents and Settings\Gustav\Local Settings\Data aplikací\smss.exe not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Gustav
->Temp folder emptied: 1984744 bytes
->Temporary Internet Files folder emptied: 434892 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 33171257 bytes

User: Kristýna

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 6698515 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2158072 bytes
%systemroot%\System32 .tmp files removed: 2504 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 49152 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 86577155 bytes

Total Files Cleaned = 125,00 mb


OTM by OldTimer - Version 3.1.9.0 log created on 02272010_215417

Files moved on Reboot...

Registry entries deleted on Reboot...

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Prosím o kontrolu logu - svchost.exe vytížen na 100%

#5 Příspěvek od Caroprd111 »

Za podporu fóra děkuji. :)

Obrázek Dejte nový log z RSIT http://www.viry.cz/forum/viewtopic.php?f=30&t=82744
Obrázek

Rengen
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 16 dub 2007 18:39

Re: Prosím o kontrolu logu - svchost.exe vytížen na 100%

#6 Příspěvek od Rengen »

Nový log...

Logfile of random's system information tool 1.06 (written by random/random)
Run by Gustav at 2010-02-28 12:39:12
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 4 GB (6%) free of 76 GB
Total RAM: 767 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:39:23, on 28.2.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Documents and Settings\Gustav\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\trend micro\Gustav.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Search - ?p=ZCfox000(2)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 1736495328
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

--
End of file - 4382 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class - C:\PROGRA~1\ICQTOO~1\toolbaru.dll [2006-12-25 701952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 501400]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
C:\Program Files\ICQLite\ICQLite.exe -minimize []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEXPRESS]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe [2007-02-04 79400]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2007-06-29 286720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe /systray /nologon []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2003-08-15 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-10-25 210472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe [2007-03-14 83608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\READER~1.0\Reader\READER~1.EXE [2009-02-27 35696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Synchronizer.lnk]
C:\PROGRA~1\Adobe\READER~1.0\Reader\ADOBEC~1.EXE [2009-02-27 542096]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~2\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mnmsrvc"=3

