Witam wszystkich bardzo serdecznie,
Po zainstalowaniu systemu Windows Vista, doinstalowaniu Service Pack’a 1 oraz wszystkich dostępnych aktualizacji - mam problem. Co jakiś czas odzywa się napęd [Nagrywarka DVD, parę znaków światełkiem, po czym gaśnie… i tak co jakiś czas]. Co może być tego przyczyną? Druga instalacja systemu na świeżo i drugi raz to samo =/ Podaję log z ComboFix’a:
ComboFix 09-06-23.01 - Eagle 2009-06-24 22:05.1 - NTFSx86
Microsoft® Windows Vista™ Business 6.0.6001.1.1250.48.1045.18.3578.2706 [GMT 2:00]
Uruchomiony z: c:\users\Eagle\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-918056312-2952985149-2686913973-500
c:\$recycle.bin\S-1-5-21-918056312-2952985149-2686913973-500\desktop.ini
.
((((((((((((((((((((((((( Pliki utworzone od 2009-05-24 do 2009-06-24 )))))))))))))))))))))))))))))))
.
2009-06-24 20:07 . 2009-06-24 20:07 -------- d-----w- c:\users\Eagle\AppData\Local\temp
2009-06-24 18:39 . 2008-05-27 05:18 44032 ----a-w- c:\windows\system32\msstrc.dll
2009-06-24 18:38 . 2008-10-22 01:22 2048 ----a-w- c:\windows\system32\tzres.dll
2009-06-24 18:31 . 2009-06-03 23:56 675152 ----a-w- c:\windows\system32\gpprefcl.dll
2009-06-24 18:27 . 2008-06-20 01:14 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2009-06-24 18:27 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-06-24 18:27 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocardapi.dll
2009-06-24 18:27 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.dll
2009-06-24 18:27 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt.exe
2009-06-24 18:27 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2009-06-24 18:27 . 2008-06-20 01:14 326160 ----a-w- c:\windows\system32\PresentationHost.exe
2009-06-24 18:24 . 2008-07-27 18:03 282112 ----a-w- c:\windows\system32\mscoree.dll
2009-06-24 18:24 . 2008-07-27 18:03 96760 ----a-w- c:\windows\system32\dfshim.dll
2009-06-24 18:24 . 2008-07-27 18:03 41984 ----a-w- c:\windows\system32\netfxperf.dll
2009-06-24 18:24 . 2008-07-27 18:03 158720 ----a-w- c:\windows\system32\mscorier.dll
2009-06-24 18:24 . 2008-07-27 18:03 83968 ----a-w- c:\windows\system32\mscories.dll
2009-06-24 18:23 . 2009-05-09 05:50 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-24 18:23 . 2009-05-09 05:34 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-06-24 18:21 . 2009-06-24 18:21 -------- d-----w- c:\program files\MSXML 4.0
2009-06-24 18:18 . 2008-05-10 01:33 113664 ----a-w- c:\windows\system32\drivers\rmcast.sys
2009-06-24 18:12 . 2008-09-10 03:40 1334272 ----a-w- c:\windows\system32\msxml6.dll
2009-06-24 18:09 . 2009-06-24 18:10 -------- d-----w- c:\users\Eagle\AppData\Roaming\Nowe Gadu-Gadu
2009-06-24 18:08 . 2009-06-24 18:08 -------- d-----w- c:\windows\system32\Macromed
2009-06-24 18:07 . 2008-10-16 21:09 51224 ----a-w- c:\windows\system32\wuauclt.exe
2009-06-24 18:07 . 2008-10-16 21:09 43544 ----a-w- c:\windows\system32\wups2.dll
2009-06-24 18:07 . 2008-10-16 21:13 1809944 ----a-w- c:\windows\system32\wuaueng.dll
2009-06-24 18:07 . 2008-10-16 20:56 1524736 ----a-w- c:\windows\system32\wucltux.dll
2009-06-24 18:07 . 2008-10-16 21:12 561688 ----a-w- c:\windows\system32\wuapi.dll
2009-06-24 18:07 . 2008-10-16 21:08 34328 ----a-w- c:\windows\system32\wups.dll
2009-06-24 18:07 . 2008-10-16 20:55 83456 ----a-w- c:\windows\system32\wudriver.dll
2009-06-24 18:07 . 2008-10-16 12:08 162064 ----a-w- c:\windows\system32\wuwebv.dll
2009-06-24 18:07 . 2008-10-16 11:56 31232 ----a-w- c:\windows\system32\wuapp.exe
