OTL logfile created on: 2012-03-14 08:11:49 - Run 1 OTL by OldTimer - Version 3.2.36.3 Folder = C:\Users\karolek\Desktop\ddd Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,43 Gb Total Physical Memory | 1,43 Gb Available Physical Memory | 58,72% Memory free 5,09 Gb Paging File | 4,08 Gb Available in Paging File | 80,18% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 111,57 Gb Total Space | 80,55 Gb Free Space | 72,20% Space Free | Partition Type: NTFS Drive D: | 111,55 Gb Total Space | 60,02 Gb Free Space | 53,81% Space Free | Partition Type: NTFS Computer Name: KAROLEK-PC | User Name: karolek | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-03-14 08:07:06 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\Users\karolek\Desktop\ddd\OTL.exe PRC - [2012-03-12 18:12:16 | 000,204,800 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Users\karolek\AppData\Local\Temp\RtkBtMnt.exe PRC - [2012-03-07 01:15:17 | 004,241,512 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe PRC - [2012-03-07 01:15:14 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe PRC - [2010-12-14 15:49:16 | 000,653,120 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe PRC - [2010-12-14 15:47:48 | 001,517,376 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe PRC - [2009-04-11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009-04-02 18:05:22 | 000,102,400 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe PRC - [2009-03-31 09:39:36 | 000,233,472 | ---- | M] (Teruten) -- C:\Windows\System32\FsUsbExService.Exe PRC - [2008-07-24 19:40:24 | 000,809,480 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\LManager.exe PRC - [2008-06-13 13:52:52 | 006,183,456 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe PRC - [2008-06-11 10:22:16 | 000,409,600 | ---- | M] (Acer Inc.) -- C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe PRC - [2008-05-14 17:05:30 | 000,500,784 | ---- | M] (Egis Incorporated) -- C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe PRC - [2008-05-14 17:05:22 | 000,526,896 | ---- | M] (Egis Incorporated) -- C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe PRC - [2008-03-21 12:22:52 | 000,024,576 | ---- | M] () -- C:\Program Files\Acer\Empowering Technology\Service\ETService.exe PRC - [2008-03-18 20:27:12 | 000,013,312 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe PRC - [2008-02-12 13:19:52 | 000,723,496 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe PRC - [2008-01-16 17:35:02 | 000,081,504 | ---- | M] () -- C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe PRC - [2007-12-06 16:15:28 | 000,110,592 | ---- | M] () -- C:\Acer\Mobility Center\MobilityService.exe PRC - [2007-10-23 10:56:18 | 000,200,704 | ---- | M] () -- C:\Windows\PLFSetI.exe PRC - [2006-05-25 00:20:50 | 000,593,920 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe PRC - [2006-05-10 09:48:08 | 000,094,208 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012-02-17 13:40:08 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\d0cf808e33a5123b33010b933d3b1597\System.ServiceProcess.ni.dll MOD - [2012-02-17 13:39:39 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\5c3bfd69e0c268baff0d169e11a6a784\System.Runtime.Remoting.ni.dll MOD - [2012-02-17 13:36:11 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\65450889f3742aada2a6c0cf8e6173e3\System.Windows.Forms.ni.dll MOD - [2012-02-17 13:35:46 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\137696d0416b65dbc1561152971488b4\System.Drawing.ni.dll MOD - [2012-02-17 13:32:23 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\c50133cb67d7c013fa31e1ffb942060b\System.ni.dll MOD - [2012-01-09 10:56:42 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll MOD - [2009-03-31 19:05:12 | 000,311,296 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pl_b77a5c561934e089\mscorlib.resources.dll MOD - [2009-03-31 19:05:12 | 000,032,768 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_pl_b77a5c561934e089\System.Runtime.Remoting.resources.dll MOD - [2008-06-11 10:21:46 | 000,204,800 | ---- | M] () -- C:\Windows\System32\SysHook.dll MOD - [2008-05-14 17:05:10 | 000,227,888 | ---- | M] () -- C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ShowErrMsg.dll MOD - [2008-05-12 23:32:57 | 000,061,440 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Framework.Library\3.0.3006.0__3036420f80dd6947\Framework.Library.dll MOD - [2008-05-12 23:32:57 | 000,036,864 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Framework.Utility\3.0.3006.0__4df5dcab8860d239\Framework.Utility.dll MOD - [2008-05-12 23:32:57 | 000,020,480 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Framework.Model.ControllerInterface\3.0.3006.0__d842b71b4d6ed079\Framework.Model.ControllerInterface.dll MOD - [2007-10-23 10:56:18 | 000,200,704 | ---- | M] () -- C:\Windows\PLFSetI.exe MOD - [2007-03-08 11:05:06 | 000,017,024 | ---- | M] () -- c:\Program Files\Adobe\Reader 8.0\Reader\ViewerPS.dll MOD - [2003-06-07 13:30:08 | 000,057,344 | ---- | M] () -- C:\Program Files\Launch Manager\PowerUtl.