OTL logfile created on: 2011-05-13 15:20:01 - Run 1 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Paulina\Moje dokumenty\Programy Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1 022,00 Mb Total Physical Memory | 112,00 Mb Available Physical Memory | 11,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 67,00% Paging File free Paging file location(s): C:\pagefile.sys 3000 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 17,21 Gb Total Space | 2,23 Gb Free Space | 12,94% Space Free | Partition Type: NTFS Drive D: | 51,22 Gb Total Space | 7,65 Gb Free Space | 14,93% Space Free | Partition Type: NTFS Computer Name: INTEL_CENTRINO | User Name: Paulina | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2011-05-13 14:28:07 | 000,151,552 | ---- | M] () -- C:\WINDOWS\Bpulea.exe PRC - [2011-05-13 14:27:44 | 000,274,432 | RHS- | M] () -- C:\Documents and Settings\Paulina\mqxoq.exe PRC - [2011-05-12 17:19:21 | 000,031,744 | ---- | M] (Epcjocdjq Software) -- C:\WINDOWS\Temp\piau\setup.exe PRC - [2011-05-11 23:42:27 | 000,147,968 | ---- | M] () -- C:\Documents and Settings\Paulina\Ustawienia lokalne\Temp\Bn7.exe PRC - [2011-05-11 23:23:39 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Paulina\Moje dokumenty\Programy\OTL.exe PRC - [2011-05-01 12:41:09 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2010-10-06 15:30:42 | 003,540,320 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgui.exe PRC - [2010-08-14 13:35:25 | 002,048,352 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgtray.exe PRC - [2010-07-22 01:24:16 | 012,477,024 | ---- | M] (GG Network S.A.) -- C:\Program Files\Gadu-Gadu 10\gg.exe PRC - [2010-01-19 15:24:16 | 002,499,584 | ---- | M] (Vodafone) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe PRC - [2010-01-19 15:24:08 | 000,009,216 | ---- | M] (Vodafone) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe PRC - [2009-12-29 12:57:16 | 000,761,600 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgscanx.exe PRC - [2009-10-24 03:18:54 | 000,360,224 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe PRC - [2009-10-24 03:18:52 | 000,597,792 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe PRC - [2009-10-14 13:36:56 | 002,793,304 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe PRC - [2009-10-14 13:34:18 | 000,560,472 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe PRC - [2009-10-07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe PRC - [2009-08-15 23:19:06 | 000,693,016 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgcsrvx.exe PRC - [2009-08-15 23:19:06 | 000,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe PRC - [2009-08-15 23:19:01 | 000,595,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgnsx.exe PRC - [2009-08-15 23:18:58 | 000,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe PRC - [2009-08-15 23:18:56 | 000,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe PRC - [2009-06-23 16:46:45 | 000,386,480 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jucheck.exe PRC - [2009-04-07 13:37:06 | 000,237,568 | ---- | M] () -- C:\Program Files\Larousse\Petit Larousse 2010\bin\Hyperappel.exe PRC - [2008-04-14 22:51:18 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007-05-10 11:22:32 | 000,405,504 | ---- | M] (SigmaTel, Inc.) -- C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe PRC - [2006-10-11 12:45:12 | 000,075,304 | ---- | M] (ScanSoft, Inc.) -- C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe PRC - [2006-01-02 17:41:22 | 000,045,056 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe PRC - [2001-10-11 12:11:16 | 000,022,560 | ---- | M] () -- C:\Program Files\Le Robert\Le Petit Robert\PRHYPER.EXE [color=#E56717]========== Modules (SafeList) ==========[/color] MOD - [2011-05-11 23:23:39 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Paulina\Moje dokumenty\Programy\OTL.exe MOD - [2008-04-14 22:29:10 | 001,054,208 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll MOD - [2006-10-04 22:07:12 | 000,144,936 | ---- | M] (ScanSoft, Inc.) -- C:\Program Files\ScanSoft\OmniPageSE4.0\OpHookSE4.