OTL logfile created on: 2010-10-26 15:23:22 - Run 1 OTL by OldTimer - Version 3.2.10.0 Folder = F:\ Windows XP Home Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 86,00% Memory free 5,00 Gb Paging File | 4,00 Gb Available in Paging File | 96,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 48,82 Gb Total Space | 25,31 Gb Free Space | 51,84% Space Free | Partition Type: NTFS Drive D: | 25,70 Gb Total Space | 7,11 Gb Free Space | 27,68% Space Free | Partition Type: NTFS Drive E: | 7,85 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Drive F: | 3,73 Gb Total Space | 2,89 Gb Free Space | 77,41% Space Free | Partition Type: FAT32 G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: MINILAB Current User Name: f Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2010-10-26 12:15:00 | 000,575,488 | ---- | M] (OldTimer Tools) -- F:\OTL.exe PRC - [2010-10-24 16:25:44 | 000,035,346 | ---- | M] () -- C:\WINDOWS\system32\temp1.exe PRC - [2009-10-06 01:05:06 | 001,532,000 | ---- | M] (The Firebird Project) -- C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe PRC - [2009-10-06 01:05:06 | 000,065,536 | ---- | M] (The Firebird Project) -- C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe PRC - [2006-09-14 06:21:48 | 000,020,480 | R-S- | M] (Microsoft Corporation) -- C:\Documents and Settings\f\Menu Start\Programy\Autostart\ctfmon.exe PRC - [2006-03-02 14:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe [color=#E56717]========== Modules (SafeList) ==========[/color] MOD - [2010-10-26 12:15:00 | 000,575,488 | ---- | M] (OldTimer Tools) -- F:\OTL.exe MOD - [2006-03-02 14:00:00 | 001,050,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll MOD - [2006-03-02 14:00:00 | 000,102,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ) SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2007-03-15 02:57:00 | 000,105,472 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata) DRV - [2007-03-15 02:55:00 | 000,019,968 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus) DRV - [2007-03-15 02:54:00 | 000,062,592 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD) DRV - [2006-11-22 11:01:48 | 000,693,760 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (Hardlock) DRV - [2006-11-22 11:01:48 | 000,100,096 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\aksusb.sys -- (aksusb) DRV - [2006-11-22 11:01:46 | 000,327,168 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\akshasp.sys -- (akshasp) DRV - [2006-05-10 15:27:20 | 001,543,168 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag) DRV - [2005-06-24 09:28:50 | 000,089,808 | ---- | M] (MCCI) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\slabser.sys -- (slabser) DRV - [2005-06-24 09:28:50 | 000,055,312 | ---- | M] (MCCI) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\slabbus.sys -- (slabbus) digital miniLab (with CPDM) driver (WDM) DRV - [2004-04-20 12:05:10 | 000,057,404 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ftser2k.sys -- (FTSER2K) DRV - [2004-04-20 12:04:56 | 000,024,209 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ftdibus.sys -- (FTDIBUS) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKU\S-1-5-21-839522115-1957994488-2147074499-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 O1 HOSTS File: ([2006-03-02 14:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O4 - HKLM..\Run: [Firebird] C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe (The Firebird Project) O4 - HKU\S-1-5-21-839522115-1957994488-2147074499-1004..\Run: [amva] C:\WINDOWS\system32\amvo.exe () O4 - Startup: C:\Documents and Settings\f\Menu Start\Programy\Autostart\ctfmon.exe (Microsoft Corporation) F3 - HKU\S-1-5-21-839522115-1957994488-2147074499-1004 WinNT: Load - (C:\WINDOWS\svchost.exe) - C:\WINDOWS\svchost.