rlk120
(Rlk120)
7 Kwiecień 2007 09:21
#1
Dzisiaj włączyłem komputer i Internet mi strasznie zamula, z rapida ściąga 10 kb/s a powinno 30
Do tego w menedzerze zadań wykorzystanie sieci jest 0% a ściąga wolno.
Często też mam 100% wykorzystania procesora,nawet gdy nic nie robie.
Daje log z HijackThis 2.0
Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 11:21:36, on 2007-04-07 Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Kaspersky Internet Security 6.0\avp.exe C:\WINDOWS\Explorer.EXE C:\Kaspersky Internet Security 6.0\avp.exe C:\WINDOWS\system32\wuauclt.exe D:\Tlen.pl\tlen.exe D:\Winamp\WINAMP.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Łukasz.XXX-886A8B7CD27\Pulpit\hijackthis 2.0\HiJackThis_v2.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL O3 - Toolbar: Steganos Internet Anonym - {00000000-5736-4205-0008-781cd0e19f00} - c:\program files\steganos internet anonym pro 7\siapro7iep.dll O4 - HKLM…\Run: [AVP] “C:\Kaspersky Internet Security 6.0\avp.exe” O4 - HKCU…\Run: [Komunikator] D:\Tlen.pl\tlen.exe O4 - HKUS\S-1-5-19…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘USŁUGA LOKALNA’) O4 - HKUS\S-1-5-19…\RunOnce: [sIAPRO7] “C:\Program Files\Steganos Internet Anonym Pro 7\SIAPRO7.exe” -firstboot (User ‘USŁUGA LOKALNA’) O4 - HKUS\S-1-5-20…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘USŁUGA SIECIOWA’) O4 - HKUS\S-1-5-20…\RunOnce: [sIAPRO7] “C:\Program Files\Steganos Internet Anonym Pro 7\SIAPRO7.exe” -firstboot (User ‘USŁUGA SIECIOWA’) O4 - HKUS\S-1-5-18…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’) O4 - HKUS\S-1-5-18…\RunOnce: [sIAPRO7] “C:\Program Files\Steganos Internet Anonym Pro 7\SIAPRO7.exe” -firstboot (User ‘SYSTEM’) O4 - HKUS.DEFAULT…\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’) O4 - HKUS.DEFAULT…\RunOnce: [sIAPRO7] “C:\Program Files\Steganos Internet Anonym Pro 7\SIAPRO7.exe” -firstboot (User ‘Default user’) O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe O8 - Extra context menu item: Clean Traces - D:\Program Files\DAP\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: Download with DAP - D:\Program Files\DAP\dapextie.htm O8 - Extra context menu item: Dodaj do blokowanych banerów - C:\Kaspersky Internet Security 6.0\ie_banner_deny.htm O8 - Extra context menu item: Download all with DAP - D:\Program Files\DAP\dapextie2.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra button: Statystyki ochrony WWW - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Kaspersky Internet Security 6.0\scieplugin.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip…{4506E289-70D2-4ED6-B277-3AC56F7A35E3}: NameServer = 194.204.152.34 217.98.63.164 O17 - HKLM\System\CS1\Services\Tcpip…{4506E289-70D2-4ED6-B277-3AC56F7A35E3}: NameServer = 194.204.152.34 217.98.63.164 O20 - AppInit_DLLs: C:\KASPER~1.0\adialhk.dll O22 - SharedTaskScheduler: Moduł wstępnego ładowania interfejsu Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Demon buforu kategorii składników - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Lavasoft\aawservice.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Kaspersky Lab - C:\Kaspersky Internet Security 6.0\avp.exe O23 - Service: CachemanXP (CachemanXPService) - OuterTechnologies - D:\CACHEM~1\CachemanXP.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe – End of file - 5356 bytes
adam9870
(adam9870)
7 Kwiecień 2007 09:26
#2
Log czysty.
Proponuję usunąć Megaupload Toolbar ponieważ jest to Toolbar wątpliwej reputacji. Bowiem zbiera dane o użytkowniki i gdzieś je wysyła, nie wiadomo gdzie.
Może prędkość ściągania jest niska ponieważ w tle działają inne aplikacje korzystające z łącza?
Który z uruchomionych procesów najczęściej wykorzystuje najwięcej zasobów?
Przeskanuj system http://www.ewido.net/en/ i wklej raport plus log z SilentRunners .
rlk120
(Rlk120)
7 Kwiecień 2007 09:50
#3
Na razie tylko log z Silenta bo
Nie chce mi się zaktualizować.
Najwięcej svchost,czasem SYSTEM i explorer.
