OTL logfile created on: 2010-10-23 17:52:28 - Run 1 OTL by OldTimer - Version 3.2.16.0 Folder = C:\Users\Mimi\Desktop Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 7.0.6001.18000) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 42,00% Memory free 6,00 Gb Paging File | 5,00 Gb Available in Paging File | 78,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 149,04 Gb Total Space | 78,18 Gb Free Space | 52,45% Space Free | Partition Type: NTFS Drive D: | 69,69 Gb Total Space | 37,52 Gb Free Space | 53,84% Space Free | Partition Type: NTFS Drive E: | 48,83 Gb Total Space | 13,33 Gb Free Space | 27,30% Space Free | Partition Type: NTFS Drive F: | 20,75 Gb Total Space | 12,09 Gb Free Space | 58,26% Space Free | Partition Type: NTFS Computer Name: ASUS | User Name: Mimi | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 90 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2010-10-23 16:58:26 | 000,124,216 | ---- | M] (Doctor Web, Ltd.) -- C:\Users\Mimi\AppData\Local\temp\21C8DC00-618BBB00-42E65500-A7C6E200\8246cc.exe PRC - [2010-10-23 16:58:24 | 002,526,984 | ---- | M] () -- C:\Users\Mimi\AppData\Local\temp\21C8DC00-618BBB00-42E65500-A7C6E200\42e87_xp.exe PRC - [2010-10-22 15:53:31 | 051,062,072 | ---- | M] () -- C:\Users\Spider\Desktop\Dr.Web CureIT.exe PRC - [2010-10-22 15:48:46 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Mimi\Desktop\OTL.exe PRC - [2010-10-08 20:54:51 | 000,014,808 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe PRC - [2010-10-08 20:54:45 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2010-09-10 23:41:42 | 001,901,056 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe PRC - [2010-09-10 23:41:20 | 002,500,552 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cfp.exe PRC - [2009-09-23 16:45:50 | 001,287,176 | ---- | M] (Panda Security) -- C:\Program Files\Panda USB Vaccine\USBVaccine.exe PRC - [2008-10-29 08:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2008-07-09 18:14:06 | 000,191,032 | ---- | M] (ATK) -- C:\Program Files\P4G\BatteryLife.exe PRC - [2008-06-18 07:10:24 | 000,297,528 | ---- | M] (ASUS) -- C:\Program Files\ASUS\SmartLogon\sensorsrv.exe PRC - [2008-06-04 02:29:08 | 000,851,968 | ---- | M] (ATK) -- C:\Program Files\ASUS\Splendid\ACMON.exe PRC - [2008-02-02 00:17:26 | 000,233,472 | ---- | M] (ATK0100) -- C:\Program Files\ATK Hotkey\HControl.exe PRC - [2008-01-23 19:51:28 | 000,151,552 | ---- | M] () -- C:\Program Files\ATK Hotkey\WDC.exe PRC - [2007-12-04 19:57:06 | 002,486,272 | ---- | M] () -- C:\Program Files\ATK Hotkey\ATKOSD.exe PRC - [2007-11-05 04:48:06 | 000,106,496 | ---- | M] () -- C:\Program Files\ATK Hotkey\MsgTranAgt.exe PRC - [2007-10-03 06:53:00 | 000,094,208 | ---- | M] () -- C:\Program Files\ATK Hotkey\AsLdrSrv.exe PRC - [2007-08-15 20:20:16 | 000,106,496 | ---- | M] () -- C:\Program Files\ATK Hotkey\KBFiltr.exe PRC - [2007-08-08 09:08:40 | 000,094,208 | ---- | M] () -- C:\Program Files\ATKGFNEX\GFNEXSrv.exe PRC - [2007-07-06 01:53:44 | 001,040,384 | ---- | M] () -- C:\Program Files\Wireless Console 2\wcourier.exe PRC - [2007-05-18 11:31:16 | 000,073,728 | ---- | M] () -- C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe PRC - [2007-01-09 17:11:20 | 000,118,784 | ---- | M] (OptionNV) -- C:\Windows\System32\Gtdetectsc.exe PRC - [2006-05-24 08:49:14 | 000,024,576 | ---- | M] (Syntek America Inc.) -- C:\Windows\System32\StkASv2K.exe PRC - [2005-07-07 00:43:42 | 000,155,648 | ---- | M] (ASUSTeK) -- C:\Windows\System32\ACEngSvr.exe [color=#E56717]========== Modules (SafeList) ==========[/color] MOD - [2010-10-22 15:48:46 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Mimi\Desktop\OTL.exe MOD - [2010-09-10 23:41:40 | 000,285,480 | ---- | M] (COMODO) -- C:\Windows\System32\guard32.dll MOD - [2008-01-21 04:24:37 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx MOD - [2008-01-21 04:23:44 | 001,684,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [Auto | Stopped] -- C:\Program Files\Netia\Mobilny Internet\AssistantServices.exe -- (UI Assistant Service) SRV - File not found [Auto | Stopped] -- d:\opel epc\BHROOT\BIN\PORTMAP.EXE -- (portmapper) SRV - File not found [Disabled | Stopped] -- d:\opel epc\BHROOT\BIN\NT611SVC.EXE -- (bh611) SRV - [2010-10-05 21:28:08 | 000,361,216 | ---- | M] (Kaspersky Lab ZAO) [Auto | Stopped] -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe -- (AVP) SRV - [2010-09-10 23:41:42 | 001,901,056 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent) SRV - [2010-03-18 16:47:22 | 000,035,160 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe -- (aspnet_state) SRV - [2010-03-18 13:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400) SRV - [2010-03-18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010-03-18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpPortSharing) SRV - [2010-03-18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpActivator) SRV - [2010-03-18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetPipeActivator) SRV - [2010-03-18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetMsmqActivator) SRV - [2009-12-10 22:23:00 | 003,480,408 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc) SRV - [2009-11-27 17:24:34 | 000,185,640 | ---- | M] (TeamViewer GmbH) [Disabled | Stopped] -- C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe -- (TeamViewer5) SRV - [2009-10-22 06:00:04 | 000,395,824 | ---- | M] (VMware, Inc.) [Disabled | Stopped] -- C:\Windows\System32\vmnat.exe -- (VMware NAT Service) SRV - [2009-10-22 05:59:58 | 000,113,200 | ---- | M] (VMware, Inc.) [Disabled | Stopped] -- C:\Program Files\VMware\VMware Workstation\vmware-authd.exe -- (VMAuthdService) SRV - [2009-10-22 05:59:48 | 000,334,384 | ---- | M] (VMware, Inc.) [Disabled | Stopped] -- C:\Windows\System32\vmnetdhcp.exe -- (VMnetDHCP) SRV - [2009-10-22 04:47:54 | 000,563,760 | ---- | M] (VMware, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe -- (VMUSBArbService) SRV - [2009-10-12 15:32:24 | 000,191,024 | ---- | M] (VMware, Inc.) [Disabled | Stopped] -- C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe -- (ufad-ws60) SRV - [2008-10-15 17:13:58 | 000,439,632 | ---- | M] (RealVNC Ltd.) [Disabled | Stopped] -- E:\Instalki PC\VNC4\winvnc4.exe -- (WinVNC4) SRV - [2008-01-21 04:25:06 | 000,371,200 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\inetsrv\iisw3adm.dll -- (WAS) SRV - [2008-01-21 04:25:06 | 000,052,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\inetsrv\apphostsvc.dll -- (AppHostSvc) SRV - [2008-01-21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2008-01-21 04:23:24 | 000,365,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm) SRV - [2008-01-21 04:23:24 | 000,167,936 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr) SRV - [2007-10-03 06:53:00 | 000,094,208 | ---- | M] () [Auto | Running] -- C:\Program Files\ATK Hotkey\AsLdrSrv.exe -- (ASLDRService) SRV - [2007-08-08 09:08:40 | 000,094,208 | ---- | M] () [Auto | Running] -- C:\Program Files\ATKGFNEX\GFNEXSrv.exe -- (ATKGFNEXSrv) SRV - [2007-08-03 21:24:54 | 000,125,496 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe -- (spmgr) SRV - [2007-05-28 18:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) [Disabled | Stopped] -- E:\Instalki PC\Alcohol 120%\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE) SRV - [2007-05-18 11:31:16 | 000,073,728 | ---- | M] () [Auto | Running] -- C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe -- (ADSMService) SRV - [2007-03-06 10:35:02 | 000,198,168 | ---- | M] (InterVideo Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe -- (Capture Device Service) SRV - [2007-01-09 17:11:20 | 000,118,784 | ---- | M] (OptionNV) [Auto | Running] -- C:\Windows\System32\Gtdetectsc.exe -- (gtdetectsc) SRV - [2006-05-24 08:49:14 | 000,024,576 | ---- | M] (Syntek America Inc.) [Auto | Running] -- C:\Windows\System32\StkASv2K.exe -- (StkASSrv) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\XDva324.sys -- (XDva324) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\XDva310.sys -- (XDva310) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- E:\SROBotVn1.31b\SROBotVn1.31b\NtProcDrv.sys -- (NTProcDrv) DRV - File not found [File_System | Boot | Stopped] -- C:\Windows\System32\DRIVERS\Lbd.sys -- (Lbd) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\EagleNT.sys -- (EagleNT) DRV - File not found [File_System | Unknown | Running] -- -- (DwProt) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\cv2k1.sys -- (CV2K1) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Jarek\AppData\Local\Temp\25778978.08- -- (ByakkoDriver) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\btwl2cap.sys -- (btwl2cap) DRV - File not found [Kernel | On_Demand | Stopped] -- G:\I386\AsProcOb.sys -- (ASUSProcObsrv) DRV - File not found [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\AsInsHelp32.sys -- (ASInsHelp) DRV - File not found [Kernel | Boot | Stopped] -- C:\Windows\System32\DRIVERS\17447622.sys -- (17447622) DRV - [2010-10-16 12:55:59 | 000,488,536 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\Windows\System32\drivers\klif.sys -- (KLIF) DRV - [2010-09-22 13:28:48 | 000,005,120 | ---- | M] () [Kernel | On_Demand | Stopped] -- E:\Instalki Gier\MayaMu\MuGuard\llck.sys -- (LLRING0) DRV - [2010-09-10 23:40:30 | 000,236,088 | ---- | M] (COMODO) [File_System | System | Running] -- C:\Windows\System32\drivers\cmdGuard.sys -- (cmdGuard) DRV - [2010-09-10 23:40:30 | 000,017,256 | ---- | M] (COMODO) [File_System | System | Running] -- C:\Windows\System32\drivers\cmderd.sys -- (cmderd) DRV - [2010-06-09 17:43:52 | 000,011,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\System32\drivers\kl2.sys -- (kl2) DRV - [2010-06-09 17:43:50 | 000,132,184 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\kl1.sys -- (KL1) DRV - [2010-04-22 19:07:34 | 000,022,104 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\System32\drivers\klim6.sys -- (KLIM6) DRV - [2010-02-03 15:56:56 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi) DRV - [2009-11-09 19:12:42 | 000,025,088 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\teamviewervpn.sys -- (teamviewervpn) DRV - [2009-11-02 20:27:16 | 000,019,984 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\klmouflt.sys -- (klmouflt) DRV - [2009-10-22 06:00:46 | 000,853,936 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmx86.sys -- (vmx86) DRV - [2009-10-22 06:00:44 | 000,070,704 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmci.sys -- (vmci) DRV - [2009-10-22 06:00:44 | 000,026,288 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmnetuserif.sys -- (VMnetuserif) DRV - [2009-10-22 06:00:44 | 000,023,216 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VMkbd.sys -- (vmkbd) DRV - [2009-10-22 04:47:52 | 000,032,304 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\hcmon.sys -- (hcmon) DRV - [2009-10-22 01:13:36 | 000,031,280 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmusb.sys -- (vmusb) DRV - [2009-10-22 01:13:32 | 000,036,400 | R--- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmnetbridge.sys -- (VMnetBridge) DRV - [2009-10-22 01:13:32 | 000,016,560 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmnetadapter.sys -- (VMnetAdapter) DRV - [2009-10-13 10:50:00 | 000,133,632 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Mkd2kfNT.sys -- (Mkd2kfNt) DRV - [2009-10-12 15:31:52 | 000,022,448 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Program Files\VMware\VMware Workstation\vstor2-ws60.sys -- (vstor2-ws60) DRV - [2009-10-09 23:31:02 | 000,311,312 | ---- | M] (Kaspersky Lab) [File_System | System | Stopped] -- C:\Windows\System32\drivers\1744762.sys -- (Kaspersky Virus Removal Tooldrv) DRV - [2009-09-25 17:59:42 | 000,128,016 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\Windows\System32\drivers\17447621.sys -- (17447621) DRV - [2009-09-06 12:08:37 | 000,051,200 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\cimo.sys -- (cimo) DRV - [2009-07-13 10:37:00 | 000,079,360 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Mkd2Nadr.sys -- (Mkd2Nadr) DRV - [2009-04-22 17:35:04 | 000,009,728 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\massfilter.sys -- (massfilter) DRV - [2009-02-03 17:36:58 | 000,059,000 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x) DRV - [2009-02-02 19:14:20 | 000,105,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea) DRV - [2009-02-02 19:14:20 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k) DRV - [2009-02-02 19:14:20 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k) DRV - [2008-12-02 21:34:54 | 000,094,624 | ---- | M] (AlcaTech) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\mmrtkrnl.sys -- (MMRTKRNL) DRV - [2008-11-24 13:04:41 | 000,717,296 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\sptd.sys -- (sptd) DRV - [2008-10-13 18:28:20 | 002,176,856 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2008-09-15 08:56:34 | 000,008,064 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt) DRV - [2008-09-15 08:56:24 | 000,022,016 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc) DRV - [2008-09-15 08:56:24 | 000,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd) DRV - [2008-09-15 08:56:24 | 000,008,064 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev) DRV - [2008-08-26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd) DRV - [2008-05-07 11:40:01 | 000,317,976 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\iaStor.sys -- (iaStor) DRV - [2008-05-02 14:59:40 | 000,122,368 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169) DRV - [2008-04-28 