OTL logfile created on: 17/07/2012 12:27:15 - Run 1 OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\jacek\Desktop Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 7.0.6000.16982) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 2.00 Gb Total Physical Memory | 1.66 Gb Available Physical Memory | 82.94% Memory free 4.20 Gb Paging File | 4.03 Gb Available in Paging File | 96.07% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 141.26 Gb Total Space | 6.70 Gb Free Space | 4.74% Space Free | Partition Type: NTFS Drive D: | 7.79 Gb Total Space | 2.07 Gb Free Space | 26.56% Space Free | Partition Type: NTFS Computer Name: JACEK-PC | User Name: jacek | Logged in as Administrator. Boot Mode: SafeMode | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012/07/17 10:16:30 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\jacek\Desktop\OTL.exe PRC - [2010/03/09 11:34:54 | 002,923,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Common Files\SureThing Shared\stllssvr.exe -- (stllssvr) SRV - [2012/06/27 12:29:22 | 001,385,896 | ---- | M] (LogMeIn Inc.) [Disabled | Stopped] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc) SRV - [2012/06/26 10:07:34 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2011/01/18 21:26:34 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2010/10/17 23:19:47 | 000,085,096 | ---- | M] (Autodesk) [On_Demand | Stopped] -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe -- (Autodesk Licensing Service) SRV - [2010/10/06 08:49:25 | 000,340,520 | ---- | M] (Kaspersky Lab) [On_Demand | Stopped] -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe -- (AVP) SRV - [2007/07/24 21:50:09 | 000,265,912 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2007/04/24 03:11:44 | 000,106,593 | ---- | M] () [Auto | Stopped] -- C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe -- (CLSched) CyberLink Task Scheduler (CTS) SRV - [2007/04/24 03:11:42 | 000,262,243 | ---- | M] () [Auto | Stopped] -- C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe -- (CLCapSvc) CyberLink Background Capture Service (CBCS) SRV - [2007/02/12 16:38:04 | 000,355,096 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R) SRV - [2006/11/02 11:46:13 | 000,365,568 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\WindowsMobile\wcescomm.dll -- (WcesComm) SRV - [2006/11/02 11:46:12 | 000,167,424 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\WindowsMobile\rapimgr.dll -- (RapiMgr) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | Disabled | Stopped] -- system32\DRIVERS\UIUSYS.SYS -- (UIUSys) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive) DRV - [2011/11/04 14:42:02 | 000,158,512 | ---- | M] (Oracle Corporation) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\VBoxDrv.sys -- (VBoxDrv) DRV - [2011/11/04 14:42:02 | 000,116,016 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\VBoxNetFlt.sys -- (VBoxNetFlt) DRV - [2011/11/04 14:42:02 | 000,104,752 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\VBoxNetAdp.sys -- (VBoxNetAdp) DRV - [2011/11/04 14:42:02 | 000,091,440 | ---- | M] (Oracle Corporation) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\VBoxUSBMon.sys -- (VBoxUSBMon) DRV - [2010/07/11 13:53:49 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\sptd.sys -- (sptd) DRV - [2010/06/02 22:47:03 | 000,025,616 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Users\jacek\AppData\Local\Temp\CVHE9A2.tmp -- (GarenaPEngine) DRV - [2010/03/03 17:38:43 | 000,311,312 | ---- | M] (Kaspersky Lab) [File_System | System | Stopped] -- C:\WINDOWS\System32\drivers\klif.sys -- (KLIF) DRV - [2010/01/04 11:30:56 | 000,112,640 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\ewusbnet.sys -- (ewusbnet) DRV - [2010/01/04 11:30:56 | 000,102,912 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\ewusbmdm.sys -- (hwdatacard) DRV - [2010/01/04 11:30:56 | 000,101,120 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\ewusbdev.sys -- (hwusbdev) DRV - [2009/12/12 20:34:40 | 000,278,984 | ---- | M] () [Kernel | Auto | Stopped] -- C:\WINDOWS\System32\drivers\atksgt.sys -- (atksgt) DRV - [2009/12/12 20:34:39 | 000,025,416 | ---- | M] () [Kernel | Auto | Stopped] -- C:\WINDOWS\System32\drivers\lirsgt.sys -- (lirsgt) DRV - [2009/10/14 21:18:34 | 000,036,880 | ---- | M] (Kaspersky Lab) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\klbg.sys -- (klbg) DRV - [2009/10/02 19:39:36 | 000,019,472 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\klmouflt.sys -- (klmouflt) DRV - [2009/09/14 14:46:36 | 000,021,520 | ---- | M] (Kaspersky Lab) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\klim6.sys -- (KLIM6) DRV - [2009/09/01 15:29:50 | 000,128,016 | ---- | M] (Kaspersky Lab) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\kl1.sys -- (kl1) DRV - [2009/03/18 17:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\hamachi.sys -- (hamachi) DRV - [2008/06/25 23:59:00 | 007,534,720 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2007/04/18 14:03:26 | 000,141,312 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\Apfiltr.sys -- (ApfiltrService) DRV - [2007/03/22 00:02:04 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\rixdptsk.sys -- (rismxdp) DRV - [2007/03/01 14:49:58 | 002,216,448 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\NETw4v32.sys -- (NETw4v32) Intel(R) DRV - [2007/02/24 16:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\rimmptsk.sys -- (rimmptsk) DRV - [2007/01/23 18:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\rimsptsk.sys -- (rimsptsk) DRV - [2006/11/30 19:24:58 | 000,008,192 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\eabfiltr.sys -- (eabfiltr) DRV - [2006/11/28 18:44:52 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Stopped] -- C:\WINDOWS\System32\drivers\XAudio.sys -- (XAudio) DRV - [2006/11/02 10:55:05 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\winusb.sys -- (winusb) DRV - [2006/06/28 18:54:00 | 000,009,472 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\CPQBttn.sys -- (HBtnKey) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1177238034-494793193-1938755863-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bph.pl/pl IE - HKU\S-1-5-21-1177238034-494793193-1938755863-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-1177238034-494793193-1938755863-1000\..\SearchScopes,DefaultScope = {2778B4E3-C46D-4B75-8F67-324065CEC3A5} IE - HKU\S-1-5-21-1177238034-494793193-1938755863-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\S-1-5-21-1177238034-494793193-1938755863-1000\..\SearchScopes\{2778B4E3-C46D-4B75-8F67-324065CEC3A5}: "URL" = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=937811&p={searchTerms} IE - HKU\S-1-5-21-1177238034-494793193-1938755863-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultthis.engineName: "Veoh Web Player Customized Web Search" FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=3&q={searchTerms}" FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.3.3.2 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.732: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=1.0.0.0: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\jacek\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/26 10:07:36 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/06/05 18:41:31 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\THBExt [2010/03/03 15:54:49 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/26 10:07:36 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/06/05 18:41:31 | 000,000,000 | ---D | M] [2009/11/07 10:35:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\jacek\AppData\Roaming\mozilla\Extensions [2012/07/15 23:16:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\jacek\AppData\Roaming\mozilla\Firefox\Profiles\57o4pwso.default\extensions [2010/04/28 18:00:26 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\jacek\AppData\Roaming\mozilla\Firefox\Profiles\57o4pwso.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2012/07/15 23:16:46 | 000,000,000 | ---D | M] (Veoh Web Player Community Toolbar) -- C:\Users\jacek\AppData\Roaming\mozilla\Firefox\Profiles\57o4pwso.default\extensions\{cd90bf73-20f6-44ef-993d-bb920303bd2e} [2011/03/29 20:18:18 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\jacek\AppData\Roaming\mozilla\Firefox\Profiles\57o4pwso.default\extensions\engine@conduit.com [2010/06/29 18:22:34 | 000,000,933 | ---- | M] () -- C:\Users\jacek\AppData\Roaming\Mozilla\Firefox\Profiles\57o4pwso.default\searchplugins\conduit.xml [2012/02/14 10:18:40 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2011/10/17 10:09:38 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2009/12/23 10:24:24 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru [2012/06/26 10:07:35 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012/06/26 10:07:30 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2012/06/26 10:07:30 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2012/06/26 10:07:30 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2012/06/26 10:07:30 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2012/06/26 10:07:30 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2012/06/26 10:07:30 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2006/09/18 23:41:30 | 000,000,761 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll (Kaspersky Lab) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found. O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab) O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Users\jacek\AppData\Roaming\Nowe Gadu-Gadu\_userdata\ggbho.1.dll File not found O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.) O4 - HKLM..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard) O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.) O4 - HKLM..\Run: [MSConfig] C:\Windows\System32\msconfig.exe (Microsoft Corporation) O4 - HKLM..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray File not found O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [Windows Mobile-based device management] C:\WINDOWS\WindowsMobile\wmdSync.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-21-1177238034-494793193-1938755863-1000..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.) O4 - HKU\S-1-5-21-1177238034-494793193-1938755863-1000..\Run: [TimeDateMUICallback] C:\Users\jacek\AppData\Local\Microsoft\Windows\3355\TimeDateMUICallback.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 60 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 File not found O9 - Extra Button: &Wirtualna klawiatura - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab) O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: &Sprawdzanie adresów - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll (Kaspersky Lab) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 10.5.1) O16 - DPF: {92ECE6FA-AC2E-4042-BFAE-0C8608E52A43} https://www.bph.pl/pi/components/bph/SignActivX.cab (SignActivX Control) O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab (Java Plug-in 1.6.0) O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 10.5.1) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1D8E1531-B6DE-48E1-87BB-189370AE83A8}: DhcpNameServer = 194.24.244.3 194.24.244.4 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5BA8963F-A9DD-40EA-8E5B-41BEB7A39CD2}: DhcpNameServer = 212.2.96.53 212.2.96.51 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E0718913-B076-4D8A-B06C-DFEF3C5EAC03}: DhcpNameServer = 212.2.96.53 212.2.96.51 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E6AF8FC2-9426-4B53-9D01-BE848924567C}: DhcpNameServer = 212.2.96.53 212.2.96.54 O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\mzvkbd3.dll (Kaspersky Lab) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\WINDOWS\System32\klogon.dll (Kaspersky Lab) O24 - Desktop WallPaper: C:\Users\jacek\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg O24 - Desktop BackupWallPaper: C:\Users\jacek\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg O32 - HKLM CDRom: AutoRun - 0 O32 - AutoRun File - [2007/07/24 22:54:32 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2005/09/11 17:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ] O33 - MountPoints2\{10cd5c55-cd6b-11de-94b3-001a6bf3d4c9}\Shell\AutoRun\command - "" = F:\boyedt.com O33 - MountPoints2\{10cd5c55-cd6b-11de-94b3-001a6bf3d4c9}\Shell\open\Command - "" = F:\boyedt.com O33 - MountPoints2\{4252252a-8ce3-11df-a0f8-001a6bf3d4c9}\Shell - "" = AutoRun O33 - MountPoints2\{4252252a-8ce3-11df-a0f8-001a6bf3d4c9}\Shell\AutoRun\command - "" = H:\AutoRun.exe O33 - MountPoints2\{4fed63b5-26c6-11df-b9fa-001a6bf3d4c9}\Shell - "" = AutoRun O33 - MountPoints2\{4fed63b5-26c6-11df-b9fa-001a6bf3d4c9}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{6bd373ad-6cec-11df-a5d1-001a6bf3d4c9}\Shell - "" = AutoRun O33 - MountPoints2\{6bd373ad-6cec-11df-a5d1-001a6bf3d4c9}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{6bd373b9-6cec-11df-a5d1-001a6bf3d4c9}\Shell - "" = AutoRun O33 - MountPoints2\{6bd373b9-6cec-11df-a5d1-001a6bf3d4c9}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{73795b72-248d-11df-a9c0-001a6bf3d4c9}\Shell - "" = AutoRun O33 - MountPoints2\{73795b72-248d-11df-a9c0-001a6bf3d4c9}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{73795b81-248d-11df-a9c0-001a6bf3d4c9}\Shell - "" = AutoRun O33 - MountPoints2\{73795b81-248d-11df-a9c0-001a6bf3d4c9}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{954e11ec-8bfe-11de-9c0f-001a6bf3d4c9}\Shell - "" = AutoRun O33 - MountPoints2\{954e11ec-8bfe-11de-9c0f-001a6bf3d4c9}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a O33 - MountPoints2\{d2dc6528-3c54-11de-b2b4-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{d2dc6528-3c54-11de-b2b4-806e6f6e6963}\Shell\AutoRun\command - "" = E:\autorun.exe O33 - MountPoints2\{d47c3623-a239-11e0-8377-d28eddce3b05}\Shell - "" = AutoRun O33 - MountPoints2\{d47c3623-a239-11e0-8377-d28eddce3b05}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{d997da87-6c6c-11de-87b0-001a6bf3d4c9}\Shell\AutoRun\command - "" = F:\SYSTEM\G-923-321232-3232-32211-23\memory.exe O33 - MountPoints2\{d997da87-6c6c-11de-87b0-001a6bf3d4c9}\Shell\open\command - "" = F:\SYSTEM\G-923-321232-3232-32211-23\memory.exe O33 - MountPoints2\G\Shell - "" = AutoRun O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\AutoRun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012/07/17 10:18:20 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\jacek\Desktop\OTL.exe [2012/07/17 10:02:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner [2012/07/17 10:02:02 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2012/07/17 10:01:16 | 003,889,704 | ---- | C] (Piriform Ltd) -- C:\Users\jacek\Desktop\ccsetup320.exe [2012/07/17 09:34:58 | 000,000,000 | ---D | C] -- C:\Users\jacek\AppData\Roaming\hellomoto [2012/07/11 21:45:06 | 000,000,000 | ---D | C] -- C:\Users\jacek\AppData\Roaming\DriverCure [2012/07/11 21:45:05 | 000,000,000 | ---D | C] -- C:\Users\jacek\AppData\Roaming\ParetoLogic [2012/07/11 21:44:57 | 000,000,000 | ---D | C] -- C:\ProgramData\ParetoLogic [2012/06/27 23:43:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi [2012/06/27 23:43:16 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn Hamachi [2012/06/18 22:32:40 | 000,227,720 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe [2012/06/18 22:32:16 | 000,174,064 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe [2012/06/18 22:32:16 | 000,174,064 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012/07/17 12:26:21 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012/07/17 11:26:41 | 000,067,627 | ---- | M] () -- C:\ProgramData\nvModes.001 [2012/07/17 11:25:05 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2012/07/17 11:25:05 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2012/07/17 10:27:10 | 007,616,868 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012/07/17 10:27:09 | 003,734,034 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012/07/17 10:16:30 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\jacek\Desktop\OTL.exe [2012/07/17 10:02:03 | 000,000,804 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2012/07/17 09:58:58 | 003,889,704 | ---- | M] (Piriform Ltd) -- C:\Users\jacek\Desktop\ccsetup320.exe [2012/07/17 09:47:06 | 000,067,627 | ---- | M] () -- C:\ProgramData\nvModes.dat [2012/07/17 06:30:50 | 000,002,484 | ---- | M] () -- C:\Windows\bthservsdp.dat [2012/07/12 09:37:39 | 000,094,720 | ---- | M] () -- C:\Users\jacek\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012/07/12 07:59:42 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore1cd5ff387ac58a5.job [2012/07/11 21:51:18 | 000,000,129 | ---- | M] () -- C:\Users\jacek\Application Data\Microsoft\Internet Explorer\Quick Launch\CD Drive.lnk [2012/07/09 15:47:55 | 000,001,356 | ---- | M] () -- C:\Users\jacek\AppData\Local\d3d9caps.dat [2012/06/18 22:31:58 | 000,174,064 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe [2012/06/18 22:31:58 | 000,174,064 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012/07/17 10:02:03 | 000,000,804 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2012/07/12 07:59:42 | 000,000,882 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore1cd5ff387ac58a5.job [2011/12/09 17:09:20 | 000,001,504 | ---- | C] () -- C:\Users\jacek\.recently-used.xbel [2011/06/27 14:49:12 | 000,122,884 | ---- | C] () -- C:\Windows\UnGins.exe [2011/03/27 13:59:07 | 000,000,117 | ---- | C] () -- C:\Users\jacek\jagex_runescape_preferences2.dat [2011/03/27 13:57:35 | 000,000,034 | ---- | C] () -- C:\Users\jacek\jagex_runescape_preferences.dat [2011/02/28 20:21:39 | 000,021,840 | ---- | C] () -- C:\Windows\System32\SIntfNT.dll [2011/02/28 20:21:39 | 000,017,212 | ---- | C] () -- C:\Windows\System32\SIntf32.dll [2011/02/28 20:21:39 | 000,012,067 | ---- | C] () -- C:\Windows\System32\SIntf16.dll [2010/11/17 17:08:37 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE [2010/10/26 21:28:00 | 000,000,115 | ---- | C] () -- C:\Windows\SDDINST.INI [2010/02/07 22:40:32 | 000,000,552 | ---- | C] () -- C:\Users\jacek\AppData\Local\d3d8caps.dat [2009/10/25 14:42:28 | 000,138,056 | ---- | C] () -- C:\Users\jacek\AppData\Roaming\PnkBstrK.sys [2009/09/12 15:38:56 | 000,000,600 | ---- | C] () -- C:\Users\jacek\AppData\Roaming\winscp.rnd [2009/09/04 19:49:15 | 000,067,627 | ---- | C] () -- C:\ProgramData\nvModes.dat [2009/09/04 19:49:15 | 000,067,627 | ---- | C] () -- C:\ProgramData\nvModes.001 [2009/08/13 15:14:23 | 000,000,936 | ---- | C] () -- C:\ProgramData\lxdi [2009/07/26 19:52:00 | 000,094,720 | ---- | C] () -- C:\Users\jacek\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/05/09 17:01:19 | 000,001,356 | ---- | C] () -- C:\Users\jacek\AppData\Local\d3d9caps.dat [2009/05/08 23:20:43 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [color=#E56717]========== LOP Check ==========[/color] [2011/11/17 17:55:04 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\Ashampoo [2010/10/26 10:10:28 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\Autodesk [2010/07/11 13:59:42 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\DAEMON Tools Lite [2012/06/13 15:34:49 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\DC++ [2012/07/11 21:45:06 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\DriverCure [2011/12/28 23:46:40 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\Gadu-Gadu 10 [2011/12/09 17:09:20 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\gtk-2.0 [2011/02/01 14:59:09 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\Guitar Pro 6 [2012/07/17 09:35:07 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\hellomoto [2010/11/30 18:34:46 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\HEXelon [2011/01/27 19:18:08 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\ipla [2011/09/20 08:41:09 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\iPlus [2009/08/08 13:07:46 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\Lexmark Productivity Studio [2012/03/25 18:06:56 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\Mathsoft [2010/07/09 23:03:02 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\Nowe Gadu-Gadu [2009/09/06 20:30:35 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\OpenFM [2012/07/11 21:45:05 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\ParetoLogic [2010/10/29 16:51:44 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\play2p [2011/11/28 17:02:41 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\PROEKO RS [2012/03/25 22:21:50 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\PTC [2011/12/15 20:21:03 | 000,000,000 | ---D | M] -- C:\Users\jacek\AppData\Roaming\wargaming.net [2012/07/17 06:30:51 | 000,032,648 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [color=#E56717]========== Purity Check ==========[/color] < End of report >