praegune kellaaeg 04.08.2025 14:50:56
|
Hinnavaatlus
:: Foorum
:: Uudised
:: Ärifoorumid
:: HV F1 ennustusvõistlus
:: Pangalink
:: Telekavad
:: HV toote otsing
|
autor |
|
Piux
HV vaatleja
liitunud: 24.11.2009
|
12.09.2011 21:50:49
Services.exe ja taskmgr.exe suur cpu kasutus |
|
|
Ei suutnud leida endale sobivat lahendust ja ei tea kas ka siia foorumisse on õige kirjutada, kuid teen proovi. Nimelt siin kuskil kuu või tiba enam tagasi hakkas HP nc4400 läpakal selline jama , et äkitselt hakkasid services.exe ja taskmgr.exe väga palju cpud õgima, et miskit teha ei lase.vahel natuke aega on uimane, siis taastu kiid mitte kauaks. Ja ei aita ka restart, sest siis isegi laeb biosi väga aeglaselt ja kogu värki yleyldse. vahel võin lasua terve päeva järjest restarte teha, siis lõpuks jooxeb taas käima, kuid seda vahel ainult mõnex ajax, vahel ka kauemax.eset smart security 4 ja sbybot ei leia ka miskit viirust. process exploreri alt ei suuda kh miskit eristada. jätan siia ka igaxjuhux hijack logi, äkki keski teab aidata. Op systeem on xp pro
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:47:18, on 12.09.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Documents and Settings\All Users\Application Data\DatacardService\DCSHost.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
c:\WINDOWS\system32\ifxspmgt.exe
C:\WINDOWS\system32\IFXTCS.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\WINDOWS\system32\IfxPsdSv.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Hewlett-Packard\IAM\bin\asghost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Tele2 Mobile Partner\Tele2 Mobile Partner.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
c:\Program Files\Hewlett-Packard\Embedded Security Software\PSDrt.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neti.ee/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live'i sisselogimisabiline - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IFXSPMGT] c:\WINDOWS\system32\ifxspmgt.exe /NotifyLogon
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe c:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} (SysInfo Class) - http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.4.21.0.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{04E8639B-7619-4FFE-B7E0-AC792562A89C}: NameServer = 212.247.156.66 212.247.156.70
O20 - AppInit_DLLs: APSHook.dll
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O20 - Winlogon Notify: OneCard - c:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: DCSHost.exe - Unknown owner - C:\Documents and Settings\All Users\Application Data\DatacardService\DCSHost.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - c:\WINDOWS\system32\flcdlock.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - c:\WINDOWS\system32\ifxspmgt.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\WINDOWS\system32\IFXTCS.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
O23 - Service: Personal Secure Drive service (PersonalSecureDriveService) - Infineon Technologies AG - c:\WINDOWS\system32\IfxPsdSv.exe
--
End of file - 7779 bytes
|
|
tagasi üles |
|
 |
mikk36
HV Guru

liitunud: 21.02.2004

|
13.09.2011 11:40:36
|
|
|
Process Explorer näitab täpsemalt ära et mis teenused nende taga jooksevad. Services.exe on lihtsalt teenuseid käima tõmbav protsess ja ei ütle midagi tarka iseenesest.
|
|
Kommentaarid: 85 loe/lisa |
Kasutajad arvavad: |
   |
:: |
0 :: |
2 :: |
78 |
|
tagasi üles |
|
 |
Piux
HV vaatleja
liitunud: 24.11.2009
|
13.09.2011 16:58:53
|
|
|
Process PID CPU Private Bytes Working Set Description Company Name
System Idle Process 0 2.05 0 K 28 K
System 4 1.37 0 K 240 K
Interrupts n/a 2.05 0 K 0 K Hardware Interrupts and DPCs
smss.exe 1028 172 K 432 K Windows NT Session Manager Microsoft Corporation
csrss.exe 1084 10.27 2 016 K 4 992 K Client Server Runtime Process Microsoft Corporation
winlogon.exe 1112 2.74 12 132 K 4 700 K Windows NT Logon Application Microsoft Corporation
services.exe 1164 36.99 2 052 K 3 852 K Services and Controller app Microsoft Corporation
svchost.exe 1396 4 696 K 9 144 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1448 0.68 4 308 K 5 728 K Generic Host Process for Win32 Services Microsoft Corporation
asghost.exe 2056 1.37 12 824 K 14 308 K Global Virtual Card Host Bioscrypt Inc.
