OTL logfile created on: 2012-07-06 19:18:19 - Run 2 OTL by OldTimer - Version 3.2.53.1 Folder = D:\ Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,50 Gb Total Physical Memory | 2,25 Gb Available Physical Memory | 64,31% Memory free 7,00 Gb Paging File | 5,65 Gb Available in Paging File | 80,79% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 83,01 Gb Total Space | 5,00 Gb Free Space | 6,02% Space Free | Partition Type: NTFS Drive D: | 146,48 Gb Total Space | 7,38 Gb Free Space | 5,04% Space Free | Partition Type: NTFS Drive E: | 236,27 Gb Total Space | 0,79 Gb Free Space | 0,33% Space Free | Partition Type: NTFS Computer Name: RAFAŁ-KOMPUTER | User Name: Rafał | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-07-06 16:05:27 | 000,595,968 | ---- | M] (OldTimer Tools) -- D:\OTL.exe PRC - [2012-06-30 20:49:58 | 000,245,168 | ---- | M] (http://yourfiledownloader.com) -- C:\Program Files\YourFileDownloader\YourFileUpdater.exe PRC - [2012-06-29 11:26:23 | 001,027,792 | ---- | M] (F-Secure Corporation) -- C:\Program Files\F-Secure\apps\ComputerSecurity\Anti-Virus\fssm32.exe PRC - [2012-06-29 11:26:23 | 000,560,848 | ---- | M] (F-Secure Corporation) -- C:\Program Files\F-Secure\apps\ComputerSecurity\Anti-Virus\fsgk32.exe PRC - [2012-06-27 12:29:26 | 001,996,200 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe PRC - [2012-06-27 12:29:22 | 001,385,896 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe PRC - [2012-06-21 13:29:36 | 000,163,536 | ---- | M] (F-Secure Corporation) -- C:\Program Files\F-Secure\fshoster32.exe PRC - [2012-06-19 17:32:30 | 003,048,136 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe PRC - [2012-04-27 19:05:40 | 000,613,208 | ---- | M] (IObit) -- C:\Program Files\IObit\Game Booster 3\gbtray.exe PRC - [2012-03-15 18:00:44 | 000,311,976 | ---- | M] (F-Secure Corporation) -- C:\Program Files\F-Secure\apps\ComputerSecurity\Common\FSM32.EXE PRC - [2012-03-15 18:00:44 | 000,213,672 | ---- | M] (F-Secure Corporation) -- C:\Program Files\F-Secure\apps\ComputerSecurity\Common\FSMA32.EXE PRC - [2012-03-15 18:00:38 | 000,610,472 | ---- | M] (F-Secure Corporation) -- C:\Program Files\F-Secure\apps\ComputerSecurity\FWES\program\fsdfwd.exe PRC - [2012-03-15 15:55:34 | 000,062,160 | ---- | M] (F-Secure Corporation) -- C:\Program Files\F-Secure\apps\CCF_Reputation\fsorsp.exe PRC - [2012-03-14 17:38:14 | 000,913,752 | ---- | M] (IObit) -- C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe PRC - [2012-03-06 18:39:50 | 000,574,296 | ---- | M] (IObit) -- C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe PRC - [2012-01-09 20:17:44 | 000,821,592 | ---- | M] (IObit) -- C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe PRC - [2012-01-04 14:26:46 | 001,606,488 | ---- | M] (IObit) -- C:\Program Files\IObit\Smart Defrag 2\SmartDefrag.exe PRC - [2011-11-10 11:17:04 | 003,514,176 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe PRC - [2011-10-15 10:53:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe PRC - [2011-10-15 10:53:00 | 001,820,480 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe PRC - [2011-10-15 10:53:00 | 001,328,960 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe PRC - [2011-10-15 01:54:40 | 000,381,248 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2011-06-30 16:16:25 | 000,072,704 | ---- | M] (Autodesk) -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe PRC - [2011-03-28 12:21:16 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE PRC - [2011-03-04 11:39:14 | 000,584,488 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Update\NASvc.exe PRC - [2010-11-23 16:14:10 | 000,099,752 | ---- | M] () -- C:\Program Files\Stardock\Object Desktop\WindowBlinds\WBVista.exe PRC - [2010-09-15 02:49:04 | 002,388,264 | ---- | M] (Apple Inc.) -- C:\Program Files\Safari\Safari.exe PRC - [2010-09-07 18:47:18 | 000,202,048 | ---- | M] () -- C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe PRC - [2010-09-07 18:47:08 | 000,664,896 | ---- | M] () -- C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe PRC - [2009-12-02 22:23:52 | 000,209,768 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe PRC - [2009-12-02 22:23:46 | 000,483,688 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe PRC - [2009-07-14 03:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2009-07-14 03:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009-06-04 17:13:20 | 000,230,648 | ---- | M] (Stardock Corporation) -- C:\Program Files\Stardock\Object Desktop\WindowBlinds\VistaSrv.exe PRC - [2009-02-15 16:22:40 | 000,839,680 | ---- | M] (Freebird) -- C:\Program Files\Monsters\PowerGramo\PowerGramo.exe PRC - [2007-12-18 14:20:00 | 000,401,408 | ---- | M] (Creative Technology Ltd.) -- C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe PRC - [2007-04-19 15:43:42 | 000,537,520 | ---- | M] ( ) -- C:\Windows\System32\lxczcoms.exe PRC - [2007-04-02 14:15:40 | 000,061,440 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\Shared Files\CTDevSrv.exe PRC - [2006-11-03 11:01:16 | 000,319,488 | ---- | M] (PixArt Imaging Incorporation) -- C:\Windows\PixArt\PAC207\Monitor.exe PRC - [2006-09-29 12:48:06 | 000,065,536 | ---- | M] () -- D:\3d\mentalray\satellite\raysat_3dsmax9_32server.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012-06-29 11:16:58 | 010,706,624 | ---- | M] () -- C:\Windows\winsxs\x86_f-secure.qt_4_6_2_2e112a926211c0a3_4.6.2.680_none_a025cb6556b2730a\QtWebKit4.dll MOD - [2012-06-29 11:16:58 | 008,347,328 | ---- | M] () -- C:\Windows\winsxs\x86_f-secure.qt_4_6_2_2e112a926211c0a3_4.6.2.680_none_a025cb6556b2730a\QtGui4.dll MOD - [2012-06-29 11:16:58 | 003,051,200 | ---- | M] () -- C:\Windows\winsxs\x86_f-secure.qt_4_6_2_2e112a926211c0a3_4.6.2.680_none_a025cb6556b2730a\QtXmlPatterns4.dll MOD - [2012-06-29 11:16:58 | 002,256,576 | ---- | M] () -- C:\Windows\winsxs\x86_f-secure.qt_4_6_2_2e112a926211c0a3_4.6.2.680_none_a025cb6556b2730a\QtCore4.dll MOD - [2012-06-29 11:16:58 | 001,162,944 | ---- | M] () -- C:\Windows\winsxs\x86_f-secure.qt_4_6_2_2e112a926211c0a3_4.6.2.680_none_a025cb6556b2730a\QtScript4.dll MOD - [2012-06-29 11:16:58 | 001,076,928 | ---- | M] () -- C:\Windows\winsxs\x86_f-secure.qt_4_6_2_2e112a926211c0a3_4.6.2.680_none_a025cb6556b2730a\QtCLucene4.dll MOD - [2012-06-29 11:16:58 | 000,986,816 | ---- | M] () -- C:\Windows\winsxs\x86_f-secure.qt_4_6_2_2e112a926211c0a3_4.6.2.680_none_a025cb6556b2730a\QtNetwork4.dll MOD - [2012-06-29 11:16:58 | 000,622,272 | ---- | M] () -- C:\Windows\winsxs\x86_f-secure.qt_4_6_2_2e112a926211c0a3_4.6.2.680_none_a025cb6556b2730a\QtSql4.dll MOD - [2012-06-29 11:16:58 | 000,450,240 | ---- | M] () -- C:\Windows\winsxs\x86_f-secure.qt_4_6_2_2e112a926211c0a3_4.6.2.680_none_a025cb6556b2730a\QtHelp4.dll MOD - [2012-06-29 11:16:58 | 000,372,416 | ---- | M] () -- C:\Windows\winsxs\x86_f-secure.qt_4_6_2_2e112a926211c0a3_4.6.2.680_none_a025cb6556b2730a\QtXml4.dll MOD - [2012-06-21 13:29:36 | 000,241,360 | ---- | M] () -- C:\Program Files\F-Secure\imageformats\qmng4.dll MOD - [2012-06-21 13:29:36 | 000,036,048 | ---- | M] () -- C:\Program Files\F-Secure\imageformats\qico4.dll MOD - [2012-06-21 13:29:36 | 000,034,000 | ---- | M] () -- C:\Program Files\F-Secure\imageformats\qgif4.dll MOD - [2012-03-15 18:00:36 | 000,086,016 | ---- | M] () -- C:\Program Files\F-Secure\apps\ComputerSecurity\FSGUI\strres.eng MOD - [2012-03-15 18:00:34 | 000,147,456 | ---- | M] () -- C:\Program Files\F-Secure\apps\ComputerSecurity\FSGUI\flyerres.eng MOD - [2012-03-15 18:00:34 | 000,049,152 | ---- | M] () -- C:\Program Files\F-Secure\apps\ComputerSecurity\FSGUI\fsavures.eng MOD - [2011-08-19 16:33:28 | 000,047,960 | ---- | M] () -- C:\Program Files\IObit\Smart Defrag 2\NtfsData.dll MOD - [2011-03-21 17:30:06 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2011-03-21 17:30:06 | 000,324,896 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libtidy.dll MOD - [2010-09-07 18:47:08 | 000,664,896 | ---- | M] () -- C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe MOD - [2010-08-10 00:01:06 | 000,067,872 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2010-01-30 02:41:12 | 004,254,560 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2012-06-27 12:29:22 | 001,385,896 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc) SRV - [2012-06-21 13:29:36 | 000,163,536 | ---- | M] (F-Secure Corporation) [Auto | Running] -- C:\Program Files\F-Secure\fshoster32.exe -- (fshoster) SRV - [2012-06-19 17:32:30 | 003,048,136 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service) SRV - [2012-05-03 08:31:10 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012-03-15 18:00:44 | 000,213,672 | ---- | M] (F-Secure Corporation) [On_Demand | Running] -- C:\Program Files\F-Secure\apps\ComputerSecurity\Common\FSMA32.EXE -- (FSMA) SRV - [2012-03-15 18:00:38 | 000,610,472 | ---- | M] (F-Secure Corporation) [On_Demand | Running] -- C:\Program Files\F-Secure\apps\ComputerSecurity\FWES\program\fsdfwd.exe -- (FSDFWD) SRV - [2012-03-15 15:55:34 | 000,062,160 | ---- | M] (F-Secure Corporation) [Auto | Running] -- C:\Program Files\F-Secure\apps\CCF_Reputation\fsorsp.exe -- (FSORSPClient) SRV - [2012-03-14 17:38:14 | 000,913,752 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe -- (AdvancedSystemCareService5) SRV - [2012-01-25 03:40:53 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc) SRV - [2012-01-10 00:52:31 | 000,419,624 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2012-01-09 20:17:44 | 000,821,592 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe -- (IMFservice) SRV - [2011-12-12 22:35:08 | 000,751,464 | ---- | M] (Tunngle.net GmbH) [On_Demand | Stopped] -- C:\Program Files\Tunngle\TnglCtrl.exe -- (TunngleService) SRV - [2011-10-15 10:53:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService) SRV - [2011-10-15 01:54:40 | 000,381,248 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2011-06-30 16:16:25 | 000,072,704 | ---- | M] (Autodesk) [Auto | Running] -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe -- (Autodesk Licensing Service) SRV - [2011-04-01 12:14:30 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc) SRV - [2011-03-28 12:21:16 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (SeaPort) SRV - [2011-03-04 11:39:14 | 000,584,488 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Nero\Update\NASvc.exe -- (NAUpdate) SRV - [2010-09-07 18:47:18 | 000,202,048 | ---- | M] () [Auto | Running] -- C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe -- (MotoHelper) SRV - [2010-03-25 10:25:22 | 030,969,208 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service) SRV - [2009-12-02 22:23:52 | 000,209,768 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa) SRV - [2009-12-02 22:23:46 | 000,483,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist) SRV - [2009-07-14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009-07-14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009-07-14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2009-06-04 17:13:20 | 000,230,648 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\Program Files\Stardock\Object Desktop\WindowBlinds\VistaSrv.exe -- (WindowBlinds) SRV - [2007-04-19 15:43:42 | 000,537,520 | ---- | M] ( ) [Auto | Running] -- C:\Windows\System32\lxczcoms.exe -- (lxcz_device) SRV - [2007-04-02 14:15:40 | 000,061,440 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files\Creative\Shared Files\CTDevSrv.exe -- (CTDevice_Srv) SRV - [2006-09-29 12:48:06 | 000,065,536 | ---- | M] () [Auto | Running] -- D:\3d\mentalray\satellite\raysat_3dsmax9_32server.exe -- (mi-raysat_3dsmax9_32) mental ray 3.5 Satellite (32-bit) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Unknown] -- -- (ajood8m4) DRV - [2012-06-29 12:33:07 | 000,144,592 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files\F-Secure\apps\ComputerSecurity\Anti-Virus\minifilter\fsgk.sys -- (F-Secure Gatekeeper) DRV - [2012-06-29 11:28:00 | 000,044,184 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\fsbts.sys -- (fsbts) DRV - [2012-06-29 11:26:24 | 000,072,976 | ---- | M] (F-Secure Corporation) [Kernel | System | Running] -- C:\Program Files\F-Secure\apps\ComputerSecurity\HIPS\drivers\fshs.sys -- (F-Secure HIPS) DRV - [2012-05-29 15:40:40 | 000,054,352 | ---- | M] (F-Secure Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\fsccsys.sys -- (fsccsys1340961806) DRV - [2012-04-08 22:34:59 | 000,428,088 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd) DRV - [2012-03-15 18:00:38 | 000,073,640 | ---- | M] (F-Secure Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\fsdfw.sys -- (FSFW) DRV - [2012-03-15 18:00:38 | 000,038,024 | ---- | M] (F-Secure Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\fses.sys -- (FSES) DRV - [2012-03-15 18:00:28 | 000,014,504 | ---- | M] () [Kernel | System | Running] -- C:\Program Files\F-Secure\apps\ComputerSecurity\Anti-Virus\minifilter\fsvista.sys -- (fsvista) DRV - [2012-02-04 09:09:50 | 000,239,168 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV - [2011-10-15 10:53:00 | 010,327,360 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2011-07-31 19:26:40 | 000,281,760 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt) DRV - [2011-07-31 19:26:38 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt) DRV - [2011-05-25 01:40:10 