https://www.virustotal.com/file/e3b0c44 ... 333896812/
--- Doplnění předchozího příspěvku (08 Dub 2012 16:55) ---
https://www.virustotal.com/file/e3b0c44 ... 333896889/
Svchost.exe velkej problem (500-xxx) processu Vyřešeno
-
- Level 2
- Příspěvky: 169
- Registrován: duben 12
- Pohlaví:
- Stav:
Offline
- Damned
- Tvůrce článků
-
Master Level 9
- Příspěvky: 8353
- Registrován: prosinec 06
- Bydliště: Rokycany
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: Svchost.exe velkej problem (500-xxx) processu
Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/Opravy do okénka vlož následující text, zobrazený zeleně:
Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.
Pod Vlastní skenování/Opravy do okénka vlož následující text, zobrazený zeleně:
Kód: Vybrat vše
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
SRV - (Update Server) -- C:\Program Files\Common Files\Bitdefender\Bitdefender Arrakis Server\bin\arrakis3.exe File not found
SRV - (SafeBox) -- C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe File not found
DRV - (WDICA) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (Changer) -- File not found
DRV - (avchv) -- C:\WINDOWS\system32\drivers\avchv.sys (BitDefender)
DRV - (bdsandbox) -- C:\WINDOWS\system32\drivers\bdsandbox.sys (BitDefender SRL)
IE - HKCU\..\SearchScopes\94A2AE90-7B04-4CE9-92A8-E74303397600: "URL" = http://searchya.com/?chnl=dcom-100&s=1& ... DtAtDyC&q={searchTerms}
FF - prefs.js..network.proxy.gopher: ""
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll File not found
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll File not found
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html File not found
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
@Alternate Data Stream - 48 bytes -> C:\Documents and Settings\All Users\DRM:احتضان
@Alternate Data Stream - 181 bytes -> C:\Documents and Settings\All Users\Data aplikací\Temp:0B4227B4
:Services
SRV - (Update Server)
SRV - (SafeBox)
DRV - (WDICA)
DRV - (PDRFRAME)
DRV - (PDRELI)
DRV - (PDFRAME)
DRV - (PDCOMP)
DRV - (PCIDump)
DRV - (lbrtfdc)
DRV - (i2omgmt)
DRV - (Changer)
DRV - (avchv)
DRV - (bdsandbox)
:Files
C:\WINDOWS\System32\d3d9caps.dat
C:\WINDOWS\System32\emptyregdb.dat
C:\Documents and Settings\All Users\Data aplikací\Alwil Software
C:\Documents and Settings\All Users\Data aplikací\Babylon
C:\Documents and Settings\All Users\Data aplikací\BDLogging
C:\Documents and Settings\All Users\Data aplikací\{BECCA440-C137-43CD-BA7B-AE580F9F6D17}
C:\Documents and Settings\All Users\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
C:\Documents and Settings\Perda\Data aplikací\Babylon
C:\Documents and Settings\All Users\Data aplikací\ctonhhte.rgb
C:\Documents and Settings\All Users\Data aplikací\qjaxlkio.dss
C:\Documents and Settings\All Users\Data aplikací\1333796597.bdinstall.bin
C:\Documents and Settings\All Users\Data aplikací\1333796539.bdinstall.bin
C:\Documents and Settings\All Users\Data aplikací\1333796579.bdinstall.bin
C:\WINDOWS\CSC
C:\WINDOWS\system32\drivers\avchv.sys
C:\WINDOWS\system32\drivers\bdsandbox.sys
C:\WINDOWS\*.tmp
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\tasks\SA.DAT
C:\WINDOWS\system32\SET*.tmp
C:\Recycler
C:\$RECYCLE.BIN
C:\RECYCLER
C:\Windows\tasks\*.job
:Reg
:Commands
[purity]
[emptytemp]
[emptyflash]
[start explorer]
[Reboot]
Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
-
- Level 2
- Příspěvky: 169
- Registrován: duben 12
- Pohlaví:
- Stav:
Offline
Re: Svchost.exe velkej problem (500-xxx) processu
nejsem si jistej jestli je to normalni ale seklo se to u processing SRV - (update server)...
--- Doplnění předchozího příspěvku (08 Dub 2012 17:26) ---
a neodpovídá
--- Doplnění předchozího příspěvku (08 Dub 2012 17:41) ---
pls pomoc mam vipnout pc nebo co ??
