OTL logfile created on: 2012-07-11 13:00:09 - Run 1 OTL by OldTimer - Version 3.2.53.1 Folder = F:\wirus otl Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1015,48 Mb Total Physical Memory | 817,90 Mb Available Physical Memory | 80,54% Memory free 2,90 Gb Paging File | 2,83 Gb Available in Paging File | 97,83% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 51,39 Gb Total Space | 37,41 Gb Free Space | 72,81% Space Free | Partition Type: NTFS Drive E: | 97,65 Gb Total Space | 96,62 Gb Free Space | 98,94% Space Free | Partition Type: NTFS Drive F: | 7,37 Gb Total Space | 4,06 Gb Free Space | 55,11% Space Free | Partition Type: FAT32 Computer Name: OEMCOMPUTER | User Name: grażyna | Logged in as Administrator. Boot Mode: SafeMode | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-07-11 08:51:56 | 000,595,968 | ---- | M] (OldTimer Tools) -- F:\wirus otl\OTL.exe PRC - [2008-04-14 19:21:16 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012-04-04 07:54:04 | 000,300,544 | ---- | M] () -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.POL [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ) SRV - [2012-04-04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2011-12-19 08:51:22 | 000,543,312 | ---- | M] () [Auto | Stopped] -- C:\Program Files\ArcaBit\ArcaAgent\ArcaRemoteSvc.exe -- (ArcaRemoteService) SRV - [2011-10-03 09:28:53 | 000,137,808 | ---- | M] (ArcaBit) [Auto | Stopped] -- C:\Program Files\ArcaBit\Common\ArcaConfSV.exe -- (ABConfSV) SRV - [2011-10-03 09:28:52 | 000,117,328 | ---- | M] (ArcaBit) [Auto | Stopped] -- C:\Program Files\ArcaBit\ArcaUpdate\update.exe -- (AVUpdate) SRV - [2011-08-29 07:42:22 | 000,155,112 | ---- | M] (ArcaBit) [Auto | Stopped] -- C:\Program Files\ArcaBit\ArcaVir\ArcaMainSV.exe -- (ABMainSV) SRV - [2011-04-05 08:23:41 | 000,186,960 | ---- | M] (ArcaBit) [Auto | Stopped] -- C:\Program Files\ArcaBit\ArcaTools\ArcaBackup\ArcaBackupService.exe -- (AVBackup) SRV - [2011-01-21 14:42:20 | 000,129,616 | ---- | M] (ArcaBit) [Auto | Stopped] -- C:\Program Files\ArcaBit\Common\ArcaTasksService.exe -- (AVTasks2) SRV - [2007-01-12 17:51:30 | 000,508,848 | ---- | M] ( ) [On_Demand | Stopped] -- C:\WINDOWS\system32\LMabcoms.exe -- (lmab_device) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\ArcaBit\ArcaVir\ps_drv.sys -- (ps_drv) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2012-04-04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector) DRV - [2011-03-03 12:03:23 | 000,052,304 | ---- | M] (ArcaBit) [File_System | On_Demand | Stopped] -- C:\Program Files\ArcaBit\ArcaVir\ABFLT.sys -- (ABFLT) DRV - [2010-10-26 14:04:30 | 000,051,280 | ---- | M] (ArcaBit) [Kernel | System | Stopped] -- C:\Program Files\ArcaBit\ArcaVir\ABTDI.sys -- (ABTDI) DRV - [2008-02-14 11:04:06 | 004,676,096 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2008-01-03 16:10:16 | 000,105,856 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp) DRV - [2007-07-16 17:29:33 | 000,017,432 | R--- | M] (Hewlett Packard) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hpfxbulk.sys -- (HPFXBULK) DRV - [2004-08-03 23:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Sterownik NT karty Realtek RTL8139(A/B/C) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "http://www.google.pl/" FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - prefs.js..extensions.enabledItems: arcabit@www.arcabit.pl:3.5 FF - prefs.js..network.proxy.type: 0 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011-01-05 09:56:27 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012-06-28 09:00:03 | 000,000,000 | ---D | M] [2011-01-05 09:56:39 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\grażyna\Dane aplikacji\Mozilla\Extensions [2012-06-25 10:30:32 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\grażyna\Dane aplikacji\Mozilla\Firefox\Profiles\n115kdz3.default\extensions [2011-01-05 10:02:52 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\grażyna\Dane aplikacji\Mozilla\Firefox\Profiles\n115kdz3.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2012-06-25 10:30:32 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2011-01-05 10:01:30 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} [2011-02-17 12:56:03 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [2011-03-03 11:29:01 | 000,000,000 | ---D | M] (ArcaBit Ext.) -- C:\Program Files\Mozilla Firefox\extensions\arcabit@www.arcabit.pl [2011-02-02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2005-04-05 05:38:20 | 000,053,355 | ---- | M] (Oracle Corporation) -- C:\Program Files\mozilla firefox\plugins\NPJinit13122.dll [2010-12-03 19:54:54 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2010-12-03 19:54:54 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2010-12-03 19:54:54 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2010-12-03 19:54:54 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2010-12-03 19:54:54 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2010-12-03 19:54:54 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2007-10-29 14:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O4 - HKLM..\Run: [ABRegmon] C:\Program Files\ArcaBit\ArcaVir\abregmon.exe (ArcaBit) O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [AvMenu] C:\Program Files\ArcaBit\ArcaVir\AVMenu.exe (ArcaBit) O4 - HKLM..\Run: [whhelper] C:\Documents and Settings\grażyna\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\4831\whhelper.exe () O4 - Startup: C:\Documents and Settings\grażyna\Menu Start\Programy\Autostart\OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found O9 - Extra Button: ArcaVir >> - {40525A66-DB98-480D-BCF9-7AF88C1AF438} - C:\Program Files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll (ArcaBit sp. z o.o) O9 - Extra 'Tools' menuitem : ArcaVir >> - {40525A66-DB98-480D-BCF9-7AF88C1AF438} - C:\Program Files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll (ArcaBit sp. z o.o) O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Reg Error: Key error.) O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF} http://shrimp.uokik.gov.pl/forms/jinitiator/jinit.exe (JInitiator 1.3.1.22) O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DB2D02DC-C54E-4187-AEF2-A3EFAA4887CE}: NameServer = 192.168.9.1,194.204.159.1 O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\grażyna\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\grażyna\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008-10-01 21:52:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{5faf076c-0f07-11de-92db-001fd002febe}\Shell - "" = AutoRun O33 - MountPoints2\{5faf076c-0f07-11de-92db-001fd002febe}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe O33 - MountPoints2\{7aabc6ea-99cd-11dd-925c-001fd002febe}\Shell\AutoRun\command - "" = F:\wd_windows_tools\WDSetup.exe O33 - MountPoints2\{9d707b41-9201-11dd-9250-001fd002febe}\Shell\AutoRun\command - "" = F:\1utbfd.bat O33 - MountPoints2\{9d707b41-9201-11dd-9250-001fd002febe}\Shell\open\Command - "" = F:\1utbfd.bat O33 - MountPoints2\{b57ba5ee-25c5-11df-9408-001fd002febe}\Shell\AutoRun\command - "" = p3vwxx.exe O33 - MountPoints2\{b57ba5ee-25c5-11df-9408-001fd002febe}\Shell\open\Command - "" = p3vwxx.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-07-11 09:11:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\grażyna\Dane aplikacji\Malwarebytes [2012-07-11 09:11:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes' Anti-Malware [2012-07-11 09:11:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes [2012-07-11 09:11:44 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2012-07-11 09:11:44 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2012-07-11 09:11:18 | 000,000,000 | ---D | C] -- C:\wirus otl [2012-07-11 09:10:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\grażyna\Pulpit\wirus otl [2012-07-10 08:19:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\grażyna\Dane aplikacji\hellomoto [2012-06-28 07:50:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\grażyna\Pulpit\książka [2012-06-26 12:26:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\grażyna\Ustawienia lokalne\Dane aplikacji\Temp [2012-06-25 10:49:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe [2012-06-13 07:42:06 | 000,521,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsdbgui.dll [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-07-11 12:59:37 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012-07-11 12:58:36 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012-07-11 12:56:04 | 000,000,478 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{44A6FC43-BE02-4AD0-9266-433C9A258B4B}.job [2012-07-11 12:55:50 | 000,000,466 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{D3A3B16E-F760-41C6-960F-582D7DFF89CB}.job [2012-07-11 12:55:48 | 000,360,136 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012-07-11 10:34:24 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2012-07-11 09:11:49 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk [2012-07-10 14:55:46 | 000,029,087 | ---- | M] () -- C:\Documents and Settings\grażyna\Moje dokumenty\Decyzja- ulgi.odt [2012-07-10 12:42:33 | 000,017,748 | ---- | M] () -- C:\Documents and Settings\grażyna\Moje dokumenty\art 165 rejniewicz posta.odt [2012-07-10 11:43:33 | 000,018,607 | ---- | M] () -- C:\Documents and Settings\grażyna\Moje dokumenty\ulgi 2011.odt [2012-07-10 11:01:09 | 000,063,209 | ---- | M] () -- C:\Documents and Settings\grażyna\Moje dokumenty\zaśnAgencja.csv [2012-07-10 10:58:08 | 000,405,294 | ---- | M] () -- C:\Documents and Settings\grażyna\Moje dokumenty\zaśnAgencja.xhtml [2012-07-10 10:57:27 | 000,213,801 | ---- | M] () -- C:\Documents and Settings\grażyna\Moje dokumenty\Białaczka..pdf [2012-07-10 10:38:14 | 000,015,122 | ---- | M] () -- C:\Documents and Settings\grażyna\Moje dokumenty\Starostwo Powiatowe w Lipsku.odt [2012-07-05 12:11:59 | 000,014,965 | ---- | M] () -- C:\Documents and Settings\grażyna\Moje dokumenty\g.sz..odt [2012-06-26 09:12:13 | 000,014,604 | ---- | M] () -- C:\Documents and Settings\grażyna\Pulpit\krus 1.odt [2012-06-25 10:49:34 | 000,001,773 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Adobe Reader X.lnk [2012-06-20 13:52:34 | 000,013,458 | ---- | M] () -- C:\Documents and Settings\grażyna\Moje dokumenty\staz.odt [2012-06-18 12:44:47 | 000,014,673 | ---- | M] () -- C:\Documents and Settings\grażyna\Moje dokumenty\szg-s.odt [2012-06-18 12:03:03 | 000,015,950 | ---- | M] () -- C:\Documents and Settings\grażyna\Pulpit\inne zaświadczenia pdf.odt [2012-06-13 15:55:21 | 001,866,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\win32k.sys [2012-06-13 15:55:21 | 001,866,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\win32k.sys [2012-06-13 08:05:42 | 000,491,064 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2012-06-13 08:05:42 | 000,432,928 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012-06-13 08:05:42 | 000,084,316 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2012-06-13 08:05:42 | 000,067,884 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-07-11 09:11:49 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk [2012-07-10 11:01:09 | 000,063,209 | ---- | C] () -- C:\Documents and Settings\grażyna\Moje dokumenty\zaśnAgencja.csv [2012-07-10 10:57:59 | 000,405,294 | ---- | C] () -- C:\Documents and Settings\grażyna\Moje dokumenty\zaśnAgencja.xhtml [2012-06-25 10:49:33 | 000,002,347 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Adobe Reader X.lnk [2012-06-25 10:49:33 | 000,001,773 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Adobe Reader X.lnk [2012-03-26 13:27:03 | 000,005,120 | ---- | C] () -- C:\Documents and Settings\grażyna\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-02-15 09:28:40 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2011-01-05 09:56:28 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat [2010-12-10 13:14:32 | 000,036,962 | ---- | C] () -- C:\WINDOWS\System32\ActPanel.dll [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 88 bytes -> C:\Documents and Settings\grażyna\Pulpit\rozporzadzenie_shrimp_23.12.2009.pdf:SummaryInformation < End of report >