OTL logfile created on: 2012-01-05 15:38:09 - Run 2 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Jola\Moje dokumenty\Downloads\Programs Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,99 Gb Total Physical Memory | 1,18 Gb Available Physical Memory | 59,32% Memory free 3,84 Gb Paging File | 3,01 Gb Available in Paging File | 78,48% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 30,01 Gb Total Space | 15,08 Gb Free Space | 50,26% Space Free | Partition Type: NTFS Drive D: | 11,00 Gb Total Space | 10,93 Gb Free Space | 99,34% Space Free | Partition Type: NTFS Drive E: | 80,01 Gb Total Space | 25,25 Gb Free Space | 31,56% Space Free | Partition Type: NTFS Drive F: | 20,81 Gb Total Space | 19,55 Gb Free Space | 93,95% Space Free | Partition Type: NTFS Drive K: | 7,21 Gb Total Space | 0,44 Gb Free Space | 6,12% Space Free | Partition Type: FAT32 Drive M: | 931,51 Gb Total Space | 864,78 Gb Free Space | 92,84% Space Free | Partition Type: NTFS Computer Name: JOLA-41BABD7503 | User Name: Jola | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-01-05 15:34:48 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jola\Moje dokumenty\Downloads\Programs\OTL_3.exe PRC - [2011-12-22 15:45:46 | 010,234,880 | ---- | M] (Creative Team S.A.) -- C:\Program Files\WapSter\WapSter AQQ\AQQ.exe PRC - [2011-12-22 15:04:40 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2011-12-14 06:59:20 | 002,684,288 | ---- | M] (TeamViewer GmbH) -- c:\Program Files\TeamViewer\Version7\TeamViewer_Desktop.exe PRC - [2011-12-14 06:59:18 | 010,981,248 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version7\TeamViewer.exe PRC - [2011-12-14 06:41:54 | 000,116,608 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version7\tv_w32.exe PRC - [2011-12-03 01:22:12 | 002,415,456 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe PRC - [2011-11-14 06:52:04 | 003,437,976 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\IDMan.exe PRC - [2011-10-18 10:03:52 | 000,161,664 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe PRC - [2011-09-08 20:53:26 | 000,743,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe PRC - [2011-08-15 06:21:40 | 000,337,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe PRC - [2011-08-02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe PRC - [2010-09-17 11:14:50 | 000,098,304 | ---- | M] (Firebird Project) -- C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe PRC - [2010-09-17 11:14:42 | 003,735,552 | ---- | M] (Firebird Project) -- C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe PRC - [2010-05-25 07:28:58 | 000,263,600 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\IEMonitor.exe PRC - [2008-08-19 06:26:44 | 000,077,824 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE PRC - [2008-06-19 09:42:44 | 002,808,832 | ---- | M] (RealTek Semicoductor Corp.) -- C:\WINDOWS\ALCWZRD.EXE PRC - [2008-06-19 09:20:52 | 000,057,344 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\ALCMTR.EXE PRC - [2008-04-15 07:00:00 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007-04-03 20:50:00 | 001,603,152 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE PRC - [2007-02-04 05:02:14 | 000,079,400 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2011-12-22 15:04:39 | 002,124,760 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll MOD - [2011-12-09 13:25:48 | 001,182,720 | ---- | M] () -- C:\Program Files\WapSter\WapSter AQQ\System\Shared\Plugins\GGNet.dll MOD - [2011-11-09 07:18:20 | 000,983,552 | ---- | M] () -- C:\Program Files\WapSter\WapSter AQQ\System\Shared\Plugins\SMS.dll MOD - [2011-09-05 12:05:04 | 000,300,544 | ---- | M] () -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.POL MOD - [2010-08-25 04:41:20 | 000,304,640 | ---- | M] () -- C:\Program Files\WapSter\WapSter AQQ\System\Shared\Plugins\Contact.dll MOD - [2010-07-04 16:32:38 | 000,010,752 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerCOM.dll MOD - [2008-04-15 07:00:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll MOD - [2008-02-14 13:04:54 | 000,005,376 | ---- | M] () -- C:\WINDOWS\system32\antiwpa.dll MOD - [2002-07-04 02:38:00 | 000,053,248 | ---- | M] () -- C:\Program Files\ArcSoft\PhotoImpression 5\Share\PIHook.