OTL logfile created on: 2012-10-03 12:27:50 - Run 3 OTL by OldTimer - Version 3.2.70.1 Folder = c:\Users\A&I\Downloads Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,75 Gb Total Physical Memory | 1,69 Gb Available Physical Memory | 61,44% Memory free 5,72 Gb Paging File | 4,50 Gb Available in Paging File | 78,59% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 74,52 Gb Total Space | 3,36 Gb Free Space | 4,51% Space Free | Partition Type: NTFS Drive D: | 54,89 Gb Total Space | 6,99 Gb Free Space | 12,73% Space Free | Partition Type: NTFS Computer Name: KOMPUTERDOMOWY | User Name: A&I | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-10-02 22:43:04 | 000,690,096 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\Macromed\Flash\FlashUtil32_11_4_402_278_ActiveX.exe PRC - [2012-10-02 17:02:33 | 000,600,064 | ---- | M] (OldTimer Tools) -- c:\Users\A&I\Downloads\OTL.exe PRC - [2012-08-21 15:30:46 | 000,307,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe PRC - [2012-08-21 11:12:26 | 004,282,728 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe PRC - [2012-08-21 11:12:25 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe PRC - [2011-11-25 17:32:36 | 000,687,400 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Update\NASvc.exe PRC - [2009-08-28 22:07:22 | 000,406,896 | ---- | M] (PIXELA CORPORATION) -- C:\Program Files\PIXELA\ImageMixer 3 SE Ver.4.5\Transfer Utility\CameraMonitor.exe PRC - [2009-04-11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009-04-11 08:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe PRC - [2004-09-03 01:51:50 | 000,221,184 | ---- | M] (ACD Systems, Ltd.) -- C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012-06-17 00:17:00 | 001,840,640 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\663112d3002034cf5126be253efff60d\System.Web.Services.ni.dll MOD - [2012-06-15 22:04:14 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll MOD - [2012-06-15 22:03:06 | 001,592,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll MOD - [2012-05-14 10:05:51 | 000,998,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\f3d4d5fe5ab848fbfcf91a49960dc8ae\System.Management.ni.dll MOD - [2012-05-14 10:04:08 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll MOD - [2012-05-14 10:03:56 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\1b337cf9a031145849bc48c11b2cfe58\Accessibility.ni.dll MOD - [2012-05-14 09:43:18 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll MOD - [2012-05-14 09:41:30 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll MOD - [2012-05-14 09:41:14 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll MOD - [2009-03-31 20:05:12 | 000,311,296 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pl_b77a5c561934e089\mscorlib.resources.dll MOD - [2008-08-29 16:15:50 | 000,364,544 | ---- | M] () -- C:\Program Files\PIXELA\ImageMixer 3 SE Ver.4.5\Transfer Utility\pxl_m17n_tool.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - [2012-10-02 22:43:06 | 000,250,288 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012-08-21 11:12:25 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2011-11-25 17:32:36 | 000,687,400 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Nero\Update\NASvc.exe -- (NAUpdate) SRV - [2011-11-16 18:23:44 | 000,377,344 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- winhttp.dll -- (WinHttpAutoProxySvc) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - [2012-08-21 11:13:15 | 000,729,752 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2012-08-21 11:13:15 | 000,355,632 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP) DRV - [2012-08-21 11:13:15 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2012-08-21 11:13:14 | 000,058,680 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt) DRV - [2012-08-21 11:13:14 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (AswRdr) DRV - [2012-08-21 11:13:13 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2011-12-01 12:40:16 | 000,056,496 | ---- | M] (Nero AG) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\NBVol.sys -- (NBVol) DRV - [2011-12-01 12:40:16 | 000,012,464 | ---- | M] (Nero AG) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\NBVolUp.sys -- (NBVolUp) DRV - [2011-04-21 02:02:41 | 000,009,856 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\pfc.sys -- (pfc) DRV - [2010-08-12 12:07:50 | 000,292,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVNET) DRV - [2009-09-05 14:25:36 | 001,183,744 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2009-07-02 00:59:00 | 009,786,752 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2009-04-11 06:46:08 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usb8023.sys -- (usb_rndis) DRV - [2007-07-31 02:39:00 | 000,007,680 | ---- | M] (ATK0100) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ATKACPI.sys -- (MTsensor) DRV - [2006-11-02 09:41:49 | 001,010,560 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\smserial.sys -- (smserial) DRV - [2005-09-24 00:18:32 | 000,171,520 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MarvinBus.sys -- (MarvinBus) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com IE - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com IE - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~1\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2012-10-03 11:45:33 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [color=#E56717]========== Chrome ==========[/color] CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms} CHR - homepage: http://www.google.com/ CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.79\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.79\pdf.dll CHR - plugin: vShare.tv plug-in (Enabled) = C:\Users\A&I\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\chvsharetvplg.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U30 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll CHR - plugin: Nero Kwik Media Helper (Enabled) = C:\PROGRA~1\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - Extension: YouTube = C:\Users\A&I\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\ CHR - Extension: Szukaj w Google = C:\Users\A&I\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\ CHR - Extension: avast! WebRep = C:\Users\A&I\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1466_0\ CHR - Extension: Gmail = C:\Users\A&I\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2006-09-18 23:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O3 - HKLM\..\Toolbar: (no name) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - No CLSID value found. O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - No CLSID value found. O3 - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\..\Toolbar\WebBrowser: (no name) - {D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} - No CLSID value found. O3 - HKU\S-1-5-21-3566313445-2323643246-291810148-1000\..\Toolbar\WebBrowser: (no name) - {F999A48B-1950-4D81-9971-79018F807B4B} - No CLSID value found. O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [Device Detector] C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe (ACD Systems, Ltd.) O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe () O4 - HKLM..\Run: [NBAgent] C:\Program Files\Nero\Nero 11\Nero BackItUp\NBAgent.exe (Nero AG) O4 - HKLM..\Run: [NeroCheck] C:\Windows\System32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-21-3566313445-2323643246-291810148-1000..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.) O4 - HKU\S-1-5-21-3566313445-2323643246-291810148-1000..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden File not found O4 - HKU\S-1-5-21-3566313445-2323643246-291810148-1000..\Run: [Odkurzacz-MCD] D:\Odkurzacz\odk_mcd.exe (Franmo Software) O4 - HKU\S-1-5-21-3566313445-2323643246-291810148-1000..\Run: [ShowBatteryBar] C:\Program Files\BatteryBar\ShowBatteryBar.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1 O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4288DDE7-01A2-456A-BE3E-3728B4189B48}: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F1FE50CE-6EB0-4E8E-A2F9-5B66B0808C78}: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\A&I\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta z Galerii fotografii systemu Windows.jpg O24 - Desktop BackupWallPaper: C:\Users\A&I\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta z Galerii fotografii systemu Windows.jpg O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006-09-18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{12aad824-e2e1-11e0-8f08-002354628dad}\Shell - "" = AutoRun O33 - MountPoints2\{12aad824-e2e1-11e0-8f08-002354628dad}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{12aad831-e2e1-11e0-8f08-002354628dad}\Shell - "" = AutoRun O33 - MountPoints2\{12aad831-e2e1-11e0-8f08-002354628dad}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{9c6ceda3-f4f5-11e0-b7de-002354628dad}\Shell - "" = AutoRun O33 - MountPoints2\{9c6ceda3-f4f5-11e0-b7de-002354628dad}\Shell\AutoRun\command - "" = F:\Launcher.exe O33 - MountPoints2\{b1a1d084-f4fa-11e0-8b1b-002354628dad}\Shell - "" = AutoRun O33 - MountPoints2\{b1a1d084-f4fa-11e0-8b1b-002354628dad}\Shell\AutoRun\command - "" = F:\Launcher.exe O33 - MountPoints2\{eedd5408-ad1a-11e0-941a-002354628dad}\Shell - "" = AutoRun O33 - MountPoints2\{eedd5408-ad1a-11e0-941a-002354628dad}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{eedd5429-ad1a-11e0-941a-001e101f1ed9}\Shell - "" = AutoRun O33 - MountPoints2\{eedd5429-ad1a-11e0-941a-001e101f1ed9}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{f09d3060-f5d4-11e0-ac46-002354628dad}\Shell - "" = AutoRun O33 - MountPoints2\{f09d3060-f5d4-11e0-ac46-002354628dad}\Shell\AutoRun\command - "" = F:\Launcher.