OTL logfile created on: 2012-12-07 14:13:23 - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Gliwice\Desktop Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000415 | Country: Poland | Language: PLK | Date Format: yyyy-MM-dd 1,99 Gb Total Physical Memory | 1,66 Gb Available Physical Memory | 83,38% Memory free 3,84 Gb Paging File | 3,69 Gb Available in Paging File | 95,93% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 25,69 Gb Total Space | 1,37 Gb Free Space | 5,34% Space Free | Partition Type: NTFS Drive D: | 48,83 Gb Total Space | 28,09 Gb Free Space | 57,54% Space Free | Partition Type: NTFS Computer Name: 66GSM-47D8763EC | User Name: Gliwice | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-12-07 09:09:30 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Gliwice\Desktop\OTL.exe PRC - [2012-09-01 08:05:12 | 000,874,896 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe PRC - [2008-04-14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012-02-18 05:55:35 | 000,166,912 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll MOD - [2009-02-27 19:04:20 | 000,311,296 | ---- | M] () -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\pdfshell.POL MOD - [2008-04-14 04:42:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll MOD - [2008-04-14 04:41:52 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt) SRV - [2012-06-05 01:46:02 | 000,116,632 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe -- (Motorola Device Manager) SRV - [2012-04-22 12:51:04 | 000,720,936 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) SRV - [2012-01-18 13:38:28 | 000,155,320 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Program Files\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbser6k.sys -- (ZTEusbser6k) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbnmea.sys -- (ZTEusbnmea) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbmdm6k.sys -- (ZTEusbmdm6k) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgusbmodem.sys -- (USBModem) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgusbdiag.sys -- (UsbDiag) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgusbbus.sys -- (usbbus) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\massfilter.sys -- (massfilter) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbmdm.sys -- (hwdatacard) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ew_jubusenum.sys -- (huawei_enumerator) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbnet.sys -- (ewusbnet) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ew_hwusbdev.sys -- (ew_hwusbdev) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2012-12-07 14:11:32 | 000,017,152 | ---- | M] (NVIDIA Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nvmini.sys -- (nvmini) DRV - [2012-04-22 12:51:38 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd) DRV - [2012-01-25 13:58:00 | 000,023,808 | ---- | M] (Motorola Mobility Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Motousbnet.sys -- (Motousbnet) DRV - [2012-01-25 13:57:48 | 000,024,192 | ---- | M] (Motorola Mobility Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\motmodem.sys -- (motmodem) DRV - [2012-01-25 13:57:44 | 000,008,448 | ---- | M] (Motorola Mobility Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\motccgpfl.sys -- (motccgpfl) DRV - [2012-01-25 13:57:36 | 000,020,864 | ---- | M] (Motorola Mobility Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\motccgp.sys -- (motccgp) DRV - [2012-01-09 17:28:20 | 000,137,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsu.sys -- (nmwcdnsu) DRV - [2012-01-09 17:28:20 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc) DRV - [2012-01-09 17:28:20 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd) DRV - [2012-01-09 17:28:20 | 000,008,576 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc) DRV - [2012-01-09 17:28:20 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt) DRV - [2012-01-09 17:28:20 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev) DRV - [2011-12-08 05:22:28 | 000,016,384 | ---- | M] (Danish Wireless Design A/S) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\flashusb.sys -- (flashusb) DRV - [2011-11-08 12:59:04 | 000,011,008 | ---- | M] (Motorola Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\motusbdevice.sys -- (motusbdevice) DRV - [2011-10-18 01:43:42 | 000,181,432 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssudobex.sys -- (ssudobex) DRV - [2011-08-25 05:43:54 | 000,181,432 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssudserd.sys -- (ssudserd) DRV - [2011-08-25 05:43:54 | 000,181,432 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssudmdm.sys -- (ssudmdm) DRV - [2011-08-25 05:43:54 | 000,077,624 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssudbus.sys -- (dg_ssudbus) DRV - [2011-07-13 09:21:20 | 000,080,968 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssdudfu.sys -- (ssdudfu) DRV - [2011-06-02 06:47:22 | 000,136,808 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdm.sys -- (ssadmdm) DRV - [2011-06-02 06:47:22 | 000,121,064 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadbus.sys -- (ssadbus) DRV - [2011-06-02 06:47:22 | 000,114,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadserd.sys -- (ssadserd) DRV - [2011-06-02 06:47:22 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadmdfl.sys -- (ssadmdfl) DRV - [2011-03-18 17:08:54 | 000,025,240 | ---- | M] (Almico Software) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan) DRV - [2011-03-18 13:46:26 | 000,061,704 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ftdibus.sys -- (FTDIBUS) DRV - [2011-03-18 13:46:10 | 000,073,096 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ftser2k.sys -- (FTSER2K) DRV - [2011-03-01 20:36:54 | 000,037,184 | ---- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cyclonebox.sys -- (cyclonebox) DRV - [2010-12-21 06:55:02 | 000,132,608 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssm_mdm.sys -- (ssm_mdm) DRV - [2010-12-21 06:55:02 | 000,123,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdm.sys -- (ss_mdm) DRV - [2010-12-21 06:55:02 | 000,123,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdm.sys -- (ss_bmdm) DRV - [2010-12-21 06:55:02 | 000,104,448 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssm_bus.sys -- (ssm_bus) DRV - [2010-12-21 06:55:02 | 000,100,224 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bserd.sys -- (ss_bserd) DRV - [2010-12-21 06:55:02 | 000,098,560 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bus.sys -- (ss_bus) DRV - [2010-12-21 06:55:02 | 000,098,432 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bbus.sys -- (ss_bbus) DRV - [2010-12-21 06:55:02 | 000,030,312 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssadadb.sys -- (androidusb) DRV - [2010-12-21 06:55:02 | 000,014,848 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssm_mdfl.sys -- (ssm_mdfl) DRV - [2010-12-21 06:55:02 | 000,014,848 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_mdfl.sys -- (ss_mdfl) DRV - [2010-12-21 06:55:02 | 000,014,848 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdfl.sys -- (ss_bmdfl) DRV - [2010-12-07 13:23:00 | 000,025,088 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgandmodem.sys -- (ANDModem) DRV - [2010-12-07 13:23:00 | 000,020,736 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lganddiag.sys -- (AndDiag) DRV - [2010-12-07 13:23:00 | 000,020,096 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgandgps.sys -- (AndGps) DRV - [2010-12-07 13:22:58 | 000,014,336 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgandbus.sys -- (Andbus) DRV - [2010-01-14 08:03:00 | 000,123,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscemdm.sys -- (sscemdm) DRV - [2010-01-14 08:03:00 | 000,100,352 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssceserd.sys -- (ssceserd) DRV - [2010-01-14 08:03:00 | 000,098,560 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscebus.sys -- (sscebus) DRV - [2010-01-14 08:03:00 | 000,014,848 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscemdfl.sys -- (sscemdfl) DRV - [2010-01-14 08:02:54 | 000,014,848 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdfl.sys -- (sscdmdfl) DRV - [2010-01-14 08:02:52 | 000,123,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdm.sys -- (sscdmdm) DRV - [2010-01-14 08:02:52 | 000,100,352 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdserd.sys -- (sscdserd) DRV - [2010-01-14 08:02:52 | 000,098,560 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdbus.sys -- (sscdbus) DRV - [2010-01-05 12:31:32 | 001,714,176 | R--- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\athuw.sys -- (AR9271) DRV - [2009-12-30 17:56:46 | 000,088,960 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hmumdm.sys -- (MobileAdapter) DRV - [2009-12-17 10:31:42 | 000,021,504 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\Ndisprot.sys -- (Ndisprot) DRV - [2009-12-05 03:20:02 | 000,098,560 | ---- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\qcusbser.sys -- (qcusbser) DRV - [2009-10-21 12:04:22 | 000,028,160 | ---- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\libusb0.sys -- (libusb0) DRV - [2009-09-29 07:11:22 | 000,012,160 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgbtport.sys -- (LgBttPort) DRV - [2009-09-29 07:11:20 | 000,012,928 