OTL logfile created on: 2012-09-12 22:23:22 - Run 3 OTL by OldTimer - Version Folder = C:\Documents and Settings\User\Moje dokumenty\Pobieranie Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.11) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 510,42 Mb Total Physical Memory | 73,40 Mb Available Physical Memory | 14,38% Memory free 1,22 Gb Paging File | 0,85 Gb Available in Paging File | 69,49% Paging File free Paging file location(s): C:\pagefile.sys 768 1536 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 48,83 Gb Total Space | 19,23 Gb Free Space | 39,38% Space Free | Partition Type: NTFS Drive D: | 100,21 Gb Total Space | 85,89 Gb Free Space | 85,71% Space Free | Partition Type: NTFS Computer Name: XXX-7800CC62D49 | User Name: User | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-09-12 20:39:43 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Moje dokumenty\Pobieranie\OTL.exe PRC - [2012-09-08 09:04:49 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2012-08-29 12:03:36 | 001,385,896 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe PRC - [2012-05-20 07:45:42 | 009,106,664 | ---- | M] (MediaGet LLC) -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\MediaGet2\mediaget.exe PRC - [2011-08-28 02:48:08 | 000,935,936 | ---- | M] () -- C:\Documents and Settings\User\Dane aplikacji\mservice32.exe PRC - [2011-01-17 19:01:46 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe PRC - [2011-01-17 19:01:46 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin PRC - [2009-08-04 17:29:54 | 000,219,360 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe PRC - [2009-08-04 17:29:52 | 000,346,320 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe PRC - [2007-03-22 17:50:06 | 001,431,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012-09-08 09:04:48 | 002,244,064 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll MOD - [2012-05-20 07:45:43 | 011,742,440 | ---- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\MediaGet2\QtWebKit4.dll MOD - [2012-05-20 07:45:43 | 002,554,088 | ---- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\MediaGet2\QtXmlPatterns4.dll MOD - [2012-05-20 07:45:43 | 002,430,184 | ---- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\MediaGet2\QtDeclarative4.dll MOD - [2012-05-20 07:45:43 | 001,298,152 | ---- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\MediaGet2\QtScript4.dll MOD - [2012-05-20 07:45:43 | 000,195,304 | ---- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\MediaGet2\QtSql4.dll MOD - [2012-05-20 07:45:42 | 002,267,368 | ---- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\MediaGet2\libvlccore.dll MOD - [2012-05-20 07:45:42 | 000,105,192 | ---- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\MediaGet2\libvlc.dll MOD - [2012-05-20 07:45:40 | 008,227,560 | ---- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\MediaGet2\QtGui4.dll MOD - [2012-05-20 07:45:40 | 002,297,576 | ---- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\MediaGet2\QtCore4.dll MOD - [2012-05-20 07:45:40 | 000,979,176 | ---- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\MediaGet2\QtNetwork4.dll MOD - [2012-05-20 07:45:40 | 000,343,784 | ---- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\MediaGet2\QtXml4.dll MOD - [2012-05-20 07:45:40 | 000,224,488 | ---- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\MediaGet2\imageformats\qmng4.dll MOD - [2012-05-20 07:45:40 | 000,200,424 | ---- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\MediaGet2\imageformats\qjpeg4.dll MOD - [2012-05-20 07:45:40 | 000,030,440 | ---- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\MediaGet2\imageformats\qgif4.dll MOD - [2012-03-05 18:14:39 | 000,985,088 | ---- | M] () -- C:\Program Files\OpenOffice.org 3\program\libxml2.dll MOD - [2011-08-28 02:48:08 | 000,935,936 | ---- | M] () -- C:\Documents and Settings\User\Dane aplikacji\mservice32.exe MOD - [2009-07-30 18:15:32 | 000,503,202 | ---- | M] () -- C:\Program Files\DeviceVM\Browser Configuration Utility\sqlite3.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [Auto | Stopped] -- %systemroot%\system32\wuauserv.dll -- (wuauserv) SRV - File not found [Auto | Stopped] -- %SystemRoot%\System32\ersvc.dll -- (ERSvc) SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\system32\cisvc.exe -- (CiSvc) SRV - [2012-09-08 09:04:49 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012-08-29 12:03:36 | 001,385,896 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc) SRV - [2011-05-03 22:18:00 | 004,137,464 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\system32\GameMon.des -- (npggsvc) SRV - [2009-08-04 17:29:54 | 000,219,360 | ---- | M] (DeviceVM, Inc.) [Auto | Running] -- C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe -- (BCUService) SRV - [2007-07-23 16:34:49 | 000,411,016 | ---- | M] (Techland Sp.z o.o.) [Auto | Stopped] -- C:\WINDOWS\System32\pr2alvyb.exe -- (pr2alvyb) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (apdz9a7z) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (ab0agq2o) DRV - [2012-06-10 08:42:06 | 000,477,240 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd) DRV - [2011-08-27 09:14:21 | 000,278,984 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt) DRV - [2011-08-27 09:14:19 | 000,025,416 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt) DRV - [2009-12-08 12:03:00 | 006,017,568 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) DRV - [2009-11-18 01:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt) DRV - [2009-11-18 01:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt) DRV - [2009-07-01 05:53:34 | 000,013,824 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus) DRV - [2009-07-01 05:53:30 | 000,066,688 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD) DRV - [2009-03-18 16:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi) DRV - [2008-10-20 02:40:58 | 000,007,680 | ---- | M] (SNEG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\FStarForce.sys -- (FStarForce) DRV - [2007-07-23 16:34:27 | 000,065,160 | ---- | M] (Techland Sp.z o.o.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\pe3alvyb.sys -- (pe3alvyb) DRV - [2007-07-23 16:33:55 | 000,068,752 | ---- | M] (Techland Sp.z o.o.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\ps6alvyb.sys -- (ps6alvyb) DRV - [2006-08-11 15:47:13 | 000,059,776 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfsync04.sys -- (sfsync04) DRV - [2006-07-05 14:46:06 | 000,063,352 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfdrv01a.sys -- (sfdrv01a) DRV - [2006-07-01 23:32:26 | 000,043,520 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8) DRV - [2006-06-14 16:56:56 | 000,013,680 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfhlp02.sys -- (sfhlp02) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-2000478354-1532298954-839522115-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank IE - HKU\S-1-5-21-2000478354-1532298954-839522115-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-21-2000478354-1532298954-839522115-1001\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.) IE - HKU\S-1-5-21-2000478354-1532298954-839522115-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-2000478354-1532298954-839522115-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\S-1-5-21-2000478354-1532298954-839522115-1001\..\SearchScopes\{775FFA76-B243-48DB-AFA4-C2AF51AFEEF3}: "URL" = http://search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=STDVM IE - HKU\S-1-5-21-2000478354-1532298954-839522115-1001\..\SearchScopes\{B4115332-C830-49c4-907C-E0923064F93B}: "URL" = http://www.google.com/cse?cx=partner-pub-3794288947762788%3A4067623346&ie=UTF-8&q={searchTerms}&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A4067623346 IE - HKU\S-1-5-21-2000478354-1532298954-839522115-1001\..\SearchScopes\{E82A4BD3-8E8F-476b-9704-C2CAE31600B6}: "URL" = http://www.bing.com/search?q={searchTerms}&form=SPLBR2&pc=SPLH IE - HKU\S-1-5-21-2000478354-1532298954-839522115-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultenginename: "" FF - prefs.js..browser.search.order.1: "" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.startup.homepage: "about:blank" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011-10-17 18:03:43 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-09-08 09:04:49 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012-09-12 22:04:26 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011-10-17 18:03:43 | 000,000,000 | ---D | M] [2011-08-11 18:39:49 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\User\Dane aplikacji\Mozilla\Extensions [2012-09-12 22:10:40 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\s20yh5dm.default\extensions [2012-07-23 21:34:51 | 000,216,359 | ---- | M] () (No name found) -- C:\Documents and Settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\s20yh5dm.default\extensions\OneClickDownloader@OneClickDownloader.com.xpi [2012-09-12 22:04:25 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2012-09-08 09:04:49 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012-06-21 14:52:21 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2012-06-21 14:52:21 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2012-06-21 14:52:21 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2012-06-21 14:52:21 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2012-06-21 14:52:21 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2012-06-21 14:52:21 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2012-09-11 17:05:42 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: localhost O4 - HKLM..\Run: [BCU] C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.) O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.) O4 - HKLM..\Run: [Microsoft(R) Windows(R) Operating System] C:\Documents and Settings\User\Pulpit\Minecraft server\exphack_metin\FishingBot.exe /tray File not found O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe () O4 - HKU\S-1-5-21-2000478354-1532298954-839522115-1001..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKU\S-1-5-21-2000478354-1532298954-839522115-1001..