OTL logfile created on: 2012-03-05 12:05:36 - Run 5 OTL by OldTimer - Version 3.2.34.0 Folder = C:\Users\Komp\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.19120) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,25 Gb Total Physical Memory | 1,32 Gb Available Physical Memory | 40,67% Memory free 6,73 Gb Paging File | 4,74 Gb Available in Paging File | 70,48% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 63,48 Gb Total Space | 24,91 Gb Free Space | 39,24% Space Free | Partition Type: NTFS Drive D: | 195,31 Gb Total Space | 157,97 Gb Free Space | 80,88% Space Free | Partition Type: NTFS Drive E: | 206,97 Gb Total Space | 206,87 Gb Free Space | 99,95% Space Free | Partition Type: NTFS Drive F: | 0,38 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: KOMP-PC | User Name: Komp | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-03-02 10:13:08 | 000,584,704 | ---- | M] (OldTimer Tools) -- C:\Users\Komp\Desktop\OTL.exe PRC - [2012-01-27 08:32:57 | 000,949,104 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe PRC - [2011-07-04 18:45:30 | 013,374,048 | ---- | M] (GG Network S.A.) -- C:\Program Files\Gadu-Gadu 10\gg.exe PRC - [2009-08-17 00:32:00 | 000,239,648 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2009-04-11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009-03-02 13:06:16 | 000,068,136 | ---- | M] () -- C:\Program Files\Gigabyte\EasySaver\essvr.exe PRC - [2008-06-25 12:04:38 | 000,336,896 | ---- | M] (Portrait Displays, Inc) -- C:\Program Files\Gateway\EzTune\dthtml.exe PRC - [2008-06-25 12:02:28 | 000,069,632 | ---- | M] () -- C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe PRC - [2008-06-25 12:02:18 | 000,114,688 | ---- | M] (Portrait Displays Inc.) -- C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe PRC - [2008-06-21 17:01:32 | 000,090,112 | ---- | M] (Portrait Displays, Inc.) -- C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe PRC - [2008-01-21 03:23:43 | 000,021,504 | ---- | M] () -- \\.\globalroot\SystemRoot\system32\svchost.exe PRC - [2008-01-19 19:01:08 | 004,388,192 | ---- | M] (Symantec Corporation) -- C:\Program Files\Norton Ghost\Agent\VProSvc.exe PRC - [2008-01-19 19:01:08 | 002,245,984 | ---- | M] (Symantec Corporation) -- C:\Program Files\Norton Ghost\Agent\VProTray.exe PRC - [2007-12-20 16:13:46 | 001,553,896 | ---- | M] (Symantec) -- C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe PRC - [2006-01-16 14:50:34 | 000,106,496 | ---- | M] () -- C:\Program Files\Samsung Network Printer Utilities\SyncThru Web Admin Service\WSTSrvDispatcher.exe PRC - [2006-01-16 14:48:48 | 000,229,376 | ---- | M] () -- C:\Program Files\Samsung Network Printer Utilities\SyncThru Web Admin Service\WSTSrvSNMP.exe PRC - [2006-01-16 14:48:24 | 000,110,592 | ---- | M] () -- C:\Program Files\Samsung Network Printer Utilities\SyncThru Web Admin Service\WSTSrvSLP.exe PRC - [2006-01-16 14:48:10 | 000,126,976 | ---- | M] () -- C:\Program Files\Samsung Network Printer Utilities\SyncThru Web Admin Service\WSTWebServer.exe PRC - [2006-01-16 14:47:34 | 000,114,688 | ---- | M] () -- C:\Program Files\Samsung Network Printer Utilities\SyncThru Web Admin Service\WSTSrvDatabase.exe PRC - [2006-01-16 14:47:18 | 000,327,680 | ---- | M] () -- C:\Program Files\Samsung Network Printer Utilities\SyncThru Web Admin Service\WSTSrvDeviceManager.exe PRC - [2005-06-22 08:15:44 | 000,266,240 | ---- | M] (Samsung) -- C:\Program Files\Samsung\NetworkScan\NSCSysTrayUI.