OTL logfile created on: 2012-07-02 19:57:42 - Run 3 OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Kasia&Paweł\Desktop Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.19088) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,93 Gb Total Physical Memory | 0,76 Gb Available Physical Memory | 39,40% Memory free 4,09 Gb Paging File | 2,81 Gb Available in Paging File | 68,59% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files Drive C: | 222,88 Gb Total Space | 157,21 Gb Free Space | 70,54% Space Free | Partition Type: NTFS Drive D: | 9,00 Gb Total Space | 2,12 Gb Free Space | 23,59% Space Free | Partition Type: NTFS Drive F: | 1021,00 Mb Total Space | 1018,74 Mb Free Space | 99,78% Space Free | Partition Type: FAT32 Computer Name: KASIAPAWEŁ | User Name: Kasia&Paweł | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe () PRC - C:\Users\Kasia&Paweł\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files\AVG\AVG2012\avgrsx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG2012\avgemcx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Program Files\AVG\AVG2012\avgcsrvx.exe (AVG Technologies CZ, s.r.o.) PRC - C:\Windows\System32\rpcnet.exe (Absolute Software Corp.) PRC - C:\Program Files\ALLPlayer\ALLUpdate.exe () PRC - C:\Windows\explorer.exe (Microsoft Corporation) PRC - c:\Program Files\Hewlett-Packard\IAM\Bin\asghost.exe (Bioscrypt Inc.) PRC - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe (Hewlett-Packard Development Company, L.P) PRC - c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe (SafeBoot International) PRC - C:\Program Files\PDF Complete\pdfsvc.exe (PDF Complete Inc) PRC - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe (Hewlett-Packard Development Company, L.P.) PRC - C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe (Hewlett-Packard) PRC - C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe (Hewlett-Packard) PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation) PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) PRC - C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard) PRC - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe ( Hewlett-Packard Development Company, L.P.) PRC - C:\Windows\System32\lpksetup.exe (Microsoft Corporation) PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems) PRC - C:\Windows\System32\AEADISRV.EXE (Andrea Electronics Corporation) PRC - c:\Program Files\ActivIdentity\ActivClient\accoca.exe (ActivIdentity) PRC - c:\Program Files\ActivIdentity\ActivClient\acevents.exe (ActivIdentity) PRC - C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe (ActivIdentity) PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo) PRC - C:\Program Files\Common Files\Siemens\S7UBTOOX\S7ubTstx.exe (SIEMENS AG) PRC - C:\Program Files\Common Files\Siemens\SQLANY\dbsrv7.exe (Sybase, Inc.) [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\cfb60f99da570cc494e27e0e8ee747e2\System.Xml.ni.dll () MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\381fb23cb39e1a61e13b8770eb9800ba\System.Windows.Forms.ni.dll () MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\f1aa2385c0109f3059e0e6ba8b58ff68\System.Drawing.ni.dll () MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System\9dff86a62a525ec8dc827fe9f50298b7\System.ni.dll () MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\0309936a8e1672d39b9cf14463ce69f9\mscorlib.ni.dll () MOD - C:\Program Files\ALLPlayer\ALLUpdate.exe () MOD - C:\windows\assembly\GAC_MSIL\System.Xml.resources\2.0.0.0_pl_b77a5c561934e089\System.Xml.resources.dll () MOD - C:\windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pl_b77a5c561934e089\mscorlib.resources.dll () MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll () MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll () MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll () [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - (vToolbarUpdater11.0.2) -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe () SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) SRV - (AVGIDSAgent) -- C:\Program