OTL logfile created on: 2012-10-02 17:23:11 - Run 1 OTL by OldTimer - Version 3.2.70.1 Folder = c:\Users\A&I\Downloads Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,75 Gb Total Physical Memory | 1,48 Gb Available Physical Memory | 53,73% Memory free 5,72 Gb Paging File | 4,19 Gb Available in Paging File | 73,27% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 74,52 Gb Total Space | 3,28 Gb Free Space | 4,40% Space Free | Partition Type: NTFS Drive D: | 54,89 Gb Total Space | 6,98 Gb Free Space | 12,72% Space Free | Partition Type: NTFS Computer Name: KOMPUTERDOMOWY | User Name: A&I | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-10-02 17:02:33 | 000,600,064 | ---- | M] (OldTimer Tools) -- c:\Users\A&I\Downloads\OTL.exe PRC - [2012-08-21 15:30:46 | 000,307,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe PRC - [2012-08-21 11:12:26 | 004,282,728 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe PRC - [2012-08-21 11:12:25 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe PRC - [2011-11-25 17:32:36 | 000,687,400 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Update\NASvc.exe PRC - [2011-11-18 22:21:46 | 000,247,968 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashUtil11e_ActiveX.exe PRC - [2011-07-04 19:45:30 | 013,374,048 | ---- | M] (GG Network S.A.) -- C:\Program Files\Gadu-Gadu 10\gg.exe PRC - [2009-08-28 22:07:22 | 000,406,896 | ---- | M] (PIXELA CORPORATION) -- C:\Program Files\PIXELA\ImageMixer 3 SE Ver.4.5\Transfer Utility\CameraMonitor.exe PRC - [2009-04-11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009-04-11 08:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe PRC - [2004-09-03 01:51:50 | 000,221,184 | ---- | M] (ACD Systems, Ltd.) -- C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012-06-17 00:17:00 | 001,840,640 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\663112d3002034cf5126be253efff60d\System.Web.Services.ni.dll MOD - [2012-06-15 22:04:14 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll MOD - [2012-06-15 22:03:06 | 001,592,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll MOD - [2012-05-14 10:05:51 | 000,998,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\f3d4d5fe5ab848fbfcf91a49960dc8ae\System.Management.ni.dll MOD - [2012-05-14 10:04:08 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll MOD - [2012-05-14 10:03:56 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\1b337cf9a031145849bc48c11b2cfe58\Accessibility.ni.dll MOD - [2012-05-14 09:43:18 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll MOD - [2012-05-14 09:41:30 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll MOD - [2012-05-14 09:41:14 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll MOD - [2011-07-04 19:46:20 | 000,217,696 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\gglog.dll MOD - [2011-07-04 19:46:18 | 000,123,488 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggipcradioproxy.dll MOD - [2011-07-04 19:46:16 | 000,017,504 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggipc.dll MOD - [2011-07-04 19:46:12 | 000,027,744 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggcrypto.dll MOD - [2011-07-04 19:46:10 | 000,356,960 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggcommon.dll MOD - [2011-04-16 05:04:30 | 014,749,696 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtWebKit4.dll MOD - [2011-02-17 11:00:28 | 001,781,760 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtScript4.dll MOD - [2011-02-17 11:00:28 | 000,393,216 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtXml4.dll MOD - [2011-02-17 11:00:28 | 000,327,680 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtSvg4.dll MOD - [2011-02-17 11:00:26 | 001,044,480 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtNetwork4.dll MOD - [2011-02-17 11:00:24 | 009,097,216 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtGui4.dll MOD - [2011-02-17 11:00:24 | 002,560,000 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtCore4.dll MOD - [2011-02-17 10:59:40 | 000,311,296 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qtiff4.dll MOD - [2011-02-17 10:59:40 | 000,274,432 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qmng4.dll