OTL logfile created on: 6/2/2013 5:46:38 PM - Run OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE Microsoft Windows XP Dodatek Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 89.00% Memory free 2.00 Gb Paging File | 2.00 Gb Available in Paging File | 97.00% Paging File free Paging file location(s): E:\pagefile.sys 3070 3070 [binary data] %SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files Drive C: | 18.64 Gb Total Space | 0.06 Gb Free Space | 0.34% Space Free | Partition Type: FAT32 Drive D: | 3.41 Gb Total Space | 0.61 Gb Free Space | 17.82% Space Free | Partition Type: FAT32 Drive E: | 48.82 Gb Total Space | 0.17 Gb Free Space | 0.35% Space Free | Partition Type: FAT32 Drive F: | 48.82 Gb Total Space | 0.12 Gb Free Space | 0.24% Space Free | Partition Type: FAT32 Drive G: | 48.82 Gb Total Space | 6.48 Gb Free Space | 13.28% Space Free | Partition Type: FAT32 Drive H: | 82.95 Gb Total Space | 0.22 Gb Free Space | 0.27% Space Free | Partition Type: NTFS Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS Computer Name: REATOGO | User Name: SYSTEM Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days Using ControlSet: ControlSet001 [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto] -- D:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto] -- D:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) SRV - [2012/10/02 15:40:38 | 002,019,184 | ---- | M] (O&O Software GmbH) [Auto] -- D:\Program Files\OO Software\Defrag\oodag.exe -- (OODefragAgent) SRV - [2010/10/11 17:28:24 | 001,632,088 | ---- | M] (Doctor Web, Ltd.) [Auto] -- D:\Program Files\Common Files\Doctor Web\Scanning Engine\dwengine.exe -- (DrWebEngine) Dr.Web Scanning Engine (DrWebEngine) SRV - [2002/12/16 12:40:44 | 000,139,264 | ---- | M] (Symantec Corporation) [Auto] -- D:\Program Files\Norton SystemWorks\Norton Utilities\Nprotect.exe -- (NProtectService) SRV - [2002/08/14 06:00:00 | 000,172,065 | ---- | M] (Symantec Corporation) [Auto] -- D:\Program Files\Norton SystemWorks\Speed Disk\NOPDB.EXE -- (Speed Disk service) SRV - [2002/01/30 07:33:14 | 000,077,824 | ---- | M] () [Auto] -- D:\Program Files\EPSON\ESM2\eEBSvc.exe -- (EpsonBidirectionalService) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand] -- -- (WDICA) DRV - File not found [Kernel | On_Demand] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand] -- -- (PDCOMP) DRV - File not found [Kernel | System] -- -- (PCIDump) DRV - File not found [Kernel | System] -- -- (lbrtfdc) DRV - File not found [Kernel | System] -- -- (i2omgmt) DRV - File not found [Kernel | System] -- -- (Changer) DRV - File not found [Kernel | Auto] -- -- (ASPI32) DRV - [2013/04/04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand] -- D:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector) DRV - [2011/11/15 05:50:16 | 000,112,096 | ---- | M] (Power Software Ltd) [Kernel | System] -- D:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu) DRV - [2010/07/26 16:52:42 | 000,125,304 | ---- | M] (Doctor Web, Ltd.) [File_System | Boot] -- D:\WINDOWS\system32\drivers\dwprot.sys -- (DwProt) DRV - [2010/07/19 13:40:54 | 000,081,400 | ---- | M] (Doctor Web, Ltd.) [File_System | Boot] -- D:\WINDOWS\system32\drivers\spiderg3.sys -- (SpiderG3) DRV - [2010/06/02 04:33:42 | 000,049,904 | R--- | M] (Avanquest Software) [Kernel | On_Demand] -- D:\WINDOWS\system32\drivers\BVRPMPR5.SYS -- (BVRPMPR5) DRV - [2010/04/18 19:57:20 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot] -- D:\WINDOWS\system32\drivers\sptd.sys -- (sptd) DRV - [2010/02/11 09:38:10 | 003,565,056 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand] -- D:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag) DRV - [2010/01/21 22:47:36 | 000,215,856 | ---- | M] (Silicon Image, Inc) [Kernel | Boot] -- D:\WINDOWS\System32\drivers\Si3132r5.sys -- (Si3132r5) DRV - [2010/01/21 22:47:36 | 000,212,520 | ---- | M] (Silicon Image, Inc) [Kernel | Boot] -- D:\WINDOWS\System32\drivers\Si3531.sys -- (Si3531) DRV - [2010/01/21 22:47:36 | 000,195,072 | ---- | M] (Silicon Image, Inc) [Kernel | Boot] -- D:\WINDOWS\System32\drivers\Si3114r5.sys -- (Si3114r5) DRV - [2010/01/21 22:47:36 | 000,074,672 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot] -- D:\WINDOWS\System32\drivers\si3132.sys -- (Si3132) DRV - [2010/01/21 22:47:36 | 000,069,248 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot] -- D:\WINDOWS\System32\drivers\si3124.sys -- (Si3124) DRV - [2010/01/21 22:47:36 | 000,062,336 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot] -- D:\WINDOWS\System32\drivers\si3112.sys -- (Si3112) DRV - [2008/05/16 12:33:14 | 000,115,752 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- D:\WINDOWS\system32\drivers\s0016unic.sys -- (s0016unic) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM) DRV - [2008/05/16 12:33:14 | 000,025,512 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- D:\WINDOWS\system32\drivers\s0016nd5.sys -- (s0016nd5) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS) DRV - [2008/05/16 12:33:12 | 000,114,216 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- D:\WINDOWS\system32\drivers\s0016mgmt.sys -- (s0016mgmt) Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM) DRV - [2008/05/16 12:33:12 | 000,110,632 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- D:\WINDOWS\system32\drivers\s0016obex.sys -- (s0016obex) DRV - [2008/05/16 12:33:12 | 000,089,256 | ---- | M] (MCCI Corporation) [Kernel | On_Demand] -- D:\WINDOWS\system32\drivers\s0016bus.sys -- (s0016bus) Sony Ericsson Device 0016 driver (WDM) DRV - [2008/04/13 23:15:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- D:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum) DRV - [2008/04/13 21:05:40 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand] -- D:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Sterownik NT karty Realtek RTL8139(A/B/C) DRV - [2007/12/14 09:21:32 | 000,009,216 | ---- | M] () [Kernel | On_Demand] -- D:\Program Files\MSI\Live Update 4\LU4\FlashSys.sys -- (FLASHSYS) DRV - [2007/07/12 11:49:16 | 000,096,384 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand] -- D:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp) DRV - [2007/02/16 01:57:06 | 000,034,760 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand] -- D:\WINDOWS\system32\drivers\ElbyCDFL.sys -- (ElbyCDFL) DRV - [2003/08/26 17:37:50 | 000,009,728 | ---- | M] (A4Tech Co.,Ltd.) [Kernel | On_Demand] -- D:\WINDOWS\system32\drivers\Amps2prt.sys -- (Amps2prt) DRV - [2002/08/29 23:14:26 | 000,073,224 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- D:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent) DRV - [2002/08/14 06:03:00 | 000,034,578 | ---- | M] (Symantec Corporation) [Kernel | On_Demand] -- D:\WINDOWS\system32\drivers\NPDRIVER.SYS -- (NPDriver) DRV - [2000/04/26 22:28:00 | 002,551,381 | ---- | M] (Yamaha Corporation) [Kernel | On_Demand] -- D:\WINDOWS\system32\drivers\Ds1.sys -- (ds1) YAMAHA DS-XG Audio Driver (WDM) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=fft&from=fft&uid=5JZA140F_ST320014A&ts=1346016027 