OTL logfile created on: 26-07-2012 15:47:58 - Run 1 OTL by OldTimer - Version 3.2.54.1 Folder = F:\ Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.19272) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: dd-MM-yyyy 2,00 Gb Total Physical Memory | 1,28 Gb Available Physical Memory | 63,87% Memory free 4,23 Gb Paging File | 3,82 Gb Available in Paging File | 90,44% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 116,44 Gb Total Space | 5,88 Gb Free Space | 5,05% Space Free | Partition Type: NTFS Drive D: | 108,63 Gb Total Space | 5,14 Gb Free Space | 4,73% Space Free | Partition Type: NTFS Drive F: | 880,69 Mb Total Space | 1,30 Mb Free Space | 0,15% Space Free | Partition Type: FAT Computer Name: Franki-PC | User Name: Franki | Logged in as Administrator. Boot Mode: SafeMode | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-07-26 15:08:30 | 000,596,480 | ---- | M] (OldTimer Tools) -- F:\OTL.exe PRC - [2012-06-22 21:17:56 | 003,075,936 | ---- | M] (Piriform Ltd) -- C:\Program Files\CCleaner\CCleaner.exe PRC - [2012-03-26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe PRC - [2009-04-11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012-06-23 01:26:58 | 000,036,864 | ---- | M] () -- C:\Program Files\CCleaner\Lang\lang-1045.dll MOD - [2011-08-01 00:27:26 | 003,532,800 | ---- | M] () -- C:\Program Files\VistaCodecPack\filters\ffdshow.ax MOD - [2010-12-29 02:19:12 | 000,045,056 | ---- | M] () -- C:\Windows\System32\ff_acm.acm MOD - [2009-08-11 20:18:28 | 000,497,664 | ---- | M] () -- C:\Windows\System32\ac3filter.acm MOD - [2007-08-08 12:52:08 | 000,331,776 | ---- | M] () -- C:\Program Files\ASUS\ASUS Data Security Manager\AdsmendecExt.dll MOD - [2007-06-15 20:28:36 | 000,147,456 | ---- | M] () -- C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt.dll MOD - [2007-06-02 03:08:18 | 000,143,360 | ---- | M] () -- C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll MOD - [2004-01-22 18:36:28 | 000,120,832 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2012-06-21 00:33:42 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012-03-26 17:03:40 | 000,214,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv) SRV - [2012-03-26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV - [2011-08-29 11:27:52 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2011-06-06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2010-04-14 16:45:21 | 000,598,696 | ---- | M] ( ) [Auto | Stopped] -- C:\Windows\System32\lxeacoms.exe -- (lxea_device) SRV - [2010-04-14 16:45:14 | 000,193,192 | ---- | M] () [Auto | Stopped] -- C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxeaserv.exe -- (lxeaCATSCustConnectService) SRV - [2009-06-02 10:10:08 | 000,637,952 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) SRV - [2008-01-19 09:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2007-11-06 22:22:26 | 000,092,792 | ---- | M] (CACE Technologies) [On_Demand | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) SRV - [2007-08-08 10:08:40 | 000,094,208 | ---- | M] () [Auto | Stopped] -- C:\Program Files\ATKGFNEX\GFNEXSrv.exe -- (ATKGFNEXSrv) SRV - [2007-08-03 22:24:54 | 000,125,496 | ---- | M] () [Auto | Stopped] -- C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe -- (spmgr) SRV - [2007-05-18 12:31:16 | 000,073,728 | ---- | M] () [Auto | Stopped] -- C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe -- (ADSMService) SRV - [2007-04-19 00:42:33 | 000,024,576 | ---- | M] (Syntek America Inc.) [Auto | Stopped] -- C:\Windows\System32\StkCSrv.exe -- (StkSSrv) SRV - [2007-02-06 04:13:14 | 000,094,208 | ---- | M] () [Auto | Stopped] -- C:\Program Files\ATK Hotkey\ASLDRSrv.exe -- (ASLDRService) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive) DRV - [2012-03-20 20:44:12 | 000,074,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv) DRV - [2011-08-17 10:56:32 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt) DRV - [2011-08-17 10:56:30 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev) DRV - [2011-08-17 10:56:26 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc) DRV - [2011-08-17 10:56:22 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd) DRV - [2010-01-24 22:02:11 | 000,271,360 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt) DRV - [2010-01-24 22:02:07 | 000,018,048 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt) DRV - [2009-07-02 