MOD - [2011-02-17 10:59:40 | 000,143,360 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qjpeg4.dll MOD - [2011-02-17 10:59:40 | 000,027,648 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qgif4.dll MOD - [2011-02-17 10:59:40 | 000,018,944 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qsvg4.dll MOD - [2011-02-17 10:59:32 | 000,059,904 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\zlib1.dll MOD - [2009-05-28 23:02:28 | 000,054,272 | ---- | M] () -- C:\Program Files\BatteryBar\BarExplorerHook.dll MOD - [2009-03-31 20:05:12 | 000,311,296 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pl_b77a5c561934e089\mscorlib.resources.dll MOD - [2008-08-29 16:15:50 | 000,364,544 | ---- | M] () -- C:\Program Files\PIXELA\ImageMixer 3 SE Ver.4.5\Transfer Utility\pxl_m17n_tool.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - [2012-08-21 11:12:25 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2011-11-25 17:32:36 | 000,687,400 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Nero\Update\NASvc.exe -- (NAUpdate) SRV - [2011-11-16 18:23:44 | 000,377,344 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- winhttp.dll -- (WinHttpAutoProxySvc) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbser6k.sys -- (ZTEusbser6k) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbnmea.sys -- (ZTEusbnmea) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbmdm6k.sys -- (ZTEusbmdm6k) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbdev.sys -- (hwusbdev) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbmdm.sys -- (hwdatacard) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbnet.sys -- (ewusbnet) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\adusbser.sys -- (adusbser) DRV - [2012-08-21 11:13:15 | 000,729,752 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2012-08-21 11:13:15 | 000,355,632 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP) DRV - [2012-08-21 11:13:15 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2012-08-21 11:13:14 | 000,058,680 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt) DRV - [2012-08-21 11:13:14 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (AswRdr) DRV - [2012-08-21 11:13:13 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2011-12-01 12:40:16 | 000,056,496 | ---- | M] (Nero AG) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\NBVol.sys -- (NBVol) DRV - [2011-12-01 12:40:16 | 000,012,464 | ---- | M] (Nero AG) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\NBVolUp.sys -- (NBVolUp) DRV - [2011-04-21 02:02:41 | 000,009,856 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\pfc.sys -- (pfc) DRV - [2010-08-12 12:07:50 | 000,292,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVNET) DRV - [2009-09-05 14:25:36 | 001,183,744 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2009-07-02 00:59:00 | 009,786,752 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2009-04-11 06:46:08 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usb8023.sys -- (usb_rndis) DRV - [2007-07-31 02:39:00 | 000,007,680 | ---- | M] (ATK0100) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ATKACPI.sys -- (MTsensor) DRV - [2006-11-02 09:41:49 | 001,010,560 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\smserial.sys -- (smserial) DRV - [2005-09-24 00:18:32 | 000,171,520 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MarvinBus.sys -- (MarvinBus) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ironto&s={searchTerms}&f=4 IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{4A00BFEE-7D01-4A32-987C-A8EA53C13D52}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=66ceb1b7-0169-11e1-8bc6-002354628dad&q={searchTerms} IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\..\SearchScopes\{6D038445-2DF3-4059-B2B5-FED7840535FB}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=66ceb1b7-0169-11e1-8bc6-002354628dad&q={searchTerms} IE - HKLM\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2737658 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com IE - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.asus.com/ IE - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\..