OTL logfile created on: 2012-12-20 20:36:50 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Swistak\Pulpit\dr Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 502,36 Mb Total Physical Memory | 108,84 Mb Available Physical Memory | 21,67% Memory free 1,20 Gb Paging File | 0,86 Gb Available in Paging File | 71,97% Paging File free Paging file location(s): C:\pagefile.sys 756 1512 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 29,29 Gb Total Space | 0,22 Gb Free Space | 0,77% Space Free | Partition Type: NTFS Drive D: | 40,91 Gb Total Space | 36,18 Gb Free Space | 88,44% Space Free | Partition Type: FAT32 Computer Name: LENOVO-2B31F5C6 | User Name: Swistak | NOT logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-12-20 20:09:38 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Swistak\Pulpit\dr\OTL.exe PRC - [2009-10-07 09:15:42 | 001,461,080 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe PRC - [2008-04-14 22:51:26 | 001,414,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mmc.exe PRC - [2008-04-14 22:51:18 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2006-08-16 18:07:00 | 000,069,632 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\AwayTask\AwaySch.EXE PRC - [2006-05-30 07:05:42 | 000,086,016 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe PRC - [2006-03-13 16:38:56 | 000,041,472 | R--- | M] (Utimaco Safeware AG) -- C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdservice.exe PRC - [2006-02-14 06:17:28 | 000,110,592 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe PRC - [2006-02-02 05:20:00 | 000,122,940 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\DLA\DLACTRLW.EXE PRC - [2005-07-05 06:57:12 | 000,077,824 | ---- | M] () -- C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2006-07-04 17:11:00 | 000,057,344 | ---- | M] () -- C:\Program Files\ThinkVantage\PrdCtr\US\LPRESMGR.DLL MOD - [2006-05-25 17:13:00 | 000,073,728 | ---- | M] () -- C:\Program Files\ThinkPad\Utilities\PWRMGRIF.DLL MOD - [2006-05-25 17:13:00 | 000,036,864 | ---- | M] () -- C:\Program Files\ThinkPad\Utilities\US\PWRMGRRT.DLL MOD - [2006-02-23 18:22:00 | 000,057,344 | ---- | M] () -- C:\Program Files\ThinkPad\Utilities\US\EZMAPRES.DLL MOD - [2005-10-28 12:29:52 | 000,208,896 | ---- | M] () -- C:\Program Files\Lenovo\PkgMgr\HOTKEY\tpfnf7.dll MOD - [2005-07-19 19:34:28 | 000,126,976 | ---- | M] () -- C:\Program Files\ThinkVantage\AMSG\ahlprunl.dll MOD - [2005-07-05 06:57:12 | 000,077,824 | ---- | M] () -- C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe MOD - [2005-06-29 19:54:50 | 000,180,224 | ---- | M] () -- C:\Program Files\ThinkVantage\AMSG\AcpPollingEngine.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [Disabled | Unknown] -- %SystemRoot%\System32\hidserv.dll -- (HidServ) SRV - File not found [On_Demand | Unknown] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt) SRV - [2009-10-07 09:21:14 | 000,020,680 | ---- | M] (ESET) [On_Demand | Unknown] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv) SRV - [2009-10-07 09:16:50 | 000,472,280 | ---- | M] (ESET) [Auto | Unknown] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn) SRV - [2006-11-17 01:07:00 | 000,015,872 | ---- | M] ( ) [Auto | Unknown] -- c:\Program Files\Lenovo\System Update\SUService.exe -- (SUService) SRV - [2006-11-16 16:14:14 | 000,023,552 | ---- | M] () [On_Demand | Unknown] -- C:\WINDOWS\system32\psasrv.exe -- (PsaSrv) SRV - [2006-08-16 18:07:00 | 000,073,728 | ---- | M] (Lenovo Group Limited) [Auto | Unknown] -- C:\WINDOWS\system32\IPSSVC.EXE -- (IPSSVC) SRV - [2006-07-14 17:24:52 | 000,629,504 | ---- | M] () [Auto | Unknown] -- C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe -- (ThinkVantage Registry Monitor Service) SRV - [2006-07-14 15:52:48 | 000,045,056 | ---- | M] () [Auto | Unknown] -- C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe -- (tvtnetwk) SRV - [2006-05-23 21:08:06 | 000,622,700 | ---- | M] (Diskeeper Corporation) [Auto | Unknown] -- C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe -- (Diskeeper) SRV - [2005-10-06 18:46:38 | 000,856,064 | ---- | M] (Microsoft Corporation) [On_Demand | Unknown] -- C:\Program Files\Windows Media Connect 2\wmccds.exe -- (WMConnectCDS) SRV - [2005-06-06 21:26:22 | 000,032,768 | ---- | M] () [Auto | Unknown] -- C:\WINDOWS\system32\TpKmpSvc.exe -- (TpKmpSVC) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Unknown] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Unknown] -- C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\SCFIDS~1\20050404.003\symidsco.sys -- (SYMIDSCO) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (PDCOMP) DRV - File not found [Kernel | System | Unknown] -- -- (PCIDump) DRV - File not found [Kernel | System | Unknown] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Unknown] -- -- (Changer) DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\Policja\USTAWI~1\Temp\catchme.sys -- (catchme) DRV - [2009-10-07 09:18:36 | 000,035,168 | ---- | M] () [Kernel | System | Unknown] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir) DRV - [2009-10-07 09:12:22 | 000,054,184 | ---- | M] (ESET) [Kernel | System | Unknown] -- C:\WINDOWS\system32\drivers\easdrv.sys -- (easdrv) DRV - [2009-10-07 09:11:10 | 000,040,824 | ---- | M] (ESET) [Kernel | Auto | Unknown] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon) DRV - [2009-01-28 13:30:01 | 000,017,536 | ---- | M] (Lenovo) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\psadd.sys -- (psadd) DRV - [2006-12-07 07:07:14 | 000,508,672 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211) DRV - [2006-08-16 18:07:00 | 000,005,120 | ---- | M] (Lenovo Group Limited) [Kernel | Auto | Unknown] -- C:\WINDOWS\system32\drivers\PROCDD.SYS -- (PROCDD) DRV - [2006-08-02 17:54:00 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | System | Unknown] -- C:\WINDOWS\system32\drivers\SMAPINT.SYS -- (Smapint) DRV - [2006-08-02 17:54:00 | 000,009,343 | ---- | M] () [Kernel | System | Unknown] -- C:\WINDOWS\system32\drivers\TDSMAPI.SYS -- (TDSMAPI) DRV - [2006-07-20 18:54:00 | 000,007,168 | ---- | M] () [Kernel | System | Unknown] -- C:\WINDOWS\system32\drivers\TSMAPIP.SYS -- (TSMAPIP) DRV - [2006-05-25 17:13:00 | 000,004,442 | ---- | M] () [Kernel | System | Unknown] -- C:\WINDOWS\system32\drivers\TPPWRIF.SYS -- (TPPWRIF) DRV - [2006-04-25 19:00:00 | 000,003,456 | ---- | M] (UPEK Inc.) [Kernel | Auto | Unknown] -- C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys -- (smihlp) DRV - [2006-03-13 16:05:54 | 000,058,368 | R--- | M] (Utimaco Safeware AG) [Kernel | Auto | Unknown] -- C:\Program Files\Lenovo\SafeGuard PrivateDisk\privatediskm.sys -- (PrivateDisk) DRV - [2006-03-09 09:20:10 | 000,152,064 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Unknown] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k) DRV - [2006-02-02 05:20:00 | 000,094,332 | ---- | M] (Sonic Solutions) [File_System | Auto | Unknown] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM) DRV - [2006-02-02 05:20:00 | 000,087,036 | ---- | M] (Sonic Solutions) [File_System | Auto | Unknown] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M) DRV - [2006-02-02 05:20:00 | 000,086,652 | ---- | M] (Sonic Solutions) [File_System | Auto | Unknown] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M) DRV - [2006-02-02 05:20:00 | 000,025,628 | ---- | M] (Sonic Solutions) [File_System | Auto | Unknown] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM) DRV - [2006-02-02 05:20:00 | 000,014,684 | ---- | M] (Sonic Solutions) [File_System | Auto | Unknown] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM) DRV - [2006-02-02 05:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Unknown] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM) DRV - [2006-02-02 05:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Unknown] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN) DRV - [2005-11-18 12:02:50 | 000,005,660 | ---- | M] (Sonic Solutions) [File_System | System | Unknown] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM) DRV - [2005-11-18 12:02:10 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Unknown] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/ IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/welcome/thinkpad [binary data] IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.live.com IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/welcome/thinkpad [binary data] IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.live.com IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2162753371-3219808102-3900027765-1009\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com.pl/0SEPLPL/SAOS01?FORM=TOOLBR IE - HKU\S-1-5-21-2162753371-3219808102-3900027765-1009\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com.pl/0SEPLPL/SAOS01?FORM=TOOLBR IE - HKU\S-1-5-21-2162753371-3219808102-3900027765-1009\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.podkarpacka.policja.gov.pl/ IE - HKU\S-1-5-21-2162753371-3219808102-3900027765-1009\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-2162753371-3219808102-3900027765-1009\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC IE - HKU\S-1-5-21-2162753371-3219808102-3900027765-1009\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) O1 HOSTS File: ([2004-08-04 21:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (CPwmIEBrowserHelper Object) - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited) O3 - HKU\S-1-5-21-2162753371-3219808102-3900027765-1009\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll File not found O4 - HKLM..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE (Lenovo Group Limited) O4 - HKLM..\Run: [BLOG] C:\Program Files\ThinkPad\Utilities\BATLOGEX.DLL () O4 - HKLM..\Run: [DiskeeperSystray] C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe (Diskeeper Corporation) O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions) O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET) O4 - HKLM..