x-kom hosting

Nie da się wytrzymać z TAK mulącym komputerem, WOłAM POMOCY

tristan202
utworzono
utworzono

Proszę dokładnie przejrzeć logi i pomóc mi, bo naprawdę bardzo potrzebuję pomocy i muszę poprawić funkcjonowanie tego komputera, a do tego niezbędna mi jest Wasza pomoc. Otóż komputer tak bardzo wolno chodzi, że naprawdę nie można nic na nim normalnie zrobić. Zamieszczam logi z:

hijackthis:

Logfile of HijackThis v1.99.1Scan saved at 17:06:27, on 2007-06-26Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:WINDOWSSystem32smss.exeC:WINDOWSsystem32winlogon.exeC:WINDOWSsystem32services.exeC:WINDOWSsystem32lsass.exeC:WINDOWSsystem32svchost.exeC:WINDOWSSystem32svchost.exeC:Program FilesCommon FilesSymantec SharedccSetMgr.exeC:WINDOWSExplorer.EXEC:Program FilesCommon FilesSymantec SharedccEvtMgr.exeC:WINDOWSsystem32spoolsv.exeC:Program FilesSymantec AntiVirusDefWatch.exeC:WINDOWSsystem32svchost.exeC:Program FilesSymantec AntiVirusRtvscan.exeC:Program FilesCommon FilesSymantec SharedccApp.exeC:PROGRA~1SYMANT~1VPTray.exeC:WINDOWSMixer.exeC:Program FilesHPHP Software UpdateHPWuSchd2.exeC:Program FilesHPDigital Imagingbinhpqtra08.exeC:Program FilesHPDigital Imagingbinhpqgalry.exeC:WINDOWSsystem32HPZipm12.exeC:Program FilesMozilla Firefoxfirefox.exeC:Documents and SettingsRafałPulpitHijackThis.exeR0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.onet.pl/R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = ŁączaO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dllO3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"O4 - HKLM..Run: [vptray] C:PROGRA~1SYMANT~1VPTray.exeO4 - HKLM..Run: [C-Media Mixer] Mixer.exe /startupO4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exeO4 - HKLM..Run: [HP Software Update] "C:Program FilesHPHP Software UpdateHPWuSchd2.exe"O4 - HKLM..Run: [HP Component Manager] "C:Program FilesHPhpcoretechhpcmpmgr.exe"O4 - HKCU..Run: [Gadu-Gadu] "C:Program FilesGadu-Gadugg.exe" /trayO4 - Global Startup: HP Digital Imaging Monitor.lnk = C:Program FilesHPDigital Imagingbinhpqtra08.exeO4 - Global Startup: HP Image Zone - szybkie uruchamianie.lnk = C:Program FilesHPDigital Imagingbinhpqthb08.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exeO20 - Winlogon Notify: NavLogon - C:WINDOWSsystem32NavLogon.dllO20 - Winlogon Notify: WgaLogon - C:WINDOWSSYSTEM32WgaLogon.dllO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccEvtMgr.exeO23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccPwdSvc.exeO23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccSetMgr.exeO23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:Program FilesSymantec AntiVirusDefWatch.exeO23 - Service: Pml Driver HPZ12 - HP - C:WINDOWSsystem32HPZipm12.exeO23 - Service: SAVRoam (SavRoam) - symantec - C:Program FilesSymantec AntiVirusSavRoam.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedSNDSrvc.exeO23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedSPBBCSPBBCSvc.exeO23 - Service: Symantec AntiVirus - Symantec Corporation - C:Program FilesSymantec AntiVirusRtvscan.exe

