svchost!???
Cze wszystkim!!!
Takie pytanie: co mam zrobic kiedy mam uruchomione 6x: svchost.exe, zobaczyłem to w men. zadań.
Zrobiłem Hijacka – moźe to coś pomoźe....
Proszę o pomoc...
Dzięki
Logfile of HijackThis v1.99.0
Scan saved at 22:59:40, on 2005–01–05
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32ONELABSvsmon.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSOUNDMAN.EXE
C:Program FilesASUSProbeAsusProb.exe
C:PROGRA~1LogitechMOUSEW~1SYSTEMEM_EXEC.EXE
C:Program FilesHewlett–PackardHP Share–to–Webhpgs2wnd.exe
C:Program Filesone LabsoneAlarmzlclient.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesGadu–Gadugg.exe
C:Program FilesHewlett–PackardAiOhp officejet 5100 seriesBinhpoant07.exe
C:Program FilesAdobeAcrobat 5.0DistillrAcroTray.exe
C:Program FilesHewlett–PackardAiOhp officejet 5100 seriesFRURemind32.exe
C:PROGRA~1HEWLET~1HPSHAR~1hpgs2wnf.exe
C:PROGRA~1HEWLET~1AiOSharedBinhpoevm07.exe
C:WINDOWSsystem32hpoipm07.exe
C:Program FilesOutlook Expressmsimn.exe
C:Program FilesHewlett–PackardAiOSharedinhpOSTS07.exe
C:Program FilesHewlett–PackardAiOSharedinhpOFXM07.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
C:DOCUME~1EdgeUSTAWI~1Tempupdate.tmp
C:DOCUME~1EdgeUSTAWI~1TempKatalog tymczasowy 3 dla hijackthis.zipHijackThis.exe
R1 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = w3cache.dialog.net.pl:8080
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 5.0AcrobatActiveXAcroIEHelper.ocx
O4 – HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 – HKLM..Run: [ASUS Probe] C:Program FilesASUSProbeAsusProb.exe
O4 – HKLM..Run: [EM_EXEC] C:PROGRA~1LogitechMOUSEW~1SYSTEMEM_EXEC.EXE
O4 – HKLM..Run: [Share–to–Web Namespace Daemon] C:Program FilesHewlett–PackardHP Share–to–Webhpgs2wnd.exe
O4 – HKLM..Run: [KAVPersonal50] C:Program FilesKaspersky LabKaspersky Anti–Virus Personalkav.exe /minimize
O4 – HKLM..Run: [Zone Labs Client] "C:Program Filesone LabsoneAlarmzlclient.exe"
O4 – HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – Startup: Hewlett–Packard Recorder.lnk = C:Program FilesHewlett–PackardAiOhp officejet 5100 seriesFRURemind32.exe
O4 – Global Startup: HPAiODevice(hp officejet 5100 series) – 1.lnk = C:Program FilesHewlett–PackardAiOhp officejet 5100 seriesBinhpoant07.exe
O4 – Global Startup: Acrobat Assistant.lnk = C:Program FilesAdobeAcrobat 5.0DistillrAcroTray.exe
O4 – Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O17 – HKLMSystemCCSServicesTcpip..{D58AF6A9–91B3–4052–8FDC–F9BC4E1DCB3D}: NameServer = 217.30.129.149 217.201.137.200
O23 – Service: kavsvc – Kaspersky Lab – C:Program FilesKaspersky LabKaspersky Anti–Virus Personalkavsvc.exe
O23 – Service: TrueVector Internet Monitor – Zone Labs Inc. – C:WINDOWSsystem32ONELABSvsmon.exe
Takie pytanie: co mam zrobic kiedy mam uruchomione 6x: svchost.exe, zobaczyłem to w men. zadań.
Zrobiłem Hijacka – moźe to coś pomoźe....
Proszę o pomoc...
