OTL logfile created on: 30-09-2010 09:35:22 - Run 2 OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\SysOp\Pulpit Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: dd-MM-yyyy 3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 75,00% Memory free 5,00 Gb Paging File | 4,00 Gb Available in Paging File | 86,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 75,12 Gb Total Space | 52,66 Gb Free Space | 70,10% Space Free | Partition Type: NTFS Drive D: | 195,31 Gb Total Space | 172,91 Gb Free Space | 88,53% Space Free | Partition Type: NTFS Drive E: | 195,32 Gb Total Space | 124,03 Gb Free Space | 63,50% Space Free | Partition Type: NTFS F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: PC Current User Name: SysOp Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2010-09-29 22:10:32 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\SysOp\Pulpit\OTL.exe PRC - [2010-09-18 08:54:19 | 000,014,808 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe PRC - [2010-09-18 08:54:18 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2010-09-15 22:34:25 | 000,352,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe PRC - [2010-07-01 21:34:46 | 000,129,720 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtblfs.exe PRC - [2010-05-04 16:05:48 | 011,981,408 | ---- | M] (GG Network S.A.) -- C:\Program Files\Gadu-Gadu 10\gg.exe PRC - [2009-11-13 12:38:36 | 001,412,552 | ---- | M] (TrueCrypt Foundation) -- C:\Program Files\TrueCrypt\TrueCrypt.exe PRC - [2009-02-17 01:10:22 | 000,185,872 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe PRC - [2008-12-03 19:14:05 | 001,553,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2008-11-28 12:48:54 | 005,837,800 | ---- | M] (o2.pl Sp. z o.o.) -- C:\Programy\Tlen\tlen.exe PRC - [2008-08-04 01:04:00 | 001,345,376 | ---- | M] (Nullsoft) -- D:\Programy\Winamp\winamp.exe PRC - [2008-07-17 14:21:34 | 000,080,392 | ---- | M] () -- C:\Program Files\Gigabyte\EasySaver\essvr.exe PRC - [2008-07-15 21:12:46 | 003,217,408 | ---- | M] () -- C:\Programy\Workrave\lib\Workrave.exe PRC - [2008-01-19 20:01:08 | 004,388,192 | ---- | M] (Symantec Corporation) -- C:\Program Files\Norton Ghost\Agent\VProSvc.exe PRC - [2007-12-20 17:13:46 | 001,553,896 | ---- | M] (Symantec) -- C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe [color=#E56717]========== Modules (SafeList) ==========[/color] MOD - [2010-09-29 22:10:32 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\SysOp\Pulpit\OTL.exe MOD - [2008-06-19 14:20:08 | 000,017,408 | ---- | M] () -- C:\Programy\Tlen\hook.dll MOD - [2008-04-14 21:46:34 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\wscsvc.dll -- (wscsvc) SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ) SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\cisvc.exe -- (CiSvc) SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\alg.exe -- (ALG) SRV - [2010-09-15 22:34:25 | 000,352,976 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe -- (AVP) SRV - [2009-02-14 11:57:36 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [Disabled | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2008-07-17 14:21:34 | 000,080,392 | ---- | M] () [Auto | Running] -- C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE -- (ES lite Service) SRV - [2008-01-19 20:01:08 | 004,388,192 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Ghost\Agent\VProSvc.exe -- (Norton Ghost) SRV - [2007-12-20 17:13:46 | 001,553,896 | ---- | M] (Symantec) [On_Demand | Running] -- C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe -- (SymSnapService) SRV - [2006-10-27 01:47:54 | 000,065,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- D:\Programy\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service) SRV - [2006-01-05 01:06:02 | 000,163,840 | ---- | M] (Alex Feinman) [Disabled | Stopped] -- C:\Program Files\ISO Recorder\ImapiHelper.exe -- (Imapi Helper) SRV - [2003-09-14 22:08:14 | 002,928,700 | ---- | M] () [Disabled | Stopped] -- c:\usr/MYSQL/bin/mysqld.exe -- (MySql) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2010-09-30 09:25:22 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\gdrv.sys -- (gdrv) DRV - [2010-09-15 22:34:25 | 000,475,736 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF) DRV - [2010-09-04 15:57:05 | 000,281,760 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt) DRV - [2010-09-04 15:57:04 