silentrunners

"Silent Runners.vbs", revision R50, http://www.silentrunners.org/Operating System: Windows XP SP2Output limited to non-default values, except where indicated by "{++}"Startup items buried in registry:---------------------------------HKLMSoftwareMicrosoftWindowsCurrentVersionRun {++}"ccApp" = ""C:Program FilesCommon FilesSymantec SharedccApp.exe"" ["Symantec Corporation"]"vptray" = "C:PROGRA~1SYMANT~1VPTray.exe" ["Symantec Corporation"]"HP Software Update" = ""C:Program FilesHPHP Software UpdateHPWuSchd2.exe"" ["Hewlett-Packard Company"]"HP Component Manager" = ""C:Program FilesHPhpcoretechhpcmpmgr.exe"" ["Hewlett-Packard Company"]HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = (no title provided)  -> {HKLM...CLSID} = "AcroIEHlprObj Class"				   InProcServer32(Default) = "C:Program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll" ["Adobe Systems Incorporated"]HKLMSoftwareMicrosoftWindowsCurrentVersionShell ExtensionsApproved"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"  -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"				   InProcServer32(Default) = "deskpan.dll" [file not found]"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"  -> {HKLM...CLSID} = "HyperTerminal Icon Ext"				   InProcServer32(Default) = "C:WINDOWSsystem32hticons.dll" ["Hilgraeve, Inc."]"{BDA77241-42F6-11d0-85E2-00AA001FE28C}" = "LDVP Shell Extensions"  -> {HKLM...CLSID} = "VpshellEx Class"				   InProcServer32(Default) = "C:Program FilesCommon FilesSymantec SharedSSCvpshell2.dll" ["Symantec Corporation"]"{59850401-6664-101B-B21C-00AA004BA90B}" = "Microsoft Office Binder Unbind"  -> {HKLM...CLSID} = "Microsoft Office Binder Unbind"				   InProcServer32(Default) = "C:PROGRA~1MICROS~2Office1045UNBIND.DLL" [MS]"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"  -> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook"				   InProcServer32(Default) = "C:PROGRA~1MICROS~2OfficeOLKFSTUB.DLL" [MS]"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"  -> {HKLM...CLSID} = "WinRAR"				   InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"  -> {HKLM...CLSID} = "Portable Media Devices Menu"				   InProcServer32(Default) = "C:WINDOWSsystem32Audiodev.dll" [MS]HKLMSoftwareMicrosoftWindows NTCurrentVersionWinlogonNotify<<!>> NavLogonDLLName = "C:WINDOWSsystem32NavLogon.dll" ["Symantec Corporation"]HKLMSoftwareClasses*shellexContextMenuHandlersLDVPMenu(Default) = "{BDA77241-42F6-11d0-85E2-00AA001FE28C}"  -> {HKLM...CLSID} = "VpshellEx Class"				   InProcServer32(Default) = "C:Program FilesCommon FilesSymantec SharedSSCvpshell2.dll" ["Symantec Corporation"]WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"  -> {HKLM...CLSID} = "WinRAR"				   InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]HKLMSoftwareClassesDirectoryshellexContextMenuHandlersWinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"  -> {HKLM...CLSID} = "WinRAR"				   InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]HKLMSoftwareClassesFoldershellexContextMenuHandlersLDVPMenu(Default) = "{BDA77241-42F6-11d0-85E2-00AA001FE28C}"  -> {HKLM...CLSID} = "VpshellEx Class"				   InProcServer32(Default) = "C:Program FilesCommon FilesSymantec SharedSSCvpshell2.dll" ["Symantec Corporation"]WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"  -> {HKLM...CLSID} = "WinRAR"				   InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]Group Policies {policy setting}:--------------------------------Note: detected settings may not have any effect.HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001{Shutdown: Allow system to be shut down without having to log on}"undockwithoutlogon" = (REG_DWORD) hex:0x00000001{Devices: Allow undock without having to log on}Active Desktop and Wallpaper:-----------------------------Active Desktop may be disabled at this entry:HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShellStateDisplayed if Active Desktop enabled and wallpaper not set by Group Policy:HKCUSoftwareMicrosoftInternet ExplorerDesktopGeneral"Wallpaper" = "C:WINDOWSwebwallpaperIdylla.bmp"Displayed if Active Desktop disabled and wallpaper not set by Group Policy:HKCUControl PanelDesktop"Wallpaper" = "C:WINDOWSwebwallpaperIdylla.bmp"Enabled Screen Saver:---------------------HKCUControl PanelDesktop"SCRNSAVE.EXE" = "C:WINDOWSSystem32logon.scr" [MS]Startup items in "Rafał" & "All Users" startup folders:-------------------------------------------------------C:Documents and SettingsAll UsersMenu StartProgramyAutostart"HP Digital Imaging Monitor" -> shortcut to: "C:Program FilesHPDigital Imagingbinhpqtra08.exe" ["Hewlett-Packard Co."]Winsock2 Service Provider DLLs:-------------------------------Namespace Service ProvidersHKLMSystemCurrentControlSetServicesWinsock2ParametersNameSpace_Catalog5Catalog_Etries {++}000000000001LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]000000000002LibraryPath = "%SystemRoot%System32winrnr.dll" [MS]000000000003LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]Transport Service ProvidersHKLMSystemCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_Enries {++}0000000000##PackedCatalogItem (contains) DLL [Company Name], (at) ## range:%SystemRoot%system32mswsock.dll [MS], 01 - 03, 06 - 17%SystemRoot%system32rsvpsp.dll [MS], 04 - 05Toolbars, Explorer Bars, Extensions:------------------------------------Extensions (Tools menu items, main toolbar menu buttons)HKLMSoftwareMicrosoftInternet ExplorerExtensions{FB5F1910-F110-11D2-BB9E-00C04F795683}"ButtonText" = "Messenger""MenuText" = "Windows Messenger""Exec" = "C:Program FilesMessengermsmsgs.exe" [MS]Running Services (Display Name, Service Name, Path {Service DLL}):------------------------------------------------------------------Symantec AntiVirus, Symantec AntiVirus, ""C:Program FilesSymantec AntiVirusRtvscan.exe"" ["Symantec Corporation"]Symantec AntiVirus Definition Watcher, DefWatch, ""C:Program FilesSymantec AntiVirusDefWatch.exe"" ["Symantec Corporation"]Symantec Event Manager, ccEvtMgr, ""C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe"" ["Symantec Corporation"]Symantec Settings Manager, ccSetMgr, ""C:Program FilesCommon FilesSymantec SharedccSetMgr.exe"" ["Symantec Corporation"]Windows User Mode Driver Framework, UMWdf, "C:WINDOWSsystem32wdfmgr.exe" [MS]Print Monitors:---------------HKLMSystemCurrentControlSetControlPrintMonitorshpzsnt10Driver = "hpzsnt10.dll" ["HP"]----------<<!>>: Suspicious data at a malware launch point.+ This report excludes default entries except where indicated.+ To see *everywhere* the script checks and *everything* it finds,  launch it from a command prompt or a shortcut with the -all parameter.+ To search all directories of local fixed drives for DESKTOP.INI  DLL launch points, use the -supp parameter or answer "No" at the  first message box and "Yes" at the second message box.---------- (total run time: 293 seconds, including 6 seconds for message boxes)

CatchMe
komentarz
komentarz

Logi są czyste. Aby wykluczyc infekcje proszę o wklejenie logów z ComboFixa i Gmera (z 2 opcji).

W tym przypadku Norton (Symantec) jest twórcą zamieszania. On na prawdę potrafi zamulić szybki komputer. :) Czekam na logi. Pozdrawiam.

Dziniu
komentarz
komentarz

zobacz w Menadżerze Zadań który proces zżera najwięcej zasobów oraz podaj temperatury z programu Everest lub AIDA32

tristan202
komentarz
komentarz

Logi po odinstalowaniu Nortona i zainstalowaniu AVG Free

hijackthis

Logfile of HijackThis v1.99.1Scan saved at 18:11:02, on 2007-06-28Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:WINDOWSSystem32smss.exeC:WINDOWSsystem32winlogon.exeC:WINDOWSsystem32services.exeC:WINDOWSsystem32lsass.exeC:WINDOWSsystem32svchost.exeC:WINDOWSSystem32svchost.exeC:WINDOWSsystem32spoolsv.exeC:WINDOWSsystem32svchost.exeC:WINDOWSExplorer.EXEC:WINDOWSMixer.exeC:PROGRA~1GrisoftAVG7avgamsvr.exeC:PROGRA~1GrisoftAVG7avgemc.exeC:PROGRA~1GrisoftAVG7avgupsvc.exeC:Program FilesGrisoftAVG7avgcc.exeC:Program FileslogiHijackThis.exeR0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.onet.pl/R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = ŁączaO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dllO4 - HKLM..Run: [HP Component Manager] "C:Program FilesHPhpcoretechhpcmpmgr.exe"O4 - HKLM..Run: [C-Media Mixer] Mixer.exe /startupO4 - HKLM..Run: [AVG7_CC] C:PROGRA~1GrisoftAVG7avgcc.exe /STARTUPO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exeO20 - Winlogon Notify: NavLogon - C:WINDOWSO20 - Winlogon Notify: WgaLogon - C:WINDOWSSYSTEM32WgaLogon.dllO23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:PROGRA~1GrisoftAVG7avgamsvr.exeO23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:PROGRA~1GrisoftAVG7avgupsvc.exeO23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:PROGRA~1GrisoftAVG7avgemc.exeO23 - Service: Pml Driver HPZ12 - HP - C:WINDOWSsystem32HPZipm12.exe