Dzięki
Logfile of HijackThis v1.99.0
Scan saved at 22:59:40, on 2005–01–05
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32ONELABSvsmon.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSOUNDMAN.EXE
C:Program FilesASUSProbeAsusProb.exe
C:PROGRA~1LogitechMOUSEW~1SYSTEMEM_EXEC.EXE
C:Program FilesHewlett–PackardHP Share–to–Webhpgs2wnd.exe
C:Program Filesone LabsoneAlarmzlclient.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesGadu–Gadugg.exe
C:Program FilesHewlett–PackardAiOhp officejet 5100 seriesBinhpoant07.exe
C:Program FilesAdobeAcrobat 5.0DistillrAcroTray.exe
C:Program FilesHewlett–PackardAiOhp officejet 5100 seriesFRURemind32.exe
C:PROGRA~1HEWLET~1HPSHAR~1hpgs2wnf.exe
C:PROGRA~1HEWLET~1AiOSharedBinhpoevm07.exe
C:WINDOWSsystem32hpoipm07.exe
C:Program FilesOutlook Expressmsimn.exe
C:Program FilesHewlett–PackardAiOSharedinhpOSTS07.exe
C:Program FilesHewlett–PackardAiOSharedinhpOFXM07.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
C:DOCUME~1EdgeUSTAWI~1Tempupdate.tmp
C:DOCUME~1EdgeUSTAWI~1TempKatalog tymczasowy 3 dla hijackthis.zipHijackThis.exe
R1 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = w3cache.dialog.net.pl:8080
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 – BHO: AcroIEHlprObj Class – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 5.0AcrobatActiveXAcroIEHelper.ocx
O4 – HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 – HKLM..Run: [ASUS Probe] C:Program FilesASUSProbeAsusProb.exe
O4 – HKLM..Run: [EM_EXEC] C:PROGRA~1LogitechMOUSEW~1SYSTEMEM_EXEC.EXE
O4 – HKLM..Run: [Share–to–Web Namespace Daemon] C:Program FilesHewlett–PackardHP Share–to–Webhpgs2wnd.exe
O4 – HKLM..Run: [KAVPersonal50] C:Program FilesKaspersky LabKaspersky Anti–Virus Personalkav.exe /minimize
O4 – HKLM..Run: [Zone Labs Client] "C:Program Filesone LabsoneAlarmzlclient.exe"
O4 – HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – Startup: Hewlett–Packard Recorder.lnk = C:Program FilesHewlett–PackardAiOhp officejet 5100 seriesFRURemind32.exe
O4 – Global Startup: HPAiODevice(hp officejet 5100 series) – 1.lnk = C:Program FilesHewlett–PackardAiOhp officejet 5100 seriesBinhpoant07.exe
O4 – Global Startup: Acrobat Assistant.lnk = C:Program FilesAdobeAcrobat 5.0DistillrAcroTray.exe
O4 – Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 – Extra button: Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O9 – Extra 'Tools' menuitem: Windows Messenger – {FB5F1910–F110–11d2–BB9E–00C04F795683} – C:Program FilesMessengermsmsgs.exe
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O17 – HKLMSystemCCSServicesTcpip..{D58AF6A9–91B3–4052–8FDC–F9BC4E1DCB3D}: NameServer = 217.30.129.149 217.201.137.200
O23 – Service: kavsvc – Kaspersky Lab – C:Program FilesKaspersky LabKaspersky Anti–Virus Personalkavsvc.exe
O23 – Service: TrueVector Internet Monitor – Zone Labs Inc. – C:WINDOWSsystem32ONELABSvsmon.exe
Odpowiedzi: 4
edge:Czy to jest normalne źe jest otwarych pięć "zadań" a jedno z nich ma ok. 20–30MB.
Tak, to normalne.
edge:Jeszcze przy otwieraniu Windows Worms Doors Cleaner jest info o moźliwości wirusa (lub czegoś) ze względu ma wielkość pliku svchost.
Falszywy alarm :?:
Cze
Czy to jest normalne źe jest otwarych pięć "zadań" a jedno z nich ma ok. 20–30MB.
Jeszcze przy otwieraniu Windows Worms Doors Cleaner jest info o moźliwości wirusa (lub czegoś) ze względu ma wielkość pliku svchost.
Pozdrowienia
Czy to jest normalne źe jest otwarych pięć "zadań" a jedno z nich ma ok. 20–30MB.
Jeszcze przy otwieraniu Windows Worms Doors Cleaner jest info o moźliwości wirusa (lub czegoś) ze względu ma wielkość pliku svchost.
Pozdrowienia
... if localized in System folder (%System%).
svchost.exe is a system process belonging to the Microsoft Windows Operating System which handles processes executed from DLLs. This program is important for the stable and secure running of your computer and should not be terminated
Strona 1 / 1