cHilfiger Skrevet 11. september 2007 Del Skrevet 11. september 2007 (endret) Hei! Har vært uten antivirus en god stund, hadde Avast!, men lisensen gikk ut. I dag fiksett jeg AVG, og Tune Up. Zonealarm støtter ikke min pc(Windows ME) Jeg skannet pcen med AVG og fant 3 stk, de blee lagret i en slags karantene hva skal jeg gjøre med dem nå? lurer også på om jeg har noe annet som keyloggere, ormer etc. hvordan ser jeg det? pcen gikk adskillig fortere før men etter sommerferien har den gått mye saktere. Tuneupen viser akkurat nå 6%, driver med diskusjon i opera med 1 fane. hvordan få den kjappere? har en god del bakrunndsprogram som kjører:(hvordan fjærne en god del her?) Klikk for å se/fjerne innholdet nedenfor - explorer- avgemc - avgcc - memoptimizer - brctrcen - winmgmt - vm_sti - dvldr16 - brmfrsmg - directcd - aircfg - systray hvilke prog. kan jeg be om å ikke starte ved oppstart?(se vedleggene, har tatt bort noen allerede) Edit: har delt harddisk ,c: og d: tar forbehold om skrivefeil! takk på forhånd 1.bmp 2.bmp Endret 11. september 2007 av Tommy_Tha_Tiger Lenke til kommentar
cHilfiger Skrevet 11. september 2007 Forfatter Del Skrevet 11. september 2007 (endret) leste posten din Norbat og lasta ned hijack her er loggen: Klikk for å se/fjerne innholdet nedenfor Logfile of Trend Micro HijackThis v2.0.2Scan saved at 20:01:43, on 11.09.2007 Platform: Windows ME (Win9x 4.90.3000) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Normal Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\WINDOWS\SYSTEM\DEVLDR16.EXE C:\WINDOWS\SYSTEM\MPREXE.EXE C:\PROGRAMFILER\WZCBDL SERVICE\WZCBDL9X.EXE C:\WINDOWS\SYSTEM\MSTASK.EXE C:\WINDOWS\SYSTEM\SSDPSRV.EXE C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE C:\WINDOWS\SYSTEM\STIMON.EXE D:\PROGRAMFILER\GRISOFT\AVG7\AVGFWSRV.EXE C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\TASKMON.EXE C:\WINDOWS\SYSTEM\SYSTRAY.EXE C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE C:\PROGRAMFILER\D-LINK\AIR UTILITY\AIRCFG.EXE C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE C:\PROGRAMFILER\BROTHER\CONTROLCENTER2\BRCTRCEN.EXE C:\WINDOWS\SYSTEM\SPOOL32.EXE C:\WINDOWS\SYSTEM\WMIEXE.EXE C:\WINDOWS\SYSTEM\BRMFRSMG.EXE D:\PROGRAMFILER\GRISOFT\AVG7\AVGCC.EXE D:\PROGRAMFILER\GRISOFT\AVG7\AVGEMC.EXE D:\PROGRAMFILER\GRISOFT\AVG7\AVGAMSVR.EXE C:\WINDOWS\VM_STI.EXE D:\PROGRAMFILER\TUNEUP UTILITIES 2007\MEMOPTIMIZER.EXE C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE C:\WINDOWS\SYSTEM\DDHELP.EXE D:\PROGRAMFILER\OPERA\OPERA.EXE D:\PROGRAMFILER\OPERA\OPERA.EXE D:\PROGRAMFILER\TUNEUP UTILITIES 2007\INTEGRATOR.EXE D:\PROGRAMFILER\TUNEUP UTILITIES 2007\STARTUPMANAGER.EXE C:\WINDOWS\PROFILES\KBN\SKRIVEBORD\HIJACK THIS\HIJACKTHIS.EXE R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startsiden.no/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch.html R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_09\bin\ssv.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX O4 - HKLM\..\Run: [scanRegistry] C:\WINDOWS\scanregw.exe /autorun O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s O4 - HKLM\..\Run: [systemTray] SysTray.Exe O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~2\ADAPTEC\DIRECTCD\DIRECTCD.EXE O4 - HKLM\..\Run: [D-Link Air Utility] C:\PROGRAMFILER\D-LINK\AIR UTILITY\AIRCFG.EXE O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\Run: [brmfRmPA.exe] C:\WINDOWS\BrmfRmPA.exe -startup O4 - HKLM\..