Drugi log zamieszczam 2 posty wyzej (ograniczenia znakow i nie da sie zrobic 2 post pod rzad ^^)
OTListIt logfile created on: 2009-05-08 21:25:43 - Run 1
OTListIt2 by OldTimer - Version 2.0.15.4 Folder = C:\Documents and Settings\Przemas\Pulpit
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
511.23 Mb Total Physical Memory | 181.11 Mb Available Physical Memory | 35.43% Memory free
1.22 Gb Paging File | 0.90 Gb Available in Paging File | 73.48% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 31.25 Gb Total Space | 15.37 Gb Free Space | 49.20% Space Free | Partition Type: NTFS
Drive D: | 21.61 Gb Total Space | 1.66 Gb Free Space | 7.66% Space Free | Partition Type: FAT32
Drive E: | 21.66 Gb Total Space | 4.45 Gb Free Space | 20.56% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PPP-6D36EB58B29
Current User Name: Przemas
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - [2004-08-12 16:09:28 | 00,389,120 | ---- | M] () – C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2008-03-29 19:11:18 | 00,017,272 | ---- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2008-03-29 19:37:02 | 00,144,760 | ---- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2008-02-18 11:16:30 | 00,110,592 | ---- | M] (Apple, Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2007-07-24 15:17:08 | 00,229,376 | ---- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2009-05-05 09:15:53 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2008-04-09 11:20:41 | 00,066,872 | ---- | M] () – C:\WINDOWS\system32\PnkBstrA.exe
PRC - [2008-03-29 19:36:22 | 00,247,160 | ---- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2008-03-29 19:30:47 | 00,345,464 | ---- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2004-08-12 16:09:28 | 00,389,120 | ---- | M] () – C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2008-04-14 19:21:16 | 01,035,264 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2004-08-12 21:10:00 | 00,339,968 | ---- | M] (ATI Technologies, Inc.) – C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
PRC - [2008-03-29 19:37:13 | 00,079,224 | ---- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009-05-05 09:15:53 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2005-05-11 23:12:54 | 00,049,152 | ---- | M] (Hewlett-Packard Co.) – C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
PRC - [2007-08-24 07:00:48 | 00,033,648 | ---- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
PRC - [2005-05-11 23:23:26 | 00,282,624 | ---- | M] (Hewlett-Packard Co.) – C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
PRC - [2004-06-30 16:59:24 | 00,724,992 | ---- | M] (Integrated Technology Express, Inc.) – C:\Program Files\ITE\ITE IT8212 ATA RAID Controller\RaidMgr.exe
PRC - [2005-05-12 00:40:38 | 00,204,800 | ---- | M] (Hewlett-Packard Co.) – C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
PRC - [2005-05-11 23:16:22 | 00,077,824 | ---- | M] (Hewlett-Packard Co.) – C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
PRC - [2009-04-30 21:30:06 | 00,307,704 | R— | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009-05-08 21:24:44 | 00,502,272 | ---- | M] (OldTimer Tools) – C:\Documents and Settings\Przemas\Pulpit\OTListIt2.exe
========== Win32 Services (SafeList) ==========
SRV - [2008-02-18 11:16:30 | 00,110,592 | ---- | M] (Apple, Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device [Auto | Running])
SRV - [2008-03-29 19:11:18 | 00,017,272 | ---- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe – (aswUpdSv [Auto | Running])
SRV - [2004-08-12 16:09:28 | 00,389,120 | ---- | M] () – C:\WINDOWS\system32\Ati2evxx.exe – (Ati HotKey Poller [Auto | Running])
SRV - [2004-08-12 21:10:00 | 00,516,096 | ---- | M] () – C:\WINDOWS\system32\ati2sgag.exe – (ATI Smart [Auto | Stopped])
SRV - [2008-03-29 19:37:02 | 00,144,760 | ---- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe – (avast! Antivirus [Auto | Running])
SRV - [2008-03-29 19:36:22 | 00,247,160 | ---- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe – (avast! Mail Scanner [On_Demand | Running])
