Potrzebuje analizy loga... Ogolnie komp wolno chodzi....
Komputer chodzi wolno, wolno sie laduje system ale procek jest w normie... Dolaczam loga: mniej wiecej wiem co usunac ale i tak nie wiem co robic dalej...prosze o pomoc, z gory dziekuje
Logfile of HijackThis v1.97.7
Scan saved at 18:39:34, on 2005–01–24
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSSYSTEM32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSSystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSSYSTEM32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32CTsvcCDA.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumFirewallPavFires.exe
C:Program FilesPanda SoftwarePanda Antivirus Platinumpavsrv51.exe
C:WINDOWSsystem32oneLabsvsmon.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumAVENGINE.EXE
C:WINDOWSSystem32MsPMSPSv.exe
C:WINDOWSSystem32winasp.exe
C:Program FilesWinampwinampa.exe
C:Program FilesJavaj2re1.4.2_05injusched.exe
C:Program FilesD–Toolsdaemon.exe
C:WINDOWSSystem32CTHELPER.EXE
C:PROGRA~1MICROS~2GAMECO~1commonswtrayv4.exe
C:Program FilesQuickTimeqttask.exe
C:Program FilesiTunesiTunesHelper.exe
C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
C:Program FilesCreativeShareDLLCtNotify.exe
C:Program FilesiPodiniPodService.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE
C:Program FilesCommon FilesCMEIICMESys.exe
C:Program FilesCreativeShareDLLMediaDet.exe
C:WINDOWSSystem32ctfmon.exe
C:Program FilesCreativeSBAudigyTaskBarCTLTray.exe
C:Program FilesCreativeSBAudigyTaskBarCTLTask.exe
C:Program FilesCommon FilesGMTGMT.exe
C:Program FilesKalendarz XPKalendarz.exe
C:Program Filesone LabsoneAlarmzonealarm.exe
C:WINDOWS wain_32A4CISWATCH.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumpavProxy.exe
C:Program FilesWinampWinamp.exe
C:Program FilesGadu–Gadugg.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesKazaa Lite K++KazaaLite.kpp
C:Documents and SettingsAdministrator.SERWERMoje dokumentyHijackThisHijackThis.exe
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R1 – HKCUSoftwareMicrosoftInternet Connection Wizard,Shellnext = http://www.sygate.com/swat/support/spf50_help.htm
O2 – BHO: (no name) – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O4 – HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_05injusched.exe
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [DAEMON Tools–1033] "C:Program FilesD–Toolsdaemon.exe" –lang 1033
O4 – HKLM..Run: [WINDVDPatch] CTHELPER.EXE
O4 – HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
O4 – HKLM..Run: [Jet Detection] "C:Program FilesCreativeSBAudigyPROGRAMADGJDet.exe"
O4 – HKLM..Run: [NeroCheck] C:WINDOWSSystem32\NeroCheck.exe
O4 – HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 –k
O4 – HKLM..Run: [SideWinderTrayV4] C:PROGRA~1MICROS~2GAMECO~1commonswtrayv4.exe
O4 – HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" –atboottime
O4 – HKLM..Run: [iTunesHelper] C:Program FilesiTunesiTunesHelper.exe
O4 – HKLM..Run: [ATIPTA] C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
O4 – HKLM..Run: [Disc Detector] C:Program FilesCreativeShareDLLCtNotify.exe
O4 – HKLM..Run: [SCANINICIO] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumInicio.exe"
O4 – HKLM..Run: [APVXDWIN] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE" /s
O4 – HKLM..Run: [NvCplScan] winasp.exe
O4 – HKLM..Run: [CMESys] "C:Program FilesCommon FilesCMEIICMESys.exe"
O4 – HKLM..RunServices: [NvCplScan] winasp.exe