2009-06-24 17:55 . 2009-06-24 17:55 -------- d-----w- c:\programdata\SonicFocus
2009-06-24 17:55 . 2009-06-24 17:55 -------- d-----w- c:\program files\Analog Devices
2009-06-24 17:48 . 2009-06-24 19:26 -------- d-----w- c:\programdata\NVIDIA
2009-06-24 17:48 . 2009-06-24 17:48 -------- d-----w- c:\program files\AGEIA Technologies
2009-06-24 17:48 . 2009-06-24 17:48 -------- d-----w- c:\windows\system32\AGEIA
2009-06-24 17:48 . 2009-06-24 17:48 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-24 17:47 . 2009-06-04 14:39 457248 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-06-24 17:47 . 2009-06-24 16:54 -------- d-----w- c:\windows\Panther
2009-06-24 17:47 . 2009-06-24 17:33 -------- d-sh--w- C:\Boot
2009-06-24 17:45 . 2008-11-19 10:32 121344 ----a-w- c:\windows\system32\hpf3l6eo.dll
2009-06-24 17:44 . 2009-06-24 17:44 -------- d-----w- c:\program files\Common Files\HP
2009-06-24 17:44 . 2009-06-24 17:44 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-06-24 17:44 . 2009-06-24 17:44 -------- d-----w- c:\program files\Hewlett-Packard
2009-06-24 17:44 . 2009-06-24 18:29 -------- d-sh--w- c:\windows\Installer
2009-06-24 17:44 . 2009-06-24 17:44 -------- d-----w- c:\program files\HP
2009-06-24 17:44 . 2009-06-24 17:46 126291 ----a-w- c:\windows\hpoins34.dat
2009-06-24 17:44 . 2009-01-07 19:09 404 ------w- c:\windows\hpomdl34.dat
2009-06-24 17:44 . 2009-06-24 17:44 -------- d-----w- c:\programdata\HP
2009-06-24 17:43 . 2008-11-19 22:49 271704 ----a-w- c:\windows\system32\hpzids01.dll
2009-06-24 17:43 . 2008-10-30 21:12 372736 ----a-w- c:\windows\system32\hppldcoi.dll
2009-06-24 17:43 . 2008-10-30 21:12 309760 ----a-w- c:\windows\system32\difxapi.dll
2009-06-24 17:43 . 2008-10-30 21:11 737280 ----a-w- c:\windows\system32\hposwia_d01a.dll
2009-06-24 17:43 . 2008-10-30 21:11 602112 ----a-w- c:\windows\system32\hpost_d01a.dll
2009-06-24 17:43 . 2008-10-30 21:11 307200 ----a-w- c:\windows\system32\hposc_d01a.dll
2009-06-24 17:38 . 2008-03-26 09:15 53248 ----a-w- c:\windows\system32\CSVer.dll
2009-06-24 17:38 . 2009-06-24 17:38 -------- d-----w- c:\program files\Intel
2009-06-24 17:11 . 2009-06-24 16:59 47560 ----a-w- c:\windows\system32\SPReview.exe
2009-06-24 17:11 . 2009-06-24 16:59 152576 ----a-w- c:\windows\system32\SPWizUI.dll
2009-06-24 17:05 . 2008-01-18 21:36 6656 ----a-w- c:\windows\system32\sdspres.dll
2009-06-24 17:05 . 2008-01-18 21:33 193024 ----a-w- c:\windows\system32\recdisc.exe
2009-06-24 17:04 . 2008-01-18 21:33 599552 ----a-w- c:\windows\system32\vsp1cln.exe
2009-06-24 17:04 . 2008-01-18 21:36 28160 ----a-w- c:\windows\system32\sxproxy.dll
2009-06-24 17:04 . 2008-01-18 21:36 142336 ----a-w- c:\windows\system32\spp.dll
2009-06-24 17:00 . 2008-01-18 21:33 44032 ----a-w- c:\windows\system32\cbsra.exe
2009-06-24 16:57 . 2009-06-24 16:57 -------- d-sh--we c:\users\Default\Ustawienia lokalne
2009-06-24 16:57 . 2009-06-24 16:57 -------- d-sh--we c:\users\Default\Szablony
2009-06-24 16:57 . 2009-06-24 16:57 -------- d-sh--we c:\users\Default\Moje dokumenty
2009-06-24 16:57 . 2009-06-24 16:57 -------- d-sh--we c:\users\Default\Menu Start
2009-06-24 16:57 . 2009-06-24 16:57 -------- d-sh--we c:\users\Default\Dane aplikacji
2009-06-24 16:57 . 2009-06-24 16:57 -------- d-sh--we c:\programdata\Ulubione
2009-06-24 16:57 . 2009-06-24 16:57 -------- d-sh--we c:\programdata\Szablony
2009-06-24 16:57 . 2009-06-24 16:57 -------- d-sh--we c:\programdata\Pulpit
2009-06-24 16:57 . 2009-06-24 16:57 -------- d-sh--we c:\programdata\Menu Start
2009-06-24 16:57 . 2009-06-24 16:57 -------- d-sh--we c:\programdata\Dokumenty
2009-06-24 16:57 . 2009-06-24 16:57 -------- d-sh--we c:\programdata\Dane aplikacji
2009-06-24 16:49 . 2009-06-24 18:50 -------- d-----w- c:\windows\system32\catroot2
2009-06-24 16:49 . 2009-06-24 18:23 -------- d-----w- c:\windows\Debug
2009-06-10 16:33 . 2009-06-10 16:33 9899296 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2009-06-10 16:33 . 2009-06-10 16:33 989696 ----a-w- c:\windows\system32\nvapi.dll
2009-06-10 16:33 . 2009-06-10 16:33 795104 ----a-w- c:\windows\system32\dpinst.exe
2009-06-10 16:33 . 2009-06-10 16:33 7611904 ----a-w- c:\windows\system32\nvd3dum.dll
2009-06-10 16:33 . 2009-06-10 16:33 678432 ----a-w- c:\windows\system32\nvcuvid.dll
2009-06-10 16:33 . 2009-06-10 16:33 457248 ----a-w- c:\windows\system32\nvudisp.exe
2009-06-10 16:33 . 2009-06-10 16:33 3148288 ----a-w- c:\windows\system32\nvwgf2um.dll
2009-06-10 16:33 . 2009-06-10 16:33 1704960 ----a-w- c:\windows\system32\nvcuda.dll
2009-06-10 16:33 . 2009-06-10 16:33 151552 ----a-w- c:\windows\system32\nvcod155.dll
2009-06-10 16:33 . 2009-06-10 16:33 151552 ----a-w- c:\windows\system32\nvcod.dll
2009-06-10 16:33 . 2009-06-10 16:33 1317408 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-06-10 16:33 . 2009-06-10 16:33 10379264 ----a-w- c:\windows\system32\nvoglv32.dll
2009-06-10 06:35 . 2009-06-10 06:35 1505824 ----a-w- c:\windows\system32\nvcpluir.dll
2009-06-10 06:35 . 2009-06-10 06:35 1358368 ----a-w- c:\windows\system32\nvsvsr.dll
2009-06-10 06:35 . 2009-06-10 06:35 1194528 ----a-w- c:\windows\system32\nvcplui.exe
2009-06-10 06:35 . 2009-06-10 06:35 1296928 ----a-w- c:\windows\system32\nvsvs.dll
2009-06-10 04:33 . 2009-06-10 04:33 244736 ----a-w- c:\windows\system32\nvStInst.exe
2009-06-10 04:33 . 2009-06-10 04:33 467968 ----a-w- c:\windows\system32\nvstlink.exe
2009-06-10 04:33 . 2009-06-10 04:33 3953152 ----a-w- c:\windows\system32\nvstwiz.exe
2009-06-10 04:33 . 2009-06-10 04:33 141824 ----a-w- c:\windows\system32\nvStereoApiI.dll
2009-06-10 04:33 . 2009-06-10 04:33 171520 ----a-w- c:\windows\system32\nvStereoApiI64.dll
2009-06-10 04:33 . 2009-06-10 04:33 232960 ----a-w- c:\windows\system32\nvSCPAPISvr.exe
2009-06-10 04:32 . 2009-06-10 04:32 257536 ----a-w- c:\windows\system32\nvSCPAPI.dll
2009-06-10 04:32 . 2009-06-10 04:32 301568 ----a-w- c:\windows\system32\nvSCPAPI64.dll
2009-06-10 04:32 . 2009-06-10 04:32 3293184 ----a-w- c:\windows\system32\nvstres.dll
2009-06-10 04:32 . 2009-06-10 04:32 5847 ----a-w- c:\windows\system32\oglstreg.reg
2009-06-10 04:31 . 2009-06-10 04:31 167424 ----a-w- c:\windows\system32\nvstreg.exe
2009-06-10 04:31 . 2009-06-10 04:31 1718272 ----a-w- c:\windows\system32\nvsttest.exe
2009-06-10 04:31 . 2009-06-10 04:31 1034752 ----a-w- c:\windows\system32\nvstview.exe
2009-06-10 04:31 . 2009-06-10 04:31 89088 ----a-w- c:\windows\system32\nvimage.dll
2009-06-10 04:29 . 2009-06-10 04:29 1656 ----a-w- c:\windows\system32\nvstdef.reg
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-24 19:30 . 2006-12-05 05:23 661818 ----a-w- c:\windows\system32\perfh015.dat
2009-06-24 19:30 . 2006-12-05 05:23 126702 ----a-w- c:\windows\system32\perfc015.dat
2009-06-24 19:26 . 2009-06-24 17:51 31871 ----a-w- c:\programdata\nvModes.dat
2009-06-24 18:47 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-06-24 18:47 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-06-24 17:42 . 2009-06-24 16:58 680 ----a-w- c:\users\Eagle\AppData\Local\d3d9caps.dat
