Mam XP, z SP3, regularne skany Avastem, reg-cleanerem i Ad-awarem, ale COŚ mi w komputerze szwankuje. Od pewnego czasu co jakiś czas przy wyłączaniu komputera pojawiały się jakieś nieodpowiadające programy, które musiałam zamykać ręcznie (niestety nie zapisałam jakie). Skany kilkoma antywirami i defragmentacja na jakiś czas pomogła, ale od wczoraj jest rozpaczliwie.
Objawy:
1. explorer.exe przez prawie cały czas zajmuje 50% CPU
2. do niego co jakiś czas dołącza się wuauclt.exe i zajmuje do 50% CPU
3. wszelkie inne działania (łącznie z uruchomieniem taskmanagera) trwają wieki
4. przy uruchamianiu komputera CHKDSK naprawia różne pliki i ich indeksy
5. ikony na pulpicie ustawiają się chaotycznie, jak je uporządkuję - po chwili znów robią bałagan
6. sporo ikon (np. w folderze panel sterowania) nie wygląda jak powinny - wyglądają jak nierozpoznane
7. nie mogę dodać ani usunąć programów - nie wyświetla się ich lista
8. przynajmniej jeden plik video (ściągnięty wczoraj z youtube, muzyka relaksacyjna) "jest używany przez jakiś program", więc nie mogę go usunąć ani przenieść - oczywiście zamknęłam wszystkie playery, nie pomaga
9. odinstalowała mi się samoczynnie Mozilla Firefox, musiałam ją na nowo zainstalować (na razie działa)
10. "pulpit się zawiesza" - znika dolny pasek i ikony i muszę restartować (zrobiło się tak również podczas pisania tego postu...)
11. na pulpicie jest ikona Moje Dokumenty, ale nie ma jej nazwy, nie mogę jej nijak wpisać
Nie mogę uzyskać loga z GMERa, gdyż występują kłopoty z aplikacją i zostaje ona zamknięta (ściągnęłam już z kilku miejsc, problem się powtarza). Nie mam świadomości posiadania programów emulujących napędy, a nawet jeśli je mam - nie umiem ich odinstalować (vide objaw 7).
EDIT: Dzięki pomocy Mikou@ja uruchomiłam GMERa. W międczyczasie ożyła opcja dodaj/usuń programy, za to padł Windows Media Player. 4-krotny reset (3 razy guzikiem, raz się sam komp zresetował) i już mam loga:
- Kod: Zaznacz wszystko
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-08 16:13:26
Windows 5.1.2600 Dodatek Service Pack 3
Running: 9y4c5nht.exe; Driver: C:\DOCUME~1\Asia\USTAWI~1\Temp\kwroykoc.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB5B806B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB5B80574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB5B80A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB5B8014C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB5B8064E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB5B8008C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB5B800F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB5B8076E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB5B8072E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB5B808AE]
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB90D4360, 0x3541AF, 0xE8000020]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\services.exe[768] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002
IAT C:\WINDOWS\system32\services.exe[768] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x93 0xAD 0xCB 0x24 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x47 0x5B 0xDA 0x5C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x0C 0x3F 0x6A 0x0E ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x93 0xAD 0xCB 0x24 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x47 0x5B 0xDA 0x5C ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x0C 0x3F 0x6A 0x0E ...