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableCMD"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoFolderOptions"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQLite\ICQLite.exe"="C:\Program Files\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite"
"C:\Program Files\Azureus\Azureus.exe"="C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\Program Files\TightVNC\WinVNC.exe"="C:\Program Files\TightVNC\WinVNC.exe:*:Enabled:TightVNC Win32 Server"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-02-27 21:50:01 ----A---- C:\WINDOWS\OEWABLog.txt
2010-02-27 21:26:52 ----D---- C:\WINDOWS\Prefetch
2010-02-27 21:20:18 ----A---- C:\WINDOWS\setuplog.txt
2010-02-27 21:19:21 ----N---- C:\WINDOWS\system32\msxml6r.dll
2010-02-27 21:19:21 ----N---- C:\WINDOWS\system32\msxml6.dll
2010-02-27 21:19:19 ----N---- C:\WINDOWS\system32\comsdupd.exe
2010-02-27 21:19:18 ----N---- C:\WINDOWS\system32\smtpapi.dll
2010-02-27 21:19:18 ----N---- C:\WINDOWS\system32\rwnh.dll
2010-02-27 21:19:14 ----N---- C:\WINDOWS\system32\ati2dvag.dll
2010-02-27 21:19:14 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
2010-02-27 21:19:14 ----N---- C:\WINDOWS\system32\ati2cqag.dll
2010-02-27 21:19:14 ----N---- C:\WINDOWS\system32\aaclient.dll
2010-02-27 21:19:13 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2010-02-27 21:19:13 ----N---- C:\WINDOWS\system32\azroles.dll
2010-02-27 21:19:13 ----N---- C:\WINDOWS\system32\ativvaxx.dll
2010-02-27 21:19:13 ----N---- C:\WINDOWS\system32\ativtmxx.dll
2010-02-27 21:19:13 ----N---- C:\WINDOWS\system32\ati3duag.dll
2010-02-27 21:19:13 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
2010-02-27 21:19:12 ----N---- C:\WINDOWS\system32\dot3svc.dll
2010-02-27 21:19:12 ----N---- C:\WINDOWS\system32\dot3msm.dll
2010-02-27 21:19:12 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2010-02-27 21:19:12 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2010-02-27 21:19:12 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2010-02-27 21:19:12 ----N---- C:\WINDOWS\system32\dot3api.dll
2010-02-27 21:19:12 ----N---- C:\WINDOWS\system32\dimsroam.dll
2010-02-27 21:19:12 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2010-02-27 21:19:12 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2010-02-27 21:19:12 ----N---- C:\WINDOWS\system32\credssp.dll
2010-02-27 21:19:11 ----N---- C:\WINDOWS\system32\eapqec.dll
2010-02-27 21:19:11 ----N---- C:\WINDOWS\system32\eappprxy.dll
2010-02-27 21:19:11 ----N---- C:\WINDOWS\system32\eapphost.dll
2010-02-27 21:19:11 ----N---- C:\WINDOWS\system32\eappgnui.dll
2010-02-27 21:19:11 ----N---- C:\WINDOWS\system32\eappcfg.dll
2010-02-27 21:19:11 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2010-02-27 21:19:11 ----N---- C:\WINDOWS\system32\eapolqec.dll
2010-02-27 21:19:11 ----N---- C:\WINDOWS\system32\dot3ui.dll
2010-02-27 21:19:10 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
2010-02-27 21:19:10 ----N---- C:\WINDOWS\system32\eapsvc.dll
2010-02-27 21:19:08 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2010-02-27 21:19:08 ----N---- C:\WINDOWS\system32\kmsvc.dll
2010-02-27 21:19:08 ----N---- C:\WINDOWS\system32\kbdpash.dll
2010-02-27 21:19:08 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2010-02-27 21:19:08 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2010-02-27 21:19:08 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2010-02-27 21:19:07 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2010-02-27 21:19:07 ----N---- C:\WINDOWS\system32\mmcex.dll
2010-02-27 21:19:07 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2010-02-27 21:19:07 ----N---- C:\WINDOWS\system32\mdmxsdk.dll
2010-02-27 21:19:06 ----N---- C:\WINDOWS\system32\mtxparhd.dll
2010-02-27 21:19:06 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2010-02-27 21:19:06 ----N---- C:\WINDOWS\system32\mssha.dll
2010-02-27 21:19:06 ----N---- C:\WINDOWS\system32\mmcperf.exe
2010-02-27 21:19:05 ----N---- C:\WINDOWS\system32\napstat.exe
2010-02-27 21:19:05 ----N---- C:\WINDOWS\system32\napmontr.dll
2010-02-27 21:19:05 ----N---- C:\WINDOWS\system32\napipsec.dll
2010-02-27 21:19:03 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2010-02-27 21:19:03 ----N---- C:\WINDOWS\system32\onex.dll
2010-02-27 21:19:02 ----N---- C:\WINDOWS\system32\slcoinst.dll
2010-02-27 21:19:02 ----N---- C:\WINDOWS\system32\setupn.exe
2010-02-27 21:19:02 ----N---- C:\WINDOWS\system32\s3gnb.dll
2010-02-27 21:19:02 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2010-02-27 21:19:02 ----N---- C:\WINDOWS\system32\rasqec.dll
2010-02-27 21:19:02 ----N---- C:\WINDOWS\system32\qutil.dll
2010-02-27 21:19:02 ----N---- C:\WINDOWS\system32\qcliprov.dll
2010-02-27 21:19:02 ----N---- C:\WINDOWS\system32\qagentrt.dll
2010-02-27 21:19:02 ----N---- C:\WINDOWS\system32\qagent.dll
2010-02-27 21:19:01 ----N---- C:\WINDOWS\system32\slserv.exe
2010-02-27 21:19:01 ----N---- C:\WINDOWS\system32\slrundll.exe
2010-02-27 21:19:01 ----N---- C:\WINDOWS\system32\slgen.dll
2010-02-27 21:19:01 ----N---- C:\WINDOWS\system32\slextspk.dll
2010-02-27 21:19:00 ----N---- C:\WINDOWS\system32\tspkg.dll
2010-02-27 21:19:00 ----N---- C:\WINDOWS\system32\tsgqec.dll
2010-02-27 21:18:59 ----N---- C:\WINDOWS\system32\wlanapi.dll
2010-02-27 21:18:59 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2010-02-27 21:18:59 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2010-02-27 21:18:58 ----N---- C:\WINDOWS\system32\wmphoto.dll
2010-02-27 21:18:57 ----N---- C:\WINDOWS\system32\xmllite.dll
2010-02-27 21:18:57 ----N---- C:\WINDOWS\slrundll.exe
2010-02-27 21:18:56 ----D---- C:\WINDOWS\system32\cs-cz
2010-02-27 21:18:55 ----D---- C:\WINDOWS\l2schemas
2010-02-27 21:18:54 ----D---- C:\WINDOWS\system32\cs
2010-02-27 21:18:54 ----D---- C:\WINDOWS\system32\bits
2010-02-27 21:14:44 ----D---- C:\WINDOWS\ServicePackFiles
2010-02-27 21:11:07 ----D---- C:\WINDOWS\network diagnostic
2010-02-27 21:03:40 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-02-27 20:04:25 ----D---- C:\_OTM
2010-02-27 19:52:49 ----D---- C:\Program Files\trend micro
2010-02-27 19:52:43 ----D---- C:\rsit
2010-02-27 18:37:52 ----A---- C:\WINDOWS\wininit.ini
2010-02-27 17:06:33 ----A---- C:\WINDOWS\imsins.BAK
2010-02-27 17:02:47 ----HDC---- C:\WINDOWS\$NtUninstallKB952011$
2010-02-27 16:15:05 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-02-27 16:15:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-02-27 16:07:32 ----D---- C:\c87b35079303a7086c
2010-02-27 14:30:20 ----A---- C:\Program Files\Uninstall Fun Web Products.dll
2010-02-27 13:03:19 ----A---- C:\WINDOWS\system32\reboot.txt
2010-02-08 12:31:19 ----D---- C:\Documents and Settings\All Users\Data aplikací\FarmFrenzy3_Arctica

