OTL logfile created on: 2011-08-05 19:04:12 - Run 1 OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\bambino\Pulpit\wirusy\Nowy folder Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 639.36 Mb Total Physical Memory | 278.50 Mb Available Physical Memory | 43.56% Memory free 1.53 Gb Paging File | 1.20 Gb Available in Paging File | 78.51% Paging File free Paging file location(s): C:\pagefile.sys 960 1920 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 9.77 Gb Total Space | 4.53 Gb Free Space | 46.42% Space Free | Partition Type: NTFS Drive D: | 26.35 Gb Total Space | 3.61 Gb Free Space | 13.72% Space Free | Partition Type: FAT32 Drive E: | 19.75 Gb Total Space | 7.10 Gb Free Space | 35.94% Space Free | Partition Type: NTFS Computer Name: BAMBINO-7D6F5F4 | User Name: bambino | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2011-08-05 18:09:00 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\bambino\Pulpit\wirusy\Nowy folder\OTL.exe PRC - [2008-08-04 01:02:20 | 000,036,352 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe PRC - [2007-07-11 16:57:42 | 000,880,640 | R--- | M] (Sony Ericsson Mobile Communications AB) -- C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe PRC - [2007-06-13 09:16:02 | 000,528,384 | R--- | M] () -- C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe PRC - [2007-03-16 04:23:20 | 000,983,040 | R--- | M] (Teleca AB) -- C:\Program Files\Common Files\Teleca Shared\Generic.exe PRC - [2005-05-12 09:15:14 | 000,102,400 | ---- | M] () -- C:\WINDOWS\ATK0100\HControl.exe PRC - [2005-05-10 04:12:22 | 001,953,792 | ---- | M] () -- C:\WINDOWS\ATK0100\ATKOSD.exe PRC - [2005-04-15 05:01:00 | 000,077,824 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE PRC - [2005-03-06 23:16:18 | 000,366,080 | ---- | M] () -- C:\Program Files\MultiKeyboard Driver\KbdDrv.exe PRC - [2005-01-04 17:52:52 | 000,331,776 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\system32\sistray.exe PRC - [2004-12-22 08:23:00 | 000,098,394 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe PRC - [2004-09-21 17:55:40 | 000,081,920 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe PRC - [2004-08-31 03:34:00 | 000,176,768 | ---- | M] (Symantec Corporation) -- C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe PRC - [2004-08-31 03:29:00 | 000,078,992 | ---- | M] (Symantec Corporation) -- C:\Program Files\Norton Internet Security\ISSVC.exe PRC - [2004-08-28 08:22:00 | 000,234,616 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccProxy.exe PRC - [2004-08-28 08:22:00 | 000,197,752 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe PRC - [2004-08-28 08:22:00 | 000,164,984 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe PRC - [2004-08-28 08:22:00 | 000,058,488 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe PRC - [2004-08-28 07:02:00 | 000,206,048 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe PRC - [2004-08-04 00:44:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2004-07-21 17:24:00 | 000,173,160 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe PRC - [2004-01-28 10:36:56 | 000,167,936 | R--- | M] (Conexant Systems , Inc.) -- C:\WINDOWS\Hsfpwcfg.exe PRC - [2003-09-19 13:54:44 | 000,172,032 | ---- | M] () -- C:\Program Files\ASUS\ASUS Live Update\ALU.exe PRC - [2003-09-12 21:25:30 | 000,032,768 | ---- | M] (asus) -- C:\Program Files\ASUS\Asus ChkMail\ChkMail.exe [color=#E56717]========== Modules (SafeList) ==========[/color] MOD - [2011-08-05 19:01:48 | 000,082,944 | RHS- | M] () -- C:\Documents and Settings\bambino\Ustawienia lokalne\temp\dsoqq0.dll MOD - [2011-08-05 18:09:00 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\bambino\Pulpit\wirusy\Nowy folder\OTL.exe MOD - [2004-12-22 08:23:00 | 000,069,722 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\system32\SynTPFcs.dll MOD - [2004-08-25 07:05:00 | 000,197,744 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\AntiSpam\asOEHook.dll MOD - [2004-08-04 00:42:34 | 001,050,624 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2004-08-31 03:34:00 | 000,176,768 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe -- (navapsvc) SRV - [2004-08-31 03:29:00 | 000,078,992 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Internet Security\ISSVC.exe -- (ISSVC) SRV - [2004-08-30 19:34:52 | 000,066,688 | ---- | M] (Symantec Corporation) [Auto | Stopped] -- C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe -- (SBService) SRV - [2004-08-28 08:22:00 | 000,234,616 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccProxy.exe -- (ccProxy) SRV - [2004-08-28 08:22:00 | 000,197,752 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe -- (ccEvtMgr) SRV - [2004-08-28 08:22:00 | 000,164,984 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe -- (ccSetMgr) SRV - [2004-08-28 08:22:00 | 000,078,968 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe -- (ccPwdSvc) SRV - [2004-08-28 07:02:00 | 000,206,048 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc) SRV - [2004-07-24 04:47:00 | 000,197,864 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe -- (SAVScan) SRV - [2004-07-21 17:24:00 | 000,173,160 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe -- (SPBBCSvc) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2009-11-20 05:02:58 | 000,268,664 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20100615.001\SymIDSCo.sys -- (SYMIDSCO) DRV - [2008-11-19 11:00:00 | 000,876,112 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090211.004\NAVEX15.SYS -- (NAVEX15) DRV - [2008-11-19 11:00:00 | 000,089,104 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090211.004\NAVENG.SYS -- (NAVENG) DRV - [2008-11-18 23:51:24 | 000,223,128 | ---- | M] (DT Soft Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\dtscsi.sys -- (dtscsi) DRV - [2007-06-19 10:51:20 | 000,107,304 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s816mdm.sys -- (s816mdm) DRV - [2007-06-19 10:51:18 | 000,099,112 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s816mgmt.sys -- (s816mgmt) Sony Ericsson Device 816 USB WMC Device Management Drivers (WDM) DRV - [2007-06-19 10:51:18 | 000,097,704 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s816unic.sys -- (s816unic) Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (WDM) DRV - [2007-06-19 10:51:18 | 000,097,320 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s816obex.sys -- (s816obex) DRV - [2007-06-19 10:51:18 | 000,021,928 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s816nd5.sys -- (s816nd5) Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (NDIS) DRV - [2007-06-19 10:51:18 | 000,013,864 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s816mdfl.sys -- (s816mdfl) DRV - [2007-06-19 10:51:16 | 000,081,832 | R--- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s816bus.sys -- (s816bus) Sony Ericsson Device 816 driver (WDM) DRV - [2005-04-19 04:40:00 | 002,317,504 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM) DRV - [2005-02-17 17:07:48 | 000,005,632 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ATKACPI.sys -- (MTsensor) DRV - [2005-02-17 13:03:48 | 000,638,720 | R--- | M] (Bison Electronics. Inc. ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Bs350u2.sys -- (Cam5603C) DRV - [2005-02-17 10:29:06 | 000,013,312 | R--- | M] (Silicon Integrated Systems Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srvkp.sys -- (SiSkp) DRV - [2005-02-17 04:59:26 | 000,240,640 | R--- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisgrp.sys -- (SiS315) DRV - [2005-02-11 21:46:22 | 000,371,712 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX) DRV - [2004-08-28 07:02:00 | 000,266,464 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI) DRV - [2004-08-28 07:02:00 | 000,171,424 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMFW.SYS -- (SYMFW) DRV - [2004-08-28 07:02:00 | 000,046,208 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMNDIS.SYS -- (SYMNDIS) DRV - [2004-08-28 07:02:00 | 000,034,496 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMIDS.SYS -- (SYMIDS) DRV - [2004-08-28 07:02:00 | 000,025,824 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV) DRV - [2004-08-28 07:02:00 | 000,011,040 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\Drivers\SYMDNS.SYS -- (SYMDNS) DRV - [2004-08-26 15:03:00 | 000,104,144 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent) DRV - [2004-08-09 08:27:18 | 000,070,144 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtlnicxp.sys -- (RTL8023xp) DRV - [2004-08-04 00:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Sterownik NT karty Realtek RTL8139(A/B/C) DRV - [2004-07-24 04:47:00 | 000,335,504 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Norton Internet Security\Norton AntiVirus\savrt.sys -- (SAVRT) DRV - [2004-07-24 04:47:00 | 000,049,808 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Norton Internet Security\Norton AntiVirus\Savrtpel.sys -- (SAVRTPEL) DRV - [2004-07-21 17:24:00 | 000,341,096 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv) DRV - [2004-06-17 08:57:16 | 000,193,280 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWSIS.sys -- (HSFHWSIS) DRV - [2004-05-17 17:11:42 | 000,067,456 | ---- | M] (REDC) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\rmedia.sys -- (rmedia) DRV - [2004-05-12 11:11:16 | 000,685,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf) DRV - [2004-05-12 11:09:42 | 001,037,056 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP) DRV - [2004-02-01 06:53:20 | 000,026,166 | ---- | M] (Compuware Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbfilt.sys -- (Usbfilt) DRV - [2003-07-01 19:47:08 | 000,009,856 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc) DRV - [2002-09-09 19:54:06 | 000,016,269 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\ASNDIS5.sys -- (ASNDIS5) DRV - [2001-08-17 23:51:32 | 000,018,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\irsir.sys -- (irsir) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2025429265-920026266-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie IE - HKU\S-1-5-21-2025429265-920026266-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com IE - HKU\S-1-5-21-2025429265-920026266-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.onet.pl/ IE - HKU\S-1-5-21-2025429265-920026266-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Program Files\Google\Update\1.2.183.23\npGoogleOneClick8.dll (Google Inc.) O1 HOSTS File: ([2008-11-27 21:49:51 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (My Global Search Bar BHO) - {37B85A21-692B-4205-9CAD-2626E4993404} - File not found O2 - BHO: (CNisExtBho Class) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (Symantec Corporation) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.) O2 - BHO: (CNavExtBho Class) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVShExt.dll (Symantec Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - File not found O3 - HKLM\..\Toolbar: (Norton Internet Security) - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (Symantec Corporation) O3 - HKLM\..\Toolbar: (My Global Search Bar) - {37B85A29-692B-4205-9CAD-2626E4993404} - File not found O3 - HKLM\..\Toolbar: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVShExt.dll (Symantec Corporation) O3 - HKLM\..\Toolbar: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare) O3 - HKU\S-1-5-21-2025429265-920026266-682003330-1003\..\Toolbar\ShellBrowser: (Norton AntiVirus) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVShExt.dll (Symantec Corporation) O3 - HKU\S-1-5-21-2025429265-920026266-682003330-1003\..\Toolbar\WebBrowser: (Norton Internet Security) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (Symantec Corporation) O3 - HKU\S-1-5-21-2025429265-920026266-682003330-1003\..\Toolbar\WebBrowser: (My Global Search Bar) - {37B85A29-692B-4205-9CAD-2626E4993404} - File not found O3 - HKU\S-1-5-21-2025429265-920026266-682003330-1003\..\Toolbar\WebBrowser: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare) O4 - HKLM..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe () O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation) O4 - HKLM..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe () O4 - HKLM..\Run: [Hsfpwcfg.exe] C:\WINDOWS\Hsfpwcfg.exe (Conexant Systems , Inc.) O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKLM..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe (ASUSTeK Computer Inc.) O4 - HKLM..\Run: [SiSPower] C:\WINDOWS\System32\SiSPower.dll (Silicon Integrated Systems Corporation) O4 - HKLM..\Run: [Sony Ericsson PC Suite] C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe () O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.) O4 - HKLM..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe (Symantec Corporation) O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe () O4 - HKU\S-1-5-21-2025429265-920026266-682003330-1003..\Run: [cdoosoft] C:\Documents and Settings\bambino\Ustawienia lokalne\temp\herss.exe () O4 - HKU\S-1-5-21-2025429265-920026266-682003330-1003..\Run: [Driver Updater] C:\Program Files\Carambis\Driver Updater\dupdater.exe (Media Fog Ltd.) O4 - HKU\S-1-5-21-2025429265-920026266-682003330-1003..\Run: [DriverUpdaterPro] D:\instalki\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe (iXi Tools) O4 - HKU\S-1-5-21-2025429265-920026266-682003330-1003..\Run: [dso32] C:\Documents and Settings\bambino\Ustawienia lokalne\temp\dsoqq.exe () O4 - HKU\S-1-5-21-2025429265-920026266-682003330-1003..\Run: [Gadu-Gadu] D:\instalki\Gadu-Gadu\gg.exe (Gadu-Gadu S.A.) O4 - HKU\S-1-5-21-2025429265-920026266-682003330-1003..\Run: [gStart] File not found O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated) O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ASUS ChkMail.lnk = C:\Program Files\ASUS\Asus ChkMail\ChkMail.exe (asus) O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe (Silicon Integrated Systems Corporation) O4 - Startup: C:\Documents and Settings\bambino\Menu Start\Programy\Autostart\MutiKeyboard Driver.lnk = C:\Program Files\MultiKeyboard Driver\KbdDrv.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 227 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-2025429265-920026266-682003330-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2025429265-920026266-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\S-1-5-21-2025429265-920026266-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-2025429265-920026266-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0 O7 - HKU\S-1-5-21-2025429265-920026266-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0 O7 - HKU\S-1-5-21-2025429265-920026266-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0 O7 - HKU\S-1-5-21-2025429265-920026266-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1 O7 - HKU\S-1-5-21-2025429265-920026266-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0 O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.) O16 - DPF: {1A781DED-C22D-4153-3213-A3211E29DF13} http://cached.gamedesire.com/g_bin/pl/cards_2_0_0_77.cab (GameDesire Card Games) O16 - DPF: {B4891BE9-835D-471B-B495-F5F3E6A8BBD7} http://cdn.iplex.pl/1791/viv-3.5.27.5/player/player_ocx.jpeg (VPlayer Control) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: O24 - Desktop BackupWallPaper: C:\Documents and Settings\bambino\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008-11-18 21:40:37 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2011-08-05 18:36:23 | 000,000,063 | RHS- | M] () - C:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2011-08-05 18:36:26 | 000,000,063 | RHS- | M] () - D:\autorun.inf -- [ FAT32 ] O32 - AutoRun File - [2011-08-05 18:36:28 | 000,000,063 | RHS- | M] () - E:\autorun.inf -- [ NTFS ] O33 - MountPoints2\{089c0a8e-adfd-11de-bc27-0017319e4d7e}\Shell\AutoRun\command - "" = G:\lcw.exe O33 - MountPoints2\{089c0a8e-adfd-11de-bc27-0017319e4d7e}\Shell\open\Command - "" = G:\lcw.exe O33 - MountPoints2\{629cb300-3767-11df-bc77-0017319e4d7e}\Shell - "" = AutoRun O33 - MountPoints2\{629cb300-3767-11df-bc77-0017319e4d7e}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a O33 - MountPoints2\{7c851826-171d-11de-bb04-0017319e4d7e}\Shell\AutoRun\command - "" = H:\lcw.exe O33 - MountPoints2\{7c851826-171d-11de-bb04-0017319e4d7e}\Shell\open\Command - "" = H:\lcw.exe O33 - MountPoints2\{aa7eb474-c108-11dd-ba18-0017319e4d7e}\Shell\AutoRun\command - "" = lcw.exe O33 - MountPoints2\{aa7eb474-c108-11dd-ba18-0017319e4d7e}\Shell\open\Command - "" = lcw.exe O33 - MountPoints2\{db0066b8-e950-11dd-ba83-0017319e4d7e}\Shell\AutoRun\command - "" = G:\lcw.exe O33 - MountPoints2\{db0066b8-e950-11dd-ba83-0017319e4d7e}\Shell\open\Command - "" = G:\lcw.exe O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2011-08-05 18:54:53 | 000,000,000 | ---D | C] -- C:\UsbFix [2011-08-05 18:08:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\bambino\Pulpit\wirusy [2011-08-05 12:23:30 | 000,371,712 | ---- | C] (Broadcom Corporation) -- C:\WINDOWS\System32\drivers\BCMWL5.SYS [2011-08-05 12:23:30 | 000,061,440 | ---- | C] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\ASUSW32N50.dll [2011-08-05 12:23:30 | 000,016,269 | ---- | C] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\ASNDIS5.sys [2011-08-04 22:36:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\bambino\Ustawienia lokalne\Dane aplikacji\GHISLER [2011-08-04 22:19:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\bambino\Dane aplikacji\GHISLER [2011-08-04 21:56:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP [2011-08-04 21:56:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\PassMark [2011-08-04 21:56:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\KeyboardTest [2011-08-04 21:56:08 | 000,000,000 | ---D | C] -- C:\Program Files\KeyboardTest [2011-07-29 22:31:01 | 000,000,000 | ---D | C] -- C:\Program Files\HD Tune [2011-07-29 22:31:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\HD Tune [8 C:\Documents and Settings\bambino\Pulpit\*.tmp files -> C:\Documents and Settings\bambino\Pulpit\*.tmp -> ] [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2011-08-05 19:06:04 | 000,451,802 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2011-08-05 19:06:04 | 000,395,534 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2011-08-05 19:06:04 | 000,075,904 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2011-08-05 19:06:04 | 000,059,774 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2011-08-05 19:01:14 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2011-08-05 19:01:07 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2011-08-05 19:01:05 | 000,134,072 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2011-08-05 18:36:23 | 000,000,063 | RHS- | M] () -- C:\autorun.inf [2011-08-05 18:10:28 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2011-08-05 12:35:35 | 000,000,162 | ---- | M] () -- C:\ASWL2K.ini [2011-08-05 12:23:28 | 000,000,567 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\ASUS WLAN Control Center.lnk [2011-08-04 21:56:10 | 000,000,670 | ---- | M] () -- C:\Documents and Settings\bambino\Pulpit\KeyboardTest.lnk [2011-08-04 21:39:53 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2011-07-28 22:15:57 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini [2011-07-28 22:15:53 | 000,048,640 | ---- | M] () -- C:\Documents and Settings\bambino\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [8 C:\Documents and Settings\bambino\Pulpit\*.tmp files -> C:\Documents and Settings\bambino\Pulpit\*.tmp -> ] [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2011-08-05 12:35:20 | 000,000,162 | ---- | C] () -- C:\ASWL2K.ini [2011-08-05 12:23:31 | 000,525,824 | ---- | C] () -- C:\WINDOWS\System32\ASWL2K.exe [2011-08-05 12:23:31 | 000,496,640 | ---- | C] () -- C:\WINDOWS\System32\ASWLSVC.exe [2011-08-05 12:23:31 | 000,159,827 | ---- | C] () -- C:\WINDOWS\System32\RemSvc.exe [2011-08-05 12:23:30 | 000,141,824 | ---- | C] () -- C:\WINDOWS\System32\ClientCpl.cpl [2011-08-05 12:23:30 | 000,015,577 | ---- | C] () -- C:\WINDOWS\System32\ASNDIS3.vxd [2011-08-05 12:23:28 | 000,000,567 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\ASUS WLAN Control Center.lnk [2011-08-04 21:56:10 | 000,000,670 | ---- | C] () -- C:\Documents and Settings\bambino\Pulpit\KeyboardTest.lnk [2009-06-20 19:19:25 | 000,004,946 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\mtbjfghn.xbe [2009-03-28 14:47:09 | 000,000,004 | ---- | C] () -- C:\WINDOWS\System32\proc395290739.bin [2009-03-05 13:53:58 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI [2009-03-05 00:10:55 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2009-01-06 23:08:15 | 000,009,093 | ---- | C] () -- C:\WINDOWS\hpdj3740.ini [2008-11-25 23:57:36 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS [2008-11-21 23:49:55 | 000,048,640 | ---- | C] () -- C:\Documents and Settings\bambino\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008-11-19 00:01:00 | 000,000,421 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2008-11-18 22:52:24 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll [2008-11-18 22:16:45 | 000,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll [2008-11-18 22:13:34 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2008-11-18 22:08:54 | 000,134,072 