SRV - [2008-03-29 19:30:47 | 00,345,464 | ---- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe – (avast! Web Scanner [On_Demand | Running])
SRV - [2007-07-24 15:17:08 | 00,229,376 | ---- | M] (Apple Inc.) – C:\Program Files\Bonjour\mDNSResponder.exe – (Bonjour Service [Auto | Running])
SRV - File not found – -- (gusvc [On_Demand | Stopped])
SRV - [2008-04-14 19:20:44 | 00,038,400 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2005-04-04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2009-05-05 09:15:53 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
SRV - [2007-08-24 06:59:20 | 00,068,464 | ---- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe – (Microsoft Office Groove Audit Service [On_Demand | Stopped])
SRV - [2007-08-24 03:19:12 | 00,443,776 | ---- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped])
SRV - [2006-10-26 13:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2004-09-29 12:14:36 | 00,069,632 | ---- | M] (HP) – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12 [Auto | Stopped])
SRV - [2008-04-09 11:20:41 | 00,066,872 | ---- | M] () – C:\WINDOWS\system32\PnkBstrA.exe – (PnkBstrA [Auto | Running])
SRV - [2008-12-10 01:10:14 | 00,024,636 | ---- | M] (Apache Software Foundation) – c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe – (wampapache [On_Demand | Stopped])
SRV - [2008-11-15 06:53:14 | 06,447,744 | ---- | M] () – c:\wamp\bin\mysql\mysql5.1.30\bin\mysqld.exe – (wampmysqld [On_Demand | Stopped])
========== Driver Services (SafeList) ==========
DRV - [2008-03-29 19:26:52 | 00,026,944 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys – (Aavmker4 [system | Running])
DRV - [2008-03-29 19:35:49 | 00,020,560 | ---- | M] (ALWIL Software) – C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys – (aswFsBlk [Auto | Running])
DRV - [2008-03-29 19:35:21 | 00,094,544 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys – (aswMon2 [Auto | Running])
DRV - [2008-03-29 19:29:08 | 00,023,152 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys – (aswRdr [On_Demand | Running])
DRV - [2008-03-29 19:31:34 | 00,075,856 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys – (aswSP [system | Running])
DRV - [2008-03-29 19:27:33 | 00,042,912 | ---- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys – (aswTdi [system | Running])
DRV - [2004-08-12 16:14:46 | 00,786,944 | ---- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys – (ati2mtag [On_Demand | Running])
DRV - [2004-07-27 18:06:54 | 01,258,432 | R— | M] (C-Media Inc) – C:\WINDOWS\system32\drivers\cmudax.sys – (cmudax [On_Demand | Running])
DRV - [2004-05-26 16:08:00 | 00,007,296 | R— | M] (ASUSTeK Computer Inc.) – C:\WINDOWS\system32\drivers\EIO.sys – (EIO [Auto | Running])
DRV - [2004-03-17 16:10:40 | 00,113,664 | ---- | M] (Windows ® Server 2003 DDK provider) – C:\WINDOWS\system32\drivers\HdAudio.sys – (HdAudAddService [On_Demand | Stopped])
DRV - [2008-04-13 18:36:05 | 00,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys – (HDAudBus [On_Demand | Running])
DRV - [2005-03-08 06:43:25 | 00,051,120 | R— | M] (HP) – C:\WINDOWS\system32\DRIVERS\HPZid412.sys – (HPZid412 [On_Demand | Stopped])
DRV - [2005-03-08 06:43:26 | 00,016,496 | R— | M] (HP) – C:\WINDOWS\system32\DRIVERS\HPZipr12.sys – (HPZipr12 [On_Demand | Stopped])
DRV - [2005-03-08 06:43:27 | 00,021,744 | R— | M] (HP) – C:\WINDOWS\system32\DRIVERS\HPZius12.sys – (HPZius12 [On_Demand | Stopped])
DRV - [2004-06-01 10:19:44 | 00,024,971 | ---- | M] (Integrated Technology Express, Inc.) – C:\WINDOWS\system32\DRIVERS\iteraid.sys – (iteraid [boot | Running])
DRV - [2003-09-10 23:36:54 | 00,021,060 | ---- | M] (InterVideo, Inc.) – C:\WINDOWS\system32\drivers\iviaspi.sys – (Iviaspi [On_Demand | Running])
DRV - [2007-03-27 04:26:56 | 00,088,960 | R— | M] (Huawei Technologies Co., Ltd.) – C:\WINDOWS\system32\DRIVERS\hmumdm.sys – (MobileAdapter [On_Demand | Stopped])
DRV - [2004-08-13 04:56:20 | 00,005,810 | R— | M] () – C:\WINDOWS\system32\DRIVERS\ASACPI.sys – (MTsensor [On_Demand | Running])
DRV - [2001-08-17 21:49:56 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\system32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2007-03-08 01:51:00 | 00,043,528 | ---- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20 [boot | Running])