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgvmodem.sys -- (LGVMODEM) DRV - [2009-09-29 07:11:20 | 000,010,496 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lgbtbus.sys -- (lgbusenum) DRV - [2009-07-13 16:51:12 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\winusb.sys -- (WinUSB) DRV - [2009-05-08 11:56:12 | 000,042,752 | ---- | M] (Motorola Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\motodrv.sys -- (MotDev) DRV - [2009-04-06 11:13:52 | 000,025,512 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ggsemc.sys -- (ggsemc) DRV - [2009-04-06 11:13:52 | 000,013,224 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ggflt.sys -- (ggflt) DRV - [2009-01-29 17:11:20 | 000,006,016 | ---- | M] (Motorola Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\motfilt.sys -- (BTCFilterService) DRV - [2008-07-23 23:29:16 | 000,047,744 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vserial.sys -- (vserial) DRV - [2008-07-23 23:29:16 | 000,015,264 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vsb.sys -- (vsbus) DRV - [2008-01-21 07:56:38 | 000,034,688 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\pcampr5.sys -- (PCAMPR5) DRV - [2008-01-21 07:56:38 | 000,032,128 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\pcandis5.sys -- (PCANDIS5) DRV - [2007-11-02 15:51:30 | 000,006,400 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\motswch.sys -- (MotoSwitchService) DRV - [2007-11-02 12:47:38 | 000,103,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s916mgmt.sys -- (s916mgmt) DRV - [2007-11-02 12:47:38 | 000,100,008 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s916obex.sys -- (s916obex) DRV - [2007-11-02 09:47:38 | 000,109,992 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s916mdm.sys -- (s916mdm) DRV - [2007-11-02 09:47:38 | 000,083,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s916bus.sys -- (s916bus) DRV - [2007-11-02 09:47:38 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s916mdfl.sys -- (s916mdfl) DRV - [2007-04-24 08:33:46 | 000,100,488 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s125mgmt.sys -- (s125mgmt) DRV - [2007-04-24 08:33:46 | 000,098,696 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s125obex.sys -- (s125obex) DRV - [2007-04-24 08:33:44 | 000,108,680 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s125mdm.sys -- (s125mdm) DRV - [2007-04-24 08:33:42 | 000,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s125mdfl.sys -- (s125mdfl) DRV - [2007-04-24 08:33:34 | 000,083,336 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s125bus.sys -- (s125bus) DRV - [2006-07-24 16:05:00 | 000,005,632 | ---- | M] () [File_System | System | Stopped] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen) DRV - [2006-05-19 10:23:00 | 000,018,880 | ---- | M] (Axalto) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\egate.sys -- (Egatecard) DRV - [2006-05-19 10:23:00 | 000,015,328 | ---- | M] (Axalto) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\egatebus.sys -- (Egatebus) DRV - [2006-05-19 10:23:00 | 000,013,440 | ---- | M] (Axalto) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\egaterdr.sys -- (Egaterdr) DRV - [2004-10-14 06:29:54 | 000,021,888 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\eps2kt1.sys -- (token) DRV - [2004-09-28 17:01:28 | 000,012,800 | ---- | M] (OEM) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\smccard.sys -- (R5BaseSmc) DRV - [2004-09-17 18:02:54 | 000,732,928 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt) DRV - [2004-08-23 23:49:30 | 000,121,472 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k) DRV - [1996-04-03 20:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.* [color=#E56717]========== FireFox ==========[/color] FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll () FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{00ADD29A-66F4-4f22-BCC0-4C1D29DA647B}: C:\Program Files\LG Electronics\LG PC Suite IV\LinkAir\{00ADD29A-66F4-4f22-BCC0-4C1D29DA647B}\ [2012-04-16 10:27:27 | 000,000,000 | ---D | M] [2012-03-20 19:12:15 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Gliwice\Application Data\Mozilla\Extensions [2012-03-20 19:12:15 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Gliwice\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} O1 HOSTS File: ([2004-08-04 13:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (HistoryTriggerBHO Class) - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Program Files\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll (LG Electronics) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found. O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [B2C_AGENT] C:\Documents and Settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe (LG Electronics) O4 - HKLM..\Run: [BEWINTERNET-PL-IEWSessionManager] "C:\Program Files\OrangeBS\BEWInternet-PL-IEW\SessionManager\SessionManager.exe" File not found O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG) O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited) O4 - HKLM..\Run: [ROC_ROC_NT] "C:\Program Files\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT File not found O4 - HKCU..\Run: [GG] C:\Documents and Settings\Gliwice\Local Settings\Application Data\GG\Application\gghub.exe (GG Network S.A.) O4 - HKCU..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG) O4 - HKCU..\Run: [NokiaSuite.exe] C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe (Nokia) O4 - HKCU..\Run: [Wpnanw] C:\Documents and Settings\Gliwice\Application Data\Wpnanw.exe () O4 - Startup: C:\Documents and Settings\Gliwice\Start Menu\Programs\Startup\Shortcut to WAŻNE.lnk = C:\Documents and Settings\Gliwice\Desktop\WAŻNE.txt () O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: LG Link Air Option - C:\Program Files\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll (Mobile Leader Co.,Ltd.) O8 - Extra context menu item: LG Link Air Save to Mobile Document Folder - C:\Program Files\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll (Mobile Leader Co.,Ltd.) O8 - Extra context menu item: LG Link Air Save to Mobile Memo - C:\Program Files\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll (Mobile Leader Co.,Ltd.) O8 - Extra context menu item: LG Link Air Save to Mobile Photo Album - C:\Program Files\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll (Mobile Leader Co.,Ltd.) O8 - Extra context menu item: LG Link Air Set as Mobile Wallpaper - C:\Program Files\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll (Mobile Leader Co.,Ltd.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{62A340FD-1D89-4BD8-9BE5-E2303141A163}: DhcpNameServer = 217.116.100.65 79.163.127.70 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B7F45D13-F58A-4C58-93A7-0B1A1E169D15}: DhcpNameServer = 192.168.0.1 O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation) O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2012-03-19 20:18:50 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{03b845c8-aeeb-11e1-b4b9-00142232dfb3}\Shell - "" = Autorun O33 - MountPoints2\{03b845c8-aeeb-11e1-b4b9-00142232dfb3}\Shell\AutoRun\command - "" = F:\Nokia_Ovi_Suite_3_0_0_291_ALL.exe O33 - MountPoints2\{06013d21-cf23-11e1-b4ef-00142232dfb3}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{06013d21-cf23-11e1-b4ef-00142232dfb3}\Shell\open\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{061345b1-0d55-11e2-b549-00142232dfb3}\Shell - "" = AutoRun O33 - MountPoints2\{061345b1-0d55-11e2-b549-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{061345b1-0d55-11e2-b549-00142232dfb3}\Shell\AutoRun\command - "" = F:\USBAutoRun.exe O33 - MountPoints2\{15827847-b5f5-11e1-b4c3-00142232dfb3}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{15827847-b5f5-11e1-b4c3-00142232dfb3}\Shell\open\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{1785029e-093f-11e2-b544-00142232dfb3}\Shell\explore\Command - "" = F:\boot.exe O33 - MountPoints2\{1785029e-093f-11e2-b544-00142232dfb3}\Shell\open\Command - "" = F:\boot.exe O33 - MountPoints2\{1c976f94-7801-11e1-b45d-00142232dfb3}\Shell - "" = AutoRun O33 - MountPoints2\{1c976f94-7801-11e1-b45d-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{1c976f94-7801-11e1-b45d-00142232dfb3}\Shell\AutoRun\command - "" = F:\AutoRunCardDetector.exe O33 - MountPoints2\{1c976f95-7801-11e1-b45d-00142232dfb3}\Shell - "" = AutoRun O33 - MountPoints2\{1c976f95-7801-11e1-b45d-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{1c976f95-7801-11e1-b45d-00142232dfb3}\Shell\AutoRun\command - "" = F:\AutoRunCardDetector.exe O33 - MountPoints2\{1c976f97-7801-11e1-b45d-00142232dfb3}\Shell - "" = AutoRun O33 - MountPoints2\{1c976f97-7801-11e1-b45d-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{1c976f97-7801-11e1-b45d-00142232dfb3}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{219f91b5-7bd1-11e1-b466-00142232dfb3}\Shell - "" = AutoRun O33 - MountPoints2\{219f91b5-7bd1-11e1-b466-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{219f91b5-7bd1-11e1-b466-00142232dfb3}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a O33 - MountPoints2\{219f91b6-7bd1-11e1-b466-00142232dfb3}\Shell\AutoRun\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{219f91b6-7bd1-11e1-b466-00142232dfb3}\Shell\open\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{3aab5bbe-02f1-11e2-b53c-00142232dfb3}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{3aab5bbe-02f1-11e2-b53c-00142232dfb3}\Shell\open\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{3dd53aaf-0ee6-11e2-b54c-00142232dfb3}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{3dd53aaf-0ee6-11e2-b54c-00142232dfb3}\Shell\open\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{3eed9636-733e-11e1-b455-00142232dfb3}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{3eed9636-733e-11e1-b455-00142232dfb3}\Shell\open\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{572158da-8616-11e1-b475-00142232dfb3}\Shell - "" = AutoRun O33 - MountPoints2\{572158da-8616-11e1-b475-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{572158da-8616-11e1-b475-00142232dfb3}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{5ebe96b7-f727-11e1-b52d-00142232dfb3}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{5ebe96b7-f727-11e1-b52d-00142232dfb3}\Shell\open\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{65fa59ca-da26-11e1-b4fe-00142232dfb3}\Shell - "" = AutoRun O33 - MountPoints2\{65fa59ca-da26-11e1-b4fe-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{65fa59ca-da26-11e1-b4fe-00142232dfb3}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{65fa59cd-da26-11e1-b4fe-00142232dfb3}\Shell - "" = AutoRun O33 - MountPoints2\{65fa59cd-da26-11e1-b4fe-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{65fa59cd-da26-11e1-b4fe-00142232dfb3}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{65fa59cd-da26-11e1-b4fe-00142232dfb3}\Shell\install\command - "" = F:\setup-top_netinfo.EXE O33 - MountPoints2\{65fa59cd-da26-11e1-b4fe-00142232dfb3}\Shell\readme\command - "" = notepad info.txt O33 - MountPoints2\{65fa59d1-da26-11e1-b4fe-00142232dfb3}\Shell - "" = AutoRun O33 - MountPoints2\{65fa59d1-da26-11e1-b4fe-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{65fa59d1-da26-11e1-b4fe-00142232dfb3}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{65fa59d1-da26-11e1-b4fe-00142232dfb3}\Shell\install\command - "" = F:\setup-top_netinfo.EXE O33 - MountPoints2\{65fa59d1-da26-11e1-b4fe-00142232dfb3}\Shell\readme\command - "" = notepad info.txt O33 - MountPoints2\{7b2a41ea-f366-11e1-b528-00142232dfb3}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{7b2a41ea-f366-11e1-b528-00142232dfb3}\Shell\open\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{81fea292-b86e-11e1-b4c6-00142232dfb3}\Shell - "" = AutoRun O33 - MountPoints2\{81fea292-b86e-11e1-b4c6-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{81fea292-b86e-11e1-b4c6-00142232dfb3}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{84ab3af0-27fb-11e2-b576-00142232dfb3}\Shell - "" = AutoRun O33 - MountPoints2\{84ab3af0-27fb-11e2-b576-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{84ab3af0-27fb-11e2-b576-00142232dfb3}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{885210b2-2e3c-11e2-b57d-00142232dfb3}\Shell\AutoRun\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{885210b2-2e3c-11e2-b57d-00142232dfb3}\Shell\open\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{885210b3-2e3c-11e2-b57d-00142232dfb3}\Shell\AutoRun\command - "" = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{885210b3-2e3c-11e2-b57d-00142232dfb3}\Shell\open\command - "" = H:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{93f1e206-ae19-11e1-b4b7-00142232dfb3}\Shell\AutoRun\command - "" = F:\Launcher.exe O33 - MountPoints2\{99a21a2a-dbee-11e1-b502-00142232dfb3}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{99a21a2a-dbee-11e1-b502-00142232dfb3}\Shell\open\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{a610f3d4-ad54-11e1-b4b6-00142232dfb3}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{a610f3d4-ad54-11e1-b4b6-00142232dfb3}\Shell\open\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{a9b48777-b9fa-11e1-b4cb-00142232dfb3}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{a9b48777-b9fa-11e1-b4cb-00142232dfb3}\Shell\open\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{a9b48778-b9fa-11e1-b4cb-00142232dfb3}\Shell\AutoRun\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{a9b48778-b9fa-11e1-b4cb-00142232dfb3}\Shell\open\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{ab0f3110-f805-11e1-b52e-00142232dfb3}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{ab0f3110-f805-11e1-b52e-00142232dfb3}\Shell\open\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{ad9d4be3-fb1b-11e1-b532-00142232dfb3}\Shell\explore\Command - "" = F:\boot.exe O33 - MountPoints2\{ad9d4be3-fb1b-11e1-b532-00142232dfb3}\Shell\open\Command - "" = F:\boot.exe O33 - MountPoints2\{aea1fb6e-b881-11e1-b4c7-00142232dfb3}\Shell - "" = AutoRun O33 - MountPoints2\{aea1fb6e-b881-11e1-b4c7-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{aea1fb6e-b881-11e1-b4c7-00142232dfb3}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{aea1fb6e-b881-11e1-b4c7-00142232dfb3}\Shell\install\command - "" = F:\setup-top_netinfo.EXE O33 - MountPoints2\{aea1fb6e-b881-11e1-b4c7-00142232dfb3}\Shell\readme\command - "" = notepad info.txt O33 - MountPoints2\{aea1fb70-b881-11e1-b4c7-00142232dfb3}\Shell - "" = AutoRun O33 - MountPoints2\{aea1fb70-b881-11e1-b4c7-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{aea1fb70-b881-11e1-b4c7-00142232dfb3}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{aea1fb70-b881-11e1-b4c7-00142232dfb3}\Shell\install\command - "" = F:\setup-top_netinfo.EXE O33 - MountPoints2\{aea1fb70-b881-11e1-b4c7-00142232dfb3}\Shell\readme\command - "" = notepad info.txt O33 - MountPoints2\{b753cbb0-7804-11e1-b45e-00142232dfb3}\Shell - "" = AutoRun O33 - MountPoints2\{b753cbb0-7804-11e1-b45e-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{b753cbb0-7804-11e1-b45e-00142232dfb3}\Shell\AutoRun\command - "" = F:\AutoRunCardDetector.exe O33 - MountPoints2\{b8ee4c6e-dcab-11e1-b503-00142232dfb3}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{b8ee4c6e-dcab-11e1-b503-00142232dfb3}\Shell\open\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{b8ee4c6f-dcab-11e1-b503-00142232dfb3}\Shell\explore\Command - "" = G:\boot.exe O33 - MountPoints2\{b8ee4c6f-dcab-11e1-b503-00142232dfb3}\Shell\open\Command - "" = G:\boot.exe O33 - MountPoints2\{c44124f6-71fd-11e1-b44c-d5d7b0680e92}\Shell\explore\Command - "" = F:\boot.exe O33 - MountPoints2\{c44124f6-71fd-11e1-b44c-d5d7b0680e92}\Shell\open\Command - "" = F:\boot.exe O33 - MountPoints2\{db26f316-0dfc-11e2-b54a-00142232dfb3}\Shell\explore\Command - "" = G:\boot.exe O33 - MountPoints2\{db26f316-0dfc-11e2-b54a-00142232dfb3}\Shell\open\Command - "" = G:\boot.exe O33 - MountPoints2\{e740fb64-77f6-11e1-b45c-00142232dfb3}\Shell - "" = AutoRun O33 - MountPoints2\{e740fb64-77f6-11e1-b45c-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{e740fb64-77f6-11e1-b45c-00142232dfb3}\Shell\AutoRun\command - "" = F:\AutoRunCardDetector.exe O33 - MountPoints2\{f31b4d93-bdd9-11e1-b4d0-00142232dfb3}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{f31b4d93-bdd9-11e1-b4d0-00142232dfb3}\Shell\open\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{f4a6c2d2-e14e-11e1-b50a-00142232dfb3}\Shell - "" = AutoRun O33 - MountPoints2\{f4a6c2d2-e14e-11e1-b50a-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{f4a6c2d2-e14e-11e1-b50a-00142232dfb3}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{f4a6c2d5-e14e-11e1-b50a-00142232dfb3}\Shell - "" = AutoRun O33 - MountPoints2\{f4a6c2d5-e14e-11e1-b50a-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{f4a6c2d5-e14e-11e1-b50a-00142232dfb3}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{f4a6c2d6-e14e-11e1-b50a-00142232dfb3}\Shell - "" = AutoRun O33 - MountPoints2\{f4a6c2d6-e14e-11e1-b50a-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{f4a6c2d6-e14e-11e1-b50a-00142232dfb3}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{fb1edd25-2b1c-11e2-b57a-00142232dfb3}\Shell - "" = AutoRun O33 - MountPoints2\{fb1edd25-2b1c-11e2-b57a-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{fb1edd25-2b1c-11e2-b57a-00142232dfb3}\Shell\AutoRun\command - "" = F:\MicroLauncher.exe O33 - MountPoints2\{fb1edd26-2b1c-11e2-b57a-00142232dfb3}\Shell\AutoRun\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{fb1edd26-2b1c-11e2-b57a-00142232dfb3}\Shell\open\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe O33 - MountPoints2\{ff9b5794-ab35-11e1-b4b3-00142232dfb3}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{ff9b5794-ab35-11e1-b4b3-00142232dfb3}\Shell\AutoRun\command - "" = caffemercy//undotres.exe O33 - MountPoints2\{ff9b5794-ab35-11e1-b4b3-00142232dfb3}\Shell\Explore\command - "" = caffemercy/undotres.exe O33 - MountPoints2\{ff9b5794-ab35-11e1-b4b3-00142232dfb3}\Shell\Open\command - "" = caffemercy/undotres.