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\taphss.sys -- (taphss) DRV - [2010-11-26 18:02:20 | 000,015,672 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\SmartDefragDriver.sys -- (SmartDefragDriver) DRV - [2010-11-01 06:08:46 | 000,014,416 | ---- | M] (OpenLibSys.org) [File_System | On_Demand | Stopped] -- C:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys -- (WinRing0_1_2_0) DRV - [2010-06-24 13:46:12 | 000,028,256 | ---- | M] (Applian Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\appliand.sys -- (appliandMP) DRV - [2010-06-18 15:09:48 | 000,023,936 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motmodem.sys -- (motmodem) DRV - [2010-06-18 14:41:34 | 000,019,968 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motccgp.sys -- (motccgp) DRV - [2010-04-01 14:31:50 | 000,023,424 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Motousbnet.sys -- (Motousbnet) DRV - [2010-01-25 19:56:44 | 000,009,472 | ---- | M] (Motorola Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motusbdevice.sys -- (motusbdevice) DRV - [2010-01-05 19:20:10 | 001,500,160 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athur.sys -- (athur) DRV - [2009-12-02 22:23:52 | 000,019,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftvollh.sys -- (Sftvol) DRV - [2009-12-02 22:23:50 | 000,021,864 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\Sftredirlh.sys -- (Sftredir) DRV - [2009-12-02 22:23:48 | 000,195,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftplaylh.sys -- (Sftplay) DRV - [2009-12-02 22:23:46 | 000,550,760 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftfslh.sys -- (Sftfs) DRV - [2009-09-16 08:02:40 | 000,027,136 | ---- | M] (Tunngle.net) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tap0901t.sys -- (tap0901t) TAP-Win32 Adapter V9 (Tunngle) DRV - [2009-07-14 03:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2009-07-14 03:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2009-07-14 03:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2009-07-14 01:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2009-07-14 01:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2009-07-14 01:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2009-03-18 17:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi) DRV - [2009-01-29 17:18:00 | 000,008,320 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motccgpfl.sys -- (motccgpfl) DRV - [2009-01-29 17:11:20 | 000,006,016 | ---- | M] (Motorola Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motfilt.sys -- (BTCFilterService) DRV - [2007-11-02 15:51:30 | 000,006,400 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motswch.sys -- (MotoSwitchService) DRV - [2007-10-25 18:31:08 | 000,616,064 | ---- | M] (PixArt Imaging Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PFC027.SYS -- (PAC207) DRV - [2007-01-04 13:48:04 | 000,104,344 | ---- | M] (Analog Devices Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e4usbaw.sys -- (e4usbaw) DRV - [2007-01-04 13:47:48 | 000,069,656 | ---- | M] (Analog Deivces) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\e4ldr.sys -- (E4LOADER) General Purpose USB Driver (e4ldr.sys) DRV - [2006-09-22 15:06:10 | 000,092,160 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mcdbus.sys -- (mcdbus) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com IE - HKLM\..\URLSearchHook: {94817c02-feac-4aa8-99d8-1cb47bf4d4c0} - C:\Program Files\Spesoft\prxtbSpe0.dll (Conduit Ltd.) IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No CLSID value found IE - HKCU\..\URLSearchHook: {90b49673-5506-483e-b92b-ca0265bd9ca8} - No CLSID value found IE - HKCU\..\URLSearchHook: {94817c02-feac-4aa8-99d8-1cb47bf4d4c0} - C:\Program Files\Spesoft\prxtbSpe0.dll (Conduit Ltd.) IE - HKCU\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaulturl: "" FF - prefs.js..browser.search.useDBForOrder: true FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.110.0: C:\Program Files\Battlelog Web Plugins\1.110.0\npesnlaunch.dll File not found FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.118.0: C:\Program Files\Battlelog Web Plugins\1.118.0\npesnlaunch.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.122.0: C:\Program Files\Battlelog Web Plugins\1.122.0\npesnlaunch.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: E:\office\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: E:\office\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Rafał\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Rafał\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Rafał\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\litmus-ff@f-secure.com: C:\Program Files\F-Secure\apps\OnlineSafety\BPP\litmus-ff@f-secure.com\ [2012-06-29 11:23:23 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011-11-19 10:24:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012-07-06 19:04:31 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011-11-18 08:49:58 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2011-04-16 09:48:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rafał\AppData\Roaming\mozilla\Extensions [2012-07-06 19:12:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rafał\AppData\Roaming\mozilla\Firefox\Profiles\icwucnp1.default\extensions [2011-04-26 10:17:02 | 000,000,000 | ---D | M] (SHOUTcast Radio Toolbar) -- C:\Users\Rafał\AppData\Roaming\mozilla\Firefox\Profiles\icwucnp1.default\extensions\{12e4c684-c03e-4e4d-85bc-0c065e7a9489} [2012-04-28 19:03:42 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Users\Rafał\AppData\Roaming\mozilla\Firefox\Profiles\icwucnp1.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2} [2012-06-30 20:50:30 | 000,000,000 | ---D | M] (BitTorrentBar Community Toolbar) -- C:\Users\Rafał\AppData\Roaming\mozilla\Firefox\Profiles\icwucnp1.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527} [2012-06-30 20:50:32 | 000,000,000 | ---D | M] (IMVU Inc Community Toolbar) -- C:\Users\Rafał\AppData\Roaming\mozilla\Firefox\Profiles\icwucnp1.default\extensions\{90b49673-5506-483e-b92b-ca0265bd9ca8} [2012-04-28 19:03:43 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Rafał\AppData\Roaming\mozilla\Firefox\Profiles\icwucnp1.