kaszana z windozy

Witam...moj znajomy ma pewien problem mianowicie kaszani mu sie caly system...!!

czesto sie zawiesza,wogole staje wszystko ze nie mozna kliknac nigdzie myszka...czasami dluzej dobrze dziala,czasami krocej!!

ale ogolnie strasznie spowolniony jest!!

mozna to jakos w miare do stabilnosci przywrocic ??
daje loga z hijacka , moze ktos cos zobaczy czego ja nie widzialem...!!pozdrawiam

Logfile of HijackThis v1.97.7
Scan saved at 12:19:40, on 2004–12–05
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32 vsvc32.exe
C:Program FilesCommon FilesYDPUserAccessManageruseraccess.exe
C:Program FilesQuickTimeqttask.exe
C:Program FilesJavaj2re1.4.2_04injusched.exe
C:WINDOWSSystem32RUNDLL32.exe
C:PROGRA~1WANADOOTaskbarIcon.exe
C:WINDOWSSystem32P2P NetworkingP2P Networking.exe
C:WINDOWSSystem32ctfmon.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesSkypePhoneSkype.exe
C:Program FilesWinZipWZQKPICK.EXE
C:Program FilesYDPYdpDictWatch.exe
C:Program FilesSAGEMSAGEM F@st 800–840dslmon.exe
C:WINDOWSSystem32wuauclt.exe
C:Program FilesWanadooEspaceWanadoo.exe
C:Program FilesWanadooComComp.exe
C:Program FilesWanadooWatch.exe
C:PROGRA~1LAVASOFTAD–AWA~1AD–AWARE.EXE
C:Documents and SettingsWlodekPulpitprogsyHijackThis.exe

R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sp/*http://www.yahoo.com
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.neostrada.pl
R1 – HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Neostrada Plus wita Cie w Internecie
R1 – HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/su/*http://www.yahoo.com
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 – BHO: (no name) – {02478D38–C3F9–4efb–9B51–7695ECA05670} – C:Program FilesYahoo!CompanionInstallscpnycomp5_3_19_0.dll
O2 – BHO: (no name) – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O3 – Toolbar: Yahoo! Companion – {EF99BD32–C1FB–11D2–892F–0090271D4F88} – C:Program FilesYahoo!CompanionInstallscpnycomp5_3_19_0.dll
O4 – HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" –atboottime
O4 – HKLM..Run: [WinampAgent] "C:Program FilesWinampWinampa.exe"
O4 – HKLM..Run: [Tsk Mngr Hlp] wins32.exe
O4 – HKLM..Run: [service32] service32.exe
O4 – HKLM..Run: [Audoi Device Loader] smssv.exe
O4 – HKLM..Run: [Windows Service Management] svcmngmt.exe
O4 – HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 – HKLM..Run: [nwiz] nwiz.exe /install
O4 – HKLM..Run: [msReg32 Loader] msReg32.exe
O4 – HKLM..Run: [Microsoft Update] wuamgrd.exe
O4 – HKLM..Run: [Win32Setup] msgms.exe
O4 – HKLM..Run: [KAVPersonal50] C:Program FilesKaspersky LabKaspersky Anti–Virus Personalkav.exe /minimize
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_04injusched.exe
O4 – HKLM..Run: [WildTangent CDA] RUNDLL32.exe "C:Program FilesWildTangentAppsCDAcdaEngine0400.dll",cdaEngineMain
O4 – HKLM..Run: [WOOWATCH] C:PROGRA~1WANADOOWatch.exe
O4 – HKLM..Run: [WOOTASKBARICON] C:PROGRA~1WANADOOTaskbarIcon.exe
O4 – HKLM..Run: [P2P Networking] C:WINDOWSSystem32P2P NetworkingP2P Networking.exe /AUTOSTART
O4 – HKLM..RunServices: [Tsk Mngr Hlp] wins32.exe
O4 – HKLM..RunServices: [service32] service32.exe
O4 – HKLM..RunServices: [Audoi Device Loader] smssv.exe
O4 – HKLM..RunServices: [winstart] winstart.exe
O4 – HKLM..RunServices: [Windows Service Management] svcmngmt.exe
O4 – HKLM..RunServices: [msReg32 Loader] msReg32.exe
O4 – HKLM..RunServices: [Microsoft Update] wuamgrd.exe
O4 – HKLM..RunServices: [Win32Setup] msgms.exe
O4 – HKLM..RunServices: [NS] ns.exe
O4 – HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 – HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 – HKCU..Run: [ssate.exe] C:WINDOWSSystem32irun4.exe
O4 – HKCU..Run: [Microsoft Update] wuamgrd.exe
O4 – HKCU..Run: [Skype] "C:Program FilesSkypePhoneSkype.exe" /nosplash /minimized
O4 – Global Startup: WinZip Quick Pick.lnk = C:Program FilesWinZipWZQKPICK.EXE
O4 – Global Startup: Aktywacja Testera.lnk = C:Program FilesYDPYdpDictWatch.exe
O4 – Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O4 – Global Startup: DSLMON.lnk = C:Program FilesSAGEMSAGEM F@st 800–840dslmon.exe
O8 – Extra context menu item: E&ksport do programu Microsoft Excel – res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 – Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 – Extra button: Related (HKLM)
O9 – Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 – DPF: {166B1BCA–3F9C–11CF–8075–444553540000} (Shockwave ActiveX Control) – http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 – DPF: {1D6711C8–7154–40BB–8380–3DEA45B69CBF} (Web P2P Installer) –
O16 – DPF: {288C5F13–7E52–4ADA–A32E–F5BF9D125F98} (CR64Loader Object) – http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 – DPF: {94837F90–A2CA–4A8A–9DA0–B5438EC563EA} (WildTangent Active Launcher) – http://install.wildtangent.com/cda/islandrally/ActiveLauncher/ActiveLauncherSetup.cab
O16 – DPF: {9F1C11AA–197B–4942–BA54–47A8489BB47F} (Update Class) – http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38106.4525694444
O16 – DPF: {A8658086–E6AC–4957–BC8E–7D54A7E8A78E} (SassCln Object) – http://www.microsoft.com/security/controls/SassCln.CAB
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 – DPF: {E7544C6C–CFD6–43EA–B4E9–360CEE20BDF7} (MainControl Class) – http://skaner.mks.com.pl/SkanerOnline.cab
O17 – HKLMSystemCCSServicesTcpip..{3FA52EB7–79A4–4318–A274–128087030866}: NameServer = 194.204.152.34 217.98.63.164