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2011-05-12 17:19:21 | 000,031,744 | ---- | M] (Epcjocdjq Software) [Auto | Stopped] -- C:\WINDOWS\TEMP\piau\setup.exe -- (AMService) SRV - [2010-01-19 15:24:08 | 000,009,216 | ---- | M] (Vodafone) [Auto | Running] -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- (VMCService) SRV - [2009-12-13 17:56:40 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2009-10-24 03:18:54 | 000,360,224 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider) SRV - [2009-10-07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv) SRV - [2009-08-15 23:18:58 | 000,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd) SRV - [2009-08-15 23:18:56 | 000,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG8\avgemc.exe -- (avg8emc) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2011-04-18 19:49:50 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd) DRV - [2009-11-04 17:59:38 | 000,113,280 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbnet.sys -- (ewusbnet) DRV - [2009-11-04 17:59:38 | 000,102,528 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard) DRV - [2009-11-04 17:59:38 | 000,100,736 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbfake.sys -- (hwusbfake) DRV - [2009-10-07 10:49:50 | 000,023,832 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvuvcflt.sys -- (FilterService) DRV - [2009-10-07 10:49:38 | 006,756,632 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lvuvc.sys -- (LVUVC) Logitech Webcam 200(UVC) DRV - [2009-10-07 10:47:55 | 000,266,008 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lvrs.sys -- (LVRS) DRV - [2009-10-07 10:46:12 | 000,114,712 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvpopflt.sys -- (lvpopflt) DRV - [2009-10-07 01:46:36 | 000,025,752 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon) DRV - [2009-08-15 23:19:06 | 000,335,240 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avgldx86.sys -- (AvgLdx86) DRV - [2009-08-15 23:19:06 | 000,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\System32\Drivers\avgmfx86.sys -- (AvgMfx86) DRV - [2009-06-23 08:01:06 | 000,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avgtdix.sys -- (AvgTdiX) DRV - [2008-04-14 00:15:36 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\IrBus.sys -- (IrBus) DRV - [2007-05-10 11:24:34 | 001,222,840 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA) DRV - [2007-02-25 07:05:24 | 002,203,520 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NETw4x32.sys -- (NETw4x32) Sterownik karty Intel(R) DRV - [2006-11-15 00:16:24 | 000,032,256 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk) DRV - [2006-11-14 19:42:46 | 000,043,520 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk) DRV - [2006-11-14 17:35:20 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp) DRV - [2006-05-23 22:06:36 | 001,578,496 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag) DRV - [2004-05-26 15:18:18 | 000,044,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.internetvodafone.es IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=14a8ebd00000000000000013029f1e86&tlver=1.4.19.19&affID=17161 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1202660629-963894560-1644491937-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes] IE - HKU\S-1-5-21-1202660629-963894560-1644491937-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mydtzone.com/startpage IE - HKU\S-1-5-21-1202660629-963894560-1644491937-1003\..\URLSearchHook: *{00A6FAF6-072E-44cf-8957-5838F569A31D} - Reg Error: Key error. File not found IE - HKU\S-1-5-21-1202660629-963894560-1644491937-1003\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found IE - HKU\S-1-5-21-1202660629-963894560-1644491937-1003\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll () IE - HKU\S-1-5-21-1202660629-963894560-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1202660629-963894560-1644491937-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultthis.engineName: "Productivity 2.2 Customized Web Search" FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2903601&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.startup.homepage: "https://www.facebook.com" FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: ffxtlbr@babylon.com:1.1.3 FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.3.0.19 FF - prefs.js..extensions.enabledItems: {e84cc2c1-b722-48fc-a39c-edb8b525c777}:3.3.0.19 FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.1.2.0185 FF - prefs.js..keyword.URL: "http://search.babylon.com/?babsrc=SP_ss&mntrId=14a8ebd00000000000000013029f1e86&tlver=1.4.19.19&instlRef=sst&affID=17161&q=" FF - user.js..browser.startup.homepage: "https://www.facebook.com" FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011-05-01 12:41:17 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011-05-01 12:41:17 | 000,000,000 | ---D | M] [2009-06-23 08:04:37 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Paulina\Dane aplikacji\Mozilla\Extensions [2011-05-13 14:42:23 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Paulina\Dane aplikacji\Mozilla\Firefox\Profiles\iggm6a8i.default\extensions [2009-10-25 15:56:15 | 000,000,000 | ---D | M] (BitComet Video Downloader) -- C:\Documents and Settings\Paulina\Dane aplikacji\Mozilla\Firefox\Profiles\iggm6a8i.