1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18. 19. 20. 21. 22. 23. 24. 25. 26. 27. 28. 29. 30. 31. 32. 33. 34. 35. 36. 37. 38. 39. 40. 41. 42. 43. 44. 45. 46. 47. 48. 49. 50. 51. 52. 53. 54. 55. 56. 57. 58. 59. 60. 61. 62. 63. 64. 65. 66. 67. 68. 69. 70. 71. 72. 73. 74. 75. 76. 77. 78. 79. 80. 81. 82. 83. 84. 85. 86. 87. 88. 89. 90. 91. 92. 93. 94. 95. 96. 97. 98. 99. 100. 101. 102. 103. 104. 105. 106. 107. 108. 109. 110. 111. 112. 113. 114. 115. 116. 117. 118. 119. 120. 121. 122. 123. 124. 125. 126. 127. 128. 129. 130. 131. 132. 133. 134. 135. 136. 137. 138. 139. 140. 141. 142. 143. 144. 145. 146. 147. 148. 149. 150. 151. 152. 153. 154. 155. 156. 157. 158. 159. 160. 161. 162. 163. 164. 165. 166. 167. 168. 169. 170. 171. 172. 173. 174. 175. 176. 177. 178. 179. 180. 181. 182. 183. 184. 185. 186. 187. 188. 189. 190. 191. 192. 193. 194. 195. 196. 197. 198. 199. 200. 201. 202. 203. 204. 205. 206. 207. 208. 209. 210. 211. 212. 213. 214. 215. 216. 217. 218. 219. 220. 221. 222. 223. 224. 225. 226. 227. 228. 229. 230. 231. 232. 233. 234. 235. 236. 237. 238. 239. 240. 241. 242. 243. 244. 245. 246. 247. 248. 249. 250. 251. 252. 253. 254. 255. 256. 257. 258. 259. 260. 261. 262. 263. 264. 265. 266. OTL logfile created on: 2010-02-17 20:04:49 - Run 1 OTL by OldTimer - Version 3.1.28.0 Folder = C:\Documents and Settings\Administrator\Pulpit Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 81,00% Memory free 4,00 Gb Paging File | 4,00 Gb Available in Paging File | 92,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 19,53 Gb Total Space | 1,62 Gb Free Space | 8,28% Space Free | Partition Type: NTFS Drive D: | 19,53 Gb Total Space | 0,20 Gb Free Space | 1,04% Space Free | Partition Type: NTFS Drive E: | 19,53 Gb Total Space | 2,12 Gb Free Space | 10,83% Space Free | Partition Type: NTFS Drive F: | 15,96 Gb Total Space | 3,51 Gb Free Space | 21,97% Space Free | Partition Type: NTFS G: Drive not present or media not loaded Drive H: | 3,18 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF I: Drive not present or media not loaded Computer Name: SPECIAL-XP Current User Name: Administrator Logged in as Administrator. Current Boot Mode: SafeMode with Networking Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Standard ========== Processes (SafeList) ========== PRC - [2010-02-17 20:01:38 | 000,549,376 | ---- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Pulpit\OTL.exe PRC - [2008-10-28 17:45:02 | 000,098,816 | ---- | M] (Opera Software) – C:\Program Files\Opera\opera.exe PRC - [2008-08-17 15:05:22 | 000,977,408 | ---- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe PRC - [2008-02-15 12:46:06 | 000,249,856 | ---- | M] (Intel Corporation) – C:\WINDOWS\system32\igfxsrvc.exe PRC - [2007-08-24 04:06:28 | 000,277,384 | ---- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\OIS.EXE ========== Modules (SafeList) ========== MOD - [2010-02-17 20:01:38 | 000,549,376 | ---- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Pulpit\OTL.exe ========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Stopped] – -- (RasAutogupdate) SRV - [2010-02-10 15:03:55 | 000,034,304 | ---- | M] (Ybezptlpyfznl Jqxvusmksqxvzkippsrbzjhomt Ypwuzmuwzjqzwzsuyegjldf) [Auto | Stopped] – C:\WINDOWS\system32\mssrv32.exe – (msupdate) SRV - [2010-01-02 16:09:10 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) [Auto | Stopped] – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService) SRV - [2009-12-26 01:13:58 | 000,075,064 | ---- | M] () [Auto | Stopped] – C:\WINDOWS\system32\PnkBstrA.exe – (PnkBstrA) SRV - [2009-12-04 16:11:38 | 000,055,936 | ---- | M] (F-Secure Corporation) [On_Demand | Stopped] – C:\Program Files\F-Secure\ORSP Client\fsorsp.exe – (FSORSPClient) SRV - [2009-11-30 10:10:13 | 000,135,664 | ---- | M] (Google Inc.) [Auto | Stopped] – C:\Program Files\Google\Update\GoogleUpdate.exe – (gupdate) Usługa Google Update (gupdate) SRV - [2009-11-23 21:29:00 | 003,559,196 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\WINDOWS\System32\GameMon.des – (npggsvc) SRV - [2009-07-09 10:34:54 | 000,186,976 | ---- | M] (F-Secure Corporation) [Auto | Stopped] – C:\Program Files\F-Secure\Common\FSMA32.EXE – (FSMA) SRV - [2009-07-09 10:33:14 | 000,522,848 | ---- | M] (F-Secure Corporation) [On_Demand | Stopped] – C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe – (FSDFWD) SRV - [2009-07-09 10:31:20 | 000,215,648 | ---- | M] (F-Secure Corporation) [Auto | Stopped] – C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe – (F-Secure Gatekeeper Handler Starter) SRV - [2007-08-24 03:19:12 | 000,443,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv) SRV - [2006-11-02 20:40:12 | 000,174,656 | ---- | M] () [Auto | Stopped] – C:\WINDOWS\system32\PSIService.exe – (ProtexisLicensing) SRV - [2006-10-26 13:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose) SRV - [2006-04-24 14:25:44 | 000,073,728 | ---- | M] (Hewlett-Packard Company) [Auto | Stopped] – C:\Program Files\Common Files\LightScribe\LSSrvc.exe – (LightScribeService) SRV - [2005-04-02 01:51:48 | 000,217,600 | ---- | M] (Rocket Division Software) [Auto | Stopped] – C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe – (StarWindService) SRV - [2003-02-25 06:52:00 | 000,303,104 | ---- | M] (Lexmark International, Inc.) [Auto | Stopped] – C:\WINDOWS\system32\LEXBCES.EXE – (LexBceS) ========== Driver Services (SafeList) ========== DRV - [2010-02-17 19:55:20 | 000,097,696 | ---- | M] () [Kernel | System | Running] – C:\WINDOWS\system32\drivers\cdrom.sys – (Cdrom) DRV - [2010-02-15 14:54:22 | 000,073,216 | ---- | M] () [Kernel | Auto | Stopped] – C:\WINDOWS\system32\drivers\uzbydcahqa.sys – (cvdqmxoa) DRV - [2009-12-12 21:27:29 | 000,025,512 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ggsemc.sys – (ggsemc) DRV - [2009-12-12 21:27:29 | 000,013,224 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ggflt.sys – (ggflt) DRV - [2009-12-09 16:29:11 | 000,107,104 | ---- | M] () [Kernel | On_Demand | Stopped] – C:\Program Files\F-Secure\Anti-Virus\minifilter\fsgk.sys – (F-Secure Gatekeeper) DRV - [2009-12-04 15:57:06 | 000,033,920 | ---- | M] () [Kernel | Boot | Stopped] – C:\WINDOWS\system32\Drivers\fsbts.sys – (fsbts) DRV - [2009-12-03 16:14:06 | 000,038,224 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mbamswissarmy.sys – (MBAMSwissArmy) DRV - [2009-07-09 10:34:18 | 000,068,064 | ---- | M] (F-Secure Corporation) [Kernel | System | Stopped] – C:\Program Files\F-Secure\HIPS\drivers\fshs.sys – (F-Secure HIPS) DRV - [2009-07-09 10:33:14 | 000,080,000 | ---- | M] (F-Secure Corporation) [Kernel | Boot | Running] – C:\WINDOWS\System32\drivers\fsdfw.sys – (FSFW) DRV - [2009-07-09 10:31:24 | 000,039,776 | ---- | M] () [Kernel | Disabled | Stopped] – C:\Program Files\F-Secure\Anti-Virus\win2k\fsfilter.sys – (F-Secure Filter) DRV - [2009-07-09 10:31:24 | 000,025,184 | ---- | M] () [Kernel | Disabled | Stopped] – C:\Program Files\F-Secure\Anti-Virus\win2k\fsrec.sys – (F-Secure Recognizer) DRV - [2008-11-20 22:12:21 | 000,038,656 | ---- | M] (Attansic Technology corporation.