OTL logfile created on: 2013-11-07 12:48:55 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Adik1\Desktop 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 4,00 Gb Total Physical Memory | 2,31 Gb Available Physical Memory | 57,72% Memory free 8,00 Gb Paging File | 5,75 Gb Available in Paging File | 71,88% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 156,25 Gb Total Space | 134,03 Gb Free Space | 85,78% Space Free | Partition Type: NTFS Drive D: | 309,50 Gb Total Space | 245,74 Gb Free Space | 79,40% Space Free | Partition Type: NTFS Computer Name: ADIK1-KOMPUTER | User Name: Adik1 | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2013-11-07 11:48:29 | 000,306,688 | ---- | C] (InstallShield Software Corporation) -- C:\Windows\IsUninst.exe [2013-11-07 09:05:01 | 000,000,000 | ---D | C] -- C:\UsbFix [2013-11-07 09:04:36 | 001,380,744 | ---- | C] (El Desaparecido - SosVirus.net - UsbFix.net) -- C:\Users\Adik1\Desktop\UsbFix.exe [2013-11-06 10:52:17 | 000,000,000 | ---D | C] -- C:\FRST [2013-11-06 10:51:45 | 000,259,584 | ---- | C] (OldTimer Tools) -- C:\Users\Adik1\Desktop\OTH.com [2013-11-06 10:51:41 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Adik1\Desktop\OTL.com [2013-11-06 10:51:36 | 001,957,098 | ---- | C] (Farbar) -- C:\Users\Adik1\Desktop\FRST64.exe [2013-11-06 10:50:54 | 000,522,752 | ---- | C] (OldTimer Tools) -- C:\Users\Adik1\Desktop\TFC.exe [2013-11-05 14:24:48 | 000,000,000 | ---D | C] -- C:\Nowy folder [2013-11-05 13:28:31 | 000,000,000 | ---D | C] -- C:\Users\Adik1\AppData\Roaming\DAEMON Tools Lite [2013-11-05 13:27:53 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite [2013-11-05 11:05:45 | 000,000,000 | -H-D | C] -- C:\ProgramData\CanonIJScan [2013-11-05 11:02:57 | 000,000,000 | ---D | C] -- C:\Users\Adik1\AppData\Roaming\Canon [2013-11-05 10:49:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities [2013-11-05 10:49:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Canon [2013-11-05 10:48:08 | 000,000,000 | -H-D | C] -- C:\ProgramData\CanonBJ [2013-11-05 10:48:05 | 000,000,000 | -H-D | C] -- C:\Windows\SysNative\CanonIJ Uninstaller Information [2013-11-05 10:48:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP250 series [2013-11-05 10:48:02 | 001,321,984 | ---- | C] (CANON INC.) -- C:\Windows\SysNative\CNC250C.dll [2013-11-05 10:48:02 | 000,328,192 | ---- | C] (CANON INC.) -- C:\Windows\SysNative\CNC250L.dll [2013-11-05 10:48:02 | 000,303,104 | ---- | C] (CANON INC.) -- C:\Windows\SysWow64\CNC250L.dll [2013-11-05 10:48:02 | 000,106,496 | ---- | C] (CANON INC.) -- C:\Windows\SysWow64\CNC250U.dll [2013-11-05 10:48:02 | 000,092,672 | ---- | C] (CANON INC.) -- C:\Windows\SysNative\CNC250I.dll [2013-11-05 10:48:02 | 000,017,920 | ---- | C] (CANON INC.) -- C:\Windows\SysNative\CNHMCA6.dll [2013-11-05 10:48:02 | 000,015,872 | ---- | C] (CANON INC.) -- C:\Windows\SysWow64\CNHMCA.dll [2013-11-05 10:47:56 | 000,336,896 | ---- | C] (CANON INC.) -- C:\Windows\SysNative\CNMLM9W.DLL [2013-11-05 10:47:55 | 000,244,736 | ---- | C] (CANON INC.) -- C:\Windows\SysNative\CNMIU9W.DLL [2013-11-05 10:47:55 | 000,104,960 | ---- | C] (Canon Inc.) -- C:\Windows\SysNative\CNC250O.dll [2013-11-05 10:47:50 | 000,000,000 | -H-D | C] -- C:\Program Files\CanonBJ [2013-11-04 09:27:16 | 000,000,000 | ---D | C] -- C:\Users\Adik1\AppData\Local\ElevatedDiagnostics [2013-11-01 09:52:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp [2013-11-01 09:52:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Winamp Detect [2013-11-01 09:52:31 | 000,000,000 | ---D | C] -- C:\Users\Adik1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Detektor Winampa [2013-11-01 09:52:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine [2013-11-01 09:52:24 | 000,000,000 | ---D | C] -- C:\Users\Adik1\AppData\Roaming\Winamp [2013-11-01 09:52:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Winamp [2013-10-31 07:59:39 | 000,000,000 | ---D | C] -- C:\Users\Adik1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tesla Coil Designer [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2013-11-07 