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-12-07 09:09:30 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Gliwice\Desktop\OTL.exe [2012-12-03 13:18:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gliwice\Local Settings\Application Data\Ahead [2012-12-03 13:17:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Nero 8 [2012-12-03 13:16:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gliwice\Application Data\Nero [2012-12-03 13:13:09 | 000,000,000 | ---D | C] -- C:\Program Files\Nero [2012-12-03 13:13:09 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nero [2012-12-03 13:13:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Nero [2012-12-03 13:11:48 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_30.dll [2012-12-03 13:11:46 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_28.dll [2012-12-03 12:57:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gliwice\My Documents\Nero 8.3.6.0 PL + KeyGen [2012-11-28 17:36:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gliwice\Local Settings\Application Data\M-Photo_Ltd [2012-11-28 17:26:21 | 000,000,000 | ---D | C] -- C:\MPR500_Submitted_Orders [2012-11-28 16:33:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\M-Photo [2012-11-28 16:32:29 | 000,000,000 | ---D | C] -- C:\FotoElita_Albumy [2012-11-19 15:57:46 | 000,017,152 | ---- | C] (NVIDIA Corporation) -- C:\WINDOWS\System32\drivers\IsDrv118.sys [2012-11-10 12:07:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gliwice\My Documents\Mobile_Partner_UTPS11.302.09.00.03 [2012-11-10 11:54:23 | 000,000,000 | ---D | C] -- C:\Program Files\OrangeBS [2012-11-10 11:53:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\France Telecom [2012-11-09 19:23:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Gliwice\Desktop\NssPro_0.51_2_b [2012-11-09 16:16:02 | 000,000,000 | ---D | C] -- C:\Program Files\HP [2012-11-09 16:15:59 | 000,106,496 | ---- | C] (Zenographics, Inc.) -- C:\WINDOWS\System32\ZSPOOL.DLL [2012-11-09 16:15:59 | 000,102,400 | ---- | C] (Zenographics, Inc.) -- C:\WINDOWS\System32\ZLhp1018.DLL [2012-11-09 16:15:59 | 000,061,440 | ---- | C] (Zenographics, Inc.) -- C:\WINDOWS\System32\ZIMF.DLL [2012-11-09 16:15:59 | 000,053,248 | ---- | C] (Zenographics, Inc.) -- C:\WINDOWS\System32\ZTAG.DLL [4 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ] [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-12-07 14:11:32 | 000,017,152 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\drivers\nvmini.sys [2012-12-07 14:11:13 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012-12-07 14:00:19 | 000,002,413 | ---- | M] () -- C:\WINDOWS\System32\lgAxconfig.ini [2012-12-07 14:00:13 | 000,236,458 | ---- | M] () -- C:\Documents and Settings\Gliwice\Application Data\Wpnanw.exe [2012-12-07 14:00:12 | 000,236,458 | ---- | M] () -- C:\Documents and Settings\Gliwice\atar.exe [2012-12-07 13:41:51 | 000,302,592 | ---- | M] () -- C:\Documents and Settings\Gliwice\Desktop\tf9g4c5y.exe [2012-12-07 09:09:30 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Gliwice\Desktop\OTL.exe [2012-12-06 08:57:29 | 000,236,458 | ---- | M] () -- C:\Documents and Settings\Gliwice\Connectio.exe [2012-12-03 18:57:30 | 000,493,054 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012-12-03 18:57:30 | 000,083,598 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2012-12-03 13:17:58 | 000,002,376 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Nero StartSmart.lnk [2012-12-03 13:15:55 | 000,001,024 | ---- | M] () -- C:\Documents and Settings\Gliwice\.rnd [2012-12-01 18:01:37 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_Motousbnet_01007.Wdf [2012-12-01 18:01:37 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_motfilt_01007.Wdf [2012-12-01 18:01:22 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_motccgpfl_01007.Wdf [2012-12-01 18:01:22 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_motccgp_01007.Wdf [2012-12-01 18:01:15 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_motusbdevice_01007.Wdf [2012-11-30 20:28:55 | 000,000,709 | ---- | M] () -- C:\Documents and Settings\Gliwice\Desktop\TELEFONY SPRZEDANE TESCO GLIWICE GRUDZIEN 2012.lnk [2012-11-30 20:28:48 | 000,000,661 | ---- | M] () -- C:\Documents and Settings\Gliwice\Desktop\RAPORT TESCO GLIWICE GRUDZIEN 2012.lnk [2012-11-30 17:15:01 | 000,017,152 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\drivers\IsDrv118.sys [2012-11-30 10:12:06 | 000,016,171 | ---- | M] () -- C:\Documents and Settings\Gliwice\Desktop\GRAFIK GRUDZIEN.ods [2012-11-28 16:31:41 | 004,304,149 | ---- | M] () -- C:\WINDOWS\System32\FotoElita_ElitBook DESIGNER_uninstaller.exe [2012-11-20 19:05:18 | 000,012,019 | ---- | M] () -- C:\Documents and Settings\Gliwice\My Documents\NOC ZAKUPOW.odt [2012-11-14 16:37:52 | 000,000,886 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Samsung Tool.lnk [2012-11-12 08:56:55 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012-11-10 16:51:46 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\Gliwice\Desktop\Samsung Tool.lnk [2012-11-10 16:27:31 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Cyclone Box.lnk [2012-11-09 19:18:50 | 000,208,004 | ---- | M] () -- C:\Documents and Settings\Gliwice\Desktop\lumia.pdf [4 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ] [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-12-07 14:00:13 | 000,236,458 | ---- | C] () -- C:\Documents and Settings\Gliwice\Application Data\Wpnanw.exe [2012-12-07 13:41:51 | 000,302,592 | ---- | C] () -- C:\Documents and Settings\Gliwice\Desktop\tf9g4c5y.exe [2012-12-07 13:13:39 | 000,236,458 | ---- | C] () -- C:\Documents and Settings\Gliwice\atar.exe [2012-12-04 19:31:00 | 000,236,458 | ---- | C] () -- C:\Documents and Settings\Gliwice\Connectio.exe [2012-12-03 13:17:58 | 000,002,376 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Nero StartSmart.lnk [2012-12-03 13:15:54 | 000,001,024 | ---- | C] () -- C:\Documents and Settings\Gliwice\.rnd [2012-12-01 18:01:37 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_Motousbnet_01007.Wdf [2012-12-01 18:01:37 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_motfilt_01007.Wdf [2012-12-01 18:01:22 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_motccgpfl_01007.Wdf [2012-12-01 18:01:22 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_motccgp_01007.Wdf [2012-12-01 18:01:15 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_motusbdevice_01007.Wdf [2012-11-30 20:28:55 | 000,000,709 | ---- | C] () -- C:\Documents and Settings\Gliwice\Desktop\TELEFONY SPRZEDANE TESCO GLIWICE GRUDZIEN 2012.lnk [2012-11-30 20:28:48 | 000,000,661 | ---- | C] () -- C:\Documents and Settings\Gliwice\Desktop\RAPORT TESCO GLIWICE GRUDZIEN 2012.lnk [2012-11-30 18:13:03 | 009,775,148 | ---- | C] () -- C:\Documents and Settings\Gliwice\My Documents\Projekt WiR - Intro.wav [2012-11-28 16:31:41 | 004,304,149 | ---- | C] () -- C:\WINDOWS\System32\FotoElita_ElitBook DESIGNER_uninstaller.exe [2012-11-20 18:51:26 | 000,012,019 | ---- | C] () -- C:\Documents and Settings\Gliwice\My Documents\NOC ZAKUPOW.odt [2012-11-09 19:18:50 | 000,208,004 | ---- | C] () -- C:\Documents and Settings\Gliwice\Desktop\lumia.pdf [2012-11-09 16:15:59 | 000,434,176 | ---- | C] () -- C:\WINDOWS\System32\ZSHP1018.EXE [2012-11-09 16:15:58 | 000,128,380 | ---- | C] () -- C:\WINDOWS\System32\hp1018.img [2012-11-09 16:15:58 | 000,010,886 | ---- | C] () -- C:\WINDOWS\System32\ZSHP1018.CHM [2012-10-05 08:20:43 | 000,022,152 | ---- | C] () -- C:\WINDOWS\System32\driver-flasher-3.5.exe [2012-07-16 11:45:29 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Gliwice\samsung_firmware_langpacks_descriptions_08_2010.pdf [2012-06-12 08:22:12 | 000,075,776 | ---- | C] () -- C:\WINDOWS\cadkasdeinst01e.exe [2012-05-07 18:39:20 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Gliwice\r8ba024_cxc1250669_generic_li [2012-05-07 18:30:25 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Gliwice\prgCXC1250669_GENERIC_LI_R8BA024.rest [2012-04-16 11:22:45 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\CommonDL.dll [2012-04-16 11:22:45 | 000,002,413 | ---- | C] () -- C:\WINDOWS\System32\lgAxconfig.ini [2012-04-05 11:39:00 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Gliwice\541711_374268792618390_187009258011012_1187646_1500184367_n.jpg [2012-03-28 12:55:34 | 000,015,872 | ---- | C] () -- C:\Documents and Settings\Gliwice\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-03-26 18:13:46 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Gliwice\Application Data\$_hpcst$.hpc [2012-03-20 16:14:22 | 000,343,424 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat [2012-03-20 12:13:47 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt [2012-03-20 12:12:55 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys [2012-03-19 21:00:23 | 000,088,064 | ---- | C] () -- C:\WINDOWS\System32\Bmp2Jpeg.dll [2012-03-19 20:20:39 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2012-03-19 20:16:12 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2012-03-19 12:09:34 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2012-03-19 12:08:29 | 000,141,240 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012-01-31 01:15:44 | 000,030,568 | ---- | C] () -- C:\WINDOWS\MusiccityDownload.exe [2012-01-31 01:15:42 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll [2012-01-31 01:15:42 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll [2012-01-31 01:15:42 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll [2012-01-31 01:15:42 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll [color=#E56717]========== ZeroAccess Check ==========[/color] [2012-03-20 20:04:23 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2008-04-14 04:42:06 | 001,499,136 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2008-04-14 04:41:54 | 000,472,064 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008-04-14 04:42:10 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both < End of report >