---- EOF - GMER 1.0.15 ----
OTL.txt:
- Kod: Zaznacz wszystko
OTL logfile created on: 2010-03-08 11:12:13 - Run 2
OTL by OldTimer - Version 3.1.35.0 Folder = D:\Moje Dokumenty\Pobieranie
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 56,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 86,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 78,13 Gb Total Space | 67,16 Gb Free Space | 85,96% Space Free | Partition Type: NTFS
Drive D: | 193,36 Gb Total Space | 21,69 Gb Free Space | 11,22% Space Free | Partition Type: NTFS
Drive E: | 194,27 Gb Total Space | 58,75 Gb Free Space | 30,24% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: POPKO-DCA9F0838
Current User Name: Asia
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2010-03-08 01:17:38 | 000,554,496 | ---- | M] (OldTimer Tools) -- D:\Moje Dokumenty\Pobieranie\OTL.exe
PRC - [2010-02-21 18:16:45 | 000,815,184 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2010-02-21 18:16:41 | 001,229,232 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2009-11-25 00:51:40 | 000,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009-11-25 00:51:35 | 000,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009-11-25 00:51:21 | 000,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009-11-25 00:48:48 | 000,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009-11-25 00:43:56 | 000,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009-11-18 20:44:12 | 000,386,872 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jucheck.exe
PRC - [2009-11-08 23:01:11 | 000,198,160 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009-08-19 10:38:10 | 007,418,368 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2009-08-19 10:38:08 | 007,424,000 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2009-04-30 12:23:26 | 000,090,112 | ---- | M] () -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
PRC - [2009-04-15 13:36:36 | 032,014,336 | ---- | M] () -- C:\Program Files\MSI\DualCoreCenter\DualCoreCenter.exe
PRC - [2008-04-14 22:51:18 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007-06-11 11:18:00 | 000,537,520 | ---- | M] ( ) -- C:\WINDOWS\system32\lxdjcoms.exe
PRC - [2007-04-30 08:19:54 | 000,020,480 | ---- | M] () -- C:\Program Files\Lexmark 1400 Series\lxdjamon.exe
PRC - [2004-09-07 16:25:12 | 001,151,090 | ---- | M] (Ahead Software AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe
PRC - [2004-09-07 14:25:58 | 001,400,944 | ---- | M] (Ahead Software AG) -- C:\Program Files\Ahead\InCD\InCD.exe
PRC - [2001-10-08 12:59:36 | 000,049,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\Fast.exe
PRC - [2001-10-08 12:59:36 | 000,045,632 | ---- | M] () -- C:\WINDOWS\system32\TaskSwitch.exe
[color=#E56717]========== Modules (SafeList) ==========[/color]
MOD - [2010-03-08 01:17:38 | 000,554,496 | ---- | M] (OldTimer Tools) -- D:\Moje Dokumenty\Pobieranie\OTL.exe
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV - [2010-02-23 23:25:11 | 000,068,096 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe -- (Macromedia Licensing Service)
SRV - [2010-02-21 18:16:41 | 001,229,232 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2009-11-25 00:51:35 | 000,138,680 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus)
SRV - [2009-11-25 00:51:21 | 000,254,040 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner)
SRV - [2009-11-25 00:48:48 | 000,352,920 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner)
SRV - [2009-11-25 00:43:56 | 000,018,752 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv)
SRV - [2009-04-30 12:23:26 | 000,090,112 | ---- | M] () [Auto | Running] -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe -- (OMSI download service)
SRV - [2007-06-11 11:18:00 | 000,537,520 | ---- | M] ( ) [Auto | Running] -- C:\WINDOWS\System32\lxdjcoms.exe -- (lxdj_device)
SRV - [2007-06-11 11:17:46 | 000,099,248 | ---- | M] () [Auto | Stopped] -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdjserv.exe -- (lxdjCATSCustConnectService)
SRV - [2004-09-07 16:25:12 | 001,151,090 | ---- | M] (Ahead Software AG) [Auto | Running] -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv)
SRV - [2001-10-08 12:59:36 | 000,049,216 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\System32\Fast.exe -- (InteractiveLogon)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - [2010-02-04 16:53:02 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2010-01-03 17:22:10 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009-11-25 00:49:07 | 000,048,560 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2009-11-25 00:48:57 | 000,023,120 | ---- | M] (ALWIL Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2009-11-25 00:47:54 | 000,027,408 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2009-09-15 12:56:14 | 000,094,160 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2009-09-15 12:55:30 | 000,114,768 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswSP.sys -- (aswSP)
