OTL logfile created on: 2012-09-02 10:33:53 - Run 9 OTL by OldTimer - Version 3.2.41.0 Folder = C:\Documents and Settings\user\Moje dokumenty Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 1,62 Gb Available Physical Memory | 80,92% Memory free 3,85 Gb Paging File | 3,63 Gb Available in Paging File | 94,41% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 100,10 Gb Total Space | 42,08 Gb Free Space | 42,04% Space Free | Partition Type: NTFS Drive D: | 197,98 Gb Total Space | 176,08 Gb Free Space | 88,94% Space Free | Partition Type: NTFS Drive F: | 1,92 Gb Total Space | 0,79 Gb Free Space | 40,90% Space Free | Partition Type: FAT Computer Name: USER-82A05D2F31 | User Name: user | NOT logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-07-09 13:05:46 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\OTL.exe PRC - [2012-07-09 13:05:46 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Moje dokumenty\OTL.exe PRC - [2009-12-15 14:47:00 | 000,103,720 | ---- | M] (CyberLink) -- C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe PRC - [2008-04-15 14:00:00 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2011-10-08 06:50:00 | 000,355,432 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\nView\nvShell.dll MOD - [2010-03-15 12:28:22 | 000,141,824 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll MOD - [2009-12-15 14:49:20 | 000,013,096 | ---- | M] () -- C:\Program Files\CyberLink\Power2Go\CLMLSvcPS.dll MOD - [2009-12-15 14:46:38 | 000,619,816 | ---- | M] () -- C:\Program Files\CyberLink\Power2Go\CLMediaLibrary.dll MOD - [2009-02-27 20:04:20 | 000,311,296 | ---- | M] () -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\pdfshell.POL [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [On_Demand | Unknown] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt) SRV - [2012-09-01 10:28:06 | 000,115,184 | ---- | M] (Mozilla Foundation) [On_Demand | Unknown] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2011-10-08 06:50:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) [Auto | Unknown] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService) SRV - [2008-04-15 14:00:00 | 000,088,576 | ---- | M] (Microsoft Corporation) [Unknown (-1) | Unknown] -- C:\WINDOWS\system32\wbem\wmiaprpl.dll -- (WmiApRpl) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Unknown] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (PDCOMP) DRV - File not found [Kernel | System | Unknown] -- -- (PCIDump) DRV - File not found [Kernel | System | Unknown] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Unknown] -- -- (i2omgmt) DRV - File not found [Kernel | System | Unknown] -- -- (Changer) DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\catchme.sys -- (catchme) DRV - [2011-01-25 20:54:04 | 006,321,768 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2011-01-14 09:06:40 | 000,277,352 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp) DRV - [2010-08-24 19:30:06 | 000,020,304 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\L8042Kbd.sys -- (L8042Kbd) DRV - [2009-11-18 09:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt) DRV - [2009-11-18 09:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt) DRV - [2008-04-15 14:00:00 | 000,088,576 | ---- | M] (Microsoft Corporation) [Unknown (-1) | Unknown (-1) | Unknown] -- C:\WINDOWS\system32\wbem\wmiaprpl.dll -- (WmiApRpl) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-507921405-764733703-1801674531-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://gazeta.pl/0,0.html?sc=1 IE - HKU\S-1-5-21-507921405-764733703-1801674531-1004\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKU\S-1-5-21-507921405-764733703-1801674531-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://alawar.pl IE - HKU\S-1-5-21-507921405-764733703-1801674531-1004\..\URLSearchHook: {8532a8b7-c06a-41bb-936a-8ce73e4711ed} - No CLSID value found IE - HKU\S-1-5-21-507921405-764733703-1801674531-1004\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKU\S-1-5-21-507921405-764733703-1801674531-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-507921405-764733703-1801674531-1004\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=111366&tt=010712_3&babsrc=SP_ss&mntrId=a0bf112800000000000000218519fe31 IE - HKU\S-1-5-21-507921405-764733703-1801674531-1004\..\SearchScopes\{5B54A900-A847-453C-83DB-5041A8F8F847}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=AWR&o=1955&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=^A17&apn_dtid=^YYYYYY^YY^PL&apn_uid=bfe73421-4583-41d8-bf72-88949002435c&apn_sauid=CDF08D57-CA41-4BD3-A436-3DF8AA28A32D IE - HKU\S-1-5-21-507921405-764733703-1801674531-1004\..\SearchScopes\{6C26EC35-3D71-405B-8799-10F862D37B3D}: "URL" = http://szukaj.gazeta.pl/portalSearch.do?s.si(navigation).navigationEnabled=true&s.sm.query={searchTerms} IE - HKU\S-1-5-21-507921405-764733703-1801674531-1004\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2417076 IE - HKU\S-1-5-21-507921405-764733703-1801674531-1004\..\SearchScopes\{B654674A-BDCD-48C7-95B1-0A51AD1C243E}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-507921405-764733703-1801674531-1004\..\SearchScopes\{FD8A4B45-D213-477E-9793-78609C3862CA}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-507921405-764733703-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-507921405-764733703-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "http://alawar.pl" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Aurora 15.0a2\extensions\\Components: C:\Program Files\Aurora\components [2012-09-01 10:28:07 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Aurora 15.0a2\extensions\\Plugins: C:\Program Files\Aurora\plugins [2012-02-08 18:32:37 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Extensions [2012-07-25 14:57:15 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\j1xz6nri.default\extensions [2012-04-23 11:17:14 | 000,000,000 | ---D | M] (cacaoweb) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\j1xz6nri.default\extensions\cacaoweb@cacaoweb.org [2012-04-08 16:36:17 | 000,000,000 | ---D | M] (Fast Dial) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\j1xz6nri.default\extensions\fastdial@telega.phpnet(2).us [2012-07-05 16:43:24 | 000,000,000 | ---D | M] (Babylon) -- C:\Documents and Settings\user\Dane aplikacji\Mozilla\Firefox\Profiles\j1xz6nri.default\extensions\ffxtlbr@babylon.com [2012-02-08 18:29:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions () (No name found) -- C:\DOCUMENTS AND SETTINGS\USER\DANE APLIKACJI\MOZILLA\FIREFOX\PROFILES\J1XZ6NRI.DEFAULT\EXTENSIONS\TESTPILOT@LABS.MOZILLA.COM.XPI [2012-03-18 20:54:03 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF O1 HOSTS File: ([2012-09-02 10:09:36 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll File not found O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll File not found O3 - HKU\S-1-5-21-507921405-764733703-1801674531-1004\..\Toolbar\WebBrowser: (no name) - {8532A8B7-C06A-41BB-936A-8CE73E4711ED} - No CLSID value found. O3 - HKU\S-1-5-21-507921405-764733703-1801674531-1004\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O4 - HKLM..\Run: [CLMLServer] C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (CyberLink) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKU\S-1-5-21-507921405-764733703-1801674531-1004..\Run: [kiayblgwwykagam] C:\Documents and Settings\All Users\Dane aplikacji\kiayblgw.exe File not found O4 - HKU\S-1-5-21-507921405-764733703-1801674531-1004..\Run: [vkmbsemfgssrjiz] C:\Documents and Settings\All Users\Dane aplikacji\vkmbsemf.exe File not found O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-21-507921405-764733703-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 0.0.0.0 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{76D9F72E-7DF5-49F5-A636-215E3F15375C}: DhcpNameServer = 192.168.1.1 0.0.0.0 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2012-01-13 14:25:23 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2008-09-13 13:49:42 | 000,000,262 | -HS- | M] () - F:\AUTOEXEC.BAT -- [ FAT ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-09-02 10:32:53 | 000,594,944 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\user\Moje dokumenty\OTL.exe [2012-09-02 10:21:42 | 000,000,000 | -HSD | C] -- C:\RECYCLER [2012-09-02 10:10:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp [2012-09-02 09:52:54 | 004,742,651 | R--- | C] (Swearware) -- C:\ComboFix.exe [2012-09-01 22:21:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\rfeynukiwptbvyt [2012-09-01 10:28:01 | 000,000,000 | ---D | C] -- C:\Program Files\Aurora [2012-08-03 11:49:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Dane aplikacji\Merscom [2012-08-03 11:49:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Merscom [2012-08-03 11:48:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Menu Start\Programy\Alawar.pl [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-09-02 10:31:09 | 000,000,593 | ---- | M] () -- C:\Documents and Settings\user\Pulpit\Skrót do Moje dokumenty.lnk [2012-09-02 10:24:57 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012-09-02 10:09:36 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2012-09-02 09:10:12 | 004,742,651 | R--- | M] (Swearware) -- C:\ComboFix.exe [2012-09-01 22:21:22 | 000,078,101 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\urytcpsvgwgaixf [2012-09-01 21:22:36 | 000,285,788 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb0.bin [2012-09-01 21:22:36 | 000,000,001 | ---- | M] () -- C:\WINDOWS\System32\nvdrssel.bin [2012-08-26 08:01:11 | 000,285,788 | ---- | M] () -- C:\WINDOWS\System32\nvdrsdb1.bin [2012-08-25 09:53:34 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012-08-18 20:29:08 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini [2012-08-18 20:29:06 | 000,033,792 | ---- | M] () -- C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-08-16 15:06:05 | 000,120,544 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012-08-16 13:48:55 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2012-08-12 11:37:57 | 000,355,486 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2012-08-12 11:37:57 | 000,311,604 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012-08-12 11:37:57 | 000,049,492 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2012-08-12 11:37:57 | 000,039,992 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-09-02 10:31:09 | 000,000,593 | ---- | C] () -- C:\Documents and Settings\user\Pulpit\Skrót do Moje dokumenty.lnk [2012-09-01 22:21:02 | 000,078,101 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\urytcpsvgwgaixf [2012-07-05 17:16:43 | 000,120,544 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012-07-05 17:10:52 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe [2012-07-05 17:10:52 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe [2012-07-05 17:10:51 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2012-07-05 17:10:51 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2012-07-05 17:10:51 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2012-05-21 20:55:58 | 000,000,013 | ---- | C] () -- C:\WINDOWS\System32\nvModes.dat [2012-02-17 07:19:35 