Wysokie użycie procesora

Witam jestem tu nowy i mam taki problem, otóż procesor od jakiegoś czasy pracuje w granicach 60-100%, a wcześniej pracował w granicach 0-12% :frowning:

Log:

http://wklej.org/id/8a3ae40f3c

CTRL+alt+del zakładka procesy i napisz jaki proces używa najwięcej CPU

taskmgr.exe 43%

exploer.exe 43%

Usuń te wpisy w HJT

Uruchom HijackThis - Do a system scan only - w oknie programu pokaże się log - zaznacz kratki przy podanych wpisach - klikasz Fix checked

Pobierz Combofix przeskanuj system i daj log na forum

Chyba sobie odpuszczę najwyżej przeinstaluje system ojciec by mnie zatłukł jak bym zepsuł kompa :?

Ale przed tym mozesz spróbowac naprawić go, więc daj logi o jakie prosimy

Oj Chyba z tymi logami nic nie będzie bo jak włączyłem Combofixa to zamiast czekać 10min czekałem 20 i zrestartowałem kompa, a jak się ucieszyłem, że windows się włączył :smiley: Więc dzięki za pomoc ale nie skorzystam.

Podaj log z pliku main.txt z Deckard’s System Scanner

No niech Ci będzie

Deckard's System Scanner v20071014.68

Run by ireneusz on 2008-07-22 14:36:19

Computer is in Normal Mode.

--------------------------------------------------------------------------------


-- System Restore --------------------------------------------------------------


Successfully created a Deckard's System Scanner Restore Point.



-- Last 5 Restore Point(s) --

10: 2008-07-22 12:36:39 UTC - RP293 - Deckard's System Scanner Restore Point

9: 2008-07-22 11:37:54 UTC - RP292 - ComboFix created restore point

8: 2008-07-22 08:11:48 UTC - RP291 - ComboFix created restore point

7: 2008-07-21 19:37:42 UTC - RP290 - Installed Ad-Aware

6: 2008-07-21 19:33:03 UTC - RP289 - Removed Ad-Aware 2007



-- First Restore Point -- 

1: 2008-07-21 18:28:07 UTC - RP284 - Operacja przywracania



Backed up registry hives.

Performed disk cleanup.




-- HijackThis (run as ireneusz.exe) --------------------------------------------


Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 14:37, on 2008-07-22

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal


Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe

C:\Program Files\Eset\nod32kui.exe

C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe

C:\Program Files\Logitech\QuickCam10\QuickCam10.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe

C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

C:\Program Files\Eset\nod32krn.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe

C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe

C:\Documents and Settings\ireneusz\Pulpit\dss.exe

C:\PROGRA~1\TRENDM~1\HIJACK~1\ireneusz.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll

O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE

O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Vistadrv] C:\Documents and Settings\JACHIN\Pulpit\Paczka\Vistadrive\vsdrv.exe

O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"

O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide

O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"

O4 - HKCU\..\Run: [Odkurzacz-MCD] D:\Programy\Odkurzacz 10.1 Pro\odk_mcd.exe

O4 - HKCU\..\Run: [UberIcon] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe"

O4 - HKCU\..\Run: [Yodm3D] C:\Documents and Settings\ireneusz\Pulpit\yodm3D(dobreprogramy.pl)\Yodm3D.exe

O4 - HKCU\..\Run: [CubeDesktop] C:\Program Files\CubeDesktop\CubeDesktop.exe

O4 - HKCU\..\Run: [LogitechSetup] I:\Setup\Setup.exe /start /restart /l:enu

O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')

O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_02] rundll32 advpack.dll,DelNodeRunDLL32 "%SystemRoot%\System32\dllcache" (User 'USŁUGA LOKALNA')

O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_04] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'USŁUGA LOKALNA')

O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_05] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'USŁUGA LOKALNA')

O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_06] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'USŁUGA LOKALNA')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')

O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_02] rundll32 advpack.dll,DelNodeRunDLL32 "%SystemRoot%\System32\dllcache" (User 'USŁUGA SIECIOWA')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')

