OTL logfile created on: 2011-12-03 11:26:39 - Run 6 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\x\Desktop\tools Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 7.0.6002.18005) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,96 Gb Total Physical Memory | 1,09 Gb Available Physical Memory | 55,36% Memory free 4,16 Gb Paging File | 3,05 Gb Available in Paging File | 73,45% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 137,82 Gb Total Space | 65,95 Gb Free Space | 47,85% Space Free | Partition Type: NTFS Drive Q: | 9,77 Gb Total Space | 3,73 Gb Free Space | 38,18% Space Free | Partition Type: NTFS Drive S: | 1,46 Gb Total Space | 0,65 Gb Free Space | 44,46% Space Free | Partition Type: NTFS Computer Name: X-PC | User Name: x | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2011-11-22 13:22:40 | 000,644,408 | ---- | M] (Lenovo Group Limited) -- c:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe PRC - [2011-11-22 13:20:58 | 000,112,152 | ---- | M] (InterVideo) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe PRC - [2011-11-22 13:18:50 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe PRC - [2011-10-16 14:22:40 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\x\Desktop\tools\OTL.exe PRC - [2011-10-04 03:04:00 | 000,486,464 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\ThinkPad\Utilities\PWMUIAux.EXE PRC - [2011-10-04 03:04:00 | 000,292,200 | ---- | M] (Lenovo.) -- C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE PRC - [2011-10-04 03:04:00 | 000,089,152 | ---- | M] (Lenovo) -- C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe PRC - [2011-10-04 03:04:00 | 000,064,576 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\ThinkPad\Utilities\SCHTASK.EXE PRC - [2011-03-25 16:25:42 | 002,852,128 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe PRC - [2011-03-25 16:25:42 | 000,840,992 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe PRC - [2011-03-25 16:25:42 | 000,660,768 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe PRC - [2010-02-04 17:20:20 | 000,214,672 | ---- | M] (PacketVideo) -- C:\Program Files\TwonkyMedia\twonkymediaserverconfig.exe PRC - [2009-04-11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2008-08-07 12:23:26 | 000,148,768 | ---- | M] (Lenovo) -- C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe PRC - [2008-08-07 12:23:22 | 000,431,392 | ---- | M] (Lenovo) -- C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe PRC - [2008-07-30 20:00:00 | 000,060,192 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\NPDIRECT\tpfnf7sp.exe PRC - [2008-07-21 04:19:50 | 002,701,880 | ---- | M] (Conexant) -- C:\Program Files\CONEXANT\SmartAudio\SmAudio.exe PRC - [2008-05-24 16:24:00 | 001,032,192 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Rescue and Recovery\rnr_gui.exe PRC - [2008-03-11 05:33:02 | 000,054,560 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe PRC - [2007-04-26 18:10:00 | 000,120,368 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\LenovoCare\LPMGR.EXE PRC - [2007-03-13 09:05:00 | 001,116,920 | ---- | M] (Roxio) -- C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe PRC - [1999-12-08 14:10:00 | 000,282,624 | ---- | M] (Palm Computing, Inc.) -- C:\Palm\HOTSYNC.EXE [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2011-12-03 09:38:14 | 000,158,208 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PWMUIAux\402474c688f7059f4bad43785631715b\PWMUIAux.ni.exe MOD - [2011-12-03 09:38:11 | 000,882,688 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PWMUICtl\873dac04a09bdd515f4f33d4b0bb895b\PWMUICtl.ni.dll MOD - [2011-10-16 15:06:50 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1363115565fff5a641243a48f396f107\System.Windows.Forms.ni.dll MOD - [2011-10-16 15:06:29 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\367c4043efc2f32d843cb588b0dc97fc\System.Drawing.ni.dll MOD - [2011-10-16 15:05:39 | 000,539,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\bd47a61dc232cd6a0feea1b30ffa2499\PresentationFramework.Luna.ni.dll MOD - [2011-10-16 15:05:37 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\231b0b42eff55de5c7d7debe555c16b7\PresentationFramework.Aero.ni.dll