Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Премахване на вирус ''svchost.com'' - Neshta

Featured Replies

Добре ще го направя сега, но имам един проблем. Днес пуснах една програма, която я имах на компа, и веднага ми се появи svhost.exe (изпълни като администратор) това се появява на всички .ехе файлове, смисъл като пускам гугъл или пък други програми и винаги трябва да давам ''Да''

Сигурни ли сте, че правилно пишете името на процеса? Правилното наименование е svchost.exe. Отделно, както споменах това е легитимен възел, за който се закачат редица услуги на Windows според конфигурацията на системата и стартираните услуги във фонов режим. Колкото до съобщението, то най-вероятно идва от UAC (User Account Control). Пробвайте да го изключите и вижте после как е положението:

http://windows.microsoft.com/bg-bg/windows/turn-user-account-control-on-off#1TC=windows-7

След това върнете Windows Updates на Automatic отново и вижте дали след поправката с Windows Repair All in One проблема с натовареността на svchost.exe остава. Би трябвало вече всичко да е наред. А иначе системата е чиста вече!

 

Поздрави!

 

  • Автор

Имах проблем с компютъра и си го преинсталирах може ли да кажете дали го има вируса още или не? Надявам се вече системата ми да е чиста

Драйвърите ще си ги сложа за компа, току що си го преинсталирах :)

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:23-09-2015
Ran by Ali (administrator) on ALI-PC (25-09-2015 09:41:35)
Running from C:\Users\Ali\Downloads
Loaded Profiles: Ali (Available Profiles: Ali)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Български (България)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Electronic Arts) C:\Program Files (x86)\Origin\OriginClientService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\SysWOW64\taskmgr.exe
(Microsoft Corporation) C:\Windows\winsxs\amd64_microsoft-windows-installer-executable_31bf3856ad364e35_6.1.7601.17514_none_a7a77a3b9cb96ce6\msiexec.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKU\S-1-5-21-1589461329-875050818-3415125408-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2899136 2015-08-19] (Valve Corporation)
HKU\S-1-5-21-1589461329-875050818-3415125408-1000\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3638256 2015-09-24] (Electronic Arts)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 217.79.79.79 217.79.79.217
Tcpip\..\Interfaces\{42ADDA2A-A11B-402C-9E1A-30293A6B8938}: [DhcpNameServer] 217.79.79.79 217.79.79.217

