Wencman utworzono 10 października 2009 utworzono 10 października 2009 Witam jak w temacie. Wolno koledze komp chodzi, może da się coś zrobić pozdro [log]OTL logfile created on: 2009-10-02 17:45:50 - Run 1 OTL by OldTimer - Version 3.0.17.0 Folder = D:\Inne Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 246,42 Mb Total Physical Memory | 22,51 Mb Available Physical Memory | 9,14% Memory free 603,26 Mb Paging File | 202,94 Mb Available in Paging File | 33,64% Paging File free Paging file location(s): C:\pagefile.sys 372 744 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 17,07 Gb Total Space | 3,51 Gb Free Space | 20,56% Space Free | Partition Type: FAT32 Drive D: | 17,24 Gb Total Space | 13,05 Gb Free Space | 75,67% Space Free | Partition Type: FAT32 E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: ACER-E3E8C2474F Current User Name: As Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2006-03-09 11:48:22 | 00,235,168 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe PRC - [2008-04-14 22:51:18 | 01,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE PRC - [2006-03-09 11:47:58 | 00,255,648 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe PRC - [2009-05-13 16:48:24 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe PRC - [2005-05-29 12:59:56 | 00,249,856 | ---- | M] (Aladdin Knowledge Systems Ltd.) -- C:\Program Files\Aladdin\HASP LM\nhsrvice.exe PRC - [2004-08-16 15:17:20 | 01,287,168 | ---- | M] (OSA Technologies Inc.) -- C:\Acer\eManager\anbmServ.exe PRC - [2009-09-21 15:10:30 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe PRC - [2003-06-19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE PRC - [2004-04-23 11:04:16 | 00,158,848 | ---- | M] (Symantec Corporation) -- C:\Program Files\Norton AntiVirus\navapsvc.exe PRC - [2004-11-02 16:59:50 | 00,316,544 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe PRC - [2003-11-19 00:41:02 | 00,088,363 | ---- | M] (Agere Systems) -- C:\WINDOWS\AGRSMMSG.exe PRC - [2004-05-20 04:57:30 | 00,098,304 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe PRC - [2004-05-20 04:57:04 | 00,532,480 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe PRC - [2003-10-21 11:52:32 | 00,040,960 | ---- | M] (Cyberlink Corp.) -- C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe PRC - [2004-02-10 10:51:30 | 00,118,784 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\hkcmd.exe PRC - [2004-07-14 14:19:00 | 00,151,552 | ---- | M] (Acer Value Labs, USA) -- C:\acer\epm\epm-dm.exe PRC - [2009-09-21 15:10:24 | 00,404,737 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\update.exe PRC - [2004-06-30 15:41:32 | 00,303,104 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\QtZgAcer.EXE PRC - [2005-01-10 15:00:52 | 00,462,848 | ---- | M] (INPROCOMM) -- C:\Program Files\acer\Wireless\Utility\WlanUtil.exe PRC - [2007-02-11 00:07:32 | 00,241,664 | ---- | M] (A4Tech Co.,Ltd.) -- C:\Program Files\A4Tech\Mouse\Amoumain.exe PRC - [2006-03-09 11:47:52 | 00,071,328 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe PRC - [2007-12-14 03:42:38 | 00,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe PRC - [2009-03-02 13:08:48 | 00,209,153 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe PRC - [2003-06-18 17:17:06 | 01,590,472 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\LuComServer.EXE PRC - [2004-09-14 17:18:58 | 00,286,720 | ---- | M] (acer Inc.) -- C:\Program Files\acer\eRecovery\Monitor.exe PRC - [2007-12-14 03:42:38 | 00,329,104 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_04\bin\jucheck.exe PRC - [2009-09-24 20:46:28 | 01,685,816 | ---- | M] (Piriform Ltd) -- C:\Program Files\CCleaner\ccleaner.exe PRC - [2009-09-22 10:26:36 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2009-10-02 17:44:30 | 00,519,168 | ---- | M] (OldTimer Tools) -- D:\Inne\OTL.exe PRC - [2008-04-14 22:51:32 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2004-08-16 15:17:20 | 01,287,168 | ---- | M] (OSA Technologies Inc.) -- C:\Acer\eManager\anbmServ.exe -- (anbmService [Auto | Running]) SRV - [2009-05-13 16:48:24 | 00,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService [Auto | Running]) SRV - [2009-09-21 15:10:30 | 00,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService [Auto | Running]) SRV - [2004-05-15 22:30:04 | 00,376,832 | ---- | M] () -- C:\WINDOWS\System32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Stopped]) SRV - [2006-03-09 11:47:58 | 00,255,648 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr [Auto | Running]) SRV - [2006-03-09 11:48:08 | 00,087,712 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe -- (ccPwdSvc [On_Demand | Stopped]) SRV - [2006-03-09 11:48:22 | 00,235,168 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr [Auto | Running]) SRV - [2009-03-03 14:53:08 | 00,033,176 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\NOS\bin\getPlus_HelperSvc.exe -- (getPlus(R) Helper [On_Demand | Stopped]) SRV - [2005-05-29 12:59:56 | 00,249,856 | ---- | M] (Aladdin Knowledge Systems Ltd.) -- C:\Program Files\Aladdin\HASP LM\nhsrvice.exe -- (HASP Loader [Auto | Running]) SRV - [2008-04-14 22:50:46 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running]) SRV - [2008-04-14 22:50:34 | 00,028,672 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\irmon.dll -- (Irmon [Auto | Running]) SRV - [2003-06-19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running]) SRV - [2004-04-23 11:04:16 | 00,158,848 | ---- | M] (Symantec Corporation) -- C:\Program Files\Norton AntiVirus\navapsvc.exe -- (navapsvc [Auto | Running]) SRV - [2003-07-28 20:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped]) SRV - [2005-01-25 21:48:50 | 00,194,272 | ---- | M] (Symantec Corporation) -- C:\Program Files\Norton AntiVirus\SAVScan.exe -- (SAVScan [On_Demand | Stopped]) SRV - [2003-06-24 18:23:10 | 00,066,784 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe -- (SBService [Auto | Stopped]) SRV - [2005-01-21 22:32:12 | 00,206,552 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc [On_Demand | Stopped]) SRV - [2004-11-02 16:59:50 | 00,316,544 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe -- (SymWSC [Auto | Running]) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2003-11-19 00:41:18 | 01,205,292 | ---- | M] (Agere Systems) -- C:\WINDOWS\System32\DRIVERS\AGRSM.sys -- (AgereSoftModem [On_Demand | Stopped]) DRV - [2006-11-22 10:01:46 | 00,327,168 | ---- | M] (Aladdin Knowledge Systems Ltd.) -- C:\WINDOWS\System32\DRIVERS\akshasp.sys -- (akshasp [On_Demand | Stopped]) DRV - [2006-11-22 10:01:48 | 00,100,096 | ---- | M] (Aladdin Knowledge Systems Ltd.) -- C:\WINDOWS\System32\DRIVERS\aksusb.sys -- (aksusb [On_Demand | Stopped]) DRV - [2007-01-24 19:46:50 | 00,008,704 | ---- | M] (A4Tech Co.,Ltd.) -- C:\WINDOWS\System32\DRIVERS\Amfilter.sys -- (Amfilter [System | Running]) DRV - [2007-02-11 01:55:50 | 00,013,824 | ---- | M] (A4Tech Co.,Ltd.) -- C:\WINDOWS\System32\DRIVERS\Amusbprt.sys -- (Amusbprt [On_Demand | Stopped]) DRV - [2004-05-15 22:41:40 | 00,745,984 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys -- (ati2mtag [On_Demand | Stopped]) DRV - [2009-02-13 12:35:06 | 00,011,608 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio [System | Running]) DRV - [2009-09-21 15:10:42 | 00,055,656 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\DRIVERS\avgntflt.sys -- (avgntflt [Auto | Running]) DRV - [2009-03-30 10:33:08 | 00,096,104 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\DRIVERS\avipbb.sys -- (avipbb [System | Running]) DRV - [2003-11-21 15:20:10 | 00,113,152 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\System32\DRIVERS\b57xp32.sys -- (b57w2k [On_Demand | Stopped]) DRV - [2003-09-26 18:41:12 | 00,044,032 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys -- (bcm4sbxp [On_Demand | Running]) DRV - [2004-04-29 22:09:20 | 00,292,352 | ---- | M] (Conexant Systems Inc.) -- C:\WINDOWS\System32\drivers\camcaud.sys -- (CAMCAUD [On_Demand | Running]) DRV - [2004-04-29 22:10:06 | 00,274,688 | ---- | M] (Conexant Systems Inc.) -- C:\WINDOWS\System32\drivers\camchal.sys -- (CAMCHALA [On_Demand | Running]) DRV - [2002-11-20 16:29:12 | 00,017,983 | ---- | M] (Dritek System Inc.) -- C:\WINDOWS\System32\Drivers\DKbFltr.sys -- (DKbFltr [On_Demand | Running]) DRV - [2004-07-19 13:10:00 | 00,004,096 | ---- | M] (Acer Value Labs, USA) -- C:\WINDOWS\System32\drivers\epm-psd.sys -- (EpmPsd [Auto | Running]) DRV - [2004-08-14 20:59:00 | 00,078,208 | ---- | M] (Acer Value Labs, USA) -- C:\WINDOWS\System32\drivers\epm-shd.sys -- (EpmShd [Auto | Running]) DRV - [2006-11-22 10:01:48 | 00,693,760 | ---- | M] (Aladdin Knowledge Systems Ltd.) -- C:\WINDOWS\System32\drivers\hardlock.sys -- (Hardlock [Auto | Running]) DRV - [2009-04-23 10:08:28 | 00,047,616 | ---- | M] (Aladdin Knowledge Systems) -- C:\WINDOWS\System32\drivers\Haspnt.sys -- (Haspnt [Auto | Running]) DRV - [2004-03-10 20:40:28 | 00,199,552 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\DRIVERS\HSFHWICH.sys -- (HSFHWICH [On_Demand | Running]) DRV - [2004-03-10 20:35:48 | 01,041,536 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\DRIVERS\HSF_DP.sys -- (HSF_DP [On_Demand | Running]) DRV - [2004-02-10 11:17:06 | 00,681,469 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\DRIVERS\ialmnt5.sys -- (ialm [On_Demand | Running]) DRV - [2003-10-01 13:29:50 | 00,069,632 | ---- | M] () -- C:\Program Files\acer\eRecovery\int15.sys -- (int15.sys [On_Demand | Running]) DRV - [2004-08-11 17:26:42 | 00,160,896 | ---- | M] (Inprocomm, Inc.) -- C:\WINDOWS\System32\DRIVERS\i2220ntx.sys -- (IPN2220 [On_Demand | Running]) DRV - [2003-04-09 22:48:08 | 00,011,043 | ---- | M] (Conexant) -- C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys -- (mdmxsdk [Auto | Running]) DRV - [2008-08-27 10:00:00 | 00,089,104 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080827.038\NAVENG.SYS -- (NAVENG [On_Demand | Running]) DRV - [2008-08-27 10:00:00 | 00,873,552 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080827.038\NAVEX15.SYS -- (NAVEX15 [On_Demand | Running]) DRV - [2008-04-14 00:24:38 | 00,028,672 | ---- | M] (National Semiconductor Corporation) -- C:\WINDOWS\System32\DRIVERS\nscirda.sys -- (NSCIRDA [On_Demand | Stopped]) DRV - [2004-10-04 10:47:54 | 00,006,912 | ---- | M] (NewTech Infosystems, Inc.) -- C:\WINDOWS\System32\DRIVERS\NTIDrvr.sys -- (NTIDrvr [On_Demand | Running]) DRV - [2002-05-02 12:52:22 | 00,017,134 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\PCANDIS5.SYS -- (PCANDIS5 [On_Demand | Running]) DRV - [2004-08-04 20:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running]) DRV - [2005-01-25 21:48:52 | 00,305,288 | ---- | M] (Symantec Corporation) -- C:\Program Files\Norton AntiVirus\SAVRT.SYS -- (SAVRT [System | Running]) DRV - [2005-01-25 21:48:52 | 00,037,000 | ---- | M] (Symantec Corporation) -- C:\Program Files\Norton AntiVirus\SAVRTPEL.SYS -- (SAVRTPEL [System | Running]) DRV - [2008-04-13 22:09:18 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped]) DRV - [2008-05-19 18:39:02 | 00,368,896 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\System32\DRIVERS\semwl5.sys -- (SEM43XX [On_Demand | Stopped]) DRV - [2008-05-19 18:38:58 | 00,114,944 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\System32\DRIVERS\GCXX.sys -- (SEMWModem [On_Demand | Stopped]) DRV - [2008-05-19 18:39:00 | 00,053,248 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\System32\DRIVERS\GCXXNet.sys -- (SEMWWNIC [On_Demand | Stopped]) DRV - [2008-04-14 00:06:34 | 00,016,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\SMBBATT.sys -- (SMBBATT [On_Demand | Running]) DRV - [2001-08-17 21:57:56 | 00,006,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\SMBHC.sys -- (SMBHC [System | Running]) DRV - [2008-05-19 18:39:00 | 00,021,888 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\System32\DRIVERS\GCXXSC.sys -- (Sony_EricssonWWSC [On_Demand | Stopped]) DRV - [2009-05-11 10:12:26 | 00,028,520 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\DRIVERS\ssmdrv.sys -- (ssmdrv [System | Running]) DRV - [2003-08-18 20:46:02 | 00,082,136 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent [On_Demand | Running]) DRV - [2005-01-21 22:31:48 | 00,026,424 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV [On_Demand | Running]) DRV - [2005-01-21 22:31:50 | 00,267,384 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI [System | Running]) DRV - [2004-05-20 04:52:40 | 00,184,768 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\System32\DRIVERS\SynTP.sys -- (SynTP [On_Demand | Running]) DRV - [2004-08-20 00:41:46 | 03,210,496 | ---- | M] (Intel® Corporation) -- C:\WINDOWS\System32\DRIVERS\w29n51.sys -- (w29n51 [On_Demand | Stopped]) DRV - [2004-03-10 20:37:26 | 00,682,624 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys -- (winachsf [On_Demand | Running]) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-275269770-416203418-1208109382-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKU\S-1-5-21-275269770-416203418-1208109382-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch IE - HKU\S-1-5-21-275269770-416203418-1208109382-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://global.acer.com IE - HKU\S-1-5-21-275269770-416203418-1208109382-1004\S-1-5-21-275269770-416203418-1208109382-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "http://www.google.pl/" FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}:6.0.04 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.14 FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2008-06-04 11:04:18 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2008-06-04 11:04:18 | 00,000,000 | ---D | M] [2008-08-26 08:59:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\As\Dane aplikacji\mozilla\Extensions [2008-08-26 08:59:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\As\Dane aplikacji\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2008-06-04 11:04:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\As\Dane aplikacji\mozilla\Firefox\Profiles\e30uaoki.default\extensions [2008-06-04 11:04:18 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2008-06-04 11:04:20 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2008-08-08 09:36:38 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} [2009-09-22 10:26:34 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2009-09-22 10:26:34 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2008-03-24 20:21:00 | 02,889,088 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\NPSWF32.dll [2007-03-22 19:23:30 | 00,017,248 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL [2009-02-27 12:13:42 | 00,103,792 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2009-09-22 10:26:40 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll [2009-09-22 10:26:40 | 00,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2009-09-22 10:26:40 | 00,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2009-09-22 10:26:40 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml [2009-09-22 10:26:40 | 00,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2009-09-22 10:26:42 | 00,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2009-09-22 10:26:42 | 00,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2009-09-22 10:26:42 | 00,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml O1 HOSTS File: (742 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (CNavExtBho Class) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll (Symantec Corporation) O3 - HKLM\..\Toolbar: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (Symantec Corporation) O3 - HKU\S-1-5-21-275269770-416203418-1208109382-1004\..\Toolbar\ShellBrowser: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (Symantec Corporation) O4 - HKLM..\Run: [acerWireless] C:\Program Files\acer\Wireless\Utility\WlanUtil.exe (INPROCOMM) O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [AGRSMMSG] C:\WINDOWS\AGRSMMSG.exe (Agere Systems) O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation) O4 - HKLM..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe (Acer Value Labs, USA) O4 - HKLM..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe (Acer Value Labs, Taiwan) O4 - HKLM..\Run: [eRecoveryService] C:\WINDOWS\System32\Check.exe (acer Inc.) O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation) O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation) O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation) O4 - HKLM..\Run: [iPlusManager] C:\Program Files\iPlus\iPlusChecker.exe () O4 - HKLM..\Run: [LaunchApp] C:\WINDOWS\Alaunch.exe (Acer Inc.) O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.) O4 - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe (Agere Systems) O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe () O4 - HKLM..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe (Symantec Corporation) O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation) O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation) O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.) O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe (Sun Microsystems, Inc.) O4 - HKLM..\Run: [Symantec NetDriver Monitor] C:\Program Files\SymNetDrv\SNDMon.exe (Symantec Corporation) O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.) O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.) O4 - HKLM..\Run: [WheelMouse] C:\Program Files\A4Tech\Mouse\Amoumain.exe (A4Tech Co.,Ltd.) O4 - HKU\S-1-5-21-275269770-416203418-1208109382-1004..