\SearchScopes,DefaultScope = {4A00BFEE-7D01-4A32-987C-A8EA53C13D52} IE - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://start.facemoods.com/?a=dpgppc&s={searchTerms}&f=4 IE - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\..\SearchScopes\{4A00BFEE-7D01-4A32-987C-A8EA53C13D52}: "URL" = http://www.google.pl/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}&rlz=1I7GGHP_pl IE - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\..\SearchScopes\{6D038445-2DF3-4059-B2B5-FED7840535FB}: "URL" = http://www.google.pl/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}&rlz=1I7ADFA_plPL429 IE - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\..\SearchScopes\{7C892461-C3C8-49DC-B3A9-67599FCCEAE6}: "URL" = http://www.google.pl/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}&rlz=1I7ADFA_plPL429 IE - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search?q={searchTerms} IE - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2737658 IE - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredimail.com/mb68/?search={searchTerms}&loc=search_box&u=92260396713916062 IE - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\..\SearchScopes\{ECCC0205-1A81-4ED6-9F30-5C99A52034EF}: "URL" = http://www.google.pl/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}&rlz=1I7ADFA_pl IE - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~1\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2011-11-17 23:30:36 | 000,002,049 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fcmdSrch.xml [color=#E56717]========== Chrome ==========[/color] CHR - homepage: http://www.google.com/ CHR - default_search_provider: Web Search (Enabled) CHR - default_search_provider: search_url = http://startsear.ch/?aff=1&src=sp&cf=66ceb1b7-0169-11e1-8bc6-002354628dad&q={searchTerms} CHR - default_search_provider: suggest_url = CHR - homepage: http://www.google.com/ CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.79\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.79\pdf.dll CHR - plugin: vShare.tv plug-in (Enabled) = C:\Users\A&I\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\chvsharetvplg.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U30 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll CHR - plugin: Nero Kwik Media Helper (Enabled) = C:\PROGRA~1\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - Extension: YouTube = C:\Users\A&I\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\ CHR - Extension: Szukaj w Google = C:\Users\A&I\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\ CHR - Extension: VshareComplete plugin for chrome = C:\Users\A&I\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlfienamagdnkekbbbocojppncdambda\1.1_0\ CHR - Extension: avast! WebRep = C:\Users\A&I\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1466_0\ CHR - Extension: Facemoods = C:\Users\A&I\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.4.1_0\ CHR - Extension: vshare plugin = C:\Users\A&I\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\ CHR - Extension: Gmail = C:\Users\A&I\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2006-09-18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (CescrtHlpr Object) - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll (facemoods.com BHO) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (IE5BarLauncherBHO Class) - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files\vShare.tv plugin\BarLcher.dll (VShare Inc.) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKLM\..\Toolbar: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files\vShare.tv plugin\BarLcher.dll (VShare Inc.) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll (facemoods.com) O3 - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found. O3 - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\..\Toolbar\WebBrowser: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files\vShare.tv plugin\BarLcher.dll (VShare Inc.) O3 - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\..\Toolbar\WebBrowser: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [Device Detector] C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe (ACD Systems, Ltd.) O4 - HKLM..