15:29:25 | 003,658,752 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5v32.sys -- (NETw5v32) Sterownik karty Intel(R) DRV - [2008-03-29 11:24:17 | 003,544,064 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag) DRV - [2008-03-17 09:42:22 | 000,081,960 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btwaudio.sys -- (btwaudio) DRV - [2008-03-17 09:42:20 | 000,100,392 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btwavdt.sys -- (btwavdt) DRV - [2008-03-17 09:42:16 | 000,017,320 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btwrchid.sys -- (btwrchid) DRV - [2008-01-25 01:39:23 | 001,090,304 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\smserial.sys -- (smserial) DRV - [2008-01-21 04:23:27 | 000,386,616 | ---- | M] (LSI Corporation, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasr.sys -- (MegaSR) DRV - [2008-01-21 04:23:27 | 000,149,560 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320) DRV - [2008-01-21 04:23:27 | 000,031,288 | ---- | M] (LSI Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas) DRV - [2008-01-21 04:23:26 | 000,101,432 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m) DRV - [2008-01-21 04:23:26 | 000,074,808 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4) DRV - [2008-01-21 04:23:26 | 000,040,504 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs) DRV - [2008-01-21 04:23:26 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (winusb) DRV - [2008-01-21 04:23:25 | 000,300,600 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci) DRV - [2008-01-21 04:23:25 | 000,089,656 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS) DRV - [2008-01-21 04:23:24 | 001,122,360 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300) DRV - [2008-01-21 04:23:24 | 000,118,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel(R) DRV - [2008-01-21 04:23:24 | 000,079,928 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas) DRV - [2008-01-21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV) DRV - [2008-01-21 04:23:23 | 000,130,616 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid) DRV - [2008-01-21 04:23:23 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2) DRV - [2008-01-21 04:23:23 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI) DRV - [2008-01-21 04:23:23 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC) DRV - [2008-01-21 04:23:23 | 000,079,416 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc) DRV - [2008-01-21 04:23:22 | 000,342,584 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor) DRV - [2008-01-21 04:23:21 | 000,422,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx) DRV - [2008-01-21 04:23:21 | 000,102,968 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid) DRV - [2008-01-21 04:23:21 | 000,073,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\USBAUDIO.sys -- (usbaudio) Sterownik audio USB (WDM) DRV - [2008-01-21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor) DRV - [2008-01-21 04:23:20 | 000,238,648 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci) DRV - [2008-01-21 04:23:00 | 000,020,024 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide) DRV - [2008-01-21 04:23:00 | 000,019,000 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide) DRV - [2008-01-21 04:23:00 | 000,017,464 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide) DRV - [2007-12-07 03:12:47 | 000,196,400 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SynTP.sys -- (SynTP) DRV - [2007-08-11 05:19:26 | 000,029,752 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [File_System | Boot | Running] -- C:\Windows\System32\drivers\AsDsm.sys -- (AsDsm) DRV - [2007-08-09 05:42:08 | 000,045,568 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk) DRV - [2007-08-03 06:26:21 | 000,020,936 | ---- | M] () [Kernel | Auto | Running] -- C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys -- (ghaio) DRV - [2007-07-30 20:54:02 | 000,038,400 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp) DRV - [2007-07-30 19:42:58 | 000,043,008 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk) DRV - [2007-07-24 20:09:04 | 000,013,880 | ---- | M] () [Kernel | Auto | Running] -- C:\Program Files\ATKGFNEX\ASMMAP.sys -- (ASMMAP) DRV - [2007-05-11 04:10:50 | 000,034,704 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\blueletaudio.sys -- (BlueletAudio) DRV - [2007-05-09 02:59:40 | 000,036,496 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btcusb.sys -- (Btcsrusb) DRV - [2007-03-05 07:00:04 | 000,027,792 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio) DRV - [2007-03-05 06:59:04 | 000,018,320 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btnetdrv.sys -- (BT) DRV - [2007-03-05 06:57:14 | 000,019,472 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VHIDMini.sys -- (VHidMinidrv) DRV - [2007-03-05 06:56:18 | 000,035,600 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\BTHidMgr.sys -- (BTHidMgr) DRV - [2007-03-05 06:55:12 | 000,020,880 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\vbtenum.sys -- (BTHidEnum) DRV - [2007-03-05 06:53:18 | 000,044,304 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VCommMgr.sys -- (VcommMgr) DRV - [2007-03-05 06:52:18 | 000,034,448 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VComm.sys -- (VComm) DRV - [2007-01-25 03:08:39 | 000,005,632 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\kbfiltr.sys -- (kbfiltr) DRV - [2006-12-15 00:11:57 | 000,007,680 | ---- | M] (ATK0100) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ATKACPI.sys -- (MTsensor) DRV - [2006-12-01 15:22:36 | 000,192,512 | ---- | M] (MorningSound Co., Ltd.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\VirtualCam.sys -- (VirtualCam) DRV - [2006-11-02 11:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx) DRV - [2006-11-02 11:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata) DRV - [2006-11-02 11:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960) DRV - [2006-11-02 11:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp) DRV - [2006-11-02 11:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx) DRV - [2006-11-02 11:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid) DRV - [2006-11-02 11:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi) DRV - [2006-11-02 11:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx) DRV - [2006-11-02 11:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3) DRV - [2006-11-02 11:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x) DRV - [2006-11-02 11:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi) DRV - [2006-11-02 10:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM) DRV - [2006-11-02 10:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer) DRV - [2006-11-02 10:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp) DRV - [2006-11-02 10:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo) DRV - [2006-11-02 10:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm) DRV - [2006-11-02 10:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm) DRV - [2006-11-02 09:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi) DRV - [2006-11-02 09:30:56 | 000,194,048 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\yk60x86.sys -- (yukonwlh) DRV - [2006-09-27 05:01:36 | 000,241,628 | ---- | M] (Syntek America Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\StkAMini.sys -- (StkAMini) DRV - [2006-08-02 08:44:04 | 000,004,772 | ---- | M] (Syntek America Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\StkScan.sys -- (StkScan) DRV - [2006-07-10 18:19:58 | 000,027,032 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x) DRV - [2006-06-14 16:56:56 | 000,013,680 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x) DRV - [2005-02-11 10:19:20 | 000,055,216 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\k750bus.sys -- (k750bus) Sony Ericsson 750 driver (WDM) DRV - [2003-07-29 09:57:20 | 000,040,448 | ---- | M] (DeviceGuys, Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\Dgivecp.Sys -- (DgiVecp) DRV - [2003-04-28 11:31:18 | 000,051,169 | ---- | M] (OEM) [Kernel | System | Running] -- C:\Windows\System32\drivers\OXSER.SYS -- (oxser) DRV - [1997-01-14 07:12:22 | 000,006,848 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\DS1410D.SYS -- (DS1410D) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = http://www.msn.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://search.bearshare.com/pl/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = : [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.update: false FF - prefs.js..browser.startup.homepage: "google.pl" FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=" FF - prefs.js..network.proxy.ftp: "218.97.194.94" FF - prefs.js..network.proxy.ftp_port: 80 FF - prefs.js..network.proxy.gopher: "218.97.194.94" FF - prefs.js..network.proxy.gopher_port: 80 FF - prefs.js..network.proxy.http: "94.75.253.67" FF - prefs.js..network.proxy.http_port: 80 FF - prefs.js..network.proxy.socks: "218.97.194.94" FF - prefs.js..network.proxy.socks_port: 80 FF - prefs.js..network.proxy.ssl: "218.97.194.94" FF - prefs.js..network.proxy.ssl_port: 80 FF - HKLM\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2008-12-27 16:30:04 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010-10-08 20:55:01 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-10-09 21:42:13 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2009-01-01 12:04:57 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\mozilla\Extensions [2009-01-01 12:04:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mimi\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2010-10-17 10:54:17 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\mozilla\Firefox\Profiles\ngz78dgt.default\extensions [2010-10-17 10:54:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mimi\AppData\Roaming\mozilla\Firefox\Profiles\ngz78dgt.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66} [2009-08-02 21:21:21 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\Mimi\AppData\Roaming\mozilla\Firefox\Profiles\ngz78dgt.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8} [2010-10-09 08:52:26 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\mozilla\Firefox\Profiles\ngz78dgt.default\extensions\personas@christopher.beard [2010-10-17 12:11:42 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions [2010-10-16 12:58:59 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru [2010-10-16 12:58:48 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru [2009-08-31 14:11:24 | 000,927,232 | ---- | M] (Ganymede Technologies) -- C:\Program Files\Mozilla Firefox\plugins\NPBOARDS.dll [2009-06-15 11:14:40 | 000,120,296 | ---- | M] ( ) -- C:\Program Files\Mozilla Firefox\plugins\npganymedenet.dll [2009-08-31 14:11:30 | 000,685,552 | ---- | M] (Ganymede Technologies) -- C:\Program Files\Mozilla Firefox\plugins\NPMAKAOV2.dll [2010-10-08 20:54:55 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml [2010-10-08 20:54:55 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml [2010-10-08 20:54:55 | 000,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml [2010-10-08 20:54:55 | 000,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml [2010-10-08 20:54:55 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml [2010-10-08 20:54:56 | 000,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2010-10-23 15:19:23 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare) O4 - HKLM..\Run: [avp] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO) O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1 O8 - Extra context menu item: Ściągnij przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_link.htm () O8 - Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_all.htm () O8 - Extra context menu item: 똠i퉓nij przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_link.htm () O8 - Extra context menu item: 똠i퉓nij wszystko przy pomocy FlashGet'a - C:\Program Files\FlashGet\jc_all.htm () O9 - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO) O9 - Extra Button: Kolekcja wycinków HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.) O9 - Extra Button: Zaznaczanie HP Smart - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.) O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO) O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (FlashGet.com) O9 - Extra 'Tools' menuitem : &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (FlashGet.com) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\gamelsp.dll (Copyright (C) GameCap) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\gamelsp.dll (Copyright (C) GameCap) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\gamelsp.dll (Copyright (C) GameCap) O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Armor2net\Armor2net Personal Firewall\NETDOG.DLL () O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Armor2net\Armor2net Personal Firewall\NETDOG.DLL () O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\System32\gamelsp.dll (Copyright (C) GameCap) O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation) O16 - DPF: {108D3206-846A-4A93-BACB-F0572D043ED7} http://triodvr.dyndns.org/webrec.cab (DHSurveillanceCtrl Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11) O16 - DPF: {ADACAA8F-3595-47FE-9C31-9C7471B9BEC7} http://212.160.173.247/ssi.cgi/cab/OCXChecker_8300.cab (OCXDownloadChecker Control) O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 94.72.64.10 94.72.64.11 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~2\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\kloehk.dll (Kaspersky