\Run: [setDefPrt] C:\Programfiler\Brother\Brmfl05a\BrStDvPt.exe O4 - HKLM\..\Run: [ControlCenter2.0] C:\Programfiler\Brother\ControlCenter2\brctrcen.exe /autorun O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\GRISOFT\AVG7\AVGCC.EXE /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] D:\PROGRA~1\GRISOFT\AVG7\AVGEMC.EXE O4 - HKLM\..\Run: [AVG7_AMSVR] D:\PROGRA~1\GRISOFT\AVG7\AVGAMSVR.EXE O4 - HKLM\..\Run: [bigDogPath] C:\WINDOWS\VM_STI.exe Philips SPC 200NC PC Camera O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe O4 - HKLM\..\RunServices: [WZCBDLService] C:\Programfiler\WZCBDL Service\WZCBDL9X.exe O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\RunServices: [schedulingAgent] mstask.exe O4 - HKLM\..\RunServices: [sSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE O4 - HKLM\..\RunServices: [stillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE O4 - HKLM\..\RunServices: [avgfwsrv] D:\PROGRA~1\GRISOFT\AVG7\AVGFWSRV.EXE /srvfsys O4 - HKCU\..\Run: [TuneUp MemOptimizer] "D:\PROGRAMFILER\TUNEUP UTILITIES 2007\MEMOPTIMIZER.EXE" autostart O4 - .DEFAULT Startup: Microsoft Office.lnk = C:\Programfiler\Microsoft Office\Office\OSA9.EXE (User 'Default user') O4 - Startup: Statusovervåkning.lnk = C:\Programfiler\Brother\Brmfcmon\BrMfcWnd.exe O4 - User Startup: Statusovervåkning.lnk = C:\Programfiler\Brother\Brmfcmon\BrMfcWnd.exe O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000 O9 - Extra button: iFinger - {936E5D60-596C-11D3-BB96-00600816DF55} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\WINDOWS\Profiles\kbn\Start-meny\Programmer\MVU\Run IMVU.lnk (file missing) O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAMFILER\JAVA\JRE1.5.0_09\BIN\SSV.DLL O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAMFILER\JAVA\JRE1.5.0_09\BIN\SSV.DLL O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab -- End of file - 5051 bytes Endret 11. september 2007 av Tommy_Tha_Tiger Lenke til kommentar
Svenni212000 Skrevet 11. september 2007 Del Skrevet 11. september 2007 (endret) Du kan først Kjøre HijackThis og poste loggen her. I mellomtiden kan du se på dise punktene: Hvilke prosesser som kan deaktiveres vil jeg liste opp etter du har postet HijackThis loggen. ~ Avinstaller programmer du ikke trenger ~ Se til at du bruker nye og orginale drivere ~ Last ned alle oppdateringer fra Windows Update ~ Deaktiver unødvendige prosesser fra Windows oppstart ~ Kjør full scan med to nye og oppdaterte Antispyware programmer ~ Kjør full scan med et nytt og oppdatert antivirusprogram. ~ (Ikke nødvendig, men kan være en fordel) Kjør full scan med en Online Scaner, som Housecall ~ Fjern unødvendige skrotfiler fra PCen ~ Fjern ubrukelig oppføring i Windows registeret. - Ved å klikke på linken under, kan du laste ned en pakke med gode gratis programmer som kan komme til nytte. http://www.megaupload.com/?d=6QYA5ZG1 Passord er: chun$NUru2h*xadr#Yatracruzuna_ucr$kug-stem Endret 11. september 2007 av Svenni212000 Lenke til kommentar
cHilfiger Skrevet 11. september 2007 Forfatter Del Skrevet 11. september 2007 (endret) har kjørt scan med CCleaner og adaware fant 247mega med ccleaner, men ingen critical objects med adaware edit: Har delt hard disk C; og D; Endret 11. september 2007 av Tommy_Tha_Tiger Lenke til kommentar
