Upomoc !!!!

Upomoc !!!!

Chatujem danas sa drugarom preko MSN messengera, kad se meni na jedno 10 sekundi zamrzo messenger i HD poceo da sljaka ko lud. Nista ne bi bilo cudno da se polje za upis teksta na Messengeru nije zatamnilo ( kao kad neka opcija u nekom programu nije dostupna dok se ne stiklira neki check box ). Pri sledecem startovanju racunara ZAP i KAV (45048-) se nisu startovali. Startovao sam KAZV i ZAP rucno, pustio update, pa skeniranje i nisam nasao nista. Jedina stvar koja zbunjuje je gomila SVCHOST.EXE u task menadzeru. Smrdi mi na neki od ovih novih crva, ali kako da ustanovim koji je ( nacicu nacin da ga se otarasim ako znam koji je ).

Pomagajte ljudi, ko boga vas molim.
Unapred hvala

zoranb ::Teo ::
istaliro sam kav i naso mi je Worm.Win32.Welchia virus koji je obriso ali kad sam gledo na sajtu kasperkog naso sam da se taj virus sastoji iz dva dela iz dllhost.exe i svchost.exe folder dllhost.exe je detektovo kav i izvriso a folder svchost.exe se jos nalazi u mom konpjuteru i kav nepokazuje da je virus...sta da radim,dali jos imam virus...uradio sam Disk Defragmenter jos pre koji dan... ali to nema veze sa ovim... evo vec sam na netu 10 min. i nije poceo konpjuer da mi koci,ali sta bi sa dllhost.exe failmom dali je i on virus?


Svchost (1) Svchost.exe

(Microsoft) Service Host – Generic Host Process for Win32 Services. Windows 2000/XP only. SVCHOST is a generic process which acts as a host for processes that run from DLLs rather than EXEs. At startup SVCHOST checks the Services portion of the Registry to construct a list of DLL-based services that it needs to load, and then loads them. There can be many instances of SVCHOST running, as there will be one instance of SVCHOST for every DLL-based service or grouping of services (the grouping of services is determined by the programmers who wrote the services in question). Under Windows XP Professional you can find out what DLL-based services SVCHOST is running by typing Tasklist /SVC at a Command Prompt (MS-DOS Prompt – this command is not available in Windows XP Home), while under Windows 2000 you need to use the TLIST –s command from a Command Prompt (MS-DOS Prompt).

Recommendation :
An integral part of the operating system, leave alone – multiple instances of SVCHOST is a normal occurrence. If you experience SVCHOST errors, the problem is most likely not with SVCHOST but with the DLLs it is hosting.

Svchost (2) SVCHOST.EXE

(???) Many viruses masquerade themselves as SVCHOST to escape detection. Some have names that are similar, such as SCCHOST, while others actually drop a program file called SVCHOST in the Windows or Windows System directory.

Recommendation :
The first recommendation is a simple one : always have a good antivirus product which is regularly updated (automatically preferably) and always renew your updates subscription when it expires. To detect if you have a virus that calls itself SVCHOST, first see if it shows up in Starter – if it does, then it is almost certain you have a virus. Secondly, if you have Windows 95/98/ME rather than WinNT4/2000/XP, then it is almost certain you have a virus. Thirdly, go to "Control Panel \ Administrative Tools \ Services" and look for any of the following services – if you find any of them, then you probably have a virus :

System Important Message service

Dllhost DLLHost.exe

(Microsoft) DCOM support module for DLL based COM objects (DCOM = Distributed Component Object Model). DCOM is a software architecture model which is an intrinsic part of Windows, of most Microsoft products, and of many non-Microsoft products. In most cases you should never see DLLHOST in your Task List, as, typically, DLLHOST starts, does what it has to do, and then terminates. However, sometimes, if a Java COM object runs (this could happen if you are browsing the Internet and come to a page which has Java code), DLLHOST may not terminate, which is when you would see it in your Task List.

Recommendation :
Do not "End Task" it as there is no way to determine whether DLLHOST has completed its task or not. For the more advanced users, however, deleting the registry key "HKEY_LOCAL_MACHINE\SOFTWARE\ Microsoft\Java VM\MSDebug" can often solve the problem of DLLHOST constantly appearing in the Task List. Finally, if you keep getting DLLHOST errors on a Windows 2000/XP/2003 PC, then you may have the Welchia virus.

Nocna patrola sajta

[Link mogu videti samo ulogovani korisnici]

Za pocetak probaj da online skeniras komp na Symantec - ovom ili McAffe-vom sajtu.

hmm, hvala momci, ali jos uvek nista nisam nasao, cak su se danas ZAP i KAV startovali normalno pri dizanju windowsa

Idi u Safe mod pa pusti KAV da skenira. Video sam slicnu situaciju...

offman ::Za pocetak probaj da online skeniras komp na Symantec - ovom ili McAffe-vom sajtu.

Pr3e nego li odes na pomenuti sajt da testiras bezbednost, pogledaj ovaj post o tom sajtu:
[Link mogu videti samo ulogovani korisnici]

Hmm, problem je bio sasvim druge prirode.
Nasao sam da je izvor problema VMWare. On produzuje podizanje sistema za bar tri minuta dok ne podigne svoje drajvere i sta ti znam sta jos.
Kako se KAV i ZAP podizu posle njega, mislio sam da je virus, ali srecom nije.
VMWare izgleda da podize one SVCHOST-ove kojih sam se ja uplasio.
Hvala na pomoci u svakom slucaju

