1.
2.
3.
4.
5.
6.
7.
8.
9.
10.
11.
12.
13.
14.
15.
16.
17.
18.
19.
20.
21.
22.
23.
24.
25.
26.
27.
28.
29.
30.
31.
32.
33.
34.
35.
36.
37.
38.
39.
40.
41.
42.
43.
44.
45.
46.
47.
48.
49.
50.
51.
52.
53.
54.
55.
56.
57.
58.
59.
60.
61.
62.
63.
64.
65.
66.
67.
68.
69.
70.
71.
72.
73.
74.
75.
76.
77.
78.
79.
80.
81.
82.
83.
84.
85.
86.
87.
88.
89.
90.
91.
92.
93.
94.
95.
96.
97.
98.
99.
100.
101.
102.
103.
104.
105.
106.
107.
108.
109.
110.
111.
112.
113.
114.
115.
116.
117.
118.
119.
120.
121.
122.
123.
124.
125.
126.
127.
128.
129.
130.
131.
132.
133.
134.
135.
136.
137.
138.
139.
140.
141.
142.
143.
144.
145.
146.
147.
148.
149.
150.
151.
152.
153.
154.
155.
156.
157.
158.
159.
160.
161.
162.
163.
164.
165.
166.
167.
168.
169.
170.
171.
172.
173.
174.
175.
176.
177.
178.
179.
180.
181.
182.
183.
184.
185.
186.
187.
188.
189.
190.
191.
192.
193.
194.
195.
196.
197.
198.
199.
200.
201.
202.
203.
204.
205.
206.
207.
208.
209.
210.
211.
212.
213.
214.
215.
216.
217.
218.
219.
220.
221.
222.
223.
224.
225.
226.
227.
228.
229.
230.
231.
232.
233.
234.
235.
236.
237.
238.
239.
240.
241.
242.
243.
244.
245.
246.
247.
248.
249.
250.
251.
252.
253.
254.
255.
256.
257.
258.
259.
260.
261.
262.
263.
264.
265.
266.
267.
268.
269.
270.
271.
272.
273.
274.
275.
276.
277.
278.
279.
280.
281.
282.
283.
284.
285.
286.
287.
288.
289.
290.
291.
292.
293.
294.
295.
296.
297.
298.
299.
300.
301.
302.
303.
304.
305.
306.
307.
308.
309.
310.
311.
312.
313.
314.
315.
316.
317.
318.
319.
320.
321.
322.
323.
324.
325.
326.
327.
328.
329.
330.
331.
332.
333.
334.
335.
336.
337.
338.
339.
340.
341.
342.
343.
344.
345.
346.
347.
348.
349.
350.
351.
352.
353.
354.
355.
356.
357.
358.
359.
360.
361.
362.
363.
364.
365.
366.
367.
368.
369.
370.
371.
372.
373.
374.
375.
376.
377.
378.
379.
380.
381.
382.
383.
384.
385.
386.
387.
388.
389.
390.
391.
392.
393.
394.
395.
396.
397.
398.
399.
400.
401.
402.
403.
404.
405.
406.
407.
408.
409.
410.
411.
412.
413.
414.
415.
416.
417.
418.
419.
420.
421.
422.
423.
424.
425.
426.
427.
428.
429.
430.
431.
432.
433.
434.
435.
436.
437.
438.
439.
440.
441.
442.
443.
444.
445.
446.
447.
448.
449.
450.
451.
452.
453.
454.
455.