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2012-01-16 12:52:50 | 002,130,002 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data [2012-01-14 06:34:31 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2012-01-13 22:14:40 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat [2012-01-13 21:07:30 | 000,033,792 | ---- | C] () -- C:\Documents and Settings\user\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-01-13 15:21:08 | 000,175,616 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2012-01-13 15:21:08 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini [2012-01-13 15:21:05 | 000,644,608 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2012-01-13 15:21:05 | 000,243,200 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2012-01-13 15:21:05 | 000,073,216 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2012-01-13 15:17:20 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2012-01-13 14:47:50 | 000,285,788 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin [2012-01-13 14:47:48 | 000,285,788 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin [2012-01-13 14:47:48 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin [2012-01-13 14:45:26 | 002,292,678 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin [2012-01-13 14:43:43 | 000,081,936 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll [2012-01-13 14:26:34 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2012-01-13 14:23:23 | 000,021,856 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [color=#E56717]========== LOP Check ==========[/color] [2012-01-28 13:52:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Alawar [2012-01-27 13:44:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Alawar Stargaze [2012-01-17 09:19:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\AlawarWrapper [2012-02-08 18:36:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\AVAST Software [2012-01-21 17:52:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonBJ [2012-02-03 13:06:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\FlyWheelGames [2012-07-05 13:05:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\gnejcivkbnlypjv [2012-07-05 16:43:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\InstallMate [2012-08-03 11:49:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Merscom [2012-07-05 16:59:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Particles [2012-02-19 10:13:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Playrix Entertainment [2012-09-01 22:21:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\rfeynukiwptbvyt [2012-01-31 12:44:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Soccer-Cup-Solitaire [2012-02-03 11:46:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TheFallTrilogy [2012-03-02 17:40:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TheFallTrilogyEp2 [2012-01-28 13:52:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\Alawar [2012-03-11 10:50:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\Alawar Entertainment [2012-02-11 11:05:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\Alawar Stargaze [2012-07-01 13:14:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\AlawarEntertainment [2012-03-11 11:43:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\Ancient Quest of Saqqarah_alawar [2012-02-02 18:39:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\Artifex Mundi [2012-07-01 08:53:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\AtlanticJourney [2012-07-27 08:58:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\Awem [2012-07-05 08:05:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\Babylon [2012-07-05 16:43:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\BabylonToolbar [2012-07-10 05:29:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\Between The Worlds 2 [2012-01-31 21:10:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\Coyotes Tale [2012-01-29 16:45:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\Divo Games [2012-02-22 13:07:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\DreamWoods2ScreenShot [2012-02-22 12:41:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\FairyTale [2012-02-14 09:06:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\Friday's games [2012-01-31 14:37:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\Frogwares [2012-02-19 11:07:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\JaiboGames [2012-02-01 09:19:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\Land Of Runes [2012-07-08 08:23:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\LegacyGames [2012-08-03 11:49:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\Merscom [2012-07-01 09:25:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\Mystery of Mortlake Mansion [2012-07-06 14:37:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\Natural Threat.Ominous Shores [2012-01-16 13:02:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\OpenOffice.org [2012-02-22 12:14:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\Phantasmat_alawar_se [2012-01-31 09:59:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\PTV Game [2012-01-31 20:35:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\RobinsonCrusoe [2012-01-27 12:47:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\SecretIslandPoland [2012-01-19 11:08:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\URSE Games [2012-02-02 19:51:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Dane aplikacji\VampireSaga [color=#E56717]========== Purity Check ==========[/color] < End of report >