IE - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.v9.com/?utm_source=b&utm_medium=fft&from=fft&uid=5JZA140F_ST320014A&ts=1346016027 IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\LocalService_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ IE - HKU\NetworkService_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ IE - HKU\XXX_ON_D\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=fft&from=fft&uid=5JZA140F_ST320014A&ts=1346016027 IE - HKU\XXX_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.v9.com/?utm_source=b&utm_medium=fft&from=fft&uid=5JZA140F_ST320014A&ts=1346016027 IE - HKU\XXX_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: D:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: D:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: D:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: D:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.3088: D:\Program Files\Real Alternative\Browser\Plugins\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.11.3006: D:\Program Files\Real Alternative\Browser\Plugins\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: D:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc) FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: D:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc) O1 HOSTS File: ([2010/04/18 13:48:00 | 000,000,789 | ---- | M]) - D:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (no name) - {28CF50DA-4A17-4442-BBF9-D916BFDE072C} - No CLSID value found. O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - D:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O3 - HKU\XXX_ON_D\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - D:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O4 - HKLM..\Run: [BluetoothAuthenticationAgent] D:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation) O4 - HKLM..\Run: [SpIDerAgent] D:\Program Files\DrWeb\SpIDerAgent.exe (Doctor Web, Ltd.) O4 - HKLM..\Run: [SpIDerMail] D:\Program Files\DrWeb\spiderml.exe (Doctor Web, Ltd.) O4 - HKLM..\Run: [WheelMouse] D:\Program Files\A4Tech\Mouse\Amoumain.exe (A4Tech Co.,Ltd.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuPinnedList = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1 O7 - HKU\LocalService_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\LocalService_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1 O7 - HKU\LocalService_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1 O7 - HKU\LocalService_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuPinnedList = 1 O7 - HKU\LocalService_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1 O7 - HKU\LocalService_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1 O7 - HKU\NetworkService_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\NetworkService_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1 O7 - HKU\NetworkService_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1 O7 - HKU\NetworkService_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuPinnedList = 1 O7 - HKU\NetworkService_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1 O7 - HKU\NetworkService_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1 O7 - HKU\XXX_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\XXX_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0 O7 - HKU\XXX_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1 O7 - HKU\XXX_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuPinnedList = 1 O7 - HKU\XXX_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1 O7 - HKU\XXX_ON_D\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1 O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - D:\Program Files\DrWeb\drwebsp.dll (Doctor Web, Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - D:\Program Files\DrWeb\drwebsp.dll (Doctor Web, Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - D:\Program Files\DrWeb\drwebsp.dll (Doctor Web, Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - D:\Program Files\DrWeb\drwebsp.dll (Doctor Web, Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - D:\Program Files\DrWeb\drwebsp.dll (Doctor Web, Ltd.) O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - D:\Program Files\DrWeb\drwebsp.dll (Doctor Web, Ltd.) O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKU\XXX_ON_D Winlogon: Shell - (explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKU\XXX_ON_D Winlogon: Shell - (D:\Documents and Settings\XXX\Dane aplikacji\skype.dat) - D:\Documents and Settings\XXX\Dane aplikacji\skype.dat () O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - D:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2010/04/17 18:47:48 | 000,000,000 | ---- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ] O32 - AutoRun File - [2012/12/25 06:10:33 | 000,000,000 | ---D | M] - H:\AUTO -- [ NTFS ] O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ] O34 - HKLM BootExecute: (autocheck autochk /p \??\L:) - File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O34 - HKLM BootExecute: (OODBS) - D:\WINDOWS\System32\OODBS.exe (O&O Software GmbH) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2013/06/02 16:16:25 | 000,000,000 | RH-D | C] -- D:\Documents and Settings\XXX\Recent [2013/06/02 16:12:52 | 000,000,000 | -HSD | C] -- D:\FOUND.000 [1 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2013/06/02 16:16:36 | 000,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat [2013/06/02 16:16:30 | 000,000,012 | ---- | M] () -- D:\WINDOWS\bthservsdp.dat [2013/06/02 16:16:24 | 000,000,004 | ---- | M] () -- D:\Documents and Settings\XXX\Dane aplikacji\skype.ini [2013/06/02 16:12:56 | 000,451,704 | ---- | M] () -- D:\WINDOWS\System32\oodbs.lor [2013/06/02 11:40:02 | 000,000,346 | ---- | M] () -- D:\WINDOWS\tasks\Dr.Web Update.job [2013/06/01 14:34:56 | 000,004,981 | ---- | M] () -- D:\WINDOWS\wincmd.ini [2013/06/01 13:32:34 | 000,000,069 | ---- | M] () -- D:\WINDOWS\NeroDigital.ini [2013/05/30 15:43:36 | 000,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl [2013/05/24 21:03:32 | 000,000,095 | ---- | M] () -- D:\WINDOWS\winamp.ini [1 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2013/06/02 00:01:49 | 000,000,004 | ---- | C] () -- D:\Documents and Settings\XXX\Dane aplikacji\skype.ini [2013/02/22 17:51:03 | 000,000,301 | ---- | C] () -- D:\WINDOWS\doom3.ini [2012/12/02 21:14:48 | 000,000,288 | ---- | C] () -- D:\WINDOWS\SIERRA.INI [2012/11/27 17:56:55 | 000,002,048 | RH-- | C] () -- D:\Documents and Settings\XXX\Recent.000 [2012/09/15 14:02:18 | 000,000,160 | ---- | C] () -- D:\WINDOWS\mafosav.INI [2012/02/12 18:03:23 | 000,000,041 | -HS- | C] () -- D:\Documents and Settings\All Users\Dane aplikacji\.zreglib [2011/09/12 01:03:52 | 000,000,498 | RHS- | C] () -- D:\Documents and Settings\XXX\ntuser.pol [2011/05/15 19:52:55 | 000,044,491 | ---- | C] () -- D:\WINDOWS\System32\MiiIniFile13.ini [2011/05/15 19:52:44 | 000,285,216 | ---- | C] () -- D:\WINDOWS\System32\drivers\Onsio.sys [2011/05/15 19:52:44 | 000,007,680 | ---- | C] () -- D:\WINDOWS\System32\drivers\Onsreged.sys [2011/05/15 19:17:33 | 000,000,035 | ---- | C] () -- D:\WINDOWS\Ulead32.INI [2011/04/23 16:55:13 | 000,015,872 | ---- | C] () -- D:\Documents and Settings\XXX\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011/04/17 21:38:58 | 000,016,384 | ---- | C] () -- D:\WINDOWS\System32\FileOps.exe [2011/02/07 05:56:30 | 000,000,012 | ---- | C] () -- D:\WINDOWS\bthservsdp.dat [2011/02/06 20:54:42 | 000,000,038 | ---- | C] () -- D:\WINDOWS\avisplitter.ini [2011/02/06 20:54:35 | 000,810,496 | ---- | C] () -- D:\WINDOWS\System32\xvidcore.dll [2011/02/06 20:54:35 | 000,183,808 | ---- | C] () -- D:\WINDOWS\System32\xvidvfw.dll [2011/02/06 20:54:34 | 000,080,896 | ---- | C] () -- D:\WINDOWS\System32\ff_vfw.dll [2011/02/06 20:36:30 | 000,000,070 | ---- | C] () -- D:\WINDOWS\WININIT.INI [2010/05/29 11:04:07 | 003,107,788 | ---- | C] () -- D:\WINDOWS\System32\ativva5x.dat [2010/05/29 11:04:07 | 000,887,724 | ---- | C] () -- D:\WINDOWS\System32\ativva6x.dat [2010/05/29 11:04:04 | 000,189,051 | ---- | C] () -- D:\WINDOWS\System32\atiicdxx.dat [2010/04/18 20:28:52 | 000,000,128 | ---- | C] () -- D:\Documents and Settings\XXX\Ustawienia lokalne\Dane aplikacji\fusioncache.dat [2010/04/18 19:13:13 | 000,000,032 | -HS- | C] () -- D:\WINDOWS\System32\{77C33A79-41C4-4F1D-A9E2-E22FC0F811CE}.dat [2010/04/18 19:13:13 | 000,000,032 | -HS- | C] () -- D:\WINDOWS\{39037598-B04A-4E6C-B766-289E4C891607}.dat [2010/04/18 19:12:35 | 000,000,032 | -HS- | C] () -- D:\WINDOWS\System32\{D55B2627-0793-4FFD-86C3-6335071B6B9C}.dat [2010/04/18 19:12:35 | 000,000,032 | -HS- | C] () -- D:\WINDOWS\{1DB3EE21-0FA2-4994-85CA-0A77D5AF0CF7}.dat [2010/04/18 19:11:30 | 000,000,032 | -HS- | C] () -- D:\WINDOWS\{C378F5FD-FD88-4487-839D-D06370E1500C}.dat [2010/04/18 19:11:30 | 000,000,032 | -HS- | C] () -- D:\WINDOWS\System32\{8ED5CCDF-DD70-48BF-BD7C-1AE49962F92B}.dat [2010/04/18 18:26:33 | 000,000,069 | ---- | C] () -- D:\WINDOWS\NeroDigital.ini [2010/04/18 18:13:45 | 000,165,376 | ---- | C] () -- D:\WINDOWS\System32\unrar.dll [2010/04/18 18:02:33 | 000,000,095 | ---- | C] () -- D:\WINDOWS\winamp.ini [2010/04/18 17:15:41 | 000,000,182 | ---- | C] () -- D:\WINDOWS\System32\EBPPORT.DAT [2010/04/18 17:15:40 | 000,122,880 | ---- | C] () -- D:\WINDOWS\System32\EEBAPI.dll [2010/04/18 17:15:40 | 000,102,400 | ---- | C] () -- D:\WINDOWS\System32\EEBDSCVR.dll [2010/04/18 17:15:40 | 000,065,536 | ---- | C] () -- D:\WINDOWS\System32\EBAPI.dll [2010/04/18 14:10:25 | 000,000,626 | ---- | C] () -- D:\WINDOWS\ODBC.INI [2010/04/17 20:30:45 | 000,002,048 | --S- | C] () -- D:\WINDOWS\bootstat.dat [2010/04/17 20:28:27 | 000,021,856 | ---- | C] () -- D:\WINDOWS\System32\emptyregdb.dat [2010/04/17 20:23:37 | 000,004,484 | ---- | C] () -- D:\WINDOWS\ODBCINST.INI [2010/04/17 20:22:44 | 000,097,456 | ---- | C] () -- D:\WINDOWS\System32\FNTCACHE.DAT [2010/04/17 19:29:55 | 000,004,981 | ---- | C] () -- D:\WINDOWS\wincmd.ini [2010/04/17 18:11:22 | 000,000,000 | ---- | C] () -- D:\WINDOWS\ativpsrm.bin [2010/01/21 22:47:36 | 013,107,200 | ---- | C] () -- D:\WINDOWS\System32\oembios.bin [2010/01/21 22:47:36 | 000,673,088 | ---- | C] () -- D:\WINDOWS\System32\mlang.dat [2010/01/21 22:47:36 | 000,508,008 | ---- | C] () -- D:\WINDOWS\System32\perfh015.dat [2010/01/21 22:47:36 | 000,448,454 | ---- | C] () -- D:\WINDOWS\System32\perfh009.dat [2010/01/21 22:47:36 | 000,313,828 | ---- | C] () -- D:\WINDOWS\System32\perfi015.dat [2010/01/21 22:47:36 | 000,272,128 | ---- | C] () -- D:\WINDOWS\System32\perfi009.dat [2010/01/21 22:47:36 | 000,218,003 | ---- | C] () -- D:\WINDOWS\System32\dssec.dat [2010/01/21 22:47:36 | 000,151,552 | ---- | C] () -- D:\Documents and Settings\XXX\Dane aplikacji\skype.dat [2010/01/21 22:47:36 | 000,091,686 | ---- | C] () -- D:\WINDOWS\System32\perfc015.dat [2010/01/21 22:47:36 | 000,072,090 | ---- | C] () -- D:\WINDOWS\System32\perfc009.dat [2010/01/21 22:47:36 | 000,046,258 | ---- | C] () -- D:\WINDOWS\System32\mib.bin [2010/01/21 22:47:36 | 000,034,990 | ---- | C] () -- D:\WINDOWS\System32\perfd015.dat [2010/01/21 22:47:36 | 000,028,626 | ---- | C] () -- D:\WINDOWS\System32\perfd009.dat [2010/01/21 22:47:36 | 000,004,569 | ---- | C] () -- D:\WINDOWS\System32\secupd.dat [2010/01/21 22:47:36 | 000,004,463 | ---- | C] () -- D:\WINDOWS\System32\oembios.dat [2010/01/21 22:47:36 | 000,001,804 | ---- | C] () -- D:\WINDOWS\System32\Dcache.bin [1997/09/12 00:00:00 | 001,691,408 | ---- | C] () -- D:\WINDOWS\System32\MSO97V.DLL [1997/09/12 00:00:00 | 000,016,384 | ---- | C] () -- D:\WINDOWS\System32\MSORFS.DLL [1997/04/03 00:00:00 | 000,022,016 | ---- | C] () -- D:\WINDOWS\System32\ODBCSTF.DLL [1997/04/03 00:00:00 | 000,022,016 | ---- | C] () -- D:\WINDOWS\System32\DOCOBJ.DLL [1997/04/03 00:00:00 | 000,012,288 | ---- | C] () -- D:\WINDOWS\System32\HLINKPRX.DLL [color=#E56717]========== LOP Check ==========[/color] [2011/09/07 20:56:40 | 000,000,000 | ---D | M] -- D:\Documents and Settings\LocalService\Dane aplikacji\Softland [2010/04/17 19:45:46 | 000,000,000 | ---D | M] -- D:\Documents and Settings\XXX\Dane aplikacji\Opera [2010/04/17 20:07:18 | 000,000,000 | ---D | M] -- D:\Documents and Settings\XXX\Dane aplikacji\The Bat! [2010/04/18 14:04:42 | 000,000,000 | ---D | M] -- D:\Documents and Settings\XXX\Dane aplikacji\Thinstall [2010/04/18 19:56:54 | 000,000,000 | ---D | M] -- D:\Documents and Settings\XXX\Dane aplikacji\DAEMON Tools Lite [2010/04/18 20:28:58 | 000,000,000 | ---D | M] -- D:\Documents and Settings\XXX\Dane aplikacji\IsolatedStorage [2011/02/06 13:20:26 | 000,000,000 | ---D | M] -- D:\Documents and Settings\XXX\Dane aplikacji\UTORRENT [2011/02/06 22:11:56 | 000,000,000 | ---D | M] -- D:\Documents and Settings\XXX\Dane aplikacji\MyPhoneExplorer [2011/02/06 13:22:46 | 000,000,000 | ---D | M] -- D:\Documents and Settings\XXX\Dane aplikacji\Test Drive Unlimited [2011/04/29 22:25:32 | 000,000,000 | ---D | M] -- D:\Documents and Settings\XXX\Dane aplikacji\Foxit Software [2011/09/07 20:56:40 | 000,000,000 | ---D | M] -- D:\Documents and Settings\XXX\Dane aplikacji\Softland [2011/10/09 14:25:08 | 000,000,000 | ---D | M] -- D:\Documents and Settings\XXX\Dane aplikacji\ImgBurn [2012/11/23 19:35:30 | 000,000,000 | ---D | M] -- D:\Documents and Settings\XXX\Dane aplikacji\systweak [2010/04/18 19:56:50 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite [2010/04/18 20:29:00 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dane aplikacji\PowerQuest [2011/02/06 12:59:00 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dane aplikacji\Doctor Web [2011/02/06 22:06:56 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dane aplikacji\PageshotsPro [2011/02/08 20:14:44 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dane aplikacji\Test Drive Unlimited [2012/10/20 18:25:02 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dane aplikacji\OO Software [2013/06/02 11:40:02 | 000,000,346 | ---- | M] () -- D:\WINDOWS\Tasks\Dr.Web Update.job [2011/02/06 12:59:06 | 000,000,288 | ---- | M] () -- D:\WINDOWS\Tasks\Dr.Web Daily scan.job [color=#E56717]========== Purity Check ==========[/color] < End of report >