456. | OTL logfile created on: 2011-01-03 23:34:18 - Run 3
OTL by OldTimer - Version 3.2.20.1 Folder = C:\Documents and Settings\emoss\Pulpit
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
255,00 Mb Total Physical Memory | 51,00 Mb Available Physical Memory | 20,00% Memory free
618,00 Mb Paging File | 337,00 Mb Available in Paging File | 55,00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,54 Gb Total Space | 1,37 Gb Free Space | 7,00% Space Free | Partition Type: NTFS
Drive D: | 54,98 Gb Total Space | 4,50 Gb Free Space | 8,19% Space Free | Partition Type: NTFS
Computer Name: EMOS | User Name: emoss | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2011-01-03 23:32:40 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\emoss\Pulpit\OTL.exe
PRC - [2010-12-11 20:46:41 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2008-08-04 00:04:00 | 001,345,376 | ---- | M] (Nullsoft) -- C:\Program Files\Winamp\winamp.exe
PRC - [2008-04-14 18:21:16 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008-03-20 11:04:46 | 002,127,296 | ---- | M] (Gadu-Gadu S.A.) -- C:\Program Files\Gadu-Gadu\gg.exe
PRC - [2006-03-03 20:03:10 | 000,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
PRC - [2004-02-26 14:43:16 | 000,962,661 | ---- | M] () -- C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
PRC - [2002-09-11 03:57:20 | 000,046,592 | ---- | M] (Avance Logic, Inc.) -- C:\WINDOWS\SOUNDMAN.EXE
[color=#E56717]========== Modules (SafeList) ==========[/color]
MOD - [2011-01-03 23:32:40 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\emoss\Pulpit\OTL.exe
MOD - [2010-08-23 17:12:53 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2006-12-21 13:30:44 | 000,102,400 | ---- | M] (Gadu-Gadu S.A.) -- C:\Program Files\Gadu-Gadu\ggwhook.dll
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV - [2006-03-03 20:03:10 | 000,069,632 | ---- | M] (HP) [Unknown | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - [2010-12-25 18:11:54 | 000,139,096 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PnkBstrK.sys -- (PnkBstrK)
DRV - [2008-04-13 19:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2006-12-17 03:50:29 | 001,918,464 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006-09-13 19:18:54 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Sterownik NT karty Realtek RTL8139(A/B/C)
DRV - [2006-09-13 19:17:20 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
DRV - [2003-07-17 16:48:44 | 000,046,167 | ---- | M] (Analog Deivces) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\adildr.sys -- (ADILOADER) General Purpose USB Driver (adildr.sys)
DRV - [2003-06-24 13:55:56 | 000,127,497 | ---- | M] (Analog Devices Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\adiusbaw.sys -- (adiusbaw)
DRV - [2002-09-16 11:25:02 | 000,941,516 | ---- | M] (Avance Logic, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Avance AC97 Audio (WDM)
DRV - [2002-07-24 03:30:00 | 000,032,128 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\viaagp1.sys -- (viaagp1)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wyborcza.pl/0,0.html?p=029
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1644491937-1965331169-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
IE - HKU\S-1-5-21-1644491937-1965331169-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..browser.startup.homepage: "www.google.pl"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010-12-19 01:58:50 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010-12-11 20:46:52 | 000,000,000 | ---D | M]
[2009-10-11 23:30:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\emoss\Dane aplikacji\Mozilla\Extensions
[2011-01-03 15:57:24 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\emoss\Dane aplikacji\Mozilla\Firefox\Profiles\wpo3qjff.default\extensions
[2009-10-21 20:24:22 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\emoss\Dane aplikacji\Mozilla\Firefox\Profiles\wpo3qjff.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011-01-03 15:57:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010-10-27 20:43:21 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010-02-19 23:28:46 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010-09-15 03:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010-12-08 23:48:45 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml
[2010-12-08 23:48:45 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml
[2010-12-08 23:48:45 | 000,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml
[2010-12-08 23:48:45 | 000,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml
[2010-12-08 23:48:45 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml
[2010-12-08 23:48:45 | 000,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml
O1 HOSTS File: ([2009-11-28 12:11:46 | 000,000,025 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Avance Logic, Inc.)
O4 - HKU\S-1-5-21-1644491937-1965331169-1801674531-1003..\Run: [Komunikator] C:\Program Files\Tlen.pl\tlen.exe (o2.pl Sp. z o.o.)
O4 - HKU\.DEFAULT..\RunOnce: [] File not found
O4 - HKU\S-1-5-18..\RunOnce: [] File not found
O4 - HKU\S-1-5-19..\RunOnce: [] File not found
O4 - HKU\S-1-5-19..\RunOnce: [nlpo_01] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [] File not found
O4 - HKU\S-1-5-20..\RunOnce: [nlpo_03] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [nlpo_04] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-21-1644491937-1965331169-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\emoss\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\emoss\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-10-11 22:51:05 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{e9fbcf9d-d6c6-11de-bdc6-4d6564696130}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe -- File not found
O33 - MountPoints2\{e9fbcf9d-d6c6-11de-bdc6-4d6564696130}\Shell\open\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
MsConfig - StartUpFolder: C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe - (Hewlett-Packard Development Company, L.P.)