O4 - S-1-5-18 Startup: Thoosje Vista Sidebar.lnk = C:\Program Files\Thoosje Sidebar V2.3\Thoosje Vista Sidebar.exe (User 'SYSTEM')

O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')

O4 - .DEFAULT Startup: Thoosje Vista Sidebar.lnk = C:\Program Files\Thoosje Sidebar V2.3\Thoosje Vista Sidebar.exe (User 'Default user')

O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Startup: Thoosje Vista Sidebar.lnk = C:\Program Files\Thoosje Sidebar V2.3\Thoosje Vista Sidebar.exe

O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.15\AMVConverter\grab.html

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.15\MediaManager\grab.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://F:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O18 - Protocol: bw+0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw+0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw-0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw-0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw00 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw00s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw10 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw10s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw20 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw20s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw30 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw30s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw40 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw40s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw50 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw50s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw60 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw60s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw70 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw70s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw80 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw80s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw90 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw90s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwa0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwa0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwb0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwb0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwc0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwc0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwd0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwd0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwe0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwe0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwf0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwf0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O18 - Protocol: bwg0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwg0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwh0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwh0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwi0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwi0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwj0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwj0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwk0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwk0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwl0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwl0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwm0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwm0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwn0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwn0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwo0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwo0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwp0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwp0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwq0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwq0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwr0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwr0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bws0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bws0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwt0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwt0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwu0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwu0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwv0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwv0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bww0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bww0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwx0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwx0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwy0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwy0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwz0 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwz0s - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: offline-8876480 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe

O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Program Files\Eset\nod32krn.exe

O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

O24 - Desktop Component 0: (no name) - http://google.pl/


--

End of file - 19505 bytes


-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------


backup-20080722-100612-427 O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Ustawienia lokalne\Temp" (User 'USŁUGA SIECIOWA')

backup-20080722-100612-510 O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Ustawienia lokalne\Temp" (User 'USŁUGA LOKALNA')


-- File Associations -----------------------------------------------------------


[COLOR=red].cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*[/COLOR]

[COLOR=red].cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*[/COLOR]

[COLOR=red].reg - regfile - shell\open\command - "regedit.exe" "%1"[/COLOR]



-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------


R0 prohlp02 (StarForce Protection Helper Driver v2) - c:\windows\system32\drivers\prohlp02.sys 

R0 prosync1 (StarForce Protection Synchronization Driver v1) - c:\windows\system32\drivers\prosync1.sys 

R0 sfhlp01 (StarForce Protection Helper Driver) - c:\windows\system32\drivers\sfhlp01.sys 

R0 VirtualK (VirtaulK) - c:\windows\system32\drivers\virtualk.sys 

R1 cdrbsdrv - c:\windows\system32\drivers\cdrbsdrv.sys 

R1 oreans32 - c:\windows\system32\drivers\oreans32.sys

R1 prodrv06 (StarForce Protection Environment Driver v6) - c:\windows\system32\drivers\prodrv06.sys 

R2 AMON - c:\windows\system32\drivers\amon.sys 

R3 GMFilter (GMFilter HID Filter Driver) - c:\windows\system32\drivers\gmfilter.sys

R3 skbusenum (SKBus Enumerator) - c:\windows\system32\drivers\skbusenum.sys 


S1 InCDPass - c:\windows\system32\drivers\incdpass.sys (file missing)

S1 InCDRm (InCD Reader) - c:\windows\system32\drivers\incdrm.sys (file missing)

S2 nvcap (nVidia WDM Video Capture (universal)) - c:\windows\system32\drivers\nvcap.sys (file missing)

S2 NVXBAR (nVidia WDM A/V Crossbar) - c:\windows\system32\drivers\nvxbar.sys (file missing)

S3 catchme - c:\combofix\catchme.sys (file missing)

S3 gggen (Generic USB Flash Driver) - c:\windows\system32\drivers\gggen.sys 

S3 pcouffin (VSO Software pcouffin) - c:\windows\system32\drivers\pcouffin.sys 

S4 InCDFs (InCD File System) - c:\windows\system32\drivers\incdfs.sys (file missing)



-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------


S3 ServiceLayer - "c:\program files\pc connectivity solution\servicelayer.exe" 

S4 gusvc (Google Updater Service) - "c:\program files\google\common\google updater\googleupdaterservice.exe" (file missing)



-- Device Manager: Disabled ----------------------------------------------------


No disabled devices found.