Svenni212000 Skrevet 11. september 2007 Del Skrevet 11. september 2007 Resultat av HijackThis loggen kan du se ved å vise det skjulte innholdet nedenfor. Jeg vil også råde deg til å avinstalelre programmene du har på D: og installere disse på samme stasjon som Windows er installert, C:\ disken. Du kan lagre filer på en annen harddisk eller partisjon, men programmer o.l bør installeres på samme stasjon som Windows. Klikk for å se/fjerne innholdet nedenfor Grønn skrift= Viktige prosesser, la disse være.Orange skrift= Er ikke nødvendig, men du vil miste funskjoneer om du deaktiverer disse prosessene. Blå skrif= Unødvendige prosesser. Disse kan trygt deaktiveres for å spare systemressurser Rød skrift= Infiserte filer. Disse bør straks renskes og fjernes fra maskinen. Grå skrift= ukjent prosess C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE mmtask.tsk C:\WINDOWS\SYSTEM\DEVLDR16.EXE O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe Associated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use "Sound Play Control" and "Sound Recorder". To disable: (1) Disable via MSCONFIG (2) Start -> Settings -> Control Panel -> System -> Device Manager then disable "Creative SB16 Emulation" under Creative Miscellaneous Devices C:\WINDOWS\SYSTEM\MPREXE.EXE C:\PROGRAMFILER\WZCBDL SERVICE\WZCBDL9X.EXE C:\WINDOWS\SYSTEM\MSTASK.EXE O4 - HKLM\..\RunServices: [schedulingAgent] mstask.exe MS Scheduling Agent displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting, ScanDisk, etc. Required if you have regularily scheduled events such as weekly virus scans C:\WINDOWS\SYSTEM\SSDPSRV.EXE O4 - HKLM\..\RunServices: [sSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe Simple Service Discovery Protocol (SSDP) and General Event Notification Architecture (GENA) services for network plug and play functionality. Starts up a web server on port 5000. Used by Universal Plug and Play (for network device discovery). To remove this program, open Add/Remove Programs, select either Communications (Me) or Networking Services (XP), and remove the checkmark next to Universal Plug and Play C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE C:\WINDOWS\SYSTEM\STIMON.EXE O4 - HKLM\..\RunServices: [stillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE Stimon.exe enables a USB still-image device (such as a scanner) to initiate data transfer to a program. For example, if your scanning device has a scan button, it may start a program and begin scanning when you press it. Create a shortcut and start it manually when needed if your scanner otherwise fails to scan. May be required for your USB scanner to work - including all HP scanners and some of their SCSI scanners D:\PROGRAMFILER\GRISOFT\AVG7\AVGFWSRV.EXE O4 - HKLM\..\RunServices: [avgfwsrv] D:\PROGRA~1\GRISOFT\AVG7\AVGFWSRV.EXE /srvfsys C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\TASKMON.EXE O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe The Task Monitor checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase) C:\WINDOWS\SYSTEM\SYSTRAY.EXE O4 - HKLM\..\Run: [systemTray] SysTray.Exe C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~2\ADAPTEC\DIRECTC\DIRECTCD.EXE DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later C:\PROGRAMFILER\D-LINK\AIR UTILITY\AIRCFG.EXE O4 - HKLM\..