DRV - [2009-09-15 12:55:19 | 000,020,560 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2009-03-18 10:56:12 | 000,055,296 | ---- | M] (Your Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\MSI\DualCoreCenter\RushTop.sys -- (RushTopDevice2)
DRV - [2009-01-15 20:42:00 | 006,305,120 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2008-12-08 10:30:22 | 000,028,672 | ---- | M] (MICRO-STAR INT'L CO., LTD.) [Kernel | On_Demand | Running] -- C:\Program Files\MSI\DualCoreCenter\NTGLM7X.sys -- (DualCoreCenter)
DRV - [2008-11-12 09:58:38 | 000,145,952 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvgts.sys -- (nvgts)
DRV - [2008-10-21 10:22:48 | 000,114,600 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017mdm.sys -- (s0017mdm)
DRV - [2008-10-21 10:22:48 | 000,109,736 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017unic.sys -- (s0017unic) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM)
DRV - [2008-10-21 10:22:48 | 000,108,328 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017mgmt.sys -- (s0017mgmt) Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM)
DRV - [2008-10-21 10:22:48 | 000,104,616 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017obex.sys -- (s0017obex)
DRV - [2008-10-21 10:22:48 | 000,086,824 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017bus.sys -- (s0017bus) Sony Ericsson Device 0017 driver (WDM)
DRV - [2008-10-21 10:22:48 | 000,026,024 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017nd5.sys -- (s0017nd5) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS)
DRV - [2008-10-21 10:22:48 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017mdfl.sys -- (s0017mdfl)
DRV - [2008-08-24 19:22:40 | 000,014,208 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2008-08-05 13:10:12 | 001,684,736 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2008-04-17 16:33:26 | 004,707,328 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008-04-13 22:06:06 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2008-01-09 11:28:34 | 000,027,632 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\seehcri.sys -- (seehcri)
DRV - [2006-10-13 08:18:14 | 000,006,912 | ---- | M] (NVidia Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\nvoclock.sys -- (NVR0Dev)
DRV - [2006-08-14 14:51:28 | 000,105,344 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata)
DRV - [2006-07-11 21:38:30 | 000,020,480 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2006-07-11 21:38:28 | 000,057,856 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2006-07-01 23:32:26 | 000,043,520 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2006-01-04 08:41:48 | 001,389,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2004-09-07 16:27:38 | 000,028,544 | ---- | M] (Ahead Software AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\InCDpass.sys -- (InCDPass)
DRV - [2004-09-07 16:27:22 | 000,091,136 | ---- | M] (Ahead Software AG) [File_System | Disabled | Running] -- C:\WINDOWS\system32\drivers\InCDfs.sys -- (InCDfs)
DRV - [2003-12-05 10:46:36 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..browser.startup.homepage: "http://poczta.onet.pl/login.html|http://profil.wp.pl/login.html?url=http%3A%2F%2Fpoczta.wp.pl%2Findex.html%3Fflg%3D1&serwis=nowa_poczta_wp&ticaid=19649"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010-03-08 10:23:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-03-08 10:23:45 | 000,000,000 | ---D | M]
[2009-11-04 12:23:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Asia\Dane aplikacji\Mozilla\Extensions
[2010-03-08 10:33:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Asia\Dane aplikacji\Mozilla\Firefox\Profiles\54kxhk9a.default\extensions
[2009-11-18 11:22:54 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Asia\Dane aplikacji\Mozilla\Firefox\Profiles\54kxhk9a.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010-03-08 10:23:57 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010-01-13 23:46:00 | 000,063,488 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2010-01-16 02:08:36 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml
[2010-01-16 02:08:36 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml
[2010-01-16 02:08:36 | 000,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml
[2010-01-16 02:08:36 | 000,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml
[2010-01-16 02:08:36 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml
[2010-01-16 02:08:36 | 000,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml
O1 HOSTS File: ([2001-10-26 16:45:16 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [CoolSwitch] C:\WINDOWS\system32\TaskSwitch.exe ()
O4 - HKLM..\Run: [DelReg] C:\Program Files\MSI\DualCoreCenter\DelReg.exe ()
O4 - HKLM..\Run: [FastUser] C:\WINDOWS\system32\Fast.exe (Microsoft Corporation)
O4 - HKLM..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe (Ahead Software AG)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [lxdjamon] C:\Program Files\Lexmark 1400 Series\lxdjamon.exe ()