DRV - [2007-11-13 12:25:55 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\system32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2008-04-09 11:01:35 | 00,717,296 | ---- | M] () – C:\WINDOWS\System32\Drivers\sptd.sys – (sptd [boot | Running])
DRV - [2006-11-04 00:45:48 | 00,178,913 | R— | M] (Creative Technology Ltd.) – C:\WINDOWS\system32\DRIVERS\V0260Vid.sys – (V0260VID [On_Demand | Running])
DRV - [2004-06-16 07:14:00 | 00,180,480 | ---- | M] (Marvell) – C:\WINDOWS\system32\DRIVERS\yk51x86.sys – (yukonwxp [On_Demand | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dl … ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl … r=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU.DEFAULT.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
IE - HKU\S-1-5-21-343818398-838170752-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl … r=iesearch
IE - HKU\S-1-5-21-343818398-838170752-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
IE - HKU\S-1-5-21-343818398-838170752-839522115-1004\S-1-5-21-343818398-838170752-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0
IE - HKU\S-1-5-21-343818398-838170752-839522115-1004\S-1-5-21-343818398-838170752-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyOverride” = *.local
========== FireFox ==========
FF - prefs.js…extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.3
FF - prefs.js…extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js…extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js…extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js…extensions.enabledItems: {5c8bfb7c-9a54-11dc-8314-0800200c9a66}:3.0.2
FF - prefs.js…extensions.enabledItems: {2458abc0-f443-11dd-87af-0800200c9a66}:0.8
FF - prefs.js…extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - prefs.js…extensions.enabledItems: {de5809e0-2b07-11dd-bd0b-0800200c9a66}:1.0.8
FF - prefs.js…extensions.enabledItems: nasanightlaunch@example.com:0.6.20090428
FF - prefs.js…extensions.enabledItems: redshift_V2@shift-themes.com:2.95
FF - HKLM\software\mozilla\Firefox\extensions\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009-05-05 09:15:54 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009-05-02 21:58:23 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009-05-05 09:16:07 | 00,000,000 | —D | M]
[2009-05-02 21:58:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Przemas\Dane aplikacji\mozilla\Extensions
[2009-05-02 21:58:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Przemas\Dane aplikacji\mozilla\Extensions{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-05-02 21:58:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Przemas\Dane aplikacji\mozilla\Firefox\Profiles\q7p025zy.default\extensions
[2009-05-08 18:32:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Przemas\Dane aplikacji\mozilla\Firefox\Profiles\qxaqa0wa.default\extensions
[2009-05-02 22:06:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Przemas\Dane aplikacji\mozilla\Firefox\Profiles\qxaqa0wa.default\extensions{2458abc0-f443-11dd-87af-0800200c9a66}
[2008-12-24 22:35:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Przemas\Dane aplikacji\mozilla\Firefox\Profiles\qxaqa0wa.default\extensions{5c8bfb7c-9a54-11dc-8314-0800200c9a66}
[2009-05-02 21:49:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Przemas\Dane aplikacji\mozilla\Firefox\Profiles\qxaqa0wa.default\extensions{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009-05-02 09:04:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Przemas\Dane aplikacji\mozilla\Firefox\Profiles\qxaqa0wa.default\extensions{de5809e0-2b07-11dd-bd0b-0800200c9a66}
[2009-05-02 09:14:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Przemas\Dane aplikacji\mozilla\Firefox\Profiles\qxaqa0wa.default\extensions\nasanightlaunch@example.com
[2009-05-02 22:07:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Przemas\Dane aplikacji\mozilla\Firefox\Profiles\qxaqa0wa.default\extensions\redshift_V2@shift-themes.com
