Prosím o kontrolu - swvchost.exe zamrzne na 100% Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

guest
Pohlaví: Nespecifikováno

Re: Prosím o kontrolu - swvchost.exe zamrzne na 100%

Příspěvekod guest » 15 říj 2013 11:25

Logy z OTL jsou výše. ;)

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43287
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu - swvchost.exe zamrzne na 100%

Příspěvekod jaro3 » 15 říj 2013 11:44

Odinstaluj:
Java(TM) 6 Update 6
Java(TM) 6 Update 24


Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.

Pod Vlastní skenování/opravy do okénka vlož následující text, zobrazený zeleně:

Kód: Vybrat vše

:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
DRV - (WDICA) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (Changer) -- File not found
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=AVB3DF&pc=AVBR
IE - HKCU\..\SearchScopes\{0AB75341-8626-4485-A916-75F5E4655D8A}: "URL" = http://www.myvideo.de.anonymize-me.de/? ... 2E6465&st={searchTerms}&clid=ef811632-7584-48b5-89e1-b12ae532863c&pid=murb&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{0C678DD5-ACAC-4440-A27E-D9B21416A137}: "URL" = http://www.pricerunner.de.anonymize-me. ... 2E6465&st={searchTerms}&clid=ef811632-7584-48b5-89e1-b12ae532863c&pid=murb&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{1B928870-0F35-48FA-A386-261EA4DBA6D7}: "URL" = http://www.amazon.de.anonymize-me.de/?t ... 2E6465&st={searchTerms}&clid=ef811632-7584-48b5-89e1-b12ae532863c&pid=murb&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{66A0B071-7162-430C-9948-CC9E31132E8C}: "URL" = http://de.wikipedia.org.anonymize-me.de ... 6F7267&st={searchTerms}&clid=ef811632-7584-48b5-89e1-b12ae532863c&pid=murb&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{8460A6EB-2246-488E-9BAF-59E6B0A9A728}: "URL" = http://search.ebay.de.anonymize-me.de/? ... 2E6465&st={searchTerms}&clid=ef811632-7584-48b5-89e1-b12ae532863c&pid=murb&mode=bounce&k=0
IE - HKCU\..\SearchScopes\{B7B664DF-3AF9-4C8E-8148-F42BB7831D27}: "URL" = http://www.ask.com/web?o=15710&l=dis&q={searchTerms}
IE - HKCU\..\SearchScopes\{F64B78B6-B8A9-4515-B3C6-745A129E50E8}: "URL" = http://www.otto.de.anonymize-me.de/?to= ... 2E6465&st={searchTerms}&clid=ef811632-7584-48b5-89e1-b12ae532863c&pid=murb&mode=bounce&k=0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: pagehacker-nico@nc:1.2
FF - prefs.js..extensions.enabledItems: {e0204bd5-9d31-402b-a99d-a6aa8ffebdca}:1.2.5
FF - prefs.js..extensions.enabledItems: cs@dictionaries.addons.mozilla.org:1.0.2
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.12
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll File not found
[2011.08.18 15:43:18 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Extensions
[2011.08.18 15:43:18 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2013.04.30 11:44:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions
[2013.04.30 11:44:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2013.02.22 16:33:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011.08.18 15:43:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011.08.18 15:43:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011.08.18 15:43:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\I4FTLO3Y.DEFAULT\EXTENSIONS\{E0204BD5-9D31-402B-A99D-A6AA8FFEBDCA}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\I4FTLO3Y.DEFAULT\EXTENSIONS\CS@DICTIONARIES.ADDONS.MOZILLA.ORG
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\DATA APLIKACĂ­\MOZILLA\FIREFOX\PROFILES\I4FTLO3Y.DEFAULT\EXTENSIONS\PAGEHACKER-NICO@NC
O2 - BHO: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
O4 - HKLM..\Run: [ISW] File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Reg Error: Key error.)

:Files
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\System32\dllcache\*.tmp
C:\WINDOWS\system32\SET*.tmp
C:\WINDOWS\system32\DUMP*.tmp
c:\windows\Tasks\*.job /s
C:\*.tmp
C:\WINDOWS\System32\drivers\*.tmp
C:\Documents and Settings\All Users\Data aplikací\*.tmp
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\*.tmp
C:\RECYCLER(2)
C:\WINDOWS\System32\d3d9caps.dat

:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" =-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" =-

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.

========== Last 20 Event Log Errors ==========
Nějak moc chyb…
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

guest
Pohlaví: Nespecifikováno

Re: Prosím o kontrolu - swvchost.exe zamrzne na 100%

Příspěvekod guest » 15 říj 2013 12:11

Javy odinstalovány.

Ano chyb je moc, je to pěkně dodrbaný, ale vůbec nevím jak k tomu došlo. :-(

OTL po opravě:
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
No active process named firefox.exe was found!
Service WDICA stopped successfully!
Service WDICA deleted successfully!
File File not found not found.
Service PDRFRAME stopped successfully!
Service PDRFRAME deleted successfully!
File File not found not found.
Service PDRELI stopped successfully!
Service PDRELI deleted successfully!
File File not found not found.
Service PDFRAME stopped successfully!
Service PDFRAME deleted successfully!
File File not found not found.
Service PDCOMP stopped successfully!
Service PDCOMP deleted successfully!
File File not found not found.
Service PCIDump stopped successfully!
Service PCIDump deleted successfully!
File File not found not found.
Service lbrtfdc stopped successfully!
Service lbrtfdc deleted successfully!
File File not found not found.
Service i2omgmt stopped successfully!
Service i2omgmt deleted successfully!
File File not found not found.
Service Changer stopped successfully!
Service Changer deleted successfully!
File File not found not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0AB75341-8626-4485-A916-75F5E4655D8A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0AB75341-8626-4485-A916-75F5E4655D8A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0C678DD5-ACAC-4440-A27E-D9B21416A137}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0C678DD5-ACAC-4440-A27E-D9B21416A137}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1B928870-0F35-48FA-A386-261EA4DBA6D7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B928870-0F35-48FA-A386-261EA4DBA6D7}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{66A0B071-7162-430C-9948-CC9E31132E8C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66A0B071-7162-430C-9948-CC9E31132E8C}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8460A6EB-2246-488E-9BAF-59E6B0A9A728}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8460A6EB-2246-488E-9BAF-59E6B0A9A728}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7B664DF-3AF9-4C8E-8148-F42BB7831D27}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7B664DF-3AF9-4C8E-8148-F42BB7831D27}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F64B78B6-B8A9-4515-B3C6-745A129E50E8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F64B78B6-B8A9-4515-B3C6-745A129E50E8}\ not found.
Prefs.js: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 removed from extensions.enabledItems
Prefs.js: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 removed from extensions.enabledItems
Prefs.js: pagehacker-nico@nc:1.2 removed from extensions.enabledItems
Prefs.js: {e0204bd5-9d31-402b-a99d-a6aa8ffebdca}:1.2.5 removed from extensions.enabledItems
Prefs.js: cs@dictionaries.addons.mozilla.org:1.0.2 removed from extensions.enabledItems
Prefs.js: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.12 removed from extensions.enabledItems
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ deleted successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Extensions folder moved successfully.
Folder C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\ not found.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\defaults\preferences folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\defaults folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\components folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\skin folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\zh-TW folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\zh-HK folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\zh-CN folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\vi folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\uk folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\tr folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\th folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\sw folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\sv folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\sq folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\sl folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\ru folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\ro folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\pt-BR folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\pt folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\pl folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\pa folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\nl folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\nb folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\mt folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\ku folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\ko folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\km folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\ka folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\ja folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\it folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\is folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\id folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\hu folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\hr folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\hi folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\he folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\gu folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\gl folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\fur folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\fr folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\fi folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\fa folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\eu folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\es folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\en folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\el folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\de folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\da folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\cs folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\ca folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\bo folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\bms folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\bg folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\ar folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale\af folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\locale folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome\content folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}\chrome folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca} folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\staged-xpis\{20a82645-c095-46ed-80e3-08825760534b} folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\staged-xpis folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\defaults\preferences folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\defaults folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\skin folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\zh-TW folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\zh-CN folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\tr-TR folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\sk-SK folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\ru-RU folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\pt-PT folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\pt-BR folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\pl-PL folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\nl-NL folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\lt-LT folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\ja-JP folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\it-IT folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\hu-HU folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\he-IL folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\fr-FR folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\es-ES folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\en-US folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\en-GB folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\de-DE folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\cs-CZ folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\ca-AD folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale\ar folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\locale folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome\content folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc\chrome folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\pagehacker-nico@nc folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\cs@dictionaries.addons.mozilla.org\dictionaries folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\cs@dictionaries.addons.mozilla.org folder moved successfully.
C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions folder moved successfully.
Folder C:\Documents and Settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\i4ftlo3y.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\ not found.
C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions folder moved successfully.
Folder C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\ not found.
Folder C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\ not found.
Folder C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ISW deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\ not found.
========== FILES ==========
C:\WINDOWS\System32\PerfStringBackup.TMP moved successfully.
File\Folder C:\WINDOWS\*.tmp not found.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
File\Folder C:\WINDOWS\System32\dllcache\*.tmp not found.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
File\Folder C:\WINDOWS\system32\DUMP*.tmp not found.
c:\windows\Tasks\Adobe Flash Player Updater.job moved successfully.
c:\windows\Tasks\avast! Emergency Update.job moved successfully.
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-1960408961-839522115-500Core.job moved successfully.
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-1960408961-839522115-500UA.job moved successfully.
File\Folder C:\*.tmp not found.
File\Folder C:\WINDOWS\System32\drivers\*.tmp not found.
File\Folder C:\Documents and Settings\All Users\Data aplikací\*.tmp not found.
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\d3d9caps.tmp moved successfully.
C:\RECYCLER(2)\S-1-5-21-1229272821-1960408961-839522115-500(2) folder moved successfully.
C:\RECYCLER(2) folder moved successfully.
C:\WINDOWS\System32\d3d9caps.dat moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirstRunDisabled deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\\DisableMonitoring deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 27024677 bytes
->Temporary Internet Files folder emptied: 10679077 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 49620185 bytes
->Opera cache emptied: 988551 bytes
->Flash cache emptied: 2206 bytes

User: All Users

User: cavy

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Guest

User: HelpAssistant

User: LocalService
->Temp folder emptied: 66472 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 184 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: SUPPORT_388945a0

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1422459 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 34181176 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 305126 bytes

Total Files Cleaned = 119,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 10152013_120049

Files\Folders moved on Reboot...
C:\Documents and Settings\Administrator\Local Settings\Temp\~DF4389.tmp moved successfully.
File\Folder C:\WINDOWS\temp\_avast_\Webshlock.txt not found!
File\Folder C:\WINDOWS\temp\ZLT06654.TMP not found!

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Po restartu zase svchost.exe na 99% a zamrzlo to, tedy nestihlo, stačil jsem ho ukončit.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43287
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu - swvchost.exe zamrzne na 100%

Příspěvekod jaro3 » 15 říj 2013 15:49

ESET OnlineScan

Poznámka:
Je doporučeno mít během skenu vypnutý antivirový a antispywarový program .Zároveň se doporučuje mít zavřeny všechny ostatní okna , programy a nesurfovat po netu. Po skončení skenu si nezapomeň zase ochrany antiviru a antispywaru zapnout.Je doporučeno použít pro kontrolu prohlížeč Internet Explorer , jinak je nutno nainstalovat ESET Smart Installer a po skončení skenu vše zase řádně odinstalovat.


1. Klikni na ESET OnlineScan
2. Klikni na tlačítko Run ESET Online Scanner
3. Jen pro jiné prohlížeče než je Internet Explorer ( Ti , co mají spuštěn IE mohou toto přeskočit)
3.1. Klikni na esetsmartinstaller_enu.exe ke stáhnutí ESET Smart Installeru , ulož si soubor na svojí plochu.
3.2. Poklepej na ploše na ikonu esetsmartinstaller_enu

4. Dej zatržítko do čtverečku YES , I accept the Terms of Use. ( k potvrzení podmínek užití)
5. Klikni na tlačítko Start
6. Akceptuj další bezpečnostní varování ze svého prohlížeče. Nainstaluj si ovl.prvek ActiveX
7. Dej zatržítko do čtverečku Scan archives
8. Ujisti se , že volba "Remove found threats" je nezaškrtnuta
9. Když se objeví display nastavení skenu počítače , klikni na Advanced settings , a dej zatržítko na :
Enable Anti-Stealth technology (pokud není již zatržena)
10. Klikni na tlačítko Start
11. ESET si pak stáhne svojí aktualizaci , nainstaluje jí a poté začne skenovat Tvůj počítač
12. Když bude sken hotov , klikni na šipku List of found threads
13. Klikni na tlačítko Export to text file , a soubor si ulož pod nějakým jménem na svojí plochu
14. Klikni na tlačítko Back
15. Klikni na tlačítko Finish

Celý obsah textového souboru , který sis uložil na plochu sem prosím vlož.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

guest
Pohlaví: Nespecifikováno

Re: Prosím o kontrolu - swvchost.exe zamrzne na 100%

Příspěvekod guest » 15 říj 2013 22:17

jaro3 Tak to mám hotový, ale byl to porod. Prvně jsem to skoro po 4 hodinách kontroly nechtíc vypnul a tak jsem jel znovu. Nic moc to nenašlo a hned jsem to odstranil

Eset on-line
C:\Instalované programy\T-Cleaner.exe probably a variant of Win32/Agent.MSRYMCJ trojan cleaned by deleting - quarantined

[b]MiliNess[/b]
Tak jsem se průběžně pustil do těch služeb. Pracovní stanice a Server byly zastavené. Zastavil jsem Nápověda a odborná pomoc, ale ta se mi po restartu automaticky spustila. Neměl bych ji tedy nejprve nastavit na ruční spouštění a pak teprve zastavit? Protože když se mi po restartu spustí automaticky, tak nepoznám že zrovna v tom je chyba.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43287
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu - swvchost.exe zamrzne na 100%

Příspěvekod jaro3 » 16 říj 2013 09:47

Spusť OTL a klikni na Vyčisti.