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [Disabled | Stopped] -- -- (HidServ) SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt) SRV - [2011-10-18 10:03:52 | 000,161,664 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService) SRV - [2011-08-02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd) SRV - [2010-09-17 11:14:50 | 000,098,304 | ---- | M] (Firebird Project) [Auto | Running] -- C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe -- (FirebirdGuardianDefaultInstance) SRV - [2010-09-17 11:14:42 | 003,735,552 | ---- | M] (Firebird Project) [On_Demand | Running] -- C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe -- (FirebirdServerDefaultInstance) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2011-10-07 06:23:48 | 000,230,608 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86) DRV - [2011-09-13 06:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86) DRV - [2011-08-08 06:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86) DRV - [2011-07-11 01:14:28 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH) DRV - [2011-07-06 08:14:42 | 000,101,616 | ---- | M] (Tonec Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\idmtdi.sys -- (IDMTDI) DRV - [2008-08-27 10:22:24 | 004,754,432 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2005-12-12 09:27:00 | 000,019,072 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PS2.sys -- (Ps2) DRV - [2005-10-20 09:01:56 | 001,095,009 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem) DRV - [2004-07-29 00:14:22 | 000,091,577 | R--- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\P0620Vid.sys -- (PD0620VID) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1177238915-573735546-2147114589-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ IE - HKU\S-1-5-21-1177238915-573735546-2147114589-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "about:home|http://www.google.com/" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011-12-22 15:04:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011-11-27 19:12:10 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Documents and Settings\Jola\Dane aplikacji\IDM\idmmzcc5 [2011-11-19 20:22:54 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Documents and Settings\Jola\Dane aplikacji\IDM\idmmzcc5 [2011-11-19 20:22:54 | 000,000,000 | ---D | M] [2011-10-16 16:49:32 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jola\Dane aplikacji\Mozilla\Extensions [2012-01-01 15:45:58 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jola\Dane aplikacji\Mozilla\Firefox\Profiles\nt1xou6x.default\extensions [2012-01-01 13:41:25 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Documents and Settings\Jola\Dane aplikacji\Mozilla\Firefox\Profiles\nt1xou6x.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} [2011-12-22 15:04:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2011-10-16 21:21:46 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2011-11-19 20:22:54 | 000,000,000 | ---D | M] (IDM CC) -- C:\DOCUMENTS AND SETTINGS\JOLA\DANE APLIKACJI\IDM\IDMMZCC5 () (No name found) -- C:\DOCUMENTS AND SETTINGS\JOLA\DANE APLIKACJI\MOZILLA\FIREFOX\PROFILES\NT1XOU6X.DEFAULT\EXTENSIONS\{097D3191-E6FA-4728-9826-B533D755359D}.XPI () (No name found) -- C:\DOCUMENTS AND SETTINGS\JOLA\DANE APLIKACJI\MOZILLA\FIREFOX\PROFILES\NT1XOU6X.DEFAULT\EXTENSIONS\{20A82645-C095-46ED-80E3-08825760534B}.XPI () (No name found) -- C:\DOCUMENTS AND SETTINGS\JOLA\DANE APLIKACJI\MOZILLA\FIREFOX\PROFILES\NT1XOU6X.DEFAULT\EXTENSIONS\{3E9BB2A7-62CA-4EFA-A4E6-F6F6168A652D}.XPI () (No name found) -- C:\DOCUMENTS AND SETTINGS\JOLA\DANE APLIKACJI\MOZILLA\FIREFOX\PROFILES\NT1XOU6X.DEFAULT\EXTENSIONS\{46551EC9-40F0-4E47-8E18-8E5CF550CFB8}.XPI () (No name found) -- C:\DOCUMENTS AND SETTINGS\JOLA\DANE APLIKACJI\MOZILLA\FIREFOX\PROFILES\NT1XOU6X.DEFAULT\EXTENSIONS\FIREBUG@SOFTWARE.JOEHEWITT.COM.XPI [2011-12-22 15:04:40 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011-10-18 10:03:52 | 000,611,224 | ---- | M] (Oracle Corporation) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2010-07-12 11:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll [2011-09-28 19:52:42 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2011-09-28 19:52:42 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2011-09-28 19:52:42 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2011-09-28 19:52:42 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2011-09-28 19:52:42 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2011-09-28 19:52:42 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2008-04-15 07:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.) O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.) O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.) O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.) O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company) O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.) O4 - HKU\S-1-5-21-1177238915-573735546-2147114589-1004..\Run: [AQQ] C:\Program Files\WapSter\WapSter AQQ\AQQ.exe (Creative Team S.A.) O4 - HKU\S-1-5-21-1177238915-573735546-2147114589-1004..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.) O4 - HKU\S-1-5-21-1177238915-573735546-2147114589-1004..