OTListIt logfile created on: 2009-06-04 11:17:52 - Run 1 OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Users\Michal\Downloads Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 7.0.6001.18000) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 100,00% Memory free 4,00 Gb Paging File | 4,00 Gb Available in Paging File | 100,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 97,66 Gb Total Space | 59,09 Gb Free Space | 60,51% Space Free | Partition Type: NTFS Drive D: | 97,66 Gb Total Space | 97,57 Gb Free Space | 99,91% Space Free | Partition Type: NTFS Drive E: | 102,78 Gb Total Space | 102,69 Gb Free Space | 99,91% Space Free | Partition Type: NTFS F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: MICHAL-PC Current User Name: Michal Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Output = Standard File Age = 30 Days Company Name Whitelist: On ========== Processes (SafeList) ========== PRC - [2009-01-14 06:59:54 | 00,729,088 | ---- | M] (ATI Technologies Inc.) – C:\Windows\system32\Ati2evxx.exe PRC - [2009-06-01 20:57:57 | 01,005,904 | ---- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe PRC - [2009-01-14 06:59:54 | 00,729,088 | ---- | M] (ATI Technologies Inc.) – C:\Windows\system32\Ati2evxx.exe PRC - [2008-10-29 08:29:41 | 02,927,104 | ---- | M] (Microsoft Corporation) – C:\Windows\Explorer.EXE PRC - [2008-01-21 04:23:32 | 01,008,184 | ---- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MSASCui.exe PRC - [2008-02-13 07:52:10 | 04,915,200 | ---- | M] (Realtek Semiconductor) – C:\Windows\RtHDVCpl.exe PRC - [2008-12-18 15:32:52 | 00,049,152 | ---- | M] (Advanced Micro Devices Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe PRC - [2009-03-09 06:19:17 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe PRC - [2009-02-27 18:10:28 | 00,035,696 | ---- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe PRC - [2008-03-25 22:27:58 | 00,049,152 | ---- | M] (Hewlett-Packard) – C:\Program Files\HP\HP Software Update\hpwuSchd2.exe PRC - [2008-06-02 09:28:22 | 00,081,920 | ---- | M] (Hewlett-Packard) – C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe PRC - [2009-06-01 20:57:59 | 00,518,488 | ---- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe PRC - [2008-01-21 04:23:29 | 01,233,920 | ---- | M] (Microsoft Corporation) – C:\Program Files\Windows Sidebar\sidebar.exe PRC - [2009-05-28 11:23:12 | 10,486,376 | ---- | M] (GG Network S.A.) – C:\Program Files\Nowe Gadu-Gadu\gg.exe PRC - [2007-06-27 20:03:40 | 00,152,872 | ---- | M] (Nero AG) – C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe PRC - [2009-05-28 10:33:44 | 00,077,824 | ---- | M] () – C:\Program Files\Nowe Gadu-Gadu\spellchecker_gg.exe PRC - [2008-12-18 14:19:44 | 00,049,152 | ---- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe PRC - [2008-01-21 04:24:59 | 00,142,336 | ---- | M] (Microsoft Corporation) – C:\Windows\system32\WUDFHost.exe PRC - [2009-04-29 21:43:53 | 00,307,704 | ---- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2007-06-27 20:04:00 | 00,279,848 | ---- | M] (Nero AG) – C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe PRC - [2008-01-21 04:23:52 | 00,037,888 | ---- | M] (Microsoft Corporation) – C:\Windows\system32\wbem\unsecapp.exe PRC - [2007-06-27 20:04:00 | 01,213,736 | ---- | M] (Nero AG) – C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe PRC - [2009-03-03 04:16:04 | 00,247,296 | ---- | M] (Microsoft Corporation) – C:\Windows\system32\wbem\wmiprvse.exe PRC - [2009-06-04 11:17:40 | 00,501,248 | ---- | M] (OldTimer Tools) – C:\Users\Michal\Downloads\OTListIt2.exe ========== Win32 Services (SafeList) ========== SRV - [2009-01-14 06:59:54 | 00,729,088 | ---- | M] (ATI Technologies Inc.) – C:\Windows\system32\Ati2evxx.exe – (Ati External Event Utility [Auto | Running]) SRV - [2008-07-27 20:03:13 | 00,069,632 | ---- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) SRV - [2008-01-21 04:25:09 | 00,292,352 | ---- | M] (Microsoft Corporation) – C:\Windows\ehome\ehRecvr.exe – (ehRecvr [On_Demand | Stopped]) SRV - [2006-11-02 14:35:29 | 00,131,072 | ---- | M] (Microsoft Corporation) – C:\Windows\ehome\ehsched.exe – (ehSched [On_Demand | Stopped]) SRV - [2006-11-02 14:35:29 | 00,013,312 | ---- | M] (Microsoft Corporation) – C:\Windows\ehome\ehstart.dll – (ehstart [Auto | Stopped]) SRV - [2008-06-20 03:14:44 | 00,046,104 | ---- | M] (Microsoft Corporation) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped]) SRV - [2008-03-25 21:38:24 | 00,217,088 | ---- | M] (Hewlett-Packard Co.) – C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll – (hpqcxs08 [On_Demand | Running]) SRV - [2008-03-25 22:27:36 | 00,135,168 | ---- | M] (Hewlett-Packard Co.) – C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll – (hpqddsvc [Auto | Running]) SRV - [2008-06-20 03:14:31 | 00,881,664 | ---- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [unknown | Stopped]) SRV - [2009-06-01 20:57:57 | 01,005,904 | ---- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service [Auto | Running]) SRV - [2007-11-28 12:27:24 | 00,800,040 | ---- | M] (Nero AG) – C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe – (NBService [On_Demand | Stopped]) SRV - [2008-07-18 13:13:20 | 00,044,032 | ---- | M] (Hewlett-Packard) – C:\Windows\system32\HPZinw12.dll – (Net Driver HPZ12 [Auto | Running]) SRV - [2008-06-20 03:14:31 | 00,132,096 | ---- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped]) SRV - [2007-06-27 20:04:00 | 00,279,848 | ---- | M] (Nero AG) – C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe – (NMIndexingService [On_Demand | Running]) SRV - [2007-08-24 04:19:12 | 00,443,776 | ---- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped]) SRV - [2006-10-26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped]) SRV - [2008-07-18 13:13:20 | 00,053,760 | ---- | M] (Hewlett-Packard) – C:\Windows\system32\HPZipm12.dll – (Pml Driver HPZ12 [Auto | Running]) SRV - [2007-10-18 12:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) – C:\Program Files\Windows Live\Messenger\usnsvc.exe – (usnjsvc [On_Demand | Stopped]) SRV - [2008-01-21 04:23:32 | 00,272,952 | ---- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\mpsvc.dll – (WinDefend [Auto | Running]) SRV - [2008-12-06 06:42:11 | 00,376,832 | ---- | M] (Microsoft Corporation) – winhttp.dll – (WinHttpAutoProxySvc [On_Demand | Running]) SRV - [2007-10-25 16:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe – (WLSetupSvc [On_Demand | Stopped]) SRV - [2008-01-21 04:25:33 | 00,896,512 | ---- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe – (WMPNetworkSvc [On_Demand | Stopped]) ========== Driver Services (SafeList) ========== DRV - [2008-01-21 04:23:21 | 00,422,968 | ---- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\adp94xx.sys – (adp94xx [Disabled | Stopped]) DRV - [2008-01-21 04:23:25 | 00,300,600 | ---- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\adpahci.sys – (adpahci [Disabled | Stopped]) DRV - [2008-01-21 04:23:26 | 00,101,432 | ---- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\adpu160m.sys – (adpu160m [Disabled | Stopped]) DRV - [2008-01-21 04:23:27 | 00,149,560 | ---- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\adpu320.sys – (adpu320 [Disabled | Stopped]) DRV - [2006-11-02 11:50:11 | 00,071,272 | ---- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\djsvs.sys – (aic78xx [Disabled | Stopped]) DRV - [2008-01-21 04:23:00 | 00,017,464 | ---- | M] (Acer Laboratories Inc.) – C:\Windows\system32\drivers\aliide.sys – (aliide [Disabled | Stopped]) DRV - [2008-01-21 04:23:23 | 00,079,416 | ---- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\arc.sys – (arc [Disabled | Stopped]) DRV - [2008-01-21 04:23:24 | 00,079,928 | ---- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\arcsas.sys – (arcsas [Disabled | Stopped]) DRV - [2009-01-14 09:15:40 | 04,235,776 | ---- | M] (ATI Technologies Inc.) – C:\Windows\system32\DRIVERS\atikmdag.sys – (atikmdag [On_Demand | Running]) DRV - [2006-11-02 10:24:45 | 00,013,568 | ---- | M] (Brother Industries, Ltd.) – C:\Windows\system32\drivers\brfiltlo.sys – (BrFiltLo [On_Demand | Stopped]) DRV - [2006-11-02 10:24:46 | 00,005,248 | ---- | M] (Brother Industries, Ltd.) – C:\Windows\system32\drivers\brfiltup.sys – (BrFiltUp [On_Demand | Stopped]) DRV - [2006-11-02 10:25:24 | 00,071,808 | ---- | M] (Brother Industries Ltd.) – C:\Windows\system32\drivers\brserid.sys – (Brserid [Disabled | Stopped]) DRV - [2006-11-02 10:24:44 | 00,062,336 | ---- | M] (Brother Industries Ltd.) – C:\Windows\system32\drivers\brserwdm.sys – (BrSerWdm [Disabled | Stopped]) DRV - [2006-11-02 10:24:44 | 00,012,160 | ---- | M] (Brother Industries Ltd.) – C:\Windows\system32\drivers\brusbmdm.sys – (BrUsbMdm [Disabled | Stopped]) DRV - [2006-11-02 10:24:47 | 00,011,904 | ---- | M] (Brother Industries Ltd.) – C:\Windows\system32\drivers\brusbser.sys – (BrUsbSer [On_Demand | Stopped]) DRV - [2008-01-21 04:23:00 | 00,019,000 | ---- | M] (CMD Technology, Inc.) – C:\Windows\system32\drivers\cmdide.sys – (cmdide [Disabled | Stopped]) DRV - [2008-01-21 04:23:24 | 00,118,784 | ---- | M] (Intel Corporation) – C:\Windows\system32\DRIVERS\E1G60I32.sys – (E1G60 [On_Demand | Stopped]) DRV - [2008-01-21 04:23:22 | 00,342,584 | ---- | M] (Emulex) – C:\Windows\system32\drivers\elxstor.sys – (elxstor [Disabled | Stopped]) DRV - [2009-02-16 09:02:49 | 00,008,059 | ---- | M] (Windows ® 2000 DDK provider) – C:\Windows\gdrv.sys – (gdrv [On_Demand | Stopped]) DRV - [2008-01-21 04:23:26 | 00,040,504 | ---- | M] (Hewlett-Packard Company) – C:\Windows\system32\drivers\hpcisss.sys – (HpCISSs [Disabled | Stopped]) DRV - [2008-01-21 04:23:23 | 00,235,064 | ---- | M] (Intel Corporation) – C:\Windows\system32\drivers\iastorv.sys – (iaStorV [Disabled | Stopped]) DRV - [2006-11-02 11:50:17 | 00,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) – C:\Windows\system32\drivers\iirsp.sys – (iirsp [Disabled | Stopped]) DRV - [2008-02-14 11:03:10 | 02,061,528 | ---- | M] (Realtek Semiconductor Corp.) – C:\Windows\system32\drivers\RTKVHDA.sys – (IntcAzAudAddService [On_Demand | Running]) DRV - [2006-11-02 11:50:07 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) – C:\Windows\system32\drivers\iteatapi.sys – (iteatapi [Disabled | Stopped]) DRV - [2006-11-02 11:50:09 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) – C:\Windows\system32\drivers\iteraid.sys – (iteraid [Disabled | Stopped]) DRV - [2009-05-02 20:56:57 | 00,064,160 | ---- | M] (Lavasoft AB) – C:\Windows\system32\DRIVERS\Lbd.sys – (Lbd [boot | Running]) DRV - [2008-01-21 04:23:23 | 00,096,312 | ---- | M] (LSI Logic) – C:\Windows\system32\drivers\lsi_fc.sys – (LSI_FC [Disabled | Stopped]) DRV - [2008-01-21 04:23:25 | 00,089,656 | ---- | M] (LSI Logic) – C:\Windows\system32\drivers\lsi_sas.sys – (LSI_SAS [Disabled | Stopped]) DRV - [2008-01-21 04:23:23 | 00,096,312 | ---- | M] (LSI Logic) – C:\Windows\system32\drivers\lsi_scsi.sys – (LSI_SCSI [Disabled | Stopped]) DRV - [2008-01-21 04:23:27 | 00,031,288 | ---- | M] (LSI Corporation) – C:\Windows\system32\drivers\megasas.sys – (megasas [Disabled | Stopped]) DRV - [2008-01-21 04:23:27 | 00,386,616 | ---- | M] (LSI Corporation, Inc.) – C:\Windows\system32\drivers\megasr.sys – (MegaSR [Disabled | Stopped]) DRV - [2006-11-02 11:49:59 | 00,033,384 | ---- | M] (LSI Logic Corporation) – C:\Windows\system32\drivers\mraid35x.sys – (Mraid35x [Disabled | Stopped]) DRV - [2006-11-02 11:50:19 | 00,045,160 | ---- | M] (IBM Corporation) – C:\Windows\system32\drivers\nfrd960.sys – (nfrd960 [Disabled | Stopped]) DRV - [2006-11-02 09:36:50 | 00,020,608 | ---- | M] (N-trig Innovative Technologies) – C:\Windows\system32\drivers\ntrigdigi.sys – (ntrigdigi [Disabled | Stopped]) DRV - [2008-01-21 04:23:21 | 00,102,968 | ---- | M] (NVIDIA Corporation) – C:\Windows\system32\drivers\nvraid.sys – (nvraid [Disabled | Stopped]) DRV - [2008-01-21 04:23:21 | 00,045,112 | ---- | M] (NVIDIA Corporation) – C:\Windows\system32\drivers\nvstor.sys – (nvstor [Disabled | Stopped]) DRV - [2008-01-21 04:23:24 | 01,122,360 | ---- | M] (QLogic Corporation) – C:\Windows\system32\drivers\ql2300.sys – (ql2300 [Disabled | Stopped]) DRV - [2006-11-02 11:50:35 | 00,106,088 | ---- | M] (QLogic Corporation) – C:\Windows\system32\drivers\ql40xx.sys – (ql40xx [Disabled | Stopped]) DRV - [2008-01-25 10:46:40 | 00,106,496 | ---- | M] (Realtek Corporation ) – C:\Windows\system32\DRIVERS\Rtlh86.sys – (RTL8169 [On_Demand | Running]) DRV - [2006-11-02 08:37:21 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\Windows\System32\drivers\secdrv.sys – (secdrv [Auto | Running]) DRV - [2008-01-21 04:23:26 | 00,074,808 | ---- | M] (Silicon Integrated Systems) – C:\Windows\system32\drivers\sisraid4.sys – (SiSRaid4 [Disabled | Stopped]) DRV - [2006-11-02 11:50:05 | 00,035,944 | ---- | M] (LSI Logic) – C:\Windows\system32\drivers\symc8xx.sys – (Symc8xx [Disabled | Stopped]) DRV - [2006-11-02 11:49:56 | 00,031,848 | ---- | M] (LSI Logic) – C:\Windows\system32\drivers\sym_hi.sys – (Sym_hi [Disabled | Stopped]) DRV - [2006-11-02 11:50:03 | 00,034,920 | ---- | M] (LSI Logic) – C:\Windows\system32\drivers\sym_u3.sys – (Sym_u3 [Disabled | Stopped]) DRV - [2008-01-21 04:23:20 | 00,238,648 | ---- | M] (ULi Electronics Inc.) – C:\Windows\system32\drivers\uliahci.sys – (uliahci [Disabled | Stopped]) DRV - [2006-11-02 11:50:35 | 00,098,408 | ---- | M] (Promise Technology, Inc.) – C:\Windows\system32\drivers\ulsata.sys – (UlSata [Disabled | Stopped]) DRV - [2008-01-21 04:23:23 | 00,115,816 | ---- | M] (Promise Technology, Inc.) – C:\Windows\system32\drivers\ulsata2.sys – (ulsata2 [Disabled | Stopped]) DRV - [2008-01-21 04:23:00 | 00,020,024 | ---- | M] (VIA Technologies, Inc.) – C:\Windows\system32\drivers\viaide.sys – (viaide [Disabled | Stopped]) DRV - [2008-01-21 04:23:23 | 00,130,616 | ---- | M] (VIA Technologies Inc.,Ltd) – C:\Windows\system32\drivers\vsmraid.sys – (vsmraid [Disabled | Stopped]) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0 ========== FireFox ========== FF - prefs.js…browser.search.defaultthis.engineName: “PHPNukeEN Customized Web Search” FF - prefs.js…browser.search.defaulturl: “http://search.conduit.com/ResultsExt.aspx?ctid=CT2086743&SearchSource=3&q=” FF - prefs.js…browser.startup.homepage: “http://www.google.pl/” FF - prefs.js…extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12 FF - prefs.js…extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13 FF - prefs.js…extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0 FF - prefs.js…extensions.enabledItems: {dd02a4eb-4afd-4d60-99d8-e67f964ca813}:1.5.48.2 FF - prefs.js…extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10 FF - prefs.js…keyword.URL: “http://search.conduit.com/ResultsExt.aspx?ctid=CT2086743&q=” FF - HKLM\software\mozilla\Firefox\Extensions\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009-03-18 22:31:49 | 00,000,000 | —D | M] FF - HKLM\software\mozilla\Firefox\Extensions\smartwebprinting@hp.com: C:\PROGRAM FILES\HP\DIGITAL IMAGING\SMART WEB PRINTING\MOZILLAADDON2 [2009-03-28 12:13:30 | 00,000,000 | —D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009-04-29 21:43:53 | 00,000,000 | —D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009-04-29 21:43:53 | 00,000,000 | —D | M] [2009-03-18 21:33:18 | 00,000,000 | —D | M] – C:\Users\Michal\AppData\Roaming\mozilla\Extensions [2009-03-18 21:33:18 | 00,000,000 | —D | M] – C:\Users\Michal\AppData\Roaming\mozilla\Extensions{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009-06-04 08:22:22 | 00,000,000 | —D | M] – C:\Users\Michal\AppData\Roaming\mozilla\Firefox\Profiles\ssaxigkf.default\extensions [2009-03-25 20:58:42 | 00,000,000 | —D | M] – C:\Users\Michal\AppData\Roaming\mozilla\Firefox\Profiles\ssaxigkf.default\extensions{dd02a4eb-4afd-4d60-99d8-e67f964ca813} [2009-02-18 12:07:20 | 00,000,880 | ---- | M] () – C:\Users\Michal\AppData\Roaming\Mozilla\FireFox\Profiles\ssaxigkf.default\searchplugins\conduit.xml [2009-03-25 00:06:27 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions [2009-04-29 21:43:53 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009-03-18 22:26:29 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} [2009-03-25 00:06:27 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [2009-04-29 21:43:53 | 00,023,032 | ---- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009-04-29 21:43:53 | 00,134,648 | ---- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2009-04-22 23:34:07 | 00,000,896 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2009-04-22 23:34:07 | 00,001,406 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2009-04-22 23:34:07 | 00,001,706 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml [2009-04-22 23:34:07 | 00,000,917 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2009-04-22 23:34:07 | 00,000,858 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2009-04-22 23:34:08 | 00,001,183 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2009-04-22 23:34:08 | 00,001,683 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found