1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
12.
13.
14.
15.
16.
17.
18.
19.
20.
21.
22.
23.
24.
25.
26.
27.
28.
29.
30.
31.
32.
33.
34.
35.
36.
37.
38.
39.
40.
41.
42.
43.
44.
45.
46.
47.
48.
49.
50.
51.
52.
53.
54.
55.
56.
57.
58.
59.
60.
61.
62.
63.
64.
65.
66.
67.
68.
69.
70.
71.
72.
73.
74.
75.
76.
77.
78.
79.
80.
81.
82.
83.
84.
85.
86.
87.
88.
89.
90.
91.
92.
93.
94.
95.
96.
97.
98.
99.
100.
101.
102.
103.
104.
105.
106.
107.
108.
109.
110.
111.
112.
113.
114.
115.
116.
117.
118.
119.
120.
121.
122.
123.
124.
125.
126.
127.
128.
129.
130.
131.
132.
133.
134.
135.
136.
137.
138.
139.
140.
141.
142.
143.
144.
145.
146.
147.
148.
149.
150.
151.
152.
153.
154.
155.
156.
157.
158.
159.
160.
161.
162.
163.
164.
165.
166.
167.
168.
169.
170.
171.
172.
173.
174.
175.
176.
177.
178.
179.
180.
181.
182.
183.
184.
185.
186.
187.
188.
189.
190.
191.
192.
193.
194.
195.
196.
197.
198.
199.
200.
201.
202.
203.
204.
205.
206.
207.
208.
209.
210.
211.
212.
213.
214.
215.
216.
217.
218.
219.
220.
221.
222.
223.
224.
225.
226.
227.
228.
229.
230.
231.
232.
233.
234.
235.
236.
237.
238.
239.
240.
241.
242.
243.
244.
245.
246.
247.
248.
249.
250.
251.
252.
253.
254.
255.
256.
257.
258.
259.
260.
261.
262.
263.
264.
265.
266.
267.
268.
269.
270.
271.
272.
273.
274.
275.
276.
277.
278.
279.
280.
281.
282.
283.
284.
285.
286.
287.
288.
289.
290.
291.
292.
293.
294.
295.
296.
297.
298.
299.
300.
301.
302.
303.
304.
305.
306.
307.
308.
309.
310.
311.
312.
313.
314.
315.
316.
317.
318. | OTL logfile created on: 2009-12-13 17:18:48 - Run 4
OTL by OldTimer - Version 3.1.16.0 Folder = C:\\Documents and Settings\\admin\\Pulpit
Windows XP Professional Edition Dodatek Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
511,49 Mb Total Physical Memory | 112,25 Mb Available Physical Memory | 21,95% Memory free
1,22 Gb Paging File | 0,83 Gb Available in Paging File | 67,71% Paging File free
Paging file location(s): C:\\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\\WINDOWS | %ProgramFiles% = C:\\Program Files
Drive C: | 24,53 Gb Total Space | 14,67 Gb Free Space | 59,81% Space Free | Partition Type: NTFS
Drive D: | 50,03 Gb Total Space | 32,72 Gb Free Space | 65,40% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PPP-CE631D22594
Current User Name: admin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2009-12-12 20:57:01 | 00,538,112 | ---- | M] (OldTimer Tools) -- C:\\Documents and Settings\\admin\\Pulpit\\OTL.exe
PRC - [2009-10-29 12:09:17 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\\Program Files\\Mozilla Firefox\\firefox.exe
PRC - [2009-05-15 17:55:51 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\\Program Files\\Java\\jre6\\bin\\jqs.exe
PRC - [2008-11-26 18:18:51 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\\Program Files\\Alwil Software\\Avast4\\ashDisp.exe
PRC - [2008-11-26 18:18:46 | 00,155,160 | ---- | M] (ALWIL Software) -- C:\\Program Files\\Alwil Software\\Avast4\\ashServ.exe
PRC - [2008-11-26 18:18:32 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\\Program Files\\Alwil Software\\Avast4\\ashMaiSv.exe
PRC - [2008-11-26 18:16:23 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\\Program Files\\Alwil Software\\Avast4\\ashWebSv.exe
PRC - [2008-11-26 18:12:08 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\\Program Files\\Alwil Software\\Avast4\\aswUpdSv.exe
PRC - [2007-07-06 13:02:26 | 00,561,152 | ---- | M] (Lavasoft AB) -- C:\\Program Files\\Lavasoft\\Ad-Aware 2007\\aawservice.exe
PRC - [2007-06-13 14:23:49 | 01,034,752 | ---- | M] (Microsoft Corporation) -- C:\\WINDOWS\\explorer.exe
PRC - [2006-11-24 17:16:50 | 20,058,152 | ---- | M] () -- C:\\Program Files\\Skype\\Phone\\Skype.exe
