OTL logfile created on: 2012-07-22 13:05:07 - Run 2 OTL by OldTimer - Version 3.2.54.0 Folder = G:\Pobieranie Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,50 Gb Total Physical Memory | 0,83 Gb Available Physical Memory | 55,60% Memory free 2,85 Gb Paging File | 2,25 Gb Available in Paging File | 78,79% Paging File free Paging file location(s): E:\pagefile.sys 0 0 [binary data] %SystemDrive% = E: | %SystemRoot% = E:\WINDOWS | %ProgramFiles% = E:\Program Files Drive E: | 74,52 Gb Total Space | 61,38 Gb Free Space | 82,37% Space Free | Partition Type: NTFS Drive G: | 465,76 Gb Total Space | 388,76 Gb Free Space | 83,47% Space Free | Partition Type: NTFS Computer Name: KACPERPC | User Name: Kacper | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-07-22 11:50:27 | 000,596,480 | ---- | M] (OldTimer Tools) -- G:\Pobieranie\OTL.exe PRC - [2012-07-20 14:11:06 | 000,962,560 | ---- | M] () -- E:\Program Files\SimracewayUpdater\SRWUpdate.exe PRC - [2012-07-16 20:24:11 | 000,918,000 | ---- | M] (Mozilla Corporation) -- G:\Program Files\Aurora\firefox.exe PRC - [2012-07-16 20:24:10 | 000,016,880 | ---- | M] (Mozilla Corporation) -- G:\Program Files\Aurora\plugin-container.exe PRC - [2012-06-19 15:52:56 | 000,519,848 | R--- | M] (iRacing.com Motorsport Simulations, LLC Bedford, MA 01730) -- G:\Program Files\iRacing\iRacingService.exe PRC - [2011-08-22 17:57:30 | 000,025,600 | ---- | M] (Creative Technology Ltd) -- E:\WINDOWS\system32\Ctxfihlp.exe PRC - [2011-08-22 17:52:46 | 001,212,928 | ---- | M] (Creative Technology Ltd) -- E:\WINDOWS\system32\CTxfispi.exe PRC - [2010-12-28 19:44:54 | 000,294,912 | ---- | M] (Creative Technology Ltd) -- E:\Program Files\Creative\Shared Files\CTAudSvc.exe PRC - [2010-09-15 11:20:52 | 000,065,536 | ---- | M] (ATI Technologies Inc.) -- G:\ATI\ATI.ACE\Core-Static\CCC.exe PRC - [2010-06-14 16:10:32 | 000,153,672 | ---- | M] (Logitech Inc.) -- E:\Program Files\Logitech\Gaming Software\LWEMon.exe PRC - [2009-07-07 13:13:38 | 000,241,789 | ---- | M] (Creative Technology Ltd) -- G:\Program Files\Creative\Volume Panel\VolPanlu.exe PRC - [2009-04-22 17:38:50 | 000,065,536 | ---- | M] (Advanced Micro Devices Inc.) -- G:\ATI\ATI.ACE\Core-Static\MOM.exe PRC - [2009-01-17 16:48:08 | 005,853,672 | ---- | M] (o2.pl Sp. z o.o.) -- G:\Program Files\Tlen.pl\tlen.exe PRC - [2008-04-14 19:21:16 | 001,035,264 | ---- | M] (Microsoft Corporation) -- E:\WINDOWS\explorer.exe PRC - [2008-03-20 12:04:46 | 002,127,296 | ---- | M] (Gadu-Gadu S.A.) -- G:\Program Files\Gadu-Gadu\gg.exe PRC - [2003-06-18 01:00:00 | 000,045,056 | ---- | M] (Creative Technology Ltd) -- G:\Program Files\Creative\DVDAudio\CTDVDDET.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012-07-20 14:11:10 | 000,252,832 | ---- | M] () -- E:\Program Files\SimracewayUpdater\patchw32.dll MOD - [2012-07-20 14:11:06 | 000,962,560 | ---- | M] () -- E:\Program Files\SimracewayUpdater\SRWUpdate.exe MOD - [2012-07-16 20:24:11 | 002,243,568 | ---- | M] () -- G:\Program Files\Aurora\mozjs.dll MOD - [2012-07-11 20:34:12 | 009,465,032 | ---- | M] () -- E:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll MOD - [2012-06-14 20:12:56 | 011,817,472 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\dbc413807cb7360b3e26ef3ca1d54f9a\System.Web.ni.dll MOD - [2012-06-14 20:03:57 | 012,433,920 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\01abbadafaf265d9f4ac9bbb247acb98\System.Windows.Forms.ni.dll MOD - [2012-06-14 20:02:49 | 000,303,104 | ---- | M] () -- E:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll MOD - [2012-06-14 13:30:03 | 001,592,320 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll MOD - [2012-05-11 14:23:39 | 000,971,264 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d5b7368bde0f65aa15d9f46b498cc89\System.Configuration.ni.dll MOD - [2012-05-11 14:23:31 | 000,025,600 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\016444dfc5f7e3d11c776f2fbc7a4594\Accessibility.ni.dll MOD - [2012-05-11 14:21:19 | 005,450,752 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\3bba1b8b0b5ef0be238b011cc7a0575e\System.Xml.ni.dll MOD - [2012-05-11 14:18:22 | 007,953,408 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll MOD - [2012-05-11 14:18:08 | 011,492,352 | ---- | M] () -- E:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll MOD - [2012-03-09 00:32:04 | 000,270,336 | ---- | M] () -- G:\ATI\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll MOD - [2011-08-22 17:57:32 | 000,002,560 | ---- | M] () -- E:\WINDOWS\CTXFIRES.DLL MOD - [2010-03-16 12:22:12 | 000,014,848 | ---- | M] () -- G:\ATI\ATI.ACE\Core-Static\AxInterop.WBOCXLib.dll MOD - [2009-01-17 16:47:38 | 000,033,792 | ---- | M] () -- G:\Program Files\Tlen.pl\languages\polish.dll MOD - [2009-01-06 13:55:46 | 000,061,464 | ---- | M] () -- G:\Program Files\Tlen.pl\plugins\TlenSMS.tpl MOD - [2008-12-23 16:11:32 | 000,195,096 | ---- | M] () -- G:\Program Files\Tlen.pl\plugins\Video.tpl MOD - [2008-12-22 15:32:06 | 000,093,720 | ---- | M] () -- G:\Program Files\Tlen.pl\plugins\Voice.tpl MOD - [2008-12-16 15:51:44 | 000,151,552 | ---- | M] () -- G:\Program Files\Tlen.pl\libgadu.dll MOD - [2008-07-22 09:49:48 | 000,075,800 | ---- | M] () -- G:\Program Files\Tlen.pl\plugins\FileTM.tpl MOD - [2008-07-22 09:49:40 | 000,106,520 | ---- | M] () -- G:\Program Files\Tlen.pl\plugins\File.tpl MOD - [2008-06-19 14:20:08 | 000,017,408 | ---- | M] () -- G:\Program Files\Tlen.pl\hook.dll MOD - [2008-06-19 14:15:54 | 000,030,720 | ---- | M] () -- G:\Program Files\Tlen.pl\libutil2.dll MOD - [2008-06-19 14:15:46 | 000,139,264 | ---- | M] () -- G:\Program Files\Tlen.pl\libexpat2.dll MOD - [2008-03-20 11:17:48 | 000,106,496 | ---- | M] () -- G:\Program Files\Gadu-Gadu\libiax2.dll MOD - [2008-03-20 11:17:44 | 000,061,440 | ---- | M] () -- G:\Program Files\Gadu-Gadu\libjb.dll MOD - [2008-01-15 16:57:06 | 000,349,720 | ---- | M] () -- G:\Program Files\Tlen.pl\plugins\Tlenofon.tpl MOD - [2007-10-25 13:51:16 | 000,198,656 | ---- | M] () -- G:\Program Files\Gadu-Gadu\libcurl.dll MOD - [2007-10-05 15:00:58 | 000,181,248 | ---- | M] () -- G:\Program Files\Tlen.pl\libutil.dll MOD - [2005-11-18 11:33:58 | 000,054,784 | ---- | M] () -- G:\Program Files\Tlen.pl\libs\libexpat.dll MOD - [2003-01-30 06:04:00 | 000,618,496 | ---- | M] () -- G:\Program Files\Tlen.pl\stlpmt45.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ) SRV - [2012-07-20 14:11:06 | 000,962,560 | ---- | M] () [Auto | Running] -- E:\Program Files\SimracewayUpdater\SRWUpdate.exe -- (Simraceway Update Service) SRV - [2012-07-16 20:24:11 | 000,114,160 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- E:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012-07-11 20:34:13 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- E:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012-06-19 15:52:56 | 000,519,848 | R--- | M] (iRacing.com Motorsport Simulations, LLC Bedford, MA 01730) [Auto | Running] -- G:\Program Files\iRacing\iRacingService.exe -- (iRacingService) SRV - [2012-04-22 