OTL logfile created on: 2012-07-12 00:03:48 - Run 2 OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\Mlody\Pulpit Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,25 Gb Total Physical Memory | 2,49 Gb Available Physical Memory | 76,54% Memory free 5,09 Gb Paging File | 4,48 Gb Available in Paging File | 88,08% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 232,88 Gb Total Space | 188,70 Gb Free Space | 81,03% Space Free | Partition Type: NTFS Drive D: | 232,88 Gb Total Space | 212,44 Gb Free Space | 91,22% Space Free | Partition Type: NTFS Computer Name: MLODY | User Name: Mlody | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-07-11 23:58:13 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mlody\Pulpit\OTL.exe PRC - [2012-06-16 00:27:34 | 000,874,384 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe PRC - [2012-06-16 00:27:34 | 000,800,656 | ---- | M] (Opera Software) -- C:\Program Files\Opera\pluginwrapper\opera_plugin_wrapper.exe PRC - [2011-07-04 19:45:30 | 013,374,048 | ---- | M] (GG Network S.A.) -- C:\Program Files\Gadu-Gadu 10\gg.exe PRC - [2010-09-27 12:58:24 | 001,528,616 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe PRC - [2010-03-25 20:07:00 | 000,147,472 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe PRC - [2010-03-25 20:07:00 | 000,124,224 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe PRC - [2010-03-25 20:07:00 | 000,070,728 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\system32\mfevtps.exe PRC - [2010-03-25 20:07:00 | 000,066,880 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe PRC - [2010-03-25 20:07:00 | 000,027,960 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe PRC - [2010-03-25 20:07:00 | 000,022,816 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe PRC - [2009-08-25 16:00:00 | 000,226,624 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\naPrdMgr.exe PRC - [2009-08-25 16:00:00 | 000,103,744 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe PRC - [2009-02-06 18:02:14 | 000,109,056 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe PRC - [2008-04-14 22:51:18 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007-10-12 17:03:30 | 000,598,016 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe PRC - [2007-10-12 17:03:06 | 000,151,552 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe PRC - [2006-03-03 22:03:10 | 000,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe PRC - [2004-12-13 05:34:32 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012-06-25 18:21:41 | 009,459,912 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll MOD - [2011-07-04 19:46:20 | 000,217,696 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\gglog.dll MOD - [2011-07-04 19:46:18 | 000,123,488 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggipcradioproxy.dll MOD - [2011-07-04 19:46:16 | 000,017,504 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggipc.dll MOD - [2011-07-04 19:46:12 | 000,027,744 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggcrypto.dll MOD - [2011-07-04 19:46:10 | 000,356,960 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggcommon.dll MOD - [2011-04-16 05:04:30 | 014,749,696 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtWebKit4.dll MOD - [2011-02-17 11:00:28 | 001,781,760 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtScript4.dll MOD - [2011-02-17 11:00:28 | 000,393,216 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtXml4.dll MOD - [2011-02-17 11:00:28 | 000,327,680 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtSvg4.dll MOD - [2011-02-17 11:00:26 | 001,044,480 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtNetwork4.dll MOD - [2011-02-17 11:00:24 | 009,097,216 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtGui4.dll MOD - [2011-02-17 11:00:24 | 002,560,000 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtCore4.dll MOD - [2011-02-17 10:59:40 | 000,311,296 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qtiff4.dll MOD - [2011-02-17 10:59:40 | 000,274,432 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qmng4.dll MOD - [2011-02-17 10:59:40 | 000,143,360 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qjpeg4.dll MOD - [2011-02-17 10:59:40 | 000,027,648 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qgif4.dll MOD - [2011-02-17 10:59:40 | 000,018,944 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qsvg4.dll MOD - [2011-02-17 10:59:32 | 000,059,904 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\zlib1.dll