• Ogłoszenie:

Log - dziwne procesy komputer strasznie wolno działa.

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Log - dziwne procesy komputer strasznie wolno działa.

Postprzez Miron185 27 Sie 2009, 10:26

Mam następujący problem. Ostatnio z komputerem w pracy dzieją się dziwne rzeczy wszystko strasznie wolno dział i Firefox się wyłącza co kilkanaście minut. Proszę o pomoc oraz o dokładne napisanie co i w jaki sposób mogę usunąć. jestem laikiem w tych sprawach. Nie chce woląc informatyka. Z góry dzięki za pomoc.
Kod: Zaznacz wszystko
OTL logfile created on: 2009-08-27 10:17:28 - Run 1
OTL by OldTimer - Version     Folder = C:\Documents and Settings\zaopatrzenie\Pulpit
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

511,48 Mb Total Physical Memory | 227,39 Mb Available Physical Memory | 44,46% Memory free
863,51 Mb Paging File | 467,45 Mb Available in Paging File | 54,13% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,53 Gb Total Space | 3,93 Gb Free Space | 20,11% Space Free | Partition Type: NTFS
Drive D: | 54,99 Gb Total Space | 22,06 Gb Free Space | 40,11% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive S: | 57,63 Gb Total Space | 5,83 Gb Free Space | 10,11% Space Free | Partition Type: NTFS

Computer Name: ZAOPATRZENIE-01
Current User Name: zaopatrzenie
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2008-08-18 14:25:10 | 00,468,224 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2006-10-26 14:40:34 | 00,335,872 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
PRC - [2007-02-10 05:29:54 | 29,178,224 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
PRC - [2006-04-14 11:07:20 | 28,933,976 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
PRC - [2007-04-12 14:56:14 | 00,178,752 | ---- | M] (Protexis Inc.) -- c:\program files\common files\protexis\license service\psiservice_2.exe
PRC - [2008-12-22 15:34:22 | 00,144,248 | ---- | M] () -- C:\Program Files\SoftActivity\AMSys\amsvc.exe
PRC - [2007-02-10 05:29:48 | 00,242,544 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
PRC - [2007-02-10 05:29:56 | 00,089,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
PRC - [2004-08-11 01:45:04 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe
PRC - [2008-12-22 15:34:22 | 00,710,520 | ---- | M] () -- C:\Program Files\SoftActivity\AMSys\swsys.exe
PRC - [2008-04-14 19:21:16 | 01,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2008-08-18 14:23:50 | 01,447,168 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2009-08-05 08:15:36 | 10,719,848 | ---- | M] (GG Network S.A.) -- C:\Program Files\Nowe Gadu-Gadu\gg.exe
PRC - [2009-07-27 16:39:44 | 00,077,824 | ---- | M] () -- C:\Program Files\Nowe Gadu-Gadu\spellchecker_gg.exe
PRC - [2009-07-15 14:55:21 | 00,288,048 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent\uTorrent.exe
PRC - [2009-07-01 18:38:40 | 01,481,056 | ---- | M] (Nullsoft) -- C:\Program Files\Winamp\winamp.exe
PRC - [2009-08-04 09:02:05 | 00,908,280 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009-08-27 10:17:04 | 00,514,048 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\zaopatrzenie\Pulpit\OTL.exe

[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - [2007-04-13 03:20:52 | 00,033,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2007-04-13 03:21:18 | 00,068,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008-08-18 14:30:58 | 00,019,200 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv [On_Demand | Stopped])
SRV - [2008-08-18 14:25:10 | 00,468,224 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn [Auto | Running])
SRV - [2008-04-14 19:20:44 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2006-10-26 14:40:34 | 00,335,872 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe -- (MDM [Auto | Running])
SRV - [2007-02-10 05:29:54 | 29,178,224 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -- (MSSQL$ACT7 [Auto | Running])
SRV - [2006-04-14 11:07:20 | 28,933,976 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe -- (MSSQL$MSSMLBIZ [Auto | Running])
SRV - [2005-10-14 02:50:20 | 00,045,272 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe -- (MSSQLServerADHelper [Disabled | Stopped])
SRV - [2006-10-26 20:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006-10-26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2007-04-12 14:56:14 | 00,178,752 | ---- | M] (Protexis Inc.) -- c:\program files\common files\protexis\license service\psiservice_2.exe -- (PSI_SVC_2 [Auto | Running])
SRV - [2008-12-22 15:34:22 | 00,144,248 | ---- | M] () -- C:\Program Files\SoftActivity\AMSys\amsvc.exe -- (Samsvc [Auto | Running])
SRV - [2009-06-02 10:10:08 | 00,637,952 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer [On_Demand | Stopped])
SRV - [2007-02-10 05:29:48 | 00,242,544 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser [Auto | Running])
SRV - [2007-02-10 05:29:56 | 00,089,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter [Auto | Running])
SRV - [2004-08-11 01:45:04 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfmgr.exe -- (UMWdf [Auto | Running])