01:59:56 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- E:\Program Files\Common Files\Creative Labs Shared\Service\DDLLicensing.exe -- (Creative Dolby Digital Live Pack Licensing Service) SRV - [2011-03-16 10:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- E:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2010-12-28 19:44:54 | 000,294,912 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- E:\Program Files\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2012-06-23 03:45:09 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV - [2012-03-09 08:22:00 | 007,586,304 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag) DRV - [2011-08-22 19:24:44 | 001,178,200 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\ha20x2k.sys -- (ha20x2k) DRV - [2011-08-22 19:24:34 | 000,095,832 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\emupia2k.sys -- (emupia) DRV - [2011-08-22 19:24:22 | 000,158,808 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k) DRV - [2011-08-22 19:24:12 | 000,014,424 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\ctprxy2k.sys -- (ctprxy2k) DRV - [2011-08-22 19:24:00 | 000,130,136 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv) DRV - [2011-08-22 19:23:50 | 000,347,144 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\ctdvda2k.sys -- (ctdvda2k) DRV - [2011-08-22 19:23:36 | 000,528,344 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\ctaud2k.sys -- (ctaud2k) Creative Audio Driver (WDM) DRV - [2011-08-22 19:23:24 | 000,511,064 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\ctac32k.sys -- (ctac32k) DRV - [2011-08-22 19:23:14 | 001,324,120 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\CTEXFIFX.sys -- (CTEXFIFX.SYS) DRV - [2011-08-22 19:23:14 | 001,324,120 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\CTEXFIFX.sys -- (CTEXFIFX) DRV - [2011-08-22 19:23:02 | 000,072,792 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\CTHWIUT.sys -- (CTHWIUT.SYS) DRV - [2011-08-22 19:23:02 | 000,072,792 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\CTHWIUT.sys -- (CTHWIUT) DRV - [2011-08-22 19:22:50 | 000,171,096 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\CT20XUT.sys -- (CT20XUT.SYS) DRV - [2011-08-22 19:22:50 | 000,171,096 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\CT20XUT.sys -- (CT20XUT) DRV - [2011-07-28 19:06:06 | 001,763,584 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\athuw.sys -- (AR9271) DRV - [2010-04-27 16:57:28 | 000,066,632 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\WmXlCore.sys -- (WmXlCore) DRV - [2010-04-27 16:57:28 | 000,015,048 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\WmVirHid.sys -- (WmVirHid) DRV - [2010-04-27 16:57:24 | 000,031,816 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\WmHidLo.sys -- (WmHidLo) DRV - [2010-04-27 16:57:22 | 000,022,856 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\WmBEnum.sys -- (WmBEnum) DRV - [2010-04-27 14:01:26 | 000,037,704 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\WmFilter.sys -- (WmFilter) DRV - [2010-03-31 00:00:00 | 000,027,760 | ---- | M] () [Kernel | On_Demand | Stopped] -- G:\EVEREST Ultimate Edition\kerneld.wnt -- (EverestDriver) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-527237240-1004336348-839522115-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-527237240-1004336348-839522115-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC IE - HKU\S-1-5-21-527237240-1004336348-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.useDBForOrder: true FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: E:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: E:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: E:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: E:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Aurora 15.0a2\extensions\\Components: G:\Program Files\Aurora\components [2012-07-16 20:24:11 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Aurora 15.0a2\extensions\\Plugins: G:\Program Files\Aurora\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0\extensions\\Components: G:\Program Files\Mozilla Firefox\components [2012-06-16 12:19:53 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0\extensions\\Plugins: G:\Program Files\Mozilla Firefox\plugins [2012-04-19 02:15:17 | 000,000,000 | ---D | M] (No name found) -- E:\Documents and Settings\Kacper\Dane aplikacji\Mozilla\Extensions [2012-07-20 13:07:55 | 000,000,000 | ---D | M] (No name found) -- E:\Documents and Settings\Kacper\Dane aplikacji\Mozilla\Firefox\Profiles\ye17vq2o.default\extensions [2012-07-15 05:51:59 | 000,000,000 | ---D | M] (Battlefield Play4Free) -- E:\Documents and Settings\Kacper\Dane aplikacji\Mozilla\Firefox\Profiles\ye17vq2o.default\extensions\battlefieldplay4free@ea.com [2012-05-26 02:57:23 | 000,001,330 | ---- | M] () -- E:\Documents and Settings\Kacper\Dane aplikacji\Mozilla\Firefox\Profiles\ye17vq2o.default\searchplugins\wikipedia-en.xml [2012-07-20 13:07:55 | 000,015,185 | ---- | M] () (No name found) -- E:\DOCUMENTS AND SETTINGS\KACPER\DANE APLIKACJI\MOZILLA\FIREFOX\PROFILES\YE17VQ2O.DEFAULT\EXTENSIONS\{B0E1B4A6-2C6F-4E99-94F2-8E625D7AE255}.XPI [2012-07-18 18:49:25 | 000,186,203 | ---- | M] () (No name found) -- E:\DOCUMENTS AND SETTINGS\KACPER\DANE APLIKACJI\MOZILLA\FIREFOX\PROFILES\YE17VQ2O.DEFAULT\EXTENSIONS\ARTUR.DUBOVOY@GMAIL.COM.XPI [2012-06-12 14:29:13 | 001,184,804 | ---- | M] () (No name found) -- E:\DOCUMENTS AND SETTINGS\KACPER\DANE APLIKACJI\MOZILLA\FIREFOX\PROFILES\YE17VQ2O.DEFAULT\EXTENSIONS\TESTPILOT@LABS.MOZILLA.COM.XPI [2012-04-19 02:22:27 | 000,040,179 | ---- | M] () (No name found) -- E:\DOCUMENTS AND SETTINGS\KACPER\DANE APLIKACJI\MOZILLA\FIREFOX\PROFILES\YE17VQ2O.DEFAULT\EXTENSIONS\UNDOCLOSEDTABSBUTTON@SUPERNOVA00.BIZ.XPI [2012-04-19 16:23:04 | 000,000,000 | ---D | M] (Java Quick Starter) -- E:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF O1 HOSTS File: ([2012-05-16 22:30:25 | 000,000,772 | ---- | M]) - E:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 activate.adobe.com O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O4 - HKLM..\Run: [CTDVDDET] g:\Program Files\Creative\DVDAudio\CTDVDDET.EXE (Creative Technology Ltd) O4 - HKLM..\Run: [CTxfiHlp] E:\WINDOWS\System32\Ctxfihlp.exe (Creative Technology Ltd) O4 - HKLM..\Run: [IMJPMIG8.1] E:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation) O4 - HKLM..\Run: [MSPY2002] E:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe () O4 - HKLM..\Run: [PHIME2002A] E:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation) O4 - HKLM..\Run: [PHIME2002ASync] E:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation) O4 - HKLM..\Run: [Start WingMan Profiler] E:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.) O4 - HKLM..\Run: [StartCCC] G:\ATI\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [VolPanel] g:\Program Files\Creative\Volume Panel\VolPanlu.exe (Creative Technology Ltd) O4 - HKU\S-1-5-21-527237240-1004336348-839522115-1003..