OTL logfile created on: 2012-04-29 15:44:39 - Run 1 OTL by OldTimer - Version 3.2.42.2 Folder = C:\Documents and Settings\Michał\Moje dokumenty\Tutoriale Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1023,48 Mb Total Physical Memory | 685,64 Mb Available Physical Memory | 66,99% Memory free 2,40 Gb Paging File | 2,21 Gb Available in Paging File | 91,86% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 24,42 Gb Total Space | 13,90 Gb Free Space | 56,93% Space Free | Partition Type: NTFS Drive D: | 24,41 Gb Total Space | 20,74 Gb Free Space | 84,97% Space Free | Partition Type: NTFS Drive E: | 25,72 Gb Total Space | 16,16 Gb Free Space | 62,83% Space Free | Partition Type: NTFS Computer Name: DOM-B25159A53EC | User Name: Michał | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-04-29 15:42:34 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Michał\Moje dokumenty\Tutoriale\OTL.exe PRC - [2012-03-07 02:15:17 | 004,241,512 | ---- | M] (AVAST Software) -- E:\Programy\avast! Free Antivirus\AvastUI.exe PRC - [2012-03-07 02:15:14 | 000,044,768 | ---- | M] (AVAST Software) -- E:\Programy\avast! Free Antivirus\AvastSvc.exe PRC - [2008-04-15 14:00:00 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012-04-29 08:20:08 | 001,771,520 | ---- | M] () -- E:\Programy\avast! Free Antivirus\defs\12042900\algo.dll MOD - [2012-04-04 07:54:04 | 000,300,544 | ---- | M] () -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.POL [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ) SRV - [2012-04-15 11:13:11 | 000,253,088 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012-03-07 02:15:14 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- E:\Programy\avast! Free Antivirus\AvastSvc.exe -- (avast! Antivirus) SRV - [2009-02-26 19:36:22 | 000,064,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Programy\Microsoft Office 2007\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\VBoxNetFlt.sys -- (VBoxNetFlt) DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\MICHA~1\USTAWI~1\Temp\uftyrkoc.sys -- (uftyrkoc) DRV - File not found [File_System | Auto | Stopped] -- -- (StarOpen) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\EagleNT.sys -- (EagleNT) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2012-04-03 14:47:54 | 000,104,752 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VBoxNetAdp.sys -- (VBoxNetAdp) DRV - [2012-03-07 02:03:51 | 000,612,184 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2012-03-07 02:03:38 | 000,337,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP) DRV - [2012-03-07 02:02:00 | 000,035,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr) DRV - [2012-03-07 02:01:53 | 000,053,848 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2012-03-07 02:01:39 | 000,095,704 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2) DRV - [2012-03-07 02:01:30 | 000,020,696 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2012-03-07 01:58:29 | 000,024,920 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4) DRV - [2012-02-23 18:11:24 | 000,024,408 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswKbd.sys -- (aswKbd) DRV - [2011-11-29 16:10:51 | 000,239,168 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV - [2006-05-03 18:50:42 | 001,540,608 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag) DRV - [2003-03-25 11:50:46 | 000,004,096 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\siside.sys -- (SiSide) DRV - [2003-02-20 03:18:36 | 000,036,608 | R--- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\SISAGPX.SYS -- (SISAGP) DRV - [2002-10-17 09:14:46 | 000,049,024 | R--- | M] (Windows (R) 2000 DDK provider) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\sisidex.sys -- (sisidex) DRV - [2002-08-20 11:19:08 | 000,009,472 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sisperf.sys -- (sisperf) DRV - [2002-07-10 17:39:34 | 000,032,256 | R--- | M] (SiS Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisnic.sys -- (SISNIC) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1547161642-1677128483-1177238915-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ IE - HKU\S-1-5-21-1547161642-1677128483-1177238915-1003\..\SearchScopes,DefaultScope = {0ADF9B48-0F42-4278-B89B-8BCB3A45B988} IE - HKU\S-1-5-21-1547161642-1677128483-1177238915-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-1547161642-1677128483-1177238915-1003\..\SearchScopes\{0ADF9B48-0F42-4278-B89B-8BCB3A45B988}: "URL" = http://www.google.pl/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} IE - HKU\S-1-5-21-1547161642-1677128483-1177238915-1003\..\SearchScopes\{24CDD26D-9AA0-46E7-BE90-2CFFC4CA9DBC}: "URL" = http://www.ceneo.pl/categories.aspx?search=yes&categoryID=0&searchText={searchTerms}&inDesc=False&minPrice=0&maxPrice=99999999 IE - HKU\S-1-5-21-1547161642-1677128483-1177238915-1003\..\SearchScopes\{FB0B999A-E913-402D-8ACB-8FDB15498E2D}: "URL" = http://pl.wikipedia.org/w/index.php?title=Specjalna:Szukaj&search={searchTerms} IE - HKU\S-1-5-21-1547161642-1677128483-1177238915-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "www.google.pl" FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: E:\Programy\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: E:\Programy\Java\bin\new_plugin\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Michał\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Michał\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\crossriderapp1466@crossrider.com: C:\Documents and Settings\All Users\Dane aplikacji\SendSpaceExtention\firefox [2011-10-25 15:01:55 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: E:\Programy\avast! Free Antivirus\WebRep\FF [2012-03-15 18:13:56 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: E:\Programy\Mozilla Firefox\components [2012-03-15 16:49:48 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: E:\Programy\Mozilla Firefox\plugins [2012-02-27 16:36:19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Michał\Dane aplikacji\Mozilla\Extensions [2012-04-26 18:16:21 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Michał\Dane aplikacji\Mozilla\Firefox\Profiles\eg68dwul.default\extensions File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\MICHAĹ‚\DANE APLIKACJI\MOZILLA\FIREFOX\PROFILES\EG68DWUL.