Internet Explorer:
==================
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-09-25] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-25] (Oracle Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\9gpcsmw7.default
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-25] (Oracle Corporation)
FF Extension: Kaldata.com news button - C:\Users\Ali\AppData\Roaming\Mozilla\Firefox\Profiles\9gpcsmw7.default\Extensions\[email protected] [2015-09-24]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 MozillaMaintenance; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [189096 2015-09-24] () [File not signed]
R3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2057736 2015-09-24] (Electronic Arts)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 RTL8023x64; C:\Windows\System32\DRIVERS\Rtnic64.sys [51712 2009-06-10] (Realtek Semiconductor Corporation                           )
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-25 09:41 - 2015-09-25 09:44 - 00004658 _____ C:\Users\Ali\Downloads\FRST.txt
2015-09-25 09:40 - 2015-09-25 09:41 - 00000000 ____D C:\FRST
2015-09-25 09:39 - 2015-09-25 09:40 - 02192384 _____ (Farbar) C:\Users\Ali\Downloads\FRST64.exe
2015-09-25 09:39 - 2015-09-25 09:39 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-09-25 09:39 - 2015-09-25 09:39 - 00000000 ____D C:\Users\Ali\AppData\Roaming\Sun
2015-09-25 09:39 - 2015-09-25 09:39 - 00000000 ____D C:\Users\Ali\.oracle_jre_usage
2015-09-25 09:39 - 2015-09-25 09:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-09-25 09:38 - 2015-09-25 09:39 - 00000000 ____D C:\ProgramData\Oracle
2015-09-25 09:38 - 2015-09-25 09:38 - 00000000 ____D C:\Program Files (x86)\Java
2015-09-25 09:37 - 2015-09-25 09:37 - 00000000 ____D C:\Program Files (x86)\SystemRequirementsLab
2015-09-25 09:36 - 2015-09-25 09:36 - 00679936 _____ C:\Users\Ali\Downloads\Detection.msi
2015-09-25 07:19 - 2015-09-24 20:41 - 00000000 ____D C:\Windows\Panther
2015-09-24 21:30 - 2012-02-17 09:38 - 01112064 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-09-24 21:30 - 2012-02-17 09:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2015-09-24 21:30 - 2012-02-17 08:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2015-09-24 21:30 - 2012-02-17 07:58 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2015-09-24 21:30 - 2012-02-17 07:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2015-09-24 21:10 - 2015-09-24 21:10 - 00000000 ____D C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-09-24 21:03 - 2015-09-24 21:03 - 00000000 ____D C:\Program Files (x86)\Origin Games
2015-09-24 21:02 - 2015-09-25 08:10 - 00000000 ____D C:\Users\Ali\AppData\Roaming\Origin
2015-09-24 21:01 - 2015-09-24 21:03 - 00000000 ____D C:\Users\Ali\AppData\Local\Origin
2015-09-24 21:01 - 2015-09-24 21:01 - 00000000 ____D C:\ProgramData\Package Cache
2015-09-24 20:57 - 2015-09-24 20:57 - 00000000 ____D C:\Users\Ali\AppData\Local\Steam
2015-09-24 20:57 - 2015-09-24 20:57 - 00000000 ____D C:\Users\Ali\AppData\Local\CEF
2015-09-24 20:54 - 2015-09-25 08:10 - 00000000 ____D C:\ProgramData\Origin
2015-09-24 20:54 - 2015-09-24 20:54 - 00000979 _____ C:\Users\Public\Desktop\Origin.lnk
2015-09-24 20:54 - 2015-09-24 20:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2015-09-24 20:54 - 2015-09-24 20:54 - 00000000 ____D C:\ProgramData\Electronic Arts
2015-09-24 20:53 - 2015-09-25 09:40 - 00000000 ____D C:\Program Files (x86)\Steam
2015-09-24 20:53 - 2015-09-24 21:01 - 00000000 ____D C:\Program Files (x86)\Origin
2015-09-24 20:53 - 2015-09-24 20:53 - 00000963 _____ C:\Users\Public\Desktop\Steam.lnk
2015-09-24 20:53 - 2015-09-24 20:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2015-09-24 20:50 - 2015-09-24 20:56 - 00000000 ____D C:\Users\Ali\AppData\Local\Mozilla
2015-09-24 20:50 - 2015-09-24 20:50 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-09-24 20:50 - 2015-09-24 20:50 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-09-24 20:50 - 2015-09-24 20:50 - 00000000 ____D C:\Users\Ali\AppData\Roaming\Mozilla
2015-09-24 20:50 - 2015-09-24 20:50 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-09-24 20:50 - 2015-09-24 20:50 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-09-24 20:46 - 2015-09-24 20:57 - 00000041 _____ C:\Windows\directx.sys
2015-09-24 20:46 - 2015-09-24 20:56 - 00000000 ____D C:\Program Files (x86)\Google
2015-09-24 20:46 - 2015-09-24 20:46 - 00057560 _____ C:\Users\Ali\AppData\Local\GDIPFONTCACHEV1.DAT
2015-09-24 20:46 - 2015-09-24 20:46 - 00000000 ____D C:\Users\Ali\AppData\Local\Google
2015-09-24 20:46 - 2015-09-24 20:46 - 00000000 ____D C:\Users\Ali\AppData\Local\Deployment
2015-09-24 20:46 - 2015-09-24 20:46 - 00000000 ____D C:\Users\Ali\AppData\Local\Apps\2.0
