OTL logfile created on: 2012-10-10 22:51:16 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Kamil\Moje dokumenty\Downloads Windows XP Home Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 1,18 Gb Available Physical Memory | 59,24% Memory free 3,85 Gb Paging File | 3,06 Gb Available in Paging File | 79,56% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 37,57 Gb Total Space | 5,35 Gb Free Space | 14,24% Space Free | Partition Type: NTFS Drive D: | 97,65 Gb Total Space | 11,45 Gb Free Space | 11,72% Space Free | Partition Type: NTFS Drive E: | 97,65 Gb Total Space | 13,20 Gb Free Space | 13,52% Space Free | Partition Type: NTFS Computer Name: LESZCZYNSKI | User Name: Kamil | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012-10-10 22:50:36 | 000,602,112 | ---- | M] (OldTimer Tools) – C:\Documents and Settings\Kamil\Moje dokumenty\Downloads\OTL.exe PRC - [2012-08-29 12:03:36 | 001,385,896 | ---- | M] (LogMeIn Inc.) – D:\Programy\LogMeIn Hamachi\hamachi-2.exe PRC - [2012-08-10 18:59:52 | 004,440,896 | ---- | M] (Akamai Technologies, Inc.) – C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe PRC - [2012-07-06 14:17:02 | 000,207,360 | ---- | M] () – C:\Program Files\Browsers Protector\regmon32.exe PRC - [2012-06-07 10:14:45 | 001,239,576 | ---- | M] (Google Inc.) – C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe PRC - [2012-03-15 04:05:14 | 003,090,056 | ---- | M] (Trend Media Corporation Limited) – D:\Programy\FlashGet 3\Flashget3.exe PRC - [2012-03-07 01:15:17 | 004,241,512 | ---- | M] (AVAST Software) – D:\Programy\avast! FREE ANTIVIRUS\AvastUI.exe PRC - [2011-02-07 09:56:11 | 000,138,192 | ---- | M] () – C:\Program Files\Canon\IJPLM\ijplmsvc.exe PRC - [2006-03-02 14:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe ========== Modules (No Company Name) ========== MOD - [2012-08-17 09:57:56 | 000,100,864 | ---- | M] () – C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\SwiftShader\1.0.1.3\libEGL.dll MOD - [2012-08-17 09:57:55 | 004,051,456 | ---- | M] () – C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\SwiftShader\1.0.1.3\libGLESv2.dll MOD - [2012-07-06 14:17:02 | 000,207,360 | ---- | M] () – C:\Program Files\Browsers Protector\regmon32.exe MOD - [2012-06-07 10:14:43 | 000,441,880 | ---- | M] () – C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\19.0.1084.56\ppgooglenaclpluginchrome.dll MOD - [2012-06-07 10:14:42 | 003,922,456 | ---- | M] () – C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\19.0.1084.56\pdf.dll MOD - [2012-06-07 10:13:16 | 000,134,696 | ---- | M] () – C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\19.0.1084.56\avutil-51.dll MOD - [2012-06-07 10:13:15 | 000,250,408 | ---- | M] () – C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\19.0.1084.56\avformat-54.dll MOD - [2012-06-07 10:13:14 | 002,375,720 | ---- | M] () – C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\19.0.1084.56\avcodec-54.dll MOD - [2012-06-07 09:23:19 | 009,252,040 | ---- | M] () – C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\19.0.1084.56\gcswf32.dll MOD - [2012-03-15 04:06:50 | 000,059,016 | ---- | M] () – D:\Programy\FlashGet 3\zlib.dll MOD - [2012-03-15 04:00:08 | 000,262,144 | ---- | M] () – D:\Programy\FlashGet 3\ckcore.dll MOD - [2012-03-15 04:00:08 | 000,249,856 | ---- | M] () – D:\Programy\FlashGet 3\BugReport.dll MOD - [2011-02-07 09:56:11 | 000,138,192 | ---- | M] () – C:\Program Files\Canon\IJPLM\ijplmsvc.exe MOD - [2009-02-27 19:04:20 | 000,311,296 | ---- | M] () – C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\pdfshell.POL MOD - [2008-03-29 16:42:20 | 000,159,744 | ---- | M] () – D:\Programy\SubEdit-Player\codec\MatroskaSplitter\mmfinfo.dll MOD - [2008-03-29 16:41:52 | 000,023,552 | ---- | M] () – D:\Programy\SubEdit-Player\codec\MatroskaSplitter\mkunicode.dll ========== Services (SafeList) ========== SRV - File not found [Disabled | Stopped] – %SystemRoot%\System32\hidserv.dll – (HidServ) SRV - File not found [On_Demand | Stopped] – %SystemRoot%\System32\appmgmts.dll – (AppMgmt) SRV - [2012-08-29 12:03:36 | 001,385,896 | ---- | M] (LogMeIn Inc.) [Auto | Running] – D:\Programy\LogMeIn Hamachi\hamachi-2.exe – (Hamachi2Svc) SRV - [2012-08-29 03:34:54 | 003,948,024 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\WINDOWS\system32\GameMon.des – (npggsvc) SRV - [2012-07-18 11:34:46 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc) SRV - [2011-02-07 09:56:11 | 000,138,192 | ---- | M] () [Auto | Running] – C:\Program Files\Canon\IJPLM\ijplmsvc.exe – (IJPLMSVC) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] – -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] – -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] – -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] – -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] – -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] – -- (PCIDump) DRV - File not found [Kernel | System | Stopped] – -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] – -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] – -- (Changer) DRV - [2012-06-30 22:03:11 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\dtsoftbus01.sys – (dtsoftbus01) DRV - [2010-07-04 21:51:26 | 000,004,096 | ---- | M] () [Kernel | Unavailable | Unknown] – D:\Programy\Unlocker\UnlockerDriver5.sys – (UnlockerDriver5) DRV - [2009-03-18 17:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hamachi.sys – (hamachi) DRV - [2009-02-16 04:25:52 | 001,057,024 | R— | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\viahduaa.sys – (VIAHdAudAddService) DRV - [2009-01-22 10:25:26 | 000,120,064 | R— | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Rtenicxp.sys – (RTLE8023xp) DRV - [2008-11-11 13:42:00 | 000,024,832 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lgusbmodem.sys – (USBModem) DRV - [2008-11-11 13:41:00 | 000,019,968 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lgusbdiag.sys – (UsbDiag) DRV - [2008-11-11 13:41:00 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lgusbbus.sys – (usbbus) DRV - [2008-02-14 08:12:00 | 001,389,056 | R— | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\monfilt.sys – (monfilt) DRV - [2007-12-28 09:22:02 | 000,010,296 | ---- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ASUSHWIO.SYS – (Asushwio) DRV - [2004-08-13 12:56:20 | 000,005,810 | R— | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ASACPI.sys – (MTsensor) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1&cf=adcdba4a- … 2618e04f4e IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1&cf=adcdba4a- … 2618e04f4e IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyOverride” = ========== FireFox ========== FF - prefs.js…browser.search.defaultengine: “Web Search” FF - prefs.js…browser.search.defaultenginename: “error” FF - prefs.js…browser.search.order.1: “error” FF - prefs.js…browser.search.selectedEngine: “error” FF - prefs.js…browser.startup.homepage: “error” FF - prefs.js…extensions.enabledAddons: {707e0f71-6097-30e2-ba06-182dc4e22896}:4.6.8.5 FF - prefs.js…keyword.URL: “error” FF - user.js - File not found FF - HKLM\Software\MozillaPlugins@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll () FF - HKLM\Software\MozillaPlugins@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins@real.com/nppl3260;version=6.0.12.450: D:\Programy\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins@real.com/nprpjplug;version=6.0.12.448: D:\Programy\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: D:\Programy\Adobe Reader 9.5.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins@tools.google.com/Google Update;version=3: C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins@tools.google.com/Google Update;version=9: C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\Components: D:\Programy\Mozilla Firefox\components [2012-07-22 19:04:08 | 000,000,000 | —D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\Plugins: D:\Programy\Mozilla Firefox\plugins [2012-07-22 19:04:08 | 000,000,000 | —D | M] [2012-07-15 20:19:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kamil\Dane aplikacji\Mozilla\Extensions [2012-07-18 20:07:28 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kamil\Dane aplikacji\Mozilla\Firefox\Profiles\8ja168nw.default\extensions [2012-07-18 20:02:26 | 000,000,792 | ---- | M] () – C:\Documents and Settings\Kamil\Dane aplikacji\Mozilla\Firefox\Profiles\8ja168nw.default\searchplugins\startsear.xml [2012-07-18 20:02:33 | 000,000,000 | —D | M] (z) – D:\PROGRAMY\MOZILLA FIREFOX\EXTENSIONS{707E0F71-6097-30E2-BA06-182DC4E22896} ========== Chrome ========== CHR - homepage: chrome://newtab/ CHR - default_search_provider: Web Search (Enabled) CHR - default_search_provider: search_url = http://startsear.ch/?aff=1&src=sp&cf=e0 … 8e04f4e&q={searchTerms} CHR - default_search_provider: suggest_url = CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\19.0.1084.56\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\19.0.1084.56\pdf.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\19.0.1084.56\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll CHR - plugin: StartSearch Video plug-in (Enabled) = C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\bildoibdboopgomcbiplincneeicgipj\1.3_0\chvsharetvplg.dll CHR - plugin: StartSearch Video plug-in (Enabled) = D:\Programy\Mozilla Firefox\plugins\npvsharetvplg.dll CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\plugins\nppl3260.dll CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\plugins\nprpjplug.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll CHR - plugin: Adobe Acrobat (Enabled) = D:\Programy\Adobe Reader 9.5.0\Reader\Browser\nppdf32.dll CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll CHR - Extension: StartSearch Video plug-in = C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\bildoibdboopgomcbiplincneeicgipj\1.3_0\ CHR - Extension: avast! WebRep = C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1426_0\ O1 HOSTS File: ([2006-03-02 14:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (YouTube To ALLPlayer) - {61DB16C5-B733-43F4-872E-B20DC9E72740} - C:\Program Files\ALLPlayer\YouTubeToALLPlayer.dll (ALLPlayer.org) O2 - BHO: (extrafind) - {9d4c55fd-3cd2-6865-9fdb-b34ff056e234} - C:\WINDOWS\system32\463e60f5.dll () O2 - BHO: (FlashGetBHO) - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Documents and Settings\Kamil\Dane aplikacji\FlashGetBHO\FlashGetBHO.dll (Trend Media Group) O2 - BHO: (IplexToALLPlayer) - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - D:\Programy\ALLPlayer\Iplex\IplexToALLPlayer.dll (ALLCinema Ltd.) O4 - HKLM…\Run: [browsers Protector] C:\Program Files\Browsers Protector\regmon32.exe () O4 - HKLM…\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found O4 - HKLM…\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM…\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM…\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe () O4 - HKLM…\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe () O4 - HKCU…\Run: [Akamai NetSession Interface] C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe (Akamai Technologies, Inc.) O4 - HKCU…\Run: [FlashGet 3] D:\Programy\FlashGet 3\FlashGet3.exe (Trend Media Corporation Limited) O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Download all links by FlashGet3 - D:\Programy\FlashGet 3\BHO\fdgetallurl.htm () O8 - Extra context menu item: Download by FlashGet3 - D:\Programy\FlashGet 3\BHO\fdgeturl.htm () O9 - Extra ‘Tools’ menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/ … vc1dmo.cab (Reg Error: Key error.) O16 - DPF: {41564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/ … mvadvd.cab (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/aut … s-i586.cab (Java Plug-in 1.4.2_03) O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/aut … s-i586.cab (Java Plug-in 1.4.2_03) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces{E2A49513-0F6F-43CB-9ADE-D2E57EE526BC}: DhcpNameServer = 192.168.0.1 O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2012-06-14 15:54:17 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT – [NTFS] O32 - AutoRun File - [2012-06-10 14:08:35 | 000,000,000 | -H-D | M] - D:\autorun.inf – [NTFS] O32 - AutoRun File - [2012-06-10 14:08:35 | 000,000,000 | -H-D | M] - E:\autorun.inf – [NTFS] O33 - MountPoints2{6dbede00-bb86-11e1-88e0-002618e04f4e}\Shell\AutoRun\command - “” = I:\EXPLORER.EXE O33 - MountPoints2{6dbede00-bb86-11e1-88e0-002618e04f4e}\Shell\explore\Command - “” = I:\EXPLORER.EXE O33 - MountPoints2{6dbede00-bb86-11e1-88e0-002618e04f4e}\Shell\open\Command - “” = I:\EXPLORER.EXE O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM…comfile [open] – “%1” %* O35 - HKLM…exefile [open] – “%1” %* O37 - HKLM…com [@ = comfile] – “%1” %* O37 - HKLM…exe [@ = exefile] – “%1” %* O38 - SubSystems\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2012-10-10 19:26:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Kamil\Menu Start\Programy\FlashGet3.7 [2012-10-10 19:26:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Kamil\Dane aplikacji\BITS [2012-10-10 19:26:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Kamil\Dane aplikacji\FlashgetSetup [2012-10-10 19:26:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Kamil\Dane aplikacji\FlashGetBHO [2012-10-10 19:26:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Kamil\Dane aplikacji\FlashGet [2012-10-08 01:22:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Kamil\Moje dokumenty\FIFAOnline2 [2012-10-08 01:22:49 | 003,948,024 | ---- | C] (INCA Internet Co., Ltd.) – C:\WINDOWS\System32\GameMon.des [2012-10-08 01:22:44 | 000,004,682 | ---- | C] (INCA Internet Co., Ltd.) – C:\WINDOWS\System32\npptNT2.sys [2012-10-08 01:22:21 | 000,000,000 | —D | C] – C:\Program Files\Common Files\INCA Shared [2012-10-08 01:21:47 | 000,000,000 | —D | C] – C:\Log [2012-10-07 00:05:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dokumenty\Amiga Files [2012-10-07 00:05:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Kamil\Menu Start\Programy\WinUAE [2012-10-06 21:43:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\TheCompany [2012-09-26 14:29:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Kamil\Menu Start\Programy\Forex.com MetaTrader 4 [2012-09-19 21:04:34 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Kamil\Recent [2012-09-16 10:33:10 | 137,250,876 | ---- | C] (Chronic Logic LLC ) – C:\Documents and Settings\All Users\Dokumenty\bridgeitsetup_polish_v2.exe [2012-09-16 10:31:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dokumenty\Kozacy - Europejskie boje [2012-09-16 10:31:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Kamil\Menu Start\Programy\Kolekcja Klasyki [2012-09-16 04:19:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dokumenty\Kozacy - Sztuka wojny [2012-09-16 04:05:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Dokumenty\BridgeIt [2012-09-16 04:02:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Menu Start\Programy\Bridge It [2012-09-13 19:40:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Kamil\Dane aplikacji\Canon [2012-09-13 19:40:20 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Dane aplikacji\CanonIJScan [2012-09-13 15:01:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Kamil\Dane aplikacji\GanymedeNet [2012-09-12 12:30:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Kamil\Moje dokumenty\Pobieranie [5 C:\WINDOWS*.tmp files -> C:\WINDOWS*.tmp ->] [1 C:\WINDOWS\System32*.tmp files -> C:\WINDOWS\System32*.tmp ->] ========== Files - Modified Within 30 Days ========== [2012-10-10 22:47:12 | 000,002,596 | ---- | M] () – C:\WINDOWS\System32\CONFIG.NT [2012-10-10 22:43:27 | 000,355,486 | ---- | M] () – C:\WINDOWS\System32\perfh015.dat [2012-10-10 22:43:27 | 000,311,604 | ---- | M] () – C:\WINDOWS\System32\perfh009.dat [2012-10-10 22:43:27 | 000,049,492 | ---- | M] () – C:\WINDOWS\System32\perfc015.dat [2012-10-10 22:43:27 | 000,039,992 | ---- | M] () – C:\WINDOWS\System32\perfc009.dat [2012-10-10 22:39:09 | 000,235,955 | ---- | M] () – C:\WINDOWS\System32\NvApps.xml [2012-10-10 22:38:53 | 000,002,048 | --S- | M] () – C:\WINDOWS\bootstat.dat [2012-10-10 19:27:02 | 000,000,494 | ---- | M] () – C:\Documents and Settings\Kamil\Pulpit\FlashGet downloads.lnk [2012-10-10 19:27:01 | 000,000,025 | ---- | M] () – C:\WINDOWS\libem.INI [2012-10-10 19:26:37 | 000,000,602 | ---- | M] () – C:\Documents and Settings\Kamil\Pulpit\FlashGet3.lnk [2012-10-10 15:01:52 | 000,001,169 | ---- | M] () – C:\WINDOWS\FOE2.ini [2012-10-10 10:49:49 | 000,013,646 | ---- | M] () – C:\WINDOWS\System32\wpa.dbl [2012-10-08 22:02:27 | 000,000,004 | ---- | M] () – C:\Program Files\is.dat [2012-10-08 01:20:09 | 000,000,563 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\Fifa Online 2.lnk [2012-10-04 00:54:03 | 000,052,736 | ---- | M] () – C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-09-26 18:37:01 | 000,000,754 | ---- | M] () – C:\WINDOWS\WORDPAD.INI [2012-09-16 02:46:50 | 732,799,642 | ---- | M] () – C:\Documents and Settings\All Users\Dokumenty\Valhalla.Rising.2009.PL.BDRip.XviD-BiDA.avi [2012-09-15 15:26:23 | 000,001,032 | ---- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cd9345b393a87c.job [5 C:\WINDOWS*.tmp files -> C:\WINDOWS*.tmp ->] [1 C:\WINDOWS\System32*.tmp files -> C:\WINDOWS\System32*.tmp ->] ========== Files Created - No Company Name ========== [2012-10-10 19:27:02 | 000,000,494 | ---- | C] () – C:\Documents and Settings\Kamil\Pulpit\FlashGet downloads.lnk [2012-10-10 19:27:01 | 000,000,025 | ---- | C] () – C:\WINDOWS\libem.INI [2012-10-10 19:26:37 | 000,000,602 | ---- | C] () – C:\Documents and Settings\Kamil\Pulpit\FlashGet3.lnk [2012-10-08 01:30:17 | 000,001,169 | ---- | C] () – C:\WINDOWS\FOE2.ini [2012-10-08 01:22:43 | 000,005,174 | ---- | C] () – C:\WINDOWS\System32\nppt9x.vxd [2012-10-08 01:20:09 | 000,000,563 | ---- | C] () – C:\Documents and Settings\All Users\Pulpit\Fifa Online 2.lnk [2012-09-16 10:33:30 | 000,409,957 | ---- | C] () – C:\Documents and Settings\All Users\Dokumenty\screenh.jpg [2012-09-16 10:33:30 | 000,126,289 | ---- | C] () – C:\Documents and Settings\All Users\Dokumenty\screen2.jpg [2012-09-16 10:33:10 | 000,001,265 | ---- | C] () – C:\Documents and Settings\All Users\Dokumenty\info.xml [2012-09-16 04:13:22 | 739,639,296 | ---- | C] () – C:\Documents and Settings\All Users\Dokumenty\Nanjing.Nanjing.2009.BRRip.XviD-EM0C0RE.avi [2012-09-16 01:09:58 | 732,799,642 | ---- | C] () – C:\Documents and Settings\All Users\Dokumenty\Valhalla.Rising.2009.PL.BDRip.XviD-BiDA.avi [2012-09-15 15:26:23 | 000,001,032 | ---- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cd9345b393a87c.job [2012-09-08 00:54:16 | 000,016,384 | ---- | C] () – C:\Program Files\uik.dat [2012-09-08 00:53:24 | 000,000,004 | ---- | C] () – C:\Program Files\is.dat [2012-08-19 19:10:22 | 000,112,640 | ---- | C] () – C:\WINDOWS\System32\ff_vfw.dll [2012-08-13 02:47:57 | 000,000,796 | ---- | C] () – C:\WINDOWS\VPlayer.INI [2012-08-10 14:49:53 | 000,000,754 | ---- | C] () – C:\WINDOWS\WORDPAD.INI [2012-07-18 20:02:33 | 000,075,045 | ---- | C] () – C:\WINDOWS\System32\4397821e.exe [2012-07-18 20:02:31 | 001,915,904 | ---- | C] () – C:\WINDOWS\System32\463e60f5.dll [2012-07-12 13:00:19 | 000,075,776 | ---- | C] () – C:\WINDOWS\cadkasdeinst01e.exe [2012-06-30 22:04:47 | 000,028,779 | ---- | C] () – C:\WINDOWS\System32\javaw.exe [2012-06-30 22:04:47 | 000,024,681 | ---- | C] () – C:\WINDOWS\System32\java.exe [2012-06-14 17:45:58 | 000,004,293 | ---- | C] () – C:\WINDOWS\ODBCINST.INI [2012-06-14 17:44:44 | 000,096,664 | ---- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT [2012-06-14 16:58:50 | 000,644,608 | ---- | C] () – C:\WINDOWS\System32\xvidcore.dll [2012-06-14 16:58:50 | 000,258,048 | ---- | C] () – C:\WINDOWS\System32\libFLAC.dll [2012-06-14 16:57:44 | 000,175,616 | ---- | C] () – C:\WINDOWS\System32\unrar.dll [2012-06-14 16:08:04 | 000,001,746 | ---- | C] () – C:\WINDOWS\Language_trs.ini [2012-06-14 16:07:40 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys [2012-06-14 16:07:26 | 000,010,296 | ---- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS [2012-06-14 15:59:53 | 000,052,736 | ---- | C] () – C:\Documents and Settings\Kamil\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-06-14 15:56:09 | 000,002,048 | --S- | C] () – C:\WINDOWS\bootstat.dat [2012-06-14 15:51:33 | 000,021,856 | ---- | C] () – C:\WINDOWS\System32\emptyregdb.dat ========== ZeroAccess Check ========== [HKEY_CURRENT_USER\Software\Classes\clsid{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] “” = %SystemRoot%\system32\shdocvw.dll – [2006-03-02 14:00:00 | 001,492,480 | ---- | M] (Microsoft Corporation) “ThreadingModel” = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] “” = C:\WINDOWS\system32\wbem\fastprox.dll – [2006-03-02 14:00:00 | 000,472,064 | ---- | M] (Microsoft Corporation) “ThreadingModel” = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] “” = C:\WINDOWS\system32\wbem\wbemess.dll – [2006-03-02 14:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation) “ThreadingModel” = Both < End of report >