“Silent Runners.vbs”, revision R50, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by “{++}” Startup items buried in registry: --------------------------------- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} “Komunikator” = “D:\Tlen.pl\tlen.exe” [“o2.pl Sp. z o.o.”] HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++} “AVP” = ““C:\Kaspersky Internet Security 6.0\avp.exe”” [“Kaspersky Lab”] HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\ {++} “megauploadtoolbar” = “C:\DOCUME~1\UKASZ~1.XXX\USTAWI~1\Temp\tbuninstall.exe -df “C:\Program Files\MegauploadToolbar”” [null data] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = (no title provided) -> {HKLM…CLSID} = “Adobe PDF Reader Link Helper” \InProcServer32(Default) = “D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll” [“Adobe Systems Incorporated”] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}(Default) = (no title provided) -> {HKLM…CLSID} = “SSVHelper Class” \InProcServer32(Default) = “C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll” [“Sun Microsystems, Inc.”] {C333CF63-767F-4831-94AC-E683D962C63C}(Default) = “TGTSoft Explorer Toolbar Changer” -> {HKLM…CLSID} = “CoTGT_BHO Class” \InProcServer32(Default) = “C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll” [null data] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ “{42071714-76d4-11d1-8b24-00a0c9068ff3}” = “Rozszerzenie CPL kadrowania wyświetlania” -> {HKLM…CLSID} = “Rozszerzenie CPL kadrowania wyświetlania” \InProcServer32(Default) = “deskpan.dll” [file not found] “{88895560-9AA2-1069-930E-00AA0030EBC8}” = “Rozszerzenie ikony HyperTerminalu” -> {HKLM…CLSID} = “HyperTerminal Icon Ext” \InProcServer32(Default) = “C:\WINDOWS\system32\hticons.dll” [“Hilgraeve, Inc.”] “{85E0B171-04FA-11D1-B7DA-00A0C90348D6}” = “Statystyki ochrony WWW” -> {HKLM…CLSID} = “Statystyki ochrony WWW” \InProcServer32(Default) = “C:\Kaspersky Internet Security 6.0\scieplugin.dll” [“Kaspersky Lab”] “{363E9C24-C4C3-4116-81A4-6D86B459CBE3}” = “Pointstone Shredder Context Menu Shell Extension” -> {HKLM…CLSID} = “Pointstone Shredder Context Menu Shell Extension” \InProcServer32(Default) = “C:\PROGRA~1\COMMON~1\POINTS~1\Shredder\SDShlExt.dll” [“Pointstone Software, LLC”] “{0AF221E8-29B6-46EB-B420-DC696F042596}” = “Find and Recover deleted files on you Computer” -> {HKLM…CLSID} = “Find and Recover deleted files on you Computer” \InProcServer32(Default) = “D:\Uneraser\contmenu.dll” [null data] “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” = “WinRAR shell extension” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] “{C169E5F0-E2B3-41F3-B81A-7BA529CBE193}” = “ZipGenius Shell Extension” -> {HKLM…CLSID} = “ZipGenius Shell Extension” \InProcServer32(Default) = “D:\ZIPGEN~1\contmenu.dll” [“M.Dev Software”] “{2E5AC2E0-406D-11D4-86B3-FA5861508E25}” = “ZipGenius Zip InfoTip” -> {HKLM…CLSID} = “ZipGenius InfoTip” \InProcServer32(Default) = “D:\ZIPGEN~1\zgtips.dll” [“M.Dev Software”] “{310A0C95-EA11-42AE-A8E4-53E69E650310}” = “ZipGenius Drop handler” -> {HKLM…CLSID} = “ZipGenius Drag and Drop handler” \InProcServer32(Default) = “D:\ZIPGEN~1\DROPHA~1.DLL” [“M.Dev Software”] “{FE8D01BF-610A-4261-9C6E-32D65A42C907}” = “ZipGenius DnD Extract handler” -> {HKLM…CLSID} = “ZipGenius DnD Extract handler” \InProcServer32(Default) = “D:\ZIPGEN~1\ZGDRAG~1.DLL” [“M.Dev Software”] “{00000000-5736-4205-0100-781cd0e19f00}” = “Steganos Internet Anonym Pro 7” -> {HKLM…CLSID} = “Steganos Internet Anonym Pro 7” \InProcServer32(Default) = “c:\program files\steganos internet anonym pro 7\siapro7se.dll” [null data] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\ <> “AppInit_DLLs” = “C:\KASPER~1.0\adialhk.dll” [“Kaspersky Lab”] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ <> AtiExtEvent\DLLName = “Ati2evxx.dll” [“ATI Technologies Inc.”] <> klogon\DLLName = “C:\WINDOWS\system32\klogon.dll” [“Kaspersky Lab”] HKLM\Software\Classes\Folder\shellex\ColumnHandlers\ {F9DB5320-233E-11D1-9F84-707F02C10627}(Default) = “PDF Column