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2008-11-18 22:07:40 | 000,015,190 | R--- | C] () -- C:\WINDOWS\M1000Twn.ini [2008-11-18 22:07:39 | 000,003,031 | R--- | C] () -- C:\WINDOWS\System32\drivers\C10H0110.bin [2008-11-18 22:07:39 | 000,003,031 | R--- | C] () -- C:\WINDOWS\System32\drivers\C10F0110.bin [2008-11-18 22:01:04 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini [2008-11-18 22:00:59 | 000,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll [2008-11-18 22:00:59 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe [2008-11-18 21:59:32 | 000,083,483 | ---- | C] () -- C:\WINDOWS\VGAsetup.ini [2008-11-18 21:59:30 | 000,032,768 | R--- | C] () -- C:\WINDOWS\InstFunc.exe [2008-11-18 21:59:26 | 000,065,536 | R--- | C] () -- C:\WINDOWS\System32\sis760.bin [2008-11-18 21:59:26 | 000,065,536 | R--- | C] () -- C:\WINDOWS\System32\sis741.bin [2008-11-18 21:59:26 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\sis660.bin [2008-11-18 21:58:53 | 000,098,517 | ---- | C] () -- C:\WINDOWS\System32\VGAunistlog.ini [2008-11-18 21:55:40 | 000,005,632 | R--- | C] () -- C:\WINDOWS\System32\drivers\ATKACPI.sys [2008-11-18 21:55:29 | 000,007,424 | R--- | C] () -- C:\WINDOWS\System32\drivers\MMIOPORT.SYS [2008-11-18 21:43:29 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2008-11-18 21:36:48 | 000,021,856 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2004-10-11 12:19:00 | 000,092,672 | ---- | C] () -- C:\WINDOWS\System32\ASUSASV2.DLL [2004-08-04 00:56:48 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin [2004-08-04 00:44:00 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll [2004-08-02 14:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat [2004-07-17 11:36:38 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys [2003-04-08 12:40:22 | 000,005,679 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI [2001-10-26 18:15:16 | 000,451,802 | ---- | C] () -- C:\WINDOWS\System32\perfh015.dat [2001-10-26 18:15:16 | 000,313,828 | ---- | C] () -- C:\WINDOWS\System32\perfi015.dat [2001-10-26 18:15:16 | 000,075,904 | ---- | C] () -- C:\WINDOWS\System32\perfc015.dat [2001-10-26 18:15:16 | 000,034,990 | ---- | C] () -- C:\WINDOWS\System32\perfd015.dat [2001-08-23 15:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin [2001-08-23 15:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat [2001-08-17 23:30:24 | 000,395,534 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat [2001-08-17 23:30:24 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat [2001-08-17 23:30:24 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat [2001-08-17 23:30:22 | 000,059,774 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat [2001-08-17 23:15:38 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin [2001-07-22 00:36:48 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat [2001-07-22 00:36:04 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat [2001-07-22 00:24:16 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat [color=#E56717]========== LOP Check ==========[/color] [2009-05-27 12:55:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\GARMIN [2011-08-04 21:56:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PassMark [2009-03-22 22:18:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Teleca [2011-08-04 22:02:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP [2008-11-26 18:04:29 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\~0 [2008-11-19 13:11:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\bambino\Dane aplikacji\Gadu-Gadu [2009-03-28 14:47:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\bambino\Dane aplikacji\GanymedeNet [2009-05-27 12:55:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\bambino\Dane aplikacji\GARMIN [2011-08-04 22:19:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\bambino\Dane aplikacji\GHISLER [2008-11-20 13:46:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\bambino\Dane aplikacji\Nowe Gadu-Gadu [2009-03-23 14:15:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\bambino\Dane aplikacji\Teleca [2009-03-23 08:39:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\bambino\Dane aplikacji\uTorrent [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:BC359956 < End of report >