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2011-07-04 18:46:20 | 000,217,696 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\gglog.dll MOD - [2011-07-04 18:46:18 | 000,123,488 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggipcradioproxy.dll MOD - [2011-07-04 18:46:16 | 000,017,504 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggipc.dll MOD - [2011-07-04 18:46:12 | 000,027,744 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggcrypto.dll MOD - [2011-07-04 18:46:10 | 000,356,960 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggcommon.dll MOD - [2011-04-16 04:04:30 | 014,749,696 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtWebKit4.dll MOD - [2011-02-17 10:00:28 | 001,781,760 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtScript4.dll MOD - [2011-02-17 10:00:28 | 000,393,216 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtXml4.dll MOD - [2011-02-17 10:00:28 | 000,327,680 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtSvg4.dll MOD - [2011-02-17 10:00:26 | 001,044,480 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtNetwork4.dll MOD - [2011-02-17 10:00:24 | 009,097,216 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtGui4.dll MOD - [2011-02-17 10:00:24 | 002,560,000 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtCore4.dll MOD - [2011-02-17 09:59:40 | 000,311,296 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qtiff4.dll MOD - [2011-02-17 09:59:40 | 000,274,432 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qmng4.dll MOD - [2011-02-17 09:59:40 | 000,143,360 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qjpeg4.dll MOD - [2011-02-17 09:59:40 | 000,027,648 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qgif4.dll MOD - [2011-02-17 09:59:40 | 000,018,944 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qsvg4.dll MOD - [2010-03-19 08:33:38 | 000,059,904 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\zlib1.dll MOD - [2009-10-03 01:50:04 | 000,102,400 | ---- | M] () -- C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\EScript.POL MOD - [2009-10-03 01:46:46 | 000,012,288 | ---- | M] () -- C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\updater.POL MOD - [2009-04-11 07:28:22 | 000,223,232 | ---- | M] () -- \\?\globalroot\systemroot\system32\mswsock.dll MOD - [2009-02-27 19:05:00 | 000,023,040 | ---- | M] () -- C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\SaveAsRTF.POL MOD - [2009-02-27 19:02:50 | 001,695,744 | ---- | M] () -- C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Annots.POL MOD - [2009-02-03 03:15:28 | 003,771,296 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32.dll MOD - [2008-06-25 12:02:34 | 000,151,552 | ---- | M] () -- C:\Program Files\Common Files\Portrait Displays\Shared\DThook.dll MOD - [2008-06-25 12:02:28 | 000,077,824 | ---- | M] () -- C:\Program Files\Common Files\Portrait Displays\Plugins\CC\gui.dll MOD - [2008-06-25 12:02:08 | 000,102,400 | ---- | M] () -- C:\Program Files\Common Files\Portrait Displays\Shared\PresetsCOM.dll MOD - [2008-06-21 17:01:32 | 000,237,568 | ---- | M] () -- C:\Program Files\Common Files\Portrait Displays\Drivers\di2c.dll MOD - [2008-06-21 17:01:32 | 000,098,304 | ---- | M] () -- C:\Program Files\Common Files\Portrait Displays\Drivers\smsc.dll MOD - [2008-06-21 17:01:32 | 000,053,248 | ---- | M] () -- C:\Program Files\Common Files\Portrait Displays\Drivers\null.dll MOD - [2008-06-21 17:00:24 | 000,098,304 | ---- | M] () -- C:\Program Files\Common Files\Portrait Displays\Drivers\vista.dll MOD - [2006-10-27 14:35:18 | 000,436,512 | ---- | M] () -- C:\Program Files\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll MOD - [2006-10-26 20:30:42 | 000,065,312 | ---- | M] () -- C:\Program Files\Microsoft Office\Office12\ADDINS\ColleagueImport.dll MOD - [2006-10-26 12:56:46 | 000,757,008 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2009-08-17 00:32:00 | 000,239,648 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2009-03-02 13:06:16 | 000,068,136 | ---- | M] () [Auto | Running] -- C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE -- (ES lite Service) SRV - [2008-06-25 12:02:28 | 000,069,632 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe -- (DTSRVC) SRV - [2008-06-21 17:01:32 | 000,090,112 | ---- | M] (Portrait Displays, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe -- (PdiService) SRV - [2008-01-21 03:23:43 | 000,005,120 | ---- | M] (Iomega) [Auto | Running] -- C:\Windows\System32\schedule.dll -- (hpqcxs08) SRV - [2008-01-19 19:01:08 | 004,388,192 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Ghost\Agent\VProSvc.exe -- (Norton Ghost) SRV - [2007-12-20 16:13:46 | 001,553,896 | ---- | M] (Symantec) [On_Demand | Running] -- C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe -- (SymSnapService) SRV - [2007-09-12 17:27:24 | 002,999,664 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE -- (LiveUpdate) SRV - [2006-01-16 14:50:34 | 000,106,496 | ---- | M] () [Auto | Running] -- C:\Program Files\Samsung Network Printer Utilities\SyncThru Web Admin Service\WSTSrvDispatcher.exe -- (DispatcherServiceNT) SRV - [2006-01-16 14:48:48 | 000,229,376 | ---- | M] () [Auto | Running] -- C:\Program Files\Samsung Network Printer Utilities\SyncThru Web Admin Service\WSTSrvSNMP.exe -- (SNMPService) SRV - [2006-01-16 14:48:24 | 000,110,592 | ---- | M] () [Auto | Running] -- C:\Program Files\Samsung Network Printer Utilities\SyncThru Web Admin Service\WSTSrvSLP.exe -- (SLPService) SRV - [2006-01-16 14:48:10 | 000,126,976 | ---- | M] () [Auto | Running] -- C:\Program Files\Samsung Network Printer Utilities\SyncThru Web Admin Service\WSTWebServer.exe -- (WebServiceNT) SRV - [2006-01-16 14:47:34 | 000,114,688 | ---- | M] () [Auto | Running] -- C:\Program Files\Samsung Network Printer Utilities\SyncThru Web Admin Service\WSTSrvDatabase.exe -- (DBService) SRV - [2006-01-16 14:47:18 | 000,327,680 | ---- | M] () [Auto | Running] -- C:\Program Files\Samsung Network Printer Utilities\SyncThru Web Admin Service\WSTSrvDeviceManager.exe -- (DMService) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2012-03-05 07:27:22 | 000,017,488 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\gdrv.sys -- (gdrv) DRV - [2011-07-04 18:58:18 | 000,085,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_jucdcacm.sys -- (huawei_cdcacm) DRV - [2011-07-04 18:58:18 | 000,072,576 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator) DRV - [2011-07-04 18:58:16 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev) DRV - [2009-08-16 23:57:00 | 009,545,152 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2009-04-01 04:54:44 | 000,050,176 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1C60x86.sys -- (L1C) DRV - [2009-03-02 13:12:10 | 000,038,400 | ---- | M] (Samsung Electronics Co., Ltd.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\DGIVECP.SYS -- (DgiVecp) DRV - [2008-06-21 17:01:44 | 000,017,064 | ---- | M] (Portrait Displays, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PdiPorts.sys -- (PdiPorts) DRV - [2008-01-19 19:12:42 | 000,128,104 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\WimFltr.sys -- (WimFltr) DRV - [2008-01-19 18:45:40 | 000,038,112 | ---- | M] (Symantec Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\v2imount.sys -- (v2imount) DRV - [2008-01-19 18:40:16 | 000,015,088 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vproeventmonitor.sys -- (VProEventMonitor) DRV - [2007-12-20 16:13:54 | 000,136,416 | ---- | M] (StorageCraft) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\symsnap.sys -- (symsnap) DRV - [2007-02-16 01:57:04 | 000,034,760 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ElbyCDFL.sys -- (ElbyCDFL) DRV - [2006-11-22 22:48:18 | 000,005,120 | ---- | M] (Samsung Electronics) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\SSPORT.SYS -- (SSPORT) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1125675357-3644848481-3202317887-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve IE - HKU\S-1-5-21-1125675357-3644848481-3202317887-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-21-1125675357-3644848481-3202317887-1000\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.6\pdfforgeToolbarIE.dll (Spigot, Inc.) IE - HKU\..