Info” -> {HKLM…CLSID} = “PDF Shell Extension” \InProcServer32(Default) = “D:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll” [“Adobe Systems, Inc.”] HKLM\Software\Classes*\shellex\ContextMenuHandlers\ DAP_ShredMenu(Default) = “{BED4C38B-F765-45AC-8C56-613F76BBF43E}” -> {HKLM…CLSID} = “DAPMenuShellExt Class” \InProcServer32(Default) = “D:\PROGRA~1\DAP\PRIVAC~1\DAPCTX~1.DLL” [“Speedbit Ltd.”] Kaspersky Anti-Virus(Default) = “{dd230880-495a-11d1-b064-008048ec2fc5}” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “C:\Kaspersky Internet Security 6.0\ShellEx.dll” [“Kaspersky Lab”] Pointstone Shredder(Default) = “{363E9C24-C4C3-4116-81A4-6D86B459CBE3}” -> {HKLM…CLSID} = “Pointstone Shredder Context Menu Shell Extension” \InProcServer32(Default) = “C:\PROGRA~1\COMMON~1\POINTS~1\Shredder\SDShlExt.dll” [“Pointstone Software, LLC”] Steganos Internet Anonym Pro 7(Default) = “{00000000-5736-4205-0100-781cd0e19f00}” -> {HKLM…CLSID} = “Steganos Internet Anonym Pro 7” \InProcServer32(Default) = “c:\program files\steganos internet anonym pro 7\siapro7se.dll” [null data] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] ZipGenius 6(Default) = “{C169E5F0-E2B3-41F3-B81A-7BA529CBE193}” -> {HKLM…CLSID} = “ZipGenius Shell Extension” \InProcServer32(Default) = “D:\ZIPGEN~1\contmenu.dll” [“M.Dev Software”] HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ DAP_ShredMenu(Default) = “{BED4C38B-F765-45AC-8C56-613F76BBF43E}” -> {HKLM…CLSID} = “DAPMenuShellExt Class” \InProcServer32(Default) = “D:\PROGRA~1\DAP\PRIVAC~1\DAPCTX~1.DLL” [“Speedbit Ltd.”] DiskInternals_Uneraser(Default) = “{0AF221E8-29B6-46EB-B420-DC696F042596}” -> {HKLM…CLSID} = “Find and Recover deleted files on you Computer” \InProcServer32(Default) = “D:\Uneraser\contmenu.dll” [null data] Pointstone Shredder(Default) = “{363E9C24-C4C3-4116-81A4-6D86B459CBE3}” -> {HKLM…CLSID} = “Pointstone Shredder Context Menu Shell Extension” \InProcServer32(Default) = “C:\PROGRA~1\COMMON~1\POINTS~1\Shredder\SDShlExt.dll” [“Pointstone Software, LLC”] Steganos Internet Anonym Pro 7(Default) = “{00000000-5736-4205-0100-781cd0e19f00}” -> {HKLM…CLSID} = “Steganos Internet Anonym Pro 7” \InProcServer32(Default) = “c:\program files\steganos internet anonym pro 7\siapro7se.dll” [null data] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] ZipGenius 6(Default) = “{C169E5F0-E2B3-41F3-B81A-7BA529CBE193}” -> {HKLM…CLSID} = “ZipGenius Shell Extension” \InProcServer32(Default) = “D:\ZIPGEN~1\contmenu.dll” [“M.Dev Software”] HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ Kaspersky Anti-Virus(Default) = “{dd230880-495a-11d1-b064-008048ec2fc5}” -> {HKLM…CLSID} = (no title provided) \InProcServer32(Default) = “C:\Kaspersky Internet Security 6.0\ShellEx.dll” [“Kaspersky Lab”] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] Group Policies {GPedit.msc branch and setting}: ----------------------------------------------- Note: detected settings may not have any effect. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ “NoLowDiskSpaceChecks” = (REG_DWORD) hex:0x00000001 {unrecognized setting} HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\ “shutdownwithoutlogon” = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Shutdown: Allow system to be shut down without having to log on} “undockwithoutlogon” = (REG_DWORD) hex:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Devices: Allow undock without having to log on} Active Desktop and Wallpaper: ----------------------------- Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState Displayed if Active Desktop enabled and wallpaper not set by Group Policy: HKCU\Software\Microsoft\Internet Explorer\Desktop\General\ “Wallpaper” = “C:\Documents and Settings\NetworkService.ZARZĄDZANIE NT\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp” Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ “Wallpaper” = “C:\Documents and Settings\Łukasz.XXX-886A8B7CD27\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp” Enabled Screen Saver: --------------------- HKCU\Control Panel\Desktop\ “SCRNSAVE.EXE” = “C:\WINDOWS\system32\logon.scr” [MS] Startup items in “Łukasz” & “All Users” startup folders: -------------------------------------------------------- C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programy\Autostart “DSLMON” -> shortcut to: “C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe” [empty string] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] 000000000002\LibraryPath = “%SystemRoot%\System32\winrnr.dll” [MS] 000000000003\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: C:\Program Files\Secure Surfing Engine\sselsp.dll [null data], 01 - 03, 17 %SystemRoot%\system32\mswsock.dll [MS], 04 - 06, 09 - 16 %SystemRoot%\system32\rsvpsp.dll [MS], 07 - 08 Toolbars, Explorer Bars, Extensions: ------------------------------------ Toolbars HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ “{00000000-5736-4205-0008-781CD0E19F00}” -> {HKLM…CLSID} = “Steganos Internet Anonym” \InProcServer32(Default) = “c:\program files\steganos internet anonym pro 7\siapro7iep.dll” [null data] HKLM\Software\Microsoft\Internet Explorer\Toolbar\ “{00000000-5736-4205-0008-781CD0E19F00}” = (no title provided) -> {HKLM…CLSID} = “Steganos Internet Anonym” \InProcServer32(Default) = “c:\program files\steganos internet anonym pro 7\siapro7iep.dll” [null data] Explorer Bars HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\ HKLM\Software\Classes\CLSID{00000000-5736-4205-0009-781CD0E19F00}(Default) = “Prywatna lista ulubionych Steganos” Implemented Categories{00021493-0000-0000-C000-000000000046}\ [vertical bar] InProcServer32(Default) = “c:\program files\steganos internet anonym pro 7\siapro7iep.dll” [null data] HKLM\Software\Classes\CLSID{85E0B171-04FA-11D1-B7DA-00A0C90348D6}(Default) = “Statystyki ochrony WWW” Implemented Categories{00021493-0000-0000-C000-000000000046}\ [vertical bar] InProcServer32(Default) = “C:\Kaspersky Internet Security 6.0\scieplugin.dll” [“Kaspersky Lab”] Extensions (Tools menu items, main toolbar menu buttons) HKLM\Software\Microsoft\Internet Explorer\Extensions\ {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ “MenuText” = “Sun Java Console” “CLSIDExtension” = “{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}” -> {HKCU…CLSID} = “Java Plug-in 1.5.0_11” \InProcServer32(Default) = “C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll” [“Sun Microsystems, Inc.”] -> {HKLM…CLSID} = “Java Plug-in 1.5.0_11” \InProcServer32(Default) = “C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll” [“Sun Microsystems, Inc.”] {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E}\ “ButtonText” = “Statystyki ochrony WWW” {FB5F1910-F110-11D2-BB9E-00C04F795683}\ “ButtonText” = “Messenger” “MenuText” = “Windows Messenger” “Exec” = “C:\Program Files\Messenger\msmsgs.exe” [MS] Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ Kaspersky Internet Security 6.0, AVP, ““C:\Kaspersky Internet Security 6.0\avp.exe” -r” [“Kaspersky Lab”] ---------- <>: Suspicious data at a malware launch point. + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + The search for DESKTOP.INI DLL launch points on all local fixed drives took 43 seconds. ---------- (total run time: 87 seconds)
adam9870
(adam9870)
7 Kwiecień 2007 09:56
#4
Start => uruchom => wpisz regedit i kliknij OK => przejdź do klucza:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
i skasuj z prawokliku znajdującą się tam wartość megauploadtoolbar
Użyj programu ATF Cleaner i przeczyść Current User Temp oraz All Users Temp .
Możesz przeskanować system skanerem on-line dostępnym na stronie:
http://www.ewido.net/en/onlinescan/
Zajrzyj tutaj:
http://portal.centrumxp.pl/forums/thread/169899.aspx
i przeczytaj punkt “explorer.exe 100% CPU” oraz “svchost.exe 100% CPU”.
rlk120
(Rlk120)
7 Kwiecień 2007 10:16
#5
adam9870 dzięki za pomoc,
Nie mogę znaleźć Activex dla mojej przeglądarki, na innych też nie działa.
Na razie sobie daruje, głównie chodziło mi o prędkość ściągania ale dziękuje, już sobie poradzę(chyba)