OTL logfile created on: 2012-11-07 18:11:50 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Documents and Settings\gitara\Pulpit
Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
 
1,87 Gb Total Physical Memory | 1,40 Gb Available Physical Memory | 74,88% Memory free
3,04 Gb Paging File | 2,75 Gb Available in Paging File | 90,54% Paging File free
Paging file location(s): C:\pagefile.sys 1344 1344 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14,65 Gb Total Space | 0,96 Gb Free Space | 6,58% Space Free | Partition Type: NTFS
Drive D: | 50,01 Gb Total Space | 24,17 Gb Free Space | 48,34% Space Free | Partition Type: NTFS
Drive E: | 47,13 Gb Total Space | 2,59 Gb Free Space | 5,50% Space Free | Partition Type: NTFS
 
Computer Name: GITARA-0N4O8PB9 | User Name: gitara | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
[color=#E56717]========== Processes (SafeList) ==========[/color]
 
PRC - [2012-11-07 17:11:54 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\gitara\Pulpit\OTL.exe
PRC - [2008-11-26 18:18:46 | 000,155,160 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2008-11-26 18:18:32 | 000,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2008-11-26 18:16:23 | 000,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2008-11-26 18:12:08 | 000,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2004-08-03 23:44:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
 
 
[color=#E56717]========== Modules (No Company Name) ==========[/color]
 
MOD - [2005-10-07 14:05:32 | 000,125,440 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2001-10-28 16:42:30 | 000,116,224 | ---- | M] () -- C:\WINDOWS\system32\pdfcmnnt.dll
 
 
[color=#E56717]========== Services (SafeList) ==========[/color]
 
SRV - File not found [Disabled | Stopped] -- C:\gitara89\pev.3XE EXEC /i C:\gitara89\HIDEC.3XE C:\gitara89\SWREG.3XE ACL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep /RESET /Q -- (PEVSystemStart)
SRV - File not found [Disabled | Stopped] -- C:\Documents and Settings\All Users\Dane aplikacji\DatacardService\DCService.exe -- (DCService.exe)
SRV - [2012-10-27 23:15:03 | 000,115,168 | ---- | M] (Mozilla Foundation) [Disabled | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012-05-05 23:20:01 | 001,044,816 | ---- | M] (Flexera Software, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2012-04-14 15:53:24 | 000,253,088 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2010-06-15 14:59:09 | 000,085,096 | ---- | M] (Autodesk) [On_Demand | Stopped] -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe -- (Autodesk Licensing Service)
SRV - [2008-11-26 18:18:46 | 000,155,160 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus)
SRV - [2008-11-26 18:18:32 | 000,254,040 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner)
SRV - [2008-11-26 18:16:23 | 000,352,920 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner)
SRV - [2008-11-26 18:12:08 | 000,018,752 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv)
SRV - [2004-08-03 23:44:02 | 000,162,155 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\znxzaii.dll -- (sfwossme)
SRV - [2004-08-03 23:44:02 | 000,162,155 | RHS- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\znxzaii.dll -- (jyzodj)
 