MsConfig - StartUpFolder: C:^Documents and Settings^emoss^Menu Start^Programy^Autostart^OpenOffice.org 2.0.2.lnk - C:\Program Files\OpenOffice.org 2.0.2\program\quickstart.exe - ()
MsConfig - StartUpReg: [b]HP Software Update[/b] - hkey= - key= - File not found
MsConfig - StartUpReg: [b]Komunikator[/b] - hkey= - key= - C:\Program Files\Tlen.pl\tlen.exe (o2.pl Sp. z o.o.)
MsConfig - StartUpReg: [b]Malwarebytes Anti-Malware (reboot)[/b] - hkey= - key= - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
MsConfig - StartUpReg: [b]Skype[/b] - hkey= - key= - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 2
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2011-01-03 13:23:13 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\emoss\Recent
[2010-12-25 13:49:54 | 000,474,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shlwapi.dll
[2010-12-25 13:48:33 | 000,974,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc42.dll
[2010-12-25 13:48:33 | 000,954,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc40.dll
[2010-12-25 13:48:33 | 000,953,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc40u.dll
[2010-12-25 13:47:47 | 000,617,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\comctl32.dll
[2010-12-25 13:45:47 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010-12-25 13:45:25 | 000,743,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010-12-25 13:43:37 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndproxy.sys
[2010-12-25 13:41:18 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\browserchoice.exe
[2010-12-25 13:34:08 | 003,558,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\moviemk.exe
[2010-12-25 13:28:06 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wab.exe
[2010-12-16 18:20:35 | 000,155,648 | ---- | C] (Analog Devices Inc.) -- C:\WINDOWS\System32\adadix32.dll
[2010-12-16 18:20:35 | 000,127,497 | ---- | C] (Analog Devices Inc.) -- C:\WINDOWS\System32\drivers\adiusbaw.sys
[2010-12-16 18:20:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\SAGEM F@st 800-840
[2010-12-16 18:20:30 | 000,135,168 | ---- | C] (Analog Devices.) -- C:\WINDOWS\System32\unaddrv.exe
[2010-12-16 18:20:30 | 000,046,167 | ---- | C] (Analog Deivces) -- C:\WINDOWS\System32\drivers\adildr.sys
[2010-12-16 18:20:30 | 000,004,981 | ---- | C] (SITECSOFT Co., LTD.) -- C:\WINDOWS\System32\adadix2k.dll
[2010-12-16 18:20:18 | 000,000,000 | ---D | C] -- C:\Program Files\SAGEM
[2010-12-16 16:40:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2010-12-11 19:00:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Microsoft Silverlight
[2010-12-11 17:34:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\emoss\Moje dokumenty\Tlen.pl
[2010-12-10 21:23:16 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidserv.dll
[2010-12-10 21:23:10 | 000,014,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhid.sys
[2010-12-10 15:53:16 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rnaph.dll
[2010-12-10 15:53:04 | 000,000,000 | ---D | C] -- C:\Program Files\Wanadoo
[2010-12-09 15:01:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\emoss\Moje dokumenty\Pobieranie
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2011-01-03 23:34:33 | 003,932,160 | -H-- | M] () -- C:\Documents and Settings\emoss\NTUSER.DAT
[2011-01-03 23:32:40 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\emoss\Pulpit\OTL.exe
[2011-01-03 23:32:39 | 000,000,462 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{A0DB8725-3118-4337-AADB-10E3EF2FC88C}.job
[2011-01-03 23:05:17 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\emoss\Pulpit\3. Ten typ tak ma.mp3