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\atl01_xp.sys – (AtcL001) DRV - [2008-11-20 22:12:21 | 000,005,810 | ---- | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ASACPI.sys – (MTsensor) DRV - [2008-11-20 22:12:10 | 000,062,208 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\si3112.sys – (Si3112) DRV - [2008-04-15 12:00:00 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus) DRV - [2008-04-15 12:00:00 | 000,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\secdrv.sys – (Secdrv) DRV - [2008-04-15 12:00:00 | 000,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ptilink.sys – (Ptilink) DRV - [2008-02-15 13:12:06 | 005,854,752 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\igxpmp32.sys – (ialm) DRV - [2007-05-14 22:41:46 | 000,014,336 | ---- | M] (A4Tech Co.,Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Amusbprt.sys – (Amusbprt) DRV - [2007-05-14 22:38:22 | 000,009,216 | ---- | M] (A4Tech Co.,Ltd.) [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\Amfilter.sys – (Amfilter) DRV - [2007-03-08 00:51:00 | 000,043,528 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20) DRV - [2006-09-12 12:27:00 | 004,381,184 | R— | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RtkHDAud.Sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM) DRV - [2005-12-21 20:22:20 | 000,005,685 | R— | M] () [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\AsIO.sys – (AsIO) DRV - [2005-08-10 13:44:04 | 000,050,688 | ---- | M] (Protection Technology) [Kernel | Boot | Running] – C:\WINDOWS\System32\drivers\sfdrv01.sys – (sfdrv01) StarForce Protection Environment Driver (version 1.x) DRV - [2005-05-16 14:20:39 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] – C:\WINDOWS\System32\drivers\sfhlp02.sys – (sfhlp02) StarForce Protection Helper Driver (version 2.x) DRV - [2005-04-25 10:43:58 | 000,159,616 | ---- | M] ( ) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\Vax347b.sys – (Vax347b) DRV - [2004-04-30 09:33:00 | 000,005,248 | ---- | M] ( ) [Kernel | Boot | Running] – C:\WINDOWS\System32\Drivers\Vax347s.sys – (Vax347s) DRV - [2003-01-07 08:32:26 | 000,015,400 | R— | M] (Motorola Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\NetMotCM.sys – (ndiscm) DRV - [2001-08-17 20:56:16 | 000,007,552 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\SONYPVU1.SYS – (SONYPVU1) Sterownik filtru USB Sony (SONYPVU1) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: “ProxyEnable” = 0 FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\Components: C:\Program Files\Mozilla Firefox\components [2010-01-10 15:39:46 | 000,000,000 | —D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-01-10 10:03:37 | 000,000,000 | —D | M] [2010-02-15 23:42:23 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions [2009-11-16 16:23:30 | 000,120,296 | ---- | M] ( ) – C:\Program Files\Mozilla Firefox\plugins\npganymedenet.dll [2009-12-26 01:19:58 | 000,002,767 | ---- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml [2009-12-26 01:19:58 | 000,001,406 | ---- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml [2009-12-26 01:19:58 | 000,000,917 | ---- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml [2009-12-26 01:19:58 | 000,000,858 | ---- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml [2009-12-26 01:19:58 | 000,001,183 | ---- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml [2009-12-26 01:19:58 | 000,001,683 | ---- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2008-04-15 12:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) O4 - HKLM…\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation) O4 - HKLM…\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation) O4 - HKLM…\Run: [Onet.pl AutoUpdate] C:\Program Files\Common Files\Onet.pl\NewAutoUpdate.exe File not found O4 - HKLM…\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation) O4 - HKLM…\Run: [Regedit32] C:\WINDOWS\System32\regedit.exe File not found O4 - HKLM…\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.) O4 - HKCU…\RunOnce: [_nltide_2] File not found O4 - HKCU…\RunOnce: [_nltide_3] C:\WINDOWS\System32\advpack.dll (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Bartek\Menu Start\Programy\IMVU\Run IMVU.lnk File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL (F-Secure Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL (F-Secure Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL (F-Secure Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL (F-Secure Corporation) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta … s-i586.cab (Java Plug-in 1.6.0_17) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 82.139.8.7 88.156.63.9 88.156.96.61 O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (\.\globalroot\systemroot\system32\userinit.exe) - \.\globalroot\systemroot\system32\userinit.exe () O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop BackupWallPaper: O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009-10-30 21:21:27 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT – [NTFS] O32 - AutoRun File - [2006-02-17 23:58:02 | 000,724,992 | R— | M] () - H:\AutoRun.exe – [UDF] O32 - AutoRun File - [2006-02-17 23:58:02 | 000,724,992 | R— | M] () - H:\AutoRun.exe – [UDF] O32 - AutoRun File - [2006-02-18 00:37:22 | 000,000,154 | R— | M] () - H:\autorun.inf – [UDF] O32 - AutoRun File - [2006-01-20 21:11:48 | 000,585,728 | R— | M] () - H:\AutoRunGUI.dll – [UDF] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - comfile [open] – “%1” %* O35 - exefile [open] – “%1” %* ========== Files/Folders - Created Within 30 Days ========== [2010-02-17 20:01:35 | 000,549,376 | ---- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Pulpit\OTL.exe [2010-02-17 19:54:52 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Moje dokumenty\Moje obrazy [2010-02-17 19:10:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Dane aplikacji\Macromedia [2010-02-17 19:10:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Dane aplikacji\Adobe [2010-02-17 19:09:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Opera [2010-02-17 19:09:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Dane aplikacji\Opera [2010-02-17 19:08:28 | 000,000,000 | --SD | C] – C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Microsoft [2010-02-17 19:08:28 | 000,000,000 | --SD | C] – C:\Documents and Settings\Administrator\Dane aplikacji\Microsoft [2010-02-17 19:08:28 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\SendTo [2010-02-17 19:08:28 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\Dane aplikacji [2010-02-17 19:08:28 | 000,000,000 | R–D | C] – C:\Documents and Settings\Administrator\Menu Start [2010-02-17 19:08:28 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Administrator\Cookies [2010-02-17 19:08:28 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Ustawienia lokalne [2010-02-17 19:08:28 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Szablony [2010-02-17 19:08:28 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Recent [2010-02-17 19:08:28 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\PrintHood [2010-02-17 19:08:28 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\NetHood [2010-02-17 19:08:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Ulubione [2010-02-17 19:08:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Pulpit [2010-02-17 19:08:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Moje dokumenty [2010-02-16 19:43:08 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC [2010-02-15 16:25:38 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Futuremark Shared [2010-02-13 11:17:03 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump [2010-02-10 15:03:56 | 000,034,304 | ---- | C] (Ybezptlpyfznl Jqxvusmksqxvzkippsrbzjhomt Ypwuzmuwzjqzwzsuyegjldf) – C:\WINDOWS\System32\mssrv32.exe [2010-01-28 23:35:35 | 000,000,000 | —D | C] – C:\Program Files\PITy [2009-12-30 12:38:23 | 000,159,616 | ---- | C] ( ) – C:\WINDOWS\System32\drivers\Vax347b.sys [2009-12-30 12:38:23 | 000,005,248 | ---- | C] ( ) – C:\WINDOWS\System32\drivers\Vax347s.sys [2009-12-04 12:50:57 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\F-Secure [2009-11-30 10:15:00 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Google [2009-11-30 10:10:23 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Google [2009-10-31 18:58:07 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\ESET [2009-10-30 21:27:28 | 000,000,000 | --SD | M] – C:\Documents and Settings\LocalService\Dane aplikacji\Microsoft [2009-10-30 21:24:59 | 000,000,000 | --SD | M] – C:\Documents and Settings\NetworkService\Dane aplikacji\Microsoft [2009-10-30 21:21:21 | 000,000,000 | --SD | M] – C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Microsoft [2009-10-30 21:21:21 | 000,000,000 | --SD | M] – C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Microsoft [4 C:\WINDOWS*.tmp files - C:\WINDOWS*.tmp -] [1 C:\WINDOWS\System32*.tmp files - C:\WINDOWS\System32*.tmp -] ========== Files - Modified Within 30 Days ========== [2010-02-17 20:04:26 | 000,014,934 | ---- | M] () – C:\Documents and Settings\Administrator\Pulpit\sss.jpg.jpg [2010-02-17 20:01:38 | 000,549,376 | ---- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Pulpit\OTL.exe [2010-02-17 20:01:35 | 000,786,432 | -H-- | M] () – C:\Documents and Settings\Administrator\NTUSER.DAT [2010-02-17 19:56:58 | 000,014,934 | ---- | M] () – C:\Documents and Settings\Administrator\Pulpit\sss1.jpg.jpg [2010-02-17 19:55:20 | 000,097,696 | ---- | M] () – C:\WINDOWS\System32\drivers\cdrom.sys [2010-02-17 19:55:20 | 000,097,696 | ---- | M] () – C:\WINDOWS\System32\dllcache\cdrom.sys [2010-02-17 19:48:52 | 000,160,566 | ---- | M] () – C:\Documents and Settings\Administrator\Pulpit\sss.jpg.bmp [2010-02-17 19:08:30 | 000,000,020 | -HS- | M] () – C:\Documents and Settings\Administrator\ntuser.ini [2010-02-17 19:08:16 | 000,002,228 | ---- | M] () – C:\WINDOWS\System32\wpa.dbl [2010-02-17 19:08:09 | 000,002,048 | --S- | M] () – C:\WINDOWS\bootstat.dat [2010-02-16 20:24:01 | 000,000,006 | -H-- | M] () – C:\WINDOWS\tasks\SA.DAT [2010-02-16 18:15:08 | 000,001,034 | ---- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2010-02-16 17:41:14 | 000,000,260 | ---- | M] () – C:\WINDOWS\tasks\WGASetup.job [2010-02-16 17:40:53 | 000,001,030 | ---- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2010-02-15 14:54:34 | 000,233,504 | ---- | M] () – C:\WINDOWS\System32\drivers\str.sys [2010-02-15 14:54:22 | 000,073,216 | ---- | M] () – C:\WINDOWS\System32\drivers\uzbydcahqa.sys [2010-02-12 20:33:59 | 000,000,116 | ---- | M] () – C:\WINDOWS\NeroDigital.ini [2010-02-10 15:03:55 | 000,034,304 | ---- | M] (Ybezptlpyfznl Jqxvusmksqxvzkippsrbzjhomt Ypwuzmuwzjqzwzsuyegjldf) – C:\WINDOWS\System32\mssrv32.exe [2010-02-07 22:49:41 | 000,000,394 | ---- | M] () – C:\WINDOWS\LEXSTAT.INI [2010-02-05 12:20:41 | 000,001,915 | ---- | M] () – C:\Documents and Settings\All Users\Pulpit\Google Earth.lnk [2010-01-25 23:55:38 | 000,000,032 | --S- | M] () – C:\WINDOWS\System32\1820496583.dat [4 C:\WINDOWS*.tmp files - C:\WINDOWS*.tmp -] [1 C:\WINDOWS\System32*.tmp files - C:\WINDOWS\System32*.tmp -] ========== Files Created - No Company Name ========== [2010-02-17 20:04:26 | 000,014,934 | ---- | C] () – C:\Documents and Settings\Administrator\Pulpit\sss.jpg.jpg [2010-02-17 19:56:58 | 000,014,934 | ---- | C] () – C:\Documents and Settings\Administrator\Pulpit\sss1.jpg.jpg [2010-02-17 19:48:52 | 000,160,566 | ---- | C] () – C:\Documents and Settings\Administrator\Pulpit\sss.jpg.bmp [2010-02-17 19:08:30 | 000,000,020 | -HS- | C] () – C:\Documents and Settings\Administrator\ntuser.ini [2010-02-17 19:08:27 | 000,786,432 | -H-- | C] () – C:\Documents and Settings\Administrator\NTUSER.DAT [2010-02-17 17:54:39 | 000,097,696 | ---- | C] () – C:\WINDOWS\System32\dllcache\cdrom.sys [2010-02-15 14:54:24 | 000,233,504 | ---- | C] () – C:\WINDOWS\System32\drivers\str.sys [2010-02-15 14:54:22 | 000,073,216 | ---- | C] () – C:\WINDOWS\System32\drivers\uzbydcahqa.sys [2010-02-05 12:20:41 | 000,001,915 | ---- | C] () – C:\Documents and Settings\All Users\Pulpit\Google Earth.lnk [2010-01-25 23:55:38 | 000,000,032 | --S- | C] () – C:\WINDOWS\System32\1820496583.dat [2010-01-10 15:39:01 | 000,147,456 | ---- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll [2010-01-10 15:00:28 | 000,354,816 | ---- | C] () – C:\WINDOWS\System32\psisdecd.dll [2009-12-30 12:42:00 | 000,034,308 | ---- | C] () – C:\WINDOWS\System32\BASSMOD.dll [2009-12-13 15:22:26 | 000,178,176 | ---- | C] () – C:\WINDOWS\System32\unrar.dll [2009-12-13 15:22:25 | 000,000,038 | ---- | C] () – C:\WINDOWS\avisplitter.ini [2009-12-13 15:22:21 | 000,881,664 | ---- | C] () – C:\WINDOWS\System32\xvidcore.dll [2009-12-13 15:22:21 | 000,205,824 | ---- | C] () – C:\WINDOWS\System32\xvidvfw.dll [2009-12-13 15:22:19 | 000,000,547 | ---- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest [2009-12-13 15:22:18 | 000,085,504 | ---- | C] () – C:\WINDOWS\System32\ff_vfw.dll [2009-12-04 22:44:26 | 000,138,504 | ---- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys [2009-12-04 17:05:14 | 000,143,360 | R— | C] () – C:\WINDOWS\System32\RtlCPAPI.dll [2009-12-04 17:03:17 | 000,017,107 | ---- | C] () – C:\WINDOWS\Ascd_tmp.ini [2009-12-04 12:50:50 | 000,033,920 | ---- | C] () – C:\WINDOWS\System32\drivers\fsbts.sys [2009-11-28 22:29:25 | 000,000,116 | ---- | C] () – C:\WINDOWS\NeroDigital.ini [2009-10-30 22:19:53 | 000,002,828 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys [2009-10-30 22:19:53 | 000,000,008 | RHS- | C] () – C:\WINDOWS\System32\1F148B5C05.sys [2009-10-30 22:04:02 | 000,000,394 | ---- | C] () – C:\WINDOWS\LEXSTAT.INI [2009-10-30 22:01:30 | 000,024,576 | R— | C] () – C:\WINDOWS\System32\AsIO.dll [2009-10-30 22:01:29 | 000,005,685 | R— | C] () – C:\WINDOWS\System32\drivers\AsIO.sys [2009-10-30 22:01:23 | 000,005,120 | ---- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp64.sys [2009-10-30 22:01:23 | 000,003,328 | ---- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp32.sys [2009-10-30 21:58:44 | 000,005,824 | ---- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS [2008-11-29 12:12:58 | 000,000,076 | ---- | C] () – C:\WINDOWS\System32\oeminfo.ini [2008-11-20 22:12:21 | 000,005,810 | ---- | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys [2008-04-15 12:00:00 | 000,097,696 | ---- | C] () – C:\WINDOWS\System32\drivers\cdrom.sys End of report