\Run: [facemoods] C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe (facemoods.com) O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe () O4 - HKLM..\Run: [NBAgent] C:\Program Files\Nero\Nero 11\Nero BackItUp\NBAgent.exe (Nero AG) O4 - HKLM..\Run: [NeroCheck] C:\Windows\System32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-21-3566313445-2323643246-291810148-1000..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.) O4 - HKU\S-1-5-21-3566313445-2323643246-291810148-1000..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden File not found O4 - HKU\S-1-5-21-3566313445-2323643246-291810148-1000..\Run: [Odkurzacz-MCD] D:\Odkurzacz\odk_mcd.exe (Franmo Software) O4 - HKU\S-1-5-21-3566313445-2323643246-291810148-1000..\Run: [ShowBatteryBar] C:\Program Files\BatteryBar\ShowBatteryBar.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1 O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4288DDE7-01A2-456A-BE3E-3728B4189B48}: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F1FE50CE-6EB0-4E8E-A2F9-5B66B0808C78}: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\A&I\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta z Galerii fotografii systemu Windows.jpg O24 - Desktop BackupWallPaper: C:\Users\A&I\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta z Galerii fotografii systemu Windows.jpg O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006-09-18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{12aad824-e2e1-11e0-8f08-002354628dad}\Shell - "" = AutoRun O33 - MountPoints2\{12aad824-e2e1-11e0-8f08-002354628dad}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{12aad831-e2e1-11e0-8f08-002354628dad}\Shell - "" = AutoRun O33 - MountPoints2\{12aad831-e2e1-11e0-8f08-002354628dad}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{9c6ceda3-f4f5-11e0-b7de-002354628dad}\Shell - "" = AutoRun O33 - MountPoints2\{9c6ceda3-f4f5-11e0-b7de-002354628dad}\Shell\AutoRun\command - "" = F:\Launcher.exe O33 - MountPoints2\{b1a1d084-f4fa-11e0-8b1b-002354628dad}\Shell - "" = AutoRun O33 - MountPoints2\{b1a1d084-f4fa-11e0-8b1b-002354628dad}\Shell\AutoRun\command - "" = F:\Launcher.exe O33 - MountPoints2\{eedd5408-ad1a-11e0-941a-002354628dad}\Shell - "" = AutoRun O33 - MountPoints2\{eedd5408-ad1a-11e0-941a-002354628dad}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{eedd5429-ad1a-11e0-941a-001e101f1ed9}\Shell - "" = AutoRun O33 - MountPoints2\{eedd5429-ad1a-11e0-941a-001e101f1ed9}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{f09d3060-f5d4-11e0-ac46-002354628dad}\Shell - "" = AutoRun O33 - MountPoints2\{f09d3060-f5d4-11e0-ac46-002354628dad}\Shell\AutoRun\command - "" = F:\Launcher.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-09-28 22:25:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome [2012-09-28 22:20:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus [2012-09-28 22:20:47 | 000,021,256 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys [2012-09-28 22:20:46 | 000,355,632 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2012-09-28 22:20:42 | 000,035,928 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys [2012-09-28 22:20:41 | 000,054,232 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2012-09-28 22:20:39 | 000,729,752 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2012-09-28 22:20:34 | 000,058,680 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2012-09-28 22:20:03 | 000,227,648 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe [2012-09-28 22:20:03 | 000,041,224 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr [2012-09-28 22:19:41 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software [2012-09-28 22:19:41 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software [2012-09-17 09:51:42 | 000,000,000 | ---D | C] -- C:\Users\A&I\Desktop\CV praca [2012-09-13 20:25:22 | 000,000,000 | ---D | C] -- C:\Users\A&I\Desktop\Fotojoker [2012-09-13 14:54:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\A4Desk [2012-09-13 14:54:45 | 000,000,000 | ---D | C] -- C:\Program Files\A4Desk [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-10-02 17:33:47 | 006,029,312 | -HS- | M] () -- C:\Users\A&I\NTUSER.DAT [2012-10-02 17:30:00 | 000,000,434 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{CE8B8E70-09A4-484A-9774-FFB1979CB56B}.job [2012-10-02 17:15:46 | 000,047,889 | ---- | M] () -- C:\ProgramData\nvModes.001 [2012-10-02 17:14:20 | 000,047,889 | ---- | M] () -- C:\ProgramData\nvModes.dat [2012-10-02 17:14:16 | 000,001,026 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012-10-02 17:14:07 | 000,003,616 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2012-10-02 17:14:07 | 000,003,616 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2012-10-02 17:14:07 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2012-10-02 17:14:01 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012-10-02 17:13:58 | 2951,958,528 | -HS- | M] () -- C:\hiberfil.sys [2012-10-02 16:35:00 | 000,001,030 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012-10-02 10:24:49 | 000,524,288 | -HS- | M] () -- C:\Users\A&I\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms [2012-10-02 10:24:49 | 000,065,536 | -HS- | M] () -- C:\Users\A&I\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf [2012-10-02 10:24:45 | 001,902,642 | -H-- | M] () -- C:\Users\A&I\AppData\Local\IconCache.db [2012-09-28 22:25:02 | 000,001,938 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2012-09-28 22:20:48 | 000,001,796 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2012-09-28 22:20:34 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt [2012-09-28 16:17:46 | 229,322,166 | ---- | M] () -- C:\Windows\MEMORY.DMP [2012-09-20 21:27:10 | 000,395,052 | ---- | M] () -- C:\Users\A&I\Desktop\CV(1).pdf [2012-09-13 14:54:57 | 000,000,695 | ---- | M] () -- C:\Users\A&I\Desktop\A4Desk.lnk [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-09-28 22:37:34 | 001,902,642 | -H-- | C] () -- C:\Users\A&I\AppData\Local\IconCache.db [2012-09-28 22:25:02 | 000,001,938 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2012-09-28 22:20:48 | 000,001,796 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2012-09-28 17:31:02 | 2951,958,528 | -HS- | C] () -- C:\hiberfil.sys [2012-09-20 21:27:08 | 000,395,052 | ---- | C] () -- C:\Users\A&I\Desktop\CV(1).pdf [2012-09-13 14:54:57 | 000,000,695 | ---- | C] () -- C:\Users\A&I\Desktop\A4Desk.lnk [2012-07-12 22:46:32 | 000,024,206 | ---- | C] () -- C:\Users\A&I\AppData\Roaming\UserTile.png [2012-05-08 19:40:16 | 001,048,576 | -HS- | C] () -- C:\Users\A&I\NTUSER.DAT{d8932e6c-6a6f-11db-b6ab-a038f15a5785}.TxR.2.regtrans-ms [2012-05-08 19:40:16 | 001,048,576 | -HS- | C] () -- C:\Users\A&I\NTUSER.DAT{d8932e6c-6a6f-11db-b6ab-a038f15a5785}.TxR.1.regtrans-ms [2012-05-08 19:40:16 | 001,048,576 | -HS- | C] () -- C:\Users\A&I\NTUSER.DAT{d8932e6c-6a6f-11db-b6ab-a038f15a5785}.TxR.0.regtrans-ms [2012-05-08 19:40:16 | 000,065,536 | -HS- | C] () -- C:\Users\A&I\NTUSER.DAT{d8932e6c-6a6f-11db-b6ab-a038f15a5785}.TxR.blf [2012-01-25 01:27:33 | 000,000,000 | ---- | C] () -- C:\Users\A&I\AppData\Local\{47B47567-83CE-4EC9-B293-798C9A47C602} [2012-01-22 00:05:57 | 000,000,000 | ---- | C] () -- C:\Users\A&I\AppData\Local\{C812CAE7-4D73-4E64-A9A2-9E8D89796EFE} [2012-01-06 21:48:00 | 000,000,418 | ---- | C] () -- C:\Windows\ODBC.INI [2011-12-17 18:05:24 | 002,392,064 | ---- | C] () -- C:\Windows\System32\videotrans.dll [2011-12-17 18:05:23 | 000,215,040 | ---- | C] () -- C:\Windows\System32\videoformat.dll [2011-12-17 18:05:22 | 000,017,920 | ---- | C] () -- C:\Windows\System32\videocore.dll [2011-12-17 18:05:21 | 000,061,440 | ---- | C] () -- C:\Windows\System32\imgscaler.dll [2011-12-17 18:05:19 | 000,022,016 | ---- | C] () -- C:\Windows\System32\img_utils.dll [2011-12-17 18:05:12 | 000,217,088 | ---- | C] () -- C:\Windows\System32\xvidcore.dll [2011-12-17 18:05:11 | 000,128,512 | ---- | C] () -- C:\Windows\System32\xvid.dll [2011-12-13 10:38:59 | 000,000,000 | ---- | C] () -- C:\Users\A&I\AppData\Local\{69EC5782-04B7-47A2-893E-2C5635B11F21} [2011-12-13 10:17:12 | 000,000,000 | ---- | C] () -- C:\Users\A&I\AppData\Local\{FC00A22F-53E8-47A0-9F55-1A846C0B2CA0} [2011-07-24 23:31:09 | 000,000,000 | ---- | C] () -- C:\Users\A&I\AppData\Local\{CDE04CA5-CC47-4AD5-A521-D80082A6A8E7} [2011-05-07 15:54:06 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2011-04-29 