igfxsrvc.exe 3924 2 372 K 4 208 K igfxsrvc Module Intel Corporation
wmiprvse.exe 4036 3 372 K 5 356 K WMI Microsoft Corporation
svchost.exe 1504 2 844 K 4 880 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1548 1.37 24 816 K 35 268 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1608 2 724 K 3 772 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1724 5 700 K 8 128 K Generic Host Process for Win32 Services Microsoft Corporation
spoolsv.exe 352 6 060 K 7 204 K Spooler SubSystem App Microsoft Corporation
agrsmsvc.exe 692 588 K 1 748 K Agere Soft Modem Call Progress Service Agere Systems
btwdins.exe 708 2 964 K 3 620 K Bluetooth Support Server Broadcom Corporation.
DCSHOST.exe 752 824 K 2 504 K DCSHOST
ekrn.exe 772 0.68 65 760 K 68 716 K ESET Service ESET
IFXSPMGT.exe 880 4 296 K 10 080 K Security Platform Management Service Infineon Technologies AG
IFXTCS.exe 916 4 148 K 7 556 K TCPA TSS Core Service Infineon Technologies AG
jqs.exe 1088 2.05 2 452 K 1 888 K Java(TM) Quick Starter Service Sun Microsystems, Inc.
IfxPsdSv.exe 1744 1 244 K 3 012 K PSD Service Infineon Technologies AG
alg.exe 192 2 132 K 4 040 K Application Layer Gateway Service Microsoft Corporation
svchost.exe 2236 4 460 K 7 804 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 2308 2 536 K 3 900 K Generic Host Process for Win32 Services Microsoft Corporation
lsass.exe 1176 0.68 6 076 K 1 864 K LSA Shell (Export Version) Microsoft Corporation
taskmgr.exe 3032 5.22 1 812 K 2 248 K Windows TaskManager Microsoft Corporation
explorer.exe 2932 8.90 34 388 K 18 240 K Windows Explorer Microsoft Corporation
SynTPEnh.exe 2016 1 888 K 5 400 K Synaptics TouchPad Enhancements Synaptics, Inc.
egui.exe 3668 0.43 2 228 K 3 940 K ESET GUI ESET
smax4pnp.exe 3832 2 652 K 4 732 K SMax4PNP Analog Devices, Inc.
igfxtray.exe 3852 1 960 K 3 964 K igfxTray Module Intel Corporation
hkcmd.exe 3864 1 956 K 3 972 K hkcmd Module Intel Corporation
igfxpers.exe 3884 1 552 K 3 388 K persistence Module Intel Corporation
ctfmon.exe 3996 1 132 K 3 740 K CTF Loader Microsoft Corporation
DTLite.exe 4080 4 548 K 8 028 K DAEMON Tools Lite DT Soft Ltd
firefox.exe 544 84 092 K 96 708 K Firefox Mozilla Corporation
procexp.exe 356 16.52 11 648 K 16 644 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
Tele2 Mobile Partner.exe 3248 8.22 9 828 K 5 200 K
PSDrt.exe 812 42 496 K 47 312 K PSD Runtime Application Infineon Technologies AG
|
|
tagasi üles |
|
 |
ollev
HV kasutaja
liitunud: 16.01.2011
|
|
tagasi üles |
|
 |
|
lisa lemmikuks |
|
|
sa ei või postitada uusi teemasid siia foorumisse sa ei või vastata selle foorumi teemadele sa ei või muuta oma postitusi selles foorumis sa ei või kustutada oma postitusi selles foorumis sa ei või vastata küsitlustele selles foorumis sa ei saa lisada manuseid selles foorumis sa võid manuseid alla laadida selles foorumis
|
|
Hinnavaatlus ei vastuta foorumis tehtud postituste eest.
|