 
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
 
DRV - File not found [Kernel | Disabled | Stopped] -- system32\DRIVERS\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - File not found [Kernel | Disabled | Stopped] -- system32\DRIVERS\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - File not found [Kernel | Disabled | Stopped] -- system32\DRIVERS\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - File not found [Kernel | Disabled | Stopped] -- System32\Drivers\StMp3Rec.sys -- (StMp3Rec)
DRV - File not found [Kernel | Disabled | Stopped] -- system32\drivers\massfilter.sys -- (massfilter)
DRV - File not found [Kernel | Disabled | Stopped] -- system32\DRIVERS\ewusbmdm.sys -- (hwdatacard)
DRV - File not found [Kernel | Disabled | Stopped] -- system32\DRIVERS\ew_jubusenum.sys -- (huawei_enumerator)
DRV - File not found [Kernel | Disabled | Stopped] -- system32\DRIVERS\ew_jucdcacm.sys -- (huawei_cdcacm)
DRV - File not found [Kernel | Disabled | Stopped] -- system32\drivers\ewfiltertdidriver.sys -- (filtertdidriver)
DRV - File not found [Kernel | Disabled | Stopped] -- system32\DRIVERS\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\01.tmp -- (cxbdu)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\DOCUME~1\gitara\USTAWI~1\Temp\catchme.sys -- (catchme)
DRV - [2009-11-09 04:21:18 | 000,059,388 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2009-08-19 08:44:54 | 000,721,904 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2009-08-18 16:32:00 | 005,884,416 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2008-11-26 18:18:18 | 000,094,032 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2008-11-26 18:17:36 | 000,111,184 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2008-11-26 18:17:25 | 000,020,560 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2008-11-26 18:16:38 | 000,050,864 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2008-11-26 18:16:29 | 000,023,152 | ---- | M] (ALWIL Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2008-11-26 18:15:35 | 000,026,944 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2008-08-05 19:10:12 | 001,684,736 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2007-11-20 14:15:10 | 000,607,232 | ---- | M] (S3 Graphics Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\S3gIGPm.sys -- (S3GIGP)
DRV - [2007-10-01 11:06:40 | 000,451,968 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rt73.sys -- (RT73)
DRV - [2006-09-28 13:10:52 | 000,011,648 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gggen.sys -- (gggen)
DRV - [2006-03-23 09:36:34 | 000,006,861 | ---- | M] (Conexant Systems, Inc) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\UIUSYS.SYS -- (UIUSys)
DRV - [2006-03-23 09:36:30 | 000,995,712 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2006-03-23 09:36:30 | 000,726,400 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2006-03-23 09:36:30 | 000,206,976 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2006-03-13 15:50:08 | 000,085,696 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w300obex.sys -- (w300obex)
DRV - [2006-03-13 15:50:06 | 000,087,824 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w300mgmt.sys -- (w300mgmt)
DRV - [2006-03-13 15:50:02 | 000,096,352 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w300mdm.sys -- (w300mdm)
DRV - [2006-03-13 15:50:00 | 000,009,264 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w300mdfl.sys -- (w300mdfl)
DRV - [2006-03-13 15:49:54 | 000,060,800 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w300bus.sys -- (w300bus)
DRV - [2006-01-04 14:41:48 | 001,389,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2004-08-03 23:00:06 | 000,149,376 | ---- | M] (M-Systems) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\tffsport.sys -- (tffsport)
DRV - [2004-06-10 21:42:38 | 000,015,429 | R--- | M] ( ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Sacm2A.sys -- (USBCM)
DRV - [2004-05-18 07:04:16 | 000,041,984 | ---- | M] (DeviceGuys, Inc.) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\DGIVECP.SYS -- (DgiVecp)
DRV - [2002-05-06 11:01:08 | 000,017,005 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (Aspi32)
 
 
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
 
 
[color=#E56717]========== Internet Explorer ==========[/color]
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
 
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
[color=#E56717]========== FireFox ==========[/color]
 
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=302398"
FF - prefs.js..browser.startup.homepage: "about:newtab"
FF - prefs.js..extensions.enabledAddons: player@vividas.com:4.1.0
FF - prefs.js..extensions.enabledAddons: {c36177c0-224a-11da-8cd6-0800200c9a91}:3.9.81
FF - prefs.js..extensions.enabledAddons: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:16.6
FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.4
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {c36177c0-224a-11da-8cd6-0800200c9a91}:3.8.4
FF - prefs.js..extensions.enabledItems: player@vividas.com:4.1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}:6.0.30
FF - prefs.js..network.proxy.type: 4
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.51204.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\gitara\Dane aplikacji\Facebook\npfbplugin_1_0_3.dll File not found
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-10-27 23:15:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012-10-27 23:14:57 | 000,000,000 | ---D | M]
 