O4 - HKLM..\Run: [MP10_EnsureFileVer] C:\WINDOWS\inf\unregmp2.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [Nowe Gadu-Gadu] C:\Program Files\Nowe Gadu-Gadu\gg.exe (GG Network S.A.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\DualCoreCenter.lnk = C:\Program Files\MSI\DualCoreCenter\StartUpDualCoreCenter.exe ()
O4 - Startup: C:\Documents and Settings\Asia\Menu Start\Programy\Autostart\OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16 - DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} http://slimak.onet.pl/_m/wirusy/ArcaOnline.cab (MainControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Moduł wstępnego ładowania interfejsu Browseui - Reg Error: Key error. File not found
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-10-28 15:10:37 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{1e4ab532-cbed-11de-b602-002421b45b81}\Shell - "" = AutoRun
O33 - MountPoints2\{1e4ab532-cbed-11de-b602-002421b45b81}\Shell\AutoRun\command - "" = I:\laucher.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2010-03-08 09:27:35 | 000,000,000 | -HSD | C] -- C:\found.000
[2010-03-08 01:10:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Asia\Dane aplikacji\Malwarebytes
[2010-03-08 01:10:07 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010-03-08 01:10:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes
[2010-03-08 01:10:05 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010-03-08 01:10:05 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010-02-28 06:40:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\Softland
[2010-02-28 06:40:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Asia\Dane aplikacji\Softland
[2010-02-28 06:40:49 | 000,021,704 | ---- | C] (Softland) -- C:\WINDOWS\System32\dopdfmn7.dll
[2010-02-28 06:40:49 | 000,018,632 | ---- | C] (Softland) -- C:\WINDOWS\System32\dopdfmi7.dll
[2010-02-28 06:40:47 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\GdiPlus.dll
[2010-02-28 06:40:45 | 000,000,000 | ---D | C] -- C:\Program Files\Softland
[2010-02-24 00:27:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Asia\Dane aplikacji\avidemux
[2010-02-24 00:27:11 | 000,000,000 | ---D | C] -- C:\Program Files\Avidemux 2.5
[2010-02-24 00:17:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Asia\Ustawienia lokalne\Dane aplikacji\WMTools Downloaded Files
[2010-02-23 23:39:55 | 000,000,000 | ---D | C] -- C:\Program Files\WebDesigner
[2010-02-23 23:25:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Macromedia Shared
[2010-02-23 23:25:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Macrovision
[2010-02-23 21:24:19 | 000,000,000 | ---D | C] -- C:\Program Files\FTP Commander
[2010-02-23 01:05:07 | 000,000,000 | ---D | C] -- D:\Moje Dokumenty\Konkursy Piasnistyczne Moje
[2010-02-22 16:20:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
[2010-02-22 16:15:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2010-02-22 16:08:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Asia\Dane aplikacji\ArcaBit
[2010-02-22 12:56:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Asia\Dane aplikacji\ArcaMicroScan
[2010-02-22 12:56:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Asia\Dane aplikacji\ArcaVirMicroScan
[2010-02-22 11:36:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Asia\Pulpit\ArcaMicroScan
[2010-02-22 11:33:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP
[2010-02-22 10:31:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\SITEguard
[2010-02-22 10:31:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\iS3
[2010-02-22 10:31:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\STOPzilla!
[2010-02-22 10:29:59 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Asia\IECompatCache
[2010-02-21 21:42:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Asia\Dane aplikacji\BESTplayer
[2010-02-21 18:00:40 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010-02-21 17:51:21 | 000,000,000 | ---D | C] -- C:\Program Files\RegCleaner
[2010-02-21 17:19:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Asia\Dane aplikacji\Uniblue
[2010-02-21 17:14:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Asia\Dane aplikacji\XnView
[2010-01-20 12:31:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Microsoft
[2010-01-13 11:59:35 | 000,148,736 | ---- | C] (Avanquest Software) -- C:\Documents and Settings\All Users\Dane aplikacji\hpe95.dll
[2009-11-15 11:33:04 | 001,232,896 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdjserv.dll
[2009-11-15 11:33:04 | 000,999,424 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdjusb1.dll
[2009-11-15 11:33:04 | 000,643,072 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdjpmui.dll
[2009-11-15 11:33:04 | 000,413,696 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdjinpa.dll
[2009-11-15 11:33:04 | 000,397,312 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdjiesc.dll