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2012-03-07 01:15:14 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2010-12-14 15:47:48 | 001,517,376 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc) SRV - [2010-12-14 15:45:42 | 000,029,504 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp) SRV - [2009-03-31 09:39:36 | 000,233,472 | ---- | M] (Teruten) [Auto | Running] -- C:\Windows\System32\FsUsbExService.Exe -- (FsUsbExService) SRV - [2008-05-14 17:05:30 | 000,500,784 | ---- | M] (Egis Incorporated) [Auto | Running] -- C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe -- (eDataSecurity Service) SRV - [2008-04-07 09:17:30 | 000,430,592 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) SRV - [2008-03-21 12:22:52 | 000,024,576 | ---- | M] () [Auto | Running] -- C:\Program Files\Acer\Empowering Technology\Service\ETService.exe -- (ETService) SRV - [2008-03-18 20:27:12 | 000,013,312 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio) SRV - [2008-01-21 03:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2008-01-16 17:35:02 | 000,081,504 | ---- | M] () [Auto | Running] -- C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe -- (CLHNService) SRV - [2007-12-06 16:15:28 | 000,110,592 | ---- | M] () [Auto | Running] -- C:\Acer\Mobility Center\MobilityService.exe -- (MobilityService) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (IpInIp) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (esihdrv) DRV - [2012-03-07 01:03:51 | 000,612,184 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2012-03-07 01:03:38 | 000,337,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP) DRV - [2012-03-07 01:02:00 | 000,035,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr) DRV - [2012-03-07 01:01:53 | 000,053,848 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2012-03-07 01:01:48 | 000,057,688 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt) DRV - [2012-03-07 01:01:30 | 000,020,696 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2010-11-29 19:27:40 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv) DRV - [2009-03-31 09:39:36 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk) DRV - [2009-03-20 10:01:26 | 000,121,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bmdm.sys -- (ss_bmdm) DRV - [2009-03-20 10:01:26 | 000,090,112 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bbus.sys -- (ss_bbus) SAMSUNG USB Mobile Device (WDM) DRV - [2009-03-20 10:01:26 | 000,014,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bmdfl.sys -- (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter) DRV - [2009-02-13 20:02:52 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\wdcsam.sys -- (WDC_SAM) DRV - [2008-04-27 20:07:44 | 000,909,824 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2008-04-18 14:01:24 | 000,061,424 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl -- ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) DRV - [2008-03-21 09:48:24 | 000,015,392 | ---- | M] (Acer, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\int15.sys -- (int15) DRV - [2008-03-01 00:13:38 | 001,202,560 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem) DRV - [2008-01-16 17:35:08 | 000,122,368 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys -- (NTIPPKernel) DRV - [2007-09-17 15:53:26 | 000,021,632 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd) DRV - [2006-05-25 00:53:06 | 000,003,712 | ---- | M] (Logitech, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\LBeepKE.sys -- (LBeepKE) DRV - [2006-05-10 09:56:54 | 000,027,264 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LHidKE.Sys -- (LHidKe) DRV - [2006-05-10 09:56:50 | 000,071,680 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMOUKE.sys -- (LMouKE) DRV - [2006-05-10 09:56:26 | 000,036,736 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LHidUsbK.sys -- (LHidUsbK) DRV - [2006-05-10 09:56:08 | 000,013,568 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\L8042Kbd.sys -- (L8042Kbd) DRV - [2005-07-07 15:26:04 | 000,055,216 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\k750bus.sys -- (k750bus) Sony Ericsson 750 driver (WDM) DRV - [2005-07-07 15:26:00 | 000,006,576 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\k750mdfl.sys -- (k750mdfl) DRV - [2005-07-07 15:25:58 | 000,089,872 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\k750mdm.sys -- (k750mdm) DRV - [2005-07-07 15:25:50 | 000,079,488 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\k750obex.sys -- (k750obex) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms} IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0415&s=2&o=vp32&d=0209&m=aspire_5735 IE - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ IE - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.) IE - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64} IE - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&AF=100482&babsrc=SP_ss&mntrId=240e99d10000000000000017c4468803 IE - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\..