[2008-09-03 09:01:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\gitara\Dane aplikacji\Mozilla\Extensions
[2012-10-26 09:57:23 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\gitara\Dane aplikacji\Mozilla\Firefox\Profiles\z0214zcy.default\extensions
[2012-10-26 09:57:23 | 000,000,000 | ---D | M] ("ColorfulTabs") -- C:\Documents and Settings\gitara\Dane aplikacji\Mozilla\Firefox\Profiles\z0214zcy.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2009-12-02 00:34:46 | 000,000,000 | ---D | M] (MinimizeToTray) -- C:\Documents and Settings\gitara\Dane aplikacji\Mozilla\Firefox\Profiles\z0214zcy.default\extensions\{3502a070-ea2f-11dd-ba2f-0800200c9a66}
[2011-03-13 18:10:24 | 000,000,000 | ---D | M] (Vividas player plugin) -- C:\Documents and Settings\gitara\Dane aplikacji\Mozilla\Firefox\Profiles\z0214zcy.default\extensions\player@vividas.com
[2012-07-13 19:03:09 | 000,177,357 | ---- | M] () (No name found) -- C:\Documents and Settings\gitara\Dane aplikacji\Mozilla\Firefox\Profiles\z0214zcy.default\extensions\{c36177c0-224a-11da-8cd6-0800200c9a91}.xpi
[2009-08-19 08:52:53 | 000,002,399 | ---- | M] () -- C:\Documents and Settings\gitara\Dane aplikacji\Mozilla\Firefox\Profiles\z0214zcy.default\searchplugins\daemon-search.xml
[2012-11-07 16:53:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012-10-27 23:15:04 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009-02-11 20:16:16 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\mozilla firefox\plugins\npbittorrent.dll
[2011-02-10 15:45:50 | 000,180,896 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npVividasPlayer.dll
[2012-06-17 11:13:05 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2012-06-17 11:13:05 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2012-06-17 11:13:05 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2012-06-17 11:13:05 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2012-06-17 11:13:05 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2012-06-17 11:13:05 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml
 
O1 HOSTS File: ([2012-04-24 14:12:34 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - Startup: C:\Documents and Settings\gitara\Menu Start\Programy\Autostart\ctfmon.lnk =  File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-1_4_2_04-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B861CE72-A313-410E-816F-567984655428}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:AutorunsDisabled () - 
O24 - Desktop WallPaper: C:\Documents and Settings\gitara\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\gitara\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012-08-24 10:21:21 | 000,085,456 | ---- | M] () - C:\AutoMapaSetupLog.txt -- [ NTFS ]
O32 - AutoRun File - [2012-01-14 19:15:33 | 000,000,000 | R--D | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2012-01-14 19:15:33 | 000,000,000 | R--D | M] - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2012-01-14 19:15:33 | 000,000,000 | R--D | M] - E:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
 
[2012-11-07 18:11:38 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\gitara\Pulpit\OTL.exe
[2012-11-07 18:10:22 | 000,000,000 | ---D | C] -- C:\Avenger
[2012-11-07 17:54:41 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2012-11-07 17:54:40 | 000,000,000 | ---D | C] -- C:\rsit
[2012-11-07 17:07:43 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012-11-07 16:41:15 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2012-11-05 23:27:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\gitara\Pulpit\babia 5'
[2012-10-27 23:14:50 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[39 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
 
[2012-11-07 18:10:53 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012-11-07 18:10:48 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012-11-07 18:10:46 | 2011,287,552 | -HS- | M] () -- C:\hiberfil.sys
[2012-11-07 17:11:54 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\gitara\Pulpit\OTL.exe
[2012-11-07 16:24:22 | 083,023,306 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\dsgsdgdsgdsgw.pad
[2012-11-07 15:29:51 | 000,568,722 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2012-11-07 15:29:51 | 000,505,060 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012-11-07 15:29:51 | 000,110,906 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2012-11-07 15:29:51 | 000,088,524 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012-11-07 01:41:40 | 000,001,061 | ---- | M] () -- C:\Documents and Settings\gitara\Menu Start\Programy\Autostart\ctfmon.lnk
[2012-11-07 00:20:03 | 000,000,082 | ---- | M] () -- C:\Documents and Settings\gitara\Pulpit\Legendary (2010) - Zalukaj.tv.URL
[2012-11-06 18:40:53 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012-11-02 11:16:55 | 000,002,513 | ---- | M] () -- C:\Documents and Settings\gitara\Pulpit\Microsoft Office Word 2007.lnk
[2012-11-01 22:08:31 | 011,938,355 | ---- | M] () -- C:\Documents and Settings\gitara\Pulpit\D. Mrozek-rozprawa doktorska.pdf.pdf
[2012-10-31 19:07:41 | 000,280,975 | ---- | M] () -- C:\Documents and Settings\gitara\Pulpit\gitara.pdf
[2012-10-27 00:14:25 | 000,000,087 | ---- | M] () -- C:\Documents and Settings\gitara\Pulpit\Bar na Victorii (2003) - Zalukaj.tv.URL
[2012-10-26 12:39:03 | 000,363,320 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012-10-26 11:34:04 | 000,000,085 | ---- | M] () -- C:\Documents and Settings\gitara\Pulpit\Wymiary okien typowych Blog Okniarza - O oknach. Okna, okienka i montaż..URL
[2012-10-26 11:16:59 | 000,000,074 | ---- | M] () -- C:\Documents and Settings\gitara\Pulpit\Płyty warstwowe - Balex.URL
[2012-10-25 00:23:30 | 000,000,080 | ---- | M] () -- C:\Documents and Settings\gitara\Pulpit\Życie może być prostsze – Demotywatory.pl.URL
[2012-10-25 00:13:33 | 000,000,068 | ---- | M] () -- C:\Documents and Settings\gitara\Pulpit\Princess Chelsea - The Cigarette Duet - YouTube.URL
[2012-10-24 14:06:19 | 000,151,529 | ---- | M] () -- C:\Documents and Settings\gitara\Pulpit\JJ_Rys04_Przekrój A-A.pdf
[2012-10-24 14:06:16 | 000,170,898 | ---- | M] () -- C:\Documents and Settings\gitara\Pulpit\JJ_Rys02_Rzut parteru_new.pdf
[2012-10-24 14:00:14 | 000,000,092 | ---- | M] () -- C:\Documents and Settings\gitara\Pulpit\Okładziny kamienne ścian, dr inż. Aleksander Byrdy Izolacje.com.pl.URL
[2012-10-24 13:59:58 | 000,000,118 | ---- | M] () -- C:\Documents and Settings\gitara\Pulpit\Rys. 2. Schemat mocowania płyt o ciężarze większym niż 40 kgm2 1 –... IZOLACJE.com.pl.URL
[2012-10-24 13:59:52 | 000,000,115 | ---- | M] () -- C:\Documents and Settings\gitara\Pulpit\httpwww.izolacje.com.plimagesphotos241047__b_b06462d6c2a2d5540b8052ce583d5c81.jpg.URL
[2012-10-24 13:56:15 | 000,106,211 | ---- | M] () -- C:\Documents and Settings\gitara\Pulpit\eps100_karta_techniczna_produktu.pdf
[2012-10-24 10:38:36 | 000,412,193 | ---- | M] () -- C:\Documents and Settings\gitara\Pulpit\P2PRGI_Szeliga.pdf
[2012-10-20 19:16:24 | 000,231,424 | ---- | M] () -- C:\Documents and Settings\gitara\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012-10-20 19:01:45 | 000,000,425 | ---- | M] () -- C:\Documents and Settings\gitara\Pulpit\Semestr VII.lnk
[39 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
[color=#E56717]========== Files Created - No Company Name ==========[/color]
 
[2012-11-07 17:45:53 | 2011,287,552 | -HS- | C] () -- C:\hiberfil.sys
[2012-11-07 01:41:39 | 000,001,061 | ---- | C] () -- C:\Documents and Settings\gitara\Menu Start\Programy\Autostart\ctfmon.lnk
[2012-11-07 01:41:34 | 083,023,306 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\dsgsdgdsgdsgw.pad
[2012-11-07 00:20:03 | 000,000,082 | ---- | C] () -- C:\Documents and Settings\gitara\Pulpit\Legendary (2010) - Zalukaj.tv.URL
[2012-11-01 22:06:39 | 011,938,355 | ---- | C] () -- C:\Documents and Settings\gitara\Pulpit\D. Mrozek-rozprawa doktorska.pdf.pdf
[2012-10-31 19:07:38 | 000,280,975 | ---- | C] () -- C:\Documents and Settings\gitara\Pulpit\gitara.pdf
[2012-10-27 00:14:25 | 000,000,087 | ---- | C] () -- C:\Documents and Settings\gitara\Pulpit\Bar na Victorii (2003) - Zalukaj.tv.URL
[2012-10-26 11:34:04 | 000,000,085 | ---- | C] () -- C:\Documents and Settings\gitara\Pulpit\Wymiary okien typowych Blog Okniarza - O oknach. Okna, okienka i montaż..URL
[2012-10-26 11:16:59 | 000,000,074 | ---- | C] () -- C:\Documents and Settings\gitara\Pulpit\Płyty warstwowe - Balex.URL
[2012-10-25 00:23:30 | 000,000,080 | ---- | C] () -- C:\Documents and Settings\gitara\Pulpit\Życie może być prostsze – Demotywatory.pl.URL
[2012-10-25 00:13:33 | 000,000,068 | ---- | C] () -- C:\Documents and Settings\gitara\Pulpit\Princess Chelsea - The Cigarette Duet - YouTube.URL
[2012-10-24 14:06:17 | 000,151,529 | ---- | C] () -- C:\Documents and Settings\gitara\Pulpit\JJ_Rys04_Przekrój A-A.pdf
[2012-10-24 14:06:15 | 000,170,898 | ---- | C] () -- C:\Documents and Settings\gitara\Pulpit\JJ_Rys02_Rzut parteru_new.pdf
[2012-10-24 14:00:14 | 000,000,092 | ---- | C] () -- C:\Documents and Settings\gitara\Pulpit\Okładziny kamienne ścian, dr inż. Aleksander Byrdy Izolacje.com.pl.URL
[2012-10-24 13:59:58 | 000,000,118 | ---- | C] () -- C:\Documents and Settings\gitara\Pulpit\Rys. 2. Schemat mocowania płyt o ciężarze większym niż 40 kgm2 1 –... IZOLACJE.com.pl.URL
[2012-10-24 13:59:52 | 000,000,115 | ---- | C] () -- C:\Documents and Settings\gitara\Pulpit\httpwww.izolacje.com.plimagesphotos241047__b_b06462d6c2a2d5540b8052ce583d5c81.jpg.URL
[2012-10-24 13:56:14 | 000,106,211 | ---- | C] () -- C:\Documents and Settings\gitara\Pulpit\eps100_karta_techniczna_produktu.pdf
[2012-10-24 10:38:32 | 000,412,193 | ---- | C] () -- C:\Documents and Settings\gitara\Pulpit\P2PRGI_Szeliga.pdf
[2012-10-20 19:01:45 | 000,000,425 | ---- | C] () -- C:\Documents and Settings\gitara\Pulpit\Semestr VII.lnk
[2012-05-09 17:12:55 | 000,558,944 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-S-1-5-21-1659004503-823518204-725345543-1003-0.dat
[2012-05-05 23:56:21 | 000,332,186 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-System.dat
[2012-04-24 14:05:42 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012-04-24 14:05:42 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012-04-24 14:05:42 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012-04-24 14:05:42 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012-04-24 14:05:42 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011-10-07 12:10:06 | 000,000,404 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2011-10-07 12:09:55 | 000,000,050 | ---- | C] () -- C:\WINDOWS\System32\BRIDF10B.DAT
[2011-06-05 15:27:39 | 000,074,232 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009-10-19 10:50:25 | 000,001,080 | ---- | C] () -- C:\Documents and Settings\gitara\NORInfo.ini
[2009-10-19 10:50:25 | 000,000,084 | ---- | C] () -- C:\Documents and Settings\gitara\USBInfo.ini
[2008-10-26 23:19:31 | 000,010,513 | ---- | C] () -- C:\Documents and Settings\gitara\tempfile.diff
[2008-09-01 23:22:50 | 000,231,424 | ---- | C] () -- C:\Documents and Settings\gitara\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
[color=#E56717]========== ZeroAccess Check ==========[/color]
 
[2009-02-09 19:01:42 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\System32\shdocvw.dll -- [2004-08-03 23:44:10 | 001,483,264 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\fastprox.dll -- [2004-08-03 23:43:58 | 000,472,064 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\System32\wbem\wbemess.dll -- [2004-08-03 23:44:14 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[color=#E56717]========== Alternate Data Streams ==========[/color]
 
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:A1EDB939

< End of report >