======List of files/folders modified in the last 1 months======

2010-02-28 12:31:59 ----D---- C:\WINDOWS\Temp
2010-02-28 12:27:49 ----D---- C:\Program Files\Azureus
2010-02-27 23:09:48 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-27 21:54:31 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-27 21:54:21 ----D---- C:\WINDOWS\system32
2010-02-27 21:54:21 ----D---- C:\WINDOWS
2010-02-27 21:50:10 ----SHD---- C:\WINDOWS\Installer
2010-02-27 21:29:06 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-02-27 21:27:56 ----D---- C:\WINDOWS\Debug
2010-02-27 21:25:54 ----D---- C:\WINDOWS\system32\Setup
2010-02-27 21:25:53 ----D---- C:\WINDOWS\system32\wbem
2010-02-27 21:25:53 ----D---- C:\WINDOWS\AppPatch
2010-02-27 21:25:52 ----RSD---- C:\WINDOWS\Fonts
2010-02-27 21:25:46 ----D---- C:\WINDOWS\system32\drivers
2010-02-27 21:25:10 ----D---- C:\WINDOWS\security
2010-02-27 21:24:10 ----D---- C:\WINDOWS\system32\CatRoot
2010-02-27 21:24:00 ----HD---- C:\WINDOWS\inf
2010-02-27 21:19:31 ----D---- C:\WINDOWS\WinSxS
2010-02-27 21:19:25 ----D---- C:\Program Files\Messenger
2010-02-27 21:19:21 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-27 21:19:20 ----D---- C:\WINDOWS\ehome
2010-02-27 21:19:18 ----D---- C:\WINDOWS\system32\inetsrv
2010-02-27 21:19:18 ----D---- C:\WINDOWS\Help
2010-02-27 21:19:17 ----D---- C:\WINDOWS\ime
2010-02-27 21:18:56 ----D---- C:\WINDOWS\system32\usmt
2010-02-27 21:18:55 ----D---- C:\Program Files\Internet Explorer
2010-02-27 21:18:54 ----D---- C:\WINDOWS\PeerNet
2010-02-27 21:18:53 ----D---- C:\Program Files\Movie Maker
2010-02-27 21:14:27 ----D---- C:\WINDOWS\system32\Restore
2010-02-27 21:14:26 ----D---- C:\WINDOWS\system32\npp
2010-02-27 21:14:24 ----D---- C:\WINDOWS\msagent
2010-02-27 21:14:21 ----D---- C:\WINDOWS\srchasst
2010-02-27 21:14:19 ----D---- C:\Program Files\NetMeeting
2010-02-27 21:14:17 ----D---- C:\WINDOWS\system32\Com
2010-02-27 21:14:13 ----D---- C:\Program Files\Windows NT
2010-02-27 21:14:13 ----D---- C:\Program Files\Windows Media Player
2010-02-27 21:14:12 ----D---- C:\Program Files\Outlook Express
2010-02-27 21:14:07 ----D---- C:\Program Files\Common Files\System
2010-02-27 21:13:38 ----D---- C:\WINDOWS\system32\oobe
2010-02-27 21:13:36 ----D---- C:\WINDOWS\system
2010-02-27 21:08:33 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-02-27 20:02:18 ----SH---- C:\boot.ini
2010-02-27 20:02:18 ----A---- C:\WINDOWS\win.ini
2010-02-27 20:02:18 ----A---- C:\WINDOWS\system.ini
2010-02-27 19:52:49 ----RD---- C:\Program Files
2010-02-27 16:52:49 ----D---- C:\Program Files\Google
2010-02-27 14:52:06 ----D---- C:\Program Files\Mozilla Firefox
2010-02-27 14:49:51 ----D---- C:\Program Files\BSPlayer
2010-02-27 14:46:29 ----D---- C:\WINDOWS\Downloaded Installations
2010-02-27 14:45:58 ----D---- C:\Program Files\Adobe
2010-02-27 14:44:23 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-27 14:43:48 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-02-27 14:31:03 ----D---- C:\Program Files\nLite
2010-02-27 14:30:41 ----D---- C:\Program Files\Mv2Player
2010-02-27 13:04:57 ----D---- C:\Program Files\Hewlett-Packard
2010-02-27 13:00:42 ----A---- C:\WINDOWS\hpdj3600.ini
2010-02-27 12:53:52 ----D---- C:\Program Files\Common Files\InstallShield
2010-02-27 12:41:34 ----D---- C:\Program Files\CCleaner
2010-02-20 21:38:40 ----D---- C:\Documents and Settings\Gustav\Data aplikací\Azureus
2010-02-17 20:15:33 ----D---- C:\Program Files\ICQ6.5