MOD - [2011-10-16 15:05:35 | 014,328,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\94f892556ec9fa7a508fc9d214ceaedf\PresentationFramework.ni.dll MOD - [2011-10-16 15:04:42 | 012,216,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\53f949f4664bb316f9b7a00d73a6e290\PresentationCore.ni.dll MOD - [2011-10-16 15:04:14 | 003,325,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\fd2c727bcef2e019eb96c1145f423701\WindowsBase.ni.dll MOD - [2011-10-16 15:04:06 | 007,950,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll MOD - [2011-10-16 15:03:21 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll MOD - [2011-10-04 03:04:00 | 000,081,920 | ---- | M] () -- C:\Program Files\ThinkPad\Utilities\US\PWMROV.DLL MOD - [2011-10-04 03:04:00 | 000,044,544 | ---- | M] () -- C:\Program Files\ThinkPad\Utilities\US\PWMRT32V.DLL MOD - [2011-09-27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2011-09-27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2011-03-25 16:25:58 | 000,148,768 | ---- | M] () -- C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll MOD - [2008-09-28 18:18:32 | 000,139,264 | ---- | M] () -- c:\Program Files\Common Files\Lenovo\CDRecord.dll MOD - [2007-06-18 16:28:44 | 000,056,056 | ---- | M] () -- C:\Windows\System32\DLAAPI_W.DLL [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [Auto | Stopped] -- -- (TwonkyMedia) SRV - File not found [Auto | Stopped] -- -- (TVT Scheduler) SRV - File not found [Auto | Stopped] -- -- (TVT Backup Service) SRV - File not found [Auto | Stopped] -- -- (TVT Backup Protection Service) SRV - File not found [Auto | Stopped] -- -- (TPHKSVC) SRV - File not found [Auto | Stopped] -- -- (SUService) SRV - File not found [Disabled | Stopped] -- -- (SessionLauncher) SRV - File not found [On_Demand | Stopped] -- -- (ServiceLayer) SRV - File not found [Auto | Stopped] -- -- (RegSrvc) SRV - File not found [Auto | Stopped] -- -- (PMSveH) SRV - File not found [Auto | Stopped] -- -- (FNF5SVC) SRV - File not found [Auto | Stopped] -- -- (EvtEng) SRV - File not found [Auto | Stopped] -- -- (AcPrfMgrSvc) SRV - [2011-11-22 13:22:40 | 000,644,408 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- c:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe -- (ThinkVantage Registry Monitor Service) SRV - [2011-11-22 13:20:58 | 000,112,152 | ---- | M] (InterVideo) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr) SRV - [2011-11-22 13:18:50 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc) SRV - [2011-11-22 13:18:07 | 000,558,368 | ---- | M] (Lenovo) [Auto | Stopped] -- C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe -- (AcSvc) SRV - [2011-10-04 03:04:00 | 000,292,200 | ---- | M] (Lenovo.) [Auto | Running] -- C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE -- (DozeSvc) SRV - [2011-10-04 03:04:00 | 000,175,168 | ---- | M] (Lenovo Group Limited) [Auto | Stopped] -- C:\Program Files\ThinkPad\Utilities\PWMEWSVC.exe -- (PwmEWSvc) SRV - [2011-10-04 03:04:00 | 000,089,152 | ---- | M] (Lenovo) [Auto | Running] -- C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE -- (Power Manager DBC Service) SRV - [2011-03-25 16:25:42 | 000,660,768 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins) SRV - [2008-05-24 15:28:20 | 000,253,952 | ---- | M] (Lenovo Group Limited) [Auto | Stopped] -- C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe -- (TVT_UpdateMonitor) SRV - [2008-04-25 08:18:10 | 000,362,992 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe -- (Roxio Upnp Server 10) SRV - [2008-04-25 08:18:02 | 000,313,840 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe -- (Roxio UPnP Renderer 10) SRV - [2008-04-25 08:16:04 | 000,309,744 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe -- (RoxLiveShare10) SRV - [2008-04-25 08:15:58 | 000,166,384 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe -- (RoxWatch10) SRV - [2008-04-25 08:15:24 | 001,120,752 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe -- (RoxMediaDB10) SRV - [2008-01-21 03:33:00 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2011-11-24 22:07:14 | 000,007,168 