MOD - [2010-09-27 13:03:08 | 000,201,512 | ---- | M] () -- C:\WINDOWS\system32\vpnapi.dll MOD - [2009-08-25 16:00:00 | 000,057,344 | ---- | M] () -- C:\Program Files\McAfee\Common Framework\boost_thread-vc71-mt-1_32.dll MOD - [2009-02-27 20:04:20 | 000,311,296 | ---- | M] () -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\pdfshell.POL MOD - [2008-04-14 22:50:38 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll MOD - [2007-10-12 17:03:30 | 000,598,016 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe MOD - [2007-10-12 17:03:06 | 000,151,552 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe MOD - [2007-10-12 16:58:36 | 000,405,504 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll MOD - [2007-10-12 16:57:36 | 000,102,400 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll MOD - [2007-09-20 19:34:58 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll MOD - [2005-08-22 16:38:16 | 003,264,512 | ---- | M] () -- C:\Program Files\McAfee\Common Framework\cryptocme2.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ) SRV - [2012-07-11 23:21:06 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012-01-18 14:38:28 | 000,155,320 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Program Files\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion) SRV - [2010-09-27 12:58:24 | 001,528,616 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND) SRV - [2010-03-25 20:07:00 | 000,147,472 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe -- (McShield) SRV - [2010-03-25 20:07:00 | 000,070,728 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\WINDOWS\system32\mfevtps.exe -- (mfevtp) SRV - [2010-03-25 20:07:00 | 000,066,880 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe -- (McTaskManager) SRV - [2010-03-25 20:07:00 | 000,022,816 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe -- (McAfeeEngineService) SRV - [2009-08-25 16:00:00 | 000,103,744 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework) SRV - [2009-02-06 18:02:14 | 000,109,056 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon) SRV - [2007-10-12 17:03:30 | 000,598,016 | ---- | M] () [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe -- (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM) SRV - [2007-10-12 17:03:06 | 000,151,552 | ---- | M] () [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe -- (nSvcIp) SRV - [2006-03-03 22:03:10 | 000,069,632 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12) SRV - [2004-12-13 05:34:32 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\catchme.sys -- (catchme) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (a3a3s0nb) DRV - [2012-05-01 10:45:26 | 000,025,512 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ggsemc.sys -- (ggsemc) DRV - [2012-05-01 10:45:26 | 000,013,224 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ggflt.sys -- (ggflt) DRV - [2010-10-31 01:47:00 | 000,682,232 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd) DRV - [2010-09-27 12:56:00 | 000,308,859 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\CVPNDRVA.sys -- (CVPNDRVA) DRV - [2010-03-25 20:07:00 | 000,343,920 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk) DRV - [2010-03-25 20:07:00 | 000,091,832 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk) DRV - [2010-03-25 20:07:00 | 000,075,704 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeapfk.sys -- (mfeapfk) DRV - [2010-03-25 20:07:00 | 000,066,600 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mferkdet.sys -- (mferkdet) DRV - [2010-03-25 20:07:00 | 000,064,208 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\mfetdik.sys -- (mfetdik) DRV - [2010-03-25 20:07:00 | 000,043,288 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk) DRV - [2009-10-21 19:30:32 | 000,433,920 | ---- | M] (Leadtek Research Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wfeaglxt.sys -- (WFLR6654) WinFast TV2000 XP Global/Global TV (XC2028) DRV - [2008-11-16 19:39:44 | 000,131,984 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dne2000.sys -- (DNE) DRV - [2008-04-14 01:16:24 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MPE.sys -- (MPE) DRV - [2007-11-14 20:05:16 | 000,394,952 | ---- | M] (Zone Labs, LLC) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant) DRV - [2007-11-01 08:38:56 | 004,620,288 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2007-10-12 10:15:10 | 000,022,016 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus) DRV - [2007-10-12 10:15:08 | 000,054,144 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD) DRV - [2007-08-09 05:11:40 | 000,102,400 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvgts.sys -- (nvgts) DRV - [2007-01-18 21:28:02 | 000,005,275 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CVirtA.sys -- (CVirtA) DRV - [2006-10-18 21:12:16 | 000,012,664 | R--- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AsIO.sys -- (AsIO) DRV - [2004-08-13 04:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-606747145-1682526488-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-21-606747145-1682526488-839522115-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-606747145-1682526488-839522115-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC IE - HKU\S-1-5-21-606747145-1682526488-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69: C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) O1 HOSTS File: ([2012-07-11 22:14:01 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll (McAfee, Inc.) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.) O4 - HKLM..\Run: [VSD3DRefDebug] C:\Documents and Settings\Mlody\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\4542\VSD3DRefDebug.exe File not found O4 - HKU\S-1-5-21-606747145-1682526488-839522115-1003..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-606747145-1682526488-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-606747145-1682526488-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-21-606747145-1682526488-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\S-1-5-21-606747145-1682526488-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA) O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.233.128.17 62.233.128.18 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{84B23838-69B4-4780-B002-7399D588A15B}: DhcpNameServer = 62.233.128.17 62.233.128.18 O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\Mlody\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mlody\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-07-12 00:03:40 | 000,000,000 | -HSD | C] -- C:\RECYCLER [2012-07-11 23:58:12 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mlody\Pulpit\OTL.exe [2012-07-11 22:16:07 | 000,000,000 | --SD | C] -- C:\ComboFix [2012-07-11 22:14:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp [2012-07-11 22:06:43 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC [2012-07-08 18:58:39 | 000,000,000 | ---D | C] -- C:\Program Files\NETPLUS [2012-07-04 19:33:10 | 000,031,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wceusbsh.sys [2012-07-04 19:13:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mlody\Pulpit\AUTOMAPA_6.10E_FINAL_PL [2012-07-03 23:05:17 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe [2012-07-03 23:05:17 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe [2012-07-03 23:05:17 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe [2012-07-03 23:05:17 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe [2012-07-03 23:05:13 | 000,000,000 | ---D | C] -- C:\Qoobox [2012-07-03 20:48:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Mlody\Pulpit\Dom [2012-06-26 07:24:10 | 000,019,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg.dll [2012-06-26 01:27:04 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Connect 2 [2012-06-14 00:46:11 | 000,521,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsdbgui.dll [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-07-11 23:58:13 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mlody\Pulpit\OTL.exe [2012-07-11 23:55:32 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012-07-11 23:55:05 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012-07-11 23:21:07 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2012-07-11 23:21:04 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe [2012-07-11 23:21:03 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl [2012-07-11 22:21:49 | 000,494,318 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2012-07-11 22:21:49 | 000,435,870 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012-07-11 22:21:49 | 000,085,610 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2012-07-11 22:21:49 | 000,068,766 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2012-07-11 22:18:18 | 000,000,462 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{5A79CE2D-9929-489D-80D1-D33FD43A0271}.job [2012-07-11 22:14:01 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2012-07-11 