[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - [2003-12-10 09:21:16 | 00,004,224 | R--- | M] (ABIT Computer Corp.) -- C:\WINDOWS\System32\Drivers\AC2003.sys -- (AC2003 [On_Demand | Stopped])
DRV - [2004-02-24 05:08:52 | 00,400,384 | ---- | M] (Sensaura) -- C:\WINDOWS\System32\drivers\ALCXSENS.SYS -- (ALCXSENS [On_Demand | Running])
DRV - [2004-05-14 17:24:10 | 00,622,172 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\drivers\ALCXWDM.SYS -- (ALCXWDM [On_Demand | Running])
DRV - [2004-08-04 02:35:04 | 00,701,440 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys -- (ati2mtag [On_Demand | Running])
DRV - [2008-08-18 14:18:26 | 00,039,944 | ---- | M] (ESET) -- C:\WINDOWS\System32\DRIVERS\eamon.sys -- (eamon [Auto | Running])
DRV - [2008-08-18 14:19:26 | 00,053,256 | ---- | M] (ESET) -- C:\WINDOWS\System32\DRIVERS\easdrv.sys -- (easdrv [System | Running])
DRV - [2008-08-18 14:27:42 | 00,034,312 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\epfwtdir.sys -- (epfwtdir [System | Running])
DRV - [2008-08-26 10:26:12 | 00,018,816 | ---- | M] (Nokia) -- C:\WINDOWS\System32\DRIVERS\pccsmcfd.sys -- (pccsmcfd [On_Demand | Stopped])
DRV - [2007-08-02 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2009-04-28 22:20:06 | 00,044,944 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2004-08-04 00:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\DRIVERS\RTL8139.SYS -- (rtl8139 [On_Demand | Running])
DRV - [2008-11-26 13:24:40 | 00,031,088 | ---- | M] (SoftActivity) -- C:\Program Files\SoftActivity\AMSys\sagendrv.sys -- (SAgentDriver [On_Demand | Running])
DRV - [2008-04-13 18:39:16 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2009-05-20 07:03:15 | 00,721,904 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2008-04-13 20:40:50 | 00,149,376 | ---- | M] (M-Systems) -- C:\WINDOWS\system32\DRIVERS\tffsport.sys -- (tffsport [Boot | Running])

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]

[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =  [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.pl/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.selectedEngine: "Wikipedia (pl)"
FF - prefs.js..browser.startup.homepage: "http://google.pl"
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.2

FF - HKLM\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009-07-08 10:41:18 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009-08-13 14:44:43 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009-08-04 09:02:09 | 00,000,000 | ---D | M]

[2009-07-16 08:37:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\zaopatrzenie\Dane aplikacji\mozilla\Extensions
[2009-07-16 08:37:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\zaopatrzenie\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-07-16 08:37:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\zaopatrzenie\Dane aplikacji\mozilla\Firefox\Profiles\zpx1pg02.default\extensions
[2009-07-16 08:37:17 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009-08-04 09:02:09 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009-08-04 09:02:03 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-08-04 09:02:03 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009-08-04 09:02:06 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009-07-15 21:00:25 | 00,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2009-07-15 21:00:25 | 00,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2009-07-15 21:00:25 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009-07-15 21:00:25 | 00,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2009-07-15 21:00:25 | 00,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2009-07-15 21:00:25 | 00,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2009-07-15 21:00:25 | 00,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts:       localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\zaopatrzenie\Dane aplikacji\Nowe Gadu-Gadu\_userdata\ggbho.1.dll (GG Network S.A.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.CPL (Microsoft Corporation)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\System32\wshbth.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: mks.com.pl ([www] https in Zaufane witryny)
O15 - HKCU\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = POMET.local
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter:  - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-07-24 08:45:09 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) -  File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) -  File not found
O34 - HKLM BootExecute: (lsdelete) -  File not found