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ute5nzyy.sys -- (ute5nzyy) DRV - [2011-10-04 03:04:00 | 000,025,968 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\System32\DRIVERS\DozeHDD.sys -- (DozeHDD) DRV - [2011-10-04 03:04:00 | 000,013,424 | ---- | M] (Lenovo Group Limited) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\TPPWR32V.SYS -- (TPPWRIF) DRV - [2009-02-25 05:34:23 | 000,038,784 | ---- | M] (Axesstel) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Axtmvprt.sys -- (Axtmvprt) DRV - [2009-02-25 05:34:12 | 000,040,064 | ---- | M] (Axesstel) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Axtmvmdm.sys -- (Axtmvmdm) DRV - [2009-02-25 05:33:58 | 000,003,456 | ---- | M] (Axesstel) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Axtmvflt.sys -- (Axtmvflt) DRV - [2008-12-13 11:28:31 | 000,030,144 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\psadd.sys -- (psadd) DRV - [2008-08-20 15:55:34 | 000,025,896 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\LPCFilter.sys -- (LPCFilter) DRV - [2008-08-07 10:01:44 | 000,097,536 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\jmcr.sys -- (JMCR) DRV - [2008-06-30 19:26:46 | 000,974,336 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vm331avs.sys -- (vm331avs) DRV - [2008-06-29 22:52:26 | 000,112,128 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\IntcHdmi.sys -- (IntcHdmiAddService) Intel(R) DRV - [2008-05-24 15:28:22 | 000,048,192 | ---- | M] (Lenovo) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\tvtumon.sys -- (tvtumon) DRV - [2008-05-21 16:35:24 | 000,220,160 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService) DRV - [2008-05-12 10:04:04 | 000,013,480 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\System32\drivers\smiif32.sys -- (lenovo.smi) DRV - [2008-04-28 06:29:26 | 003,658,752 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5v32.sys -- (NETw5v32) Sterownik karty Intel(R) DRV - [2008-04-18 16:40:24 | 000,128,104 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\WimFltr.sys -- (WimFltr) DRV - [2008-03-14 14:23:12 | 000,169,008 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService) DRV - [2008-02-22 15:54:40 | 000,037,312 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tvti2c.sys -- (TVTI2C) DRV - [2008-01-21 08:56:22 | 000,028,224 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PCAMp50.sys -- (PCAMp50) DRV - [2008-01-21 08:56:22 | 000,027,072 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PCASp50.sys -- (PCASp50) DRV - [2008-01-21 03:32:52 | 000,045,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tpm.sys -- (TPM) DRV - [2008-01-21 03:32:51 | 000,220,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express) Intel(R) DRV - [2008-01-21 03:32:47 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice) DRV - [2007-11-29 10:39:52 | 000,008,064 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt) DRV - [2007-11-29 10:39:42 | 000,016,896 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd) DRV - [2007-11-29 10:39:42 | 000,008,064 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev) DRV - [2007-11-29 10:39:40 | 000,019,328 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc) DRV - [2007-10-18 08:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio) DRV - [2007-09-17 15:53:26 | 000,021,632 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd) DRV - [2007-08-08 12:07:42 | 000,101,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard) DRV - [2007-06-18 16:29:56 | 000,009,400 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\Windows\System32\DLA\DLADResM.SYS -- (DLADResM) DRV - [2007-06-18 16:29:10 | 000,035,064 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\Windows\System32\DLA\DLABMFSM.SYS -- (DLABMFSM) DRV - [2007-06-18 16:29:08 | 000,093,752 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\Windows\System32\DLA\DLAUDFAM.SYS -- (DLAUDFAM) DRV - [2007-06-18 16:29:06 | 000,098,136 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\Windows\System32\DLA\DLAUDF_M.SYS -- (DLAUDF_M) DRV - [2007-06-18 16:29:04 | 000,026,744 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\Windows\System32\DLA\DLAOPIOM.SYS -- (DLAOPIOM) DRV - [2007-06-18 16:28:58 | 000,032,472 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\Windows\System32\DLA\DLABOIOM.SYS -- (DLABOIOM) DRV - [2007-06-18 16:28:54 | 000,014,520 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\Windows\System32\DLA\DLAPoolM.SYS -- (DLAPoolM) DRV - [2007-06-18 16:28:52 | 000,105,048 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\Windows\System32\DLA\DLAIFS_M.SYS -- (DLAIFS_M) DRV - [2007-02-08 20:05:30 | 000,028,120 | ---- | M] (Roxio) [File_System | System | Running] -- C:\Windows\System32\drivers\DLARTL_M.SYS -- (DLARTL_M) DRV - [2007-02-08 20:05:30 | 000,012,856 | ---- | M] (Roxio) [File_System | System | Running] -- C:\Windows\System32\drivers\DLACDBHM.SYS -- (DLACDBHM) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2432683531-2990122382-1468029114-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/welcome/3000notebook [binary data] IE - HKU\S-1-5-21-2432683531-2990122382-1468029114-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ IE - HKU\S-1-5-21-2432683531-2990122382-1468029114-1003\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-2432683531-2990122382-1468029114-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2432683531-2990122382-1468029114-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files\VistaCodecPack\rm\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011-06-23 14:01:13 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011-07-20 06:41:36 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011-07-20 06:41:52 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011-06-23 14:01:13 | 000,000,000 | ---D | M] O1 HOSTS File: ([2011-11-22 13:28:14 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo) O4 - HKLM..\Run: [ACWlIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo) O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [CameraApplicationLauncher] C:\Program Files\Lenovo\Camera Center\bin\CameraApplicationLaunchPadLauncher.exe () O4 - HKLM..\Run: [LPManager] C:\Program Files\Lenovo\LenovoCare\LPMGR.EXE (Lenovo Group Limited) O4 - HKLM..\Run: [PMHandler] C:\Program Files\Lenovo\PM Driver\PMHandler.exe (Lenovo) O4 - HKLM..\Run: [PWMTRV] C:\Program Files\ThinkPad\Utilities\PWMTR32V.DLL (Lenovo Group Limited) O4 - HKLM..\Run: [RoxioDragToDisc] C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe (Roxio) O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe (Sonic Solutions) O4 - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SMARTAUDIO\SMAUDIO.EXE (Conexant) O4 - HKLM..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe () O4 - HKLM..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe (Lenovo Group Limited) O4 - HKLM..\Run: [TPWAUDAP] C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe (Lenovo Group Limited) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present O7 - HKU\S-1-5-21-2432683531-2990122382-1468029114-1003\Software\Policies\Microsoft\Internet Explorer\control panel present O7 - HKU\S-1-5-21-2432683531-2990122382-1468029114-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8 - Extra context menu item: Wyślij obraz do urządzenia &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O8 - Extra context menu item: Wyślij stronę do urządzenia &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.) O9 - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (MksSkanerOnline Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07) O16 - DPF: {92ECE6FA-AC2E-4042-BFAE-0C8608E52A43} https://www.bph.pl/sezam/components/SignActivX.cab (SignActivX Control) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 95.160.170.92 88.156.222.92 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F7AEF555-65B1-432B-A129-577EF5E2E975}: DhcpNameServer = 95.160.170.92 88.156.222.92 O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\x\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta z Galerii fotografii systemu Windows.jpg O24 - Desktop BackupWallPaper: C:\Users\x\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta z Galerii fotografii systemu Windows.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006-09-18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2011-12-03 11:08:26 | 000,000,000 | ---D | C] -- C:\Users\x\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Urządzenia interfejsu Bluetooth [2011-12-03 11:08:17 | 000,000,000 | ---D | C] -- C:\Users\x\Documents\Folder wymiany interfejsu Bluetooth [2011-12-03 11:08:17 | 000,000,000 | ---D | C] -- C:\Users\x\AppData\Local\Broadcom [2011-12-03 11:00:43 | 000,020,008 | ---- | C] (Broadcom Corporation.) -- C:\Windows\System32\btwcoins.dll [2011-12-03 10:58:47 | 000,000,000 | ---D | C] -- C:\Program Files\WIDCOMM [2011-12-03 10:55:08 | 003,673,544 | ---- | C] (Broadcom Corporation.) -- C:\Users\x\Desktop\SetupBtwDownloadSE.exe [2011-12-03 10:23:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Symantec [2011-12-03 10:13:40 | 000,000,000 | ---D | C] -- C:\Users\x\AppData\Roaming\PwrMgr [2011-12-03 09:59:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2011-12-03 09:58:06 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes [2011-12-03 09:37:40 | 000,527,424 | ---- | C] (Lenovo Group Limited) -- C:\Windows\PWMBTHLV.EXE [2011-12-03 09:37:39 | 000,834,624 | ---- | C] (Lenovo Group Limited) -- C:\Windows\System32\PWMCP32V.cpl [2011-12-03 09:37:39 | 000,025,968 | ---- | C] (Lenovo.) -- C:\Windows\System32\drivers\DOZEHDD.SYS [2011-12-03 09:37:39 | 000,013,424 | ---- | C] (Lenovo Group Limited) -- C:\Windows\System32\drivers\TPPWR32V.SYS [2011-12-03 09:08:56 | 000,000,000 | ---D | C] -- C:\ProgramData\PCDr [2011-12-03 09:08:56 | 000,000,000 | ---D | C] -- C:\ProgramData\PC-Doctor for Windows [2011-12-03 09:08:52 | 000,000,000 | ---D | C] -- C:\Program Files\PC-Doctor [2011-12-03 09:00:56 | 000,000,000 | ---D | C] -- C:\Users\x\AppData\Roaming\Update [2011-12-02 17:56:46 | 000,000,000 | ---D | C] -- C:\Windows\Hewlett-Packard [2011-11-30 10:27:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hewlett-Packard Company [2011-11-30 10:27:38 | 000,000,000 | ---D | C] -- C:\DriveKey [2011-11-30 10:27:38 | 000,000,000 | ---D | C] -- \DriveKey [2011-11-29 17:35:18 | 000,000,000 | ---D | C] -- C:\USBXP [2011-11-29 17:35:18 | 000,000,000 | ---D | C] -- \USBXP [2011-11-24 21:53:51 | 000,000,000 | -H-D | C] -- C:\Windows\PIF [2011-11-24 21:52:58 | 000,000,000 | ---D | C] -- C:\Users\x\AppData\Local\GHISLER [2011-11-24 21:50:56 | 000,000,000 | ---D | C] -- C:\totalcmd [2011-11-24 21:50:56 | 000,000,000 | ---D | C] -- \totalcmd [2011-11-24 21:50:56 | 000,000,000 | ---D | C] -- C:\Users\x\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander [2011-11-24 21:50:56 | 000,000,000 | ---D | C] -- C:\Users\x\AppData\Roaming\GHISLER [2011-11-24 15:51:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab [2011-11-24 15:49:15 | 000,000,000 | ---D | C] -- C:\Users\x\Desktop\minidump [2011-11-23 15:01:09 | 000,000,000 | ---D | C] -- C:\Users\x\Desktop\tools [2011-11-23 10:09:13 | 000,000,000 | ---D | C] -- C:\Users\x\AppData\Roaming\PCDr [2011-11-22 13:28:22 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN [2011-11-22 13:28:22 | 000,000,000 | ---D | C] -- \$RECYCLE.BIN [2011-11-22 13:24:48 | 000,000,000 | ---D | C] -- C:\Windows\temp [2011-11-22 13:24:48 | 000,000,000 | ---D | C] -- C:\Users\x\AppData\Local\temp [2011-11-22 13:05:36 | 000,000,000 | ---D | C] -- C:\ComboFix [2011-11-22 13:05:36 | 000,000,000 | ---D | C] -- \ComboFix [2011-11-22 12:40:21 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe [2011-11-22 12:40:21 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe [2011-11-22 12:40:15 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT [2011-11-22 12:40:12 | 000,000,000 | ---D | C] -- C:\Qoobox [2011-11-22 12:40:12 | 000,000,000 | ---D | C] -- \Qoobox [2011-11-06 14:21:05 | 000,101,720 | ---- | C] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys [2011-11-03 14:02:26 | 000,000,000 | ---D | C] -- C:\Users\x\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyNoMore [2011-11-03 14:02:26 | 000,000,000 | ---D | C] -- C:\Program Files\SpyNoMore [2011-11-03 12:55:36 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft [2011-11-03 12:55:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft [2011-11-03 12:24:56 | 000,000,000 | ---D | C] -- C:\Users\x\AppData\Roaming\GetRightToGo [2011-11-03 12:05:57 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\iS3 [2010-08-25 18:59:08 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll [2008-12-13 10:59:14 | 000,131,072 | ---- | C] ( ) -- C:\Windows\vm331Rmv.exe [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2011-12-03 11:08:27 | 000,001,082 | ---- | M] () -- C:\Users\x\Desktop\Nokia N70.lnk [2011-12-03 11:08:27 | 000,001,082 | ---- | M] () -- C:\Users\x\Desktop\MJ.lnk [2011-12-03 11:08:27 | 000,001,082 | ---- | M] () -- C:\Users\x\Desktop\Leszek.lnk [2011-12-03 11:05:49 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2011-12-03 11:05:49 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2011-12-03 11:05:39 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011-12-03 11:05:36 | 2106,134,528 | -HS- | M] () -- C:\hiberfil.sys [2011-12-03 11:04:40 | 000,003,204 | ---- | M] () -- C:\Windows\bthservsdp.dat [2011-12-03 11:02:55 | 000,000,954 | ---- | M] () -- C:\Users\Public\Desktop\Bluetooth Problem Report.lnk [2011-12-03 11:02:55 | 000,000,741 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2011-12-03 10:57:44 | 000,020,008 | ---- | M] (Broadcom Corporation.) -- C:\Windows\System32\btwcoins.dll [2011-12-03 10:55:08 | 003,673,544 | ---- | M] (Broadcom Corporation.) -- C:\Users\x\Desktop\SetupBtwDownloadSE.exe [2011-12-03 10:17:15 | 000,010,652 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.CAT [2011-12-03 10:17:15 | 000,000,806 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.INF [2011-12-03 10:09:21 | 000,000,528 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job [2011-12-03 10:09:21 | 000,000,466 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job [2011-12-03 09:59:12 | 000,001,674 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk [2011-12-03 09:58:24 | 000,000,393 | ---- | M] () -- C:\Users\Public\Documents\BluetoothLog.html [2011-12-02 17:51:42 | 000,722,196 | ---- | M] () -- C:\Windows\System32\perfh015.dat [2011-12-02 17:51:42 | 000,645,608 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2011-12-02 17:51:42 | 000,149,294 | ---- | M] () -- C:\Windows\System32\perfc015.dat [2011-12-02 17:51:42 | 000,122,436 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2011-12-02 17:04:45 | 221,898,062 | ---- | M] () -- C:\Windows\MEMORY.DMP [2011-11-28 14:14:34 | 000,160,256 | ---- | M] () -- C:\Users\x\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011-11-24 22:07:14 | 000,007,168 | ---- | M] () -- C:\Windows\System32\drivers\ute5nzyy.sys [2011-11-24 21:50:57 | 000,000,594 | ---- | M] () -- C:\Users\x\Desktop\Total Commander.lnk [2011-11-23 11:26:18 | 000,001,356 | ---- | M] () -- C:\Users\x\AppData\Local\d3d9caps.dat [2011-11-22 13:28:14 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts [2011-11-22 11:46:42 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS [2011-11-22 11:46:42 | 000,000,000 | RHS- | M] () -- C:\IO.SYS [2011-11-16 19:06:19 | 000,001,732 | ---- | M] () -- C:\tvtpktfilter.dat [2011-11-06 14:21:05 | 000,101,720 | ---- | M] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys [2011-11-03 15:15:43 | 000,416,624 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2011-11-03 12:29:59 | 000,001,152 | ---- | M] () -- C:\Windows\System32\windrv.sys [color=#E56717]========== Files Created - No Company Name ==========[/color] [2011-12-03 11:08:27 | 000,001,082 | ---- | C] () -- C:\Users\x\Desktop\Nokia N70.lnk [2011-12-03 11:08:27 | 000,001,082 | ---- | C] () -- C:\Users\x\Desktop\MJ.lnk [2011-12-03 11:08:27 | 000,001,082 | ---- | C] () -- C:\Users\x\Desktop\Leszek.lnk [2011-12-03 11:02:55 | 000,000,966 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bluetooth Problem Report.lnk [2011-12-03 11:02:55 | 000,000,954 | ---- | C] () -- C:\Users\Public\Desktop\Bluetooth Problem Report.lnk [2011-12-03 10:58:52 | 000,000,741 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2011-12-03 10:02:50 | 000,010,652 | ---- | C] () -- C:\Windows\System32\drivers\SYMEVENT.CAT [2011-12-03 10:02:50 | 000,000,806 | ---- | C] () -- C:\Windows\System32\drivers\SYMEVENT.INF [2011-12-03 09:59:12 | 000,001,674 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk [2011-12-03 09:09:35 | 000,000,528 | ---- | C] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job [2011-12-03 09:09:33 | 000,000,466 | ---- | C] () -- C:\Windows\tasks\SystemToolsDailyTest.job [2011-12-02 17:46:51 | 2106,134,528 | -HS- | C] () -- C:\hiberfil.sys [2011-12-02 17:46:51 | 2106,134,528 | -HS- | C] () -- \hiberfil.sys [2011-11-24 22:06:53 | 000,007,168 | ---- | C] () -- C:\Windows\System32\drivers\ute5nzyy.sys [2011-11-24 21:50:57 | 000,000,594 | ---- | C] () -- C:\Users\x\Desktop\Total Commander.lnk [2011-11-24 21:50:56 | 000,000,545 | ---- | C] () -- C:\Windows\UC.PIF [2011-11-24 21:50:56 | 000,000,545 | ---- | C] () -- C:\Windows\RAR.PIF [2011-11-24 21:50:56 | 000,000,545 | ---- | C] () -- C:\Windows\PKZIP.PIF [2011-11-24 21:50:56 | 000,000,545 | ---- | C] () -- C:\Windows\PKUNZIP.PIF [2011-11-24 21:50:56 | 000,000,545 | ---- | C] () -- C:\Windows\NOCLOSE.PIF [2011-11-24 21:50:56 | 000,000,545 | ---- | C] () -- C:\Windows\LHA.PIF [2011-11-24 21:50:56 | 000,000,545 | ---- | C] () -- C:\Windows\ARJ.PIF [2011-11-22 12:40:21 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe [2011-11-22 12:40:21 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe [2011-11-22 12:40:21 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe [2011-11-22 12:40:21 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe [2011-11-22 12:40:21 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe [2011-11-22 11:46:42 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS [2011-11-22 11:46:42 | 000,000,000 | RHS- | C] () -- \MSDOS.SYS [2011-11-22 11:46:42 | 000,000,000 | RHS- | C] () -- C:\IO.SYS [2011-11-22 11:46:42 | 000,000,000 | RHS- | C] () -- \IO.SYS [2011-11-16 19:06:19 | 000,001,732 | ---- | C] () -- C:\tvtpktfilter.dat [2011-11-16 19:06:19 | 000,001,732 | ---- | C] () -- \tvtpktfilter.dat [2011-11-03 12:29:59 | 000,001,152 | ---- | C] () -- C:\Windows\System32\windrv.sys [2011-06-23 13:47:14 | 000,212,551 | ---- | C] () -- C:\Windows\hpoins56.dat [2011-06-04 17:49:40 | 000,000,610 | ---- | C] () -- \SISTodo [2011-06-04 17:49:40 | 000,000,006 | ---- | C] () -- \SISHashTodo [2010-08-25 19:30:02 | 000,439,308 | ---- | C] () -- C:\Windows\System32\igcompkrng500.bin [2010-08-25 19:30:00 | 000,982,240 | ---- | C] () -- C:\Windows\System32\igkrng500.bin [2010-08-25 19:30:00 | 000,092,356 | ---- | C] () -- C:\Windows\System32\igfcg500m.bin [2010-08-25 18:57:00 | 000,000,151 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config [2010-08-25 18:52:00 | 000,208,896 | ---- | C] () -- C:\Windows\System32\iglhsip32.dll [2010-08-25 18:52:00 | 000,143,360 | ---- | C] () -- C:\Windows\System32\iglhcp32.dll [2010-06-15 16:39:05 | 000,000,118 | ---- | C] () -- C:\Windows\System32\MRT.INI [2010-05-27 09:57:27 | 000,000,552 | ---- | C] () -- C:\Windows\hpomdl56.dat [2010-03-17 07:56:56 | 000,001,356 | ---- | C] () -- C:\Users\x\AppData\Local\d3d9caps.dat [2009-09-15 08:27:15 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2009-09-15 08:27:15 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2009-05-30 00:37:40 | 000,205,824 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll [2009-05-30 00:31:52 | 000,881,664 | ---- | C] () -- C:\Windows\System32\xvidcore.dll [2009-05-10 09:41:53 | 000,000,583 | ---- | C] () -- C:\Windows\PowerReg.dat [2009-03-29 14:33:30 | 000,004,096 | ---- | C] () -- \WirelessDiagLog.csv [2009-02-04 20:03:22 | 000,160,256 | ---- | C] () -- C:\Users\x\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008-12-13 19:33:15 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2008-12-13 19:29:56 | 000,016,896 | ---- | C] () -- C:\Windows\Eventclr.exe [2008-12-13 11:22:45 | 000,204,800 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll [2008-12-13 11:22:45 | 000,200,704 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll [2008-12-13 11:22:45 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll [2008-12-13 11:22:45 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll [2008-12-13 11:22:45 | 000,188,416 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll [2008-12-13 11:22:45 | 000,020,480 | ---- | C] () -- C:\Windows\System32\IVIresize.dll [2008-12-13 11:20:16 | 000,056,056 | ---- | C] () -- C:\Windows\System32\DLAAPI_W.DLL [2008-12-13 11:20:16 | 000,000,120 | ---- | C] () -- C:\Windows\wininit.ini [2008-12-13 11:09:02 | 000,004,608 | ---- | C] () -- C:\Windows\System32\HdmiCoin.dll [2008-12-13 11:09:01 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1518.dll [2008-12-13 11:09:00 | 000,147,172 | ---- | C] () -- C:\Windows\System32\igfcg550.bin [2008-12-13 10:59:14 | 000,001,291 | ---- | C] () -- C:\Windows\vm331Rmv.ini [2008-12-13 10:53:19 | 000,003,204 | ---- | C] () -- C:\Windows\bthservsdp.dat [2008-04-18 18:14:54 | 000,332,832 | ---- | C] () -- C:\Windows\System32\perfi015.dat [2008-04-18 18:14:53 | 000,722,196 | ---- | C] () -- C:\Windows\System32\perfh015.dat [2008-04-18 18:14:53 | 000,149,294 | ---- | C] () -- C:\Windows\System32\perfc015.dat [2008-04-18 18:14:53 | 000,037,468 | ---- | C] () -- C:\Windows\System32\perfd015.dat [2007-09-04 10:56:10 | 000,164,352 | ---- | C] () -- C:\Windows\System32\unrar.dll [2007-04-16 03:24:16 | 000,023,752 | ---- | C] () -- C:\Windows\System32\providers.bin [2007-02-05 18:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI [2006-11-02 13:53:49 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2006-11-02 13:44:53 | 000,416,624 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006-11-02 11:33:01 | 000,645,608 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006-11-02 11:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006-11-02 11:33:01 | 000,122,436 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006-11-02 11:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006-11-02 11:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006-11-02 11:23:09 | 000,000,024 | ---- | C] () -- \autoexec.bat [2006-11-02 09:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006-11-02 09:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006-11-02 08:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006-11-02 08:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat [2006-11-02 07:25:08 | 000,000,010 | ---- | C] () -- \config.sys [color=#E56717]========== LOP Check ==========[/color] [2009-08-09 12:19:33 | 000,000,000 | ---D | M] -- C:\Users\x\AppData\Roaming\.szafir [2009-03-01 21:19:38 | 000,000,000 | ---D | M] -- C:\Users\x\AppData\Roaming\Datalayer [2011-11-03 12:26:28 | 000,000,000 | ---D | M] -- C:\Users\x\AppData\Roaming\GetRightToGo [2011-11-24 21:50:56 | 000,000,000 | ---D | M] -- C:\Users\x\AppData\Roaming\GHISLER [2009-10-11 17:12:04 | 000,000,000 | ---D | M] -- C:\Users\x\AppData\Roaming\InterVideo [2009-08-09 11:55:47 | 000,000,000 | ---D | M] -- C:\Users\x\AppData\Roaming\KIR [2009-02-14 17:33:48 | 000,000,000 | ---D | M] -- C:\Users\x\AppData\Roaming\Leadertech [2011-10-22 18:58:07 | 000,000,000 | ---D | M] -- C:\Users\x\AppData\Roaming\MyFelix [2011-02-06 14:57:13 | 000,000,000 | ---D | M] -- C:\Users\x\AppData\Roaming\Nokia [2010-01-31 14:40:29 | 000,000,000 | ---D | M] -- C:\Users\x\AppData\Roaming\Nokia Multimedia Player [2009-03-01 21:21:36 | 000,000,000 | ---D | M] -- C:\Users\x\AppData\Roaming\PC Suite [2011-12-03 09:16:15 | 000,000,000 | ---D | M] -- C:\Users\x\AppData\Roaming\PCDr [2011-03-06 15:31:09 | 000,000,000 | ---D | M] -- C:\Users\x\AppData\Roaming\PITy2010 [2011-12-03 10:13:40 | 000,000,000 | ---D | M] -- C:\Users\x\AppData\Roaming\PwrMgr [2011-12-03 09:09:40 | 000,000,000 | ---D | M] -- C:\Users\x\AppData\Roaming\Update [2010-05-09 17:21:25 | 000,000,000 | ---D | M] -- C:\Users\x\AppData\Roaming\VistaCodecs [2011-12-03 10:09:21 | 000,000,528 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job [2011-12-03 11:04:42 | 000,032,594 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2011-12-03 10:09:21 | 000,000,466 | ---- | M] () -- C:\Windows\Tasks\SystemToolsDailyTest.job [2010-12-19 10:26:42 | 000,000,410 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{C6E9670C-FBCF-447B-8539-1CD3DFAA980C}.job [color=#E56717]========== Purity Check ==========[/color] < End of report >