\SearchScopes\{101A8B43-6F06-446D-A3CF-B158F7E4CDE7}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGLL_pl IE - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW IE - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms} IE - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms} IE - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = IE - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 127.0.0.1:25475 [color=#E56717]========== FireFox ==========[/color] FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-03-13 11:23:43 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-03-06 13:26:55 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2012-03-03 11:07:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\karolek\AppData\Roaming\mozilla\Extensions [2012-03-06 13:26:55 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2012-02-16 16:14:21 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012-02-16 12:12:03 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2012-02-16 12:12:03 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2012-02-16 12:12:03 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2012-02-16 12:12:03 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2012-02-16 12:12:03 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2012-02-16 12:12:03 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2010-10-21 06:42:21 | 000,002,107 | RHS- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O1 - Hosts: 89.248.160.148 google.com O1 - Hosts: 89.248.160.148 google.com.au O1 - Hosts: 89.248.160.148 www.google.com.au O1 - Hosts: 89.248.160.148 google.be O1 - Hosts: 89.248.160.148 www.google.be O1 - Hosts: 89.248.160.148 google.com.br O1 - Hosts: 89.248.160.148 www.google.com.br O1 - Hosts: 89.248.160.148 google.ca O1 - Hosts: 89.248.160.148 www.google.ca O1 - Hosts: 89.248.160.148 google.ch O1 - Hosts: 89.248.160.148 www.google.ch O1 - Hosts: 89.248.160.148 google.de O1 - Hosts: 89.248.160.148 www.google.de O1 - Hosts: 89.248.160.148 google.dk O1 - Hosts: 89.248.160.148 www.google.dk O1 - Hosts: 89.248.160.148 google.fr O1 - Hosts: 89.248.160.148 www.google.fr O1 - Hosts: 89.248.160.148 google.ie O1 - Hosts: 89.248.160.148 www.google.ie O1 - Hosts: 89.248.160.148 google.it O1 - Hosts: 89.248.160.148 www.google.it O1 - Hosts: 89.248.160.148 google.co.jp O1 - Hosts: 89.248.160.148 www.google.co.jp O1 - Hosts: 24 more lines... O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll (Egis) O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.) O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found. O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O3 - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.) O3 - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe (Egis Incorporated) O4 - HKLM..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe (Acer Inc.) O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.) O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech Inc.) O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe () O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O7 - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowRun = 1 O7 - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2 O7 - HKU\S-1-5-21-2788582013-2975435611-3338148792-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1 O8 - Extra context menu item: Funkcja Google Sidewiki - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html File not found O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\MenuExt.html () O8 - Extra context menu item: Wyślij obraz do urządzenia &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O8 - Extra context menu item: Wyślij stronę do urządzenia &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O13 - gopher Prefix: missing O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.172.224.160 89.231.1.206 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3B822729-1CBA-49F4-8D54-BA58CB08D63E}: DhcpNameServer = 217.172.224.160 89.231.1.206 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BDA7F0D9-6CA3-442B-9263-B6A6A9980F18}: DhcpNameServer = 217.172.224.160 89.231.1.206 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: D:\zdjęcia\Wrzesień 2011\HPIM3846.JPG O24 - Desktop BackupWallPaper: D:\zdjęcia\Wrzesień 2011\HPIM3846.JPG O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006-09-18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{a9061dc6-27cb-11e1-b80e-001d72d3e53f}\Shell - "" = AutoRun O33 - MountPoints2\{a9061dc6-27cb-11e1-b80e-001d72d3e53f}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Start.hta O33 - MountPoints2\{cb3747db-b1fb-11e0-b4e5-001d72d3e53f}\Shell - "" = AutoRun O33 - MountPoints2\{cb3747db-b1fb-11e0-b4e5-001d72d3e53f}\Shell\AutoRun\command - "" = F:\AutoRunCardDetector.exe O33 - MountPoints2\{fa18fea7-2305-11e1-aa4d-001d72d3e53f}\Shell - "" = AutoRun O33 - MountPoints2\{fa18fea7-2305-11e1-aa4d-001d72d3e53f}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Start.hta O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (sdnclean.exe) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-03-14 08:10:13 | 000,000,000 | ---D | C] -- C:\Users\karolek\Desktop\ddd [2012-03-14 08:10:01 | 000,000,000 | ---D | C] -- C:\Users\karolek\Desktop\hosts-perm [2012-03-14 08:09:45 | 000,000,000 | ---D | C] -- C:\Users\karolek\Desktop\totalcmd [2012-03-13 13:28:49 | 000,000,000 | ---D | C] -- C:\Users\karolek\AppData\Roaming\Malwarebytes [2012-03-13 13:28:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012-03-13 13:28:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012-03-13 13:28:42 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2012-03-13 13:28:42 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2012-03-13 10:59:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus [2012-03-13 10:59:34 | 000,337,880 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2012-03-13 10:59:34 | 000,020,696 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys [2012-03-13 10:59:31 | 000,035,672 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys [2012-03-13 10:59:30 | 000,612,184 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2012-03-13 10:59:30 | 000,053,848 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2012-03-13 10:59:29 | 000,057,688 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2012-03-13 10:59:22 | 000,201,352 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe [2012-03-13 10:59:22 | 000,041,184 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr [2012-03-13 10:59:05 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software [2012-03-12 21:07:22 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\HostsMan Backups [2012-03-12 21:07:22 | 000,000,000 | ---D | C] -- C:\Users\karolek\AppData\Roaming\abelhadigital.com [2012-03-12 21:07:22 | 000,000,000 | ---D | C] -- C:\ProgramData\abelhadigital.com [2012-03-12 19:24:54 | 000,000,000 | ---D | C] -- C:\Users\karolek\AppData\Local\GHISLER [2012-03-12 19:23:21 | 000,000,000 | ---D | C] -- C:\Users\karolek\AppData\Roaming\GHISLER [2012-03-12 18:51:40 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2012-03-12 18:35:23 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll [2012-03-12 18:35:23 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll [2012-03-12 18:35:23 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe [2012-03-12 18:35:23 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2012-03-12 18:35:22 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2012-03-12 18:35:22 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll [2012-03-12 18:35:22 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2012-03-12 18:35:22 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll [2012-03-12 18:35:22 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe [2012-03-12 18:35:22 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll [2012-03-12 18:35:21 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat [2012-03-12 18:35:21 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2012-03-12 18:35:21 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll [2012-03-12 18:35:21 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll [2012-03-12 18:35:21 | 000,353,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2012-03-12 18:35:21 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll [2012-03-12 18:35:21 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll [2012-03-12 18:35:21 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe [2012-03-12 18:35:21 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll [2012-03-12 18:35:21 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2012-03-12 18:35:20 | 000,580,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2012-03-12 18:35:20 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe [2012-03-12 18:35:20 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe [2012-03-12 18:35:20 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll [2012-03-12 18:35:19 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2012-03-12 18:35:19 | 001,798,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll [2012-03-12 18:35:19 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll [2012-03-12 18:35:19 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll [2012-03-12 18:35:19 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2012-03-12 18:35:19 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll [2012-03-12 18:35:19 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2012-03-12 18:35:19 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll [2012-03-12 18:35:19 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll [2012-03-12 18:35:19 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll [2012-03-12 18:35:19 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2012-03-12 18:35:19 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll [2012-03-12 18:35:19 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2012-03-12 18:09:36 | 000,290,816 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\RTKVADDA.EXE [2012-03-12 18:08:49 | 001,777,664 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\WavesLib.dll [2012-03-12 18:08:49 | 000,339,968 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSXT.dll [2012-03-12 18:08:49 | 000,185,776 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSHD.dll [2012-03-12 18:08:49 | 000,135,168 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSWOW.dll [2012-03-12 18:08:48 | 001,196,032 