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2012-03-03 16:36:07 | 000,000,000 | ---D | M] (TheBflix) -- C:\Users\Rafał\AppData\Roaming\mozilla\Firefox\Profiles\icwucnp1.default\extensions\info@bflix.info [2012-06-26 13:52:59 | 000,000,000 | ---D | M] (OneClickDownloader) -- C:\Users\Rafał\AppData\Roaming\mozilla\Firefox\Profiles\icwucnp1.default\extensions\OneClickDownload@OneClickDownload.com [2012-02-04 09:07:11 | 000,002,055 | ---- | M] () -- C:\Users\Rafał\AppData\Roaming\Mozilla\Firefox\Profiles\icwucnp1.default\searchplugins\daemon-search.xml [2012-06-29 10:55:01 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2012-06-22 01:53:16 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2012-06-29 10:55:01 | 000,000,000 | ---D | M] (ArcaBit Ext.) -- C:\Program Files\Mozilla Firefox\extensions\arcabit@www.arcabit.pl File not found (No name found) -- C:\USERS\RAFAĹ‚\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ICWUCNP1.DEFAULT\EXTENSIONS\{59C81DF5-4B7A-477B-912D-4E0FDF64E5F2} File not found (No name found) -- C:\USERS\RAFAĹ‚\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ICWUCNP1.DEFAULT\EXTENSIONS\{76063E7F-3558-4B68-8287-54EB6512ADC0}.XPI [2011-11-19 10:24:41 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2011-05-02 23:11:36 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2011-03-22 20:38:12 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll [2011-10-21 16:11:32 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2011-10-21 16:11:32 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2011-10-21 16:11:32 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2011-10-21 16:11:32 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2011-10-21 16:11:32 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2011-10-21 16:11:32 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml [color=#E56717]========== Chrome ==========[/color] CHR - default_search_provider: (Enabled) CHR - default_search_provider: search_url = CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms} CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Users\Rafa\u0142\AppData\Local\Google\Chrome\Application\20.0.1132.47\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Rafa\u0142\AppData\Local\Google\Chrome\Application\20.0.1132.47\pdf.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Rafa\u0142\AppData\Local\Google\Chrome\Application\20.0.1132.47\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Rafa\u0142\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll CHR - plugin: (Enabled) = C:\Users\Rafa\u0142\AppData\Local\Google\Chrome\User Data\Default\Extensions\clbfjfbnelcflpgpklppgplejolacbej\1.0.5_0\chromeNPAPI.dll CHR - plugin: Skype Click to Call (Enabled) = C:\Users\Rafa\u0142\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0\npSkypeChromePlugin.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: Java Deployment Toolkit 6.0.250.6 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U25 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: downloadUpdater (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnu.dll CHR - plugin: downloadUpdater2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll CHR - plugin: (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files\Battlelog Web Plugins\1.118.0\npesnlaunch.dll CHR - plugin: ESN Sonar API (Enabled) = C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll CHR - plugin: Google Update (Enabled) = C:\Users\Rafa\u0142\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll CHR - plugin: Microsoft Office 2010 (Enabled) = E:\office\Office14\NPAUTHZ.DLL CHR - plugin: Microsoft Office 2010 (Enabled) = E:\office\Office14\NPSPWRAP.DLL O1 HOSTS File: ([2009-06-10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\office\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Spesoft Toolbar) - {94817c02-feac-4aa8-99d8-1cb47bf4d4c0} - C:\Program Files\Spesoft\prxtbSpe0.dll (Conduit Ltd.) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\office\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (Browsing Protection Class) - {C6867EB7-8350-4856-877F-93CF8AE3DC9C} - C:\Program Files\F-Secure\apps\OnlineSafety\BPP\iescript\BaseLitmus.dll (F-Secure Corporation) O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) O3 - HKLM\..\Toolbar: (Browsing Protection Toolbar) - {265EEE8E-3228-44D3-AEA5-F7FDF5860049} - C:\Program Files\F-Secure\apps\OnlineSafety\BPP\iescript\BaseLitmus.dll (F-Secure Corporation) O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) O3 - HKLM\..\Toolbar: (Spesoft Toolbar) - {94817c02-feac-4aa8-99d8-1cb47bf4d4c0} - C:\Program Files\Spesoft\prxtbSpe0.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {90B49673-5506-483E-B92B-CA0265BD9CA8} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (Spesoft Toolbar) - {94817C02-FEAC-4AA8-99D8-1CB47BF4D4C0} - C:\Program Files\Spesoft\prxtbSpe0.dll (Conduit Ltd.) O4 - HKLM..\Run: [BCSSync] E:\office\Office14\BCSSync.exe (Microsoft Corporation) O4 - HKLM..\Run: [F-Secure Hoster (666)] C:\Program Files\F-Secure\fshoster32.exe (F-Secure Corporation) O4 - HKLM..\Run: [F-Secure Manager] C:\Program Files\F-Secure\apps\ComputerSecurity\Common\FSM32.EXE (F-Secure Corporation) O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.) O4 - HKLM..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe (PixArt Imaging Incorporation) O4 - HKLM..\Run: [PAC207_Monitor] C:\Windows\PixArt\PAC207\Monitor.exe (PixArt Imaging Incorporation) O4 - HKLM..\Run: [PowerGramo] C:\Program Files\Monsters\PowerGramo\PowerGramo.exe (Freebird) O4 - HKCU..\Run: [AdobeBridge] File not found O4 - HKCU..\Run: [Advanced SystemCare 5] C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe (IObit) O4 - HKCU..\Run: [Akamai NetSession Interface] "C:\Users\Rafał\AppData\Local\Akamai\netsession_win.exe" File not found O4 - HKCU..\Run: [CTZDetec.exe] C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe (Creative Technology Ltd.) O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKCU..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.) O4 - HKCU..\Run: [MX Skype Recorder] "C:\ProgramData\MXSkypeRecorder\MXSkypeRecorder.exe" /autorun File not found O4 - HKCU..\Run: [RGSC] E:\Grand theft auto IV\Rockstar Games Social Club\RGSCLauncher.exe (Take-Two Interactive Software, Inc.) O4 - Startup: C:\Users\Rafał\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - E:\office\Office14\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: Wyślij &do programu OneNote - E:\office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: ArcaVir >> - {40525A66-DB98-480D-BCF9-7AF88C1AF438} - C:\Program Files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll File not found O9 - Extra 'Tools' menuitem : ArcaVir >> - {40525A66-DB98-480D-BCF9-7AF88C1AF438} - C:\Program Files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll File not found O9 - Extra Button: &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - E:\office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : &Notatki połączone programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - E:\office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\Rafał\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk () O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites) O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites) O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites) O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A7CC3D70-4190-47BD-8010-66171340718E}: DhcpNameServer = 192.168.1.1 192.168.1.