SDFix: Version 1.114
Run by Administrator on 2007-11-12 at 20:35
Microsoft Windows XP [Wersja 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\TEMP\WIN1.TMP - Deleted
C:\WINDOWS\TEMP\WIN10.TMP - Deleted
C:\WINDOWS\TEMP\WIN11.TMP - Deleted
C:\WINDOWS\TEMP\WIN12.TMP - Deleted
C:\WINDOWS\TEMP\WIN13.TMP - Deleted
C:\WINDOWS\TEMP\WIN14.TMP - Deleted
C:\WINDOWS\TEMP\WIN15.TMP - Deleted
C:\WINDOWS\TEMP\WIN16.TMP - Deleted
C:\WINDOWS\TEMP\WIN17.TMP - Deleted
C:\WINDOWS\TEMP\WIN18.TMP - Deleted
C:\WINDOWS\TEMP\WIN19.TMP - Deleted
C:\WINDOWS\TEMP\WIN1A.TMP - Deleted
C:\WINDOWS\TEMP\WIN1B.TMP - Deleted
C:\WINDOWS\TEMP\WIN1D.TMP - Deleted
C:\WINDOWS\TEMP\WIN1E.TMP - Deleted
C:\WINDOWS\TEMP\WIN1F.TMP - Deleted
C:\WINDOWS\TEMP\WIN2.TMP - Deleted
C:\WINDOWS\TEMP\WIN20.TMP - Deleted
C:\WINDOWS\TEMP\WIN21.TMP - Deleted
C:\WINDOWS\TEMP\WIN22.TMP - Deleted
C:\WINDOWS\TEMP\WIN23.TMP - Deleted
C:\WINDOWS\TEMP\WIN24.TMP - Deleted
C:\WINDOWS\TEMP\WIN25.TMP - Deleted
C:\WINDOWS\TEMP\WIN26.TMP - Deleted
C:\WINDOWS\TEMP\WIN2C.TMP - Deleted
C:\WINDOWS\TEMP\WIN2D.TMP - Deleted
C:\WINDOWS\TEMP\WIN2E.TMP - Deleted
C:\WINDOWS\TEMP\WIN3.TMP - Deleted
C:\WINDOWS\TEMP\WIN31.TMP - Deleted
C:\WINDOWS\TEMP\WIN32.TMP - Deleted
C:\WINDOWS\TEMP\WIN34.TMP - Deleted
C:\WINDOWS\TEMP\WIN35.TMP - Deleted
C:\WINDOWS\TEMP\WIN36.TMP - Deleted
C:\WINDOWS\TEMP\WIN37.TMP - Deleted
C:\WINDOWS\TEMP\WIN3D.TMP - Deleted
C:\WINDOWS\TEMP\WIN3E.TMP - Deleted
C:\WINDOWS\TEMP\WIN3F.TMP - Deleted
C:\WINDOWS\TEMP\WIN4.TMP - Deleted
C:\WINDOWS\TEMP\WIN40.TMP - Deleted
C:\WINDOWS\TEMP\WIN41.TMP - Deleted
C:\WINDOWS\TEMP\WIN42.TMP - Deleted
C:\WINDOWS\TEMP\WIN43.TMP - Deleted
C:\WINDOWS\TEMP\WIN44.TMP - Deleted
C:\WINDOWS\TEMP\WIN45.TMP - Deleted
C:\WINDOWS\TEMP\WIN46.TMP - Deleted
C:\WINDOWS\TEMP\WIN48.TMP - Deleted
C:\WINDOWS\TEMP\WIN49.TMP - Deleted
C:\WINDOWS\TEMP\WIN4A.TMP - Deleted
C:\WINDOWS\TEMP\WIN4B.TMP - Deleted
C:\WINDOWS\TEMP\WIN4C.TMP - Deleted
C:\WINDOWS\TEMP\WIN4D.TMP - Deleted
C:\WINDOWS\TEMP\WIN4E.TMP - Deleted
C:\WINDOWS\TEMP\WIN4F.TMP - Deleted
C:\WINDOWS\TEMP\WIN5.TMP - Deleted
C:\WINDOWS\TEMP\WIN50.TMP - Deleted
C:\WINDOWS\TEMP\WIN51.TMP - Deleted
C:\WINDOWS\TEMP\WIN52.TMP - Deleted
C:\WINDOWS\TEMP\WIN53.TMP - Deleted
C:\WINDOWS\TEMP\WIN54.TMP - Deleted
C:\WINDOWS\TEMP\WIN55.TMP - Deleted
C:\WINDOWS\TEMP\WIN57.TMP - Deleted
C:\WINDOWS\TEMP\WIN58.TMP - Deleted
C:\WINDOWS\TEMP\WIN59.TMP - Deleted
C:\WINDOWS\TEMP\WIN5A.TMP - Deleted
C:\WINDOWS\TEMP\WIN5B.TMP - Deleted
C:\WINDOWS\TEMP\WIN5C.TMP - Deleted
C:\WINDOWS\TEMP\WIN5D.TMP - Deleted
C:\WINDOWS\TEMP\WIN5E.TMP - Deleted
C:\WINDOWS\TEMP\WIN5F.TMP - Deleted
C:\WINDOWS\TEMP\WIN6.TMP - Deleted
C:\WINDOWS\TEMP\WIN60.TMP - Deleted
C:\WINDOWS\TEMP\WIN61.TMP - Deleted
C:\WINDOWS\TEMP\WIN62.TMP - Deleted
C:\WINDOWS\TEMP\WIN63.TMP - Deleted
C:\WINDOWS\TEMP\WIN64.TMP - Deleted
C:\WINDOWS\TEMP\WIN65.TMP - Deleted
C:\WINDOWS\TEMP\WIN66.TMP - Deleted
C:\WINDOWS\TEMP\WIN67.TMP - Deleted
C:\WINDOWS\TEMP\WIN68.TMP - Deleted
C:\WINDOWS\TEMP\WIN69.TMP - Deleted
C:\WINDOWS\TEMP\WIN6A.TMP - Deleted
C:\WINDOWS\TEMP\WIN6C.TMP - Deleted
C:\WINDOWS\TEMP\WIN6D.TMP - Deleted
C:\WINDOWS\TEMP\WIN6E.TMP - Deleted
C:\WINDOWS\TEMP\WIN6F.TMP - Deleted
C:\WINDOWS\TEMP\WIN7.TMP - Deleted
C:\WINDOWS\TEMP\WIN70.TMP - Deleted
C:\WINDOWS\TEMP\WIN71.TMP - Deleted
C:\WINDOWS\TEMP\WIN72.TMP - Deleted
C:\WINDOWS\TEMP\WIN73.TMP - Deleted
C:\WINDOWS\TEMP\WIN74.TMP - Deleted
C:\WINDOWS\TEMP\WIN75.TMP - Deleted
C:\WINDOWS\TEMP\WIN76.TMP - Deleted
C:\WINDOWS\TEMP\WIN77.TMP - Deleted
C:\WINDOWS\TEMP\WIN78.TMP - Deleted
C:\WINDOWS\TEMP\WIN79.TMP - Deleted
C:\WINDOWS\TEMP\WIN7A.TMP - Deleted
C:\WINDOWS\TEMP\WIN7B.TMP - Deleted
C:\WINDOWS\TEMP\WIN7C.TMP - Deleted
C:\WINDOWS\TEMP\WIN7D.TMP - Deleted
C:\WINDOWS\TEMP\WIN7E.TMP - Deleted
C:\WINDOWS\TEMP\WIN7F.TMP - Deleted
C:\WINDOWS\TEMP\WIN8.TMP - Deleted
C:\WINDOWS\TEMP\WIN80.TMP - Deleted
C:\WINDOWS\TEMP\WIN81.TMP - Deleted
C:\WINDOWS\TEMP\WIN82.TMP - Deleted
C:\WINDOWS\TEMP\WIN83.TMP - Deleted
C:\WINDOWS\TEMP\WIN84.TMP - Deleted
C:\WINDOWS\TEMP\WIN85.TMP - Deleted
C:\WINDOWS\TEMP\WIN86.TMP - Deleted
C:\WINDOWS\TEMP\WIN87.TMP - Deleted
C:\WINDOWS\TEMP\WIN88.TMP - Deleted
C:\WINDOWS\TEMP\WIN89.TMP - Deleted
C:\WINDOWS\TEMP\WIN8A.TMP - Deleted
C:\WINDOWS\TEMP\WIN8C.TMP - Deleted
C:\WINDOWS\TEMP\WIN8D.TMP - Deleted
C:\WINDOWS\TEMP\WIN8E.TMP - Deleted
C:\WINDOWS\TEMP\WIN8F.TMP - Deleted
C:\WINDOWS\TEMP\WIN90.TMP - Deleted
C:\WINDOWS\TEMP\WIN91.TMP - Deleted
C:\WINDOWS\TEMP\WIN92.TMP - Deleted
C:\WINDOWS\TEMP\WIN93.TMP - Deleted
C:\WINDOWS\TEMP\WIN94.TMP - Deleted
C:\WINDOWS\TEMP\WIN95.TMP - Deleted
C:\WINDOWS\TEMP\WIN96.TMP - Deleted
C:\WINDOWS\TEMP\WIN97.TMP - Deleted
C:\WINDOWS\TEMP\WIN98.TMP - Deleted
C:\WINDOWS\TEMP\WIN99.TMP - Deleted
C:\WINDOWS\TEMP\WIN9A.TMP - Deleted
C:\WINDOWS\TEMP\WIN9B.TMP - Deleted
C:\WINDOWS\TEMP\WIN9C.TMP - Deleted
C:\WINDOWS\TEMP\WIN9D.TMP - Deleted
C:\WINDOWS\TEMP\WIN9E.TMP - Deleted
C:\WINDOWS\TEMP\WIN9F.TMP - Deleted
C:\WINDOWS\TEMP\WINA.TMP - Deleted
C:\WINDOWS\TEMP\WINA0.TMP - Deleted
C:\WINDOWS\TEMP\WINA1.TMP - Deleted
C:\WINDOWS\TEMP\WINA2.TMP - Deleted
C:\WINDOWS\TEMP\WINA3.TMP - Deleted
C:\WINDOWS\TEMP\WINA4.TMP - Deleted
C:\WINDOWS\TEMP\WINA5.TMP - Deleted
C:\WINDOWS\TEMP\WINA6.TMP - Deleted
C:\WINDOWS\TEMP\WINA7.TMP - Deleted
C:\WINDOWS\TEMP\WINA8.TMP - Deleted
C:\WINDOWS\TEMP\WINA9.TMP - Deleted
C:\WINDOWS\TEMP\WINAA.TMP - Deleted
C:\WINDOWS\TEMP\WINAB.TMP - Deleted
C:\WINDOWS\TEMP\WINAC.TMP - Deleted
C:\WINDOWS\TEMP\WINAD.TMP - Deleted
C:\WINDOWS\TEMP\WINAE.TMP - Deleted
C:\WINDOWS\TEMP\WINAF.TMP - Deleted
C:\WINDOWS\TEMP\WINB.TMP - Deleted
C:\WINDOWS\TEMP\WINB0.TMP - Deleted
C:\WINDOWS\TEMP\WINB1.TMP - Deleted
C:\WINDOWS\TEMP\WINB2.TMP - Deleted
C:\WINDOWS\TEMP\WINB3.TMP - Deleted
C:\WINDOWS\TEMP\WINB4.TMP - Deleted
C:\WINDOWS\TEMP\WINB5.TMP - Deleted
C:\WINDOWS\TEMP\WINB6.TMP - Deleted
C:\WINDOWS\TEMP\WINB7.TMP - Deleted
C:\WINDOWS\TEMP\WINB8.TMP - Deleted
C:\WINDOWS\TEMP\WINBA.TMP - Deleted
C:\WINDOWS\TEMP\WINBB.TMP - Deleted
C:\WINDOWS\TEMP\WINBC.TMP - Deleted
C:\WINDOWS\TEMP\WINBD.TMP - Deleted
C:\WINDOWS\TEMP\WINBE.TMP - Deleted
C:\WINDOWS\TEMP\WINBF.TMP - Deleted
C:\WINDOWS\TEMP\WINC.TMP - Deleted
C:\WINDOWS\TEMP\WINC0.TMP - Deleted
C:\WINDOWS\TEMP\WINC1.TMP - Deleted
C:\WINDOWS\TEMP\WINC2.TMP - Deleted
C:\WINDOWS\TEMP\WINC4.TMP - Deleted
C:\WINDOWS\TEMP\WINC7.TMP - Deleted
C:\WINDOWS\TEMP\WINC8.TMP - Deleted
C:\WINDOWS\TEMP\WINC9.TMP - Deleted
C:\WINDOWS\TEMP\WINCA.TMP - Deleted
C:\WINDOWS\TEMP\WINCB.TMP - Deleted
C:\WINDOWS\TEMP\WINCC.TMP - Deleted
C:\WINDOWS\TEMP\WINCD.TMP - Deleted
C:\WINDOWS\TEMP\WINCE.TMP - Deleted
C:\WINDOWS\TEMP\WINCF.TMP - Deleted
C:\WINDOWS\TEMP\WIND.TMP - Deleted
C:\WINDOWS\TEMP\WIND0.TMP - Deleted
C:\WINDOWS\TEMP\WIND1.TMP - Deleted
C:\WINDOWS\TEMP\WIND2.TMP - Deleted
C:\WINDOWS\TEMP\WIND3.TMP - Deleted
C:\WINDOWS\TEMP\WINE.TMP - Deleted
C:\WINDOWS\TEMP\WINF.TMP - Deleted
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-12 20:43:26
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A\1\5\1c]
"Order"=hex:08,00,00,00,02,00,00,00,b8,01,00,00,01,00,00,00,04,00,00,00,8c,..
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\\Programs\\Microsoft Office\\Office12\\ONENOTE.EXE"="D:\\Programs\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\Gadu-Gadu\\gg.exe"="C:\\Program Files\\Gadu-Gadu\\gg.exe:*:Enabled:Gadu-Gadu - program gˆ˘wny"
"C:\\Program Files\\Tlen.pl\\tlen.exe"="C:\\Program Files\\Tlen.pl\\tlen.exe:*:Enabled:Komunikator Tlen.pl"
"D:\\Programs\\Azureus\\Azureus.exe"="D:\\Programs\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"D:\\Programs\\eMule\\emule.exe"="D:\\Programs\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:uTorrent"
"C:\\DOCUME~1\\MACIEK~1.HOM\\USTAWI~1\\Temp\\win29.exe"="C:\\DOCUME~1\\MACIEK~1.HOM\\USTAWI~1\\Temp\\win29.exe:*:Enabled:win29"
"C:\\WINDOWS\\system32\\wyoibytm.exe"="C:\\WINDOWS\\system32\\wyo"
"C:\\WINDOWS\\TEMP\\winC6.exe"="C:\\WINDOWS\\TEMP\\winC6.exe:*:Enabled:winC6"
"C:\\WINDOWS\\system32\\ndvrxgug.exe"="C:\\WINDOWS\\system32\\ndv"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files:
---------------
C:\WINDOWS\TEMP\WIN3.TMP Found
C:\WINDOWS\TEMP\WIN4.TMP Found
C:\WINDOWS\TEMP\WIN5.TMP Found
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Wed 4 Aug 2004 3,555,328 A..H. --- "C:\Program Files\Movie Maker\moviemk.exe"
Fri 26 Oct 2001 110,657 A..H. --- "C:\Program Files\Movie Maker\wmmfilt.dll"
Fri 26 Oct 2001 327,743 A..H. --- "C:\Program Files\Movie Maker\wmmres.dll"
Fri 26 Oct 2001 163,906 A..H. --- "C:\Program Files\Movie Maker\wmmutil.dll"
Wed 4 Aug 2004 385,024 A..H. --- "C:\Program Files\NetMeeting\callcont.dll"
Fri 26 Oct 2001 12,288 A..H. --- "C:\Program Files\NetMeeting\cb32.exe"
Wed 4 Aug 2004 1,036,288 A..H. --- "C:\Program Files\NetMeeting\conf.exe"
Wed 4 Aug 2004 45,056 A..H. --- "C:\Program Files\NetMeeting\confmrsl.dll"
Wed 4 Aug 2004 40,960 A..H. --- "C:\Program Files\NetMeeting\dcap32.dll"
Wed 4 Aug 2004 57,344 A..H. --- "C:\Program Files\NetMeeting\h323cc.dll"
Wed 4 Aug 2004 274,432 A..H. --- "C:\Program Files\NetMeeting\mst120.dll"
Wed 4 Aug 2004 57,344 A..H. --- "C:\Program Files\NetMeeting\mst123.dll"
Wed 4 Aug 2004 221,184 A..H. --- "C:\Program Files\NetMeeting\nac.dll"
Wed 4 Aug 2004 229,376 A..H. --- "C:\Program Files\NetMeeting\nmas.dll"
Wed 4 Aug 2004 28,672 A..H. --- "C:\Program Files\NetMeeting\nmasnt.dll"
Wed 4 Aug 2004 81,920 A..H. --- "C:\Program Files\NetMeeting\nmchat.dll"
Wed 4 Aug 2004 77,824 A..H. --- "C:\Program Files\NetMeeting\nmcom.dll"
Wed 4 Aug 2004 151,552 A..H. --- "C:\Program Files\NetMeeting\nmft.dll"
Wed 4 Aug 2004 172,032 A..H. --- "C:\Program Files\NetMeeting\nmoldwb.dll"
Wed 4 Aug 2004 188,416 A..H. --- "C:\Program Files\NetMeeting\nmwb.dll"
Wed 4 Aug 2004 61,440 A..H. --- "C:\Program Files\NetMeeting\rrcm.dll"
Fri 26 Oct 2001 12,288 A..H. --- "C:\Program Files\NetMeeting\wb32.exe"
Mon 12 Nov 2007 20,640 ..SH. --- "C:\WINDOWS\system32\rwwendug.dllbox"
Sat 24 Mar 2007 13 ...H. --- "C:\Documents and Settings\All Users\Dane aplikacji\íŢĆŽ3113>.sys"
Tue 5 Dec 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 26 Oct 2001 77,824 A..H. --- "C:\Program Files\MSN\MSNCoreFiles\copymar.exe"
Fri 26 Oct 2001 72,104 A..H. --- "C:\Program Files\MSN\MSNCoreFiles\csapi3t1.dll"
Fri 26 Oct 2001 24,576 A..H. --- "C:\Program Files\MSN\MSNCoreFiles\custdial.dll"
Fri 26 Oct 2001 161,184 A..H. --- "C:\Program Files\MSN\MSNCoreFiles\dw.exe"
Fri 26 Oct 2001 245,760 A..H. --- "C:\Program Files\MSN\MSNCoreFiles\logonmgr.dll"
Fri 26 Oct 2001 53,248 A..H. --- "C:\Program Files\MSN\MSNCoreFiles\migrate.dll"
Fri 26 Oct 2001 65,536 A..H. --- "C:\Program Files\MSN\MSNCoreFiles\msdbx.dll"
Fri 26 Oct 2001 372,736 A..H. --- "C:\Program Files\MSN\MSNCoreFiles\msmom.dll"
Fri 26 Oct 2001 90,112 A..H. --- "C:\Program Files\MSN\MSNCoreFiles\msn6.exe"
Fri 26 Oct 2001 1,032,192 A..H. --- "C:\Program Files\MSN\MSNCoreFiles\msnmetal.dll"
Fri 26 Oct 2001 90,112 A..H. --- "C:\Program Files\MSN\MSNCoreFiles\msnmtllc.dll"
Fri 26 Oct 2001 94,208 A..H. --- "C:\Program Files\MSN\MSNCoreFiles\msnspell.dll"
Fri 26 Oct 2001 90,112 A..H. --- "C:\Program Files\MSN\MSNCoreFiles\popc.dll"
Fri 26 Oct 2001 141,736 A..H. --- "C:\Program Files\MSN\MSNCoreFiles\sqdll.dll"
Fri 26 Oct 2001 77,824 A..H. --- "C:\Program Files\MSN\MSNCoreFiles\update.exe"
Fri 26 Oct 2001 82,501 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\bckg.dll"
Fri 26 Oct 2001 1,817,687 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\bckgres.dll"
Fri 26 Oct 2001 42,577 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\bckgzm.exe"
Fri 26 Oct 2001 40,515 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\chkr.dll"
Fri 26 Oct 2001 781,397 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\chkrres.dll"
Fri 26 Oct 2001 42,575 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\chkrzm.exe"
Fri 26 Oct 2001 217,160 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\Cmnclim.dll"
Fri 26 Oct 2001 1,041,491 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\Cmnresm.dll"
Fri 26 Oct 2001 57,409 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\hrtz.dll"
Fri 26 Oct 2001 1,175,635 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\Hrtzres.dll"
Fri 26 Oct 2001 42,573 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.exe"
Fri 26 Oct 2001 48,706 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\rvse.dll"
Fri 26 Oct 2001 753,236 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\Rvseres.dll"
Fri 26 Oct 2001 42,574 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\Rvsezm.exe"
Fri 26 Oct 2001 66,113 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\shvl.dll"
Fri 26 Oct 2001 2,178,131 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\Shvlres.dll"
Fri 26 Oct 2001 42,573 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\shvlzm.exe"
Fri 26 Oct 2001 32,339 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\UniAnsi.dll"
Fri 26 Oct 2001 36,937 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\zClientm.exe"
Fri 26 Oct 2001 41,029 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\ZCorem.dll"
Fri 26 Oct 2001 4,677 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\zeeverm.dll"
Fri 26 Oct 2001 29,760 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\ZNetM.dll"
Fri 26 Oct 2001 113,222 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\zoneclim.dll"
Fri 26 Oct 2001 13,894 A..H. --- "C:\Program Files\MSN Gaming Zone\Windows\zonelibM.dll"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico1.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico10.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico11.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico12.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico13.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico14.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico15.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico16.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico17.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico18.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico19.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico1A.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico1B.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico1C.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico1D.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico1E.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico1F.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico2.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico20.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico21.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico22.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico23.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico24.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico25.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico26.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico27.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico28.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico29.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico2A.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico2B.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico2C.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico2D.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico2E.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico2F.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico3.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico30.