Kod:
OTL logfile created on: 2011-10-08 14:52:36 - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Marta\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000415 | Country: Poland | Language: PLK | Date Format: yyyy-MM-dd
1023,49 Mb Total Physical Memory | 372,77 Mb Available Physical Memory | 36,42% Memory free
2,40 Gb Paging File | 1,76 Gb Available in Paging File | 73,41% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,07 Gb Total Space | 0,31 Gb Free Space | 1,62% Space Free | Partition Type: NTFS
Drive D: | 19,07 Gb Total Space | 7,28 Gb Free Space | 38,17% Space Free | Partition Type: NTFS
Drive H: | 3,73 Gb Total Space | 1,19 Gb Free Space | 31,96% Space Free | Partition Type: FAT32
Computer Name: DARKEDITION | User Name: Marta | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011-10-08 14:51:31 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Marta\My Documents\Downloads\OTL.exe
PRC - [2011-10-01 01:38:03 | 001,030,200 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Marta\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2011-04-26 08:57:54 | 008,989,184 | ---- | M] (Creative Team S.A.) -- C:\Program Files\WapSter\WapSter AQQ\AQQ.exe
PRC - [2010-05-06 22:59:42 | 002,815,192 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010-05-06 22:59:38 | 000,040,384 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2009-10-14 13:36:56 | 002,793,304 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
PRC - [2009-10-14 13:34:18 | 000,560,472 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2009-10-07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2009-02-24 14:00:00 | 001,641,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008-05-01 19:15:46 | 000,015,872 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerAssistant.exe
PRC - [2006-10-05 15:56:28 | 000,280,779 | ---- | M] () -- C:\WINDOWS\VistaDrive\VistaDrive.exe
PRC - [2004-09-19 07:27:46 | 000,065,536 | ---- | M] () -- C:\Program Files\LClock\LClock.exe
PRC - [2001-12-20 03:37:32 | 000,124,416 | R--- | M] (Avance Logic, Inc.) -- C:\WINDOWS\soundman.exe
========== Modules (No Company Name) ==========
MOD - [2011-10-08 11:01:30 | 001,596,416 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\11100800\algo.dll
MOD - [2011-10-06 11:55:24 | 000,212,640 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\11100800\aswRep.dll
MOD - [2011-10-01 01:38:02 | 000,412,728 | ---- | M] () -- C:\Documents and Settings\Marta\Local Settings\Application Data\Google\Chrome\Application\14.0.835.187\ppgooglenaclpluginchrome.dll
MOD - [2011-10-01 01:38:00 | 003,696,184 | ---- | M] () -- C:\Documents and Settings\Marta\Local Settings\Application Data\Google\Chrome\Application\14.0.835.187\pdf.dll
MOD - [2011-10-01 01:37:30 | 000,352,824 | ---- | M] () -- C:\Documents and Settings\Marta\Local Settings\Application Data\Google\Chrome\Application\14.0.835.187\Locales\pl.dll
MOD - [2011-10-01 01:36:24 | 000,142,568 | ---- | M] () -- C:\Documents and Settings\Marta\Local Settings\Application Data\Google\Chrome\Application\14.0.835.187\avutil-51.dll
MOD - [2011-10-01 01:36:23 | 000,253,320 | ---- | M] () -- C:\Documents and Settings\Marta\Local Settings\Application Data\Google\Chrome\Application\14.0.835.187\avformat-53.dll
MOD - [2011-10-01 01:36:22 | 002,403,240 | ---- | M] () -- C:\Documents and Settings\Marta\Local Settings\Application Data\Google\Chrome\Application\14.0.835.187\avcodec-53.dll
MOD - [2011-09-30 23:07:32 | 006,338,720 | ---- | M] () -- C:\Documents and Settings\Marta\Local Settings\Application Data\Google\Chrome\Application\14.0.835.187\gcswf32.dll
MOD - [2011-04-07 12:33:30 | 000,890,368 | ---- | M] () -- C:\Program Files\WapSter\WapSter AQQ\System\Shared\Plugins\GGNet.dll
MOD - [2010-12-22 11:24:48 | 000,574,464 | ---- | M] () -- C:\Program Files\WapSter\WapSter AQQ\System\Shared\Plugins\SMS.dll
MOD - [2010-08-25 11:41:20 | 000,304,640 | ---- | M] () -- C:\Program Files\WapSter\WapSter AQQ\System\Shared\Plugins\Contact.dll
MOD - [2009-10-14 13:36:56 | 002,793,304 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
MOD - [2009-10-14 13:34:18 | 000,560,472 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
MOD - [2009-02-27 19:04:20 | 000,311,296 | ---- | M] () -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\pdfshell.POL
MOD - [2009-02-24 14:00:00 | 001,532,416 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2009-02-24 14:00:00 | 000,394,240 | ---- | M] () -- C:\WINDOWS\system32\HMTCD.dll
