OTL logfile created on: 2014-12-18 13:04:23 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = D:\Narzedzia\OTL Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,00 Gb Total Physical Memory | 2,27 Gb Available Physical Memory | 75,85% Memory free 4,35 Gb Paging File | 3,80 Gb Available in Paging File | 87,47% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 14,65 Gb Total Space | 3,71 Gb Free Space | 25,32% Space Free | Partition Type: NTFS Drive D: | 59,87 Gb Total Space | 2,87 Gb Free Space | 4,79% Space Free | Partition Type: NTFS Computer Name: GS | User Name: Greg | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2014-12-18 13:02:17 | 000,602,112 | ---- | M] (OldTimer Tools) -- D:\Narzedzia\OTL\OTL.exe PRC - [2014-07-31 16:37:46 | 004,085,896 | ---- | M] (AVAST Software) -- D:\Programy\AVAST Software\avastui.exe PRC - [2014-05-17 18:54:11 | 000,879,456 | ---- | M] (Opera Software) -- D:\Programy\Opera\opera.exe PRC - [2008-04-14 18:21:16 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2014-11-26 17:54:12 | 016,841,392 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_239.dll MOD - [2014-07-07 20:22:35 | 019,329,904 | ---- | M] () -- D:\Programy\AVAST Software\libcef.dll MOD - [2014-07-07 20:22:33 | 000,301,152 | ---- | M] () -- D:\Programy\AVAST Software\aswProperty.dll MOD - [2014-05-17 18:54:20 | 000,312,832 | ---- | M] () -- D:\Programy\Opera\gstreamer\plugins\gstoggdec.dll MOD - [2014-05-17 18:54:20 | 000,158,208 | ---- | M] () -- D:\Programy\Opera\gstreamer\plugins\gstffmpegcolorspace.dll MOD - [2014-05-17 18:54:20 | 000,101,888 | ---- | M] () -- D:\Programy\Opera\gstreamer\plugins\gstwebmdec.dll MOD - [2014-05-17 18:54:20 | 000,096,256 | ---- | M] () -- D:\Programy\Opera\gstreamer\plugins\gstcoreplugins.dll MOD - [2014-05-17 18:54:20 | 000,073,728 | ---- | M] () -- D:\Programy\Opera\gstreamer\plugins\gstwavparse.dll MOD - [2014-05-17 18:54:20 | 000,067,072 | ---- | M] () -- D:\Programy\Opera\gstreamer\plugins\gstdirectsound.dll MOD - [2014-05-17 18:54:20 | 000,062,976 | ---- | M] () -- D:\Programy\Opera\gstreamer\plugins\gstdecodebin2.dll MOD - [2014-05-17 18:54:20 | 000,057,344 | ---- | M] () -- D:\Programy\Opera\gstreamer\plugins\gstautodetect.dll MOD - [2014-05-17 18:54:20 | 000,038,912 | ---- | M] () -- D:\Programy\Opera\gstreamer\plugins\gstwaveform.dll MOD - [2014-05-17 18:54:19 | 000,835,584 | ---- | M] () -- D:\Programy\Opera\gstreamer\gstreamer.dll MOD - [2014-05-17 18:54:19 | 000,094,208 | ---- | M] () -- D:\Programy\Opera\gstreamer\plugins\gstaudioresample.dll MOD - [2014-05-17 18:54:19 | 000,093,696 | ---- | M] () -- D:\Programy\Opera\gstreamer\plugins\gstaudioconvert.dll MOD - [2010-03-09 03:55:56 | 000,010,752 | ---- | M] () -- D:\Programy\Unlocker\UnlockerCOM.dll MOD - [2008-04-14 18:20:37 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll MOD - [2002-05-26 22:44:50 | 000,122,880 | ---- | M] () -- D:\Programy\WinRar\RarExt.dll MOD - [1998-03-10 10:07:18 | 000,902,656 | ---- | M] () -- D:\Programy\Corel\Programs\CMFFld80.dll MOD - [1997-08-08 20:20:34 | 000,121,344 | ---- | M] () -- D:\Corel\Versions\vers232.dll MOD - [1997-08-08 20:20:32 | 000,017,920 | ---- | M] () -- D:\Corel\Versions\implode.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ) SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Google\Update\GoogleUpdate.exe /medsvc -- (gupdatem) SRV - [2014-11-30 14:17:48 | 000,068,608 | ---- | M] (globalUpdate) [On_Demand | Stopped] -- C:\Program Files\globalUpdate\Update\GoogleUpdate.exe -- (globalUpdatem) SRV - [2014-11-30 14:17:48 | 000,068,608 | ---- | M] (globalUpdate) [Auto | Stopped] -- C:\Program Files\globalUpdate\Update\GoogleUpdate.exe -- (globalUpdate) SRV - [2014-11-26 17:54:13 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2014-08-18 10:25:39 | 000,182,696 | ---- | M] (Oracle Corporation) [On_Demand | Stopped] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService) SRV - [2014-07-07 20:22:32 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Stopped] -- D:\Programy\AVAST Software\AvastSvc.exe -- (avast! Antivirus) SRV - [2013-10-23 08:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012-11-30 14:53:58 | 000,088,696 | ---- | M] (VIA Technologies, Inc.) [Auto | Stopped] -- C:\WINDOWS\system32\KaraokeSer.exe -- (KaraokeService) SRV - [2012-01-25 17:40:56 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2010-05-20 