scarp utworzono 26 czerwca 2010 utworzono 26 czerwca 2010 Cześć, tak jak w temacie ciągle coś mi się bugguje!;X 4 przykłady: Gram w Lola wyskakuje mi że nie mam direxa, po resecie pc all działa... Gram w maple: nagle zaczyna migac ( czarne, pulpit, czarne pulpit) ( tak jakby sie minimalizowało i maksymalizowalo...) Gram W warcrafta, wywala mnie z gry. Coś robie na ps cs 4 I blue ekran i res pc... O co biega?:X
Gość komentarz 26 czerwca 2010 komentarz 26 czerwca 2010 podaj dokładną konfigurację komputera wraz z marką i mocą zasilacza
scarp komentarz 26 czerwca 2010 Autor komentarz 26 czerwca 2010 (edytowane) marke itd moge podać ale zasilacza nie, gdy otwieram blaszkę kompa nie ma napisanego nigdzie mocy zasilacza nic, da się jakoś inaczej spr? zara podam konf i marke [color="#ff0000"]//nie cytujemy całych postów //dan[/color]
Gość komentarz 26 czerwca 2010 komentarz 26 czerwca 2010 moc zasilacza podana jest na ZASILACZU a nie w innym miejscu
scarp komentarz 26 czerwca 2010 Autor komentarz 26 czerwca 2010 (edytowane) Gdy otwieram blaszkę.... Widzę zasilacz, nic tam nie ma "Nigdzie" mam jeszcze 1 pytanie dotyczące dlaczego 1 rdzen nigdy nie jest uzywany? zdj:
raazor90 komentarz 26 czerwca 2010 komentarz 26 czerwca 2010 Jeśli chodzi o blue screen wykonaj: http://www.forumpc.pl/index.php?showtopic=153598 Poza tym pachnie mi tu infekcją, więc daj loga z OTL
scarp komentarz 26 czerwca 2010 Autor komentarz 26 czerwca 2010 (edytowane) K, otl, lecz mogę Linka do poradnika ? bo otl'a mam tylko nie pamiętam co trza ustawić;x Infekcja była... 172 coś wirów ale pare dni temu usunołem mój anty Vir= AVG
raazor90 komentarz 26 czerwca 2010 komentarz 26 czerwca 2010 Proszę: http://www.forumpc.pl/index.php?showtopic=104338
scarp komentarz 26 czerwca 2010 Autor komentarz 26 czerwca 2010 (edytowane) Dziękuje Ci bardzo, a o co biega z tymi rdzeniami? [quote]mam jeszcze 1 pytanie dotyczące dlaczego 1 rdzen nigdy nie jest uzywany? zdj:[/quote] + [quote]blue screen tutaj[/quote] to ja to mialem odznaczone, lecz i tak musiałem resetować, ponieważ nic nie mogłem zrobić otl.txt [log] OTL logfile created on: 2010-06-26 22:04:16 - Run 5 OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\scarp's\Moje dokumenty\Downloads Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 895,00 Mb Total Physical Memory | 371,00 Mb Available Physical Memory | 41,00% Memory free 3,00 Gb Paging File | 2,00 Gb Available in Paging File | 78,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 97,65 Gb Total Space | 25,09 Gb Free Space | 25,69% Space Free | Partition Type: NTFS Drive D: | 200,43 Gb Total Space | 199,31 Gb Free Space | 99,45% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: LION Current User Name: scarp's Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 60 Days Output = Standard [color=#E56717]========== Processes (All) ==========[/color] PRC - [2010-06-26 22:02:02 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\scarp's\Moje dokumenty\Downloads\OTL.exe PRC - [2010-06-15 06:54:53 | 000,134,808 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.2.183.29\GoogleCrashHandler.exe PRC - [2010-06-03 09:53:00 | 002,065,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgtray.exe PRC - [2010-06-03 09:52:50 | 000,515,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe PRC - [2010-06-03 09:52:49 | 000,620,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe PRC - [2010-06-03 09:51:37 | 000,722,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe PRC - [2010-06-03 09:51:35 | 001,101,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe PRC - [2010-06-02 07:57:48 | 000,945,648 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe PRC - [2010-05-22 04:48:06 | 000,308,064 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe PRC - [2010-05-04 16:05:48 | 011,981,408 | ---- | M] (GG Network S.A.) -- C:\Program Files\Gadu-Gadu 10\gg.exe PRC - [2010-04-03 19:23:16 | 000,154,216 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe PRC - [2010-03-28 11:16:06 | 000,797,112 | ---- | M] (iMesh, Inc) -- C:\Program Files\BearShare Applications\MediaBar\DataMngr\DataMngrUI.exe PRC - [2010-02-13 15:47:10 | 000,030,192 | ---- | M] (Google) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe PRC - [2009-11-09 05:17:50 | 000,180,224 | ---- | M] (PowerISO Computing, Inc.) -- C:\Program Files\PowerISO\PWRISOVM.EXE PRC - [2009-10-28 10:46:04 | 001,515,520 | ---- | M] (IVO Software Sp. z o.o.) -- C:\Program Files\IVONA\IVONA ControlCenter\IVONA ControlCenter.exe PRC - [2009-09-23 15:04:56 | 000,203,608 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe PRC - [2009-09-23 15:04:52 | 000,447,832 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe PRC - [2009-05-26 16:51:45 | 000,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe PRC - [2009-02-09 13:25:57 | 000,111,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\services.exe PRC - [2008-09-24 08:50:36 | 000,086,016 | ---- | M] (Nektra S.A.) -- C:\Program Files\IVONA\IVONA Reader\integr\OutlookExpress\IROElauncher.exe PRC - [2008-07-23 10:51:26 | 016,804,864 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTHDCPL.exe PRC - [2008-04-15 14:00:00 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2008-04-15 14:00:00 | 000,510,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\winlogon.exe PRC - [2008-04-15 14:00:00 | 000,126,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\wmiapsrv.exe PRC - [2008-04-15 14:00:00 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msiexec.exe PRC - [2008-04-15 14:00:00 | 000,057,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spoolsv.exe PRC - [2008-04-15 14:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\smss.exe PRC - [2008-04-15 14:00:00 | 000,044,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\alg.exe PRC - [2008-04-15 14:00:00 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ctfmon.exe PRC - [2008-04-15 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [RPCSS] PRC - [2008-04-15 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [NETWORKSERVICE] PRC - [2008-04-15 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [NETSVCS] PRC - [2008-04-15 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [LOCALSERVICE] PRC - [2008-04-15 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [LOCALSERVICE] PRC - [2008-04-15 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [IMGSVC] PRC - [2008-04-15 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [DCOMLAUNCH] PRC - [2008-04-15 14:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [AKAMAI] PRC - [2008-04-15 14:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\lsass.exe PRC - [2008-04-15 14:00:00 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\csrss.exe PRC - [2008-01-16 12:04:36 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe PRC - [2007-10-12 09:34:56 | 000,071,096 | ---- | M] () -- C:\Program Files\Super_DVD_Creator_9.8\NMSAccessU.exe PRC - [2007-09-25 10:10:50 | 002,007,088 | ---- | M] (FlashGet.com) -- C:\Program Files\FlashGet\flashget.exe PRC - [2007-07-24 12:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe PRC - [2007-03-06 10:35:02 | 000,198,168 | ---- | M] (InterVideo Inc.) -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe PRC - [2007-03-03 13:48:28 | 000,067,056 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe PRC - [2006-09-24 10:43:42 | 000,061,440 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe PRC - [2006-02-28 13:42:38 | 000,229,376 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe [color=#E56717]========== Modules (All) ==========[/color] MOD - [2010-06-26 22:02:02 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\scarp's\Moje dokumenty\Downloads\OTL.exe MOD - [2010-05-06 12:35:43 | 000,916,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wininet.dll MOD - [2010-05-06 12:35:42 | 001,209,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\urlmon.dll MOD - [2010-05-06 12:35:37 | 001,985,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\iertutil.dll MOD - [2009-12-08 11:25:45 | 000,474,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\shlwapi.dll MOD - [2009-06-25 10:27:54 | 000,056,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\secur32.dll MOD - [2009-04-15 16:54:38 | 000,585,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rpcrt4.dll MOD - [2009-03-21 16:08:59 | 001,018,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\kernel32.dll MOD - [2009-02-09 12:53:44 | 000,686,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\advapi32.dll MOD - [2009-02-09 12:53:43 | 000,722,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntdll.dll MOD - [2009-01-07 18:20:36 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\normaliz.dll MOD - [2008-10-23 14:42:41 | 000,286,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\gdi32.dll MOD - [2008-06-17 21:03:15 | 008,489,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\shell32.dll MOD - [2008-04-15 14:00:00 | 002,953,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\xpsp2res.dll MOD - [2008-04-15 14:00:00 | 002,843,136 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msi.dll MOD - [2008-04-15 14:00:00 | 001,287,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ole32.dll MOD - [2008-04-15 14:00:00 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll MOD - [2008-04-15 14:00:00 | 000,997,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\setupapi.dll MOD - [2008-04-15 14:00:00 | 000,822,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\comres.dll MOD - [2008-04-15 14:00:00 | 000,580,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\user32.dll MOD - [2008-04-15 14:00:00 | 000,551,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\oleaut32.dll MOD - [2008-04-15 14:00:00 | 000,498,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\clbcatq.dll MOD - [2008-04-15 14:00:00 | 000,343,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcrt.dll MOD - [2008-04-15 14:00:00 | 000,297,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MSCTF.dll MOD - [2008-04-15 14:00:00 | 000,280,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\comdlg32.dll MOD - [2008-04-15 14:00:00 | 000,219,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\uxtheme.dll MOD - [2008-04-15 14:00:00 | 000,185,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\framedyn.dll MOD - [2008-04-15 14:00:00 | 000,177,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MSCTFIME.IME MOD - [2008-04-15 14:00:00 | 000,172,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wldap32.dll MOD - [2008-04-15 14:00:00 | 000,146,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\winspool.drv MOD - [2008-04-15 14:00:00 | 000,119,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntmarta.dll MOD - [2008-04-15 14:00:00 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx MOD - [2008-04-15 14:00:00 | 000,110,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\imm32.dll MOD - [2008-04-15 14:00:00 | 000,084,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\olepro32.dll MOD - [2008-04-15 14:00:00 | 000,067,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\srclient.dll MOD - [2008-04-15 14:00:00 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\samlib.dll MOD - [2008-04-15 14:00:00 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\psapi.dll MOD - [2008-04-15 14:00:00 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\version.dll MOD - [2007-05-18 18:13:08 | 000,053,329 | ---- | M] (www.flashget.com) -- C:\Program Files\FlashGet\fgmgr.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2010-06-26 09:26:44 | 002,561,624 | ---- | M] () [Auto | Running] -- c:\Program Files\Common Files\Akamai\rswin_3725.dll -- (Akamai) SRV - [2010-05-22 04:48:06 | 000,308,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd) SRV - [2010-05-01 10:42:30 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2010-02-13 15:47:10 | 000,030,192 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -- (GoogleDesktopManager-110309-193829) SRV - [2010-01-13 03:33:00 | 003,477,452 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\System32\GameMon.des -- (npggsvc) SRV - [2009-10-20 20:19:48 | 000,117,264 | ---- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental) SRV - [2009-09-26 07:35:02 | 000,819,600 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE -- (cvhsvc) SRV - [2009-09-26 04:28:22 | 004,639,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc) SRV - [2009-09-23 15:04:56 | 000,203,608 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa) SRV - [2009-09-23 15:04:52 | 000,447,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist) SRV - [2009-06-07 22:55:16 | 001,096,584 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService) SRV - [2009-01-07 12:40:56 | 000,348,752 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService) SRV - [2008-11-24 22:31:12 | 000,087,904 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter) SRV - [2008-01-16 12:04:36 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc) SRV - [2007-10-12 09:34:56 | 000,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files\Super_DVD_Creator_9.8\NMSAccessU.exe -- (NMSAccessU) SRV - [2007-07-24 12:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2) SRV - [2007-03-06 10:35:02 | 000,198,168 | ---- | M] (InterVideo Inc.) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe -- (Capture Device Service) SRV - [2007-03-03 13:48:28 | 000,067,056 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2010-06-03 09:52:50 | 000,242,896 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (AvgTdiX) DRV - [2010-06-03 09:52:49 | 000,029,584 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (AvgMfx86) DRV - [2010-05-22 04:48:15 | 000,216,200 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (AvgLdx86) DRV - [2010-04-29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy) DRV - [2010-04-07 22:47:56 | 000,002,688 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\Grudgemu\GrudgeMU 2010\grudgemu s4 muguard\MuGuard\llck1.sys -- (LLRING0) DRV - [2010-04-03 22:55:32 | 010,232,128 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv) DRV - [2010-02-11 14:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6) DRV - [2009-11-09 05:21:18 | 000,059,388 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\scdemu.sys -- (SCDEmu) DRV - [2009-10-20 20:19:44 | 000,050,704 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF) DRV - [2009-09-23 15:05:06 | 000,021,864 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Sftredirxp.sys -- (Sftredir) DRV - [2009-09-23 15:04:56 | 000,014,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Microsoft Application Virtualization Client\drivers\SftVolXP.sys -- (sftvol) DRV - [2009-09-23 15:04:54 | 000,190,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Microsoft Application Virtualization Client\drivers\sftplayxp.sys -- (sftplay) DRV - [2009-09-23 15:04:52 | 000,543,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Microsoft Application Virtualization Client\drivers\SftFSXP.sys -- (sftfs) DRV - [2009-04-03 11:18:26 | 000,130,936 | ---- | M] (PC Tools) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\PCTCore.sys -- (PCTCore) DRV - [2008-08-14 07:57:42 | 000,074,720 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\adfs.sys -- (adfs) DRV - [2008-07-24 12:02:44 | 004,749,824 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2008-04-15 14:00:00 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus) DRV - [2008-04-15 14:00:00 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx) DRV - [2008-04-15 14:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb) DRV - [2008-04-15 14:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx) DRV - [2008-03-25 05:48:08 | 000,022,016 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus) DRV - [2008-03-25 05:48:06 | 000,054,400 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD) DRV - [2008-02-15 09:15:26 | 000,014,336 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvsmu.sys -- (nvsmu) DRV - [2006-09-24 15:28:46 | 000,005,248 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan) DRV - [2006-07-02 00:32:26 | 000,043,520 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8) DRV - [2001-08-17 21:51:32 | 000,018,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\irsir.sys -- (irsir) DRV - [1996-04-03 21:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie IE - HKLM\..\URLSearchHook: {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-823518204-1303643608-682003330-1018\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com IE - HKU\S-1-5-21-823518204-1303643608-682003330-1018\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ IE - HKU\S-1-5-21-823518204-1303643608-682003330-1018\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\software\mozilla\Firefox\extensions\\{6E19037A-12E3-4295-8915-ED48BC341614}: C:\Program Files\RelevantKnowledge FF - HKLM\software\mozilla\Firefox\extensions\\m3ffxtbr@mywebsearch.com: C:\Program Files\MyWebSearch\bar\firefox\ FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010-06-03 09:55:02 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.4\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010-06-26 10:14:50 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.4\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-06-26 10:14:49 | 000,000,000 | ---D | M] [2010-06-26 11:00:47 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions [2009-09-24 00:49:46 | 000,000,000 | ---D | M] (SeekService) -- C:\Program Files\Mozilla Firefox\extensions\{86009AEF-9162-4EBC-B698-FF71D7B6B049} [2009-07-07 21:58:53 | 000,000,000 | ---D | M] (BearShare MediaBar) -- C:\Program Files\Mozilla Firefox\extensions\{D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} [2009-11-28 03:54:07 | 000,000,000 | ---D | M] (QuestService) -- C:\Program Files\Mozilla Firefox\extensions\{F2DDDB92-1605-4260-9B25-45A4DAE87B50} [2009-10-14 19:36:14 | 000,027,648 | ---- | M] (Ivo Software Sp. z o.o.) -- C:\Program Files\Mozilla Firefox\components\IvonaFirefoxToolbar.dll [2009-12-29 14:48:13 | 000,238,776 | ---- | M] (Pando Networks) -- C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll [2009-09-25 18:03:10 | 000,071,016 | ---- | M] ( ) -- C:\Program Files\Mozilla Firefox\plugins\npsharedview.dll [2010-04-14 04:25:15 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml [2010-03-28 11:04:34 | 000,002,476 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\BearShareWebSearch.xml [2010-04-14 04:25:15 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml [2010-04-14 04:25:15 | 000,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml [2010-04-14 04:25:15 | 000,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml [2009-09-24 00:49:47 | 000,002,399 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seekservice129.xml [2010-04-14 04:25:15 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml [2010-04-14 04:25:15 | 000,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2010-06-14 08:27:43 | 000,000,055 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 activate.adobe.com O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O2 - BHO: (FGCatchUrl) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll (www.flashget.com) O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.) O2 - BHO: (Free Lunch Design Toolbar) - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\tbFre0.dll (Conduit Ltd.) O2 - BHO: (IVONA Reader) - {8664889D-ED18-4713-918F-E2BB69D8452B} - C:\Program Files\IVONA\IVONA Reader\integr\IR_iexplorer2.dll File not found O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.) O2 - BHO: (OnRPG Toolbar) - {d22f6f66-2f47-4184-8625-fbfa4cbdb7ce} - C:\Program Files\OnRPG\tbOnR0.dll (Conduit Ltd.) O2 - BHO: (FlashGet GetFlash Class) - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll (www.flashget.com) O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10\_userdata\ggbho.2.dll (GG Network S.A.) O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\HyperCam Toolbar\tbcore3.dll File not found O3 - HKLM\..\Toolbar: (BigSeekPro Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\BigSeekPro Toolbar\tbcore3.dll () O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O3 - HKLM\..\Toolbar: (Free Lunch Design Toolbar) - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\tbFre0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (IVONA Reader) - {8664889D-ED18-4713-918F-E2BB69D8452B} - C:\Program Files\IVONA\IVONA Reader\integr\IR_iexplorer2.dll File not found O3 - HKLM\..\Toolbar: (OnRPG Toolbar) - {d22f6f66-2f47-4184-8625-fbfa4cbdb7ce} - C:\Program Files\OnRPG\tbOnR0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll File not found O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O3 - HKU\S-1-5-21-823518204-1303643608-682003330-1018\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O3 - HKU\S-1-5-21-823518204-1303643608-682003330-1018\..\Toolbar\WebBrowser: (Free Lunch Design Toolbar) - {57CC715D-37CA-44E4-9EC2-8C2CBDDB25EC} - C:\Program Files\Free_Lunch_Design\tbFre0.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-823518204-1303643608-682003330-1018\..\Toolbar\WebBrowser: (OnRPG Toolbar) - {D22F6F66-2F47-4184-8625-FBFA4CBDB7CE} - C:\Program Files\OnRPG\tbOnR0.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-823518204-1303643608-682003330-1018\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll (AOL LLC.) O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [ClocX] C:\Program Files\ClocX\ClocX.exe (BonSoft) O4 - HKLM..\Run: [DataMngr] C:\Program Files\BearShare Applications\MediaBar\DataMngr\DataMngrUI.exe (iMesh, Inc) O4 - HKLM..\Run: [Flashget] C:\Program Files\FlashGet\FlashGet.exe (FlashGet.com) O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google) O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.) O4 - HKU\S-1-5-21-823518204-1303643608-682003330-1018..\Run: [IROElauncher] C:\Program Files\IVONA\IVONA Reader\integr\OutlookExpress\IROElauncher.exe (Nektra S.A.) O4 - HKU\S-1-5-21-823518204-1303643608-682003330-1018..\Run: [IVONA ControlCenter] C:\Program Files\IVONA\IVONA ControlCenter\IVONA ControlCenter.exe (IVO Software Sp. z o.o.) O4 - HKU\S-1-5-21-823518204-1303643608-682003330-1018..\Run: [IVONA Reader] C:\Program Files\IVONA\IVONA Reader\IVONA Reader.exe File not found O4 - HKU\S-1-5-21-823518204-1303643608-682003330-1018..\Run: [Skype] C:\Program Files\Skype\Phone\Skype.exe File not found O4 - HKU\S-1-5-21-823518204-1303643608-682003330-1018..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.) O4 - HKU\S-1-5-21-823518204-1303643608-682003330-1018..\Run: [VideoBarApp] C:\Program Files\Gameztar Toolbar\2.1.1.5200\mvbapp.exe File not found O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Gadu-Gadu 10 (2).lnk = C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.) O4 - Startup: C:\Documents and Settings\Kasika\Menu Start\Programy\Autostart\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) O4 - Startup: C:\Documents and Settings\Kasika\Menu Start\Programy\Autostart\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVH.EXE (Microsoft Corporation) O4 - Startup: C:\Documents and Settings\Scarp\Menu Start\Programy\Autostart\Skrót do steam.lnk = C:\Program Files\Valve\Steam\steam.exe (Valve Corporation) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStrCmpLogical = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-823518204-1303643608-682003330-1018\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\JC_ALL.HTM () O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\JC_LINK.HTM () O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.) O8 - Extra context menu item: Funkcja Google Sidewiki - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.) O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe File not found O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (FlashGet.com) O9 - Extra 'Tools' menuitem : FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (FlashGet.com) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.) O15 - HKU\S-1-5-21-823518204-1303643608-682003330-1018\..Trusted Domains: localhost ([]http in Lokalny intranet) O15 - HKU\S-1-5-21-823518204-1303643608-682003330-1018\..Trusted Ranges: GD ([http] in Lokalny intranet) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.) O20 - Winlogon\Notify\WB: DllName - C:\Program Files\AlienGUIse\fastload.dll - C:\Program Files\AlienGUIse\fastload.dll (Stardock) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009-03-17 16:39:28 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O36 - AppCertDlls: debuexec - (C:\WINDOWS\system32\clipdump.dll) - C:\WINDOWS\System32\clipdump.dll File not found O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs: Ias - C:\WINDOWS\system32\ias [2010-01-08 18:22:58 | 000,000,000 | ---D | M] NetSvcs: Iprip - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation) NetSvcs: WmdmPmSp - File not found SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PEVSystemStart - Service SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: procexp90.Sys - Driver SafeBootMin: SCSI Class - Driver Group SafeBootMin: sdauxservice - C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools) SafeBootMin: sdcoreservice - C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools) SafeBootMin: sermouse.sys - Driver SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vga.sys - Driver SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PEVSystemStart - Service SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: procexp90.Sys - Driver SafeBootNet: rdpwd.sys - Driver SafeBootNet: SCSI Class - Driver Group SafeBootNet: sdauxservice - C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools) SafeBootNet: sdcoreservice - C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools) SafeBootNet: sermouse.sys - Driver SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: tdpipe.sys - Driver SafeBootNet: tdtcp.sys - Driver SafeBootNet: vga.sys - Driver SafeBootNet: {1a3e09be-1e45-494b-9174-d7385b45bbf5} - SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices [color=#E56717]========== Files/Folders - Created Within 60 Days ==========[/color] [2010-06-26 18:38:21 | 000,000,000 | ---D | C] -- C:\My Downloads [2010-06-26 18:35:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\1D1F4 [2010-06-26 18:35:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Moje dokumenty\My Received Files [2010-06-26 18:35:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Ustawienia lokalne\Dane aplikacji\BearShare [2010-06-26 18:35:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Moje dokumenty\BearShare [2010-06-26 17:44:14 | 000,000,000 | ---D | C] -- C:\Program Files\SpeedFan [2010-06-26 17:42:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Dane aplikacji\DivX [2010-06-26 17:26:28 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\scarp's\PrivacIE [2010-06-26 17:26:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Ustawienia lokalne\Dane aplikacji\Conduit [2010-06-26 17:26:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Ustawienia lokalne\Dane aplikacji\OnRPG [2010-06-26 17:26:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Dane aplikacji\Google [2010-06-26 17:26:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Ustawienia lokalne\Dane aplikacji\Free_Lunch_Design [2010-06-26 17:26:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Moje dokumenty\Downloads [2010-06-26 17:26:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Ustawienia lokalne\Dane aplikacji\Winamp Toolbar [2010-06-26 16:56:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Ustawienia lokalne\Dane aplikacji\cache [2010-06-26 16:55:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Moje dokumenty\Moje rozszerzenia Google Gadgets [2010-06-26 16:55:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Dane aplikacji\Gadu-Gadu 10 [2010-06-26 16:55:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Ustawienia lokalne\Dane aplikacji\Google [2010-06-26 16:54:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Dane aplikacji\Adobe [2010-06-26 16:54:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Dane aplikacji\Identities [2010-06-26 16:54:31 | 000,000,000 | R--D | C] -- C:\Documents and Settings\scarp's\Moje dokumenty\Moje obrazy [2010-06-26 16:54:31 | 000,000,000 | R--D | C] -- C:\Documents and Settings\scarp's\Moje dokumenty\Moja muzyka [2010-06-26 16:54:30 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\scarp's\IETldCache [2010-06-26 16:54:16 | 000,000,000 | --SD | C] -- C:\Documents and Settings\scarp's\Dane aplikacji\Microsoft [2010-06-26 16:54:16 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\scarp's\SendTo [2010-06-26 16:54:16 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\scarp's\Recent [2010-06-26 16:54:16 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\scarp's\Dane aplikacji [2010-06-26 16:54:16 | 000,000,000 | R--D | C] -- C:\Documents and Settings\scarp's\Ulubione [2010-06-26 16:54:16 | 000,000,000 | R--D | C] -- C:\Documents and Settings\scarp's\Moje dokumenty [2010-06-26 16:54:16 | 000,000,000 | R--D | C] -- C:\Documents and Settings\scarp's\Menu Start [2010-06-26 16:54:16 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\scarp's\Cookies [2010-06-26 16:54:16 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\scarp's\Szablony [2010-06-26 16:54:16 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\scarp's\PrintHood [2010-06-26 16:54:16 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\scarp's\NetHood [2010-06-26 16:54:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Pulpit [2010-06-26 16:54:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Dane aplikacji\Macromedia [2010-06-26 16:54:15 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\scarp's\Ustawienia lokalne [2010-06-26 16:54:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Ustawienia lokalne\Dane aplikacji\Microsoft Help [2010-06-26 16:54:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Ustawienia lokalne\Dane aplikacji\Microsoft [2010-06-26 00:37:28 | 000,000,000 | --SD | C] -- C:\ComboFix [2010-06-24 13:26:44 | 000,000,000 | ---D | C] -- C:\Program Files\NEXON [2010-06-24 09:13:14 | 000,000,000 | ---D | C] -- C:\Nexon [2010-06-24 03:28:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\1730D [2010-06-20 01:30:31 | 000,000,000 | ---D | C] -- C:\Program Files\BearShare Applications [2010-06-19 15:33:11 | 000,000,000 | ---D | C] -- C:\Program Files\ElfBot NG [2010-06-19 14:48:18 | 002,433,024 | ---- | C] (CipSoft GmbH) -- C:\Documents and Settings\All Users\Dane aplikacji\Tibia.bak [2010-06-11 12:01:29 | 000,000,000 | ---D | C] -- C:\Program Files\Lavalys [2010-06-10 14:03:46 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR [2010-06-10 14:00:36 | 000,000,000 | ---D | C] -- C:\Riot Games [2010-06-10 00:28:26 | 000,000,000 | ---D | C] -- C:\Program Files\Pando Networks [2010-06-09 09:51:29 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8 [2010-06-08 12:52:13 | 000,000,000 | ---D | C] -- C:\Program Files\Rockstar Games [2010-06-08 12:39:17 | 000,000,000 | ---D | C] -- C:\Program Files\PowerISO [2010-06-05 01:22:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\VirtualizedApplications [2010-06-03 09:51:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Virtualized Applications [2010-06-03 09:46:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dokumenty\SoftGrid Client [2010-06-03 09:45:25 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Application Virtualization Client [2010-06-03 09:45:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Microsoft [2010-05-26 23:56:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\scarp's\Pulpit\photoshop [2010-05-26 23:38:20 | 000,000,000 | ---D | C] -- C:\Program Files\FTP Commander [2010-05-26 01:09:37 | 000,000,000 | ---D | C] -- C:\gre [2010-05-26 01:06:26 | 000,000,000 | ---D | C] -- C:\Program Files\grepolis [2010-05-25 07:17:41 | 000,000,000 | ---D | C] -- C:\Nostale(PL) [2010-05-22 12:25:16 | 000,000,000 | -H-D | C] -- C:\$AVG [2010-05-22 05:06:59 | 000,000,000 | ---D | C] -- C:\Program Files\Gadu-Gadu 10 [2010-05-22 04:48:28 | 000,012,464 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll [2010-05-22 04:48:22 | 000,242,896 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys [2010-05-22 04:48:15 | 000,216,200 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys [2010-05-22 04:48:11 | 000,029,584 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys [2010-05-22 04:48:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Avg [2010-05-22 04:48:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\avg9 [2010-05-22 04:48:05 | 000,000,000 | ---D | C] -- C:\Program Files\AVG [2010-05-07 21:35:57 | 000,000,000 | ---D | C] -- C:\Program Files\Grudgemu [2010-05-01 11:02:37 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe Media Player [2010-05-01 10:46:40 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2010-04-30 16:55:42 | 000,000,000 | ---D | C] -- C:\Program Files\Tasker [2010-04-30 02:07:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Akamai [2010-04-30 01:41:14 | 000,090,624 | ---- | C] (VasanSoft) -- C:\Program Files\Photoshop.exe [2010-04-30 01:41:09 | 000,000,000 | ---D | C] -- C:\Program Files\Core [2010-04-28 01:46:16 | 000,000,000 | ---D | C] -- C:\Downloads [2010-04-28 01:45:20 | 000,000,000 | ---D | C] -- C:\Program Files\FlashGet [6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 60 Days ==========[/color] [2010-06-26 22:09:00 | 000,000,464 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{E5D8E31D-B0BC-41AC-A372-3F12B113B3BB}.job [2010-06-26 22:09:00 | 000,000,462 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{A4E3C0B5-8912-493B-BACA-003A74D9E454}.job [2010-06-26 22:09:00 | 000,000,462 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{48293FFF-3349-4CF8-8EE3-B4719E1D429C}.job [2010-06-26 22:03:10 | 000,001,993 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Bluetooth Remote Control - Installation Quick Guide.lnk [2010-06-26 22:03:10 | 000,000,896 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Bluetooth Remote Control.lnk [2010-06-26 21:58:57 | 000,272,164 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml [2010-06-26 21:58:11 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cb0c46f0a3950c.job [2010-06-26 21:56:00 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2010-06-26 19:16:14 | 001,572,864 | -H-- | M] () -- C:\Documents and Settings\scarp's\NTUSER.DAT [2010-06-26 19:16:14 | 000,000,188 | -HS- | M] () -- C:\Documents and Settings\scarp's\ntuser.ini [2010-06-26 19:05:22 | 002,640,892 | -H-- | M] () -- C:\Documents and Settings\scarp's\Ustawienia lokalne\Dane aplikacji\IconCache.db [2010-06-26 18:40:34 | 000,000,000 | ---- | M] () -- C:\testwma.raw [2010-06-26 18:39:06 | 061,420,629 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm [2010-06-26 17:56:15 | 000,062,346 | ---- | M] () -- C:\Documents and Settings\scarp's\Pulpit\bez tytułu.JPG [2010-06-26 17:44:15 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\scarp's\Pulpit\SpeedFan.lnk [2010-06-26 17:44:14 | 000,000,045 | ---- | M] () -- C:\WINDOWS\System32\initdebug.nfo [2010-06-26 17:42:47 | 000,003,584 | ---- | M] () -- C:\Documents and Settings\scarp's\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010-06-26 17:31:47 | 000,000,767 | ---- | M] () -- C:\Documents and Settings\scarp's\Pulpit\EVEREST Home Edition.lnk [2010-06-26 17:21:35 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2010-06-26 17:21:24 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010-06-25 18:00:00 | 000,000,474 | ---- | M] () -- C:\WINDOWS\tasks\Program Norton Security Scan for Scarp.job [2010-06-25 07:32:04 | 001,028,666 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2010-06-25 07:32:04 | 000,821,088 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2010-06-25 07:32:04 | 000,348,610 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2010-06-25 07:32:04 | 000,270,766 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2010-06-25 07:32:03 | 000,005,292 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2010-06-24 09:13:13 | 000,421,888 | ---- | M] (NEXON Inc.) -- C:\WINDOWS\NEXON_EU_DownloaderUpdater.exe [2010-06-24 08:26:35 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini [2010-06-22 22:26:41 | 000,000,017 | ---- | M] () -- C:\WINDOWS\System32\shortcut_ex.dat [2010-06-19 14:48:59 | 002,433,024 | ---- | M] (CipSoft GmbH) -- C:\Documents and Settings\All Users\Dane aplikacji\Tibia.bak [2010-06-19 14:48:59 | 000,266,402 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\Tibia_dat.bak [2010-06-19 14:48:42 | 000,114,688 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\Patch.bak [2010-06-14 12:50:27 | 000,000,848 | ---- | M] () -- C:\Documents and Settings\scarp's\Pulpit\Skrót do Photoshop.lnk [2010-06-14 08:27:43 | 000,000,055 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2010-06-13 16:02:09 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat [2010-06-11 10:36:08 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2010-06-11 06:55:41 | 002,349,648 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2010-06-11 01:57:56 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2010-06-10 14:32:59 | 000,001,632 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\p.lnk [2010-06-08 13:01:53 | 000,098,304 | ---- | M] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\CmdLineExt.dll [2010-06-05 12:17:55 | 000,002,020 | ---- | M] () -- C:\Documents and Settings\scarp's\Pulpit\WC3Banlist.lnk [2010-06-03 09:52:50 | 000,242,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys [2010-06-03 09:52:49 | 000,029,584 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys [2010-06-01 16:26:25 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Adobe Reader 9.lnk [2010-05-29 01:54:41 | 000,000,098 | ---- | M] () -- C:\1 [2010-05-29 01:54:41 | 000,000,068 | ---- | M] () -- C:\1.cmd [2010-05-26 00:47:38 | 000,000,654 | ---- | M] () -- C:\Documents and Settings\scarp's\Pulpit\Tasker.lnk [2010-05-26 00:00:00 | 000,007,292 | ---- | M] () -- C:\index.html [2010-05-22 12:35:47 | 000,000,762 | ---- | M] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Gadu-Gadu 10 (2).lnk [2010-05-22 05:24:57 | 000,000,065 | ---- | M] () -- C:\WINDOWS\System32\-1 [2010-05-22 05:22:41 | 000,081,376 | ---- | M] () -- C:\WINDOWS\System32\GDIPFONTCACHEV1.DAT [2010-05-22 05:09:51 | 000,000,762 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Gadu-Gadu 10.lnk [2010-05-22 04:54:02 | 000,000,722 | ---- | M] () -- C:\Documents and Settings\scarp's\Pulpit\Skrót do steam.lnk [2010-05-22 04:48:28 | 000,012,464 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll [2010-05-22 04:48:15 | 000,216,200 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys [2010-05-22 04:48:11 | 000,113,461 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\iavichjw.avm [2010-05-04 22:53:30 | 000,000,781 | ---- | M] () -- C:\WINDOWS\win.ini [2010-04-30 23:53:38 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini [2010-04-29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2010-04-29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2010-06-26 22:03:10 | 000,001,993 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Bluetooth Remote Control - Installation Quick Guide.lnk [2010-06-26 22:03:10 | 000,000,896 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Bluetooth Remote Control.lnk [2010-06-26 17:44:15 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\scarp's\Pulpit\SpeedFan.lnk [2010-06-26 17:44:13 | 000,000,045 | ---- | C] () -- C:\WINDOWS\System32\initdebug.nfo [2010-06-26 17:42:47 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\scarp's\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010-06-26 17:36:11 | 000,062,346 | ---- | C] () -- C:\Documents and Settings\scarp's\Pulpit\bez tytułu.JPG [2010-06-26 17:31:47 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\scarp's\Pulpit\EVEREST Home Edition.lnk [2010-06-26 16:54:18 | 000,000,188 | -HS- | C] () -- C:\Documents and Settings\scarp's\ntuser.ini [2010-06-26 16:54:15 | 001,572,864 | -H-- | C] () -- C:\Documents and Settings\scarp's\NTUSER.DAT [2010-06-26 16:54:15 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\scarp's\Ntuser.dat.LOG [2010-06-22 22:26:38 | 000,000,017 | ---- | C] () -- C:\WINDOWS\System32\shortcut_ex.dat [2010-06-20 11:20:38 | 000,000,000 | ---- | C] () -- C:\testwma.raw [2010-06-19 14:48:19 | 000,266,402 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\Tibia_dat.bak [2010-06-19 14:48:01 | 000,114,688 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\Patch.bak [2010-06-15 06:55:13 | 000,001,032 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cb0c46f0a3950c.job [2010-06-14 12:50:26 | 000,000,848 | ---- | C] () -- C:\Documents and Settings\scarp's\Pulpit\Skrót do Photoshop.lnk [2010-06-10 14:04:38 | 000,001,632 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\p.lnk [2010-06-05 12:17:55 | 000,002,020 | ---- | C] () -- C:\Documents and Settings\scarp's\Pulpit\WC3Banlist.lnk [2010-06-01 16:25:11 | 000,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Adobe Reader 9.lnk [2010-05-29 01:54:41 | 000,000,098 | ---- | C] () -- C:\1 [2010-05-29 01:54:41 | 000,000,068 | ---- | C] () -- C:\1.cmd [2010-05-26 23:45:38 | 000,007,292 | ---- | C] () -- C:\index.html [2010-05-26 01:22:10 | 000,464,896 | ---- | C] () -- C:\GrepolisBot.exe [2010-05-22 12:35:47 | 000,000,762 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Gadu-Gadu 10 (2).lnk [2010-05-22 05:25:02 | 001,281,024 | ---- | C] () -- C:\Documents and Settings\scarp's\Pulpit\VisualCustomKick.exe [2010-05-22 05:09:51 | 000,000,762 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Gadu-Gadu 10.lnk [2010-05-22 04:54:02 | 000,000,722 | ---- | C] () -- C:\Documents and Settings\scarp's\Pulpit\Skrót do steam.lnk [2010-05-22 04:48:11 | 061,420,629 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm [2010-05-22 04:48:11 | 000,113,461 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\iavichjw.avm [2010-04-30 01:41:09 | 000,000,166 | ---- | C] () -- C:\Program Files\VasanSoft.txt [2010-02-04 22:47:43 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll [2010-01-16 04:18:06 | 000,000,052 | ---- | C] () -- C:\WINDOWS\mafosav.INI [2010-01-16 04:17:07 | 000,000,024 | ---- | C] () -- C:\WINDOWS\clofghls.dll [2009-12-05 22:42:33 | 000,860,211 | --S- | C] () -- C:\WINDOWS\System32\XSIFtk-3.6.2.1.dll [2009-10-20 20:19:30 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll [2009-10-09 00:43:23 | 000,210,456 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll [2009-10-09 00:43:22 | 000,206,360 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll [2009-10-09 00:43:22 | 000,198,168 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll [2009-10-09 00:43:22 | 000,198,168 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll [2009-10-09 00:43:22 | 000,194,072 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll [2009-10-09 00:43:22 | 000,026,136 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll [2009-09-20 07:04:57 | 000,000,056 | ---- | C] () -- C:\WINDOWS\wb.ini [2009-08-29 10:19:24 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2009-08-29 02:44:31 | 000,000,196 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini [2009-04-17 18:22:54 | 000,000,533 | ---- | C] () -- C:\WINDOWS\netdet.ini [2009-03-30 21:15:42 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2009-03-17 16:44:15 | 000,005,524 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini [2009-03-17 16:44:11 | 000,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS [2009-02-26 20:46:50 | 000,042,320 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll [2002-03-17 02:00:00 | 000,007,420 | ---- | C] () -- C:\WINDOWS\UA000088.DLL [1996-04-03 21:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys [color=#E56717]========== LOP Check ==========[/color] [2009-11-17 23:23:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminek\Dane aplikacji\ChomikBox [2009-11-23 16:48:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminek\Dane aplikacji\Opera [2009-06-13 03:19:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminek\Dane aplikacji\Tibia [2009-10-20 07:37:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminek\Dane aplikacji\Ulead Systems [2009-12-11 09:29:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\aLiCjA\Dane aplikacji\ChomikBox [2010-04-11 11:11:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\aLiCjA\Dane aplikacji\Gadu-Gadu 10 [2010-04-11 11:12:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\aLiCjA\Dane aplikacji\ipla [2010-06-18 19:38:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\aLiCjA\Dane aplikacji\SoftGrid Client [2010-06-04 12:22:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\aLiCjA\Dane aplikacji\Tibia [2009-12-11 09:29:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\aLiCjA\Dane aplikacji\Ulead Systems [2009-09-27 15:46:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\1134B [2009-04-15 16:05:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\13167 [2009-04-28 15:27:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\142DE [2010-06-24 03:28:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\1730D [2010-06-26 18:35:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\1D1F4 [2009-04-23 20:27:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\2222 [2009-04-28 22:05:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\2936B [2010-05-22 04:48:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\avg9 [2009-10-23 13:28:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\F0 [2009-04-12 00:08:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\F33C [2010-04-02 12:41:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10 [2009-10-09 00:43:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\InterVideo [2010-05-26 09:55:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ipla [2010-05-24 20:42:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\OpenFM [2009-09-08 03:21:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\pI3demoLicense [2010-06-10 13:59:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PMB Files [2010-02-07 01:38:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Sony [2010-06-24 07:02:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP [2009-10-09 00:51:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Ulead Systems [2010-06-04 20:24:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Virtualized Applications [2010-06-05 01:22:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\VirtualizedApplications [2010-04-14 02:55:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Wru [2009-12-03 08:22:00 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\{E44AB4E0-C03E-42A0-A133-858C5B8AD6CB} [2009-09-19 22:51:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kasika\Dane aplikacji\ChomikBox [2010-06-18 08:39:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kasika\Dane aplikacji\Gadu-Gadu 10 [2010-06-03 11:31:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kasika\Dane aplikacji\GetRightToGo [2009-12-19 16:46:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kasika\Dane aplikacji\ipla [2010-03-27 11:47:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kasika\Dane aplikacji\Nowe Gadu-Gadu [2010-06-03 10:04:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kasika\Dane aplikacji\NVD [2009-10-09 20:27:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kasika\Dane aplikacji\OpenFM [2009-11-29 14:42:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kasika\Dane aplikacji\Opera [2010-06-26 14:24:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kasika\Dane aplikacji\SoftGrid Client [2009-03-28 14:55:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kasika\Dane aplikacji\Tibia [2010-06-03 09:51:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kasika\Dane aplikacji\TP [2009-10-09 09:02:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kasika\Dane aplikacji\Ulead Systems [2010-06-04 20:22:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kasika\Dane aplikacji\{20140062-0062-0409-0000-0000000FF1CE} [2009-09-27 01:14:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\ChomikBox [2010-03-11 00:59:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\Cream Software [2010-04-02 12:41:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\Gadu-Gadu 10 [2009-10-08 01:09:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\GetRightToGo [2010-02-28 13:17:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\GHISLER [2010-04-11 11:12:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\gtk-2.0 [2010-02-19 00:47:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\Inkscape [2010-04-14 18:25:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\ipla [2009-11-06 02:11:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\IVONA Player [2009-11-14 02:51:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\IVONA Reader [2009-10-11 19:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\Nowe Gadu-Gadu [2009-10-13 15:16:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\OpenFM [2009-09-26 15:14:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\Opera [2010-02-07 01:47:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\Publish Providers [2009-09-26 15:21:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\Soldat [2010-02-07 01:51:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\Sony [2009-10-12 14:04:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\StealthBot [2010-04-13 21:23:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\Tibia [2010-02-18 16:25:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\Toolbar4 [2009-10-09 10:11:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\Ulead Systems [2010-04-01 18:07:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\uTorrent [2009-10-06 01:14:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Scarp\Dane aplikacji\Xtranormal [2010-06-26 17:19:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\scarp's\Dane aplikacji\Gadu-Gadu 10 [2010-06-25 18:00:00 | 000,000,474 | ---- | M] () -- C:\WINDOWS\Tasks\Program Norton Security Scan for Scarp.job [2010-06-26 22:09:00 | 000,000,462 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{48293FFF-3349-4CF8-8EE3-B4719E1D429C}.job [2010-06-26 22:09:00 | 000,000,462 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{A4E3C0B5-8912-493B-BACA-003A74D9E454}.job [2010-06-26 22:09:00 | 000,000,464 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{E5D8E31D-B0BC-41AC-A372-3F12B113B3BB}.job [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Custom Scans ==========[/color] [color=#A23BEC]< %systemdrive%\*.* >[/color] [2010-05-29 01:54:41 | 000,000,098 | ---- | M] () -- C:\1 [2010-05-29 01:54:41 | 000,000,068 | ---- | M] () -- C:\1.cmd [2010-05-26 23:45:10 | 000,000,019 | ---- | M] () -- C:\Answer.txt [2009-03-17 16:39:28 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT [2009-03-17 16:46:18 | 000,000,223 | ---- | M] () -- C:\Boot.bak [2010-04-27 09:23:53 | 000,000,293 | RHS- | M] () -- C:\boot.ini [2008-04-15 14:00:00 | 000,004,952 | RHS- | M] () -- C:\Bootfont.bin [2004-08-03 23:00:14 | 000,262,400 | ---- | M] () -- C:\cmldr [2009-03-17 16:39:28 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS [2010-05-30 08:37:45 | 000,019,184 | ---- | M] () -- C:\debug.txt [2010-03-20 13:20:38 | 000,000,025 | ---- | M] () -- C:\freeware.txt [2010-04-26 22:18:36 | 000,464,896 | ---- | M] () -- C:\GrepolisBot.exe [2010-05-26 00:00:00 | 000,007,292 | ---- | M] () -- C:\index.html [2009-03-17 16:39:28 | 000,000,000 | RHS- | M] () -- C:\IO.SYS [2009-03-17 16:39:28 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS [2008-04-15 14:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM [2008-04-15 14:00:00 | 000,251,152 | RHS- | M] () -- C:\ntldr [2010-02-04 22:59:11 | 000,000,020 | -HS- | M] () -- C:\ntuser.ini [2010-06-26 17:21:20 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys [2010-04-28 02:35:25 | 000,003,912 | ---- | M] () -- C:\profile_43.txt [2010-05-30 02:47:10 | 000,000,023 | ---- | M] () -- C:\queue.txt [2010-05-30 02:48:25 | 000,000,113 | ---- | M] () -- C:\settings.txt [2010-06-26 18:40:34 | 000,000,000 | ---- | M] () -- C:\testwma.raw [2010-04-11 15:31:10 | 000,001,892 | ---- | M] () -- C:\translation.txt [color=#A23BEC]< MD5 for: AGP440.SYS >[/color] [2008-04-15 14:00:00 | 020,110,420 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:agp440.sys [color=#A23BEC]< MD5 for: ATAPI.SYS >[/color] [2008-04-15 14:00:00 | 020,110,420 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys [2008-04-15 14:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys [2008-04-15 14:00:00 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys [color=#A23BEC]< MD5 for: BEEP.SYS >[/color] [2008-04-15 14:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\ERDNT\cache\beep.sys [2008-04-15 14:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\system32\dllcache\beep.sys [2008-04-15 14:00:00 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\system32\drivers\beep.sys [color=#A23BEC]< MD5 for: CDROM.SYS >[/color] [2008-04-15 14:00:00 | 020,110,420 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys [2008-04-15 14:00:00 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys [2009-08-23 23:00:38 | 000,062,592 | ---- | M] (Microsoft Corporation) MD5=7B53584D94E9D8716B2DE91D5F1CB42D -- C:\WINDOWS\system32\dllcache\cdrom.sys [color=#A23BEC]< MD5 for: EVENTLOG.DLL >[/color] [2008-04-15 14:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\ERDNT\cache\eventlog.dll [2008-04-15 14:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\system32\dllcache\eventlog.dll [2008-04-15 14:00:00 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=35FCCFD093582FA9098762E6F84EE119 -- C:\WINDOWS\system32\eventlog.dll [color=#A23BEC]< MD5 for: NDIS.SYS >[/color] [2008-04-15 14:00:00 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ERDNT\cache\ndis.sys [2008-04-15 14:00:00 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\dllcache\ndis.sys [2008-04-15 14:00:00 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys [color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color] [2008-04-15 14:00:00 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\ERDNT\cache\winlogon.exe [2008-04-15 14:00:00 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\system32\dllcache\winlogon.exe [2008-04-15 14:00:00 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\system32\winlogon.exe [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 261 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:6BE50C2B @Alternate Data Stream - 226 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:4EE74317 @Alternate Data Stream - 174 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:E41EAF13 @Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:671329E4 @Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:DFC5A2B2 @Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:D1B5B4F1 < End of report > [/log] extras.txt [log]OTL Extras logfile created on: 2010-06-26 22:04:17 - Run 5 OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\scarp's\Moje dokumenty\Downloads Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 895,00 Mb Total Physical Memory | 371,00 Mb Available Physical Memory | 41,00% Memory free 3,00 Gb Paging File | 2,00 Gb Available in Paging File | 78,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 97,65 Gb Total Space | 25,09 Gb Free Space | 25,69% Space Free | Partition Type: NTFS Drive D: | 200,43 Gb Total Space | 199,31 Gb Free Space | 99,45% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: LION Current User Name: scarp's Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 60 Days Output = Standard [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .txt [@ = txtfile] -- C:\Program Files\JGsoft\EditPadLite\EditPadLite.exe File not found [HKEY_USERS\S-1-5-21-823518204-1303643608-682003330-1018\SOFTWARE\Classes\<extension>] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found [color=#E56717]========== Shell Spawning ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- "C:\Program Files\JGsoft\EditPadLite\EditPadLite.exe" "%1" File not found Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Directory [Winamp.Bookmark] -- "C:\Documents and Settings\Scarp\Pulpit\○\Programiki\Winamp\winamp.exe" /BOOKMARK "%1" File not found Directory [Winamp.Enqueue] -- "C:\Documents and Settings\Scarp\Pulpit\○\Programiki\Winamp\winamp.exe" /ADD "%1" File not found Directory [Winamp.Play] -- "C:\Documents and Settings\Scarp\Pulpit\○\Programiki\Winamp\winamp.exe" "%1" File not found Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusOverride" = 0 "FirewallOverride" = 0 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DoNotAllowExceptions" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "56136:TCP" = 56136:TCP:*:Enabled:Pando Media Booster "56136:UDP" = 56136:UDP:*:Enabled:Pando Media Booster [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724 "8461:TCP" = 8461:TCP:*:Enabled:GoD High Port "8462:TCP" = 8462:TCP:*:Enabled:GoD Low Port "139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002 "6112:UDP" = 6112:UDP:*:Enabled:Warcraft III "6112:TCP" = 6112:TCP:*:Enabled:6112 "50001:TCP" = 50001:TCP:*:Enabled:ArcaVir CommunicationPort (S) "50000:TCP" = 50000:TCP:*:Enabled:ArcaVir CommunicationPort (A) "4536:UDP" = 4536:UDP:*:Enabled:Windows Media Format SDK (ipla.exe) "4537:UDP" = 4537:UDP:*:Enabled:Windows Media Format SDK (ipla.exe) "4544:UDP" = 4544:UDP:*:Enabled:Windows Media Format SDK (ipla.exe) "57086:TCP" = 57086:TCP:*:Disabled:Pando Media Booster "57086:UDP" = 57086:UDP:*:Disabled:Pando Media Booster "5353:TCP" = 5353:TCP:*:Enabled:Adobe CSI CS4 "56136:TCP" = 56136:TCP:*:Enabled:Pando Media Booster "56136:UDP" = 56136:UDP:*:Enabled:Pando Media Booster "8378:TCP" = 8378:TCP:*:Enabled:League of Legends Launcher "8378:UDP" = 8378:UDP:*:Enabled:League of Legends Launcher "6909:TCP" = 6909:TCP:*:Enabled:League of Legends Launcher "6909:UDP" = 6909:UDP:*:Enabled:League of Legends Launcher "6920:TCP" = 6920:TCP:*:Enabled:League of Legends Launcher "6920:UDP" = 6920:UDP:*:Enabled:League of Legends Launcher [color=#E56717]========== Authorized Applications List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- () [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\Metin2_PL\metin2.bin" = C:\Program Files\Metin2_PL\metin2.bin:*:Enabled:metin2 -- () "C:\Program Files\Nowe Gadu-Gadu\gg.exe" = C:\Program Files\Nowe Gadu-Gadu\gg.exe:*:Enabled:Nowe Gadu-Gadu -- File not found "C:\Program Files\Valve\Steam\SteamApps\gajnaro\counter-strike\hl.exe" = C:\Program Files\Valve\Steam\SteamApps\gajnaro\counter-strike\hl.exe:*:Enabled:Half-Life Launcher -- (Valve) "C:\WINDOWS\system32\ftp.exe" = C:\WINDOWS\system32\ftp.exe:*:Enabled:Program do transferu plików -- (Microsoft Corporation) "C:\Program Files\Valve\hl.exe" = C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher -- (Valve) "C:\Program Files\Ares\Ares.exe" = C:\Program Files\Ares\Ares.exe:*:Enabled:Ares p2p for windows -- (Ares Development Group) "C:\Program Files\Metin2_PL\metin2client.bin" = C:\Program Files\Metin2_PL\metin2client.bin:*:Enabled:metin2client -- () "C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- (Microsoft Corporation) "C:\Documents and Settings\Scarp\Menu Start\Programy\Akcesoria\Połączenie lokalne.lnk" = C:\Documents and Settings\Scarp\Menu Start\Programy\Akcesoria\Połączenie lokalne.lnk:*:Enabled:Połączenie lokalne -- () "C:\Program Files\Metin2_PL\metin2.exe" = C:\Program Files\Metin2_PL\metin2.exe:*:Enabled:metin2 -- (Ymir Entertainment) "C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation) "C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.) "C:\Program Files\Valve\hlds.exe" = C:\Program Files\Valve\hlds.exe:*:Enabled:HLDS Launcher -- (Valve) "C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation) "C:\Program Files\WinPcap\rpcapd.exe" = C:\Program Files\WinPcap\rpcapd.exe:*:Enabled:Remote Packet Capture Daemon -- (CACE Technologies, Inc.) "C:\Program Files\Valve\Steam\steam.exe" = C:\Program Files\Valve\Steam\steam.exe:*:Enabled:Steam -- (Valve Corporation) "C:\Program Files\Gadu-Gadu 10\gg.exe" = C:\Program Files\Gadu-Gadu 10\gg.exe:*:Enabled:Gadu-Gadu 10 -- (GG Network S.A.) "C:\Program Files\FlashGet\flashget.exe" = C:\Program Files\FlashGet\flashget.exe:*:Enabled:Flashget -- (FlashGet.com) "C:\Program Files\Warcraft III\Warcraft III.exe" = C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III -- (Blizzard Entertainment) "C:\Program Files\Valve\Steam\SteamApps\scarps1\deathmatch classic\hl.exe" = C:\Program Files\Valve\Steam\SteamApps\scarps1\deathmatch classic\hl.exe:*:Enabled:Deathmatch Classic -- (Valve) "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 -- (Adobe Systems Incorporated) "C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.) "C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.) "C:\Program Files\Valve\Steam\SteamApps\scarps1\ricochet\hl.exe" = C:\Program Files\Valve\Steam\SteamApps\scarps1\ricochet\hl.exe:*:Enabled:Ricochet -- (Valve) "C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- () "C:\Riot Games\League of Legends\air\LolClient.exe" = C:\Riot Games\League of Legends\air\LolClient.exe:*:Enabled:League of Legends Lobby -- () "C:\Riot Games\League of Legends\game\League of Legends.exe" = C:\Riot Games\League of Legends\game\League of Legends.exe:*:Enabled:League of Legends Game Client -- () "C:\Program Files\BearShare Applications\BearShare\BearShare.exe" = C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Enabled:BearShare -- (MusicLab, LLC) "C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe" = [String data over 1000 bytes] "C:\Program Files\Valve\Steam\SteamApps\scarps1\day of defeat\hl.exe" = C:\Program Files\Valve\Steam\SteamApps\scarps1\day of defeat\hl.exe:*:Enabled:Day of Defeat -- (Valve) "C:\Program Files\Valve\Steam\SteamApps\scarps1\counter-strike\hl.exe" = C:\Program Files\Valve\Steam\SteamApps\scarps1\counter-strike\hl.exe:*:Enabled:Counter-Strike -- (Valve) [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4 "{01B8CDED-16D4-4106-935C-2A9AA236BF1A}" = Nexus Radio "{036FD544-AED6-3F33-856D-A2292D0CF471}" = Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - PLK "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam(TM) "{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3 "{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4 "{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4 "{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting "{098727E1-775A-4450-B573-3F441F1CA243}" = kuler "{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4 "{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup "{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4 "{11C86A01-3C83-4EE3-ADC1-8DE5C3037772}" = Enigma "{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter "{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4 "{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4 "{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin "{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate "{190297F8-14EC-4ECA-BFAC-72843DBFB382}" = Microsoft SharedView "{1AED4ABF-0852-4B3F-9F87-00CF88F25CE0}" = IconHandler 32 bit "{1C220811-048F-4D60-B42E-B86027C57372}" = LightScribe 1.4.119.1 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{20140000-006D-0409-0000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010 (Beta) "{20140062-0062-0409-0000-0000000FF1CE}" = Microsoft Office Home and Business 2010 (Beta) - English "{2085F05D-24C5-4E27-B7B4-A51DE890FFC9}" = Opera 10.00 "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2 "{255FC1CF-2620-4B64-BE02-79B9E609BB3D}" = Webzen Game Starter "{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 13 "{28F8F8F0-C278-454A-9507-46B344AAD188}" = Corel Painter 11 "{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3 "{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{353F1BEA-EF4B-421C-8838-7FA4A444A614}" = Xtranormal My Movie - English Voices - Samantha "{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4 "{363B9A0E-ACB5-4022-9237-1BF052014EB8}" = X-WORLD MuOnline Season2 "{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player "{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4 "{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4 "{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin "{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker "{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension "{4A5A9AAC-E7A7-4C11-826F-DF711E39BAEE}" = GHost++ "{4ac40384-37ba-421c-b14c-2ecbe4403817}" = Business Contact Manager z dodatkiem SP2 dla programu Outlook 2007 "{4DFF1415-4C29-44A8-BFD4-2BCE249C4991}" = SpPhones "{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies "{521AAD14-5030-44BB-8B0E-5CE65FCE57E0}" = InterVideo DeviceService "{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English) "{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3 "{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4 "{560F47F7-EB23-44B1-AAFC-667F1CD8FE5C}" = Sp5 "{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer "{5B51BB5F-4E7C-4275-A653-E98534E9C1D2}" = Corel Painter 11 - ICA "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{6179A7D2-A668-4F1D-BC9A-DCC6A10C7871}" = Adobe Color NA Extra Settings "{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4 "{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support "{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}" = Adobe Setup "{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4 "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK "{6C3959C6-943E-44B3-BAAD-570B04B134E5}" = SpCommon "{6D12B99F-EAAA-49D8-8E2F-74FA7459CCB2}" = Adobe Asset Services CS3 "{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}" = Adobe Color Common Settings "{7124AA83-2E57-4D7A-A0BF-1EC66ECF84B5}" = Xtranormal State - Showpack-Playgoz-Preview "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{78EFD06D-7583-42F1-9E77-671D8782EB70}" = Adobe Photoshop CS3 "{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec "{7C77393F-8237-3825-A88A-AFAF3C69C072}" = Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - PLK "{7EC69F77-5494-4E1F-8BC6-956DAA5A91F2}" = Corel Painter 11 - IPM "{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3 "{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4 "{840B4273-BCBB-4686-8BFF-41488A554B3C}" = Xtranormal My Movie - English Voices - Tom "{840BF2FE-033D-437C-89D1-AAA206BA13B6}" = Langauge "{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4 "{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar "{873038F3-5518-49C3-96B4-3823FECB8A28}" = Dark Stars "{881C5A81-AD1D-4646-9E6D-07CEED651937}" = GrudgeMU 2010 "{8867CEBD-E6C0-4C7A-83B3-9E45669A1045}" = Nero 7 Essentials "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player "{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3 "{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12 "{90120000-0010-0415-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Polish) 12 "{90120000-0015-0415-0000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2007 "{90120000-0015-0415-0000-0000000FF1CE}_PROR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}_PROR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0017-0000-0000-0000000FF1CE}" = Microsoft Office SharePoint Designer 2007 "{90120000-0017-0000-0000-0000000FF1CE}_SharePointDesigner_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{90120000-0017-0000-0000-0000000FF1CE}_SharePointDesigner_{E1C33B03-3FE9-45BF-91E4-0266F38618C6}" = Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2) "{90120000-0017-0415-0000-0000000FF1CE}" = Microsoft Office SharePoint Designer MUI (Polish) 2007 "{90120000-0017-0415-0000-0000000FF1CE}_SharePointDesigner_{A740A405-DDE4-461F-AC66-6C79E81C87BE}" = Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2) "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}_PROR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0019-0415-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2007 "{90120000-0019-0415-0000-0000000FF1CE}_PROR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001A-0415-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2007 "{90120000-001A-0415-0000-0000000FF1CE}_PROR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}_PROR_{79EB535E-76E4-4356-8146-A24EE55AB69D}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_SharePointDesigner_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}_SharePointDesigner_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-001F-0415-0000-0000000FF1CE}_SharePointDesigner_{E9EA2604-8AC9-47D2-8F4B-6BF60787A357}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}_SharePointDesigner_{D45F91DE-F0FC-4D5F-9A0C-FDE5B251AAC6}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00B4-0409-0000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2007 "{90120000-00B4-0409-0000-0000000FF1CE}_PRJPROR_{27A9D316-D332-433B-8EB1-1D93EE49F26D}" = Microsoft Office Project 2007 Service Pack 2 (SP2) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3 "{90A40415-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components "{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007 "{91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-0014-0000-0000-0000000FF1CE}_PROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{91120000-003B-0000-0000-0000000FF1CE}" = Microsoft Office Project Professional 2007 "{91120000-003B-0000-0000-0000000FF1CE}_PRJPROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{91120000-003B-0000-0000-0000000FF1CE}_PRJPROR_{9E73617F-2F38-4864-BD61-BB2DDFE43323}" = Microsoft Office Project 2007 Service Pack 2 (SP2) "{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends "{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4 "{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4 "{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster "{9ABFB92D-93DA-49EE-8ABF-F8195DE45CA9}" = Counter-Strike 1.6 "{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3 "{A0BA5AAC-CA61-4C71-9A29-FDF521296225}" = Xtranormal State - SoundPack-Starter Kit "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A56028FC-1F40-4369-9941-7AAAC6ACE924}" = LastChaosPoland "{A589DA26-51BD-475D-8C32-E19E34145842}" = Camtasia Studio 6 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Składniki łączności pakietu Microsoft Office Small Business "{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder "{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter "{AC76BA86-7AD7-1045-7B44-A93000000001}" = Adobe Reader 9.3.2 - Polish "{AD448510-B1E7-11DD-3D81-001422E6FFBA}_is1" = Mystic Galaxies mOX 0.2 "{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder "{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter "{B29AD377-CC12-490A-A480-1452337C618D}" = Connect "{B369483E-0728-405C-8F8C-3427B263B01F}" = Content "{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0 "{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}" = Adobe Setup "{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4 "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player "{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module "{BD087F50-46B2-43E4-BD73-5DB3DC20B47C}" = Adobe Color EU Recommended Settings "{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client "{BEAD39CD-901D-4267-8B8B-EAA83CB4B70D}" = Pivot Stickfigure Animator "{C05DEB30-501D-4106-958D-C5E147D2BF7E}" = StealthBot 2.7 "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver "{C3234E43-10BF-470E-BD2B-2E36EA29D11C}" = League of Legends "{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4 "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CBF4DADD-974D-49C8-BC83-C6F31554001E}" = Adobe Setup "{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw "{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client "{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1 "{D35CFCCA-2DD4-4E2A-A662-1D9DB00BEE4F}" = Xtranormal My Movie - English Voices - Daniel "{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas "{D7ADCF9A-1F30-4ECE-B40E-A155DEAD0FCD}" = Xtranormal State "{D7D753B4-678C-4E12-9D17-B277364B80C0}" = Bluetooth Remote Control "{DA507A38-4B2A-40C0-90AC-E30AAA0B757C}" = Vegas Movie Studio Platinum 9.0 "{DBA5E973-660D-4CBE-A469-F5C37FBF0CE4}" = DesktopEarth "{DF5A03CC-D5AA-43D8-B948-D9903F2AF94A}" = Counter-Strike(TM) "{E1BBBAC5-2857-4155-82A6-54492CE88620}" = Opera 9.64 "{E2E96CD8-3CDB-4971-8096-A80B1AA1F1FE}" = Xtranormal My Movie - English Voices - Serena "{E415C943-37E5-473F-8BAE-043C56734124}" = Sp5TTInt "{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4 "{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3 "{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F1CBC6F7-D82D-4DC5-B81C-9A14F418593A}_is1" = WC3Banlist "{F31E509D-3597-324E-83CF-0C160B2320F0}" = Microsoft .NET Framework 3.5 Language Pack - plk "{F57CEB84-3D22-4657-8EDA-F8CD5217B83E}" = Mu "{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4 "{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4 "{F99F9E24-EE2F-47FD-AEB0-FDB82859B5C9}" = VideoStudio "{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All "{FD4B33E1-24AE-4535-AA7B-162B30FB57CD}" = Sp5Intl "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player "Adobe_3e054d2218e7aa282c2369d939e58ff" = Adobe ExtendScript Toolkit 2 "Adobe_678cd98c8365a5647f9a2e539d120a8" = Adobe Photoshop CS3 "Adobe_6c8e2cb4fd241c55406016127a6ab2e" = Adobe Color Common Settings "Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4 "AhnLab Online Security" = AhnLab Online Security "Akamai" = Akamai NetSession Interface "Ares" = Ares 2.1.1 "AVG9Uninstall" = AVG Free 9.0 "BearShare" = BearShare "BigSeekPro Toolbar" = BigSeekPro Toolbar "Business Contact Manager" = Business Contact Manager z dodatkiem SP2 dla programu Outlook 2007 "ClocX" = ClocX (1.5b2) "com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player "DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters "EditPad Lite" = Just Great Software EditPad Lite PL 6.4.5 "ElfBot NG_is1" = ElfBot NG 4.5.6 "Europe MapleStory_is1" = Europe MapleStory "EuroPlus+ Angielski dla nastolatków poziom 1" = EuroPlus+ Angielski dla nastolatków poziom 1 "EVEREST Home Edition_is1" = EVEREST Home Edition v2.20 "EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v5.50 "FlashGet" = FlashGet 1.9.6.1073 "Fraps" = Fraps "Free_Lunch_Design Toolbar" = Free_Lunch_Design Toolbar "FreeCommander_is1" = FreeCommander 2009.02 "FTP Commander" = FTP Commander "Gadu-Gadu 10" = Gadu-Gadu 10 "GAMEFORGE Nostale(PL)_is1" = Nostale Online PL (Remove) "Google Chrome" = Google Chrome "Google Desktop" = Google Desktop "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "Icy Tower v1.3.1_is1" = Icy Tower v1.3.1 "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "ie8" = Windows Internet Explorer 8 "InstallShield_{F99F9E24-EE2F-47FD-AEB0-FDB82859B5C9}" = Ulead VideoStudio 11 "ipla" = ipla 2.1.4 "IVONA ControlCenter" = IVONA ControlCenter "LameACM" = LameACM "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 Language Pack - plk" = Pakiet językowy programu Microsoft .NET Framework 3.5 — PLK "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox (3.6.4)" = Mozilla Firefox (3.6.4) "MP3MyMP3_is1" = MP3MyMP3 3.0 "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "NaturalMotion endorphin_is1" = NaturalMotion endorphin 2.7.1 "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "NSS" = Norton Security Scan "NVIDIA Display Control Panel" = NVIDIA Display Control Panel "NVIDIA Drivers" = NVIDIA Drivers "NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager "Office14.Click2Run" = Microsoft Office Click-to-Run 2010 (Beta) "OnRPG Toolbar" = OnRPG Toolbar "Picasa 3" = Picasa 3 "PowerISO" = PowerISO "PRJPROR" = Microsoft Office Project Professional 2007 Trial "PROR" = Produkt Microsoft Office Professional 2007 w wersji próbnej "Registry Mechanic_is1" = Registry Mechanic 8.0 "RocketDock_is1" = RocketDock 1.3.5 "SharePointDesigner" = Microsoft Office SharePoint Designer 2007 "Shock Desktop v1.53" = Shock Desktop v1.53 "SpeedFan" = SpeedFan (remove only) "Spyware Doctor" = Spyware Doctor 6.0 "Steam App 130" = Half-Life: Blue Shift "Steam App 5" = Dedicated Server "Super DVD Creator_is1" = Super DVD Creator 9.8 Trial Version "SWiSH Max3" = SWiSH Max3 "SystemRequirementsLab" = System Requirements Lab "Tasker_is1" = Tasker version 3.13 "Tibia_is1" = Tibia "TibiaBot NG_is1" = TibiaBot NG 4.9.5 "TMIPC" = Tibia MULTI-ip changer "Totalcmd" = Total Commander (Remove or Repair) "Winamp Toolbar" = Winamp Toolbar "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "WinGimp-2.0_is1" = GIMP 2.6.8 "WinPcapInst" = WinPcap 4.1.1 "WinRAR archiver" = Archiwizator WinRAR "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0 "YDP Flash Speech Recognition Support" = YDP Flash Speech Recognition Support 1.0 [color=#E56717]========== Last 10 Event Log Errors ==========[/color] [ Application Events ] Error - 2010-06-26 04:50:49 | Computer Name = LION | Source = Application Virtualization Client | ID = 6096 Description = [pl-PL] {tid=1788:usr=Kasika} An error occurred while opening the virtual registry (section: false), rc: 07B01F0C-0000004A Error - 2010-06-26 04:50:49 | Computer Name = LION | Source = Application Virtualization Client | ID = 6034 Description = {tid=1620:usr=Kasika} Błąd ( 32 ) podczas przenoszenia pliku ustawień przemieszczonych ( Q:\140062.ENU\SoftGridUserSettings\settings.cp.temp ) Error - 2010-06-26 04:50:50 | Computer Name = LION | Source = Application Virtualization Client | ID = 6096 Description = [pl-PL] {tid=1788} An error occurred while opening the virtual registry (section: false), rc: 07B01F0C-0000004A Error - 2010-06-26 08:03:47 | Computer Name = LION | Source = Application Virtualization Client | ID = 6096 Description = [pl-PL] {tid=1554:usr=Kasika} An error occurred while opening the virtual registry (section: false), rc: 07B01F0C-0000004A Error - 2010-06-26 08:03:50 | Computer Name = LION | Source = Application Virtualization Client | ID = 6096 Description = [pl-PL] {tid=1554} An error occurred while opening the virtual registry (section: false), rc: 07B01F0C-0000004A Error - 2010-06-26 08:04:25 | Computer Name = LION | Source = Application Virtualization Client | ID = 6032 Description = {tid=1668:usr=Kasika} Znaleziono plik ustawień tymczasowych. Ten plik ( C:\Documents and Settings\Kasika\Ustawienia lokalne\Dane aplikacji\Q$_140062.ENU_SoftGridUserSettings_settings.cp.temp ) może być uszkodzony i zostanie usunięty Error - 2010-06-26 08:04:25 | Computer Name = LION | Source = Application Virtualization Client | ID = 6096 Description = [pl-PL] {tid=1668:usr=Kasika} An error occurred while opening the virtual registry (section: false), rc: 07B01F0C-0000004A Error - 2010-06-26 08:04:25 | Computer Name = LION | Source = Application Virtualization Client | ID = 6096 Description = [pl-PL] {tid=1668} An error occurred while opening the virtual registry (section: false), rc: 07B01F0C-0000004A Error - 2010-06-26 11:10:17 | Computer Name = LION | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca hl.exe, wersja 1.1.1.1, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error - 2010-06-26 11:17:52 | Computer Name = LION | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca hl.exe, wersja 1.1.1.1, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. [ Application Events ] Error - 2010-06-26 04:50:49 | Computer Name = LION | Source = Application Virtualization Client | ID = 6096 Description = [pl-PL] {tid=1788:usr=Kasika} An error occurred while opening the virtual registry (section: false), rc: 07B01F0C-0000004A Error - 2010-06-26 04:50:49 | Computer Name = LION | Source = Application Virtualization Client | ID = 6034 Description = {tid=1620:usr=Kasika} Błąd ( 32 ) podczas przenoszenia pliku ustawień przemieszczonych ( Q:\140062.ENU\SoftGridUserSettings\settings.cp.temp ) Error - 2010-06-26 04:50:50 | Computer Name = LION | Source = Application Virtualization Client | ID = 6096 Description = [pl-PL] {tid=1788} An error occurred while opening the virtual registry (section: false), rc: 07B01F0C-0000004A Error - 2010-06-26 08:03:47 | Computer Name = LION | Source = Application Virtualization Client | ID = 6096 Description = [pl-PL] {tid=1554:usr=Kasika} An error occurred while opening the virtual registry (section: false), rc: 07B01F0C-0000004A Error - 2010-06-26 08:03:50 | Computer Name = LION | Source = Application Virtualization Client | ID = 6096 Description = [pl-PL] {tid=1554} An error occurred while opening the virtual registry (section: false), rc: 07B01F0C-0000004A Error - 2010-06-26 08:04:25 | Computer Name = LION | Source = Application Virtualization Client | ID = 6032 Description = {tid=1668:usr=Kasika} Znaleziono plik ustawień tymczasowych. Ten plik ( C:\Documents and Settings\Kasika\Ustawienia lokalne\Dane aplikacji\Q$_140062.ENU_SoftGridUserSettings_settings.cp.temp ) może być uszkodzony i zostanie usunięty Error - 2010-06-26 08:04:25 | Computer Name = LION | Source = Application Virtualization Client | ID = 6096 Description = [pl-PL] {tid=1668:usr=Kasika} An error occurred while opening the virtual registry (section: false), rc: 07B01F0C-0000004A Error - 2010-06-26 08:04:25 | Computer Name = LION | Source = Application Virtualization Client | ID = 6096 Description = [pl-PL] {tid=1668} An error occurred while opening the virtual registry (section: false), rc: 07B01F0C-0000004A Error - 2010-06-26 11:10:17 | Computer Name = LION | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca hl.exe, wersja 1.1.1.1, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. Error - 2010-06-26 11:17:52 | Computer Name = LION | Source = Application Hang | ID = 1002 Description = Aplikacja zawieszająca hl.exe, wersja 1.1.1.1, moduł zawieszenia hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000. [ OSession Events ] Error - 2010-01-07 15:08:49 | Computer Name = LION | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 20 seconds with 0 seconds of active time. This session ended with a crash. Error - 2010-03-28 12:22:58 | Computer Name = LION | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 409 seconds with 360 seconds of active time. This session ended with a crash. [ System Events ] Error - 2010-06-26 03:25:26 | Computer Name = LION | Source = Service Control Manager | ID = 7034 Description = Usługa SQL Server VSS Writer niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2010-06-26 03:34:39 | Computer Name = LION | Source = Disk | ID = 262155 Description = Sterownik wykrył błąd kontrolera na \Device\Harddisk0\D. Error - 2010-06-26 09:04:35 | Computer Name = LION | Source = Service Control Manager | ID = 7022 Description = Usługa SQL Server VSS Writer zawiesiła się podczas uruchamiania. Error - 2010-06-26 09:04:35 | Computer Name = LION | Source = Service Control Manager | ID = 7026 Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: FO_PAnt Error - 2010-06-26 09:06:21 | Computer Name = LION | Source = Service Control Manager | ID = 7034 Description = Usługa SQL Server VSS Writer niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. Error - 2010-06-26 11:22:57 | Computer Name = LION | Source = Service Control Manager | ID = 7009 Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się z usługą Client Virtualization Handler. Error - 2010-06-26 11:22:57 | Computer Name = LION | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Client Virtualization Handler z powodu następującego błędu: %%1053 Error - 2010-06-26 11:24:41 | Computer Name = LION | Source = Service Control Manager | ID = 7022 Description = Usługa SQL Server VSS Writer zawiesiła się podczas uruchamiania. Error - 2010-06-26 11:24:41 | Computer Name = LION | Source = Service Control Manager | ID = 7026 Description = Nie można załadować następujących sterowników startu rozruchowego lub systemowego: FO_PAnt Error - 2010-06-26 11:24:41 | Computer Name = LION | Source = Service Control Manager | ID = 7034 Description = Usługa SQL Server VSS Writer niespodziewanie zakończyła pracę. Wystąpiło to razy: 1. < End of report > [/log]