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2009-08-27 10:15:49 | 00,514,048 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\zaopatrzenie\Pulpit\OTL.exe
[2009-08-26 08:49:40 | 00,348,048 | ---- | C] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\zam t.jpg
[2009-08-25 09:45:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\zaopatrzenie\Dane aplikacji\Ashampoo
[2009-08-25 09:43:57 | 00,000,846 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Ashampoo Burning Studio 2009.lnk
[2009-08-25 09:43:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\zaopatrzenie\Ustawienia lokalne\Dane aplikacji\ashampoo
[2009-08-25 09:43:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\ashampoo
[2009-08-25 09:43:41 | 00,000,000 | ---D | C] -- C:\Program Files\Ashampoo
[2009-08-25 09:13:44 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009-08-25 09:13:42 | 01,414,440 | ---- | C] (Nero AG) -- C:\WINDOWS\System32\ShellManager310E2D762.dll
[2009-08-25 09:13:42 | 00,773,120 | ---- | C] () -- C:\WINDOWS\System32\NEROINSTAEC43759.DB
[2009-08-25 09:07:51 | 00,391,168 | ---- | C] (YouKing) -- C:\Documents and Settings\zaopatrzenie\Pulpit\Craagle.exe
[2009-08-25 05:50:08 | 00,792,313 | ---- | C] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\20090825087.jpg
[2009-08-25 05:49:34 | 00,875,065 | ---- | C] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\20090825086.jpg
[2009-08-21 12:39:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\zaopatrzenie\Pulpit\JDownloader_0.7
[2009-08-21 12:35:18 | 19,910,908 | ---- | C] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\JDownloader_0.7.zip
[2009-08-21 10:42:55 | 00,334,562 | ---- | C] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\zamówienie PPM pomet.jpg
[2009-08-21 09:17:12 | 00,673,437 | ---- | C] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\oferta POMET.pdf
[2009-08-21 07:56:48 | 00,199,001 | ---- | C] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\upow.jpg
[2009-08-21 07:13:32 | 00,028,160 | ---- | C] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\upowaznienie do odbierania materiałów 3.doc
[2009-08-14 12:23:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\zaopatrzenie\Pulpit\Fisz Emade - Piątek 13
[2009-08-14 12:21:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\zaopatrzenie\Pulpit\Fisz Envee - Fru!
[2009-08-14 12:19:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\zaopatrzenie\Pulpit\Fisz Emade - Heavi Meta[www.0mp3.pl]
[2009-08-14 10:33:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\zaopatrzenie\Pulpit\tor
[2009-08-14 09:56:07 | 00,089,088 | ---- | C] () -- C:\Documents and Settings\zaopatrzenie\Moje dokumenty\borkowski Skazani budowy i produkcja (14.08.2009).doc
[2009-08-14 09:15:02 | 00,143,360 | ---- | C] () -- C:\Documents and Settings\zaopatrzenie\Moje dokumenty\Borkowski Środki czystości Cywile (14.08.2009).doc
[2009-08-13 07:05:32 | 00,028,160 | ---- | C] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\upowaznienie do odbierania materiałów 2.doc
[2009-08-13 07:03:50 | 00,027,648 | ---- | C] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\upowaznienie do odbierania materiałów 1.doc
[2009-08-12 11:21:57 | 00,102,912 | ---- | C] () -- C:\Documents and Settings\zaopatrzenie\Moje dokumenty\reklamacja fencom 1 szt. 12.08.09r..doc
[2009-08-12 09:38:50 | 00,000,162 | -H-- | C] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\~$gpx.doc
[2009-08-05 14:00:47 | 00,388,096 | ---- | C] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\Zapytanie sroda slaska 5.08.2009r..doc
[2009-08-04 11:17:29 | 00,013,400 | ---- | C] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\TERBUD SRODA ŚLASKA 4.07.2009r..docx
[2009-08-04 05:52:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\zaopatrzenie\Dane aplikacji\WinRAR
[2009-07-31 13:20:30 | 00,383,488 | ---- | C] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\Zapytanie drzwi radecz 31.07.2009r..doc
