OTL logfile created on: 2009-09-25 16:47:09 - Run 1 OTL by OldTimer - Version 3.0.14.0 Folder = C:\Documents and Settings\kubaa\Pulpit Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 766,80 Mb Total Physical Memory | 366,72 Mb Available Physical Memory | 47,82% Memory free 1,83 Gb Paging File | 1,44 Gb Available in Paging File | 78,78% Paging File free Paging file location(s): C:\pagefile.sys 1152 2304 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 7,07 Gb Total Space | 0,21 Gb Free Space | 2,95% Space Free | Partition Type: NTFS Drive D: | 48,83 Gb Total Space | 4,01 Gb Free Space | 8,21% Space Free | Partition Type: NTFS E: Drive not present or media not loaded Drive F: | 3,72 Gb Total Space | 0,18 Gb Free Space | 4,75% Space Free | Partition Type: FAT32 Drive G: | 7,52 Gb Total Space | 7,05 Gb Free Space | 93,73% Space Free | Partition Type: FAT32 H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: KUBA Current User Name: kubaa Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard ========== Processes (SafeList) ========== PRC - [2006-05-03 18:43:46 | 00,413,696 | ---- | M] (ATI Technologies Inc.) – C:\WINDOWS\System32\Ati2evxx.exe PRC - [2009-09-15 12:49:40 | 00,018,752 | ---- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe PRC - [2009-09-15 12:56:43 | 00,138,680 | ---- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe PRC - [2006-05-03 18:43:46 | 00,413,696 | ---- | M] (ATI Technologies Inc.) – C:\WINDOWS\System32\Ati2evxx.exe PRC - [2007-06-13 15:23:49 | 01,034,752 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE PRC - [2009-09-15 12:56:48 | 00,081,000 | ---- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashDisp.exe PRC - [2005-01-28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wdfmgr.exe PRC - [2009-09-25 13:06:17 | 00,908,280 | ---- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2009-09-15 12:56:28 | 00,254,040 | ---- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe PRC - [2009-09-15 12:54:13 | 00,352,920 | ---- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe PRC - [2008-08-09 19:45:30 | 00,770,048 | ---- | M] (sms-express.com) – C:\Program Files\Gadu-Gadu\gg.exe PRC - [2009-09-25 16:46:22 | 00,514,560 | ---- | M] (OldTimer Tools) – C:\Documents and Settings\kubaa\Pulpit\OTL.exe ========== Win32 Services (SafeList) ========== SRV - [2008-07-25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped]) SRV - [2009-09-15 12:49:40 | 00,018,752 | ---- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe – (aswUpdSv [Auto | Running]) SRV - [2006-05-03 18:43:46 | 00,413,696 | ---- | M] (ATI Technologies Inc.) – C:\WINDOWS\System32\Ati2evxx.exe – (Ati HotKey Poller [Auto | Running]) SRV - [2006-05-03 11:57:00 | 00,520,192 | ---- | M] () – C:\WINDOWS\System32\ati2sgag.exe – (ATI Smart [Auto | Stopped]) SRV - [2009-09-15 12:56:43 | 00,138,680 | ---- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe – (avast! Antivirus [Auto | Running]) SRV - [2009-09-15 12:56:28 | 00,254,040 | ---- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe – (avast! Mail Scanner [On_Demand | Running]) SRV - [2009-09-15 12:54:13 | 00,352,920 | ---- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe – (avast! Web Scanner [On_Demand | Running]) SRV - [2008-07-25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) SRV - [2008-07-29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped]) SRV - [2004-08-04 00:44:08 | 00,038,912 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running]) SRV - [2007-03-12 03:35:02 | 00,217,088 | ---- | M] (Hewlett-Packard Co.) – C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll – (hpqcxs08 [On_Demand | Stopped]) SRV - [2008-07-29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [unknown | Stopped]) SRV - [2004-08-04 00:44:02 | 00,027,648 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\System32\irmon.dll – (Irmon [Auto | Running]) SRV - [2006-10-27 00:47:54 | 00,065,824 | ---- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe – (Microsoft Office Groove Audit Service [On_Demand | Stopped]) SRV - [2006-11-08 16:35:36 | 00,043,520 | ---- | M] (Hewlett-Packard) – C:\WINDOWS\System32\HPZinw12.dll – (Net Driver HPZ12 [Auto | Running]) SRV - [2008-07-29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped]) SRV - [2006-10-26 19:49:34 | 00,441,136 | ---- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped]) SRV - [2006-10-26 13:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped]) SRV - [2006-11-08 16:35:38 | 00,053,248 | ---- | M] (Hewlett-Packard) – C:\WINDOWS\System32\HPZipm12.dll – (Pml Driver HPZ12 [Auto | Running]) SRV - [2007-03-26 13:06:24 | 00,292,864 | ---- | M] (Nokia.) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe – (ServiceLayer [On_Demand | Stopped]) SRV - [2005-01-28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wdfmgr.exe – (UMWdf [Auto | Running]) ========== Driver Services (SafeList) ========== DRV - [2009-09-15 12:53:24 | 00,027,408 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys – (Aavmker4 [system | Running]) DRV - [2009-09-15 12:55:19 | 00,020,560 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\DRIVERS\aswFsBlk.sys – (aswFsBlk [Auto | Running]) DRV - [2009-09-15 12:56:14 | 00,094,160 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys – (aswMon2 [Auto | Running]) DRV - [2009-09-15 12:54:21 | 00,023,152 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys – (aswRdr [On_Demand | Running]) DRV - [2009-09-15 12:55:30 | 00,114,768 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys – (aswSP [system | Running]) DRV - [2009-09-15 12:54:30 | 00,052,368 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys – (aswTdi [system | Running]) DRV - [2006-05-03 18:50:42 | 01,540,608 | ---- | M] (ATI Technologies Inc.) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys – (ati2mtag [On_Demand | Running]) DRV - [2001-08-17 21:19:20 | 00,003,712 | ---- | M] (Creative Technology Ltd.) – C:\WINDOWS\System32\DRIVERS\ctljystk.sys – (ctljystk [On_Demand | Running]) DRV - [2004-08-03 23:08:22 | 00,010,624 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\gameenum.sys – (gameenum [On_Demand | Running]) DRV - [2007-03-08 21:20:48 | 00,049,920 | ---- | M] (HP) – C:\WINDOWS\System32\DRIVERS\HPZid412.sys – (HPZid412 [On_Demand | Stopped]) DRV - [2007-03-08 21:20:49 | 00,016,496 | ---- | M] (HP) – C:\WINDOWS\System32\DRIVERS\HPZipr12.sys – (HPZipr12 [On_Demand | Stopped]) DRV - [2007-03-08 21:20:50 | 00,021,568 | ---- | M] (HP) – C:\WINDOWS\System32\DRIVERS\HPZius12.sys – (HPZius12 [On_Demand | Stopped]) DRV - [2001-08-17 22:51:32 | 00,018,688 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\System32\DRIVERS\irsir.sys – (irsir [On_Demand | Running]) DRV - [2008-04-05 01:10:02 | 00,568,320 | ---- | M] (Eugene Gavrilov) – C:\WINDOWS\System32\drivers\kx.sys – (kxwdmdrv [On_Demand | Running]) DRV - [2007-02-22 10:15:56 | 00,137,216 | ---- | M] (Nokia) – C:\WINDOWS\System32\drivers\nmwcd.sys – (nmwcd [On_Demand | Stopped]) DRV - [2007-02-22 10:15:14 | 00,008,320 | ---- | M] (Nokia) – C:\WINDOWS\System32\drivers\nmwcdc.sys – (nmwcdc [On_Demand | Stopped]) DRV - [2007-02-22 10:15:14 | 00,012,288 | ---- | M] (Nokia) – C:\WINDOWS\System32\drivers\nmwcdcj.sys – (nmwcdcj [On_Demand | Stopped]) DRV - [2007-02-22 10:15:14 | 00,012,288 | ---- | M] (Nokia) – C:\WINDOWS\System32\drivers\nmwcdcm.sys – (nmwcdcm [On_Demand | Stopped]) DRV - [2001-08-17 23:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running]) DRV - [2007-03-08 01:51:00 | 00,043,528 | ---- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20 [boot | Running]) DRV - [2005-03-04 05:10:26 | 00,074,496 | ---- | M] (Realtek Semiconductor Corporation ) – C:\WINDOWS\System32\DRIVERS\Rtlnicxp.sys – (RTL8023xp [On_Demand | Running]) DRV - [2004-08-03 22:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) – C:\WINDOWS\System32\DRIVERS\RTL8139.SYS – (rtl8139 [On_Demand | Stopped]) DRV - [2007-11-13 12:25:55 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\System32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped]) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dl … r=iesearch IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm IE - HKU.