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: explorer = `.vbe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 [2009-08-21 16:49:28 | 000,000,000 | ---D | M] O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 [2009-08-21 16:49:28 | 000,000,000 | ---D | M] O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-839522115-1957994488-2147074499-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.2 O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2007-10-28 11:42:06 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2010-10-26 10:01:01 | 000,000,584 | RHS- | M] () - C:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2006-05-09 21:36:18 | 000,000,034 | RHS- | M] () - D:\autorun.inf -- [ NTFS ] O32 - AutoRun File - [2010-05-28 13:03:36 | 000,000,195 | RHS- | M] () - F:\autorun.inf -- [ FAT32 ] O33 - MountPoints2\{03b4ed3e-d417-11de-a94b-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{07cc9c70-88f1-11df-aa11-00044b0670b7}\Shell\AutoRun\command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{07cc9c70-88f1-11df-aa11-00044b0670b7}\Shell\open\Command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{0be57acc-df12-11de-a959-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{0f887e14-7819-11de-a8d2-00044b0670b7}\Shell\AutoRun\command - "" = rgjkmy3p.exe -- [2008-05-08 10:04:48 | 000,104,684 | RHS- | M] () O33 - MountPoints2\{0f887e14-7819-11de-a8d2-00044b0670b7}\Shell\explore\Command - "" = rgjkmy3p.exe -- [2008-05-08 10:04:48 | 000,104,684 | RHS- | M] () O33 - MountPoints2\{0f887e14-7819-11de-a8d2-00044b0670b7}\Shell\open\Command - "" = rgjkmy3p.exe -- [2008-05-08 10:04:48 | 000,104,684 | RHS- | M] () O33 - MountPoints2\{1615592a-e58b-11de-a965-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{1ceb0762-1853-11dd-a748-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{21974190-3726-11df-a9bb-00044b0670b7}\Shell\Open(&0)\command - "" = F:\Recycled\ctfmon.exe -- [2006-09-14 06:21:48 | 000,020,480 | RHS- | M] () O33 - MountPoints2\{28f27684-4cb5-11dc-a73c-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{2f7b1ea0-2263-11dd-a750-00044b0670b7}\Shell\AutoRun\command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{2f7b1ea0-2263-11dd-a750-00044b0670b7}\Shell\open\Command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{338c9cd6-a2ea-11de-a902-00044b0670b7}\Shell\AutoRun\command - "" = H:\rgjkmy3p.exe -- File not found O33 - MountPoints2\{338c9cd6-a2ea-11de-a902-00044b0670b7}\Shell\explore\Command - "" = H:\rgjkmy3p.exe -- File not found O33 - MountPoints2\{338c9cd6-a2ea-11de-a902-00044b0670b7}\Shell\open\Command - "" = H:\rgjkmy3p.exe -- File not found O33 - MountPoints2\{3677ab4a-9636-11de-a8f6-00044b0670b7}\Shell\AutoRun\command - "" = H:\n68mqcra.exe -- File not found O33 - MountPoints2\{3677ab4a-9636-11de-a8f6-00044b0670b7}\Shell\open\Command - "" = H:\n68mqcra.exe -- File not found O33 - MountPoints2\{3746cf81-5bfb-11de-a8ab-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{37d8687c-37e3-11df-a9bc-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{393e5fe4-8540-11dc-b406-806d6172696f}\Shell - "" = AutoRun O33 - MountPoints2\{393e5fe4-8540-11dc-b406-806d6172696f}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found O33 - MountPoints2\{393e5fe5-8540-11dc-b406-806d6172696f}\Shell - "" = AutoRun O33 - MountPoints2\{393e5fe5-8540-11dc-b406-806d6172696f}\Shell\AutoRun\command - "" = F:\autorun.exe -- File not found O33 - MountPoints2\{3bb9416e-7d6a-11df-aa09-00044b0670b7}\Shell\AutoRun\command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{3bb9416e-7d6a-11df-aa09-00044b0670b7}\Shell\open\Command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{3bb9416f-7d6a-11df-aa09-00044b0670b7}\Shell\AutoRun\command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{3bb9416f-7d6a-11df-aa09-00044b0670b7}\Shell\open\Command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{400974b6-691d-11dd-a7a6-00044b0670b7}\Shell\AutoRun\command - "" = F:\rgjkmy3p.exe -- [2008-05-08 10:04:48 | 000,104,684 | RHS- | M] () O33 - MountPoints2\{400974b6-691d-11dd-a7a6-00044b0670b7}\Shell\explore\Command - "" = F:\rgjkmy3p.exe -- [2008-05-08 10:04:48 | 000,104,684 | RHS- | M] () O33 - MountPoints2\{400974b6-691d-11dd-a7a6-00044b0670b7}\Shell\open\Command - "" = F:\rgjkmy3p.exe -- [2008-05-08 10:04:48 | 000,104,684 | RHS- | M] () O33 - MountPoints2\{4077a832-e6e3-11dd-a83b-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{412e6640-a4fb-11de-a906-00044b0670b7}\Shell\AutoRun\command - "" = mb9x.exe O33 - MountPoints2\{412e6640-a4fb-11de-a906-00044b0670b7}\Shell\open\Command - "" = mb9x.exe O33 - MountPoints2\{49bc230a-3d00-11dd-a771-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{4d7b2b22-d29b-11de-a948-00044b0670b7}\Shell\AutoRun\command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{4d7b2b22-d29b-11de-a948-00044b0670b7}\Shell\open\Command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{4df1e51a-500e-11de-a89d-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{50bbd7c6-d0cd-11dd-a82b-00044b0670b7}\Shell\AutoRun\command - "" = H:\rgjkmy3p.exe -- File not found O33 - MountPoints2\{50bbd7c6-d0cd-11dd-a82b-00044b0670b7}\Shell\explore\Command - "" = H:\rgjkmy3p.exe -- File not found O33 - MountPoints2\{50bbd7c6-d0cd-11dd-a82b-00044b0670b7}\Shell\open\Command - "" = H:\rgjkmy3p.exe -- File not found O33 - MountPoints2\{58cfa18f-eee4-11dc-a719-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{656e8a8c-eadd-11dc-a711-00044b0670b7}\Shell\AutoRun\command - "" = tfk8.exe O33 - MountPoints2\{656e8a8c-eadd-11dc-a711-00044b0670b7}\Shell\explore\Command - "" = tfk8.exe O33 - MountPoints2\{656e8a8c-eadd-11dc-a711-00044b0670b7}\Shell\open\Command - "" = tfk8.exe O33 - MountPoints2\{677e6dd2-feef-11dc-a72b-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{6a8c2dfa-68b6-11df-a9ea-00044b0670b7}\Shell\Open(&0)\command - "" = F:\Recycled\ctfmon.exe -- [2006-09-14 06:21:48 | 000,020,480 | RHS- | M] () O33 - MountPoints2\{70dc0f82-0040-11df-a982-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{73dffeb8-f126-11dd-a846-00044b0670b7}\Shell\AutoRun\command - "" = F:\rgjkmy3p.exe -- [2008-05-08 10:04:48 | 000,104,684 | RHS- | M] () O33 - MountPoints2\{73dffeb8-f126-11dd-a846-00044b0670b7}\Shell\explore\Command - "" = F:\rgjkmy3p.exe -- [2008-05-08 10:04:48 | 000,104,684 | RHS- | M] () O33 - MountPoints2\{73dffeb8-f126-11dd-a846-00044b0670b7}\Shell\open\Command - "" = F:\rgjkmy3p.exe -- [2008-05-08 10:04:48 | 000,104,684 | RHS- | M] () O33 - MountPoints2\{7946c34c-e8a3-11de-a967-00044b0670b7}\Shell\AutoRun\command - "" = F:\rgjkmy3p.exe -- [2008-05-08 10:04:48 | 000,104,684 | RHS- | M] () O33 - MountPoints2\{7946c34c-e8a3-11de-a967-00044b0670b7}\Shell\explore\Command - "" = F:\rgjkmy3p.exe -- [2008-05-08 10:04:48 | 000,104,684 | RHS- | M] () O33 - MountPoints2\{7946c34c-e8a3-11de-a967-00044b0670b7}\Shell\open\Command - "" = F:\rgjkmy3p.exe -- [2008-05-08 10:04:48 | 000,104,684 | RHS- | M] () O33 - MountPoints2\{79da1320-c23e-11df-aa58-00044b0670b7}\Shell\AutoRun\command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{79da1320-c23e-11df-aa58-00044b0670b7}\Shell\open\Command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{7d98a6b6-1822-11dd-a747-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{7dbd6a60-d5c6-11de-a94f-00044b0670b7}\Shell\AutoRun\command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{7dbd6a60-d5c6-11de-a94f-00044b0670b7}\Shell\open\Command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{800be354-ef73-11dc-a71a-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{886e0500-c17c-11dd-a816-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{8abcf579-a904-11dc-a6ea-806d6172696f}\Shell - "" = AutoRun O33 - MountPoints2\{8cefe74d-fc03-11dc-a726-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{8d4f7c9c-9931-11de-a8fa-00044b0670b7}\Shell\Open(&0)\command - "" = H:\Recycled\ctfmon.exe -- File not found O33 - MountPoints2\{8dce3ba4-f72a-11dc-a721-00044b0670b7}\Shell\AutoRun\command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{8dce3ba4-f72a-11dc-a721-00044b0670b7}\Shell\open\Command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{8f80ca4c-b981-11df-aa4f-00044b0670b7}\Shell\AutoRun\command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{8f80ca4c-b981-11df-aa4f-00044b0670b7}\Shell\open\Command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{96b7a40e-4dbd-11de-a898-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{9d68e20d-5957-11dd-a793-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{a41c8294-b23e-11dd-a800-00044b0670b7}\Shell\AutoRun\command - "" = H:\e8kj.exe -- File not found O33 - MountPoints2\{a41c8294-b23e-11dd-a800-00044b0670b7}\Shell\explore\Command - "" = H:\e8kj.exe -- File not found O33 - MountPoints2\{a41c8294-b23e-11dd-a800-00044b0670b7}\Shell\open\Command - "" = H:\e8kj.exe -- File not found O33 - MountPoints2\{a7c8841c-bfb4-11dd-a813-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{ba078424-779c-11df-a9fb-00044b0670b7}\Shell\AutoRun\command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{ba078424-779c-11df-a9fb-00044b0670b7}\Shell\open\Command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{bfcc2076-742f-11dd-a7b0-00044b0670b7}\Shell\AutoRun\command - "" = F:\rgjkmy3p.exe -- [2008-05-08 10:04:48 | 000,104,684 | RHS- | M] () O33 - MountPoints2\{bfcc2076-742f-11dd-a7b0-00044b0670b7}\Shell\explore\Command - "" = F:\rgjkmy3p.exe -- [2008-05-08 10:04:48 | 000,104,684 | RHS- | M] () O33 - MountPoints2\{bfcc2076-742f-11dd-a7b0-00044b0670b7}\Shell\open\Command - "" = F:\rgjkmy3p.exe -- [2008-05-08 10:04:48 | 000,104,684 | RHS- | M] () O33 - MountPoints2\{c928941c-42e1-11dd-a777-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{caf79665-9a26-11df-aa25-00044b0670b7}\Shell\AutoRun\command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{caf79665-9a26-11df-aa25-00044b0670b7}\Shell\open\Command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{caf79666-9a26-11df-aa25-00044b0670b7}\Shell\AutoRun\command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{caf79666-9a26-11df-aa25-00044b0670b7}\Shell\open\Command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{cdd2fe0b-921f-11dd-a7db-00044b0670b7}\Shell\AutoRun\command - "" = H:\rgjkmy3p.exe -- File not found O33 - MountPoints2\{cdd2fe0b-921f-11dd-a7db-00044b0670b7}\Shell\explore\Command - "" = H:\rgjkmy3p.exe -- File not found O33 - MountPoints2\{cdd2fe0b-921f-11dd-a7db-00044b0670b7}\Shell\open\Command - "" = H:\rgjkmy3p.exe -- File not found O33 - MountPoints2\{d710afc4-1537-11dd-a743-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{de686730-a513-11df-aa34-00044b0670b7}\Shell\AutoRun\command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{de686730-a513-11df-aa34-00044b0670b7}\Shell\open\Command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{dfd3a79e-a825-11dc-8f62-806d6172696f}\Shell - "" = AutoRun O33 - MountPoints2\{e04f26d2-6d2a-11de-a8c2-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{e84ceaf8-b6ec-11dd-a804-00044b0670b7}\Shell\AutoRun\command - "" = H:\rgjkmy3p.exe -- File not found O33 - MountPoints2\{e84ceaf8-b6ec-11dd-a804-00044b0670b7}\Shell\explore\Command - "" = H:\rgjkmy3p.exe -- File not found O33 - MountPoints2\{e84ceaf8-b6ec-11dd-a804-00044b0670b7}\Shell\open\Command - "" = H:\rgjkmy3p.exe -- File not found O33 - MountPoints2\{ecd00afc-a8e1-11dc-8f64-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{f1b0a8e6-8cac-11de-a8eb-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{f3f038f8-a903-11dc-bffa-806d6172696f}\Shell - "" = AutoRun O33 - MountPoints2\{f3f038f9-a903-11dc-bffa-806d6172696f}\Shell - "" = AutoRun O33 - MountPoints2\{f5f33a3a-759d-11dd-a7b2-00044b0670b7}\Shell - "" = AutoRun O33 - MountPoints2\{f8c89fb5-c5d0-11dd-a81d-00044b0670b7}\Shell\AutoRun\command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{f8c89fb5-c5d0-11dd-a81d-00044b0670b7}\Shell\open\Command - "" = WScript.exe .\`.vbs O33 - MountPoints2\{fbf9114e-33e5-11de-a879-00044b0670b7}\Shell\AutoRun\command - "" = H:\rgjkmy3p.exe -- File not found O33 - MountPoints2\{fbf9114e-33e5-11de-a879-00044b0670b7}\Shell\explore\Command - "" = H:\rgjkmy3p.exe -- File not found O33 - MountPoints2\{fbf9114e-33e5-11de-a879-00044b0670b7}\Shell\open\Command - "" = H:\rgjkmy3p.exe -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2010-10-25 13:11:36 | 000,356,448 | ---- | C] (The Firebird Project) -- C:\WINDOWS\System32\FBCLIENT.DLL [2010-10-25 12:41:42 | 000,000,000 | ---D | C] -- C:\Kopia (2) digital Contact Printing [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2010-10-26 10:01:01 | 000,000,584 | RHS- | M] () -- C:\autorun.inf [2010-10-25 13:13:02 | 000,651,264 | ---- | M] () -- C:\LBNDBX.GDB [2010-10-25 12:56:19 | 000,070,656 | RHS- | M] () -- C:\WINDOWS\System32\amvo0.dll [2010-10-24 16:25:44 | 000,035,346 | ---- | M] () -- C:\WINDOWS\System32\temp1.exe [2010-10-24 16:25:44 | 000,002,085 | ---- | M] () -- C:\WINDOWS\System32\temp2.exe [2010-10-24 16:25:39 | 000,002,422 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2010-10-24 16:25:39 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2010-10-24 16:25:37 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010-10-22 16:07:10 | 003,932,160 | -H-- | M] () -- C:\Documents and Settings\f\NTUSER.DAT [2010-10-22 16:07:10 | 000,000,188 | -HS- | M] () -- C:\Documents and Settings\f\ntuser.ini [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2010-10-25 13:13:02 | 000,651,264 | ---- | C] () -- C:\LBNDBX.GDB [2010-08-17 09:54:29 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI [2008-06-24 09:58:46 | 000,070,656 | RHS- | C] () -- C:\WINDOWS\System32\amvo0.dll [2007-12-13 01:14:40 | 000,082,944 | ---- | C] () -- C:\Documents and Settings\f\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2007-10-28 14:39:26 | 000,000,283 | ---- | C] () -- C:\WINDOWS\System32\ftdiun2k.ini [2007-10-28 11:52:50 | 000,000,725 | ---- | C] () -- C:\WINDOWS\WINCMD.INI [2006-03-02 14:00:00 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll [2006-03-02 14:00:00 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys [2005-05-25 20:37:58 | 000,025,600 | ---- | C] () -- C:\WINDOWS\System32\ekjpegi.dll [2005-05-25 20:36:16 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\Jpegi.dll [2005-04-28 00:17:52 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\psetsi.dll [2003-08-07 19:25:20 | 000,184,392 | R--- | C] () -- C:\WINDOWS\System32\PCDLIB32.DLL [color=#E56717]========== LOP Check ==========[/color] [2007-12-18 09:42:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\IsolatedStorage [2010-10-26 12:53:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:49E9A6FB < End of report >