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt) DRV - [2010-06-09 17:43:52 | 000,011,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\kl2.sys -- (kl2) DRV - [2010-06-09 17:43:50 | 000,132,184 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\kl1.sys -- (kl1) DRV - [2010-05-07 12:06:26 | 000,032,856 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klim5.sys -- (klim5) DRV - [2009-12-29 00:12:34 | 000,721,904 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd) DRV - [2009-12-10 18:23:36 | 006,017,568 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2009-11-18 08:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt) DRV - [2009-11-18 08:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt) DRV - [2009-11-13 12:38:36 | 000,223,432 | ---- | M] (TrueCrypt Foundation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\truecrypt.sys -- (truecrypt) DRV - [2009-11-02 20:27:24 | 000,019,472 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\klmouflt.sys -- (klmouflt) DRV - [2009-06-17 10:55:34 | 000,010,384 | ---- | M] (Logitech, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\LBeepKE.sys -- (LBeepKE) DRV - [2008-12-03 18:40:59 | 000,062,208 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\si3112.sys -- (Si3112) DRV - [2008-10-17 10:50:00 | 000,131,072 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Mkd2kfNT.sys -- (Mkd2kfNt) DRV - [2008-10-17 10:50:00 | 000,079,104 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Mkd2Nadr.sys -- (Mkd2Nadr) DRV - [2008-09-12 16:00:50 | 000,041,680 | ---- | M] (Sun Microsystems, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\VBoxUSBMon.sys -- (VBoxUSBMon) DRV - [2008-09-12 16:00:46 | 000,095,888 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\VBoxDrv.sys -- (VBoxDrv) DRV - [2008-08-24 13:11:00 | 006,128,352 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv) DRV - [2008-04-13 23:50:44 | 000,091,520 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ndiswan.sys -- (NdisWan) DRV - [2008-04-13 21:06:06 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus) DRV - [2008-01-19 20:12:42 | 000,128,104 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WimFltr.sys -- (WimFltr) DRV - [2008-01-19 19:45:40 | 000,038,112 | ---- | M] (Symantec Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\v2imount.sys -- (v2imount) DRV - [2008-01-19 19:40:16 | 000,015,088 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vproeventmonitor.sys -- (VProEventMonitor) DRV - [2008-01-03 16:10:16 | 000,105,856 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp) DRV - [2007-12-20 17:13:54 | 000,136,416 | ---- | M] (StorageCraft) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\symsnap.sys -- (symsnap) DRV - [2002-01-12 17:30:34 | 000,003,567 | ---- | M] (Beyond Logic http://www.beyondlogic.org) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PortTalk.sys -- (PortTalk) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=101687&l=dis IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultengine: "Ask.com" FF - prefs.js..browser.search.defaultenginename: "Ask.com" FF - prefs.js..browser.search.order.1: "Ask.com" FF - prefs.js..browser.search.selectedEngine: "Mininova" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://www.google.pl/ig?hl=pl&source=iglk" FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2 FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8 FF - prefs.js..extensions.enabledItems: {2E18002D-DF43-4c65-9FDA-40D02F066D9E}:1.6.1 FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.5.4 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: linky@gemal.dk:3.0.0 FF - prefs.js..extensions.enabledItems: bossknb@ttt-jl.blogspot.com:2.1 FF - prefs.js..extensions.enabledItems: {de1b245c-de57-11da-ba2d-0050c2490048}:1.0.8 FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:11.0.1.400 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: KavAntiBanner@Kaspersky.ru:11.0.1.400 FF - prefs.js..extensions.enabledItems: beta@linkdiagnosis.com:2.2.41 FF - prefs.js..extensions.enabledItems: {DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}:1.0 FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6 FF - prefs.js..extensions.enabledItems: {D249FD00-4DF9-11D9-9FDC-0080481ADA61}:1.2.7 FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=" FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010-09-28 00:05:02 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-09-30 