silentrunners

"Silent Runners.vbs", revision R50, http://www.silentrunners.org/Operating System: Windows XP SP2Output limited to non-default values, except where indicated by "{++}"Startup items buried in registry:---------------------------------HKLMSoftwareMicrosoftWindowsCurrentVersionRun {++}"HP Component Manager" = ""C:Program FilesHPhpcoretechhpcmpmgr.exe"" ["Hewlett-Packard Company"]"C-Media Mixer" = "Mixer.exe /startup" ["C-Media Electronic Inc. (www.cmedia.com.tw)"]"AVG7_CC" = "C:PROGRA~1GrisoftAVG7avgcc.exe /STARTUP" ["GRISOFT, s.r.o."]HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = (no title provided)  -> {HKLM...CLSID} = "AcroIEHlprObj Class"				   InProcServer32(Default) = "C:Program FilesAdobeAcrobat 6.0 CEReaderActiveXAcroIEHelper.dll" ["Adobe Systems Incorporated"]HKLMSoftwareMicrosoftWindowsCurrentVersionShell ExtensionsApproved"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"  -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"				   InProcServer32(Default) = "deskpan.dll" [file not found]"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"  -> {HKLM...CLSID} = "HyperTerminal Icon Ext"				   InProcServer32(Default) = "C:WINDOWSsystem32hticons.dll" ["Hilgraeve, Inc."]"{59850401-6664-101B-B21C-00AA004BA90B}" = "Microsoft Office Binder Unbind"  -> {HKLM...CLSID} = "Microsoft Office Binder Unbind"				   InProcServer32(Default) = "C:PROGRA~1MICROS~2Office1045UNBIND.DLL" [MS]"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"  -> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook"				   InProcServer32(Default) = "C:PROGRA~1MICROS~2OfficeOLKFSTUB.DLL" [MS]"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"  -> {HKLM...CLSID} = "WinRAR"				   InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"  -> {HKLM...CLSID} = "Portable Media Devices Menu"				   InProcServer32(Default) = "C:WINDOWSsystem32Audiodev.dll" [MS]"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension"  -> {HKLM...CLSID} = "AVG7 Shell Extension Class"				   InProcServer32(Default) = "C:Program FilesGrisoftAVG7avgse.dll" ["GRISOFT, s.r.o."]"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension"  -> {HKLM...CLSID} = "AVG7 Find Extension Class"				   InProcServer32(Default) = "C:Program FilesGrisoftAVG7avgse.dll" ["GRISOFT, s.r.o."]HKLMSoftwareClasses*shellexContextMenuHandlersAVG7 Shell Extension(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"  -> {HKLM...CLSID} = "AVG7 Shell Extension Class"				   InProcServer32(Default) = "C:Program FilesGrisoftAVG7avgse.dll" ["GRISOFT, s.r.o."]WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"  -> {HKLM...CLSID} = "WinRAR"				   InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]HKLMSoftwareClassesDirectoryshellexContextMenuHandlersWinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"  -> {HKLM...CLSID} = "WinRAR"				   InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]HKLMSoftwareClassesFoldershellexContextMenuHandlersAVG7 Shell Extension(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"  -> {HKLM...CLSID} = "AVG7 Shell Extension Class"				   InProcServer32(Default) = "C:Program FilesGrisoftAVG7avgse.dll" ["GRISOFT, s.r.o."]WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"  -> {HKLM...CLSID} = "WinRAR"				   InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]Group Policies {policy setting}:--------------------------------Note: detected settings may not have any effect.HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001{Shutdown: Allow system to be shut down without having to log on}"undockwithoutlogon" = (REG_DWORD) hex:0x00000001{Devices: Allow undock without having to log on}Active Desktop and Wallpaper:-----------------------------Active Desktop may be disabled at this entry:HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShellStateDisplayed if Active Desktop enabled and wallpaper not set by Group Policy:HKCUSoftwareMicrosoftInternet ExplorerDesktopGeneral"Wallpaper" = "C:WINDOWSwebwallpaperIdylla.bmp"Displayed if Active Desktop disabled and wallpaper not set by Group Policy:HKCUControl PanelDesktop"Wallpaper" = "C:WINDOWSwebwallpaperIdylla.bmp"Enabled Screen Saver:---------------------HKCUControl PanelDesktop"SCRNSAVE.EXE" = "C:WINDOWSSystem32logon.scr" [MS]Winsock2 Service Provider DLLs:-------------------------------Namespace Service ProvidersHKLMSystemCurrentControlSetServicesWinsock2ParametersNameSpace_Catalog5Catalog_Etries {++}000000000001LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]000000000002LibraryPath = "%SystemRoot%System32winrnr.dll" [MS]000000000003LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]Transport Service ProvidersHKLMSystemCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_Enries {++}0000000000##PackedCatalogItem (contains) DLL [Company Name], (at) ## range:%SystemRoot%system32mswsock.dll [MS], 01 - 03, 06 - 17%SystemRoot%system32rsvpsp.dll [MS], 04 - 05Toolbars, Explorer Bars, Extensions:------------------------------------Extensions (Tools menu items, main toolbar menu buttons)HKLMSoftwareMicrosoftInternet ExplorerExtensions{FB5F1910-F110-11D2-BB9E-00C04F795683}"ButtonText" = "Messenger""MenuText" = "Windows Messenger""Exec" = "C:Program FilesMessengermsmsgs.exe" [MS]Running Services (Display Name, Service Name, Path {Service DLL}):------------------------------------------------------------------AVG E-mail Scanner, AVGEMS, "C:PROGRA~1GrisoftAVG7avgemc.exe" ["GRISOFT, s.r.o."]AVG7 Alert Manager Server, Avg7Alrt, "C:PROGRA~1GrisoftAVG7avgamsvr.exe" ["GRISOFT, s.r.o."]AVG7 Update Service, Avg7UpdSvc, "C:PROGRA~1GrisoftAVG7avgupsvc.exe" ["GRISOFT, s.r.o."]Windows User Mode Driver Framework, UMWdf, "C:WINDOWSsystem32wdfmgr.exe" [MS]Print Monitors:---------------HKLMSystemCurrentControlSetControlPrintMonitorshpzsnt10Driver = "hpzsnt10.dll" ["HP"]----------+ This report excludes default entries except where indicated.+ To see *everywhere* the script checks and *everything* it finds,  launch it from a command prompt or a shortcut with the -all parameter.+ To search all directories of local fixed drives for DESKTOP.INI  DLL launch points, use the -supp parameter or answer "No" at the  first message box and "Yes" at the second message box.---------- (total run time: 730 seconds, including 3 seconds for message boxes)
CatchMe
komentarz
komentarz

Teraz logi wyglądają lepiej. Czekam na CF i Gmer. :)

SE
komentarz
komentarz

kup sobie więcej ramu i wywal Norton i pzreskonuj avastem (skanowaniegruntowne)

itgregory
komentarz
komentarz

SE a skad wiesz ile gosc ma RAMu? Jak pisal Nortona juz wywalil i AVG jest rownie dobry jak Avast :P

osmaga94
komentarz
komentarz

Nic nie trzeba skanować avastem! ! Powiedzi ile masz ramu i wklej te logi o które prosił CatchMe

Yugo
komentarz
komentarz

masz zasmiecony komputer tez tak miałem, ;) format

Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!

Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.

×
×
  • Dodaj nową pozycję...

Powiadomienie o plikach cookie

Strona wykorzystuje pliki cookies w celu prawidłowego świadczenia usług i wygody użytkowników. Warunki przechowywania i dostępu do plików cookies możesz zmienić w ustawieniach przeglądarki.