O4 – HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 – HKCU..Run: [TaskTray] "C:Program FilesCreativeSBAudigyTaskBarCTLTray.exe"
O4 – HKCU..Run: [TaskBar] "C:Program FilesCreativeSBAudigyTaskBarCTLTask.exe"
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – HKCU..Run: [NvCplScan] winasp.exe
O4 – HKLM..RunOnce: [NvCplScan] winasp.exe
O4 – HKCU..RunOnce: [NvCplScan] winasp.exe
O4 – Startup: Watch.lnk = C:WINDOWS wain_32A4CISWATCH.exe
O4 – Global Startup: GStartup.lnk = C:Program FilesCommon FilesGMTGMT.exe
O4 – Global Startup: Kalendarz XP.lnk = C:Program FilesKalendarz XPKalendarz.exe
O4 – Global Startup: ZoneAlarm.lnk = C:Program Filesone LabsoneAlarmzonealarm.exe
O9 – Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 – Extra button: Related (HKLM)
O9 – Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 – DPF: {02BF25D5–8C17–4B23–BC80–D3488ABDDC6B} (QuickTime Object) – http://www.apple.com/qtactivex/qtplugin.cab
O16 – DPF: {166B1BCA–3F9C–11CF–8075–444553540000} (Shockwave ActiveX Control) – http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 – DPF: {D27CDB6E–0000–0000–0000–000000000000} – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Logfile of HijackThis v1.97.7
Scan saved at 18:39:34, on 2005–01–24
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSSYSTEM32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSSystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSSYSTEM32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32CTsvcCDA.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumFirewallPavFires.exe
C:Program FilesPanda SoftwarePanda Antivirus Platinumpavsrv51.exe
C:WINDOWSsystem32oneLabsvsmon.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumAVENGINE.EXE
C:WINDOWSSystem32MsPMSPSv.exe
C:WINDOWSSystem32winasp.exe
C:Program FilesWinampwinampa.exe
C:Program FilesJavaj2re1.4.2_05injusched.exe
C:Program FilesD–Toolsdaemon.exe
C:WINDOWSSystem32CTHELPER.EXE
C:PROGRA~1MICROS~2GAMECO~1commonswtrayv4.exe
C:Program FilesQuickTimeqttask.exe
C:Program FilesiTunesiTunesHelper.exe
C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
C:Program FilesCreativeShareDLLCtNotify.exe
C:Program FilesiPodiniPodService.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE
C:Program FilesCommon FilesCMEIICMESys.exe
C:Program FilesCreativeShareDLLMediaDet.exe
C:WINDOWSSystem32ctfmon.exe
C:Program FilesCreativeSBAudigyTaskBarCTLTray.exe
C:Program FilesCreativeSBAudigyTaskBarCTLTask.exe
C:Program FilesCommon FilesGMTGMT.exe
C:Program FilesKalendarz XPKalendarz.exe
C:Program Filesone LabsoneAlarmzonealarm.exe
C:WINDOWS wain_32A4CISWATCH.exe
C:Program FilesPanda SoftwarePanda Antivirus PlatinumpavProxy.exe
C:Program FilesWinampWinamp.exe
C:Program FilesGadu–Gadugg.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesKazaa Lite K++KazaaLite.kpp
C:Documents and SettingsAdministrator.SERWERMoje dokumentyHijackThisHijackThis.exe
R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/
R0 – HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
R1 – HKCUSoftwareMicrosoftInternet Connection Wizard,Shellnext = http://www.sygate.com/swat/support/spf50_help.htm
O2 – BHO: (no name) – {06849E9F–C8D7–4D59–B87D–784B7D6BE0B3} – C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O3 – Toolbar: &Radio – {8E718888–423F–11D2–876E–00A0C9082467} – C:WINDOWSSystem32msdxm.ocx
O4 – HKLM..Run: [WinampAgent] C:Program FilesWinampwinampa.exe
O4 – HKLM..Run: [SunJavaUpdateSched] C:Program FilesJavaj2re1.4.2_05injusched.exe