\Run: [MediaGet2] C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\MediaGet2\mediaget.exe (MediaGet LLC) O4 - HKU\.DEFAULT..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found O4 - HKU\S-1-5-18..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found O4 - HKU\S-1-5-21-2000478354-1532298954-839522115-1001..\RunOnce: [UpdateN] C:\Documents and Settings\User\Dane aplikacji\mservice32.exe () O4 - Startup: C:\Documents and Settings\User\Menu Start\Programy\Autostart\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O7 - HKU\S-1-5-21-2000478354-1532298954-839522115-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-2000478354-1532298954-839522115-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1 O7 - HKU\S-1-5-21-2000478354-1532298954-839522115-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1 O7 - HKU\S-1-5-21-2000478354-1532298954-839522115-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1 O7 - HKU\S-1-5-21-2000478354-1532298954-839522115-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1 O7 - HKU\S-1-5-21-2000478354-1532298954-839522115-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O7 - HKU\S-1-5-21-2000478354-1532298954-839522115-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1 O7 - HKU\S-1-5-21-2000478354-1532298954-839522115-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EA9B440D-5047-453A-BD9D-8B29E56BC504}: DhcpNameServer = O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\User\Moje dokumenty\Moje obrazy\bez tytułu.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Moje dokumenty\Moje obrazy\bez tytułu.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2011-07-20 20:48:05 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{342e1124-60a3-11e1-a423-6cf049d2b5d9}\Shell\AutoRun\command - "" = K:\RunClubSanDisk.exe O33 - MountPoints2\{ee4132c0-6ae9-11e1-a452-6cf049d2b5d9}\Shell - "" = AutoRun O33 - MountPoints2\{ee4132c0-6ae9-11e1-a452-6cf049d2b5d9}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-09-12 22:19:05 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\User\Recent [2012-09-12 22:04:52 | 000,000,000 | -HSD | C] -- C:\RECYCLER [2012-09-12 22:04:24 | 000,000,000 | ---D | C] -- C:\_OTL [2012-09-11 17:14:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom [2012-09-11 17:14:24 | 000,000,000 | ---D | C] -- C:\Program Files\xerox [2012-09-11 17:14:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\srchasst [2012-09-11 17:14:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe [2012-09-11 17:14:24 | 000,000,000 | ---D | C] -- C:\Program Files\movie maker [2012-09-11 17:14:22 | 000,000,000 | ---D | C] -- C:\Program Files\netmeeting [2012-09-11 17:14:22 | 000,000,000 | ---D | C] -- C:\Program Files\msn gaming zone [2012-09-11 17:14:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\msagent [2012-09-11 17:14:22 | 000,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage [2012-09-11 17:06:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp [2012-09-11 16:58:56 | 000,000,000 | RHSD | C] -- C:\cmdcons [2012-09-11 16:57:09 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe [2012-09-11 16:57:09 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe [2012-09-11 16:57:09 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe [2012-09-11 16:57:09 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe [2012-09-11 16:56:01 | 000,000,000 | ---D | C] -- C:\Qoobox [2012-09-11 16:55:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt [2012-09-11 16:48:27 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC [2012-09-08 09:03:39 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2012-08-29 15:02:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\LogMeIn Hamachi [2012-08-29 15:02:53 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn Hamachi [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-09-12 22:20:54 | 000,230,240 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml [2012-09-12 22:20:53 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2012-09-12 22:20:52 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012-09-12 22:19:22 | 003,145,728 | -H-- | M] () -- C:\Documents and Settings\User\NTUSER.DAT [2012-09-12 22:19:09 | 000,000,188 | -HS- | M] () -- C:\Documents and Settings\User\ntuser.ini [2012-09-12 22:19:05 | 001,418,216 | -H-- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\IconCache.db [2012-09-12 22:11:15 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Mozilla Firefox.lnk [2012-09-12 22:11:13 | 000,000,797 | ---- | M] () -- C:\Documents and Settings\User\Pulpit\Internet Explorer.lnk [2012-09-11 17:10:24 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat [2012-09-11 17:05:48 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini [2012-09-11 17:05:42 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2012-09-11 16:59:00 | 000,000,339 | RHS- | M] () -- C:\boot.ini [2012-09-11 16:41:44 | 000,002,184 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012-09-07 14:30:30 | 000,000,434 