[2011-01-03 21:26:21 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2011-01-03 21:26:16 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011-01-03 21:26:13 | 267,968,512 | -HS- | M] () -- C:\hiberfil.sys
[2011-01-03 18:11:16 | 000,000,188 | -HS- | M] () -- C:\Documents and Settings\emoss\ntuser.ini
[2011-01-03 18:11:00 | 001,579,550 | -H-- | M] () -- C:\Documents and Settings\emoss\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2011-01-02 14:08:45 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2011-01-02 14:08:13 | 000,033,280 | ---- | M] () -- C:\Documents and Settings\emoss\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-01-01 14:40:24 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010-12-26 02:08:23 | 000,111,784 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010-12-25 21:52:44 | 001,043,386 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010-12-25 21:52:44 | 000,490,628 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2010-12-25 21:52:44 | 000,432,492 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010-12-25 21:52:44 | 000,083,880 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2010-12-25 21:52:44 | 000,067,448 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010-12-25 18:11:54 | 000,139,096 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010-12-18 14:17:27 | 000,000,154 | ---- | M] () -- C:\WINDOWS\adidsl.ini
[2010-12-18 14:17:27 | 000,000,023 | ---- | M] () -- C:\WINDOWS\System32\drivers\adidsl.cfg
[2010-12-16 18:20:43 | 000,000,998 | ---- | M] () -- C:\WINDOWS\adiras.ini
[2010-12-16 18:20:43 | 000,000,021 | ---- | M] () -- C:\WINDOWS\Fast800.ini
[2010-12-16 18:20:37 | 000,000,836 | ---- | M] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\DSLMON.lnk
[2010-12-06 13:49:25 | 000,000,630 | ---- | M] () -- C:\Documents and Settings\emoss\Pulpit\MoorHunt.lnk
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2011-01-03 23:05:17 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\emoss\Pulpit\3. Ten typ tak ma.mp3
[2010-12-16 18:20:43 | 000,000,154 | ---- | C] () -- C:\WINDOWS\adidsl.ini
[2010-12-16 18:20:43 | 000,000,021 | ---- | C] () -- C:\WINDOWS\Fast800.ini
[2010-12-16 18:20:37 | 000,000,836 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\DSLMON.lnk
[2010-12-16 18:20:35 | 001,531,904 | ---- | C] () -- C:\WINDOWS\adiras.exe
[2010-12-16 18:20:35 | 000,127,456 | ---- | C] () -- C:\WINDOWS\System32\ipdetect.exe
[2010-12-16 18:20:35 | 000,011,961 | ---- | C] () -- C:\WINDOWS\System32\drivers\adiusbaw.cat
[2010-12-16 18:20:30 | 000,261,932 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld0.bnm
[2010-12-16 18:20:30 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\coclassfast.dll
[2010-12-16 18:20:30 | 000,046,892 | ---- | C] () -- C:\WINDOWS\System32\adadix16.dll
[2010-12-16 18:20:30 | 000,008,208 | ---- | C] () -- C:\WINDOWS\System32\drivers\adildr.cat
[2010-12-16 18:20:30 | 000,000,023 | ---- | C] () -- C:\WINDOWS\System32\drivers\adidsl.cfg
[2010-12-16 18:20:29 | 000,261,964 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld9i1.bnm
[2010-12-16 18:20:29 | 000,261,962 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld9p3.bnm
[2010-12-16 18:20:29 | 000,261,960 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld9i0.bnm
[2010-12-16 18:20:29 | 000,261,952 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld9p1.bnm
[2010-12-16 18:20:29 | 000,261,952 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld3.bnm
[2010-12-16 18:20:29 | 000,261,930 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld9p0.bnm
[2010-12-16 18:20:29 | 000,261,926 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld9p2.bnm
[2010-12-16 18:20:29 | 000,261,920 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld2.bnm
[2010-12-16 18:20:29 | 000,261,918 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld9i2.bnm