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico31.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico32.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico3C.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico3D.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico3E.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico3F.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico4.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico40.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico41.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico42.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico43.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico44.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico45.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico4B.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico4C.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico4D.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico4E.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico4F.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico5.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico50.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico51.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico52.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico53.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico54.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico56.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico57.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico58.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico59.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico5A.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico5B.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico5C.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico5D.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico5E.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico5F.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico6.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico62.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico63.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico64.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico65.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico66.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico67.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico68.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico69.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico6A.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico6B.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico6C.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico6D.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico6E.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico6F.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico7.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico70.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico73.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico74.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico75.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico76.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico77.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico78.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico79.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico7A.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico7B.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico7C.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico8.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico82.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico83.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico84.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico85.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico86.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico87.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico88.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico89.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico8A.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico8B.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico9.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico98.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico99.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico9A.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico9B.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico9C.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoA.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoB.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoC.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoD.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoE.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoF.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico1.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico10.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico2.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico27.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico28.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico29.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico2A.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico2B.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico3.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico38.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico39.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico3A.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico3B.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico3C.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico4.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico5.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico7.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico8.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\ico9.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoA.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoB.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoBA.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoBB.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoBC.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoBD.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoBE.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoC.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoD.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoD6.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoD7.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoD8.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoD9.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoDA.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoDB.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoDC.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoDD.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoDE.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoDF.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoE.tmp"
Mon 12 Nov 2007 4,286 A..H. --- "C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ustawienia lokalne\Temp\icoF.tmp"
Fri 26 Oct 2001 55,440 A..H. --- "C:\Program Files\MSN\MSNCoreFiles\1045\dwintl.dll"
Fri 26 Oct 2001 28,672 A..H. --- "C:\Program Files\MSN\MSNCoreFiles\Setup\migrate.dll"
Fri 26 Oct 2001 6,656 A..H. --- "C:\Program Files\MSN\MSNCoreFiles\Setup\msn9xmig.dll"
Fri 26 Oct 2001 32,768 A..H. --- "C:\Program Files\MSN\MSNCoreFiles\Setup\msnunin.exe"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\066f4c6032ec52b2d0460047fd5c67aa\BIT44.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\076f1aa5a201db5b428fbe164817aab2\BIT4B.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0d5de1cd7fc62d3668ea0afcc642fb24\BIT42.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\1679cd06c3d72c42ad169baedad676c9\BIT51.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\20a4a6e3d70f3001229eaa8cf46f9b6e\BIT41.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\22d177b61fde58f114e05dfd9b70c96d\BIT37.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\24823ed08383f02a4a29c3ae029f9c14\BIT45.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\286ced246fa8efd37a907f9f08846ce8\BIT57.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2c7c094c07d8ab1c6d2c7df6e96d2df0\BIT50.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\42a9e16ebc4d2a5515c111ecad82af2f\BIT3F.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\5c9fd830c61df8040995447f1d8e61b0\BIT29.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\6d3e4a8f99a381f392de0d99b22fc9a6\BIT4D.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\762fc57e7d7138faef1f37e9eec268dc\BIT4F.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\7bfd24c44368c1f4c08da0b18d20b54e\BIT4C.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\8024f4e99b89fb365c808f79d373434f\BIT4A.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\8b0720d229b505788fc5c09af3f8c479\BIT3E.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\8fc9362cdeea2d9e312dca7d0ae818ee\BIT40.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\929cd614a46aa170511c3292b3848eb2\BIT3C.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\9fde447cfd86a360844378b784e73f37\BIT33.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\a23edd26fc03189a66774c8772cf784c\BIT54.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\a700888399b59cee38c0ae52e87f0a91\BIT56.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\a973a4b0bff52375def6ea55f54d9f60\BIT53.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\abf37927fe96bc682b342849c5743771\BIT34.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\be1ffa8cce945fce80b8bcf08e4890c5\BIT32.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\c636f36b2a084e07ecb5cf11b488b148\BIT48.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\c7ca82c6527101a1221a39f48bd67bac\BIT38.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\cceb21cd2a7a35a4e5b1d264978f4dfd\BIT4E.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d24445e8cd369b6927c4ffb132d21fca\BIT3B.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\df4c8391579dd99f8d7ffa70e2eb37c3\BIT52.tmp"
