rundll32.exe vytazuje CPU
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Re: rundll32.exe vytazuje CPU
tak ne....nieco to zo zaciatku robilo... a potom to zase zamrzlo...
u tohoto
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
to aj posledne....
u tohoto
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
to aj posledne....
- stell
- VIP in memoriam

- Příspěvky: 5175
- Registrován: 09 Pro 2007 09:27
- Místo/Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: rundll32.exe vytazuje CPU
dobre,vynechaj otl-a pokracuj dalej,
Re: rundll32.exe vytazuje CPU
log z mbr
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86B401D0]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x86b401d0
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
log z avenger
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
File move operation "C:\atapi.sys|C:\Windows\System32\drivers\atapi.sys" completed successfully.
Completed script processing.
*******************
Finished! Terminate.
a ani special version Gmer neslape...zacal skenovat a potom prestal pracovat
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86B401D0]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x86b401d0
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
log z avenger
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
File move operation "C:\atapi.sys|C:\Windows\System32\drivers\atapi.sys" completed successfully.
Completed script processing.
*******************
Finished! Terminate.
a ani special version Gmer neslape...zacal skenovat a potom prestal pracovat
- stell
- VIP in memoriam

- Příspěvky: 5175
- Registrován: 09 Pro 2007 09:27
- Místo/Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: rundll32.exe vytazuje CPU
2:Zatvorte všetky spustené programy a okná.
dvoj-kliknite na súbor spustite a postupujte podľa
pokynov na obrazovke
Ak nastroj zistí MBR infekcie, prosím,nechajte
bezat- povolte MBR -f
Vypnut pocitac a prosím počkajte asi 5 minút,
Zapnut pocitac-
Kliknite na Štart> Spustiť a zadajte nasledujúci
príkaz
helpasst -mbrt [Enter]
Pri skonceni,otvori sa log.
Prosím postnite obsah tu.
Re: rundll32.exe vytazuje CPU
co znamena bezat- povolte MBR -f ?
- stell
- VIP in memoriam

- Příspěvky: 5175
- Registrován: 09 Pro 2007 09:27
- Místo/Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: rundll32.exe vytazuje CPU
spust program a uvidis-nechaj bezat program ak zisti infekciu
Re: rundll32.exe vytazuje CPU
to sa stalo...dvakrat chcel zmackut lubovolne tlacitko a tym to skoncilo...
tak to ma byt?
tak to ma byt?
- stell
- VIP in memoriam

- Příspěvky: 5175
- Registrován: 09 Pro 2007 09:27
- Místo/Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: rundll32.exe vytazuje CPU
ok,
klik start klik spustit a vloz prikaz
helpasst -mbrt [enter]
klik start klik spustit a vloz prikaz
helpasst -mbrt [enter]
Re: rundll32.exe vytazuje CPU
C:\Documents and Settings\Miroslava - Slamená\Plocha\HelpAsst_mebroot_fix.exe
čt 15.07.2010 at 17:22:21,60
Could not determine language ~ no action taken on account ~ please consult noahdfear
00000405
U§ivatelsk‚ jm‚no HelpAssistant
Jm‚no a pýˇjmenˇ éźet pomoci vzd len‚ plochy
Koment ý éźet pro poskytov nˇ vzd len‚ pomoci.
Koment ý u§ivatele
SmŘrov‚ źˇslo zemŘ 000 (Věchozˇ syst‚mov‚ nastavenˇ)
éźet je aktivnˇ Ne
éźet vyprçel Nikdy
Heslo bylo naposledy nastaveno 12/21/2006 8:57 AM
Heslo vyprçˇ Nikdy
Heslo lze mŘnit 12/21/2006 8:57 AM
Heslo je vy§adov no Ano
U§ivatel smˇ mŘnit heslo Ne
Pracovnˇ stanice byla povolena Vçe
Pýihlaçovacˇ skript
Profil u§ivatele
Domovskě adres ý
Naposledy pýihl çen Nikdy
Povolen‚ pýihlaçovacˇ hodiny Vçe
¬lenstvˇ v mˇstnˇch skupin ch
¬lenstvˇ v glob lnˇch skupin ch *None
Pýˇkaz byl ŁspŘçnŘ dokonźen.
~~ Checking for termsrv32.dll ~~
termsrv32.dll not found
~~ Checking firewall ports ~~
HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\globallyopenports\list
HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\globallyopenports\list
~~ Checking profile list ~~
No HelpAssistant profile in registry
~~ Checking mbr ~~
user & kernel MBR OK
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Status check on čt 15.07.2010 at 17:22:49,93
éźet je aktivnˇ Ne
~~ Checking mbr ~~
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86B2DCC0]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x86b2dcc0
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
~~ Checking for termsrv32.dll ~~
termsrv32.dll not found
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %SystemRoot%\System32\termsrv.dll
~~ Checking profile list ~~
No HelpAssistant profile in registry
~~ Checking for HelpAssistant directories ~~
none found
~~ Checking firewall ports ~~
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\GloballyOpenPorts\List]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
~~ EOF ~~
čt 15.07.2010 at 17:22:21,60
Could not determine language ~ no action taken on account ~ please consult noahdfear
00000405
U§ivatelsk‚ jm‚no HelpAssistant
Jm‚no a pýˇjmenˇ éźet pomoci vzd len‚ plochy
Koment ý éźet pro poskytov nˇ vzd len‚ pomoci.
Koment ý u§ivatele
SmŘrov‚ źˇslo zemŘ 000 (Věchozˇ syst‚mov‚ nastavenˇ)
éźet je aktivnˇ Ne
éźet vyprçel Nikdy
Heslo bylo naposledy nastaveno 12/21/2006 8:57 AM
Heslo vyprçˇ Nikdy
Heslo lze mŘnit 12/21/2006 8:57 AM
Heslo je vy§adov no Ano
U§ivatel smˇ mŘnit heslo Ne
Pracovnˇ stanice byla povolena Vçe
Pýihlaçovacˇ skript
Profil u§ivatele
Domovskě adres ý
Naposledy pýihl çen Nikdy
Povolen‚ pýihlaçovacˇ hodiny Vçe
¬lenstvˇ v mˇstnˇch skupin ch
¬lenstvˇ v glob lnˇch skupin ch *None
Pýˇkaz byl ŁspŘçnŘ dokonźen.
~~ Checking for termsrv32.dll ~~
termsrv32.dll not found
~~ Checking firewall ports ~~
HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\globallyopenports\list
HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\globallyopenports\list
~~ Checking profile list ~~
No HelpAssistant profile in registry
~~ Checking mbr ~~
user & kernel MBR OK
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Status check on čt 15.07.2010 at 17:22:49,93
éźet je aktivnˇ Ne
~~ Checking mbr ~~
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86B2DCC0]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x86b2dcc0
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
~~ Checking for termsrv32.dll ~~
termsrv32.dll not found
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %SystemRoot%\System32\termsrv.dll
~~ Checking profile list ~~
No HelpAssistant profile in registry
~~ Checking for HelpAssistant directories ~~
none found
~~ Checking firewall ports ~~
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\GloballyOpenPorts\List]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
~~ EOF ~~
- stell
- VIP in memoriam