[2009-07-31 10:38:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\zaopatrzenie\Pulpit\T3
[2009-07-30 07:58:17 | 00,000,664 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Winamp.lnk
[2009-07-30 07:57:45 | 00,000,000 | ---D | C] -- C:\Program Files\Winamp
[2009-07-30 07:57:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\zaopatrzenie\Dane aplikacji\Winamp
[2009-07-29 07:51:01 | 00,391,680 | ---- | C] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\zam ubranie.doc
[2009-07-28 11:13:49 | 00,034,304 | ---- | C] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\Zapotrzebowanie 2 mieczysław moliński 28.07.2009r..doc
[2009-07-28 10:59:30 | 00,053,760 | ---- | C] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\Zapotrzebowanie mieczysław moliński 28.07.2009r..doc
[2009-02-23 14:36:03 | 00,000,077 | ---- | C] () -- C:\WINDOWS\SW_Win2000X24.DLL
[2009-02-23 14:34:11 | 00,001,806 | ---- | C] () -- C:\WINDOWS\CITP_SearchHistory.INI
[2009-02-17 12:02:45 | 00,000,029 | ---- | C] () -- C:\WINDOWS\HF.ini
[2009-02-17 11:10:40 | 00,000,429 | ---- | C] () -- C:\WINDOWS\DD.ini
[2009-02-16 10:54:36 | 00,001,149 | ---- | C] () -- C:\WINDOWS\Admin.ini
[2009-02-16 10:49:17 | 00,000,761 | ---- | C] () -- C:\WINDOWS\AmhmSQL.ini
[2009-02-11 11:03:20 | 00,118,784 | ---- | C] () -- C:\WINDOWS\System32\MKCoInstaller.dll
[2009-02-11 10:49:13 | 00,019,775 | ---- | C] () -- C:\WINDOWS\System32\SBMiniDrv.dll
[2009-01-26 13:58:21 | 00,000,042 | ---- | C] () -- C:\WINDOWS\fiscprn.ini
[2009-01-26 13:57:58 | 00,000,110 | ---- | C] () -- C:\WINDOWS\mxreader.INI
[2009-01-26 13:57:09 | 00,000,647 | ---- | C] () -- C:\WINDOWS\amhm.ini
[2009-01-26 13:56:43 | 00,101,888 | ---- | C] () -- C:\WINDOWS\System32\BUTIL.DLL
[2009-01-26 13:56:43 | 00,002,055 | R--- | C] () -- C:\WINDOWS\BTI.INI
[2008-11-19 10:39:20 | 00,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008-11-12 10:15:43 | 00,000,117 | ---- | C] () -- C:\WINDOWS\ConverterCore.INI
[2008-11-12 10:05:23 | 00,021,240 | ---- | C] () -- C:\WINDOWS\System32\solidlocalmon.dll
[2008-11-12 10:05:23 | 00,013,560 | ---- | C] () -- C:\WINDOWS\System32\solidlocalui.dll
[2008-09-17 14:06:08 | 00,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2008-08-25 09:30:11 | 00,000,091 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008-08-20 07:25:20 | 00,000,000 | ---- | C] () -- C:\WINDOWS\Ui.INI
[2008-08-18 07:00:58 | 00,000,000 | ---- | C] () -- C:\WINDOWS\WATCH.INI
[2008-07-29 14:23:36 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008-07-24 10:35:45 | 00,000,320 | ---- | C] () -- C:\WINDOWS\hpbafd.ini
[2008-07-24 10:23:54 | 00,233,525 | ---- | C] () -- C:\WINDOWS\System32\isutil.dll
[2008-07-24 10:23:52 | 00,000,271 | ---- | C] () -- C:\WINDOWS\apptune.ini
[2008-07-24 09:30:45 | 00,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2008-07-24 09:30:41 | 00,155,648 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2008-07-24 08:57:50 | 00,000,427 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008-02-20 11:11:16 | 00,034,312 | ---- | C] () -- C:\WINDOWS\System32\drivers\epfwtdir.sys
[2007-08-02 14:00:00 | 00,000,590 | ---- | C] () -- C:\WINDOWS\win.ini
[2007-08-02 14:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[1 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009-08-27 10:17:04 | 00,514,048 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\zaopatrzenie\Pulpit\OTL.exe
[2009-08-27 09:48:58 | 00,196,608 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-08-27 07:55:12 | 00,000,320 | ---- | M] () -- C:\WINDOWS\hpbafd.ini
[2009-08-27 06:58:01 | 00,002,422 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-08-27 06:56:39 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-08-27 06:56:38 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-08-27 06:20:59 | 00,000,012 | ---- | M] () -- C:\WINDOWS\bthservsdp.dat
[2009-08-26 08:49:40 | 00,348,048 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\zam t.jpg
