OTL logfile created on: 2012-08-02 10:37:43 - Run 1 OTL by OldTimer - Version 3.2.55.0 Folder = C:\Documents and Settings\wzorcownia05\Moje dokumenty\Pobieranie Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1014,36 Mb Total Physical Memory | 341,44 Mb Available Physical Memory | 33,66% Memory free 2,38 Gb Paging File | 1,61 Gb Available in Paging File | 67,65% Paging File free Paging file location(s): C:\pagefile.sys 1524 3048 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 71,04 Gb Total Space | 0,79 Gb Free Space | 1,11% Space Free | Partition Type: NTFS Drive D: | 72,00 Gb Total Space | 1,19 Gb Free Space | 1,65% Space Free | Partition Type: NTFS Computer Name: LAPTOP | User Name: wzorcownia05 | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-08-02 10:19:33 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\wzorcownia05\Moje dokumenty\Pobieranie\OTL.exe PRC - [2012-08-02 09:39:37 | 000,078,336 | ---- | M] (Arima Computer Corporation) -- C:\Documents and Settings\All Users\Dane aplikacji\pgysafji.exe PRC - [2012-07-29 23:31:28 | 000,428,544 | ---- | M] () -- C:\Program Files\cacaoweb\cacaoweb.exe PRC - [2012-07-12 00:07:34 | 000,138,096 | ---- | M] (Facebook Inc.) -- C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Facebook\Update\FacebookUpdate.exe PRC - [2012-07-03 18:21:30 | 004,273,976 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe PRC - [2012-07-03 18:21:29 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe PRC - [2012-06-27 12:29:26 | 001,996,200 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe PRC - [2012-06-27 12:29:22 | 001,385,896 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe PRC - [2012-06-15 00:17:36 | 000,913,888 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2012-04-29 23:09:17 | 000,296,056 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe PRC - [2012-02-10 12:28:06 | 000,240,408 | ---- | M] (Microsoft Corporation.) -- C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE PRC - [2012-02-03 17:50:18 | 003,508,624 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Kies\KiesTrayAgent.exe PRC - [2011-11-07 09:13:24 | 000,235,232 | ---- | M] () -- C:\Program Files\Przyspiesz Komputer\PCSUService.exe PRC - [2010-04-20 14:26:44 | 000,300,912 | ---- | M] () -- C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe PRC - [2009-07-08 03:53:36 | 000,472,112 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Pure Networks\Network Magic\nmapp.exe PRC - [2009-07-07 15:48:44 | 000,647,216 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe PRC - [2009-07-07 15:48:44 | 000,647,216 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe PRC - [2008-10-20 11:32:54 | 002,768,896 | ---- | M] () -- C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe PRC - [2008-10-06 19:07:26 | 000,679,936 | ---- | M] (SAMSUNG Electronics) -- C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe PRC - [2008-09-17 14:25:46 | 001,440,384 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe PRC - [2008-09-17 14:25:46 | 000,580,200 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe PRC - [2008-05-21 17:44:30 | 000,299,008 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\MagicKBD\PerformanceManager.exe PRC - [2008-05-20 21:02:08 | 000,372,736 | ---- | M] (SAMSUNG Electronics Co., Ltd.) -- C:\Program Files\Samsung\MagicKBD\MagicKBD.exe PRC - [2008-04-15 14:00:00 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2008-04-15 14:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\dwwin.exe PRC - [2007-12-20 21:40:30 | 000,659,456 | ---- | M] (Samsung Electronics,.LTD) -- C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe PRC - [2004-01-28 19:49:40 | 000,020,480 | ---- | M] () -- C:\Program Files\Samsung\MagicKBD\Session.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012-08-02 00:06:10 | 001,790,464 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12080101\algo.dll MOD - [2012-07-29 23:31:28 | 000,428,544 | ---- | M] () -- C:\Program Files\cacaoweb\cacaoweb.exe MOD - [2012-06-15 00:17:55 | 002,042,848 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll MOD - [2011-11-07 09:13:24 | 000,235,232 | ---- | M] () -- C:\Program Files\Przyspiesz Komputer\PCSUService.exe MOD - [2011-07-27 08:57:20 | 000,562,072 | ---- | M] () -- C:\Program Files\Przyspiesz Komputer\Sqlite3.dll MOD - [2009-07-13 18:37:04 | 000,152,112 | ---- | M] () -- C:\Program Files\Common Files\Pure Networks Shared\Platform\CAntiVirusCOM.dll MOD - [2009-07-13 18:37:04 | 000,098,304 | ---- | M] () -- C:\Program Files\Common Files\Pure Networks Shared\Platform\CFirewallCOM.dll MOD - [2008-10-20 11:32:54 | 002,768,896 | ---- | M] () -- C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe MOD - [2008-09-17 14:20:08 | 002,842,624 | ---- | M] () -- C:\WINDOWS\system32\btwicons.dll MOD - [2006-08-12 13:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll MOD - [2005-07-12 17:34:22 | 000,045,056 | ---- | M] () -- C:\Program Files\Samsung\MagicKBD\EasyBoxDll.