[2008-04-09 11:04:30 | 00,002,921 | ---- | M] () – C:\Documents and Settings\Przemas\Dane aplikacji\Mozilla\FireFox\Profiles\qxaqa0wa.default\searchplugins\daemon-search.xml
[2009-05-08 18:32:29 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009-04-30 21:30:05 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008-08-05 09:45:46 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009-05-05 09:16:11 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009-04-30 21:30:05 | 00,023,032 | ---- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-04-30 21:30:05 | 00,134,648 | ---- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008-12-17 18:21:37 | 00,000,896 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2008-12-17 18:21:37 | 00,001,406 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2008-12-17 18:21:37 | 00,001,706 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008-12-17 18:21:37 | 00,000,917 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2008-12-17 18:21:37 | 00,000,858 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2008-12-17 18:21:37 | 00,001,183 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2008-12-17 18:21:37 | 00,001,683 | ---- | M] () – C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml
O1 HOSTS File: (161317 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 abcsearch.com
O1 - Hosts: 127.0.0.1 admin.abcsearch.com
O1 - Hosts: 127.0.0.1 www3.abcsearch.com #[browseraid]
O1 - Hosts: 127.0.0.1 http://www.abcsearch.com
O1 - Hosts: 127.0.0.1 abc517.net #[Trojan.Mitglieder.H]
O1 - Hosts: 127.0.0.1 acestats.com
O1 - Hosts: 127.0.0.1 http://www.acestats.com
O1 - Hosts: 127.0.0.1 actualnames.com #[Parasite.ActualNames]
O1 - Hosts: 127.0.0.1 http://www.actualnames.com
O1 - Hosts: 127.0.0.1 ad-up.com
O1 - Hosts: 127.0.0.1 http://www.ad-up.com
O1 - Hosts: 127.0.0.1 adatom.com
O1 - Hosts: 127.0.0.1 aesp.adatom.com
O1 - Hosts: 127.0.0.1 adbest.com
O1 - Hosts: 127.0.0.1 adserv.adbonus.com
O1 - Hosts: 127.0.0.1 http://www.adbonus.com
O1 - Hosts: 127.0.0.1 http://www.adblaster2.info #[Restricted Zone site]
O1 - Hosts: 127.0.0.1 ad2.adcept.net
O1 - Hosts: 127.0.0.1 ad3.adcept.net
O1 - Hosts: 127.0.0.1 http://www.adcept.net
O1 - Hosts: 127.0.0.1 adcomplete.com
O1 - Hosts: 127.0.0.1 http://www.adcomplete.com
O1 - Hosts: 127.0.0.1 http://www.adcopy.info
O1 - Hosts: 127.0.0.1 ads.adcorps.com
O1 - Hosts: 4671 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll File not found
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll File not found
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_9993303B90FE6C1D.dll File not found
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM…\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll File not found
O4 - HKLM…\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM…\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM…\Run: [GrooveMonitor] “C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe” (Microsoft Corporation)
O4 - HKLM…\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM…\Run: [skrót do strony właściwości High Definition Audio] HDAudPropShortcut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM…\Run: [sunJavaUpdateSched] “C:\Program Files\Java\jre6\bin\jusched.exe” (Sun Microsystems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\RAID Manager.lnk = C:\Program Files\ITE\ITE IT8212 ATA RAID Controller\RaidMgr.exe (Integrated Technology Express, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-21-343818398-838170752-839522115-1004\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-21-343818398-838170752-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-343818398-838170752-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-343818398-838170752-839522115-1004_Classes\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra ‘Tools’ menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra ‘Tools’ menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra ‘Tools’ menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM…Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc … wflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_9993303B90FE6C1D.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll ()
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-04-07 21:17:01 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT – [NTFS]
O33 - MountPoints2{ee8665c0-a113-11dd-8ba4-0011d85c3f90}\Shell - “” = AutoRun
O33 - MountPoints2{ee8665c0-a113-11dd-8ba4-0011d85c3f90}\Shell\AutoRun\command - “” = H:\LaunchU3.exe – File not found
O33 - MountPoints2\H\Shell - “” = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - “” = H:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[1 C:\WINDOWS\System32*.tmp files]
[2009-05-08 21:24:39 | 00,502,272 | ---- | C] (OldTimer Tools) – C:\Documents and Settings\Przemas\Pulpit\OTListIt2.exe
[2009-05-08 20:48:48 | 00,000,618 | ---- | C] () – C:\Documents and Settings\Przemas\Pulpit\Play Quake III Arena.lnk
[2009-05-08 20:48:17 | 00,000,000 | —D | C] – C:\Program Files\Mplayer
[2009-05-08 20:43:26 | 00,000,777 | ---- | C] () – C:\WINDOWS\QIII.INI
[2009-05-08 18:27:25 | 00,360,021 | ---- | C] () – C:\Documents and Settings\Przemas\Pulpit\dds.scr
[2009-05-08 18:27:14 | 00,360,021 | ---- | C] () – C:\Documents and Settings\Przemas\Pulpit\dds.pif
[2009-05-08 18:20:30 | 00,000,000 | —D | C] – C:\Documents and Settings\Przemas\Dane aplikacji\Malwarebytes
[2009-05-08 18:20:26 | 00,000,696 | ---- | C] () – C:\Documents and Settings\All Users\Pulpit\Malwarebytes’ Anti-Malware.lnk
[2009-05-08 18:20:25 | 00,015,504 | ---- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009-05-08 18:20:23 | 00,038,496 | ---- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009-05-08 18:20:20 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes’ Anti-Malware
[2009-05-08 18:20:20 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes
[2009-05-07 20:25:17 | 00,001,734 | ---- | C] () – C:\Documents and Settings\Przemas\Pulpit\HijackThis.lnk
[2009-05-07 20:25:16 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009-05-06 08:02:42 | 00,000,260 | ---- | C] () – C:\WINDOWS\tasks\WGASetup.job
[2009-05-06 08:02:42 | 00,000,000 | —D | C] – C:\WINDOWS\System32\KB905474
[2009-05-05 09:19:12 | 03,686,454 | ---- | C] () – C:\Documents and Settings\Przemas\Pulpit\log.bmp
[2009-05-02 21:58:22 | 00,000,000 | —D | C] – C:\Documents and Settings\Przemas\Dane aplikacji\Mozilla
[2009-04-27 20:04:54 | 00,000,208 | ---- | C] () – C:\Documents and Settings\Przemas\Pulpit\CMI Audio Config.lnk
[2009-04-26 11:10:07 | 00,000,000 | —D | C] – C:\Documents and Settings\Przemas\Dane aplikacji\Nowe Gadu-Gadu
[2009-04-26 11:09:22 | 00,000,000 | —D | C] – C:\Program Files\Nowe Gadu-Gadu
[2009-04-20 18:43:19 | 00,001,176 | ---- | C] () – C:\WINDOWS\ImpTable.bin
[2009-04-16 20:34:08 | 00,030,700 | ---- | C] () – C:\Documents and Settings\All Users\Dokumenty\Scenariusz Zak. KL VI.docx
[2009-04-16 10:21:02 | 00,000,000 | —D | C] – C:\Documents and Settings\Przemas\Pulpit\dom2
[2009-04-15 18:52:07 | 00,227,840 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009-04-15 18:52:06 | 00,401,408 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009-04-15 18:52:06 | 00,285,696 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009-04-15 18:52:06 | 00,111,104 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009-04-15 18:52:05 | 00,686,592 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009-04-15 18:52:05 | 00,473,600 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009-04-15 18:52:03 | 00,731,136 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\lsasrv.dll
[2009-04-15 18:52:03 | 00,722,944 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009-04-15 18:52:03 | 00,453,120 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009-04-15 18:46:32 | 01,203,922 | ---- | C] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009-04-15 18:46:31 | 00,218,112 | ---- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009-04-09 10:12:50 | 00,019,903 | ---- | C] () – C:\Documents and Settings\Przemas\Pulpit\dietaLekkostrawna.pdf
[2009-01-07 21:03:24 | 00,000,884 | ---- | C] () – C:\WINDOWS\SOFPLAT.ini
[2008-04-13 17:39:04 | 00,138,280 | ---- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008-04-09 15:19:29 | 00,000,049 | ---- | C] () – C:\WINDOWS\NeroDigital.ini
