Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Съмнение за вирус [РЕШЕН]

Featured Replies

  • Автор

Ето ме отново. Съжалявам че пиша след толкова време но ... работа кво да се прави. Направих и последните стъпки. Ето снимката и доклада:

post-158750-0-67724000-1327411160_thumb.

KL_syscure.zip

  • Отговори 51
  • Прегледи 6,7k
  • Създадено
  • Последен отговор

Изключете временно антивирусната си програма и защитната стена.

Изпълнете следния скрипт : Как да изпълним скрипт с AVZ

begin
SearchRootkit(true, true);
SetAVZGuardStatus(True);
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
  ClearHostsFile;
   QuarantineFile('C:\Documents and Settings\Administrator\Desktop\pbsetup.zip','');
BC_ImportALL;
ExecuteSysClean;
BC_Activate;
ExecuteWizard('SCU',2,3,true);
RebootWindows(true);
end.

След изпълнение на скрипта компютъра ви ще се рестартира..!

След процедурата изпълнете следния скрипт Как да изпълним скрипт с AVZ

begin
CreateQurantineArchive(GetAVZDirectory+'quarantine.zip');
end.

В резултат на изпълнението на втория скрипт ще се генерира карантина quarantine.zip.Изпратете получения файл quarantine.zip,който се намира в ппката на АВЗ, адрес [email protected]

  • Автор

След първия скрипт програмата се почуди известно време и след това започна рестарта. Започна да се рестартира и по едно време заби и квото и да натискам нищо не ставаше. Оставих го така за известно време и след 10мин се рестартира. След изпълнението на втория скрипт изобщо не се рестартира.

Изчаквам резултатите от анализа на файла....Изпратен е в Kaspersky Lab и Служба вирусного мониторинга "Доктор Веб"..! Какво положението със компютъра ви...?Мина доста време..!

  • Автор

Анализите се върнаха - всичко е ок...! :)

Ааа не знам до колко е ОК ама при мен всичко си е същото :)

Известно време не ми пречеше процеса включваше се доста рядко и почти не го забелязвах.

Ама вчера се включи 4-5 пъти последователно и направо ми скъса нервите нищо не можех да направя от него.

А защо си мислите че проблема се дължи на вирус...? В продължение на един месец ви разпънах системата на кръст....повярвайте ми ако беше вирус ...щях да го хвана..!:)

Направете така:

Временно спрете работата на Антивирусната си програма.

Изтеглете querysvc.exe от sUBs

Стартирайте приложението.

Ще се отвори лог файл, копирайте съдържанието му в следващия си пост.

Направете и нова проверка с DDS и публикувате лог файловете.

  • Автор

А защо си мислите че проблема се дължи на вирус...?

В продължение на един месец ви разпънах системата на кръст....повярвайте ми ако беше вирус ...щях да го хвана..! :)

Емм пъро това ми мина през главата не случаино заглавието е Съмнение :)

Може и да е може и да не е не бях сигурен затова питах вас.

Щом не е вирус значи ще трябва ремонт или нова ОС .

Ето докладите:

sUBs

------ REGISTRY:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
- HTTPFilter - HTTPFilter
- LocalService - Alerter, WebClient, LmHosts, RemoteRegistry, upnphost, SSDPSRV
- NetworkService - DnsCache
- DcomLaunch - DcomLaunch, TermService
- rpcss - RpcSs
- imgsvc - StiSvc
- termsvcs - TermService
- eapsvcs - eaphost
- dot3svc - dot3svc
- WudfServiceGroup - WUDFSvc
- netsvcs - 6to4, AppMgmt, AudioSrv, Browser, CryptSvc, DMServer, DHCP, ERSvc, EventSystem, FastUserSwitchingCompatibility, HidServ, Ias, Iprip, Irmon, LanmanServer, LanmanWorkstation, Messenger, Netman, Nla, Ntmssvc, NWCWorkstation, Nwsapagent, Rasauto, Rasman, Remoteaccess, Schedule, Seclogon, SENS, Sharedaccess, SRService, Tapisrv, Themes, TrkWks, UxTuneUp, W32Time, WZCSVC, Wmi, WmdmPmSp, winmgmt, wscsvc, xmlprov, BITS, wuauserv, ShellHWDetection, helpsvc, WmdmPmSN, napagent, hkmsvc