\SearchScopes,DefaultScope = {8682E36F-EC24-4D74-8D3D-137CE49997BD} IE - HKU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\..\SearchScopes\{2482FA88-60CE-4A6D-A931-87750DE08159}: "URL" = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=302398&p={searchTerms} IE - HKU\..\SearchScopes\{8682E36F-EC24-4D74-8D3D-137CE49997BD}: "URL" = http://www.google.com/search?hl=pl&q={searchTerms}&rlz=1I7ADSA_plPL450 IE - HKU\S-1-5-21-1125675357-3644848481-3202317887-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Komp\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Komp\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.) [2011-08-24 06:40:25 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [color=#E56717]========== Chrome ==========[/color] CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms} CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Komp\AppData\Local\Google\Chrome\Application\17.0.963.56\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Users\Komp\AppData\Local\Google\Chrome\Application\17.0.963.56\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Komp\AppData\Local\Google\Chrome\Application\17.0.963.56\pdf.dll CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - plugin: Default Plug-in (Enabled) = default_plugin CHR - Extension: YouTube = C:\Users\Komp\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\ CHR - Extension: Szukaj w Google = C:\Users\Komp\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\ CHR - Extension: Gmail = C:\Users\Komp\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\ O1 HOSTS File: ([2012-03-01 15:48:56 | 000,441,412 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 www.1-2005-search.com O1 - Hosts: 15174 more lines... O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.6\pdfforgeToolbarIE.dll (Spigot, Inc.) O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\4.6\pdfforgeToolbarIE.dll (Spigot, Inc.) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKU\S-1-5-21-1125675357-3644848481-3202317887-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O3 - HKU\S-1-5-21-1125675357-3644848481-3202317887-1000\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found. O4 - HKLM..\Run: [DT GWY] C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe () O4 - HKLM..\Run: [Norton Ghost 14.0] C:\Program Files\Norton Ghost\Agent\VProTray.exe (Symantec Corporation) O4 - HKLM..\Run: [NSCSysTrayUI] C:\Program Files\Samsung\NetworkScan\NSCSysTrayUI.exe (Samsung) O4 - HKU\S-1-5-21-1125675357-3644848481-3202317887-1000..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.) O4 - HKLM..\RunOnce: [NoIE4StubProcessing] C:\Windows\system32\reg.exe DELETE "HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" /v "NoIE4StubProcessing" /f File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - %SystemRoot%\System32\winrnr.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - %SystemRoot%\System32\winrnr.dll File not found O13 - gopher Prefix: missing O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (MksSkanerOnline Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{71666F19-5147-480A-B1E3-C6BC3505957C}: NameServer = 10.0.0.1 O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKU\S-1-5-21-1125675357-3644848481-3202317887-1000 Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img33.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img33.