[2008-04-09 11:01:35 | 00,717,296 | ---- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2008-04-08 19:44:38 | 00,000,526 | ---- | C] () – C:\WINDOWS\ODBC.INI
[2008-04-07 21:30:55 | 00,122,880 | ---- | C] () – C:\WINDOWS\System32\cddvdint.dll
[2008-04-07 21:26:27 | 00,028,672 | R— | C] () – C:\WINDOWS\System32\cmirmdrv.dll
[2008-04-07 21:26:23 | 00,003,407 | R— | C] () – C:\WINDOWS\cmudax.ini
[2008-04-07 21:24:01 | 00,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2008-04-07 21:23:57 | 00,002,812 | ---- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2008-04-07 21:23:55 | 00,005,824 | ---- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008-04-07 21:22:53 | 00,151,552 | R— | C] ( ) – C:\WINDOWS\System32\ATIDEMGR.dll
[2005-10-31 21:28:22 | 00,069,632 | ---- | C] () – C:\WINDOWS\System32\MobOlExt.dll
[2004-08-12 16:10:50 | 00,086,016 | ---- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[2001-07-21 22:16:20 | 00,000,679 | ---- | C] () – C:\WINDOWS\win.ini
[2001-07-21 22:15:52 | 00,000,435 | ---- | C] () – C:\WINDOWS\system.ini
[2001-07-06 15:30:02 | 00,003,234 | ---- | C] () – C:\WINDOWS\System32\HPTCPMON.INI
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32*.tmp files]
[4 C:\WINDOWS*.tmp files]
[2009-05-08 21:24:44 | 00,502,272 | ---- | M] (OldTimer Tools) – C:\Documents and Settings\Przemas\Pulpit\OTListIt2.exe
[2009-05-08 20:48:48 | 00,000,618 | ---- | M] () – C:\Documents and Settings\Przemas\Pulpit\Play Quake III Arena.lnk
[2009-05-08 20:48:21 | 00,000,777 | ---- | M] () – C:\WINDOWS\QIII.INI
[2009-05-08 20:36:29 | 00,000,260 | ---- | M] () – C:\WINDOWS\tasks\WGASetup.job
[2009-05-08 20:36:21 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\Przemas\Ustawienia lokalne\desktop.ini
[2009-05-08 20:35:41 | 00,000,006 | -H-- | M] () – C:\WINDOWS\tasks\SA.DAT
[2009-05-08 20:35:30 | 00,002,048 | --S- | M] () – C:\WINDOWS\bootstat.dat
[2009-05-08 18:48:01 | 00,360,021 | ---- | M] () – C:\Documents and Settings\Przemas\Pulpit\dds.pif
[2009-05-08 18:47:51 | 00,360,021 | ---- | M] () – C:\Documents and Settings\Przemas\Pulpit\dds.scr
[2009-05-08 18:45:06 | 00,000,435 | ---- | M] () – C:\WINDOWS\system.ini
[2009-05-08 18:20:26 | 00,000,696 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\Malwarebytes’ Anti-Malware.lnk
[2009-05-07 20:25:17 | 00,001,734 | ---- | M] () – C:\Documents and Settings\Przemas\Pulpit\HijackThis.lnk
[2009-05-07 19:48:04 | 00,001,891 | ---- | M] () – C:\WINDOWS\imsins.BAK
[2009-05-05 09:53:35 | 00,000,049 | ---- | M] () – C:\WINDOWS\NeroDigital.ini
[2009-05-05 09:19:13 | 03,686,454 | ---- | M] () – C:\Documents and Settings\Przemas\Pulpit\log.bmp
[2009-05-02 21:50:56 | 00,012,800 | -HS- | M] () – C:\Documents and Settings\Przemas\Pulpit\Thumbs.db
[2009-05-01 09:30:17 | 00,000,318 | ---- | M] () – C:\WINDOWS\System\cmicnfg.ini
[2009-04-30 09:14:19 | 00,013,329 | ---- | M] () – C:\Documents and Settings\Przemas\Pulpit\Nowy Dokument programu Microsoft Office Word.docx
[2009-04-27 20:04:54 | 00,000,208 | ---- | M] () – C:\Documents and Settings\Przemas\Pulpit\CMI Audio Config.lnk
[2009-04-27 18:42:07 | 00,000,284 | ---- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009-04-20 18:43:19 | 00,001,176 | ---- | M] () – C:\WINDOWS\ImpTable.bin
[2009-04-16 21:27:49 | 00,002,259 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\Skype.lnk
[2009-04-16 20:34:08 | 00,030,700 | ---- | M] () – C:\Documents and Settings\All Users\Dokumenty\Scenariusz Zak. KL VI.docx
[2009-04-16 20:04:53 | 00,772,674 | ---- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009-04-16 20:04:53 | 00,359,178 | ---- | M] () – C:\WINDOWS\System32\perfh015.dat
[2009-04-16 20:04:53 | 00,314,644 | ---- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009-04-16 20:04:53 | 00,050,968 | ---- | M] () – C:\WINDOWS\System32\perfc015.dat
[2009-04-16 20:04:53 | 00,040,972 | ---- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009-04-12 19:44:36 | 00,002,206 | ---- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009-04-09 10:12:50 | 00,019,903 | ---- | M] () – C:\Documents and Settings\Przemas\Pulpit\dietaLekkostrawna.pdf
< End of report >
:x :x :x