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (c:\windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - E:\office\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009-06-10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2011-06-18 20:43:22 | 000,000,000 | ---D | M] - D:\AUTODESK.3DSMAX.V9.0.DVD-ISO -- [ NTFS ] O32 - AutoRun File - [2011-04-15 23:20:01 | 000,000,000 | -H-- | M] () - D:\Autodesk_3ds_Max_2012_English_Win_32-64bit.exe.part -- [ NTFS ] O33 - MountPoints2\{1fa9186b-4eff-11e1-a209-df239a9b3f79}\Shell - "" = AutoRun O33 - MountPoints2\{1fa9186b-4eff-11e1-a209-df239a9b3f79}\Shell\AutoRun\command - "" = G:\setup.exe O33 - MountPoints2\{7e73ec79-9e30-11e0-800b-00241d2e23b9}\Shell - "" = AutoRun O33 - MountPoints2\{7e73ec79-9e30-11e0-800b-00241d2e23b9}\Shell\AutoRun\command - "" = L:\SetupPuma.exe O33 - MountPoints2\{7e73ec79-9e30-11e0-800b-00241d2e23b9}\Shell\menu1\command - "" = L:\SetupPuma.exe O33 - MountPoints2\{92aaf01b-81a0-11e1-aafc-8f32a7611e91}\Shell - "" = AutoRun O33 - MountPoints2\{92aaf01b-81a0-11e1-aafc-8f32a7611e91}\Shell\AutoRun\command - "" = H:\AutoRunMorrowind.exe O33 - MountPoints2\{92aaf01b-81a0-11e1-aafc-8f32a7611e91}\Shell\install\command - "" = H:\Setup.exe O33 - MountPoints2\{bab1b1b1-e3a4-11e0-acc8-00241d2e23b9}\Shell - "" = AutoRun O33 - MountPoints2\{bab1b1b1-e3a4-11e0-acc8-00241d2e23b9}\Shell\AutoRun\command - "" = I:\setup.exe -a O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-07-06 19:02:35 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2012-07-06 09:59:31 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{CC6C8439-3C81-43F5-9CAA-C857C24D9EB1} [2012-07-06 09:59:07 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{7D13B323-A9D9-40C7-B5D8-40B088301F5C} [2012-07-05 21:34:32 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{EC4F3E3A-6FCC-4EFD-B00F-A24D7B511FEE} [2012-07-05 09:33:48 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{40873755-502F-4308-857A-3485F849F898} [2012-07-05 09:33:01 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{4932B634-AAF6-4C52-B261-99C58E4D0B73} [2012-07-04 20:39:39 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{FC258CA6-8045-4DF0-814E-55782FB4C090} [2012-07-04 20:39:16 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{F91D85FF-A03C-4774-87D6-C442AECB4AE9} [2012-07-04 08:38:47 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{B1D03033-D86B-433D-A244-820DD8FA305F} [2012-07-04 08:38:26 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{1C77EADB-8336-4108-843D-005C94FF5150} [2012-07-03 20:37:52 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{AB9E34FF-EBBF-4DF6-9A7F-C29D08568707} [2012-07-03 20:37:29 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{AA6CAEE1-0474-45E3-B452-C8926E02C498} [2012-07-03 08:36:44 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{6B3EA066-3CFF-4501-9B6C-DB0661212E0B} [2012-07-03 08:36:28 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{DE0CE725-ADA5-49B3-907E-8E8BED79294F} [2012-07-02 21:48:31 | 000,000,000 | ---D | C] -- C:\Users\Rafał\Desktop\Nowy folder (2) [2012-07-02 21:44:43 | 000,000,000 | ---D | C] -- C:\Users\Rafał\Documents\textures [2012-07-02 21:44:43 | 000,000,000 | ---D | C] -- C:\Users\Rafał\Documents\scripts [2012-07-02 20:22:39 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{468BC27A-C63B-4E0F-BCA6-54B2C2C42F9A} [2012-07-02 20:22:28 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{B5BA2828-0B44-4095-ABEA-5EBCADCD8417} [2012-07-02 14:05:13 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{5485FAEE-89B3-4B4C-85D7-8C961420F7F8} [2012-07-02 08:17:14 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{8B09A643-A814-444B-9497-0712FC5C6FF0} [2012-07-01 11:01:25 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{62DED119-9D9D-475C-A5E3-54F1F7ABC9DD} [2012-07-01 11:00:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi [2012-07-01 11:00:47 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn Hamachi [2012-07-01 11:00:16 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{E79A2D32-3C0C-4069-BC0D-58CBC2F6F39D} [2012-06-30 20:49:36 | 009,873,328 | ---- | C] (http://yourfiledownloader.com) -- C:\Users\Rafał\Documents\skyrim_patch_1.5_razor1911.rar_downloader_224a.exe [2012-06-30 09:33:58 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{2279317A-C6D1-4EA9-A1F2-31D29D065B7B} [2012-06-30 09:32:30 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{6CF75023-0FAE-47CD-B410-2F16B718FC0F} [2012-06-29 14:02:54 | 000,000,000 | ---D | C] -- C:\Users\Rafał\Documents\FIFA 12 [2012-06-29 11:23:26 | 000,054,352 | ---- | C] (F-Secure Corporation) -- C:\Windows\System32\drivers\fsccsys.sys [2012-06-29 11:22:28 | 000,038,024 | ---- | C] (F-Secure Corporation) -- C:\Windows\System32\drivers\fses.sys [2012-06-29 11:22:26 | 000,073,640 | ---- | C] (F-Secure Corporation) -- C:\Windows\System32\drivers\fsdfw.sys [2012-06-29 11:17:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\F-Secure [2012-06-29 11:16:48 | 000,000,000 | ---D | C] -- C:\Program Files\F-Secure [2012-06-29 11:13:11 | 000,000,000 | ---D | C] -- C:\ProgramData\F-Secure [2012-06-29 10:52:07 | 000,000,000 | ---D | C] -- C:\ProgramData\ArcaBit [2012-06-29 09:03:40 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{8A92E82A-096F-4EC3-A8C8-681920E1170B} [2012-06-28 21:03:01 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{ECDD8888-7B8F-47F7-831E-68F86AB48D15} [2012-06-28 09:02:22 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{084651FB-CFB9-4258-99D7-5FD978EA22B5} [2012-06-28 09:01:58 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{52EA4F27-F71F-4A1B-BEE3-3323408D1D62} [2012-06-27 08:37:27 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{C78ED925-CEEB-4970-AD14-AC00551030D3} [2012-06-27 08:37:13 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{76C69609-47A2-4B38-813A-0C0B3C5FC962} [2012-06-27 08:30:17 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{99A4F503-9746-41CB-AC9F-E9CBC81DF37B} [2012-06-27 01:40:24 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{23C01FCA-C939-44AB-A137-92369E9E6F17} [2012-06-26 13:39:56 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{A028E60D-6EBC-494F-A256-86F612A3968E} [2012-06-26 13:39:33 