

- Kod: Zaznacz wszystko
OTL logfile created on: 06/09/2009 01:19:27 - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = F:\
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18813)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.82 Gb Available Physical Memory | 91.06% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97.66 Gb Total Space | 32.01 Gb Free Space | 32.78% Space Free | Partition Type: NTFS
Drive D: | 360.29 Gb Total Space | 270.52 Gb Free Space | 75.08% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 298.09 Gb Total Space | 57.43 Gb Free Space | 19.27% Space Free | Partition Type: NTFS
Drive G: | 964.55 Mb Total Space | 245.00 Mb Free Space | 25.40% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MAX-PC
Current User Name: Max
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2008/11/12 15:19:00 | 00,720,896 | ---- | M] (ATI Technologies Inc.) -- C:\Windows\System32\Ati2evxx.exe
PRC - [2008/11/12 15:19:00 | 00,720,896 | ---- | M] (ATI Technologies Inc.) -- C:\Windows\System32\Ati2evxx.exe
PRC - [2009/04/11 07:27:36 | 02,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\Explorer.EXE
PRC - [2009/05/14 15:47:54 | 00,731,840 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe
PRC - [2008/04/30 19:41:12 | 00,815,104 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe
PRC - [2008/04/15 17:54:42 | 00,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
PRC - [2008/11/05 09:21:04 | 00,159,744 | ---- | M] (Micro-Star Int'l Co., Ltd.) -- C:\Program Files\System Control Manager\MSIService.exe
PRC - [2007/02/12 09:43:00 | 00,065,536 | ---- | M] (O2Micro International) -- C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
PRC - [2008/04/30 19:10:10 | 00,466,944 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
PRC - [2008/10/10 23:17:50 | 00,132,456 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
PRC - [2008/01/21 03:24:59 | 00,142,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WUDFHost.exe
PRC - [2009/01/26 15:31:10 | 01,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2009/04/11 07:28:15 | 00,247,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\wmiprvse.exe
PRC - [2008/01/21 03:23:32 | 01,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008/09/02 11:48:12 | 00,049,152 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
PRC - [2008/11/12 04:42:42 | 06,687,264 | ---- | M] (Realtek Semiconductor) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
PRC - [2008/06/11 11:16:00 | 01,454,080 | ---- | M] (Motorola Inc.) -- C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
PRC - [2008/04/15 17:54:40 | 00,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009/01/06 10:05:52 | 00,708,608 | ---- | M] (Micro-Star International Co., Ltd.) -- C:\Program Files\System Control Manager\MGSysCtrl.exe
PRC - [2009/05/14 15:47:08 | 02,029,640 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\egui.exe
PRC - [2007/09/13 14:26:50 | 00,090,112 | ---- | M] () -- C:\MSI\Advanced Wheel Mouse\wh_exec.exe
PRC - [2009/04/11 07:28:03 | 01,233,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Sidebar\sidebar.exe
PRC - [2009/06/26 15:56:32 | 25,604,904 | R--- | M] (Skype Technologies S.A.) -- C:\Program Files\Skype\Phone\Skype.exe
PRC - [2009/04/23 14:51:38 | 00,691,656 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\daemon.exe
PRC - [2009/01/06 19:11:08 | 02,360,648 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
PRC - [2009/04/11 07:28:08 | 00,037,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\unsecapp.exe
PRC - [2008/09/02 11:40:46 | 00,049,152 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
PRC - [2009/04/11 07:28:03 | 01,233,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Sidebar\sidebar.exe
PRC - [2009/01/07 11:23:32 | 00,357,704 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
PRC - [2008/07/24 11:24:24 | 00,083,272 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
PRC - [2009/01/13 11:01:14 | 00,308,552 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
PRC - [2008/07/24 11:25:00 | 00,111,944 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtKbd.exe
PRC - [2008/08/01 13:29:56 | 00,075,080 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
PRC - [2009/08/07 01:34:55 | 00,908,280 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/09/06 01:17:54 | 00,514,048 | ---- | M] (OldTimer Tools) -- F:\OTL.exe
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV - [2008/11/12 15:19:00 | 00,720,896 | ---- | M] (ATI Technologies Inc.) -- C:\Windows\System32\Ati2evxx.exe -- (Ati External Event Utility [Auto | Running])
