OTL logfile created on: 11-01-02 13:27:13 - Run 13 OTL by OldTimer - Version 3.2.20.0 Folder = C:\ Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yy-MM-dd 255,00 Mb Total Physical Memory | 101,00 Mb Available Physical Memory | 39,00% Memory free 938,00 Mb Paging File | 769,00 Mb Available in Paging File | 82,00% Paging File free Paging file location(s): C:\pagefile.sys 704 768 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 14,66 Gb Total Space | 0,49 Gb Free Space | 3,33% Space Free | Partition Type: FAT32 Drive D: | 3,97 Gb Total Space | 0,29 Gb Free Space | 7,37% Space Free | Partition Type: NTFS Computer Name: TRAXTER-EBE67FC | User Name: Admin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2011-01-01 18:35:28 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\OTL.exe PRC - [2010-10-18 00:42:38 | 000,075,496 | ---- | M] (SANDBOXIE L.T.D) -- C:\Program Files\Sandboxie\SbieSvc.exe PRC - [2010-08-09 13:53:18 | 000,140,608 | ---- | M] (Panda Security, S.L.) -- C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe PRC - [2010-05-14 14:06:30 | 000,406,848 | ---- | M] (Panda Security, S.L.) -- C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe PRC - [2008-04-14 22:51:18 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2006-01-21 13:31:46 | 000,118,784 | ---- | M] (Rainy) -- C:\Program Files\Rainlendar\Rainlendar.exe PRC - [2001-11-15 19:17:36 | 000,196,608 | ---- | M] (HP) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe [color=#E56717]========== Modules (SafeList) ==========[/color] MOD - [2011-01-01 18:35:28 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\OTL.exe MOD - [2010-08-23 18:12:54 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2010-10-18 00:42:38 | 000,075,496 | ---- | M] (SANDBOXIE L.T.D) [Auto | Running] -- C:\Program Files\Sandboxie\SbieSvc.exe -- (SbieSvc) SRV - [2010-08-09 13:53:18 | 000,140,608 | ---- | M] (Panda Security, S.L.) [Auto | Running] -- C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe -- (NanoServiceMain) SRV - [2010-03-18 13:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400) SRV - [2010-03-18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2010-10-18 00:42:34 | 000,124,648 | ---- | M] (SANDBOXIE L.T.D) [Kernel | On_Demand | Running] -- C:\Program Files\Sandboxie\SbieDrv.sys -- (SbieDrv) DRV - [2010-08-23 19:32:22 | 000,016,472 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\pwdrvio.sys -- (pwdrvio) DRV - [2010-08-23 19:32:22 | 000,011,104 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\pwdspio.sys -- (pwdspio) DRV - [2010-08-22 13:49:38 | 000,697,328 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd) DRV - [2010-07-21 21:02:06 | 000,112,456 | ---- | M] (Panda Security, S.L.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\PSINProt.sys -- (PSINProt) DRV - [2010-07-21 21:02:06 | 000,097,096 | ---- | M] (Panda Security, S.L.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\PSINFile.sys -- (PSINFile) DRV - [2010-06-17 12:41:12 | 000,129,992 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\PSINKNC.sys -- (PSINKNC) DRV - [2010-05-27 17:39:32 | 000,141,384 | ---- | M] (Panda Security, S.L.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\PSINAflt.sys -- (PSINAflt) DRV - [2010-04-30 12:46:52 | 000,111,624 | ---- | M] (Panda Security, S.L.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\PSINProc.sys -- (PSINProc) DRV - [2010-04-24 06:48:00 | 000,016,896 | ---- | M] () [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\dc_fsf.sys -- (dc_fsf) DRV - [2010-04-24 06:47:54 | 000,133,120 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\dcrypt.sys -- (dcrypt) DRV - [2010-01-20 19:39:18 | 000,025,400 | ---- | M] () [File_System | System | Running] -- C:\WINDOWS\system32\drivers\UnHooker.sys -- (UnHooker) DRV - [2006-09-13 18:15:48 | 000,066,591 | ---- | M] (3Com Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\el90xbc5.sys -- (EL90XBC) DRV - [2006-09-13 18:14:52 | 000,096,256 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ac97intc.sys -- (ac97intc) Usługa instalacyjna sterownika audio Intel(r) 82801 (WDM) DRV - [2002-01-12 16:30:34 | 000,003,567 | ---- | M] (Beyond Logic http://www.beyondlogic.org) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PortTalk.sys -- (PortTalk) DRV - [2001-08-31 00:40:30 | 000,282,688 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtaa.sys -- (ati2mtaa) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1957994488-299502267-725345543-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.wp.pl/ IE - HKU\S-1-5-21-1957994488-299502267-725345543-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 O1 HOSTS File: ([2010-11-27 14:53:54 | 000,000,765 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: O1 - Hosts: 127.0.0.1 mpa.one.microsoft.com O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll () O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe (HP) O4 - HKLM..