Files\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.) SRV - (avgwd) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) SRV - (rpcnet) Remote Procedure Call (RPC) -- C:\Windows\System32\rpcnet.exe (Absolute Software Corp.) SRV - (ASBroker) -- c:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll (Bioscrypt Inc.) SRV - (ASChannel) -- c:\Program Files\Hewlett-Packard\IAM\Bin\ASChnl.dll (Bioscrypt Inc.) SRV - (HP ProtectTools Service) -- c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe (Hewlett-Packard Development Company, L.P) SRV - (HpFkCryptService) -- c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe (SafeBoot International) SRV - (pdfcDispatcher) -- C:\Program Files\PDF Complete\pdfsvc.exe (PDF Complete Inc) SRV - (HPFSService) -- C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe (Hewlett-Packard) SRV - (IAANTMON) Intel(R) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation) SRV - (RoxMediaDB10) -- c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions) SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems) SRV - (AEADIFilters) -- C:\Windows\System32\AEADISRV.EXE (Andrea Electronics Corporation) SRV - (accoca) -- c:\Program Files\ActivIdentity\ActivClient\accoca.exe (ActivIdentity) SRV - (IviRegMgr) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found DRV - (ao00jy2w) -- File not found DRV - (AVGIDSHX) -- C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o. ) DRV - (Avgtdix) -- C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.) DRV - (Avgldx86) -- C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.) DRV - (Avgrkx86) -- C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.) DRV - (Avgmfx86) -- C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.) DRV - (AVGIDSShim) -- C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o. ) DRV - (AVGIDSFilter) -- C:\Windows\System32\drivers\avgidsfilterx.sys (AVG Technologies CZ, s.r.o. ) DRV - (AVGIDSDriver) -- C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o. ) DRV - (sptd) -- C:\Windows\System32\drivers\sptd.sys () DRV - (io.sys) -- C:\Windows\System32\drivers\io.sys () DRV - (libusb0) -- C:\Windows\System32\drivers\libusb0.sys (http://libusb-win32.sourceforge.net) DRV - (SbAlg) -- C:\windows\System32\drivers\SbAlg.sys (SafeBoot N.V.) DRV - (SbFsLock) -- C:\windows\System32\drivers\SbFsLock.sys (SafeBoot International) DRV - (RsvLock) -- C:\windows\System32\drivers\rsvlock.sys (SafeBoot International) DRV - (SafeBoot) -- C:\windows\System32\drivers\SafeBoot.sys () DRV - (HBtnKey) -- C:\Windows\System32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.) DRV - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) -- C:\Windows\System32\drivers\snp2uvc.sys () DRV - (hpdskflt) -- C:\Windows\System32\drivers\hpdskflt.sys (Hewlett-Packard Corporation) DRV - (Accelerometer) -- C:\Windows\System32\drivers\Accelerometer.sys (Hewlett-Packard Corporation) DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems) DRV - (TPM) -- C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation) DRV - (HpqKbFiltr) -- C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.) DRV - (e4usbaw) -- C:\Windows\System32\drivers\e4usbaw.sys (Analog Devices Inc.) DRV - (E4LOADER) General Purpose USB Driver (e4ldr.sys) -- C:\Windows\System32\drivers\e4ldr.sys (Analog Deivces) DRV - (TVicPort) -- C:\windows\System32\drivers\TVicPort.sys (EnTech Taiwan) DRV - (Dpmtrcdd) -- C:\Windows\System32\drivers\dpmtrcdd.sys (Siemens AG) DRV - (s7oefs_x) -- C:\Windows\System32\drivers\s7oefs_x.sys (SIEMENS AG) DRV - (IOPort) -- C:\Windows\System32\drivers\IOPORT.SYS (Erik Salaj) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\..\URLSearchHook: {e8de9422-3b2c-4243-bf6f-235da84d8ef8} - No CLSID value found IE - HKCU\..\SearchScopes,DefaultScope = {57E2A3A9-05DD-47CD-B7C4-E626EDCF06C8} IE - HKCU\..