SRV - [2009/03/30 05:42:14 | 00,066,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/01/21 03:25:09 | 00,292,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehRecvr.exe -- (ehRecvr [On_Demand | Stopped])
SRV - [2006/11/02 13:35:29 | 00,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched [On_Demand | Stopped])
SRV - [2006/11/02 13:35:29 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehstart.dll -- (ehstart [Auto | Stopped])
SRV - [2009/05/14 15:54:22 | 00,020,680 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv [On_Demand | Stopped])
SRV - [2009/05/14 15:47:54 | 00,731,840 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn [Auto | Running])
SRV - [2009/04/11 07:28:25 | 01,017,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wevtsvc.dll -- (Eventlog [Auto | Running])
SRV - [2008/04/30 19:41:12 | 00,815,104 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng [Auto | Running])
SRV - [2009/02/18 19:39:20 | 00,043,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/04/15 17:54:42 | 00,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMON [Auto | Running])
SRV - [2009/02/18 19:38:42 | 00,879,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008/11/05 09:21:04 | 00,159,744 | ---- | M] (Micro-Star Int'l Co., Ltd.) -- C:\Program Files\System Control Manager\MSIService.exe -- (Micro Star SCM [Auto | Running])
SRV - [2009/02/18 19:38:43 | 00,129,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2007/02/12 09:43:00 | 00,065,536 | ---- | M] (O2Micro International) -- C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe -- (o2flash [Auto | Running])
SRV - [2003/07/28 20:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2008/04/30 19:10:10 | 00,466,944 | ---- | M] (Intel(R) Corporation) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc [Auto | Running])
SRV - [2009/01/26 15:31:10 | 01,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService [Auto | Running])
SRV - [2008/10/10 23:17:50 | 00,132,456 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service [Auto | Running])
SRV - [2008/01/21 03:23:32 | 00,272,952 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend [Auto | Running])
SRV - [2008/01/21 03:25:33 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - [2008/01/21 03:23:21 | 00,422,968 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx [Disabled | Stopped])
DRV - [2008/01/21 03:23:25 | 00,300,600 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci [Disabled | Stopped])
DRV - [2008/01/21 03:23:26 | 00,101,432 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m [Disabled | Stopped])
DRV - [2008/01/21 03:23:27 | 00,149,560 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320 [Disabled | Stopped])
DRV - [2006/11/02 10:50:11 | 00,071,272 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx [Disabled | Stopped])
DRV - [2008/01/21 03:23:00 | 00,017,464 | ---- | M] (Acer Laboratories Inc.) -- C:\Windows\system32\drivers\aliide.sys -- (aliide [Disabled | Stopped])
DRV - [2008/01/21 03:23:23 | 00,079,416 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\arc.sys -- (arc [Disabled | Stopped])
DRV - [2008/01/21 03:23:24 | 00,079,928 | ---- | M] (Adaptec, Inc.) -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas [Disabled | Stopped])
DRV - [2008/11/12 16:41:00 | 04,179,456 | ---- | M] (ATI Technologies Inc.) -- C:\Windows\System32\DRIVERS\atikmdag.sys -- (atikmdag [On_Demand | Running])
DRV - [2009/08/05 18:38:24 | 00,279,712 | ---- | M] () -- C:\Windows\System32\DRIVERS\atksgt.sys -- (atksgt [Auto | Running])
DRV - [2006/11/02 09:24:45 | 00,013,568 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo [On_Demand | Stopped])
DRV - [2006/11/02 09:24:46 | 00,005,248 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp [On_Demand | Stopped])
DRV - [2006/11/02 09:25:24 | 00,071,808 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brserid.sys -- (Brserid [Disabled | Stopped])
DRV - [2006/11/02 09:24:44 | 00,062,336 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm [Disabled | Stopped])
DRV - [2006/11/02 09:24:44 | 00,012,160 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm [Disabled | Stopped])
DRV - [2006/11/02 09:24:47 | 00,011,904 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer [On_Demand | Stopped])
DRV - [2008/01/21 03:23:00 | 00,019,000 | ---- | M] (CMD Technology, Inc.) -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide [Disabled | Stopped])
DRV - [2008/01/21 03:23:24 | 00,118,784 | ---- | M] (Intel Corporation) -- C:\Windows\System32\DRIVERS\E1G60I32.sys -- (E1G60 [On_Demand | Stopped])
DRV - [2009/05/14 15:41:10 | 00,114,472 | ---- | M] (ESET) -- C:\Windows\System32\DRIVERS\eamon.sys -- (eamon [Auto | Running])
DRV - [2009/05/14 15:47:14 | 00,107,256 | ---- | M] (ESET) -- C:\Windows\System32\DRIVERS\ehdrv.sys -- (ehdrv [System | Running])
DRV - [2008/01/21 03:23:22 | 00,342,584 | ---- | M] (Emulex) -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor [Disabled | Stopped])
DRV - [2008/04/28 18:54:58 | 00,054,784 | ---- | M] (ENE TECHNOLOGY INC.) -- C:\Windows\System32\DRIVERS\enecir.sys -- (enecir [On_Demand | Running])
DRV - [2009/05/14 15:49:22 | 00,133,000 | ---- | M] (ESET) -- C:\Windows\System32\DRIVERS\epfw.sys -- (epfw [Auto | Running])
DRV - [2009/05/14 15:49:26 | 00,033,096 | ---- | M] (ESET) -- C:\Windows\System32\DRIVERS\Epfwndis.sys -- (Epfwndis [On_Demand | Running])
DRV - [2009/05/14 15:49:32 | 00,038,240 | ---- | M] (ESET) -- C:\Windows\System32\DRIVERS\epfwwfp.sys -- (epfwwfp [Auto | Running])
DRV - [2008/01/21 03:23:26 | 00,040,504 | ---- | M] (Hewlett-Packard Company) -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs [Disabled | Stopped])
DRV - [2008/04/15 17:53:44 | 00,312,344 | ---- | M] (Intel Corporation) -- C:\Windows\system32\DRIVERS\iaStor.sys -- (iaStor [Boot | Running])
DRV - [2008/01/21 03:23:23 | 00,235,064 | ---- | M] (Intel Corporation) -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV [Disabled | Stopped])
DRV - [2006/11/02 10:50:17 | 00,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp [Disabled | Stopped])
DRV - [2008/11/11 10:15:12 | 02,236,512 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService [On_Demand | Running])
DRV - [2006/11/02 10:50:07 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi [Disabled | Stopped])
DRV - [2006/11/02 10:50:09 | 00,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid [Disabled | Stopped])
DRV - [2009/08/05 18:38:24 | 00,025,888 | ---- | M] () -- C:\Windows\System32\DRIVERS\lirsgt.sys -- (lirsgt [Auto | Running])
DRV - [2008/01/21 03:23:23 | 00,096,312 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC [Disabled | Stopped])
DRV - [2008/01/21 03:23:25 | 00,089,656 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS [Disabled | Stopped])
DRV - [2008/01/21 03:23:23 | 00,096,312 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI [Disabled | Stopped])
DRV - [2008/01/21 03:23:27 | 00,031,288 | ---- | M] (LSI Corporation) -- C:\Windows\system32\drivers\megasas.sys -- (megasas [Disabled | Stopped])
DRV - [2008/01/21 03:23:27 | 00,386,616 | ---- | M] (LSI Corporation, Inc.) -- C:\Windows\system32\drivers\megasr.sys -- (MegaSR [Disabled | Stopped])
DRV - [2006/11/02 10:49:59 | 00,033,384 | ---- | M] (LSI Logic Corporation) -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x [Disabled | Stopped])
DRV - [2008/04/28 06:29:26 | 03,658,752 | ---- | M] (Intel Corporation) -- C:\Windows\System32\DRIVERS\NETw5v32.sys -- (NETw5v32 [On_Demand | Running])
DRV - [2006/11/02 10:50:19 | 00,045,160 | ---- | M] (IBM Corporation) -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960 [Disabled | Stopped])
DRV - [2006/11/02 08:36:50 | 00,020,608 | ---- | M] (N-trig Innovative Technologies) -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi [Disabled | Stopped])
DRV - [2008/01/21 03:23:21 | 00,102,968 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid [Disabled | Stopped])
DRV - [2008/01/21 03:23:21 | 00,045,112 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor [Disabled | Stopped])
DRV - [2008/07/15 09:38:00 | 00,051,288 | ---- | M] (O2Micro ) -- C:\Windows\System32\DRIVERS\o2media.sys -- (O2MDRDR [On_Demand | Running])
DRV - [2008/06/12 02:28:00 | 00,043,608 | ---- | M] (O2Micro ) -- C:\Windows\System32\DRIVERS\o2sd.sys -- (O2SDRDR [On_Demand | Running])
DRV - [2008/01/21 03:23:24 | 01,122,360 | ---- | M] (QLogic Corporation) -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300 [Disabled | Stopped])
DRV - [2006/11/02 10:50:35 | 00,106,088 | ---- | M] (QLogic Corporation) -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx [Disabled | Stopped])
DRV - [2008/11/11 11:29:42 | 00,154,272 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\drivers\RtHDMIV.sys -- (RTHDMIAzAudService [On_Demand | Running])
DRV - [2008/05/02 06:59:00 | 00,122,368 | ---- | M] (Realtek Corporation ) -- C:\Windows\System32\DRIVERS\Rtlh86.sys -- (RTL8169 [On_Demand | Running])
DRV - [2006/11/02 07:37:21 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\Windows\System32\drivers\secdrv.sys -- (secdrv [Auto | Running])
DRV - [2008/01/21 03:23:26 | 00,074,808 | ---- | M] (Silicon Integrated Systems) -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4 [Disabled | Stopped])
DRV - [2008/06/11 11:23:00 | 01,097,856 | ---- | M] (Motorola Inc.) -- C:\Windows\System32\DRIVERS\smserial.sys -- (smserial [On_Demand | Running])
DRV - [2009/07/16 17:56:39 | 00,721,904 | ---- | M] () -- C:\Windows\System32\Drivers\sptd.sys -- (sptd [Boot | Running])
DRV - [2006/11/02 10:50:05 | 00,035,944 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx [Disabled | Stopped])
DRV - [2006/11/02 10:49:56 | 00,031,848 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi [Disabled | Stopped])
DRV - [2006/11/02 10:50:03 | 00,034,920 | ---- | M] (LSI Logic) -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3 [Disabled | Stopped])
DRV - [2005/07/11 18:58:00 | 00,003,712 | ---- | M] (TOSHIBA Corporation.) -- C:\Windows\System32\drivers\Toshidpt.sys -- (toshidpt [On_Demand | Stopped])
DRV - [2008/03/25 13:54:02 | 00,041,472 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\DRIVERS\tosporte.sys -- (tosporte [On_Demand | Running])
DRV - [2008/10/06 17:56:38 | 00,137,984 | ---- | M] (TOSHIBA CORPORATION) -- C:\Windows\System32\DRIVERS\tosrfbd.sys -- (tosrfbd [On_Demand | Stopped])
DRV - [2007/11/29 09:45:44 | 00,036,608 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\Drivers\tosrfbnp.sys -- (tosrfbnp [On_Demand | Stopped])
DRV - [2008/08/22 13:50:34 | 00,064,000 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\Drivers\tosrfcom.sys -- (Tosrfcom [System | Running])
DRV - [2008/08/27 18:01:56 | 00,074,240 | ---- | M] (TOSHIBA Corporation.) -- C:\Windows\System32\DRIVERS\Tosrfhid.sys -- (Tosrfhid [On_Demand | Stopped])
DRV - [2005/01/07 05:42:00 | 00,018,612 | ---- | M] (TOSHIBA Corporation.) -- C:\Windows\System32\DRIVERS\tosrfnds.sys -- (tosrfnds [On_Demand | Stopped])
DRV - [2008/12/11 18:02:20 | 00,054,272 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\drivers\tosrfsnd.sys -- (TosRfSnd [On_Demand | Stopped])
DRV - [2009/01/15 14:01:56 | 00,042,880 | ---- | M] (TOSHIBA CORPORATION) -- C:\Windows\System32\DRIVERS\tosrfusb.sys -- (Tosrfusb [On_Demand | Stopped])
DRV - [2008/01/21 03:23:20 | 00,238,648 | ---- | M] (ULi Electronics Inc.) -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci [Disabled | Stopped])
DRV - [2006/11/02 10:50:35 | 00,098,408 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata [Disabled | Stopped])
DRV - [2008/01/21 03:23:23 | 00,115,816 | ---- | M] (Promise Technology, Inc.) -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2 [Disabled | Stopped])
DRV - [2008/01/21 03:23:00 | 00,020,024 | ---- | M] (VIA Technologies, Inc.) -- C:\Windows\system32\drivers\viaide.sys -- (viaide [Disabled | Stopped])
DRV - [2008/01/21 03:23:23 | 00,130,616 | ---- | M] (VIA Technologies Inc.,Ltd) -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid [Disabled | Stopped])
DRV - [2007/01/25 16:45:02 | 00,006,784 | ---- | M] () -- C:\Windows\System32\DRIVERS\whfltr2k.sys -- (whfltr2k [On_Demand | Running])
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKU\S-1-5-21-1901676302-259906463-4087737416-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\S-1-5-21-1901676302-259906463-4087737416-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKU\S-1-5-21-1901676302-259906463-4087737416-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
IE - HKU\S-1-5-21-1901676302-259906463-4087737416-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1901676302-259906463-4087737416-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKU\S-1-5-21-1901676302-259906463-4087737416-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A3 E1 B4 12 24 FF C9 01 [binary data]
IE - HKU\S-1-5-21-1901676302-259906463-4087737416-1000\S-1-5-21-1901676302-259906463-4087737416-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..browser.search.selectedEngine: "IMDB"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.pl/"
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.6.2
FF - prefs.js..extensions.enabledItems: {446c03e0-2c35-11db-a98b-0800200c9a67}:0.5
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.0.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2a}:1.3.6
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: smartbookmarksbar@remy.juteau:1.4.3
FF - prefs.js..extensions.enabledItems: testpilot@labs.mozilla.com:0.2.1
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.2
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/07/07 17:39:25 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/07 01:35:00 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/17 19:50:31 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
[2009/07/07 18:41:51 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\mozilla\Extensions
[2009/07/07 18:41:51 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/09/05 18:16:02 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\mozilla\Firefox\Profiles\q2m1xly6.default\extensions
[2009/09/05 12:55:23 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\mozilla\Firefox\Profiles\q2m1xly6.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2009/07/07 18:49:11 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\mozilla\Firefox\Profiles\q2m1xly6.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/07/07 18:51:11 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\mozilla\Firefox\Profiles\q2m1xly6.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
[2009/07/07 18:49:59 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\mozilla\Firefox\Profiles\q2m1xly6.default\extensions\{446c03e0-2c35-11db-a98b-0800200c9a67}
[2009/08/20 17:02:16 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\mozilla\Firefox\Profiles\q2m1xly6.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/07/07 18:51:53 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\mozilla\Firefox\Profiles\q2m1xly6.default\extensions\smartbookmarksbar@remy.juteau
[2009/09/05 12:56:03 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\mozilla\Firefox\Profiles\q2m1xly6.default\extensions\testpilot@labs.mozilla.com
[2009/07/07 18:52:46 | 00,002,447 | ---- | M] () -- C:\Users\Max\AppData\Roaming\Mozilla\FireFox\Profiles\q2m1xly6.default\searchplugins\album-cover-artorg.xml
[2009/07/07 18:54:04 | 00,001,512 | ---- | M] () -- C:\Users\Max\AppData\Roaming\Mozilla\FireFox\Profiles\q2m1xly6.default\searchplugins\imdb.xml
[2009/09/03 23:58:37 | 00,004,868 | ---- | M] () -- C:\Users\Max\AppData\Roaming\Mozilla\FireFox\Profiles\q2m1xly6.default\searchplugins\isohunt---bt-search.xml
[2009/07/07 18:52:18 | 00,001,626 | ---- | M] () -- C:\Users\Max\AppData\Roaming\Mozilla\FireFox\Profiles\q2m1xly6.default\searchplugins\mozilla-add-ons.xml
[2009/07/07 18:56:09 | 00,004,153 | ---- | M] () -- C:\Users\Max\AppData\Roaming\Mozilla\FireFox\Profiles\q2m1xly6.default\searchplugins\youtube.xml
[2009/09/05 18:16:02 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/08/07 01:35:00 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/07/10 20:00:25 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
[2009/08/07 01:34:52 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/07 01:34:52 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/05/01 22:02:48 | 01,044,480 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files\mozilla firefox\plugins\libdivx.dll
[2007/04/10 17:21:08 | 00,163,256 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\np-mswmp.dll
[2006/02/07 16:41:38 | 00,049,152 | ---- | M] (Macromedia, Inc.) -- C:\Program Files\mozilla firefox\plugins\np32dsw.dll
[2009/07/10 20:00:17 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2009/05/12 19:46:20 | 01,650,992 | ---- | M] (DivX,Inc.) -- C:\Program Files\mozilla firefox\plugins\npdivx32.dll
[2009/08/07 01:34:56 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009/02/27 12:13:42 | 00,103,792 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2008/09/10 20:56:44 | 00,144,960 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nppl3260.dll
[2008/09/10 20:37:54 | 00,094,208 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprpjplug.dll
[2009/05/01 22:02:48 | 00,200,704 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files\mozilla firefox\plugins\ssldivx.dll
[2009/08/07 01:34:57 | 00,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2009/08/07 01:34:57 | 00,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2009/08/07 01:34:57 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/07/07 19:03:29 | 00,001,085 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\ling-pl.gif
[2009/07/07 19:03:17 | 00,000,916 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\ling-pl.src
[2009/08/07 01:34:57 | 00,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2009/08/07 01:34:57 | 00,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2009/08/07 01:34:57 | 00,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2009/08/07 01:34:58 | 00,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml
O1 HOSTS File: (327720 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 11213 more lines...
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (IeCatch2 Class) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\Program Files\FlashGet\Jccatch.dll (Amaze Soft)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (FlashGet Bar) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll (Amaze Soft)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe (Micro-Star International Co., Ltd.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [WheelMouse] C:\MSI\Advanced Wheel Mouse\wh_exec.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.DLL (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.DLL (Microsoft Corporation)
O4 - HKU\S-1-5-21-1901676302-259906463-4087737416-1000..\Run: [ALLUpdate] C:\Program Files\ALLPlayer\ALLUpdate.exe ()
O4 - HKU\S-1-5-21-1901676302-259906463-4087737416-1000..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-1901676302-259906463-4087737416-1000..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1901676302-259906463-4087737416-1000..\Run: [Skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm ()
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm ()
O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (Amaze Soft)
O9 - Extra 'Tools' menuitem : &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (Amaze Soft)
O13 - gopher Prefix: missing
O15 - HKLM\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\.DEFAULT\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-18\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-1901676302-259906463-4087737416-1000\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.168.4.100 192.168.123.254
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{6e0ffc67-93eb-11de-a566-00242164ce5c}\Shell - "" = AutoRun
O33 - MountPoints2\{6e0ffc67-93eb-11de-a566-00242164ce5c}\Shell\AutoRun\command - "" = I:\1.bat -- File not found
O33 - MountPoints2\{a81586f3-6a6d-11de-8888-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{a81586f3-6a6d-11de-8888-806e6f6e6963}\Shell\AutoRun\command - "" = E:\CDSetup.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2009/09/06 01:13:01 | 00,001,702 | ---- | C] () -- C:\Users\Max\Desktop\HijackThis.lnk
[2009/09/06 01:13:00 | 00,000,000 | ---D | C] -- C:\Program Files\HijackThis
[2009/09/05 23:01:19 | 00,001,943 | ---- | C] () -- C:\Users\Max\Desktop\Wlatcy Moch.lnk
[2009/09/05 19:36:39 | 00,001,080 | ---- | C] () -- C:\Users\Public\Desktop\PLIPTV.pl.lnk
[2009/09/05 18:36:05 | 00,002,368 | ---- | C] () -- C:\Windows\System32\sdbackup.reg
[2009/09/05 15:00:26 | 00,001,055 | ---- | C] () -- C:\Users\Max\Desktop\Spybot - Search & Destroy.lnk
[2009/09/05 15:00:21 | 00,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2009/09/05 15:00:21 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2009/09/04 16:48:38 | 04,240,384 | ---- | C] (Microsoft) -- C:\Windows\System32\GameUXLegacyGDFs.dll
[2009/09/04 16:48:38 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Apphlpdm.dll
[2009/08/31 19:28:58 | 00,000,000 | ---D | C] -- C:\Windows\Sun
[2009/08/30 18:28:47 | 00,000,000 | ---D | C] -- C:\ProgramData\Hagel Technologies
[2009/08/29 20:19:07 | 00,001,879 | ---- | C] () -- C:\Users\Public\Desktop\Worms 4 Mayhem.lnk
[2009/08/29 18:20:33 | 00,000,000 | ---D | C] -- C:\Users\Max\AppData\Roaming\PlayFirst
[2009/08/29 18:20:33 | 00,000,000 | ---D | C] -- C:\ProgramData\PlayFirst
[2009/08/29 18:20:20 | 00,001,252 | ---- | C] () -- C:\Users\Max\Desktop\Chocolatier - Decadence by Design.lnk
[2009/08/29 18:20:13 | 00,000,000 | ---D | C] -- C:\Windows\Chocolatier Decadence by Design
[2009/08/29 17:51:29 | 00,018,120 | ---- | C] () -- C:\Users\Max\AppData\Local\slot1.mm1
[2009/08/29 15:48:47 | 00,000,454 | -H-- | C] () -- C:\Windows\tasks\User_Feed_Synchronization-{6E5B0C0D-4451-486F-B03A-19E499FAE3F1}.job
[2009/08/29 09:06:20 | 00,000,000 | ---D | C] -- C:\Users\Max\AppData\Roaming\POLENG4
[2009/08/29 09:04:11 | 00,000,000 | ---D | C] -- C:\Program Files\Translatica 4
[2009/08/27 16:50:06 | 00,000,000 | ---D | C] -- C:\ProgramData\Office Genuine Advantage
[2009/08/26 17:40:53 | 00,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2009/08/23 19:01:44 | 00,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\id Software
[2009/08/22 13:38:43 | 00,000,000 | -HSD | C] -- C:\Windows\ftpcache
[2009/08/21 23:10:36 | 00,000,000 | ---D | C] -- C:\Users\Max\AppData\Roaming\Red Alert 3 Uprising
[2009/08/21 23:06:42 | 00,000,484 | ---- | C] () -- C:\Users\Max\Desktop\Mafia.pdf — skrót.lnk
[2009/08/21 22:55:26 | 00,001,033 | ---- | C] () -- C:\Users\Max\Desktop\MISE.exe — skrót.lnk
[2009/08/21 21:35:20 | 00,000,000 | ---D | C] -- C:\Users\Max\AppData\Roaming\LucasArts
[2009/08/21 19:37:11 | 00,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_2.dll
[2009/08/21 19:37:11 | 00,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_2.dll
[2009/08/21 19:37:11 | 00,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_1.dll
[2009/08/21 19:37:10 | 03,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_39.dll
[2009/08/21 19:37:10 | 01,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_39.dll
[2009/08/21 19:37:10 | 00,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_39.dll
[2009/08/21 19:23:07 | 00,000,000 | ---D | C] -- C:\Users\Public\Documents\Silent Hill Homecoming
[2009/08/21 19:05:19 | 00,000,000 | ---D | C] -- C:\Program Files\Creative
[2009/08/21 17:36:47 | 00,000,000 | ---D | C] -- C:\Users\Max\AppData\Roaming\Hoyle FaceCreator
[2009/08/21 17:36:44 | 00,000,000 | ---D | C] -- C:\Users\Max\AppData\Roaming\Hoyle
[2009/08/21 17:33:08 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Datalode
[2009/08/21 14:09:22 | 00,000,000 | ---D | C] -- C:\Windows\Minidump
[2009/08/21 01:09:54 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Sandlot Shared
[2009/08/21 01:09:53 | 00,000,000 | ---D | C] -- C:\ProgramData\Sandlot Games
[2009/08/20 23:26:03 | 00,000,000 | ---D | C] -- C:\Users\Max\Documents\Boolat Games
[2009/08/19 17:51:03 | 00,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2009/08/19 17:51:03 | 00,000,000 | RHS- | C] () -- C:\IO.SYS
[2009/08/17 20:15:57 | 00,000,000 | ---D | C] -- C:\Users\Max\AppData\Roaming\RayV
[2009/08/17 20:15:54 | 00,000,000 | ---D | C] -- C:\Program Files\RayV
[2009/08/14 22:35:47 | 00,000,762 | ---- | C] () -- C:\Users\Max\Desktop\ALLPlayer V4.1.lnk
[2009/08/14 22:35:41 | 00,795,648 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2009/08/14 22:35:41 | 00,000,000 | ---D | C] -- C:\ProgramData\ALLPlayer
[2009/08/14 22:35:40 | 00,892,928 | ---- | C] (Free Software Foundation) -- C:\Windows\System32\iconv.dll
[2009/08/14 22:35:40 | 00,675,840 | ---- | C] () -- C:\Windows\System32\ac3filter.ax
[2009/08/14 22:35:36 | 00,000,000 | ---D | C] -- C:\Program Files\ALLPlayer
[2009/08/14 22:34:20 | 06,309,344 | ---- | C] (ALLPlayer ) -- C:\Users\Max\Desktop\ALLPlayerPL.exe
[2009/08/12 17:21:32 | 02,066,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstscax.dll
[2009/08/12 17:21:30 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\atl.dll
[2009/08/12 17:21:29 | 00,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wkssvc.dll
[2009/08/12 17:21:25 | 00,499,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\kerberos.dll
[2009/08/12 17:21:25 | 00,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msv1_0.dll
[2009/08/12 17:21:25 | 00,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wdigest.dll
[2009/08/12 17:21:24 | 00,270,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\schannel.dll
[2009/08/12 17:21:23 | 01,259,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lsasrv.dll
[2009/08/12 17:21:23 | 00,439,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\ksecdd.sys
[2009/08/12 17:21:22 | 00,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\secur32.dll
[2009/08/12 17:21:22 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\lsass.exe
[2009/08/12 17:21:10 | 10,628,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmp.dll
[2009/08/12 17:21:09 | 00,313,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmpdxm.dll
[2009/08/12 17:21:08 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\spwmp.dll
[2009/08/12 17:21:08 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdxm.ocx
[2009/08/12 17:21:08 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxmasf.dll
[2009/08/12 17:21:07 | 08,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wmploc.DLL
[2009/08/12 17:21:07 | 00,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdxm.tlb
[2009/08/12 17:21:07 | 00,018,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\amcompat.tlb
[2009/08/12 17:21:04 | 00,091,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\avifil32.dll
[2009/08/11 17:30:50 | 00,000,000 | ---D | C] -- C:\Users\Max\AppData\Local\ESET
[2009/08/11 17:27:09 | 00,000,135 | ---- | C] () -- C:\Windows\SCRABMAN.INI
[2009/08/03 15:07:42 | 00,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/07/17 18:20:04 | 00,279,712 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2009/07/17 18:20:03 | 00,025,888 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2009/07/16 17:56:39 | 00,721,904 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
[2009/07/14 19:46:30 | 00,138,184 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2009/07/14 18:07:25 | 00,168,448 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2009/07/07 17:49:49 | 00,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2008/11/12 15:21:00 | 00,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2007/01/25 16:45:02 | 00,006,784 | ---- | C] () -- C:\Windows\System32\drivers\whfltr2k.sys
[2006/11/02 13:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 11:23:31 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini
[2006/11/02 11:23:31 | 00,000,144 | ---- | C] () -- C:\Windows\win.ini
[2006/11/02 08:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2009/09/06 01:13:01 | 00,001,702 | ---- | M] () -- C:\Users\Max\Desktop\HijackThis.lnk
[2009/09/06 01:07:18 | 00,004,112 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/09/06 01:07:18 | 00,004,112 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/09/06 01:07:16 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/09/06 01:07:15 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/09/05 23:22:05 | 00,000,454 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{6E5B0C0D-4451-486F-B03A-19E499FAE3F1}.job
[2009/09/05 23:01:19 | 00,001,943 | ---- | M] () -- C:\Users\Max\Desktop\Wlatcy Moch.lnk
[2009/09/05 19:36:39 | 00,001,080 | ---- | M] () -- C:\Users\Public\Desktop\PLIPTV.pl.lnk
[2009/09/05 18:36:05 | 00,002,368 | ---- | M] () -- C:\Windows\System32\sdbackup.reg
[2009/09/05 16:36:55 | 00,158,208 | ---- | M] () -- C:\Users\Max\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/05 15:48:11 | 03,659,412 | -H-- | M] () -- C:\Users\Max\AppData\Local\IconCache.db
[2009/09/05 15:37:56 | 00,001,356 | ---- | M] () -- C:\Users\Max\AppData\Local\d3d9caps.dat
[2009/09/05 15:05:28 | 00,327,720 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2009/09/05 15:00:26 | 00,001,055 | ---- | M] () -- C:\Users\Max\Desktop\Spybot - Search & Destroy.lnk
[2009/08/31 00:49:54 | 00,018,120 | ---- | M] () -- C:\Users\Max\AppData\Local\slot1.mm1
[2009/08/30 18:49:49 | 01,468,980 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009/08/30 18:49:49 | 00,666,750 | ---- | M] () -- C:\Windows\System32\perfh015.dat
[2009/08/30 18:49:49 | 00,600,394 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009/08/30 18:49:49 | 00,131,410 | ---- | M] () -- C:\Windows\System32\perfc015.dat
[2009/08/30 18:49:49 | 00,105,868 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009/08/29 20:20:38 | 00,001,879 | ---- | M] () -- C:\Users\Public\Desktop\Worms 4 Mayhem.lnk
[2009/08/29 18:20:20 | 00,001,252 | ---- | M] () -- C:\Users\Max\Desktop\Chocolatier - Decadence by Design.lnk
[2009/08/29 01:27:49 | 04,240,384 | ---- | M] (Microsoft) -- C:\Windows\System32\GameUXLegacyGDFs.dll
[2009/08/29 01:14:38 | 00,028,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\Apphlpdm.dll
[2009/08/21 23:06:42 | 00,000,484 | ---- | M] () -- C:\Users\Max\Desktop\Mafia.pdf — skrót.lnk
[2009/08/21 22:55:26 | 00,001,033 | ---- | M] () -- C:\Users\Max\Desktop\MISE.exe — skrót.lnk
[2009/08/19 17:51:03 | 00,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2009/08/19 17:51:03 | 00,000,000 | RHS- | M] () -- C:\IO.SYS
[2009/08/16 22:18:25 | 00,002,379 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2009/08/14 22:35:47 | 00,000,762 | ---- | M] () -- C:\Users\Max\Desktop\ALLPlayer V4.1.lnk
[2009/08/14 22:35:00 | 06,309,344 | ---- | M] (ALLPlayer ) -- C:\Users\Max\Desktop\ALLPlayerPL.exe
[2009/08/11 17:30:03 | 00,000,135 | ---- | M] () -- C:\Windows\SCRABMAN.INI
[color=#E56717]========== LOP Check ==========[/color]
[2006/11/02 13:37:34 | 00,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming
[2006/11/02 13:37:34 | 00,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\Media Center Programs
[2006/11/02 13:37:34 | 00,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming
[2006/11/02 13:37:34 | 00,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\Media Center Programs
[2009/09/05 17:54:48 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming
[2009/08/05 18:40:30 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Atari
[2009/07/06 22:18:39 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\ATI
[2009/08/28 10:29:35 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\BESTplayer
[2009/07/16 18:00:32 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\DAEMON Tools Lite
[2009/07/16 18:38:15 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\DAEMON Tools Pro
[2009/07/07 18:21:56 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\ESET
[2009/08/29 13:21:26 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Hoyle
[2009/08/22 03:52:42 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Hoyle FaceCreator
[2009/07/14 19:44:01 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Leadertech
[2009/08/21 21:35:20 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\LucasArts
[2006/11/02 13:37:34 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Media Center Programs
[2009/08/29 18:20:33 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\PlayFirst
[2009/08/29 09:06:20 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\POLENG4
[2009/09/05 21:12:14 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\RayV
[2009/08/22 01:17:23 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Red Alert 3 Uprising
[2009/08/04 22:55:42 | 00,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\TAC-CM CRACKED
[2009/09/06 01:07:16 | 00,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA.DAT
[2009/09/05 15:48:16 | 00,031,704 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009/09/05 23:22:05 | 00,000,454 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{6E5B0C0D-4451-486F-B03A-19E499FAE3F1}.job
[color=#E56717]========== Purity Check ==========[/color]
< End of report >
OTL Extras
- Kod: Zaznacz wszystko
http://wklej.org/hash/eec81ac1f9/
HijackThis Log
- Kod: Zaznacz wszystko
http://wklej.org/hash/e33b7d9376/