12:25:00 | 000,001,046 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013-11-07 11:53:47 | 001,523,412 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013-11-07 11:53:47 | 000,687,590 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat [2013-11-07 11:53:47 | 000,606,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013-11-07 11:53:47 | 000,131,176 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat [2013-11-07 11:53:47 | 000,103,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013-11-07 11:50:24 | 000,103,140 | RHS- | M] () -- C:\ouqqh.pif [2013-11-07 11:50:24 | 000,000,255 | RHS- | M] () -- C:\autorun.inf [2013-11-07 11:49:24 | 000,001,042 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013-11-07 11:49:18 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013-11-07 11:49:14 | 3220,037,632 | -HS- | M] () -- C:\hiberfil.sys [2013-11-07 09:04:55 | 001,380,744 | ---- | M] (El Desaparecido - SosVirus.net - UsbFix.net) -- C:\Users\Adik1\Desktop\UsbFix.exe [2013-11-06 10:52:06 | 000,960,816 | ---- | M] () -- C:\Users\Adik1\Desktop\SecurityCheck.exe [2013-11-06 10:51:56 | 000,259,584 | ---- | M] (OldTimer Tools) -- C:\Users\Adik1\Desktop\OTH.com [2013-11-06 10:51:53 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Adik1\Desktop\OTL.com [2013-11-06 10:51:52 | 001,957,098 | ---- | M] (Farbar) -- C:\Users\Adik1\Desktop\FRST64.exe [2013-11-06 10:50:58 | 000,522,752 | ---- | M] (OldTimer Tools) -- C:\Users\Adik1\Desktop\TFC.exe [2013-11-05 14:23:15 | 000,017,120 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013-11-05 14:23:15 | 000,017,120 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013-11-05 10:49:35 | 000,002,095 | ---- | M] () -- C:\Users\Public\Desktop\Canon MP Navigator EX 3.0.lnk [2013-11-01 09:52:51 | 000,000,979 | ---- | M] () -- C:\Users\Public\Desktop\Winamp.lnk [color=#E56717]========== Files Created - No Company Name ==========[/color] [2013-11-07 11:50:24 | 000,103,140 | RHS- | C] () -- C:\ouqqh.pif [2013-11-07 11:50:17 | 000,000,255 | RHS- | C] () -- C:\autorun.inf [2013-11-06 10:52:00 | 000,960,816 | ---- | C] () -- C:\Users\Adik1\Desktop\SecurityCheck.exe [2013-11-05 10:49:35 | 000,002,095 | ---- | C] () -- C:\Users\Public\Desktop\Canon MP Navigator EX 3.0.lnk [2013-11-05 10:48:02 | 000,012,288 | ---- | C] () -- C:\Windows\SysWow64\CNC173AD.TBL [2013-11-05 10:48:02 | 000,012,288 | ---- | C] () -- C:\Windows\SysNative\CNC173AD.TBL [2013-11-01 09:52:51 | 000,000,979 | ---- | C] () -- C:\Users\Public\Desktop\Winamp.lnk [2013-09-25 21:53:33 | 000,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll [2013-09-25 21:43:40 | 000,644,608 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll [2013-09-25 21:43:40 | 000,258,048 | ---- | C] () -- C:\Windows\SysWow64\libFLAC.dll [2013-09-25 15:31:32 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2012-07-04 06:34:16 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat [2012-07-04 06:34:16 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat [2012-04-18 18:39:10 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll [color=#E56717]========== ZeroAccess Check ==========[/color] [2009-07-14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2009-07-14 02:41:54 | 014,161,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2009-07-14 02:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009-07-14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== Custom Scans ==========[/color] [color=#A23BEC]< type C:\autorun.inf /C >[/color] [AutoRun] ;gUQPrvgAEbxibxFikKpfxjEeOLaI ; oPen=ouqqh.pif ;JOoXCcepabHrcpWuQYtoIj XWtQylgkGvyOkSqc ShELl\OPen\comMAnd=ouqqh.pif ;TtMlS shELl\exploRe\ComMANd= ouqqh.pif ;oKlljIjMpgrx DUeSk sHEll\OpeN\DEFAuLt=1 shell\AutopLay\cOMManD= ouqqh.pif [color=#A23BEC]< type C:\autorun.inf /C >[/color] [AutoRun] ;gUQPrvgAEbxibxFikKpfxjEeOLaI ; oPen=ouqqh.pif ;JOoXCcepabHrcpWuQYtoIj XWtQylgkGvyOkSqc ShELl\OPen\comMAnd=ouqqh.pif ;TtMlS shELl\exploRe\ComMANd= ouqqh.pif ;oKlljIjMpgrx DUeSk sHEll\OpeN\DEFAuLt=1 shell\AutopLay\cOMManD= ouqqh.pif < End of report >