raazor90 komentarz 26 czerwca 2010 komentarz 26 czerwca 2010 Zanim przeniosę Twój temat do działu Bezpieczeństwo, wykonaj jeszcze to: http://www.forumpc.pl/index.php?showtopic=16074
scarp komentarz 27 czerwca 2010 Autor komentarz 27 czerwca 2010 z tym że ja mam kilka tych liczb tam dam ssa i all [u][i][b]Mini030210-01[/b][/i][/u] [log] Microsoft (R) Windows Debugger Version 6.12.0002.633 X86 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\WINDOWS\Minidump\Mini030210-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available Symbol search path is: *** Invalid *** **************************************************************************** * Symbol loading may be unreliable without a symbol search path. * * Use .symfix to have the debugger choose a symbol path. * * After setting your symbol path, use .reload to refresh symbol locations. * **************************************************************************** Executable search path is: ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Personal Machine Name: Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720 Debug session time: Tue Mar 2 12:52:52.078 2010 (UTC + 2:00) System Uptime: 0 days 3:38:53.773 ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Loading Kernel Symbols ............................................................... ................................................................ Loading User Symbols Loading unloaded module list .............. Unable to load image win32k.sys, Win32 error 0n2 *** WARNING: Unable to verify timestamp for win32k.sys *** ERROR: Module load completed but symbols could not be loaded for win32k.sys ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 1000008E, {c0000005, bf953492, b26a8c00, 0} ***** Kernel symbols are WRONG. Please fix symbols to do analysis. ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* Probably caused by : win32k.sys ( win32k+153492 ) Followup: MachineOwner --------- [/log] [u][i][b]Mini030310-01.dmp[/b][/i][/u] [log]********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Personal Machine Name: Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720 Debug session time: Wed Mar 3 15:58:16.140 2010 (UTC + 2:00) System Uptime: 0 days 6:28:52.849 ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Loading Kernel Symbols ............................................................... ................................................................ Loading User Symbols Loading unloaded module list ........... Unable to load image win32k.sys, Win32 error 0n2 *** WARNING: Unable to verify timestamp for win32k.sys *** ERROR: Module load completed but symbols could not be loaded for win32k.sys ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 10000050, {e64cf01c, 0, bf8374d3, 1} ***** Kernel symbols are WRONG. Please fix symbols to do analysis. ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* Probably caused by : win32k.sys ( win32k+374d3 ) Followup: MachineOwner --------- [/log] [u][i][b]Mini030610-01[/b][/i][/u] [log] Microsoft (R) Windows Debugger Version 6.12.0002.633 X86 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\WINDOWS\Minidump\Mini030610-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available Symbol search path is: *** Invalid *** **************************************************************************** * Symbol loading may be unreliable without a symbol search path. * * Use .symfix to have the debugger choose a symbol path. * * After setting your symbol path, use .reload to refresh symbol locations. * **************************************************************************** Executable search path is: ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Personal Machine Name: Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720 Debug session time: Sat Mar 6 01:46:47.468 2010 (UTC + 2:00) System Uptime: 0 days 16:22:44.162 ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Loading Kernel Symbols ............................................................... ................................................................ Loading User Symbols Loading unloaded module list .............. Unable to load image win32k.sys, Win32 error 0n2 *** WARNING: Unable to verify timestamp for win32k.sys *** ERROR: Module load completed but symbols could not be loaded for win32k.sys ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 1000008E, {c0000005, bf953492, ad299c00, 0} ***** Kernel symbols are WRONG. Please fix symbols to do analysis. ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* Probably caused by : win32k.sys ( win32k+153492 ) Followup: MachineOwner --------- [/log] [u][i][b]Mini031210-01[/b][/i][/u] [log] Microsoft (R) Windows Debugger Version 6.12.0002.633 X86 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\WINDOWS\Minidump\Mini031210-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available Symbol search path is: *** Invalid *** **************************************************************************** * Symbol loading may be unreliable without a symbol search path. * * Use .symfix to have the debugger choose a symbol path. * * After setting your symbol path, use .reload to refresh symbol locations. * **************************************************************************** Executable search path is: ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Personal Machine Name: Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720 Debug session time: Fri Mar 12 19:58:27.671 2010 (UTC + 2:00) System Uptime: 0 days 6:20:21.370 ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Loading Kernel Symbols ............................................................... ................................................................ Loading User Symbols Loading unloaded module list .................. Unable to load image RtkHDAud.sys, Win32 error 0n2 *** WARNING: Unable to verify timestamp for RtkHDAud.sys *** ERROR: Module load completed but symbols could not be loaded for RtkHDAud.sys ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 1000008E, {c0000005, b459f5ab, b1cfb70c, 0} ***** Kernel symbols are WRONG. Please fix symbols to do analysis. *** WARNING: Unable to verify timestamp for portcls.sys *** ERROR: Module load completed but symbols could not be loaded for portcls.sys *** WARNING: Unable to verify timestamp for ks.sys *** ERROR: Module load completed but symbols could not be loaded for ks.sys *** WARNING: Unable to verify timestamp for sysaudio.sys *** ERROR: Module load completed but symbols could not be loaded for sysaudio.sys ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* Probably caused by : RtkHDAud.sys ( RtkHDAud+705ab ) Followup: MachineOwner --------- [/log] [u][i][b]Mini031610-01.dmp[/b][/i][/u] [log] Microsoft (R) Windows Debugger Version 6.12.0002.633 X86 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\WINDOWS\Minidump\Mini031610-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available Symbol search path is: *** Invalid *** **************************************************************************** * Symbol loading may be unreliable without a symbol search path. * * Use .symfix to have the debugger choose a symbol path. * * After setting your symbol path, use .reload to refresh symbol locations. * **************************************************************************** Executable search path is: ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Personal Machine Name: Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720 Debug session time: Tue Mar 16 18:35:36.125 2010 (UTC + 2:00) System Uptime: 0 days 5:15:45.822 ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Loading Kernel Symbols ............................................................... ................................................................ . Loading User Symbols Loading unloaded module list ......... Unable to load image win32k.sys, Win32 error 0n2 *** WARNING: Unable to verify timestamp for win32k.sys *** ERROR: Module load completed but symbols could not be loaded for win32k.sys ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 1000008E, {c0000005, bf953492, b1d24c00, 0} ***** Kernel symbols are WRONG. Please fix symbols to do analysis. ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* Probably caused by : win32k.sys ( win32k+153492 ) Followup: MachineOwner --------- [/log] [u][i][b]Mini032710-01[/b][/i][/u] [log] Microsoft (R) Windows Debugger Version 6.12.0002.633 X86 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\WINDOWS\Minidump\Mini032710-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available Symbol search path is: *** Invalid *** **************************************************************************** * Symbol loading may be unreliable without a symbol search path. * * Use .symfix to have the debugger choose a symbol path. * * After setting your symbol path, use .reload to refresh symbol locations. * **************************************************************************** Executable search path is: ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Personal Machine Name: Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720 Debug session time: Sat Mar 27 17:18:07.890 2010 (UTC + 2:00) System Uptime: 0 days 3:23:35.585 ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Loading Kernel Symbols ............................................................... ................................................................ Loading User Symbols Loading unloaded module list ............ Unable to load image win32k.sys, Win32 error 0n2 *** WARNING: Unable to verify timestamp for win32k.sys *** ERROR: Module load completed but symbols could not be loaded for win32k.sys ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 10000050, {e46df01c, 0, bf8374d3, 1} ***** Kernel symbols are WRONG. Please fix symbols to do analysis. ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* Probably caused by : win32k.sys ( win32k+374d3 ) Followup: MachineOwner --------- [/log] [u][i][b]Mini032710-02[/b][/i][/u] [log] Microsoft (R) Windows Debugger Version 6.12.0002.633 X86 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\WINDOWS\Minidump\Mini032710-02.dmp] Mini Kernel Dump File: Only registers and stack trace are available Symbol search path is: *** Invalid *** **************************************************************************** * Symbol loading may be unreliable without a symbol search path. * * Use .symfix to have the debugger choose a symbol path. * * After setting your symbol path, use .reload to refresh symbol locations. * **************************************************************************** Executable search path is: ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Personal Machine Name: Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720 Debug session time: Sat Mar 27 23:11:13.265 2010 (UTC + 2:00) System Uptime: 0 days 5:52:21.963 ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Loading Kernel Symbols ............................................................... ................................................................ . Loading User Symbols Loading unloaded module list ........... Unable to load image win32k.sys, Win32 error 0n2 *** WARNING: Unable to verify timestamp for win32k.sys *** ERROR: Module load completed but symbols could not be loaded for win32k.sys ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 1000008E, {c0000005, bf953492, af776c00, 0} ***** Kernel symbols are WRONG. Please fix symbols to do analysis. ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* Probably caused by : win32k.sys ( win32k+153492 ) Followup: MachineOwner --------- [/log] [u][i][b]Mini033010-01[/b][/i][/u] [log] Microsoft (R) Windows Debugger Version 6.12.0002.633 X86 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\WINDOWS\Minidump\Mini033010-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available Symbol search path is: *** Invalid *** **************************************************************************** * Symbol loading may be unreliable without a symbol search path. * * Use .symfix to have the debugger choose a symbol path. * * After setting your symbol path, use .reload to refresh symbol locations. * **************************************************************************** Executable search path is: ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Personal Machine Name: Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720 Debug session time: Tue Mar 30 08:07:50.000 2010 (UTC + 2:00) System Uptime: 0 days 0:56:41.700 ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Loading Kernel Symbols ............................................................... ............................................................... Loading User Symbols Loading unloaded module list ........... Unable to load image win32k.sys, Win32 error 0n2 *** WARNING: Unable to verify timestamp for win32k.sys *** ERROR: Module load completed but symbols could not be loaded for win32k.sys ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 1000008E, {c0000005, bf8124e9, b1cc833c, 0} ***** Kernel symbols are WRONG. Please fix symbols to do analysis. ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* Probably caused by : win32k.sys ( win32k+124e9 ) Followup: MachineOwner --------- [/log] [u][i][b]Mini040610-01.dmp[/b][/i][/u] [log] Microsoft (R) Windows Debugger Version 6.12.0002.633 X86 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\WINDOWS\Minidump\Mini040610-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available Symbol search path is: *** Invalid *** **************************************************************************** * Symbol loading may be unreliable without a symbol search path. * * Use .symfix to have the debugger choose a symbol path. * * After setting your symbol path, use .reload to refresh symbol locations. * **************************************************************************** Executable search path is: ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Personal Machine Name: Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720 Debug session time: Tue Apr 6 13:24:56.625 2010 (UTC + 2:00) System Uptime: 0 days 1:43:02.338 ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Loading Kernel Symbols ............................................................... ................................................................ .... Loading User Symbols Loading unloaded module list ................. ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck F4, {3, 89389500, 89389674, 805d297e} ***** Kernel symbols are WRONG. Please fix symbols to do analysis. ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_WMI_LOGGER_CONTEXT *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_WMI_BUFFER_HEADER *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_WMI_BUFFER_HEADER *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_WMI_BUFFER_HEADER *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_WMI_BUFFER_HEADER *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_WMI_LOGGER_CONTEXT *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_WMI_LOGGER_CONTEXT *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_WMI_LOGGER_CONTEXT *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_WMI_LOGGER_CONTEXT *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_WMI_LOGGER_CONTEXT *** *** *** ************************************************************************* unable to get nt!KiCurrentEtwBufferOffset unable to get nt!KiCurrentEtwBufferBase *** WARNING: Unable to verify timestamp for PCTCore.sys *** ERROR: Module load completed but symbols could not be loaded for PCTCore.sys ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* Probably caused by : winlogon.exe Followup: MachineOwner --------- [/log] [u][i][b]Mini042610-01[/b][/i][/u] [log] Microsoft (R) Windows Debugger Version 6.12.0002.633 X86 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\WINDOWS\Minidump\Mini042610-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available Symbol search path is: *** Invalid *** **************************************************************************** * Symbol loading may be unreliable without a symbol search path. * * Use .symfix to have the debugger choose a symbol path. * * After setting your symbol path, use .reload to refresh symbol locations. * **************************************************************************** Executable search path is: ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Personal Machine Name: Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720 Debug session time: Mon Apr 26 19:05:17.218 2010 (UTC + 2:00) System Uptime: 0 days 4:31:21.918 ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Loading Kernel Symbols ............................................................... ................................................................ . Loading User Symbols Loading unloaded module list ............. *** WARNING: Unable to verify timestamp for nv4_disp.dll *** ERROR: Module load completed but symbols could not be loaded for nv4_disp.dll ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 100000EA, {839b9920, 83e44008, f78d6cbc, 1} ***** Kernel symbols are WRONG. Please fix symbols to do analysis. ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* ERROR - could not read driver name for bugcheck parameter 3 ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* Probably caused by : nv4_disp.dll ( nv4_disp+5c4f5 ) Followup: MachineOwner --------- [/log] [i][u][b]Mini052810-01[/b][/u][/i] [log] Microsoft (R) Windows Debugger Version 6.12.0002.633 X86 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\WINDOWS\Minidump\Mini052810-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available Symbol search path is: *** Invalid *** **************************************************************************** * Symbol loading may be unreliable without a symbol search path. * * Use .symfix to have the debugger choose a symbol path. * * After setting your symbol path, use .reload to refresh symbol locations. * **************************************************************************** Executable search path is: ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Personal Machine Name: Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720 Debug session time: Fri May 28 14:52:08.781 2010 (UTC + 2:00) System Uptime: 0 days 0:24:13.472 ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Loading Kernel Symbols ............................................................... ............................................................... Loading User Symbols Loading unloaded module list ........ *** WARNING: Unable to verify timestamp for nv4_disp.dll *** ERROR: Module load completed but symbols could not be loaded for nv4_disp.dll ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 100000EA, {83b59ba8, 83dae148, f7902cbc, 1} ***** Kernel symbols are WRONG. Please fix symbols to do analysis. ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* ERROR - could not read driver name for bugcheck parameter 3 ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* Probably caused by : nv4_disp.dll ( nv4_disp+5bb65 ) Followup: MachineOwner --------- [/log] [u][i][b]Mini061510-01[/b][/i][/u] [log] Microsoft (R) Windows Debugger Version 6.12.0002.633 X86 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\WINDOWS\Minidump\Mini061510-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available Symbol search path is: *** Invalid *** **************************************************************************** * Symbol loading may be unreliable without a symbol search path. * * Use .symfix to have the debugger choose a symbol path. * * After setting your symbol path, use .reload to refresh symbol locations. * **************************************************************************** Executable search path is: ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Personal Machine Name: Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720 Debug session time: Tue Jun 15 16:16:18.171 2010 (UTC + 2:00) System Uptime: 0 days 3:03:29.864 ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Loading Kernel Symbols ............................................................... ................................................................ .... Loading User Symbols Loading unloaded module list .......... *** WARNING: Unable to verify timestamp for nv4_disp.dll *** ERROR: Module load completed but symbols could not be loaded for nv4_disp.dll ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 100000EA, {8389b020, 83de9008, f78dacbc, 1} ***** Kernel symbols are WRONG. Please fix symbols to do analysis. ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* ERROR - could not read driver name for bugcheck parameter 3 ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* Probably caused by : nv4_disp.dll ( nv4_disp+5bb65 ) Followup: MachineOwner --------- [/log] [u][i][b]Mini061710-01.dmp[/b][/i][/u] [log]***** Kernel symbols are WRONG. Please fix symbols to do analysis. ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* ERROR - could not read driver name for bugcheck parameter 3 ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* Probably caused by : nv4_disp.dll ( nv4_disp+6bdd7 ) Followup: MachineOwner --------- [/log] [u][i][b]062010-01.dmp[/b][/i][/u] [log] Microsoft (R) Windows Debugger Version 6.12.0002.633 X86 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\WINDOWS\Minidump\Mini062010-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available Symbol search path is: *** Invalid *** **************************************************************************** * Symbol loading may be unreliable without a symbol search path. * * Use .symfix to have the debugger choose a symbol path. * * After setting your symbol path, use .reload to refresh symbol locations. * **************************************************************************** Executable search path is: ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Personal Machine Name: Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720 Debug session time: Sun Jun 20 14:31:35.718 2010 (UTC + 2:00) System Uptime: 0 days 3:24:07.416 ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* Unable to load image ntoskrnl.exe, Win32 error 0n2 *** WARNING: Unable to verify timestamp for ntoskrnl.exe *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe Loading Kernel Symbols ............................................................... ................................................................ .... Loading User Symbols Loading unloaded module list ............. *** WARNING: Unable to verify timestamp for hal.dll *** ERROR: Module load completed but symbols could not be loaded for hal.dll Unable to load image win32k.sys, Win32 error 0n2 *** WARNING: Unable to verify timestamp for win32k.sys *** ERROR: Module load completed but symbols could not be loaded for win32k.sys ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 100000EA, {839f5da8, 84112008, f78c6cbc, 1} ***** Kernel symbols are WRONG. Please fix symbols to do analysis. *** WARNING: Unable to verify timestamp for dxg.sys *** ERROR: Module load completed but symbols could not be loaded for dxg.sys ********************************************************************* * Symbols can not be loaded because symbol path is not initialized. * * * * The Symbol Path can be set by: * * using the _NT_SYMBOL_PATH environment variable. * * using the -y <symbol_path> argument when starting the debugger. * * using .sympath and .sympath+ * ********************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* ************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* Probably caused by : win32k.sys ( win32k+59f4d ) Followup: MachineOwner --------- [/log]
raazor90 komentarz 27 czerwca 2010 komentarz 27 czerwca 2010 [quote]Probably caused by : win32k.sys ( win32k+153492 )[/quote] [quote]Probably caused by : nv4_disp.dll ( nv4_disp+6bdd7 ) [/quote] Poczytaj tutaj: http://www.forumpc.pl/index.php?showtopic=163186
scarp komentarz 1 lipca 2010 Autor komentarz 1 lipca 2010 (edytowane) [quote]win32k.sys naprawa za pomoca płyty instalacyjnej Windows[/quote] No mam płytke, mam kod, ale nie wiem jak to zrobic;>^^ [quote]nv4_disp.dll problem ze sterownikiem karty graficznej[/quote] a co do tego to juz nie wiem "automatycznie wyszukaj i zainstaluj sterowniki" pare razy juz tak robiłem, nadal źle;x? a z tymi rdzeniami dlaczego 1 pracuje a nie 2? + komp kolegi ma 5+lat działa jest slabszy od mojego duuzo ale szybciej mu chodzi... nie ma awarii [b]2 nowe "awarie"[/b] 1: gram w gre, minimalizuje ją i maxymalizuje jest dzwiek zminimalizuje, nie ma, Tak jakby losowo daje dzwięk... 2: Mialem 2 myszki, dziwne ze mają taki sam blad cena ok.70zl +"Myszka się zwiesza, raz dziala, raz nie, kabelek nie jest przerwany "nie dziala=odlacze, podłącze= działa... i znowu się zwiesza. [quote]Gram w Lola wyskakuje mi że nie mam direxa, po resecie pc all działa... Gram w maple: nagle zaczyna migac ( czarne, pulpit, czarne pulpit) ( tak jakby sie minimalizowało i maksymalizowalo...) Gram W warcrafta, wywala mnie z gry.[/quote] tylko te, zostaly da się jakoś?;x [b]w ogóle mój komp za wolno działa;x[/b] @edit: nie mogę przełączyć uzytkowników, lecz jak jest wstapm wstrzymania i "odstampowywuje?"^^ to mam tak jakby na pulpicie profili.a więc wie ktos?;Xsuper...
Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!
Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.