01:59:00 | 009,786,752 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2009-04-03 10:18:44 | 000,049,904 | R--- | M] (Avanquest Software) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BVRPMPR5.SYS -- (BVRPMPR5) DRV - [2009-03-13 13:50:18 | 001,095,808 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\smserial.sys -- (smserial) DRV - [2008-08-26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd) DRV - [2007-12-27 05:40:56 | 000,012,800 | ---- | M] (CSR, plc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BthAvrcp.sys -- (BthAvrcp) DRV - [2007-11-06 22:22:06 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\npf.sys -- (NPF) DRV - [2007-09-26 13:12:22 | 002,251,776 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32) DRV - [2007-08-29 18:38:59 | 000,046,080 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\l160x86.sys -- (AtcL001) DRV - [2007-08-11 06:19:26 | 000,029,752 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [File_System | Boot | Running] -- C:\Windows\System32\drivers\AsDsm.sys -- (AsDsm) DRV - [2007-08-03 06:26:21 | 000,020,936 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys -- (ghaio) DRV - [2007-07-24 21:09:04 | 000,013,880 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Program Files\ATKGFNEX\ASMMAP.sys -- (ASMMAP) DRV - [2007-06-06 04:40:25 | 001,260,672 | ---- | M] (Syntek) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\StkCMini.sys -- (StkCMini) DRV - [2007-03-21 16:02:03 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp) DRV - [2007-02-24 08:42:21 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk) DRV - [2007-01-24 12:08:39 | 000,005,632 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\kbfiltr.sys -- (kbfiltr) DRV - [2007-01-23 10:40:19 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk) DRV - [2006-12-14 09:11:57 | 000,007,680 | ---- | M] (ATK0100) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ATKACPI.sys -- (MTsensor) DRV - [2006-11-02 11:50:17 | 000,041,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tpm.sys -- (TPM) DRV - [2006-11-02 09:30:56 | 000,044,544 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169) DRV - [2006-11-02 09:30:54 | 001,781,760 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw3v32.sys -- (NETw3v32) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000&st=12&barid={4697A619-D45F-4243-938E-7F561DFCA00B} IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3695335105-2956647426-788024086-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=128 IE - HKU\S-1-5-21-3695335105-2956647426-788024086-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2 IE - HKU\S-1-5-21-3695335105-2956647426-788024086-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKU\S-1-5-21-3695335105-2956647426-788024086-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC IE - HKU\S-1-5-21-3695335105-2956647426-788024086-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=113480&tt=060612_8_&babsrc=SP_ss&mntrId=7c120f1b000000000000001e8c966b40 IE - HKU\S-1-5-21-3695335105-2956647426-788024086-1000\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ANT&o=102825&src=crm&q={searchTerms}&locale=&apn_ptnrs=4R&apn_dtid=YYYYYYYYPL&apn_uid=c4c3d1f8-ba5a-49a7-9f34-07437a05a2a2&apn_sauid=6EC247C5-A3AD-4674-85CC-D5C553DC53E2 IE - HKU\S-1-5-21-3695335105-2956647426-788024086-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3695335105-2956647426-788024086-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local [color=#E56717]========== FireFox ==========[/color] FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-07-25 11:37:37 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012-07-13 11:21:20 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010-06-01 15:17:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Franki\AppData\Roaming\mozilla\Extensions [2010-06-01 15:17:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Franki\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2012-07-25 11:43:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Franki\AppData\Roaming\mozilla\Firefox\Profiles\9rs1br2k.default\extensions [2012-07-25 11:43:44 | 000,000,000 | ---D | M] (FireShot) -- C:\Users\Franki\AppData\Roaming\mozilla\Firefox\Profiles\9rs1br2k.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba} [2011-02-05 02:29:47 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Franki\AppData\Roaming\mozilla\Firefox\Profiles\9rs1br2k.