2015-09-24 20:46 - 2014-05-14 19:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-09-24 20:46 - 2014-05-14 19:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-09-24 20:46 - 2014-05-14 19:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-09-24 20:46 - 2014-05-14 19:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-09-24 20:46 - 2014-05-14 19:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-09-24 20:46 - 2014-05-14 19:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-09-24 20:46 - 2014-05-14 19:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-09-24 20:46 - 2014-05-14 19:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-09-24 20:46 - 2014-05-14 19:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-09-24 20:46 - 2014-05-14 19:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-09-24 20:46 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-09-24 20:46 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-09-24 20:46 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-09-24 20:46 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-09-24 20:43 - 2015-09-24 20:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-LINK
2015-09-24 20:42 - 2015-09-24 20:42 - 00041472 _____ C:\Windows\svchost.com
2015-09-24 20:42 - 2015-09-24 20:42 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-09-24 20:42 - 2015-09-24 20:42 - 00000000 ____D C:\ProgramData\TP-LINK
2015-09-24 20:42 - 2013-06-28 14:49 - 01930240 _____ (Atheros Communications, Inc.) C:\Windows\system32\Drivers\athurx.sys
2015-09-24 20:42 - 2013-06-28 14:49 - 01930240 _____ (Atheros Communications, Inc.) C:\Windows\system32\athurx.sys
2015-09-24 20:42 - 2013-06-28 14:49 - 00007518 _____ C:\Windows\system32\athurextx.cat
2015-09-24 20:41 - 2015-09-25 09:39 - 00000000 ____D C:\Users\Ali
2015-09-24 20:41 - 2015-09-24 20:41 - 00001427 _____ C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-09-24 20:41 - 2015-09-24 20:41 - 00001393 _____ C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2015-09-24 20:41 - 2015-09-24 20:41 - 00000020 ___SH C:\Users\Ali\ntuser.ini
2015-09-24 20:41 - 2015-09-24 20:41 - 00000000 __SHD C:\Recovery
2015-09-24 20:41 - 2015-09-24 20:41 - 00000000 ____D C:\Users\Ali\AppData\Local\VirtualStore
2015-09-24 20:41 - 2009-07-14 07:54 - 00000000 ___RD C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-24 20:41 - 2009-07-14 07:49 - 00000000 ___RD C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-09-24 20:24 - 2015-09-24 20:24 - 00001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2015-09-24 20:24 - 2015-09-24 20:24 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2015-09-24 20:23 - 2015-09-25 09:35 - 01052065 _____ C:\Windows\WindowsUpdate.log
2015-09-24 20:23 - 2015-09-24 20:23 - 00001355 _____ C:\Windows\TSSysprep.log
2015-09-24 20:23 - 2015-09-24 20:23 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-25 09:41 - 2009-07-14 07:45 - 00016640 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-25 09:41 - 2009-07-14 07:45 - 00016640 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-25 08:15 - 2009-07-14 08:13 - 00713888 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-25 08:10 - 2009-07-14 08:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2015-09-25 08:09 - 2010-11-21 06:47 - 00005666 _____ C:\Windows\PFRO.log
2015-09-25 08:09 - 2009-07-14 08:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-25 08:09 - 2009-07-14 07:51 - 00022750 _____ C:\Windows\setupact.log
2015-09-25 07:19 - 2009-07-14 08:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG
2015-09-25 07:19 - 2009-07-14 08:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template
2015-09-24 22:01 - 2009-07-14 06:20 - 00000000 ____D C:\Windows\SysWOW64\bg-BG
2015-09-24 22:01 - 2009-07-14 06:20 - 00000000 ____D C:\Windows\system32\bg-BG
2015-09-24 21:09 - 2009-07-14 06:20 - 00000000 __RHD C:\Users\Public\Libraries
2015-09-24 20:53 - 2009-07-14 06:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-09-24 20:42 - 2009-07-14 08:32 - 00000000 ____D C:\Windows\system32\restore
2015-09-24 20:41 - 2009-07-14 06:20 - 00000000 ____D C:\Windows\system32\Recovery
2015-09-24 20:41 - 2009-07-14 06:20 - 00000000 ____D C:\Windows\rescache
2015-09-24 20:24 - 2009-07-14 08:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-09-24 20:24 - 2009-07-14 06:20 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-24 20:23 - 2009-07-14 07:46 - 00002790 _____ C:\Windows\DtcInstall.log
2015-09-24 20:23 - 2009-07-14 06:20 - 00000000 ____D C:\Windows\system32\sysprep
2015-09-24 20:21 - 2011-04-12 11:28 - 00000000 ____D C:\Windows\CSC
2015-09-24 20:21 - 2009-07-14 07:45 - 00274320 _____ C:\Windows\system32\FNTCACHE.DAT