\Run: [Odkurzacz-MCD] C:\Program Files\Odkurzacz\odk_mcd.exe (Franmo Software) O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1177238915-573735546-2147114589-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Jola\Dane aplikacji\DVDVideoSoftIEHelpers\freeyoutubedownload.htm () O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Jola\Dane aplikacji\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm () O8 - Extra context menu item: Ściągnij przez IDM - C:\Program Files\Internet Download Manager\IEExt.htm () O8 - Extra context menu item: Ściągnij wszystkie linki przez IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm () O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01) O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab (Java Plug-in 1.7.0_01) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.7.0_01) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.67.222.222 208.67.220.220 167.206.245.129 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C52E862A-8ACC-4AA4-88EE-F34903394031}: DhcpNameServer = 208.67.222.222 208.67.220.220 167.206.245.129 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C52E862A-8ACC-4AA4-88EE-F34903394031}: NameServer = 208.67.222.222,208.67.220.220 O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\Antiwpa: DllName - (antiwpa.dll) - C:\WINDOWS\System32\antiwpa.dll () O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2011-10-16 08:52:21 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2001-07-27 22:07:38 | 000,000,000 | -HS- | M] () - K:\AUTOEXEC.BAT -- [ FAT32 ] O32 - AutoRun File - [2004-04-30 14:01:14 | 000,000,053 | -HS- | M] () - K:\Autorun.inf -- [ FAT32 ] O32 - AutoRun File - [2011-04-21 21:19:35 | 000,000,000 | -H-D | M] - M:\autorun -- [ NTFS ] O32 - AutoRun File - [2010-09-01 01:26:34 | 000,000,124 | -H-- | M] () - M:\autorun.inf -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-01-01 13:41:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jola\Dane aplikacji\DVDVideoSoftIEHelpers [2012-01-01 13:39:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\DVDVideoSoft [2012-01-01 13:39:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jola\Dane aplikacji\DVDVideoSoft [2012-01-01 13:37:43 | 000,000,000 | ---D | C] -- C:\Program Files\DVDVideoSoft [2012-01-01 13:37:43 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DVDVideoSoft [2012-01-01 13:37:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jola\Moje dokumenty\DVDVideoSoft [2011-12-23 23:02:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jola\Pulpit\Nowy folder [2011-12-23 16:46:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jola\Ustawienia lokalne\Dane aplikacji\GHISLER [2011-12-09 19:05:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jola\Dane aplikacji\AVG2012 [2011-12-09 19:04:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\AVG 2012 [2011-12-09 19:03:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\AVG2012 [2011-12-09 19:03:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG [2011-12-09 19:03:01 | 000,000,000 | ---D | C] -- C:\Program Files\AVG [2011-12-09 16:02:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss [2011-12-06 17:00:04 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software [2011-12-06 17:00:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\AVAST Software [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-01-05 09:44:26 | 086,023,149 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm [2012-01-05 07:04:08 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012-01-04 12:55:21 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012-01-03 22:00:28 | 000,010,921 | ---- | M] () -- C:\Documents and Settings\Jola\Moje dokumenty\22 - 75koniec.m3u [2012-01-03 10:53:39 | 006,373,939 | ---- | M] () -- C:\Documents and Settings\Jola\Pulpit\Norman - Powiedz mi.mpg - YouTube.flv [2012-01-02 10:46:28 | 000,005,120 | ---- | M] () -- C:\Documents and Settings\Jola\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-01-01 17:09:25 | 000,116,105 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm [2011-12-29 18:33:30 | 000,277,113 | ---- | M] () -- C:\Documents and Settings\Jola\Pulpit\renia.JPG [2011-12-14 09:18:20 | 000,003,391 | ---- | M] () -- C:\Documents and Settings\Jola\Moje dokumenty\lista 1.m3u [2011-12-11 16:44:01 | 000,002,596 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT [2011-12-09 16:57:48 | 000,000,211 | -HS- | M] () -- C:\boot.ini [2011-12-06 16:01:59 | 000,081,920 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\ALCFDRTM.VER [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-01-05 09:44:26 | 086,023,149 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm [2012-01-03 22:00:28 | 000,010,921 | ---- | C] () -- C:\Documents and Settings\Jola\Moje dokumenty\22 - 75koniec.m3u [2012-01-03 10:53:36 | 006,373,939 | ---- | C] () -- C:\Documents and Settings\Jola\Pulpit\Norman - Powiedz mi.mpg - YouTube.flv [2012-01-02 10:57:42 | 023,103,257 | ---- | C] () -- C:\Documents and Settings\Jola\Pulpit\YouTube - Życzenia Świąteczne .wmv.flv [2012-01-02 10:54:30 | 000,179,982 | ---- | C] () -- C:\Documents and Settings\Jola\Pulpit\sc0018.JPG [2012-01-02 10:47:51 | 000,151,478 | ---- | C] () -- C:\Documents and Settings\Jola\Pulpit\zdrowie.jpg [2012-01-01 17:09:25 | 000,116,105 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm [2011-12-29 18:33:13 | 000,277,113 | ---- | C] () -- C:\Documents and Settings\Jola\Pulpit\renia.JPG [2011-12-14 09:06:14 | 000,003,391 | ---- | C] () -- C:\Documents and Settings\Jola\Moje dokumenty\lista 1.m3u [2011-10-30 13:04:24 | 000,005,120 | ---- | C] () -- C:\Documents and Settings\Jola\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011-10-19 03:28:45 | 000,005,376 | ---- | C] () -- C:\WINDOWS\System32\antiwpa.dll [2011-10-16 22:08:59 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat [2011-10-16 20:33:48 | 000,011,776 | ---- | C] () -- C:\WINDOWS\System32\pmsbfn32.dll [2011-10-16 20:32:26 | 000,000,412 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI [2011-10-16 20:15:09 | 000,000,021 | ---- | C] () -- C:\WINDOWS\PI5_SETUP.ini [2011-10-16 20:14:20 | 000,000,021 | ---- | C] () -- C:\WINDOWS\ME_setup.ini [2011-10-16 19:56:46 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe [2011-10-16 10:25:11 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2011-10-16 10:24:05 | 000,098,256 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2011-10-16 08:54:15 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2011-10-16 08:49:49 | 000,021,856 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2008-04-15 07:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin [2008-04-15 07:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat [2008-04-15 07:00:00 | 000,554,468 | ---- | C] () -- C:\WINDOWS\System32\perfh015.dat [2008-04-15 07:00:00 | 000,492,750 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat [2008-04-15 07:00:00 | 000,313,828 | ---- | C] () -- C:\WINDOWS\System32\perfi015.dat [2008-04-15 07:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat [2008-04-15 07:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat [2008-04-15 07:00:00 | 000,104,156 | ---- | C] () -- C:\WINDOWS\System32\perfc015.dat [2008-04-15 07:00:00 | 000,083,398 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat [2008-04-15 07:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin [2008-04-15 07:00:00 | 000,034,990 | ---- | C] () -- C:\WINDOWS\System32\perfd015.dat [2008-04-15 07:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat [2008-04-15 07:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat [2008-04-15 07:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat [2008-04-15 07:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin [2008-04-15 07:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat [color=#E56717]========== LOP Check ==========[/color] [2011-12-09 18:53:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\AVAST Software [2011-12-09 19:10:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\AVG2012 [2011-10-16 20:29:05 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonBJ [2011-11-08 08:12:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Cisco Systems [2011-10-16 16:02:55 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Common Files [2011-12-27 19:30:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\firebird [2011-10-18 08:24:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10 [2012-01-05 09:44:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\MFAData [2011-10-16 20:32:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ScanSoft [2011-12-09 19:05:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jola\Dane aplikacji\AVG2012 [2012-01-01 13:38:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jola\Dane aplikacji\DMCache [2012-01-01 13:43:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jola\Dane aplikacji\DVDVideoSoft [2012-01-01 13:41:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jola\Dane aplikacji\DVDVideoSoftIEHelpers [2011-10-16 19:32:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jola\Dane aplikacji\ElevatedDiagnostics [2011-12-06 13:56:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jola\Dane aplikacji\ESET [2011-12-17 17:13:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jola\Dane aplikacji\EurekaLog [2011-10-18 09:48:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jola\Dane aplikacji\Gadu-Gadu 10 [2011-12-23 16:44:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jola\Dane aplikacji\GHISLER [2011-12-08 22:07:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jola\Dane aplikacji\IDM [2011-10-16 20:32:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jola\Dane aplikacji\ScanSoft [2012-01-05 14:21:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jola\Dane aplikacji\TeamViewer [color=#E56717]========== Purity Check ==========[/color] < End of report >