Mon 12 Nov 2007 804,768 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\e6a7525a4b32c7adb3b1c81ba8f28cb5\BIT2D.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f0b88fe1ffe91bd3a9ea0d5ad18f24b7\BIT58.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f57c255e25adcef74d2dff8c5940b09c\BIT46.tmp"
Wed 19 Sep 2007 444 ...HR --- "C:\Documents and Settings\Maciek\Dane aplikacji\SecuROM\UserData\securom_v7_01.bak"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0300c0210ca0c3725210067af2e4882c\download\BIT55.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0fffd07eaf930cc2973bc1444b13a2dd\download\BIT5F.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\12653710f178a9422c9846070c687e8e\download\BIT49.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\1b87084fdbfcd6d6273c66bb33faa288\download\BIT14.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2f591c6de1d57e751071795880d0c1d2\download\BIT5D.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\31383aab90693af2687520e301606b09\download\BITE.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\3685dbdd2272739b2f3609d9dc699b5f\download\BIT11.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\4594f50665d34bef5af87c38b6953ce2\download\BITB.tmp"
Mon 12 Nov 2007 765,039 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\4c41adde360d8087c4b4dd4e2d835dec\download\BIT65.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\4d39b1b575a5584d11abd56a8de2f045\download\BIT10.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\607c3e95df650a193f50ba0792fb4a68\download\BIT5E.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\67363d1e42ce421cde25a6a620fabf78\download\BIT60.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\6d09d0f1482adb9cdbb79b3d45a002d6\download\BIT5B.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\94ccbe980556f2828ed2d3768c02f4dd\download\BIT8.tmp"
Mon 12 Nov 2007 171,842 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\99c63b8154c86bb80bd4d4ef1f97d4ee\download\BIT6B.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\download\BITF.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\a8e852df97910fef5d18e30ff3fc6517\download\BIT5C.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\aa5843f35b888e23da16633e2a1ea0ba\download\BITA.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b96f4018a5a1e8840e523891e4664d45\download\BITC.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\baf5873d097c20aedd3e06e2ff27a933\download\BIT13.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\c16cb0a8736e71c6b91afa7e786ebaca\download\BIT59.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d36bccab140cfdcbeab0c880e5a7c294\download\BIT4.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d4630b482e634466a28ee1e624558dd5\download\BIT9.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d73b5fdacb6f744050beee3d7f715ec6\download\BIT26.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ec799b70d90cb0bf29b4da57cffabd91\download\BIT3.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f34ea1aa600dc2889509baa1a15ec8f8\download\BITD.tmp"
Mon 12 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fd43c53f6dd72556f6c8c981a93ce522\download\BIT12.tmp"
Finished!
ComboFix 07-11-08.1 - Maciek 2007-11-12 20:53:15.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.175 [GMT 1:00]
Running from: D:\Installs\Security\ComboFix.exe
* Created a new restore point
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users.WINDOWS\Menu Start\Live Safety Center.lnk
C:\Documents and Settings\All Users.WINDOWS\Menu Start\Online Security Guide.lnk
C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ulubione\Online Security Guide.lnk
C:\Documents and Settings\Kasia\Pulpit\internet.lnk
C:\Documents and Settings\LocalService\Dane aplikacji\NetMon
C:\Documents and Settings\LocalService\Dane aplikacji\NetMon\domains.txt
C:\Documents and Settings\LocalService\Dane aplikacji\NetMon\log.txt
C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Ulubione\Online Security Guide.lnk
C:\Documents and Settings\Maciek\Dane aplikacji\Install.dat
C:\WINDOWS\system32\ayadd.ini
C:\WINDOWS\system32\ayadd.ini2
C:\WINDOWS\system32\ddabc.dll
C:\WINDOWS\system32\ddaya.dll
C:\WINDOWS\system32\rwwendug.dllbox
C:\WINDOWS\system32\winrkq32.dll
C:\windows\xpupdate.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-10-12 to 2007-11-12 )))))))))))))))))))))))))))))))
.
2007-11-12 20:50 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-12 20:34 <DIR> d-------- C:\WINDOWS\ERUNT
2007-11-12 20:33 <DIR> d--h----- C:\Documents and Settings\Administrator.HOME-MSJ0FOWGZT\Ustawienia lokalne
2007-11-12 20:33 <DIR> d-------- C:\Documents and Settings\Administrator.HOME-MSJ0FOWGZT\Ulubione
2007-11-12 20:33 <DIR> d--h----- C:\Documents and Settings\Administrator.HOME-MSJ0FOWGZT\Szablony
2007-11-12 20:33 <DIR> d-------- C:\Documents and Settings\Administrator.HOME-MSJ0FOWGZT\Pulpit
2007-11-12 20:33 <DIR> d-------- C:\Documents and Settings\Administrator.HOME-MSJ0FOWGZT\Moje dokumenty
2007-11-12 20:33 <DIR> dr------- C:\Documents and Settings\Administrator.HOME-MSJ0FOWGZT\Menu Start
2007-11-12 20:33 <DIR> dr-h----- C:\Documents and Settings\Administrator.HOME-MSJ0FOWGZT\Dane aplikacji