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\DComLaunch
   CoInitializeSecurityParam REG_DWORD	   1 (0x1)
   DefaultRpcStackSize REG_DWORD	   8 (0x8)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\dot3svc
   AuthenticationCapabilities REG_DWORD	   12320 (0x3020)
   CoInitializeSecurityParam REG_DWORD	   1 (0x1)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\eapsvcs
   AuthenticationCapabilities REG_DWORD	   12320 (0x3020)
   CoInitializeSecurityParam REG_DWORD	   1 (0x1)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\HTTPFilter
   CoInitializeSecurityParam REG_DWORD	   1 (0x1)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\LocalService
   CoInitializeSecurityParam REG_DWORD	   1 (0x1)
   AuthenticationCapabilities REG_DWORD	   8192 (0x2000)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\netsvcs
   CoInitializeSecurityParam REG_DWORD	   1 (0x1)
   AuthenticationCapabilities REG_DWORD	   12320 (0x3020)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\PCHealth
   CoInitializeSecurityParam REG_DWORD	   2 (0x2)
   AuthenticationCapabilities REG_DWORD	   64 (0x40)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost\termsvcs
   CoInitializeSecurityParam REG_DWORD	   1 (0x1)
   DefaultRpcStackSize REG_DWORD	   8 (0x8)

