jak w temacie, ostatnio nie wszystko śmiga jak powinno, każdy najmniejszy proces zajmuje przynajmniej 1500K, jeśli dojdzie do tego powiedzmy Firefox, GG i foobar, czyli dość standardowy zestaw, to robi się nieprzyjemnie. Dwuklik w cokolwiek skutkuje kilkakrotnie dłuższym oczekiwaniem niż zazwyczaj. Log z DDS:
- Kod: Zaznacz wszystko
DDS (Ver_09-07-30.01) - NTFSx86
Run by Piondis at 11:07:41,79 on 2009-08-10
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.495.91 [GMT 2:00]
AV: avast! antivirus 4.8.1335 [VPS 090809-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
D:\Zabezpieczenia\Comodo\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
d:\Programy\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
svchost.exe
D:\Programy\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\nvsvc32.exe
D:\Zabezpieczenia\Comodo\COMODO Internet Security\cfp.exe
C:\WINDOWS\system32\UTSCSI.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HACE\Mmm\Mmm.exe
D:\Programy\Nowe Gadu-Gadu\gg.exe
d:\Programy\Alwil Software\Avast4\ashMaiSv.exe
d:\Programy\Alwil Software\Avast4\ashWebSv.exe
D:\Programy\Nowe Gadu-Gadu\spellchecker_gg.exe
d:\Programy\foobar2000\foobar2000.exe
D:\Programy\Last.fm\LastFM.exe
C:\WINDOWS\system32\taskmgr.exe
D:\Programy\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Piondis\Pulpit\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.pl/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - d:\programy\bitcomet\tools\BitCometBHO_1.2.8.7.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: IEPluginBHO Class: {f5cc7f02-6f4e-4462-b5b1-394a57fd3e0d} - c:\documents and settings\piondis\dane aplikacji\nowe gadu-gadu\_userdata\ggbho.1.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [Mmm] "c:\program files\hace\mmm\Mmm.exe"
uRun: [Nowe Gadu-Gadu] "d:\programy\nowe gadu-gadu\gg.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SkyTel] SkyTel.EXE
mRun: [avast!] d:\programy\alwils~1\avast4\ashDisp.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [COMODO Internet Security] "d:\zabezpieczenia\comodo\comodo internet security\cfp.exe" -h
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: E&ksport do programu Microsoft Excel - d:\programy\micros~1\office11\EXCEL.EXE/3000
IE: Pobierz wszystkie VIdeo za pomocą BitComet - d:\programy\bitcomet\BitComet.exe/AddVideo.htm
IE: Pobierz wszystko za pomocą BitComet - d:\programy\bitcomet\BitComet.exe/AddAllLink.htm
IE: Pobierz za pomocą BitComet - d:\programy\bitcomet\BitComet.exe/AddLink.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\programy\micros~1\office11\REFIEBAR.DLL
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1249332941656
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} - file://f:\cdviewer\CdViewer.cab
TCP: {23F252FE-E98F-4056-8FD3-E379E631F0B7} = 217.30.129.149,217.30.137.200
AppInit_DLLs: c:\windows\system32\guard32.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\piondis\daneap~1\mozilla\firefox\profiles\bsexdlyw.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - google.pl
FF - plugin: c:\documents and settings\all users\dane aplikacji\id software\quakelive\npquakezero.dll
FF - plugin: c:\documents and settings\piondis\dane aplikacji\nowe gadu-gadu\_userdata\npgg.1.dll
FF - plugin: d:\programy\adobe\reader\browser\nppdf32.dll
FF - plugin: d:\programy\real alternative\browser\plugins\nppl3260.dll
FF - plugin: d:\programy\real alternative\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Java Console: No Registry Reference - d:\programy\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - d:\programy\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
d:\programy\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
d:\programy\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
d:\programy\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
d:\programy\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
d:\programy\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
d:\programy\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
d:\programy\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
d:\programy\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
d:\programy\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
d:\programy\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
d:\programy\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
d:\programy\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
d:\programy\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
d:\programy\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
d:\programy\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
d:\programy\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
d:\programy\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
d:\programy\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
d:\programy\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
d:\programy\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-10-20 114768]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-2-17 132040]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2009-2-17 25160]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-10-20 20560]
R2 avast! Antivirus;avast! Antivirus;d:\programy\alwil software\avast4\ashServ.exe [2008-10-20 138680]
R2 cmdAgent;COMODO Internet Security Helper Service;d:\zabezpieczenia\comodo\comodo internet security\cmdagent.exe [2009-2-17 707152]
R3 avast! Mail Scanner;avast! Mail Scanner;d:\programy\alwil software\avast4\ashMaiSv.exe [2008-10-20 254040]
R3 avast! Web Scanner;avast! Web Scanner;d:\programy\alwil software\avast4\ashWebSv.exe [2008-10-20 352920]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\f:\ntglm7x.sys --> f:\NTGLM7X.sys [?]