[2010-12-16 18:20:29 | 000,261,912 | R--- | C] () -- C:\WINDOWS\System32\drivers\rtbldei0.bnm
[2010-12-16 18:20:29 | 000,261,894 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld1.bnm
[2010-12-16 18:20:29 | 000,055,228 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld4.bnm
[2010-12-16 18:20:29 | 000,053,590 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld9i4.bnm
[2010-12-16 18:20:29 | 000,041,620 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtbld9p4.bnm
[2010-12-16 18:20:28 | 000,261,948 | R--- | C] () -- C:\WINDOWS\System32\drivers\rtbldei3.bnm
[2010-12-16 18:20:28 | 000,261,946 | R--- | C] () -- C:\WINDOWS\System32\drivers\rtbldei1.bnm
[2010-12-16 18:20:28 | 000,261,920 | R--- | C] () -- C:\WINDOWS\System32\drivers\rtbldei2.bnm
[2010-12-16 18:20:28 | 000,261,912 | R--- | C] () -- C:\WINDOWS\System32\drivers\rtbldep0.bnm
[2010-12-16 18:20:28 | 000,261,910 | R--- | C] () -- C:\WINDOWS\System32\drivers\rtbldep3.bnm
[2010-12-16 18:20:28 | 000,261,906 | R--- | C] () -- C:\WINDOWS\System32\drivers\rtbldep2.bnm
[2010-12-16 18:20:28 | 000,261,902 | R--- | C] () -- C:\WINDOWS\System32\drivers\rtbldep1.bnm
[2010-12-16 18:20:28 | 000,143,360 | ---- | C] () -- C:\WINDOWS\autoclk.exe
[2010-12-16 18:20:28 | 000,079,334 | R--- | C] () -- C:\WINDOWS\System32\drivers\rtbldep4.bnm
[2010-12-16 18:20:28 | 000,072,072 | R--- | C] () -- C:\WINDOWS\System32\drivers\rtbldei4.bnm
[2010-12-16 18:20:28 | 000,022,395 | ---- | C] () -- C:\WINDOWS\System32\drivers\fpga.bin
[2010-03-08 23:30:53 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009-11-11 14:59:18 | 000,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009-11-11 14:59:18 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2009-11-11 14:59:16 | 000,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009-11-11 14:59:16 | 000,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009-11-11 14:59:15 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2009-11-11 14:59:14 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009-11-11 14:59:14 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009-11-04 18:57:40 | 000,139,096 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009-10-25 16:09:54 | 000,033,280 | ---- | C] () -- C:\Documents and Settings\emoss\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-10-15 22:39:50 | 000,000,221 | ---- | C] () -- C:\WINDOWS\NCLogConfig.ini
[2009-10-15 22:30:23 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\HPZIDS01.dll
[2009-10-15 22:23:39 | 000,000,749 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\hpzinstall.log
[2009-10-12 00:40:48 | 001,043,386 | ---- | C] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009-10-12 00:40:47 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009-10-12 00:40:08 | 000,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\desktop.ini
[2009-10-11 23:27:01 | 000,015,992 | ---- | C] () -- C:\Documents and Settings\emoss\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
[2009-10-11 23:25:04 | 000,000,998 | ---- | C] () -- C:\WINDOWS\adiras.ini
[2009-10-11 23:11:59 | 001,579,550 | -H-- | C] () -- C:\Documents and Settings\emoss\Ustawienia lokalne\Dane aplikacji\IconCache.db
[2009-10-11 23:08:21 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2009-10-11 22:59:08 | 000,000,062 | -HS- | C] () -- C:\Documents and Settings\emoss\Dane aplikacji\desktop.ini
[2009-10-11 22:51:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\control.ini
[2009-10-11 22:47:20 | 000,000,037 | ---- | C] () -- C:\WINDOWS\vbaddin.ini
[2009-10-11 22:47:20 | 000,000,036 | ---- | C] () -- C:\WINDOWS\vb.ini
[2009-10-11 22:46:43 | 000,026,717 | ---- | C] () -- C:\WINDOWS\System32\tslabels.ini