-- Scheduled Tasks -------------------------------------------------------------


2008-07-20 09:00:01 386 --a------ C:\WINDOWS\Tasks\rpc.job



-- Files created between 2008-06-22 and 2008-07-22 -----------------------------


2020-09-30 15:01:41 114688 --a------ C:\WINDOWS\system32\nms32.dll

2020-09-30 15:01:41 245760 --a------ C:\WINDOWS\system32\imon.dll

2020-09-30 15:01:41 300048 --a------ C:\WINDOWS\system32\drivers\amon.sys 

2008-07-22 14:25:14 0 d--h----- C:\WINDOWS\system32\GroupPolicy

2008-07-22 13:35:53 422400 --a------ C:\WINDOWS\system32\CF373.exe 

2008-07-22 10:10:38 161792 --a------ C:\WINDOWS\swreg.exe 

2008-07-22 10:10:37 68096 --a------ C:\WINDOWS\zip.exe

2008-07-22 10:10:37 49152 --a------ C:\WINDOWS\VFind.exe

2008-07-22 10:10:37 212480 --a------ C:\WINDOWS\swxcacls.exe 

2008-07-22 10:10:37 136704 --a------ C:\WINDOWS\swsc.exe 

2008-07-22 10:10:37 98816 --a------ C:\WINDOWS\sed.exe

2008-07-22 10:10:37 80412 --a------ C:\WINDOWS\grep.exe

2008-07-22 10:10:37 89504 --a------ C:\WINDOWS\fdsv.exe 

2008-07-22 10:09:37 422400 --a------ C:\WINDOWS\system32\CF25494.exe 

2008-07-22 10:08:03 422400 --a------ C:\WINDOWS\system32\CF25187.exe 

2008-07-22 10:06:56 422400 --a------ C:\WINDOWS\system32\CF24965.exe 

2008-07-22 09:16:14 0 d-------- C:\Program Files\Trend Micro

2008-07-21 21:36:55 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard

2008-07-21 12:30:52 48 --ah----- C:\WINDOWS\system32\ezsidmv.dat

2008-07-21 12:29:04 0 d-------- C:\Program Files\Common Files\Skype

2008-07-20 14:33:48 0 d-------- C:\Program Files\Superfrog for Windows

2008-07-17 13:50:57 0 --a------ C:\WINDOWS\system32\0

2008-07-17 13:50:57 32 --a------ C:\WINDOWS\0

2008-07-12 19:49:48 0 d-------- C:\Program Files\Common Files\Logishrd

2008-07-12 19:49:46 0 d-------- C:\Program Files\Logitech

2008-06-23 10:07:10 0 d-------- C:\Program Files\Project64 1.6



-- Find3M Report ---------------------------------------------------------------


2008-07-22 14:05:00 0 d-------- C:\Program Files\Mozilla Firefox 3 Beta 3

2008-07-22 12:14:25 0 d-------- C:\Documents and Settings\ireneusz\Dane aplikacji\Skype

2008-07-22 10:27:32 0 d-------- C:\Documents and Settings\ireneusz\Dane aplikacji\skypePM

2008-07-21 21:37:44 0 d-------- C:\Program Files\Lavasoft

2008-07-21 21:36:55 0 d-------- C:\Program Files\Common Files

2008-07-21 21:29:35 0 d-------- C:\Program Files\Image-Line

2008-07-21 21:22:17 458022 --a------ C:\WINDOWS\system32\perfh015.dat

2008-07-21 21:22:17 79408 --a------ C:\WINDOWS\system32\perfc015.dat

2008-07-21 21:15:31 0 d-------- C:\Program Files\VstPlugins

2008-07-21 20:20:34 737280 --a------ C:\WINDOWS\iun6002.exe 

2008-07-20 15:34:21 0 d-------- C:\Program Files\AIMP2

2008-07-13 13:57:04 0 d-------- C:\Program Files\Mozilla Thunderbird

2008-07-12 19:55:57 0 d--h----- C:\Program Files\InstallShield Installation Information

