Dodaj do ulubionych

Podgląd zdarzeń -WXP.

IP: *.neoplus.adsl.tpnet.pl 02.09.05, 21:42
W podglądzie zdarzeń znalazłem często powtarzający się bład LoadPerf po
podświetleniu pisze że chodzi o jakieś ciągi licznika wydajności dla uslugi
WmiApRpl nie wiem co to za usługa,a może nie jest mi potrzebna.Na googlach
wyczytałem że może to być związane z saserem,ale mi system idzie dobrze. A
może się tym nie przejmować? HijackThis v1.99.1
Safe. Shows the version of HijackThis an. The newest version is: v1.99.1!
This should be the newest version. (v1.99.1)
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Safe. Shows the version of your Internet Explorer. Newest Version is:
6.00.2800.1106!
This should be the newest version. (6.00.2900.2180)
C:\WINDOWS\System32\smss.exe
Safe. running process. (smss.exe)
Systemprozess - Anwendung, die benutzt wird um Sitzungen zu starten,
verwalten und löschen.


C:\WINDOWS\system32\winlogon.exe
Safe. running process. (winlogon.exe)
Systemprozess - Windows Login Routine


C:\WINDOWS\system32\services.exe
Safe. running process. (services.exe)
Systemprozess - Verwaltet die Systemdienste.


C:\WINDOWS\system32\lsass.exe
Safe. running process. (lsass.exe)
Systemprozess


C:\WINDOWS\system32\Ati2evxx.exe
Safe. running process. (Ati2evxx.exe)
ATI2evxx.exe is related to ATI Technologies Inc. hardware.


C:\WINDOWS\system32\svchost.exe
Safe. running process. (svchost.exe)
Systemprozess - Allgemeiner Hostprozessname für Dienste.


C:\WINDOWS\System32\svchost.exe
Safe. running process. (svchost.exe)
Systemprozess - Allgemeiner Hostprozessname für Dienste.


C:\WINDOWS\system32\LEXBCES.EXE
Safe. running process. (LEXBCES.EXE)
Lexmark LexBce Service


C:\WINDOWS\system32\spoolsv.exe
Safe. running process. (spoolsv.exe)
Systemprozess


C:\WINDOWS\system32\LEXPPS.EXE
Safe. running process. (LEXPPS.EXE)



C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
Safe. running process. (aswUpdSv.exe)



C:\Program Files\Alwil Software\Avast4\ashServ.exe
Safe. running process. (ashServ.exe)
Avast Antivirus-Scanner


C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe
Safe. running process. (outpost.exe)
Agnitum Outpost firewall

Possibly nasty! According to our database this process runs normally in
c:\programme\agnitum\outpost firewall.*\! Check if you know this process and
arrange a viruscheck where required.
C:\WINDOWS\System32\svchost.exe
Safe. running process. (svchost.exe)
Systemprozess - Allgemeiner Hostprozessname für Dienste.


C:\WINDOWS\system32\Ati2evxx.exe
Safe. running process. (Ati2evxx.exe)
ATI2evxx.exe is related to ATI Technologies Inc. hardware.


C:\WINDOWS\Explorer.EXE
Safe. running process. (Explorer.EXE)
Systemprozess für Desktop und Taskleiste.


C:\WINDOWS\SOUNDMAN.EXE
Safe. running process. (SOUNDMAN.EXE)



C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
Safe. running process. (atiptaxx.exe)
ATI Desktop Control Panel from ATI Technologies


C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
Safe. running process. (Dragdiag.exe)



C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
Safe. running process. (ashDisp.exe)


Possibly nasty! According to our database this process runs normally in
c:\programme\alwil software\avast4\! Check if you know this process and
arrange a viruscheck where required.
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
Safe. running process. (realsched.exe)



C:\Program Files\Wanadoo\taskbaricon.exe
Unknown running process. (taskbaricon.exe)

This is a unknown process.

C:\WINDOWS\gtwatch.exe
Safe. running process. (gtwatch.exe)
Associated with a Mustec scanner and not required
Not dangerous, but unnecessary.

C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
Safe. running process. (jusched.exe)
Java Runtime


C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
Safe. running process. (gcasServ.exe)
Microsoft Antispyware


C:\Program Files\Winamp\winampa.exe
Safe. running process. (winampa.exe)



C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
Safe. running process. (printray.exe)


Possibly nasty! According to our database this process runs normally in
c:\windows\system\! Check if you know this process and arrange a viruscheck
where required.
C:\WINDOWS\system32\ctfmon.exe
Safe. running process. (ctfmon.exe)



C:\WINDOWS\twain_32\S6U12K\WATCH.exe
Unknown running process. (WATCH.exe)
Associated with an Eicon Networks Diva ISDN or ADSL modem. What does it do
and is it required?
This is a unknown process.

C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
Safe. running process. (gcasDtServ.exe)
Microsoft AntiSpyware


C:\Program Files\Adobe\Acrobat 4.0\Reader\AcroRd32.exe
Safe. running process. (AcroRd32.exe)
Acrobat Reader


C:\Program Files\Wanadoo\Profil1\HijackThis.exe
Safe. running process. (HijackThis.exe)
Tool, mit dem sie dieses Logfile erzeugt haben.
Remember that Hijackthis must be run in an own folder. Only if Hijackthis
run in an own folder it will create backups!
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
szukaj.wp.pl
Safe. This page has been identified as safe.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
www.neostrada.pl
Safe. This page has been identified as safe.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title =
Neostrada Plus wita Cie w Internecie
Safe. This page has been identified as safe.

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
Łącza
Safe. This page has been identified as safe.

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
Safe. Entries found in this registry zone are potentially nasty. This
application ([06849E9F-C8D7-4D59-B87D-784B7D6BE0B3] - Result: 06849E9F-C8D7-
4D59-B87D-784B7D6BE0B3) has been checked. Hit rate: 99 %

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1
\SPYBOT~1\SDHelper.dll
Safe. Entries found in this registry zone are potentially nasty. This
application ([53707962-6F74-2D53-2644-206D7942484F] - Result: 53707962-6F74-
2D53-2644-206D7942484F) has been checked. Hit rate: 99 %

O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
Safe. System Tray icon for the Realtek AC97 Audio Sound Manager for AC97
onboard audio. Available via Start -> Settings-> Control Panel
Hit rate: 40 % (result)
Not dangerous, but unnecessary.
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control
Panel\atiptaxx.exe
Safe. Control panel for the ATI series of video cards allowing access to
such features as display resolution, colour depth, etc. Available via Start -
> Settings -> Control Panel -> Display. Some users may need it if they have
optimised their settings
Hit rate: 78 % (result)

O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program
Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
Safe. For an external Alcatel ADSL high-speed modem. A diagnostic tool and
can be run from the Start menu when required. The only reason it might be
useful on startup is if you like seeing an \'at-a-glance\' status indicator
on the taskbar (the icon is a different colour depending on the status
Obserwuj wątek
    • Gość: tata1959 Re: Podgląd zdarzeń -WXP. IP: *.neoplus.adsl.tpnet.pl 02.09.05, 22:20
      witam
      tak..po co wklejasz te gó.. z automatu,chcesz żebyśmy oślepli?
      wklej loga normalnie z programu hijackthis1.99.1.
      z tego automatu nie należy korzystać,bo to durna maszyna.
      tu do pobrania www.mgregor.republika.pl/
      pozdrawiam
      • Gość: jan232 Re: Podgląd zdarzeń -WXP. IP: *.neoplus.adsl.tpnet.pl 02.09.05, 22:35
        Już się poprawiam masz rację że można oślepnąć hLogfile of HijackThis v1.99.1
        Scan saved at 22:27:29, on 2005-09-02
        Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\LEXBCES.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\LEXPPS.EXE
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\Wanadoo\taskbaricon.exe
        C:\WINDOWS\gtwatch.exe
        C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
        C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
        C:\Program Files\Winamp\winampa.exe
        C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\WINDOWS\twain_32\S6U12K\WATCH.exe
        C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
        C:\Program Files\Wanadoo\Profil1\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
        szukaj.wp.pl
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        www.neostrada.pl
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada
        Plus wita Cie w Internecie
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
        C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1
        \SPYBOT~1\SDHelper.dll
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control
        Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program
        Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
        O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
        O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRA~1\Agnitum\OUTPOS~1.0
        \outpost.exe /waitservice
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
        Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
        O4 - HKLM\..\Run: [Gtwatch] C:\WINDOWS\gtwatch.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04
        \bin\jusched.exe
        O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft
        AntiSpyware\gcasServ.exe"
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2
        \printray.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
        Office\Office\OSA9.EXE
        O4 - Global Startup: Watch.lnk = C:\WINDOWS\twain_32\S6U12K\WATCH.exe
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
        C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
        00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner -
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32
        \Ati2evxx.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil
        Software\Avast4\ashServ.exe
        O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. -
        C:\WINDOWS\system32\LEXBCES.EXE
        O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum -
        C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe

        • Gość: tata1959 Re: Podgląd zdarzeń -WXP. IP: *.neoplus.adsl.tpnet.pl 02.09.05, 23:14
          witaj
          tak..teraz lepiej,w logu nic nie ma ,tylko dożo zbędników w autostarcie.
          O4 - HKLM\..\Run:[SunJavaUpdateSched] C:\Program
          Files\Java\j2re1.4.2_06\bin\jusched.exe
          Panel sterowania >>> Java Plug-in >>> Update >>> odptaszkuj Check for updates
          automatically
          O4 - HKLM\..\Run:[WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
          Agent winampa siedzi sobie w trayu i pilnuje żeby żaden inny progs nie
          przechwycił np. mp3.Kliknij na ikone i usuń z traya.
          O4 - HKLM\..\Run:[NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          Start >>> Uruchom >>> msconfig >>> w zakładce Uruchamianie wyłącz te wpisy.
          O4 - HKCU\..\Run:[CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          Panel sterowania >>> Ustawienia regionalne >>> Języki >>> Detale >>>
          Zaawansowane >>> odznaczyć usługi tekstowe zrób tak jeżeli nie używasz wielu języków
          O4 - Startup:Microsoft Office.lnk =C:\Program Files\Microsoft Office\Office\OSA9.EXE
          Zaś ten usuniesz przez Start >>> Programy >>> Autostart >>> kasacja z prawokliku.
          i jeszcze jedno...ten gó.wniany program od tepsy jest ci potrzebny? to kolejne
          dwie pozycje mniej w autostartach.
          a ta drukarka potrzebna w autostarcie?
          no...tak powinien komp wyglądać,a nie od samego startu być zamulony.
          ale się rozpisałem,chyba mam dobry humor.
          pozdrawiam
          .

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka