OTL logfile created on: 2013-02-22 18:59:02 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Kozakiewicz\Pulpit Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 502,42 Mb Total Physical Memory | 131,36 Mb Available Physical Memory | 26,14% Memory free 1,20 Gb Paging File | 0,81 Gb Available in Paging File | 67,24% Paging File free Paging file location(s): C:\pagefile.sys 756 1512 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 55,88 Gb Total Space | 5,52 Gb Free Space | 9,87% Space Free | Partition Type: NTFS Computer Name: SATELLITE_A80 | User Name: Kozakiewicz | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2013-02-03 15:25:27 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kozakiewicz\Pulpit\OTL.exe PRC - [2013-01-24 20:33:09 | 000,057,344 | ---- | M] () -- c:\Documents and Settings\Kozakiewicz\Ustawienia lokalne\temp\DAT1318.tmp.exe PRC - [2012-06-26 19:15:26 | 000,180,552 | ---- | M] (Solid Documents, LLC) -- C:\WINDOWS\Installer\MSI1A7E.tmp PRC - [2011-07-16 11:56:22 | 000,024,992 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\AllShare\AllShareDMS\AllShareDMS.exe PRC - [2011-07-16 11:52:16 | 000,282,512 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\AllShare\AllShareAgent.exe PRC - [2009-05-17 10:38:02 | 001,794,320 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\cfp.exe PRC - [2009-05-17 10:37:32 | 000,692,496 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe PRC - [2009-03-19 10:44:50 | 000,731,840 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe PRC - [2009-03-19 10:44:28 | 002,029,640 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe PRC - [2008-04-14 18:21:16 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007-11-06 07:37:56 | 000,734,472 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\RAXCO\PerfectDisk\PDEngine.exe PRC - [2007-11-06 07:37:48 | 000,414,984 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\RAXCO\PerfectDisk\PDAgent.exe PRC - [2005-01-14 13:40:08 | 000,024,576 | ---- | M] (TOSHIBA) -- C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe PRC - [2005-01-03 17:37:36 | 000,028,672 | ---- | M] (TOSHIBA) -- C:\WINDOWS\system32\TCtrlIOHook.exe PRC - [2004-12-17 15:29:44 | 000,266,240 | ---- | M] (TOSHIBA Corporation) -- C:\WINDOWS\system32\TPSMain.exe PRC - [2004-12-17 15:29:30 | 000,040,960 | ---- | M] (TOSHIBA Corporation) -- C:\WINDOWS\system32\TPSBattM.exe PRC - [2004-11-29 21:06:26 | 000,053,248 | ---- | M] (COMPAL ELECTRONIC INC.) -- C:\Program Files\TOSHIBA\TouchPad\TPTray.exe PRC - [2004-11-29 09:12:12 | 000,114,688 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe PRC - [2004-11-29 09:10:22 | 000,667,648 | ---- | M] (COMPAL ELECTRONIC INC.) -- C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe PRC - [2004-11-12 21:54:56 | 000,929,792 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe PRC - [2004-11-12 17:57:12 | 000,073,728 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\Tvs\TvsTray.exe PRC - [2004-11-10 11:14:08 | 000,036,864 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe PRC - [2004-07-14 16:07:32 | 000,024,576 | ---- | M] (TOSHIBA) -- C:\WINDOWS\system32\ZoomingHook.exe PRC - [2003-09-15 16:52:04 | 000,065,536 | ---- | M] (TOSHIBA) -- C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe PRC - [2003-04-02 03:20:37 | 000,012,288 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2013-01-24 20:33:09 | 000,057,344 | ---- | M] () -- c:\Documents and Settings\Kozakiewicz\Ustawienia lokalne\temp\DAT1318.tmp.exe MOD - [2013-01-24 20:33:01 | 000,061,440 | ---- | M] () -- C:\WINDOWS\Installer\{A9A1DCF2-B263-0A66-5B7C-844D3B4A108B}\syshost.exe MOD - [2013-01-14 18:10:51 | 000,400,896 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\38d7801308f456f03608b4355bf78961\System.Xml.Linq.ni.dll MOD - [2013-01-14 18:09:33 | 000,212,992 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\f43e890d874ef521aba51f76f64cd97b\System.ServiceProcess.ni.dll MOD - [2013-01-14 18:07:07 | 000,971,264 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\96b7a0136e9e72e8f4eb0230c20766d2\System.Configuration.ni.dll MOD - [2013-01-14 17:55:19 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\fe025743210c22bea2f009e1612c38bf\System.Xml.ni.dll MOD - [2013-01-14 17:54:55 | 012,433,920 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\4c91371e83d124ecb39664613e7e0417\System.Windows.Forms.ni.dll MOD - [2013-01-14 17:54:29 | 001,593,856 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\7782f356a838c403b4a8e9c80df5a577\System.Drawing.ni.dll MOD - [2013-01-14 17:53:38 | 002,295,296 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Core\edbf4e4a55e63b9fbf0b0b40cba13063\System.Core.ni.dll MOD - [2013-01-14 17:52:19 | 012,218,368 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationCore\2e26794770e6d33cf79a7f8daa4a48c3\PresentationCore.ni.dll MOD - [2013-01-14 17:51:49 | 003,325,440 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\4b889e41364baff1e456817b4777b610\WindowsBase.ni.dll MOD - [2013-01-14 17:51:21 | 007,977,984 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\aeac298c43c77d8860db8e7634d9f2eb\System.ni.dll MOD - [2013-01-14 17:50:38 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\eab2340ead8e1a84bdf1a87868659979\mscorlib.ni.dll MOD - [2013-01-14 17:45:45 | 000,303,104 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll MOD - [2011-10-21 01:21:46 | 000,027,976 | ---- | M] () -- C:\WINDOWS\system32\solidlocalmon.dll MOD - [2011-07-13 15:43:50 | 001,102,848 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\AllShareDMSWrap.dll MOD - [2011-07-13 15:43:50 | 000,641,536 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\ContentDirectoryPresenter.dll MOD - [2011-07-13 15:43:50 | 000,289,792 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\libThumbnail.dll MOD - [2011-07-13 15:43:50 | 000,289,792 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\libKeyFrame.dll MOD - [2011-07-13 15:43:50 | 000,132,608 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\VideoMetadataDriver.dll MOD - [2011-07-13 15:43:50 | 000,105,472 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\DCMCDP.dll MOD - [2011-07-13 15:43:50 | 000,093,696 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\FolderCDP.dll MOD - [2011-07-13 15:43:50 | 000,077,312 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\MetadataFramework.dll MOD - [2011-07-13 15:43:50 | 000,063,488 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\ID3Driver.dll MOD - [2011-07-13 15:43:50 | 000,054,784 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\RosettaAllShare.dll MOD - [2011-07-13 15:43:50 | 000,031,232 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\Autobackup.dll MOD - [2011-07-13 15:43:50 | 000,028,672 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\AutoChaptering.dll MOD - [2011-07-13 15:43:50 | 000,028,160 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\AudioExtractor.dll MOD - [2011-07-13 15:43:50 | 000,024,064 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\SECMetaDriver.dll MOD - [2011-07-13 15:43:50 | 000,023,040 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\photoDriver.dll MOD - [2011-07-13 15:43:50 | 000,022,528 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\RichInfoDriver.dll MOD - [2011-07-13 15:43:50 | 000,018,432 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\VideoExtractor.dll MOD - [2011-07-13 15:43:50 | 000,017,920 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\ThumbnailMaker.dll MOD - [2011-07-13 15:43:50 | 000,013,824 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\TextExtractor.dll MOD - [2011-07-13 15:43:50 | 000,012,800 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\VideoThumb.dll MOD - [2011-07-13 15:43:50 | 000,012,288 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\ImageExtractor.dll MOD - [2011-02-01 12:01:10 | 000,044,032 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\us.dll MOD - [2010-12-16 13:09:50 | 005,717,504 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\DCMImgExtractor.dll MOD - [2010-12-16 13:09:48 | 000,366,592 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\tag.dll MOD - [2010-12-15 14:13:18 | 000,399,826 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\libexif-12.dll.dll MOD - [2010-12-15 14:13:16 | 000,686,080 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\avformat-52.dll MOD - [2010-12-15 14:13:16 | 000,520,234 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\sqlite3.dll MOD - [2010-12-15 14:13:16 | 000,450,560 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\MoodExtractor.dll MOD - [2010-12-15 14:13:16 | 000,152,064 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\swscale-0.dll MOD - [2010-12-15 14:13:16 | 000,147,456 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\libexpat.dll MOD - [2010-12-15 14:13:16 | 000,070,656 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\avutil-50.dll MOD - [2010-12-15 14:13:14 | 004,671,488 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\avcodec-52.dll MOD - [2010-01-21 01:34:10 | 008,793,952 | ---- | M] () -- C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll MOD - [2010-01-09 20:18:18 | 004,254,560 | ---- | M] () -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF MOD - [2009-05-17 10:40:22 | 000,295,184 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\scanners\pkann.dll MOD - [2009-05-17 10:40:22 | 000,094,480 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\scanners\mem.cav MOD - [2009-05-17 10:40:20 | 001,028,368 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\scanners\mach32.dll MOD - [2009-05-17 10:40:16 | 000,364,816 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\scanners\gunpack.cav MOD - [2009-05-17 10:40:14 | 000,097,552 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\scanners\heur.cav MOD - [2009-05-17 10:40:14 | 000,015,120 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\scanners\white.cav MOD - [2009-05-17 10:40:01 | 000,237,840 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\scanners\unarch.cav MOD - [2009-05-17 10:40:00 | 000,561,424 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\scanners\unpack.cav MOD - [2009-05-17 10:39:57 | 000,284,944 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\Themes\cfp.theme MOD - [2009-05-17 10:39:38 | 000,016,656 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\scanners\common.cav MOD - [2009-05-17 10:39:38 | 000,016,144 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\scanners\first.cav MOD - [2009-05-17 10:39:38 | 000,010,000 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\scanners\pe32.cav MOD - [2009-05-17 10:39:37 | 000,270,608 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\framework.dll MOD - [2009-05-17 10:39:37 | 000,008,976 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\scanners\dosmz.cav MOD - [2009-05-17 10:38:02 | 001,794,320 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\cfp.exe MOD - [2009-05-17 10:37:32 | 000,692,496 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe MOD - [2007-11-06 07:38:10 | 000,365,832 | ---- | M] () -- C:\Program Files\RAXCO\PerfectDisk\sqlite3.dll MOD - [2007-11-06 07:37:54 | 000,075,016 | ---- | M] () -- C:\Program Files\RAXCO\PerfectDisk\PDDb.dll MOD - [2004-12-29 15:09:52 | 000,077,824 | ---- | M] () -- C:\WINDOWS\system32\TPeculiarity.dll MOD - [2004-12-14 07:45:36 | 000,057,344 | ---- | M] () -- C:\Program Files\TOSHIBA\TouchPad\TPECioctl.dll MOD - [2004-12-14 07:40:16 | 000,057,344 | ---- | M] () -- C:\WINDOWS\system32\EKECioCtl.dll MOD - [2004-07-21 09:04:02 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\TosBtHcrpAPI.dll MOD - [2003-04-02 03:20:37 | 000,012,288 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt) SRV - [2013-01-24 20:33:09 | 000,057,344 | ---- | M] () [Auto | Stopped] -- C:\Documents and Settings\Kozakiewicz\Ustawienia lokalne\temp\DAT1318.tmp.exe -- (jmsmxofeftaqfvj) SRV - [2013-01-24 20:33:01 | 000,061,440 | ---- | M] () [Auto | Running] -- C:\WINDOWS\Installer\{A9A1DCF2-B263-0A66-5B7C-844D3B4A108B}\syshost.exe -- (syshost32) SRV - [2012-06-26 19:15:26 | 000,180,552 | ---- | M] (Solid Documents, LLC) [Auto | Running] -- C:\WINDOWS\Installer\MSI1A7E.tmp -- (SCPDFReadSpool) SRV - [2011-07-16 11:56:22 | 000,024,992 | ---- | M] (Samsung Electronics Co., Ltd.) [Auto | Running] -- C:\Program Files\Samsung\AllShare\AllShareDMS\AllShareDMS.exe -- (SamsungAllShareV2.0) SRV - [2011-07-16 11:56:18 | 000,027,584 | ---- | M] (Samsung Electronics Co., Ltd.) [On_Demand | Stopped] -- C:\Program Files\Samsung\AllShare\AllShareSlideShowService.exe -- (SimpleSlideShowServer) SRV - [2010-03-09 13:46:56 | 001,029,456 | ---- | M] (Lavasoft) [On_Demand | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service) SRV - [2010-01-21 17:51:12 | 030,963,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service) SRV - [2009-05-17 10:37:32 | 000,692,496 | ---- | M] () [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent) SRV - [2009-03-19 10:48:08 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv) SRV - [2009-03-19 10:44:50 | 000,731,840 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn) SRV - [2007-11-06 07:37:56 | 000,734,472 | ---- | M] (Raxco Software, Inc.) [On_Demand | Running] -- C:\Program Files\RAXCO\PerfectDisk\PDEngine.exe -- (PDEngine) SRV - [2007-11-06 07:37:48 | 000,414,984 | ---- | M] (Raxco Software, Inc.) [Auto | Running] -- C:\Program Files\RAXCO\PerfectDisk\PDAgent.exe -- (PDAgent) SRV - [2004-11-10 11:14:08 | 000,036,864 