14:27:24 | 000,139,632 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc) SRV - [2009-10-27 09:26:36 | 000,657,408 | ---- | M] (Nokia) [Disabled | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) SRV - [2006-12-19 18:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Stopped] -- C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe -- (EpsonBidirectionalService) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\Greg.GS\USTAWI~1\Temp\catchme.sys -- (catchme) DRV - [2014-12-09 11:56:18 | 000,055,824 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{2f6db162-50b5-48ec-8bd0-c6ac5074038f}t.sys -- ({2f6db162-50b5-48ec-8bd0-c6ac5074038f}t) DRV - [2014-12-06 18:53:04 | 000,055,824 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{1dc3c8ee-7a5c-414f-bf32-ae563ad31ed1}t.sys -- ({1dc3c8ee-7a5c-414f-bf32-ae563ad31ed1}t) DRV - [2014-12-03 08:35:08 | 000,055,824 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{9794b31c-7078-45aa-8534-9fee5d10dfe6}t.sys -- ({9794b31c-7078-45aa-8534-9fee5d10dfe6}t) DRV - [2014-11-30 15:33:08 | 000,055,824 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{6610c2c8-50f9-4a6a-b791-c2b9e2bdc00d}t.sys -- ({6610c2c8-50f9-4a6a-b791-c2b9e2bdc00d}t) DRV - [2014-11-30 02:34:24 | 000,055,824 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{b8202deb-d90b-4859-9db1-238d59fbcdd4}t.sys -- ({b8202deb-d90b-4859-9db1-238d59fbcdd4}t) DRV - [2014-11-21 20:41:20 | 000,779,536 | ---- | M] (AVAST Software) [File_System | System | Stopped] -- C:\WINDOWS\system32\drivers\aswsnx.sys -- (aswSnx) DRV - [2014-10-24 01:33:24 | 000,055,824 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{6cfec6a5-9d93-4492-985a-470a68eff4e9}t.sys -- ({6cfec6a5-9d93-4492-985a-470a68eff4e9}t) DRV - [2014-10-22 00:29:12 | 000,055,824 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{2429c312-24d3-4127-94ed-c247fe9e02fc}t.sys -- ({2429c312-24d3-4127-94ed-c247fe9e02fc}t) DRV - [2014-10-21 04:01:52 | 000,055,824 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{f8280ede-2ab0-420d-ae0f-169ba406978b}t.sys -- ({f8280ede-2ab0-420d-ae0f-169ba406978b}t) DRV - [2014-10-20 07:17:00 | 000,055,824 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{2ac9eb83-636e-4a51-ab66-bf4f388a02ab}t.sys -- ({2ac9eb83-636e-4a51-ab66-bf4f388a02ab}t) DRV - [2014-10-18 06:00:40 | 000,055,824 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{9390ab08-5703-448b-94f8-b8b1934c8841}t.sys -- ({9390ab08-5703-448b-94f8-b8b1934c8841}t) DRV - [2014-10-17 09:03:28 | 000,055,824 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{18fa7aee-6838-42dd-8d32-3fd665a7e664}t.sys -- ({18fa7aee-6838-42dd-8d32-3fd665a7e664}t) DRV - [2014-10-17 01:59:26 | 000,055,824 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{fff2d2b4-0f90-4edd-a75a-047e2658236a}t.sys -- ({fff2d2b4-0f90-4edd-a75a-047e2658236a}t) DRV - [2014-10-15 06:25:04 | 000,055,824 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{38f72c19-9857-4bc2-b729-9d00bd429872}t.sys -- ({38f72c19-9857-4bc2-b729-9d00bd429872}t) DRV - [2014-10-13 11:47:28 | 000,055,824 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{1fe5a9eb-d0ad-44c6-8e0e-e079118db915}t.sys -- ({1fe5a9eb-d0ad-44c6-8e0e-e079118db915}t) DRV - [2014-10-13 02:00:44 | 000,055,824 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{c89879cb-75b8-4cb6-bc13-07c704396fd0}t.sys -- ({c89879cb-75b8-4cb6-bc13-07c704396fd0}t) DRV - [2014-10-11 20:42:30 | 000,055,824 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{b35afcf6-0992-4551-b2da-3af8a5dc5119}t.sys -- ({b35afcf6-0992-4551-b2da-3af8a5dc5119}t) DRV - [2014-10-11 08:11:48 | 000,055,824 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{0c7dc56c-1fb8-4d6b-a40f-10611881a3b6}t.sys -- ({0c7dc56c-1fb8-4d6b-a40f-10611881a3b6}t) DRV - [2014-09-21 01:16:56 | 000,055,056 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\{c5e48979-bd7f-4cf7-9b73-2482a67a4f37}t.sys -- ({c5e48979-bd7f-4cf7-9b73-2482a67a4f37}t) DRV - [2014-07-07 20:22:48 | 000,414,520 | ---- | M] (AVAST Software) [File_System | System | Stopped] -- C:\WINDOWS\system32\drivers\aswsp.sys -- (aswSP) DRV - [2014-07-07 20:22:37 | 000,057,800 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\aswTdi.sys -- (aswTdi) DRV - [2014-07-07 20:22:36 | 000,192,352 | ---- | M] () [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\aswVmm.sys -- (aswVmm) DRV - [2014-07-07 20:22:36 | 000,067,824 | ---- | M] (AVAST Software) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\drivers\aswmonflt.sys -- (aswMonFlt) DRV - [2014-07-07 20:22:36 | 000,055,112 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswrdr.sys -- (AswRdr) DRV - [2014-07-07 20:22:36 | 000,049,944 | ---- | M] () [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\aswRvrt.sys -- (aswRvrt) DRV - [2014-07-07 20:22:36 | 000,024,184 | ---- | M] () [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\aswHwid.sys -- (aswHwid) DRV - [2014-01-23 04:21:04 | 000,184,192 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssudserd.sys -- (ssudserd) DRV - [2014-01-23 04:21:04 | 000,184,192 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssudmdm.sys -- (ssudmdm) DRV - [2014-01-23 04:21:04 | 000,088,576 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssudbus.sys -- (dg_ssudbus) DRV - [2013-08-25 11:30:48 | 000,013,120 | ---- | M] () [File_System | Auto | Stopped] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen) DRV - [2013-08-21 05:31:30 | 000,016,384 | ---- | M] (Intel Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\FlashUSB.sys -- (FlashUSB) DRV - [2012-11-30 14:54:10 | 002,558,712 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\viahduaa.sys -- (VIAHdAudAddService) DRV - [2012-11-07 15:34:46 | 001,343,760 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTWlanU.sys -- (RtlWlanu) DRV - [2012-09-17 12:05:12 | 000,106,296 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\jraid.sys -- (JRAID) DRV - [2012-05-14 07:12:12 | 000,103,040 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AtihdXP3.sys -- (AtiHDAudioService) DRV - [2010-12-21 06:55:02 | 000,132,608 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssm_mdm.sys -- (ssm_mdm) DRV - [2010-12-21 06:55:02 | 000,104,448 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssm_bus.sys -- (ssm_bus) DRV - [2010-12-21 06:55:02 | 000,014,848 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssm_mdfl.sys -- (ssm_mdfl) DRV - [2010-05-20 11:27:26 | 001,961,072 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\VX1000.sys -- (VX1000) DRV - [2010-03-19 17:15:49 | 000,046,632 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l1e51x86.sys -- (L1e) DRV - [2009-10-06 11:52:50 | 000,007,936 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt) DRV - [2009-10-06 11:52:34 | 000,022,016 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc) DRV - [2009-10-06 11:52:34 | 000,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd) DRV - [2009-10-06 11:52:34 | 000,007,936 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev) DRV - [2009-03-13 09:00:00 | 000,908,544 | ---- | M] (NXP Semiconductors Germany GmbH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\3xHybrid.sys -- (3xHybrid) DRV - [2008-08-26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd) DRV - [2008-04-13 19:46:22 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mpe.sys -- (MPE) DRV - [2008-02-14 07:12:00 | 001,389,056 | R--- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\monfilt.sys -- (monfilt) DRV - [2005-03-15 11:00:00 | 000,277,504 | ---- | M] (Philips Semiconductors) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SAA713x.sys -- (SAA713x) DRV - [2005-03-15 11:00:00 | 000,277,504 | ---- | M] (Philips Semiconductors) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\SAA713x.sys -- (713xTVCard) DRV - [2004-08-13 03:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor) DRV - [2003-09-16 14:56:40 | 000,353,792 | R--- | M] (Philips Semiconductors) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Cap7134.sys -- (Cap7134) DRV - [2003-09-13 08:32:02 | 000,025,344 | R--- | M] (Philips Semiconductors) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PhTVTune.sys -- (PhTVTune) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&ts=1417348758&from=wpc&uid=WDCXWD800BB-00JHC0_WD-WCAM9A04904249042 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type=ds&ts=1417348758&from=wpc&uid=WDCXWD800BB-00JHC0_WD-WCAM9A04904249042&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type=ds&ts=1417348758&from=wpc&uid=WDCXWD800BB-00JHC0_WD-WCAM9A04904249042&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hp&ts=1417348758&from=wpc&uid=WDCXWD800BB-00JHC0_WD-WCAM9A04904249042 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mystartsearch.com/web/?type=ds&ts=1417348758&from=wpc&uid=WDCXWD800BB-00JHC0_WD-WCAM9A04904249042&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mystartsearch.com/web/?type=ds&ts=1417348758&from=wpc&uid=WDCXWD800BB-00JHC0_WD-WCAM9A04904249042&q={searchTerms} IE - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.mystartsearch.com/web/?type=ds&ts=1417348758&from=wpc&uid=WDCXWD800BB-00JHC0_WD-WCAM9A04904249042&q={searchTerms} IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-861567501-1604221776-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&ts=1417348758&from=wpc&uid=WDCXWD800BB-00JHC0_WD-WCAM9A04904249042 IE - HKU\S-1-5-21-861567501-1604221776-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.trovi.com/?gd=&ctid=CT3319709&octid=EB_ORIGINAL_CTID&ISID=MDDAA7C1E-524E-4416-9E5A-7C4A68724F5A&SearchSource=55&CUI=&UM=6&UP=SPE1FEEB4D-FD3A-4308-9233-AC61828D2C7C&SSPV= IE - HKU\S-1-5-21-861567501-1604221776-839522115-1003\..\SearchScopes,DefaultScope = {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} IE - HKU\S-1-5-21-861567501-1604221776-839522115-1003\..\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}: "URL" = http://www.trovi.com/Results.aspx?gd=&ctid=CT3319709&octid=EB_ORIGINAL_CTID&ISID=MDDAA7C1E-524E-4416-9E5A-7C4A68724F5A&SearchSource=58&CUI=&UM=6&UP=SPE1FEEB4D-FD3A-4308-9233-AC61828D2C7C&q={searchTerms}&SSPV= IE - HKU\S-1-5-21-861567501-1604221776-839522115-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC IE - HKU\S-1-5-21-861567501-1604221776-839522115-1003\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.mystartsearch.com/web/?type=ds&ts=1417348758&from=wpc&uid=WDCXWD800BB-00JHC0_WD-WCAM9A04904249042&q={searchTerms} IE - HKU\S-1-5-21-861567501-1604221776-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_239.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1209149.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.67.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found FF - HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10: C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate) FF - HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4: C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll File not found FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: D:\Programy\AVAST Software\WebRep\FF [2014-07-07 20:22:37 | 000,000,000 | ---D | M] [color=#E56717]========== Chrome ==========[/color] CHR - plugin: Error reading preferences file CHR - Extension: avast! Online Security = C:\Documents and Settings\Greg.GS\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2021.112_0\ CHR - Extension: Google Wallet = C:\Documents and Settings\Greg.GS\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\ O1 HOSTS File: ([2013-12-06 00:19:34 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Programy\AVAST Software\aswWebRepIE.dll (AVAST Software) O2 - BHO: (Shopper Pro) - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\ShopperPro\ShopperPro.dll (Goobzo Ltd.) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\Greg.GS\Dane aplikacji\Nowe Gadu-Gadu\_userdata\ggbho.1.dll (GG Network S.A.) O4 - HKLM..\Run: [AvastUI.exe] D:\Programy\AVAST Software\AvastUI.exe (AVAST Software) O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found O4 - HKLM..\Run: [VX1000] C:\WINDOWS\vVX1000.exe (Microsoft Corporation) O4 - HKLM..\Run: [WinampAgent] D:\Programy\Winamp\winampa.exe () O4 - HKU\S-1-5-21-861567501-1604221776-839522115-1003..\Run: [] D:\Programy\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-861567501-1604221776-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-861567501-1604221776-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-21-861567501-1604221776-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1 O7 - HKU\S-1-5-21-861567501-1604221776-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1 O7 - HKU\S-1-5-21-861567501-1604221776-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-21-861567501-1604221776-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2B3E968F-418A-45DE-B23F-81124E402D5D}: DhcpNameServer = 192.168.1.1 192.168.1.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\Greg.GS\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Greg.GS\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008-05-02 20:51:12 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2014-12-18 12:56:28 | 000,000,000 | ---D | C] -- C:\FRST [2014-12-18 12:22:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\F-Secure [2014-12-18 12:14:22 | 000,000,000 | ---D | C] -- C:\Program Files\NortonInstaller [2014-12-18 10:48:02 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2014-12-18 09:59:04 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC [2014-12-09 22:24:09 | 000,055,824 | ---- | C] (StdLib) -- C:\WINDOWS\System32\drivers\{2f6db162-50b5-48ec-8bd0-c6ac5074038f}t.sys [2014-12-07 13:52:23 | 000,055,824 | ---- | C] (StdLib) -- C:\WINDOWS\System32\drivers\{1dc3c8ee-7a5c-414f-bf32-ae563ad31ed1}t.sys [2014-12-03 17:51:35 | 000,055,824 | ---- | C] (StdLib) -- C:\WINDOWS\System32\drivers\{9794b31c-7078-45aa-8534-9fee5d10dfe6}t.sys [2014-12-02 14:23:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Greg.GS\Menu Start\Programy\YTDownloader [2014-12-01 07:56:24 | 000,055,824 | ---- | C] (StdLib) -- C:\WINDOWS\System32\drivers\{6610c2c8-50f9-4a6a-b791-c2b9e2bdc00d}t.sys [2014-11-30 14:43:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Greg.GS\Ustawienia lokalne\Dane aplikacji\iWebar [2014-11-30 14:36:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Greg.GS\Ustawienia lokalne\Dane aplikacji\Installer [2014-11-30 14:23:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Greg.GS\Moje dokumenty\Downloads [2014-11-30 14:20:11 | 000,055,824 | ---- | C] (StdLib) -- C:\WINDOWS\System32\drivers\{b8202deb-d90b-4859-9db1-238d59fbcdd4}t.sys [2014-11-30 14:19:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\Pay-By-Ads [2014-11-30 14:18:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\1790955706 [2014-11-30 14:17:50 | 000,000,000 | ---D | C] -- C:\Program Files\globalUpdate [2014-11-30 14:17:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Greg.GS\Ustawienia lokalne\Dane aplikacji\globalUpdate [2014-11-30 14:16:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\ShopperPro [2014-11-30 14:16:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dokumenty\ShopperPro [2014-11-30 14:15:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Greg.GS\Pulpit\DownLite Downloads [2014-11-30 14:15:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\DownLite [2014-11-30 14:12:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Greg.GS\Menu Start\Programy\VOPackage [2014-11-30 14:12:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\VOPackage [2014-11-30 14:09:37 | 000,391,032 | ---- | C] (Software Installer ) -- C:\Documents and Settings\Greg.GS\Pulpit\StartDownload.exe [2014-11-30 13:51:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\RHEng [2014-11-30 13:51:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\OpenCandy [2014-11-30 13:50:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\uTorrent [2014-11-30 12:58:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Trusted Publisher [2014-11-30 12:54:58 | 000,000,000 | ---D | C] -- C:\Program Files\YoutubeAdBlocke [2014-11-30 12:54:39 | 000,000,000 | ---D | C] -- C:\Program Files\BuyNsave [2014-11-30 12:54:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\ahphemkffjccicjbnjjgmkiibfngenlf [2014-11-30 12:54:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\15553404656720149986 [2 C:\Documents and Settings\Greg.GS\Ustawienia lokalne\Dane aplikacji\*.tmp files -> C:\Documents and Settings\Greg.GS\Ustawienia lokalne\Dane aplikacji\*.tmp -> ] [19 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2014-12-18 12:45:26 | 000,000,178 | ---- | M] () -- C:\WINDOWS\tasks\Microsoft_Hardware_Launch_vVX1000_exe.job [2014-12-18 12:45:08 | 000,000,552 | ---- | M] () -- C:\WINDOWS\System32\d3d8caps.dat [2014-12-18 12:36:06 | 000,005,120 | ---- | M] () -- C:\Documents and Settings\Greg.GS\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2014-12-18 12:29:50 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat [2014-12-18 12:27:24 | 000,728,952 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2014-12-18 12:27:24 | 000,593,036 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2014-12-18 12:27:24 | 000,204,868 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2014-12-18 12:27:24 | 000,159,418 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2014-12-18 12:23:03 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2014-12-18 10:44:27 | 000,000,342 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2014-12-18 