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [DAEMON Tools–1033] "C:Program FilesD–Toolsdaemon.exe" –lang 1033
O4 – HKLM..Run: [WINDVDPatch] CTHELPER.EXE
O4 – HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
O4 – HKLM..Run: [Jet Detection] "C:Program FilesCreativeSBAudigyPROGRAMADGJDet.exe"
O4 – HKLM..Run: [NeroCheck] C:WINDOWSSystem32\NeroCheck.exe
O4 – HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 –k
O4 – HKLM..Run: [SideWinderTrayV4] C:PROGRA~1MICROS~2GAMECO~1commonswtrayv4.exe
O4 – HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" –atboottime
O4 – HKLM..Run: [iTunesHelper] C:Program FilesiTunesiTunesHelper.exe
O4 – HKLM..Run: [ATIPTA] C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
O4 – HKLM..Run: [Disc Detector] C:Program FilesCreativeShareDLLCtNotify.exe
O4 – HKLM..Run: [SCANINICIO] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumInicio.exe"
O4 – HKLM..Run: [APVXDWIN] "C:Program FilesPanda SoftwarePanda Antivirus PlatinumAPVXDWIN.EXE" /s
O4 – HKLM..Run: [NvCplScan] winasp.exe
O4 – HKLM..Run: [CMESys] "C:Program FilesCommon FilesCMEIICMESys.exe"
O4 – HKLM..RunServices: [NvCplScan] winasp.exe
O4 – HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 – HKCU..Run: [TaskTray] "C:Program FilesCreativeSBAudigyTaskBarCTLTray.exe"
O4 – HKCU..Run: [TaskBar] "C:Program FilesCreativeSBAudigyTaskBarCTLTask.exe"
O4 – HKCU..Run: [Gadu–Gadu] "C:Program FilesGadu–Gadugg.exe" /tray
O4 – HKCU..Run: [NvCplScan] winasp.exe
O4 – HKLM..RunOnce: [NvCplScan] winasp.exe
O4 – HKCU..RunOnce: [NvCplScan] winasp.exe
O4 – Startup: Watch.lnk = C:WINDOWS wain_32A4CISWATCH.exe
O4 – Global Startup: GStartup.lnk = C:Program FilesCommon FilesGMTGMT.exe
O4 – Global Startup: Kalendarz XP.lnk = C:Program FilesKalendarz XPKalendarz.exe
O4 – Global Startup: ZoneAlarm.lnk = C:Program Filesone LabsoneAlarmzonealarm.exe
O9 – Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 – Extra button: Related (HKLM)
O9 – Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 – Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 – DPF: {02BF25D5–8C17–4B23–BC80–D3488ABDDC6B} (QuickTime Object) – http://www.apple.com/qtactivex/qtplugin.cab
O16 – DPF: {166B1BCA–3F9C–11CF–8075–444553540000} (Shockwave ActiveX Control) – http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 – DPF: {D27CDB6E–0000–0000–0000–000000000000} – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 – DPF: {D27CDB6E–AE6D–11CF–96B8–444553540000} (Shockwave Flash Object) – http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Odpowiedzi: 1
Wylacz przywracanie systemu
Zakoncz proces:
winasp.exe
Usun z HDD:
winasp.exe
FIX:
Update:
Zapomniałbym
C:Program FilesCommon FilesGMTGMT.exe tez do wylaczenia i odstrzału
fix:
To samo z: C:Program FilesCommon FilesCMEIICMESys.exe
fix:
Zakoncz proces:
winasp.exe
Usun z HDD:
winasp.exe
FIX:
O4 – HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 –k
O4 – HKLM..RunServices: [NvCplScan] winasp.exe
O4 – HKCU..Run: [NvCplScan] winasp.exe
O4 – HKLM..RunOnce: [NvCplScan] winasp.exe
O4 – HKCU..RunOnce: [NvCplScan] winasp.exe
O9 – Extra button: Related (HKLM)
O9 – Extra 'Tools' menuitem: Show &Related Links (HKLM)
Update:
Zapomniałbym
C:Program FilesCommon FilesGMTGMT.exe tez do wylaczenia i odstrzału
fix:
O4 – Global Startup: GStartup.lnk = C:Program FilesCommon FilesGMTGMT.exe
To samo z: C:Program FilesCommon FilesCMEIICMESys.exe
fix:
O4 – HKLM..Run: [CMESys] "C:Program FilesCommon FilesCMEIICMESys.exe"
Strona 1 / 1