Z mé strany je to vše.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

guest
Pohlaví: Nespecifikováno

Re: Prosím o kontrolu - swvchost.exe zamrzne na 100%

Příspěvekod guest » 16 říj 2013 09:54

jaro3 moc děkuji.

Nechám to otevřené a budu pokračovat dle rad MiliNesse.

Tak jsem zkusil zastavit vzdálený přístup. Nejde a ani nejde služba restartovat.
Bez názvu.JPG


Při pokusu o restart služby to hlásí zase chybu.
Bez názvu2.JPG


Ale je zajímavé, že služba byla spuštěna i když je nastaveno ruční spouštění. Po pokusu o ukončení a restart služby a následném restartu PC je služba zastavena a čeká na ruční spuštění.

Uživatelský avatar
MiliNess
člen BSOD týmu
Master Level 9.5
Master Level 9.5
Příspěvky: 9112
Registrován: říjen 09
Bydliště: Cheb
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu - swvchost.exe zamrzne na 100%

Příspěvekod MiliNess » 16 říj 2013 18:57

Tak jsem se průběžně pustil do těch služeb. Pracovní stanice a Server byly zastavené. Zastavil jsem Nápověda a odborná pomoc, ale ta se mi po restartu automaticky spustila. Neměl bych ji tedy nejprve nastavit na ruční spouštění a pak teprve zastavit? Protože když se mi po restartu spustí automaticky, tak nepoznám že zrovna v tom je chyba.

Ve vlastnostech služby na záložce Obecné, musíš Typ spouštění nastavit na Zakázáno. Po restartu se služba už nespustí. Někdy se už nespustí ani počítač :lol:
Ale většina služeb nezbytných pro činnost systému běží v jiných procesech.
-každý má svou pravdu a ta se nemusí vždycky shodovat s tvou vlastní
-naše problémy jsou pouze v naší hlavě
-okolní svět není ani dobrý ani špatný, je mu zcela lhostejné, jestli existuješ
-nejdůležitější v životě je láska. Všechno ostatní jsou zbytečnosti

guest
Pohlaví: Nespecifikováno

Re: Prosím o kontrolu - swvchost.exe zamrzne na 100%

Příspěvekod guest » 16 říj 2013 19:00

Ve vlastnostech služby na záložce Obecné, musíš Typ spouštění nastavit na Zakázáno. Po restartu se služba už nespustí. Někdy se už nespustí ani počítač
:lol:

A co si s tím potom počnu? :roll:

Tam ale zakázáno není!
Přílohy
Bez názvu.JPG

Uživatelský avatar
MiliNess
člen BSOD týmu
Master Level 9.5
Master Level 9.5
Příspěvky: 9112
Registrován: říjen 09
Bydliště: Cheb
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu - swvchost.exe zamrzne na 100%

Příspěvekod MiliNess » 16 říj 2013 19:04

F8 a Poslední známá funkční konfigurace nebo kladivo. A v nejhorším se to dá jednoduše opravit z HBCD, editací registru.
Tím, že jí zakážeš, se po restartu nespustí.
-každý má svou pravdu a ta se nemusí vždycky shodovat s tvou vlastní
-naše problémy jsou pouze v naší hlavě
-okolní svět není ani dobrý ani špatný, je mu zcela lhostejné, jestli existuješ
-nejdůležitější v životě je láska. Všechno ostatní jsou zbytečnosti

guest
Pohlaví: Nespecifikováno

Re: Prosím o kontrolu - swvchost.exe zamrzne na 100%

Příspěvekod guest » 16 říj 2013 19:06

To jsou věci :-( No z HBCD v registru bych to jistě neopravil Nezbývá než se modlit a pokračovat.

Moc děkuji!

Uživatelský avatar
MiliNess
člen BSOD týmu
Master Level 9.5
Master Level 9.5
Příspěvky: 9112
Registrován: říjen 09
Bydliště: Cheb
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu - swvchost.exe zamrzne na 100%

Příspěvekod MiliNess » 16 říj 2013 19:19

Zatím nemáš zač, třeba mi za pár minut budeš nadávat :-)
A trocha modlení neuškodí. Je to forma meditace, dobré proti stresu.
-každý má svou pravdu a ta se nemusí vždycky shodovat s tvou vlastní
-naše problémy jsou pouze v naší hlavě
-okolní svět není ani dobrý ani špatný, je mu zcela lhostejné, jestli existuješ
-nejdůležitější v životě je láska. Všechno ostatní jsou zbytečnosti


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 71 hostů