OTL logfile created on: 2013-09-09 12:55:03 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Właściciel\Pulpit Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1022,92 Mb Total Physical Memory | 137,10 Mb Available Physical Memory | 13,40% Memory free 2,40 Gb Paging File | 1,42 Gb Available in Paging File | 58,92% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 29,29 Gb Total Space | 16,59 Gb Free Space | 56,65% Space Free | Partition Type: NTFS Drive D: | 45,23 Gb Total Space | 44,73 Gb Free Space | 98,89% Space Free | Partition Type: NTFS Drive F: | 14,94 Gb Total Space | 13,99 Gb Free Space | 93,66% Space Free | Partition Type: FAT32 Computer Name: TTT-2E93A879B61 | User Name: Właściciel | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2013-09-09 08:44:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Właściciel\Pulpit\OTL.exe PRC - [2013-08-23 09:40:38 | 000,276,376 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2013-04-04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2013-04-04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2013-04-04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe PRC - [2013-03-21 15:19:46 | 001,341,664 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe PRC - [2013-03-21 15:19:40 | 005,078,504 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe PRC - [2013-01-18 14:51:24 | 010,376,704 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe PRC - [2013-01-18 14:51:24 | 010,368,512 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin PRC - [2013-01-18 14:51:24 | 000,103,936 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\scalc.exe PRC - [2008-04-14 19:21:16 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2005-06-20 10:28:42 | 001,780,224 | ---- | M] (KONICA MINOLTA) -- C:\Program Files\LINKMAGIC\LinkMagic.exe PRC - [2004-10-14 10:11:10 | 001,388,544 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe PRC - [2002-09-20 15:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2013-08-23 09:40:34 | 003,551,640 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll MOD - [2013-02-01 14:27:57 | 000,170,496 | ---- | M] () -- C:\Program Files\OpenOffice.org 3\program\libxslt.dll MOD - [2013-02-01 14:27:56 | 000,985,088 | ---- | M] () -- C:\Program Files\OpenOffice.org 3\program\libxml2.dll MOD - [2005-05-24 13:09:54 | 000,126,464 | ---- | M] () -- C:\Program Files\LINKMAGIC\pdf.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt) SRV - [2013-08-23 09:40:35 | 000,117,656 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013-04-04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2013-04-04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) SRV - [2013-03-21 15:19:46 | 001,341,664 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn) SRV - [2002-09-20 15:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\hpfxfax.sys -- (HPFXFAX) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\hpfxbulk.sys -- (HPFXBULK) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2013-04-04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector) DRV - [2013-01-10 09:25:22 | 000,105,784 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir) DRV - [2013-01-10 09:25:20 | 000,161,368 | ---- | M] (ESET) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon) DRV - [2013-01-10 09:25:20 | 000,122,240 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv) DRV - [2007-05-02 10:54:08 | 000,472,224 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211) DRV - [2006-08-29 00:12:00 | 000,990,592 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV) DRV - [2006-08-29 00:11:00 | 000,247,808 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWICH.sys -- (HSFHWICH) DRV - [2006-08-29 00:10:00 | 000,728,576 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf) DRV - [2005-05-25 22:59:12 | 001,133,056 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HTS541080G9AT00_MP28MBXBGY1GYHGY1GYHX&ts=1377174050 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HTS541080G9AT00_MP28MBXBGY1GYHGY1GYHX&ts=1377174050 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HTS541080G9AT00_MP28MBXBGY1GYHGY1GYHX&ts=1377174050 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HTS541080G9AT00_MP28MBXBGY1GYHGY1GYHX&ts=1377174050 IE - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HTS541080G9AT00_MP28MBXBGY1GYHGY1GYHX&ts=1377174050 IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1417001333-746137067-1343024091-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HTS541080G9AT00_MP28MBXBGY1GYHGY1GYHX&ts=1377174050 IE - HKU\S-1-5-21-1417001333-746137067-1343024091-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HTS541080G9AT00_MP28MBXBGY1GYHGY1GYHX&ts=1377174050 IE - HKU\S-1-5-21-1417001333-746137067-1343024091-1003\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86} IE - HKU\S-1-5-21-1417001333-746137067-1343024091-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-1417001333-746137067-1343024091-1003\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HTS541080G9AT00_MP28MBXBGY1GYHGY1GYHX&ts=1377174050 IE - HKU\S-1-5-21-1417001333-746137067-1343024091-1003\..\SearchScopes\{4E8D5F3D-7C39-41FF-AB03-BD3E8FDBEDA5}: "URL" = http://www.google.com/search?hl=pl&q={searchTerms}&rlz=1I7ADFA_plPL416 IE - HKU\S-1-5-21-1417001333-746137067-1343024091-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2013-09-02 08:24:01 | 000,000,000 | ---D | M] [2012-07-26 10:43:21 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Właściciel\Dane aplikacji\Mozilla\Extensions [2013-08-23 09:40:06 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2013-08-23 09:40:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions [2013-08-23 09:40:40 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [color=#E56717]========== Chrome ==========[/color] CHR - homepage: http://www.delta-homes.com/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=HTS541080G9AT00_MP28MBXBGY1GYHGY1GYHX&ts=1377174050 CHR - Extension: Lightning Newtab = C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\0.0.4.1_0\ O1 HOSTS File: ([2006-03-02 14:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O3 - HKU\S-1-5-21-1417001333-746137067-1343024091-1003\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET) O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.) O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\LINKMAGIC.lnk = C:\Program Files\LINKMAGIC\LinkMagic.exe (KONICA MINOLTA) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1417001333-746137067-1343024091-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O16 - DPF: {075B975E-4FFE-4491-9DDA-C8D367ECFE1E} http://192.168.1.21/adm/DDCAlertCfg.cab (AlertCfg Control) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1297577261578 (MUWebControl Class) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O16 - DPF: {D4A5D384-6C53-4F3A-8A4F-5BA0D6A654A9} http://192.168.1.21/img/DDCViewer.cab (Viewer Control) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/4.0.1.0/GarminAxControl_32.CAB (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.20 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3C1B62FE-6659-4E62-9B73-74754698AA42}: DhcpNameServer = 192.168.1.20 O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2011-01-17 17:11:21 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2011-01-19 20:39:01 | 000,000,089 | ---- | M] () - D:\AUTORUN.INF -- [ NTFS ] O32 - AutoRun File - [2012-05-04 15:10:36 | 000,000,016 | -H-- | M] () - F:\AUTORUN.INF -- [ FAT32 ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2013-09-09 11:44:01 | 000,000,000 | ---D | C] -- C:\FRST [2013-09-09 08:44:09 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Właściciel\Pulpit\OTL.exe [2013-09-09 08:42:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Dane aplikacji\Malwarebytes [2013-09-09 08:42:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes' Anti-Malware [2013-09-09 08:42:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes [2013-09-09 08:42:30 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2013-09-09 08:42:29 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2013-09-09 08:41:51 | 001,082,207 | ---- | C] (Farbar) -- C:\Documents and Settings\Właściciel\Pulpit\FRST.exe [2013-09-09 08:37:12 | 010,285,040 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Właściciel\Pulpit\mbam-setup-1.75.0.1300.exe [2013-09-04 09:26:47 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Właściciel\Recent [2013-09-04 09:19:14 | 004,454,952 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\Właściciel\Pulpit\ccsetup405.exe [2013-09-04 08:28:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Pulpit\magazyny skupu stare złe [2013-09-02 09:00:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\ESET [2013-09-02 08:23:43 | 000,000,000 | ---D | C] -- C:\Program Files\ESET [2013-09-02 08:23:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\ESET [2013-09-02 08:23:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\ESET [2013-08-28 08:44:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Pulpit\Stare dane programu Firefox [2013-08-26 15:20:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Właściciel\Pulpit\Kanye West - Yeezus (2013) [2013-08-23 12:11:24 | 000,000,000 | ---D | C] -- C:\FBBM [2013-08-23 12:11:23 | 000,047,104 | ---- | C] (Avision Inc.) -- C:\WINDOWS\System32\SP701A.cpl [2013-08-23 12:11:21 | 000,388,608 | ---- | C] (LEAD Technologies, Inc.) -- C:\WINDOWS\System32\ltkrn12n.dll [2013-08-23 12:11:21 | 000,341,504 | ---- | C] (LEAD Technologies, Inc.) -- C:\WINDOWS\System32\LFCMP12n.DLL [2013-08-23 12:11:21 | 000,258,560 | ---- | C] (LEAD Technologies, Inc.) -- C:\WINDOWS\System32\LTDIS12n.dll [2013-08-23 12:11:21 | 000,207,872 | ---- | C] (LEAD Technologies, Inc.) -- C:\WINDOWS\System32\ltefx12n.dll [2013-08-23 12:11:21 | 000,165,888 | ---- | C] (LEAD Technologies, Inc.) -- C:\WINDOWS\System32\ltimg12n.dll [2013-08-23 12:11:21 | 000,141,824 | ---- | C] (LEAD Technologies, Inc.) -- C:\WINDOWS\System32\lftif12n.dll [2013-08-23 12:11:21 | 000,130,048 | ---- | C] (LEAD Technologies, Inc.) -- C:\WINDOWS\System32\ltfil12n.DLL [2013-08-23 12:11:21 | 000,073,216 | ---- | C] (LEAD Technologies, Inc.) -- C:\WINDOWS\System32\lffax12n.dll [2013-08-23 12:11:21 | 000,035,328 | ---- | C] (LEAD Technologies, Inc.) -- C:\WINDOWS\System32\lttwn12n.dll [2013-08-23 12:11:21 | 000,030,720 | ---- | C] (LEAD Technologies, Inc.) -- C:\WINDOWS\System32\lfbmp12n.dll [2013-08-23 12:11:21 | 000,026,624 | ---- | C] (LEAD Technologies, Inc.) -- C:\WINDOWS\System32\lfpcx12n.dll [2013-08-23 12:11:21 | 000,020,992 | ---- | C] (LEAD Technologies, Inc.) -- C:\WINDOWS\System32\lftga12n.dll [2013-08-23 12:11:21 | 000,020,992 | ---- | C] (LEAD Technologies, Inc.) -- C:\WINDOWS\System32\lfimg12n.dll [2013-08-23 12:11:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\PagePro1380 MF [2013-08-23 12:11:20 | 000,000,000 | ---D | C] -- C:\Program Files\LINKMAGIC [2013-08-23 11:54:04 | 000,000,000 | ---D | C] -- C:\LinkMagic [2013-08-23 11:54:01 | 000,025,088 | ---- | C] (Avision Inc.) -- C:\WINDOWS\rmreg.exe [2013-08-23 09:40:03 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2013-08-23 09:07:16 | 004,429,440 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\Właściciel\Pulpit\ccsetup404.exe [2013-08-22 14:20:16 | 000,773,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr100.dll [2013-08-22 14:20:16 | 000,421,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp100.dll [2013-08-22 14:20:14 | 000,000,000 | ---D | C] -- C:\Program Files\WinZipper [2013-08-22 09:22:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MRT [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2013-09-09 12:19:13 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2013-09-09 11:13:14 | 000,377,856 | ---- | M] () -- C:\Documents and Settings\Właściciel\Pulpit\2mirw7n9.exe [2013-09-09 08:44:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Właściciel\Pulpit\OTL.exe [2013-09-09 08:42:33 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk [2013-09-09 08:41:56 | 001,082,207 | ---- | M] (Farbar) -- C:\Documents and Settings\Właściciel\Pulpit\FRST.exe [2013-09-09 08:39:15 | 010,285,040 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Właściciel\Pulpit\mbam-setup-1.75.0.1300.exe [2013-09-09 08:02:11 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2013-09-05 16:08:01 | 000,002,067 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk [2013-09-04 09:26:21 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\CCleaner.lnk [2013-09-04 09:19:27 | 004,454,952 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Właściciel\Pulpit\ccsetup405.exe [2013-08-30 08:00:32 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe [2013-08-30 08:00:31 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl [2013-08-29 14:21:09 | 000,028,707 | ---- | M] () -- C:\Documents and Settings\Właściciel\Pulpit\Dagma_pro_forma_100162188.pdf [2013-08-28 09:01:20 | 000,000,454 | ---- | M] () -- C:\WINDOWS\System32\SP701ASM.dat [2013-08-26 15:19:24 | 097,197,557 | ---- | M] () -- C:\Documents and Settings\Właściciel\Pulpit\Kanye West - Yeezus (2013).rar [2013-08-26 08:07:37 | 000,356,952 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2013-08-23 12:16:58 | 000,000,482 | ---- | M] () -- C:\tmp.tif [2013-08-23 12:11:24 | 000,000,071 | ---- | M] () -- C:\WINDOWS\install.ini [2013-08-23 12:11:20 | 000,000,473 | ---- | M] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\LINKMAGIC.lnk [2013-08-23 12:11:20 | 000,000,461 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\LINKMAGIC.lnk [2013-08-23 09:13:09 | 000,000,324 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2013-08-23 09:07:32 | 004,429,440 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Właściciel\Pulpit\ccsetup404.exe [2013-08-22 14:20:54 | 000,000,978 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Mozilla Firefox.lnk [2013-08-22 14:20:13 | 000,773,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr100.dll [2013-08-22 14:20:13 | 000,421,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp100.dll [2013-08-22 13:23:29 | 000,212,073 | ---- | M] () -- C:\Documents and Settings\Właściciel\Pulpit\magazyn Bez tytułu 1.ods [2013-08-22 09:17:07 | 000,536,398 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2013-08-22 09:17:07 | 000,476,162 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2013-08-22 09:17:07 | 000,095,680 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2013-08-22 09:17:07 | 000,077,196 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2013-09-09 11:13:10 | 000,377,856 | ---- | C] () -- C:\Documents and Settings\Właściciel\Pulpit\2mirw7n9.exe [2013-09-09 08:42:33 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk [2013-08-29 14:21:07 | 000,028,707 | ---- | C] () -- C:\Documents and Settings\Właściciel\Pulpit\Dagma_pro_forma_100162188.pdf [2013-08-26 15:07:09 | 097,197,557 | ---- | C] () -- C:\Documents and Settings\Właściciel\Pulpit\Kanye West - Yeezus (2013).rar [2013-08-23 12:16:58 | 000,000,482 | ---- | C] () -- C:\tmp.tif [2013-08-23 12:11:22 | 000,000,764 | ---- | C] () -- C:\WINDOWS\Cm3.ini [2013-08-23 12:11:20 | 000,000,473 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\LINKMAGIC.lnk [2013-08-23 12:11:20 | 000,000,461 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\LINKMAGIC.lnk [2013-08-23 11:54:31 | 000,000,454 | ---- | C] () -- C:\WINDOWS\System32\SP701ASM.dat [2013-08-23 11:54:04 | 000,000,071 | ---- | C] () -- C:\WINDOWS\install.ini [2013-08-23 11:54:02 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\SP701ALM.dll [2013-08-23 11:54:02 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\SP701ASM.exe [2013-08-23 11:54:01 | 000,024,576 | ---- | C] () -- C:\WINDOWS\rmdrv98.exe [2013-08-23 11:54:01 | 000,024,576 | ---- | C] () -- C:\WINDOWS\rmdrv2k.exe [2013-08-22 13:23:26 | 000,212,073 | ---- | C] () -- C:\Documents and Settings\Właściciel\Pulpit\magazyn Bez tytułu 1.ods [2013-07-09 12:48:52 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys.sum [2013-07-09 12:48:52 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswSP.sys.sum [2013-07-09 12:48:52 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswSnx.sys.sum [2013-02-01 12:43:30 | 000,005,120 | ---- | C] () -- C:\Documents and Settings\Właściciel\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-05-11 10:15:00 | 000,038,481 | ---- | C] () -- C:\Documents and Settings\Właściciel\Dane aplikacji\Wartości rozdzielane przecinkiem (Windows).ADR [2012-04-09 23:02:46 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2012-02-15 20:32:27 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2011-02-11 06:57:25 | 000,885,222 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-S-1-5-21-1417001333-746137067-1343024091-1003-0.dat [2011-02-10 15:22:21 | 000,340,566 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-System.dat [2011-02-02 22:01:44 | 000,000,384 | ---- | C] () -- C:\Documents and Settings\Właściciel\intlname.ols [color=#E56717]========== ZeroAccess Check ==========[/color] [2011-02-12 22:01:50 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2008-04-14 19:20:47 | 001,499,136 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009-02-09 12:53:44 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008-04-14 19:20:57 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2013-07-09 12:46:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\AVAST Software [2013-09-02 08:21:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\eSafe [2013-09-02 08:23:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ESET [2012-04-11 17:33:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Garmin [2013-07-26 10:58:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\eIntaller [2012-04-11 17:33:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\GARMIN [2011-02-17 11:39:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\GHISLER [2011-02-23 05:14:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Właściciel\Dane aplikacji\OpenOffice.org [color=#E56717]========== Purity Check ==========[/color] < End of report >