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
   Authentication Packages REG_MULTI_SZ	msv1_0\0\0
   Notification Packages REG_MULTI_SZ	scecli\0\0
------ SVCHOST SERVICES NOT RUNNING
STOPPED: DEMAND_START: AppMgmt : Application Management
STOPPED: DEMAND_START: Dot3svc : Wired AutoConfig
STOPPED: DEMAND_START: EapHost : Extensible Authentication Protocol Service
STOPPED: DEMAND_START: hkmsvc : Health Key and Certificate Management Service
STOPPED: DEMAND_START: HTTPFilter : HTTP SSL
STOPPED: DEMAND_START: napagent : Network Access Protection Agent
STOPPED: DEMAND_START: NtmsSvc : Removable Storage
STOPPED: DEMAND_START: RasAuto : Remote Access Auto Connection Manager
STOPPED: DEMAND_START: upnphost : Universal Plug and Play Device Host
STOPPED: DEMAND_START: WebClient : WebClient
STOPPED: DEMAND_START: WmdmPmSN : Portable Media Serial Number Service
STOPPED: DEMAND_START: Wmi : Windows Management Instrumentation Driver Extensions
STOPPED: DEMAND_START: WZCSVC : Wireless Zero Configuration
STOPPED: DEMAND_START: xmlprov : Network Provisioning Service
STOPPED: DISABLED: Messenger : Messenger
STOPPED: DISABLED: RemoteAccess : Routing and Remote Access
------ SVCHOST CURRENTLY RUNNING:
632- C:\WINDOWS\system32\svchost.exe -k DcomLaunch
- DcomLaunch : DCOM Server Process Launcher
- TermService : Terminal Services
696- C:\WINDOWS\system32\svchost.exe -k rpcss
- RpcSs : Remote Procedure Call (RPC)
776- C:\WINDOWS\System32\svchost.exe -k netsvcs
- AudioSrv : Windows Audio
- BITS : Background Intelligent Transfer Service
- Browser : Computer Browser
- CryptSvc : CryptSvc
- Dhcp : DHCP Client
- dmserver : Logical Disk Manager
- ERSvc : Error Reporting Service
- EventSystem : COM+ Event System
- FastUserSwitchingCompatibility : Fast User Switching Compatibility
- helpsvc : Help and Support
- HidServ : HID Input Service
- lanmanserver : Server
- lanmanworkstation : Workstation
- Netman : Network Connections
- Nla : Network Location Awareness (NLA)
- RasMan : Remote Access Connection Manager
- Schedule : Task Scheduler
- seclogon : Secondary Logon
- SENS : System Event Notification
- SharedAccess : Windows Firewall/Internet Connection Sharing (ICS)
- ShellHWDetection : Shell Hardware Detection
- srservice : System Restore Service
- TapiSrv : Telephony
- Themes : Themes
- TrkWks : Distributed Link Tracking Client
- UxTuneUp : TuneUp Theme Extension
- W32Time : Windows Time
- winmgmt : Windows Management Instrumentation
- wscsvc : Security Center
- wuauserv : Automatic Updates
812- C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
- WudfSvc : Windows Driver Foundation - User-mode Driver Framework
928- C:\WINDOWS\system32\svchost.exe -k NetworkService
- Dnscache : DNS Client
1088- C:\WINDOWS\system32\svchost.exe -k LocalService
- Alerter : Alerter
- LmHosts : TCP/IP NetBIOS Helper
- RemoteRegistry : Remote Registry
- SSDPSRV : SSDP Discovery Service
732- C:\WINDOWS\system32\svchost.exe -k imgsvc
- stisvc : Windows Image Acquisition (WIA)
------ SVCHOST SUB-DEPENDENTS
SSDPSRV = 1
STOPPED: upnphost: Universal Plug and Play Device Host
DMServer = 1
STOPPED: dmadmin: Logical Disk Manager Administrative Service
EventSystem = 1
RUNNING: SENS: System Event Notification
LanmanServer = 1
RUNNING: Browser: Computer Browser
LanmanWorkstation = 5
RUNNING: Alerter: Alerter