MOD - [2009-02-24 14:00:00 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2009-02-24 14:00:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008-05-01 19:15:46 | 000,015,872 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerAssistant.exe
MOD - [2008-05-01 19:15:36 | 000,004,608 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerHook.dll
MOD - [2006-10-05 15:56:28 | 000,280,779 | ---- | M] () -- C:\WINDOWS\VistaDrive\VistaDrive.exe
MOD - [2006-08-17 07:35:00 | 000,196,608 | ---- | M] () -- C:\WINDOWS\system32\nvapi.dll
MOD - [2004-09-19 07:27:46 | 000,065,536 | ---- | M] () -- C:\Program Files\LClock\LClock.exe
MOD - [2004-09-19 07:27:36 | 000,069,632 | ---- | M] () -- C:\Program Files\LClock\LC.dll
MOD - [2004-09-19 07:27:32 | 000,081,920 | ---- | M] () -- C:\Program Files\LClock\Calendar.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011-05-03 17:10:00 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010-05-06 22:59:38 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010-05-06 22:59:38 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010-05-06 22:59:38 | 000,040,384 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2009-10-07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
========== Driver Services (SafeList) ==========
DRV - [2010-05-06 22:39:23 | 000,046,672 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2010-05-06 22:39:00 | 000,164,048 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2010-05-06 22:34:27 | 000,023,376 | ---- | M] (ALWIL Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2010-05-06 22:33:59 | 000,100,432 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2010-05-06 22:33:47 | 000,019,024 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010-05-06 22:33:29 | 000,028,880 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2009-10-07 10:49:50 | 000,023,832 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvuvcflt.sys -- (FilterService)
DRV - [2009-10-07 10:49:38 | 006,756,632 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvuvc.sys -- (LVUVC) Logitech Webcam 200(UVC)
DRV - [2009-10-07 10:47:55 | 000,266,008 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvrs.sys -- (LVRS)
DRV - [2009-10-07 10:46:12 | 000,114,712 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvpopflt.sys -- (lvpopflt)
DRV - [2009-10-07 01:46:36 | 000,025,752 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2009-02-24 14:00:00 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2009-02-24 14:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2009-02-24 14:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
DRV - [2008-04-13 19:15:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2001-12-20 03:37:32 | 000,243,164 | R--- | M] (Avance Logic, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Avance AC97 Audio (WDM)
DRV - [2001-12-19 06:45:00 | 000,008,576 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Program Files\System\CPL Bonus\vcdrom.sys -- (vcdrom)
DRV - [2001-12-13 07:57:00 | 000,003,279 | ---- | M] (VIA Technologies. Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\VIAPFD.SYS -- (VIAPFD)
DRV - [2001-10-18 06:00:00 | 000,006,144 | R--- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\viaidexp.sys -- (ViaIde)
DRV - [2001-08-23 21:03:54 | 000,025,434 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139)
DRV - [2001-08-17 09:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddr&s={searchTerms}&f=4
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-1844237615-152049171-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-1844237615-152049171-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1844237615-152049171-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Marta\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Marta\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
[2010-12-13 14:36:54 | 000,002,035 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fcmdSrchddr.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Marta\Local Settings\Application Data\Google\Chrome\Application\14.0.835.187\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Marta\Local Settings\Application Data\Google\Chrome\Application\14.0.835.187\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Marta\Local Settings\Application Data\Google\Chrome\Application\14.0.835.187\pdf.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Marta\Local Settings\Application Data\Google\Update\1.3.21.65\npGoogleUpdate3.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Facemoods = C:\Documents and Settings\Marta\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.4.0_0\
CHR - Extension: AT_ScottDraves = C:\Documents and Settings\Marta\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lefeecbpfmnmdoajflbekahgnbcjihcc\2_0\
O1 HOSTS File: ([2009-02-24 14:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\All Users\Application Data\Gadu-Gadu 10\_userdata\ggbho.2.dll File not found
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [LClock] C:\Program Files\LClock\LClock.exe ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Avance Logic, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKLM..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exe ()
O4 - HKU\S-1-5-21-1844237615-152049171-839522115-1003..\Run: [AQQ] C:\Program Files\WapSter\WapSter AQQ\AQQ.exe (Creative Team S.A.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-1844237615-152049171-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1844237615-152049171-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-21-1844237615-152049171-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.4.1 212.87.224.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7C806BDA-A7C3-478D-BCAA-DAC55E4412AE}: DhcpNameServer = 192.168.4.1 212.87.224.2
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Marta\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Marta\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011-04-30 07:42:34 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
========== Files/Folders - Created Within 30 Days ==========
[2011-10-08 14:11:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Marta\Application Data\Malwarebytes
[2011-10-08 14:11:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011-10-08 14:11:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011-10-08 14:11:42 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011-10-07 19:31:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth
[2011-10-06 20:51:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Marta\Desktop\HTML
[2011-09-27 18:45:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Marta\Desktop\obrobione
[2011-09-26 18:20:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Marta\Desktop\kaczka
[2011-09-25 17:08:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Marta\Application Data\Google
[2011-09-23 20:17:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\kED
[2011-09-19 23:06:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Marta\Desktop\nowee
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011-10-08 14:49:00 | 000,001,132 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-152049171-839522115-1004UA.job
[2011-10-08 14:33:00 | 000,001,128 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-152049171-839522115-1003UA.job
[2011-10-08 14:29:56 | 000,081,191 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2011-10-08 14:29:44 | 000,001,030 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011-10-08 14:29:21 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011-10-08 14:29:18 | 1073,274,880 | -HS- | M] () -- C:\hiberfil.sys
[2011-10-08 14:11:47 | 000,000,625 | ---- | M] () -- C:\Documents and Settings\Marta\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011-10-08 14:11:47 | 000,000,625 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011-10-08 14:08:02 | 000,001,034 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011-10-08 12:56:23 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\lvuvc.hs
[2011-10-08 12:56:19 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\logiflt.iad
[2011-10-07 21:33:04 | 000,001,076 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-152049171-839522115-1003Core.job
[2011-10-07 19:49:00 | 000,001,080 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-152049171-839522115-1004Core.job
[2011-10-07 19:31:14 | 000,001,915 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2011-10-06 20:51:25 | 000,029,328 | ---- | M] () -- C:\Documents and Settings\Marta\.recently-used.xbel
[2011-10-06 19:27:52 | 000,056,417 | ---- | M] () -- C:\Documents and Settings\Marta\Desktop\czerowny button.xcf
[2011-10-04 20:12:56 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011-10-03 17:41:00 | 000,002,284 | ---- | M] () -- C:\Documents and Settings\Marta\Desktop\Google Chrome.lnk
[2011-10-03 17:41:00 | 000,002,262 | ---- | M] () -- C:\Documents and Settings\Marta\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011-10-02 08:59:37 | 000,002,267 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011-09-26 17:59:30 | 000,057,763 | ---- | M] () -- C:\WINDOWS\FontData.fdb
[2011-09-26 17:58:13 | 000,021,704 | ---- | M] () -- C:\Documents and Settings\Marta\Desktop\legitymacja IId mk.cdr
[2011-09-25 16:33:30 | 000,752,137 | ---- | M] () -- C:\Documents and Settings\Marta\My Documents\d1ff5dff873af0ab47315da21371093f.png
[2011-09-23 20:56:54 | 000,343,307 | ---- | M] () -- C:\Documents and Settings\Marta\Desktop\eng.png
[2011-09-23 20:48:16 | 000,000,220 | ---- | M] () -- C:\Documents and Settings\Marta\Desktop\angielski.html
[2011-09-23 20:44:00 | 001,219,120 | ---- | M] () -- C:\Documents and Settings\Marta\Desktop\welcome2.xcf
[2011-09-23 20:44:00 | 001,219,120 | ---- | M] () -- C:\Documents and Settings\Marta\Desktop\welcome1.xcf
[2011-09-08 20:28:01 | 001,871,653 | ---- | M] () -- C:\Documents and Settings\Marta\Desktop\Ray Charles - Hit the road, Jack [zapiska.pl].mp3
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011-10-08 14:11:47 | 000,000,625 | ---- | C] () -- C:\Documents and Settings\Marta\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011-10-08 14:11:47 | 000,000,625 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011-10-07 19:31:14 | 000,001,915 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2011-10-06 20:51:25 | 000,029,328 | ---- | C] () -- C:\Documents and Settings\Marta\.recently-used.xbel
[2011-10-06 19:27:52 | 000,056,417 | ---- | C] () -- C:\Documents and Settings\Marta\Desktop\czerowny button.xcf
[2011-09-26 17:59:21 | 000,057,763 | ---- | C] () -- C:\WINDOWS\FontData.fdb
[2011-09-26 17:58:14 | 000,021,704 | ---- | C] () -- C:\Documents and Settings\Marta\Desktop\legitymacja IId mk.cdr
[2011-09-25 17:03:40 | 000,001,034 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011-09-25 17:03:39 | 000,001,030 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011-09-25 16:33:47 | 000,752,137 | ---- | C] () -- C:\Documents and Settings\Marta\My Documents\d1ff5dff873af0ab47315da21371093f.png
[2011-09-23 21:28:45 | 001,219,120 | ---- | C] () -- C:\Documents and Settings\Marta\Desktop\welcome2.xcf
[2011-09-23 20:56:53 | 000,343,307 | ---- | C] () -- C:\Documents and Settings\Marta\Desktop\eng.png
[2011-09-23 20:48:16 | 000,000,220 | ---- | C] () -- C:\Documents and Settings\Marta\Desktop\angielski.html
[2011-09-23 20:44:00 | 001,219,120 | ---- | C] () -- C:\Documents and Settings\Marta\Desktop\welcome1.xcf
[2011-09-08 20:23:36 | 001,871,653 | ---- | C] () -- C:\Documents and Settings\Marta\Desktop\Ray Charles - Hit the road, Jack [zapiska.pl].mp3
[2011-05-14 09:42:22 | 000,082,289 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2011-05-04 10:00:39 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2011-04-30 14:27:53 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011-04-30 14:24:08 | 001,651,648 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011-04-30 13:11:45 | 001,617,920 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2011-04-30 13:11:45 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2011-04-30 13:11:45 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2011-04-30 13:11:45 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2011-04-30 13:11:44 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2011-04-30 13:11:44 | 001,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2011-04-30 13:11:44 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2011-04-30 13:11:44 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2011-04-30 13:11:44 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2011-04-30 13:11:44 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2011-04-30 13:11:30 | 000,196,608 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2011-04-30 13:06:53 | 000,000,164 | R--- | C] () -- C:\WINDOWS\avrack.ini
[2011-04-30 13:06:52 | 000,000,584 | R--- | C] () -- C:\WINDOWS\System32\drivers\alcxinit.dat
[2011-04-30 13:02:35 | 000,532,480 | ---- | C] () -- C:\WINDOWS\System32\DeleteFiles.exe
[2011-04-30 13:02:35 | 000,387,584 | ---- | C] () -- C:\WINDOWS\System32\LostRun.exe
[2011-04-30 13:02:35 | 000,381,440 | ---- | C] () -- C:\WINDOWS\System32\Counter.exe
[2011-04-30 13:02:35 | 000,351,232 | ---- | C] () -- C:\WINDOWS\System32\CheckPath.exe
[2011-04-30 13:02:34 | 000,382,464 | ---- | C] () -- C:\WINDOWS\System32\Restart.exe
[2011-04-30 13:02:34 | 000,374,784 | ---- | C] () -- C:\WINDOWS\System32\RunAP.exe
[2011-04-30 13:02:34 | 000,363,008 | ---- | C] () -- C:\WINDOWS\System32\Change.exe
[2011-04-30 07:43:17 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011-04-30 07:42:39 | 000,001,651 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2011-04-30 07:37:28 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009-10-07 01:46:36 | 000,025,752 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009-10-07 01:23:08 | 000,013,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009-02-24 14:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2009-02-24 14:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2009-02-24 14:00:00 | 000,394,240 | ---- | C] () -- C:\WINDOWS\System32\HMTCD.dll
[2009-02-24 14:00:00 | 000,308,358 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2009-02-24 14:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2009-02-24 14:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2009-02-24 14:00:00 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\cabarc.exe
[2009-02-24 14:00:00 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\CopyToSendTo.dll
[2009-02-24 14:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2009-02-24 14:00:00 | 000,038,740 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2009-02-24 14:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2009-02-24 14:00:00 | 000,008,636 | ---- | C] () -- C:\WINDOWS\modifyPE.exe
[2009-02-24 14:00:00 | 000,006,144 | ---- | C] () -- C:\WINDOWS\System32\FontReg.exe
[2009-02-24 14:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2009-02-24 14:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2009-02-24 14:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2009-02-24 14:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011-05-01 13:09:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2011-05-15 16:26:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011-05-03 16:53:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gadu-Gadu 10
[2011-08-13 21:04:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\OpenFM
[2011-07-30 13:38:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marcin\Application Data\facemoods.com
[2011-05-25 20:40:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marcin\Application Data\Gadu-Gadu 10
[2011-10-02 08:59:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marcin\Application Data\go
[2011-05-26 15:52:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marcin\Application Data\OpenFM
[2011-04-30 20:50:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Application Data\CometPlayer
[2011-05-27 18:08:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Application Data\EurekaLog
[2011-08-16 14:15:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Application Data\facemoods.com
[2011-05-07 14:53:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Application Data\Gadu-Gadu 10
[2011-10-08 10:51:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Application Data\go
[2011-10-06 20:51:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Application Data\gtk-2.0
[2011-05-14 09:44:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Application Data\Leadertech
[2011-05-06 12:11:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Application Data\OpenFM
[2011-04-30 20:50:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Application Data\tigerplayer
[2011-05-27 18:35:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Application Data\VSRevoGroup
========== Purity Check ==========
========== Custom Scans ==========
< %systemdrive%\*.* >
[2011-04-30 07:42:34 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2011-04-30 07:33:29 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2011-04-30 07:42:34 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2011-10-08 14:29:18 | 1073,274,880 | -HS- | M] () -- C:\hiberfil.sys
[2011-04-30 07:42:34 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2011-04-30 07:42:34 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2009-02-24 14:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009-02-24 14:00:00 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2011-10-08 14:29:16 | 1610,612,736 | -HS- | M] () -- C:\pagefile.sys
< End of report >
Znajdziesz nas na: