Procek non stop chodzi na 100% !!!
Witam. Mam problem taki jak w tytule, procek non stop pracuje na 95-100%. Stało się to po tym jak zainstalowałem kartę wifi na PCMCIA. Mam celerona M 1,6Ghz, więc wątpię żeby był za wolny. Co może być tego powodem? Zamieszczam log z
programu ComboFix. Pozdrawiam
ComboFix 08-01-03.3 - Decewicz A&K 2008-01-04 18:20:03.2 - NTFSx86
Running from: C:\Documents and Settings\Decewicz A&K\Pulpit\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-04 to 2008-01-04 )))))))))))))))))))))))))))))))
.
2008-01-04 16:44 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-04 14:11 . 2008-01-04 14:11 d-------- C:\temp
2008-01-04 03:00 . 2007-12-04 15:44 23,600 --a------ C:\WINDOWS\system32\drivers\TVICHW32.SYS
2008-01-04 03:00 . 2008-01-04 03:00 1,609 --a------ C:\WINDOWS\mozver.dat
2008-01-04 01:22 . 2008-01-04 01:24 d-------- C:\Program Files\SysTool
2008-01-03 11:55 . 2007-05-29 13:55 22,112 --a------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-01-03 11:55 . 2007-05-29 13:55 10,592 --a------ C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-01-03 11:55 . 2007-05-29 13:55 705 --a------ C:\WINDOWS\system32\drivers\COH_Mon.inf
2007-12-31 00:22 . 2007-12-31 00:22 d-------- C:\Program Files\IrfanView
2007-12-28 19:26 . 2007-12-28 19:26 d-------- C:\WINDOWS\system32\LogFiles
2007-12-27 23:58 . 2007-12-27 23:58 d-------- C:\Program Files\Real Alternative
2007-12-25 17:51 . 2008-01-04 16:30 d-------- C:\Documents and Settings\Decewicz A&K\Dane aplikacji\skypePM
2007-12-25 17:51 . 2007-12-25 17:51 32 --a------ C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2007-12-25 17:48 . 2007-12-25 17:49 d-------- C:\Program Files\Skype
2007-12-25 17:48 . 2007-12-25 17:48 d-------- C:\Program Files\Common Files\Skype
2007-12-24 23:04 . 2007-12-24 23:04 d-------- C:\Program Files\Linksys
2007-12-24 23:04 . 2007-12-24 23:04 d-------- C:\Program Files\Funk Software
2007-12-24 23:04 . 2007-12-24 23:04 d-------- C:\Program Files\Common Files\Funk Software
2007-12-24 23:04 . 2002-02-02 00:00 1,497,088 --a------ C:\WINDOWS\system32\cc3260mt.dll
2007-12-24 23:04 . 2000-01-31 05:00 1,496,064 --a------ C:\WINDOWS\system32\cc3250mt.dll
2007-12-24 23:04 . 2004-03-10 21:54 385,536 --a------ C:\WINDOWS\system32\drivers\TNET1130x.sys
2007-12-24 23:04 . 2003-07-16 22:43 94,208 --a------ C:\WINDOWS\system32\W32N50CT.dll
2007-12-24 23:04 . 2004-03-10 21:13 84,644 --a------ C:\WINDOWS\system32\drivers\FwRad17.bin
2007-12-24 23:04 . 2004-03-10 21:13 83,024 --a------ C:\WINDOWS\system32\drivers\FwRad16.bin
2007-12-24 23:04 . 2003-05-14 16:01 62,673 -ra------ C:\WINDOWS\system32\drivers\odysseyIM3.sys
2007-12-24 23:04 . 2000-01-31 05:00 25,600 --a------ C:\WINDOWS\system32\borlndmm.dll
2007-12-24 23:04 . 2003-07-16 22:28 17,142 --a------ C:\WINDOWS\system32\CBTNDIS5.sys
2007-12-24 23:04 . 1998-05-13 00:00 4,716 --a------ C:\WINDOWS\system32\VERSION.LIB
2007-12-24 00:32 . 2007-12-24 00:35 d-------- C:\xampp
2007-12-24 00:26 . 2007-12-24 00:26 d-------- C:\Program Files\Lavalys
2007-12-23 18:22 . 2007-10-11 00:52 6,065,664 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-12-23 18:22 . 2007-07-01 04:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-12-23 18:22 . 2007-07-01 04:36 1,036,288 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-12-23 18:22 . 2007-10-11 00:52 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-12-23 18:22 . 2007-10-11 00:52 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-12-23 18:22 . 2007-10-11 00:52 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-12-23 18:22 . 2007-10-11 00:52 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2007-12-23 18:22 . 2007-10-11 00:52 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-12-23 18:22 . 2007-10-10 11:59 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-22 19:35 . 2007-12-22 19:49 d-------- C:\Documents and Settings\Decewicz A&K\Dane aplikacji\phpDesigner 2008
2007-12-22 19:32 . 2007-12-27 23:49 d-------- C:\Program Files\phpDesigner 2008
2007-12-22 01:40 . 2007-12-23 18:32 d-------- C:\WINDOWS\system32\pl-pl
2007-12-05 19:52 . 2007-12-05 19:52 8,628 --ah----- C:\WINDOWS\system32\ZSHP1020.GID
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-04 16:57 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Symantec
2008-01-04 16:41 --------- d-----w C:\Documents and Settings\Decewicz A&K\Dane aplikacji\Skype
2008-01-04 14:39 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-04 13:12 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-03 10:47 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-01-03 10:47 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-01-03 10:47 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-01-03 10:47 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-01-03 10:47 --------- d-----w C:\Program Files\Symantec