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [Disabled | Unknown] -- C:\Program Files\AVAST Software\Avast\afwServ.exe -- (avast! Firewall) SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt) SRV - [2012-07-27 15:55:51 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012-07-03 18:21:29 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2012-06-27 12:29:22 | 001,385,896 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc) SRV - [2012-06-15 00:17:46 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012-05-03 08:31:10 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012-02-10 12:28:06 | 000,240,408 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE -- (BBUpdate) SRV - [2012-02-10 12:28:06 | 000,193,816 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files\Microsoft\BingBar\7.1.361.0\BBSvc.EXE -- (BBSvc) SRV - [2011-11-07 09:13:24 | 000,235,232 | ---- | M] () [Auto | Running] -- C:\Program Files\Przyspiesz Komputer\PCSUService.exe -- (PCSUService) SRV - [2009-07-07 15:48:44 | 000,647,216 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe -- (nmservice) SRV - [2009-04-21 10:09:00 | 000,282,624 | ---- | M] (Marvell) [Auto | Running] -- C:\WINDOWS\system32\yk51x86.dll -- (yksvc) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbdev.sys -- (hwusbdev) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbmdm.sys -- (hwdatacard) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbnet.sys -- (ewusbnet) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2012-07-03 18:21:54 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2012-07-03 18:21:53 | 000,721,000 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2012-07-03 18:21:53 | 000,353,688 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP) DRV - [2012-07-03 18:21:53 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2) DRV - [2012-07-03 18:21:53 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr) DRV - [2012-07-03 18:21:53 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2012-07-03 18:21:52 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4) DRV - [2011-02-24 07:13:31 | 000,218,688 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV - [2010-07-28 15:33:16 | 000,123,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdm.sys -- (ss_bmdm) DRV - [2010-07-28 15:33:16 | 000,100,224 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bserd.sys -- (ss_bserd) DRV - [2010-07-28 15:33:16 | 000,098,432 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bbus.sys -- (ss_bbus) DRV - [2010-07-28 15:33:16 | 000,014,848 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ss_bmdfl.sys -- (ss_bmdfl) DRV - [2009-07-07 15:48:44 | 000,026,672 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\purendis.sys -- (purendis) DRV - [2009-07-07 15:48:44 | 000,025,392 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\pnarp.sys -- (pnarp) DRV - [2009-04-21 10:09:00 | 000,297,344 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp) DRV - [2009-03-18 18:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi) DRV - [2009-01-18 17:19:10 | 000,003,567 | ---- | M] (Beyond Logic http://www.beyondlogic.org) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\porttalk.sys -- (PortTalk) DRV - [2008-10-08 08:35:10 | 001,334,432 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\athw.sys -- (AR5416) DRV - [2008-09-23 22:23:58 | 000,238,464 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VMC326.sys -- (VMC326) DRV - [2008-08-27 01:35:00 | 004,753,920 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) DRV - [2008-07-29 17:59:08 | 000,879,832 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL) DRV - [2008-07-29 17:59:02 | 000,156,816 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS) DRV - [2008-07-27 01:29:54 | 000,074,688 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB) DRV - [2008-07-27 01:29:44 | 000,055,352 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwhid.sys -- (btwhid) DRV - [2008-07-27 01:29:36 | 000,037,424 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver) DRV - [2008-07-27 01:29:28 | 000,539,640 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio) DRV - [2008-01-14 20:01:02 | 000,030,208 | ---- | M] (Samsung Electronics,.LTD) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SamsungEDS.SYS -- (DNSeFilter) DRV - [2007-09-25 16:59:46 | 000,015,152 | ---- | M] () [Kernel | On_Demand | Stopped] -- D:\Program Files\MediaCoder\SysInfo.sys -- (CrystalSysInfo) DRV - [2005-10-27 06:18:05 | 000,004,300 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\MEMIO.SYS -- (DOSMEMIO) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddr&s={searchTerms}&f=4 IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms} IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=SMSN&bmod=SMSN IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes] IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.facemoods.com/?a=ddr IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\..\URLSearchHook: {3ba34663-845a-4931-a6f3-1e033ec342a7} - C:\Program Files\Thoosje\tbTho1.dll (Conduit Ltd.) IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\..\URLSearchHook: {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\tbFre1.dll (Conduit Ltd.) IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64} IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://start.facemoods.com/?a=ddr&s={searchTerms}&f=4 IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN_plPL340 IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}: "URL" = http://search.bearshare.com/webResults.html?src=ieb&q={searchTerms} IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search?q={searchTerms} IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2434356 IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://search.avg.com/route/?d=4b3d2cf0&i=23&tp=chrome&q={searchTerms}&lng={language}&ychte=us&nt=1 IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-501\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=SMSN&bmod=SMSN IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-501\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-501\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-501\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?brand=SMSN&bmod=SMSN IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-501\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-501\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - No CLSID value found IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-501\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-501\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64} IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-501\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-501\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN_plPL340 IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-501\..\SearchScopes\{E4BB8FF9-F085-47C9-ACB3-0DA995349A02}: "URL" = http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms} IE - HKU\S-1-5-21-3067154918-2645452998-3899191450-501\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultthis.engineName: "Free Lunch Design Customized Web Search" FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1708250&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://start.facemoods.com/?a=ddr" FF - prefs.js..extensions.enabledItems: {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}:3.13.0.6 FF - prefs.js..extensions.enabledItems: {E84D42CA-64EB-11DE-A65F-8C3656D89593}:3.0 FF - prefs.js..extensions.enabledItems: {3ba34663-845a-4931-a6f3-1e033ec342a7}:3.13.0.6 FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.7.3 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.20 FF - prefs.js..extensions.enabledItems: saloonbar@ligny.org.uk:3.0 FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:15.0.3 FF - prefs.js..extensions.enabledItems: wrc@avast.com:7.0.1426 FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.1.7.0190 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}:6.0.27 FF - prefs.js..extensions.enabledItems: ffxtlbr@Facemoods.com:1.2.1 FF - prefs.js..extensions.enabledItems: cacaoweb@cacaoweb.org:1.0.24 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}:6.0.31 FF - prefs.js..extensions.enabledItems: {e213bb8f-8ebd-11db-96b7-005056c00008}:3.0.0.91 FF - prefs.js..extensions.enabledItems: {48e23fba-bb14-4745-b768-382150cd83fb}:1.0.1 FF - prefs.js..keyword.URL: "http://start.facemoods.com/results.php?f=5&a=ddr&q=" FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_268.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\Documents and Settings\All Users\Dane aplikacji\NexonEU\NGM\npNxGameeu.dll (Nexon) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.3.37: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.3.37: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.3.37: C:\Documents and Settings\All Users\Dane aplikacji\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.3.37: C:\Documents and Settings\All Users\Dane aplikacji\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.3.37: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc) FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc) FF - HKLM\Software\MozillaPlugins\@vividas.com/npVividasPlayer: C:\Program Files\Vividas\Player\npVividasPlayer.dll ( ) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-07-08 15:28:33 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Dane aplikacji\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012-04-29 23:10:22 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-06-24 15:18:19 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012-06-24 15:18:11 | 000,000,000 | ---D | M] [2009-12-23 01:36:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Extensions [2009-12-23 01:36:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Extensions\mozswing@mozswing.org [2012-08-02 10:22:08 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\extensions [2012-06-01 14:40:11 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2012-07-09 05:53:56 | 000,000,000 | ---D | M] (Thoosje Community Toolbar) -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\extensions\{3ba34663-845a-4931-a6f3-1e033ec342a7} [2010-06-06 01:52:11 | 000,000,000 | ---D | M] ("Metal3D") -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\extensions\{48e23fba-bb14-4745-b768-382150cd83fb} [2012-07-18 16:16:44 | 000,000,000 | ---D | M] (Free Lunch Design Community Toolbar) -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\extensions\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} [2012-05-30 13:01:32 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\extensions\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}-trash [2010-06-06 01:47:59 | 000,000,000 | ---D | M] (myFireFox) -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\extensions\{e213bb8f-8ebd-11db-96b7-005056c00008} [2012-05-30 13:01:44 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781} [2009-12-22 12:22:51 | 000,000,000 | ---D | M] (MediaBar) -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\extensions\{E84D42CA-64EB-11DE-A65F-8C3656D89593} [2012-01-18 10:13:10 | 000,000,000 | ---D | M] (cacaoweb) -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\extensions\cacaoweb@cacaoweb.org [2011-02-24 07:12:59 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\extensions\DTToolbar@toolbarnet.com [2011-11-10 18:05:17 | 000,000,000 | ---D | M] (Facemoods) -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\extensions\ffxtlbr@Facemoods.com [2010-08-27 23:28:25 | 000,000,000 | ---D | M] (The Saloon Bar) -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\extensions\saloonbar@ligny.org.uk [2012-08-02 10:22:08 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\extensions\staged [2011-09-07 16:00:39 | 000,000,000 | ---D | M] ("Ask Toolbar") -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\extensions\toolbar@ask.com [2010-06-06 01:48:00 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\extensions\{e213bb8f-8ebd-11db-96b7-005056c00008}\chrome\mozapps\extensions [2009-07-18 01:02:48 | 000,002,476 | ---- | M] () -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\searchplugins\BearShareWebSearch.xml [2009-05-31 19:45:28 | 000,000,896 | ---- | M] () -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\searchplugins\conduit.xml [2011-02-24 07:11:53 | 000,002,055 | ---- | M] () -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\searchplugins\daemon-search.xml [2009-08-29 15:54:32 | 000,001,979 | ---- | M] () -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\Mozilla\Firefox\Profiles\7h6hwefi.default\searchplugins\wrzuta.xml [2012-06-24 15:18:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2012-06-15 00:19:07 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012-03-31 18:10:57 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [2010-09-21 16:30:02 | 000,120,296 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npganymedenet.dll [2012-06-15 01:13:23 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2009-07-18 01:02:48 | 000,002,476 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\BearShareWebSearch.xml [2012-06-15 01:13:23 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2010-12-13 14:36:54 | 000,002,035 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fcmdSrchddr.xml [2012-06-15 01:13:23 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2012-06-15 01:13:23 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2012-06-15 01:13:23 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2012-06-15 01:13:23 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml [color=#E56717]========== Chrome ==========[/color] CHR - homepage: http://start.facemoods.com/?a=ddr CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms} CHR - homepage: http://start.facemoods.com/?a=ddr CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\20.0.1132.57\pdf.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\20.0.1132.57\gcswf32.dll CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll CHR - plugin: Shockwave for Director (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll CHR - plugin: GanymedeNet.Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npganymedenet.dll CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Dane aplikacji\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll CHR - plugin: Nexon Game Controller (Enabled) = C:\Documents and Settings\All Users\Dane aplikacji\NexonEU\NGM\npNxGameeu.dll CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Dane aplikacji\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Facebook\Video\Skype\npFacebookVideoCalling.dll CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.111\npGoogleUpdate3.dll CHR - plugin: Unity Player (Enabled) = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Unity\WebPlayer\loader\npUnity3D32.dll CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll CHR - plugin: Vividas Player Plugin (Enabled) = C:\Program Files\Vividas\Player\npVividasPlayer.dll CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - Extension: Pool = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\cedbddnnmhgnedpamoenmdkhnpnfbpjb\1.0.4_0\ CHR - Extension: Virtual Piano Black = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\fjagcpcbacoaogfljhglghpjhkmmfeeo\4_0\ CHR - Extension: Virtual Piano = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\hjlaliolmnfholhmakjfbapkkfngamko\5.5.0_0\ CHR - Extension: Plypp Piano = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\hofckkgpnnjabffkjemconojemcibifh\6.1_0\ CHR - Extension: avast! WebRep = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1456_0\ CHR - Extension: Facemoods = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.6.0_0\ CHR - Extension: Facemoods = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.6.0_0\facemoods\ CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\ CHR - Extension: A Little Piano = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\jkpachigjhabablcmghoeecepjoogakp\1.1_0\ CHR - Extension: PingPong Blast = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\kjdkomgefikcdchdpjfgjfpagieofnem\1.2_0\ CHR - Extension: BeGone = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ndfpieflbjbdpgklkeolbmbdkfdiicfk\1.2_0\ CHR - Extension: Piano = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nioialpkfokidhfbafkafkcnmndeamle\1.1_0\ CHR - Extension: MegaSkipper = C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\phlpjnmkcepflfoglccifhajagahaglm\19.66_0\ O1 HOSTS File: ([2008-04-15 14:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShareTb\BearShareDx.dll () O2 - BHO: (Bing Bar Helper) - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.) O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dane aplikacji\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (Thoosje Toolbar) - {3ba34663-845a-4931-a6f3-1e033ec342a7} - C:\Program Files\Thoosje\tbTho1.dll (Conduit Ltd.) O2 - BHO: (Free Lunch Design Toolbar) - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\tbFre1.dll (Conduit Ltd.) O2 - BHO: (CescrtHlpr Object) - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files\facemoods.com\facemoods\1.4.17.3\bh\facemoods.dll (facemoods.com BHO) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.) O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10\_userdata\ggbho.2.dll File not found O3 - HKLM\..