00:57:09 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2011-04-29 00:57:09 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2011-04-29 00:56:46 | 000,368,640 | ---- | C] () -- C:\Windows\System32\msjetoledb40.dll [2011-04-26 02:09:52 | 000,098,304 | ---- | C] () -- C:\Windows\System32\redmonnt.dll [2011-04-25 10:43:32 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2011-04-24 20:10:08 | 000,047,889 | ---- | C] () -- C:\ProgramData\nvModes.001 [2011-04-24 20:10:06 | 000,047,889 | ---- | C] () -- C:\ProgramData\nvModes.dat [2011-04-24 18:46:56 | 000,035,328 | ---- | C] () -- C:\Users\A&I\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011-04-24 13:33:19 | 000,139,080 | ---- | C] () -- C:\Users\A&I\AppData\Local\GDIPFONTCACHEV1.DAT [2011-04-24 13:32:49 | 000,000,680 | ---- | C] () -- C:\Users\A&I\AppData\Local\d3d9caps.dat [2011-04-24 13:32:48 | 000,000,020 | -HS- | C] () -- C:\Users\A&I\ntuser.ini [2011-04-24 13:32:47 | 006,029,312 | -HS- | C] () -- C:\Users\A&I\NTUSER.DAT [2011-04-24 13:32:47 | 000,524,288 | -HS- | C] () -- C:\Users\A&I\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000002.regtrans-ms [2011-04-24 13:32:47 | 000,524,288 | -HS- | C] () -- C:\Users\A&I\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms [2011-04-24 13:32:47 | 000,065,536 | -HS- | C] () -- C:\Users\A&I\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf [color=#E56717]========== ZeroAccess Check ==========[/color] [2011-11-18 22:23:34 | 000,002,048 | -HS- | M] () -- C:\Windows\Installer\{20a7ac98-7a98-182e-89dc-95c72484c748}\@ [2011-11-18 22:23:34 | 000,045,568 | -HS- | M] () -- C:\Windows\Installer\{20a7ac98-7a98-182e-89dc-95c72484c748}\n [2011-11-18 22:23:34 | 000,000,000 | -HSD | M] -- C:\Windows\Installer\{20a7ac98-7a98-182e-89dc-95c72484c748}\L [2012-10-02 17:31:34 | 000,000,000 | -HSD | M] -- C:\Windows\Installer\{20a7ac98-7a98-182e-89dc-95c72484c748}\U [2012-09-27 17:46:52 | 000,000,928 | ---- | M] () -- C:\Windows\Installer\{20a7ac98-7a98-182e-89dc-95c72484c748}\U\00000001.@ [2012-09-28 22:37:18 | 000,002,048 | -HS- | M] () -- C:\Users\A&I\AppData\Local\{20a7ac98-7a98-182e-89dc-95c72484c748}\@ [2011-11-18 22:23:34 | 000,000,000 | -HSD | M] -- C:\Users\A&I\AppData\Local\{20a7ac98-7a98-182e-89dc-95c72484c748}\L [2011-11-18 22:23:34 | 000,000,000 | -HSD | M] -- C:\Users\A&I\AppData\Local\{20a7ac98-7a98-182e-89dc-95c72484c748}\U [2006-11-02 14:51:16 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "ThreadingModel" = Both "" = C:\Users\A&I\AppData\Local\{20a7ac98-7a98-182e-89dc-95c72484c748}\n. [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012-06-08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009-04-11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009-04-11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2011-04-24 17:05:55 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\ACD Systems [2011-11-05 09:13:04 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\All Free Disc Burner [2012-06-19 11:00:16 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\BatteryBar [2011-05-21 06:23:38 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\DAEMON Tools Lite [2011-05-21 07:06:28 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\Dev-Cpp [2011-05-14 09:34:52 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\ESET [2011-11-05 11:42:55 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\FDRLab [2011-04-26 00:02:16 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\Gadu-Gadu 10 [2011-12-17 17:53:41 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\GetRightToGo [2012-01-12 22:11:56 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\ipla [2011-04-24 13:40:41 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\iPlus [2011-05-02 17:46:06 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\LibreOffice [2011-04-26 00:20:21 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\OpenFM [2012-07-12 22:46:32 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\PeerNetworking [2011-12-02 13:56:24 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\VshareComplete [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:0E08FC17 < End of report >