\Run: [PSUNMain] C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe (Panda Security, S.L.) O4 - Startup: C:\Documents and Settings\Admin\Menu Start\Programy\Autostart\Rainlendar.lnk = C:\Program Files\Rainlendar\Rainlendar.exe (Rainy) O4 - Startup: C:\Documents and Settings\Uzytkownik\Menu Start\Programy\Autostart\Rainlendar.lnk = C:\Program Files\Rainlendar\Rainlendar.exe (Rainy) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableLocalMachineRun = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableLocalMachineRunOnce = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableCurrentUserRun = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisableCurrentUserRunOnce = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1957994488-299502267-725345543-1007\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-1957994488-299502267-725345543-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3 O7 - HKU\S-1-5-21-1957994488-299502267-725345543-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0 O8 - Extra context menu item: Pobierz plik wideo we Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm () O8 - Extra context menu item: Pobierz w Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm () O8 - Extra context menu item: Pobierz wszystkie pliki w Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm () O8 - Extra context menu item: Pobierz zaznaczone w Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm () O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {45830FF9-D9E6-4F41-86ED-B266933D8E90} http://87.204.164.159/RtspVaPgDec.cab (RtspVaPgCtrlNew Class) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1261309704734 (WUWebControl Class) O16 - DPF: {6BA530D8-94B2-49E0-AC55-70899582FE1F} http://87.204.164.160/AV718.cab (CV781Object Object) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1254567772843 (MUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 77.252.62.1 62.148.78.126 O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\Antiwpa: DllName - antiwpa.dll - C:\WINDOWS\System32\antiwpa.dll () O24 - Desktop Components:0 () - O24 - Desktop WallPaper: C:\Documents and Settings\Admin\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Admin\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009-10-03 22:38:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ] O32 - AutoRun File - [2010-07-06 15:45:22 | 000,000,000 | -HSD | M] - C:\autorun.inf -- [ FAT32 ] O32 - AutoRun File - [2011-01-01 18:55:18 | 000,000,000 | -HSD | M] - D:\autorun.inf -- [ NTFS ] O34 - HKLM BootExecute: (sef) - C:\WINDOWS\System32\sef.exe (WinSoftware) O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2011-01-01 20:16:17 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Admin\Recent [2011-01-01 18:51:29 | 000,118,784 | ---- | C] (http://somacon.com/blog/page32.php) -- C:\WINDOWS\DirectoryFixer.exe [2011-01-01 18:35:16 | 000,602,624 | ---- | C] (OldTimer Tools) -- C:\OTL.exe [2011-01-01 15:25:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Dane aplikacji\Hidden File Scanner [2011-01-01 10:13:47 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdkor.dll [2011-01-01 10:13:46 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdjpn.dll [2011-01-01 10:13:46 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbd103.dll [2011-01-01 10:13:44 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbd101c.dll [2011-01-01 10:13:42 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbd101b.dll [2011-01-01 10:13:39 | 001,677,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\chsbrkr.dll [2011-01-01 10:13:37 | 000,838,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\chtbrkr.dll [2011-01-01 10:13:35 | 001,875,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msir3jp.lex [2011-01-01 10:13:35 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\korwbrkr.dll [2011-01-01 10:13:34 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msir3jp.dll [2011-01-01 10:12:47 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbd101a.dll [2011-01-01 10:11:27 | 000,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdnecAT.dll [2011-01-01 10:11:27 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdnecNT.dll [2011-01-01 10:11:27 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdnec95.dll [2011-01-01 10:08:38 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\c_is2022.dll [2010-12-26 09:49:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dokumenty\PearlMountainSoft [2010-12-26 09:49:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\PearlMountainSoft [2010-12-25 07:09:15 | 000,000,000 | ---D | C] -- C:\Program Files\freac [2010-12-12 