\Toolbar: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShareTb\BearShareDx.dll () O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKLM\..\Toolbar: (Thoosje Toolbar) - {3ba34663-845a-4931-a6f3-1e033ec342a7} - C:\Program Files\Thoosje\tbTho1.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Free Lunch Design Toolbar) - {57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - C:\Program Files\Free_Lunch_Design\tbFre1.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found. O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files\facemoods.com\facemoods\1.4.17.3\facemoodsTlbr.dll (facemoods.com) O3 - HKLM\..\Toolbar: (Bing Bar) - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.) O3 - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\..\Toolbar\WebBrowser: (Thoosje Toolbar) - {3BA34663-845A-4931-A6F3-1E033EC342A7} - C:\Program Files\Thoosje\tbTho1.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\..\Toolbar\WebBrowser: (Free Lunch Design Toolbar) - {57CC715D-37CA-44E4-9EC2-8C2CBDDB25EC} - C:\Program Files\Free_Lunch_Design\tbFre1.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKU\S-1-5-21-3067154918-2645452998-3899191450-501\..\Toolbar\WebBrowser: (Thoosje Toolbar) - {3BA34663-845A-4931-A6F3-1E033EC342A7} - C:\Program Files\Thoosje\tbTho1.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-3067154918-2645452998-3899191450-501\..\Toolbar\WebBrowser: (Free Lunch Design Toolbar) - {57CC715D-37CA-44E4-9EC2-8C2CBDDB25EC} - C:\Program Files\Free_Lunch_Design\tbFre1.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-3067154918-2645452998-3899191450-501\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [BatteryManager] C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe () O4 - HKLM..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause File not found O4 - HKLM..\Run: [DMHotKey] C:\Program Files\Samsung\Easy Display Manager\DMLoader.exe (SAMSUNG Electronics) O4 - HKLM..\Run: [EDS] C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe (Samsung Electronics,.LTD) O4 - HKLM..\Run: [facemoods] C:\Program Files\facemoods.com\facemoods\1.4.17.3\facemoodssrv.exe (facemoods.com) O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.) O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.) O4 - HKLM..\Run: [MagicKeyboard] C:\Program Files\Samsung\MagicKBD\PreMKbd.exe () O4 - HKLM..\Run: [nmapp] C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Cisco Systems, Inc.) O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.) O4 - HKLM..\Run: [SUPBackground] C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe () O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.) O4 - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005..\Run: [ALLUpdate] C:\Program Files\ALLPlayer\ALLUpdate.exe () O4 - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005..\Run: [ares] C:\Program Files\Ares\Ares.exe (Ares Development Group) O4 - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005..\Run: [BitTorrent] C:\Program Files\BitTorrent\BitTorrent.exe (BitTorrent, Inc.) O4 - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005..\Run: [cacaoweb] C:\Program Files\cacaoweb\cacaoweb.exe () O4 - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005..\Run: [Dxtory Update Checker 2.0] D:\Program Files\Dxtory Software\Dxtory2.0\UpdateChecker.exe (Dxtory Software) O4 - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005..\Run: [Facebook Update] C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Facebook\Update\FacebookUpdate.exe (Facebook Inc.) O4 - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.) O4 - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe (Samsung) O4 - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe () O4 - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005..\Run: [KPeerNexonEU] C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe (NEXON Inc.) O4 - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005..\Run: [PCSpeedUp] C:\Program Files\Przyspiesz Komputer\PCSpeedUp.lnk () O4 - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005..\Run: [Twoje TVN24] File not found O4 - HKU\S-1-5-21-3067154918-2645452998-3899191450-501..\Run: [pgysafjichatsxi] C:\Documents and Settings\All Users\Dane aplikacji\pgysafji.exe (Arima Computer Corporation) O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\BTTray.