[2009-08-25 09:50:22 | 05,875,642 | -H-- | M] () -- C:\Documents and Settings\zaopatrzenie\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2009-08-25 09:50:08 | 00,000,846 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Ashampoo Burning Studio 2009.lnk
[2009-08-25 09:07:58 | 00,391,168 | ---- | M] (YouKing) -- C:\Documents and Settings\zaopatrzenie\Pulpit\Craagle.exe
[2009-08-25 07:23:22 | 00,002,513 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\Microsoft Office Word 2007.lnk
[2009-08-25 07:06:29 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009-08-25 05:50:12 | 00,792,313 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\20090825087.jpg
[2009-08-25 05:49:38 | 00,875,065 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\20090825086.jpg
[2009-08-21 14:06:50 | 00,000,153 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Dane aplikacji\default.pls
[2009-08-21 12:38:41 | 19,910,908 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\JDownloader_0.7.zip
[2009-08-21 10:42:55 | 00,334,562 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\zamówienie PPM pomet.jpg
[2009-08-21 09:18:17 | 00,673,437 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\oferta POMET.pdf
[2009-08-21 07:56:49 | 00,199,001 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\upow.jpg
[2009-08-21 07:13:32 | 00,028,160 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\upowaznienie do odbierania materiałów 3.doc
[2009-08-14 09:56:08 | 00,089,088 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Moje dokumenty\borkowski Skazani budowy i produkcja (14.08.2009).doc
[2009-08-14 09:15:03 | 00,143,360 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Moje dokumenty\Borkowski Środki czystości Cywile (14.08.2009).doc
[2009-08-13 07:05:32 | 00,028,160 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\upowaznienie do odbierania materiałów 2.doc
[2009-08-13 07:03:51 | 00,027,648 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\upowaznienie do odbierania materiałów 1.doc
[2009-08-12 11:21:58 | 00,102,912 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Moje dokumenty\reklamacja fencom 1 szt. 12.08.09r..doc
[2009-08-12 09:38:50 | 00,000,162 | -H-- | M] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\~$gpx.doc
[2009-08-05 14:01:33 | 00,388,096 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\Zapytanie sroda slaska 5.08.2009r..doc
[2009-08-04 11:17:30 | 00,013,400 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\TERBUD SRODA ŚLASKA 4.07.2009r..docx
[2009-07-31 13:21:33 | 00,383,488 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\Zapytanie drzwi radecz 31.07.2009r..doc
[2009-07-30 07:58:17 | 00,000,664 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Winamp.lnk
[2009-07-29 07:51:02 | 00,391,680 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\zam ubranie.doc
[2009-07-28 11:13:49 | 00,034,304 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\Zapotrzebowanie 2 mieczysław moliński 28.07.2009r..doc
[2009-07-28 11:00:20 | 00,053,760 | ---- | M] () -- C:\Documents and Settings\zaopatrzenie\Pulpit\Zapotrzebowanie mieczysław moliński 28.07.2009r..doc
< End of report >
Awatar użytkownika
Posty: 80
Dołączenie: 13 Lis 2004, 12:27
Miejscowość: WROCŁAW

Log - dziwne procesy komputer strasznie wolno działa.

Postprzez wojtas 27 Sie 2009, 14:59

1.Uruchom OTL z opcji CleanUp
2. wykonaj optymalizację windowsa
3.Wyłącz przywracanie systemu ( właściwości mój komputer-zakładka przywracanie - wyłącz przywracanie na wszystkich dyskach). Po chwili włącz je powrotem]
4. zrób skan Malwarebytes Anti-Malware (usuń co znajdzie )

Przeskanuj obszar mojego komputera http://www.kaspersky.pl/virusscanner.html (uruchom przez IE) Daj raport z niego na forum.
Awatar użytkownika
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656

Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 10 gości