[2009-11-15 11:33:04 | 000,323,584 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdjhcp.dll
[2009-11-15 11:33:04 | 000,163,840 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdjprox.dll
[2009-11-15 11:33:04 | 000,094,208 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdjpplc.dll
[2009-11-15 11:33:03 | 000,700,416 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdjhbn3.dll
[2009-11-15 11:33:03 | 000,585,728 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdjlmpm.dll
[2009-11-15 11:33:02 | 000,684,032 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdjcomc.dll
[2009-11-15 11:33:02 | 000,425,984 | ---- | C] ( ) -- C:\WINDOWS\System32\lxdjcomm.dll
[2009-10-28 15:13:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Microsoft
[2009-10-28 15:10:35 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Dane aplikacji\Microsoft
[2009-10-28 15:10:35 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\Microsoft
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2010-03-08 10:23:46 | 000,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Mozilla Firefox.lnk
[2010-03-08 10:17:32 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010-03-08 09:28:21 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010-03-08 09:28:19 | 000,194,724 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010-03-08 09:28:16 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010-03-08 01:46:16 | 000,940,794 | ---- | M] () -- C:\WINDOWS\System32\LoopyMusic.wav
[2010-03-08 01:46:16 | 000,146,650 | ---- | M] () -- C:\WINDOWS\System32\BuzzingBee.wav
[2010-03-08 01:10:09 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Malwarebytes' Anti-Malware.lnk
[2010-03-07 23:35:07 | 000,002,539 | ---- | M] () -- C:\Documents and Settings\Asia\Pulpit\WORD.lnk
[2010-03-07 23:26:56 | 004,718,592 | -H-- | M] () -- C:\Documents and Settings\Asia\NTUSER.DAT
[2010-03-07 21:09:21 | 000,000,535 | ---- | M] () -- C:\Documents and Settings\Asia\Pulpit\BESTplayer.lnk
[2010-03-06 01:02:51 | 000,131,584 | ---- | M] () -- C:\Documents and Settings\Asia\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-03-03 01:13:26 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010-02-27 01:00:46 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010-02-24 03:00:27 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010-02-23 22:50:20 | 000,000,025 | ---- | M] () -- C:\WINDOWS\popcinfot.dat
[2010-02-22 23:59:02 | 000,000,340 | ---- | M] () -- C:\WINDOWS\QTW.INI
[2010-02-22 16:17:35 | 000,015,672 | ---- | M] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2010-02-22 16:09:01 | 000,000,352 | ---- | M] () -- C:\WINDOWS\System32\drivers\kgpfr2.cfg
[2010-02-22 12:56:22 | 000,000,524 | ---- | M] () -- C:\Documents and Settings\Asia\Pulpit\ArcaVirMicroScan.lnk
[2010-02-21 18:18:36 | 000,095,024 | ---- | M] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010-02-21 18:18:19 | 000,015,880 | ---- | M] () -- C:\WINDOWS\System32\lsdelete.exe
[2010-02-21 18:04:16 | 000,000,645 | ---- | M] () -- C:\Documents and Settings\Asia\Pulpit\RegCleaner.lnk
[2010-02-21 18:00:39 | 000,000,867 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Ad-Aware.lnk
[2010-02-17 15:17:06 | 000,021,704 | ---- | M] (Softland) -- C:\WINDOWS\System32\dopdfmn7.dll
[2010-02-17 15:17:04 | 000,018,632 | ---- | M] (Softland) -- C:\WINDOWS\System32\dopdfmi7.dll
[2010-02-14 19:51:46 | 000,000,986 | ---- | M] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2010-03-08 01:46:16 | 000,940,794 | ---- | C] () -- C:\WINDOWS\System32\LoopyMusic.wav
[2010-03-08 01:46:16 | 000,146,650 | ---- | C] () -- C:\WINDOWS\System32\BuzzingBee.wav
[2010-03-08 01:10:09 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Malwarebytes' Anti-Malware.lnk
[2010-03-07 21:09:21 | 000,000,535 | ---- | C] () -- C:\Documents and Settings\Asia\Pulpit\BESTplayer.lnk
[2010-03-06 10:32:29 | 000,001,525 | ---- | C] () -- C:\Documents and Settings\Asia\Pulpit\FLAC Frontend.lnk
[2010-02-28 06:40:49 | 000,007,549 | ---- | C] () -- C:\WINDOWS\System32\dopdf7.ctm
[2010-02-22 16:09:01 | 000,000,352 | ---- | C] () -- C:\WINDOWS\System32\drivers\kgpfr2.cfg
[2010-02-22 12:56:22 | 000,000,524 | ---- | C] () -- C:\Documents and Settings\Asia\Pulpit\ArcaVirMicroScan.lnk
[2010-02-22 10:35:20 | 000,015,672 | ---- | C] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2010-02-21 18:00:39 | 000,000,867 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Ad-Aware.lnk
[2010-02-21 17:51:23 | 000,000,645 | ---- | C] () -- C:\Documents and Settings\Asia\Pulpit\RegCleaner.lnk
[2010-02-14 19:51:46 | 000,000,986 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk
[2010-01-03 17:47:01 | 000,000,340 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2010-01-03 17:46:34 | 000,027,136 | ---- | C] () -- C:\WINDOWS\System32\QTUninst.dll
[2010-01-03 17:45:53 | 000,000,109 | ---- | C] () -- C:\WINDOWS\TB50.INI
[2010-01-03 17:45:30 | 000,000,138 | ---- | C] () -- C:\WINDOWS\asym.ini