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\RtlUpd.exe [2012-03-12 18:08:48 | 000,540,672 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RTSndMgr.cpl [2012-03-12 18:08:48 | 000,167,936 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSHP360.dll [2012-03-12 18:08:47 | 006,183,456 | ---- | C] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe [2012-03-12 18:08:47 | 001,933,312 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioEQ.dll [2012-03-12 18:08:47 | 000,721,408 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkPgExt.dll [2012-03-12 18:08:47 | 000,285,216 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkApoApi.dll [2012-03-12 18:08:47 | 000,159,744 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO20.dll [2012-03-12 18:08:47 | 000,143,360 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\System32\FMAPO.dll [2012-03-12 18:08:47 | 000,126,976 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO.dll [2012-03-12 18:08:46 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek [2012-03-12 18:08:44 | 000,520,192 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\RtlExUpd.dll [2012-03-12 17:55:12 | 000,000,000 | ---D | C] -- C:\Program Files\Launch Manager [2012-03-12 13:51:35 | 000,031,552 | ---- | C] (TuneUp Software) -- C:\Windows\System32\TURegOpt.exe [2012-03-12 13:51:32 | 000,029,504 | ---- | C] (TuneUp Software) -- C:\Windows\System32\uxtuneup.dll [2012-03-12 13:51:32 | 000,021,312 | ---- | C] (TuneUp Software) -- C:\Windows\System32\authuitu.dll [2012-03-12 13:51:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2011 [2012-03-12 13:51:23 | 000,000,000 | ---D | C] -- C:\Users\karolek\AppData\Roaming\TuneUp Software [2012-03-12 13:51:19 | 000,000,000 | ---D | C] -- C:\Program Files\TuneUp Utilities 2011 [2012-03-12 13:51:13 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software [2012-03-12 13:51:08 | 000,000,000 | -HSD | C] -- C:\ProgramData\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16} [2012-03-03 11:06:47 | 000,000,000 | ---D | C] -- C:\Users\karolek\AppData\Roaming\Mozilla [2012-03-03 11:06:40 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2012-03-03 10:44:39 | 000,414,368 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [2012-02-16 16:03:11 | 002,044,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-03-14 08:12:00 | 003,407,872 | -HS- | M] () -- C:\Users\karolek\NTUSER.DAT [2012-03-14 08:11:21 | 001,519,634 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI [2012-03-14 08:11:21 | 000,685,356 | ---- | M] () -- C:\Windows\System32\perfh015.dat [2012-03-14 08:11:21 | 000,599,038 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012-03-14 08:11:21 | 000,135,134 | ---- | M] () -- C:\Windows\System32\perfc015.dat [2012-03-14 08:11:21 | 000,106,920 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012-03-14 08:00:59 | 000,000,000 | ---- | M] () -- C:\Windows\System32\LogConfigTemp.xml [2012-03-14 07:59:19 | 000,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl [2012-03-14 07:58:43 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2012-03-14 07:58:42 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2012-03-14 07:58:36 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012-03-13 17:17:14 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2012-03-13 17:17:05 | 000,524,288 | -HS- | M] () -- C:\Users\karolek\NTUSER.DAT{08c124d6-6cfb-11e1-954d-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms [2012-03-13 17:17:05 | 000,065,536 | -HS- | M] () -- C:\Users\karolek\NTUSER.DAT{08c124d6-6cfb-11e1-954d-806e6f6e6963}.TM.blf [2012-03-13 17:16:41 | 002,395,618 | -H-- | M] () -- C:\Users\karolek\AppData\Local\IconCache.db [2012-03-13 13:28:44 | 000,000,910 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk [2012-03-13 12:46:11 | 000,524,288 | -HS- | M] () -- C:\Users\karolek\NTUSER.DAT{08c124d6-6cfb-11e1-954d-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms [2012-03-13 11:58:44 | 003,407,872 | -HS- | M] () -- C:\Users\karolek\NTUSER.DAT_tureg_old [2012-03-13 11:58:42 | 000,524,288 | -HS- | M] () -- C:\Users\karolek\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms [2012-03-13 11:58:42 | 000,065,536 | -HS- | M] () -- C:\Users\karolek\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf [2012-03-13 11:30:37 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt [2012-03-13 10:59:35 | 000,001,833 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2012-03-13 10:54:47 | 000,000,640 | RHS- | M] () -- C:\Users\karolek\ntuser.pol [2012-03-12 19:38:39 | 000,303,400 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012-03-12 18:50:10 | 000,054,156 | -H-- | M] () -- C:\Windows\QTFont.qfn [2012-03-12 18:35:36 | 000,008,798 | ---- | M] () -- C:\Windows\System32\icrav03.rat [2012-03-12 18:35:36 | 000,001,988 | ---- | M] () -- C:\Windows\System32\ticrf.rat [2012-03-12 18:35:23 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll [2012-03-12 18:35:23 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msls31.dll [2012-03-12 18:35:23 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SetIEInstalledDate.exe [2012-03-12 18:35:23 