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -- (CFSvcs) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\VBoxNetFlt.sys -- (VBoxNetFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tifm21.sys -- (tifm21) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- system32\drivers\InCDRm.sys -- (InCDRm) DRV - File not found [Kernel | System | Stopped] -- system32\drivers\InCDPass.sys -- (InCDPass) DRV - File not found [File_System | Disabled | Stopped] -- system32\drivers\InCDFs.sys -- (InCDFs) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\KOZAKI~1\USTAWI~1\Temp\catchme.sys -- (catchme) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\aksusb.sys -- (aksusb) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\akshhl.sys -- (akshhl) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\akshasp.sys -- (akshasp) DRV - [2009-05-17 10:39:14 | 000,082,080 | ---- | M] (COMODO) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\drivers\inspect.sys -- (Inspect) DRV - [2009-05-17 10:39:14 | 000,024,096 | ---- | M] (COMODO) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\cmdhlp.sys -- (cmdHlp) DRV - [2009-05-17 10:39:12 | 000,132,640 | ---- | M] (COMODO) [File_System | System | Stopped] -- C:\WINDOWS\system32\drivers\cmdguard.sys -- (cmdGuard) DRV - [2009-05-05 12:46:20 | 000,064,160 | ---- | M] (Lavasoft AB) [File_System | Boot | Stopped] -- C:\WINDOWS\system32\drivers\Lbd.sys -- (Lbd) DRV - [2009-03-19 10:45:38 | 000,093,848 | ---- | M] (ESET) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir) DRV - [2009-03-19 10:44:34 | 000,107,256 | ---- | M] (ESET) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv) DRV - [2009-03-19 10:41:38 | 000,113,960 | ---- | M] (ESET) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon) DRV - [2008-12-16 19:47:03 | 000,025,280 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi) DRV - [2008-02-20 10:47:14 | 000,017,408 | ---- | M] (Xilinx, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\xusb_emb.sys -- (XilinxFirmwareEmbeddedLpLoader) DRV - [2008-02-20 10:47:12 | 000,194,362 | ---- | M] (Jungo) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\windrvr6.sys -- (WinDriver6) DRV - [2008-01-09 05:19:16 | 002,216,064 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51) DRV - [2007-10-22 04:33:40 | 000,068,624 | ---- | M] (Raxco Software, Inc.) [File_System | Boot | Running] -- C:\WINDOWS\System32\drivers\DefragFs.sys -- (DefragFS) DRV - [2004-12-22 16:45:36 | 000,393,600 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211) DRV - [2004-12-14 02:29:28 | 000,016,128 | ---- | M] (TOSHIBA ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\TPwSav.sys -- (TPwSav) DRV - [2004-12-11 14:12:00 | 000,006,144 | ---- | M] (TOSHIBA ) [Kernel | System | Running] -- C:\Program Files\TOSHIBA\Windows Utilities\spDispatch.sys -- (SPCtl) DRV - [2004-12-11 14:12:00 | 000,006,144 | ---- | M] () [Kernel | System | Running] -- C:\Program Files\TOSHIBA\TOSHIBA Applet\HWS_IoDispatch.sys -- (HWSCtrl) DRV - [2004-12-11 02:52:14 | 000,006,144 | ---- | M] (TOSHIBA ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\TCtrlIO.sys -- (TCtrlIO) DRV - [2004-12-10 14:00:44 | 000,006,144 | ---- | M] (TOSHIBA) [Kernel | System | Running] -- C:\Program Files\TOSHIBA\Accessibility\StickyMesger.sys -- (StickyMesger) DRV - [2004-12-10 13:49:18 | 000,006,144 | ---- | M] (TOAHIBA, ) [Kernel | System | Running] -- C:\Program Files\TOSHIBA\TouchPad\TPECioCtl.sys -- (TPECioCtl) DRV - [2004-12-10 08:29:50 | 000,006,144 | ---- | M] (TOAHIBA, ) [Kernel | System | Running] -- C:\Program Files\TOSHIBA\E-KEY\EKECioCtl.sys -- (EKECioCtl) DRV - [2004-11-26 13:04:38 | 000,029,056 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Tvs.sys -- (Tvs) DRV - [2004-11-26 07:29:00 | 000,224,000 | R--- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp) DRV - [2004-11-15 16:22:08 | 000,101,874 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService) DRV - [2004-10-28 14:37:50 | 001,270,572 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem) DRV - [2004-10-27 13:57:38 | 002,284,864 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) DRV - [2004-07-30 15:05:04 | 000,006,400 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\EPIOMngr.sys -- (SerTVOutCtlr) DRV - [2004-07-29 23:05:08 | 000,006,400 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | System | Running] -- C:\Program Files\TOSHIBA\E-KEY\SSIOMngr.sys -- (SrvcSSIOMngr) DRV - [2004-07-29 23:05:04 | 000,006,400 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | System | Running] -- C:\Program Files\TOSHIBA\E-KEY\EKIOMngr.sys -- (SrvcEKIOMngr) DRV - [2004-06-16 11:19:58 | 000,046,080 | ---- | M] (SMSC) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\smcirda.sys -- (SMCIRDA) DRV - [2004-05-18 07:18:26 | 000,008,573 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Tosrfec.sys -- (tosrfec) DRV - [2003-12-27 20:42:12 | 000,137,216 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\d344bus.sys -- (d344bus) DRV - [2003-12-27 02:38:10 | 000,005,248 | ---- | M] ( ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\d344prt.sys -- (d344prt) DRV - [2003-01-29 14:35:00 | 000,012,032 | ---- | M] (TOSHIBA Corporation.