Mam następujący problem, od pewnego czasu system działa dosyć opieszale a zaraz po starcie pojawia się okienko systemowe informujące o tym, iż nie można się połączyć z internetem, gdyż nieprawidłowy użytkownik i hasło… Wygląda na to, że coś wymusza modemowe połączenie z internetem, gdyż nigdy nie starałem się nawet automatycznego połączenia wprowadzać…
Log jest następujący:
Logfile of HijackThis v1.99.1 Scan saved at 21:50:06, on 2006-06-16 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: E:\WINXP\System32\smss.exe E:\WINXP\system32\winlogon.exe E:\WINXP\system32\services.exe E:\WINXP\system32\lsass.exe E:\WINXP\system32\svchost.exe E:\WINXP\System32\svchost.exe E:\WINXP\system32\spoolsv.exe E:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe E:\Program Files\Trend Micro\Internet Security\tmproxy.exe E:\WINXP\Explorer.EXE E:\Program Files\Trend Micro\Internet Security\PccPfw.exe E:\Program Files\EPoX\USDM\USDM.EXE E:\Program Files\Trend Micro\Internet Security\pccguide.exe E:\Program Files\Trend Micro\Internet Security\PCClient.exe E:\Program Files\Trend Micro\Internet Security\TMOAgent.exe E:\WINXP\System32\CTHELPER.EXE E:\PROGRA~1\NEOSTR~1\CnxMon.exe E:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe E:\PROGRA~1\NEOSTR~1\taskbaricon.exe E:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe E:\WINXP\System32\ctfmon.exe E:\Program Files\Konnekt\konnekt.exe E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe E:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe C:\Program Files\Fic_Products\DoctorTweak XP\DrTweakXP.exe E:\PROGRA~1\NEOSTR~1\NeostradaTP.exe E:\PROGRA~1\NEOSTR~1\ComComp.exe E:\PROGRA~1\NEOSTR~1\Watch.exe E:\Program Files\AntiVir PersonalEdition Classic\avguard.exe E:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe E:\Program Files\AntiVir PersonalEdition Classic\sched.exe E:\Program Files\AntiVir PersonalEdition Classic\avcenter.exe E:\Program Files\AntiVir PersonalEdition Classic\avscan.exe E:\Program Files\Mozilla Firefox\firefox.exe E:\Documents and Settings\Błazej\Pulpit\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neostrada.pl R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada TP R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - E:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINXP\System32\msdxm.ocx O4 - HKLM…\Run: [NeroCheck] E:\WINXP\System32\NeroCheck.exe O4 - HKLM…\Run: [EPoXUSDM] “E:\Program Files\EPoX\USDM\USDM.EXE” “5000” O4 - HKLM…\Run: [pccguide.exe] “E:\Program Files\Trend Micro\Internet Security\pccguide.exe” O4 - HKLM…\Run: [PCClient.exe] “E:\Program Files\Trend Micro\Internet Security\PCClient.exe” O4 - HKLM…\Run: [TM Outbreak Agent] “E:\Program Files\Trend Micro\Internet Security\TMOAgent.exe” /run O4 - HKLM…\Run: [WINDVDPatch] CTHELPER.EXE O4 - HKLM…\Run: [Jet Detection] “E:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe” O4 - HKLM…\Run: [CTStartup] E:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run O4 - HKLM…\Run: [WooCnxMon] E:\PROGRA~1\NEOSTR~1\CnxMon.exe O4 - HKLM…\Run: [speedTouch USB Diagnostics] “E:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe” /icon O4 - HKLM…\Run: [WOOWATCH] E:\PROGRA~1\NEOSTR~1\Watch.exe O4 - HKLM…\Run: [WOOTASKBARICON] E:\PROGRA~1\NEOSTR~1\taskbaricon.exe O4 - HKLM…\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM…\Run: [AtiPTA] atiptaxx.exe O4 - HKLM…\Run: [sunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_05\bin\jusched.exe O4 - HKLM…\Run: [updReg] E:\WINXP\UpdReg.EXE O4 - HKLM…\Run: [statusClient] E:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto O4 - HKLM…\Run: [TomcatStartup] E:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe O4 - HKLM…\Run: [DXDllRegExe] E:\WINXP\System32\dxdllreg.exe O4 - HKCU…\Run: [CTFMON.EXE] E:\WINXP\System32\ctfmon.exe O4 - HKCU…\Run: [Konnekt] “E:\Program Files\Konnekt\konnekt.exe” /autostart O4 - HKCU…\Run: [spybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU…\Run: [shell] “E:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00019.exe” O4 - HKCU…\Run: [Windows installer] C:\winstall.