10:43:06 | 000,137,176 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys [2012-07-11 10:43:01 | 000,268,952 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.xtr [2012-07-11 07:11:37 | 000,215,264 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012-07-11 01:15:10 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2012-07-04 19:31:27 | 000,289,280 | ---- | M] () -- C:\Documents and Settings\Mlody\Pulpit\gpstest.exe [2012-07-04 11:25:57 | 502,098,085 | ---- | M] () -- C:\Documents and Settings\Mlody\Pulpit\AUTOMAPA.6.10E.FINAL.PL.rar [2012-07-01 16:22:18 | 000,023,040 | ---- | M] () -- C:\Documents and Settings\Mlody\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-06-29 18:28:24 | 003,449,066 | ---- | M] () -- C:\Documents and Settings\Mlody\Pulpit\justin bieber- boyfriend.mp3 [2012-06-27 09:23:24 | 007,719,089 | ---- | M] () -- C:\Documents and Settings\Mlody\Pulpit\ATB - Never Give Up.mp3 [2012-06-26 01:27:18 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb [2012-06-26 01:27:18 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb [2012-06-26 01:10:47 | 006,724,552 | ---- | M] () -- C:\Documents and Settings\Mlody\Pulpit\shaggy feat. eve - girls just wanna have fun.mp3 [2012-06-26 01:10:22 | 005,295,597 | ---- | M] () -- C:\Documents and Settings\Mlody\Pulpit\jula - nie zatrzymasz mnie.mp3 [2012-06-26 00:45:41 | 014,461,350 | ---- | M] () -- C:\Documents and Settings\Mlody\Pulpit\Kelly Clarkson - Dark Side (Maison & Dragen Club Remix) [www.muzeno.pl].mp3 [2012-06-26 00:42:06 | 015,584,646 | ---- | M] () -- C:\Documents and Settings\Mlody\Pulpit\Perfect World (dBerrie Remix).mp3 [2012-06-22 07:59:14 | 003,603,426 | ---- | M] () -- C:\Documents and Settings\Mlody\Pulpit\loreen - euphoria.mp3 [2012-06-21 23:08:46 | 005,655,887 | ---- | M] () -- C:\Documents and Settings\Mlody\Pulpit\will.i.am feat. eva simons - this is love.mp3 [2012-06-13 15:55:21 | 001,866,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\win32k.sys [2012-06-13 15:55:21 | 001,866,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\win32k.sys [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-07-04 19:31:26 | 000,289,280 | ---- | C] () -- C:\Documents and Settings\Mlody\Pulpit\gpstest.exe [2012-07-04 09:37:41 | 502,098,085 | ---- | C] () -- C:\Documents and Settings\Mlody\Pulpit\AUTOMAPA.6.10E.FINAL.PL.rar [2012-07-03 23:05:17 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe [2012-07-03 23:05:17 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe [2012-07-03 23:05:17 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2012-07-03 23:05:17 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2012-07-03 23:05:17 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2012-06-29 18:28:00 | 003,449,066 | ---- | C] () -- C:\Documents and Settings\Mlody\Pulpit\justin bieber- boyfriend.mp3 [2012-06-27 09:22:54 | 007,719,089 | ---- | C] () -- C:\Documents and Settings\Mlody\Pulpit\ATB - Never Give Up.mp3 [2012-06-26 01:09:55 | 006,724,552 | ---- | C] () -- C:\Documents and Settings\Mlody\Pulpit\shaggy feat. eve - girls just wanna have fun.mp3 [2012-06-26 01:06:26 | 005,295,597 | ---- | C] () -- C:\Documents and Settings\Mlody\Pulpit\jula - nie zatrzymasz mnie.mp3 [2012-06-26 00:44:27 | 014,461,350 | ---- | C] () -- C:\Documents and Settings\Mlody\Pulpit\Kelly Clarkson - Dark Side (Maison & Dragen Club Remix) [www.muzeno.pl].mp3 [2012-06-26 00:40:33 | 015,584,646 | ---- | C] () -- C:\Documents and Settings\Mlody\Pulpit\Perfect World (dBerrie Remix).mp3 [2012-06-22 07:58:47 | 003,603,426 | ---- | C] () -- C:\Documents and Settings\Mlody\Pulpit\loreen - euphoria.mp3 [2012-06-21 23:08:04 | 005,655,887 | ---- | C] () -- C:\Documents and Settings\Mlody\Pulpit\will.i.am feat. eva simons - this is love.mp3 [2012-04-22 00:02:37 | 000,442,368 | R--- | C] () -- C:\WINDOWS\System32\zshp1018.exe [2012-04-22 00:02:37 | 000,106,496 | R--- | C] () -- C:\WINDOWS\System32\vshp1018.dll [2012-03-13 19:53:26 | 000,000,042 | ---- | C] () -- C:\Documents and Settings\Mlody\default.pls [2012-02-21 22:54:50 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mlody\foto2.bmp [2012-02-15 20:14:38 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2012-02-08 21:59:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpqEmlSz.INI [2011-12-26 20:06:51 | 000,000,018 | ---- | C] () -- C:\WINDOWS\avi2divx.INI [2011-11-16 19:36:31 | 000,000,022 | -HS- | C] () -- C:\Documents and Settings\Mlody\Dane