OTL logfile created on: 2012-07-07 12:37:39 - Run 2 OTL by OldTimer - Version 3.2.53.1 Folder = D:\Documents and Settings\Administrator\Moje dokumenty\Pobieranie Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1023,17 Mb Total Physical Memory | 410,45 Mb Available Physical Memory | 40,12% Memory free 2,40 Gb Paging File | 1,90 Gb Available in Paging File | 79,11% Paging File free Paging file location(s): D:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files Drive C: | 19,53 Gb Total Space | 0,28 Gb Free Space | 1,42% Space Free | Partition Type: NTFS Drive D: | 54,99 Gb Total Space | 29,19 Gb Free Space | 53,09% Space Free | Partition Type: NTFS Drive F: | 37,26 Gb Total Space | 16,24 Gb Free Space | 43,58% Space Free | Partition Type: NTFS Drive H: | 3,77 Gb Total Space | 3,77 Gb Free Space | 100,00% Space Free | Partition Type: FAT32 Computer Name: KLOC-F4BA539FA3 | User Name: Admon | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-07-07 11:27:03 | 000,595,968 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Administrator\Moje dokumenty\Pobieranie\OTL.exe PRC - [2012-06-22 01:51:49 | 000,913,888 | ---- | M] (Mozilla Corporation) -- D:\Program Files\Mozilla Firefox\firefox.exe PRC - [2012-04-04 19:47:32 | 000,161,664 | ---- | M] (Oracle Corporation) -- D:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe PRC - [2012-04-04 16:56:38 | 000,981,680 | ---- | M] (Malwarebytes Corporation) -- D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe PRC - [2012-03-26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Microsoft Security Client\msseces.exe PRC - [2012-03-26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- d:\Program Files\Microsoft Security Client\MsMpEng.exe PRC - [2008-04-14 23:51:18 | 001,035,264 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\explorer.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012-06-22 01:51:47 | 002,042,848 | ---- | M] () -- D:\Program Files\Mozilla Firefox\mozjs.dll MOD - [2012-05-15 12:18:00 | 000,357,184 | ---- | M] () -- D:\Program Files\NVIDIA Corporation\nview\nvShell.dll MOD - [2012-04-04 07:54:04 | 000,300,544 | ---- | M] () -- D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.POL [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ) SRV - [2012-06-28 09:48:50 | 000,670,816 | ---- | M] (Wellbia.com Co., Ltd.) [On_Demand | Stopped] -- D:\WINDOWS\system32\xsherlock.xem -- (xsherlock) SRV - [2012-04-04 19:47:32 | 000,161,664 | ---- | M] (Oracle Corporation) [Auto | Running] -- D:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe -- (JavaQuickStarterService) SRV - [2012-03-26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- d:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- D:\WINDOWS\xhunter1.sys -- (xhunter1) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- D:\WINDOWS\vtany.sys -- (vtany) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2012-07-07 12:35:12 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- d:\Documents and Settings\All Users\Dane aplikacji\Microsoft\Microsoft Antimalware\Definition Updates\{BC9061F3-6934-4FB2-950D-A3ACFBF9C4BE}\MpKsl6bf67de2.sys -- (MpKsl6bf67de2) DRV - [2012-07-07 12:34:43 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy) DRV - [2012-03-08 10:35:35 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- D:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV - [2007-11-01 15:38:56 | 004,620,288 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2007-06-21 11:44:32 | 000,029,696 | R--- | M] (Atheros Communications) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\l251x86.sys -- (AtcL002) DRV - [2004-08-13 19:56:20 | 000,005,810 | ---- | M] () [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000.10011&barid={34F1204D-CD90-4BE9-8267-CE51A8F59F50} IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10011&barid={34F1204D-CD90-4BE9-8267-CE51A8F59F50} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=110819&babsrc=SP_ss&mntrId=8c4520f4000000000000001d60e2ae16 IE - HKCU\..\SearchScopes\{A39443A6-F8D2-4915-B5F9-580415219697}: "URL" = http://www.google.com/search?hl=pl&q={searchTerms} IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10011&barid={34F1204D-CD90-4BE9-8267-CE51A8F59F50} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "www.google.pl" FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: D:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_257.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.1: D:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1: D:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: d:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: D:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\@Webzen.com/NPBrowserExt: D:\Program Files\WEBZEN\BrowserExtension\NPWZCmnCtrl.dll (WEBZEN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: D:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2012-06-22 01:51:54 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2012-06-02 18:23:13 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Admon\Dane aplikacji\Mozilla\Extensions [2012-06-27 10:34:00 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Admon\Dane aplikacji\Mozilla\Firefox\Profiles\rugleozx.default\extensions [2012-06-27 10:34:00 | 000,000,000 | ---D | M] (Battlefield Play4Free) -- D:\Documents and Settings\Admon\Dane aplikacji\Mozilla\Firefox\Profiles\rugleozx.default\extensions\battlefieldplay4free@ea.com [2012-06-02 18:23:04 | 000,000,000 | ---D | M] (No name found) -- D:\Program Files\Mozilla Firefox\extensions [2012-06-22 01:51:53 | 000,085,472 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\browsercomps.dll [2012-06-22 01:51:39 | 000,002,767 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2012-06-22 01:51:39 | 000,001,406 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2012-06-22 01:51:39 | 000,000,917 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2012-06-22 01:51:39 | 000,000,858 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2012-06-22 01:51:39 | 000,001,183 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2012-06-22 01:51:39 | 000,001,683 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2007-08-02 14:00:00 | 000,000,742 | ---- | M]) - D:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - D:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll File not found O4 - HKLM..\Run: [Alcmtr] D:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [MSC] d:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) O4 - HKLM..\Run: [NvCplDaemon] D:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] D:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] D:\Program Files\NVIDIA Corporation\nview\nwiz.exe () O4 - HKCU..\Run: [DAEMON Tools Lite] D:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKCU..\Run: [Overwolf] D:\Program Files\Overwolf\Overwolf.exe -silent File not found O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1E2733B9-A898-4388-8BA9-FFD7909EB4FD}: DhcpNameServer = 192.168.1.1 O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (D:\WINDOWS\system32\userinit.exe) - D:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: D:\Documents and Settings\Admon\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: D:\Documents and Settings\Admon\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2012-03-07 23:08:05 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2012-03-07 22:26:12 | 000,000,000 | ---- | M] () - F:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-07-07 12:34:43 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbamswissarmy.sys [2012-07-07 11:00:53 | 000,000,000 | -HSD | C] -- D:\WINDOWS\CSC [2012-07-06 15:28:21 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Admon\Dane aplikacji\hellomoto [2012-07-04 19:51:13 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Admon\Dane aplikacji\wargaming.net [2012-07-04 19:50:54 | 000,527,192 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\XAudio2_7.dll [2012-07-04 19:50:54 | 000,239,960 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\xactengine3_7.dll [2012-07-04 19:50:54 | 000,074,072 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\XAPOFX1_5.dll [2012-07-04 19:50:53 | 001,868,128 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\d3dcsx_43.dll [2012-07-04 19:50:53 | 000,470,880 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\d3dx10_43.dll [2012-07-04 19:50:53 | 000,248,672 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\d3dx11_43.dll [2012-07-04 19:50:52 | 000,238,936 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\xactengine3_6.dll [2012-07-04 19:50:51 | 000,515,416 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\XAudio2_5.dll [2012-07-04 19:50:51 | 000,238,936 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\xactengine3_5.dll [2012-07-04 19:50:50 | 005,501,792 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\d3dcsx_42.dll [2012-07-04 19:50:50 | 000,235,344 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\d3dx11_42.dll [2012-07-04 19:50:49 | 000,453,456 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\d3dx10_42.dll [2012-07-04 19:49:20 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Menu Start\Programy\World of Tanks [2012-07-04 19:48:04 | 007,516,152 | ---- | C] (Wargaming.net ) -- D:\Documents and Settings\Admon\Pulpit\WoT_internet_install_eu.exe [2012-07-03 16:50:38 | 000,000,000 | ---D | C] -- D:\WINDOWS\Minidump [2012-07-02 21:07:58 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Admon\Dane aplikacji\LolClient [2012-06-28 09:48:38 | 000,670,816 | ---- | C] (Wellbia.com Co., Ltd.) -- D:\WINDOWS\System32\xsherlock.xem [2012-06-28 09:48:12 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Admon\Moje dokumenty\C9 [2012-06-27 11:52:06 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Admon\Ustawienia lokalne\Dane aplikacji\PunkBuster [2012-06-27 11:31:39 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Admon\Moje dokumenty\Battlefield Play4Free [2012-06-27 11:24:36 | 000,230,920 | ---- | C] (WEBZEN, INC.) -- D:\WINDOWS\System32\EPWZCmnCtrl.dll [2012-06-27 11:24:35 | 000,000,000 | ---D | C] -- D:\Program Files\WEBZEN [2012-06-27 11:24:31 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Dane aplikacji\WEBZEN [2012-06-27 11:23:54 | 002,988,968 | ---- | C] (Acresso Software Inc.) -- D:\Documents and Settings\Admon\Pulpit\WebzenBrowserExt.exe [2012-06-27 11:19:44 | 000,000,000 | ---D | C] -- D:\WINDOWS\System32\LogFiles [2012-06-27 07:29:48 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Admon\Overwolf [2012-06-26 10:05:14 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Admon\Ustawienia lokalne\Dane aplikacji\Overwolf [2012-06-26 10:03:33 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Menu Start\Programy\C9 [2012-06-18 22:26:36 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Menu Start\Programy\THQ [2012-06-18 21:18:34 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Menu Start\Programy\NapiProjekt [2012-06-18 21:18:34 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Admon\Dane aplikacji\NapiProjekt [2012-06-18 21:18:19 | 000,000,000 | ---D | C] -- D:\Program Files\NapiProjekt [2012-06-15 21:52:07 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Admon\Ustawienia lokalne\Dane aplikacji\Chromium [2012-06-15 08:50:56 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Admon\Moje dokumenty\EA Games [2012-06-15 08:34:24 | 000,000,000 | ---D | C] -- D:\WINDOWS\System32\DRVSTORE [2012-06-15 08:33:50 | 000,000,000 | ---D | C] -- D:\Program Files\Common Files\Wise Installation Wizard [2012-06-13 19:07:14 | 000,521,728 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\dllcache\jsdbgui.dll [2012-06-13 17:36:59 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Admon\Moje dokumenty\NBA LIVE 08 [2012-06-09 15:48:51 | 000,258,352 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\unicows.dll [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-07-07 12:41:52 | 000,000,406 | -H-- | M] () -- D:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job [2012-07-07 12:32:33 | 000,013,646 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl [2012-07-07 12:31:25 | 000,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat [2012-07-07 12:12:15 | 000,000,664 | ---- | M] () -- D:\WINDOWS\System32\d3d9caps.dat [2012-07-07 11:12:34 | 000,098,256 | ---- | M] () -- D:\WINDOWS\System32\FNTCACHE.DAT [2012-07-05 08:29:17 | 000,008,704 | ---- | M] () -- D:\Documents and Settings\Admon\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-07-04 19:49:20 | 000,000,575 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\World of Tanks.lnk [2012-07-04 19:48:23 | 007,516,152 | ---- | M] (Wargaming.net ) -- D:\Documents and Settings\Admon\Pulpit\WoT_internet_install_eu.exe [2012-06-28 09:48:50 | 000,670,816 | ---- | M] (Wellbia.com Co., Ltd.) -- D:\WINDOWS\System32\xsherlock.xem [2012-06-27 12:04:38 | 000,139,424 | ---- | M] () -- D:\WINDOWS\System32\drivers\PnkBstrK.sys [2012-06-27 12:04:09 | 000,282,104 | ---- | M] () -- D:\WINDOWS\System32\PnkBstrB.xtr [2012-06-27 11:24:13 | 002,988,968 | ---- | M] (Acresso Software Inc.) -- D:\Documents and Settings\Admon\Pulpit\WebzenBrowserExt.exe [2012-06-27 11:20:02 | 000,138,056 | ---- | M] () -- D:\Documents and Settings\Admon\Dane aplikacji\PnkBstrK.sys [2012-06-26 17:09:04 | 000,000,581 | ---- | M] () -- D:\Documents and Settings\Admon\Pulpit\Skrót do C9Launcher.lnk [2012-06-26 10:03:35 | 000,000,095 | ---- | M] () -- D:\Documents and Settings\Admon\Pulpit\C9.url [2012-06-22 14:37:27 | 000,556,154 | ---- | M] () -- D:\WINDOWS\System32\perfh015.dat [2012-06-22 14:37:27 | 000,493,882 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat [2012-06-22 14:37:27 | 000,105,186 | ---- | M] () -- D:\WINDOWS\System32\perfc015.dat [2012-06-22 14:37:27 | 000,084,426 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat [2012-06-18 22:29:52 | 000,000,600 | ---- | M] () -- D:\Documents and Settings\All Users\Pulpit\Dawn of War.lnk [2012-06-18 21:18:34 | 000,000,725 | ---- | M] () -- D:\Documents and Settings\Admon\Pulpit\NapiProjekt.lnk [2012-06-15 10:09:50 | 001,074,636 | ---- | M] () -- D:\WINDOWS\System32\nvdrsdb0.bin [2012-06-15 10:09:50 | 000,000,001 | ---- | M] () -- D:\WINDOWS\System32\nvdrssel.bin [2012-06-15 10:09:42 | 001,074,636 | ---- | M] () -- D:\WINDOWS\System32\nvdrsdb1.bin [2012-06-14 03:06:07 | 000,001,374 | ---- | M] () -- D:\WINDOWS\imsins.BAK [2012-06-12 10:00:12 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- D:\WINDOWS\System32\FlashPlayerApp.exe [2012-06-12 10:00:11 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- D:\WINDOWS\System32\FlashPlayerCPLApp.cpl [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-07-07 11:17:40 | 000,000,664 | ---- | C] () -- D:\WINDOWS\System32\d3d9caps.dat [2012-07-04 19:49:20 | 000,000,575 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\World of Tanks.lnk [2012-06-27 11:53:25 | 000,282,104 | ---- | C] () -- D:\WINDOWS\System32\PnkBstrB.xtr [2012-06-27 11:20:02 | 000,139,424 | ---- | C] () -- D:\WINDOWS\System32\drivers\PnkBstrK.sys [2012-06-27 11:20:02 | 000,138,056 | ---- | C] () -- D:\Documents and Settings\Admon\Dane aplikacji\PnkBstrK.sys [2012-06-27 11:19:47 | 000,282,104 | ---- | C] () -- D:\WINDOWS\System32\PnkBstrB.exe [2012-06-27 11:19:45 | 000,076,888 | ---- | C] () -- D:\WINDOWS\System32\PnkBstrA.exe [2012-06-27 00:32:38 | 000,064,200 | ---- | C] () -- D:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat [2012-06-26 17:09:04 | 000,000,581 | ---- | C] () -- D:\Documents and Settings\Admon\Pulpit\Skrót do C9Launcher.lnk [2012-06-26 10:03:35 | 000,000,095 | ---- | C] () -- D:\Documents and Settings\Admon\Pulpit\C9.url [2012-06-18 22:29:52 | 000,000,600 | ---- | C] () -- D:\Documents and Settings\All Users\Pulpit\Dawn of War.lnk [2012-06-18 21:18:34 | 000,000,725 | ---- | C] () -- D:\Documents and Settings\Admon\Pulpit\NapiProjekt.lnk [2012-05-29 09:44:36 | 000,354,816 | ---- | C] () -- D:\WINDOWS\System32\psisdecd.dll [2012-05-28 03:02:17 | 000,003,072 | ---- | C] () -- D:\WINDOWS\System32\iacenc.dll [2012-03-08 00:46:06 | 000,008,704 | ---- | C] () -- D:\Documents and Settings\Admon\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-03-08 00:00:27 | 000,004,293 | ---- | C] () -- D:\WINDOWS\ODBCINST.INI [2012-03-07 23:59:20 | 000,098,256 | ---- | C] () -- D:\WINDOWS\System32\FNTCACHE.DAT [2012-03-07 23:39:55 | 001,074,636 | ---- | C] () -- D:\WINDOWS\System32\nvdrsdb1.bin [2012-03-07 23:39:55 | 001,074,636 | ---- | C] () -- D:\WINDOWS\System32\nvdrsdb0.bin [2012-03-07 23:39:55 | 000,000,001 | ---- | C] () -- D:\WINDOWS\System32\nvdrssel.bin [2012-03-07 23:39:36 | 002,807,708 | ---- | C] () -- D:\WINDOWS\System32\nvdata.data [2012-03-07 23:10:38 | 000,002,048 | --S- | C] () -- D:\WINDOWS\bootstat.dat [2012-03-07 23:05:01 | 000,021,856 | ---- | C] () -- D:\WINDOWS\System32\emptyregdb.dat [2012-03-06 13:45:51 | 000,005,810 | ---- | C] () -- D:\WINDOWS\System32\drivers\ASACPI.sys < End of report >