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB} [2011-01-18 18:14:05 | 000,000,000 | ---D | M] (Productivity 2.2 Community Toolbar) -- C:\Documents and Settings\Paulina\Dane aplikacji\Mozilla\Firefox\Profiles\iggm6a8i.default\extensions\{e84cc2c1-b722-48fc-a39c-edb8b525c777} [2011-04-18 19:50:28 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Documents and Settings\Paulina\Dane aplikacji\Mozilla\Firefox\Profiles\iggm6a8i.default\extensions\DTToolbar@toolbarnet.com [2011-01-18 18:14:06 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\Paulina\Dane aplikacji\Mozilla\Firefox\Profiles\iggm6a8i.default\extensions\engine@conduit.com [2011-03-22 23:15:50 | 000,000,000 | ---D | M] (Babylon) -- C:\Documents and Settings\Paulina\Dane aplikacji\Mozilla\Firefox\Profiles\iggm6a8i.default\extensions\ffxtlbr@babylon.com [2011-01-17 15:45:38 | 000,000,935 | ---- | M] () -- C:\Documents and Settings\Paulina\Dane aplikacji\Mozilla\Firefox\Profiles\iggm6a8i.default\searchplugins\conduit.xml [2011-04-18 19:50:02 | 000,002,059 | ---- | M] () -- C:\Documents and Settings\Paulina\Dane aplikacji\Mozilla\Firefox\Profiles\iggm6a8i.default\searchplugins\daemon-search.xml [2011-05-12 21:28:27 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2010-03-25 11:46:09 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2009-06-23 16:46:45 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009-07-17 10:40:12 | 000,704,512 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll [2010-10-27 07:37:26 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml [2011-03-22 23:15:54 | 000,002,423 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml [2010-10-27 07:37:26 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml [2010-10-27 07:37:26 | 000,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml [2010-10-27 07:37:26 | 000,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml [2010-10-27 07:37:26 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml [2010-10-27 07:37:26 | 000,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml Hosts file not found O2 - BHO: (CescrtHlpr Object) - {2EECD738-5844-4a99-B4B6-146BF802613B} - File not found O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.7.16.dll (BitComet) O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.) O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll () O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll () O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll () O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - File not found O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll () O3 - HKU\S-1-5-21-1202660629-963894560-1644491937-1003\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKU\S-1-5-21-1202660629-963894560-1644491937-1003\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll () O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.) O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [BabylonToolbar] File not found O4 - HKLM..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Languages\PL\Programs\Registration.exe (Corel Corporation) O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe () O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone) O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe (ScanSoft, Inc.) O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation) O4 - HKLM..\Run: [Preeminence CD/DVD Helper] File not found O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.) O4 - HKLM..\Run: [UIUCU] File not found O4 - HKU\S-1-5-21-1202660629-963894560-1644491937-1003..\Run: [5GUTNY6MFK] C:\WINDOWS\Bpulea.exe () O4 - HKU\S-1-5-21-1202660629-963894560-1644491937-1003..\Run: [ALLUpdate] C:\Program Files\ALLPlayer\ALLUpdate.exe () O4 - HKU\S-1-5-21-1202660629-963894560-1644491937-1003..\Run: [ares] File not found O4 - HKU\S-1-5-21-1202660629-963894560-1644491937-1003..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.) O4 - HKU\S-1-5-21-1202660629-963894560-1644491937-1003..