16:38:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\Logs [2010-12-12 11:20:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Admin\Ustawienia lokalne\Dane aplikacji\Temp [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2011-01-02 13:18:24 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2011-01-02 13:18:22 | 267,468,800 | -HS- | M] () -- C:\hiberfil.sys [2011-01-02 13:16:14 | 000,000,202 | ---- | M] () -- C:\Documents and Settings\Admin\defogger_reenable [2011-01-02 13:14:44 | 000,050,477 | ---- | M] () -- C:\Defogger.exe [2011-01-02 13:13:46 | 000,296,448 | ---- | M] () -- C:\lhmkuy4e.exe [2011-01-02 12:45:32 | 000,773,350 | ---- | M] () -- C:\Admin.zip [2011-01-02 09:59:54 | 000,003,436 | ---- | M] () -- C:\WINDOWS\Sandboxie.ini [2011-01-01 18:35:28 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\OTL.exe [2011-01-01 18:22:14 | 000,127,704 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2011-01-01 18:20:20 | 005,505,024 | ---- | M] () -- C:\Documents and Settings\Admin\ntuser.bak [2011-01-01 16:04:08 | 000,000,211 | -HS- | M] () -- C:\boot.ini [2011-01-01 10:18:24 | 000,002,228 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2010-12-26 20:10:08 | 000,006,673 | ---- | M] () -- C:\WINDOWS\wininit.ini [2010-12-26 12:23:58 | 000,043,410 | ---- | M] () -- C:\Documents and Settings\Admin\Moje dokumenty\hashTab.jpg [2010-12-25 17:02:46 | 000,012,288 | ---- | M] () -- C:\Documents and Settings\Admin\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010-12-20 18:09:00 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2010-12-20 18:08:40 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2010-12-18 11:15:24 | 000,001,403 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Pulpit\Opera.lnk [color=#E56717]========== Files Created - No Company Name ==========[/color] [2011-01-02 13:15:47 | 000,000,202 | ---- | C] () -- C:\Documents and Settings\Admin\defogger_reenable [2011-01-02 13:14:41 | 000,050,477 | ---- | C] () -- C:\Defogger.exe [2011-01-02 13:13:44 | 000,296,448 | ---- | C] () -- C:\lhmkuy4e.exe [2011-01-02 12:45:30 | 000,773,350 | ---- | C] () -- C:\Admin.zip [2011-01-01 16:04:05 | 000,001,503 | ---- | C] () -- C:\Documents and Settings\Admin\Menu Start\Programy\Autostart\Rainlendar.lnk [2011-01-01 10:13:37 | 000,001,486 | ---- | C] () -- C:\WINDOWS\System32\noise.kor [2011-01-01 10:13:36 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\korwbrkr.lex [2011-01-01 10:13:35 | 000,002,060 | ---- | C] () -- C:\WINDOWS\System32\noise.jpn [2011-01-01 10:13:18 | 000,146,126 | ---- | C] () -- C:\WINDOWS\System32\array30.tab [2011-01-01 10:13:18 | 000,018,600 | ---- | C] () -- C:\WINDOWS\System32\arrayhw.tab [2011-01-01 10:13:17 | 000,211,938 | ---- | C] () -- C:\WINDOWS\System32\lcphrase.tbl [2011-01-01 10:13:17 | 000,110,566 | ---- | C] () -- C:\WINDOWS\System32\arphr.tbl [2011-01-01 10:13:17 | 000,043,242 | ---- | C] () -- C:\WINDOWS\System32\phoncode.tbl [2011-01-01 10:13:17 | 000,024,114 | ---- | C] () -- C:\WINDOWS\System32\lcptr.tbl [2011-01-01 10:13:17 | 000,016,312 | ---- | C] () -- C:\WINDOWS\System32\arptr.tbl [2011-01-01 10:13:17 | 000,004,071 | ---- | C] () -- C:\WINDOWS\System32\phon.tbl [2011-01-01 10:13:17 | 000,002,714 | ---- | C] () -- C:\WINDOWS\System32\phonptr.tbl [2011-01-01 10:13:17 | 000,000,700 | ---- | C] () -- C:\WINDOWS\System32\dayiptr.tbl [2011-01-01 10:13:17 | 000,000,520 | ---- | C] () -- C:\WINDOWS\System32\dayiphr.tbl [2011-01-01 10:13:16 | 000,116,285 | ---- | C] () -- C:\WINDOWS\System32\msdayi.tbl [2011-01-01 10:13:16 | 000,044,370 | ---- | C] () -- C:\WINDOWS\System32\acode.tbl [2011-01-01 10:13:16 | 000,044,370 | ---- | C] () -- C:\WINDOWS\System32\a234.tbl [2011-01-01 10:13:16 | 000,001,460 | ---- | C] () -- C:\WINDOWS\System32\a15.tbl [2011-01-01 10:13:09 | 001,564,868 | ---- | C] () -- C:\WINDOWS\System32\WINSP.MB [2011-01-01 10:13:09 | 001,223,500 | ---- | C] () -- C:\WINDOWS\System32\WINZM.MB [2011-01-01 10:13:08 | 001,783,864 | ---- | C] () -- C:\WINDOWS\System32\WINPY.MB [2010-12-26 12:23:56 | 000,043,410 | ---- | C] () -- C:\Documents and Settings\Admin\Moje dokumenty\hashTab.jpg [2010-12-18 11:15:21 | 000,001,403 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Pulpit\Opera.lnk [2010-11-13 18:00:37 | 000,000,914 | ---- | C] () -- C:\WINDOWS\Lit.INI [2010-10-02 16:46:34 | 000,012,288 | ---- | C] () -- C:\Documents and Settings\Admin\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010-09-29 10:06:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ColorConsole_Portable.INI [2010-09-17 13:22:37 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll [2010-08-23 19:32:21 | 000,016,472 | ---- | C] () -- C:\WINDOWS\System32\pwdrvio.sys [2010-08-23 19:32:21 | 000,011,104 | ---- | C] () -- C:\WINDOWS\System32\pwdspio.sys [2010-07-25 12:18:45 | 000,133,120 | ---- | C] () -- C:\WINDOWS\System32\drivers\dcrypt.sys [2010-07-25 12:18:45 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\drivers\dc_fsf.sys [2010-07-20 15:57:33 | 000,000,073 | ---- | C] () -- C:\WINDOWS\EurekaLog.ini [2010-06-29 10:09:54 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NtRegEdit.INI [2010-06-06 16:47:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\WHD.INI [2010-05-07 16:28:00 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll [2010-05-01 07:10:26 | 000,003,436 | ---- | C] () -- C:\WINDOWS\Sandboxie.ini [2010-04-19 15:07:50 | 000,034,816 | ---- | C] () -- C:\WINDOWS\System32\drivers\.sys [2010-03-01 10:09:34 | 000,000,020 | ---- | C] () -- C:\WINDOWS\MeinPlatz.ini [2010-01-20 19:39:18 | 000,025,400 | ---- | C] () -- C:\WINDOWS\System32\drivers\UnHooker.sys [2010-01-04 14:09:31 | 000,000,071 | ---- | C] () -- C:\WINDOWS\Parameters.ini [2009-12-22 21:46:39 | 000,000,235 | ---- | C] () -- C:\WINDOWS\SuperBlank.INI [2009-11-01 09:40:34 | 000,044,544 | ---- | C] () -- C:\WINDOWS\System32\Gif89.dll [2009-10-26 15:36:40 | 000,006,673 | ---- | C] () -- C:\WINDOWS\wininit.ini [2009-10-03 14:18:46 | 000,060,416 | ---- | C] () -- C:\WINDOWS\System32\antiwpa.dll [2009-10-03 02:14:50 | 000,060,416 | ---- | C] () -- C:\WINDOWS\System32\antiwpa.dll3E857E [2009-10-03 00:35:10 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2006-01-08 15:53:24 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\hash2.dll [color=#E56717]========== LOP Check ==========[/color] [2009-10-03 22:59:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\Thinstall [2010-05-13 08:59:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Gadu-Gadu 10 [2010-11-28 06:51:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Panda Security [2010-12-26 09:49:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\PearlMountainSoft [2009-10-03 16:13:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\FreeDownloadManager.ORG [2009-10-29 13:48:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\TEMP [2010-06-17 14:04:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService.ZARZĄDZANIE NT\Dane aplikacji\Softland [2010-05-04 09:48:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Dane aplikacji\BonkEnc [2009-10-03 22:43:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Dane aplikacji\Rainlendar [2010-04-18 09:24:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Dane aplikacji\Thinstall [2009-10-04 09:33:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Dane aplikacji\OpenOffice.org [2010-09-10 09:58:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Dane aplikacji\Opera [2010-05-07 16:20:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Dane aplikacji\XnView [2009-10-11 12:57:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Dane aplikacji\Free Download Manager [2010-07-02 16:41:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Dane aplikacji\Foxit Software [2010-08-24 12:42:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Dane aplikacji\Gadu-Gadu 10 [2011-01-01 15:25:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Dane aplikacji\Hidden File Scanner [2010-11-28 06:54:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Admin\Dane aplikacji\Panda Security [2010-05-04 11:30:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Uzytkownik\Dane aplikacji\XnView [2009-10-03 22:52:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Uzytkownik\Dane aplikacji\ChomikBox [2009-10-03 22:52:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Uzytkownik\Dane aplikacji\Free Download Manager [2010-09-10 10:18:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Uzytkownik\Dane aplikacji\Opera [2010-12-25 17:25:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Uzytkownik\Dane aplikacji\FileVerifier++ [2009-10-03 22:53:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Uzytkownik\Dane aplikacji\Rainlendar [2009-10-04 20:43:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Uzytkownik\Dane aplikacji\OpenOffice.org [2010-07-04 17:03:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Uzytkownik\Dane aplikacji\Foxit Software [2010-12-25 07:12:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Uzytkownik\Dane aplikacji\freac [2009-10-11 09:58:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Uzytkownik\Dane aplikacji\Thinstall [2010-11-28 09:36:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Uzytkownik\Dane aplikacji\Panda Security [2010-12-26 09:49:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Uzytkownik\Dane aplikacji\PearlMountainSoft [2010-01-09 16:37:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Uzytkownik\Dane aplikacji\Gadu-Gadu 10 [color=#E56717]========== Purity Check ==========[/color] < End of report >