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office\OSA9.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll O17 - HKLM\System\CCS\Services\Tcpip…{8CE23585-D09F-4D5B-8A24-C5A56229DCFC}: NameServer = 194.204.152.34 217.98.63.164 O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - E:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - E:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Trend Micro Personal Firewall (PccPfw) - Trend Micro Incorporated. - E:\Program Files\Trend Micro\Internet Security\PccPfw.exe O23 - Service: Pml Driver HPZ12 - HP - E:\WINXP\System32\HPZipm12.exe O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - E:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - E:\Program Files\Trend Micro\Internet Security\tmproxy.exe
Bieniol
(Bbieniol)
16 Czerwiec 2006 19:59
#2
W trybie awaryjnym z wyłączonym przywracaniem systemu usuwasz (wpisy Hijackiem, pliki/foldery na czerwono ręcznie z dysku (w razie problemów z usuwaniem plików użyj narzędzia KillBox ):
Po zabiegach nowy log z Hijacka + log z Silent Runners
Więc tak, zrobiłem jak kazałeś, z tym że tych plików nie było już, prawdopodobnie skasowałem je już dawno temu podczas jakiejś wcześniejszej infekcji. Mimo to nadal wyskakuje połączenie z neostradą, okienko systemowe… no ale zapodaję logami
HiJack
Logfile of HijackThis v1.99.1 Scan saved at 22:21:25, on 2006-06-16 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: E:\WINXP\System32\smss.exe E:\WINXP\system32\winlogon.exe E:\WINXP\system32\services.exe E:\WINXP\system32\lsass.exe E:\WINXP\system32\svchost.exe E:\WINXP\System32\svchost.exe E:\WINXP\Explorer.EXE E:\WINXP\system32\spoolsv.exe E:\Program Files\AntiVir PersonalEdition Classic\sched.exe E:\Program Files\EPoX\USDM\USDM.EXE E:\Program Files\Trend Micro\Internet Security\pccguide.exe E:\Program Files\Trend Micro\Internet Security\PCClient.exe E:\Program Files\Trend Micro\Internet Security\TMOAgent.exe E:\WINXP\System32\CTHELPER.EXE E:\PROGRA~1\NEOSTR~1\CnxMon.exe E:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe E:\PROGRA~1\NEOSTR~1\taskbaricon.exe E:\Program Files\AntiVir PersonalEdition Classic\avguard.exe E:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe E:\WINXP\System32\ctfmon.exe E:\Program Files\Konnekt\konnekt.exe E:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe E:\Program Files\Trend Micro\Internet Security\tmproxy.exe E:\Program Files\Trend Micro\Internet Security\PccPfw.exe E:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe E:\WINXP\System32\rasautou.exe E:\Documents and Settings\Błazej\Pulpit\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neostrada.pl R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada TP R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - E:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINXP\System32\msdxm.ocx O4 - HKLM…\Run: [NeroCheck] E:\WINXP\System32\NeroCheck.exe O4 - HKLM…\Run: [EPoXUSDM] “E:\Program Files\EPoX\USDM\USDM.EXE” “5000” O4 - HKLM…\Run: [pccguide.exe] “E:\Program Files\Trend Micro\Internet Security\pccguide.exe” O4 - HKLM…\Run: [PCClient.exe] “E:\Program Files\Trend Micro\Internet Security\PCClient.exe” O4 - HKLM…\Run: [TM Outbreak Agent] “E:\Program Files\Trend Micro\Internet Security\TMOAgent.exe” /run O4 - HKLM…\Run: [WINDVDPatch] CTHELPER.EXE O4 - HKLM…\Run: [Jet Detection] “E:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe” O4 - HKLM…\Run: [CTStartup] E:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run O4 - HKLM…\Run: [WooCnxMon] E:\PROGRA~1\NEOSTR~1\CnxMon.exe O4 - HKLM…\Run: [speedTouch USB Diagnostics] “E:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe” /icon O4 - HKLM…\Run: [WOOWATCH] E:\PROGRA~1\NEOSTR~1\Watch.exe O4 - HKLM…\Run: [WOOTASKBARICON] E:\PROGRA~1\NEOSTR~1\taskbaricon.exe O4 - HKLM…\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM…\Run: [AtiPTA] atiptaxx.exe O4 - HKLM…\Run: [sunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_05\bin\jusched.exe O4 - HKLM…\Run: [updReg] E:\WINXP\UpdReg.EXE O4 - HKLM…\Run: [statusClient] E:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto O4 - HKLM…\Run: [TomcatStartup] E:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe O4 - HKCU…\Run: [CTFMON.EXE] E:\WINXP\System32\ctfmon.exe O4 - HKCU…\Run: [Konnekt] “E:\Program Files\Konnekt\konnekt.exe” /autostart O4 - HKCU…\Run: [spybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office\OSA9.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - E:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - E:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Trend Micro Personal Firewall (PccPfw) - Trend Micro Incorporated. - E:\Program Files\Trend Micro\Internet Security\PccPfw.exe O23 - Service: Pml Driver HPZ12 - HP - E:\WINXP\System32\HPZipm12.exe O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - E:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - E:\Program Files\Trend Micro\Internet Security\tmproxy.exe
Silent Runners
“Silent Runners.vbs”, revision 45, http://www.silentrunners.org/ Operating System: Windows XP Output limited to non-default values, except where indicated by “{++}” Startup items buried in registry: --------------------------------- HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} “CTFMON.EXE” = “E:\WINXP\System32\ctfmon.exe” [MS] “Konnekt” = ““E:\Program Files\Konnekt\konnekt.exe” /autostart” [“Stamina”] “SpybotSD TeaTimer” = “E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe” [file not found] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} “NeroCheck” = “E:\WINXP\System32\NeroCheck.exe” [“Ahead Software Gmbh”] “EPoXUSDM” = "“E:\Program Files\EPoX\USDM\USDM.EXE” “5000"” [“EPoX COMPUTER CO.,LTD.”] “pccguide.exe” = ““E:\Program Files\Trend Micro\Internet Security\pccguide.exe”” [“Trend Micro Incorporated.”] “PCClient.exe” = ““E:\Program Files\Trend Micro\Internet Security\PCClient.exe”” [“Trend Micro Incorporated.”] “TM Outbreak Agent” = ““E:\Program Files\Trend Micro\Internet Security\TMOAgent.exe” /run” [“Trend Micro Incorporated.”] “WINDVDPatch” = “CTHELPER.EXE” [“Creative Technology Ltd”] “Jet Detection” = ““E:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe”” [empty string] “CTStartup” = “E:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run” [“Creative Technology Ltd.”] “WooCnxMon” = “E:\PROGRA~1\NEOSTR~1\CnxMon.exe” [empty string] “SpeedTouch USB Diagnostics” = ““E:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe” /icon” [“THOMSON Telecom Belgium”] “WOOWATCH” = “E:\PROGRA~1\NEOSTR~1\Watch.exe” [“France Télécom R&D”] “WOOTASKBARICON” = “E:\PROGRA~1\NEOSTR~1\taskbaricon.exe” [“France Télécom R&D”] “KernelFaultCheck” = “E:\WINXP\system32\dumprep 0 -k” [MS] “AtiPTA” = “atiptaxx.exe” [“ATI Technologies, Inc.”] “SunJavaUpdateSched” = “E:\Program Files\Java\jre1.5.0_05\bin\jusched.exe” [“Sun Microsystems, Inc.”] “UpdReg” = “E:\WINXP\UpdReg.EXE” [“Creative Technology