--- Doplnění předchozího příspěvku (08 Dub 2012 17:26) ---
a neodpovídá
--- Doplnění předchozího příspěvku (08 Dub 2012 17:41) ---
pls pomoc mam vipnout pc nebo co ??
- Damned
- Tvůrce článků
-
Master Level 9
- Příspěvky: 8353
- Registrován: prosinec 06
- Bydliště: Rokycany
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: Svchost.exe velkej problem (500-xxx) processu
Nevšiml sis jestli u služby nebo u souboru arrakis3.exe?
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
-
- Level 2
- Příspěvky: 169
- Registrován: duben 12
- Pohlaví:
- Stav:
Offline
Re: Svchost.exe velkej problem (500-xxx) processu
nejde OTL.exe a csrss.exe
--- Doplnění předchozího příspěvku (08 Dub 2012 18:02) ---
vis co uz se o to nestarej muj notebook bezi lip nez predtim fakt dik diky ale myslim ze hlavni problem je uz v poho diky a zase nekdy jindy
--- Doplnění předchozího příspěvku (08 Dub 2012 18:02) ---
vis co uz se o to nestarej muj notebook bezi lip nez predtim fakt dik diky ale myslim ze hlavni problem je uz v poho diky a zase nekdy jindy
- Damned
- Tvůrce článků
-
Master Level 9
- Příspěvky: 8353
- Registrován: prosinec 06
- Bydliště: Rokycany
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: Svchost.exe velkej problem (500-xxx) processu
Pokud neodstraníme zbytky, co sem napsal v OTL, zas se ti bude sekat.
Zkus OTL vypnout a podívej se, jestli ve složce C:\_OTL není texťák
Zkus OTL vypnout a podívej se, jestli ve složce C:\_OTL není texťák
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
- Damned
- Tvůrce článků
-
Master Level 9
- Příspěvky: 8353
- Registrován: prosinec 06
- Bydliště: Rokycany
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: Svchost.exe velkej problem (500-xxx) processu
Upravil jsem ten script pro OTL. Máš tam jinak ještě 2x malware. Takže těch pár minut co ti půjde ntb lépe...
Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/Opravy do okénka vlož následující text, zobrazený zeleně:
Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.
Poklepej na ikonu OTL na ploše.Ujisti se , že máš všechny ostatní aplikace a prohlížeče zavřeny.
Pod Vlastní skenování/Opravy do okénka vlož následující text, zobrazený zeleně:
Kód: Vybrat vše
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
SRV - (Update Server) -- C:\Program Files\Common Files\Bitdefender\Bitdefender Arrakis Server\bin\arrakis3.exe File not found
SRV - (SafeBox) -- C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe File not found
DRV - (WDICA) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (Changer) -- File not found
DRV - (avchv) -- C:\WINDOWS\system32\drivers\avchv.sys (BitDefender)
DRV - (bdsandbox) -- C:\WINDOWS\system32\drivers\bdsandbox.sys (BitDefender SRL)
IE - HKCU\..\SearchScopes\94A2AE90-7B04-4CE9-92A8-E74303397600: "URL" = http://searchya.com/?chnl=dcom-100&s=1& ... DtAtDyC&q={searchTerms}
FF - prefs.js..network.proxy.gopher: ""
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll File not found
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll File not found
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html File not found
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
@Alternate Data Stream - 48 bytes -> C:\Documents and Settings\All Users\DRM:احتضان
@Alternate Data Stream - 181 bytes -> C:\Documents and Settings\All Users\Data aplikací\Temp:0B4227B4
:Services
DRV - (WDICA)
DRV - (PDRFRAME)
DRV - (PDRELI)
DRV - (PDFRAME)
DRV - (PDCOMP)
DRV - (PCIDump)
DRV - (lbrtfdc)
DRV - (i2omgmt)
DRV - (Changer)
DRV - (avchv)
DRV - (bdsandbox)
:Files
c:\windows\polop.exe
C:\WINDOWS\System32\d3d9caps.dat
C:\WINDOWS\System32\emptyregdb.dat
C:\Documents and Settings\All Users\Data aplikací\Alwil Software
C:\Documents and Settings\All Users\Data aplikací\Babylon
C:\Documents and Settings\All Users\Data aplikací\BDLogging
C:\Documents and Settings\All Users\Data aplikací\{BECCA440-C137-43CD-BA7B-AE580F9F6D17}
C:\Documents and Settings\All Users\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
C:\Documents and Settings\Perda\Data aplikací\Babylon
C:\Documents and Settings\All Users\Data aplikací\ctonhhte.rgb
