svchost (netsvcs)

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Odpovědět
Zpráva
Autor
chlebo666
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 20 Kvě 2013 08:41

svchost (netsvcs)

#1 Příspěvek od chlebo666 »

prosim o radu,tento subor mi prehrieva komp az tak ze sa vypina...vdaka...ten vypis z rsit:

Logfile of random's system information tool 1.09 (written by random/random)
Run by chlebo at 2013-05-20 09:24:04
Microsoft Windows 7 Home Premium
System drive C: has 7 GB (12%) free of 55 GB
Total RAM: 1918 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:24:06, on 20. 5. 2013
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\System32\perfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\wuauclt.exe
C:\Users\chlebo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5CR0PTAP\RSIT[1].exe
C:\Program Files\trend micro\chlebo.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe

--
End of file - 2183 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2013-05-20 09:23:05 ----D---- C:\rsit
2013-05-20 09:23:05 ----D---- C:\Program Files\trend micro
2013-05-20 09:14:12 ----D---- C:\Windows\temp
2013-05-20 09:14:11 ----A---- C:\ComboFix.txt
2013-05-20 09:13:27 ----SHD---- C:\$RECYCLE.BIN
2013-05-20 09:06:39 ----A---- C:\Windows\zip.exe
2013-05-20 09:06:39 ----A---- C:\Windows\SWSC.exe
2013-05-20 09:06:39 ----A---- C:\Windows\SWREG.exe
2013-05-20 09:06:39 ----A---- C:\Windows\sed.exe
2013-05-20 09:06:39 ----A---- C:\Windows\PEV.exe
2013-05-20 09:06:39 ----A---- C:\Windows\NIRCMD.exe
2013-05-20 09:06:39 ----A---- C:\Windows\MBR.exe
2013-05-20 09:06:39 ----A---- C:\Windows\grep.exe
2013-05-20 09:06:15 ----D---- C:\Windows\erdnt
2013-05-20 08:58:14 ----SHD---- C:\Windows\Installer
2013-05-20 08:45:26 ----D---- C:\Program Files\Microsoft Office
2013-05-20 08:40:58 ----A---- C:\Windows\ntbtlog.txt
2013-05-20 00:59:28 ----D---- C:\Windows\Panther
2013-05-20 00:48:57 ----D---- C:\Windows.old
2013-05-20 00:37:56 ----D---- C:\ad14f42cc7a9c7527327e1d90c99
2013-05-20 00:37:19 ----D---- C:\ProgramData\Spybot - Search & Destroy
2013-05-20 00:37:19 ----D---- C:\Program Files\Spybot - Search & Destroy
2013-05-20 00:32:51 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-05-20 00:30:34 ----A---- C:\Windows\system32\wups2.dll
2013-05-20 00:30:34 ----A---- C:\Windows\system32\wucltux.dll
2013-05-20 00:30:34 ----A---- C:\Windows\system32\wuaueng.dll
2013-05-20 00:30:34 ----A---- C:\Windows\system32\wuauclt.exe
2013-05-20 00:29:47 ----D---- C:\Users\chlebo\AppData\Roaming\Identities
2013-05-20 00:29:38 ----A---- C:\Windows\system32\wuwebv.dll
2013-05-20 00:29:38 ----A---- C:\Windows\system32\wuapp.exe
2013-05-20 00:29:10 ----SD---- C:\Users\chlebo\AppData\Roaming\Microsoft
2013-05-20 00:29:10 ----D---- C:\Users\chlebo\AppData\Roaming\Media Center Programs
2013-05-20 00:04:25 ----D---- C:\Windows\SoftwareDistribution
2013-05-20 00:00:46 ----D---- C:\Windows\Prefetch
2013-05-20 00:00:38 ----ASH---- C:\hiberfil.sys
2013-05-19 14:02:33 ----D---- C:\Qoobox
2013-05-18 13:19:22 ----D---- C:\Config.Msi