RUNNING: Browser: Computer Browser
STOPPED: Messenger: Messenger
STOPPED: Netlogon: Net Logon
STOPPED: RpcLocator: Remote Procedure Call (RPC) Locator
Netman = 1
RUNNING: SharedAccess: Windows Firewall/Internet Connection Sharing (ICS)
Rasman = 1
STOPPED: RasAuto: Remote Access Auto Connection Manager
Tapisrv = 2
RUNNING: RasMan: Remote Access Connection Manager
STOPPED: RasAuto: Remote Access Auto Connection Manager
Themes = 1
RUNNING: UxTuneUp: TuneUp Theme Extension
winmgmt = 3
RUNNING: nSvcIp: ForceWare IP service
RUNNING: SharedAccess: Windows Firewall/Internet Connection Sharing (ICS)
RUNNING: wscsvc: Security Center
TermService = 1
RUNNING: FastUserSwitchingCompatibility: Fast User Switching Compatibility
RpcSs = 56
RUNNING: AudioSrv: Windows Audio
RUNNING: avast! Antivirus: avast! Antivirus
RUNNING: BITS: Background Intelligent Transfer Service
RUNNING: CryptSvc: CryptSvc
RUNNING: dmserver: Logical Disk Manager
RUNNING: ERSvc: Error Reporting Service
RUNNING: EventSystem: COM+ Event System
RUNNING: FastUserSwitchingCompatibility: Fast User Switching Compatibility
RUNNING: helpsvc: Help and Support
RUNNING: HidServ: HID Input Service
RUNNING: ICQ Service: ICQ Service
RUNNING: LMIGuardianSvc: LMIGuardianSvc
RUNNING: LogMeIn: LogMeIn
RUNNING: Netman: Network Connections
RUNNING: nSvcIp: ForceWare IP service
RUNNING: PolicyAgent: IPSEC Services
RUNNING: ProtectedStorage: Protected Storage
RUNNING: RasMan: Remote Access Connection Manager
RUNNING: RemoteRegistry: Remote Registry
RUNNING: SamSs: Security Accounts Manager
RUNNING: Schedule: Task Scheduler
RUNNING: SENS: System Event Notification
RUNNING: SharedAccess: Windows Firewall/Internet Connection Sharing (ICS)
RUNNING: ShellHWDetection: Shell Hardware Detection
RUNNING: Spooler: Print Spooler
RUNNING: srservice: System Restore Service
RUNNING: stisvc: Windows Image Acquisition (WIA)
RUNNING: TapiSrv: Telephony
RUNNING: TermService: Terminal Services
RUNNING: TrkWks: Distributed Link Tracking Client
RUNNING: winmgmt: Windows Management Instrumentation
RUNNING: wscsvc: Security Center
STOPPED: CiSvc: Indexing Service
STOPPED: COMSysApp: COM+ System Application
STOPPED: dmadmin: Logical Disk Manager Administrative Service
STOPPED: Dot3svc: Wired AutoConfig
STOPPED: EapHost: Extensible Authentication Protocol Service
STOPPED: gupdate: Услуга Google Update (gupdate)
STOPPED: gupdatem: Услуга на Google Актуализация (gupdatem)
STOPPED: gusvc: Google Software Updater
STOPPED: hkmsvc: Health Key and Certificate Management Service
STOPPED: Messenger: Messenger
STOPPED: MSDTC: Distributed Transaction Coordinator
STOPPED: MSIServer: Windows Installer
STOPPED: napagent: Network Access Protection Agent
STOPPED: NtmsSvc: Removable Storage
STOPPED: RasAuto: Remote Access Auto Connection Manager
STOPPED: RDSessMgr: Remote Desktop Help Session Manager
STOPPED: RemoteAccess: Routing and Remote Access
STOPPED: RSVP: QoS RSVP
STOPPED: SwPrv: MS Software Shadow Copy Provider
STOPPED: TlntSvr: Telnet
STOPPED: VSS: Volume Shadow Copy
STOPPED: WmiApSrv: WMI Performance Adapter
STOPPED: WZCSVC: Wireless Zero Configuration
STOPPED: xmlprov: Network Provisioning Service
TermService = 1
RUNNING: FastUserSwitchingCompatibility: Fast User Switching Compatibility
eaphost = 1
STOPPED: Dot3svc: Wired AutoConfig