2008-07-12 19:49:51 0 d-------- C:\Program Files\Common Files\Logitech

2008-06-20 16:48:53 0 d-------- C:\Program Files\Outsim

2008-06-13 13:16:23 0 d-------- C:\Program Files\Sony Ericsson

2008-05-31 15:46:47 0 d-------- C:\Program Files\GermaniX Transcoder

2008-05-31 14:47:10 0 d-------- C:\Program Files\Red Kawa

2008-05-26 19:22:53 0 d-------- C:\Program Files\OLYMPUS

2008-05-26 19:15:09 0 d-------- C:\Documents and Settings\ireneusz\Dane aplikacji\Adobe

2008-05-26 18:20:44 0 d-------- C:\Program Files\Common Files\Adobe

2008-05-26 18:16:58 0 d-------- C:\Program Files\Common Files\Adobe Systems Shared

2008-05-22 15:52:13 345 --a------ C:\Documents and Settings\ireneusz\Dane aplikacji\NMM-MetaData.db

2008-05-19 16:23:04 67616 --a------ C:\WINDOWS\unTMV.exe



-- Registry Dump ---------------------------------------------------------------


*Note* empty entries & legit default entries are not shown



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SoundMan"="SOUNDMAN.EXE" [2004-12-22 11:09 C:\WINDOWS\SOUNDMAN.EXE]

"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-10-10 15:49]

"nwiz"="nwiz.exe" [2005-10-10 15:49 C:\WINDOWS\system32\nwiz.exe]

"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-10-10 15:49]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]

"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-08-26 13:18]

"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" []

"NWEReboot"="" []

"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]

"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2020-09-30 15:00]

"@"="" []

"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 17:17]

"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 14:06]

"Vistadrv"="C:\Documents and Settings\JACHIN\Pulpit\Paczka\Vistadrive\vsdrv.exe" []

"LogitechCommunicationsManager"="C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-10-31 01:03]

"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" [2006-11-15 21:58]

"LVCOMSX"="C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-11-15 22:01]


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Odkurzacz-MCD"="D:\Programy\Odkurzacz 10.1 Pro\odk_mcd.exe" []

"UberIcon"="C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe" []

"Yodm3D"="C:\Documents and Settings\ireneusz\Pulpit\yodm3D(dobreprogramy.pl)\Yodm3D.exe" []

"CubeDesktop"="C:\Program Files\CubeDesktop\CubeDesktop.exe" []

"LogitechSetup"="I:\Setup\Setup.exe" []

"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2008-07-12 19:56]


C:\Documents and Settings\ireneusz\Menu Start\Programy\Autostart\

Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]

"disableregistrytools"=0 (0x0)


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"EditLevel"=0 (0x0)

"NoRun"=0 (0x0)

"NoClose"=0 (0x0)

"NoSaveSettings"=0 (0x0)

"NoFileMenu"=0 (0x0)

"NoCommonGroups"=0 (0x0)


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

@="Service"


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]

@="Service"


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"rpcapd"=3 (0x3)

"NVSvc"=2 (0x2)

"LVSrvLauncher"=2 (0x2)

"gusvc"=3 (0x3)

"Adobe LM Service"=3 (0x3)

"aawservice"=2 (0x2)



[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a267e037-bac5-11dc-8a4d-0014858fb418}]

AutoRun\command- G:\Autorun.exe


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a267e038-bac5-11dc-8a4d-0014858fb418}]

AutoRun\command- H:\RunGame.exe


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a267e039-bac5-11dc-8a4d-0014858fb418}]

AutoRun\command- J:\RunGame.exe


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a267e03a-bac5-11dc-8a4d-0014858fb418}]

AutoRun\command- K:\RunGame.exe





-- End of Deckard's System Scanner: finished at 2008-07-22 14:38:46 ------------

Pobierz The Avenger

wklej do niego ten tekst:

Files to delete:

C:\WINDOWS\system32\0

C:\WINDOWS\0

C:\WINDOWS\swsc.exe

C:\WINDOWS\sed.exe

C:\WINDOWS\grep.exe

C:\WINDOWS\fdsv.exe

kopiuj to i klikasz na Paste Script from Clipboard wybierasz Execute oraz Potwierdzasz i zgadzasz się na restart klikając OK.