======List of files/folders modified in the last 1 month======

2013-05-20 09:23:42 ----D---- C:\Windows\system32\catroot2
2013-05-20 09:23:42 ----D---- C:\Windows\system32\catroot
2013-05-20 09:23:37 ----D---- C:\Windows\system32\config
2013-05-20 09:23:05 ----RD---- C:\Program Files
2013-05-20 09:19:03 ----D---- C:\Windows\system32\LogFiles
2013-05-20 09:17:52 ----D---- C:\Windows
2013-05-20 09:15:12 ----SHD---- C:\System Volume Information
2013-05-20 09:12:46 ----A---- C:\Windows\system.ini
2013-05-20 09:10:35 ----D---- C:\Windows\system32\drivers
2013-05-20 09:10:35 ----D---- C:\Windows\System32
2013-05-20 09:10:35 ----D---- C:\Windows\AppPatch
2013-05-20 09:10:33 ----D---- C:\Program Files\Common Files
2013-05-20 09:10:25 ----D---- C:\Windows\inf
2013-05-20 08:58:59 ----D---- C:\Windows\system32\wdi
2013-05-20 00:38:19 ----D---- C:\Windows\Logs
2013-05-20 00:37:57 ----SD---- C:\ProgramData\Microsoft
2013-05-20 00:37:19 ----D---- C:\ProgramData
2013-05-20 00:32:27 ----D---- C:\Windows\system32\wbem
2013-05-20 00:31:53 ----D---- C:\Windows\winsxs
2013-05-20 00:31:47 ----D---- C:\Windows\system32\sk-SK
2013-05-20 00:29:08 ----D---- C:\Windows\system32\restore
2013-05-20 00:29:07 ----RD---- C:\Users
2013-05-20 00:28:49 ----D---- C:\Windows\system32\Recovery
2013-05-20 00:28:49 ----D---- C:\Recovery
2013-05-20 00:27:45 ----D---- C:\Windows\rescache
2013-05-20 00:27:20 ----D---- C:\Windows\debug
2013-05-20 00:10:26 ----D---- C:\Windows\system32\CodeIntegrity
2013-05-20 00:07:08 ----D---- C:\Windows\Microsoft.NET
2013-05-20 00:06:56 ----RSD---- C:\Windows\assembly
2013-05-20 00:05:38 ----D---- C:\Windows\system32\sysprep
2013-05-20 00:04:14 ----D---- C:\Windows\system32\drivers\UMDF

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-07-14 1096704]
R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2009-07-14 43008]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 78336]
S3 catchme;catchme; \??\C:\Users\chlebo\AppData\Local\Temp\catchme.sys []
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 SBSDWSCService;SBSD Security Center Service; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]

-----------------EOF-----------------

chlebo666
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 20 Kvě 2013 08:41

Re: svchost (netsvcs)

#2 Příspěvek od chlebo666 »

niekde som sa o nom docital ze to niekomu pomohlo ... mam len tento log z neho:

ComboFix 13-05-18.04 - chlebo . 05. 2013 9:07.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.1918.1405 [GMT 2:00]
Running from: c:\users\chlebo\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2013-04-20 to 2013-05-20 )))))))))))))))))))))))))))))))
.
.
2013-05-20 07:12 . 2013-05-20 07:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-05-20 06:58 . 2013-05-20 06:58 -------- d-sh--w- c:\windows\Installer
2013-05-19 22:59 . 2013-05-19 22:28 -------- d-----w- c:\windows\Panther
2013-05-19 22:48 . 2013-05-19 22:48 -------- d-----w- C:\Windows.old
2013-05-19 22:37 . 2013-05-19 22:37 -------- d-----w- C:\ad14f42cc7a9c7527327e1d90c99
2013-05-19 22:37 . 2013-05-20 06:52 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2013-05-19 22:37 . 2013-05-19 22:37 -------- d-----w- c:\program files\Spybot - Search & Destroy
2013-05-19 22:32 . 2013-05-20 07:10 -------- d-----w- c:\windows\system32\wbem\Performance
2013-05-19 22:30 . 2012-06-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe
2013-05-19 22:30 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll
2013-05-19 22:30 . 2012-06-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2013-05-19 22:30 . 2012-06-02 22:12 2422272 ----a-w- c:\windows\system32\wucltux.dll
2013-05-19 22:29 . 2012-06-02 13:19 171904 ----a-w- c:\windows\system32\wuwebv.dll
2013-05-19 22:29 . 2012-06-02 13:12 33792 ----a-w- c:\windows\system32\wuapp.exe
2013-05-19 22:29 . 2013-05-19 22:30 -------- d-----w- c:\users\chlebo
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-20 06:58 . 2013-05-20 06:58 119808 ----a-r- c:\users\chlebo\AppData\Roaming\Microsoft\Installer\{CCF298AF-9CE1-4B26-B251-486E98A34789}\icons.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [x]
.
.
.
------- Supplementary Scan -------
.
TCP: DhcpNameServer = 192.168.2.1 195.146.132.58 195.146.128.62 192.168.2.1
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-05-20 09:14:10
ComboFix-quarantined-files.txt 2013-05-20 07:14
.
Pre-Run: 7 052 730 368 bytes free
Post-Run: 6 979 776 512 bytes free
.
- - End Of File - - CB7E90F435AF3B4F31530C81F044EF8C

Odpovědět