\Run: [iGoD] File not found O4 - HKU\S-1-5-21-1202660629-963894560-1644491937-1003..\Run: [Le Petit Robert Hyperappel] C:\Program Files\Le Robert\Le Petit Robert\PRHYPER.EXE () O4 - HKU\S-1-5-21-1202660629-963894560-1644491937-1003..\Run: [mqxoq] C:\Documents and Settings\Paulina\mqxoq.exe () O4 - HKU\S-1-5-21-1202660629-963894560-1644491937-1003..\Run: [R8388QA8U8] File not found O4 - HKU\.DEFAULT..\RunOnce: [nltide_2] File not found O4 - HKU\S-1-5-18..\RunOnce: [nltide_2] File not found O4 - HKU\S-1-5-19..\RunOnce: [nltide_2] File not found O4 - HKU\S-1-5-20..\RunOnce: [nltide_2] File not found O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Hyperappel du Petit Larousse 2010.lnk = C:\Program Files\Larousse\Petit Larousse 2010\bin\Hyperappel.exe () O4 - Startup: C:\Documents and Settings\Paulina\Menu Start\Programy\Autostart\Tchatche Messenger.lnk = File not found O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1202660629-963894560-1644491937-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html () O8 - Extra context menu item: Easy-WebPrint – Dodaj do listy drukowania - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll () O8 - Extra context menu item: Easy-WebPrint – Drukuj - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll () O8 - Extra context menu item: Easy-WebPrint – Drukuj z dużą szybkością - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll () O8 - Extra context menu item: Easy-WebPrint – Podgląd - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll () O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html () O8 - Extra context menu item: Pobierz wszystkie VIdeo za pomocą BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com) O8 - Extra context menu item: Pobierz wszystko za pomocą BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com) O8 - Extra context menu item: Pobierz za pomocą BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com) O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.7.16.dll (BitComet) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 192.168.0.1 O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: TaskMan - (C:\Documents and Settings\Paulina\Dane aplikacji\vfbu.exe) - File not found O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.) O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\Paulina\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Paulina\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009-06-23 00:11:52 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2008-03-22 11:37:21 | 000,000,000 | ---- | M] () - D:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{438d42da-68d2-11df-b463-0015c517e910}\Shell - "" = AutoRun O33 - MountPoints2\{438d42da-68d2-11df-b463-0015c517e910}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL qIueQO.exe O33 - MountPoints2\{57364bf3-c4c1-11df-b4d8-0015c517e910}\Shell\AutoRun\command - "" = H:\PMBP_Win.exe O33 - MountPoints2\{5d851894-fbe4-11de-b345-0015c517e910}\Shell\AutoRun\command - "" = G:\U3ROM/usbdrive.exe O33 - MountPoints2\{5d851894-fbe4-11de-b345-0015c517e910}\Shell\explore\command - "" = G:\U3ROM/usbdrive.exe O33 - MountPoints2\{5d851894-fbe4-11de-b345-0015c517e910}\Shell\open\command - "" = G:\U3ROM/usbdrive.exe O33 - MountPoints2\{6a3e0a78-f243-11de-b32f-0015c517e910}\Shell\AutoRun\command - "" = F:\Autorun.exe O33 - MountPoints2\{6b77a657-d922-11de-b2e5-0015c517e910}\Shell\AutoRun\command - "" = filesystem/pagefile.exe O33 - MountPoints2\{6b77a657-d922-11de-b2e5-0015c517e910}\Shell\eXpLorE\cOMMand - "" = filesystem/pagefile.exe O33 - MountPoints2\{6b77a657-d922-11de-b2e5-0015c517e910}\Shell\oPen\CoMMAnd - "" = filesystem/pagefile.exe O33 - MountPoints2\{a578d182-bdbd-11df-b4cb-0015c517e910}\Shell\AutoRun\command - "" = G:\SoebUa.eXE O33 - MountPoints2\{aa420021-65b4-11df-b45a-0015c517e910}\Shell - "" = AutoRun O33 - MountPoints2\{aa420021-65b4-11df-b45a-0015c517e910}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL LeiojUG.exe O33 - MountPoints2\{b51dd017-90da-11de-b23a-0015c517e910}\Shell\AutoRun\command - "" = p9rs.exe O33 - MountPoints2\{b51dd017-90da-11de-b23a-0015c517e910}\Shell\open\Command - "" = p9rs.exe O33 - MountPoints2\{b98ef91a-e505-11df-b518-0015c517e910}\Shell - "" = AutoRun O33 - MountPoints2\{b98ef91a-e505-11df-b518-0015c517e910}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O33 - MountPoints2\{b98ef91d-e505-11df-b518-0015c517e910}\Shell - "" = AutoRun O33 - MountPoints2\{b98ef91d-e505-11df-b518-0015c517e910}\Shell\AutoRun\command - "" = F:\setup_vmc_lite.exe /checkApplicationPresence O34 - HKLM BootExecute: (autocheck autochk /r \??\G:) - File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs: 6to4 - File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2011-05-12 21:20:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paulina\Dane aplikacji\Ruqife [2011-05-12 21:20:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paulina\Dane aplikacji\Owlam [2011-05-12 17:55:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paulina\Pulpit\certyfikat koncowy [2011-05-12 00:02:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paulina\Pulpit\datosCompra.do_pliki [2011-05-11 18:04:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Dane aplikacji\Macromedia [2011-05-11 18:04:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Dane aplikacji\Adobe [2011-05-11 00:59:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paulina\Pulpit\MURAIL comenius [2011-05-10 17:24:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paulina\Pulpit\PRACA [2011-05-05 21:24:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paulina\Pulpit\TEIDE-reserva-paso_pliki [2011-05-02 19:11:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paulina\Menu Start\Programy\UltraStar [2011-05-02 19:11:20 | 000,000,000 | ---D | C] -- C:\Program Files\UltraStar [2011-05-01 19:25:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paulina\Pulpit\Cris [2011-04-30 19:55:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paulina\Pulpit\habitacion [2011-04-27 20:06:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paulina\Dane aplikacji\Corel [2011-04-27 20:04:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\CorelDRAW Graphics Suite 12 [2011-04-27 20:03:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Corel [2011-04-27 20:01:16 | 000,000,000 | ---D | C] -- C:\Program Files\Corel [2011-04-20 15:40:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paulina\Pulpit\MUZ [2011-04-18 20:52:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paulina\Pulpit\mon essentiel_pliki [2011-04-18 20:02:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paulina\Menu Start\Programy\Leksykonia [2011-04-18 20:02:06 | 000,000,000 | ---D | C] -- C:\Program Files\Leksykonia [2011-04-18 19:50:02 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Toolbar [2011-04-18 19:49:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\DAEMON Tools Lite [2011-04-18 19:49:35 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite [2011-04-18 19:49:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Paulina\Dane aplikacji\DAEMON Tools Lite [2011-04-18 19:49:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2011-05-13 15:39:21 | 000,000,250 | -H-- | M] () -- C:\WINDOWS\tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job [2011-05-13 15:31:24 | 000,000,290 | -H-- | M] () -- C:\WINDOWS\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job [2011-05-13 15:26:01 | 000,000,290 | -H-- | M] () -- C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job [2011-05-13 14:30:35 | 075,703,590 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm [2011-05-13 14:28:07 | 000,151,552 | ---- | M] () -- C:\WINDOWS\Bpulea.exe [2011-05-13 14:27:44 | 000,274,432 | RHS- | M] () -- C:\Documents and Settings\Paulina\mqxoq.exe [2011-05-13 14:24:50 | 000,000,310 | -HS- | M] () -- C:\WINDOWS\tasks\Ytmysnm.job [2011-05-13 14:24:40 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2011-05-13 14:24:03 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\lvuvc.hs [2011-05-13 14:24:01 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\logiflt.iad [2011-05-12 20:52:30 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat [2011-05-12 00:02:55 | 000,071,390 | ---- | M] () -- C:\Documents and Settings\Paulina\Pulpit\datosCompra.do.htm [2011-05-11 23:42:23 | 000,152,064 | ---- | M] () -- C:\WINDOWS\Bpuleb.exe [2011-05-11 17:48:03 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2011-05-07 20:53:48 | 000,070,047 | ---- | M] () -- C:\Documents and Settings\Paulina\Pulpit\p. Robert 2.png [2011-05-07 20:49:51 | 000,363,276 | ---- | M] () -- C:\Documents and Settings\Paulina\Pulpit\Video call snapshot 9.png [2011-05-07 20:49:10 | 000,090,987 | ---- | M] () -- C:\Documents and Settings\Paulina\Pulpit\Video call snapshot 10.png [2011-05-07 20:48:59 | 000,092,022 | ---- | M] () -- C:\Documents and Settings\Paulina\Pulpit\Video call snapshot 12.png [2011-05-06 13:55:31 | 000,075,454 | ---- | M] () -- C:\Documents and Settings\Paulina\Pulpit\zdj Paulina Błaszczyk.JPG [2011-05-05 21:24:26 | 000,018,359 | ---- | M] () -- C:\Documents and Settings\Paulina\Pulpit\TEIDE-reserva-paso.htm [2011-05-02 15:10:43 | 000,026,169 | ---- | M] () -- C:\Documents and Settings\Paulina\Pulpit\PB.JPG [2011-05-01 19:25:34 | 000,026,624 | ---- | M] () -- C:\Documents and Settings\Paulina\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011-04-30 12:37:12 | 001,224,814 | ---- | M] () -- C:\Documents and Settings\Paulina\Pulpit\CALLAO DE LIMA 40.bmp [2011-04-28 17:12:14 | 000,448,586 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2011-04-28 17:12:14 | 000,392,630 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2011-04-28 17:12:14 | 000,074,648 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2011-04-28 17:12:13 | 000,058,930 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2011-04-28 17:11:24 | 001,474,560 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2011-04-24 18:48:20 | 000,000,226 | ---- | M] () -- C:\Documents and Settings\Paulina\Moje dokumenty\NOTEBOOK.DBF [2011-04-24 18:48:20 | 000,000,145 | ---- | M] () -- C:\WINDOWS\PR1V2.INI [2011-04-20 23:18:06 | 000,236,366 | ---- | M] () -- C:\Documents and Settings\Paulina\Moje dokumenty\Nowy-5.jpg [2011-04-20 15:38:03 | 000,149,047 | ---- | M] () -- C:\Documents and Settings\Paulina\Pulpit\tapeta.jpg [2011-04-18 20:52:40 | 000,048,868 | ---- | M] () -- C:\Documents and Settings\Paulina\Pulpit\mon essentiel.htm [2011-04-18 20:02:13 | 000,000,827 | ---- | M] () -- C:\Documents and Settings\Paulina\Pulpit\SystemTL+.lnk [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2011-05-13 14:58:14 | 000,151,552 | ---- | C] () -- C:\WINDOWS\Bpulea.exe [2011-05-13 14:27:44 | 000,274,432 | RHS- | C] () -- C:\Documents and Settings\Paulina\mqxoq.exe [2011-05-12 17:05:28 | 000,152,064 | ---- | C] () -- C:\WINDOWS\Bpuleb.exe [2011-05-12 00:02:50 | 000,071,390 | ---- | C] () -- C:\Documents and Settings\Paulina\Pulpit\datosCompra.do.htm [2011-05-11 18:33:10 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2011-05-11 17:53:30 | 000,000,310 | -HS- | C] () -- C:\WINDOWS\tasks\Ytmysnm.job [2011-05-11 17:53:09 | 000,000,290 | -H-- | C] () -- C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job [2011-05-11 17:53:06 | 000,000,290 | -H-- | C] () -- C:\WINDOWS\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job [2011-05-11 17:52:34 | 000,000,250 | -H-- | C] () -- C:\WINDOWS\tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job [2011-05-07 20:53:48 | 000,070,047 | ---- | C] () -- C:\Documents and Settings\Paulina\Pulpit\p. Robert 2.png [2011-05-07 20:49:00 | 000,363,276 | ---- | C] () -- C:\Documents and Settings\Paulina\Pulpit\Video call snapshot 9.png [2011-05-07 20:48:52 | 000,090,987 | ---- | C] () -- C:\Documents and Settings\Paulina\Pulpit\Video call snapshot 10.png [2011-05-07 20:48:43 | 000,092,022 | ---- | C] () -- C:\Documents and Settings\Paulina\Pulpit\Video call snapshot 12.png [2011-05-06 13:54:30 | 000,075,454 | ---- | C] () -- C:\Documents and Settings\Paulina\Pulpit\zdj Paulina Błaszczyk.JPG [2011-05-05 21:24:23 | 000,018,359 | ---- | C] () -- C:\Documents and Settings\Paulina\Pulpit\TEIDE-reserva-paso.htm [2011-05-02 15:10:40 | 000,026,169 | ---- | C] () -- C:\Documents and Settings\Paulina\Pulpit\PB.JPG [2011-04-30 12:37:11 | 001,224,814 | ---- | C] () -- C:\Documents and Settings\Paulina\Pulpit\CALLAO DE LIMA 40.bmp [2011-04-27 19:47:35 | 095,000,000 | ---- | C] () -- C:\Documents and Settings\Paulina\Moje dokumenty\Corel_12_PL.part1.rar [2011-04-20 23:17:37 | 000,236,366 | ---- | C] () -- C:\Documents and Settings\Paulina\Moje dokumenty\Nowy-5.jpg [2011-04-20 15:37:40 | 000,149,047 | ---- | C] () -- C:\Documents and Settings\Paulina\Pulpit\tapeta.jpg [2011-04-18 20:52:34 | 000,048,868 | ---- | C] () -- C:\Documents and Settings\Paulina\Pulpit\mon essentiel.htm [2011-04-18 20:02:13 | 000,000,827 | ---- | C] () -- C:\Documents and Settings\Paulina\Pulpit\SystemTL+.lnk [2011-03-23 00:02:26 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2011-03-23 00:02:25 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini [2011-03-23 00:02:24 | 000,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2011-03-23 00:02:24 | 