\RunOnce: [FlashPlayerUpdate] C:\Program Files\Mozilla Firefox\plugins\NPSWF32_FlashUtil.exe (Adobe Systems, Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-275269770-416203418-1208109382-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: E&ksport do programu Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\npjpi160_04.dll (Sun Microsystems, Inc.) O9 - Extra Button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1212573418041 (MUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Java Plug-in 1.6.0_04) O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Java Plug-in 1.6.0_04) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Java Plug-in 1.6.0_04) O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab (get_atlcom Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.179.1.62 62.179.1.63 O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\ipp - No CLSID value found O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2004-10-04 10:32:38 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ] O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2009-10-02 17:29:07 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner [2009-10-02 17:03:24 | 00,000,000 | -HSD | C] -- C:\FOUND.003 [2009-09-21 15:26:53 | 00,153,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\triedit.dll [2009-04-23 10:08:27 | 00,000,383 | ---- | C] () -- C:\WINDOWS\System32\haspdos.sys [2008-08-26 11:51:57 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\hppapr02.dll [2008-06-04 11:46:27 | 00,000,421 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2008-06-03 11:39:15 | 00,002,430 | ---- | C] () -- C:\WINDOWS\wincmd.ini [2004-10-04 11:11:30 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini [2004-10-04 10:48:34 | 00,000,033 | ---- | C] () -- C:\WINDOWS\Acer.ini [2004-10-04 10:48:33 | 00,000,328 | ---- | C] () -- C:\WINDOWS\uninstall.ini [2004-10-04 10:47:52 | 00,001,024 | RH-- | C] () -- C:\WINDOWS\System32\ntiembed.dll [2004-10-04 10:47:25 | 00,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIMPEG2.dll [2004-10-04 10:47:25 | 00,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTICDMK32.dll [2004-10-04 10:43:51 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\SynTPCoI.dll [2004-10-04 10:37:49 | 00,000,751 | ---- | C] () -- C:\WINDOWS\poweroption.ini [2004-10-04 10:37:48 | 00,037,684 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI [2004-10-04 10:28:58 | 00,003,619 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini [2003-04-08 11:40:22 | 00,005,679 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI [2001-12-26 16:12:30 | 00,065,536 | R--- | C] () -- C:\WINDOWS\System32\multiplex_vcd.dll [2001-09-03 23:46:38 | 00,110,592 | R--- | C] () -- C:\WINDOWS\System32\Hmpg12.dll [2001-07-30 16:33:56 | 00,118,784 | R--- | C] () -- C:\WINDOWS\System32\HMPV2_ENC.dll [2001-07-23 22:04:36 | 00,118,784 | R--- | C] () -- C:\WINDOWS\System32\HMPV2_ENC_MMX.dll [1980-01-01 00:00:00 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\ati2evxx.dll [1980-01-01 00:00:00 | 00,002,790 | ---- | C] () -- C:\WINDOWS\ANTIV.INI [1980-01-01 00:00:00 | 00,000,619 | ---- | C] () -- C:\WINDOWS\win.ini [1980-01-01 00:00:00 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini [1980-01-01 00:00:00 | 00,000,083 | ---- | C] () -- C:\WINDOWS\ALaunch.ini [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2009-10-02 17:07:48 | 00,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job [2009-10-02 17:04:10 | 00,000,012 | ---- | M] () -- C:\WINDOWS\System32\haspaddr.dat [2009-10-02 17:04:00 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009-10-02 17:03:46 | 00,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009-10-02 17:03:36 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009-10-02 17:03:30 | 25,846,1696 | -HS- | M] () -- C:\hiberfil.sys [2009-09-21 15:14:06 | 00,007,168 | ---- | M] () -- C:\Documents and Settings\As\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009-09-21 15:10:42 | 00,055,656 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys [color=#E56717]========== LOP Check ==========[/color] [2004-10-04 10:24:08 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Default User\Dane aplikacji [2004-10-04 10:24:08 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji [2004-10-04 10:47:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CyberLink [2004-10-04 10:37:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Dane aplikacji [2004-10-04 10:37:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji [2004-10-04 10:24:08 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji [2008-06-03 15:50:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\Intel [2004-10-04 10:24:08 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\As\Dane aplikacji [2009-05-29 23:49:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\As\Dane aplikacji\CyberLink [2008-06-03 15:50:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\As\Dane aplikacji\Intel [2008-06-05 