\SearchScopes\{57E2A3A9-05DD-47CD-B7C4-E626EDCF06C8}: "URL" = http://www.google.pl/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}&rlz=1I7ADSA_plPL393 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaulturl: "" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "www.google.pl" FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Kasia&Paweł\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files\AVG\AVG2012\Firefox\DoNotTrack\ [2012-07-02 18:10:25 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-07-01 17:58:34 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-07-01 17:58:34 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-04-07 12:38:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kasia&Paweł\AppData\Roaming\mozilla\Extensions [2012-07-02 19:24:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kasia&Paweł\AppData\Roaming\mozilla\Firefox\Profiles\00i9i2s5.default\extensions [2011-07-10 10:23:56 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2012-07-01 17:58:34 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012-07-01 17:58:29 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2012-07-01 17:58:29 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2012-07-01 17:58:29 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2012-07-01 17:58:29 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2012-07-01 17:58:29 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2012-07-01 17:58:29 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml [color=#E56717]========== Chrome ==========[/color] O1 HOSTS File: ([2011-07-04 21:49:37 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.) O2 - BHO: (BHO_Startup Class) - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll (Hewlett-Packard) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.) O2 - BHO: (Credential Manager for HP ProtectTools) - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll (Bioscrypt Inc.) O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\ProgramData\Gadu-Gadu 10\_userdata\ggbho.2.dll (GG Network S.A.) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E8DE9422-3B2C-4243-BF6F-235DA84D8EF8} - No CLSID value found. O4 - HKLM..\Run: [accrdsub] c:\Program Files\ActivIdentity\ActivClient\accrdsub.exe (ActivIdentity) O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [CognizanceTS] c:\Program Files\Hewlett-Packard\IAM\Bin\ASTSVCC.dll (Bioscrypt Inc.) O4 - HKLM..\Run: [File Sanitizer] C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe (Hewlett-Packard) O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard) O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) O4 - HKLM..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe (PDF Complete Inc) O4 - HKLM..\Run: [PTHOSTTR] c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE (Hewlett-Packard Development Company, L.P.) O4 - HKLM..\Run: [S7UB Start] C:\Program Files\Common Files\Siemens\S7ubtoox\s7ubtstx.exe (SIEMENS AG) O4 - HKLM..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe" File not found O4 - HKLM..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.) O4 - HKCU..\Run: [ALLUpdate] C:\Program Files\ALLPlayer\ALLUpdate.exe () O4 - HKCU..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8 - Extra context menu item: Funkcja Google Sidewiki - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.) O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab (Java Plug-in 1.6.0_06) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.) O20 - AppInit_DLLs: (APSHook.dll) - C:\windows\System32\APSHook.dll (Bioscrypt Inc.) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\Kasia&Paweł\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta z Galerii fotografii systemu Windows.jpg O24 - Desktop BackupWallPaper: C:\Users\Kasia&Paweł\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta z Galerii fotografii systemu Windows.jpg O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-07-02 19:43:48 | 000,000,000 | ---D | C] -- C:\_OTL [2012-07-02 19:41:06 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Secure Search [2012-07-02 19:29:30 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2012-07-02 18:12:30 | 000,000,000 | ---D | C] -- C:\Users\Kasia&Paweł\AppData\Roaming\AVG2012 [2012-07-02 18:11:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG [2012-07-02 