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-10-03 11:47:37 | 000,000,000 | ---D | C] -- C:\Program Files\DownloadManager [2012-10-03 09:27:57 | 000,000,000 | ---D | C] -- C:\_OTL [2012-10-02 22:43:05 | 000,696,240 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe [2012-09-28 22:25:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome [2012-09-28 22:20:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus [2012-09-28 22:20:47 | 000,021,256 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys [2012-09-28 22:20:46 | 000,355,632 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys [2012-09-28 22:20:42 | 000,035,928 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys [2012-09-28 22:20:41 | 000,054,232 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys [2012-09-28 22:20:39 | 000,729,752 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys [2012-09-28 22:20:34 | 000,058,680 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys [2012-09-28 22:20:03 | 000,227,648 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe [2012-09-28 22:20:03 | 000,041,224 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr [2012-09-28 22:19:41 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software [2012-09-28 22:19:41 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software [2012-09-17 09:51:42 | 000,000,000 | ---D | C] -- C:\Users\A&I\Desktop\CV praca [2012-09-13 20:25:22 | 000,000,000 | ---D | C] -- C:\Users\A&I\Desktop\Fotojoker [2012-09-13 14:54:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\A4Desk [2012-09-13 14:54:45 | 000,000,000 | ---D | C] -- C:\Program Files\A4Desk [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-10-03 12:31:36 | 006,029,312 | -HS- | M] () -- C:\Users\A&I\NTUSER.DAT [2012-10-03 12:30:00 | 000,000,434 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{CE8B8E70-09A4-484A-9774-FFB1979CB56B}.job [2012-10-03 12:06:04 | 000,047,889 | ---- | M] () -- C:\ProgramData\nvModes.001 [2012-10-03 12:04:58 | 000,047,889 | ---- | M] () -- C:\ProgramData\nvModes.dat [2012-10-03 12:04:53 | 000,001,026 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012-10-03 12:04:42 | 000,003,616 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2012-10-03 12:04:42 | 000,003,616 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2012-10-03 12:04:40 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2012-10-03 12:04:36 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012-10-03 12:04:33 | 2951,958,528 | -HS- | M] () -- C:\hiberfil.sys [2012-10-03 11:54:30 | 000,524,288 | -HS- | M] () -- C:\Users\A&I\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms [2012-10-03 11:54:30 | 000,065,536 | -HS- | M] () -- C:\Users\A&I\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf [2012-10-03 11:54:29 | 001,817,075 | -H-- | M] () -- C:\Users\A&I\AppData\Local\IconCache.db [2012-10-03 11:43:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012-10-03 11:35:00 | 000,001,030 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012-10-02 22:43:05 | 000,696,240 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe [2012-10-02 22:43:05 | 000,073,136 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [2012-09-28 22:25:02 | 000,001,938 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2012-09-28 22:20:48 | 000,001,796 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2012-09-28 22:20:34 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt [2012-09-28 16:17:46 | 229,322,166 | ---- | M] () -- C:\Windows\MEMORY.DMP [2012-09-20 21:27:10 | 000,395,052 | ---- | M] () -- C:\Users\A&I\Desktop\CV(1).pdf [2012-09-13 14:54:57 | 000,000,695 | ---- | M] () -- C:\Users\A&I\Desktop\A4Desk.lnk [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-10-03 11:48:11 | 000,001,789 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk [2012-10-03 11:48:10 | 000,001,733 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Uninstaller.lnk [2012-10-03 11:48:10 | 000,001,712 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk [2012-10-02 22:43:11 | 000,000,930 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012-09-28 22:37:34 | 001,817,075 | -H-- | C] () -- C:\Users\A&I\AppData\Local\IconCache.db [2012-09-28 22:25:02 | 000,001,938 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2012-09-28 22:20:48 | 000,001,796 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2012-09-28 17:31:02 | 2951,958,528 | -HS- | C] () -- C:\hiberfil.sys [2012-09-20 21:27:08 | 000,395,052 | ---- | C] () -- C:\Users\A&I\Desktop\CV(1).pdf [2012-09-13 14:54:57 | 000,000,695 | ---- | C] () -- C:\Users\A&I\Desktop\A4Desk.lnk [2012-07-12 22:46:32 | 000,024,206 | ---- | C] () -- C:\Users\A&I\AppData\Roaming\UserTile.png [2012-05-08 19:40:16 | 001,048,576 | -HS- | C] () -- C:\Users\A&I\NTUSER.DAT{d8932e6c-6a6f-11db-b6ab-a038f15a5785}.TxR.2.regtrans-ms [2012-05-08 19:40:16 | 001,048,576 | -HS- | C] () -- C:\Users\A&I\NTUSER.DAT{d8932e6c-6a6f-11db-b6ab-a038f15a5785}.TxR.1.regtrans-ms [2012-05-08 19:40:16 | 001,048,576 | -HS- | C] () -- C:\Users\A&I\NTUSER.DAT{d8932e6c-6a6f-11db-b6ab-a038f15a5785}.TxR.0.regtrans-ms [2012-05-08 19:40:16 | 000,065,536 | -HS- | C] () -- C:\Users\A&I\NTUSER.DAT{d8932e6c-6a6f-11db-b6ab-a038f15a5785}.TxR.blf [2012-01-25 01:27:33 | 000,000,000 | ---- | C] () -- C:\Users\A&I\AppData\Local\{47B47567-83CE-4EC9-B293-798C9A47C602} [2012-01-22 00:05:57 | 000,000,000 | ---- | C] () -- C:\Users\A&I\AppData\Local\{C812CAE7-4D73-4E64-A9A2-9E8D89796EFE} [2012-01-06 21:48:00 | 000,000,418 | ---- | C] () -- C:\Windows\ODBC.INI [2011-12-17 18:05:24 | 002,392,064 | ---- | C] () -- C:\Windows\System32\videotrans.dll [2011-12-17 18:05:23 | 000,215,040 | ---- | C] () -- C:\Windows\System32\videoformat.dll [2011-12-17 18:05:22 | 000,017,920 | ---- | C] () -- C:\Windows\System32\videocore.dll [2011-12-17 18:05:21 | 000,061,440 | ---- | C] () -- C:\Windows\System32\imgscaler.dll [2011-12-17 18:05:19 | 000,022,016 | ---- | C] () -- C:\Windows\System32\img_utils.dll [2011-12-17 18:05:12 | 000,217,088 | ---- | C] () -- C:\Windows\System32\xvidcore.dll [2011-12-17 18:05:11 | 000,128,512 | ---- | C] () -- C:\Windows\System32\xvid.dll [2011-12-13 10:38:59 | 000,000,000 | ---- | C] () -- C:\Users\A&I\AppData\Local\{69EC5782-04B7-47A2-893E-2C5635B11F21} [2011-12-13 10:17:12 | 000,000,000 | ---- | C] () -- C:\Users\A&I\AppData\Local\{FC00A22F-53E8-47A0-9F55-1A846C0B2CA0} [2011-07-24 23:31:09 | 000,000,000 | ---- | C] () -- C:\Users\A&I\AppData\Local\{CDE04CA5-CC47-4AD5-A521-D80082A6A8E7} [2011-05-07 15:54:06 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2011-04-29 00:57:09 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2011-04-29 00:57:09 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2011-04-29 00:56:46 | 000,368,640 | ---- | C] () -- C:\Windows\System32\msjetoledb40.dll [2011-04-26 02:09:52 | 000,098,304 | ---- | C] () -- C:\Windows\System32\redmonnt.dll [2011-04-25 10:43:32 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2011-04-24 20:10:08 | 000,047,889 | ---- | C] () -- C:\ProgramData\nvModes.001 [2011-04-24 20:10:06 | 000,047,889 | ---- | C] () -- C:\ProgramData\nvModes.dat [2011-04-24 18:46:56 | 000,035,328 | ---- | C] () -- C:\Users\A&I\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011-04-24 13:33:19 | 000,139,080 | ---- | C] () -- C:\Users\A&I\AppData\Local\GDIPFONTCACHEV1.DAT [2011-04-24 13:32:49 | 000,000,680 | ---- | C] () -- C:\Users\A&I\AppData\Local\d3d9caps.dat [2011-04-24 13:32:48 | 000,000,020 | -HS- | C] () -- C:\Users\A&I\ntuser.ini [2011-04-24 13:32:47 | 006,029,312 | -HS- | C] () -- C:\Users\A&I\NTUSER.DAT [2011-04-24 13:32:47 | 000,524,288 | -HS- | C] () -- C:\Users\A&I\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000002.regtrans-ms [2011-04-24 13:32:47 | 000,524,288 | -HS- | C] () -- C:\Users\A&I\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms [2011-04-24 13:32:47 | 000,065,536 | -HS- | C] () -- C:\Users\A&I\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf [color=#E56717]========== ZeroAccess Check ==========[/color] [2006-11-02 14:51:16 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012-06-08 19:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009-04-11 08:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009-04-11 08:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2011-04-24 17:05:55 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\ACD Systems [2011-11-05 09:13:04 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\All Free Disc Burner [2012-06-19 11:00:16 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\BatteryBar [2011-05-21 06:23:38 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\DAEMON Tools Lite [2011-05-21 07:06:28 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\Dev-Cpp [2011-05-14 09:34:52 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\ESET [2011-11-05 11:42:55 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\FDRLab [2011-04-26 00:02:16 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\Gadu-Gadu 10 [2011-12-17 17:53:41 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\GetRightToGo [2012-01-12 22:11:56 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\ipla [2011-04-24 13:40:41 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\iPlus [2011-05-02 17:46:06 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\LibreOffice [2011-04-26 00:20:21 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\OpenFM [2012-07-12 22:46:32 | 000,000,000 | ---D | M] -- C:\Users\A&I\AppData\Roaming\PeerNetworking [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:0E08FC17 < End of report >