[2010-01-03 17:22:09 | 000,691,696 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009-11-26 20:12:10 | 000,000,194 | ---- | C] () -- C:\WINDOWS\OPPE.INI
[2009-11-15 11:35:21 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxdjvs.dll
[2009-11-15 11:35:20 | 000,348,160 | ---- | C] () -- C:\WINDOWS\System32\lxdjcoin.dll
[2009-11-15 11:33:04 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\lxdjinst.dll
[2009-11-15 11:33:03 | 000,208,896 | ---- | C] () -- C:\WINDOWS\System32\lxdjgrd.dll
[2009-11-08 23:28:49 | 000,131,584 | ---- | C] () -- C:\Documents and Settings\Asia\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-11-08 13:15:49 | 000,000,421 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009-11-08 09:42:44 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009-10-28 17:04:26 | 000,040,960 | ---- | C] () -- C:\Program Files\Uninstall_CDS.exe
[2009-10-28 15:22:02 | 000,217,088 | ---- | C] () -- C:\WINDOWS\NVGfxOgl.dll
[2009-01-15 20:42:00 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2009-01-15 20:42:00 | 001,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2009-01-15 20:42:00 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2009-01-15 20:42:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006-08-16 15:35:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006-08-16 15:35:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2003-04-08 11:40:22 | 000,005,679 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001-10-08 13:24:26 | 000,148,544 | ---- | C] () -- C:\WINDOWS\System32\msvdm.dll
[2001-10-08 12:59:46 | 000,016,960 | ---- | C] () -- C:\WINDOWS\System32\mag.dll
[2001-03-30 13:24:54 | 000,032,768 | RHS- | C] () -- C:\WINDOWS\System32\intrasegmentip.dll
[color=#E56717]========== Alternate Data Streams ==========[/color]
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:A8ADE5D8
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:DFC5A2B2
< End of report >
extras.txt:
- Kod: Zaznacz wszystko
OTL Extras logfile created on: 2010-03-08 10:08:19 - Run 1
OTL by OldTimer - Version 3.1.35.0 Folder = D:\Moje Dokumenty\Pobieranie
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 63,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 88,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 78,13 Gb Total Space | 67,19 Gb Free Space | 86,00% Space Free | Partition Type: NTFS
Drive D: | 193,36 Gb Total Space | 21,74 Gb Free Space | 11,25% Space Free | Partition Type: NTFS
Drive E: | 194,27 Gb Total Space | 58,75 Gb Free Space | 30,24% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: POPKO-DCA9F0838
Current User Name: Asia
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
[color=#E56717]========== Extra Registry (SafeList) ==========[/color]
[color=#E56717]========== File Associations ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = Opera.HTML] -- C:\Program Files\Opera\opera.exe (Opera Software)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.exe [@ = exefile] -- Reg Error: Key error. File not found
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
[color=#E56717]========== Shell Spawning ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
http [open] -- "C:\Program Files\Opera\opera.exe" (Opera Software)
https [open] -- "C:\Program Files\Opera\opera.exe" (Opera Software)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /k "cd %L" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Przeglądaj w XnView] -- "C:\Program Files\XnView\xnview.exe" "%1" File not found
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[color=#E56717]========== Security Center Settings ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
[color=#E56717]========== Authorized Applications List ==========[/color]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Lexmark 1400 Series\app4r.exe" = C:\Program Files\Lexmark 1400 Series\app4r.exe:*:Enabled:Printing Application -- ()
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- (BitTorrent, Inc.)
"C:\WINDOWS\system32\lxdjcoms.exe" = C:\WINDOWS\system32\lxdjcoms.exe:*:Enabled:1400 Series Server -- ( )
"C:\Program Files\Lexmark 1400 Series\App4R.exe" = C:\Program Files\Lexmark 1400 Series\App4R.exe:*:Disabled:Printing Application -- ()
"C:\Program Files\Lexmark 1400 Series\lxdjamon.exe" = C:\Program Files\Lexmark 1400 Series\lxdjamon.exe:*:Disabled:Device Monitor Application -- ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdjjswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdjjswx.exe:*:Enabled: -- ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdjpswx.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdjpswx.exe:*:Enabled: -- ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdjtime.exe" = C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdjtime.exe:*:Enabled: -- (Lexmark International, Inc.)
"C:\Program Files\Nowe Gadu-Gadu\gg.exe" = C:\Program Files\Nowe Gadu-Gadu\gg.exe:*:Enabled:Nowe Gadu-Gadu -- (GG Network S.A.)
