procesy wrr

hej ludziki mam prosbe... czy moze kots mi powiedziec ktore z procesow moge zamknac bo juz mi zuzycie procesora dochodzi do 100% i sie komp starsznie muli wrr... z gory dzieki za pomoc... papa

SVCHOST.EXE SYSTEM
mspaint.exe Megusia
taskmgr.exe Megusia
emule.exe Megusia
csrss.exe Megusia
ntddetect.exe Megusia
jusched.exe Megusia
ashDisp.exe Megusia
BTWINDS.EXE SYSTEM
ashServ.exe SYSTEM
aswUpdSv.exe SYSTEM
SPOOLSV.EXE SYSTEM
SVCHOST.EXE USLUGA LOKALNA
SVCGOST.EXE USLUGA LOKALNA
SVCHOST.EXE SYSTEM
SVCHOST.EXE SYSTEM
LSASS.EXE SYSTEM
SERVICES.EXE SYSTEM
CSRSS.EXE SYSTEM
SMSS.EXE SYSTEM
msmsgs.exe Megusia
ashMauSv.exe SYSTEM
TeaTimer.exe Megusia
explorer.EXE Megusia
ctfmon.exe Megusia
System.exe SYSTEM
Proces bezczynnosci systemu SYSTEM

Odpowiedzi: 8

Dobra megiś postaram sie to wytłumaczyć zrozumiale

Menadzera zadan masz po wcisnieciu kombinacji Alt+Ctrl+Delete, przechodzisz do zakładki procesy, rozciagasz okno i wciskasz Print screen z klawiatury, teraz otwierasz Painta i Ctrl+V

Wylacz przywracanie systemu (jak ?? wszystko masz w temacie o Hijack This w dziale bezpieczenstwo)

Włączasz menadzera i zamykasz proces:
ntddetect.exe >> robal

Zaznaczasz pokazywanie plikow ukrytych i systemowych (rowniez opisane w temacie o HijackThis)
Z dysku usuwasz:
ntddetect.exe
mkjn.dll
systime.exe
oprozniasz Temp

Teraz otwierasz Hijacka, zaznaczasz wpisy podane ponizej i wciskasz FIX CHECKED:
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Megusia\USTAWI~1\Temp\se.dll/sp.html
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.interia.pl/
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Megusia\USTAWI~1\Temp\se.dll/sp.html
R1 – HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 – BHO: (no name) – {0A4E67DE–565B–489A–AA99–B97DE863A398} – C:\WINDOWS\System32\mkjn.dll (file missing)
O2 – BHO: (no name) – {83DE62E0–5805–11D8–9B25–00E04C60FAF2} – C:\WINDOWS\2_0_1browserhelper2.dll (file missing)
O4 – HKLM\..\Run: [ntddetect] C:\WINDOWS\System32\ntddetect.exe
O4 – HKLM\..\RunServices: [ntddetect] C:\WINDOWS\System32\ntddetect.exe
O4 – HKCU\..\Run: [SysTime] C:\WINDOWS\System32\systime.exe
O4 – HKCU\..\Run: [ntddetect] C:\WINDOWS\System32\ntddetect.exe
O9 – Extra button: Related – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:\WINDOWS\web\related.htm
O9 – Extra 'Tools' menuitem: Show &Related Links – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:\WINDOWS\web\related.htm
O16 – DPF: {15AD4789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://public.windupdates.com/get_file.php?bt=ie&p=bfef0b2a528b91928edcd29464b84891acceeb23d2ed0abe04b4c68c60f5f05401eb42c32da863452d9dcd3f6524f022e9cd782b033d9556373797521e465c0731:4bf9e5f754d65d14399f92c372c739a3
O18 – Filter: text/html – {214C76CF–A238–4A41–857D–360998E59215} – C:\WINDOWS\System32\mkjn.dll
O18 – Filter: text/plain – {214C76CF–A238–4A41–857D–360998E59215} – C:\WINDOWS\System32\mkjn.dll
O21 – SSODL: System – {76C9BA35–B140–489D–8DBD–A110906697D5} – memsw.dll (file missing)


PS:
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Zainstaluj SP do XP i IE

PS2: Logi zamieszczaj w tagach code
Bobi
Dodano
05.03.2005 17:58:23
ALT+CTRL+DEL
Anonymous
Dodano
05.03.2005 17:46:14
bo moze mi ktos powie gdfzie ten menedzer zadan jest hmm... bo nie mam zielonego pojecia... :oops:
megiś
Dodano
05.03.2005 17:36:04
a wiec to bedzie tak:


Logfile of HijackThis v1.99.0
Scan saved at 16:25:24, on 2005–03–05
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\WINDOWS\System32\ntddetect.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot – Search & Destroy\TeaTimer.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\Programy\Anti\HijackThis.exe

R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Megusia\USTAWI~1\Temp\se.dll/sp.html
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.interia.pl/
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Megusia\USTAWI~1\Temp\se.dll/sp.html
R1 – HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
F2 – REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 – BHO: (no name) – {0A4E67DE–565B–489A–AA99–B97DE863A398} – C:\WINDOWS\System32\mkjn.dll (file missing)
O2 – BHO: (no name) – {53707962–6F74–2D53–2644–206D7942484F} – C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 – BHO: (no name) – {83DE62E0–5805–11D8–9B25–00E04C60FAF2} – C:\WINDOWS\2_0_1browserhelper2.dll (file missing)
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:\WINDOWS\System32\msdxm.ocx
O4 – HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 – HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 – HKLM\..\Run: [CafeNews] C:\Program Files\MMCafe\CafeNews\CN.exe
O4 – HKLM\..\Run: [ntddetect] C:\WINDOWS\System32\ntddetect.exe
O4 – HKLM\..\Run: [webscan] C:\Program Files\Acceleration Software\Anti–Virus\stopsignav.exe –k
O4 – HKLM\..\RunServices: [ntddetect] C:\WINDOWS\System32\ntddetect.exe
O4 – HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 – HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 – HKCU\..\Run: [SysTime] C:\WINDOWS\System32\systime.exe
O4 – HKCU\..\Run: [ntddetect] C:\WINDOWS\System32\ntddetect.exe
O4 – HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot – Search & Destroy\TeaTimer.exe
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 – Extra context menu item: Send To &Bluetooth – C:\Program Files\Bluetooth Software\btsendto_ie_ctx.htm
O9 – Extra button: (no name) – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:\WINDOWS\System32\msjava.dll
O9 – Extra 'Tools' menuitem: Sun Java Console – {08B0E5C0–4FCB–11CF–AAA5–00401C608501} – C:\WINDOWS\System32\msjava.dll
O9 – Extra button: Related – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:\WINDOWS\web\related.htm
O9 – Extra 'Tools' menuitem: Show &Related Links – {c95fe080–8f5d–11d2–a20b–00aa003c157a} – C:\WINDOWS\web\related.htm
O9 – Extra button: @btrez.dll,–4015 – {CCA281CA–C863–46ef–9331–5C8D4460577F} – C:\Program Files\Bluetooth Software\btsendto_ie.htm
O9 – Extra 'Tools' menuitem: @btrez.dll,–4017 – {CCA281CA–C863–46ef–9331–5C8D4460577F} – C:\Program Files\Bluetooth Software\btsendto_ie.htm
O16 – DPF: {15AD4789–CDB4–47E1–A9DA–992EE8E6BAD6} – http://public.windupdates.com/get_file.php?bt=ie&p=bfef0b2a528b91928edcd29464b84891acceeb23d2ed0abe04b4c68c60f5f05401eb42c32da863452d9dcd3f6524f022e9cd782b033d9556373797521e465c0731:4bf9e5f754d65d14399f92c372c739a3
O16 – DPF: {31B7EB4E–8B4B–11D1–A789–00A0CC6651A8} (Cult3D ActiveX Player) – http://www.cult3d.com/download/cult.cab
O17 – HKLM\System\CCS\Services\Tcpip\..\{15CC4432–1471–4DC8–ACAC–99562D5B2F9C}: NameServer = 194.204.159.1,194.204.152.34
O17 – HKLM\System\CS1\Services\Tcpip\..\{15CC4432–1471–4DC8–ACAC–99562D5B2F9C}: NameServer = 194.204.159.1,194.204.152.34
O17 – HKLM\System\CS2\Services\Tcpip\..\{15CC4432–1471–4DC8–ACAC–99562D5B2F9C}: NameServer = 194.204.159.1,194.204.152.34
O18 – Filter: text/html – {214C76CF–A238–4A41–857D–360998E59215} – C:\WINDOWS\System32\mkjn.dll
O18 – Filter: text/plain – {214C76CF–A238–4A41–857D–360998E59215} – C:\WINDOWS\System32\mkjn.dll
O21 – SSODL: System – {76C9BA35–B140–489D–8DBD–A110906697D5} – memsw.dll (file missing)
O23 – Service: avast! iAVS4 Control Service – Unknown – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 – Service: avast! Antivirus – Unknown – C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 – Service: avast! Mail Scanner – ALWIL Software – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 – Service: avast! Web Scanner – ALWIL Software – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 – Service: Bluetooth Service – WIDCOMM, Inc. – C:\Program Files\Bluetooth Software\bin\btwdins.exe

narazie tylko to podaje papatki
megiś
Dodano
05.03.2005 17:32:25
teatimer.exe to jest straźnik spy bot search and destroy
Hunter86
Dodano
05.03.2005 15:52:27
svchosta sobie nie wylaczaj, zostaw w spokoju :wink:
Pokaz w miare mozliwosci screen z menadzera zadan, rozciagnij go tak zeby bylo widac wszystkie procesy i print screen, ale musisz go wysłac na jakis inny serwer bo narazie załaczniki na forum sa wyłaczone.
Log z Hijack This tez mozesz zapodac bo mam wrazenie ze system tez lekko zasyfiony bedzie. Uprzedze pytanie "co to takiego ?? " i napisze zebys udała sie do działu bezpieczenstwo
Bobi
Dodano
05.03.2005 15:30:50
no tak wiem ze pait i emule to tak no bo to akurat mialam otwarte jak pisalam posta ale np svchost to wszytskie moge zakonczyc czy jak?? i nic wiecej sie nie mozna zakonczyc...??
megiś
Dodano
05.03.2005 15:23:22
mspaint.exe
emule.exe
jusched.exe
BTWINDS.EXE
TeaTimer.exe
SVCGOST.EXE (?)
Anonymous
Dodano
05.03.2005 12:22:50
megiś
Dodano:
05.03.2005 12:15:00
Komentarzy:
8
Strona 1 / 1