\Run: [DAEMON Tools Lite] G:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKU\S-1-5-21-527237240-1004336348-839522115-1003..\Run: [Gadu-Gadu] G:\Program Files\Gadu-Gadu\gg.exe (Gadu-Gadu S.A.) O4 - HKU\S-1-5-21-527237240-1004336348-839522115-1003..\Run: [Komunikator] G:\Program Files\Tlen.pl\tlen.exe (o2.pl Sp. z o.o.) O4 - HKU\S-1-5-21-527237240-1004336348-839522115-1003..\Run: [MCW Startup] G:\Program Files\Monitor Calibration Wizard\MCW.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-527237240-1004336348-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1334849253125 (MUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3233C71E-937F-404E-BF13-EB7C83E248E1}: DhcpNameServer = 192.168.1.1 O20 - HKLM Winlogon: Shell - (Explorer.exe) - E:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (E:\WINDOWS\system32\userinit.exe) - E:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - E:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: E:\WINDOWS\Web\Wallpaper\Idylla.bmp O24 - Desktop BackupWallPaper: E:\WINDOWS\Web\Wallpaper\Idylla.bmp O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-07-22 11:34:03 | 000,000,000 | ---D | C] -- E:\WINDOWS\CSC [2012-07-21 22:00:38 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Kacper\Pulpit\MOHAA [2012-07-16 16:02:44 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Kacper\Moje dokumenty\Battlefield Play4Free [2012-07-16 03:45:43 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Kacper\Menu Start\Programy\EA Games [2012-07-10 21:48:30 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Kacper\Menu Start\Programy\Monitor Calibration Wizard [2012-07-04 12:24:27 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Kacper\Moje dokumenty\iRacing [2012-07-04 11:47:27 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Menu Start\Programy\iRacing [2012-07-04 11:46:55 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Kacper\Dane aplikacji\InstallShield [2012-06-27 03:21:31 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Kacper\Dane aplikacji\fofix [2012-06-26 00:31:32 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Kacper\Ustawienia lokalne\Dane aplikacji\PunkBuster [2012-06-26 00:27:49 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Kacper\Moje dokumenty\America's Army 3 [2012-06-25 18:46:59 | 000,000,000 | ---D | C] -- E:\Program Files\Common Files\Steam [2012-06-25 18:46:58 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Menu Start\Programy\Steam [2012-06-23 03:53:52 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Kacper\Menu Start\Programy\Bohemia Interactive [2012-06-23 03:49:50 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Kacper\Menu Start\Programy\Codemasters [2012-06-23 03:45:26 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Menu Start\Programy\DAEMON Tools Lite [2012-06-23 03:45:08 | 000,242,240 | ---- | C] (DT Soft Ltd) -- E:\WINDOWS\System32\drivers\dtsoftbus01.sys [2012-06-23 03:45:00 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Kacper\Dane aplikacji\DAEMON Tools Lite [2012-06-23 03:44:32 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite [2012-06-22 16:04:04 | 000,000,000 | -H-D | C] -- E:\Documents and Settings\Kacper\Dane aplikacji\TempMods [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-07-22 12:58:53 | 001,089,416 | ---- | M] () -- E:\WINDOWS\System32\PerfStringBackup.INI [2012-07-22 12:58:53 | 000,490,712 | ---- | M] () -- E:\WINDOWS\System32\perfh015.dat [2012-07-22 12:58:53 | 000,432,784 | ---- | M] () -- E:\WINDOWS\System32\perfh009.dat [2012-07-22 12:58:53 | 000,084,088 | ---- | M] () -- E:\WINDOWS\System32\perfc015.dat [2012-07-22 12:58:53 | 000,067,740 | ---- | M] () -- E:\WINDOWS\System32\perfc009.dat [2012-07-22 12:54:54 | 000,013,646 | ---- | M] () -- E:\WINDOWS\System32\wpa.dbl [2012-07-22 12:54:50 | 000,000,006 | -H-- | M] () -- E:\WINDOWS\tasks\SA.DAT [2012-07-22 12:54:48 | 000,002,048 | --S- | M] () -- E:\WINDOWS\bootstat.dat [2012-07-22 12:53:55 | 000,000,188 | -HS- | M] () -- E:\Documents and Settings\Kacper\ntuser.ini [2012-07-22 12:53:54 | 003,407,872 | -H-- | M] () -- E:\Documents and Settings\Kacper\NTUSER.DAT [2012-07-22 12:42:13 | 000,000,664 | ---- | M] () -- E:\WINDOWS\System32\d3d9caps.dat [2012-07-22 11:33:09 | 000,054,928 | ---- | M] () -- E:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000001-00001102-00000005-00211102}.rfx [2012-07-22 11:33:09 | 000,054,928 | ---- | M] () -- E:\WINDOWS\System32\BMXState-{00000002-00000000-00000001-00001102-00000005-00211102}.rfx [2012-07-22 11:33:09 | 000,000,788 | ---- | M] () -- E:\WINDOWS\System32\DVCState-{00000002-00000000-00000001-00001102-00000005-00211102}.rfx [2012-07-22 11:31:14 | 003,712,656 | -H-- | M] () -- E:\Documents and Settings\Kacper\Ustawienia lokalne\Dane aplikacji\IconCache.db [2012-07-22 03:34:00 | 000,000,930 | ---- | M] () -- E:\WINDOWS\tasks\Adobe Flash Player Updater.job [2012-07-21 22:20:43 | 000,000,622 | ---- | M] () -- E:\WINDOWS\eReg.dat [2012-07-20 13:11:40 | 000,180,749 | ---- | M] () -- E:\Documents and Settings\Kacper\Pulpit\Wrocław-Wwa.png [2012-07-17 20:08:27 | 000,010,240 | ---- | M] () -- E:\Documents and Settings\Kacper\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-07-16 16:39:11 | 000,139,424 | ---- | M] () -- E:\WINDOWS\System32\drivers\PnkBstrK.sys [2012-07-16 16:39:02 | 000,282,104 | ---- | M] () -- E:\WINDOWS\System32\PnkBstrB.xtr [2012-07-16 03:46:08 | 000,138,056 | ---- | M] () -- E:\Documents and Settings\Kacper\Dane aplikacji\PnkBstrK.sys [2012-07-16 02:40:37 | 000,004,096 | ---- | M] () -- E:\WINDOWS\System32\crash [2012-07-12 14:43:16 | 000,168,304 | ---- | M] () -- E:\WINDOWS\System32\FNTCACHE.DAT [2012-07-11 20:34:12 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- E:\WINDOWS\System32\FlashPlayerApp.exe [2012-07-11 20:34:12 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- E:\WINDOWS\System32\FlashPlayerCPLApp.cpl [2012-07-11 14:00:33 | 000,001,374 | ---- | M] () -- E:\WINDOWS\imsins.BAK [2012-07-10 21:48:31 | 000,000,007 | ---- | M] () -- E:\WINDOWS\INI2=No [2012-07-10 21:48:31 | 000,000,007 | ---- | M] () -- E:\WINDOWS\INI1=No [2012-07-06 23:56:37 | 000,858,143 | ---- | M] () -- E:\Documents and Settings\Kacper\Pulpit\DSC_7069.jpg [2012-07-06 23:49:32 | 000,893,875 | ---- | M] () -- E:\Documents and Settings\Kacper\Pulpit\DSC_6997.jpg [2012-07-06 23:39:42 | 008,506,567 | ---- | M] () -- E:\Documents and Settings\Kacper\Pulpit\DSC_7069.NEF [2012-07-06 23:35:40 | 008,617,051 | R--- | M] () -- E:\Documents and Settings\Kacper\Pulpit\DSC_7036.NEF [2012-07-06 23:33:18 | 008,683,680 | R--- | M] () -- E:\Documents and Settings\Kacper\Pulpit\DSC_6997.NEF [2012-06-28 05:18:27 | 000,001,080 | ---- | M] () -- E:\WINDOWS\System32\settingsbkup.sfm [2012-06-28 05:18:27 | 000,001,080 | ---- | M] () -- E:\WINDOWS\System32\settings.sfm [2012-06-25 19:27:20 | 003,360,624 | ---- | M] () -- E:\WINDOWS\System32\pbsvc.exe [2012-06-25 18:47:00 | 000,000,570 | ---- | M] () -- E:\Documents and Settings\All