12:50:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\As\Dane aplikacji\iPlus [2008-08-08 09:43:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\As\Dane aplikacji\OpenOffice.org2 [2008-08-06 12:34:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\As\Dane aplikacji\WKPolska [2004-08-04 20:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini [2009-10-02 17:04:00 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT [2008-08-04 12:08:02 | 00,000,406 | ---- | M] () -- C:\WINDOWS\Tasks\Symantec NetDetect.job [2009-04-24 20:01:56 | 00,000,520 | ---- | M] () -- C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job [2009-10-02 17:07:48 | 00,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job [color=#E56717]========== Purity Check ==========[/color] < End of report > [/log] [log] OTL Extras logfile created on: 2009-10-02 17:45:50 - Run 1 OTL by OldTimer - Version 3.0.17.0 Folder = D:\Inne Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 246,42 Mb Total Physical Memory | 22,51 Mb Available Physical Memory | 9,14% Memory free 603,26 Mb Paging File | 202,94 Mb Available in Paging File | 33,64% Paging File free Paging file location(s): C:\pagefile.sys 372 744 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 17,07 Gb Total Space | 3,51 Gb Free Space | 20,56% Space Free | Partition Type: FAT32 Drive D: | 17,24 Gb Total Space | 13,05 Gb Free Space | 75,67% Space Free | Partition Type: FAT32 E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: ACER-E3E8C2474F Current User Name: As Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* File not found chm.file [open] -- "C:\WINDOWS\hh.exe" %1 (Microsoft Corporation) cmdfile [open] -- "%1" %* File not found comfile [open] -- "%1" %* File not found exefile [open] -- "%1" %* File not found htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation) piffile [open] -- "%1" %* File not found regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" File not found scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S File not found txtfile [edit] -- Reg Error: Key error. Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 1 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation) [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{1526D87C-A955-4FAB-BF18-697BA457E352}" = Norton WMI Update "{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com "{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java(TM) 6 Update 4 "{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{4820DD99-52D1-42BB-927E-B6B6DF231AF5}" = acer Wireless LAN "{4DB39959-75DC-444C-A351-6AB4C6C81AFA}" = OpenOffice.org 2.4 "{4E68EAA3-775A-4542-A08A-47DB8E8E74A6}" = NTI Backup NOW! 3 "{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePowerManagement "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{7169B8E4-2632-46B1-AA5F-167CB5FE5029}" = Symantec Network Drivers Update "{827289F5-B44F-4E49-9993-840741585A62}" = Acer eManager for Notebook "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Extreme Graphics 2 Driver "{91130415-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003 "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1 "{C438B7C4-B4F8-49C5-A4DF-FF6F1F242778}" = NTI CD & DVD-Maker "{C6F5B6CF-609C-428E-876F-CA83176C021B}" = Norton AntiVirus 2004 "{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus(R) for Adobe "{D327AFC9-7BAA-473A-8319-6EB7A0D40138}" = Symantec Script Blocking Installer "{D6414CC7-F215-467F-88B1-546ED863F35B}" = CC_ccStart "{DC367608-64A7-4BF7-92F4-8BAA25BA02DB}" = ccCommon "{E47EE8FB-ACC0-4608-859C-4E2851B18A6A}" = SymNet "{E5EE9939-259F-4DE2-8023-5C49E16A4F43}" = Norton AntiVirus Parent MSI "{FC37ABD0-2108-4beb-B010-1254E0662B5A}" = MSRedist "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Agere Systems Soft Modem" = Agere Systems AC'97 Modem "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus "CCleaner" = CCleaner (remove only) "CNXT_MODEM_PCI_VEN_8086&DEV_24C6&SUBSYS_00641025" = SoftV92 Data Fax Modem with SmartCP "Conexant PCI Audio" = Conexant AC-Link Audio "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "InstallShield_{4E68EAA3-775A-4542-A08A-47DB8E8E74A6}" = NTI Backup NOW! 3 "InstallShield_{827289F5-B44F-4E49-9993-840741585A62}" = Acer eManager for Notebook "InstallShield_{C438B7C4-B4F8-49C5-A4DF-FF6F1F242778}" = NTI CD & DVD-Maker Gold "iPlus manager_is1" = iPlus manager 2.0 "LEX" = LEX "LiveReg" = LiveReg (Symantec Corporation) "LiveUpdate" = LiveUpdate 1.90 (Symantec Corporation) "LManager" = Launch Manager "Mozilla Firefox (3.0.14)" = Mozilla Firefox (3.0.14) "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "Sterownik klucza HASP" = Sterownik klucza HASP "SymSetup.