\Run: [PDService.exe] C:\Program Files\Lenovo\SafeGuard PrivateDisk\pdservice.exe (Utimaco Safeware AG) O4 - HKLM..\Run: [PWRMGRTR] C:\Program Files\ThinkPad\Utilities\PWRMGRTR.DLL (Lenovo Group Limited) O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.) O4 - HKLM..\Run: [TP4EX] C:\WINDOWS\System32\TP4EX.exe (Lenovo Group Limited) O4 - HKLM..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe (Lenovo) O4 - HKLM..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-2162753371-3219808102-3900027765-1009\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm File not found O8 - Extra context menu item: Wyślij do urządzenia &Bluetooth... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm File not found O9 - Extra Button: System Update - {DA320635-F48C-4613-8325-D75A933C549E} - C:\Program Files\Lenovo\System Update\sulauncher.exe () O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1288173063031 (MUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06) O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4D469529-6E0A-4D2F-97F1-A237E2A3182A}: NameServer = 172.16.0.1 O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: GinaDLL - (vrlogon.dll) - C:\WINDOWS\System32\vrlogon.dll (UPEK Inc.) O20 - Winlogon\Notify\AwayNotify: DllName - (C:\Program Files\Lenovo\AwayTask\AwayNotify.dll) - C:\Program Files\Lenovo\AwayTask\AwayNotify.dll (Lenovo Group Limited) O20 - Winlogon\Notify\NavLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found O20 - Winlogon\Notify\psfus: DllName - (psqlpwd.dll) - C:\WINDOWS\System32\psqlpwd.dll (UPEK Inc.) O20 - Winlogon\Notify\tpfnf2: DllName - (notifyf2.dll) - C:\WINDOWS\System32\notifyf2.dll () O20 - Winlogon\Notify\tphotkey: DllName - (tphklock.dll) - C:\WINDOWS\System32\tphklock.dll () O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp O24 - Desktop BackupWallPaper: C:\WINDOWS\1024_768 Think EMEA Map.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006-03-03 03:58:15 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-12-20 20:26:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Swistak\Pulpit\dr [2012-12-20 08:29:44 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Swistak\Pulpit\Nowy Aktówka [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-12-20 20:39:00 | 000,000,464 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{6CF56361-11B7-4872-B023-67AA95A0A3DE}.job [2012-12-20 20:19:01 | 000,000,258 | ---- | M] () -- C:\WINDOWS\tasks\Sprawdź aktualizacje paska narzędzi Windows Live Toolbar.job [2012-12-20 19:42:37 | 000,009,930 | ---- | M] () -- C:\WINDOWS\System32\PROCDB.INI [2012-12-20 19:42:18 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012-12-20 19:42:16 | 526,831,616 | -HS- | M] () -- C:\hiberfil.sys [2012-12-20 17:40:42 | 095,023,320 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\1072d!.pad [2012-12-18 13:58:04 | 000,000,809 | ---- | M] () -- C:\Documents and Settings\Swistak\Menu Start\Programy\Autostart\runctf.lnk [2012-12-17 08:06:57 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012-12-13 11:48:21 | 000,247,904 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012-12-12 15:38:03 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-12-18 13:58:03 | 000,000,809 | ---- | C] () -- C:\Documents and Settings\Swistak\Menu Start\Programy\Autostart\runctf.lnk [2012-12-18 13:56:59 | 095,023,320 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\1072d!.pad [2012-02-15 12:03:47 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2009-01-29 10:15:06 | 000,000,135 | ---- | C] () -- C:\Documents and Settings\Swistak\Ustawienia lokalne\Dane aplikacji\fusioncache.dat [2009-01-28 13:37:36 | 000,000,542 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\tvt_userinfo.ini [color=#E56717]========== ZeroAccess Check ==========[/color] [2006-03-03 04:15:12 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2008-04-14 22:50:48 | 001,499,136 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009-02-09 11:53:44 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008-04-14 22:50:58 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2009-01-28 14:31:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ESET [2009-01-28 13:37:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Lenovo [2009-01-28 14:36:36 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\{A25FEDC1-F6D7-440C-BCE2-B71F595F6646} [2009-01-28 13:37:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Dane aplikacji\Lenovo [2009-01-28 13:37:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Dane aplikacji\ThinkVantage [2009-04-18 07:24:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Swistak\Dane aplikacji\InterVideo [2009-01-28 13:37:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Swistak\Dane aplikacji\Lenovo [2009-01-28 13:37:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Swistak\Dane aplikacji\ThinkVantage [color=#E56717]========== Purity Check ==========[/color] < End of report >