10:44:01 | 000,000,890 | ---- | M] () -- C:\WINDOWS\tasks\globalUpdateUpdateTaskMachineCore.job [2014-12-18 10:44:00 | 000,000,220 | ---- | M] () -- C:\WINDOWS\tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — logowanie.job [2014-12-18 10:43:59 | 000,000,428 | ---- | M] () -- C:\WINDOWS\tasks\SMupdate2.job [2014-12-18 10:43:59 | 000,000,428 | ---- | M] () -- C:\WINDOWS\tasks\SMupdate1.job [2014-12-18 10:43:58 | 000,000,428 | ---- | M] () -- C:\WINDOWS\tasks\SMupdate3.job [2014-12-18 10:43:55 | 000,000,356 | ---- | M] () -- C:\WINDOWS\tasks\YTDownloader.job [2014-12-18 08:28:41 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2014-12-10 13:54:51 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2014-12-10 13:28:00 | 000,000,960 | ---- | M] () -- C:\WINDOWS\tasks\SPBIW_UpdateTask_Time_333436303534383239362d3437415a556c2a3223346c41.job [2014-12-09 11:56:18 | 000,055,824 | ---- | M] (StdLib) -- C:\WINDOWS\System32\drivers\{2f6db162-50b5-48ec-8bd0-c6ac5074038f}t.sys [2014-12-08 14:22:01 | 000,000,894 | ---- | M] () -- C:\WINDOWS\tasks\globalUpdateUpdateTaskMachineUA.job [2014-12-06 18:53:04 | 000,055,824 | ---- | M] (StdLib) -- C:\WINDOWS\System32\drivers\{1dc3c8ee-7a5c-414f-bf32-ae563ad31ed1}t.sys [2014-12-03 08:35:08 | 000,055,824 | ---- | M] (StdLib) -- C:\WINDOWS\System32\drivers\{9794b31c-7078-45aa-8534-9fee5d10dfe6}t.sys [2014-11-30 22:19:38 | 000,304,152 | ---- | M] () -- C:\img2-001.raw [2014-11-30 22:09:14 | 000,149,252 | ---- | M] () -- C:\Documents and Settings\Greg.GS\Pulpit\webcam-toy-foto5.jpg [2014-11-30 15:33:08 | 000,055,824 | ---- | M] (StdLib) -- C:\WINDOWS\System32\drivers\{6610c2c8-50f9-4a6a-b791-c2b9e2bdc00d}t.sys [2014-11-30 14:09:37 | 000,391,032 | ---- | M] (Software Installer ) -- C:\Documents and Settings\Greg.GS\Pulpit\StartDownload.exe [2014-11-30 02:34:24 | 000,055,824 | ---- | M] (StdLib) -- C:\WINDOWS\System32\drivers\{b8202deb-d90b-4859-9db1-238d59fbcdd4}t.sys [2014-11-26 17:54:13 | 000,701,104 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe [2014-11-26 17:54:12 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl [2014-11-21 20:41:20 | 000,779,536 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswsnx.sys [2 C:\Documents and Settings\Greg.GS\Ustawienia lokalne\Dane aplikacji\*.tmp files -> C:\Documents and Settings\Greg.GS\Ustawienia lokalne\Dane aplikacji\*.tmp -> ] [19 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2014-12-18 12:45:26 | 000,000,178 | ---- | C] () -- C:\WINDOWS\tasks\Microsoft_Hardware_Launch_vVX1000_exe.job [2014-12-18 12:45:08 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat [2014-12-18 12:36:03 | 000,005,120 | ---- | C] () -- C:\Documents and Settings\Greg.GS\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2014-12-02 14:23:57 | 000,000,428 | ---- | C] () -- C:\WINDOWS\tasks\SMupdate3.job [2014-12-02 14:23:57 | 000,000,428 | ---- | C] () -- C:\WINDOWS\tasks\SMupdate2.job [2014-12-02 14:23:57 | 000,000,428 | ---- | C] () -- C:\WINDOWS\tasks\SMupdate1.job [2014-12-02 14:23:41 | 000,000,356 | ---- | C] () -- C:\WINDOWS\tasks\YTDownloader.job [2014-11-30 22:09:14 | 000,149,252 | ---- | C] () -- C:\Documents and Settings\Greg.GS\Pulpit\webcam-toy-foto5.jpg [2014-11-30 14:17:52 | 000,000,894 | ---- | C] () -- C:\WINDOWS\tasks\globalUpdateUpdateTaskMachineUA.job [2014-11-30 14:17:52 | 000,000,890 | ---- | C] () -- C:\WINDOWS\tasks\globalUpdateUpdateTaskMachineCore.job [2014-11-30 14:16:55 | 000,000,960 | ---- | C] () -- C:\WINDOWS\tasks\SPBIW_UpdateTask_Time_333436303534383239362d3437415a556c2a3223346c41.job [2014-10-25 15:01:23 | 000,000,016 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\mntemp [2014-10-01 19:13:41 | 000,000,472 | RHS- | C] () -- C:\Documents and Settings\All Users.WINDOWS\ntuser.pol [2014-05-16 22:06:52 | 000,024,184 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswHwid.sys [2014-02-14 18:21:12 | 000,000,188 | ---- | C] () -- C:\Documents and Settings\Greg.GS\Ustawienia lokalne\Dane aplikacji\rbxcsettings.rbx [2013-12-06 13:25:53 | 000,001,670 | ---- | C] () -- C:\WINDOWS\TVP3XDrv.ini [2013-12-06 00:14:04 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe [2013-12-06 00:14:04 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe [2013-12-06 00:14:04 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2013-12-06 00:14:04 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2013-12-06 