PRC - [2006-08-14 13:01:04 | 00,921,600 | ---- | M] (Eset ) -- C:\\Program Files\\ESET\\nod32kui.exe
PRC - [2006-08-14 13:01:04 | 00,507,904 | ---- | M] (Eset ) -- C:\\Program Files\\ESET\\nod32krn.exe
PRC - [2006-03-09 14:29:00 | 00,143,436 | ---- | M] (NVIDIA Corporation) -- C:\\WINDOWS\\system32\\nvsvc32.exe
PRC - [2005-07-13 02:32:18 | 00,294,400 | ---- | M] (DOSPRN) -- C:\\Program Files\\Dosprn\\DOSprn.exe
[color=#E56717]========== Modules (SafeList) ==========[/color]
MOD - [2009-12-12 20:57:01 | 00,538,112 | ---- | M] (OldTimer Tools) -- C:\\Documents and Settings\\admin\\Pulpit\\OTL.exe
MOD - [2006-08-25 16:51:13 | 01,054,208 | ---- | M] (Microsoft Corporation) -- C:\\WINDOWS\\WinSxS\\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\\comctl32.dll
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV - [2009-05-15 17:55:51 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- C:\\Program Files\\Java\\jre6\\bin\\jqs.exe -- (JavaQuickStarterService)
SRV - [2008-11-26 18:18:46 | 00,155,160 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\\Program Files\\Alwil Software\\Avast4\\ashServ.exe -- (avast! Antivirus)
SRV - [2008-11-26 18:18:32 | 00,254,040 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\\Program Files\\Alwil Software\\Avast4\\ashMaiSv.exe -- (avast! Mail Scanner)
SRV - [2008-11-26 18:16:23 | 00,352,920 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\\Program Files\\Alwil Software\\Avast4\\ashWebSv.exe -- (avast! Web Scanner)
SRV - [2008-11-26 18:12:08 | 00,018,752 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\\Program Files\\Alwil Software\\Avast4\\aswUpdSv.exe -- (aswUpdSv)
SRV - [2007-07-06 13:02:26 | 00,561,152 | ---- | M] (Lavasoft AB) [Auto | Running] -- C:\\Program Files\\Lavasoft\\Ad-Aware 2007\\aawservice.exe -- (aawservice)
SRV - [2006-08-14 13:01:04 | 00,507,904 | ---- | M] (Eset ) [Auto | Running] -- C:\\Program Files\\Eset\\nod32krn.exe -- (NOD32krn)
SRV - [2006-03-09 14:29:00 | 00,143,436 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\\WINDOWS\\system32\\nvsvc32.exe -- (NVSvc)
SRV - [2005-04-03 23:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Common Files\\InstallShield\\Driver\\11\\Intel 32\\IDriverT.exe -- (IDriverT)
SRV - [2003-07-28 19:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Common Files\\Microsoft Shared\\Source Engine\\OSE.EXE -- (ose)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - [2008-11-26 18:18:18 | 00,094,032 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\\WINDOWS\\system32\\drivers\\aswmon2.sys -- (aswMon2)
DRV - [2008-11-26 18:17:36 | 00,111,184 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\\WINDOWS\\system32\\drivers\\aswSP.sys -- (aswSP)
DRV - [2008-11-26 18:17:25 | 00,020,560 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\\WINDOWS\\system32\\drivers\\aswFsBlk.sys -- (aswFsBlk)
DRV - [2008-11-26 18:16:38 | 00,050,864 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\\WINDOWS\\system32\\drivers\\aswTdi.sys -- (aswTdi)
DRV - [2008-11-26 18:16:29 | 00,023,152 | ---- | M] (ALWIL Software) [Kernel | On_Demand | Running] -- C:\\WINDOWS\\system32\\drivers\\aswRdr.sys -- (aswRdr)
DRV - [2008-11-26 18:15:35 | 00,026,944 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\\WINDOWS\\system32\\drivers\\aavmker4.sys -- (Aavmker4)
DRV - [2007-06-04 14:18:48 | 00,009,344 | ---- | M] (Lavasoft AB) [Kernel | On_Demand | Stopped] -- C:\\WINDOWS\\system32\\drivers\\NSDriver.sys -- (Ad-Watch Connect Filter)
DRV - [2006-11-03 23:45:48 | 00,178,913 | R--- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\\WINDOWS\\system32\\drivers\\V0260Vid.sys -- (V0260VID)
DRV - [2006-08-14 13:01:05 | 00,502,368 | ---- | M] (Eset ) [Kernel | Auto | Running] -- C:\\WINDOWS\\system32\\drivers\\amon.sys -- (AMON)
DRV - [2006-06-13 00:05:12 | 00,043,008 | ---- | M] (VIA Technologies, Inc. ) [Kernel | On_Demand | Stopped] -- C:\\WINDOWS\\system32\\drivers\\fetnd5bv.sys -- (FETND5BV)
DRV - [2006-03-31 13:38:00 | 03,960,896 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\\WINDOWS\\system32\\drivers\\alcxwdm.sys -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2006-03-09 14:29:00 | 03,650,368 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\\WINDOWS\\system32\\drivers\\nv4_mini.sys -- (nv)
DRV - [2004-08-04 00:08:22 | 00,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\\WINDOWS\\system32\\drivers\\gameenum.sys -- (gameenum)
DRV - [2004-07-17 11:36:38 | 00,027,440 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\\WINDOWS\\system32\\drivers\\secdrv.sys -- (Secdrv)
DRV - [2003-09-04 03:37:04 | 00,041,984 | R--- | M] (VIA Technologies, Inc. ) [Kernel | On_Demand | Running] -- C:\\WINDOWS\\system32\\drivers\\fetnd5b.sys -- (FETNDISB)
DRV - [2003-07-17 09:10:06 | 00,007,040 | R--- | M] (VIA Networking Technologies, Inc. ) [Kernel | On_Demand | Stopped] -- C:\\WINDOWS\\system32\\ntsim.sys -- (NTSIM)
DRV - [2003-07-01 21:42:00 | 00,027,904 | R--- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\\WINDOWS\\system32\\DRIVERS\\viaagp1.sys -- (viaagp1)
DRV - [2001-08-18 01:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\\WINDOWS\\system32\\drivers\\ptilink.sys -- (Ptilink)
DRV - [2001-08-17 23:00:04 | 00,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\\WINDOWS\\system32\\drivers\\msmpu401.sys -- (ms_mpu401)
DRV - [2001-08-17 21:13:08 | 00,027,165 | ---- | M] (VIA Technologies, Inc. ) [Kernel | On_Demand | Stopped] -- C:\\WINDOWS\\system32\\drivers\\fetnd5.sys -- (FETNDIS)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = %SystemRoot%\\system32\\blank.htm
IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = http://szukaj.interia.pl/
IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..keyword.URL: \"http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZS&fl=0&ptb=RXlXIHVAruvnUN6m4x4hLQ&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor=\"
FF - HKLM\\software\\mozilla\\Mozilla Firefox 3.0.15\\extensions\\\\Components: C:\\Program Files\\Mozilla Firefox\\components [2009-10-31 18:03:33 | 00,000,000 | ---D | M]
FF - HKLM\\software\\mozilla\\Mozilla Firefox 3.0.15\\extensions\\\\Plugins: C:\\Program Files\\Mozilla Firefox\\plugins [2009-12-13 14:12:22 | 00,000,000 | ---D | M]
FF - HKLM\\software\\mozilla\\Mozilla Thunderbird 2.0.0.16\\extensions\\\\Components: C:\\Program Files\\Mozilla Thunderbird\\components [2008-08-26 07:34:55 | 00,000,000 | ---D | M]
FF - HKLM\\software\\mozilla\\Mozilla Thunderbird 2.0.0.16\\extensions\\\\Plugins: C:\\Program Files\\Mozilla Thunderbird\\plugins [2008-12-22 18:24:04 | 00,000,000 | ---D | M]
[2008-08-26 08:20:37 | 00,000,000 | ---D | M] -- C:\\Documents and Settings\\admin\\Dane aplikacji\\Mozilla\\Extensions
[2009-12-13 14:24:33 | 00,000,000 | ---D | M] -- C:\\Documents and Settings\\admin\\Dane aplikacji\\Mozilla\\Firefox\\Profiles\\e1jfl1ih.default\\extensions
[2009-12-13 14:24:25 | 00,000,000 | ---D | M] -- C:\\Documents and Settings\\admin\\Dane aplikacji\\Mozilla\\Firefox\\Profiles\\e1jfl1ih.default\\extensions\\firefox@tvunetworks.com
[2009-09-13 16:03:48 | 00,000,000 | ---D | M] -- C:\\Documents and Settings\\admin\\Dane aplikacji\\Mozilla\\Firefox\\Profiles\\e1jfl1ih.default\\extensions\\fr-FR@dictionaries.addons.mozilla.org
[2009-12-13 14:24:33 | 00,000,000 | ---D | M] -- C:\\Program Files\\Mozilla Firefox\\extensions
[2009-07-29 23:42:45 | 00,002,767 | ---- | M] () -- C:\\Program Files\\Mozilla Firefox\\searchplugins\\allegro-pl.xml
[2008-12-20 13:21:06 | 00,001,406 | ---- | M] () -- C:\\Program Files\\Mozilla Firefox\\searchplugins\\fbc-pl.xml
[2008-12-20 13:21:06 | 00,000,917 | ---- | M] () -- C:\\Program Files\\Mozilla Firefox\\searchplugins\\merlin-pl.xml
[2008-12-20 13:21:06 | 00,000,858 | ---- | M] () -- C:\\Program Files\\Mozilla Firefox\\searchplugins\\pwn-pl.xml
[2008-12-20 13:21:06 | 00,001,183 | ---- | M] () -- C:\\Program Files\\Mozilla Firefox\\searchplugins\\wikipedia-pl.xml
[2008-12-20 13:21:06 | 00,001,683 | ---- | M] () -- C:\\Program Files\\Mozilla Firefox\\searchplugins\\wp-pl.xml
O1 HOSTS File: (742 bytes) - C:\\WINDOWS\\system32\\drivers\\etc\\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\\Program Files\\Yahoo!\\Companion\\Installs\\cpn\\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\\Program Files\\Common Files\\Adobe\\Acrobat\\ActiveX\\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files\\Java\\jre6\\bin\\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files\\Java\\jre6\\bin\\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\\Program Files\\Java\\jre6\\lib\\deploy\\jqs\\ie\\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\\Documents and Settings\\admin\\Dane aplikacji\\Nowe Gadu-Gadu\\_userdata\\ggbho.1.dll (GG Network S.A.)
O3 - HKLM\\..\\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\\Program Files\\Yahoo!\\Companion\\Installs\\cpn\\yt.dll (Yahoo! Inc.)
O3 - HKCU\\..\\Toolbar\\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\\Program Files\\Yahoo!\\Companion\\Installs\\cpn\\yt.dll (Yahoo! Inc.)
O4 - HKLM..\\Run: [avast!] C:\\Program Files\\Alwil Software\\Avast4\\ashDisp.exe (ALWIL Software)
O4 - HKLM..\\Run: [nod32kui] C:\\Program Files\\Eset\\nod32kui.exe (Eset )
O4 - HKLM..\\Run: [NvCplDaemon] C:\\WINDOWS\\System32\\NvCpl.DLL (NVIDIA Corporation)
O4 - HKCU..\\Run: [Skype] C:\\Program Files\\Skype\\Phone\\Skype.exe ()
O4 - Startup: C:\\Documents and Settings\\admin\\Menu Start\\Programy\\Autostart\\DOSprn.lnk = C:\\Program Files\\Dosprn\\DOSprn.exe (DOSPRN)
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra \'Tools\' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files\\Java\\jre6\\bin\\npjpi160_13.dll (Sun Microsystems, Inc.)
O10 - Protocol_Catalog9\\Catalog_Entries\\000000000001 - C:\\WINDOWS\\System32\\imon.dll (Eset )
O10 - Protocol_Catalog9\\Catalog_Entries\\000000000002 - C:\\WINDOWS\\System32\\imon.dll (Eset )
O10 - Protocol_Catalog9\\Catalog_Entries\\000000000003 - C:\\WINDOWS\\System32\\imon.dll (Eset )
O10 - Protocol_Catalog9\\Catalog_Entries\\000000000004 - C:\\WINDOWS\\System32\\imon.dll (Eset )
O10 - Protocol_Catalog9\\Catalog_Entries\\000000000005 - C:\\WINDOWS\\System32\\imon.dll (Eset )
O10 - Protocol_Catalog9\\Catalog_Entries\\000000000011 - C:\\WINDOWS\\System32\\imon.dll (Eset )
O15 - HKLM\\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {18506D80-9B80-11D4-82C2-0080C8D7ED4A} http://67.15.101.3/g_bin/pl/roulette_2_0_0_23.cab (GameDesire Roulette)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\\WINDOWS\\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 () - http://www.autogaleria.pl/fotografie/mazda/mazda_ryuga_concept_2007_08.jpg
O24 - Desktop Components:1 (Moja bieżąca strona główna) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006-08-14 12:53:49 | 00,000,000 | ---- | M] () - C:\\AUTOEXEC.BAT -- [ NTFS ]
O32 - Unable to obtain root file information for disk D:\\
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\\WINDOWS\\System32\\lsdelete.exe ()
O35 - comfile [open] -- \"%1\" %*
O35 - exefile [open] -- \"%1\" %*
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2009-12-13 14:46:08 | 00,000,000 | ---D | C] -- C:\\Documents and Settings\\All Users\\Dane aplikacji\\Panda Security
[2009-12-13 14:46:03 | 00,000,000 | ---D | C] -- C:\\Program Files\\Panda USB Vaccine
[2009-12-13 14:12:18 | 00,000,000 | ---D | C] -- C:\\_OTL
[2009-12-13 14:10:24 | 00,000,000 | -H-D | C] -- C:\\WINDOWS\\System32\\GroupPolicy
[2009-12-13 14:09:29 | 00,848,856 | ---- | C] (Panda Security ) -- C:\\Documents and Settings\\admin\\Pulpit\\USBVaccineSetup.exe
[2009-12-12 22:43:17 | 00,000,000 | ---D | C] -- C:\\Program Files\\CCleaner
[2009-12-12 22:36:30 | 03,326,576 | ---- | C] (Piriform Ltd) -- C:\\Documents and Settings\\admin\\Pulpit\\ccsetup_2.26.1050(dobreprogramy.pl).exe
[2009-12-12 20:57:55 | 00,000,000 | ---D | C] -- C:\\Program Files\\Trend Micro
[2009-12-12 20:56:43 | 00,538,112 | ---- | C] (OldTimer Tools) -- C:\\Documents and Settings\\admin\\Pulpit\\OTL.exe
[2009-12-12 20:56:07 | 00,812,344 | ---- | C] (Trend Micro Inc.) -- C:\\Documents and Settings\\admin\\Pulpit\\HJTInstall.exe
[2009-12-07 22:37:46 | 00,000,000 | ---D | C] -- C:\\Documents and Settings\\admin\\Pulpit\\45508-46-krajowa_rada_radiofonii_i_telewizji_pliki
[2009-12-05 13:23:51 | 00,000,000 | ---D | C] -- C:\\Program Files\\BuildDesk Polska
[2009-12-04 08:48:25 | 00,000,000 | ---D | C] -- C:\\Documents and Settings\\admin\\Moje dokumenty\\3.12.09r EDEN mecenas
[2009-11-29 17:11:12 | 00,000,000 | ---D | C] -- C:\\Documents and Settings\\admin\\Dane aplikacji\\gtk-2.0
[2009-11-29 16:38:29 | 00,000,000 | ---D | C] -- C:\\Documents and Settings\\admin\\.thumbnails
[2009-11-29 16:37:31 | 00,000,000 | ---D | C] -- C:\\Documents and Settings\\admin\\.gimp-2.6
[2009-11-29 16:37:25 | 00,000,000 | ---D | C] -- C:\\Documents and Settings\\admin\\.gegl-0.0
[2009-11-29 16:36:38 | 00,000,000 | ---D | C] -- C:\\Program Files\\GIMP-2.0
[2009-11-26 12:36:53 | 00,000,000 | ---D | C] -- C:\\Documents and Settings\\admin\\Pulpit\\sukienka na studniówkę
[2006-09-17 20:43:44 | 00,000,000 | ---D | M] -- C:\\Documents and Settings\\LocalService\\Ustawienia lokalne\\Dane aplikacji\\Microsoft
[2006-09-17 20:43:29 | 00,000,000 | --SD | M] -- C:\\Documents and Settings\\LocalService\\Dane aplikacji\\Microsoft
[2006-08-14 12:57:40 | 00,000,000 | --SD | M] -- C:\\Documents and Settings\\NetworkService\\Dane aplikacji\\Microsoft
[2006-08-14 12:57:40 | 00,000,000 | ---D | M] -- C:\\Documents and Settings\\NetworkService\\Ustawienia lokalne\\Dane aplikacji\\Microsoft
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2009-12-13 17:17:10 | 00,050,302 | ---- | M] () -- C:\\WINDOWS\\System32\\nvapps.xml
[2009-12-13 17:16:22 | 00,000,006 | -H-- | M] () -- C:\\WINDOWS\\tasks\\SA.DAT
[2009-12-13 17:16:14 | 00,002,048 | --S- | M] () -- C:\\WINDOWS\\bootstat.dat
[2009-12-13 17:16:12 | 53,640,3968 | -HS- | M] () -- C:\\hiberfil.sys
[2009-12-13 17:15:18 | 07,864,320 | -H-- | M] () -- C:\\Documents and Settings\\admin\\NTUSER.DAT
[2009-12-13 17:15:18 | 00,000,188 | -HS- | M] () -- C:\\Documents and Settings\\admin\\ntuser.ini
[2009-12-13 15:36:22 | 00,002,539 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\Microsoft Office Word 2003 (2).lnk
[2009-12-13 14:29:00 | 00,000,713 | ---- | M] () -- C:\\WINDOWS\\win.ini
[2009-12-13 14:29:00 | 00,000,243 | ---- | M] () -- C:\\WINDOWS\\system.ini
[2009-12-13 14:29:00 | 00,000,211 | -HS- | M] () -- C:\\boot.ini
[2009-12-13 14:11:05 | 00,000,448 | RHS- | M] () -- C:\\Documents and Settings\\All Users\\ntuser.pol
[2009-12-13 14:09:34 | 00,848,856 | ---- | M] (Panda Security ) -- C:\\Documents and Settings\\admin\\Pulpit\\USBVaccineSetup.exe
[2009-12-12 22:40:31 | 03,326,576 | ---- | M] (Piriform Ltd) -- C:\\Documents and Settings\\admin\\Pulpit\\ccsetup_2.26.1050(dobreprogramy.pl).exe
[2009-12-12 20:57:58 | 00,001,734 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\HijackThis.lnk
[2009-12-12 20:57:01 | 00,538,112 | ---- | M] (OldTimer Tools) -- C:\\Documents and Settings\\admin\\Pulpit\\OTL.exe
[2009-12-12 20:56:16 | 00,812,344 | ---- | M] (Trend Micro Inc.) -- C:\\Documents and Settings\\admin\\Pulpit\\HJTInstall.exe
[2009-12-12 17:02:41 | 00,002,206 | ---- | M] () -- C:\\WINDOWS\\System32\\wpa.dbl
[2009-12-07 22:37:49 | 00,065,798 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\45508-46-krajowa_rada_radiofonii_i_telewizji.htm
[2009-12-07 21:39:22 | 00,034,816 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\monika.doc
[2009-12-07 13:55:26 | 00,057,060 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\6.12.09r.pdf
[2009-12-07 13:55:06 | 00,062,141 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\4.12.09r.pdf
[2009-12-06 02:15:57 | 16,559,261 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\audyt Marzena 1.12.09r.rtf
[2009-12-06 01:15:26 | 01,384,812 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\Audyt zdjecie 1.jpg
[2009-12-05 23:46:12 | 00,022,016 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\POLITECHNIKA CZĘSTOCHOWSKA.doc
[2009-12-05 14:33:48 | 01,950,121 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\143356.JPG
[2009-12-05 14:31:26 | 01,943,817 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\143113.JPG
[2009-12-05 14:17:01 | 00,005,985 | ---- | M] () -- C:\\Documents and Settings\\admin\\.recently-used.xbel
[2009-12-05 14:17:01 | 00,004,456 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\male.jpg
[2009-12-05 13:59:07 | 00,355,321 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\raport_z_obliczen-1261.pdf
[2009-12-05 13:58:55 | 00,336,088 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\certyfikat-1261.pdf
[2009-12-05 13:57:00 | 01,356,452 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\MPeru(2).JPG
[2009-12-05 13:57:00 | 00,039,642 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\MPeru(2).bdec
[2009-12-05 13:23:56 | 00,000,847 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\BDEC Professional.lnk
[2009-12-03 16:46:53 | 00,043,520 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\studniówka!!.doc
[2009-12-02 09:11:55 | 00,283,598 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\IMG00009-20091201-1505.jpg
[2009-11-30 20:13:46 | 00,002,658 | ---- | M] () -- C:\\WINDOWS\\System32\\CONFIG.NT
[2009-11-30 13:52:54 | 00,083,968 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\Lista uczestników wycieczki kl. IIIb;klIIIC.doc
[2009-11-30 11:30:07 | 00,018,861 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\Lista uczestników wycieczki kl. IIIb;klIIIC.odt
[2009-11-29 16:37:07 | 00,000,794 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\GIMP 2.lnk
[2009-11-29 13:46:15 | 00,159,883 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\Odpowiedzi_Matematyka.zip
[2009-11-29 13:36:01 | 00,194,557 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\Arkusze_Matematyka(2).zip
[2009-11-28 21:11:14 | 00,054,156 | -H-- | M] () -- C:\\WINDOWS\\QTFont.qfn
[2009-11-27 23:59:34 | 00,194,557 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\Arkusze_Matematyka.zip
[2009-11-18 09:53:38 | 00,037,888 | ---- | M] () -- C:\\Documents and Settings\\admin\\Moje dokumenty\\Małgorzata Dybka plan.doc
[2009-11-17 13:51:00 | 00,046,592 | ---- | M] () -- C:\\Documents and Settings\\admin\\Pulpit\\Ogłoszenie przetarg- najem.doc
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2009-12-13 14:11:05 | 00,000,448 | RHS- | C] () -- C:\\Documents and Settings\\All Users\\ntuser.pol
[2009-12-12 20:57:57 | 00,001,734 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\HijackThis.lnk
[2009-12-07 22:37:46 | 00,065,798 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\45508-46-krajowa_rada_radiofonii_i_telewizji.htm
[2009-12-07 21:39:20 | 00,034,816 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\monika.doc
[2009-12-07 13:55:26 | 00,057,060 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\6.12.09r.pdf
[2009-12-07 13:55:06 | 00,062,141 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\4.12.09r.pdf
[2009-12-06 01:21:35 | 16,559,261 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\audyt Marzena 1.12.09r.rtf
[2009-12-05 23:35:29 | 00,022,016 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\POLITECHNIKA CZĘSTOCHOWSKA.doc
[2009-12-05 16:12:52 | 01,384,812 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\Audyt zdjecie 1.jpg
[2009-12-05 14:37:46 | 01,950,121 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\143356.JPG
[2009-12-05 14:37:45 | 01,943,817 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\143113.JPG
[2009-12-05 14:17:01 | 00,005,985 | ---- | C] () -- C:\\Documents and Settings\\admin\\.recently-used.xbel
[2009-12-05 14:17:01 | 00,004,456 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\male.jpg
[2009-12-05 13:59:07 | 00,355,321 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\raport_z_obliczen-1261.pdf
[2009-12-05 13:58:55 | 00,336,088 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\certyfikat-1261.pdf
[2009-12-05 13:57:00 | 01,356,452 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\MPeru(2).JPG
[2009-12-05 13:55:35 | 00,039,642 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\MPeru(2).bdec
[2009-12-05 13:23:56 | 00,000,847 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\BDEC Professional.lnk
[2009-12-03 16:46:52 | 00,043,520 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\studniówka!!.doc
[2009-12-02 09:11:55 | 00,283,598 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\IMG00009-20091201-1505.jpg
[2009-11-30 13:52:50 | 00,083,968 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\Lista uczestników wycieczki kl. IIIb;klIIIC.doc
[2009-11-30 10:55:04 | 00,018,861 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\Lista uczestników wycieczki kl. IIIb;klIIIC.odt
[2009-11-29 16:37:07 | 00,000,794 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\GIMP 2.lnk
[2009-11-29 13:46:15 | 00,159,883 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\Odpowiedzi_Matematyka.zip
[2009-11-29 13:35:59 | 00,194,557 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\Arkusze_Matematyka(2).zip
[2009-11-27 23:59:33 | 00,194,557 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\Arkusze_Matematyka.zip
[2009-11-18 09:53:37 | 00,037,888 | ---- | C] () -- C:\\Documents and Settings\\admin\\Moje dokumenty\\Małgorzata Dybka plan.doc
[2009-11-17 13:50:58 | 00,046,592 | ---- | C] () -- C:\\Documents and Settings\\admin\\Pulpit\\Ogłoszenie przetarg- najem.doc
[2009-10-30 19:14:36 | 00,000,132 | ---- | C] () -- C:\\WINDOWS\\winamp.ini
[2009-10-01 20:11:06 | 00,000,239 | ---- | C] () -- C:\\WINDOWS\\WINCMD.INI
[2009-01-24 16:31:09 | 00,000,600 | ---- | C] () -- C:\\Documents and Settings\\admin\\Ustawienia lokalne\\Dane aplikacji\\PUTTY.RND
[2009-01-01 18:40:44 | 00,022,723 | R--- | C] () -- C:\\WINDOWS\\System32\\sst1cl3.dll
[2009-01-01 18:39:27 | 00,139,776 | R--- | C] () -- C:\\WINDOWS\\System32\\SaXPEH.dll
[2009-01-01 18:39:27 | 00,138,752 | R--- | C] () -- C:\\WINDOWS\\System32\\SaXPWIA.dll
[2009-01-01 18:39:27 | 00,138,240 | R--- | C] () -- C:\\WINDOWS\\System32\\SaXPUIEx.dll
[2009-01-01 18:39:27 | 00,116,736 | R--- | C] () -- C:\\WINDOWS\\System32\\SaXPIPH.dll
[2009-01-01 18:39:27 | 00,087,040 | R--- | C] () -- C:\\WINDOWS\\System32\\SaXPSTI.dll
[2008-12-04 11:07:07 | 00,011,776 | ---- | C] () -- C:\\WINDOWS\\System32\\pmsbfn32.dll
[2008-12-04 11:01:18 | 00,000,412 | ---- | C] () -- C:\\WINDOWS\\MAXLINK.INI
[2008-03-15 20:30:20 | 00,000,021 | ---- | C] () -- C:\\WINDOWS\\pccuo.ini
[2008-03-15 20:30:17 | 00,001,871 | R--- | C] () -- C:\\WINDOWS\\~~~runcd.ini
[2008-03-15 20:30:15 | 00,028,672 | R--- | C] () -- C:\\WINDOWS\\pccuo.dll
[2008-03-01 12:44:54 | 00,000,000 | ---- | C] () -- C:\\WINDOWS\\PROTOCOL.INI
[2008-03-01 12:44:41 | 00,000,161 | ---- | C] () -- C:\\WINDOWS\\BrzeDemo.ini
[2007-06-26 15:40:26 | 00,000,013 | ---- | C] () -- C:\\WINDOWS\\TEXTware.ini
[2007-06-26 15:40:23 | 00,147,456 | ---- | C] () -- C:\\WINDOWS\\System32\\Twavbx32.dll
[2007-06-26 15:40:22 | 00,115,200 | ---- | C] () -- C:\\WINDOWS\\System32\\UnzDll.dll
[2007-06-26 15:40:22 | 00,088,064 | ---- | C] () -- C:\\WINDOWS\\System32\\idiom010227.dll
[2007-06-26 15:40:21 | 00,099,092 | ---- | C] () -- C:\\WINDOWS\\System32\\bass.dll
[2007-06-26 15:40:17 | 00,143,360 | ---- | C] () -- C:\\WINDOWS\\System32\\ILXTBS.DLL
[2007-05-20 19:12:30 | 00,000,112 | ---- | C] () -- C:\\WINDOWS\\ActiveSkin.INI
[2007-01-27 22:12:22 | 00,026,624 | ---- | C] () -- C:\\Documents and Settings\\admin\\Ustawienia lokalne\\Dane aplikacji\\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006-08-29 20:08:58 | 00,000,164 | ---- | C] () -- C:\\WINDOWS\\avrack.ini
[2006-08-27 11:42:41 | 00,000,238 | ---- | C] () -- C:\\WINDOWS\\mafosav.INI
[2006-08-25 20:54:01 | 00,000,258 | ---- | C] () -- C:\\WINDOWS\\naglos.INI
[2006-08-21 21:18:09 | 00,000,116 | ---- | C] () -- C:\\WINDOWS\\NeroDigital.ini
[2006-08-14 13:17:52 | 00,000,421 | ---- | C] () -- C:\\WINDOWS\\ODBC.INI
[2006-08-14 13:02:21 | 00,135,168 | ---- | C] () -- C:\\WINDOWS\\System32\\RtlCPAPI.dll
[2006-08-14 13:00:44 | 00,157,696 | ---- | C] () -- C:\\WINDOWS\\System32\\unrar.dll
[2006-08-14 13:00:41 | 00,856,064 | ---- | C] () -- C:\\WINDOWS\\System32\\xvidcore.dll
[2006-08-14 13:00:41 | 00,568,850 | ---- | C] () -- C:\\WINDOWS\\System32\\x264vfw.dll
[2006-08-14 13:00:41 | 00,217,088 | ---- | C] () -- C:\\WINDOWS\\System32\\xvidvfw.dll
[2006-08-14 13:00:40 | 03,596,288 | ---- | C] () -- C:\\WINDOWS\\System32\\qt-dx331.dll
[2006-08-14 13:00:39 | 00,005,120 | ---- | C] () -- C:\\WINDOWS\\System32\\ff_vfw.dll
[2006-08-14 13:00:39 | 00,000,547 | ---- | C] () -- C:\\WINDOWS\\System32\\ff_vfw.dll.manifest
[2006-03-09 14:29:00 | 01,662,976 | ---- | C] () -- C:\\WINDOWS\\System32\\nvwdmcpl.dll
[2006-03-09 14:29:00 | 01,466,368 | ---- | C] () -- C:\\WINDOWS\\System32\\nview.dll
[2006-03-09 14:29:00 | 01,019,904 | ---- | C] () -- C:\\WINDOWS\\System32\\nvwimg.dll
[2006-03-09 14:29:00 | 00,573,440 | ---- | C] () -- C:\\WINDOWS\\System32\\nvhwvid.dll
[2006-03-09 14:29:00 | 00,466,944 | ---- | C] () -- C:\\WINDOWS\\System32\\nvshell.dll
[2006-03-09 14:29:00 | 00,286,720 | ---- | C] () -- C:\\WINDOWS\\System32\\nvnt4cpl.dll
[2006-03-09 14:29:00 | 00,098,304 | ---- | C] () -- C:\\WINDOWS\\System32\\nvapi.dll
[2005-06-17 17:41:14 | 00,061,440 | ---- | C] () -- C:\\WINDOWS\\System32\\vuins32.dll
[2004-08-04 00:44:00 | 00,081,920 | ---- | C] () -- C:\\WINDOWS\\System32\\ieencode.dll
[2004-07-17 11:36:38 | 00,027,440 | ---- | C] () -- C:\\WINDOWS\\System32\\drivers\\secdrv.sys
< End of report >
|