Lab ZAO) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\klogon: DllName - C:\Windows\system32\klogon.dll - C:\Windows\System32\klogon.dll (Kaspersky Lab ZAO) O24 - Desktop WallPaper: C:\Users\Mimi\AppData\Roaming\Mozilla\Firefox\Tapeta pulpitu.bmp O24 - Desktop BackupWallPaper: C:\Users\Mimi\AppData\Roaming\Mozilla\Firefox\Tapeta pulpitu.bmp O27 - HKLM IFEO\taskmgr.exe: Debugger - "C:\USERS\MIMI\DESKTOP\PROCESSEXPLORER.EXE" File not found O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006-09-18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2009-06-23 17:08:11 | 000,004,057 | ---- | M] () - E:\autopot.ahk -- [ NTFS ] O32 - AutoRun File - [2010-09-12 21:27:50 | 000,000,118 | -H-- | M] () - E:\autopot.ini -- [ NTFS ] O32 - AutoRun File - [2008-12-28 17:15:39 | 000,024,576 | ---- | M] (FREE) - E:\Autopotion.exe -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 90 Days ==========[/color] [2010-10-23 17:44:29 | 000,000,000 | ---D | C] -- C:\Users\Mimi\Desktop\CCleaner [2010-10-23 17:42:30 | 001,187,896 | ---- | C] (Piriform Ltd) -- C:\Users\Mimi\Desktop\ccsetup236.exe [2010-10-23 17:00:40 | 000,000,000 | ---D | C] -- C:\Users\Mimi\DoctorWeb [2010-10-23 16:38:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Panda Security [2010-10-23 16:38:18 | 000,000,000 | ---D | C] -- C:\Program Files\Panda USB Vaccine [2010-10-23 16:30:09 | 000,000,000 | ---D | C] -- C:\Users\Mimi\AppData\Local\COMODO [2010-10-23 16:01:29 | 000,000,000 | -H-D | C] -- C:\VritualRoot [2010-10-23 15:33:18 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN [2010-10-23 15:25:30 | 000,000,000 | ---D | C] -- C:\Windows\temp [2010-10-23 15:25:29 | 000,000,000 | ---D | C] -- C:\Users\Mimi\AppData\Local\temp [2010-10-23 14:58:27 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT [2010-10-23 14:20:21 | 000,311,312 | ---- | C] (Kaspersky Lab) -- C:\Windows\System32\drivers\1744762.sys [2010-10-23 14:20:21 | 000,128,016 | ---- | C] (Kaspersky Lab) -- C:\Windows\System32\drivers\17447621.sys [2010-10-23 13:53:50 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\Mimi\Desktop\OTL.exe [2010-10-23 13:29:49 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO [2010-10-23 13:28:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo [2010-10-16 12:55:59 | 000,488,536 | ---- | C] (Kaspersky Lab) -- C:\Windows\System32\drivers\klif.sys [2010-10-13 19:04:34 | 000,000,000 | ---D | C] -- C:\Users\Mimi\AppData\Local\Sunbelt Software [2010-10-07 16:57:45 | 000,000,000 | ---D | C] -- C:\ProgramData\TamoSoft [2010-10-07 16:47:08 | 000,000,000 | ---D | C] -- C:\Users\Mimi\Documenty\Nowy folder [2010-10-05 21:27:04 | 000,228,024 | ---- | C] (Kaspersky Lab ZAO) -- C:\Windows\System32\klogon.dll [2010-10-03 22:19:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Gadu-Gadu 10 [2010-09-26 20:37:29 | 000,000,000 | ---D | C] -- C:\Users\Mimi\AppData\Roaming\fltk.org [2010-09-26 20:11:50 | 000,000,000 | ---D | C] -- C:\Users\Mimi\Desktop\ePSXe [2010-09-26 15:49:53 | 000,000,000 | ---D | C] -- C:\Users\Mimi\Desktop\SRO - niemiły update. Koniec SRO_pliki [2010-09-18 09:42:49 | 000,000,000 | ---D | C] -- C:\Program Files\Xvid [2010-09-18 09:41:01 | 000,031,744 | ---- | C] (Disappearing Inc.) -- C:\Windows\System32\huffyuv.dll [2010-09-17 14:56:51 | 000,000,000 | ---D | C] -- C:\Users\Mimi\Documenty\Sony Media Libraries [2010-09-17 14:54:25 | 000,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information [2010-09-17 14:51:08 | 000,000,000 | ---D | C] -- C:\Program Files\Vstplugins [2010-09-17 14:50:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony [2010-09-17 14:08:48 | 000,000,000 | ---D | C] -- C:\Users\Mimi\Documenty\My Videos [2010-09-16 20:01:04 | 000,000,000 | ---D | C] -- C:\Users\Mimi\AppData\Roaming\Sony Creative Software [2010-09-16 19:28:05 | 000,000,000 | ---D | C] -- C:\Users\Mimi\Desktop\trailer [2010-09-16 18:00:11 | 000,000,000 | ---D | C] -- C:\ProgramData\eSellerate [2010-09-16 18:00:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\eSellerate [2010-09-16 17:56:29 | 000,000,000 | ---D | C] -- C:\Users\Mimi\Documenty\Vegas Movie Studio PE 9.0 Projects [2010-09-16 17:54:49 | 000,000,000 | ---D | C] -- C:\Program Files\Sony [2010-09-11 13:35:28 | 000,118,784 | ---- | C] (OptionNV) -- C:\Windows\System32\Gtdetectsc.exe [2010-09-11 13:35:28 | 000,065,635 | ---- | C] (Option) -- C:\Windows\System32\GtmNicApp.cpl [2010-09-11 13:35:27 | 000,000,000 | ---D | C] -- C:\Program Files\option [2010-09-10 23:41:40 | 000,285,480 | ---- | C] (COMODO) -- C:\Windows\System32\guard32.dll [2010-09-10 23:40:32 | 000,078,504 | ---- | C] (COMODO) -- C:\Windows\System32\drivers\inspect.sys [2010-09-10 23:40:32 | 000,030,112 | ---- | C] (COMODO) -- C:\Windows\System32\drivers\cmdhlp.sys [2010-09-10 23:40:30 | 000,236,088 | ---- | C] (COMODO) -- C:\Windows\System32\drivers\cmdGuard.sys [2010-09-10 23:40:30 | 000,017,256 | ---- | C] (COMODO) -- C:\Windows\System32\drivers\cmderd.sys [2010-09-04 09:20:19 | 000,000,000 | ---D | C] -- C:\Program Files\CeRegEditor [2010-08-29 17:07:04 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation [2010-08-28 18:26:46 | 000,000,000 | ---D | C] -- C:\Users\Mimi\Documenty\VirtualDJ [2010-08-28 18:26:46 | 000,000,000 | ---D | C] -- C:\Program Files\VirtualDJ [2010-08-27 16:20:35 | 000,679,936 | ---- | C] (Generated by JEDI) -- C:\Windows\System32\D3DX81ab.dll [2010-08-27 16:10:39 | 000,000,000 | ---D | C] -- C:\Users\Mimi\Desktop\ZSZC_105_1.679 [2010-08-24 20:18:58 | 000,000,000 | ---D | C] -- C:\Users\Mimi\AppData\Local\Activision [2010-08-20 21:07:13 | 000,000,000 | ---D | C] -- C:\Program Files\AviSynth 2.5 [2010-08-20 21:06:45 | 000,000,000 | ---D | C] -- C:\Program Files\Gabest [2010-08-20 21:05:45 | 000,000,000 | ---D | C] -- C:\Program Files\GordianKnot [2010-08-16 10:54:10 | 002,271,152 | ---- | C] (Codejock Software) -- C:\Windows\System32\Codejock.CommandBars.Unicode.v12.1.1.ocx [2010-08-16 10:54:07 | 001,779,632 | ---- | C] (Codejock Software) -- C:\Windows\System32\Codejock.Controls.v12.1.1.ocx [2010-08-15 11:05:08 | 000,000,000 | ---D | C] -- C:\Program Files\Call of Duty [2010-08-15 10:46:20 | 000,005,744 | ---- | C] (MCCI) -- C:\Windows\System32\drivers\k750whnt.sys [2010-08-15 10:46:20 | 000,005,744 | ---- | C] (MCCI) -- C:\Windows\System32\drivers\k750wh.sys [2010-08-15 10:46:19 | 000,055,216 | ---- | C] (MCCI) -- C:\Windows\System32\drivers\k750bus.sys [2010-08-09 13:45:03 | 000,000,000 | ---D | C] -- C:\perflogs [2010-08-07 19:05:11 | 000,000,000 | ---D | C] -- C:\ProgramData\HPAppData [2010-08-03 13:26:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla [2010-08-02 19:10:40 | 000,000,000 | ---D | C] -- C:\Program Files\FLVPlayer [2010-07-31 12:01:42 | 000,000,000 | ---D | C] -- C:\Users\Mimi\AppData\Roaming\Download Manager [2010-07-30 19:45:04 | 000,000,000 | ---D | C] -- C:\Program Files\Active WebCam [2010-07-29 20:48:40 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\csnp325.dll [2010-07-29 19:25:56 | 001,777,664 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\WavesLib.dll [2010-07-29 19:25:56 | 000,339,968 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSXT.dll [2010-07-29 19:25:56 | 000,185,776 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSHD.dll [2010-07-29 19:25:56 | 000,167,936 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSHP360.dll [2010-07-29 19:25:56 | 000,135,168 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSWOW.dll [2010-07-29 19:25:55 | 001,933,312 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioEQ.dll [2010-07-29 19:25:55 | 000,159,744 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO20.dll [2010-07-29 19:25:55 | 000,126,976 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO.dll [2010-07-29 19:25:53 | 000,143,360 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\System32\FMAPO.dll [2010-07-25 21:16:22 | 000,000,000 | ---D | C] -- C:\Program Files\QS [2007-01-25 03:08:39 | 000,005,632 | ---- | C] ( ) -- C:\Windows\System32\drivers\kbfiltr.sys [6 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [color=#E56717]========== Files - Modified Within 90 Days ==========[/color] [2010-10-23 17:44:31 | 000,000,602 | ---- | M] () -- C:\Users\Mimi\Desktop\CCleaner.lnk [2010-10-23 17:42:40 | 001,187,896 | ---- | M] (Piriform Ltd) -- C:\Users\Mimi\Desktop\ccsetup236.exe [2010-10-23 16:57:21 | 000,045,056 | ---- | M] () -- C:\Windows\System32\acovcnt.exe [2010-10-23 16:57:16 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2010-10-23 16:57:15 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2010-10-23 16:57:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010-10-23 16:56:58 | 3220,295,680 | -HS- | M] () -- C:\hiberfil.sys [2010-10-23 16:56:08 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2010-10-23 16:42:19 | 000,798,748 | ---- | M] () -- C:\Windows\System32\perfh015.dat [2010-10-23 16:42:19 | 000,716,830 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2010-10-23 16:42:19 | 000,185,750 | ---- | M] () -- C:\Windows\System32\perfc015.dat [2010-10-23 16:42:19 | 000,151,594 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2010-10-23 16:01:36 | 000,000,105 | ---- | M] () -- C:\Users\Mimi\AppData\Roaming\private_server_loader.ini [2010-10-23 15:31:14 | 000,001,246 | RHS- | M] () -- C:\Users\Mimi\ntuser.pol [2010-10-23 15:19:23 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts [2010-10-23 15:08:33 | 000,000,680 | ---- | M] () -- C:\Users\Mimi\AppData\Local\d3d9caps.dat [2010-10-23 14:15:49 | 000,488,384 | ---- | M] () -- C:\Windows\System32\drivers\sfi.dat [2010-10-23 13:54:49 | 524,288,000 | ---- | M] () -- C:\REMOVE_THIS_FILE.livecd.swap [2010-10-23 13:30:06 | 000,001,753 | ---- | M] () -- C:\Users\Public\Desktop\COMODO Antivirus.lnk [2010-10-22 15:48:46 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\Mimi\Desktop\OTL.exe [2010-10-17 20:19:39 | 000,001,125 | ---- | M] () -- C:\Windows\winamp.ini [2010-10-17 16:34:57 | 000,000,059 | ---- | M] () -- C:\Users\Mimi\Desktop\Enter 1.ahk [2010-10-16 13:27:21 | 000,000,641 | ---- | M] () -- C:\Users\Mimi\Desktop\ZSZC Loader.lnk [2010-10-16 13:25:49 | 000,000,048 | ---- | M] () -- C:\loader.ini [2010-10-16 12:58:24 | 000,113,933 | ---- | M] () -- C:\Windows\System32\drivers\klin.dat [2010-10-16 12:58:24 | 000,097,549 | ---- | M] () -- C:\Windows\System32\drivers\klick.dat [2010-10-16 12:55:59 | 000,488,536 | ---- | M] (Kaspersky Lab) -- C:\Windows\System32\drivers\klif.sys [2010-10-16 12:55:43 | 000,000,654 | ---- | M] () -- C:\Users\Mimi\SciTE.session [2010-10-16 08:18:32 | 000,005,871 | ---- | M] () -- C:\Users\Mimi\Desktop\Loader Edited Source.au3 [2010-10-15 16:16:37 | 000,002,466 | ---- | M] () -- C:\Users\Mimi\Desktop\SYF.lnk [2010-10-10 08:54:47 | 000,423,584 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2010-10-09 21:15:24 | 000,019,208 | ---- | M] () -- C:\Users\Mimi\Desktop\cc_20100828_220051.reg [2010-10-06 19:30:27 | 000,001,102 | ---- | M] () -- C:\Users\Mimi\Desktop\EdxLoader.lnk [2010-10-05 21:27:04 | 000,228,024 | ---- | M] (Kaspersky Lab ZAO) -- C:\Windows\System32\klogon.dll [2010-10-01 14:51:15 | 000,027,794 | ---- | M] () -- C:\Users\Mimi\.recently-used.xbel [2010-09-28 18:20:42 | 000,041,888 | ---- | M] () -- C:\Windows\System32\drivers\Oreans.sys [2010-09-26 15:49:53 | 000,056,723 | ---- | M] () -- C:\Users\Mimi\Desktop\SRO - niemiły update. Koniec SRO.htm [2010-09-25 15:15:21 | 000,002,224 | ---- | M] () -- C:\Users\Mimi\Documenty\Nowy AutoIt v3 Script.au3 [2010-09-25 15:15:21 | 000,002,224 | ---- | M] () -- C:\Users\Mimi\Desktop\Loader Source.au3 [2010-09-21 14:49:59 | 000,102,400 | ---- | M] (Copyright (C) GameCap) -- C:\Windows\System32\gamelsp.dll [2010-09-20 19:03:43 | 000,000,116 | ---- | M] () -- C:\Windows\NeroDigital.ini [2010-09-20 18:59:05 | 000,141,824 | ---- | M] () -- C:\Users\Mimi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010-09-17 15:02:30 | 000,000,871 | ---- | M] () -- C:\Users\Mimi\Desktop\Sony Vegas 7.0.lnk [2010-09-16 14:04:09 | 000,000,060 | ---- | M] () -- C:\Users\Mimi\Desktop\Enter 2.ahk [2010-09-14 14:03:52 | 000,001,227 | ---- | M] () -- C:\Users\Mimi\Desktop\Server Stats.lnk [2010-09-14 14:03:23 | 000,001,798 | ---- | M] () -- C:\Users\Mimi\Desktop\Sea-Emulator.lnk [2010-09-13 19:47:18 | 000,001,890 | -HS- | M] () -- C:\ProgramData\KGyGaAvL.sys [2010-09-12 10:51:52 | 000,001,455 | ---- | M] () -- C:\Users\Mimi\Desktop\JB Hider.lnk [2010-09-12 10:51:50 | 000,001,486 | ---- | M] () -- C:\Users\Mimi\Desktop\Select-Bot ZSZC.lnk [2010-09-11 15:30:51 | 000,000,472 | ---- | M] () -- C:\Windows\WINCMD.INI [2010-09-11 14:51:49 | 000,001,695 | ---- | M] () -- C:\Users\Mimi\Desktop\ZSZC Char Status.lnk [2010-09-10 23:41:40 | 000,285,480 | ---- | M] (COMODO) -- C:\Windows\System32\guard32.dll [2010-09-10 23:40:32 | 000,078,504 | ---- | M] (COMODO) -- C:\Windows\System32\drivers\inspect.sys [2010-09-10 23:40:32 | 000,030,112 | ---- | M] (COMODO) -- C:\Windows\System32\drivers\cmdhlp.sys [2010-09-10 23:40:30 | 000,236,088 | ---- | M] (COMODO) -- C:\Windows\System32\drivers\cmdGuard.sys [2010-09-10 23:40:30 | 000,017,256 | ---- | M] (COMODO) -- C:\Windows\System32\drivers\cmderd.sys [2010-09-06 18:59:12 | 000,000,151 | ---- | M] () -- C:\Windows\PhotoSnapViewer.INI [2010-08-24 18:21:56 | 000,000,347 | ---- | M] () -- C:\Windows\CoDUO.INI [2010-08-18 14:42:11 | 000,794,408 | ---- | M] () -- C:\Windows\System32\pbsvc.exe [2010-08-18 14:05:50 | 000,139,152 | ---- | M] () -- C:\Users\Mimi\AppData\Roaming\PnkBstrK.sys [2010-08-15 11:14:25 | 000,000,745 | ---- | M] () -- C:\Windows\COD.INI [2010-08-04 18:50:57 | 000,015,360 | ---- | M] () -- C:\Windows\System32\BASSMOD.dll [2010-08-01 14:15:00 | 000,002,562 | ---- | M] () -- C:\Windows\diagwrn.xml [2010-08-01 14:15:00 | 000,001,908 | ---- | M] () -- C:\Windows\diagerr.xml [6 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2010-10-23 17:44:30 | 000,000,602 | ---- | C] () -- C:\Users\Mimi\Desktop\CCleaner.lnk [2010-10-23 16:01:36 | 000,000,105 | ---- | C] () -- C:\Users\Mimi\AppData\Roaming\private_server_loader.ini [2010-10-23 15:29:22 | 3220,295,680 | -HS- | C] () -- C:\hiberfil.sys [2010-10-23 15:08:19 | 000,000,680 | ---- | C] () -- C:\Users\Mimi\AppData\Local\d3d9caps.dat [2010-10-23 13:35:46 | 000,488,384 | ---- | C] () -- C:\Windows\System32\drivers\sfi.dat [2010-10-23 13:34:15 | 524,288,000 | ---- | C] () -- C:\REMOVE_THIS_FILE.livecd.swap [2010-10-23 13:30:06 | 000,001,753 | ---- | C] () -- C:\Users\Public\Desktop\COMODO Antivirus.lnk [2010-10-16 13:23:47 | 000,000,048 | ---- | C] () -- C:\loader.ini [2010-10-16 12:58:24 | 000,113,933 | ---- | C] () -- C:\Windows\System32\drivers\klin.dat [2010-10-16 12:58:24 | 000,097,549 | ---- | C] () -- C:\Windows\System32\drivers\klick.dat [2010-10-15 16:16:10 | 000,002,466 | ---- | C] () -- C:\Users\Mimi\Desktop\SYF.lnk [2010-10-06 19:30:27 | 000,001,102 | ---- | C] () -- C:\Users\Mimi\Desktop\EdxLoader.lnk [2010-10-05 14:53:39 | 000,000,641 | ---- | C] () -- C:\Users\Mimi\Desktop\ZSZC Loader.lnk [2010-10-01 14:51:15 | 000,027,794 | ---- | C] () -- C:\Users\Mimi\.recently-used.xbel [2010-09-29 17:18:36 | 000,005,871 | ---- | C] () -- C:\Users\Mimi\Desktop\Loader Edited Source.au3 [2010-09-28 18:20:42 | 000,041,888 | ---- | C] () -- C:\Windows\System32\drivers\Oreans.sys [2010-09-26 15:49:53 | 000,056,723 | ---- | C] () -- C:\Users\Mimi\Desktop\SRO - niemiły update. Koniec SRO.htm [2010-09-25 15:15:27 | 000,002,224 | ---- | C] () -- C:\Users\Mimi\Documenty\Nowy AutoIt v3 Script.au3 [2010-09-25 15:13:59 | 000,002,224 | ---- | C] () -- C:\Users\Mimi\Desktop\Loader Source.au3 [2010-09-18 09:42:49 | 000,819,200 | ---- | C] () -- C:\Windows\System32\xvidcore.dll [2010-09-18 09:42:49 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll [2010-09-18 09:42:49 | 000,077,824 | ---- | C] () -- C:\Windows\System32\xvid.ax [2010-09-17 15:02:30 | 000,000,871 | ---- | C] () -- C:\Users\Mimi\Desktop\Sony Vegas 7.0.lnk [2010-09-16 19:28:13 | 000,000,060 | ---- | C] () -- C:\Users\Mimi\Desktop\Enter 2.ahk [2010-09-12 16:21:37 | 000,000,059 | ---- | C] () -- C:\Users\Mimi\Desktop\Enter 1.ahk [2010-09-12 10:40:24 | 000,001,486 | ---- | C] () -- C:\Users\Mimi\Desktop\Select-Bot ZSZC.lnk [2010-09-12 10:39:44 | 000,001,227 | ---- | C] () -- C:\Users\Mimi\Desktop\Server Stats.lnk [2010-08-30 10:53:53 | 000,001,455 | ---- | C] () -- C:\Users\Mimi\Desktop\JB Hider.lnk [2010-08-28 22:00:53 | 000,019,208 | ---- | C] () -- C:\Users\Mimi\Desktop\cc_20100828_220051.reg [2010-08-27 16:20:35 | 001,970,176 | ---- | C] () -- C:\Windows\System32\d3dx9.dll [2010-08-24 18:06:55 | 000,000,347 | ---- | C] () -- C:\Windows\CoDUO.INI [2010-08-17 18:21:30 | 000,794,408 | ---- | C] () -- C:\Windows\System32\pbsvc.exe [2010-08-15 11:14:25 | 000,000,745 | ---- | C] () -- C:\Windows\COD.INI [2010-07-31 11:35:01 | 000,001,798 | ---- | C] () -- C:\Users\Mimi\Desktop\Sea-Emulator.lnk [2010-07-29 20:48:46 | 000,020,480 | ---- | C] () -- C:\Windows\FixCamera.exe [2010-07-29 19:18:59 | 000,000,553 | ---- | C] () -- C:\Windows\USetup.iss [2010-07-09 21:04:40 | 000,041,872 | ---- | C] () -- C:\Windows\System32\xfcodec.dll [2010-05-10 21:43:08 | 000,000,151 | ---- | C] () -- C:\Windows\PhotoSnapViewer.INI [2010-04-08 20:30:19 | 000,210,456 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll [2010-04-08 20:30:19 | 000,206,360 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll [2010-04-08 20:30:19 | 000,198,168 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll [2010-04-08 20:30:19 | 000,198,168 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll [2010-04-08 20:30:19 | 000,194,072 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll [2010-04-08 20:30:19 | 000,026,136 | ---- | C] () -- C:\Windows\System32\IVIresize.dll [2010-03-27 19:09:19 | 000,304,128 | ---- | C] () -- C:\Windows\presys64.dll [2010-03-27 19:09:19 | 000,296,448 | ---- | C] () -- C:\Windows\mdiwindb.dll [2010-03-27 19:09:12 | 000,002,430 | ---- | C] () -- C:\Windows\memsetk.dll [2010-03-27 19:09:12 | 000,000,000 | ---- | C] () -- C:\Windows\sntlevel.dll [2010-03-27 19:09:12 | 000,000,000 | ---- | C] () -- C:\Windows\javcorbin.dll [2010-03-27 19:09:12 | 000,000,000 | ---- | C] () -- C:\Windows\javcorain.dll [2010-03-10 15:03:38 | 000,001,125 | ---- | C] () -- C:\Windows\winamp.ini [2010-01-24 20:34:52 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini [2009-12-09 17:29:36 | 001,589,248 | ---- | C] () -- C:\Windows\System32\libmysql_d.dll [2009-11-12 17:05:16 | 000,000,024 | ---- | C] () -- C:\Windows\System32\sysmwwod.dll [2009-08-19 11:15:03 | 000,055,808 | ---- | C] () -- C:\Windows\System32\zlib1.dll [2009-06-22 14:05:55 | 000,051,200 | ---- | C] () -- C:\Windows\System32\cimo.sys [2009-06-13 18:58:07 | 000,000,000 | ---- | C] () -- C:\Windows\PROTOCOL.INI [2009-06-12 15:14:45 | 000,009,656 | ---- | C] () -- C:\Windows\System32\drivers\AntiyFW.sys [2009-06-07 11:20:27 | 000,000,260 | ---- | C] () -- C:\Windows\Clony2.ini [2009-04-26 18:21:20 | 000,143,360 | ---- | C] () -- C:\Windows\System32\XNMHB425.DLL [2009-04-26 18:21:20 | 000,066,560 | ---- | C] () -- C:\Windows\System32\XNMHN425.DLL [2009-04-26 18:21:20 | 000,056,320 | ---- | C] () -- C:\Windows\System32\XNMTE425.DLL [2009-04-26 18:21:20 | 000,006,848 | ---- | C] () -- C:\Windows\System32\drivers\DS1410D.SYS [2009-04-26 18:21:19 | 000,303,616 | ---- | C] () -- C:\Windows\System32\XNMBA425.DLL [2009-04-26 18:21:15 | 000,006,848 | ---- | C] () -- C:\Windows\System32\DS1410D.SYS [2009-04-26 18:20:29 | 000,000,096 | ---- | C] () -- C:\Windows\System32\Win32s.Ini [2009-04-13 21:35:34 | 000,000,276 | ---- | C] () -- C:\Windows\game.ini [2009-04-09 11:02:01 | 000,012,208 | -HS- | C] () -- C:\Windows\System32\KGyGaAvL.sys [2009-03-24 18:33:26 | 000,000,000 | ---- | C] () -- C:\Windows\System32\main.ini [2009-03-08 15:13:48 | 000,000,993 | ---- | C] () -- C:\Windows\VPlayer.INI [2009-02-04 22:22:42 | 001,073,152 | ---- | C] () -- C:\Windows\System32\libmysql_c.dll [2009-02-04 22:22:04 | 000,000,023 | ---- | C] () -- C:\Windows\ODBCINST.INI [2009-02-04 20:38:04 | 000,086,016 | ---- | C] () -- C:\Windows\System32\custmon32.dll [2009-02-04 14:11:20 | 000,001,890 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys [2009-02-04 14:11:20 | 000,000,088 | RHS- | C] () -- C:\ProgramData\DE57113282.sys [2009-01-19 16:27:36 | 000,001,679 | ---- | C] () -- C:\Windows\System32\sk_bho.ini [2009-01-19 16:09:14 | 000,860,211 | --S- | C] () -- C:\Windows\System32\XSIFtk-3.6.2.1.dll [2008-12-31 19:00:48 | 000,139,152 | ---- | C] () -- C:\Users\Mimi\AppData\Roaming\PnkBstrK.sys [2008-12-12 17:35:50 | 000,000,020 | ---- | C] () -- C:\Windows\ATKPF.ini [2008-12-11 21:49:26 | 000,000,040 | ---- | C] () -- C:\Windows\nero.INI [2008-12-10 09:45:12 | 000,000,544 | ---- | C] () -- C:\Windows\ODBC.INI [2008-12-08 20:26:06 | 000,000,116 | ---- | C] () -- C:\Windows\NeroDigital.ini [2008-12-07 20:43:59 | 000,003,972 | ---- | C] () -- C:\Windows\System32\drivers\PciBus.sys [2008-12-06 11:32:03 | 000,014,467 | ---- | C] () -- C:\Windows\CDPLAYER.INI [2008-12-05 19:07:32 | 000,015,360 | ---- | C] () -- C:\Windows\System32\BASSMOD.dll [2008-12-03 14:44:23 | 000,000,472 | ---- | C] () -- C:\Windows\WINCMD.INI [2008-11-22 16:37:54 | 000,141,824 | ---- | C] () -- C:\Users\Mimi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008-04-18 01:45:31 | 000,000,010 | ---- | C] () -- C:\Windows\System32\ABLKSR.ini [2008-04-17 16:44:02 | 006,538,067 | ---- | C] () -- C:\Windows\System32\SRPFSig.dll [2008-04-17 16:44:02 | 000,623,157 | ---- | C] () -- C:\Windows\System32\SRPESig.dll [2008-03-29 09:19:11 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll [2008-02-28 13:25:52 | 000,025,964 | ---- | C] () -- C:\Windows\System32\SRPSigLevel.dll [2008-02-28 13:25:51 | 008,813,777 | ---- | C] () -- C:\Windows\System32\SRPRSig.dll [2008-02-28 13:25:51 | 000,622,113 | ---- | C] () -- C:\Windows\System32\SRPList.dll [2008-02-28 13:25:51 | 000,013,772 | ---- | C] () -- C:\Windows\System32\SRPImmData.dll [2008-02-28 13:25:51 | 000,002,380 | ---- | C] () -- C:\Windows\System32\SRPBlkCoo.dll [2008-02-28 13:25:51 | 000,000,162 | ---- | C] () -- C:\Windows\System32\SRPCritProc.dll [2007-11-26 22:56:28 | 000,151,415 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat [2007-03-29 23:00:40 | 000,203,264 | ---- | C] () -- C:\Windows\System32\CddbCdda.dll [2007-03-06 23:39:19 | 000,049,152 | ---- | C] () -- C:\Windows\revdevdll.dll [2006-11-02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006-11-02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006-03-09 18:57:59 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll [2003-04-08 12:40:22 | 000,005,679 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI [2002-10-16 00:54:04 | 000,153,088 | ---- | C] () -- C:\Windows\System32\unrar.dll [2002-03-21 14:39:02 | 000,073,728 | ---- | C] () -- C:\Windows\System32\UNACEV2.DLL [2002-03-17 02:00:00 | 000,007,420 | ---- | C] () -- C:\Windows\UA000088.DLL [2001-11-14 14:56:00 | 001,802,240 | ---- | C] () -- C:\Windows\System32\lcppn21.dll [color=#E56717]========== LOP Check ==========[/color] [2009-06-25 16:43:58 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\ACD Systems [2009-01-20 20:30:46 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\Ashampoo [2010-01-29 22:59:52 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\Audacity [2009-05-01 14:30:10 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\avidemux [2009-02-04 11:03:07 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\Canneverbe_Limited [2010-04-23 14:59:16 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\Command & Conquer 3 Tiberium Wars [2008-11-24 13:04:24 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\DAEMON Tools [2010-03-30 09:49:14 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\ESET [2010-09-29 16:14:28 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\fltk.org [2008-11-21 15:20:08 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\Gadu-Gadu [2009-12-05 19:01:25 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\GanymedeNet [2010-03-26 09:07:10 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\GHISLER [2010-09-19 11:42:31 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\gtk-2.0 [2009-10-31 17:04:48 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\ImgBurn [2010-10-23 17:31:06 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\install [2009-02-05 11:39:38 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\ipla [2009-08-02 08:33:18 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\KeePass [2009-05-01 20:41:38 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\KillProcess [2009-05-01 16:31:25 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\Kingston [2010-05-21 17:37:21 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\Megaupload [2010-01-30 13:57:20 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\My Games [2010-02-13 13:18:40 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\Nokia [2009-07-28 11:17:20 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\Nowe Gadu-Gadu [2010-02-13 13:11:45 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\PC Suite [2010-02-24 13:00:03 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\PE Explorer [2008-12-09 20:03:36 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\Publish Providers [2009-11-05 14:54:37 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\Resource Tuner [2010-09-17 14:52:55 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\Sony [2010-09-16 20:01:04 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\Sony Creative Software [2010-03-12 16:59:25 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\Subversion [2010-01-25 23:11:55 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\TeamViewer [2009-01-01 12:04:56 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\Thunderbird [2010-07-07 11:12:19 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\Ubisoft [2010-04-09 13:34:46 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\Ulead Systems [2010-10-02 21:29:54 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\uTorrent [2010-01-15 18:17:00 | 000,000,000 | ---D | M] -- C:\Users\Mimi\AppData\Roaming\WNR [2010-10-23 16:56:08 | 000,032,562 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Files - Unicode (All) ==========[/color] [2010-10-23 16:10:30 | 000,000,000 | ---D | M](C:\Users\Mimi\Documenty\?? ???) -- C:\Users\Mimi\Documenty\넥슨 플러그 [2010-06-29 18:49:30 | 000,000,000 | ---D | C](C:\Users\Mimi\Documenty\?? ???) -- C:\Users\Mimi\Documenty\넥슨 플러그 [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 96 bytes -> C:\ProgramData\Temp:C8B8CEBD @Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:05EE1EEF @Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:D1B5B4F1 @Alternate Data Stream - 12 bytes -> C:\Windows\System32:{DA6227CB-326B-4B4D-9A81-04B61F1538DD} @Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:7E95B6FD @Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:888AFB86 @Alternate Data Stream - 110 bytes -> C:\ProgramData\Temp:11B93A40 @Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:92412C7B < End of report >