[2009-10-11 22:46:42 | 000,003,813 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.ini
[2006-09-13 19:17:44 | 000,157,696 | ---- | C] () -- C:\WINDOWS\System32\paqsp.dll
[2004-08-04 01:44:10 | 000,270,848 | ---- | C] () -- C:\WINDOWS\System32\sbe.dll
[2004-08-04 01:44:04 | 000,014,336 | ---- | C] () -- C:\WINDOWS\System32\msdmo.dll
[2004-08-04 01:43:58 | 000,186,880 | ---- | C] () -- C:\WINDOWS\System32\encdec.dll
[2004-08-04 01:43:56 | 000,253,440 | ---- | C] () -- C:\WINDOWS\System32\compatui.dll
[2004-08-04 01:43:54 | 000,070,656 | ---- | C] () -- C:\WINDOWS\System32\amstream.dll
[2004-08-04 01:43:16 | 000,733,696 | ---- | C] () -- C:\WINDOWS\System32\qedwipes.dll
[2004-08-03 23:46:56 | 000,042,537 | ---- | C] () -- C:\WINDOWS\System32\keyboard.sys
[2004-08-03 23:45:34 | 000,033,936 | ---- | C] () -- C:\WINDOWS\System32\ntio.sys
[2004-08-03 23:45:16 | 000,035,424 | ---- | C] () -- C:\WINDOWS\System32\ntio412.sys
[2004-08-03 23:45:16 | 000,034,560 | ---- | C] () -- C:\WINDOWS\System32\ntio404.sys
[2004-08-03 23:45:14 | 000,034,560 | ---- | C] () -- C:\WINDOWS\System32\ntio804.sys
[2004-08-03 23:45:12 | 000,035,648 | ---- | C] () -- C:\WINDOWS\System32\ntio411.sys
[2004-07-17 12:46:14 | 000,053,478 | ---- | C] () -- C:\WINDOWS\System32\tcpmon.ini
[2004-07-17 12:34:48 | 000,355,112 | ---- | C] () -- C:\WINDOWS\System32\msjetoledb40.dll
[2001-10-26 20:29:40 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\scriptpw.dll
[2001-10-26 20:29:32 | 000,199,168 | ---- | C] () -- C:\WINDOWS\System32\ir32_32.dll
[2001-10-26 20:28:34 | 000,094,282 | ---- | C] () -- C:\WINDOWS\System32\msencode.dll
[2001-10-26 20:27:02 | 000,015,360 | ---- | C] () -- C:\WINDOWS\System32\tsd32.dll
[2001-10-26 19:15:04 | 000,027,898 | ---- | C] () -- C:\WINDOWS\System32\ntdos.sys
[2001-10-26 19:14:52 | 000,004,976 | ---- | C] () -- C:\WINDOWS\System32\himem.sys
[2001-10-26 19:14:32 | 000,009,043 | ---- | C] () -- C:\WINDOWS\System32\ansi.sys
[2001-10-26 19:12:52 | 000,000,359 | ---- | C] () -- C:\WINDOWS\System32\prodspec.ini
[2001-10-26 18:45:26 | 000,016,024 | ---- | C] () -- C:\WINDOWS\System32\rsvp.ini
[2001-10-26 18:45:26 | 000,006,074 | ---- | C] () -- C:\WINDOWS\System32\rasctrs.ini
[2001-10-26 18:45:24 | 000,013,819 | ---- | C] () -- C:\WINDOWS\System32\pschdprf.ini
[2001-10-26 18:42:08 | 000,020,629 | ---- | C] () -- C:\WINDOWS\System32\mqperf.ini
[2001-10-26 18:42:08 | 000,002,992 | ---- | C] () -- C:\WINDOWS\System32\perfci.ini
[2001-10-26 18:42:08 | 000,002,890 | ---- | C] () -- C:\WINDOWS\System32\perfwci.ini
[2001-10-26 18:42:08 | 000,001,295 | ---- | C] () -- C:\WINDOWS\System32\perffilt.ini
[2001-08-18 00:31:56 | 000,042,809 | ---- | C] () -- C:\WINDOWS\System32\key01.sys
[2001-08-18 00:31:56 | 000,027,097 | ---- | C] () -- C:\WINDOWS\System32\country.sys
[2001-08-18 00:31:50 | 000,029,274 | ---- | C] () -- C:\WINDOWS\System32\ntdos412.sys
[2001-08-18 00:31:46 | 000,029,370 | ---- | C] () -- C:\WINDOWS\System32\ntdos411.sys
[2001-08-18 00:31:46 | 000,029,146 | ---- | C] () -- C:\WINDOWS\System32\ntdos404.sys
[2001-08-18 00:31:44 | 000,029,146 | ---- | C] () -- C:\WINDOWS\System32\ntdos804.sys
[2001-08-18 00:13:24 | 000,002,656 | ---- | C] () -- C:\WINDOWS\System32\netware.drv
[2001-08-17 22:55:06 | 001,015,477 | ---- | C] () -- C:\WINDOWS\System32\esentprf.ini
[2001-07-22 05:25:18 | 000,001,405 | ---- | C] () -- C:\WINDOWS\msdfmap.ini
[2001-07-22 01:16:20 | 000,000,532 | ---- | C] () -- C:\WINDOWS\win.ini
[2001-07-22 01:15:52 | 000,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2001-07-22 01:15:50 | 000,013,312 | ---- | C] () -- C:\WINDOWS\System32\win87em.dll
[2001-07-07 02:00:02 | 000,003,234 | ---- | C] () -- C:\WINDOWS\System32\HPTCPMON.INI