Ltd.”] “StatusClient” = “E:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto” [“Hewlett-Packard”] “TomcatStartup” = “E:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe” [“Hewlett-Packard”] “(Default)” = (empty string) HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = (no title provided) -> {HKLM…CLSID} = “AcroIEHlprObj Class” \InProcServer32(Default) = “E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll” [“Adobe Systems Incorporated”] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ “{42071714-76d4-11d1-8b24-00a0c9068ff3}” = “Rozszerzenie CPL kadrowania wyświetlania” -> {HKLM…CLSID} = “Rozszerzenie CPL kadrowania wyświetlania” \InProcServer32(Default) = “deskpan.dll” [file not found] “{88895560-9AA2-1069-930E-00AA0030EBC8}” = “Rozszerzenie ikony HyperTerminalu” -> {HKLM…CLSID} = “HyperTerminal Icon Ext” \InProcServer32(Default) = “E:\WINXP\System32\hticons.dll” [“Hilgraeve, Inc.”] “{48F45200-91E6-11CE-8A4F-0080C81A28D4}” = “TMD Shell Extension” -> {HKLM…CLSID} = “TMD Shell Extension” \InProcServer32(Default) = “E:\Program Files\Trend Micro\Internet Security\Tmdshell.dll” [“Trend Micro Incorporated.”] “{771A9DA0-731A-11CE-993C-00AA004ADB6C}” = “VBPropSheet” -> {HKLM…CLSID} = “VBPropSheet” \InProcServer32(Default) = “E:\Program Files\Trend Micro\Internet Security\VBProp.dll” [“Trend Micro Incorporated.”] “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” = “WinRAR shell extension” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] “{45AC2688-0253-4ED8-97DE-B5370FA7D48A}” = “Shell Extension for Malware scanning” -> {HKLM…CLSID} = “Shell Extension for Malware scanning” \InProcServer32(Default) = “E:\Program Files\AntiVir PersonalEdition Classic\shlext.dll” [“H+BEDV Datentechnik GmbH”] HKLM\Software\Classes\Folder\shellex\ColumnHandlers\ {F9DB5320-233E-11D1-9F84-707F02C10627}(Default) = “PDF Column Info” -> {HKLM…CLSID} = “PDF Shell Extension” \InProcServer32(Default) = “E:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll” [“Adobe Systems, Inc.”] HKLM\Software\Classes*\shellex\ContextMenuHandlers\ Shell Extension for Malware scanning(Default) = “{45AC2688-0253-4ED8-97DE-B5370FA7D48A}” -> {HKLM…CLSID} = “Shell Extension for Malware scanning” \InProcServer32(Default) = “E:\Program Files\AntiVir PersonalEdition Classic\shlext.dll” [“H+BEDV Datentechnik GmbH”] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ Shell Extension for Malware scanning(Default) = “{45AC2688-0253-4ED8-97DE-B5370FA7D48A}” -> {HKLM…CLSID} = “Shell Extension for Malware scanning” \InProcServer32(Default) = “E:\Program Files\AntiVir PersonalEdition Classic\shlext.dll” [“H+BEDV Datentechnik GmbH”] WinRAR(Default) = “{B41DB860-8EE4-11D2-9906-E49FADC173CA}” -> {HKLM…CLSID} = “WinRAR” \InProcServer32(Default) = “C:\Program Files\WinRAR\rarext.dll” [null data] Active Desktop and Wallpaper: ----------------------------- Active Desktop is disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState HKCU\Control Panel\Desktop\ “Wallpaper” = “E:\Documents and Settings\Błazej\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp” Enabled Screen Saver: --------------------- HKCU\Control Panel\Desktop\ “SCRNSAVE.EXE” = “E:\WINXP\System32\logon.scr” [MS] Startup items in “Błazej” & “All Users” startup folders: -------------------------------------------------------- E:\Documents and Settings\All Users.WINXP\Menu Start\Programy\Autostart “Adobe Reader Speed Launch” -> shortcut to: “E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe” [“Adobe Systems Incorporated”] “Microsoft Office” -> shortcut to: “E:\Program Files\Microsoft Office\Office\OSA9.EXE -b -l” [MS] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] 000000000002\LibraryPath = “%SystemRoot%\System32\winrnr.dll” [MS] 000000000003\LibraryPath = “%SystemRoot%\System32\mswsock.dll” [MS] Transport Service Providers HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 17 %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05 Toolbars, Explorer Bars, Extensions: ------------------------------------ Explorer Bars Dormant Explorer Bars in “View, Explorer Bar” menu HKLM\Software\Classes\CLSID{01002DB2-8170-4D9B-A8B1-DDC9DD114E03}(Default) = “Volet Wanadoo” Implemented Categories{00021494-0000-0000-C000-000000000046}\ [horizontal bar] InProcServer32(Default) = “E:\PROGRA~1\NEOSTR~1\audience\audience.dll” [empty string] HKLM\Software\Classes\CLSID{3BAF4A27-C764-4E1A-A6F4-62F7A7E5E51C}(Default) = “ToolBand Class” Implemented Categories{00021494-0000-0000-C000-000000000046}\ [horizontal bar] InProcServer32(Default) = “E:\PROGRA~1\NEOSTR~1\audience\audience.dll” [empty string] HKLM\Software\Classes\CLSID{5BF498C0-931E-4A4F-B33F-456D07137EAA}(Default) = “Volet Wanadoo” Implemented Categories{00021494-0000-0000-C000-000000000046}\ [horizontal bar] InProcServer32(Default) = “E:\PROGRA~1\NEOSTR~1\audience\audience.dll” [empty string] Extensions (Tools menu items, main toolbar menu buttons) HKLM\Software\Microsoft\Internet Explorer\Extensions\ {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ “MenuText” = “Sun Java Console” “CLSIDExtension” = “{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}” -> {HKLM…CLSID} = “Java Plug-in 1.5.0_05” \InProcServer32(Default) = “E:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll” [“Sun Microsystems, Inc.”] Miscellaneous IE Hijack Points ------------------------------ HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\ Missing lines (compared with English-language version): “{08C06D61-F1F3-4799-86F8-BE1A89362C85}” = (no title provided) -> {HKLM…CLSID} = “Search Class” \InProcServer32(Default) = “E:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL” [empty string] Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ AntiVir PersonalEdition Classic Guard, AntiVirService, “E:\Program Files\AntiVir PersonalEdition Classic\avguard.exe” [“AVIRA GmbH”] AntiVir PersonalEdition Classic Scheduler, AntiVirScheduler, “E:\Program Files\AntiVir PersonalEdition Classic\sched.exe” [“Avira GmbH”] Trend Micro Personal Firewall, PccPfw, “E:\Program Files\Trend Micro\Internet Security\PccPfw.exe” [“Trend Micro Incorporated.”] Trend Micro Proxy Service, tmproxy, “E:\Program Files\Trend Micro\Internet Security\tmproxy.exe” [“Trend Micro Incorporated.”] Trend NT Realtime Service, Tmntsrv, ““E:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe”” [“Trend Micro Incorporated.”] Print Monitors: --------------- HKLM\System\CurrentControlSet\Control\Print\Monitors\ HP Master Monitor\Driver = “HPBMMON.DLL” [“Hewlett-Packard”] ---------- + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + The search for DESKTOP.INI DLL launch points on all local fixed drives took 115 seconds. + The search for all Registry CLSIDs containing dormant Explorer Bars took 11 seconds. ---------- (total run time: 206 seconds)
komp nadal się dławi
Bieniol
(Bbieniol)
16 Czerwiec 2006 20:28
#4
Logi są czyste
Proponuję zainstalować SP2
Przeczyść rejestr (polecam do tego jv16 PowerTools 1.3.0.195 ), zrób defragmentację, oraz przejrzyj: Optymalizacja XP
Wejdź: Start --> uruchom --> msconfig i w zakładce uruchamianie odznacz (według Ciebie) niepotrzbne przy autostarcie programy
hm… tak myślałem… że są czyste no nic… dziięki piękne… zaraz wezmę się za czyszczenie
Złączono Posta : 17.06.2006 (Sob) 11:43
cholerka… dalej to samo, komp wolny jak cholera i połączenie wyskakujące na początku… zajęte jest około 60-70% pamięci