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006-09-18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2009-04-29 10:02:01 | 000,000,055 | R--- | M] () - F:\autorun.inf -- [ CDFS ] O33 - MountPoints2\{0afbcefe-2a79-11df-add7-00241d54f35a}\Shell\AutoRun\command - "" = G:\s1.exe O33 - MountPoints2\{0afbcefe-2a79-11df-add7-00241d54f35a}\Shell\open\Command - "" = G:\s1.exe O33 - MountPoints2\{499556b2-ae4d-11de-a1c5-00241d54f35a}\Shell\AutoRun\command - "" = RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise.exe O33 - MountPoints2\{499556b2-ae4d-11de-a1c5-00241d54f35a}\Shell\open\command - "" = RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise.exe O33 - MountPoints2\{6eefac5d-a31f-11de-b576-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{6eefac5d-a31f-11de-b576-806e6f6e6963}\Shell\AutoRun\command - "" = F:\BlueBirds.exe -- [2009-04-29 10:02:01 | 000,270,336 | R--- | M] (LG Electronics) O33 - MountPoints2\{8f34aedc-f625-11e0-a691-00241d54f35a}\Shell - "" = AutoRun O33 - MountPoints2\{8f34aedc-f625-11e0-a691-00241d54f35a}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{8f34aeea-f625-11e0-a691-00241d54f35a}\Shell - "" = AutoRun O33 - MountPoints2\{8f34aeea-f625-11e0-a691-00241d54f35a}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{d9b89d0e-1665-11e1-8f81-00241d54f35a}\Shell - "" = AutoRun O33 - MountPoints2\{d9b89d0e-1665-11e1-8f81-00241d54f35a}\Shell\AutoRun\command - "" = G:\AutoRun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-03-02 13:04:29 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\bdclndrv [2012-03-02 13:03:05 | 000,335,504 | ---- | C] (BitDefender S.R.L.) -- C:\Windows\System32\drivers\TrufosAlt.sys [2012-03-02 12:59:07 | 007,396,728 | ---- | C] (BitDefender LLC) -- C:\Users\Komp\Desktop\BDRemovalTool_sirefef_x86.exe [2012-03-02 10:44:05 | 000,000,000 | ---D | C] -- C:\Users\Komp\AppData\Local\Threat Expert [2012-03-02 10:25:37 | 000,233,976 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTSD.sys [2012-03-02 10:25:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools [2012-03-02 10:24:35 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools [2012-03-02 10:24:34 | 000,000,000 | ---D | C] -- C:\Users\Komp\AppData\Roaming\TestApp [2012-03-02 10:13:08 | 000,584,704 | ---- | C] (OldTimer Tools) -- C:\Users\Komp\Desktop\OTL.exe [2012-03-02 10:02:13 | 000,000,000 | ---D | C] -- C:\Program Files\HJ [2012-03-02 10:02:13 | 000,000,000 | ---D | C] -- C:\Users\Komp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis [2012-03-01 13:25:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner [2012-03-01 13:25:00 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2012-03-01 11:41:47 | 000,000,000 | -HSD | C] -- C:\Users\Komp\AppData\Local\99805d09 [2012-03-01 11:41:27 | 000,103,936 | -H-- | C] (YL Software) -- C:\Users\Komp\AppData\Roaming\WMPRWISE.EXE [2012-02-08 12:33:41 | 000,000,000 | ---D | C] -- C:\Users\Komp\Desktop\Ulotka-MamoTato-do-druku-2-en [2012-02-08 12:32:27 | 000,000,000 | ---D | C] -- C:\Users\Komp\Desktop\mamo-tato-ulotka-fonty [4 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-03-05 12:07:13 | 008,388,608 | -HS- | M] () -- C:\Users\Komp\NTUSER.DAT [2012-03-05 11:27:12 | 000,003,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2012-03-05 11:27:12 | 000,003,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2012-03-05 11:20:00 | 000,001,054 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1125675357-3644848481-3202317887-1000UA.job [2012-03-05 11:07:42 | 000,302,592 | ---- | M] () -- C:\Users\Komp\Desktop\wli4cwlj.exe [2012-03-05 08:20:00 | 000,001,002 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1125675357-3644848481-3202317887-1000Core.job [2012-03-05 07:39:52 | 001,524,616 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI [2012-03-05 07:39:52 | 000,675,250 | ---- | M] () -- C:\Windows\System32\perfh015.dat [2012-03-05 07:39:52 | 000,598,702 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012-03-05 07:39:52 | 000,131,566 | ---- | M] () -- C:\Windows\System32\perfc015.dat [2012-03-05 07:39:52 | 000,104,716 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012-03-05 07:30:08 | 000,000,000 | -HS- | M] () -- C:\Windows\System32\dds_log_trash.cmd [2012-03-05 07:27:26 | 000,057,872 | ---- | M] () -- C:\ProgramData\nvModes.dat [2012-03-05 07:27:26 | 000,057,872 | ---- | M] () -- C:\ProgramData\nvModes.001 [2012-03-05 07:27:22 | 000,017,488 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\Windows\gdrv.sys [2012-03-05 07:27:13 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2012-03-05 07:27:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012-03-05 07:27:10 | 3486,027,776 | -HS- | M] () -- C:\hiberfil.sys [2012-03-02 15:51:51 | 000,524,288 | -HS- | M] () -- C:\Users\Komp\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms [2012-03-02 15:51:51 | 000,065,536 | -HS- | M] () -- C:\Users\Komp\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf [2012-03-02 15:51:26 | 002,153,194 | -H-- | M] () -- C:\Users\Komp\AppData\Local\IconCache.db [2012-03-02 15:20:51 | 000,075,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\bdclndrv [2012-03-02 15:20:18 | 000,335,504 | ---- | M] (BitDefender S.R.L.) -- C:\Windows\System32\drivers\TrufosAlt.sys [2012-03-02 13:23:36 | 002,544,456 | ---- | M] () -- C:\Users\Komp\Desktop\avg_rem_zeroaccess_all_1_764.exe [2012-03-02 13:00:20 | 000,026,354 | ---- | M] () -- C:\Users\Komp\Documents\Samsung SCX-4x20 Series_20120302125951.tif [2012-03-02 12:59:07 | 007,396,728 | ---- | M] (BitDefender LLC) -- C:\Users\Komp\Desktop\BDRemovalTool_sirefef_x86.exe [2012-03-02 12:38:12 | 000,337,137 | ---- | M] () -- C:\Users\Komp\Desktop\FSS.exe [2012-03-02 11:43:07 | 000,233,976 | ---- | M] (PC Tools) -- C:\Windows\System32\drivers\PCTSD.sys [2012-03-02 10:26:03 | 002,098,279 | ---- | M] () -- C:\Windows\System32\drivers\Cat.DB [2012-03-02 10:13:08 | 000,584,704 | ---- | M] (OldTimer Tools) -- C:\Users\Komp\Desktop\OTL.exe [2012-03-02 10:02:17 | 000,002,597 | ---- | M] () -- C:\Users\Komp\Desktop\HiJackThis.lnk [2012-03-02 09:30:34 | 000,026,624 | ---- | M] () -- C:\Users\Komp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-03-01 15:48:56 | 000,441,412 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts [2012-03-01 13:25:01 | 000,000,804 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2012-03-01 11:41:28 | 000,055,808 | -H-- | M] () -- C:\Users\Komp\AppData\Roaming\ntuser.dat [2012-03-01 11:41:27 | 000,103,936 | -H-- | M] (YL Software) -- C:\Users\Komp\AppData\Roaming\WMPRWISE.EXE [2012-02-28 15:37:13 | 000,441,352 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20120301-154856.backup [2012-02-23 07:32:15 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [2012-02-17 15:20:22 | 000,126,788 | ---- | M] () -- C:\Users\Komp\Desktop\2106995697.jpg [2012-02-17 08:21:04 | 000,002,074 | ---- | M] () -- C:\Users\Komp\Desktop\Google Chrome.lnk [2012-02-13 15:46:12 | 000,441,283 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20120228-153713.backup [2012-02-13 07:30:51 | 000,503,776 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012-02-10 13:20:21 | 000,107,496 | ---- | M] () -- C:\Users\Komp\AppData\Local\GDIPFONTCACHEV1.DAT [4 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-03-05 11:07:42 | 000,302,592 | ---- | C] () -- C:\Users\Komp\Desktop\wli4cwlj.exe [2012-03-02 13:23:29 | 002,544,456 | ---- | C] () -- C:\Users\Komp\Desktop\avg_rem_zeroaccess_all_1_764.exe [2012-03-02 12:59:51 | 000,026,354 | ---- | C] () -- C:\Users\Komp\Documents\Samsung