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{28574CFD-E923-44FA-A7FE-04041017F8EA} [2012-06-25 11:56:53 | 000,000,000 | ---D | C] -- C:\Program Files\Grand Theft Auto Vice City [2012-06-25 10:57:40 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{C8439083-AB95-4941-AE72-7400A6F3CF41} [2012-06-25 10:57:13 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{B675CFF8-EC6C-4F43-AE9B-1776336B94F7} [2012-06-24 16:07:24 | 000,000,000 | ---D | C] -- C:\Users\Rafał\Documents\GTA Vice City User Files [2012-06-24 09:59:19 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{1804CEE4-C679-4E37-90CB-70F98FDCCCBF} [2012-06-24 09:58:45 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{0DDE2183-F11C-4E74-ABF5-DFAFAB2F3344} [2012-06-23 23:00:19 | 000,000,000 | ---D | C] -- C:\Users\Rafał\Desktop\np [2012-06-23 09:15:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MegaDev [2012-06-23 09:15:12 | 000,000,000 | ---D | C] -- C:\Program Files\MegaDev [2012-06-22 08:32:04 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{7C439103-A687-43AC-A14C-14C32EA43B60} [2012-06-22 08:31:37 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{324A30D5-0507-4587-B86E-987F68EB46A0} [2012-06-21 07:50:50 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{A66BC5BB-18A2-49C8-A0A9-0160828447B4} [2012-06-21 07:50:38 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{E893B439-6A40-4DE8-ACAB-6B56DA00AE81} [2012-06-20 13:26:45 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{781B7912-3BC4-41F8-AF3C-49610F69D1FD} [2012-06-20 13:26:33 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{3B022E92-EEA1-44CF-AFE1-0C8C37174686} [2012-06-20 07:07:42 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{BF8AEE63-5D6B-41AF-8AD5-0A90CD2B0B4F} [2012-06-19 10:40:36 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{101BD708-D1CC-438B-92D0-51613EAC1086} [2012-06-19 10:40:15 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{FA9FC2E0-339D-468E-89A8-4F608D7723BB} [2012-06-18 15:30:42 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{11D08DD6-78A9-40F5-83A1-3A8681A137CB} [2012-06-16 23:26:15 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{3D1193BE-9B5D-42E6-BDE4-E79E92793554} [2012-06-16 17:47:08 | 000,000,000 | ---D | C] -- C:\Crash [2012-06-16 17:38:07 | 000,347,208 | ---- | C] (Softonic) -- C:\Users\Rafał\Documents\SoftonicDownloader_for_dc-universe-online.exe [2012-06-16 08:09:20 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{3627BC34-5287-4A50-9EF5-F87E8BCA1004} [2012-06-15 15:20:55 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{852F159C-C740-45D8-9C18-6A949114BF61} [2012-06-13 19:16:40 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Roaming\SecondLife [2012-06-13 19:16:40 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\SecondLife [2012-06-13 19:16:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Second Life Viewer [2012-06-13 19:16:23 | 000,000,000 | ---D | C] -- C:\Program Files\SecondLifeViewer [2012-06-13 16:33:03 | 000,000,000 | ---D | C] -- C:\Program Files\1ClickDownload [2012-06-13 15:28:26 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{8D50CE97-54C6-4FE1-9029-2F6490942176} [2012-06-13 15:28:01 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{21373EB0-FE01-437C-881B-26F9AF92C44C} [2012-06-12 15:41:31 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{428C12C6-39B0-4D08-AEAE-B2631E37A27E} [2012-06-12 15:41:00 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{176C82EE-8CA2-4994-95D8-C7A562B0768C} [2012-06-11 17:23:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Creative Assembly [2012-06-11 16:58:24 | 000,000,000 | ---D | C] -- C:\Users\Rafał\Desktop\savy empire [2012-06-11 15:28:40 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{56454FB5-D942-46C0-A388-92860EA2EA1B} [2012-06-11 15:28:28 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{0938C405-50CC-481F-94EB-07E6531EA193} [2012-06-08 23:57:23 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Napoleon Total Factions [2012-06-08 09:37:07 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{8A4B2DDD-1D19-469C-BF1E-E0CB6A96BEDB} [2012-06-07 21:36:29 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{1D9F9D34-C974-45EC-AA9D-E3907562654E} [2012-06-07 09:35:38 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{80858190-B633-4DAD-B17D-99C6B7C12DE2} [2012-06-07 09:35:26 | 000,000,000 | ---D | C] -- C:\Users\Rafał\AppData\Local\{03793E1E-B0F4-4FD9-8279-C2B27119869C} [2006-11-20 09:01:08 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Program Files\Common Files\AMCap.exe [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-07-06 19:21:33 | 000,014,224 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012-07-06 19:21:33 | 000,014,224 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012-07-06 19:13:33 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012-07-06 19:13:28 | 2817,384,448 | -HS- | M] () -- C:\hiberfil.sys [2012-07-06 19:11:00 | 000,001,058 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3691077182-3707542728-1493853906-1000UA.job [2012-07-06 02:11:04 | 000,001,006 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3691077182-3707542728-1493853906-1000Core.job [2012-07-05 23:42:19 | 000,740,302 | ---- | M] () -- C:\Windows\System32\perfh015.dat [2012-07-05 23:42:19 | 000,654,510 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012-07-05 23:42:19 | 000,155,330 | ---- | M] () -- C:\Windows\System32\perfc015.dat [2012-07-05 23:42:19 | 000,121,782 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012-07-04 09:21:53 | 000,000,411 | ---- | M] () -- C:\Users\Public\Desktop\Morrowind.lnk [2012-07-02 21:47:07 | 022,423,201 | ---- | M] () -- C:\Users\Rafał\Documents\Buildable_Home_v1_71-18480-1-71.rar [2012-07-02 21:42:20 | 013,152,691 | ---- | M] () -- C:\Users\Rafał\Documents\Bandolier_-_Bags_and_Pouches_v1dot1-16438-1-101.zip [2012-07-02 21:37:50 | 000,974,010 | ---- | M] () -- C:\Users\Rafał\Documents\FollowerWander6-3-9504-6-3.zip [2012-07-02 21:14:35 | 000,002,363 | ---- | M] () -- C:\Users\Rafał\Desktop\Google Chrome.lnk [2012-06-30 20:50:17 | 000,000,993 | ---- | M] () -- C:\user.js [2012-06-30 20:49:59 | 000,001,925 | ---- | M] () -- C:\Users\Public\Desktop\YourFile Downloader.lnk [2012-06-30 20:49:49 | 009,873,328 | ---- | M] (http://yourfiledownloader.com) -- C:\Users\Rafał\Documents\skyrim_patch_1.5_razor1911.rar_downloader_224a.exe [2012-06-29 14:00:48 | 000,000,720 | ---- | M] () -- C:\Users\Public\Desktop\FIFA 12.lnk [2012-06-29 11:28:00 | 000,044,184 | ---- | M] () -- C:\Windows\System32\drivers\fsbts.sys [2012-06-29 11:22:28 | 000,019,569 | ---- | M] () -- C:\Windows\prodsett_copy.ini [2012-06-29 11:17:10 | 000,001,930 | ---- | M] () -- C:\Users\Public\Desktop\F-Secure Launch pad.lnk [2012-06-29 11:02:07 | 004,029,448 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012-06-29 09:57:34 | 000,157,416 | -H-- | M] () -- C:\Windows\System32\mlfcache.dat [2012-06-28 11:36:10 | 000,000,023 | ---- | M] () -- C:\Windows\BlendSettings.ini [2012-06-27 15:33:42 | 000,000,198 | ---- | M] () -- C:\Users\Rafał\Desktop\Champions Online Free For All.url [2012-06-26 14:02:41 | 000,274,168 | ---- | M] () -- C:\Users\Rafał\Documents\Iron_Man_2_lektor_PL.exe [2012-06-26 13:59:43 | 000,014,580 | ---- | M] () -- C:\Users\Rafał\Documents\Iron Man 2 Lektor PL.torrent [2012-06-26 13:56:28 | 000,056,515 | ---- | M] () -- C:\Users\Rafał\Documents\IRON MAN 2 - 2010 DVDRip Lektor PL meti-FILMY-mega.avi.torrent [2012-06-26 13:55:09 | 000,274,088 | ---- | M] () -- C:\Users\Rafał\Documents\Iron_Man_2__2010__[DVDRip.XviD-EM0C0RE]_[Lektor_PL].exe [2012-06-26 13:52:52 | 000,001,921 | ---- | M] () -- C:\Users\Rafał\Desktop\Download Iron_Man_2_(2010)_DVDRip_XviD-MAXSPEED.lnk [2012-06-26 13:52:42 | 000,274,064 | ---- | M] () -- C:\Users\Rafał\Documents\Iron_Man_2_(2010)_DVDRip_XviD-MAXSPEED.exe [2012-06-23 23:04:43 | 000,020,751 | ---- | M] () -- C:\Users\Rafał\Documents\The_Avengers_2012_TS_XviD_AC3-ADTRG.torrent [2012-06-23 19:03:10 | 000,140,800 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2012-06-23 19:03:00 | 000,283,304 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr [2012-06-23 19:02:45 | 000,280,904 | ---- | M] () -- C:\Windows\System32\PnkBstrB.ex0 [2012-06-23 09:15:16 | 000,002,144 | ---- | M] () -- C:\Users\Rafał\Desktop\MegaTrainer eXperience.lnk [2012-06-23 09:15:16 | 000,002,111 | ---- | M] () -- C:\Users\Rafał\Desktop\MT-X - Guide.lnk [2012-06-20 17:08:06 | 000,075,118 | ---- | M] () -- C:\Users\Rafał\Documents\Dr_Bandolier.esp [2012-06-20 07:05:39 | 339,102,898 | ---- | M] () -- C:\Windows\MEMORY.DMP [2012-06-19 21:12:33 | 003,878,112 | ---- | M] () -- C:\Users\Rafał\Documents\battlelog-web-plugins-1.122.0-retail-prod.exe [2012-06-19 01:16:40 | 000,000,707 | ---- | M] () -- C:\Users\Rafał\Desktop\DC Universe Online Live.lnk [2012-06-16 17:39:05 | 017,117,624 | ---- | M] () -- C:\Users\Rafał\Documents\DCUO_setup.exe [2012-06-16 17:38:08 | 000,347,208 | ---- | M] (Softonic) -- C:\Users\Rafał\Documents\SoftonicDownloader_for_dc-universe-online.exe [2012-06-13 19:16:38 | 000,001,087 | ---- | M] () -- C:\Users\Public\Desktop\Second Life Viewer.lnk [2012-06-13 16:33:36 | 000,000,218 | ---- | M] () -- C:\Users\Rafał\Desktop\SweetPcFix.url [2012-06-13 16:33:10 | 000,001,886 | ---- | M] () -- C:\Users\Rafał\Desktop\Download The_Elder_Scrolls_III___Morrowind.lnk [2012-06-13 16:32:04 | 011,854,463 | ---- | M] () -- C:\Users\Rafał\Documents\sa-mp-0.3e-install.zip [2012-06-13 16:25:53 | 010,877,829 | ---- | M] () -- C:\Users\Rafał\Documents\sa-mp-0.3d-install.zip [2012-06-11 17:23:39 | 000,000,731 | ---- | M] () -- C:\Users\Rafał\Desktop\Empire Total War™.lnk [2012-06-09 00:16:32 | 000,000,664 | ---- | M] () -- C:\Users\Rafał\Desktop\NTF.lnk [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-07-04 09:21:53 | 000,000,411 | ---- | C] () -- C:\Users\Public\Desktop\Morrowind.lnk [2012-07-02 21:45:46 | 022,423,201 | ---- | C] () -- C:\Users\Rafał\Documents\Buildable_Home_v1_71-18480-1-71.rar [2012-07-02 21:44:43 | 000,075,118 | ---- | C] () -- C:\Users\Rafał\Documents\Dr_Bandolier.esp [2012-07-02 21:40:07 | 013,152,691 | ---- | C] () -- C:\Users\Rafał\Documents\Bandolier_-_Bags_and_Pouches_v1dot1-16438-1-101.zip [2012-07-02 21:37:58 | 001,156,430 | ---- | C] () -- C:\Users\Rafał\Documents\FollowerWander2.bsa [2012-07-02 21:37:58 | 000,050,862 | ---- | C] () -- C:\Users\Rafał\Documents\FollowerWander2.esp [2012-07-02 21:37:41 | 000,974,010 | ---- | C] () -- C:\Users\Rafał\Documents\FollowerWander6-3-9504-6-3.zip [2012-06-29 14:00:48 | 000,000,720 | ---- | C] () -- C:\Users\Public\Desktop\FIFA 12.lnk [2012-06-29 14:00:48 | 000,000,720 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 12.lnk [2012-06-29 11:22:57 | 000,044,184 | ---- | C] () -- C:\Windows\System32\drivers\fsbts.sys [2012-06-29 11:22:28 | 000,019,569 | ---- | C] () -- C:\Windows\prodsett_copy.ini [2012-06-29 11:17:10 | 000,001,930 | ---- | C] () -- C:\Users\Public\Desktop\F-Secure Launch pad.lnk [2012-06-27 15:33:42 | 000,000,198 | ---- | C] () -- C:\Users\Rafał\Desktop\Champions Online Free For All.url [2012-06-26 14:02:41 | 000,274,168 | ---- | C] () -- C:\Users\Rafał\Documents\Iron_Man_2_lektor_PL.exe [2012-06-26 13:59:43 | 000,014,580 | ---- | C] () -- C:\Users\Rafał\Documents\Iron Man 2 Lektor PL.torrent [2012-06-26 13:56:28 | 000,056,515 | ---- | C] () -- C:\Users\Rafał\Documents\IRON MAN 2 - 2010 DVDRip Lektor PL meti-FILMY-mega.avi.torrent [2012-06-26 13:55:09 | 000,274,088 | ---- | C] () -- C:\Users\Rafał\Documents\Iron_Man_2__2010__[DVDRip.XviD-EM0C0RE]_[Lektor_PL].exe [2012-06-26 13:52:52 | 000,001,921 | ---- | C] () -- C:\Users\Rafał\Desktop\Download Iron_Man_2_(2010)_DVDRip_XviD-MAXSPEED.lnk [2012-06-26 13:52:42 | 000,274,064 | ---- | C] () -- C:\Users\Rafał\Documents\Iron_Man_2_(2010)_DVDRip_XviD-MAXSPEED.exe [2012-06-25 14:25:32 | 000,338,432 | R--- | C] () -- C:\Users\Rafał\Desktop\Mss32.dll [2012-06-23 23:04:43 | 000,020,751 | ---- | C] () -- C:\Users\Rafał\Documents\The_Avengers_2012_TS_XviD_AC3-ADTRG.torrent [2012-06-23 09:15:16 | 000,002,144 | ---- | C] () -- C:\Users\Rafał\Desktop\MegaTrainer eXperience.lnk [2012-06-23 09:15:16 | 000,002,111 | ---- | C] () -- C:\Users\Rafał\Desktop\MT-X - Guide.lnk [2012-06-20 07:05:39 | 339,102,898 | ---- | C] () -- C:\Windows\MEMORY.DMP [2012-06-19 21:12:27 | 003,878,112 | ---- | C] () -- C:\Users\Rafał\Documents\battlelog-web-plugins-1.122.0-retail-prod.exe [2012-06-16 17:46:40 | 000,000,707 | ---- | C] () -- C:\Users\Rafał\Desktop\DC Universe Online Live.lnk [2012-06-16 17:38:20 | 017,117,624 | ---- | C] () -- C:\Users\Rafał\Documents\DCUO_setup.exe [2012-06-13 19:16:38 | 000,001,087 | ---- | C] () -- C:\Users\Public\Desktop\Second Life Viewer.lnk [2012-06-13 16:33:36 | 000,000,218 | ---- | C] () -- C:\Users\Rafał\Desktop\SweetPcFix.url [2012-06-13 16:33:10 | 000,001,886 | ---- | C] () -- C:\Users\Rafał\Desktop\Download The_Elder_Scrolls_III___Morrowind.lnk [2012-06-13 16:32:12 | 011,869,040 | ---- | C] () -- C:\Users\Rafał\Documents\sa-mp-0.3e-install.exe [2012-06-13 16:32:12 | 000,000,052 | ---- | C] () -- C:\Users\Rafał\Documents\GTAMultiplayer.pl.URL [2012-06-13 16:31:47 | 011,854,463 | ---- | C] () -- C:\Users\Rafał\Documents\sa-mp-0.3e-install.zip [2012-06-13 16:26:04 | 