{C6F5B6CF-609C-428E-876F-CA83176C021B}" = Norton AntiVirus 2004 (Symantec Corporation) "SynTPDeinstKey" = Synaptics Pointing Device Driver "Totalcmd" = Total Commander (Remove or Repair) "WheelMouse" = 2X-Office 7.80 "Windows XP Service Pack" = Windows XP Service Pack 3 "Zarządca licencji HASP" = Zarządca licencji HASP [color=#E56717]========== Last 10 Event Log Errors ==========[/color] [ Application Events ] Error - 2009-05-20 10:59:48 | Computer Name = ACER-E3E8C2474F | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd syntpenh.exe, wersja 7.10.12.0, moduł powodujący błąd syntpenh.exe, wersja 7.10.12.0, adres błędu 0x0001b9a0. Error - 2009-05-20 11:12:49 | Computer Name = ACER-E3E8C2474F | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca firefox.exe, wersja 1.9.0.3399, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error - 2009-07-29 13:37:55 | Computer Name = ACER-E3E8C2474F | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd syntpenh.exe, wersja 7.10.12.0, moduł powodujący błąd syntpenh.exe, wersja 7.10.12.0, adres błędu 0x0001b9a0. Error - 2009-07-29 14:07:14 | Computer Name = ACER-E3E8C2474F | Source = crypt32 | ID = 131080 Description = Nie można automatycznie pobrać aktualizacji numeru sekwencji głównej listy innych firm z: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>, wystąpił błąd: Operacja została zwrócona, ponieważ przekroczono limit czasu. Error - 2009-08-30 11:07:28 | Computer Name = ACER-E3E8C2474F | Source = Avira AntiVir | ID = 4112 Description = An error occurred during a resource request to the Windows NT system. The resource <ThreadInit> has not been allocated. This could be due to an out-of-memory error or any other system failure. Returned error code: 0x18 Error - 2009-08-30 15:46:27 | Computer Name = ACER-E3E8C2474F | Source = crypt32 | ID = 131080 Description = Nie można automatycznie pobrać aktualizacji numeru sekwencji głównej listy innych firm z: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>, wystąpił błąd: Operacja została zwrócona, ponieważ przekroczono limit czasu. Error - 2009-09-29 14:41:07 | Computer Name = ACER-E3E8C2474F | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd update.exe, wersja 9.0.0.52, moduł powodujący błąd msvcr90.dll, wersja 9.0.30729.1, adres błędu 0x000371e2. Error - 2009-10-02 11:07:24 | Computer Name = ACER-E3E8C2474F | Source = crypt32 | ID = 131080 Description = Nie można automatycznie pobrać aktualizacji numeru sekwencji głównej listy innych firm z: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>, wystąpił błąd: Operacja została zwrócona, ponieważ przekroczono limit czasu. Error - 2009-10-02 11:17:11 | Computer Name = ACER-E3E8C2474F | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca firefox.exe, wersja 1.9.0.3526, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error - 2009-10-02 11:17:11 | Computer Name = ACER-E3E8C2474F | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca firefox.exe, wersja 1.9.0.3526, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. [ Application Events ] Error - 2009-05-20 10:59:48 | Computer Name = ACER-E3E8C2474F | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd syntpenh.exe, wersja 7.10.12.0, moduł powodujący błąd syntpenh.exe, wersja 7.10.12.0, adres błędu 0x0001b9a0. Error - 2009-05-20 11:12:49 | Computer Name = ACER-E3E8C2474F | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca firefox.exe, wersja 1.9.0.3399, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error - 2009-07-29 13:37:55 | Computer Name = ACER-E3E8C2474F | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd syntpenh.exe, wersja 7.10.12.0, moduł powodujący błąd syntpenh.exe, wersja 7.10.12.0, adres błędu 0x0001b9a0. Error - 2009-07-29 14:07:14 | Computer Name = ACER-E3E8C2474F | Source = crypt32 | ID = 131080 Description = Nie można automatycznie pobrać aktualizacji numeru sekwencji głównej listy innych firm z: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>, wystąpił błąd: Operacja została zwrócona, ponieważ przekroczono limit czasu. Error - 2009-08-30 11:07:28 | Computer Name = ACER-E3E8C2474F | Source = Avira AntiVir | ID = 4112 Description = An error occurred during a resource request to the Windows NT system. The resource <ThreadInit> has not been allocated. This could be due to an out-of-memory error or any other system failure. Returned error code: 0x18 Error - 2009-08-30 15:46:27 | Computer Name = ACER-E3E8C2474F | Source = crypt32 | ID = 131080 Description = Nie można automatycznie pobrać aktualizacji numeru sekwencji głównej listy innych firm z: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>, wystąpił błąd: Operacja została zwrócona, ponieważ przekroczono limit czasu. Error - 2009-09-29 14:41:07 | Computer Name = ACER-E3E8C2474F | Source = Application Error | ID = 1000 Description = Aplikacja powodująca błąd update.exe, wersja 9.0.0.52, moduł powodujący błąd msvcr90.dll, wersja 9.0.30729.1, adres błędu 0x000371e2. Error - 2009-10-02 11:07:24 | Computer Name = ACER-E3E8C2474F | Source = crypt32 | ID = 131080 Description = Nie można automatycznie pobrać aktualizacji numeru sekwencji głównej listy innych firm z: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>, wystąpił błąd: Operacja została zwrócona, ponieważ przekroczono limit czasu. Error - 2009-10-02 11:17:11 | Computer Name = ACER-E3E8C2474F | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca firefox.exe, wersja 1.9.0.3526, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error - 2009-10-02 11:17:11 | Computer Name = ACER-E3E8C2474F | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca firefox.exe, wersja 1.9.0.3526, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. [ System Events ] Error - 2009-09-21 09:07:24 | Computer Name = ACER-E3E8C2474F | Source = sr | ID = 1 Description = Filtr Przywracania systemu napotkał nieoczekiwany błąd '0xC000000D' podczas przetwarzania pliku 'OBR3.INI' w woluminie 'HarddiskVolume1'. W rezultacie zostało zatrzymane monitorowanie woluminu. Error - 2009-09-24 14:32:31 | Computer Name = ACER-E3E8C2474F | Source = Service Control Manager | ID = 7009 Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się z usługą Usługa bramy warstwy aplikacji. Error - 2009-09-24 14:32:31 | Computer Name = ACER-E3E8C2474F | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Usługa bramy warstwy aplikacji z powodu następującego błędu: %%1053 Error - 2009-09-24 14:33:52 | Computer Name = ACER-E3E8C2474F | Source = sr | ID = 1 Description = Filtr Przywracania systemu napotkał nieoczekiwany błąd '0xC000000D' podczas przetwarzania pliku 'OBR3.INI' w woluminie 'HarddiskVolume1'. W rezultacie zostało zatrzymane monitorowanie woluminu. Error - 2009-09-29 14:38:31 | Computer Name = ACER-E3E8C2474F | Source = Service Control Manager | ID = 7011 Description = Limit czasu (30000 milisekund) podczas oczekiwania na odpowiedź transakcji z usługi AntiVirSchedulerService. Error - 2009-09-29 14:41:05 | Computer Name = ACER-E3E8C2474F | Source = Service Control Manager | ID = 7009 Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się z usługą Usługa COM nagrywania dysków CD IMAPI. Error - 2009-09-29 14:41:05 | Computer Name = ACER-E3E8C2474F | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Usługa COM nagrywania dysków CD IMAPI z powodu następującego błędu: %%1053 Error - 2009-10-02 11:06:42 | Computer Name = ACER-E3E8C2474F | Source = Service Control Manager | ID = 7009 Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się z usługą Usługa bramy warstwy aplikacji. Error - 2009-10-02 11:06:42 | Computer Name = ACER-E3E8C2474F | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Usługa bramy warstwy aplikacji z powodu następującego błędu: %%1053 Error - 2009-10-02 11:08:46 | Computer Name = ACER-E3E8C2474F | Source = sr | ID = 1 Description = Filtr Przywracania systemu napotkał nieoczekiwany błąd '0xC000000D' podczas przetwarzania pliku 'OBR3.INI' w woluminie 'HarddiskVolume1'. W rezultacie zostało zatrzymane monitorowanie woluminu. < End of report > [/log]
Gość komentarz 10 października 2009 komentarz 10 października 2009 Logi są OK. [b]1.[/b] Odpal OTL i wywołaj go z opcji [b]CleanUp[/b], zgódź się na czyszczenie + restart komputera. [b]2.[/b] Wykonaj [url=http://www.forumpc.pl/index.php?showtopic=17478][b][color=blue][u]Optymalizację Systemu[/url][/b][/color][/u]. [b]3.[/b] Użyj programu [url="http://www.forumpc.pl/index.php?showtopic=107753&st=0&p=752434&#entry752434"][b][color="blue"][u]Malwarebytes[/url][/b][/color][/u]. Wciskamy [b]Skanuj[/b], wybieramy dyski do skanowania i [b]Rozpoczynamy skanowanie[/b], na końcu wciskamy [b]Usuń zaznaczone[/b] jak będą i Ok. Wrzuć wygenerowany raport po usuwaniu MBAMem. .
Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!
Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.