OTL logfile created on: 2011-11-11 20:15:34 - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Poland | Language: PLK | Date Format: yyyy-MM-dd 1,24 Gb Total Physical Memory | 0,70 Gb Available Physical Memory | 56,28% Memory free 1,49 Gb Paging File | 0,99 Gb Available in Paging File | 66,74% Paging File free Paging file location(s): C:\pagefile.sys 400 400 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 9,69 Gb Total Space | 0,34 Gb Free Space | 3,53% Space Free | Partition Type: NTFS Drive D: | 32,41 Gb Total Space | 3,79 Gb Free Space | 11,70% Space Free | Partition Type: FAT32 Drive E: | 32,42 Gb Total Space | 3,76 Gb Free Space | 11,59% Space Free | Partition Type: NTFS Computer Name: ANONYMOUS | User Name: Owner | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2011-11-11 20:14:26 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe PRC - [2011-11-05 07:53:18 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2009-08-27 16:05:04 | 000,092,008 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe PRC - [2009-07-20 11:30:50 | 000,813,584 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe PRC - [2009-07-10 11:42:32 | 000,055,824 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe PRC - [2009-07-03 15:49:06 | 001,029,456 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe PRC - [2009-07-03 15:49:06 | 000,520,024 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe PRC - [2009-04-20 19:17:01 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007-08-09 14:48:40 | 000,528,384 | R--- | M] (VIA Technologies, Inc.) -- C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe PRC - [2007-04-14 09:48:28 | 000,075,392 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashDisp.exe PRC - [2007-04-14 09:48:22 | 000,132,736 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashServ.exe PRC - [2007-04-14 09:48:04 | 000,243,328 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe PRC - [2007-04-14 09:47:18 | 000,345,728 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashWebSv.exe PRC - [2007-04-14 09:37:44 | 000,016,512 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe PRC - [2007-04-02 07:15:40 | 000,061,440 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Shared Files\CTDevSrv.exe PRC - [2007-03-06 09:35:02 | 000,198,168 | ---- | M] (InterVideo Inc.) -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe PRC - [2007-02-10 23:07:32 | 000,241,664 | ---- | M] (A4Tech Co.,Ltd.) -- C:\Program Files\A4Tech\Mouse\Amoumain.exe PRC - [2004-10-15 18:40:56 | 002,577,632 | ---- | M] (Sygate Technologies, Inc.) -- C:\Program Files\Sygate\SPF\Smc.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2011-11-05 07:53:18 | 001,989,592 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll MOD - [2010-02-05 19:29:26 | 001,291,776 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll MOD - [2009-07-20 11:27:14 | 000,017,936 | ---- | M] () -- C:\Program Files\Logitech\SetPoint\khalwrapper.dll MOD - [2009-07-03 15:49:08 | 001,630,560 | ---- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\Resources.dll MOD - [2009-07-03 15:49:08 | 000,246,128 | ---- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\RPAPI.dll MOD - [2009-07-03 15:49:08 | 000,168,960 | ---- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\unrar.dll MOD - [2009-02-27 18:04:20 | 000,311,296 | ---- | M] () -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\pdfshell.POL MOD - [2008-04-14 13:00:00 | 000,386,048 | ---- | M] () -- C:\WINDOWS\system32\qdvd.dll MOD - [2008-04-14 13:00:00 | 000,192,512 | ---- | M] () -- C:\WINDOWS\system32\qcap.dll MOD - [2008-04-14 13:00:00 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll MOD - [2008-04-14 13:00:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll MOD - [2005-07-01 15:29:48 | 000,075,776 | ---- | M] () -- D:\Program Files\Alwil Software\Avast4\unacev2.dll MOD - [2004-10-15 17:32:20 | 001,385,712 | ---- | M] () -- C:\Program Files\Sygate\SPF\tse.dll MOD - [2004-10-15 17:32:18 | 000,832,744 | ---- | M] () -- C:\Program Files\Sygate\SPF\SyLink.dll MOD - [2004-10-15 17:32:12 | 000,890,088 | ---- | M] () -- C:\Program Files\Sygate\SPF\SpNet.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [Disabled | Stopped] -- -- (HidServ) SRV - [2009-08-27 16:05:04 | 000,092,008 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService) SRV - [2009-07-03 15:49:06 | 001,029,456 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service) SRV - [2008-05-21 12:42:56 | 000,064,000 | ---- | M] (Creative Technology Ltd) [On_Demand | Stopped] -- C:\Program Files\Creative\Creative Centrale\CTUPnPSv.exe -- (CTUPnPSv) SRV - [2007-04-14 09:48:22 | 000,132,736 | ---- | M] (ALWIL Software) [Auto | Running] -- D:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus) SRV - [2007-04-14 09:48:04 | 000,243,328 | ---- | M] (ALWIL Software) [On_Demand | Running] -- D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner) SRV - [2007-04-14 09:47:18 | 000,345,728 | ---- | M] (ALWIL Software) [On_Demand | Running] -- D:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner) SRV - [2007-04-14 09:37:44 | 000,016,512 | ---- | M] (ALWIL Software) [Auto | Running] -- D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv) SRV - [2007-04-02 07:15:40 | 000,061,440 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files\Creative\Shared Files\CTDevSrv.exe -- (CTDevice_Srv) SRV - [2007-03-06 09:35:02 | 000,198,168 | ---- | M] (InterVideo Inc.) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe -- (Capture Device Service) SRV - [2004-10-15 18:40:56 | 002,577,632 | ---- | M] (Sygate Technologies, Inc.) [Auto | Running] -- C:\Program Files\Sygate\SPF\Smc.exe -- (SmcService) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2010-11-09 14:35:30 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\cpuz135_x32.sys -- (cpuz135) DRV - [2009-12-23 10:32:26 | 000,086,016 | ---- | M] (PACE Anti-Piracy, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\TPkd.sys -- (TPkd) DRV - [2009-12-18 11:58:52 | 000,011,336 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\SystemRequirementsLab\cpudrv.sys -- (cpudrv) DRV - [2009-08-13 22:46:57 | 000,721,904 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd) DRV - [2009-07-03 15:49:08 | 000,064,160 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd) DRV - [2009-06-17 17:56:32 | 000,028,560 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LUsbFilt.sys -- (LUsbFilt) DRV - [2009-06-17 17:56:24 | 000,079,248 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LMouKE.Sys -- (LMouKE) DRV - [2009-06-17 17:55:26 | 000,063,248 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\L8042mou.Sys -- (L8042mou) DRV - [2009-03-25 13:29:52 | 000,130,432 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp) DRV - [2009-03-18 16:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi) DRV - [2007-06-27 13:42:00 | 000,207,488 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vinyl97.sys -- (VIAudio) Vinyl AC'97 Audio Controller (WDM) DRV - [2007-04-14 09:47:32 | 000,094,552 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2) DRV - [2007-04-14 09:45:36 | 000,023,416 | ---- | M] (ALWIL Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr) DRV - [2007-04-14 09:44:52 | 000,043,176 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2007-04-14 09:43:32 | 000,026,888 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4) DRV - [2007-02-11 00:55:50 | 000,013,824 | ---- | M] (A4Tech Co.,Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Amusbprt.sys -- (Amusbprt) DRV - [2007-02-10 03:04:52 | 000,014,336 | ---- | M] (A4Tech Co.,Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Amps2prt.sys -- (Amps2prt) DRV - [2007-01-24 18:46:50 | 000,008,704 | ---- | M] (A4Tech Co.,Ltd.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\Amfilter.sys -- (Amfilter) DRV - [2006-11-04 05:45:48 | 000,178,913 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\V0260Vid.sys -- (V0260VID) DRV - [2006-05-03 17:50:42 | 001,540,608 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag) DRV - [2006-03-26 13:22:14 | 000,051,200 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x) DRV - [2006-03-13 10:38:23 | 000,006,656 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x) DRV - [2005-12-29 15:58:24 | 003,843,776 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM) DRV - [2005-03-16 07:23:54 | 000,013,696 | R--- | M] (BIOSTAR Group) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\BIOS.sys -- (BIOS) DRV - [2004-10-15 17:32:44 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\Drivers\wg6n.sys -- (wg6n) DRV - [2004-10-15 17:32:42 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\Drivers\wg5n.sys -- (wg5n) DRV - [2004-10-15 17:32:40 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\Drivers\wg4n.sys -- (wg4n) DRV - [2004-10-15 17:32:38 | 000,014,568 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\Drivers\wg3n.sys -- (wg3n) DRV - [2004-10-15 17:18:46 | 000,021,075 | ---- | M] (Sygate Technologies, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\wpsdrvnt.sys -- (wpsdrvnt) DRV - [2004-10-15 17:17:02 | 000,060,496 | ---- | M] (Sygate Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\SYSTEM32\Drivers\Teefer.sys -- (Teefer) DRV - [2002-07-17 08:05:10 | 000,016,512 | ---- | M] (Adaptec) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ASPI32.SYS -- (ASPI) DRV - [2002-05-21 09:50:00 | 000,068,886 | ---- | M] (Logitech) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LMouFlt2.sys -- (LMouFlt2) DRV - [2002-05-21 09:50:00 | 000,023,270 | ---- | M] (Logitech) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LHidFlt2.sys -- (LHidFlt2) DRV - [2002-05-21 09:50:00 | 000,005,846 | ---- | M] (Logitech) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LKbdFlt2.sys -- (LKbdFlt2) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1275210071-854245398-1644491937-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = BD 4D 85 AC 3E 1C CA 01 [binary data] IE - HKU\S-1-5-21-1275210071-854245398-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: noia2_option@kk.noia:3.76 FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.2 FF - prefs.js..extensions.enabledItems: {9D6218B8-03C7-4b91-AA43-680B305DD35C}:1.7.9.7 FF - prefs.js..extensions.enabledItems: {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}:3.76 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: \NGM\npNxGameUS.dll File not found FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\Documents and Settings\All Users\Application Data\NexonEU\NGM\npNxGameeu.dll (Nexon) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKCU\Software\MozillaPlugins\@powerchallenge.com/PowerLoader: C:\DOCUME~1\Owner\APPLIC~1\POWERC~1\nppowerloader.dll (Power Challenge Sweden AB) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2009-08-16 19:33:48 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011-11-11 09:10:39 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011-11-11 09:10:34 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\SeaMonkey 2.4.1\extensions\\Components: C:\Program Files\SeaMonkey\components [2011-11-11 18:08:42 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\SeaMonkey 2.4.1\extensions\\Plugins: C:\Program Files\SeaMonkey\plugins FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2009-08-16 19:33:48 | 000,000,000 | ---D | M] [2009-08-14 11:55:34 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions [2009-08-14 11:55:34 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\home2@tomtom.com [2011-11-11 17:36:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1kifo0m5.default\extensions [2011-07-04 17:41:02 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1kifo0m5.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2011-11-11 18:08:55 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Owner\Application Data\Mozilla\SeaMonkey\Profiles\ihgxkmo2.default\extensions [2011-11-11 09:10:39 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions () (No name found) -- C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\1KIFO0M5.DEFAULT\EXTENSIONS\{3474C305-9DAD-11D8-9207-00055D74C2E4}.XPI [2009-08-14 13:43:06 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009-12-07 06:58:54 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [2011-11-05 07:53:18 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2010-08-20 10:05:36 | 000,955,904 | ---- | M] (Ganymede Technologies) -- C:\Program Files\mozilla firefox\plugins\NPDEMON.dll [2010-04-12 16:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2011-11-05 04:21:03 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml [2011-11-05 04:21:03 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml [color=#E56717]========== Chrome ==========[/color] CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms} O1 HOSTS File: ([2008-04-14 13:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found. O4 - HKLM..\Run: [AtiPTA] C:\WINDOWS\System32\atiptaxx.exe (ATI Technologies, Inc.) O4 - HKLM..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe (VIA Technologies, Inc.) O4 - HKLM..\Run: [avast!] D:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software) O4 - HKLM..\Run: [CorelDRAW Graphics Suite 11b] E:\Program Files\Corel\Corel Graphics 12\Languages\CZ\Programs\Registration.exe (Corel Corporation) O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation) O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.) O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation) O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation) O4 - HKLM..\Run: [SmcService] C:\Program Files\Sygate\SPF\Smc.exe (Sygate Technologies, Inc.) O4 - HKLM..\Run: [WheelMouse] C:\Program Files\A4Tech\Mouse\Amoumain.exe (A4Tech Co.,Ltd.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1275210071-854245398-1644491937-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15108/CTPID.cab (Creative Software AutoUpdate Support Package) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 86.63.129.29 86.63.129.30 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2CF99348-2325-4E1F-B855-7DB34610C89F}: DhcpNameServer = 86.63.129.29 86.63.129.30 O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - D:\Program Files\LogiTech\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.) O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.) O22 - SharedTaskScheduler: {1984DD45-52CF-49cd-AB77-18F378FEA264} - FencesShellExt - C:\Program Files\Stardock\Fences\FencesMenu.dll (Stardock) O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009-08-14 01:39:50 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{03bcbf24-f0d6-11de-898f-00e04cf836a9}\Shell\AutoRun\command - "" = H:\Launcher.exe O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (lsdelete) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2011-11-11 20:14:25 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe [2011-11-11 18:36:17 | 000,000,000 | ---D | C] -- C:\EbuDllTmpDir [2011-11-11 18:35:25 | 000,069,632 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\Alcmtr.exe [2011-11-11 18:35:24 | 002,808,832 | ---- | C] (RealTek Semicoductor Corp.) -- C:\WINDOWS\alcwzrd.exe [2011-11-11 18:35:21 | 009,715,200 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTLCPL.exe [2011-11-11 18:35:21 | 002,162,688 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\MicCal.exe [2011-11-11 18:35:21 | 001,191,936 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RtlUpd.exe [2011-11-11 18:35:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\RTCOM [2011-11-11 18:35:19 | 004,432,384 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\drivers\RtkHDAud.sys [2011-11-11 18:35:19 | 000,282,624 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\RTSndMgr.cpl [2011-11-11 18:34:38 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek [2011-11-11 18:34:25 | 000,831,488 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RtlExUpd.dll [2011-11-11 18:32:24 | 000,000,000 | ---D | C] -- C:\Intel [2011-11-11 18:08:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\SeaMonkey [2011-11-11 18:08:37 | 000,000,000 | ---D | C] -- C:\Program Files\SeaMonkey [2011-11-11 17:58:02 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Owner\Recent [2011-11-05 18:23:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\Corel User Files [2011-11-05 18:20:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\Corel [2011-11-05 18:18:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\InstallShield [2011-11-05 18:18:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\CorelDRAW Graphics Suite 12 [2011-11-05 18:17:39 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Corel [2011-11-01 11:56:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\Prace dodatkowe ŻABKA [2011-10-29 20:34:53 | 000,000,000 | ---D | C] -- C:\Program Files\Skype [2011-10-27 12:36:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\Różne [2011-10-27 12:35:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\Dawid [2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2011-11-11 20:16:30 | 000,215,040 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\net-log.exe [2011-11-11 20:14:26 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe [2011-11-11 18:49:27 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2011-11-11 18:48:25 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2011-11-11 17:56:04 | 000,105,984 | ---- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011-11-11 09:10:43 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk [2011-11-07 15:01:00 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [2011-11-05 21:51:35 | 000,359,344 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2011-10-30 08:56:21 | 000,444,028 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2011-10-30 08:56:21 | 000,071,904 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2011-10-28 20:57:32 | 002,084,937 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Misha B Purple Rain.mp3 [2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2011-11-11 20:16:30 | 000,215,040 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\net-log.exe [2011-11-11 09:10:43 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk [2011-10-30 11:40:50 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk [2011-10-28 20:57:17 | 002,084,937 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Misha B Purple Rain.mp3 [2011-03-06 10:19:30 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat [2011-02-05 18:49:40 | 000,000,004 | ---- | C] () -- C:\WINDOWS\System32\proc625010911.bin [2010-09-25 13:27:12 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini [2010-09-25 13:27:10 | 000,134,144 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2010-09-25 13:27:09 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2010-09-25 13:17:14 | 000,790,528 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2010-09-25 13:17:14 | 000,258,048 | ---- | C] () -- C:\WINDOWS\System32\libFLAC.dll [2010-03-19 22:04:01 | 000,000,134 | ---- | C] () -- C:\WINDOWS\naglos.INI [2010-03-05 19:11:49 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll [2010-03-05 19:11:49 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll [2010-03-05 19:11:49 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll [2010-03-05 18:07:57 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat [2010-02-23 23:21:06 | 000,000,051 | ---- | C] () -- C:\WINDOWS\COOL.INI [2010-02-23 17:13:16 | 000,000,029 | ---- | C] () -- C:\WINDOWS\wordpad.ini [2010-01-24 22:43:42 | 005,640,880 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall.exe [2010-01-24 22:39:50 | 000,000,124 | ---- | C] () -- C:\WINDOWS\mp3wavcon.ini [2010-01-24 22:38:57 | 000,000,005 | ---- | C] () -- C:\WINDOWS\System32\SySmp3con.dat [2010-01-24 22:38:52 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll [2009-12-12 18:08:58 | 000,001,288 | ---- | C] () -- C:\WINDOWS\eReg.dat [2009-11-01 21:30:37 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat [2009-10-17 22:04:56 | 000,028,545 | ---- | C] () -- C:\WINDOWS\System32\lap20nh3l4dkszi4a.dll [2009-10-17 22:04:56 | 000,010,690 | ---- | C] () -- C:\WINDOWS\System32\xkh1udoe84fkszi4a.dll [2009-10-17 22:04:56 | 000,003,416 | ---- | C] () -- C:\WINDOWS\System32\qke3kixfeflkszi4a.dll [2009-10-03 21:33:50 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2009-10-03 21:33:29 | 000,051,712 | ---- | C] () -- C:\WINDOWS\System32\coodest.dll [2009-10-03 20:11:57 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2009-08-22 11:56:54 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll [2009-08-16 19:26:26 | 000,149,725 | ---- | C] () -- C:\WINDOWS\hpoins34.dat [2009-08-16 19:26:26 | 000,000,404 | ---- | C] () -- C:\WINDOWS\hpomdl34.dat [2009-08-15 14:06:55 | 000,015,688 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe [2009-08-14 01:40:14 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2009-08-14 01:36:34 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2009-08-13 23:17:08 | 000,127,614 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat [2009-08-13 23:17:08 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\atiiprxx.exe [2009-08-13 23:17:08 | 000,000,011 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.ini [2009-08-13 20:18:15 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2009-08-13 20:14:44 | 000,359,344 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2009-08-13 19:58:56 | 000,105,984 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009-08-13 18:59:05 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2009-08-13 18:58:15 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe [2009-08-13 18:56:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat [2009-08-13 18:52:27 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe [2009-08-13 18:52:01 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll [2009-04-20 19:25:16 | 000,210,944 | ---- | C] () -- C:\WINDOWS\System32\msvcrt10.dll [2008-04-14 13:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin [2008-04-14 13:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat [2008-04-14 13:00:00 | 000,444,028 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat [2008-04-14 13:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat [2008-04-14 13:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat [2008-04-14 13:00:00 | 000,071,904 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat [2008-04-14 13:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin [2008-04-14 13:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat [2008-04-14 13:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat [2008-04-14 13:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat [2008-04-14 13:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin [2008-04-14 13:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat [2004-10-15 17:31:56 | 000,218,264 | ---- | C] () -- C:\WINDOWS\System32\SetAid.dll [2002-03-17 01:00:00 | 000,007,420 | ---- | C] () -- C:\WINDOWS\UA000088.DLL [color=#E56717]========== LOP Check ==========[/color] [2009-10-21 08:52:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Stardock [2010-08-23 15:04:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Acoustica [2011-07-15 21:32:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AlawarWrapper [2010-12-11 10:35:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software [2009-08-13 22:52:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite [2009-08-23 16:53:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DriverCure [2011-07-15 18:16:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Easy CD-DA Extractor [2011-07-15 21:35:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy2 [2011-08-02 23:26:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FarmFrenzy3_Madagascar [2009-08-21 12:01:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Innovative Solutions [2009-12-24 22:48:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations [2009-08-14 12:00:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MainType [2009-10-31 14:00:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nexon [2009-10-31 14:38:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NexonEU [2009-10-31 12:52:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NexonUS [2009-08-23 16:51:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic [2011-03-06 09:05:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files [2011-07-15 20:54:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP [2009-09-03 19:10:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tlen.pl [2009-08-20 08:55:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TomTom [2010-08-22 18:02:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems [2009-10-28 22:35:02 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{615DB4DC-B7C1-4125-9858-78EF460B76D2} [2009-09-25 19:43:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} [2009-10-28 22:34:30 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{9BA38AC8-8A1E-463A-97ED-AE291D3E1A06} [2010-04-01 23:29:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{A87EB928-0C6C-4071-AEF1-59E32BAEDF1B} [2009-08-15 14:01:04 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864} [2010-08-22 17:32:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Acoustica [2011-11-02 22:57:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\BESTplayer [2009-08-15 15:49:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\DAEMON Tools Lite [2009-08-23 16:52:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\DriverCure [2011-02-05 18:49:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\GanymedeNet [2009-10-26 22:15:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\GetRightToGo [2009-08-24 21:45:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\LexisNexis [2011-03-06 09:54:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\LolClient [2010-06-13 14:26:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Moje pliki Bitwy o Śródziemie™ II [2010-06-12 14:40:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Moje pliki gry Władca Pierścieni, Król Nazguli [2010-10-15 15:14:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Moje pliki zapisu Bitwy o Sródziemie [2010-06-20 12:40:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Moje pliki zapisu Bitwy o Śródziemie [2009-12-25 19:37:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Mount&Blade [2009-09-14 18:32:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Mp3tag [2009-08-24 18:45:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\PowerChallenge [2009-08-15 13:38:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Stardock [2010-08-22 17:36:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\SynthMaker [2011-11-11 18:24:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\SystemRequirementsLab [2010-08-13 00:12:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Tibia [2009-09-03 19:10:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Tlen.pl [2009-08-14 11:55:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\TomTom [2010-07-20 23:04:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Ulead Systems [2009-10-20 16:29:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Uniblue [2011-11-11 20:24:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\uTorrent [2009-10-26 22:16:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Xilisoft Corporation [2011-11-07 15:01:00 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:036B9593 @Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:592D7272 < End of report >