=============== Created Last 30 ================
2009-08-08 11:29 <DIR> --d----- c:\docume~1\piondis\daneap~1\K-Meleon
2009-08-04 20:40 227,840 -c------ c:\windows\system32\dllcache\wmiprvse.exe
2009-08-04 20:40 2,190,336 -c------ c:\windows\system32\dllcache\ntoskrnl.exe
2009-08-04 20:40 401,408 -c------ c:\windows\system32\dllcache\rpcss.dll
2009-08-04 20:40 285,696 -c------ c:\windows\system32\dllcache\pdh.dll
2009-08-04 20:40 111,104 -c------ c:\windows\system32\dllcache\services.exe
2009-08-04 20:40 731,136 -c------ c:\windows\system32\dllcache\lsasrv.dll
2009-08-04 20:40 722,944 -c------ c:\windows\system32\dllcache\ntdll.dll
2009-08-04 20:40 686,592 -c------ c:\windows\system32\dllcache\advapi32.dll
2009-08-04 20:40 473,600 -c------ c:\windows\system32\dllcache\fastprox.dll
2009-08-04 20:40 453,120 -c------ c:\windows\system32\dllcache\wmiprvsd.dll
2009-08-04 20:40 2,146,816 -c------ c:\windows\system32\dllcache\ntkrnlmp.exe
2009-08-04 20:40 2,025,472 -c------ c:\windows\system32\dllcache\ntkrpamp.exe
2009-08-04 20:37 337,408 -c------ c:\windows\system32\dllcache\netapi32.dll
2009-08-04 20:19 273,024 -c------ c:\windows\system32\dllcache\bthport.sys
2009-08-04 20:16 203,136 -c------ c:\windows\system32\dllcache\rmcast.sys
2009-08-04 20:15 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2009-08-04 20:15 333,952 -c------ c:\windows\system32\dllcache\srv.sys
2009-08-04 20:14 691,712 -c------ c:\windows\system32\dllcache\inetcomm.dll
2009-08-04 10:37 27,496 a------- c:\windows\system32\mucltui.dll.mui
2009-08-04 10:37 268,648 a------- c:\windows\system32\mucltui.dll
2009-08-03 23:42 <DIR> --d----- c:\windows\l2schemas
2009-08-03 23:42 <DIR> --d----- c:\windows\system32\pl
2009-08-03 23:42 <DIR> --d----- c:\windows\system32\bits
2009-08-03 23:32 <DIR> --d----- c:\windows\ServicePackFiles
2009-08-03 22:53 25,471 -------- c:\windows\system32\drivers\watv10nt.sys
2009-08-03 22:52 184,320 -------- c:\windows\system32\microsoft.managementconsole.dll
2009-08-03 22:51 4,255 -------- c:\windows\system32\drivers\adv01nt5.dll
2009-08-03 22:51 3,967 -------- c:\windows\system32\drivers\adv02nt5.dll
2009-08-03 22:51 3,775 -------- c:\windows\system32\drivers\adv11nt5.dll
2009-08-03 22:51 3,711 -------- c:\windows\system32\drivers\adv09nt5.dll
2009-08-03 22:51 3,647 -------- c:\windows\system32\drivers\adv07nt5.dll
2009-08-03 22:51 3,615 -------- c:\windows\system32\drivers\adv05nt5.dll
2009-08-03 22:51 3,135 -------- c:\windows\system32\drivers\adv08nt5.dll
2009-08-03 22:51 136,192 -------- c:\windows\system32\aaclient.dll
2009-08-03 22:51 <DIR> --dsh--- c:\documents and settings\piondis\IECompatCache
2009-08-03 22:51 <DIR> --dsh--- c:\documents and settings\piondis\PrivacIE
2009-08-03 22:22 <DIR> --dsh--- c:\documents and settings\piondis\IETldCache
2009-08-03 22:18 12,800 -c------ c:\windows\system32\dllcache\xpshims.dll
2009-08-03 22:18 1,985,536 -c------ c:\windows\system32\dllcache\iertutil.dll
2009-08-03 22:18 594,432 -c------ c:\windows\system32\dllcache\msfeeds.dll
2009-08-03 22:18 246,272 -c------ c:\windows\system32\dllcache\ieproxy.dll
2009-08-03 22:18 55,296 -c------ c:\windows\system32\dllcache\msfeedsbs.dll
2009-08-03 22:18 11,067,392 -c------ c:\windows\system32\dllcache\ieframe.dll
2009-08-03 22:18 <DIR> --d----- c:\windows\ie8updates
2009-08-03 22:18 101,376 -c------ c:\windows\system32\dllcache\iecompat.dll
2009-08-03 22:15 <DIR> -cd-h--- c:\windows\ie8
2009-08-03 22:15 <DIR> --d----- c:\windows\system32\pl-PL
2009-07-31 12:16 <DIR> --d----- c:\program files\common files\Xing Shared
2009-07-31 12:16 <DIR> --d----- c:\program files\Xing
2009-07-31 12:16 317,952 a------- c:\windows\system32\Roboex32.dll
2009-07-27 04:43 58,908 a------- c:\windows\system32\drivers\scdemu.sys
==================== Find3M ====================
2009-08-04 21:10 355,486 a------- c:\windows\system32\perfh015.dat
2009-08-04 21:10 49,492 a------- c:\windows\system32\perfc015.dat
2009-08-03 23:47 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-07-31 14:52 179,792 a------- c:\windows\system32\guard32.dll
2009-07-31 14:52 25,160 a------- c:\windows\system32\drivers\cmdhlp.sys
2009-07-31 14:52 132,040 a------- c:\windows\system32\drivers\cmdguard.sys
2009-07-03 18:59 915,456 a------- c:\windows\system32\wininet.dll
2009-06-27 12:04 75,064 a------- c:\windows\system32\PnkBstrA.exe
2009-06-27 11:31 22,328 a------- c:\docume~1\piondis\daneap~1\PnkBstrK.sys
2009-06-19 09:17 45,056 a------- c:\windows\system32\UTSCSI.EXE
2009-06-16 16:40 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 16:40 81,920 a------- c:\windows\system32\fontsub.dll
2009-06-03 21:11 1,294,848 a------- c:\windows\system32\quartz.dll
============= FINISH: 11:08:28,37 ===============
.