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Netdevio.sys -- (Netdevio) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wyborcza.pl/ IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3859823971-3261552694-948437020-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.wyborcza.pl/ IE - HKU\S-1-5-21-3859823971-3261552694-948437020-1006\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-3859823971-3261552694-948437020-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "www.wp.pl" FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@idsoftware.com/QuakeLive: C:\Documents and Settings\All Users\Dane aplikacji\id Software\QuakeLive\npquakezero.dll (id Software Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-06-21 19:44:31 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013-02-16 15:58:57 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2009-05-06 08:01:37 | 000,000,000 | ---D | M] [2008-12-16 21:31:39 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\Mozilla\Extensions [2013-02-03 15:22:37 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\Mozilla\Firefox\Profiles\g473oue5.default\extensions [2009-10-16 20:29:27 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\Mozilla\Firefox\Profiles\g473oue5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2013-02-03 15:22:37 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2011-01-26 20:20:50 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} [2011-01-26 20:20:17 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2011-01-26 20:20:14 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2010-04-03 17:09:01 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2010-04-03 17:09:01 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2010-04-03 17:09:02 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2010-04-03 17:09:02 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2010-04-03 17:09:02 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2010-04-03 17:09:02 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2009-05-06 07:05:23 | 000,000,023 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) O3 - HKU\S-1-5-21-3859823971-3261552694-948437020-1006\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found. O3 - HKU\S-1-5-21-3859823971-3261552694-948437020-1006\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found. O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft) O4 - HKLM..\Run: [AllShareAgent] C:\Program Files\Samsung\AllShare\AllShareAgent.exe (Samsung Electronics Co., Ltd.) O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation) O4 - HKLM..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe (COMPAL ELECTRONIC INC.) O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe () O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET) O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe (TOSHIBA CO.,LTD.) O4 - HKLM..\Run: [NDSTray.exe] NDSTray.exe File not found O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe (TOSHIBA) O4 - HKLM..\Run: [TCtryIOHook] C:\WINDOWS\System32\TCtrlIOHook.exe (TOSHIBA) O4 - HKLM..\Run: [TFncKy] TFncKy.exe File not found O4 - HKLM..\Run: [TOSHIBA Accessibility] C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe (TOSHIBA) O4 - HKLM..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe (COMPAL ELECTRONIC INC.) O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation) O4 - HKLM..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe (TOSHIBA Corporation) O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\Winampa.exe () O4 - HKLM..\Run: [Zooming] C:\WINDOWS\System32\ZoomingHook.exe (TOSHIBA) O4 - HKU\S-1-5-21-3859823971-3261552694-948437020-1006..\Run: [AML] C:\Documents and Settings\All Users\Dane aplikacji\c0a378\AMc0a_2121.exe () O4 - HKU\S-1-5-21-3859823971-3261552694-948437020-1006..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-3859823971-3261552694-948437020-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-3859823971-3261552694-948437020-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-21-3859823971-3261552694-948437020-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-21-3859823971-3261552694-948437020-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra Button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe () O9 - Extra 'Tools' menuitem : PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - C:\Program Files\PPLive\PPLive.exe () O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1230112000937 (WUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Java Plug-in 1.5.0) O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\WINDOWS\TOSHIBA Satellite 1024x768.bmp O24 - Desktop BackupWallPaper: C:\WINDOWS\TOSHIBA Satellite 1024x768.bmp O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2005-01-17 13:36:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{3610698d-a9e5-11de-aec5-000e35de9b65}\Shell - "" = AutoRun O33 - MountPoints2\{3610698d-a9e5-11de-aec5-000e35de9b65}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a O33 - MountPoints2\{e62aa5d9-cb86-11dd-ad3d-000e35de9b65}\Shell - "" = AutoRun O33 - MountPoints2\{e62aa5d9-cb86-11dd-ad3d-000e35de9b65}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a O34 - HKLM BootExecute: (PDBoot.exe) O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (lsdelete) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2013-02-16 20:05:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kozakiewicz\Moje dokumenty\Outlook Files [2013-02-16 16:11:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\SharePoint [2013-02-16 16:11:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Microsoft Office [2013-02-16 16:09:40 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER [2013-02-16 16:03:51 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Synchronization Services [2013-02-16 16:03:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW [2013-02-16 16:01:25 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET [2013-02-16 16:01:25 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Sync Framework [2013-02-16 16:01:25 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition [2013-02-16 16:01:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Microsoft [2013-02-16 15:52:14 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Analysis Services [2013-02-03 15:37:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kozakiewicz\Pulpit\Nowy folder [2013-02-03 15:25:26 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Kozakiewicz\Pulpit\OTL.exe [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2013-02-22 18:54:09 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2013-02-19 17:53:02 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2013-02-16 20:05:22 | 000,503,930 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2013-02-16 20:05:22 | 000,444,848 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2013-02-16 20:05:22 | 000,090,366 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2013-02-16 20:05:22 | 000,072,724 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2013-02-16 16:32:35 | 000,286,112 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2013-02-13 20:27:25 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn [2013-02-03 15:25:27 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kozakiewicz\Pulpit\OTL.exe [2013-01-27 13:37:54 | 000,114,203 | ---- | M] () -- C:\WINDOWS\System32\drivers\qstr.sys [2013-01-24 20:34:05 | 000,059,776 | ---- | M] () -- C:\WINDOWS\System32\drivers\328283668ce358b1.sys [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2013-01-27 22:12:18 | 000,250,736 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat [2013-01-24 20:34:05 | 000,059,776 | ---- | C] () -- C:\WINDOWS\System32\drivers\328283668ce358b1.sys [2013-01-24 20:33:18 | 000,114,203 | ---- | C] () -- C:\WINDOWS\System32\drivers\qstr.sys [2012-11-08 18:23:51 | 004,436,797 | ---- | C] () -- C:\WINDOWS\System32\Empik_Empikfotobook_uninstaller.exe [2012-06-26 19:15:34 | 000,027,976 | ---- | C] () -- C:\WINDOWS\System32\solidlocalmon.dll [2012-06-26 19:15:34 | 000,019,272 | ---- | C] () -- C:\WINDOWS\System32\solidlocalui.dll [2012-06-18 22:09:19 | 000,339,968 | ---- | C] () -- C:\WINDOWS\System32\pythoncom25.dll [2012-06-18 22:09:19 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\pywintypes25.dll [2012-02-16 17:21:30 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2011-12-15 20:48:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI [2009-06-05 18:24:06 | 000,107,832 | ---- | C] () -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\PnkBstrB.exe [2009-05-07 13:48:31 | 000,003,808 | ---- | C] () -- C:\Documents and Settings\Kozakiewicz\.recently-used.xbel [2009-01-25 13:55:04 | 000,000,066 | ---- | C] () -- C:\Documents and Settings\Kozakiewicz\.gtk-bookmarks [2008-12-25 20:46:29 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\Kozakiewicz\Ustawienia lokalne\Dane aplikacji\fusioncache.dat [2008-12-16 18:24:23 | 000,080,384 | ---- | C] () -- C:\Documents and Settings\Kozakiewicz\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [color=#E56717]========== ZeroAccess Check ==========[/color] [2005-01-17 13:43:44 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2008-10-16 02:02:54 | 001,499,136 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009-02-09 11:53:44 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008-04-14 18:20:57 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2011-07-11 20:27:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\c0a378 [2009-05-11 07:56:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\DassaultSystemes [2009-05-06 08:01:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ESET [2012-03-08 21:56:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\id Software [2009-05-05 19:40:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Jlcm [2012-11-08 18:27:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\M-Photo [2009-11-02 18:04:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Mistrz Klawiatury 2009 Data [2009-05-05 19:42:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PPLive [2009-05-05 20:03:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PPLiveVA [2012-06-26 19:14:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\SolidDocuments [2012-11-25 16:01:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\tmp [2009-05-05 12:43:10 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} [2005-01-18 09:48:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Dane aplikacji\toshiba [2011-04-17 18:07:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\AIMP [2009-04-09 18:43:19 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\CrystalSpace [2009-05-11 07:56:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\DassaultSystemes [2012-06-13 15:58:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\Dev-Cpp [2012-02-07 18:33:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\e-pity [2008-12-16 19:45:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\Gadu-Gadu [2009-05-07 13:48:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\gtk-2.0 [2009-06-05 18:25:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\id Software [2011-12-04 12:46:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\InterVideo [2009-03-12 12:59:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\Nokia [2008-12-16 19:35:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\Notepad++ [2011-04-14 18:44:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\Opera [2009-05-05 19:46:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\PPLive [2009-05-05 19:43:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\PPLiveVA [2012-02-15 20:12:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\Samsung [2012-06-26 19:18:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\SolidDocuments [2009-05-19 21:54:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\Tlen.pl [2010-10-20 20:34:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\toshiba [2010-06-30 16:32:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\uTorrent [2009-01-13 16:24:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kozakiewicz\Dane aplikacji\Xilinx [2012-02-15 18:32:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\Samsung [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Files - Unicode (All) ==========[/color] [2008-12-16 17:31:02 | 000,873,363 | ---- | C] ()(C:\Documents and Settings\Kozakiewicz\Moje dokumenty\METODY KONSTRUOWANIA I ANALIZOWANIA ALGORYTM?.pdf) -- C:\Documents and Settings\Kozakiewicz\Moje dokumenty\METODY KONSTRUOWANIA I ANALIZOWANIA ALGORYTMӅ.pdf [2007-11-08 00:17:03 | 000,873,363 | ---- | M] ()(C:\Documents and Settings\Kozakiewicz\Moje dokumenty\METODY KONSTRUOWANIA I ANALIZOWANIA ALGORYTM?.pdf) -- C:\Documents and Settings\Kozakiewicz\Moje dokumenty\METODY KONSTRUOWANIA I ANALIZOWANIA ALGORYTMӅ.pdf < End of report >