\Run: [D-Link Air Utility] C:\PROGRAMFILER\D-LINK\AIR UTILITY\AIRCFG.EXE C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE C:\PROGRAMFILER\BROTHER\CONTROLCENTER2\BRCTRCEN.EXE Brother scanner 'Control Center' application - can be started manually C:\WINDOWS\SYSTEM\SPOOL32.EXE ASASSIN eller YAB.A Trojaner C:\WINDOWS\SYSTEM\WMIEXE.EXE C:\WINDOWS\SYSTEM\BRMFRSMG.EXE D:\PROGRAMFILER\GRISOFT\AVG7\AVGCC.EXE O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\GRISOFT\AVG7\AVGCC.EXE /STARTUP D:\PROGRAMFILER\GRISOFT\AVG7\AVGEMC.EXE O4 - HKLM\..\Run: [AVG7_EMC] D:\PROGRA~1\GRISOFT\AVG7\AVGEMC.EXE D:\PROGRAMFILER\GRISOFT\AVG7\AVGAMSVR.EXE O4 - HKLM\..\Run: [AVG7_AMSVR] D:\PROGRA~1\GRISOFT\AVG7\AVGAMSVR.EXE C:\WINDOWS\VM_STI.EXE O4 - HKLM\..\Run: [bigDogPath] C:\WINDOWS\VM_STI.exe Philips SPC 200NC PC Camera This is a valid program that is bundled with many digital cameras that use a USB connection. The program is used to capture still shots from the camera. D:\PROGRAMFILER\TUNEUP UTILITIES 2007\MEMOPTIMIZER.EXE O4 - HKCU\..\Run: [TuneUp MemOptimizer] "D:\PROGRAMFILER\TUNEUP UTILITIES 2007\MEMOPTIMIZER.EXE" autostart Part of "TuneUp Utilities", specifically 2003 version. "Monitors and optimizes free memory in the background." Basically, it cleans RAM and also allows you to clear the clipboard C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" C:\WINDOWS\SYSTEM\DDHELP.EXE D:\PROGRAMFILER\OPERA\OPERA.EXE D:\PROGRAMFILER\OPERA\OPERA.EXE D:\PROGRAMFILER\TUNEUP UTILITIES 2007\INTEGRATOR.EXE D:\PROGRAMFILER\TUNEUP UTILITIES 2007\STARTUPMANAGER.EXE O4 - HKLM\..\Run: [scanRegistry] C:\WINDOWS\scanregw.exe /autorun O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings O4 - HKLM\..\Run: [brmfRmPA.exe] C:\WINDOWS\BrmfRmPA.exe -startup O4 - HKLM\..\Run: [setDefPrt] C:\Programfiler\Brother\Brmfl05a\BrStDvPt.exe O4 - HKLM\..\Run: [ControlCenter2.0] C:\Programfiler\Brother\ControlCenter2\brctrcen.exe/autorun Brother scanner 'Control Center' application - can be started manually O4 - HKLM\..\RunServices: [WZCBDLService] C:\Programfiler\WZCBDL Service\WZCBDL9X.exe O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe O4 - .DEFAULT Startup: Microsoft Office.lnk = C:\Programfiler\Microsoft Office\Office\OSA9.EXE (User 'Default user') Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show O4 - Startup: Statusovervåkning.lnk = C:\Programfiler\Brother\Brmfcmon\BrMfcWnd.exe Brother scanner status monitor - can be started manually Lenke til kommentar
cHilfiger Skrevet 12. september 2007 Forfatter Del Skrevet 12. september 2007 problemmet er at jeg har 100megabyte ledig plass på C; Lenke til kommentar
Trainman Skrevet 12. september 2007 Del Skrevet 12. september 2007 Resultat av HijackThis loggen kan du se ved å vise det skjulte innholdet nedenfor.Jeg vil også råde deg til å avinstalelre programmene du har på D: og installere disse på samme stasjon som Windows er installert, C:\ disken. Du kan lagre filer på en annen harddisk eller partisjon, men programmer o.l bør installeres på samme stasjon som Windows. Klikk for å se/fjerne innholdet nedenfor Grønn skrift= Viktige prosesser, la disse være.Orange skrift= Er ikke nødvendig, men du vil miste funskjoneer om du deaktiverer disse prosessene. Blå skrif= Unødvendige prosesser. Disse kan trygt deaktiveres for å spare systemressurser