Users\Pulpit\Steam.lnk [2012-06-23 03:45:26 | 000,000,705 | ---- | M] () -- E:\Documents and Settings\All Users\Pulpit\DAEMON Tools Lite.lnk [2012-06-23 03:45:09 | 000,242,240 | ---- | M] (DT Soft Ltd) -- E:\WINDOWS\System32\drivers\dtsoftbus01.sys [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-07-22 12:31:30 | 000,000,664 | ---- | C] () -- E:\WINDOWS\System32\d3d9caps.dat [2012-07-21 22:20:37 | 000,000,622 | ---- | C] () -- E:\WINDOWS\eReg.dat [2012-07-20 13:10:21 | 000,180,749 | ---- | C] () -- E:\Documents and Settings\Kacper\Pulpit\Wrocław-Wwa.png [2012-07-16 02:40:37 | 000,004,096 | ---- | C] () -- E:\WINDOWS\System32\crash [2012-07-10 21:48:31 | 000,000,007 | ---- | C] () -- E:\WINDOWS\INI2=No [2012-07-10 21:48:31 | 000,000,007 | ---- | C] () -- E:\WINDOWS\INI1=No [2012-07-06 23:56:28 | 000,858,143 | ---- | C] () -- E:\Documents and Settings\Kacper\Pulpit\DSC_7069.jpg [2012-07-06 23:49:21 | 000,893,875 | ---- | C] () -- E:\Documents and Settings\Kacper\Pulpit\DSC_6997.jpg [2012-07-06 23:40:51 | 008,683,680 | R--- | C] () -- E:\Documents and Settings\Kacper\Pulpit\DSC_6997.NEF [2012-07-06 23:36:53 | 008,617,051 | R--- | C] () -- E:\Documents and Settings\Kacper\Pulpit\DSC_7036.NEF [2012-07-06 23:26:53 | 008,506,567 | ---- | C] () -- E:\Documents and Settings\Kacper\Pulpit\DSC_7069.NEF [2012-06-26 00:31:35 | 000,282,104 | ---- | C] () -- E:\WINDOWS\System32\PnkBstrB.xtr [2012-06-25 23:58:44 | 000,139,424 | ---- | C] () -- E:\WINDOWS\System32\drivers\PnkBstrK.sys [2012-06-25 23:58:44 | 000,138,056 | ---- | C] () -- E:\Documents and Settings\Kacper\Dane aplikacji\PnkBstrK.sys [2012-06-25 23:58:27 | 000,282,104 | ---- | C] () -- E:\WINDOWS\System32\PnkBstrB.exe [2012-06-25 23:58:26 | 003,360,624 | ---- | C] () -- E:\WINDOWS\System32\pbsvc.exe [2012-06-25 23:58:26 | 000,076,888 | ---- | C] () -- E:\WINDOWS\System32\PnkBstrA.exe [2012-06-25 18:47:00 | 000,000,570 | ---- | C] () -- E:\Documents and Settings\All Users\Pulpit\Steam.lnk [2012-06-23 03:45:26 | 000,000,705 | ---- | C] () -- E:\Documents and Settings\All Users\Pulpit\DAEMON Tools Lite.lnk [2012-06-11 12:40:18 | 000,306,688 | ---- | C] () -- E:\WINDOWS\System32\Lffpx7.dll [2012-06-11 12:40:18 | 000,095,232 | ---- | C] () -- E:\WINDOWS\System32\Lfkodak.dll [2012-05-16 23:43:31 | 000,010,240 | ---- | C] () -- E:\Documents and Settings\Kacper\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-05-03 04:54:46 | 000,042,392 | ---- | C] () -- E:\WINDOWS\System32\xfcodec.dll [2012-04-22 02:00:56 | 000,000,029 | ---- | C] () -- E:\WINDOWS\sfbm.INI [2012-04-22 01:55:15 | 000,002,560 | ---- | C] () -- E:\WINDOWS\CTXFIRES.DLL [2012-04-22 01:54:59 | 000,021,266 | ---- | C] () -- E:\WINDOWS\System32\instwdm.ini [2012-04-22 01:54:59 | 000,000,054 | ---- | C] () -- E:\WINDOWS\System32\ctzapxx.ini [2012-04-19 18:39:48 | 000,175,616 | ---- | C] () -- E:\WINDOWS\System32\unrar.dll [2012-04-19 17:53:07 | 000,003,072 | ---- | C] () -- E:\WINDOWS\System32\iacenc.dll [2012-04-19 01:27:15 | 001,746,360 | ---- | C] () -- E:\WINDOWS\System32\CTAA1.DAT [2012-04-19 00:16:28 | 000,002,560 | ---- | C] () -- E:\WINDOWS\System32\CtxfiRes.dll [2012-04-19 00:15:03 | 000,060,928 | ---- | C] ( ) -- E:\WINDOWS\System32\a3d.dll [2012-04-19 00:14:45 | 000,016,384 | ---- | C] () -- E:\WINDOWS\System32\regplib.exe [2012-04-19 00:14:30 | 000,012,800 | ---- | C] ( ) -- E:\WINDOWS\System32\killapps.exe [2012-04-19 00:14:25 | 000,007,680 | ---- | C] () -- E:\WINDOWS\System32\enlocstr.exe [2012-04-19 00:12:35 | 