aplikacji\Sys2662.Config.Repository.bin [2011-11-14 17:33:06 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mlody\Zdjęcie0022.jpg [2011-11-14 17:33:05 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mlody\Zdjęcie0023.jpg [2011-11-07 18:49:03 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Mlody\Dane aplikacji\winscp.rnd [2011-10-30 20:30:08 | 000,000,061 | ---- | C] () -- C:\WINDOWS\wininit.ini [2011-10-16 13:33:54 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI [2011-10-14 09:55:02 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mlody\ItemslistV110.png [2011-08-31 18:43:57 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mlody\wtorek.jpg [2011-08-31 18:43:56 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mlody\środa.jpg [2011-08-31 18:43:55 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mlody\poniedziałek.jpg [2011-08-31 18:43:55 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mlody\piatek.jpg [2011-08-31 18:43:55 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Mlody\czwartek.jpg [2011-03-25 23:08:15 | 000,000,221 | ---- | C] () -- C:\WINDOWS\NCLogConfig.ini [2011-01-23 12:04:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat [2011-01-20 00:43:31 | 000,000,008 | RHS- | C] () -- C:\Documents and Settings\All Users\ntuser.pol [2010-12-04 21:23:57 | 000,023,040 | ---- | C] () -- C:\Documents and Settings\Mlody\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010-11-22 22:37:36 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2010-11-18 21:46:13 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Mlody\Ustawienia lokalne\Dane aplikacji\PUTTY.RND [2010-11-10 23:03:56 | 000,137,176 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys [2010-11-10 23:03:48 | 000,268,952 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe [2010-11-10 23:03:32 | 000,075,136 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe [2010-10-31 11:39:32 | 000,000,350 | ---- | C] () -- C:\WINDOWS\System32\AF15IRTBL.bin [2010-10-31 11:37:21 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\PsisDecd.dll [2010-10-31 11:20:09 | 000,120,278 | ---- | C] () -- C:\WINDOWS\hpoins11.dat [2010-10-30 17:34:39 | 000,790,528 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2010-10-30 17:33:55 | 000,134,144 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2010-10-30 17:32:13 | 000,207,360 | ---- | C] () -- C:\WINDOWS\System32\evrprop.dll [2010-10-30 17:31:34 | 000,258,048 | ---- | C] () -- C:\WINDOWS\System32\libFLAC.dll [2010-10-30 17:26:06 | 000,080,384 | ---- | C] () -- C:\WINDOWS\System32\mkzlib.dll [2010-10-30 17:09:24 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\mkunicode.dll [2010-10-30 15:10:49 | 000,240,592 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin [2010-10-30 15:10:49 | 000,240,592 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin [2010-10-30 15:10:49 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin [2010-10-30 15:10:45 | 002,293,194 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin [2010-10-30 14:25:32 | 000,000,421 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2010-10-30 14:12:34 | 000,024,576 | R--- | C] () -- C:\WINDOWS\System32\AsIO.dll [2010-10-30 14:12:34 | 000,012,664 | R--- | C] () -- C:\WINDOWS\System32\drivers\AsIO.sys [2010-10-30 14:12:27 | 000,012,096 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp64.sys [2010-10-30 14:12:27 | 000,010,304 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp32.sys [2010-10-30 14:11:05 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe [2010-10-30 14:05:45 | 000,003,276 | R--- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin [2010-10-30 14:04:29 | 000,015,739 | ---- | C] () -- C:\WINDOWS\Ascd_log.ini [2010-10-30 14:04:04 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys [2010-10-30 14:04:02 | 000,015,498 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini [2010-10-30 14:03:48 | 000,012,536 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS [2010-10-30 02:09:15 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2010-10-30 02:08:14 | 000,215,264 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2010-10-30 00:23:20 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2010-10-30 00:19:36 | 000,021,856 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2010-09-27 13:03:08 | 000,201,512 | ---- | C] () -- C:\WINDOWS\System32\vpnapi.dll [2010-09-27 12:57:26 | 000,197,416 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll < End of report >