attach

.
==== Installed Programs ======================
.
????? II?
Архиватор WinRAR
Говорилка
µTorrent
Пакет за езиков интерфейс на Windows
7-Zip 4.57
ABBYY PDF Transformer 2.0
Adobe Acrobat X Pro - English, Franзais, Deutsch
Adobe Flash Player 10 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader 6.0.1
Adobe Shockwave Player 11.5
Application Verifier
ArcSoft Camera Suite
avast! Internet Security
Battlefield 2(TM)
BitComet 1.31
BSPlayer
Camtasia Studio 7
CCleaner
Counter-Strike: Source
CuneiForm v12 Master
Debugging Tools for Windows (x86)
EASEUS Data Recovery Wizard Professional 5.0.1
Edimax Wireless LAN
Garena 2010
GeoVision ADPCM
GeoVision H264
GeoVision JPEG
GeoVision MPEG4
GeoVision MPEG4 ASP
GeoVision MPEG4 AVC
GeoVision MXPG
GetDataBack for FAT and GetDataBack for NTFS
Google Земя
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
Half-Life 2: Deathmatch
Half-Life(R) 2
Hama Black Force Pad
HD Tune Pro 4.60
Hide IP NG 1.65
HLSW v1.3.1
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB976002-v5)
ICQ Toolbar
ICQ7.2
IkaMinister
Java Auto Updater
Java(TM) 6 Update 24
K-Lite Mega Codec Pack 6.7.0
LogMeIn
LogMeIn Hamachi
LS-USBMX1/2/3 Steering...
Malwarebytes' Anti-Malware, версия 1.51.2.1300
MegaCam
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Chart Controls for Microsoft .NET Framework 3.5
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (Bulgarian) 2007
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (Bulgarian) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (Bulgarian) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (Bulgarian) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Language Pack 2007 - Bulgarian/български
Microsoft Office O MUI (Bulgarian) 2007
Microsoft Office OneNote MUI (Bulgarian) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (Bulgarian) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (Bulgarian) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (Bulgarian) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (German) 2007
Microsoft Office Proof (Russian) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (Bulgarian) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (Bulgarian) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (Bulgarian) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (Bulgarian) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Office X MUI (Bulgarian) 2007
Microsoft Software Update for Web Folders  (Bulgarian) 12
Microsoft Software Update for Web Folders  (English) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319
Microsoft Windows Performance Toolkit
Microsoft Windows SDK for Windows 7 (7.1)
Microsoft Windows SDK for Windows 7 Common Utilities (30514)
Microsoft Windows SDK for Windows 7 Headers and Libraries (30514)
Microsoft Windows SDK for Windows 7 Redistributable Components for Application Verifier (30514)
Microsoft Windows SDK for Windows 7 Redistributable Components for Common Tools (30514)
Microsoft Windows SDK for Windows 7 Redistributable Components for Windows Debugging Tools (30514)
Microsoft Windows SDK for Windows 7 Samples (30514)
Microsoft Windows SDK for Windows 7 Utilities for Win32 Development (30514)
Mozilla Firefox 9.0.1 (x86 bg)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB973686)
MyFreeCodec
Nero 6 Ultra Edition
Notepad++
NVIDIA Control Panel 285.58
NVIDIA Drivers
NVIDIA ForceWare Network Access Manager
NVIDIA Graphics Driver 285.58
NVIDIA Install Application
NVIDIA nView 135.95
NVIDIA PhysX
NVIDIA Update 1.5.20
NVIDIA Update Components
OpenAL
Oracle VM VirtualBox 4.1.4
oZone3D.Net FurMark v1.8.2
Paint.NET v3.5.4
Password Generator Professional
PowerDVD
PunkBuster Services
Realtek High Definition Audio Driver
Samsung Kies
Samsung Networking Wizard
Samsung PC Studio 3
Samsung PC Studio 3 USB Driver Installer
Samsung Samples Installer
SAMSUNG USB Driver for Mobile Phones
Security Update for 2007 Microsoft Office System (KB2277947)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for 2007 Microsoft Office System (KB982312)
Security Update for 2007 Microsoft Office System (KB982331)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB982308)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office Outlook 2007 (KB980376)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office Publisher 2007 (KB982124)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2251419)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165-v2)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB982381)
Skype Toolbars
Skype™ 3.5
SpeechLab
SpeedFan (remove only)
Steam
Synergy
System Requirements Lab
System Requirements Lab CYRI
Tunatic
Unknown Device Identifier 7.00
Unlocker 1.8.5
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Outlook 2007 Junk Email Filter (kb2279264)
Update for Windows XP (KB955759)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB978207)
USB FireWall 1.1.3
VLC media player 1.1.5
VTFEdit 1.2.5
WebFldrs XP
Winamp
Windows Driver Package - Advanced Micro Devices (AmdK8) Processor  (05/27/2006 1.3.2.0)
Windows Imaging Component
Windows Media Format 11 runtime
WinPcap 4.1.2
Wireshark 1.4.6
XML Paper Specification Shared Components Pack 1.0
.
==== End Of File ===========================

dds

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.5512  BrowserJavaVersion: 1.6.0_24
Run by Administrator at 23:27:58 on 2012-01-24
Microsoft Windows XP Professional  5.1.2600.3.1251.359.1033.18.1023.384 [GMT 2:00]
.
AV: avast! Internet Security *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Internet Security *Disabled*
FW: ActiveArmor Firewall *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\PROGRAMKI\hamachi\hamachi-2.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Java\jre6\bin\jqs.exe
D:\PROGRAMKI\logmein\x86\LMIGuardianSvc.exe
D:\PROGRAMKI\logmein\x86\RaMaint.exe
D:\PROGRAMKI\logmein\x86\LogMeIn.exe
D:\Install\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\Net Studio\USB FireWall\USB FireWall.exe
D:\PROGRAMKI\HotKeyz\HotKeyz.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
D:\Install\adobe\Acrobat\Acrotray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\wscntfy.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.systemrequirementslab.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\program files\icq6toolbar\ICQToolBar.dll
uURLSearchHooks: H - No File
mURLSearchHooks: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\program files\icq6toolbar\ICQToolBar.dll
mURLSearchHooks: H - No File
mURLSearchHooks: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\program files\icq6toolbar\ICQToolBar.dll
mURLSearchHooks: H - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - d:\programki\bitcomet\tools\BitCometBHO_1.5.4.11.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7227.1100\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\program files\icq6toolbar\ICQToolBar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [avast] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
mRun: [USBFW] c:\program files\net studio\usb firewall\USB FireWall.exe
mRun: [HotKeyz.exe Startup] d:\programki\hotkeyz\HotKeyz.exe Startup
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [<NO NAME>]
mRun: [Adobe Acrobat Speed Launcher] "d:\install\adobe\acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "d:\install\adobe\acrobat\Acrotray.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\outlook.lnk - c:\program files\microsoft office\office12\OUTLOOK.EXE
IE: &С&валяне &с BitComet - d:\programki\bitcomet\BitComet.exe/AddLink.htm
IE: &С&валяне на всички с BitComet - d:\programki\bitcomet\BitComet.exe/AddAllLink.htm
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - d:\install\icq 7\icq7.2\ICQ.exe
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://d:\programki\bitcomet\tools\BitCometBHO_1.5.4.11.dll/206
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {ADACAA8F-3595-47FE-9C31-9C7471B9BEC7} - hxxp://belozem.dipmap.com/cab/OCXChecker_8320.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.4.26.0.cab
TCP: DhcpNameServer = 85.130.60.11 62.221.132.211
TCP: Interfaces\{CB0EB507-C13C-4FF8-93D8-C4EC6D88B407} : DhcpNameServer = 85.130.60.11 62.221.132.211
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AutorunsDisabled - LMIinit.dll
Notify: LMIinit - LMIinit.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\administrator\application data\mozilla\firefox\profiles\nmd593mr.default\
FF - prefs.js: browser.search.selectedEngine - Yandex Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.bg/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=bg&q=
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.93\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
.
---- FIREFOX POLICIES ----
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: network.http.max-persistent-connections-per-server - 4
.
============= SERVICES / DRIVERS ===============
.
R0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\drivers\aswNdis.sys [2010-9-19 12112]
R0 aswNdis2;avast! Firewall Core Firewall Service;c:\windows\system32\drivers\aswNdis2.sys [2010-9-19 195416]
R1 aswFW;avast! TDI Firewall driver;c:\windows\system32\drivers\aswFW.sys [2010-9-19 111320]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2010-9-19 442200]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-9-19 320856]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [2010-5-27 158512]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [2010-5-27 91440]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-9-19 20568]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-19 44768]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;d:\programki\hamachi\hamachi-2.exe -s --> d:\programki\hamachi\hamachi-2.exe -s [?]
R2 ICQ Service;ICQ Service;c:\program files\icq6toolbar\ICQ Service.exe [2010-6-2 246520]
R2 LMIGuardianSvc;LMIGuardianSvc;d:\programki\logmein\x86\LMIGuardianSvc.exe [2011-3-1 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;d:\programki\logmein\x86\rainfo.sys [2009-12-31 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2011-6-3 47640]
R2 MBAMService;MBAMService;d:\install\malwarebytes' anti-malware\mbamservice.exe [2010-12-31 366152]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-6-25 35088]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-11-25 2253120]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-12-31 22216]
S2 avast! Firewall;avast! Firewall;c:\program files\alwil software\avast5\afwServ.exe [2010-9-19 127192]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Услуга Google Update (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-3-14 135664]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2011-4-30 1691480]
S3 ASUDriver;ASUDriver;\??\d:\programki\amd over drive\i386\aoddriver.sys --> d:\programki\amd over drive\i386\AODDriver.sys [?]
S3 GGSAFERDriver;GGSAFER Driver;\??\d:\programki\garena\safedrv.sys --> d:\programki\garena\safedrv.sys [?]
S3 gupdatem;Услуга на Google Актуализация (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-3-14 135664]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [2011-8-9 98432]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [2011-8-9 14848]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [2011-8-9 123648]
S3 ss_bserd;SAMSUNG USB Mobile Logging Driver;c:\windows\system32\drivers\ss_bserd.sys [2011-8-9 100224]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2010-6-25 104752]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\drivers\vboxnetflt.sys --> c:\windows\system32\drivers\VBoxNetFlt.sys [?]
S3 VBoxUSB;VirtualBox USB;c:\windows\system32\drivers\VBoxUSB.sys [2010-5-27 82736]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
=============== Created Last 30 ================
.
2012-01-24 10:21:58 -------- d-----w- C:\antivir
2012-01-23 18:56:32 -------- d-----w- c:\windows\system32\NtmsData
2012-01-19 15:05:54 22879528 ----a-r- c:\program files\Skype.exe
2012-01-19 00:57:08 -------- d-----w- c:\documents and settings\all users\application data\regid.1986-12.com.adobe
2012-01-11 22:53:15 138904 ----a-w- c:\documents and settings\administrator\application data\PnkBstrK.sys
2012-01-11 22:52:33 840264 ----a-w- c:\windows\system32\pbsvc.exe
2012-01-09 16:54:38 548864 ----a-w- c:\program files\mozilla firefox\msvcp80.dll
2012-01-09 16:54:38 479232 ----a-w- c:\program files\mozilla firefox\msvcm80.dll
2012-01-09 16:54:38 43992 ----a-w- c:\program files\mozilla firefox\mozutils.dll
2012-01-09 16:54:37 626688 ----a-w- c:\program files\mozilla firefox\msvcr80.dll
2011-12-31 00:52:36 -------- d-----w- c:\documents and settings\administrator\application data\hideip_firefox_plugin
2011-12-31 00:51:25 -------- d-----w- c:\documents and settings\administrator\application data\Hide IP NG
2011-12-29 23:33:44 -------- d-----w- c:\documents and settings\administrator\application data\NVIDIA
.
==================== Find3M  ====================
.
2012-01-16 23:30:29 234536 -c--a-w- c:\windows\system32\PnkBstrB.xtr
2012-01-16 23:30:29 234536 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-01-16 21:59:46 138520 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-01-16 21:57:22 234536 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-01-11 22:52:35 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-12-09 13:18:04 285176 ----a-w- c:\windows\system32\nvdrsdb0.bin
2011-12-09 13:18:04 1 ----a-w- c:\windows\system32\nvdrssel.bin
2011-12-09 13:15:39 285176 ----a-w- c:\windows\system32\nvdrsdb1.bin
2011-11-20 14:59:49 414368 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
============= FINISH: 23:29:30,09 ===============