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2011-02-05 02:29:47 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Users\Franki\AppData\Roaming\mozilla\Firefox\Profiles\9rs1br2k.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2012-07-14 17:07:13 | 000,000,000 | ---D | M] (SeoQuake) -- C:\Users\Franki\AppData\Roaming\mozilla\Firefox\Profiles\9rs1br2k.default\extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74} [2011-03-20 20:52:29 | 000,000,000 | ---D | M] (Web Developer) -- C:\Users\Franki\AppData\Roaming\mozilla\Firefox\Profiles\9rs1br2k.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12} [2012-06-20 16:40:21 | 000,000,000 | ---D | M] (FoxLingo) -- C:\Users\Franki\AppData\Roaming\mozilla\Firefox\Profiles\9rs1br2k.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66} [2012-07-20 09:17:40 | 000,000,000 | ---D | M] ("Giant Savings") -- C:\Users\Franki\AppData\Roaming\mozilla\Firefox\Profiles\9rs1br2k.default\extensions\crossriderapp4479@crossrider.com [2012-04-22 17:23:32 | 000,000,000 | ---D | M] ("Alexa Toolbar") -- C:\Users\Franki\AppData\Roaming\mozilla\Firefox\Profiles\9rs1br2k.default\extensions\toolbar@alexa.com [2012-07-14 17:14:52 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2012-07-25 11:37:36 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012-03-09 17:05:09 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2011-09-16 12:26:02 | 001,825,680 | ---- | M] (Caminova, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdjvu.dll [2012-07-25 11:37:16 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2012-06-20 10:00:30 | 000,002,352 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml [2012-07-25 11:37:16 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2012-07-25 11:37:16 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2012-07-25 11:37:16 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2012-07-25 11:37:16 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2012-07-25 11:37:16 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml [color=#E56717]========== Chrome ==========[/color] CHR - homepage: http://home.sweetim.com/?crg=3.1010000&st=12&barid={4697A619-D45F-4243-938E-7F561DFCA00B} CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms} CHR - homepage: http://home.sweetim.com/?crg=3.1010000&st=12&barid={4697A619-D45F-4243-938E-7F561DFCA00B} CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\20.0.1132.57\pdf.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\20.0.1132.57\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.2.183.23\npGoogleOneClick8.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - plugin: Default Plug-in (Enabled) = default_plugin CHR - Extension: YouTube = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\ CHR - Extension: YouTube = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\ CHR - Extension: Szukaj w Google = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\ CHR - Extension: Szukaj w Google = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\ CHR - Extension: General Crawler = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel\2.5_0\ CHR - Extension: SweetIM for Facebook = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\Copy of CHR - Extension: SweetIM for Facebook = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\ CHR - Extension: Giant Savings = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndkhncnongaclekkbelchmeafffimifj\1.17.12_0\ CHR - Extension: Gmail = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\ CHR - Extension: Gmail = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ CHR - Extension: YouTube = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\ CHR - Extension: YouTube = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\ CHR - Extension: Szukaj w Google = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\ CHR - Extension: Szukaj w Google = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\ CHR - Extension: General Crawler = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel\2.5_0\ CHR - Extension: SweetIM for Facebook = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\Copy of CHR - Extension: SweetIM for Facebook = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\ CHR - Extension: Giant Savings = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndkhncnongaclekkbelchmeafffimifj\1.17.12_0\ CHR - Extension: Gmail = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\ CHR - Extension: Gmail = C:\Users\Franki\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2009-01-04 22:56:20 | 000,290,820 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O1 - Hosts: 127.0.0.1 www.007guard.com O1 - Hosts: 127.0.0.1 007guard.com O1 - Hosts: 127.0.0.1 008i.com O1 - Hosts: 127.0.0.1 www.008k.com O1 - Hosts: 127.0.0.1 008k.com O1 - Hosts: 127.0.0.1 www.00hq.com O1 - Hosts: 127.0.0.1 00hq.com O1 - Hosts: 127.0.0.1 010402.com O1 - Hosts: 127.0.0.1 www.032439.com O1 - Hosts: 127.0.0.1 032439.com O1 - Hosts: 127.0.0.1 www.0scan.com O1 - Hosts: 127.0.0.1 0scan.com O1 - Hosts: 127.0.0.1 1000gratisproben.com O1 - Hosts: 127.0.0.1 www.1000gratisproben.com O1 - Hosts: 127.0.0.1 www.1001namen.com O1 - Hosts: 127.0.0.1 1001namen.com O1 - Hosts: 127.0.0.1 www.100888290cs.com O1 - Hosts: 127.0.0.1 100888290cs.com O1 - Hosts: 127.0.0.1 www.100sexlinks.com O1 - Hosts: 127.0.0.1 100sexlinks.com O1 - Hosts: 127.0.0.1 www.10sek.com O1 - Hosts: 127.0.0.1 10sek.com O1 - Hosts: 127.0.0.1 www.1-2005-search.com O1 - Hosts: 10017 more lines... O2 - BHO: (Giant Savings) - {11111111-1111-1111-1111-110011441179} - C:\Program Files\Giant Savings\Giant Savings.dll (215 Apps) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (FlashGetBHO) - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Users\Franki\AppData\Roaming\FlashGetBHO\FlashGetBHO.dll (Trend Media Group) O2 - BHO: (Help the General-Search Project) - {CA4520F3-AE13-4FB1-A513-58E23991C86D} - C:\Users\Franki\AppData\Roaming\MEDIAF~1\EXTENS~1\GENCRA~1.DLL () O2 - BHO: (no name) - {EEE6C35C-6118-11DC-9C72-001320C79847} - No CLSID value found. O3 - HKLM\..\Toolbar: (Show Xmlbar Toolbar) - {6B896ADB-4A82-46e2-858C-13134782CE34} - C:\Program Files\Xmlbar\FLV Downloader\IEBar\xbietb.dll (Xmlbar.com) O3 - HKU\S-1-5-21-3695335105-2956647426-788024086-1000\..\Toolbar\ShellBrowser: (no name) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No CLSID value found. O3 - HKU\S-1-5-21-3695335105-2956647426-788024086-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O4 - HKLM..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe () O4 - HKLM..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe () O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMedia.exe (ASUSTeK Computer INC.) O4 - HKLM..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\PL\Programs\Registration.exe (Corel Corporation) O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark S300-S400 Series\ezprint.exe () O4 - HKLM..\Run: [lxeamon.exe] C:\Program Files\Lexmark S300-S400 Series\lxeamon.exe () O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone.exe () O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor) O4 - HKLM..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-21-3695335105-2956647426-788024086-1000..\Run: [FlashGet 3] C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe (Trend Media Corporation Limited) O4 - HKU\S-1-5-21-3695335105-2956647426-788024086-1000..\Run: [Media Finder] "C:\Program Files\Media Finder\Media Finder.exe" /opentotray File not found O4 - HKU\S-1-5-21-3695335105-2956647426-788024086-1000..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - HKU\S-1-5-21-3695335105-2956647426-788024086-1000..\Run: [WcsPlugInService] C:\Users\Franki\AppData\Local\Microsoft\Windows\4337\WcsPlugInService.exe () O4 - Startup: C:\Users\Franki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe () O4 - Startup: C:\Users\Franki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rejestrowanie produktów Corela.lnk = File not found O8 - Extra context menu item: &Xmlbar Search - http://www.xmlbar.com/iebar/iemenu.php?lang=Polish&ver=1.0 File not found O8 - Extra context menu item: Download all links by FlashGet3 - C:\Program Files\FlashGet Network\FlashGet 3\BHO\fdgetallurl.htm () O8 - Extra context menu item: Download by FlashGet3 - C:\Program Files\FlashGet Network\FlashGet 3\BHO\fdgeturl.htm () O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html File not found O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 File not found O9 - Extra Button: Run YoukuDownloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\FLV Downloader\FLVDownloader(xmlbar).exe (Xmlbar.net, Inc.) O9 - Extra 'Tools' menuitem : Video Downloader - {612F6E5C-B314-4bab-93D1-D266AAFBE700} - C:\Program Files\Xmlbar\FLV Downloader\FLVDownloader(xmlbar).exe (Xmlbar.net, Inc.) O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.) O13 - gopher Prefix: missing O15 - HKU\S-1-5-21-3695335105-2956647426-788024086-1000\..Trusted Domains: mks.com.pl ([www] https in Zaufane witryny) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 87.99.33.7 87.99.33.159 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A5B890F0-C5BF-46DF-BA2D-0D3EE35E2308}: DhcpNameServer = 87.99.33.7 87.99.33.159 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\Public\Pictures\Sample Pictures\Green Sea Turtle.jpg O24 - Desktop BackupWallPaper: C:\Users\Public\Pictures\Sample Pictures\Green Sea Turtle.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006-09-18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{adce4ad5-8d97-11df-877d-001e8c966b40}\Shell - "" = AutoRun O33 - MountPoints2\{adce4ad5-8d97-11df-877d-001e8c966b40}\Shell\AutoRun\command - "" = F:\setup.exe AUTORUN=1 O33 - MountPoints2\{ea1f5b9e-bfa2-11de-b5b9-001d60fdd1bf}\Shell - "" = AutoRun O33 - MountPoints2\{ea1f5b9e-bfa2-11de-b5b9-001d60fdd1bf}\Shell\AutoRun\command - "" = G:\WM0453F.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-07-26 10:25:01 | 000,000,000 | ---D | C] -- C:\Users\Franki\AppData\Roaming\hellomoto [2012-07-23 11:26:14 | 000,000,000 | ---D | C] -- C:\Users\Franki\AppData\Roaming\Skype [2012-07-23 11:25:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [2012-07-23 11:25:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype [2012-07-23 11:25:26 | 000,000,000 | R--D | C] -- C:\Program Files\Skype [2012-07-23 11:25:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype [2012-07-21 19:00:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SB Pinger [2012-07-21 19:00:17 | 000,000,000 | ---D | C] -- C:\Program Files\SB Pinger [2012-07-13 11:54:28 | 000,000,000 | ---D | C] -- C:\Users\Franki\AppData\Roaming\Video Downloader(xmlbar) [2012-07-12 03:16:19 | 002,047,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2012-07-11 16:09:58 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll [2012-07-10 23:04:41 | 000,000,000 | ---D | C] -- C:\Users\Franki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++ [2012-07-10 23:04:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ [2012-07-10 23:04:34 | 000,000,000 | ---D | C] -- C:\Users\Franki\AppData\Roaming\Notepad++ [2012-07-10 23:04:34 | 000,000,000 | ---D | C] -- C:\Program Files\Notepad++ [2012-07-04 12:40:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Download Toolz [2012-07-04 12:40:28 | 000,000,000 | ---D | C] -- C:\Program Files\DownloadToolz [2012-07-02 15:13:44 | 000,000,000 | ---D | C] -- C:\Users\Franki\Desktop\Praca [2012-03-12 11:30:17 | 002,371,152 | ---- | C] (DownVision ) -- C:\Users\Franki\AppData\Local\setup.exe [4 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [4 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [11 C:\Users\Franki\Desktop\*.tmp files -> C:\Users\Franki\Desktop\*.tmp -> ] [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-07-26 15:47:07 | 009,437,184 | -HS- | M] () -- C:\Users\Franki\ntuser.dat [2012-07-26 15:31:43 | 000,001,356 | ---- | M] () -- C:\Users\Franki\AppData\Local\d3d9caps.dat [2012-07-26 15:31:43 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini [2012-07-26 15:19:34 | 001,510,476 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI [2012-07-26 15:19:34 | 000,676,602 | ---- | M] () -- C:\Windows\System32\perfh015.dat [2012-07-26 15:19:34 | 000,600,390 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012-07-26 15:19:34 | 000,132,188 | ---- | M] () -- C:\Windows\System32\perfc015.dat [2012-07-26 15:19:34 | 000,105,304 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012-07-26 14:48:13 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012-07-26 14:47:06 | 000,196,608 | ---- | M] () -- C:\Windows\System32\Ikeext.etl [2012-07-26 14:47:06 | 000,001,904 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2012-07-26 14:47:06 | 000,001,904 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2012-07-26 14:47:06 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2012-07-26 14:47:06 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2012-07-26 14:47:05 | 000,524,288 | -HS- | M] () -- C:\Users\Franki\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms [2012-07-26 14:47:05 | 000,065,536 | -HS- | M] () -- C:\Users\Franki\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf [2012-07-26 14:42:59 | 000,080,734 | ---- | M] () -- C:\ProgramData\nvModes.001 [2012-07-26 14:41:45 | 000,080,734 | ---- | M] () -- C:\ProgramData\nvModes.dat [2012-07-26 14:41:43 | 000,001,032 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012-07-26 13:26:14 | 000,000,811 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2012-07-26 13:25:57 | 000,107,520 | ---- | M] () -- C:\Users\Franki\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-07-26 12:50:01 | 000,001,036 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012-07-26 10:59:22 | 001,750,944 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012-07-26 10:46:20 | 000,002,243 | ---- | M] () -- C:\Windows\epplauncher.mif [2012-07-25 15:08:13 | 000,122,002 | ---- | M] () -- C:\Users\Franki\Desktop\814_sterigat.jpg [2012-07-25 14:07:15 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{94DA0606-68D4-4CC9-A795-4927D3F15118}.job [2012-07-25 11:22:00 | 000,045,056 | ---- | M] () -- C:\Windows\System32\acovcnt.exe [2012-07-24 22:50:47 | 000,085,600 | ---- | M] () -- C:\Users\Franki\Desktop\VAT-7(12)_v1-0_062012.pdf [2012-07-24 14:14:45 | 000,000,627 | ---- | M] () -- C:\Users\Franki\Desktop\SB4Edytor.exe — skrót.lnk [2012-07-23 21:40:08 | 000,000,752 | ---- | M] () -- C:\Users\Franki\Desktop\tcCRc7_8.part [2012-07-23 14:15:24 | 008,909,250 | ---- | M] () -- C:\Users\Franki\Desktop\A. OTR Brand Identity Styleguide.pdf.zip [2012-07-23 11:25:36 | 000,001,878 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk [2012-07-21 19:00:20 | 000,000,823 | ---- | M] () -- C:\Users\Franki\Desktop\Uruchom SB Pingera.lnk [2012-07-21 17:49:51 | 000,000,619 | ---- | M] () -- C:\Users\Franki\Desktop\sb4_2012.exe — skrót.lnk [2012-07-17 15:31:23 | 000,095,859 | ---- | M] () -- C:\Users\Franki\Desktop\Ar11829.jpg [2012-07-14 17:14:55 | 000,000,853 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2012-07-13 12:36:33 | 000,000,248 | ---- | M] () -- C:\Windows\System32\secustat.dat [2012-07-13 11:54:26 | 000,001,041 | ---- | M] () -- C:\Users\Franki\Desktop\Video Downloader.lnk [2012-07-13 11:21:20 | 000,001,899 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2012-07-12 03:14:53 | 000,000,240 | ---- | M] () -- C:\Windows\win.ini [2012-07-12 00:53:21 | 000,001,978 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2012-07-11 00:55:11 | 000,004,361 | ---- | M] () -- C:\Users\Franki\Desktop\marketing-point.png [2012-07-11 00:48:02 | 000,021,482 | ---- | M] () -- C:\Users\Franki\Desktop\logo-golden.jpg [2012-07-10 00:33:22 | 002,149,649 | ---- | M] () -- C:\Users\Franki\Desktop\loga.png [2012-07-10 00:20:06 | 000,373,625 | ---- | M] () -- C:\Users\Franki\Desktop\zdrowie.jpg [2012-07-09 17:07:05 | 000,068,703 | ---- | M] () -- C:\Users\Franki\Desktop\blue5.jpg [2012-07-05 15:53:20 | 000,000,670 | ---- | M] () -- C:\Users\Franki\Desktop\2012 — skrót.lnk [2012-07-04 12:40:31 | 000,001,102 | ---- | M] () -- C:\Users\Franki\Desktop\Metacafe Video Downloader.lnk [4 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [4 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ] [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [11 C:\Users\Franki\Desktop\*.tmp files -> C:\Users\Franki\Desktop\*.tmp -> ] [1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-07-26 11:03:09 | 000,001,904 | -H-- | C] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2012-07-26 11:03:09 | 000,001,904 | -H-- | C] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2012-07-26 10:58:07 | 000,196,608 | ---- | C] () -- C:\Windows\System32\Ikeext.etl [2012-07-25 15:08:09 | 000,122,002 | ---- | C] () -- C:\Users\Franki\Desktop\814_sterigat.jpg [2012-07-24 22:47:48 | 000,085,600 | ---- | C] () -- C:\Users\Franki\Desktop\VAT-7(12)_v1-0_062012.pdf [2012-07-24 14:14:45 | 000,000,627 | ---- | C] () -- C:\Users\Franki\Desktop\SB4Edytor.exe — skrót.lnk [2012-07-23 21:39:37 | 000,000,752 | ---- | C] () -- C:\Users\Franki\Desktop\tcCRc7_8.part [2012-07-23 14:15:09 | 008,909,250 | ---- | C] () -- C:\Users\Franki\Desktop\A. OTR Brand Identity Styleguide.pdf.zip [2012-07-23 11:25:36 | 000,001,878 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk [2012-07-21 19:00:20 | 000,000,823 | ---- | C] () -- C:\Users\Franki\Desktop\Uruchom SB Pingera.lnk [2012-07-21 