09:29:12 | 000,000,000 | ---D | M] [2008-01-04 05:00:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Extensions [2010-07-07 23:55:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\1Firefox\Profiles\l4qni2j6.default\extensions [2010-05-06 20:16:36 | 000,000,000 | ---D | M] (Extended Copy Menu) -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\1Firefox\Profiles\l4qni2j6.default\extensions\{2E18002D-DF43-4c65-9FDA-40D02F066D9E} [2009-10-20 21:20:45 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\1Firefox\Profiles\l4qni2j6.default\extensions\{31513E58-F253-47ad-86DB-D5F21E905429} [2009-12-08 15:35:31 | 000,000,000 | ---D | M] (Nightly Tester Tools) -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\1Firefox\Profiles\l4qni2j6.default\extensions\{8620c15f-30dc-4dba-a131-7c5d20cf4a29} [2010-05-01 11:10:36 | 000,000,000 | ---D | M] (Live HTTP Headers) -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\1Firefox\Profiles\l4qni2j6.default\extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [2010-04-29 22:40:55 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\1Firefox\Profiles\l4qni2j6.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2010-05-01 11:10:22 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\1Firefox\Profiles\l4qni2j6.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2010-05-01 11:10:46 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\1Firefox\Profiles\l4qni2j6.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781} [2010-05-06 20:16:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\1Firefox\Profiles\l4qni2j6.default\extensions\firebug@software.joehewitt.com [2010-03-12 19:54:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\1Firefox\Profiles\l4qni2j6.default\extensions\linky@gemal.dk [2010-09-29 23:16:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\l4qni2j6.default\extensions [2010-05-06 20:16:36 | 000,000,000 | ---D | M] (Extended Copy Menu) -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\l4qni2j6.default\extensions\{2E18002D-DF43-4c65-9FDA-40D02F066D9E} [2009-10-20 21:20:45 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\l4qni2j6.default\extensions\{31513E58-F253-47ad-86DB-D5F21E905429} [2010-08-08 11:33:19 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\l4qni2j6.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2010-08-19 00:04:42 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\l4qni2j6.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2010-09-27 16:24:46 | 000,000,000 | ---D | M] (MetaProducts Integration) -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\l4qni2j6.default\extensions\{D249FD00-4DF9-11D9-9FDC-0080481ADA61} [2010-09-24 08:48:36 | 000,000,000 | ---D | M] (flashget3 Extension) -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\l4qni2j6.default\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A} [2010-08-06 12:47:59 | 000,000,000 | ---D | M] (MinimizeToTray Plus) -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\l4qni2j6.default\extensions\{de1b245c-de57-11da-ba2d-0050c2490048} [2010-09-26 17:12:53 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\l4qni2j6.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781} [2010-09-20 09:57:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\l4qni2j6.default\extensions\beta@linkdiagnosis.com [2010-08-06 12:47:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\l4qni2j6.default\extensions\bossknb@ttt-jl.blogspot.com [2010-05-06 20:16:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\l4qni2j6.default\extensions\firebug@software.joehewitt.com [2010-03-12 19:54:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\l4qni2j6.default\extensions\linky@gemal.dk [2010-09-26 22:12:45 | 000,002,568 | ---- | M] () -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\l4qni2j6.default\searchplugins\askcom.xml [2009-10-17 23:31:58 | 000,000,998 | ---- | M] () -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\l4qni2j6.default\searchplugins\mininova.xml [2010-09-21 09:26:34 | 000,002,039 | ---- | M] () -- C:\Documents and Settings\SysOp\Dane aplikacji\Mozilla\Firefox\Profiles\l4qni2j6.default\searchplugins\torrentyorg.xml [2010-09-29 23:16:35 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions [2010-08-09 23:58:01 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2010-06-28 18:31:33 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010-08-24 15:40:15 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [2010-09-10 08:55:23 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru [2010-09-10 08:55:21 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru [2010-07-17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll [2010-06-26 09:59:22 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml [2010-06-26 09:59:22 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml [2010-06-26 09:59:22 | 000,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml [2010-06-26 09:59:22 | 000,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml [2010-06-26 09:59:22 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml [2010-06-26 09:59:22 | 000,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2010-09-27 00:04:27 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll (Kaspersky Lab ZAO) O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO) O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation) O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) O4 - HKCU..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.) O4 - HKCU..\Run: [Komunikator] C:\Programy\Tlen\tlen.exe (o2.pl Sp. z o.o.) O4 - HKCU..\Run: [TrueCrypt] C:\Program Files\TrueCrypt\TrueCrypt.exe (TrueCrypt Foundation) O4 - HKCU..\Run: [Workrave] C:\Programy\Workrave\lib\Workrave.exe () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 351 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm () O9 - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO) O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.233.233.233 87.204.204.204 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~2\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\kloehk.dll (Kaspersky Lab ZAO) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (cr1t1cal) O20 - Winlogon\Notify\klogon: DllName - C:\WINDOWS\system32\klogon.dll - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - D:\Programy\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs: 6to4 - File not found NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2010-09-30 09:04:02 | 000,000,000 | ---D | C] -- C:\_OTL [2010-09-29 22:10:32 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\SysOp\Pulpit\OTL.exe [2010-09-29 22:00:32 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\SysOp\Recent [2010-09-28 18:40:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\SysOp\Dane aplikacji\uTorrent [2010-09-27 20:35:45 | 003,623,736 | ---- | C] (Sysinternals) -- C:\Documents and Settings\SysOp\Pulpit\procexp.exe [2010-09-27 17:05:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\SysOp\Dane aplikacji\Xi [2010-09-27 16:35:23 | 000,086,016 | ---- | C] (Giganology Inc.) -- C:\WINDOWS\System32\gigagetbho_v10.dll [2010-09-27 16:24:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\SysOp\Dane aplikacji\MetaProducts [2010-09-27 11:19:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\SysOp\.gnome2 [2010-09-27 00:13:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\SysOp\Dane aplikacji\ReGet Software [2010-09-27 00:12:39 | 000,000,000 | ---D | C] -- C:\Program Files\ReGet Software [2010-09-27 00:07:25 | 000,000,000 | -HSD | C] -- C:\RECYCLER [2010-09-26 23:46:52 | 000,000,000 | ---D | C] -- C:\Qoobox [2010-09-26 22:35:23 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ReGet Shared [2010-09-26 22:12:25 | 000,000,000 | ---D | C] -- C:\Program Files\Ask.com [2010-09-26 21:49:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP [2010-09-26 21:48:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\SpeedBit [2010-09-20 12:38:26 | 000,832,448 | ---- | C] (APEX Software Corporation) -- C:\WINDOWS\System32\TDBG6.OCX [2010-09-20 12:38:26 | 000,416,528 | ---- | C] (Microsoft Corporation ) -- C:\WINDOWS\System32\COMCT332.OCX [2010-09-20 12:38:26 | 000,316,344 | ---- | C] (Apex Software Corporation) -- C:\WINDOWS\System32\TDBGPP.DLL [2010-09-20 12:38:26 | 000,122,880 | ---- | C] (R.M. de Boer Software) -- C:\WINDOWS\System32\ActiveWizard.ocx [2010-09-20 12:38:26 | 000,111,552 | ---- | C] (ComponentOne LLC) -- C:\WINDOWS\System32\XARRAYDB.OCX [2010-09-20 12:38:26 | 000,086,504 | ---- | C] (APEX Software Corporation) -- C:\WINDOWS\System32\XARRAY32.OCX [2010-09-20 12:38:25 | 000,224,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\Tabctl32.ocx [2010-09-20 12:38:24 | 001,046,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msjet35.dll [2010-09-20 12:38:23 | 000,368,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vbar332.dll [2010-09-20 12:38:23 | 000,123,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSJINT35.DLL [2010-09-20 12:38:23 | 000,024,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSJTER35.DLL [2010-09-20 12:29:08 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft [2010-09-16 13:10:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\SysOp\Pulpit\Nowy folder [2010-09-04 16:01:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\SysOp\Dane aplikacji\Ubisoft [2010-09-04 15:58:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Tages [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2010-09-30 09:26:01 | 000,200,513 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml [2010-09-30 09:25:22 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\gdrv.sys [2010-09-30 09:25:14 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2010-09-30 09:25:11 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010-09-30 09:25:07 | 3488,014,336 | -HS- | M] () -- C:\hiberfil.sys [2010-09-30 09:24:16 | 013,631,488 | ---- | M] () -- C:\Documents and Settings\SysOp\NTUSER.DAT [2010-09-30 09:01:00 | 000,000,234 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job [2010-09-30 00:38:00 | 000,001,132 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-448539723-1677128483-1801674531-1001UA.job [2010-09-29 22:11:09 | 000,869,051 | ---- | M] () -- C:\Documents and Settings\SysOp\Pulpit\SecurityCheck.exe [2010-09-29 22:10:49 | 000,293,376 | ---- | M] () -- C:\Documents and Settings\SysOp\Pulpit\t1k2jnmy.exe [2010-09-29 22:10:32 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\SysOp\Pulpit\OTL.exe [2010-09-29 22:01:49 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2010-09-29 20:36:33 | 000,003,193 | ---- | M] () -- C:\WINDOWS\wincmd.ini [2010-09-28 20:47:15 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini [2010-09-28 20:18:40 | 000,174,080 | ---- | M] () -- C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010-09-28 18:38:02 | 000,001,080 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-448539723-1677128483-1801674531-1001Core.job [2010-09-27 20:51:00 | 000,000,326 | ---- | M] () -- C:\Documents and Settings\SysOp\Pulpit\Art.lnk [2010-09-27 17:40:04 | 000,002,560 | ---- | M] () -- C:\WINDOWS\_MSRSTRT.EXE [2010-09-27 17:09:52 | 000,000,633 | ---- | M] () -- C:\WINDOWS\win.ini [2010-09-27 00:04:37 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini [2010-09-27 00:04:27 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2010-09-26 23:42:07 | 000,000,053 | ---- | M] () -- C:\WINDOWS\english.lng [2010-09-26 10:32:14 | 000,000,638 | ---- | M] () -- C:\WINDOWS\wcx_ftp.ini [2010-09-20 19:49:48 | 000,020,606 | ---- | M] () -- C:\Documents and Settings\SysOp\Pulpit\53090843.jpg [2010-09-19 22:48:21 | 000,000,188 | -HS- | M] () -- C:\Documents and Settings\SysOp\ntuser.ini [2010-09-15 22:34:25 | 000,475,736 | ---- | M] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys [2010-09-10 09:30:34 | 000,113,933 | ---- | M] () -- C:\WINDOWS\System32\drivers\klin.dat [2010-09-10 09:30:34 | 000,097,549 | ---- | M] () -- C:\WINDOWS\System32\drivers\klick.dat [2010-09-09 11:51:07 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job [2010-09-04 15:57:05 | 000,281,760 | ---- | M] () -- C:\WINDOWS\System32\drivers\atksgt.sys [2010-09-04 15:57:04 | 000,025,888 | ---- | M] () -- C:\WINDOWS\System32\drivers\lirsgt.sys [2010-09-01 08:42:28 | 005,880,680 | -H-- | M] () -- C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\IconCache.db [color=#E56717]========== Files Created - No Company Name ==========[/color] [2010-09-29 22:11:03 | 000,869,051 | ---- | C] () -- C:\Documents and Settings\SysOp\Pulpit\SecurityCheck.exe [2010-09-29 22:10:49 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\SysOp\Pulpit\t1k2jnmy.exe [2010-09-27 20:51:00 | 000,000,326 | ---- | C] () -- C:\Documents and Settings\SysOp\Pulpit\Art.lnk [2010-09-27 20:36:07 | 000,000,594 | ---- | C] () -- C:\Documents and Settings\SysOp\Pulpit\Tomi (sieć).lnk [2010-09-27 20:36:04 | 000,000,350 | ---- | C] () -- C:\Documents and Settings\SysOp\Pulpit\Videoarty.lnk [2010-09-27 20:35:43 | 000,000,724 | ---- | C] () -- C:\Documents and Settings\SysOp\Pulpit\Mozilla Firefox.lnk [2010-09-27 20:35:39 | 000,000,353 | ---- | C] () -- C:\Documents and Settings\SysOp\Pulpit\MP3 - Data.lnk [2010-09-27 20:35:37 | 000,000,365 | ---- | C] () -- C:\Documents and Settings\SysOp\Pulpit\Moje Dokumenty.lnk [2010-09-27 20:35:30 | 000,000,939 | ---- | C] () -- C:\Documents and Settings\SysOp\Pulpit\iS.m3u [2010-09-27 20:35:30 | 000,000,061 | ---- | C] () -- C:\Documents and Settings\SysOp\Pulpit\kontestacja.pls [2010-09-27 20:35:28 | 000,000,803 | ---- | C] () -- C:\Documents and Settings\SysOp\Pulpit\Internet Explorer.lnk [2010-09-27 20:35:27 | 000,000,356 | ---- | C] () -- C:\Documents and Settings\SysOp\Pulpit\FF Download.lnk [2010-09-27 20:35:25 | 000,002,302 | ---- | C] () -- C:\Documents and Settings\SysOp\Pulpit\Google Chrome.lnk [2010-09-27 20:35:23 | 000,000,545 | ---- | C] () -- C:\Documents and Settings\SysOp\Pulpit\Bait (sieć).lnk [2010-09-27 20:35:18 | 000,000,803 | ---- | C] () -- C:\Documents and Settings\SysOp\Pulpit\d.m3u [2010-09-27 20:35:15 | 000,000,544 | ---- | C] () -- C:\Documents and Settings\SysOp\Pulpit\CASHFLOW® 202 THE E-GAME.lnk [2010-09-27 17:40:04 | 000,002,560 | ---- | C] () -- C:\WINDOWS\_MSRSTRT.EXE [2010-09-26 22:35:24 | 000,000,053 | ---- | C] () -- C:\WINDOWS\english.lng [2010-09-26 22:12:29 | 000,000,234 | ---- | C] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job [2010-09-20 19:49:48 | 000,020,606 | ---- | C] () -- C:\Documents and Settings\SysOp\Pulpit\53090843.jpg [2010-09-04 15:57:05 | 000,281,760 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys [2010-09-04 15:57:04 | 000,025,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys [2010-04-26 10:32:24 | 000,001,153 | ---- | C] () -- C:\WINDOWS\ARPR.INI [2010-02-20 01:06:06 | 000,000,914 | ---- | C] () -- C:\WINDOWS\Lit.INI [2010-01-03 11:56:10 | 000,004,096 | -H-- | C] () -- C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\keyfile3.drm [2009-11-20 17:15:06 | 000,000,050 | ---- | C] () -- C:\WINDOWS\cdplayer.ini [2009-11-06 11:58:04 | 000,178,975 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat [2009-10-20 13:12:40 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2009-04-19 12:50:26 | 000,095,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\VBoxDrv.sys [2009-04-07 09:43:44 | 000,138,504 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys [2009-04-07 09:43:43 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\SysOp\Dane aplikacji\PnkBstrK.sys [2009-04-02 16:25:30 | 000,003,972 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciBus.sys [2009-03-29 12:32:42 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll [2009-03-26 21:39:57 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll [2009-03-21 15:03:37 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini [2009-03-12 20:54:12 | 000,000,200 | ---- | C] () -- C:\WINDOWS\w32demo8.ini [2009-02-27 21:44:06 | 000,000,234 | ---- | C] () -- C:\WINDOWS\Fakturka.ini [2009-02-22 23:26:08 | 000,685,849 | ---- | C] () -- C:\Documents and Settings\SysOp\Dane aplikacji\unins000.exe [2009-02-22 23:26:08 | 000,028,508 | ---- | C] () -- C:\Documents and Settings\SysOp\Dane aplikacji\unins000.dat [2009-02-14 15:56:40 | 000,000,638 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini [2009-02-14 15:55:18 | 000,003,193 | ---- | C] () -- C:\WINDOWS\wincmd.ini [2009-01-27 23:13:49 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll [2009-01-27 23:13:46 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll [2009-01-27 23:13:29 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll [2009-01-27 23:13:17 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll [2009-01-27 23:13:04 | 001,499,136 | ---- | C] () -- C:\WINDOWS\System32\nview.dll [2009-01-17 18:48:33 | 000,343,880 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat [2009-01-17 15:22:31 | 000,033,576 | ---- | C] () -- C:\WINDOWS\System32\BCGPOleAcc.dll [2009-01-15 14:13:27 | 000,000,319 | ---- | C] () -- C:\WINDOWS\game.ini [2009-01-14 00:19:53 | 000,174,080 | ---- | C] () -- C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2004-09-24 01:31:08 | 000,233,472 | ---- | C] () -- C:\WINDOWS\System32\libmySQL.dll [2004-07-29 19:08:30 | 000,024,633 | ---- | C] () -- C:\WINDOWS\php.ini [2003-01-28 01:09:20 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\libexpat.dll [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 88 bytes -> C:\WINDOWS\regedit.exe:SummaryInformation @Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:2B11E0DF < End of report >