000,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2011-03-23 00:02:22 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2010-10-02 23:34:43 | 000,026,624 | ---- | C] () -- C:\Documents and Settings\Paulina\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010-10-01 22:43:00 | 000,082,289 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini [2010-02-24 01:49:12 | 000,000,139 | ---- | C] () -- C:\WINDOWS\Antidote.ini [2010-02-10 20:20:59 | 000,000,072 | ---- | C] () -- C:\WINDOWS\MediaManager.INI [2010-01-18 20:45:17 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Paulina\Dane aplikacji\winscp.rnd [2010-01-11 00:28:36 | 000,154,248 | R--- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\DeviceManager.xml.rc4 [2009-11-16 22:58:11 | 139,757,672 | ---- | C] () -- C:\Program Files\OOo_3.1.1_Win32Intel_install_pl.exe [2009-11-05 16:00:10 | 000,000,518 | ---- | C] () -- C:\WINDOWS\System32\SPC220NC.INI [2009-10-07 01:46:36 | 000,025,752 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys [2009-10-07 01:23:08 | 000,013,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll [2009-09-01 12:27:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Setup.INI [2009-07-05 11:34:22 | 000,000,145 | ---- | C] () -- C:\WINDOWS\PR1V2.INI [2009-06-25 09:44:29 | 000,000,416 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI [2009-06-23 16:48:53 | 000,002,327 | ---- | C] () -- C:\WINDOWS\VPlayer.INI [2009-06-23 12:47:35 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat [2009-06-23 08:04:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat [2009-06-23 01:48:01 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2009-06-23 01:46:30 | 001,474,560 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2009-06-23 00:21:32 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll [2009-06-23 00:15:11 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2009-06-23 00:07:31 | 000,021,856 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2009-06-22 19:14:16 | 000,127,614 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat [2008-04-14 23:16:20 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin [2008-03-22 12:49:07 | 000,086,016 | -H-- | C] () -- C:\WINDOWS\System32\preflib.dll [2008-03-22 12:49:07 | 000,018,944 | -H-- | C] () -- C:\WINDOWS\System32\WLTRYSVC.EXE [2008-03-22 12:49:00 | 000,757,760 | -H-- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll [2006-12-31 07:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat [2004-09-16 14:26:40 | 000,012,634 | ---- | C] () -- C:\WINDOWS\System32\drivers\ADFUUD.SYS [2004-09-16 14:26:40 | 000,012,634 | ---- | C] () -- C:\WINDOWS\ADFUUD.SYS [2003-01-21 02:20:21 | 000,000,140 | -H-- | C] () -- C:\WINDOWS\AJ820503.bin [2001-10-26 18:15:16 | 000,448,586 | ---- | C] () -- C:\WINDOWS\System32\perfh015.dat [2001-10-26 18:15:16 | 000,313,828 | ---- | C] () -- C:\WINDOWS\System32\perfi015.dat [2001-10-26 18:15:16 | 000,074,648 | ---- | C] () -- C:\WINDOWS\System32\perfc015.dat [2001-10-26 18:15:16 | 000,034,990 | ---- | C] () -- C:\WINDOWS\System32\perfd015.dat [2001-08-23 15:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin [2001-08-23 15:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat [2001-08-17 23:30:24 | 000,392,630 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat [2001-08-17 23:30:24 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat [2001-08-17 23:30:24 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat [2001-08-17 23:30:22 | 000,058,930 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat [2001-08-17 23:15:38 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin [2001-07-22 00:36:48 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat [2001-07-22 00:36:04 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat [2001-07-22 00:24:16 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat [color=#E56717]========== LOP Check ==========[/color] [2009-08-26 18:17:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\AVG Security Toolbar [2009-06-25 09:38:58 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\CanonBJ [2011-04-18 19:49:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite [2010-08-28 20:29:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10 [2010-08-28 20:33:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ipla [2010-08-29 19:12:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\OpenFM [2009-06-25 09:44:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ScanSoft [2010-10-31 17:56:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Vodafone [2010-10-31 17:56:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\Vodafone [2010-08-31 18:44:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\aerix [2010-01-29 14:29:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\Apetito.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 [2010-03-25 14:21:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\Audacity [2010-09-27 08:42:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\BabylonToolbar [2009-07-28 17:47:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\Canon [2009-11-22 00:18:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\com.m123.flash.tchatche.messenger.7F3C319CF8CDEE1219096E2B277B950B47049697.1 [2011-04-18 20:10:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\DAEMON Tools Lite [2010-02-24 01:55:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\Druide [2009-10-19 21:12:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\FunWebProducts [2009-06-30 16:16:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\Gadu-Gadu [2010-08-28 20:30:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\Gadu-Gadu 10 [2010-09-01 20:40:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\ipla [2010-10-01 22:44:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\Leadertech [2010-08-29 19:12:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\OpenFM [2009-12-13 17:41:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\OpenOffice.org [2009-06-23 16:58:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\Opera [2011-05-12 22:47:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\Owlam [2011-05-13 15:00:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\Ruqife [2009-06-25 09:44:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\ScanSoft [2010-10-31 17:57:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Paulina\Dane aplikacji\Vodafone [2011-05-13 14:24:50 | 000,000,310 | -HS- | M] () -- C:\WINDOWS\Tasks\Ytmysnm.job [2011-05-13 15:26:01 | 000,000,290 | -H-- | M] () -- C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job [2011-05-13 15:39:21 | 000,000,250 | -H-- | M] () -- C:\WINDOWS\Tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job [2011-05-13 15:31:24 | 000,000,290 | -H-- | M] () -- C:\WINDOWS\Tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Custom Scans ==========[/color] [color=#A23BEC]< C:\*.* >[/color] [2009-06-23 00:11:52 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT [2011-01-10 16:05:28 | 000,000,211 | -HS- | M] () -- C:\boot.ini [2001-07-22 00:13:54 | 000,004,952 | RHS- | M] () -- C:\Bootfont.bin [2009-06-23 00:11:52 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS [2009-06-23 00:11:52 | 000,000,000 | RHS- | M] () -- C:\IO.SYS [2009-06-23 00:11:52 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS [2008-04-13 22:13:04 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM [2008-04-14 00:02:00 | 000,251,152 | RHS- | M] () -- C:\ntldr [2011-05-13 14:24:35 | 3145,728,000 | -HS- | M] () -- C:\pagefile.sys [2010-04-19 20:51:53 | 000,304,160 | ---- | M] () -- C:\SPC220NC.DAT [2003-03-12 14:50:11 | 000,000,140 | -H-- | M] () -- C:\WM800918.bin [color=#A23BEC]< D:\*.* >[/color] [2009-04-02 23:52:57 | 000,000,020 | -H-- | M] () -- D:\Ankieta2.sha [2008-03-22 11:37:21 | 000,000,000 | ---- | M] () -- D:\AUTOEXEC.BAT [2009-04-22 21:36:17 | 000,000,020 | -H-- | M] () -- D:\baner.doc.sha [2009-06-22 18:54:48 | 000,407,625 | ---- | M] () -- D:\bookmarksnajnowsze.html [2008-03-22 11:37:21 | 000,000,000 | ---- | M] () -- D:\CONFIG.SYS [2008-09-08 18:36:54 | 000,000,020 | -H-- | M] () -- D:\Dok1.doc.sha [2008-04-10 08:07:52 | 000,032,768 | ---- | M] () -- D:\Est-il normal d’être filmé.doc [2008-10-12 15:14:02 | 000,000,020 | -H-- | M] () -- D:\fiche_outil_3.pdf.sha [2008-03-22 11:37:21 | 000,000,000 | RHS- | M] () -- D:\IO.SYS [2008-03-22 11:37:21 | 000,000,000 | RHS- | M] () -- D:\MSDOS.SYS [2009-06-22 19:50:51 | 003,072,054 | ---- | M] () -- D:\Nero Sn.bmp [2008-11-02 21:27:27 | 000,000,020 | -H-- | M] () -- D:\rysunki_0013.jpg.sha [2009-02-25 21:33:54 | 000,000,020 | -H-- | M] () -- D:\Zdjęcie205.jpg.sha [2008-07-09 08:20:13 | 000,000,162 | -H-- | M] () -- D:\~$onjour.doc [2009-02-25 19:35:17 | 000,000,162 | -H-- | M] () -- D:\~$ulouse-lautrec.doc [2 D:\*.tmp files -> D:\*.tmp -> ] [color=#A23BEC]< E:\*.* >[/color] [color=#A23BEC]< F:\*.* >[/color] < End of report >