[color=#E56717]========== Custom Scans ==========[/color]
[color=#A23BEC]< %systemdrive%\*.* >[/color]
[2009-10-11 22:51:05 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010-04-01 21:48:59 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2001-07-22 01:13:54 | 000,004,952 | RHS- | M] () -- C:\Bootfont.bin
[2009-10-11 22:51:05 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2011-01-03 21:26:13 | 267,968,512 | -HS- | M] () -- C:\hiberfil.sys
[2009-10-11 22:51:05 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2009-10-11 22:51:05 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004-08-03 23:38:34 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009-10-23 22:49:45 | 000,251,152 | RHS- | M] () -- C:\ntldr
[2011-01-03 22:54:52 | 402,653,184 | -HS- | M] () -- C:\pagefile.sys
[color=#A23BEC]< MD5 for: AGP440.SYS >[/color]
[2006-09-13 18:13:16 | 016,728,567 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:agp440.sys
[2009-10-23 22:45:44 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:agp440.sys
[2009-10-23 22:45:44 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:agp440.sys
[2008-04-13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008-04-13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[color=#A23BEC]< MD5 for: ATAPI.SYS >[/color]
[2006-09-13 18:13:16 | 016,728,567 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009-10-23 22:45:44 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009-10-23 22:45:44 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008-04-13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008-04-13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004-08-03 23:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[color=#A23BEC]< MD5 for: BEEP.SYS >[/color]
[2001-08-18 00:47:36 | 000,004,224 | ---- | M] (Microsoft Corporation) MD5=DA1F27D85E0D1525F6621372E7B685E9 -- C:\WINDOWS\system32\drivers\beep.sys
[color=#A23BEC]< MD5 for: CDROM.SYS >[/color]
[2006-09-13 18:13:16 | 016,728,567 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2009-10-23 22:45:44 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:cdrom.sys
[2009-10-23 22:45:44 | 023,908,281 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:cdrom.sys
[2008-04-13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\ServicePackFiles\i386\cdrom.sys
[2008-04-13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\system32\drivers\cdrom.sys
[2004-08-03 23:59:54 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys
[color=#A23BEC]< MD5 for: NDIS.SYS >[/color]
[2008-04-13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\ServicePackFiles\i386\ndis.sys
[2008-04-13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\system32\drivers\ndis.sys
[2004-08-04 00:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
[color=#A23BEC]< MD5 for: USERINIT.EXE >[/color]
[2008-04-14 18:21:45 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=2A5B37D520508BE6570A3EA79695F5B5 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008-04-14 18:21:45 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=2A5B37D520508BE6570A3EA79695F5B5 -- C:\WINDOWS\system32\userinit.exe
[2004-08-04 01:44:30 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=BD768099B4C44AA631728CB74EB54396 -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color]
[2004-08-04 01:44:30 | 000,504,832 | ---- | M] (Microsoft Corporation) MD5=0344407089B08548D4FEBA62BB0F32D0 -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008-04-14 18:21:48 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008-04-14 18:21:48 | 000,510,464 | ---- | M] (Microsoft Corporation) MD5=51FD2E13D723857B9CA239AE77150F48 -- C:\WINDOWS\system32\winlogon.exe
< End of report >
|