- Příspěvky: 5175
- Registrován: 09 Pro 2007 09:27
- Místo/Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: rundll32.exe vytazuje CPU
MBR -f
teraz tento prikaz-
potom restartni pocitac a znova daj tento prikaz
helpasst -mbrt
log postni sem.
teraz tento prikaz-
potom restartni pocitac a znova daj tento prikaz
helpasst -mbrt
log postni sem.
Re: rundll32.exe vytazuje CPU
C:\Documents and Settings\Miroslava - Slamená\Plocha\HelpAsst_mebroot_fix.exe
čt 15.07.2010 at 17:22:21,60
Could not determine language ~ no action taken on account ~ please consult noahdfear
00000405
U§ivatelsk‚ jm‚no HelpAssistant
Jm‚no a pýˇjmenˇ éźet pomoci vzd len‚ plochy
Koment ý éźet pro poskytov nˇ vzd len‚ pomoci.
Koment ý u§ivatele
SmŘrov‚ źˇslo zemŘ 000 (Věchozˇ syst‚mov‚ nastavenˇ)
éźet je aktivnˇ Ne
éźet vyprçel Nikdy
Heslo bylo naposledy nastaveno 12/21/2006 8:57 AM
Heslo vyprçˇ Nikdy
Heslo lze mŘnit 12/21/2006 8:57 AM
Heslo je vy§adov no Ano
U§ivatel smˇ mŘnit heslo Ne
Pracovnˇ stanice byla povolena Vçe
Pýihlaçovacˇ skript
Profil u§ivatele
Domovskě adres ý
Naposledy pýihl çen Nikdy
Povolen‚ pýihlaçovacˇ hodiny Vçe
¬lenstvˇ v mˇstnˇch skupin ch
¬lenstvˇ v glob lnˇch skupin ch *None
Pýˇkaz byl ŁspŘçnŘ dokonźen.
~~ Checking for termsrv32.dll ~~
termsrv32.dll not found
~~ Checking firewall ports ~~
HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\globallyopenports\list
HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\globallyopenports\list
~~ Checking profile list ~~
No HelpAssistant profile in registry
~~ Checking mbr ~~
user & kernel MBR OK
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Status check on čt 15.07.2010 at 17:22:49,93
éźet je aktivnˇ Ne
~~ Checking mbr ~~
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86B2DCC0]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x86b2dcc0
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
~~ Checking for termsrv32.dll ~~
termsrv32.dll not found
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %SystemRoot%\System32\termsrv.dll
~~ Checking profile list ~~
No HelpAssistant profile in registry
~~ Checking for HelpAssistant directories ~~
none found
~~ Checking firewall ports ~~
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\GloballyOpenPorts\List]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
~~ EOF ~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Status check on źt 15.07.2010 at 17:35:43,95
éźet je aktivnˇ Ne
~~ Checking mbr ~~
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86B5EC40]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x86b5ec40
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
~~ Checking for termsrv32.dll ~~
termsrv32.dll not found
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %SystemRoot%\System32\termsrv.dll
~~ Checking profile list ~~
No HelpAssistant profile in registry
~~ Checking for HelpAssistant directories ~~
none found
~~ Checking firewall ports ~~
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\GloballyOpenPorts\List]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
~~ EOF ~~
čt 15.07.2010 at 17:22:21,60
Could not determine language ~ no action taken on account ~ please consult noahdfear
00000405
U§ivatelsk‚ jm‚no HelpAssistant
Jm‚no a pýˇjmenˇ éźet pomoci vzd len‚ plochy
Koment ý éźet pro poskytov nˇ vzd len‚ pomoci.
Koment ý u§ivatele
SmŘrov‚ źˇslo zemŘ 000 (Věchozˇ syst‚mov‚ nastavenˇ)
éźet je aktivnˇ Ne
éźet vyprçel Nikdy
Heslo bylo naposledy nastaveno 12/21/2006 8:57 AM
Heslo vyprçˇ Nikdy
Heslo lze mŘnit 12/21/2006 8:57 AM
Heslo je vy§adov no Ano
U§ivatel smˇ mŘnit heslo Ne
Pracovnˇ stanice byla povolena Vçe
Pýihlaçovacˇ skript
Profil u§ivatele
Domovskě adres ý
Naposledy pýihl çen Nikdy
Povolen‚ pýihlaçovacˇ hodiny Vçe
¬lenstvˇ v mˇstnˇch skupin ch
¬lenstvˇ v glob lnˇch skupin ch *None
Pýˇkaz byl ŁspŘçnŘ dokonźen.
~~ Checking for termsrv32.dll ~~
termsrv32.dll not found
~~ Checking firewall ports ~~
HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\globallyopenports\list
HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\globallyopenports\list
~~ Checking profile list ~~
No HelpAssistant profile in registry
~~ Checking mbr ~~
user & kernel MBR OK
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Status check on čt 15.07.2010 at 17:22:49,93
éźet je aktivnˇ Ne
~~ Checking mbr ~~
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86B2DCC0]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x86b2dcc0
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
~~ Checking for termsrv32.dll ~~
termsrv32.dll not found
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %SystemRoot%\System32\termsrv.dll
~~ Checking profile list ~~
No HelpAssistant profile in registry
~~ Checking for HelpAssistant directories ~~
none found
~~ Checking firewall ports ~~
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\GloballyOpenPorts\List]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
~~ EOF ~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Status check on źt 15.07.2010 at 17:35:43,95
éźet je aktivnˇ Ne
~~ Checking mbr ~~
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86B5EC40]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x86b5ec40
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
~~ Checking for termsrv32.dll ~~
termsrv32.dll not found
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %SystemRoot%\System32\termsrv.dll
~~ Checking profile list ~~
No HelpAssistant profile in registry
~~ Checking for HelpAssistant directories ~~
none found
~~ Checking firewall ports ~~
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\GloballyOpenPorts\List]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
~~ EOF ~~
- stell
- VIP in memoriam

- Příspěvky: 5175
- Registrován: 09 Pro 2007 09:27
- Místo/Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: rundll32.exe vytazuje CPU
klik-start-klik-spustit-napis prikaz
devmgmt.msc ok
klik-zalozka zobrazit-preboduj,zobrazit skryte zarizeni-v zozname najdi-ovladace nepodporujuce plug/and play technologiu.-klik na znamienko +,a sprav screenshot,,tak aby som videl vsetky ovladace.
devmgmt.msc ok
klik-zalozka zobrazit-preboduj,zobrazit skryte zarizeni-v zozname najdi-ovladace nepodporujuce plug/and play technologiu.-klik na znamienko +,a sprav screenshot,,tak aby som videl vsetky ovladace.
Re: rundll32.exe vytazuje CPU
je to v prilohe na dvakrat
- Přílohy
-
- 2.gif (2.6 KiB) Zobrazeno 1443 x
-
- 1.gif
- (10.17 KiB) Staženo 14 x
- stell
- VIP in memoriam

- Příspěvky: 5175
- Registrován: 09 Pro 2007 09:27
- Místo/Bydliště: SK-REVUCA
- Kontaktovat uživatele:
Re: rundll32.exe vytazuje CPU
pravy klik na serial-vlastnosti-ovladac-podrobnosti-screenshot.


Přispějete na provoz fóra?