000,056,509 | ---- | C] () -- E:\WINDOWS\System32\ctdnlstr.dat [2012-04-19 00:12:30 | 000,321,512 | ---- | C] () -- E:\WINDOWS\System32\ctdlang.dat [2012-04-19 00:12:05 | 000,000,285 | ---- | C] () -- E:\WINDOWS\System32\kill.ini [2012-04-19 00:09:36 | 000,035,176 | ---- | C] () -- E:\Documents and Settings\Kacper\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT [2012-04-19 00:07:35 | 000,000,000 | ---- | C] () -- E:\WINDOWS\ativpsrm.bin [2012-04-19 00:07:15 | 000,887,724 | ---- | C] () -- E:\WINDOWS\System32\ativva6x.dat [2012-04-19 00:07:14 | 000,601,728 | ---- | C] () -- E:\WINDOWS\System32\atiicdxx.dat [2012-04-19 00:07:14 | 000,000,003 | ---- | C] () -- E:\WINDOWS\System32\ativva5x.dat [2012-04-18 23:55:46 | 001,089,416 | ---- | C] () -- E:\WINDOWS\System32\PerfStringBackup.INI [2012-04-18 23:55:45 | 000,004,293 | ---- | C] () -- E:\WINDOWS\ODBCINST.INI [2012-04-18 23:55:44 | 003,712,656 | -H-- | C] () -- E:\Documents and Settings\Kacper\Ustawienia lokalne\Dane aplikacji\IconCache.db [2012-04-18 23:52:56 | 000,168,304 | ---- | C] () -- E:\WINDOWS\System32\FNTCACHE.DAT [2012-04-18 23:14:26 | 000,000,188 | -HS- | C] () -- E:\Documents and Settings\Kacper\ntuser.ini [2012-04-18 23:14:25 | 003,407,872 | -H-- | C] () -- E:\Documents and Settings\Kacper\NTUSER.DAT [2012-04-18 23:08:06 | 000,002,048 | --S- | C] () -- E:\WINDOWS\bootstat.dat [2012-04-18 23:05:58 | 000,000,000 | ---- | C] () -- E:\WINDOWS\control.ini [2012-04-18 23:05:00 | 000,000,488 | RH-- | C] () -- E:\WINDOWS\System32\logonui.exe.manifest [2012-04-18 23:04:54 | 000,000,749 | RH-- | C] () -- E:\WINDOWS\System32\cdplayer.exe.manifest [2012-04-18 23:03:17 | 000,021,856 | ---- | C] () -- E:\WINDOWS\System32\emptyregdb.dat [2012-04-18 23:03:06 | 000,000,037 | ---- | C] () -- E:\WINDOWS\vbaddin.ini [2012-04-18 23:03:06 | 000,000,036 | ---- | C] () -- E:\WINDOWS\vb.ini [2012-04-18 23:02:34 | 000,026,717 | ---- | C] () -- E:\WINDOWS\System32\tslabels.ini [2012-04-18 23:02:33 | 000,003,813 | ---- | C] () -- E:\WINDOWS\System32\msdtcprf.ini [color=#E56717]========== LOP Check ==========[/color] [2012-06-23 03:46:22 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite [2012-04-19 15:41:30 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Dane aplikacji\Test Drive Unlimited [2012-04-19 15:48:22 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Dane aplikacji\Tlen.pl [2012-04-19 00:11:44 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Dane aplikacji\TP-LINK [2012-05-03 00:43:19 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Kacper\Dane aplikacji\Audacity [2012-07-22 11:51:46 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Kacper\Dane aplikacji\DAEMON Tools Lite [2012-06-27 03:21:36 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Kacper\Dane aplikacji\fofix [2012-04-24 18:42:08 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Kacper\Dane aplikacji\Gadu-Gadu [2012-06-22 16:39:18 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Kacper\Dane aplikacji\Simraceway [2012-05-11 18:30:16 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Kacper\Dane aplikacji\SpinTires [2012-06-22 16:06:19 | 000,000,000 | -H-D | M] -- E:\Documents and Settings\Kacper\Dane aplikacji\TempMods [2012-07-17 18:30:33 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Kacper\Dane aplikacji\Tlen.pl [2012-07-21 23:54:48 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Kacper\Dane aplikacji\uTorrent [color=#E56717]========== Purity Check ==========[/color] < End of report >