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{2085F05D-24C5-4E27-B7B4-A51DE890FFC9}" = Opera 10.00
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java(TM) 6 Update 16
"{2FFE93F0-BB72-4E52-8761-354D1AAA9387}" = Sony Ericsson PC Suite 6.009.00
"{338F08AB-C262-42C7-B000-34DE1A475273}" = Ad-Aware Email Scanner for Outlook
"{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{6C31E111-96BB-4ADC-9C81-E6D3EEDDD8D3}" = Powertoys For Windows XP
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{90110415-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0415-0000-0000000FF1CE}" = Pakiet zgodności dla systemu Office 2007
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{B7D0C5B8-27E8-4057-B4EE-A7BF18A18CD7}" = TibrachyNvg
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver
"{C829F201-A2C1-451A-A93A-48E202D4CEAD}" = B2000 Series PCL - GDI Drivers from OKI® Printing Solutions for Windows XP x64 Edition - Windows Server 2003 x64 Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D2D3D146-67BC-43D0-9015-2E7BAC2E032B}" = OpenOffice.org 3.1
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"avast!" = avast! Antivirus
"Avidemux 2.5" = Avidemux 2.5
"BitTorrent" = BitTorrent
"Diagram Designer" = Diagram Designer
"doPDF 7 printer_is1" = doPDF 7.1 printer
"DualCoreCenter_is1" = DualCoreCenter
"EasyLanguage_is1" = EasyLanguage
"EPSON Scanner" = EPSON Scan
"EVEREST Corporate Edition_is1" = EVEREST Corporate Edition v5.30
"FLAC" = FLAC 1.2.1b (remove only)
"FTP Commander" = FTP Commander
"ie8" = Windows Internet Explorer 8
"InCD!UninstallKey" = InCD
"JDownloader" = JDownloader
"Lexmark 1400 Series" = Lexmark 1400 Series
"Liveupdate4_is1" = Liveupdate4
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.8)" = Mozilla Firefox (3.5.8)
"Nero - Burning Rom!UninstallKey" = Nero OEM
"Nowe Gadu-Gadu" = Nowe Gadu-Gadu
"NVIDIA Drivers" = NVIDIA Drivers
"QuickTime 3.0" = QuickTime 3.0
"RealPlayer 12.0" = RealPlayer
"Winamp" = Winamp
"Windows Essentials Media Codec Pack" = Windows Essentials Media Codec Pack 2.3d
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"WinRAR archiver" = Archiwizator WinRAR
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
[color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Detektor Winampa
[color=#E56717]========== Last 10 Event Log Errors ==========[/color]
[ Antivirus Events ]
Error - 2009-11-10 11:27:44 | Computer Name = POPKO-DCA9F0838 | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
http://www.dogomania.pl/forum/ failed, 0000A413.
Error - 2010-02-03 17:40:48 | Computer Name = POPKO-DCA9F0838 | Source = avast! | ID = 33554522
Description = Error in aswChestC: chestAddFile Error 1392.
[ Application Events ]
Error - 2010-03-07 20:40:55 | Computer Name = POPKO-DCA9F0838 | Source = ESENT | ID = 489
Description = wuauclt (2028) Próba otwarcia pliku "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
w trybie tylko do odczytu zakończyła się niepomyślnie z błędem systemowym 32 (0x00000020):
"Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny
proces. ". Operacja otwierania pliku zostanie zakończona z błędem -1032 (0xfffffbf8).
Error - 2010-03-07 20:40:55 | Computer Name = POPKO-DCA9F0838 | Source = ESENT | ID = 455
Description = wuaueng.dll (2028) SUS20ClientDataStore: Wystąpił błąd -1032 (0xfffffbf8)
podczas otwierania pliku dziennika C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
Error - 2010-03-07 20:41:09 | Computer Name = POPKO-DCA9F0838 | Source = ESENT | ID = 489
Description = wuauclt (3944) Próba otwarcia pliku "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
w trybie tylko do odczytu zakończyła się niepomyślnie z błędem systemowym 32 (0x00000020):
"Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny
proces. ". Operacja otwierania pliku zostanie zakończona z błędem -1032 (0xfffffbf8).
Error - 2010-03-07 20:41:09 | Computer Name = POPKO-DCA9F0838 | Source = ESENT | ID = 455
Description = wuaueng.dll (3944) SUS20ClientDataStore: Wystąpił błąd -1032 (0xfffffbf8)
podczas otwierania pliku dziennika C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
Error - 2010-03-07 20:41:19 | Computer Name = POPKO-DCA9F0838 | Source = ESENT | ID = 489
Description = wuauclt (3944) Próba otwarcia pliku "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
w trybie tylko do odczytu zakończyła się niepomyślnie z błędem systemowym 32 (0x00000020):
"Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny
proces. ". Operacja otwierania pliku zostanie zakończona z błędem -1032 (0xfffffbf8).