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe [2012-03-12 18:35:23 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2012-03-12 18:35:22 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2012-03-12 18:35:22 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll [2012-03-12 18:35:22 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2012-03-12 18:35:22 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll [2012-03-12 18:35:22 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtmler.dll [2012-03-12 18:35:21 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dat [2012-03-12 18:35:21 | 001,427,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2012-03-12 18:35:21 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll [2012-03-12 18:35:21 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll [2012-03-12 18:35:21 | 000,353,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2012-03-12 18:35:21 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll [2012-03-12 18:35:21 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll [2012-03-12 18:35:21 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe [2012-03-12 18:35:21 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf [2012-03-12 18:35:21 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll [2012-03-12 18:35:21 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll [2012-03-12 18:35:20 | 000,580,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2012-03-12 18:35:20 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wextract.exe [2012-03-12 18:35:20 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iexpress.exe [2012-03-12 18:35:20 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll [2012-03-12 18:35:19 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2012-03-12 18:35:19 | 001,798,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll [2012-03-12 18:35:19 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll [2012-03-12 18:35:19 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakui.dll [2012-03-12 18:35:19 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2012-03-12 18:35:19 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieakeng.dll [2012-03-12 18:35:19 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll [2012-03-12 18:35:19 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IEAdvpack.dll [2012-03-12 18:35:19 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\admparse.dll [2012-03-12 18:35:19 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\pngfilt.dll [2012-03-12 18:35:19 | 000,041,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll [2012-03-12 18:35:19 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\imgutil.dll [2012-03-12 18:35:19 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe [2012-03-12 18:23:17 | 000,001,409 | ---- | M] () -- C:\Windows\QTFont.for [2012-03-12 18:08:51 | 000,319,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\DIFxAPI.dll [2012-03-12 17:55:13 | 000,000,083 | ---- | M] () -- C:\Windows\LManager.UNI [2012-03-12 17:10:37 | 000,000,594 | ---- | M] () -- C:\Windows\tasks\Automatyczna konserwacja.job [2012-03-08 11:20:04 | 000,143,051 | ---- | M] () -- C:\Users\karolek\Desktop\C4D641335B.pdf [2012-03-07 01:15:19 | 000,041,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr [2012-03-07 01:15:14 | 000,201,352 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe [2012-03-07 01:03:51 | 000,612,184 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2012-03-07 01:03:38 | 000,337,880 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2012-03-07 01:02:00 | 000,035,672 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys [2012-03-07 01:01:53 | 000,053,848 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2012-03-07 01:01:48 | 000,057,688 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2012-03-07 01:01:30 | 000,020,696 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys [2012-03-06 13:26:56 | 000,000,850 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2012-03-03 11:08:50 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [2012-02-23 09:18:36 | 000,237,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe [2012-02-22 10:47:37 | 000,309,080 | ---- | M] () -- C:\Users\karolek\Documents\Curriculum Vitae Karolina Dembicka.pdf [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-03-13 15:43:47 | 002,395,618 | -H-- | C] () -- C:\Users\karolek\AppData\Local\IconCache.db [2012-03-13 13:28:44 | 000,000,910 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk [2012-03-13 11:59:26 | 000,524,288 | -HS- | C] () -- C:\Users\karolek\NTUSER.DAT{08c124d6-6cfb-11e1-954d-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms [2012-03-13 11:59:26 | 000,524,288 | -HS- | C] () -- C:\Users\karolek\NTUSER.DAT{08c124d6-6cfb-11e1-954d-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms [2012-03-13 11:59:26 | 000,065,536 | -HS- | C] () -- C:\Users\karolek\NTUSER.DAT{08c124d6-6cfb-11e1-954d-806e6f6e6963}.TM.blf [2012-03-13 10:59:35 | 000,001,833 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2012-03-13 10:54:47 | 000,000,640 | RHS- | C] () -- C:\Users\karolek\ntuser.pol [2012-03-12 18:35:21 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf [2012-03-12 18:23:17 | 000,054,156 | -H-- | C] () -- C:\Windows\QTFont.qfn [2012-03-12 18:23:17 | 000,001,409 | ---- | C] () -- C:\Windows\QTFont.for [2012-03-12 18:08:50 | 000,001,694 | ---- | C] () -- C:\Windows\RtDefLvl.ini [2012-03-12 13:53:08 | 000,000,594 | ---- | C] () -- C:\Windows\tasks\Automatyczna konserwacja.job [2012-03-12 13:51:30 | 000,001,901 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2011.lnk [2012-03-08 11:20:04 | 000,143,051 | ---- | C] () -- C:\Users\karolek\Desktop\C4D641335B.pdf [2012-03-03 11:06:42 | 000,000,862 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2012-03-03 11:06:42 | 000,000,850 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2012-03-02 15:57:11 | 013,155,583 | ---- | C] () -- C:\Users\karolek\Desktop\The Manual of Chess Combinations - 1a.pdf [2012-02-22 10:47:35 | 000,309,080 | ---- | C] () -- C:\Users\karolek\Documents\Curriculum Vitae Karolina Dembicka.pdf [2011-10-10 15:05:13 | 000,000,112 | ---- | C] () -- C:\Windows\ActiveSkin.INI [2011-04-04 15:10:02 | 000,167,940 | ---- | C] () -- C:\Windows\hpoins45.dat [2011-02-11 18:40:40 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll [2010-12-29 09:18:28 | 000,002,432 | ---- | C] () -- C:\Users\karolek\AppData\Local\TempVrU912.html [2010-12-29 09:18:28 | 000,002,089 | ---- | C] () -- C:\Users\karolek\AppData\Local\TempGWc912.html [2010-08-25 19:30:02 | 000,439,308 | ---- | C] () -- C:\Windows\System32\igcompkrng500.bin [2010-08-25 19:30:00 | 000,982,240 | ---- | C] () -- C:\Windows\System32\igkrng500.bin [2010-08-25 19:30:00 | 000,092,356 | ---- | C] () -- C:\Windows\System32\igfcg500m.bin [2010-08-25 18:57:00 | 000,000,151 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config [color=#E56717]========== LOP Check ==========[/color] [2008-05-12 23:27:42 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Acer GameZone Console [2008-05-12 23:27:42 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Acer GameZone Console [2010-03-19 21:53:58 | 000,000,000 | -HSD | M] -- C:\Users\karolek\AppData\Roaming\.# [2012-03-12 21:07:22 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\abelhadigital.com [2008-05-12 23:27:42 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\Acer GameZone Console [2012-01-12 09:13:05 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\Babylon [2009-03-06 12:18:46 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\Big Fish Games [2011-07-25 08:32:47 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\Dropbox [2009-02-26 20:33:15 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\eSobi [2009-03-06 12:03:43 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\FloodLightGames [2010-11-28 08:51:37 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\Gadu-Gadu 10 [2012-03-12 19:23:22 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\GHISLER [2009-10-29 20:57:12 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\Leadertech [2010-10-22 12:52:42 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\Nowe Gadu-Gadu [2011-08-02 08:38:57 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\OpenFM [2010-10-22 11:53:46 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\Opera [2009-12-29 11:54:40 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\PC Suite [2010-01-11 12:58:16 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\PTC [2009-12-16 15:23:42 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\ReliaSoft [2009-12-29 11:48:45 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\Samsung [2010-10-20 23:00:26 | 000,000,000 | -HSD | M] -- C:\Users\karolek\AppData\Roaming\Smart Engine [2012-01-12 09:13:16 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\SumatraPDF [2012-03-12 13:51:23 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\TuneUp Software [2011-08-01 07:47:08 | 000,000,000 | ---D | M] -- C:\Users\karolek\AppData\Roaming\YoudaGames [2012-03-12 17:10:37 | 000,000,594 | ---- | M] () -- C:\Windows\Tasks\Automatyczna konserwacja.job [2010-10-22 11:44:57 | 000,000,510 | ---- | M] () -- C:\Windows\Tasks\Install.job [2011-10-03 12:49:55 | 000,032,546 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2012-01-31 18:33:23 | 000,000,436 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{44C9B47C-FE2B-456C-8C39-057A11B7BD52}.job [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:8AB6C1D7 @Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:E36F5B57 @Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:4F636E25 @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:FEBEC560 @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:B623B5B8 @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:4CF61E54 @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:9F683177 @Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:861A898F @Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:4BB26BE9 @Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:793F316E @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:C95B63DA @Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:8173A019 < End of report >