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2003-08-14 404736]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2003-08-21 462940]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\WINDOWS\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 NTACCESS;NTACCESS; \??\D:\NTACCESS.sys []
S3 s916bus;Sony Ericsson Device 916 driver (WDM); C:\WINDOWS\system32\DRIVERS\s916bus.sys [2007-11-02 83496]
S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s916mdfl.sys [2007-11-02 15016]
S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s916mdm.sys [2007-11-02 109992]
S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s916mgmt.sys [2007-11-02 103976]
S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s916obex.sys [2007-11-02 100008]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\D:\NTGLM7X.sys []
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM); C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 58320]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter; C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 8304]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers; C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 94000]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2001-02-23 270336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-22 136120]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 hpdj3600;hpdj3600; C:\DOCUME~1\Gustav\LOCALS~1\Temp\hpdj3600.exe -servicerunning=true -uninstall=hp deskjet 3600 series -product=3600 []

-----------------EOF-----------------

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Prosím o kontrolu logu - svchost.exe vytížen na 100%

#7 Příspěvek od Caroprd111 »

Obrázek Stáhněte OTC http://oldtimer.geekstogo.com/OTC.exe
  • Spusťte.
  • Klikněte na "CleanUp!". Potvrďte hlášky stiskem "Yes" (Bude následovat restart)

  • Obrázek Stáhněte Ccleaner http://viry.cz/forum/viewtopic.php?t=7478
  • Nainstalujte a v průběhu instalace odškrtněte, že chcete instalovat yahoo toolbar.

    Obrázek Záložka Čistič
  • Dejte analyzovat, po dokončení dejte Spustit Ccleaner.

    Obrázek Záložka Registry
  • Klikněte na Hledej problémy, po dokončení klikněte na Opravit problémy, zálohu dělat nemusíte, potom dejte Opravit všechny problémy.
    Obrázek OK Obrázek Zavřít

Obrázek V logu nevidím firewall, doinstalujte :!: Přehled: http://www.viry.cz/forum/viewtopic.php?f=41&t=6523
Obrázek

Odpovědět