18:11:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AVG Secure Search [2012-07-02 18:09:42 | 000,000,000 | -H-D | C] -- C:\$AVG [2012-07-02 18:09:41 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2012 [2012-07-02 18:09:41 | 000,000,000 | ---D | C] -- C:\windows\System32\drivers\AVG [2012-07-02 18:08:02 | 000,000,000 | ---D | C] -- C:\Program Files\AVG [2012-07-02 17:16:51 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files [2012-07-02 17:16:26 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData [2012-07-02 17:10:39 | 000,000,000 | ---D | C] -- C:\windows\pss [2012-07-02 16:55:40 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2012-07-02 15:22:20 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Kasia&Paweł\Desktop\OTL.exe [2012-06-29 10:50:20 | 000,000,000 | ---D | C] -- C:\Users\Kasia&Paweł\AppData\Roaming\hellomoto [2012-06-02 20:16:22 | 000,000,000 | ---D | C] -- C:\Users\Kasia&Paweł\Desktop\program do bramy [2011-08-18 18:11:47 | 002,081,832 | ---- | C] (DownVision ) -- C:\Users\Kasia&Paweł\AppData\Local\setup.exe [2010-10-25 11:39:51 | 000,333,128 | ---- | C] (FTDI Ltd) -- C:\Program Files\ftd2xx64.dll [2010-10-25 11:39:51 | 000,176,128 | ---- | C] (FTDI Ltd) -- C:\Program Files\Ftd2xx.dll [2010-10-25 11:39:51 | 000,176,128 | ---- | C] (FTDI Ltd) -- C:\Program Files\FTD2XNT.DLL [2010-10-25 11:39:51 | 000,081,920 | ---- | C] (FTDI Ltd) -- C:\Program Files\FTD2X98.DLL [2010-10-25 11:39:51 | 000,061,440 | ---- | C] (FTDI Ltd) -- C:\Program Files\FtChipId.dll [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-07-02 19:56:09 | 000,000,374 | ---- | M] () -- C:\windows\System32\drivers\etc\hosts.ics [2012-07-02 19:55:37 | 000,017,408 | ---- | M] () -- C:\windows\System32\rpcnetp.exe [2012-07-02 19:55:34 | 000,058,288 | ---- | M] (Absolute Software Corp.) -- C:\windows\System32\rpcnet.dll [2012-07-02 19:55:27 | 000,001,032 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job [2012-07-02 19:54:05 | 000,003,216 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2012-07-02 19:54:03 | 000,003,216 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2012-07-02 19:53:14 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat [2012-07-02 19:53:11 | 2073,313,280 | -HS- | M] () -- C:\hiberfil.sys [2012-07-02 19:47:24 | 000,000,012 | ---- | M] () -- C:\windows\bthservsdp.dat [2012-07-02 19:42:56 | 000,000,680 | ---- | M] () -- C:\Users\Kasia&Paweł\AppData\Local\d3d9caps.dat [2012-07-02 19:33:37 | 000,001,036 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job [2012-07-02 18:11:30 | 000,000,872 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2012.lnk [2012-07-02 18:10:55 | 100,725,600 | ---- | M] () -- C:\windows\System32\drivers\AVG\incavi.avm [2012-07-02 18:05:51 | 000,714,424 | ---- | M] () -- C:\windows\System32\perfh015.dat [2012-07-02 18:05:51 | 000,634,400 | ---- | M] () -- C:\windows\System32\perfh009.dat [2012-07-02 18:05:51 | 000,152,468 | ---- | M] () -- C:\windows\System32\perfc015.dat [2012-07-02 18:05:51 | 000,119,964 | ---- | M] () -- C:\windows\System32\perfc009.dat [2012-07-02 17:09:41 | 000,000,765 | ---- | M] () -- C:\Users\Kasia&Paweł\Documents\Moje foldery udostępniania.lnk [2012-07-02 17:02:40 | 000,002,577 | ---- | M] () -- C:\windows\System32\config.nt [2012-07-02 16:55:41 | 000,000,804 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2012-07-02 15:22:24 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Kasia&Paweł\Desktop\OTL.exe [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-07-02 18:11:30 | 000,000,872 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2012.lnk [2012-07-02 17:09:41 | 000,000,765 | ---- | C] () -- C:\Users\Kasia&Paweł\Documents\Moje foldery udostępniania.lnk [2012-07-02 16:55:41 | 000,000,804 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2012-06-29 12:19:40 | 2073,313,280 | -HS- | C] () -- C:\hiberfil.sys [2012-06-26 08:39:38 | 100,725,600 | ---- | C] () -- C:\windows\System32\drivers\AVG\incavi.avm [2011-11-22 16:47:34 | 000,077,824 | ---- | C] () -- C:\windows\System32\GkSui20.EXE [2011-09-01 19:46:54 | 000,000,669 | ---- | C] () -- C:\windows\basavr.ini [2011-09-01 18:18:31 | 000,012,466 | ---- | C] () -- C:\Users\Kasia&Paweł\AppData\Roaming\bascom-avr.xml [2011-08-30 17:33:55 | 000,000,012 | ---- | C] () -- C:\windows\MPIKABELMANAGER.INI [2011-07-14 10:47:46 | 000,000,127 | ---- | C] () -- C:\windows\System32\MRT.INI [2011-07-12 12:13:19 | 000,000,000 | ---- | C] () -- C:\Users\Kasia&Paweł\AppData\Local\{45A5577A-BC47-443B-8120-89A0EA6D31AC} [2011-07-11 19:33:36 | 000,000,000 | ---- | C] () -- C:\windows\System32\AUTOCHK.EXE [2011-07-04 21:19:57 | 000,256,000 | ---- | C] () -- C:\windows\PEV.exe [2011-07-04 21:19:57 | 000,208,896 | ---- | C] () -- C:\windows\MBR.exe [2011-07-04 21:19:57 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe [2011-07-04 21:19:57 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe [2011-07-04 21:19:57 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe [2011-07-04 15:11:03 | 000,000,000 | ---- | C] () -- C:\Users\Kasia&Paweł\AppData\Local\{4F61ED0E-9108-4432-92D3-2C14D68329F0} [2011-07-02 17:50:08 | 000,000,000 | ---- | C] () -- C:\Users\Kasia&Paweł\AppData\Local\{DB70B8A6-A59B-470A-89D2-C37A299551E1} [2011-07-02 13:09:08 | 000,000,000 | ---- | C] () -- C:\Users\Kasia&Paweł\AppData\Local\{C1C34A0A-BD89-44AC-8AD1-E0246F8A65A7} [2011-07-01 21:53:04 | 000,000,000 | ---- | C] () -- C:\Users\Kasia&Paweł\AppData\Local\{42BFFB15-8EA7-412E-89B1-CA4D629C05EA} [2011-06-30 22:51:40 | 000,000,000 | ---- | C] () -- C:\Users\Kasia&Paweł\AppData\Local\{4309166F-B0DE-45A9-AA88-9A32F19D3AA8} [2011-06-25 09:38:06 | 000,000,000 | ---- | C] () -- C:\Users\Kasia&Paweł\AppData\Local\{930F3B82-C665-428F-A1AB-67BBDDB38118} [2011-06-12 10:00:38 | 000,000,000 | ---- | C] () -- C:\Users\Kasia&Paweł\AppData\Local\{FA20F6B5-B106-40AF-9B65-F7290770657F} [2011-05-12 16:53:58 | 000,000,000 | R--- | C] () -- C:\Users\Kasia&Paweł\Desktop\Automatyka\crococlip20\@ [2011-04-22 10:57:41 | 000,569,450 | ---- | C] () -- C:\windows\System32\steveshoutcast.dll [2011-04-22 10:57:39 | 000,045,056 | ---- | C] () -- C:\windows\System32\AspiShim.dll [2010-11-29 17:44:24 | 000,000,680 | ---- | C] () -- C:\Users\Kasia&Paweł\AppData\Local\d3d9caps.dat [2010-11-25 17:58:03 | 000,258,048 | ---- | C] () -- C:\windows\System32\libFLAC.dll [2010-11-25 17:38:52 | 000,165,376 | ---- | C] () -- C:\windows\System32\unrar.dll [2010-11-14 19:42:53 | 000,000,076 | ---- | C] () -- C:\windows\iltwain.ini [2010-10-25 11:45:22 | 000,000,829 | ---- | C] () -- C:\ProgramData\qcaddemorc [2010-10-25 11:39:51 | 010,346,496 | ---- | C] () -- C:\Program Files\DWG.EXE [2010-10-25 11:39:51 | 005,443,072 | ---- | C] () -- C:\Program Files\LANCELOT.EXE [2010-10-25 11:39:51 | 004,724,224 | ---- | C] () -- C:\Program Files\KAY.EXE [2010-10-25 11:39:51 | 004,688,384 | ---- | C] () -- C:\Program Files\KYNON.EXE [2010-10-25 11:39:51 | 000,156,160 | ---- | C] () -- C:\Program Files\COPYRUN.EXE [2010-10-25 11:39:51 | 000,124,767 | ---- | C] () -- C:\Program Files\DOWNLOAD.EXE [2010-10-25 11:39:51 | 000,000,000 | ---- | C] () -- C:\Program Files\GAHERIET.EXE [2010-08-22 12:08:33 | 000,000,099 | ---- | C] () -- C:\Users\Kasia&Paweł\AppData\Local\fusioncache.dat [2010-07-29 14:26:17 | 000,012,288 | ---- | C] () -- C:\Users\Kasia&Paweł\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010-07-26 16:47:08 | 000,000,000 | ---- | C] () -- C:\windows\s7alibxx.INI [2010-07-26 16:10:43 | 000,000,000 | ---- | C] () -- C:\windows\S7USFAPX.INI [2010-07-25 12:49:14 | 000,000,027 | ---- | C] () -- C:\windows\s7esApiX.INI [2010-07-22 17:48:41 | 000,000,291 | ---- | C] () -- C:\windows\Microwin.ini [2010-07-21 17:47:48 | 000,040,960 | ---- | C] () -- C:\windows\System32\cp551inf.dll [2010-03-21 13:08:59 | 000,000,000 | ---- | C] () -- C:\windows\System32\crococlip20\@ [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 22528 bytes -> C:\windows\System32\AUTOCHK.EXE:BAK @Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:29C60577 @Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:E3E746AD @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:5BCD33F0 < End of report >