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-09-24 20:20

==================== End of FRST.txt ============================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:23-09-2015
Ran by Ali (2015-09-25 09:45:32)
Running from C:\Users\Ali\Downloads
Windows 7 Ultimate Service Pack 1 (X64) (2015-09-24 17:41:05)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1589461329-875050818-3415125408-500 - Administrator - Disabled)
Ali (S-1-5-21-1589461329-875050818-3415125408-1000 - Administrator - Enabled) => C:\Users\Ali
Guest (S-1-5-21-1589461329-875050818-3415125408-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version:  - Valve)
Java 8 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Mozilla Firefox 41.0 (x86 bg) (HKLM-x32\...\Mozilla Firefox 41.0 (x86 bg)) (Version: 41.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 41.0 - Mozilla)
Origin (HKLM-x32\...\Origin) (Version: 9.7.2.53208 - Electronic Arts, Inc.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
System Requirements Lab Detection (HKLM-x32\...\{6568B9D8-E9F0-4C7B-A1C0-51B628D324E2}) (Version: 6.1.6.0 - Husdawg, LLC)
TP-LINK TL-WN721N_TL-WN722N Driver (HKLM-x32\...\{86A7EED0-02D0-4D91-8183-8D2F23F5E6AE}) (Version: 1.3.1 - TP-LINK)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================

24-09-2015 20:42:38 Installed TP-LINK Wireless Configuration Utility and Driver
24-09-2015 20:46:01 Windows Update
24-09-2015 21:00:58 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
24-09-2015 21:01:27 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
24-09-2015 21:30:09 Windows Update
25-09-2015 09:37:07 Installed System Requirements Lab Detection

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 05:34 - 2009-06-11 00:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Loaded Modules (Whitelisted) ==============

2015-09-24 21:00 - 2015-09-24 21:00 - 01016832 _____ () C:\Program Files (x86)\Origin\platforms\qwindows.dll
2015-09-24 21:00 - 2015-09-24 21:00 - 00028160 _____ () C:\Program Files (x86)\Origin\imageformats\qgif.dll
2015-09-24 21:00 - 2015-09-24 21:00 - 00029696 _____ () C:\Program Files (x86)\Origin\imageformats\qico.dll
2015-09-24 21:00 - 2015-09-24 21:00 - 00256000 _____ () C:\Program Files (x86)\Origin\imageformats\qjpeg.dll
2015-09-24 21:00 - 2015-09-24 21:00 - 00266240 _____ () C:\Program Files (x86)\Origin\imageformats\qmng.dll
2015-09-24 21:00 - 2015-09-24 21:00 - 00023552 _____ () C:\Program Files (x86)\Origin\imageformats\qtga.dll
2015-09-24 21:00 - 2015-09-24 21:00 - 00346112 _____ () C:\Program Files (x86)\Origin\imageformats\qtiff.dll
2015-09-24 21:00 - 2015-09-24 21:00 - 00023552 _____ () C:\Program Files (x86)\Origin\imageformats\qwbmp.dll
2015-09-24 21:00 - 2015-09-24 21:00 - 00243200 _____ () C:\Program Files (x86)\Origin\mediaservice\wmfengine.dll
2015-09-24 20:57 - 2015-07-03 19:12 - 00778240 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2015-09-24 20:57 - 2015-07-03 19:12 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll
2015-09-24 20:57 - 2015-07-03 19:12 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2015-09-24 20:57 - 2015-07-03 19:12 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2015-09-24 20:57 - 2015-08-19 23:39 - 02413248 _____ () C:\Program Files (x86)\Steam\video.dll
2015-09-24 20:56 - 2014-12-02 00:31 - 02396672 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2015-09-24 20:56 - 2014-12-02 00:31 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2015-09-24 20:56 - 2014-12-02 00:31 - 00479744 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2015-09-24 20:56 - 2014-12-02 00:31 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2015-09-24 20:56 - 2014-12-02 00:31 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2015-09-24 20:57 - 2015-08-19 23:39 - 00704192 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2015-09-24 20:56 - 2015-07-27 04:13 - 00171008 _____ () C:\Program Files (x86)\Steam\bin\openvr_api.dll
2015-09-24 20:57 - 2015-07-03 19:12 - 39553928 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKLM\...\exefile\open\command: C:\Windows\svchost.com "%1" %* <===== ATTENTION

