OTL logfile created on: 2009-12-17 19:10:31 - Run 1 OTL by OldTimer - Version 3.1.17.0 Folder = C:\Documents and Settings\Karol\Desktop\antispyware Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.11) Locale: 00000415 | Country: Poland | Language: PLK | Date Format: yyyy-MM-dd 1023,36 Mb Total Physical Memory | 695,13 Mb Available Physical Memory | 67,93% Memory free 1,65 Gb Paging File | 1,44 Gb Available in Paging File | 87,24% Paging File free Paging file location(s): C:\pagefile.sys 768 1536 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 20,00 Gb Total Space | 2,40 Gb Free Space | 12,00% Space Free | Partition Type: NTFS Drive D: | 17,24 Gb Total Space | 2,19 Gb Free Space | 12,71% Space Free | Partition Type: FAT32 E: Drive not present or media not loaded Drive F: | 212,44 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: IMMORTAL Current User Name: Karol Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard ========== Processes (SafeList) ========== PRC - [2009-12-17 19:04:15 | 00,538,112 | ---- | M] (OldTimer Tools) – C:\Documents and Settings\Karol\Desktop\antispyware\OTL.exe PRC - [2009-06-16 18:13:20 | 00,198,160 | ---- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe PRC - [2007-09-06 12:28:18 | 00,110,592 | ---- | M] (Apple, Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe PRC - [2007-04-05 10:29:28 | 00,208,896 | ---- | M] (UASSOFT.COM) – C:\Program Files\Mouse Driver\KMWDSrv.exe PRC - [2007-04-04 11:30:40 | 00,327,680 | ---- | M] (UASSOFT.COM) – C:\Program Files\Mouse Driver\KMProcess.exe PRC - [2007-03-28 00:38:48 | 00,397,312 | ---- | M] (UASSOFT.COM) – C:\Program Files\Mouse Driver\KMCONFIG.exe PRC - [2007-03-06 14:51:14 | 00,212,992 | ---- | M] (UASSOFT.COM) – C:\Program Files\Mouse Driver\StartAutorun.exe PRC - [2006-10-17 11:04:40 | 00,622,080 | --S- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe PRC - [2006-08-22 16:18:10 | 00,036,864 | ---- | M] () – C:\Program Files\SanDisk\Sansa Updater\SansaSvr.exe PRC - [2006-05-09 18:03:08 | 00,126,976 | ---- | M] () – C:\WINDOWS\system32\UAService7.exe PRC - [2004-08-04 13:00:00 | 01,032,192 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe PRC - [2004-06-10 22:44:56 | 00,376,832 | ---- | M] () – C:\WINDOWS\system32\ati2evxx.exe PRC - [1998-07-23 16:06:26 | 00,067,584 | ---- | M] (IntelliQuest Communications, Inc.) – C:\Program Files\Corel\Graphics9\Register\Remind32.exe ========== Modules (SafeList) ========== MOD - [2009-12-17 19:04:15 | 00,538,112 | ---- | M] (OldTimer Tools) – C:\Documents and Settings\Karol\Desktop\antispyware\OTL.exe MOD - [2006-08-25 16:45:55 | 01,054,208 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll MOD - [2003-10-03 13:21:00 | 00,174,592 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\system\framedyn.dll ========== Win32 Services (SafeList) ========== SRV - [2007-09-26 13:41:56 | 00,503,608 | ---- | M] (Apple Inc.) [On_Demand | Stopped] – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service) SRV - [2007-09-06 12:28:18 | 00,110,592 | ---- | M] (Apple, Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device) SRV - [2007-04-05 10:29:28 | 00,208,896 | ---- | M] (UASSOFT.COM) [Auto | Running] – C:\Program Files\Mouse Driver\KMWDSrv.exe – (KMWDSERVICE) SRV - [2006-08-22 16:18:10 | 00,036,864 | ---- | M] () [Auto | Running] – C:\Program Files\SanDisk\Sansa Updater\SansaSvr.exe – (SansaService) SRV - [2006-05-09 18:03:08 | 00,126,976 | ---- | M] () [Auto | Running] – C:\WINDOWS\system32\UAService7.exe – (UserAccess7) SecuROM User Access Service (V7) SRV - [2006-05-08 05:20:40 | 00,074,360 | ---- | M] (Autodesk, Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe – (Autodesk Licensing Service) SRV - [2005-04-04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe – (IDriverT) SRV - [2004-07-15 00:49:26 | 00,032,768 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe – (aspnet_state) SRV - [2004-06-10 22:44:56 | 00,376,832 | ---- | M] () [Auto | Running] – C:\WINDOWS\system32\ati2evxx.exe – (Ati HotKey Poller) SRV - [2003-07-28 20:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose) ========== Driver Services (SafeList) ========== DRV - [2008-01-17 18:16:34 | 00,163,644 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\secdrv.sys – (Secdrv) DRV - [2007-03-29 15:00:16 | 00,017,024 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\KMWDFilter.SYS – (KMWDFilter) DRV - [2006-09-19 13:44:04 | 00,015,664 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys – (GEARAspiWDM) DRV - [2006-06-22 06:38:07 | 00,223,128 | ---- | M] (Alcohol Soft Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\Drivers\vaxscsi.sys – (vaxscsi) DRV - [2006-06-18 16:45:41 | 00,642,560 | ---- | M] () [Kernel | Boot | Running] – C:\WINDOWS\System32\Drivers\sptd.sys – (sptd) DRV - [2005-01-24 14:38:04 | 00,084,512 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ss_mdm.sys – (ss_mdm) DRV - [2005-01-24 14:38:04 | 00,006,064 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ss_mdfl.sys – (ss_mdfl) DRV - [2005-01-24 14:38:00 | 00,052,384 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ss_bus.sys – (ss_bus) Samsung Mobile USB Device 1.0 driver (WDM) DRV - [2004-08-09 12:33:26 | 00,114,016 | ---- | M] (Protection Technology) [Kernel | Boot | Running] – C:\WINDOWS\System32\drivers\prohlp02.sys – (prohlp02) DRV - [2004-08-09 12:29:28 | 00,053,920 | ---- | M] (Protection Technology) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\prodrv06.sys – (prodrv06) DRV - [2004-08-04 13:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ptilink.sys – (Ptilink) DRV - [2004-08-03 23:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RTL8139.sys – (rtl8139) Realtek RTL8139(A/B/C) DRV - [2004-07-23 16:43:26 | 00,159,488 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\vinyl97.sys – (VIAudio) Vinyl AC’97 Audio Controller (WDM) DRV - [2004-07-19 15:49:54 | 00,007,040 | ---- | M] (Protection Technology) [Kernel | Boot | Running] – C:\WINDOWS\System32\drivers\prosync1.sys – (prosync1) DRV - [2004-06-10 22:57:04 | 00,746,496 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag) DRV - [2004-05-07 10:44:54 | 00,182,688 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP) DRV - [2004-04-30 08:37:02 | 00,160,640 | ---- | M] ( ) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\a347bus.sys – (a347bus) DRV - [2004-04-30 08:33:00 | 00,005,248 | ---- | M] ( ) [Kernel | Boot | Running] – C:\WINDOWS\System32\Drivers\a347scsi.sys – (a347scsi) DRV - [2004-03-08 03:43:10 | 01,657,344 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\w22n51.sys – (w22n51) Intel® DRV - [2004-02-12 01:18:00 | 00,191,092 | ---- | M] (O2 Micro ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\o2mmb.sys – (CONAN) DRV - [2004-01-27 23:00:00 | 00,006,100 | ---- | M] (O2 Micro) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\MbxStby.sys – (MbxStby) DRV - [2003-12-01 16:20:52 | 00,004,832 | ---- | M] (Protection Technology) [Kernel | Boot | Running] – C:\WINDOWS\System32\drivers\sfhlp01.sys – (sfhlp01) DRV - [2002-07-17 08:05:10 | 00,016,512 | ---- | M] (Adaptec) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\ASPI32.SYS – (Aspi32) DRV - [2001-11-08 07:53:54 | 00,018,120 | ---- | M] ( ) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\gt680x.sys – (GT680x) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0 ========== FireFox ========== FF - prefs.js…browser.search.selectedEngine: “Google” FF - prefs.js…browser.startup.homepage: “http://www.google.pl/” [2006-05-08 12:20:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Karol\Application Data\Mozilla\Firefox\Profiles\qisb5hgl.default\extensions [2009-03-09 17:01:38 | 00,120,296 | ---- | M] ( ) – C:\Program Files\Mozilla Firefox\plugins\npganymedenet.dll [2006-05-10 18:22:43 | 00,626,688 | ---- | M] (Ganymede Technologies) – C:\Program Files\Mozilla Firefox\plugins\NPSNOOKER.dll [2006-05-08 13:00:44 | 01,312,392 | ---- | M] () – C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll O1 HOSTS File: (27 bytes) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found. O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (IE to GetRight Helper) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll (Headlight Software, Inc.) O2 - BHO: (RedTube To ALLPlayer) - {41F21158-4211-4D32-9E02-D57B19661561} - C:\Program Files\ALLPlayer\RedTubeToALLPlayer.dll (ALLPlayer.org) O2 - BHO: (YouTube To ALLPlayer) - {61DB16C5-B733-43F4-872E-B20DC9E72740} - C:\Program Files\ALLPlayer\YouTubeToALLPlayer.dll (ALLPlayer.org) O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc.) O3 - HKCU…\Toolbar\WebBrowser: (no name) - {1CE4EE89-2D5C-4361-AF3B-D902AB545381} - No CLSID value found. O4 - HKLM…\Run: [iSUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation) O4 - HKLM…\Run: [KMCONFIG] C:\Program Files\Mouse Driver\StartAutorun.exe KMConfig.exe File not found O4 - HKLM…\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.) O4 - HKLM…\Run: [sysgif32] C:\WINDOWS\temp~TMC.tmp () O4 - HKLM…\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) O4 - HKCU…\Run: [ALLUpdate] C:\Program Files\ALLPlayer\ALLUpdate.exe () O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Przyspieszenie uruchomienia programu AutoCAD.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe (Autodesk, Inc) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ulead Photo Express 3.0 SE Calendar Checker.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 3.0 SE\CalCheck.exe (Ulead Systems, Inc.) O4 - Startup: C:\Documents and Settings\Karol\Start Menu\Programs\Startup\Rejestrowanie produktów Corela.lnk = C:\Program Files\Corel\Graphics9\Register\Remind32.exe (IntelliQuest Communications, Inc.) O4 - Startup: C:\Documents and Settings\Karol\Start Menu\Programs\Startup\siszyd32.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data] O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRDownload.htm () O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRBrowse.htm () O9 - Extra ‘Tools’ menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll (Sun Microsystems, Inc.) O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars) O9 - Extra Button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe (Microgaming) O15 - HKLM…Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/ … vc1dmo.cab (Reg Error: Key error.) O16 - DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} http://download05.managerzone.com/socce … Loader.cab (PowerLoader Class) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microso … 0072781851 (WUWebControl Class) O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (MksSkanerOnline Class) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microso … 0072765207 (MUWebControl Class) O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} http://dl.uc.sina.com/cab/downloader.cab (DLoader Class) O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} http://67.15.101.3/g_bin/pl/poker_2_0_0_43.cab (GameDesire Poker Games) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinsta … s-i586.cab (Java Plug-in 1.5.0_06) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl … rashim.cab (Reg Error: Key error.) O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://80.55.165.82:8080/activex/AxisCamControl.cab (CamImage Class) O16 - DPF: {A6212120-01D4-11D5-9A39-0080C8D85044} http://67.15.101.3/g_bin/pl/slots70_2_0_0_30.cab (GameDesire Slots 70th) O16 - DPF: {A9ED6AA2-D9D4-4D71-9586-E293E2E3580B} http://67.15.101.3/g_bin/pl/marbles_2_0_0_26.cab (GameDesire Marbles&Diamonds&Runes) O16 - DPF: {BFA1F11D-3121-AFE1-4112-894323212DAC} http://67.15.101.3/g_bin/pl/words_2_0_0_42.cab (GameDesire Word Games) O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinsta … s-i586.cab (Java Plug-in 1.5.0_06) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinsta … s-i586.cab (Java Plug-in 1.5.0_06) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s … wflash.cab (Shockwave Flash Object) O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} http://67.15.101.33/g_bin/pl/billard8_2_0_0_35.cab (GameDesire Pool 8) O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C5} http://67.15.101.3/g_bin/pl/snooker_2_0_0_35.cab (GameDesire Snooker) O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} http://pdl.stream.aol.com/downloads/aol … _en_dl.cab (IWinAmpActiveX Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.172.224.160 89.228.6.83 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - AppInit_DLLs: (G) - File not found O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll () O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006-05-05 17:59:23 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT – [NTFS] O32 - AutoRun File - [2009-01-31 17:12:56 | 00,000,000 | RHSD | M] - C:\autorun.inf – [NTFS] O32 - AutoRun File - [2009-01-31 17:12:58 | 00,000,000 | RHSD | M] - D:\autorun.inf – [FAT32] O32 - AutoRun File - [2003-10-30 18:06:22 | 00,023,040 | R— | M] () - F:\autorun.exe – [CDFS] O32 - AutoRun File - [2003-10-30 18:06:22 | 00,000,027 | R— | M] () - F:\autorun.inf – [CDFS] O33 - MountPoints2{2a482891-5dc2-11de-8648-00030d2a34d0}\Shell - “” = AutoRun O33 - MountPoints2{2a482891-5dc2-11de-8648-00030d2a34d0}\Shell\AutoRun - “” = Auto&Play O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - comfile [open] – “%1” %* O35 - exefile [open] – “%1” %* ========== Files/Folders - Created Within 30 Days ========== [2009-12-17 19:05:03 | 00,000,000 | —D | C] – C:\Documents and Settings\Karol\Desktop\antispyware [2009-12-17 18:35:26 | 00,000,000 | —D | C] – C:\WINDOWS\LastGood.Tmp [2009-12-17 18:35:24 | 00,064,288 | ---- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys [2009-12-17 18:33:18 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data~0 [2009-12-17 18:32:48 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft [2009-11-26 17:16:01 | 00,000,000 | —D | C] – C:\Documents and Settings\Karol\Desktop\fryzury [2009-11-24 