Kasujesz ręcznie z dysku plik: C:\Avenger\backup.zip i wklejasz na forum raport: C:\avenger.txt

otwórz notatnik i wklej

Z menu Notatnika -> Plik -> Zapisz jako -> Zmień rozszerzenie z .txt na wszystkie pliki -> zapisz pod nazwą Fix.reg

Uruchom ten plik, uruchom ponownie komputer

raport:

Logfile of The Avenger Version 2.0, (c) by Swandog46

http://swandog46.geekstogo.com


Platform: Windows XP


*******************


Script file opened successfully.

Script file read successfully.


Backups directory opened successfully at C:\Avenger


*******************


Beginning to process script file:


Rootkit scan active.

No rootkits found!


File "C:\WINDOWS\system32\0" deleted successfully.

File "C:\WINDOWS\0" deleted successfully.

File "C:\WINDOWS\swsc.exe" deleted successfully.

File "C:\WINDOWS\sed.exe" deleted successfully.

File "C:\WINDOWS\grep.exe" deleted successfully.

File "C:\WINDOWS\fdsv.exe" deleted successfully.


Completed script processing.


*******************


Finished! Terminate.

Daj nowy log z Deckard

Log

Deckard's System Scanner v20071014.68

Run by ireneusz on 2008-07-22 15:01:26

Computer is in Normal Mode.

--------------------------------------------------------------------------------




-- HijackThis Clone ------------------------------------------------------------



Emulating logfile of Trend Micro HijackThis v2.0.2

Scan saved at 2008-07-22 15:02:12

Platform: Windows XP Dodatek Service Pack 2 (5.01.2600)

MSIE: Internet Explorer (6.00.2900.2180)

Boot mode: Normal


Running processes:

C:\WINDOWS\system32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcSrv.exe

C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe

C:\Program Files\ESET\nod32kui.exe

C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe

C:\Program Files\ESET\nod32krn.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe

C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe

C:\Documents and Settings\ireneusz\Pulpit\dss.exe


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll

O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE

O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Vistadrv] C:\Documents and Settings\JACHIN\Pulpit\Paczka\Vistadrive\vsdrv.exe

O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"

O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide

O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"

O4 - HKCU\..\Run: [Odkurzacz-MCD] D:\Programy\Odkurzacz 10.1 Pro\odk_mcd.exe

O4 - HKCU\..\Run: [UberIcon] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe"

O4 - HKCU\..\Run: [Yodm3D] C:\Documents and Settings\ireneusz\Pulpit\yodm3D(dobreprogramy.pl)\Yodm3D.exe

O4 - HKCU\..\Run: [CubeDesktop] C:\Program Files\CubeDesktop\CubeDesktop.exe

O4 - HKCU\..\Run: [LogitechSetup] I:\Setup\Setup.exe /start /restart /l:enu

O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_02] rundll32 advpack.dll,DelNodeRunDLL32 "%SystemRoot%\System32\dllcache" (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] cmd.exe /c md "%SystemRoot%\System32\dllcache" (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_04] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_05] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_06] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_02] rundll32 advpack.dll,DelNodeRunDLL32 "%SystemRoot%\System32\dllcache" (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_03] cmd.exe /c md "%SystemRoot%\System32\dllcache" (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_04] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_05] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_06] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Startup: Thoosje Vista Sidebar.lnk = C:\Program Files\Thoosje Sidebar V2.3\Thoosje Vista Sidebar.exe

O4 - Global Startup: Logitech Desktop Messenger.lnk = ?