010,892,559 | ---- | C] () -- C:\Users\Rafał\Documents\sa-mp-0.3d-install.exe [2012-06-13 16:26:04 | 000,000,052 | ---- | C] () -- C:\Users\Rafał\Documents\GTAMultiplayer.URL [2012-06-13 16:25:39 | 010,877,829 | ---- | C] () -- C:\Users\Rafał\Documents\sa-mp-0.3d-install.zip [2012-06-11 17:23:39 | 000,000,731 | ---- | C] () -- C:\Users\Rafał\Desktop\Empire Total War™.lnk [2012-06-08 23:57:23 | 000,000,664 | ---- | C] () -- C:\Users\Rafał\Desktop\NTF.lnk [2012-05-11 18:01:42 | 000,000,034 | ---- | C] () -- C:\Windows\cdplayer.ini [2012-05-07 17:21:59 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll [2012-04-08 22:49:56 | 000,000,036 | ---- | C] () -- C:\Windows\DTLite.INI [2012-03-30 15:39:25 | 000,015,672 | ---- | C] () -- C:\Windows\System32\drivers\SmartDefragDriver.sys [2012-03-27 11:58:58 | 000,002,719 | ---- | C] () -- C:\Users\Rafał\.recently-used.xbel [2012-03-15 19:47:59 | 055,636,781 | ---- | C] () -- C:\Users\Rafał\AppData\Roaming\.minecraft.rar [2012-02-04 09:28:38 | 000,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini [2012-01-04 19:37:12 | 000,795,510 | ---- | C] () -- C:\Users\Rafał\sa-mp-377.png [2012-01-04 19:37:12 | 000,784,933 | ---- | C] () -- C:\Users\Rafał\sa-mp-378.png [2012-01-04 19:37:12 | 000,780,590 | ---- | C] () -- C:\Users\Rafał\sa-mp-376.png [2011-11-01 09:23:17 | 000,057,904 | ---- | C] () -- C:\Windows\System32\wbload.dll [2011-10-15 01:54:52 | 000,321,856 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe [2011-10-01 23:23:55 | 000,000,017 | ---- | C] () -- C:\Windows\System32\shortcut_ex.dat [2011-09-28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat [2011-09-18 13:40:48 | 000,017,408 | ---- | C] () -- C:\Users\Rafał\AppData\Local\WebpageIcons.db [2011-09-17 17:39:56 | 000,000,000 | ---- | C] () -- C:\Windows\System32\Access.dat [2011-09-16 10:10:09 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll [2011-07-31 19:26:40 | 000,281,760 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys [2011-07-31 19:26:38 | 000,025,888 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys [2011-07-21 14:10:31 | 000,138,056 | ---- | C] () -- C:\Users\Rafał\AppData\Roaming\PnkBstrK.sys [2011-07-21 14:10:10 | 000,840,264 | ---- | C] () -- C:\Windows\System32\pbsvc.exe [2011-07-06 18:48:30 | 000,140,800 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2011-07-06 14:14:57 | 000,283,304 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe [2011-07-06 14:14:53 | 000,076,888 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe [2011-06-30 15:13:04 | 000,000,000 | ---- | C] () -- C:\Users\Rafał\AppData\Roaming\.NANotifyHere [2011-05-25 20:28:04 | 000,000,108 | ---- | C] () -- C:\Windows\Lexstat.ini [2011-05-25 20:26:54 | 001,224,704 | ---- | C] ( ) -- C:\Windows\System32\lxczserv.dll [2011-05-25 20:26:54 | 000,991,232 | ---- | C] ( ) -- C:\Windows\System32\lxczusb1.dll [2011-05-25 20:26:54 | 000,696,320 | ---- | C] ( ) -- C:\Windows\System32\lxczhbn3.dll [2011-05-25 20:26:54 | 000,684,032 | ---- | C] ( ) -- C:\Windows\System32\lxczcomc.dll [2011-05-25 20:26:54 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\lxczpmui.dll [2011-05-25 20:26:54 | 000,585,728 | ---- | C] ( ) -- C:\Windows\System32\lxczlmpm.dll [2011-05-25 20:26:54 | 000,537,520 | ---- | C] ( ) -- C:\Windows\System32\lxczcoms.exe [2011-05-25 20:26:54 | 000,421,888 | ---- | C] ( ) -- C:\Windows\System32\lxczcomm.dll [2011-05-25 20:26:54 | 000,413,696 | ---- | C] () -- C:\Windows\System32\lxczutil.dll [2011-05-25 20:26:54 | 000,413,696 | ---- | C] ( ) -- C:\Windows\System32\lxczinpa.dll [2011-05-25 20:26:54 | 000,397,312 | ---- | C] ( ) -- C:\Windows\System32\lxcziesc.dll [2011-05-25 20:26:54 | 000,385,968 | ---- | C] ( ) -- C:\Windows\System32\lxczih.exe [2011-05-25 20:26:54 | 000,381,872 | ---- | C] ( ) -- C:\Windows\System32\lxczcfg.exe [2011-05-25 20:26:54 | 000,323,584 | ---- | C] ( ) -- C:\Windows\System32\LXCZhcp.dll [2011-05-25 20:26:54 | 000,274,432 | ---- | C] () -- C:\Windows\System32\LXCZinst.dll [2011-05-25 20:26:54 | 000,163,840 | ---- | C] ( ) -- C:\Windows\System32\lxczprox.dll [2011-05-25 20:26:54 | 000,094,208 | ---- | C] ( ) -- C:\Windows\System32\lxczpplc.dll [2011-05-09 16:51:41 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat [2011-05-08 14:19:20 | 000,157,416 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat [2011-04-11 19:46:40 | 000,000,168 | ---- | C] () -- C:\Windows\adidsl.ini [2011-04-11 19:46:40 | 000,000,021 | ---- | C] () -- C:\Windows\Fast800.ini [2011-04-11 19:46:34 | 000,253,008 | ---- | C] () -- C:\Windows\adirasx64.exe [2011-04-11 19:46:34 | 000,194,128 | ---- | C] () -- C:\Windows\adiras.exe [2011-04-11 19:46:34 | 000,127,456 | ---- | C] () -- C:\Windows\System32\IPDETECT.EXE [2011-04-11 19:46:34 | 000,001,094 | ---- | C] () -- C:\Windows\adiras.ini [2011-04-11 19:46:33 | 000,152,132 | ---- | C] () -- C:\Windows\System32\drivers\L1E4P2.BIN [2011-04-11 19:46:33 | 000,152,132 | ---- | C] () -- C:\Windows\System32\drivers\L1E4P1.BIN [2011-04-11 19:46:33 | 000,152,126 | ---- | C] () -- C:\Windows\System32\drivers\L1E9P2.BIN [2011-04-11 19:46:33 | 000,046,892 | ---- | C] () -- C:\Windows\System32\ADADIX16.DLL [2011-04-11 19:46:33 | 000,024,576 | ---- | C] () -- C:\Windows\enddisk32.exe [2011-04-11 19:46:32 | 000,152,220 | ---- | C] () -- C:\Windows\System32\drivers\L1E4I2.BIN [2011-04-11 19:46:32 | 000,152,220 | ---- | C] () -- C:\Windows\System32\drivers\L1E4I1.BIN [2011-04-11 19:46:32 | 000,152,220 | ---- | C] () -- C:\Windows\System32\drivers\L1E4I0.BIN [2011-04-11 19:46:32 | 000,152,132 | ---- | C] () -- C:\Windows\System32\drivers\L1E4P0.BIN [2011-04-11 19:46:32 | 000,152,126 | ---- | C] () -- C:\Windows\System32\drivers\L1E9P1.BIN [2011-04-11 19:46:32 | 000,152,126 | ---- | C] () -- C:\Windows\System32\drivers\L1E9P0.BIN [2011-04-11 19:46:32 | 000,152,126 | ---- | C] () -- C:\Windows\System32\drivers\L1E9I2.BIN [2011-04-11 19:46:32 | 000,152,126 | ---- | C] () -- C:\Windows\System32\drivers\L1E9I1.BIN [2011-04-11 19:46:32 | 000,152,126 | ---- | C] () -- C:\Windows\System32\drivers\L1E9I0.BIN [2011-04-11 19:46:32 | 000,152,036 | ---- | C] () -- C:\Windows\System32\drivers\L1E4D2.BIN [2011-04-11 19:46:32 | 000,152,034 | ---- | C] () -- C:\Windows\System32\drivers\L1E4D1.BIN [2011-04-11 19:46:32 | 000,152,034 | ---- | C] () -- C:\Windows\System32\drivers\L1E4D0.BIN [2011-04-11 19:46:32 | 000,022,395 | ---- | C] () -- C:\Windows\System32\drivers\fpga.bin [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 816 bytes -> C:\Users\Rafał\Desktop\Call of Duty: Modern Warfare 3.lnk @Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:05EE1EEF < End of report >