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1589461329-875050818-3415125408-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Ali\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 217.79.79.79 - 217.79.79.217
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{E1F6605F-C4EB-4316-81F1-E7CEFAC53290}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{8CD2DB87-4667-478E-9385-9967585E12E1}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{99E61F13-C3F4-40BE-943A-2AB6B08064E4}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{A505C54B-7A7D-474B-8593-10E2868AD572}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{A0549209-1F76-4BCC-A0B3-92955DDBF321}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{952EEE78-488C-4EE0-9CFD-C4BF589C5EEA}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{57CD226F-740A-4E49-89C2-0A2EF62D3AA8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{FA1576E3-BA81-4A94-8CD6-9EE9C9607E61}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/25/2015 08:15:33 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 002 language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (09/25/2015 08:15:33 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 002 language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (09/25/2015 08:11:24 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (09/25/2015 08:10:30 AM) (Source: Steam Client Service) (EventID: 1) (User: )
Description: Error: Failed to add firewall exception for C:\PROGRA~2\Steam\steam.exe

Error: (09/24/2015 08:57:21 PM) (Source: Steam Client Service) (EventID: 1) (User: )
Description: Error: Failed to add firewall exception for C:\PROGRA~2\Steam\steam.exe

Error: (09/24/2015 08:48:03 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Грешка при извличане на списък с главни сертификати на трети лица от архивен файл за автоматична актуализация в: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> с грешка: Задължителният сертификат не се намира в своя период на валидност, когато е проверен за съответствие с текущия системен часовник или времевото клеймо в подписания файл.
.

Error: (09/24/2015 08:45:53 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 002 language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (09/24/2015 08:45:53 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 002 language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (09/24/2015 08:40:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (09/24/2015 08:57:19 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Услуга Steam Client Service не може да бъде стартирана поради следната грешка:
%%1053

Error: (09/24/2015 08:57:19 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Изтекъл период на изчакване (30000 милисекунди) при изчакване на услуга Steam Client Service да се свърже.

Error: (09/24/2015 08:45:43 PM) (Source: NetBT) (EventID: 4321) (User: )
Description: The name "ALI-PC         :0" could not be registered on the interface with IP address 192.168.1.105.
The computer with the IP address 192.168.1.102 did not allow the name to be claimed by
this computer.

Error: (09/24/2015 08:45:42 PM) (Source: NetBT) (EventID: 4321) (User: )
Description: The name "ALI-PC         :20" could not be registered on the interface with IP address 192.168.1.105.
The computer with the IP address 192.168.1.102 did not allow the name to be claimed by
this computer.

Error: (09/24/2015 08:45:42 PM) (Source: Server) (EventID: 2505) (User: )
Description: The server could not bind to the transport \Device\NetBT_Tcpip_{42ADDA2A-A11B-402C-9E1A-30293A6B8938} because another computer on the network has the same name.  The server could not start.