П.П: А да ви попитам знаете ли svchost.exe каква информация съдържа ?

Интересува ме възможно ли е да взема файма svchost от ново инсталиран windows xp и да го замена с сегашния ?

Редактирано от doktorkartar (преглед на промените)

При стартиране Svchost.exe проверява услугите, които са част от системния регистър, за да състави списък с услуги, които трябва да зареди. По едно и също време могат да работят множество екземпляри на svchost.exe. Всяка сесия на Svchost.exe може да съдържа група от услуги.Или колкото повече услуги имаш пуснати,толкова повече Svchost.exe ще работят и ще се виждат в TaskManager..! :)

http://support.micro...om/kb/314056/bg

Сега се опитваме да разберем коя услуга или група от услуги товари и създава проблеми..!

  • Автор

Ами тогава да започна да изключвам една по една работещите програми ?

Не бързайте....! Включете си Task Manager и в таба View натиснете Select Columns и поставете отметка на PID.....После вижте кой точно Svchost и с кой PID товари...!

Също така:

Изтеглете Process Explorer.

Разархивирайте инструмента и стартирайте файла procexp.exe

Намерете и кликнете върху процеса наSvchost.exe (..но само на този който товари системата)

Отидете до секцията Threads

Разпънете графата така че да се виждат по-възможност всички обекти/нишки.

Направете снимка (screenshot) и я качете тук .

Докато сте в менюто Threads, кликнете с двукратен клик на мишката върху даден обект(желателно на всички) и направете снимка на Stack прозореца

Публикувайте линкове към снимките за да ги разгледамe в следващия си пост.

  • Автор

PID 268

Ето линк към снимките:

http://prikachi.com/...55/4311955K.jpg

http://prikachi.com/...56/4311956j.jpg

Опитах се да снимам всички но от време на време се появяваха нови за части от секундата и изчезваха. Случваше се новите обекти/нишки да бъдат с червен или зелен цвят.

Да се опитам ли да заснема и цветните обекти ?

Сега трябва да цъкна на всичките 60-70 обекта и да заснема менютата които се отварят или само на TID 3536 wuaueng.dll+0xa4adf ?

Редактирано от doktorkartar (преглед на промените)

Не докато сте в в менюто Threads, кликнете с двукратен клик на мишката върху обекта който натоварва (видях един на 86%) и направете снимка на Stack прозореца

Имам едни съмнения ...можеш ли да деинсталираш TuneUp и да видим как ще се държи машината..!

  • Автор

Не докато сте в в менюто Threads, кликнете с двукратен клик на мишката върху обекта който натоварва (видях един на 86%) и направете снимка на Stack прозореца

Имам едни съмнения ...можеш ли да деинсталираш TuneUp и да видим как ще се държи машината..!

Този път процеса е с друг PID защото се наложи да ресна.

Ето и снимката:

http://prikachi.com/images/80/4312080n.jpg

П.П: Нямам инсталиран TuneUP имам само портабле версия да я изтрия ли ?

  • Автор

Ами виждам UxTuneUp в услугите....да махни го..После не е проблем да си изтеглиш пак...!

Готово.

Рестартирайте компютъра и вижте пак ще товари ли..? Много услуги имате стартирани много от тях са излишни.....!:)

  • Автор

Пак се показа:

http://prikachi.com/...98/4312198Z.jpg

Ами в startup съм оставил само наи важните неща ама пак си има много процеси.

Оставил съм си само skype, outlook, avast, hotkeyz, usb firewall и realtek

Редактирано от doktorkartar (преглед на промените)

Моля да бъда извинен за намесата, но понеже имах подобен проблем при стартиращ се outlook заедно с Windows - опитайте да го забраните да се стартира само за да пробвате. При мене така се оправи и чак след като зареди Windows напълно си го стартирам ръчно...

И пак се извинявам за намесата...

modedit:Това да не се повтаря..!Приканвам към спазване на т.2 от правилата на подраздела..!

Здравейте..!

Направете стъпките от този линк..:http://ask-leo.com/comments_003020.php

Windows Update е най-вероятната причина...!Успех..! :)

  • Автор

Стъпка 2 не може да се изпълни. Никъде не намирам папка WuTemp затова я прескочих. Изпълних останалите стъпки (до номер 6). Сега да изпълня ли и следващото (това с регистрите) ? П.П: След рестарта от точка 6 svchost не се показа :) Е случвало се е и друг път да пропуска изява затова ще следя дали ще се появи отново.

  • Автор

Вие казвате че най вероятната причина е windows update но на този windows ne e правен update от години (може и изобщо да не е правен от както е инсталиран).

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.