Rundll zdere 100%

poruka: 13
|
čitano: 2.719
|
moderatori: pirat, XXX-Man
1
+/- sve poruke
ravni prikaz
starije poruke gore
14 godina
neaktivan
offline
Rundll32 100% cpu

Pozdrav. Imam problem koji se pojavio u zadnja 3 dana...dakle nekaj sa pobrao negdje (neam pojma gdje), ali kad god upalim komp i nešto krenem radit pod procesima mi "rundll32.exe" uzima 100% kompa , a lokacija od filea je; C:\Users\....\AppData\Local\Temp\8274.tmp  , dakle nije onaj pravi rundll... probao sam brisat, al opet se generira sam u temp folderu, skenirao sa malwarebytes i nod32, 0 infected fileova, probao sam i u system32 izbrisat rundll i zamjenit ga sa friškom kopijom sa win 7 instalacijskog cd-a , al i dalje kad god restartam on je opet tu, i nemrem uopće radit na kompu dok ga ne zgasim.

 

Ima netko kakvu ideju kak da to rješim?

 
0 0 hvala 0
16 godina
neaktivan
offline
Re: Rundll32 100% cpu

Skini process hacker

http://processhacker.sourceforge.net/

 

Pronađi sporni process koji ti ždere CPU time, desni klik->properties, prebaci na tab "General" i kopiraj ovamo ono što stoji u "Command line" (pazi da sve kopiraš).

Oscar-Mike-Golf Whiskey-Tango-Foxtrot
14 godina
neaktivan
offline
Rundll zdere 100%

evo;

 

rundll32.exe  -k phatk -o http://lohman.strangled.net:80 -u lohman -p 123 -I 1

 

 

-znači neko smeće je...

 
0 0 hvala 0
16 godina
neaktivan
offline
Re: Rundll zdere 100%

Ajde još samo kopiraj "Image file name" (sa istog taba), da vidim jel pravi rundll32, jer ovo gotovo sigurno nije pravi rundll, argumenti uopće ne odgovaraju

http://support.microsoft.com/kb/164787

Oscar-Mike-Golf Whiskey-Tango-Foxtrot
Poruka je uređivana zadnji put sub 25.8.2012 15:47 (rustweaver).
14 godina
neaktivan
offline
Re: Rundll zdere 100%

Evo, image file name;

 

C:\Users\Marv\AppData\Local\Temp\3C53.tmp\rundll32.exe

16 godina
neaktivan
offline
Re: Rundll zdere 100%
Doovx kaže...

C:\Users\Marv\AppData\Local\Temp\3C53.tmp\rundll32.exe

Ubij proces (možeš i process hackerom) zatim obriši tu datoteku, restartiraj računalo i vidi je li se pojavila opet. Kao što sam i mislio, nije pravi rundll...

Oscar-Mike-Golf Whiskey-Tango-Foxtrot
Poruka je uređivana zadnji put sub 25.8.2012 15:52 (rustweaver).
14 godina
neaktivan
offline
Rundll zdere 100%
Ma pojavi se svaki put, kao što sam napisao u uvodnom postu , to ja tak već od jučer stalno da bi mogao uopće radit na kompu ugasim, zbrišem cijeli temp folder, al kad se restarta opet je tu.
 
0 0 hvala 0
16 godina
neaktivan
offline
Re: Rundll zdere 100%

sorry nisam dobro pročitao prvi post, skini hijack this i ovdje zalijepi log. Da vidimo što se sve pokreće na startupu.

Oscar-Mike-Golf Whiskey-Tango-Foxtrot
14 godina
neaktivan
offline
Rundll zdere 100%

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:54:14, on 25.8.2012.
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16448)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Logitech\SetPointG\SetPointII.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe
C:\Program Files\Process Hacker 2\ProcessHacker.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\BSplayerPro\bsplayer.exe
C:\Users\Marko\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: 173.212.255.178 embedded.garena.com

O1 - Hosts: 173.212.255.178 embedded.garenanow.com

O1 - Hosts: 94.174.242.66 www.codemplosion.com

O1 - Hosts: 94.174.242.66 codemplosion.com

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MIC30F~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MIC30F~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office 2010\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\Run: [AMD Catalyst] C:\ProgramData\Catalyst\color.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: CurseClientStartup.ccip
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MIC30F~1\Office14\EXCEL.EXE/3000
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\Windows\SYSTEM32\crypserv.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 7098 bytes

Poruka je uređivana zadnji put sub 25.8.2012 16:24 (Doovx).
 
0 0 hvala 0
18 godina
offline
Rundll zdere 100%

O1 - Hosts: 173.212.255.178 embedded.garena.com

O1 - Hosts: 173.212.255.178 embedded.garenanow.com

O1 - Hosts: 94.174.242.66 www.codemplosion.com

O1 - Hosts: 94.174.242.66 codemplosion.com

 

To 4 ti je "Nasty" i treba popraviti "fix" tj ukloniti.

 

Preporučio bih da nakon što to "popraviš" proskeniraš komp s SuperAntiSpyware i s Malwarebytes Anti-Malware.

Puni scan naravno. Možeš i sa HitmanPro također.

I zamijeni antivirus, Nod32 se pokazao kao loš.

Povoljni CD-keyevi: http://www.cjs-cdkeys.com/affiliate/idevaffiliate.php?id=250
Moj PC  
0 0 hvala 0
14 godina
neaktivan
offline
Re: Rundll zdere 100%

ej jesam otišo sam u hosts file i maknuo to sad, sve zbrisao , al opet se pojavio proces minutu nakon restarta.

Ma malwarebytes sam jučer vrtio par puta full scan 0 bodova.

 

 

Poruka je uređivana zadnji put sub 25.8.2012 16:23 (Doovx).
18 godina
offline
Re: Rundll zdere 100%
Doovx kaže...

ej jesam otišo sam u hosts file i maknuo to sad, sve zbrisao , al opet se pojavio proces minutu nakon restarta.

Ma malwarebytes sam jučer vrtio par puta full scan 0 bodova.

 

 

Skeniraj u safe modu. Prođi s SAS i HitmanPro koje sam ti naveo.

 

Probaj i u "start search" upisati cmd.exe i pokrenuti kao administrator. E, u tom command promptu s admin pravima upišeš "sfc /scannow" bez navodnika naravno i udariše enter.

Zanima me hoće li ti šta popravljati, tj jel ti kakav windows file oštećen.

Povoljni CD-keyevi: http://www.cjs-cdkeys.com/affiliate/idevaffiliate.php?id=250
17 godina
neaktivan
offline
Re: Rundll zdere 100%
Doovx kaže...

ej jesam otišo sam u hosts file i maknuo to sad, sve zbrisao , al opet se pojavio proces minutu nakon restarta.

Ma malwarebytes sam jučer vrtio par puta full scan 0 bodova.

 

 

uradi kako piše  ovom postu , kad pregledam, logove znat ćemo puno preciznije o kojem se virusu radi

 

1
Nova poruka
E-mail:
Lozinka:
 
vrh stranice