Error: (09/24/2015 08:21:29 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Неуспешно зареждане на следния драйвер, който се активира с включване на компютъра или стартиране на системата:
cdrom


==================== Memory info ===========================

Processor: Intel(R) Core(TM)2 Quad CPU Q8200 @ 2.33GHz
Percentage of memory in use: 47%
Total physical RAM: 4094.49 MB
Available physical RAM: 2142.68 MB
Total Virtual: 8187.18 MB
Available Virtual: 6307.41 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:99.56 GB) (Free:79.59 GB) NTFS
Drive d: () (Fixed) (Total:831.41 GB) (Free:686.09 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: CE1AE8C5)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=99.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Partition 4: (Not Active) - (Size=831.4 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

П.П Виждам че на някой места отново има svchost.com :@

Редактирано от D71149 (преглед на промените)

И за чий ви беше да преинсталирате след като бяхме почистили проблема? Както казах, svchost.exe си е ЛЕГИТИМЕН възел в Windows. Ако очаквате, че след преинсталация няма да го имате се лъжете. Казах ви и как ще се реши проблема с въпросите при стартиране на програми - като спрете UAC!

Разбира се, сега вируса се е ВЪРНАЛ и няма как да е иначе, защото това е МРЕЖОВ червей и напада незащитени системи, а вие в момента сте само с Windows Defender, който при Windows 7 играе ролята само на анти-малуер програма, а не на пълноценна антивирусна такава, каквато е Microsoft Security Essentials. И второ...явно идва от крак за игрите, които използвате, защото няма епидемия на този червей, който е от 2005-та година и се лови от всички антивирусни програми отдавна. Но много хора ми се оплакаха по Л.С. от него...явно идва от краковете ви за игри, както и bitcoin миньорите.

Научете се да не спирате антивирусните програми по време на инсталацията на игри, защото не всичко е фалшива тревога, както ви уверяват под торентите и дори се смеят на тези, които не си изключват антивирусните....И също така е добре да намалите пиратството до минимум. И преди да сте се размрънкали, че нямате пари за легалните версии само ще кажа, че в GOG пускат постоянно промоции за смешни пари...има цели поредици на цената на една пица да речем....и най-хубавото е, че игрите там са оптимизирани без излишни bloatware-и и вървят дори на най-новите ОС (говорим за стари игри, които по принцип не са съвместими с 8 и нагоре, а те ги правят да са съвместими) и това ви спестява време за търсене на заобиколно решение и пробване на различните режими за съвместимост.

Ето ви скрипта за поправяне на проблема за n-ти път =>

 

fixlist.txt

  • Автор

Благодаря! Да, вирусът тръгна от пиратска игра, която я имах но без да искам я пуснах още преди да си преинсталирам компютъра и от там почнаха проблемите, след това си преинсталирах компютъра.. Вече нямам пиратски игри, а само купените ми седят :)

Fix result of Farbar Recovery Scan Tool (x64) Version:23-09-2015
Ran by Ali (2015-09-25 10:54:59) Run:1
Running from C:\Users\Ali\Desktop
Loaded Profiles: Ali (Available Profiles: Ali)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CreateRestorePoint:
2015-09-24 20:46 - 2015-09-24 20:57 - 00000041 _____ C:\Windows\directx.sys
2015-09-24 20:42 - 2015-09-24 20:42 - 00041472 _____ C:\Windows\svchost.com
HKLM\...\exefile\open\command: C:\Windows\svchost.com "%1" %* <===== ATTENTION
Reg: reg add HKLM\SOFTWARE\Classes\exefile\shell\open\command /ve /t REG_SZ /d "\"%1\" %*" /f
emptytemp:
end
*****************

Restore point was successfully created.
C:\Windows\directx.sys => moved successfully
C:\Windows\svchost.com => moved successfully
HKLM\Software\Classes\exefile\shell\open\command\\Default => value restored successfully

========= reg add HKLM\SOFTWARE\Classes\exefile\shell\open\command /ve /t REG_SZ /d "\"%1\" %*" /f =========

ЋЇҐа жЁпв  § ўкаиЁ гбЇҐи­®.

 

========= End of Reg: =========

EmptyTemp: => 650.2 MB temporary data Removed.


The system needed a reboot..

==== End of Fixlog 10:56:35 ====

 

Готово както преди :) А каква антивирусна ми препоръчвате безплатна, но да върши работа, защото съм скаран с тия програмки :D Благодаря, че ми обръщате внимание за пореден път ;)

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.