00:14:04 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2013-12-04 19:23:44 | 000,001,065 | ---- | C] () -- C:\WINDOWS\winamp.ini [2013-12-03 17:59:48 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2013-12-03 17:59:45 | 002,102,272 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll [2013-12-03 17:59:45 | 000,755,027 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2013-12-03 17:59:45 | 000,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2013-12-03 17:59:44 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll [2013-12-03 17:59:44 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2013-12-03 17:15:20 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\LauncherAccess.dt [2013-12-03 17:14:25 | 000,013,120 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys [2013-11-03 23:18:00 | 000,000,108 | ---- | C] () -- C:\WINDOWS\SKYMAP.INI [2013-10-30 12:06:54 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll [2013-10-30 12:06:54 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll [2013-10-30 12:06:54 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll [2013-10-30 12:06:54 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll [2013-08-20 16:18:26 | 000,111,932 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat [2013-08-20 16:18:26 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat [2013-08-20 16:18:26 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat [2013-08-20 16:18:26 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat [2013-08-20 16:18:26 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat [2013-08-20 16:18:26 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat [2013-08-20 16:18:26 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat [2013-08-20 16:18:26 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat [2013-08-20 16:18:26 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat [2013-08-20 16:18:26 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat [2013-08-20 16:18:26 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat [2013-08-20 16:18:26 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat [2013-08-20 16:18:26 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat [2013-08-20 16:18:26 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat [2013-08-20 16:18:26 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat [2013-08-20 16:18:26 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat [2013-08-20 16:18:26 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat [2013-08-20 16:18:26 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat [2013-08-20 16:18:26 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini [2013-08-17 19:42:34 | 000,000,132 | ---- | C] () -- C:\Documents and Settings\Greg.GS\Ustawienia lokalne\Dane aplikacji\fusioncache.dat [2013-08-16 22:40:37 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat [2013-08-16 16:54:14 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\sh33w32.dll [2013-08-16 16:53:32 | 000,039,095 | ---- | C] () -- C:\WINDOWS\iccsigs.dat [2013-08-16 07:49:26 | 000,000,626 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2013-08-15 23:13:09 | 000,015,498 | ---- | C] () -- C:\WINDOWS\VX1000.ini [2013-08-15 23:01:21 | 000,009,760 | ---- | C] () -- C:\WINDOWS\System32\34CoInstaller.dll [2013-08-15 23:00:57 | 000,226,116 | ---- | C] () -- C:\WINDOWS\System32\drivers\beholder.bin [2013-08-15 20:26:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin [2013-08-15 14:57:14 | 000,192,352 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys [2013-08-15 14:57:14 | 000,049,944 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswRvrt.sys [2013-08-15 13:47:51 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2013-08-15 02:52:45 | 000,004,484 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2013-08-15 02:51:35 | 000,476,352 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2013-08-15 01:22:28 | 000,001,746 | ---- | C] () -- C:\WINDOWS\Language_trs.ini [2013-08-15 01:21:50 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys [2013-08-15 01:21:38 | 000,030,998 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini [2013-08-15 01:21:38 | 000,010,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS [2013-08-15 01:03:40 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2013-08-15 00:58:50 | 000,021,856 