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for User.job [2012-09-02 12:47:49 | 000,020,992 | ---- | M] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-09-11 16:59:00 | 000,000,223 | ---- | C] () -- C:\Boot.bak [2012-09-11 16:58:57 | 000,262,400 | RHS- | C] () -- C:\cmldr [2012-09-11 16:57:09 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe [2012-09-11 16:57:09 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe [2012-09-11 16:57:09 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2012-09-11 16:57:09 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2012-09-11 16:57:09 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2012-09-10 16:29:41 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2012-02-05 18:58:34 | 1699,258,328 | ---- | C] () -- C:\Program Files\Rappelz_PL.exe [2011-11-23 20:53:40 | 000,008,035 | ---- | C] () -- C:\Documents and Settings\User\.recently-used.xbel [2011-11-12 09:34:46 | 000,000,460 | RHS- | C] () -- C:\Documents and Settings\All Users\ntuser.pol [2011-10-17 17:57:21 | 000,174,683 | ---- | C] () -- C:\WINDOWS\hpoins45.dat [2011-10-17 17:57:21 | 000,000,450 | ---- | C] () -- C:\WINDOWS\hpomdl45.dat [2011-08-29 17:34:10 | 000,935,936 | ---- | C] () -- C:\Documents and Settings\User\Dane aplikacji\mservice32.exe [2011-08-29 14:55:29 | 000,016,264 | ---- | C] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT [2011-08-27 09:14:21 | 000,278,984 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys [2011-08-27 09:14:19 | 000,025,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys [2011-08-11 18:39:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat [2011-07-24 20:56:36 | 000,006,136 | R--- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin [2011-07-24 20:55:26 | 000,000,010 | ---- | C] () -- C:\WINDOWS\GSetup.ini [2011-07-24 20:55:25 | 000,203,328 | R--- | C] () -- C:\WINDOWS\GSetup.exe [2011-07-24 20:49:27 | 000,020,992 | ---- | C] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011-07-20 22:41:38 | 000,755,114 | ---- | C] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2011-07-20 22:41:37 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2011-07-20 22:40:29 | 000,117,360 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2011-07-20 20:53:08 | 001,418,216 | -H-- | C] () -- C:\Documents and Settings\User\Ustawienia lokalne\Dane aplikacji\IconCache.db [2011-07-20 20:49:48 | 000,000,188 | -HS- | C] () -- C:\Documents and Settings\User\ntuser.ini [2011-07-20 20:49:46 | 003,145,728 | -H-- | C] () -- C:\Documents and Settings\User\NTUSER.DAT [2011-07-20 20:48:45 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2011-07-20 20:48:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\control.ini [2011-07-20 20:47:21 | 000,000,488 | RH-- | C] () -- C:\WINDOWS\System32\logonui.exe.manifest [2011-07-20 20:47:18 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\cdplayer.exe.manifest [2011-07-20 20:46:21 | 000,021,856 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2011-07-20 20:46:14 | 000,000,037 | ---- | C] () -- C:\WINDOWS\vbaddin.ini [2011-07-20 20:46:14 | 000,000,036 | ---- | C] () -- C:\WINDOWS\vb.ini [2011-07-20 20:45:54 | 000,026,717 | ---- | C] () -- C:\WINDOWS\System32\tslabels.ini [2011-07-20 20:45:53 | 000,003,813 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.ini [2011-01-20 16:02:24 | 002,994,176 | ---- | C] () -- C:\Program Files\openofficeorg33.msi [2011-01-20 15:58:40 | 130,026,163 | ---- | C] () -- C:\Program Files\openofficeorg1.cab [2011-01-20 15:13:20 | 000,000,290 | ---- | C] () -- C:\Program Files\setup.ini [color=#E56717]========== LOP Check ==========[/color] [2012-06-10 08:41:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite [2011-11-04 15:22:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10 [2012-05-20 07:45:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Media Get LLC [2012-03-30 20:55:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PMB Files [2012-09-07 13:56:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\.minecraft [2012-03-04 22:46:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\Crystal Player [2012-05-19 17:27:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\DAEMON Tools [2012-05-19 17:23:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\DAEMON Tools Lite [2012-05-19 17:27:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\DAEMON Tools Pro [2012-08-07 15:04:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\fizzy [2011-11-04 15:22:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\Gadu-Gadu 10 [2011-11-11 20:47:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\gtk-2.0 [2012-03-28 12:21:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\LolClient [2012-05-20 07:45:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\Media Get LLC [2012-03-05 18:16:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\OpenOffice.org [2012-06-02 15:18:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Dane aplikacji\TS3Client [color=#E56717]========== Purity Check ==========[/color] < End of report >