2007-11-12 19:51 81,472 --a------ C:\WINDOWS\system32\qxxlymws.dll
2007-11-12 19:43 145,984 --a------ C:\WINDOWS\system32\eqavocfd.dll
2007-11-12 19:43 89,664 --a------ C:\WINDOWS\system32\enqjhvkh.dll
2007-11-12 18:51 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-11-12 18:14 145,984 --a------ C:\WINDOWS\system32\vyfvefsg.dll
2007-11-12 14:56 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Spybot - Search & Destroy
2007-11-12 14:47 1,448 --a------ C:\WINDOWS\system32\tmp.reg
2007-11-12 14:46 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-11-12 14:46 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-11-12 14:46 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-11-12 14:34 <DIR> d-------- C:\WINDOWS\pss
2007-11-12 14:30 81,472 --a------ C:\WINDOWS\system32\rwkmjsgf.dll
2007-11-12 14:25 89,664 --a------ C:\WINDOWS\system32\dmmllmca.dll
2007-11-12 14:25 71,232 --a------ C:\WINDOWS\system32\fdeihcdg.exe
2007-11-12 12:47 <DIR> d-------- C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Dane aplikacji\vlc
2007-11-12 09:15 11,914 --a------ C:\WINDOWS\system32\drivers\wg3n.sys
2007-11-12 09:14 83,096 --a------ C:\WINDOWS\system32\SSSensor.dll
2007-11-12 09:14 55,891 --a------ C:\WINDOWS\system32\drivers\Teefer.sys
2007-11-12 09:14 18,518 --a------ C:\WINDOWS\system32\drivers\wpsdrvnt.sys
2007-11-12 09:03 89,664 --------- C:\WINDOWS\system32\postrdtr.dll
2007-11-12 08:57 81,472 --a------ C:\WINDOWS\system32\wcfpqjid.dll
2007-11-12 08:57 71,232 --a------ C:\WINDOWS\system32\fsitypin.exe
2007-11-12 08:49 81,472 --a------ C:\WINDOWS\system32\kcopwnwq.dll
2007-11-12 08:43 89,664 --a------ C:\WINDOWS\system32\giutllwo.dll
2007-11-12 08:40 145,984 --a------ C:\WINDOWS\system32\qwocqfpr.dll
2007-11-11 22:54 <DIR> d-------- C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Dane aplikacji\Grisoft
2007-11-11 20:58 <DIR> d-------- C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Dane aplikacji\AdobeUM
2007-11-11 17:09 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Adobe Systems
2007-11-11 15:32 <DIR> d-------- C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Dane aplikacji\Grisoft
2007-11-11 15:32 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Grisoft
2007-11-11 15:32 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-11 15:15 44,054 --a------ C:\WINDOWS\system32\xxyaxvw.dll.vir
2007-11-11 15:14 <DIR> d-------- C:\Program Files\MalwareAlarm
2007-11-11 12:10 <DIR> d-------- C:\Program Files\uTorrent
2007-11-11 12:10 <DIR> d-------- C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Dane aplikacji\uTorrent
2007-11-08 23:21 <DIR> d-------- C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Dane aplikacji\Gadu-Gadu
2007-11-08 23:17 <DIR> d-------- C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Gadu-Gadu
2007-11-08 20:49 <DIR> d-------- C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\.jpi_cache
2007-11-08 20:49 <DIR> d-------- C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\.java
2007-11-08 13:34 <DIR> d-------- C:\Program Files\Tlen.pl
2007-11-08 13:34 <DIR> d-------- C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Dane aplikacji\Tlen.pl
2007-11-08 13:31 <DIR> d-------- C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\.jpi_cache
2007-11-08 13:31 <DIR> d-------- C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\.java
2007-11-08 00:09 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2007-11-08 00:08 <DIR> d-------- C:\Program Files\Microsoft Works
2007-11-08 00:07 <DIR> d-------- C:\Program Files\Microsoft.NET
2007-11-08 00:05 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-11-08 00:05 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Microsoft Help
2007-11-08 00:01 <DIR> C:\Documents and Settings\LocalService.ZARZąDZANIE NT\Menu Start
2007-11-08 00:01 <DIR> C:\Documents and Settings\LocalService.ZARZąDZANIE NT\Menu Start
2007-11-08 00:00 <DIR> d---s---- C:\WINDOWS\system32\Microsoft
2007-11-07 23:52 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2007-11-07 23:48 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-11-07 23:46 <DIR> d-------- C:\WINDOWS\EHome
2007-11-07 22:14 <DIR> d-------- C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Dane aplikacji\Azureus
2007-11-07 19:10 <DIR> d-------- C:\Program Files\Gadu-Gadu
2007-11-07 19:10 <DIR> d-------- C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Gadu-Gadu
2007-11-07 15:51 20,992 --a------ C:\WINDOWS\system32\drivers\rtl8139.sys
2007-11-07 09:04 <DIR> d-------- C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Dane aplikacji\Talkback
2007-11-07 09:03 <DIR> d-------- C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Dane aplikacji\Talkback
2007-11-07 08:58 <DIR> d-------- C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Dane aplikacji\Skype
2007-11-07 08:57 <DIR> d-------- C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Dane aplikacji\Thunderbird
2007-11-07 08:54 <DIR> d--h----- C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ustawienia lokalne
2007-11-07 08:54 <DIR> dr------- C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Ulubione
2007-11-07 08:54 <DIR> d--h----- C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Szablony
2007-11-07 08:54 <DIR> d-------- C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Pulpit
2007-11-07 08:54 <DIR> dr------- C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Moje dokumenty
2007-11-07 08:54 <DIR> dr------- C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Menu Start
2007-11-07 08:54 <DIR> dr-h----- C:\Documents and Settings\Kasia.HOME-MSJ0FOWGZT\Dane aplikacji
2007-11-07 08:53 <DIR> d-------- C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Dane aplikacji\Tlen.pl
2007-11-07 08:45 <DIR> d-------- C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\Dane aplikacji\Thunderbird
2007-11-06 21:21 <DIR> d-------- C:\WINDOWS\system32\Lang
2007-11-06 21:21 60,416 --a------ C:\WINDOWS\ALCFDRTM.EXE
2007-11-06 21:16 0 --a------ C:\WINDOWS\nsreg.dat
2007-11-06 21:10 9,409,536 -ra------ C:\WINDOWS\system32\RTLCPL.EXE
2007-11-06 21:10 2,324,160 -ra------ C:\WINDOWS\system32\drivers\ALCXWDM.SYS
2007-11-06 21:10 294,912 -r------- C:\WINDOWS\alcupd.exe
2007-11-06 21:10 200,704 -r------- C:\WINDOWS\alcrmv.exe
2007-11-06 21:10 156,672 -ra------ C:\WINDOWS\system32\RTLCPAPI.dll
2007-11-06 21:10 145,792 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2007-11-06 21:10 77,824 -ra------ C:\WINDOWS\SOUNDMAN.EXE
2007-11-06 21:10 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2007-11-06 21:10 40,960 -r------- C:\WINDOWS\system32\ChCfg.exe
2007-11-06 21:09 5,824 --a------ C:\WINDOWS\system32\drivers\ASUSHWIO.SYS
2007-11-06 21:04 <DIR> d-------- C:\Program Files\Java Web Start
2007-11-06 21:04 <DIR> d-------- C:\Program Files\Java
2007-11-06 21:04 <DIR> d-------- C:\Documents and Settings\Maciek.HOME-MSJ0FOWGZT\.javaws
2007-11-06 21:02 <DIR> d-------- C:\Documents and Settings\MACIEK~1~HOM\USTAWI~1
2007-11-06 20:47 <DIR> d--h----- C:\Program Files\Zenographics
2007-11-06 20:47 <DIR> d-------- C:\Program Files\Hewlett-Packard
2007-11-06 20:47 397,312 -ra------ C:\WINDOWS\system32\zshp1020.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-12 20:01 237,568 ---ha-w C:\Documents and Settings\NetworkService.ZARZąDZANIE NT\NTUSER.DAT
2007-11-12 20:01 237,568 ---ha-w C:\Documents and Settings\NetworkService.ZARZąDZANIE NT\NTUSER.DAT
2007-11-12 20:01 237,568 ---ha-w C:\Documents and Settings\LocalService.ZARZąDZANIE NT\NTUSER.DAT
2007-11-12 20:01 237,568 ---ha-w C:\Documents and Settings\LocalService.ZARZąDZANIE NT\NTUSER.DAT
2007-11-07 08:01 --------- d-----w C:\Documents and Settings\Kasia\Dane aplikacji\Thunderbird
2007-11-07 07:54 --------- d-----w C:\Documents and Settings\Maciek\Dane aplikacji\Tlen.pl
2007-11-07 07:52 --------- d-----w C:\Documents and Settings\Maciek\Dane aplikacji\Thunderbird
2007-11-07 07:52 --------- d-----w C:\Documents and Settings\Maciek\Dane aplikacji\Skype
2007-11-06 13:45 --------- d-s---w C:\Documents and Settings\NetworkService.ZARZąDZANIE NT\Dane aplikacji\Microsoft
2007-11-06 13:45 --------- d-s---w C:\Documents and Settings\NetworkService.ZARZąDZANIE NT\Dane aplikacji\Microsoft
2007-11-06 13:45 --------- d-s---w C:\Documents and Settings\NetworkService.ZARZąDZANIE NT\Dane aplikacji\Microsoft
2007-11-06 13:45 --------- d-s---w C:\Documents and Settings\LocalService.ZARZąDZANIE NT\Dane aplikacji\Microsoft
2007-11-06 13:44 --------- d-----w C:\Program Files\Usługi online
2007-11-01 21:59 --------- d-----w C:\Documents and Settings\Kasia\Dane aplikacji\Tlen.pl
2007-10-30 10:48 --------- d-----w C:\Program Files\Common Files\Ahead
2007-10-30 10:16 --------- d-----w C:\Program Files\Common Files\Adobe
2007-10-22 19:07 --------- d-----w C:\Documents and Settings\Maciek\Dane aplikacji\Ahead
2007-10-17 18:45 --------- d-----w C:\Documents and Settings\Maciek\Dane aplikacji\Winamp
2007-10-09 13:14 --------- d-----w C:\Documents and Settings\Kasia\Dane aplikacji\Ahead
2007-10-08 14:15 --------- d-----w C:\Documents and Settings\Maciek\Dane aplikacji\GameHouse
2007-09-25 20:35 --------- d-----w C:\Documents and Settings\Maciek\Dane aplikacji\Azureus
2007-09-24 05:15 48,632 ----a-w C:\Documents and Settings\Kasia\Dane aplikacji\GDIPFONTCACHEV1.DAT
2007-09-15 19:19 --------- d-----w C:\Documents and Settings\Maciek\Dane aplikacji\Nero
2007-09-13 17:49 --------- d-----w C:\Documents and Settings\Kasia\Dane aplikacji\Skype
2007-09-11 15:59 48,632 ----a-w C:\Documents and Settings\Maciek\Dane aplikacji\GDIPFONTCACHEV1.DAT
2007-01-12 11:07 23,022 ----a-w C:\Documents and Settings\Maciek\Menu Start.zip
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3138fdf3-89d8-4279-99f2-af91741ec15c}]
2007-11-12 19:51 81472 --a------ C:\WINDOWS\system32\qxxlymws.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"OrderReminder"="C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2005-03-18 12:18]
"HydraVisionDesktopManager"="C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe" [2003-09-15 21:00]
"SoundMan"="SOUNDMAN.EXE" [2005-06-14 11:36 C:\WINDOWS\SOUNDMAN.EXE]
"Adobe Photo Downloader"="D:\Programs\Adobe\Lightroom\apdproxy.exe" [2007-08-30 06:32]
"!AVG Anti-Spyware"="D:\Programs\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"SmcService"="D:\Programs\Sygate\SPF\smc.exe" [2004-02-24 16:35]
"b0b6f076"="C:\WINDOWS\system32\enqjhvkh.dll" [2007-11-12 19:43]