[ nikitaGradov @ 19.09.2009. 10:03 ] @
Evo ovako: na jednom racunaru, Windows XP, SP2 ili SP3 (nisam siguran), opterecenje procesora je uvijek 100% (treba li da kazem da racunar radi sporo, da se razlicite aplikacije ponasaju cudno i slicno). Pokusavao sam da ubijem razne sumnjive procese u Task Manager-u, ali i dalje opterecenje procesora stoji 100%. Ono sto sam ustanovio jeste da postoji proces iz naslova: HP1006MC.exe. Kada ga ubijem sa End Task, on se odmah ponovo pojavi u listi procesa. Malo sam guglovao i pokusavao da nadjem nesto vise ... Evo, rekoh da i ovdje postavim ovo pitanje, mozda je neko vec imao iskustava sa ovim problemom, pa bi svaka pomoc dobrodosla ... postoji li neki freeware alat na ovu temu?
[ Dashkes @ 19.09.2009. 10:18 ] @
Dobro resenje je Dr.Web CureIt!. Mozete da postavite ovde HijackThis log.
[ lega99 @ 19.09.2009. 16:33 ] @
Najbrza provera je da pronadjes taj file i uplodujes ga na
Code:
http://www.virustotal.com/

sacekas da 41 AV program iskenira taj file i dobijes rezultat, fajl lici ba neki HP ali i ako je HP file mozda je zarazen
[ freelancer @ 19.09.2009. 16:52 ] @
U pitanju je drajver za HP 1006 laserski štampač, instalirao sam ga pre više od dve godine i od tada imam hp1006mc.exe u proces listi, ponaša se istovetno kao što si opisao; ako ga ubijem u task manageru startuje se ponovo odmah. Dakle taj proces u osnovi nije maliciozan program, naravno nije iskljuceno da se nije mogao inficirati sa necim.
[ nikitaGradov @ 20.09.2009. 21:35 ] @
Hvala na prijedlogu ... taj racunar mi nije, da tako kazem blizu - cim budem u prilici da ga testiram, okacicu rezultat ...
[ nikitaGradov @ 20.09.2009. 21:36 ] @
Hvala na korisnom linku - pokusacu ...
[ nikitaGradov @ 25.09.2009. 22:09 ] @
Evo HiJackThis loga:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:49:30, on 25.09.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\EpStsSrv.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\ESDUSBMon.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\temp\ztmp\SaLLe-soft1.exe
C:\WINDOWS\system32\MSgid.exe
c:\MetaLINE\Run\MetaLINK.exe
C:\WINDOWS\system32\wuauclt.exe
F:\HiJackThis\HijackThis.exe
C:\WINDOWS\system32\MSgid.exe
c:\WINDOWS\system32\vsrsc.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http:www.petnaesta.edu.yu
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://companyweb
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;*.local;<local>
R3 - URLSearchHook: (no name) - {ce0c2586-da36-452b-acdb-320d9bcb19bf} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Windows Live pomagac za prijavljivanje - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {ce0c2586-da36-452b-acdb-320d9bcb19bf} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {ce0c2586-da36-452b-acdb-320d9bcb19bf} - (no file)
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [salle-soft] C:\temp\ztmp\zzSTART-ShortCut.bat
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI05E6~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://companyweb
O16 - DPF: {485D813E-EE26-4DF8-9FAF-DEDF2885306E} (NSHelp Class) - http://192.168.2.2/ConnectComputer/nshelp.dll
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = wpcpartizan.local
O17 - HKLM\Software\..\Telephony: DomainName = wpcpartizan.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = wpcpartizan.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = wpcpartizan.local
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: EPSON ESC/POS Status Service (EPSON ESCPOS Status Service) - SEIKO EPSON Corp. - C:\WINDOWS\SYSTEM32\EpStsSrv.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 4531 bytes


Dalje, otkrio sam koji proces usporava racunar: MSgid.exe. Ne znam sta je ovaj proces i pokusavam da nadjem nesto vise na Internetu - za sada bezuspjesno. Posumnjao sam da je nesto u vezi mesindzera, ali je isti dizejblovan u listi servisa, a podizanje mesindzera sam ukinuo preko msconfig-a. Prilikom restarta ovaj MSgid.exe se podigne i opterecenje CPU-a bude 100%, a kada se 'ubije' sa End Task, opterecenje CPU-a pada na nulu ...

Ako neko ima bilo kakav savjet, odgovor ili pomoc, bicu mu zahvalan ...
[ nikitaGradov @ 25.09.2009. 22:11 ] @
Zaboravih da napisem da je program: dculrg4c, pronasao jedan virus (neki trojanac) na fajlu: winuyw32.dll ...
[ Dashkes @ 25.09.2009. 22:17 ] @
Stiklirajte sledece objekte i kliknite “Fix checked”
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;*.local;
R3 - URLSearchHook: (no name) - {ce0c2586-da36-452b-acdb-320d9bcb19bf} - (no file)
O2 - BHO: (no name) - {ce0c2586-da36-452b-acdb-320d9bcb19bf} - (no file)
O3 - Toolbar: (no name) - {ce0c2586-da36-452b-acdb-320d9bcb19bf} - (no file)
O4 - HKCU\..\Run: [salle-soft] C:\temp\ztmp\zzSTART-ShortCut.bat

Posle toga restartujte racunar.

Ako mozete fajlove
C:\temp\ztmp\zzSTART-ShortCut.bat
C:\WINDOWS\system32\MSgid.exe
c:\WINDOWS\system32\vsrsc.exe
C:\temp\ztmp\SaLLe-soft1.exe
C:\WINDOWS\system32\MSgid.exe
c:\MetaLINE\Run\MetaLINK.exe

da zapakujete u ".rar"/".zip" sa password-om "virus", upload-ujete na Rapidshare i posaljete mi link preko PP.
[ valjan @ 25.09.2009. 22:40 ] @
Zar nije Metalink program za Galebove fiskalne printere?
[ Dashkes @ 25.09.2009. 22:47 ] @
Citat:
valjan: Zar nije Metalink program za Galebove fiskalne printere?


Mozda jeste, nece biti lose da proverim. :)
[ nikitaGradov @ 25.09.2009. 23:08 ] @
Citat:
Dashkes: Stiklirajte sledece objekte i kliknite “Fix checked”
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;*.local;
R3 - URLSearchHook: (no name) - {ce0c2586-da36-452b-acdb-320d9bcb19bf} - (no file)
O2 - BHO: (no name) - {ce0c2586-da36-452b-acdb-320d9bcb19bf} - (no file)
O3 - Toolbar: (no name) - {ce0c2586-da36-452b-acdb-320d9bcb19bf} - (no file)
O4 - HKCU\..\Run: [salle-soft] C:\temp\ztmp\zzSTART-ShortCut.bat

Posle toga restartujte racunar.

Ako mozete fajlove
C:\temp\ztmp\zzSTART-ShortCut.bat
C:\WINDOWS\system32\MSgid.exe
c:\WINDOWS\system32\vsrsc.exe
C:\temp\ztmp\SaLLe-soft1.exe
C:\WINDOWS\system32\MSgid.exe
c:\MetaLINE\Run\MetaLINK.exe

da zapakujete u ".rar"/".zip" sa password-om "virus", upload-ujete na Rapidshare i posaljete mi link preko PP.



Uradicu Fix checked kako ste naveli i poslacu navedene fajlove ... na zalost nista prije ponedjeljka ... MetaLINK.exe jeste interfejs za Galeb-ove fiskalne stampace ...