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI [2012-03-15 18:13:56 | 000,000,000 | ---D | M] (avast! WebRep) -- E:\PROGRAMY\AVAST! FREE ANTIVIRUS\WEBREP\FF [color=#E56717]========== Chrome ==========[/color] CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms} CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Micha\u0142\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\18.0.1025.151\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Micha\u0142\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\18.0.1025.151\pdf.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Micha\u0142\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\18.0.1025.151\gcswf32.dll CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Micha\u0142\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll CHR - plugin: Java(TM) Platform SE 7 U2 (Enabled) = E:\Programy\Java\bin\new_plugin\npjp2.dll CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Micha\u0142\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.79\npGoogleUpdate3.dll CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll CHR - plugin: DivX VOD Helper Plug-in (Enabled) = E:\Programy\DivX\DivX OVS Helper\npovshelper.dll CHR - Extension: AdBlock = C:\Documents and Settings\Michał\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.32_0\ CHR - Extension: avast! WebRep = C:\Documents and Settings\Michał\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1426_0\ O1 HOSTS File: ([2008-04-15 14:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Programy\Microsoft Office 2007\Office12\GrooveShellExtensions.dll (Microsoft Corporation) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Programy\avast! Free Antivirus\aswWebRepIE.dll (AVAST Software) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Programy\Java\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Programy\avast! Free Antivirus\aswWebRepIE.dll (AVAST Software) O4 - HKLM..\Run: [avast] E:\Programy\avast! Free Antivirus\avastUI.exe (AVAST Software) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1547161642-1677128483-1177238915-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0 O7 - HKU\S-1-5-21-1547161642-1677128483-1177238915-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3 O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - E:\Programy\Microsoft Office 2007\Office12\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Programy\Microsoft Office 2007\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Programy\Microsoft Office 2007\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\Programy\Microsoft Office 2007\Office12\REFIEBAR.DLL (Microsoft Corporation) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1310559961765 (MUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 1.7.0_02) O16 - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 1.7.0_02) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 1.7.0_02) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 109.199.15.2 109.199.16.2 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AEA45BCA-B626-4E86-8769-3B5D65D49839}: DhcpNameServer = 109.199.15.2 109.199.16.2 O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\Programy\Microsoft Office 2007\Office12\GrooveSystemServices.dll (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\Michał\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Michał\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - E:\Programy\Microsoft Office 2007\Office12\GrooveShellExtensions.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2011-07-12 18:56:38 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2012-04-22 10:17:03 | 000,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2012-04-22 10:17:03 | 000,000,000 | RHSD | M] - D:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2012-04-22 10:17:03 | 000,000,000 | RHSD | M] - E:\autorun.inf -- [ NTFS ] O33 - MountPoints2\{35ec8415-e52f-11e0-b89c-000d8734d2f1}\Shell - "" = AutoRun O33 - MountPoints2\{35ec8415-e52f-11e0-b89c-000d8734d2f1}\Shell\AutoRun\command - "" = H:\setup.exe /autorun O33 - MountPoints2\{35ec8415-e52f-11e0-b89c-000d8734d2f1}\Shell\directx\command - "" = H:\DirectX\dxsetup.exe O33 - MountPoints2\{35ec8415-e52f-11e0-b89c-000d8734d2f1}\Shell\setup\command - "" = H:\setup.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-04-27 11:05:56 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Michał\Recent [2012-04-27 09:02:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michał\DoctorWeb [2012-04-25 10:58:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michał\VirtualBox VMs [2012-04-25 10:58:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michał\.VirtualBox [2012-04-24 16:00:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\nLite [2012-04-22 10:17:03 | 000,000,000 | RHSD | C] -- C:\autorun.inf [2012-04-11 17:31:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michał\Moje dokumenty\Tutoriale [2012-04-05 11:02:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\WinRAR [2012-04-05 11:02:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michał\Menu Start\Programy\WinRAR [2012-04-03 18:03:29 | 000,418,464 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe [2012-04-03 14:47:54 | 000,104,752 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\drivers\VBoxNetAdp.sys [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-04-29 15:12:16 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2012-04-29 15:10:47 | 000,457,526 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2012-04-29 15:10:47 | 000,400,464 