Error - 2010-03-07 20:41:19 | Computer Name = POPKO-DCA9F0838 | Source = ESENT | ID = 455
Description = wuaueng.dll (3944) SUS20ClientDataStore: Wystąpił błąd -1032 (0xfffffbf8)
podczas otwierania pliku dziennika C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
Error - 2010-03-07 20:41:37 | Computer Name = POPKO-DCA9F0838 | Source = ESENT | ID = 489
Description = wuauclt (2416) Próba otwarcia pliku "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
w trybie tylko do odczytu zakończyła się niepomyślnie z błędem systemowym 32 (0x00000020):
"Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny
proces. ". Operacja otwierania pliku zostanie zakończona z błędem -1032 (0xfffffbf8).
Error - 2010-03-07 20:41:37 | Computer Name = POPKO-DCA9F0838 | Source = ESENT | ID = 455
Description = wuaueng.dll (2416) SUS20ClientDataStore: Wystąpił błąd -1032 (0xfffffbf8)
podczas otwierania pliku dziennika C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
Error - 2010-03-07 20:41:51 | Computer Name = POPKO-DCA9F0838 | Source = ESENT | ID = 489
Description = wuauclt (2416) Próba otwarcia pliku "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
w trybie tylko do odczytu zakończyła się niepomyślnie z błędem systemowym 32 (0x00000020):
"Proces nie może uzyskać dostępu do pliku, ponieważ jest on używany przez inny
proces. ". Operacja otwierania pliku zostanie zakończona z błędem -1032 (0xfffffbf8).
Error - 2010-03-07 20:41:51 | Computer Name = POPKO-DCA9F0838 | Source = ESENT | ID = 455
Description = wuaueng.dll (2416) SUS20ClientDataStore: Wystąpił błąd -1032 (0xfffffbf8)
podczas otwierania pliku dziennika C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
[ System Events ]
Error - 2010-01-08 15:34:02 | Computer Name = POPKO-DCA9F0838 | Source = Service Control Manager | ID = 7009
Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się
z usługą lxdjCATSCustConnectService.
Error - 2010-01-08 15:34:02 | Computer Name = POPKO-DCA9F0838 | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi lxdjCATSCustConnectService z powodu następującego
błędu: %%1053
Error - 2010-01-09 19:10:16 | Computer Name = POPKO-DCA9F0838 | Source = Service Control Manager | ID = 7009
Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się
z usługą lxdjCATSCustConnectService.
Error - 2010-01-09 19:10:16 | Computer Name = POPKO-DCA9F0838 | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi lxdjCATSCustConnectService z powodu następującego
błędu: %%1053
Error - 2010-01-10 06:34:17 | Computer Name = POPKO-DCA9F0838 | Source = Service Control Manager | ID = 7009
Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się
z usługą lxdjCATSCustConnectService.
Error - 2010-01-10 06:34:17 | Computer Name = POPKO-DCA9F0838 | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi lxdjCATSCustConnectService z powodu następującego
błędu: %%1053
Error - 2010-01-12 22:17:54 | Computer Name = POPKO-DCA9F0838 | Source = Service Control Manager | ID = 7009
Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się
z usługą lxdjCATSCustConnectService.
Error - 2010-01-12 22:17:54 | Computer Name = POPKO-DCA9F0838 | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi lxdjCATSCustConnectService z powodu następującego
błędu: %%1053
Error - 2010-01-13 22:17:27 | Computer Name = POPKO-DCA9F0838 | Source = Service Control Manager | ID = 7009
Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się
z usługą lxdjCATSCustConnectService.
Error - 2010-01-13 22:17:27 | Computer Name = POPKO-DCA9F0838 | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi lxdjCATSCustConnectService z powodu następującego
błędu: %%1053
< End of report >
BARDZO proszę o pilną pomoc, mam rozpaczliwie mało czasu na ogromną robotę, awaria komputera to ostatnia rzecz, której potrzebowałam. Proszę o uwzględnienie, że ABSOLUTNIE nie czuję się specem od komputerów i potrzebuję bardzo łopatologicznych instrukcji.
Komputer zwolnił jeszcze bardziej, więc wysyłam ten post zanim padnie na amen.
Ratunku!
Joanna