Rød skrift= Infiserte filer. Disse bør straks renskes og fjernes fra maskinen. Grå skrift= ukjent prosess C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE mmtask.tsk C:\WINDOWS\SYSTEM\DEVLDR16.EXE O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe Associated with some Creative Labs sound cards. Provides audio support for DOS applications. Not needed if you don't have those. Required if you use "Sound Play Control" and "Sound Recorder". To disable: (1) Disable via MSCONFIG (2) Start -> Settings -> Control Panel -> System -> Device Manager then disable "Creative SB16 Emulation" under Creative Miscellaneous Devices C:\WINDOWS\SYSTEM\MPREXE.EXE C:\PROGRAMFILER\WZCBDL SERVICE\WZCBDL9X.EXE C:\WINDOWS\SYSTEM\MSTASK.EXE O4 - HKLM\..\RunServices: [schedulingAgent] mstask.exe MS Scheduling Agent displayed as a box with a stopwatch in the System Tray that is only needed if you have regular scheduled disk defragmenting, ScanDisk, etc. Required if you have regularily scheduled events such as weekly virus scans C:\WINDOWS\SYSTEM\SSDPSRV.EXE O4 - HKLM\..\RunServices: [sSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe Simple Service Discovery Protocol (SSDP) and General Event Notification Architecture (GENA) services for network plug and play functionality. Starts up a web server on port 5000. Used by Universal Plug and Play (for network device discovery). To remove this program, open Add/Remove Programs, select either Communications (Me) or Networking Services (XP), and remove the checkmark next to Universal Plug and Play C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE C:\WINDOWS\SYSTEM\STIMON.EXE O4 - HKLM\..\RunServices: [stillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE Stimon.exe enables a USB still-image device (such as a scanner) to initiate data transfer to a program. For example, if your scanning device has a scan button, it may start a program and begin scanning when you press it. Create a shortcut and start it manually when needed if your scanner otherwise fails to scan. May be required for your USB scanner to work - including all HP scanners and some of their SCSI scanners D:\PROGRAMFILER\GRISOFT\AVG7\AVGFWSRV.EXE O4 - HKLM\..\RunServices: [avgfwsrv] D:\PROGRA~1\GRISOFT\AVG7\AVGFWSRV.EXE /srvfsys C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\TASKMON.EXE O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe The Task Monitor checks the disk-access patterns of programs when they are started and stores this information in log files in the Applog folder. Task Monitor also records the number of times you use a program. The Disk Defragmenter tool uses this information to optimize your hard disk so that programs that you use frequently are loaded faster. Not required - but can be useful. Note: for Norton Anti-Virus 2002 users, loading TaskMonitor will typically solve many, if not most, of those annoying IE scripting errors (per Symantec's Knowledgebase) C:\WINDOWS\SYSTEM\SYSTRAY.EXE O4 - HKLM\..\Run: [systemTray] SysTray.Exe C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~2\ADAPTEC\DIRECTC\DIRECTCD.EXE DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later C:\PROGRAMFILER\D-LINK\AIR UTILITY\AIRCFG.EXE O4 - HKLM\..