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.15\AMVConverter\grab.html

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.15\MediaManager\grab.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://F:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: imon.dllO10 - Unknown file in Winsock LSP: imon.dllO10 - Unknown file in Winsock LSP: imon.dllO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

O18 - Protocol: bw+0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw+0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw-0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw-0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw00 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw00s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw10 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw10s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw20 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw20s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw30 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw30s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw40 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw40s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw50 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw50s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw60 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw60s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw70 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw70s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw80 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw80s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw90 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw90s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwa0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwa0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwb0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwb0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwc0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwc0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwd0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwd0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwe0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwe0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwf0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwf0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O18 - Protocol: bwg0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwg0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwh0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwh0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwi0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwi0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwj0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwj0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwk0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwk0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwl0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwl0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwm0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwm0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwn0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwn0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwo0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwo0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwp0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwp0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwq0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwq0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwr0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwr0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bws0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bws0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwt0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwt0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwu0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwu0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwv0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwv0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bww0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bww0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwx0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwx0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwy0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwy0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwz0 - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwz0s - {760429b2-131d-4ddf-9ced-67a16fe086b3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: offline-8876480 - {760429B2-131D-4DDF-9CED-67A16FE086B3} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcSrv.exe

O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe

O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Program Files\ESET\nod32krn.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe

O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

O24 - Desktop Component 0: - http://google.pl/


--

End of file - 23969 bytes


-- Files created between 2008-06-22 and 2008-07-22 -----------------------------


2020-09-30 15:01:41 114688 --a------ C:\WINDOWS\system32\nms32.dll

2020-09-30 15:01:41 245760 --a------ C:\WINDOWS\system32\imon.dll

2020-09-30 15:01:41 300048 --a------ C:\WINDOWS\system32\drivers\amon.sys 

2008-07-22 14:25:14 0 d--h----- C:\WINDOWS\system32\GroupPolicy

2008-07-22 13:35:53 422400 --a------ C:\WINDOWS\system32\CF373.exe 

2008-07-22 10:10:38 161792 --a------ C:\WINDOWS\swreg.exe 

2008-07-22 10:10:37 68096 --a------ C:\WINDOWS\zip.exe

2008-07-22 10:10:37 49152 --a------ C:\WINDOWS\VFind.exe

2008-07-22 10:10:37 212480 --a------ C:\WINDOWS\swxcacls.exe 

2008-07-22 10:09:37 422400 --a------ C:\WINDOWS\system32\CF25494.exe 

2008-07-22 10:08:03 422400 --a------ C:\WINDOWS\system32\CF25187.exe 

2008-07-22 10:06:56 422400 --a------ C:\WINDOWS\system32\CF24965.exe 

2008-07-21 21:36:55 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard

2008-07-21 12:30:52 48 --ah----- C:\WINDOWS\system32\ezsidmv.dat

2008-07-21 12:29:04 0 d-------- C:\Program Files\Common Files\Skype

2008-07-20 14:33:48 0 d-------- C:\Program Files\Superfrog for Windows

2008-07-12 19:49:48 0 d-------- C:\Program Files\Common Files\Logishrd

2008-07-12 19:49:46 0 d-------- C:\Program Files\Logitech

2008-06-23 10:07:10 0 d-------- C:\Program Files\Project64 1.6



-- Find3M Report ---------------------------------------------------------------


2008-07-22 15:00:10 0 d-------- C:\Program Files\Mozilla Firefox 3 Beta 3

2008-07-22 12:14:25 0 d-------- C:\Documents and Settings\ireneusz\Dane aplikacji\Skype

2008-07-22 10:27:32 0 d-------- C:\Documents and Settings\ireneusz\Dane aplikacji\skypePM