SCX-4x20 Series_20120302125951.tif [2012-03-02 12:38:10 | 000,337,137 | ---- | C] () -- C:\Users\Komp\Desktop\FSS.exe [2012-03-02 10:25:39 | 002,098,279 | ---- | C] () -- C:\Windows\System32\drivers\Cat.DB [2012-03-02 10:02:13 | 000,002,597 | ---- | C] () -- C:\Users\Komp\Desktop\HiJackThis.lnk [2012-03-01 13:25:01 | 000,000,804 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2012-03-01 11:42:33 | 000,000,000 | -HS- | C] () -- C:\Windows\System32\dds_log_trash.cmd [2012-03-01 11:41:28 | 000,055,808 | -H-- | C] () -- C:\Users\Komp\AppData\Roaming\ntuser.dat [2012-02-17 15:20:27 | 000,126,788 | ---- | C] () -- C:\Users\Komp\Desktop\2106995697.jpg [2011-09-07 14:39:13 | 000,000,221 | ---- | C] () -- C:\Windows\NCLogConfig.ini [2011-08-22 10:51:33 | 000,482,408 | ---- | C] () -- C:\Windows\ssndii.exe [2011-08-22 10:51:10 | 000,022,723 | ---- | C] () -- C:\Windows\System32\ml285pl3.dll [2011-05-21 10:36:14 | 000,909,312 | ---- | C] () -- C:\Windows\System32\AVC_AP_H264.dll [2011-05-21 10:36:13 | 000,909,312 | ---- | C] () -- C:\Windows\System32\AVC_H264.dll [2011-03-31 06:29:41 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat [2010-08-06 07:50:51 | 000,036,864 | ---- | C] () -- C:\Windows\System32\SvcMan.exe [2010-08-06 07:49:00 | 000,110,592 | ---- | C] () -- C:\Windows\Wiainst.exe [2010-08-06 07:48:57 | 000,027,136 | R--- | C] () -- C:\Windows\System32\ssimgfilter.dll [2010-08-06 07:48:57 | 000,011,264 | R--- | C] () -- C:\Windows\System32\sssegfilter.dll [2010-08-06 07:48:57 | 000,010,752 | R--- | C] () -- C:\Windows\System32\sserrhandler.dll [2010-08-05 13:58:26 | 000,172,032 | ---- | C] () -- C:\Windows\System32\SecSNMP.dll [2010-08-05 13:58:17 | 000,000,124 | ---- | C] () -- C:\Windows\Readiris.ini [2010-08-05 13:58:16 | 000,023,040 | ---- | C] () -- C:\Windows\System32\irisco32.dll [2010-03-11 07:37:30 | 000,000,197 | ---- | C] () -- C:\Windows\System32\MRT.INI [2010-03-08 16:24:32 | 000,026,624 | ---- | C] () -- C:\Users\Komp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010-03-06 12:35:00 | 000,000,041 | -HS- | C] () -- C:\ProgramData\.zreglib [color=#E56717]========== LOP Check ==========[/color] [2010-10-28 19:00:06 | 000,000,000 | ---D | M] -- C:\Users\Komp\AppData\Roaming\2K Sports [2009-11-02 17:02:20 | 000,000,000 | ---D | M] -- C:\Users\Komp\AppData\Roaming\ACD Systems [2009-09-21 10:35:59 | 000,000,000 | ---D | M] -- C:\Users\Komp\AppData\Roaming\DisplayTune [2010-09-13 15:16:00 | 000,000,000 | ---D | M] -- C:\Users\Komp\AppData\Roaming\Gadu-Gadu 10 [2011-09-07 12:07:04 | 000,000,000 | ---D | M] -- C:\Users\Komp\AppData\Roaming\Image Zone Express [2010-09-13 15:18:29 | 000,000,000 | ---D | M] -- C:\Users\Komp\AppData\Roaming\ipla [2009-10-05 16:34:18 | 000,000,000 | ---D | M] -- C:\Users\Komp\AppData\Roaming\Nowe Gadu-Gadu [2009-09-22 20:14:04 | 000,000,000 | ---D | M] -- C:\Users\Komp\AppData\Roaming\OpenFM [2012-01-09 11:22:47 | 000,000,000 | ---D | M] -- C:\Users\Komp\AppData\Roaming\OpenOffice.org [2011-07-08 09:50:16 | 000,000,000 | ---D | M] -- C:\Users\Komp\AppData\Roaming\Opera [2011-10-14 12:25:40 | 000,000,000 | ---D | M] -- C:\Users\Komp\AppData\Roaming\Plus Internet [2011-09-07 12:07:03 | 000,000,000 | ---D | M] -- C:\Users\Komp\AppData\Roaming\Printer Info Cache [2012-03-02 10:24:34 | 000,000,000 | ---D | M] -- C:\Users\Komp\AppData\Roaming\TestApp [2010-03-25 12:04:47 | 000,000,000 | ---D | M] -- C:\Users\Komp\AppData\Roaming\Vso [2012-03-02 15:51:30 | 000,032,546 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 24 bytes -> C:\Windows:9AE6BB7C47D65027 @Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:B755D674 @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84 @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:DFC5A2B2 < End of report >