\Run: [D-Link Air Utility] C:\PROGRAMFILER\D-LINK\AIR UTILITY\AIRCFG.EXE C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE C:\PROGRAMFILER\BROTHER\CONTROLCENTER2\BRCTRCEN.EXE Brother scanner 'Control Center' application - can be started manually C:\WINDOWS\SYSTEM\SPOOL32.EXE ASASSIN eller YAB.A Trojaner C:\WINDOWS\SYSTEM\WMIEXE.EXE C:\WINDOWS\SYSTEM\BRMFRSMG.EXE D:\PROGRAMFILER\GRISOFT\AVG7\AVGCC.EXE O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\GRISOFT\AVG7\AVGCC.EXE /STARTUP D:\PROGRAMFILER\GRISOFT\AVG7\AVGEMC.EXE O4 - HKLM\..\Run: [AVG7_EMC] D:\PROGRA~1\GRISOFT\AVG7\AVGEMC.EXE D:\PROGRAMFILER\GRISOFT\AVG7\AVGAMSVR.EXE O4 - HKLM\..\Run: [AVG7_AMSVR] D:\PROGRA~1\GRISOFT\AVG7\AVGAMSVR.EXE C:\WINDOWS\VM_STI.EXE O4 - HKLM\..\Run: [bigDogPath] C:\WINDOWS\VM_STI.exe Philips SPC 200NC PC Camera This is a valid program that is bundled with many digital cameras that use a USB connection. The program is used to capture still shots from the camera. D:\PROGRAMFILER\TUNEUP UTILITIES 2007\MEMOPTIMIZER.EXE O4 - HKCU\..\Run: [TuneUp MemOptimizer] "D:\PROGRAMFILER\TUNEUP UTILITIES 2007\MEMOPTIMIZER.EXE" autostart Part of "TuneUp Utilities", specifically 2003 version. "Monitors and optimizes free memory in the background." Basically, it cleans RAM and also allows you to clear the clipboard C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE Used for Enterprise Management. If you are not an IT Administrator you don't need it to be running. Also runs from the PCHealth "scheduler" C:\WINDOWS\SYSTEM\DDHELP.EXE D:\PROGRAMFILER\OPERA\OPERA.EXE D:\PROGRAMFILER\OPERA\OPERA.EXE D:\PROGRAMFILER\TUNEUP UTILITIES 2007\INTEGRATOR.EXE D:\PROGRAMFILER\TUNEUP UTILITIES 2007\STARTUPMANAGER.EXE O4 - HKLM\..\Run: [scanRegistry] C:\WINDOWS\scanregw.exe /autorun O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe Control panel for the ATI series of video cards allowing access to such features as display resolution, colour depth, etc. Available via Start -> Settings -> Control Panel -> Display. Some users may need it if they have optimised their settings O4 - HKLM\..\Run: [brmfRmPA.exe] C:\WINDOWS\BrmfRmPA.exe -startup O4 - HKLM\..\Run: [setDefPrt] C:\Programfiler\Brother\Brmfl05a\BrStDvPt.exe O4 - HKLM\..\Run: [ControlCenter2.0] C:\Programfiler\Brother\ControlCenter2\brctrcen.exe/autorun Brother scanner 'Control Center' application - can be started manually O4 - HKLM\..\RunServices: [WZCBDLService] C:\Programfiler\WZCBDL Service\WZCBDL9X.exe O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe O4 - .DEFAULT Startup: Microsoft Office.lnk = C:\Programfiler\Microsoft Office\Office\OSA9.EXE (User 'Default user') Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it but it usually isn't required. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show O4 - Startup: Statusovervåkning.lnk = C:\Programfiler\Brother\Brmfcmon\BrMfcWnd.exe Brother scanner status monitor - can be started manually 9475246[/snapback] Ikke enig at alle programmer bør innstalleres på samme harddisk som windows. Ligger windows på C-disken, bør du legge programmer og alt annet på D-disken. PC`en jobber raskere hvis windows har en harddisk for seg selv. Jeg vet at mange av bl.a DLL filene fra de forskjellige programmene legger seg i systemmappene i windows, men hvis du i tillegg skal ha alle programmer liggende sammen med windows vil windows bli treg. Lenke til kommentar
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå