OTL logfile created on: 27-11-2011 09:45:05 - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Marta\Pulpit\fixit Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: dd-MM-yyyy 1.99 Gb Total Physical Memory | 1.46 Gb Available Physical Memory | 73.13% Memory free 3.83 Gb Paging File | 3.51 Gb Available in Paging File | 91.66% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 125.84 Gb Total Space | 73.29 Gb Free Space | 58.24% Space Free | Partition Type: NTFS Drive D: | 205.07 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Drive G: | 335.15 Gb Total Space | 29.78 Gb Free Space | 8.89% Space Free | Partition Type: NTFS Computer Name: THINKPAD | User Name: Marta | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2011-11-26 22:04:48 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Marta\Pulpit\fixit\OTL.exe PRC - [2011-11-17 06:58:04 | 003,303,000 | ---- | M] (Akamai Technologies, Inc) -- C:\Documents and Settings\Marta\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe PRC - [2011-11-15 14:26:02 | 001,384,448 | ---- | M] () -- C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe PRC - [2011-11-15 14:15:50 | 006,003,000 | ---- | M] (Doctor Web, Ltd.) -- C:\Program Files\DrWeb\spideragent.exe PRC - [2011-11-08 11:04:48 | 000,040,960 | ---- | M] () -- C:\WINDOWS\system32\TpKmpSvc.exe PRC - [2011-11-07 11:00:00 | 000,086,528 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe PRC - [2011-11-07 10:59:58 | 000,077,824 | ---- | M] () -- C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe PRC - [2010-10-01 21:41:10 | 000,619,800 | ---- | M] (http://tortoisesvn.net) -- C:\Program Files\TortoiseSVN\bin\TSVNCache.exe PRC - [2008-06-12 02:25:18 | 000,037,232 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe PRC - [2008-06-11 22:43:26 | 000,640,376 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe PRC - [2008-04-14 18:21:16 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2005-12-21 17:08:06 | 001,988,144 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauthe.exe PRC - [2005-11-15 12:13:24 | 000,049,152 | R--- | M] (Utimaco Safeware AG) -- C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe PRC - [2005-07-05 13:57:12 | 000,077,824 | ---- | M] () -- C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2011-11-18 02:19:53 | 003,313,752 | ---- | M] () -- c:\Program Files\Common Files\Akamai\netsession_win_d768ebc.dll MOD - [2011-11-15 14:26:02 | 001,384,448 | ---- | M] () -- C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe MOD - [2011-11-08 11:04:48 | 000,040,960 | ---- | M] () -- C:\WINDOWS\system32\TpKmpSvc.exe MOD - [2011-11-07 10:59:58 | 000,077,824 | ---- | M] () -- C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe MOD - [2008-03-29 16:42:20 | 000,159,744 | ---- | M] () -- C:\Program Files\SubEdit-Player\codec\MatroskaSplitter\mmfinfo.dll MOD - [2008-03-29 16:41:52 | 000,023,552 | ---- | M] () -- C:\Program Files\SubEdit-Player\codec\MatroskaSplitter\mkunicode.dll MOD - [2006-03-23 00:13:00 | 000,073,728 | ---- | M] () -- C:\Program Files\ThinkPad\Utilities\PWRMGRIF.DLL MOD - [2006-03-23 00:13:00 | 000,036,864 | ---- | M] () -- C:\Program Files\ThinkPad\Utilities\US\PWRMGRRT.DLL MOD - [2006-03-23 00:10:00 | 000,057,344 | ---- | M] () -- C:\Program Files\ThinkVantage\PrdCtr\US\LPRESMGR.DLL MOD - [2006-02-24 01:22:00 | 000,057,344 | ---- | M] () -- C:\Program Files\ThinkPad\Utilities\US\EZMAPRES.DLL MOD - [2005-12-21 17:23:06 | 000,139,264 | ---- | M] () -- C:\Program Files\IBM ThinkVantage\Rescue and Recovery\CDRecord.dll MOD - [2005-12-21 17:19:10 | 000,155,648 | ---- | M] () -- C:\Program Files\IBM ThinkVantage\Rescue and Recovery\ui.dll MOD - [2005-12-21 17:19:02 | 000,069,632 | ---- | M] () -- C:\Program Files\IBM ThinkVantage\Rescue and Recovery\zlib.dll MOD - [2005-12-21 17:15:14 | 000,671,744 | ---- | M] () -- C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rr_res.dll MOD - [2005-11-30 19:16:02 | 000,024,576 | ---- | M] () -- C:\WINDOWS\system32\tphklock.dll MOD - [2005-10-28 19:29:52 | 000,208,896 | ---- | M] () -- C:\Program Files\Lenovo\PkgMgr\HOTKEY\tpfnf7.dll MOD - [2005-07-13 02:55:00 | 000,122,880 | ---- | M] () -- C:\WINDOWS\system32\tp4uires.dll MOD - [2005-07-05 13:57:12 | 000,077,824 | ---- | M] () -- C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [Auto | Stopped] -- -- (LexBceS) SRV - File not found [Disabled | Stopped] -- -- (HidServ) SRV - File not found [Auto | Stopped] -- -- (DrWebAVService) SRV - File not found [On_Demand | Stopped] -- -- (ACS) SRV - [2011-11-18 02:19:53 | 003,313,752 | ---- | M] () [Auto | Running] -- c:\program files\common files\akamai/netsession_win_d768ebc.dll -- (Akamai) SRV - [2011-11-15 19:48:42 | 001,867,776 | ---- | M] (Doctor Web, Ltd.) [Auto | Stopped] -- C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwengine.exe -- (DrWebEngine) Dr.Web Scanning Engine (DrWebEngine) SRV - [2011-11-15 15:02:12 | 002,116,408 | ---- | M] (Doctor Web, Ltd.) [Auto | Stopped] -- C:\Program Files\DrWeb\dwnetfilter.exe -- (DrWebNetFilter) SRV - [2011-11-15 14:26:02 | 001,384,448 | ---- | M] () [Auto | Running] -- C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe -- (TVT Backup Service) SRV - [2011-11-08 11:04:48 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\TpKmpSvc.exe -- (TpKmpSVC) SRV - [2011-11-07 11:00:00 | 000,086,528 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8) SRV - [2011-11-07 10:59:58 | 000,077,824 | ---- | M] () [Auto | Running] -- C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe -- (TVT Scheduler) SRV - [2011-03-01 15:26:44 | 000,649,216 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2010-02-19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard) SRV - [2009-03-26 01:15:54 | 000,068,096 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe -- (Macromedia Licensing Service) SRV - [2007-03-09 13:16:16 | 000,077,824 | ---- | M] (NAVO) [On_Demand | Stopped] -- C:\Program Files\NAVO Enterprise 2002\System\navoservice.exe -- (NAVOEnterprise2002) SRV - [2005-09-23 06:01:16 | 002,799,808 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe -- (msvsmon80) SRV - [2004-08-10 23:46:56 | 000,483,328 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- c:\Program Files\Windows Media Connect\mswmccds.exe -- (WmcCds) Windows Media Connect (WMC) SRV - [2004-08-10 20:50:42 | 000,028,160 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Media Connect\mswmcls.exe -- (WmcCdsLs) Pomocnik programu Windows Media Connect (WMC) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2011-11-17 22:19:11 | 000,012,544 | ---- | M] (IBM) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ibmfilter.sys -- (IBMFilter) DRV - [2011-11-15 14:15:51 | 000,149,272 | ---- | M] (Doctor Web, Ltd.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\dwprot.sys -- (DwProt) DRV - [2011-11-15 14:15:49 | 000,111,896 | ---- | M] (Doctor Web, Ltd.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\spiderg3.sys -- (SpiderG3) DRV - [2011-11-15 14:15:48 | 000,055,800 | ---- | M] (Doctor Web, Ltd.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dw_wfp.sys -- (DrWebWfp) DRV - [2011-11-14 13:56:16 | 000,133,208 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\65116954.sys -- (65116954) DRV - [2011-11-14 13:56:16 | 000,133,208 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\39755060.sys -- (39755060) DRV - [2011-11-14 13:56:16 | 000,133,208 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\07231497.sys -- (07231497) DRV - [2010-06-11 10:36:48 | 000,196,064 | ---- | M] (Jungo) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\windrvr6.sys -- (WinDriver6) DRV - [2009-09-29 16:09:18 | 000,007,680 | ---- | M] (Nanjing Universal Networks (U-NET) Co., LTD.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\TDKeybd.sys -- (TDKeybd) DRV - [2008-08-26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd) DRV - [2008-06-12 16:26:32 | 000,019,968 | ---- | M] (Nanjing Universal Networks (U-NET) Co., LTD.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\Drivers\CDD_HOST.sys -- (CDD_HOST) DRV - [2006-03-23 00:13:00 | 000,004,442 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\TPPWRIF.SYS -- (TPPWRIF) DRV - [2006-02-27 01:52:00 | 000,007,168 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\TSMAPIP.SYS -- (TSMAPIP) DRV - [2006-01-17 00:52:00 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\SMAPINT.SYS -- (Smapint) DRV - [2006-01-17 00:52:00 | 000,009,343 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\TDSMAPI.SYS -- (TDSMAPI) DRV - [2005-12-21 09:19:10 | 000,470,208 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211) DRV - [2005-11-15 12:11:28 | 000,046,142 | R--- | M] (Utimaco Safeware AG) [Kernel | Auto | Running] -- C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\privatediskm.sys -- (PrivateDisk) DRV - [2005-10-26 09:01:02 | 000,142,720 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k) DRV - [2003-12-08 10:53:48 | 000,053,600 | ---- | M] (THOMSON) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\alcan5wn.sys -- (alcan5wn) SpeedTouch USB ADSL PPP Networking Driver (NDISWAN) DRV - [2003-12-08 10:53:46 | 000,070,688 | ---- | M] (THOMSON) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\alcaudsl.sys -- (alcaudsl) DRV - [2001-08-17 22:04:08 | 000,173,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\philcam2.sys -- (phil2vid) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-220993969-3265632603-3924391503-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-21-220993969-3265632603-3924391503-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "about:blank" FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.7 FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.6.2 FF - prefs.js..extensions.enabledItems: activities@kaply.com:0.7.7 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: 2020Player@2020Technologies.com:5.0.4.0 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - prefs.js..network.proxy.backup.gopher: "" FF - prefs.js..network.proxy.backup.gopher_port: 0 FF - prefs.js..network.proxy.type: 0 FF - HKLM\Software\MozillaPlugins\@fronter.com/FronterOES: C:\Program Files\Fronter\Fronter OES\npfronter_oes2.dll ( ) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll File not found [2009-12-28 09:14:56 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Marta\Dane aplikacji\Mozilla\Extensions [2009-12-28 09:14:56 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Marta\Dane aplikacji\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2011-11-08 11:14:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Marta\Dane aplikacji\Mozilla\Firefox\Profiles\ukm1r614.default\extensions [2010-05-27 22:14:43 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Marta\Dane aplikacji\Mozilla\Firefox\Profiles\ukm1r614.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2011-02-18 22:31:43 | 000,000,000 | ---D | M] (20-20 3D Viewer) -- C:\Documents and Settings\Marta\Dane aplikacji\Mozilla\Firefox\Profiles\ukm1r614.default\extensions\2020Player@2020Technologies.com [2010-03-20 10:31:40 | 000,000,000 | ---D | M] ("IE8 Activities (Accelerators) for Firefox") -- C:\Documents and Settings\Marta\Dane aplikacji\Mozilla\Firefox\Profiles\ukm1r614.default\extensions\activities@kaply.com [2011-08-28 22:09:32 | 000,000,000 | ---D | M] (Vividas player plugin) -- C:\Documents and Settings\Marta\Dane aplikacji\Mozilla\Firefox\Profiles\ukm1r614.default\extensions\player@vividas.com [2011-11-26 21:57:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2010-08-05 07:40:27 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [2011-02-10 06:28:31 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} () (No name found) -- C:\DOCUMENTS AND SETTINGS\MARTA\DANE APLIKACJI\MOZILLA\FIREFOX\PROFILES\UKM1R614.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI () (No name found) -- C:\DOCUMENTS AND SETTINGS\MARTA\DANE APLIKACJI\MOZILLA\FIREFOX\PROFILES\UKM1R614.DEFAULT\EXTENSIONS\FIREBUG@SOFTWARE.JOEHEWITT.COM.XPI [2011-11-17 00:54:52 | 000,611,224 | ---- | M] (Oracle Corporation) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2011-06-20 14:47:30 | 000,189,088 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npVividasPlayer.dll O1 HOSTS File: ([2011-11-13 22:35:08 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll File not found O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKU\S-1-5-21-220993969-3265632603-3924391503-1005\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.) O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [BLOG] C:\Program Files\ThinkPad\Utilities\BATLOGEX.DLL () O4 - HKLM..\Run: [cssauthe] C:\Program Files\IBM ThinkVantage\Client Security Solution\cssauthe.exe (Lenovo Group Limited) O4 - HKLM..\Run: [PDService.exe] C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe (Utimaco Safeware AG) O4 - HKLM..\Run: [PWRMGRTR] C:\Program Files\ThinkPad\Utilities\PWRMGRTR.DLL (Lenovo Group Limited) O4 - HKLM..\Run: [SpIDerAgent] C:\Program Files\DrWeb\spideragent.exe (Doctor Web, Ltd.) O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [TP4EX] C:\WINDOWS\System32\TP4EX.exe (Lenovo Group Limited) O4 - HKLM..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe (Lenovo) O4 - HKU\S-1-5-21-220993969-3265632603-3924391503-1005..\Run: [Akamai NetSession Interface] C:\Documents and Settings\Marta\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe (Akamai Technologies, Inc) O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-220993969-3265632603-3924391503-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-220993969-3265632603-3924391503-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-21-220993969-3265632603-3924391503-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\S-1-5-21-220993969-3265632603-3924391503-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O9 - Extra Button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe () O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - mswsock.dll File not found O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (MksSkanerOnline Class) O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} http://www-307.ibm.com/pc/support/IbmEgath.cab (IBM Access Support) O18 - Protocol\Handler\ic32pp - No CLSID value found O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\tpfnf2: DllName - (notifyf2.dll) - C:\WINDOWS\System32\notifyf2.dll () O20 - Winlogon\Notify\tphotkey: DllName - (tphklock.dll) - C:\WINDOWS\System32\tphklock.dll () O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\WINDOWS\1024_768 Think EMEA Map.bmp O24 - Desktop BackupWallPaper: C:\WINDOWS\1024_768 Think EMEA Map.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008-06-08 15:11:01 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2009-08-08 09:02:43 | 000,017,506 | ---- | M] () - C:\AutoMapaSetupLog.txt -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (pgdfgsvc C 1) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] File not found -- C:\WINDOWS\System32\ [2011-11-27 08:07:24 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2011-11-26 22:04:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Marta\Pulpit\fixit [2011-11-26 21:55:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Sun [2011-11-25 22:13:36 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0 [2011-11-21 22:37:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Marta\Moje dokumenty\034 [2011-11-17 22:19:14 | 000,000,000 | RHSD | C] -- C:\RRbackups [2011-11-17 22:19:11 | 000,012,544 | ---- | C] (IBM) -- C:\WINDOWS\System32\drivers\ibmfilter.sys [2011-11-17 22:18:53 | 000,000,000 | ---D | C] -- C:\Program Files\TVT SMBus [2011-11-17 02:44:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Marta\Ustawienia lokalne\Dane aplikacji\Sun [2011-11-16 20:07:28 | 000,000,000 | -HSD | C] -- C:\RECYCLER [2011-11-16 19:40:41 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group [2011-11-16 06:30:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Comodo Downloader [2011-11-15 20:04:41 | 000,133,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\WINDOWS\System32\drivers\07231497.sys [2011-11-15 20:04:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Marta\Pulpit\aa [2011-11-15 19:05:51 | 000,133,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\WINDOWS\System32\drivers\39755060.sys [2011-11-15 18:47:09 | 000,133,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\WINDOWS\System32\drivers\65116954.sys [2011-11-15 14:25:46 | 000,000,000 | -HSD | C] -- C:\DrWeb Quarantine [2011-11-15 14:16:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Marta\Doctor Web [2011-11-15 14:15:51 | 000,149,272 | ---- | C] (Doctor Web, Ltd.) -- C:\WINDOWS\System32\drivers\dwprot.sys [2011-11-15 14:15:49 | 000,111,896 | ---- | C] (Doctor Web, Ltd.) -- C:\WINDOWS\System32\drivers\spiderg3.sys [2011-11-15 14:15:48 | 000,055,800 | ---- | C] (Doctor Web, Ltd.) -- C:\WINDOWS\System32\drivers\dw_wfp.sys [2011-11-15 14:15:41 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Doctor Web [2011-11-15 14:15:06 | 000,000,000 | ---D | C] -- C:\Program Files\DrWeb [2011-11-15 14:15:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Doctor Web [2011-11-15 14:10:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Marta\Ustawienia lokalne\Dane aplikacji\Downloaded Installations [2011-11-15 10:49:01 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Marta\Ustawienia lokalne\Dane aplikacji\cc808513 [2011-11-15 10:22:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Marta\Ustawienia lokalne\Dane aplikacji\Akamai [2011-11-13 14:33:06 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ipsec.sys [2011-11-13 14:30:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Marta\Pulpit\logi_forum [2011-11-13 14:30:29 | 000,000,000 | ---D | C] -- C:\Tmp [2011-11-08 22:34:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Dane aplikacji\Macromedia [2011-11-07 14:06:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Dane aplikacji\Adobe [2011-11-02 14:08:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Marta\Moje dokumenty\025 [2011-11-02 10:18:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Marta\Pulpit\kuba [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] File not found -- C:\WINDOWS\System32\ [2011-11-27 09:42:48 | 000,000,374 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics [2011-11-27 09:42:48 | 000,000,368 | ---- | M] () -- C:\WINDOWS\tasks\CisPostUninstall.job [2011-11-27 09:42:42 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2011-11-27 09:42:18 | 000,000,316 | ---- | M] () -- C:\WINDOWS\tasks\PMTask.job [2011-11-27 09:42:01 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2011-11-27 09:42:00 | 2137,509,888 | -HS- | M] () -- C:\hiberfil.sys [2011-11-27 09:41:10 | 001,239,392 | ---- | M] () -- C:\WINDOWS\System32\drivers\sfi.dat [2011-11-27 07:36:01 | 000,000,264 | -HS- | M] () -- C:\BOOT.INI [2011-11-27 07:14:49 | 003,516,096 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2011-11-26 19:46:07 | 000,006,534 | ---- | M] () -- C:\kav_cd_raport [2011-11-25 20:42:47 | 000,009,900 | ---- | M] () -- C:\WINDOWS\wincmd.ini [2011-11-25 14:24:04 | 000,006,464 | ---- | M] () -- C:\WINDOWS\wcx_ftp.ini [2011-11-25 12:21:42 | 000,094,264 | ---- | M] () -- C:\Documents and Settings\Marta\Moje dokumenty\korekta_23 11_echo.rtf [2011-11-25 12:21:42 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Marta\Moje dokumenty\~$rekta_23 11_echo.rtf [2011-11-17 22:19:11 | 000,012,544 | ---- | M] (IBM) -- C:\WINDOWS\System32\drivers\ibmfilter.sys [2011-11-17 00:54:52 | 000,544,656 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll [2011-11-16 11:07:41 | 000,016,049 | ---- | M] () -- C:\WINDOWS\CDPLAYER.INI [2011-11-15 22:15:06 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2011-11-15 14:27:16 | 000,018,603 | ---- | M] () -- C:\Documents and Settings\Marta\Pulpit\trojany.png [2011-11-15 14:15:51 | 000,149,272 | ---- | M] (Doctor Web, Ltd.) -- C:\WINDOWS\System32\drivers\dwprot.sys [2011-11-15 14:15:49 | 000,111,896 | ---- | M] (Doctor Web, Ltd.) -- C:\WINDOWS\System32\drivers\spiderg3.sys [2011-11-15 14:15:48 | 000,055,800 | ---- | M] (Doctor Web, Ltd.) -- C:\WINDOWS\System32\drivers\dw_wfp.sys [2011-11-15 09:18:57 | 000,007,891 | ---- | M] () -- C:\Documents and Settings\Marta\Pulpit\logomon.png [2011-11-14 13:56:16 | 000,133,208 | ---- | M] (Kaspersky Lab ZAO) -- C:\WINDOWS\System32\drivers\65116954.sys [2011-11-14 13:56:16 | 000,133,208 | ---- | M] (Kaspersky Lab ZAO) -- C:\WINDOWS\System32\drivers\39755060.sys [2011-11-14 13:56:16 | 000,133,208 | ---- | M] (Kaspersky Lab ZAO) -- C:\WINDOWS\System32\drivers\07231497.sys [2011-11-13 22:35:08 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2011-11-08 11:29:11 | 000,000,600 | ---- | M] () -- C:\Documents and Settings\Marta\Dane aplikacji\winscp.rnd [2011-11-08 11:04:48 | 000,040,960 | ---- | M] () -- C:\WINDOWS\System32\TpKmpSvc.exe [2011-11-08 10:41:28 | 000,627,238 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2011-11-08 10:41:28 | 000,566,048 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2011-11-08 10:41:28 | 000,138,252 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2011-11-08 10:41:28 | 000,117,810 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2011-10-28 10:14:07 | 000,009,311 | ---- | M] () -- C:\Documents and Settings\Marta\Moje dokumenty\InformatykaEuropejczyka.ie2 [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2011-11-27 09:37:36 | 000,000,368 | ---- | C] () -- C:\WINDOWS\tasks\CisPostUninstall.job [2011-11-26 19:46:07 | 000,006,534 | ---- | C] () -- C:\kav_cd_raport [2011-11-25 12:21:42 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Marta\Moje dokumenty\~$rekta_23 11_echo.rtf [2011-11-25 12:21:41 | 000,094,264 | ---- | C] () -- C:\Documents and Settings\Marta\Moje dokumenty\korekta_23 11_echo.rtf [2011-11-17 02:38:43 | 2137,509,888 | -HS- | C] () -- C:\hiberfil.sys [2011-11-16 06:39:28 | 001,239,392 | ---- | C] () -- C:\WINDOWS\System32\drivers\sfi.dat [2011-11-15 14:27:16 | 000,018,603 | ---- | C] () -- C:\Documents and Settings\Marta\Pulpit\trojany.png [2011-11-15 09:18:57 | 000,007,891 | ---- | C] () -- C:\Documents and Settings\Marta\Pulpit\logomon.png [2011-11-09 03:58:19 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\ibmpmsvc.exe [2011-03-07 17:16:38 | 000,000,037 | ---- | C] () -- C:\WINDOWS\SWFConverter.INI [2010-12-13 23:50:21 | 000,000,092 | ---- | C] () -- C:\WINDOWS\VOGEL.INI [2010-12-03 00:38:40 | 000,000,132 | ---- | C] () -- C:\Documents and Settings\Marta\Dane aplikacji\Preferencje Adobe CS5 dla formatu PNG [2010-10-19 12:59:47 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2010-07-17 21:09:06 | 000,000,046 | ---- | C] () -- C:\WINDOWS\adiras.ini [2010-05-18 11:48:51 | 000,016,049 | ---- | C] () -- C:\WINDOWS\CDPLAYER.INI [2010-03-15 10:23:41 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2010-01-12 14:36:29 | 000,000,619 | R--- | C] () -- C:\WINDOWS\System32\hppapr13.dat [2009-07-12 17:36:00 | 000,697,353 | ---- | C] () -- C:\WINDOWS\unins000.exe [2009-07-12 17:36:00 | 000,124,542 | ---- | C] () -- C:\WINDOWS\unins000.dat [2009-06-03 14:22:58 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Marta\Ustawienia lokalne\Dane aplikacji\PUTTY.RND [2009-05-06 14:07:34 | 000,072,704 | ---- | C] () -- C:\WINDOWS\cadkasdeinst01e.exe [2009-04-22 10:24:49 | 001,073,152 | ---- | C] () -- C:\WINDOWS\System32\libmysql_c.dll [2009-02-23 15:10:40 | 000,000,199 | ---- | C] () -- C:\WINDOWS\swacnfg.ini [2009-02-17 13:26:33 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ams70.INI [2009-01-23 01:00:36 | 000,000,032 | RHS- | C] () -- C:\Documents and Settings\Marta\Ustawienia lokalne\Dane aplikacji\t50.dat [2009-01-22 16:34:18 | 000,000,421 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2009-01-08 14:19:10 | 000,102,032 | ---- | C] () -- C:\WINDOWS\hpoins04.dat [2009-01-08 14:19:10 | 000,017,218 | ---- | C] () -- C:\WINDOWS\hpomdl04.dat [2008-10-15 19:38:17 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Marta\Dane aplikacji\winscp.rnd [2008-09-24 17:21:02 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat [2008-08-16 14:30:40 | 000,024,576 | ---- | C] () -- C:\Documents and Settings\Marta\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008-08-04 15:55:19 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI [2008-07-26 13:13:30 | 000,000,227 | ---- | C] () -- C:\WINDOWS\LEXSTAT.INI [2008-07-03 09:55:13 | 000,434,176 | ---- | C] () -- C:\WINDOWS\System32\ZSHP1020.EXE [2008-06-25 09:14:03 | 000,089,088 | ---- | C] () -- C:\WINDOWS\System32\hpgt33.dll [2008-06-12 11:57:20 | 000,000,398 | ---- | C] () -- C:\WINDOWS\navo3.ini [2008-06-12 11:46:15 | 000,014,290 | ---- | C] () -- C:\Program Files\settings.dat [2008-06-09 22:31:54 | 000,001,160 | ---- | C] () -- C:\WINDOWS\mozver.dat [2008-06-09 22:17:00 | 000,006,464 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini [2008-06-09 22:15:00 | 000,009,900 | ---- | C] () -- C:\WINDOWS\wincmd.ini [2008-06-09 22:11:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat [2008-06-08 18:30:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI [2008-06-08 18:08:43 | 000,005,606 | ---- | C] () -- C:\WINDOWS\System32\stci.dll [2008-06-08 15:10:53 | 000,000,130 | ---- | C] () -- C:\Documents and Settings\Marta\Ustawienia lokalne\Dane aplikacji\fusioncache.dat [2008-06-08 15:03:32 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini [2008-06-08 15:03:13 | 000,016,384 | ---- | C] () -- C:\WINDOWS\PWMBTHLP.EXE [2008-06-08 15:03:12 | 000,004,442 | ---- | C] () -- C:\WINDOWS\System32\drivers\TPPWRIF.SYS [2008-06-08 14:59:33 | 000,000,040 | ---- | C] () -- C:\WINDOWS\System32\profile.dat [2008-06-08 14:53:12 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll [2008-06-08 14:53:12 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll [2008-06-08 14:53:12 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll [2008-06-08 14:53:12 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll [2008-06-08 14:53:12 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll [2008-06-08 14:53:12 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll [2008-06-08 14:52:42 | 000,028,848 | ---- | C] () -- C:\WINDOWS\System32\drivers\USBkey.sys [2008-06-08 14:52:11 | 000,000,148 | ---- | C] () -- C:\WINDOWS\wininit.ini [2008-06-08 14:41:39 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\FPCALL.dll [2008-06-08 14:41:24 | 000,009,343 | ---- | C] () -- C:\WINDOWS\System32\drivers\TDSMAPI.SYS [2008-06-08 14:41:13 | 000,147,520 | ---- | C] () -- C:\WINDOWS\_tpiu000.exe [2008-06-08 14:40:55 | 000,651,264 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll [2008-06-08 14:40:55 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll [2008-06-08 14:40:27 | 000,315,392 | ---- | C] () -- C:\WINDOWS\System32\AegisI5.exe [2008-06-08 14:40:19 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\TpKmpSvc.exe [2008-06-08 14:29:39 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\tp4uires.dll [2008-06-08 14:24:55 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\notifyf2.dll [2008-06-08 14:24:55 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\tphklock.dll [2007-06-28 11:54:10 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2007-06-28 11:52:18 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2006-02-02 14:40:26 | 000,002,035 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI [2006-01-20 15:05:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini [2005-07-08 00:06:00 | 000,114,688 | ---- | C] () -- C:\WINDOWS\desktopset.exe [2005-05-23 07:22:24 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.BIN [2005-05-23 07:22:24 | 000,004,547 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.DAT [2004-09-15 16:05:45 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2004-09-15 15:56:40 | 000,021,856 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2004-09-15 15:51:29 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2004-09-15 15:50:41 | 003,516,096 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2003-04-08 11:40:22 | 000,005,679 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI [1979-12-31 23:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat [1979-12-31 23:00:00 | 000,627,238 | ---- | C] () -- C:\WINDOWS\System32\perfh015.dat [1979-12-31 23:00:00 | 000,566,048 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat [1979-12-31 23:00:00 | 000,313,828 | ---- | C] () -- C:\WINDOWS\System32\perfi015.dat [1979-12-31 23:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat [1979-12-31 23:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat [1979-12-31 23:00:00 | 000,138,252 | ---- | C] () -- C:\WINDOWS\System32\perfc015.dat [1979-12-31 23:00:00 | 000,117,810 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat [1979-12-31 23:00:00 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\tp4unins.exe [1979-12-31 23:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin [1979-12-31 23:00:00 | 000,034,990 | ---- | C] () -- C:\WINDOWS\System32\perfd015.dat [1979-12-31 23:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat [1979-12-31 23:00:00 | 000,005,788 | ---- | C] () -- C:\WINDOWS\System32\tp4table.dat [1979-12-31 23:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat [1979-12-31 23:00:00 | 000,002,016 | ---- | C] () -- C:\WINDOWS\System32\h09wownt.dll [1979-12-31 23:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin [1979-12-31 23:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat [color=#E56717]========== LOP Check ==========[/color] [2008-06-08 14:50:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\IBM [2008-06-08 15:10:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\ThinkVantage [2009-01-23 01:00:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Axure [2010-08-25 20:39:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite [2011-11-15 14:15:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Doctor Web [2008-09-06 05:21:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Downloaded Installations [2011-11-27 08:12:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Installations [2008-06-08 14:51:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Lenovo [2011-02-10 06:37:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Panda Security [2008-09-06 15:04:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PC Suite [2010-12-02 23:48:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\regid.1986-12.com.adobe [2008-06-08 15:11:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ThinkVantage [2008-08-12 22:06:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\WiP [2008-06-08 14:50:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Dane aplikacji\IBM [2008-06-08 15:10:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Dane aplikacji\ThinkVantage [2008-06-08 14:50:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gość\Dane aplikacji\IBM [2008-11-25 16:42:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gość\Dane aplikacji\Opera [2008-09-25 05:28:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gość\Dane aplikacji\PC Suite [2008-06-08 15:10:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Gość\Dane aplikacji\ThinkVantage [2011-10-17 15:03:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\Audacity [2010-04-29 15:58:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\Axialis [2009-01-23 01:00:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\Axure [2009-01-19 11:42:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\DAEMON Tools [2010-08-25 21:26:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\DAEMON Tools Lite [2009-01-19 11:42:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\DAEMON Tools Pro [2008-08-27 16:56:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\DataLayer [2009-02-17 13:25:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\Downloaded Installations [2011-01-07 01:35:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\Elluminate [2008-12-10 13:38:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\FileZilla [2008-06-10 09:50:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\Gadu-Gadu [2008-06-08 14:50:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\IBM [2011-01-26 23:51:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\InterVideo [2008-12-31 13:23:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\Langenscheidt [2008-06-08 17:23:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\Leadertech [2008-09-17 16:46:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\Nokia [2008-08-27 17:38:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\Nokia Multimedia Player [2010-06-16 11:40:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\Notepad++ [2008-07-10 22:07:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\Opera [2011-02-10 06:39:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\Panda Security [2008-09-17 16:46:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\PC Suite [2011-01-14 09:44:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\Program Files [2008-11-17 23:20:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\PWNEAG2009 [2008-10-31 15:11:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\PWNEAH2009 [2008-11-21 00:54:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\PWNEAP2009 [2009-09-24 23:07:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\PWNEncy2009 [2009-06-08 09:00:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\PWNMalaEmPWN2007 [2010-06-22 12:25:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\start_m [2010-10-22 14:16:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\Subversion [2009-09-27 22:35:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\SuperMemo World [2008-06-08 15:10:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\ThinkVantage [2010-11-08 12:12:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\Thinstall [2009-12-28 09:14:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\Thunderbird [2008-10-12 23:52:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\USJP2009 [2009-03-10 11:34:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\WiP [2010-05-28 23:15:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\WSiP [2010-06-22 12:25:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Marta\Dane aplikacji\WSIP - MIS [2011-11-27 09:42:48 | 000,000,368 | ---- | M] () -- C:\WINDOWS\Tasks\CisPostUninstall.job [2011-11-27 09:42:18 | 000,000,316 | ---- | M] () -- C:\WINDOWS\Tasks\PMTask.job [color=#E56717]========== Purity Check ==========[/color] < End of report >