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2013-08-15 00:50:04 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll [2013-08-14 22:23:04 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2013-04-18 18:07:00 | 000,030,568 | ---- | C] () -- C:\WINDOWS\MusiccityDownload.exe [color=#E56717]========== ZeroAccess Check ==========[/color] [2013-08-15 13:14:41 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2008-04-14 18:20:47 | 001,499,136 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009-02-09 11:53:44 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2008-04-14 18:20:57 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2014-12-18 10:15:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.GS\Dane aplikacji\AVAST Software [2014-12-18 10:45:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.GS\Dane aplikacji\Opera [2014-11-30 12:54:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\15553404656720149986 [2014-11-30 14:18:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\1790955706 [2014-11-30 12:54:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\ahphemkffjccicjbnjjgmkiibfngenlf [2014-08-18 10:28:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\APN [2013-10-21 18:09:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\AVAST Software [2013-08-18 16:42:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Canneverbe Limited [2014-03-17 21:46:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\d7d8cb213bb5fde2 [2013-12-06 11:39:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\DriverGenius [2014-02-10 11:15:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\EPSON [2014-12-18 12:22:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\F-Secure [2014-02-24 21:29:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\FileOpen [2014-03-17 21:28:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\InstallMate [2014-05-03 17:25:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\ipla [2014-10-25 15:01:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Martau [2013-10-29 17:34:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\PC Suite [2013-11-04 20:03:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\RDRM [2014-04-21 09:54:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Samsung [2014-11-30 14:16:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\ShopperPro [2014-11-30 12:58:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Trusted Publisher [2013-08-20 16:22:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\UDL [2014-09-27 20:07:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\.minecraft [2014-08-18 10:29:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\.minecraftzyczu [2013-10-21 18:58:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\AVAST Software [2013-08-18 16:42:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\Canneverbe Limited [2014-11-30 14:15:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\DownLite [2014-02-24 17:04:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\ElevatedDiagnostics [2014-02-24 21:29:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\FileOpen [2014-05-03 17:23:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\ipla [2013-10-29 17:36:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\Nokia [2013-08-17 00:01:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\Nowe Gadu-Gadu [2013-11-21 12:57:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\ooVoo Details [2014-11-30 13:51:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\OpenCandy [2013-08-14 21:26:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\Opera [2014-11-30 14:19:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\Pay-By-Ads [2013-10-29 17:34:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\PC Suite [2014-11-30 13:51:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\RHEng [2014-05-28 16:50:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\Riot Games [2014-04-21 10:04:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\Samsung [2014-11-30 14:49:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\uTorrent [2014-11-30 14:12:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\VOPackage [2013-12-03 13:54:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg.GS\Dane aplikacji\wsInspector [color=#E56717]========== Purity Check ==========[/color] < End of report >