17:46:40 | 000,000,619 | ---- | C] () -- C:\Users\Franki\Desktop\sb4_2012.exe — skrót.lnk [2012-07-17 15:31:14 | 000,095,859 | ---- | C] () -- C:\Users\Franki\Desktop\Ar11829.jpg [2012-07-14 17:14:55 | 000,000,853 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2012-07-13 12:36:33 | 000,000,248 | ---- | C] () -- C:\Windows\System32\secustat.dat [2012-07-13 11:54:26 | 000,001,041 | ---- | C] () -- C:\Users\Franki\Desktop\Video Downloader.lnk [2012-07-13 11:21:20 | 000,001,899 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk [2012-07-13 11:21:20 | 000,001,804 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk [2012-07-11 00:54:32 | 000,004,361 | ---- | C] () -- C:\Users\Franki\Desktop\marketing-point.png [2012-07-11 00:48:01 | 000,021,482 | ---- | C] () -- C:\Users\Franki\Desktop\logo-golden.jpg [2012-07-10 00:33:17 | 002,149,649 | ---- | C] () -- C:\Users\Franki\Desktop\loga.png [2012-07-10 00:20:07 | 000,373,625 | ---- | C] () -- C:\Users\Franki\Desktop\zdrowie.jpg [2012-07-09 17:07:02 | 000,068,703 | ---- | C] () -- C:\Users\Franki\Desktop\blue5.jpg [2012-07-05 15:53:20 | 000,000,670 | ---- | C] () -- C:\Users\Franki\Desktop\2012 — skrót.lnk [2012-07-04 12:40:31 | 000,001,102 | ---- | C] () -- C:\Users\Franki\Desktop\Metacafe Video Downloader.lnk [2012-06-21 09:55:41 | 000,004,407 | ---- | C] () -- C:\Windows\System32\secushr.dat [2012-06-21 09:53:17 | 000,000,025 | ---- | C] () -- C:\Windows\libem.INI [2011-10-31 15:01:20 | 000,040,960 | ---- | C] () -- C:\Windows\System32\lxeavs.dll [2011-10-31 15:01:13 | 000,442,368 | ---- | C] ( ) -- C:\Windows\System32\lxeacoin.dll [2011-10-31 15:01:03 | 000,086,016 | ---- | C] () -- C:\Windows\System32\lxeagcfg.dll [2011-10-31 15:01:02 | 000,294,912 | ---- | C] () -- C:\Windows\System32\lxeacui.dll [2011-10-31 15:01:02 | 000,110,592 | ---- | C] () -- C:\Windows\System32\lxeacuir.dll [2011-10-31 14:58:19 | 000,364,544 | ---- | C] ( ) -- C:\Windows\System32\lxeainpa.dll [2011-10-31 14:58:19 | 000,356,352 | ---- | C] ( ) -- C:\Windows\System32\LXEAhcp.dll [2011-10-31 14:58:19 | 000,331,776 | ---- | C] () -- C:\Windows\System32\LXEAinst.dll [2011-10-31 14:58:18 | 000,847,872 | ---- | C] ( ) -- C:\Windows\System32\lxeausb1.dll [2011-10-31 14:58:18 | 000,344,064 | ---- | C] ( ) -- C:\Windows\System32\lxeaiesc.dll [2011-10-31 14:58:17 | 001,048,576 | ---- | C] ( ) -- C:\Windows\System32\lxeaserv.dll [2011-10-31 14:58:17 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\lxeapmui.dll [2011-10-31 14:58:17 | 000,577,536 | ---- | C] ( ) -- C:\Windows\System32\lxealmpm.dll [2011-10-31 14:58:17 | 000,323,584 | ---- | C] () -- C:\Windows\System32\lxeains.dll [2011-10-31 14:58:17 | 000,262,144 | ---- | C] () -- C:\Windows\System32\lxeainsb.dll [2011-10-31 14:58:17 | 000,110,592 | ---- | C] () -- C:\Windows\System32\lxeainsr.dll [2011-10-31 14:58:17 | 000,057,344 | ---- | C] () -- C:\Windows\System32\lxeajswr.dll [2011-10-31 14:58:16 | 000,688,128 | ---- | C] ( ) -- C:\Windows\System32\lxeahbn3.dll [2011-10-31 14:58:16 | 000,598,696 | ---- | C] ( ) -- C:\Windows\System32\lxeacoms.exe [2011-10-31 14:58:16 | 000,324,264 | ---- | C] ( ) -- C:\Windows\System32\lxeaih.exe [2011-10-31 14:58:16 | 000,253,952 | ---- | C] () -- C:\Windows\System32\lxeacu.dll [2011-10-31 14:58:16 | 000,208,896 | ---- | C] () -- C:\Windows\System32\lxeagrd.dll [2011-10-31 14:58:16 | 000,090,112 | ---- | C] () -- C:\Windows\System32\lxeacub.dll [2011-10-31 14:58:16 | 000,036,864 | ---- | C] () -- C:\Windows\System32\lxeacur.dll [2011-10-31 14:58:15 | 000,802,816 | ---- | C] ( ) -- C:\Windows\System32\lxeacomc.dll [2011-10-31 14:58:15 | 000,373,416 | ---- | C] ( ) -- C:\Windows\System32\lxeacfg.exe [2011-10-31 14:58:15 | 000,372,736 | ---- | C] ( ) -- C:\Windows\System32\lxeacomm.dll [2011-10-31 14:58:08 | 000,299,008 | ---- | C] () -- C:\Windows\System32\LXEAsm.dll [2011-10-31 14:58:08 | 000,024,576 | ---- | C] () -- C:\Windows\System32\LXEAsmr.dll [2011-07-30 11:57:46 | 003,999,744 | ---- | C] () -- C:\Windows\System32\x264vfw.dll [2011-07-12 19:56:50 | 000,074,752 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll [2011-03-19 11:06:02 | 000,240,640 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll [2011-03-19 11:04:28 | 000,650,752 | ---- | C] () -- C:\Windows\System32\xvidcore.dll [2011-01-20 15:16:48 | 000,000,900 | ---- | C] () -- C:\Users\Franki\.recently-used.xbel [2011-01-12 11:43:45 | 000,001,356 | ---- | C] () -- C:\Users\Franki\AppData\Local\d3d9caps.dat [2010-12-28 22:32:41 | 000,080,734 | ---- | C] () -- C:\ProgramData\nvModes.dat [2010-12-28 22:32:41 | 000,080,734 | ---- | C] () -- C:\ProgramData\nvModes.001 [2010-12-19 02:06:06 | 000,000,590 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll.manifest [2010-10-28 02:34:09 | 000,000,024 | ---- | C] () -- C:\Windows\ATKPF.ini [2009-09-08 17:08:21 | 000,002,828 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys [2009-09-08 17:08:21 | 000,000,088 | RHS- | C] () -- C:\ProgramData\4CB2213D7D.sys [2009-08-31 01:52:19 | 000,026,340 | ---- | C] () -- C:\Users\Franki\AppData\Roaming\UserTile.png [2009-01-16 01:13:08 | 002,788,800 | ---- | C] () -- C:\Program Files\FLV PlayerFCSetup.exe [2008-01-23 00:51:41 | 000,027,430 | ---- | C] () -- C:\Users\Franki\AppData\Roaming\nvModes.dat [2008-01-23 00:51:41 | 000,027,430 | ---- | C] () -- C:\Users\Franki\AppData\Roaming\nvModes.001 [2008-01-20 23:56:44 | 000,107,520 | ---- | C] () -- C:\Users\Franki\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008-01-20 21:50:39 | 000,110,648 | ---- | C] () -- C:\Users\Franki\AppData\Local\GDIPFONTCACHEV1.DAT [2008-01-20 21:44:39 | 009,437,184 | -HS- | C] () -- C:\Users\Franki\ntuser.dat [2008-01-20 21:44:39 | 000,524,288 | -HS- | C] () -- C:\Users\Franki\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms [2008-01-20 21:44:39 | 000,524,288 | -HS- | C] () -- C:\Users\Franki\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms [2008-01-20 21:44:39 | 000,065,536 | -HS- | C] () -- C:\Users\Franki\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf [2008-01-20 21:44:39 | 000,000,020 | -HS- | C] () -- C:\Users\Franki\ntuser.ini [color=#E56717]========== LOP Check ==========[/color] [2009-08-18 12:56:41 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\Acubix PicoBackup Outlook Express Edition [2012-07-26 12:49:42 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\BITS [2012-07-07 00:00:14 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\DC++ [2012-05-07 13:17:18 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\FireShot [2012-06-21 12:06:57 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\FlashGet [2012-06-21 09:51:08 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\FlashGetBHO [2012-06-21 09:51:30 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\FlashgetSetup [2011-02-05 02:29:36 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\Free Monitor for Google [2008-09-12 09:32:49 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\Gadu-Gadu [2011-08-10 16:07:17 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\Gadu-Gadu 10 [2011-02-05 02:29:37 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\GHISLER [2011-02-05 02:29:37 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\gtk-2.0 [2012-07-26 10:25:10 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\hellomoto [2012-06-25 00:20:55 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\Media Finder [2010-07-16 00:16:04 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\Nokia [2012-07-11 00:45:45 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\Notepad++ [2011-08-10 10:39:19 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\OpenFM [2010-02-25 03:38:07 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\OpenOffice.org [2011-08-18 11:36:32 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\Opera [2009-08-13 00:49:43 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\PC Suite [2009-08-31 01:52:19 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\PeerNetworking [2011-02-05 02:29:49 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\Thunderbird [2011-08-06 01:03:47 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\uTorrent [2012-07-13 11:54:28 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\Video Downloader(xmlbar) [2011-08-06 01:55:06 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\VistaCodecs [2012-06-26 10:26:25 | 000,000,000 | ---D | M] -- C:\Users\Franki\AppData\Roaming\Youku Downloader(xmlbar) [2012-07-26 14:47:06 | 000,032,528 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2012-07-25 14:07:15 | 000,000,420 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{94DA0606-68D4-4CC9-A795-4927D3F15118}.job [color=#E56717]========== Purity Check ==========[/color] < End of report >