O2 - BHO: (Pomocnik rejestracji usługi Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation) O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Users\Michal\AppData\Roaming\Nowe Gadu-Gadu_userdata\ggbho.1.dll (GG Network S.A.) O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) O3 - HKLM…\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation) O3 - HKCU…\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation) O4 - HKLM…\Run: [Adobe Reader Speed Launcher] “C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe” (Adobe Systems Incorporated) O4 - HKLM…\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft) O4 - HKLM…\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard) O4 - HKLM…\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe (Hewlett-Packard) O4 - HKLM…\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG) O4 - HKLM…\Run: [Onet.pl AutoUpdate] C:\Program Files\Common Files\Onet.pl\AutoUpdate.exe /tsr File not found O4 - HKLM…\Run: [RtHDVCpl] RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM…\Run: [startCCC] “C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” MSRun (Advanced Micro Devices, Inc.) O4 - HKLM…\Run: [sunJavaUpdateSched] “C:\Program Files\Java\jre6\bin\jusched.exe” (Sun Microsystems, Inc.) O4 - HKLM…\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide (Microsoft Corporation) O4 - HKCU…\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] “C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe” (Nero AG) O4 - HKCU…\Run: [Nowe Gadu-Gadu] “C:\Program Files\Nowe Gadu-Gadu\gg.exe” (GG Network S.A.) O4 - HKCU…\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (Microsoft Corporation) O4 - HKCU…\Run: [Tester] c:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe () O4 - Startup: C:\Users\Michal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe () O4 - Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17 O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm (Microsoft Corporation) O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 (Microsoft Corporation) O9 - Extra Button: Wpis w blogu - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra ‘Tools’ menuitem : &Wpis w blogu w Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: Zaznaczanie HP Smart - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s … wflash.cab (Shockwave Flash Object) O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation) O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation) O18 - Protocol\Filter: - application/octet-stream - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter: - application/x-complus - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter: - application/x-msdownload - mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (Control_RunDLL “sysdm.cpl”) - sysdm.cpl (Microsoft Corporation) O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006-09-18 23:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat – [NTFS] O33 - MountPoints2{3c83f4f8-3e1d-11de-85ce-001fd06d0a1b}\Shell\AutoRun\command - “” = K:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe – File not found O33 - MountPoints2{3c83f4f8-3e1d-11de-85ce-001fd06d0a1b}\Shell\open\command - “” = K:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe – File not found O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\Windows\system32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - * [2009-06-04 10:12:56 | 00,000,000 | —D | M] ========== Files/Folders - Created Within 30 Days ========== [2009-06-04 08:15:41 | 00,001,874 | ---- | C] () – C:\Users\Michal\Desktop\HijackThis.lnk [2009-06-04 08:15:41 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro [2009-06-01 21:04:38 | 00,000,000 | RHSD | C] – C:\RECYCLER [2009-05-30 17:29:58 | 00,013,719 | ---- | C] () – C:\Users\Michal\Desktop\Nowy OpenDocument Dokument tekstowy (2).odt [2009-05-30 15:30:27 | 00,001,887 | ---- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk [2009-05-28 06:05:12 | 00,020,236 | ---- | C] () – C:\Users\Michal\Desktop\Nowy OpenDocument Dokument tekstowy.odt [2009-05-26 18:00:59 | 00,000,000 | —D | C] – C:\Users\Michal\Desktop\lic01 [2009-05-24 17:15:46 | 00,000,000 | —D | C] – C:\Users\Michal\Desktop\logika [2009-05-14 15:52:22 | 00,000,000 | —D | C] – C:\ProgramData\OpenFM [2009-05-14 02:25:45 | 00,000,000 | —D | C] – C:\Users\Michal\Desktop\licencjacka [2009-05-12 21:07:38 | 00,000,000 | —D | C] – C:\Users\Michal\Desktop\zur [2009-02-16 15:56:11 | 00,000,010 | ---- | C] () – C:\Windows\GSetup.ini [2008-03-12 23:17:44 | 00,159,744 | ---- | C] () – C:\Windows\System32\atitmmxx.dll [2006-11-02 14:35:32 | 00,005,632 | ---- | C] () – C:\Windows\System32\sysprepMCE.dll [2006-11-02 12:23:31 | 00,000,472 | ---- | C] () – C:\Windows\win.ini [2006-11-02 12:23:31 | 00,000,219 | ---- | C] () – C:\Windows\system.ini [2006-11-02 09:40:29 | 00,013,750 | ---- | C] () – C:\Windows\System32\pacerprf.ini ========== Files - Modified Within 30 Days ========== [2009-06-04 11:14:16 | 00,003,664 | -H-- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2009-06-04 11:14:16 | 00,003,664 | -H-- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2009-06-04 11:14:13 | 00,000,006 | -H-- | M] () – C:\Windows\tasks\SA.DAT [2009-06-04 11:14:11 | 00,067,584 | --S- | M] () – C:\Windows\bootstat.dat [2009-06-04 11:14:08 | 32,207,58528 | -HS- | M] () – C:\hiberfil.sys [2009-06-04 10:12:56 | 01,468,980 | ---- | M] () – C:\Windows\System32\PerfStringBackup.INI [2009-06-04 10:12:56 | 00,661,818 | ---- | M] () – C:\Windows\System32\perfh015.dat [2009-06-04 10:12:56 | 00,586,980 | ---- | M] () – C:\Windows\System32\perfh009.dat [2009-06-04 10:12:56 | 00,126,702 | ---- | M] () – C:\Windows\System32\perfc015.dat [2009-06-04 10:12:56 | 00,101,052 | ---- | M] () – C:\Windows\System32\perfc009.dat [2009-06-04 08:59:00 | 00,000,270 | ---- | M] () – C:\Windows\tasks\Sprawdź aktualizacje paska narzędzi Windows Live Toolbar.job [2009-06-04 08:15:41 | 00,001,874 | ---- | M] () – C:\Users\Michal\Desktop\HijackThis.lnk [2009-06-04 03:40:32 | 00,000,420 | -H-- | M] () – C:\Windows\tasks\User_Feed_Synchronization-{8A163302-895E-4073-A1F5-FCC991BE4909}.job [2009-06-01 20:58:50 | 00,000,472 | ---- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job [2009-05-30 17:30:25 | 00,013,719 | ---- | M] () – C:\Users\Michal\Desktop\Nowy OpenDocument Dokument tekstowy (2).odt [2009-05-30 15:30:27 | 00,001,887 | ---- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk [2009-05-28 06:13:34 | 00,020,236 | ---- | M] () – C:\Users\Michal\Desktop\Nowy OpenDocument Dokument tekstowy.odt [2009-05-15 12:07:36 | 00,000,103 | ---- | M] () – C:\Users\Michal\AppData\default.pls [2009-05-07 09:16:29 | 24,699,336 | ---- | M] (Microsoft Corporation) – C:\Windows\System32\mrt.exe < End of report >