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012-04-29 15:10:47 | 000,077,464 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2012-04-29 15:10:47 | 000,060,624 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2012-04-29 15:06:58 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012-04-29 15:06:36 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012-04-29 15:06:34 | 1073,270,784 | -HS- | M] () -- C:\hiberfil.sys [2012-04-27 12:09:49 | 000,267,800 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012-04-27 08:46:57 | 000,023,758 | ---- | M] () -- C:\Documents and Settings\Michał\Moje dokumenty\cc_20120427_084654.reg [2012-04-15 11:13:11 | 000,418,464 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe [2012-04-15 11:13:11 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl [2012-04-11 20:28:10 | 000,002,653 | ---- | M] () -- C:\Documents and Settings\Michał\Pulpit\~Aleph373291.htm [2012-04-03 14:47:54 | 000,158,512 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\drivers\VBoxDrv.sys [2012-04-03 14:47:54 | 000,104,752 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\drivers\VBoxNetAdp.sys [2012-04-03 14:47:54 | 000,091,952 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\drivers\VBoxUSBMon.sys [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-04-27 12:09:49 | 000,267,800 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012-04-27 08:46:56 | 000,023,758 | ---- | C] () -- C:\Documents and Settings\Michał\Moje dokumenty\cc_20120427_084654.reg [2012-04-11 20:28:16 | 000,002,653 | ---- | C] () -- C:\Documents and Settings\Michał\Pulpit\~Aleph373291.htm [2012-04-03 18:03:31 | 000,000,930 | ---- | C] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2012-02-21 14:26:54 | 000,001,769 | ---- | C] () -- C:\WINDOWS\Language_trs.ini [2012-02-15 13:44:05 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2011-09-23 17:54:22 | 000,000,555 | ---- | C] () -- C:\WINDOWS\eReg.dat [2011-08-14 07:40:39 | 000,109,216 | ---- | C] () -- C:\WINDOWS\System32\EasyHook64.dll [2011-08-14 07:40:39 | 000,090,784 | ---- | C] () -- C:\WINDOWS\System32\EasyHook32.dll [2011-07-26 10:10:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PowerReg.dat [2011-07-13 19:33:49 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\CNMVS53.DLL [2011-07-13 13:28:03 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\xmltok.dll [2011-07-13 13:28:03 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\xmlparse.dll [2011-07-12 20:45:38 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2011-07-12 20:16:22 | 000,175,616 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2011-07-12 20:16:21 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini [2011-07-12 20:16:20 | 000,644,608 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2011-07-12 20:16:20 | 000,243,200 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2011-07-12 20:16:20 | 000,073,216 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2011-07-12 20:13:57 | 000,018,432 | ---- | C] () -- C:\Documents and Settings\Michał\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011-07-12 19:21:03 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe [2011-07-12 19:20:20 | 000,001,020 | ---- | C] () -- C:\WINDOWS\ATICIM.INI [2011-07-12 19:09:20 | 000,000,092 | ---- | C] () -- C:\WINDOWS\CMISETUP.INI [2011-07-12 19:09:19 | 000,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI [2011-07-12 19:09:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Wininit.ini [2011-07-12 19:09:17 | 001,900,544 | ---- | C] () -- C:\WINDOWS\System32\cmiwcnfg.dll [2011-07-12 19:09:17 | 000,221,184 | ---- | C] () -- C:\WINDOWS\System32\cmirmdrv.exe [2011-07-12 19:09:17 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\cmirmdrv.dll [2011-07-12 19:09:16 | 000,059,998 | ---- | C] () -- C:\WINDOWS\Cmuda.ini [2011-07-12 19:09:12 | 000,266,240 | ---- | C] () -- C:\WINDOWS\CMIUninstall.exe [2011-07-12 19:09:11 | 000,225,280 | ---- | C] () -- C:\WINDOWS\CmiRmRedundDir.exe [2011-07-12 19:09:11 | 000,028,672 | ---- | C] () -- C:\WINDOWS\CMIRmDriver.dll [2011-07-12 18:59:28 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2011-07-12 18:52:59 | 000,021,856 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [color=#E56717]========== LOP Check ==========[/color] [2012-03-15 18:13:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\AVAST Software [2011-10-18 09:47:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Canneverbe Limited [2012-01-15 16:50:27 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonBJ [2012-01-15 16:57:26 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonEPP [2012-01-16 08:59:19 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJEGV [2012-01-15 16:57:26 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJEPPEX2 [2012-01-15 16:54:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJMSetup [2012-02-20 19:16:14 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJScan [2012-01-15 16:53:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonIJWSpt [2011-11-29 16:09:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite [2011-10-25 15:02:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\InstallMate [2011-10-25 14:58:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Premium [2011-10-25 15:01:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\SendSpaceExtention [2011-08-14 07:45:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP [2011-11-10 17:04:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michał\Dane aplikacji\Audacity [2011-11-21 17:38:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michał\Dane aplikacji\Canneverbe Limited [2012-02-20 19:16:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michał\Dane aplikacji\Canon [2012-04-27 11:06:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michał\Dane aplikacji\DAEMON Tools Lite [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:553CA6CA < End of report >