2007-12-30 23:21 --------- d-----w C:\Documents and Settings\Decewicz A&K\Dane aplikacji\Tlen.pl
2007-12-25 19:15 --------- d-----w C:\Documents and Settings\Gość\Dane aplikacji\Skype
2007-12-25 16:48 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Skype
2007-11-30 22:57 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-11-30 22:57 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-11-30 22:57 279,088 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-11-30 22:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-11-30 22:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-11-30 22:57 10,545 ----a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-11-30 22:57 1,430 ----a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-11-30 22:57 1,421 ----a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-11-30 22:57 1,415 ----a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-23 11:38 --------- d-----w C:\Program Files\Java
2007-11-22 19:55 --------- d-----w C:\Program Files\Norton Internet Security
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-30 18:55 625,032 ----a-w C:\WINDOWS\system32\SymNeti.dll
2007-10-30 18:55 242,056 ----a-w C:\WINDOWS\system32\SymRedir.dll
2007-10-29 22:44 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-25 09:00 230,912 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-02-21 16:07 0 ----a-w C:\Documents and Settings\Decewicz A&K\Dane aplikacji\wklnhst.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-15 20:25 68856]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-12-07 15:08 21686568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-22 21:15 344064]
"SoundMan"="SOUNDMAN.EXE" [2005-05-17 18:48 77824 C:\WINDOWS\SOUNDMAN.EXE]
"SMSERIAL"="sm56hlpr.exe" [2005-07-06 04:47 544768 C:\WINDOWS\sm56hlpr.exe]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-12-05 14:22 159744]
"PowerManager"="C:\Program Files\Power Manager\PM.exe" [2005-08-19 09:11 163840]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 11:48 157592]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-02-13 19:29 35328]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 21:59 115816]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2006-09-05 18:22 26248]
"BigDog305"="C:\WINDOWS\VM305_STI.exe" [2005-08-05 08:15 61440]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 11:22 517768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\AutostartAdobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
Wireless-G Notebook Adapter Utility.lnk - C:\Program Files\Linksys\Wireless-G Notebook Adapter\Startup.exe [2007-12-24 23:04:57]
R1 SysTool;SysTool Overclocking Utility;C:\WINDOWS\system32\DRIVERS\SysTool.sys [2006-11-10 14:08]
R2 Harmonogram automatycznej usługi LiveUpdate;Harmonogram automatycznej usługi LiveUpdate;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2006-09-13 13:54]
R3 CBTNDIS5;CBTNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\CBTNDIS5.SYS [2003-07-16 22:28]
R3 EKBfltr;ENE Keyboard Controller;C:\WINDOWS\system32\DRIVERS\EKBfltr.sys [2005-01-14 17:22]
R3 odysseyIM3;Odyssey Network Services Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM3.sys [2003-05-14 16:01]
S2 NICSer_WPC54G;NICSer_WPC54G;C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe [2003-11-13 13:29]
S3 TNET1130x;Wireless-G Notebook Adapter v.2.0;C:\WINDOWS\system32\DRIVERS\tnet1130x.sys [2004-03-10 21:54]
S3 ZSMC0305;A4 Tech PC Camera V;C:\WINDOWS\system32\Drivers\usbVM305.sys [2006-05-08 03:24]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{98b020f0-a518-11dc-abad-0040cad9eca2}]
\Shell\AutoRun\command - G:\Shell\open\Command - rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b1d7b120-f8a1-11db-aa0f-0040cad9eca2}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\Shell\Open(&0)\command - Recycled\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b28fbd3e-8e3c-11dc-ab6a-0040cad9eca2}]
\Shell\AutoRun\command - G:\InstallTomTomHOME.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e96b6312-7afb-11dc-ab30-0040cad9eca2}]
\Shell\AutoRun\command - G:\InstallTomTomHOME.exe
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2007-12-28 19:32:52 C:\WINDOWS\Tasks\Norton Internet Security - Uruchom pełne skanowanie systemu - Decewicz A&K.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exef/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-04 18:26:10
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BigDog305 = C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)???????????????????0?????????@??????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-04 18:27:51
ComboFix-quarantined-files.txt 2008-01-04 17:27:25
ComboFix2.txt 2008-01-04 15:58:17
.
2007-12-23 17:33:19 --- E O F ---
Odpowiedzi: 0
Strona 0 / 0