Odpowiedzi: 2

A jest połączony z internetem i coś pobiera? U mnie tez czasami sie tak dzieje ale po jakims czasie sie stabilizuje.
Pozdrawiam
Damianos
Dodano
06.12.2004 14:59:58
Wylacz przywracanie, zakoncz ponizsze procesy w menedzerze zadan i usun je z dysku. Zobacz czy w dodaj/usun programy nie ma czegos z ponizszych pozycji

C:WINDOWSSystem32P2P NetworkingP2P Networking.exe
O4 – HKLM..Run: [Tsk Mngr Hlp] wins32.exe
O4 – HKLM..Run: [service32] service32.exe
O4 – HKLM..Run: [Audoi Device Loader] smssv.exe
O4 – HKLM..Run: [Windows Service Management] svcmngmt.exe
O4 – HKLM..Run: [msReg32 Loader] msReg32.exe
O4 – HKLM..Run: [Microsoft Update] wuamgrd.exe
O4 – HKLM..Run: [Win32Setup] msgms.exe
O4 – HKLM..Run: [WildTangent CDA] RUNDLL32.exe "C:Program FilesWildTangentAppsCDAcdaEngine0400.dll",cdaEngineMain
O4 – HKLM..Run: [P2P Networking] C:WINDOWSSystem32P2P NetworkingP2P Networking.exe /AUTOSTART
O4 – HKLM..RunServices: [Tsk Mngr Hlp] wins32.exe
O4 – HKLM..RunServices: [service32] service32.exe
O4 – HKLM..RunServices: [Audoi Device Loader] smssv.exe
O4 – HKLM..RunServices: [winstart] winstart.exe
O4 – HKLM..RunServices: [Windows Service Management] svcmngmt.exe
O4 – HKLM..RunServices: [msReg32 Loader] msReg32.exe
O4 – HKLM..RunServices: [Microsoft Update] wuamgrd.exe
O4 – HKLM..RunServices: [Win32Setup] msgms.exe
O4 – HKLM..RunServices: [NS] ns.exe
O4 – HKCU..Run: [ssate.exe] C:WINDOWSSystem32irun4.exe
O4 – HKCU..Run: [Microsoft Update] wuamgrd.exe

i na koniec mozna wlaczyc przywracanie systemu
wins
Dodano
05.12.2004 14:50:30
mistic
Dodano:
05.12.2004 13:23:39
Komentarzy:
2
Strona 1 / 1