18:19:42 | 00,000,000 | -HSD | C] – C:\Documents and Settings\Karol\UserData [2009-11-22 12:48:14 | 00,000,000 | —D | C] – C:\Documents and Settings\Karol\Desktop\2.10 Produkcja kabli swiatłowodowych [2009-11-21 12:47:30 | 00,000,000 | —D | C] – C:\Documents and Settings\Karol\Desktop\2.9 Łączenie światłowodów [2009-02-25 00:32:29 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft [2009-02-25 00:30:41 | 00,000,000 | --SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft [2009-02-25 00:30:41 | 00,000,000 | --SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft [2009-02-25 00:30:41 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft [2007-11-10 20:23:02 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple [2007-08-23 20:33:59 | 00,160,640 | ---- | C] ( ) – C:\WINDOWS\System32\drivers\a347bus.sys [2007-08-23 20:33:59 | 00,005,248 | ---- | C] ( ) – C:\WINDOWS\System32\drivers\a347scsi.sys [2004-06-11 01:27:12 | 00,131,072 | ---- | C] ( ) – C:\WINDOWS\System32\ATIDEMGR.dll [2001-11-08 07:53:54 | 00,018,120 | ---- | C] ( ) – C:\WINDOWS\System32\drivers\gt680x.sys [9 C:\WINDOWS*.tmp files -> C:\WINDOWS*.tmp ->] [5 C:\WINDOWS\System32*.tmp files -> C:\WINDOWS\System32*.tmp ->] [1 C:*.tmp files -> C:*.tmp ->] ========== Files - Modified Within 30 Days ========== [2009-12-17 19:09:42 | 00,001,734 | ---- | M] () – C:\Documents and Settings\Karol\Desktop\HijackThis.lnk [2009-12-17 18:50:21 | 27,000,832 | -H-- | M] () – C:\Documents and Settings\Karol\NTUSER.DAT [2009-12-17 18:43:39 | 00,000,006 | -H-- | M] () – C:\WINDOWS\tasks\SA.DAT [2009-12-17 18:43:38 | 00,000,458 | ---- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [2009-12-17 18:43:37 | 00,002,048 | --S- | M] () – C:\WINDOWS\bootstat.dat [2009-12-17 18:43:29 | 00,000,000 | ---- | M] () – C:\WINDOWS\MEMORY.DMP [2009-12-17 18:42:28 | 00,697,856 | ---- | M] () – C:\WINDOWS\System32\drivers\voodijk.sys [2009-12-17 18:39:59 | 00,000,278 | -HS- | M] () – C:\Documents and Settings\Karol\ntuser.ini [2009-12-17 18:14:11 | 00,000,116 | ---- | M] () – C:\WINDOWS\System32\fjhdyfhsn.bat [2009-12-16 22:57:15 | 00,000,363 | ---- | M] () – C:\WINDOWS\slt.ini [2009-12-16 18:37:38 | 00,697,856 | ---- | M] () – C:\WINDOWS\System32\drivers\eojbh.sys [2009-12-15 19:18:23 | 00,000,004 | ---- | M] () – C:\Documents and Settings\Karol\Application Data\avdrn.dat [2009-12-15 16:43:01 | 00,000,284 | ---- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job [2009-12-14 21:33:17 | 00,002,335 | ---- | M] () – C:\Documents and Settings\Karol\Desktop\MZ Manager 2.4.lnk [2009-12-13 12:50:20 | 00,000,132 | ---- | M] () – C:\WINDOWS\winamp.ini [2009-12-10 17:40:39 | 00,002,206 | ---- | M] () – C:\WINDOWS\System32\wpa.dbl [2009-12-09 17:46:30 | 00,047,706 | ---- | M] () – C:\WINDOWS\bestplayer.bbt [2009-12-09 17:46:30 | 00,001,200 | ---- | M] () – C:\WINDOWS\bestplayer.ini [2009-12-09 17:46:30 | 00,000,000 | ---- | M] () – C:\WINDOWS\bestplayer.bpp [2009-12-06 20:30:18 | 00,000,116 | ---- | M] () – C:\WINDOWS\NeroDigital.ini [2009-12-02 14:19:06 | 00,064,288 | ---- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys [2009-11-28 12:37:26 | 00,056,481 | ---- | M] () – C:\Documents and Settings\Karol\Desktop\Search.pdf [2009-11-22 15:28:08 | 11,703,8468 | ---- | M] () – C:\Documents and Settings\Karol\Desktop\Vademecum_Teleinformatyka_III.rar [2009-11-22 13:34:54 | 00,346,243 | ---- | M] () – C:\Documents and Settings\Karol\Desktop\wstep_A-M-A.pdf [2009-11-22 13:34:47 | 00,468,480 | ---- | M] () – C:\Documents and Settings\Karol\Desktop\070403_PK-01_opis_1.5.doc [2009-11-22 13:10:40 | 00,315,137 | ---- | M] () – C:\Documents and Settings\Karol\Desktop\Nabuda.pdf [2009-11-22 13:08:35 | 06,016,000 | ---- | M] () – C:\Documents and Settings\Karol\Desktop\nsk_wyklad2_5_dwdm_2003.ppt [2009-11-22 13:07:42 | 00,253,758 | ---- | M] () – C:\Documents and Settings\Karol\Desktop\praca mgr.pdf [2009-11-22 13:03:48 | 00,256,100 | ---- | M] () – C:\Documents and Settings\Karol\Desktop\0400.pdf [9 C:\WINDOWS*.tmp files -> C:\WINDOWS*.tmp ->] [5 C:\WINDOWS\System32*.tmp files -> C:\WINDOWS\System32*.tmp ->] [1 C:*.tmp files -> C:*.tmp ->] ========== Files Created - No Company Name ========== [2009-12-17 19:09:42 | 00,001,734 | ---- | C] () – C:\Documents and Settings\Karol\Desktop\HijackThis.lnk [2009-12-17 18:40:16 | 00,000,458 | ---- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [2009-12-17 18:14:37 | 00,697,856 | ---- | C] () – C:\WINDOWS\System32\drivers\voodijk.sys [2009-12-17 18:14:11 | 00,000,116 | ---- | C] () – C:\WINDOWS\System32\fjhdyfhsn.bat [2009-12-15 19:18:54 | 00,697,856 | ---- | C] () – C:\WINDOWS\System32\drivers\eojbh.sys [2009-12-15 19:18:31 | 00,000,016 | ---- | C] () – C:\Documents and Settings\NetworkService\Application Data\fvgqad.dat [2009-12-15 19:18:23 | 00,000,004 | ---- | C] () – C:\Documents and Settings\Karol\Application Data\avdrn.dat [2009-11-28 12:37:26 | 00,056,481 | ---- | C] () – C:\Documents and Settings\Karol\Desktop\Search.pdf [2009-11-22 15:27:49 | 11,703,8468 | ---- | C] () – C:\Documents and Settings\Karol\Desktop\Vademecum_Teleinformatyka_III.rar [2009-11-22 13:34:51 | 00,346,243 | ---- | C] () – C:\Documents and Settings\Karol\Desktop\wstep_A-M-A.pdf [2009-11-22 13:34:43 | 00,468,480 | ---- | C] () – C:\Documents and Settings\Karol\Desktop\070403_PK-01_opis_1.5.doc [2009-11-22 13:10:37 | 00,315,137 | ---- | C] () – C:\Documents and Settings\Karol\Desktop\Nabuda.pdf [2009-11-22 13:08:35 | 06,016,000 | ---- | C] () – C:\Documents and Settings\Karol\Desktop\nsk_wyklad2_5_dwdm_2003.ppt [2009-11-22 13:07:38 | 00,253,758 | ---- | C] () – C:\Documents and Settings\Karol\Desktop\praca mgr.pdf [2009-11-22 13:03:46 | 00,256,100 | ---- | C] () – C:\Documents and Settings\Karol\Desktop\0400.pdf [2009-04-18 13:47:54 | 00,000,492 | ---- | C] () – C:\WINDOWS\MAXLINK.INI [2009-04-16 19:02:37 | 00,000,569 | ---- | C] () – C:\WINDOWS\ULEAD32.INI [2009-02-14 13:31:50 | 00,130,048 | ---- | C] () – C:\WINDOWS\System32\xvidvfw.dll [2009-02-14 13:31:38 | 00,258,048 | ---- | C] () – C:\WINDOWS\System32\libFLAC.dll [2009-02-14 13:29:36 | 00,108,032 | ---- | C] () – C:\WINDOWS\System32\avi.dll [2009-02-14 13:29:35 | 00,141,312 | ---- | C] () – C:\WINDOWS\System32\mp4.dll [2009-02-14 13:29:32 | 00,148,992 | ---- | C] () – C:\WINDOWS\System32\mkx.dll [2009-02-14 13:29:29 | 00,159,744 | ---- | C] () – C:\WINDOWS\System32\mmfinfo.dll [2009-02-14 13:29:27 | 00,120,832 | ---- | C] () – C:\WINDOWS\System32\ogm.dll [2009-02-14 13:29:25 | 00,163,840 | ---- | C] () – C:\WINDOWS\System32\ts.dll [2009-02-14 13:29:22 | 00,079,360 | ---- | C] () – C:\WINDOWS\System32\mkzlib.dll [2009-02-14 13:29:20 | 00,023,552 | ---- | C] () – C:\WINDOWS\System32\mkunicode.dll [2009-02-14 13:28:29 | 00,560,802 | ---- | C] () – C:\WINDOWS\System32\libmplayer.dll [2009-02-14 13:28:20 | 00,145,609 | ---- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll [2009-02-14 13:28:17 | 04,302,881 | ---- | C] () – C:\WINDOWS\System32\libavcodec.dll [2009-02-14 13:27:08 | 00,093,184 | ---- | C] () – C:\WINDOWS\System32\ff_wmv9.dll [2009-02-14 13:27:06 | 00,113,152 | ---- | C] () – C:\WINDOWS\System32\ff_unrar.dll [2009-02-14 13:27:04 | 00,183,296 | ---- | C] () – C:\WINDOWS\System32\ff_samplerate.dll [2009-02-14 13:27:01 | 00,178,688 | ---- | C] () – C:\WINDOWS\System32\ff_libmad.dll [2009-02-14 13:26:58 | 00,485,888 | ---- | C] () – C:\WINDOWS\System32\ff_libfaad2.dll [2009-02-14 13:26:50 | 00,257,024 | ---- | C] () – C:\WINDOWS\System32\ff_libdts.dll [2009-02-14 13:26:46 | 00,142,848 | ---- | C] () – C:\WINDOWS\System32\ff_liba52.dll [2009-02-14 13:26:40 | 02,041,363 | ---- | C] () – C:\WINDOWS\System32\x264vfw.dll [2009-02-14 13:26:07 | 00,237,568 | ---- | C] () – C:\WINDOWS\System32\OggDS.dll [2009-02-14 13:26:03 | 00,921,600 | ---- | C] () – C:\WINDOWS\System32\vorbisenc.dll [2009-02-14 13:25:48 | 00,188,416 | ---- | C] () – C:\WINDOWS\System32\vorbis.dll [2009-02-14 13:25:45 | 00,045,056 | ---- | C] () – C:\WINDOWS\System32\ogg.dll [2009-01-24 10:50:45 | 00,000,363 | ---- | C] () – C:\WINDOWS\slt.ini [2009-01-20 09:51:00 | 00,383,238 | ---- | C] () – C:\WINDOWS\System32\libmp3lame-0.dll [2009-01-20 09:50:59 | 03,086,336 | ---- | C] () – C:\WINDOWS\System32\NCMedia.dll [2009-01-20 09:50:59 | 03,086,336 | ---- | C] () – C:\WINDOWS\System32\flvvideo.dll [2008-10-18 20:25:37 | 00,000,050 | ---- | C] () – C:\WINDOWS\MegaManager.INI [2008-03-09 21:05:39 | 00,000,019 | ---- | C] () – C:\WINDOWS\powerplayer.ini [2008-03-09 21:05:37 | 00,000,382 | ---- | C] () – C:\WINDOWS\psnetwork.ini [2008-03-08 22:53:27 | 00,000,056 | ---- | C] () – C:\WINDOWS\EntPack.ini [2008-03-08 19:10:18 | 00,000,661 | ---- | C] () – C:\WINDOWS\mamba.ini [2008-01-10 17:06:21 | 00,000,025 | ---- | C] () – C:\WINDOWS\SW_Win2146X32.DLL [2008-01-10 17:05:40 | 00,002,490 | ---- | C] () – C:\WINDOWS\CD_SearchHistory.INI [2007-12-13 17:38:03 | 00,003,096 | ---- | C] () – C:\WINDOWS\PSPICEEV.INI [2007-12-13 17:37:51 | 00,176,128 | ---- | C] () – C:\WINDOWS\System32\lffax60n.dll [2007-12-13 17:37:51 | 00,141,824 | ---- | C] () – C:\WINDOWS\System32\lfcmp60n.dll [2007-12-13 17:37:51 | 00,110,080 | ---- | C] () – C:\WINDOWS\System32\lfpng60n.dll [2007-12-13 17:37:51 | 00,046,080 | ---- | C] () – C:\WINDOWS\System32\lftif60n.dll [2007-12-13 17:37:51 | 00,043,008 | ---- | C] () – C:\WINDOWS\System32\ltfil60n.dll [2007-12-13 17:37:51 | 00,023,552 | ---- | C] () – C:\WINDOWS\System32\lfpcx60n.dll [2007-12-13 17:37:51 | 00,022,528 | ---- | C] () – C:\WINDOWS\System32\lfpct60n.dll [2007-12-13 17:37:51 | 00,022,528 | ---- | C] () – C:\WINDOWS\System32\lfeps60n.dll [2007-12-13 17:37:51 | 00,022,016 | ---- | C] () – C:\WINDOWS\System32\lfbmp60n.dll [2007-12-13 17:37:51 | 00,020,480 | ---- | C] () – C:\WINDOWS\System32\lfpsd60n.dll [2007-12-13 17:37:51 | 00,019,968 | ---- | C] () – C:\WINDOWS\System32\lftga60n.dll [2007-12-13 17:37:51 | 00,019,456 | ---- | C] () – C:\WINDOWS\System32\lfwpg60n.dll [2007-12-13 17:37:51 | 00,019,456 | ---- | C] () – C:\WINDOWS\System32\lfwmf60n.dll [2007-12-13 17:37:51 | 00,018,432 | ---- | C] () – C:\WINDOWS\System32\lfmsp60n.dll [2007-12-13 17:37:51 | 00,017,920 | ---- | C] () – C:\WINDOWS\System32\lfmac60n.dll [2007-12-13 17:37:51 | 00,017,920 | ---- | C] () – C:\WINDOWS\System32\implode.dll [2007-11-10 20:25:55 | 00,003,682 | ---- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\55FD2231-2E8B-46CE-96C3-4EAF8E862DDE.txt [2007-08-17 07:12:57 | 00,004,574 | ---- | C] () – C:\Documents and Settings\Karol\Local Settings\Application Data\55FD2231-2E8B-46CE-96C3-4EAF8E862DDE.txt [2007-08-16 19:46:10 | 00,044,544 | ---- | C] () – C:\WINDOWS\System32\blrqnibh.dll.bak [2007-07-23 21:42:01 | 00,003,264 | ---- | C] () – C:\Documents and Settings\Karol\Local Settings\Application Data\C5C2B37B-2A21-4308-83DB-5BC47C3CD3AA.txt [2007-07-23 21:38:50 | 00,752,128 | ---- | C] () – C:\WINDOWS\System32\adnxzwga.dll.bak [2007-07-23 21:38:34 | 00,045,056 | ---- | C] () – C:\WINDOWS\System32\bnbzphcp.dll.bak [2007-06-07 18:40:24 | 00,000,134 | ---- | C] () – C:\WINDOWS\naglos.INI [2007-03-08 17:40:24 | 00,112,688 | ---- | C] () – C:\WINDOWS\System32\shw32.dll [2006-12-13 18:42:24 | 00,000,315 | ---- | C] () – C:\WINDOWS\gmer.ini [2006-12-13 18:42:22 | 00,565,311 | ---- | C] () – C:\WINDOWS\gmer.dll [2006-10-15 18:38:41 | 00,000,023 | ---- | C] () – C:\WINDOWS\cdplayer.ini [2006-10-06 06:43:33 | 00,000,393 | ---- | C] () – C:\WINDOWS\fmtap.INI [2006-09-12 08:14:02 | 00,000,057 | ---- | C] () – C:\WINDOWS\System32\peer.ini [2006-06-22 06:38:28 | 00,034,308 | ---- | C] () – C:\WINDOWS\System32\BASSMOD.dll [2006-06-18 16:45:41 | 00,642,560 | ---- | C] () – C:\WINDOWS\System32\drivers\sptd.sys [2006-06-18 16:45:41 | 00,096,256 | ---- | C] () – C:\WINDOWS\System32\drivers\sptd8829.sys [2006-05-20 10:12:55 | 00,000,132 | ---- | C] () – C:\WINDOWS\winamp.ini [2006-05-11 14:29:46 | 00,000,324 | ---- | C] () – C:\WINDOWS\wininit.ini [2006-05-11 00:33:36 | 00,001,200 | ---- | C] () – C:\WINDOWS\bestplayer.ini [2006-05-09 19:40:23 | 00,000,116 | ---- | C] () – C:\WINDOWS\NeroDigital.ini [2006-05-09 19:40:20 | 00,165,888 | ---- | C] () – C:\Documents and Settings\Karol\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2006-05-08 19:48:15 | 00,204,800 | ---- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll [2006-05-08 19:48:14 | 00,200,704 | ---- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll [2006-05-08 19:48:14 | 00,192,512 | ---- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll [2006-05-08 19:48:14 | 00,192,512 | ---- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll [2006-05-08 19:48:14 | 00,188,416 | ---- | C] () – C:\WINDOWS\System32\IVIresizePX.dll [2006-05-08 19:48:14 | 00,020,480 | ---- | C] () – C:\WINDOWS\System32\IVIresize.dll [2006-05-08 19:44:23 | 00,077,824 | ---- | C] () – C:\WINDOWS\System32\SynTPCoI.dll [2006-05-08 19:31:03 | 00,000,646 | ---- | C] () – C:\WINDOWS\ODBC.INI [2006-05-08 11:51:44 | 00,009,216 | ---- | C] () – C:\WINDOWS\System32\cpuinf32.dll [2006-05-08 11:51:42 | 00,795,648 | ---- | C] () – C:\WINDOWS\System32\xvidcore.dll [2006-05-08 05:20:15 | 00,000,128 | ---- | C] () – C:\Documents and Settings\Karol\Local Settings\Application Data\fusioncache.dat [2006-05-05 19:20:45 | 00,036,864 | ---- | C] () – C:\WINDOWS\System32\UnAudioNT.dll [2005-04-26 03:05:50 | 00,053,248 | ---- | C] () – C:\WINDOWS\System32\zlib.dll [2004-06-10 22:46:34 | 00,086,016 | ---- | C] () – C:\WINDOWS\System32\ati2evxx.dll [2003-04-08 11:40:22 | 00,005,679 | ---- | C] () – C:\WINDOWS\System32\OUTLPERF.INI [2002-05-16 01:38:40 | 00,091,136 | ---- | C] () – C:\WINDOWS\System32\mp4fil32.dll [2002-05-04 15:19:00 | 00,049,152 | ---- | C] () – C:\WINDOWS\System32\avisynthEx.dll [2000-09-12 11:58:26 | 00,160,256 | ---- | C] () – C:\WINDOWS\System32\ShrLk21.dll ========== Alternate Data Streams ========== @Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0F8F5844 < End of report >