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl … r=iesearch IE - HKU.DEFAULT.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0 IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl … r=iesearch IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0 IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0 IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0 IE - HKU\S-1-5-21-842925246-1957994488-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dl … r=iesearch IE - HKU\S-1-5-21-842925246-1957994488-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKU\S-1-5-21-842925246-1957994488-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl … r=iesearch IE - HKU\S-1-5-21-842925246-1957994488-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/ IE - HKU\S-1-5-21-842925246-1957994488-682003330-1003\S-1-5-21-842925246-1957994488-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0 ========== FireFox ========== FF - prefs.js…extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3 FF - HKLM\software\mozilla\Firefox\Extensions\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009-09-25 14:14:05 | 00,000,000 | —D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\Components: C:\Program Files\Mozilla Firefox\components [2009-09-25 13:06:31 | 00,000,000 | —D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009-09-25 13:06:31 | 00,000,000 | —D | M] [2008-09-12 18:15:07 | 00,000,000 | —D | M] – C:\Documents and Settings\kubaa\Dane aplikacji\mozilla\Extensions [2008-09-12 18:15:07 | 00,000,000 | —D | M] – C:\Documents and Settings\kubaa\Dane aplikacji\mozilla\Extensions{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2008-08-09 19:44:32 | 00,000,000 | —D | M] – C:\Documents and Settings\kubaa\Dane aplikacji\mozilla\Firefox\Profiles\h75kvatr.default\extensions [2008-09-12 18:15:10 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions [2009-09-25 13:06:31 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009-09-25 13:06:14 | 00,023,544 | ---- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009-09-25 13:06:14 | 00,137,208 | ---- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2002-11-01 20:15:54 | 00,086,125 | ---- | M] (JavaSoft / Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\NPJava11.dll [2002-11-01 20:15:54 | 00,086,125 | ---- | M] (JavaSoft / Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\NPJava12.dll [2002-11-01 20:15:54 | 00,086,125 | ---- | M] (JavaSoft / Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\NPJava13.dll [2002-11-01 20:15:54 | 00,086,125 | ---- | M] (JavaSoft / Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\NPJava32.dll [2003-01-13 16:08:06 | 00,499,712 | ---- | M] (Morgan Multimedia) – C:\Program Files\mozilla firefox\plugins\npjp2.dll [2002-11-01 20:15:54 | 00,086,122 | ---- | M] (JavaSoft / Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\NPJPI140_03.dll [2008-11-06 00:43:22 | 00,024,576 | ---- | M] (My Global Search) – C:\Program Files\mozilla firefox\plugins\NPMyGlSh.dll [2009-09-25 13:06:21 | 00,065,016 | ---- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll [2002-11-01 20:15:54 | 00,086,126 | ---- | M] (JavaSoft / Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\NPOJI610.dll [2004-11-09 02:43:08 | 00,139,305 | ---- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nppl3260.dll [2004-11-08 20:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2004-11-08 20:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2004-11-08 20:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2004-11-08 20:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2004-11-08 20:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2004-11-08 20:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll [2004-11-08 20:01:50 | 00,106,496 | ---- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll [2004-11-09 02:43:04 | 00,081,967 | ---- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nprpjplug.dll [2009-09-25 13:06:23 | 00,002,767 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2009-09-25 13:06:23 | 00,001,406 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2009-09-25 13:06:23 | 00,002,371 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml [2009-09-25 13:06:23 | 00,000,917 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2009-09-25 13:06:23 | 00,000,858 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2009-09-25 13:06:23 | 00,001,183 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2009-09-25 13:06:23 | 00,001,683 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml O1 HOSTS File: (742 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) O4 - HKLM…\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software) O4 - HKU.DEFAULT…\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.) O4 - HKU\S-1-5-18…\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.) O4 - HKU\S-1-5-21-842925246-1957994488-682003330-1003…\Run: [Gadu-Gadu] C:\Program Files\Gadu-Gadu\gg.exe (sms-express.com) O4 - HKLM…\RunOnce: [My Global Search Uninstall] C:\PROGRA~1\UNINST~1.DLL File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O7 - HKU.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-842925246-1957994488-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95 00 00 00 [binary data] O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra ‘Tools’ menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra ‘Tools’ menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O15 - HKLM…Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone. O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ipp - No CLSID value found O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.) O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - File not found O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008-08-09 16:10:28 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT – [NTFS] O32 - AutoRun File - [2006-05-09 20:36:18 | 00,000,034 | RHS- | M] () - F:\autorun.inf – [FAT32] O32 - AutoRun File - [2009-09-22 17:59:30 | 00,000,063 | RHS- | M] () - G:\autorun.inf – [FAT32] O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found ========== Files/Folders - Created Within 30 Days ========== [1 C:\WINDOWS\System32*.tmp files] [3 C:\WINDOWS*.tmp files] [2009-09-25 16:46:21 | 00,514,560 | ---- | C] (OldTimer Tools) – C:\Documents and Settings\kubaa\Pulpit\OTL.exe [2009-09-25 14:48:18 | 00,000,000 | —D | C] – C:\Documents and Settings\kubaa\Pulpit\HiJackThis [2009-09-25 14:45:18 | 00,000,000 | —D | C] – C:\WINDOWS\LastGood [2009-09-25 14:11:20 | 00,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer [2009-09-25 14:10:57 | 00,000,000 | —D | C] – C:\WINDOWS\System32\en-US [2009-09-25 14:10:36 | 00,000,000 | —D | C] – C:\Program Files\Reference Assemblies [2009-09-25 14:08:33 | 00,597,504 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe [2009-09-25 14:08:33 | 00,117,760 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll [2009-09-25 14:08:33 | 00,089,088 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll [2009-09-25 14:08:32 | 01,676,288 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll [2009-09-25 14:08:32 | 01,676,288 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll [2009-09-25 14:08:32 | 00,575,488 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsshhdr.dll [2009-09-25 14:08:32 | 00,575,488 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll [2009-09-24 22:58:30 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\Hewlett-Packard [2009-09-24 22:57:40 | 00,117,760 | ---- | C] (Hewlett-Packard Company) – C:\WINDOWS\System32\hpzll5ha.dll [2009-09-24 22:56:27 | 00,015,104 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\usbscan.sys [2009-09-24 22:50:09 | 00,000,000 | —D | C] – C:\Program Files\Hewlett-Packard [2009-09-24 22:49:08 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Hewlett-Packard [2009-09-24 22:47:20 | 00,021,568 | ---- | C] (HP) – C:\WINDOWS\System32\drivers\HPZius12.sys [2009-09-24 22:47:16 | 00,016,496 | ---- | C] (HP) – C:\WINDOWS\System32\drivers\HPZipr12.sys [2009-09-24 22:47:08 | 00,049,920 | ---- | C] (HP) – C:\WINDOWS\System32\drivers\HPZid412.sys [2009-09-24 22:46:55 | 00,267,864 | ---- | C] (Hewlett-Packard) – C:\WINDOWS\System32\hpzids01.dll [2009-09-24 22:46:35 | 00,364,544 | ---- | C] (Hewlett-Packard) – C:\WINDOWS\System32\hppldcoi.dll [2009-09-24 22:46:35 | 00,309,760 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\difxapi.dll [2009-09-24 22:46:35 | 00,303,104 | ---- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\hpovst10.dll [2009-09-24 22:46:34 | 00,675,840 | ---- | C] (Hewlett-Packard) – C:\WINDOWS\System32\hpowiax3.dll [2009-09-24 22:46:34 | 00,569,344 | ---- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\hpotscl3.dll [2009-09-24 22:45:44 | 00,000,000 | —D | C] – C:\Program Files\HP [2009-09-24 22:45:22 | 00,000,000 | -H-D | C] – C:\Config.Msi [2009-09-24 22:43:16 | 00,127,758 | ---- | C] () – C:\WINDOWS\hpoins14.dat [2009-09-24 22:43:16 | 00,001,996 | ---- | C] () – C:\WINDOWS\hpomdl14.dat [2009-09-24 22:41:20 | 00,310,310 | ---- | C] () – C:\WINDOWS\System32\autorun.inf [2009-09-24 14:57:33 | 00,025,856 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\usbprint.sys [2009-09-24 14:35:11 | 00,031,616 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\usbccgp.sys [2009-09-24 14:27:04 | 00,035,328 | ---- | C] () – C:\Documents and Settings\kubaa\Moje dokumenty\tata cv.doc [2009-09-23 21:32:51 | 00,000,000 | —D | C] – C:\WINDOWS\ServicePackFiles [2009-09-23 19:16:02 | 00,153,088 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\triedit.dll [2009-09-23 19:14:57 | 00,128,512 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dhtmled.ocx [2009-09-23 19:12:01 | 00,655,872 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstscax.dll [2009-09-17 01:14:31 | 00,009,995 | ---- | C] () – C:\Documents and Settings\kubaa\Pulpit\honda.docx [2008-09-25 16:24:29 | 00,000,761 | ---- | C] () – C:\WINDOWS\m3jp2k.ini [2008-09-25 16:24:29 | 00,000,702 | ---- | C] () – C:\WINDOWS\mmtvmj.ini [2008-09-25 16:24:28 | 00,000,714 | ---- | C] () – C:\WINDOWS\m3jpeg.ini [2008-08-17 18:24:18 | 00,000,086 | ---- | C] () – C:\WINDOWS\kit.ini [2008-08-17 18:10:35 | 00,041,068 | ---- | C] () – C:\WINDOWS\System32\ActPanel.dll [2008-08-09 21:13:43 | 00,019,968 | ---- | C] () – C:\WINDOWS\System32\cpuinf32.dll [2008-08-09 21:13:41 | 00,152,064 | ---- | C] () – C:\WINDOWS\System32\unrar.dll [2008-08-09 21:13:39 | 00,761,856 | ---- | C] () – C:\WINDOWS\System32\xvidcore.dll [2008-08-09 16:20:50 | 00,005,824 | ---- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS [2005-12-09 00:19:24 | 00,009,728 | ---- | C] () – C:\WINDOWS\System32\ff_vfw.dll [2005-12-07 12:31:00 | 00,202,752 | R— | C] () – C:\WINDOWS\System32\CddbCdda.dll [2005-11-05 18:46:26 | 00,000,537 | ---- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest [2001-07-22 00:16:20 | 00,000,639 | ---- | C] () – C:\WINDOWS\win.ini [2001-07-22 00:15:52 | 00,009,415 | ---- | C] () – C:\WINDOWS\system.ini ========== Files - Modified Within 30 Days ========== [1 C:\WINDOWS\System32*.tmp files] [3 C:\WINDOWS*.tmp files] [2009-09-25 16:46:22 | 00,514,560 | ---- | M] (OldTimer Tools) – C:\Documents and Settings\kubaa\Pulpit\OTL.exe [2009-09-25 14:37:35 | 00,000,006 | -H-- | M] () – C:\WINDOWS\tasks\SA.DAT [2009-09-25 14:37:22 | 00,002,048 | --S- | M] () – C:\WINDOWS\bootstat.dat [2009-09-25 14:37:18 | 00,270,984 | ---- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT [2009-09-25 14:13:21 | 01,092,142 | ---- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI [2009-09-25 14:13:21 | 00,493,976 | ---- | M] () – C:\WINDOWS\System32\perfh015.dat [2009-09-25 14:13:21 | 00,435,396 | ---- | M] () – C:\WINDOWS\System32\perfh009.dat [2009-09-25 14:13:21 | 00,085,136 | ---- | M] () – C:\WINDOWS\System32\perfc015.dat [2009-09-25 14:13:21 | 00,068,292 | ---- | M] () – C:\WINDOWS\System32\perfc009.dat [2009-09-25 13:47:22 | 00,002,645 | ---- | M] () – C:\WINDOWS\System32\CONFIG.NT [2009-09-25 00:11:54 | 00,001,374 | ---- | M] () – C:\WINDOWS\imsins.BAK [2009-09-25 00:10:50 | 04,287,760 | -H-- | M] () – C:\Documents and Settings\kubaa\Ustawienia lokalne\Dane aplikacji\IconCache.db [2009-09-24 22:51:54 | 00,127,758 | ---- | M] () – C:\WINDOWS\hpoins14.dat [2009-09-24 22:32:10 | 00,009,415 | ---- | M] () – C:\WINDOWS\system.ini [2009-09-24 22:32:10 | 00,000,639 | ---- | M] () – C:\WINDOWS\win.ini [2009-09-24 22:32:10 | 00,000,211 | RHS- | M] () – C:\boot.ini [2009-09-24 14:27:05 | 00,035,328 | ---- | M] () – C:\Documents and Settings\kubaa\Moje dokumenty\tata cv.doc [2009-09-21 11:00:25 | 00,002,206 | ---- | M] () – C:\WINDOWS\System32\wpa.dbl [2009-09-17 01:14:32 | 00,009,995 | ---- | M] () – C:\Documents and Settings\kubaa\Pulpit\honda.docx [2009-09-15 12:59:36 | 01,279,968 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe [2009-09-15 12:56:21 | 00,093,424 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys [2009-09-15 12:56:14 | 00,094,160 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys [2009-09-15 12:55:30 | 00,114,768 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys [2009-09-15 12:55:19 | 00,020,560 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys [2009-09-15 12:54:30 | 00,052,368 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys [2009-09-15 12:54:21 | 00,023,152 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys [2009-09-15 12:53:24 | 00,027,408 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys [2009-09-15 12:53:01 | 00,097,480 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\AvastSS.scr ========== LOP Check ========== [2009-09-24 22:58:30 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Dane aplikacji [2008-08-18 00:20:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\Installations [2008-08-18 00:28:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Dane aplikacji\PC Suite [2008-08-09 16:58:44 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Default User\Dane aplikacji [2008-12-12 18:23:40 | 00,000,000 | RH-D | M] – C:\Documents and Settings\kubaa\Dane aplikacji [2008-08-09 19:26:51 | 00,000,000 | —D | M] – C:\Documents and Settings\kubaa\Dane aplikacji\ATI [2008-08-10 15:38:48 | 00,000,000 | —D | M] – C:\Documents and Settings\kubaa\Dane aplikacji\Jpeg Resampler [2008-08-18 00:31:48 | 00,000,000 | —D | M] – C:\Documents and Settings\kubaa\Dane aplikacji\Nokia [2008-08-18 00:28:47 | 00,000,000 | —D | M] – C:\Documents and Settings\kubaa\Dane aplikacji\PC Suite [2008-08-09 16:16:40 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Dane aplikacji [2008-08-09 16:16:39 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Dane aplikacji [2001-07-22 00:17:50 | 00,000,065 | RH-- | M] () – C:\WINDOWS\Tasks\desktop.ini [2009-09-25 14:37:35 | 00,000,006 | -H-- | M] () – C:\WINDOWS\Tasks\SA.DAT ========== Purity Check ========== < End of report >