2008-07-21 21:37:44 0 d-------- C:\Program Files\Lavasoft

2008-07-21 21:36:55 0 d-------- C:\Program Files\Common Files

2008-07-21 21:29:35 0 d-------- C:\Program Files\Image-Line

2008-07-21 21:22:17 458022 --a------ C:\WINDOWS\system32\perfh015.dat

2008-07-21 21:22:17 79408 --a------ C:\WINDOWS\system32\perfc015.dat

2008-07-21 21:15:31 0 d-------- C:\Program Files\VstPlugins

2008-07-21 20:20:34 737280 --a------ C:\WINDOWS\iun6002.exe 

2008-07-20 15:34:21 0 d-------- C:\Program Files\AIMP2

2008-07-13 13:57:04 0 d-------- C:\Program Files\Mozilla Thunderbird

2008-07-12 19:55:57 0 d--h----- C:\Program Files\InstallShield Installation Information

2008-07-12 19:49:51 0 d-------- C:\Program Files\Common Files\Logitech

2008-06-20 16:48:53 0 d-------- C:\Program Files\Outsim

2008-06-13 13:16:23 0 d-------- C:\Program Files\Sony Ericsson

2008-05-31 15:46:47 0 d-------- C:\Program Files\GermaniX Transcoder

2008-05-31 14:47:10 0 d-------- C:\Program Files\Red Kawa

2008-05-26 19:22:53 0 d-------- C:\Program Files\OLYMPUS

2008-05-26 19:15:09 0 d-------- C:\Documents and Settings\ireneusz\Dane aplikacji\Adobe

2008-05-26 18:20:44 0 d-------- C:\Program Files\Common Files\Adobe

2008-05-26 18:16:58 0 d-------- C:\Program Files\Common Files\Adobe Systems Shared

2008-05-22 15:52:13 345 --a------ C:\Documents and Settings\ireneusz\Dane aplikacji\NMM-MetaData.db

2008-05-19 16:23:04 67616 --a------ C:\WINDOWS\unTMV.exe



-- Registry Dump ---------------------------------------------------------------


*Note* empty entries & legit default entries are not shown



[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SoundMan"="SOUNDMAN.EXE" [2004-12-22 11:09 C:\WINDOWS\SOUNDMAN.EXE]

"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-10-10 15:49]

"nwiz"="nwiz.exe" [2005-10-10 15:49 C:\WINDOWS\system32\nwiz.exe]

"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-10-10 15:49]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]

"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-08-26 13:18]

"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" []

"NWEReboot"="" []

"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]

"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2020-09-30 15:00]

"@"="" []

"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 17:17]

"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 14:06]

"Vistadrv"="C:\Documents and Settings\JACHIN\Pulpit\Paczka\Vistadrive\vsdrv.exe" []

"LogitechCommunicationsManager"="C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-10-31 01:03]

"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" [2006-11-15 21:58]

"LVCOMSX"="C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-11-15 22:01]


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Odkurzacz-MCD"="D:\Programy\Odkurzacz 10.1 Pro\odk_mcd.exe" []

"UberIcon"="C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe" []

"Yodm3D"="C:\Documents and Settings\ireneusz\Pulpit\yodm3D(dobreprogramy.pl)\Yodm3D.exe" []

"CubeDesktop"="C:\Program Files\CubeDesktop\CubeDesktop.exe" []

"LogitechSetup"="I:\Setup\Setup.exe" []

"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2008-07-12 19:56]


C:\Documents and Settings\ireneusz\Menu Start\Programy\Autostart\

Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]

"disableregistrytools"=0 (0x0)


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"EditLevel"=0 (0x0)

"NoRun"=0 (0x0)

"NoClose"=0 (0x0)

"NoSaveSettings"=0 (0x0)

"NoFileMenu"=0 (0x0)

"NoCommonGroups"=0 (0x0)


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

@="Service"


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]

@="Service"


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"rpcapd"=3 (0x3)

"NVSvc"=2 (0x2)

"LVSrvLauncher"=2 (0x2)

"gusvc"=3 (0x3)

"Adobe LM Service"=3 (0x3)

"aawservice"=2 (0x2)





-- End of Deckard's System Scanner: finished at 2008-07-22 15:03:03 ------------

Aha i mam pytanie czy z moimi logami jest coś nie tak?

I zauważyłem jeszcze to że chyba mam rozwalony licznik wykorzystania CPU bo ciągle pokazuje mi 100% albo nic się nie wyświetla