C:\Documents and Settings\All Users\Data aplikací\qjaxlkio.dss
C:\Documents and Settings\All Users\Data aplikací\1333796597.bdinstall.bin
C:\Documents and Settings\All Users\Data aplikací\1333796539.bdinstall.bin
C:\Documents and Settings\All Users\Data aplikací\1333796579.bdinstall.bin
C:\WINDOWS\CSC
C:\WINDOWS\system32\drivers\avchv.sys
C:\WINDOWS\system32\drivers\bdsandbox.sys
C:\WINDOWS\*.tmp
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\system32\*.tmp.dll
C:\WINDOWS\tasks\SA.DAT
C:\WINDOWS\system32\SET*.tmp
C:\Recycler
C:\$RECYCLE.BIN
C:\RECYCLER
C:\Windows\tasks\*.job
:Reg
:Commands
[purity]
[emptytemp]
[emptyflash]
[start explorer]
[Reboot]
Poté klikni nahoře na Opravit. Nech program nerušeně běžet, na konci se provede restart PC.
Po restartu se objeví log , prosím zkopíruj sem celý jeho obsah.
Nic není nemožné, proto tam, kde jsme s rozumem v koncích, neváháme použít kladivo.
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
Chceš-li vědět, co je nového, podívej se do starých knih.
Damnedovy češtiny - překlady programů pro údržbu PC
HiJackThis 2+návod FCleaner+čeština Wise Registry Cleaner
-
- Level 2
- Příspěvky: 169
- Registrován: duben 12
- Pohlaví:
- Stav:
Offline
Re: Svchost.exe velkej problem (500-xxx) processu
zase se sekl OTL.exe a csrss.exe
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43287
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Svchost.exe velkej problem (500-xxx) processu
Zkus to v nouz . režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
-
- Level 2
- Příspěvky: 169
- Registrován: duben 12
- Pohlaví:
- Stav:
Offline
Re: Svchost.exe velkej problem (500-xxx) processu
uz znam problem byli pred tím mezery
tady je log:
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
Error: No service named Update Server was found to stop!
Service\Driver key Update Server not found.
File C:\Program Files\Common Files\Bitdefender\Bitdefender Arrakis Server\bin\arrakis3.exe File not found not found.
Error: No service named SafeBox was found to stop!
Service\Driver key SafeBox not found.
File C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe File not found not found.
Error: No service named WDICA was found to stop!
Service\Driver key WDICA not found.
File File not found not found.
Error: No service named PDRFRAME was found to stop!
Service\Driver key PDRFRAME not found.
File File not found not found.
Error: No service named PDRELI was found to stop!
Service\Driver key PDRELI not found.
File File not found not found.
Error: No service named PDFRAME was found to stop!
Service\Driver key PDFRAME not found.
File File not found not found.
Error: No service named PDCOMP was found to stop!
Service\Driver key PDCOMP not found.
File File not found not found.
Error: No service named PCIDump was found to stop!
Service\Driver key PCIDump not found.
File File not found not found.
Error: No service named lbrtfdc was found to stop!
Service\Driver key lbrtfdc not found.
File File not found not found.
Error: No service named i2omgmt was found to stop!
Service\Driver key i2omgmt not found.
File File not found not found.
Error: No service named Changer was found to stop!
Service\Driver key Changer not found.
File File not found not found.
Error: No service named avchv was found to stop!
Service\Driver key avchv not found.
File C:\WINDOWS\system32\drivers\avchv.sys not found.
Error: No service named bdsandbox was found to stop!
Service\Driver key bdsandbox not found.
File C:\WINDOWS\system32\drivers\bdsandbox.sys not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{searchTerms}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{searchTerms}\ not found.
Prefs.js: "" removed from network.proxy.gopher
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{98889811-442D-49dd-99D7-DC866BE87DBC} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}\ not found.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download with &Media Finder\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
File C:\Program Files\Messenger\msmsgs.exe not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
File C:\Program Files\Messenger\msmsgs.exe not found.
Unable to delete ADS C:\Documents and Settings\All Users\DRM:?????? .
Unable to delete ADS C:\Documents and Settings\All Users\Data aplikací\Temp:0B4227B4 .
========== SERVICES/DRIVERS ==========
Error: No service named DRV - (WDICA) was found to stop!
Service\Driver key DRV - (WDICA) not found.
Error: No service named DRV - (PDRFRAME) was found to stop!
Service\Driver key DRV - (PDRFRAME) not found.
Error: No service named DRV - (PDRELI) was found to stop!
Service\Driver key DRV - (PDRELI) not found.
Error: No service named DRV - (PDFRAME) was found to stop!
Service\Driver key DRV - (PDFRAME) not found.
Error: No service named DRV - (PDCOMP) was found to stop!
Service\Driver key DRV - (PDCOMP) not found.
Error: No service named DRV - (PCIDump) was found to stop!
Service\Driver key DRV - (PCIDump) not found.
Error: No service named DRV - (lbrtfdc) was found to stop!
Service\Driver key DRV - (lbrtfdc) not found.
Error: No service named DRV - (i2omgmt) was found to stop!
Service\Driver key DRV - (i2omgmt) not found.
Error: No service named DRV - (Changer) was found to stop!
Service\Driver key DRV - (Changer) not found.
Error: No service named DRV - (avchv) was found to stop!
Service\Driver key DRV - (avchv) not found.
Error: No service named DRV - (bdsandbox) was found to stop!
Service\Driver key DRV - (bdsandbox) not found.
========== FILES ==========
c:\windows\polop.exe moved successfully.
C:\WINDOWS\System32\d3d9caps.dat moved successfully.
C:\WINDOWS\System32\emptyregdb.dat moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\spool\suspic folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\spool folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\sounds folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\report folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\moved folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\log folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\journal folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\integ folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\HtmlData folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\fw folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\chest folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\backup folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\arpot\TEMP folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\arpot folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5 folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Babylon folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\BDLogging\updatesrv folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\BDLogging folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\{BECCA440-C137-43CD-BA7B-AE580F9F6D17} folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86\x86 folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86 folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521} folder moved successfully.
C:\Documents and Settings\Perda\Data aplikací\Babylon folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\ctonhhte.rgb moved successfully.
C:\Documents and Settings\All Users\Data aplikací\qjaxlkio.dss moved successfully.
C:\Documents and Settings\All Users\Data aplikací\1333796597.bdinstall.bin moved successfully.
C:\Documents and Settings\All Users\Data aplikací\1333796539.bdinstall.bin moved successfully.
C:\Documents and Settings\All Users\Data aplikací\1333796579.bdinstall.bin moved successfully.
C:\WINDOWS\CSC\d8 folder moved successfully.
C:\WINDOWS\CSC\d7 folder moved successfully.
C:\WINDOWS\CSC\d6 folder moved successfully.
C:\WINDOWS\CSC\d5 folder moved successfully.
C:\WINDOWS\CSC\d4 folder moved successfully.
C:\WINDOWS\CSC\d3 folder moved successfully.
C:\WINDOWS\CSC\d2 folder moved successfully.
C:\WINDOWS\CSC\d1 folder moved successfully.
C:\WINDOWS\CSC folder moved successfully.
File\Folder C:\WINDOWS\system32\drivers\avchv.sys not found.
File\Folder C:\WINDOWS\system32\drivers\bdsandbox.sys not found.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\System32\CONFIG.TMP moved successfully.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
C:\WINDOWS\tasks\SA.DAT moved successfully.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\RECYCLER\S-1-5-21-1390067357-562591055-725345543-1003\Dc5\ywgzombies2 folder moved successfully.
C:\RECYCLER\S-1-5-21-1390067357-562591055-725345543-1003\Dc5\openwarfare folder moved successfully.
C:\RECYCLER\S-1-5-21-1390067357-562591055-725345543-1003\Dc5 folder moved successfully.
C:\RECYCLER\S-1-5-21-1390067357-562591055-725345543-1003\Dc16 folder moved successfully.
C:\RECYCLER\S-1-5-21-1390067357-562591055-725345543-1003 folder moved successfully.
C:\RECYCLER folder moved successfully.
File\Folder C:\$RECYCLE.BIN not found.
File\Folder C:\RECYCLER not found.
File\Folder C:\Windows\tasks\*.job not found.
========== REGISTRY ==========
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Perda
->Temp folder emptied: 5508175 bytes
->Temporary Internet Files folder emptied: 2305691 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 288390996 bytes
->Apple Safari cache emptied: 2979840 bytes
->Flash cache emptied: 1239 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 32916 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 285,00 mb
[EMPTYFLASH]
User: Administrator
User: All Users
User: Default User
User: LocalService
User: NetworkService
User: Perda
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0,00 mb
OTL by OldTimer - Version 3.2.39.2 log created on 04112012_142934
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
tady je log:
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
Error: No service named Update Server was found to stop!
Service\Driver key Update Server not found.
File C:\Program Files\Common Files\Bitdefender\Bitdefender Arrakis Server\bin\arrakis3.exe File not found not found.
Error: No service named SafeBox was found to stop!
Service\Driver key SafeBox not found.
File C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe File not found not found.
Error: No service named WDICA was found to stop!
Service\Driver key WDICA not found.
File File not found not found.
Error: No service named PDRFRAME was found to stop!
Service\Driver key PDRFRAME not found.
File File not found not found.
Error: No service named PDRELI was found to stop!
Service\Driver key PDRELI not found.
File File not found not found.
Error: No service named PDFRAME was found to stop!
Service\Driver key PDFRAME not found.
File File not found not found.
Error: No service named PDCOMP was found to stop!
Service\Driver key PDCOMP not found.
File File not found not found.
Error: No service named PCIDump was found to stop!
Service\Driver key PCIDump not found.
File File not found not found.
Error: No service named lbrtfdc was found to stop!
Service\Driver key lbrtfdc not found.
File File not found not found.
Error: No service named i2omgmt was found to stop!
Service\Driver key i2omgmt not found.
File File not found not found.
Error: No service named Changer was found to stop!
Service\Driver key Changer not found.
File File not found not found.
Error: No service named avchv was found to stop!
Service\Driver key avchv not found.
File C:\WINDOWS\system32\drivers\avchv.sys not found.
Error: No service named bdsandbox was found to stop!
Service\Driver key bdsandbox not found.
File C:\WINDOWS\system32\drivers\bdsandbox.sys not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{searchTerms}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{searchTerms}\ not found.
Prefs.js: "" removed from network.proxy.gopher
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{98889811-442D-49dd-99D7-DC866BE87DBC} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}\ not found.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download with &Media Finder\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
File C:\Program Files\Messenger\msmsgs.exe not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
File C:\Program Files\Messenger\msmsgs.exe not found.
Unable to delete ADS C:\Documents and Settings\All Users\DRM:?????? .
Unable to delete ADS C:\Documents and Settings\All Users\Data aplikací\Temp:0B4227B4 .
========== SERVICES/DRIVERS ==========
Error: No service named DRV - (WDICA) was found to stop!
Service\Driver key DRV - (WDICA) not found.
Error: No service named DRV - (PDRFRAME) was found to stop!
Service\Driver key DRV - (PDRFRAME) not found.
Error: No service named DRV - (PDRELI) was found to stop!
Service\Driver key DRV - (PDRELI) not found.
Error: No service named DRV - (PDFRAME) was found to stop!
Service\Driver key DRV - (PDFRAME) not found.
Error: No service named DRV - (PDCOMP) was found to stop!
Service\Driver key DRV - (PDCOMP) not found.
Error: No service named DRV - (PCIDump) was found to stop!
Service\Driver key DRV - (PCIDump) not found.
Error: No service named DRV - (lbrtfdc) was found to stop!
Service\Driver key DRV - (lbrtfdc) not found.
Error: No service named DRV - (i2omgmt) was found to stop!
Service\Driver key DRV - (i2omgmt) not found.
Error: No service named DRV - (Changer) was found to stop!
Service\Driver key DRV - (Changer) not found.
Error: No service named DRV - (avchv) was found to stop!
Service\Driver key DRV - (avchv) not found.
Error: No service named DRV - (bdsandbox) was found to stop!
Service\Driver key DRV - (bdsandbox) not found.
========== FILES ==========
c:\windows\polop.exe moved successfully.
C:\WINDOWS\System32\d3d9caps.dat moved successfully.
C:\WINDOWS\System32\emptyregdb.dat moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\spool\suspic folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\spool folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\sounds folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\report folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\moved folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\log folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\journal folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\integ folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\HtmlData folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\fw folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\chest folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\backup folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\arpot\TEMP folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5\arpot folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software\Avast5 folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Alwil Software folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Babylon folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\BDLogging\updatesrv folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\BDLogging folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\{BECCA440-C137-43CD-BA7B-AE580F9F6D17} folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86\x86 folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}\x86 folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521} folder moved successfully.
C:\Documents and Settings\Perda\Data aplikací\Babylon folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\ctonhhte.rgb moved successfully.
C:\Documents and Settings\All Users\Data aplikací\qjaxlkio.dss moved successfully.
C:\Documents and Settings\All Users\Data aplikací\1333796597.bdinstall.bin moved successfully.
C:\Documents and Settings\All Users\Data aplikací\1333796539.bdinstall.bin moved successfully.
C:\Documents and Settings\All Users\Data aplikací\1333796579.bdinstall.bin moved successfully.
C:\WINDOWS\CSC\d8 folder moved successfully.
C:\WINDOWS\CSC\d7 folder moved successfully.
C:\WINDOWS\CSC\d6 folder moved successfully.
C:\WINDOWS\CSC\d5 folder moved successfully.
C:\WINDOWS\CSC\d4 folder moved successfully.
C:\WINDOWS\CSC\d3 folder moved successfully.
C:\WINDOWS\CSC\d2 folder moved successfully.
C:\WINDOWS\CSC\d1 folder moved successfully.
C:\WINDOWS\CSC folder moved successfully.
File\Folder C:\WINDOWS\system32\drivers\avchv.sys not found.
File\Folder C:\WINDOWS\system32\drivers\bdsandbox.sys not found.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\System32\CONFIG.TMP moved successfully.
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
C:\WINDOWS\tasks\SA.DAT moved successfully.
File\Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\RECYCLER\S-1-5-21-1390067357-562591055-725345543-1003\Dc5\ywgzombies2 folder moved successfully.
C:\RECYCLER\S-1-5-21-1390067357-562591055-725345543-1003\Dc5\openwarfare folder moved successfully.
C:\RECYCLER\S-1-5-21-1390067357-562591055-725345543-1003\Dc5 folder moved successfully.
C:\RECYCLER\S-1-5-21-1390067357-562591055-725345543-1003\Dc16 folder moved successfully.
C:\RECYCLER\S-1-5-21-1390067357-562591055-725345543-1003 folder moved successfully.
C:\RECYCLER folder moved successfully.
File\Folder C:\$RECYCLE.BIN not found.
File\Folder C:\RECYCLER not found.
File\Folder C:\Windows\tasks\*.job not found.
========== REGISTRY ==========
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Perda
->Temp folder emptied: 5508175 bytes
->Temporary Internet Files folder emptied: 2305691 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 288390996 bytes
->Apple Safari cache emptied: 2979840 bytes
->Flash cache emptied: 1239 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 32916 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 285,00 mb
[EMPTYFLASH]
User: Administrator
User: All Users
User: Default User
User: LocalService
User: NetworkService
User: Perda
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0,00 mb
OTL by OldTimer - Version 3.2.39.2 log created on 04112012_142934
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43287
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Svchost.exe velkej problem (500-xxx) processu
Jak to vypadá nyní?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
-
- Level 2
- Příspěvky: 169
- Registrován: duben 12
- Pohlaví:
- Stav:
Offline
-
- Mohlo by vás zajímat
- Odpovědi
- Zobrazení
- Poslední příspěvek
-
- 4
- 3378
-
od lukas222
Zobrazit poslední příspěvek
05 lis 2024 13:36
-
- 4
- 4005
-
od petr22
Zobrazit poslední příspěvek
28 lis 2024 10:06
-
- 3
- 3584
-
od Alferi
Zobrazit poslední příspěvek
22 črc 2024 08:09
-
- 8
- 2349
-
od sloliv
Zobrazit poslední příspěvek
08 led 2025 22:03
-
- 1
- 2360
-
od petr22
Zobrazit poslední příspěvek
27 led 2025 07:19
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 3 hosti