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-3067154918-2645452998-3899191450-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-3067154918-2645452998-3899191450-501\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Funkcja Google Sidewiki - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html File not found O8 - Extra context menu item: Wyślij do interfejsu Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O8 - Extra context menu item: Wyślij do urządzenia &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07) O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.204.159.1 194.204.152.34 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5E5FD80B-7D4B-4915-A875-F4CAE4E86CAB}: DhcpNameServer = 194.204.159.1 194.204.152.34 O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009-02-16 12:42:32 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{0d1e5bb8-302f-11df-85d2-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{0d1e5bb8-302f-11df-85d2-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{106412d6-ee2e-11de-852d-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{106412d6-ee2e-11de-852d-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{14e05ace-051c-11df-8561-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{14e05ace-051c-11df-8561-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{24310e3a-3803-11df-85e2-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{24310e3a-3803-11df-85e2-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{24310e3b-3803-11df-85e2-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{24310e3b-3803-11df-85e2-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{31b16c24-e79b-11df-879e-cd9740c6646b}\Shell - "" = AutoRun O33 - MountPoints2\{31b16c24-e79b-11df-879e-cd9740c6646b}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{4165eb48-ae00-11de-844b-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{4165eb48-ae00-11de-844b-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{470e6c5a-bc15-11de-8489-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{470e6c5a-bc15-11de-8489-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{470e6c5b-bc15-11de-8489-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{470e6c5b-bc15-11de-8489-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{470e6c5c-bc15-11de-8489-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{470e6c5c-bc15-11de-8489-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{470e6c5d-bc15-11de-8489-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{470e6c5d-bc15-11de-8489-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{4c7bb28e-d7a1-11df-8758-d3c364fb5fc2}\Shell - "" = AutoRun O33 - MountPoints2\{4c7bb28e-d7a1-11df-8758-d3c364fb5fc2}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{4c7bb294-d7a1-11df-8758-9b4c5b8ac716}\Shell - "" = AutoRun O33 - MountPoints2\{4c7bb294-d7a1-11df-8758-9b4c5b8ac716}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{5cb66b4c-8996-11de-83ed-001377f6807b}\Shell - "" = AutoRun O33 - MountPoints2\{5cb66b4c-8996-11de-83ed-001377f6807b}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{5cb66b4f-8996-11de-83ed-001377f6807b}\Shell - "" = AutoRun O33 - MountPoints2\{5cb66b4f-8996-11de-83ed-001377f6807b}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{5e6186da-27bd-11df-85b7-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{5e6186da-27bd-11df-85b7-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{63fe5504-dc6d-11df-876b-8b9021f376c3}\Shell - "" = AutoRun O33 - MountPoints2\{63fe5504-dc6d-11df-876b-8b9021f376c3}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{6640a42a-ae01-11de-844c-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{6640a42a-ae01-11de-844c-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{698c8040-eb54-11df-87a4-9d62a2bccb6b}\Shell - "" = AutoRun O33 - MountPoints2\{698c8040-eb54-11df-87a4-9d62a2bccb6b}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{7b280fee-42d0-11e0-87ed-8a7e1c0ea16b}\Shell\AutoplAY\CommAnD - "" = E:\yesg.exe O33 - MountPoints2\{7b280fee-42d0-11e0-87ed-8a7e1c0ea16b}\Shell\AutoRun\command - "" = E:\yesg.exe O33 - MountPoints2\{7b280fee-42d0-11e0-87ed-8a7e1c0ea16b}\Shell\exPlore\COMManD - "" = E:\yesg.exe O33 - MountPoints2\{7b280fee-42d0-11e0-87ed-8a7e1c0ea16b}\Shell\OpEN\commAnd - "" = E:\yesg.exe O33 - MountPoints2\{9cdf3cc1-eb2d-11de-8525-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{9cdf3cc1-eb2d-11de-8525-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{a7244a2a-46bb-11df-8605-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{a7244a2a-46bb-11df-8605-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{a86a4ad2-b184-11de-8454-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{a86a4ad2-b184-11de-8454-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{bd6bc1f7-eb74-11df-87a6-bcc3bfec4978}\Shell - "" = AutoRun O33 - MountPoints2\{bd6bc1f7-eb74-11df-87a6-bcc3bfec4978}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{c41d7aec-e76b-11df-879d-b4f5e8deeb6b}\Shell - "" = AutoRun O33 - MountPoints2\{c41d7aec-e76b-11df-879d-b4f5e8deeb6b}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{c41d7aef-e76b-11df-879d-b4f5e8deeb6b}\Shell - "" = AutoRun O33 - MountPoints2\{c41d7aef-e76b-11df-879d-b4f5e8deeb6b}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{c78f0adc-2960-11e1-bc7d-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{c78f0adc-2960-11e1-bc7d-00242cf6bbb8}\Shell\AutoRun\command - "" = G:\ICM_Manager.exe O33 - MountPoints2\{c7e83943-fefe-11df-87bf-ce0ff41df97f}\Shell - "" = AutoRun O33 - MountPoints2\{c7e83943-fefe-11df-87bf-ce0ff41df97f}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{cbc8cfca-3812-11df-85e3-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{cbc8cfca-3812-11df-85e3-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{cbc8cfe0-3812-11df-85e3-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{cbc8cfe0-3812-11df-85e3-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{cd98af66-c7f4-11df-8737-d2aa8ab95778}\Shell - "" = AutoRun O33 - MountPoints2\{cd98af66-c7f4-11df-8737-d2aa8ab95778}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{d077de98-492a-11df-860d-e5647ca2a49f}\Shell - "" = AutoRun O33 - MountPoints2\{d077de98-492a-11df-860d-e5647ca2a49f}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{df77feea-b401-11de-8460-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{df77feea-b401-11de-8460-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{df77feee-b401-11de-8460-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{df77feee-b401-11de-8460-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{e0bbddde-27e1-11df-85bc-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{e0bbddde-27e1-11df-85bc-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{ed25876e-964e-11de-8401-001377f6807b}\Shell - "" = AutoRun O33 - MountPoints2\{ed25876e-964e-11de-8401-001377f6807b}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{f1139d04-27b5-11df-85b6-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{f1139d04-27b5-11df-85b6-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O33 - MountPoints2\{f1139d07-27b5-11df-85b6-00242cf6bbb8}\Shell - "" = AutoRun O33 - MountPoints2\{f1139d07-27b5-11df-85b6-00242cf6bbb8}\Shell\AutoRun\command - "" = E:\AutoRun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-08-02 09:39:59 | 000,078,336 | ---- | C] (Arima Computer Corporation) -- C:\Documents and Settings\All Users\Dane aplikacji\dmfpttbr.exe [2012-08-02 09:39:57 | 000,078,336 | ---- | C] (Arima Computer Corporation) -- C:\Documents and Settings\All Users\Dane aplikacji\pgysafji.exe [2012-08-02 09:39:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\ktswiwrqcctszth [2012-07-22 13:09:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dokumenty\Wichu1993 ModPack v5.0 for Minecraft 1.2.5 [2012-07-21 01:05:10 | 562,044,991 | ---- | C] (Macrovision Corporation) -- C:\Documents and Settings\All Users\Dokumenty\BF2_Patch_1.41.exe [2012-07-17 12:50:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\LogMeIn Hamachi [2012-07-17 12:50:40 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn Hamachi [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-08-02 11:01:08 | 000,000,248 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job [2012-08-02 10:52:16 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2012-08-02 10:41:00 | 000,001,048 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2012-08-02 10:36:01 | 000,001,160 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3067154918-2645452998-3899191450-1005UA.job [2012-08-02 10:03:48 | 000,000,316 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2012-08-02 10:03:10 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat [2012-08-02 09:58:02 | 000,000,292 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3067154918-2645452998-3899191450-1005.job [2012-08-02 09:57:37 | 000,001,044 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2012-08-02 09:57:23 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3067154918-2645452998-3899191450-1008.job [2012-08-02 09:57:04 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012-08-02 09:57:00 | 1063,702,528 | -HS- | M] () -- C:\hiberfil.sys [2012-08-02 09:39:59 | 000,000,051 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\rlorxbpvytytyqp [2012-08-02 09:39:37 | 000,078,336 | ---- | M] (Arima Computer Corporation) -- C:\Documents and Settings\All Users\Dane aplikacji\pgysafji.exe [2012-08-02 09:39:37 | 000,078,336 | ---- | M] (Arima Computer Corporation) -- C:\Documents and Settings\All Users\Dane aplikacji\dmfpttbr.exe [2012-08-02 09:13:00 | 000,001,180 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-3067154918-2645452998-3899191450-1005UA.job [2012-08-02 06:36:00 | 000,001,108 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3067154918-2645452998-3899191450-1005Core.job [2012-08-02 00:13:00 | 000,001,158 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-3067154918-2645452998-3899191450-1005Core.job [2012-08-01 21:32:00 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3067154918-2645452998-3899191450-1008.job [2012-08-01 19:00:00 | 000,000,268 | ---- | M] () -- C:\WINDOWS\tasks\RMSchedule.job [2012-07-31 13:31:13 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job [2012-07-29 23:12:03 | 000,000,300 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3067154918-2645452998-3899191450-1005.job [2012-07-27 15:55:48 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe [2012-07-27 15:55:47 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl [2012-07-13 09:41:20 | 000,002,355 | ---- | M] () -- C:\Documents and Settings\wzorcownia05\Pulpit\Google Chrome.lnk [2012-07-11 20:50:03 | 000,118,152 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012-07-11 20:28:28 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2012-07-08 15:28:49 | 000,002,644 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT [2012-07-03 18:21:54 | 000,054,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys [2012-07-03 18:21:53 | 000,721,000 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys [2012-07-03 18:21:53 | 000,353,688 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys [2012-07-03 18:21:53 | 000,097,608 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys [2012-07-03 18:21:53 | 000,089,624 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys [2012-07-03 18:21:53 | 000,035,928 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys [2012-07-03 18:21:53 | 000,021,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys [2012-07-03 18:21:52 | 000,025,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys [2012-07-03 18:21:32 | 000,041,224 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr [2012-07-03 18:21:28 | 000,227,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-08-02 09:39:41 | 000,000,051 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\rlorxbpvytytyqp [2012-07-19 14:15:20 | 2067,515,943 | ---- | C] () -- C:\Documents and Settings\All Users\Dokumenty\bf2patch150.exe [2012-07-19 14:14:59 | 2056,960,000 | ---- | C] () -- C:\Documents and Settings\All Users\Dokumenty\Battlefield 2.iso [2012-07-08 15:28:43 | 000,000,316 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2012-05-10 21:49:39 | 000,170,672 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat [2012-04-10 03:15:14 | 000,321,718 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-S-1-5-21-3067154918-2645452998-3899191450-1005-0.dat [2012-04-10 03:15:10 | 000,121,122 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-System.dat [2012-03-19 12:53:42 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2012-03-19 02:31:45 | 000,548,864 | ---- | C] () -- C:\WINDOWS\System32\JWinAPI.dll [2012-03-18 21:03:30 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2012-01-31 18:15:44 | 000,030,568 | ---- | C] () -- C:\WINDOWS\MusiccityDownload.exe [2012-01-31 18:15:42 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll [2012-01-31 18:15:42 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll [2012-01-31 18:15:42 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll [2012-01-31 18:15:42 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll [2012-01-22 16:28:59 | 000,000,917 | ---- | C] () -- C:\WINDOWS\GTA-SA_Trn_Settings.ini [2011-12-02 17:56:29 | 002,362,837 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\Dane aplikacji\minecraft.jar [2011-11-23 22:50:59 | 000,000,113 | ---- | C] () -- C:\WINDOWS\mgboss_reg.ini [2011-11-23 22:26:35 | 000,000,021 | ---- | C] () -- C:\WINDOWS\mgboss_win.ini [2011-03-27 01:21:55 | 000,000,478 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\Skrót do wzorcownia05.lnk [2011-03-04 17:32:07 | 008,892,928 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\atscie.msi [2011-03-03 08:10:50 | 000,000,137 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\fusioncache.dat [2011-02-13 01:06:43 | 000,175,616 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2011-01-09 15:05:47 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\Settings.dat [2011-01-09 15:05:47 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\Save.dat [2011-01-09 13:13:47 | 000,001,467 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\.recently-used.xbel [2010-10-28 12:01:01 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2010-08-09 15:46:06 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\02 Fly by Night [2010-07-30 04:47:10 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\04-Modlitwa III - Pozwol Mi.mp3 [2010-04-30 22:25:04 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\Cat Nap.jpg [2010-02-20 01:20:11 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\PIOTR.jpg [2010-02-13 00:33:33 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\_mini_8.gif [2010-02-13 00:33:02 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\_mini_1.gif [2010-02-13 00:32:21 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\_mini_3.gif [2010-02-13 00:31:47 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\39.jpg [2010-02-13 00:31:14 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\_mini_29.jpg [2010-02-13 00:31:11 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\_mini_16.jpg [2010-02-13 00:31:08 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\_mini_6.jpg [2010-02-13 00:17:30 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\piotr5555.JPG [2010-02-12 23:46:23 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\PIOTR5.png [2010-02-12 20:23:32 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\0148vs2[1].gif [2010-02-12 20:18:10 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\15o8ht1.gif [2010-02-12 20:07:22 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\2--Chocia-tam-gdzie-dal-770.jpg [2010-02-12 19:57:36 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\kot.jpeg [2010-02-12 19:55:33 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\ChomikImage.aspx.jpeg [2010-02-12 19:54:02 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\2311-800.jpg [2010-02-11 20:26:57 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\863.gif [2010-01-26 17:43:31 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\213.gif [2010-01-22 22:22:49 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\95134591.gif [2009-12-23 01:57:33 | 000,064,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009-10-10 00:20:37 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\http___www_gladpige_dk_Blomster-no2_Side2_ro3_gif.gif [2009-10-08 02:38:10 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\a4295750.gif [2009-09-24 21:50:08 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\aneta.jpeg [2009-09-24 21:10:45 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\kiru.jpeg [2009-09-11 21:09:21 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\wzorcownia05\12kitty.gif [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 487 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:05EE1EEF @Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:302A9871 @Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:D1B5B4F1 < End of report >