2009-06-24 17:29 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-06-24 17:29 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-06-24 17:29 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-06-24 17:29 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-06-24 17:29 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-06-24 17:29 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-06-24 17:18 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2009-06-24 17:18 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2009-06-24 16:58 . 2009-06-24 16:58 48600 ----a-w- c:\users\Eagle\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-10 16:33 . 2009-06-10 16:33 4224 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2009-05-28 09:23 . 2009-06-24 18:19 42088 ----a-w- c:\users\Eagle\AppData\Roaming\Nowe Gadu-Gadu\_userdata\ggbho.1.dll
2009-04-28 07:55 . 2009-04-28 07:55 70936 ----a-w- c:\windows\system32\PhysXLoader.dll
2009-04-23 12:43 . 2009-06-24 18:17 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-24 18:17 636928 ----a-w- c:\windows\system32\localspl.dll
2009-04-21 11:55 . 2009-06-24 18:18 2033152 ----a-w- c:\windows\system32\win32k.sys
2009-04-07 08:50 . 2009-04-07 08:50 288024 ----a-w- c:\windows\system32\PhysXCplUI.exe
2009-04-07 08:50 . 2009-04-07 08:50 288024 ----a-w- c:\windows\system32\PhysXCompatCplUI.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-18 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2008-01-18 2153472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13785632]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2008-07-08 1310720]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-4025696193-1505281613-2581706604-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{0A24AC06-537D-4DC5-BB38-E219636C8FFA}"= c:\program files\Hp\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{2510614F-48BB-461B-AF51-30FFBB2641F7}"= c:\program files\Hp\Digital Imaging\bin\hpfccopy.exe:hpfccopy.exe
"{F08F47CB-1B8D-4824-B2F9-57BA652CEEC1}"= c:\program files\Hp\Digital Imaging\bin\hpiscnapp.exe:hpiscnapp.exe
"TCP Query User{A702C75E-D474-4B15-8150-4A15B3F65906}d:\\programy\\komunikatory internetowe\\gadu-gadu\\gg.exe"= UDP:d:\programy\komunikatory internetowe\gadu-gadu\gg.exe:Nowe Gadu-Gadu
"UDP Query User{446D7CC2-73FD-4A32-8547-99643C2DE0B3}d:\\programy\\komunikatory internetowe\\gadu-gadu\\gg.exe"= TCP:d:\programy\komunikatory internetowe\gadu-gadu\gg.exe:Nowe Gadu-Gadu
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\windows\System32\nvSCPAPISvr.exe [2009-06-10 232960]
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\System32\drivers\e1k6032.sys [2008-07-25 165984]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Zawartość folderu 'Zaplanowane zadania'
2009-06-24 c:\windows\Tasks\User_Feed_Synchronization-{C39E0749-C05D-46FD-B0C4-8B258B42435D}.job
- c:\windows\system32\msfeedssync.exe [2009-06-24 11:31]
.
.
------- Skan uzupełniający -------
.
uStart Page = about:blank
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-24 22:07
Windows 6.0.6001 Service Pack 1 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
c:\windows\TEMP\TMP0000004F1F3E7A135318DDFA 524288 bytes executable
skanowanie pomyślnie ukończone
ukryte pliki: 1
**************************************************************************
.
Czas ukończenia: 2009-06-24 22:08
ComboFix-quarantined-files.txt 2009-06-24 20:08
Przed: 62 951 968 768 bajtów wolnych
Po: 62 975 508 480 bajtów wolnych
208 --- E O F --- 2009-06-24 18:54