OTL logfile created on: 2012-08-08 19:08:30 - Run 1 OTL by OldTimer - Version Folder = C:\Program Files\uTorrent\Downloads Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,00 Gb Total Physical Memory | 2,26 Gb Available Physical Memory | 75,25% Memory free 6,00 Gb Paging File | 5,33 Gb Available in Paging File | 88,93% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 60,00 Gb Total Space | 2,15 Gb Free Space | 3,59% Space Free | Partition Type: NTFS Drive D: | 520,18 Gb Total Space | 11,69 Gb Free Space | 2,25% Space Free | Partition Type: NTFS Computer Name: ROBERT-KOMPUTER | User Name: Robert | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-08-08 19:04:18 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Program Files\uTorrent\Downloads\OTL.exe PRC - [2012-08-02 23:23:11 | 001,536,712 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe PRC - [2012-07-18 11:06:03 | 000,913,888 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2012-06-27 12:29:22 | 001,385,896 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe PRC - [2011-02-25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012-08-02 23:23:11 | 009,465,032 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_11_3_300_270.dll MOD - [2012-07-18 11:06:03 | 002,003,424 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll MOD - [2012-05-15 02:21:26 | 000,368,448 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2012-08-02 23:23:11 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012-07-18 11:06:03 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012-07-10 21:30:01 | 004,419,392 | ---- | M] () [Auto | Stopped] -- c:\program files\common files\akamai/netsession_win_4f7fccd.dll -- (Akamai) SRV - [2012-07-03 13:19:28 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012-07-02 17:25:14 | 002,232,504 | ---- | M] (Giraffic) [Auto | Stopped] -- C:\Program Files\Giraffic\Veoh_GirafficWatchdog.exe -- (Giraffic) SRV - [2012-06-27 12:29:22 | 001,385,896 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc) SRV - [2012-05-15 12:26:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2012-05-15 02:21:40 | 000,382,272 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2012-04-06 12:09:55 | 000,624,856 | ---- | M] (Pandora.TV) [Auto | Stopped] -- C:\Program Files\PANDORA.TV\PanService\PandoraService.exe -- (PanService) SRV - [2012-03-28 14:01:52 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2010-11-20 14:19:20 | 000,397,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\inetsrv\iisw3adm.dll -- (WAS) SRV - [2010-11-20 14:19:20 | 000,397,824 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\System32\inetsrv\iisw3adm.dll -- (W3SVC) SRV - [2010-11-20 14:18:03 | 000,061,440 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\System32\inetsrv\apphostsvc.dll -- (AppHostSvc) SRV - [2010-08-22 00:14:40 | 000,253,952 | ---- | M] (Ryan Conrad) [Auto | Stopped] -- C:\Program Files\Droid Explorer\DroidExplorer.Service.exe -- (DroidExplorerService) SRV - [2010-05-27 03:00:40 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc) SRV - [2010-03-04 19:50:00 | 003,486,792 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc) SRV - [2009-11-30 22:26:36 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner) SRV - [2009-11-30 22:26:36 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner) SRV - [2009-11-30 22:26:36 | 000,040,384 | ---- | M] (ALWIL Software) [Auto | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus) SRV - [2009-08-27 17:09:10 | 001,253,376 | ---- | M] (MAGIX AG) [Auto | Stopped] -- C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe -- (Fabs) SRV - [2009-07-14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009-07-14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2008-08-07 11:10:02 | 003,276,800 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\WinFast\WFTVFM\WFIOCTL.SYS -- (WFIOCTL) DRV - File not found [Kernel | Auto | Stopped] -- system32\drivers\wf2kxbar.sys -- (Tv2kXbar) DRV - File not found [Kernel | Auto | Stopped] -- system32\drivers\wf2ktunr.sys -- (tv2ktunr) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\gdrv.sys -- (gdrv) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleNT.sys -- (EagleNT) DRV - [2012-05-15 12:26:00 | 011,354,944 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2012-03-25 16:29:00 | 000,371,349 | ---- | M] (Illusion & Hope.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\BT848.sys -- (BT848) DRV - [2011-09-07 01:00:02 | 000,322,528 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\V0700Vid.sys -- (V0700Vid) DRV - [2011-03-24 14:28:36 | 000,150,176 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CtClsFlt.sys -- (CtClsFlt) DRV - [2010-11-20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010-11-20 11:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUSB) DRV - [2010-07-29 01:25:02 | 000,025,112 | ---- | M] (Initio Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ivusb.sys -- (ivusb) DRV - [2010-04-29 17:04:13 | 000,281,760 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt) DRV - [2010-04-29 17:04:12 | 000,025,888 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt) DRV - [2010-01-27 04:09:02 | 000,050,704 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\npf.sys -- (npf) DRV - [2009-12-09 21:33:29 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\sptd.sys -- (sptd) DRV - [2009-11-30 22:15:21 | 000,046,544 | ---- | M] (ALWIL Software) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2009-11-30 22:14:54 | 000,149,840 | ---- | M] (ALWIL Software) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP) DRV - [2009-11-30 22:12:05 | 000,023,248 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr) DRV - [2009-11-30 22:11:49 | 000,051,792 | ---- | M] (ALWIL Software) [File_System | Auto | Stopped] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt) DRV - [2009-11-30 22:11:28 | 000,019,024 | ---- | M] (ALWIL Software) [File_System | Auto | Stopped] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2009-10-28 13:48:54 | 000,016,896 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RP24GV1.sys -- (KMWDFilter1X) DRV - [2009-03-18 16:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi) DRV - [2007-03-16 11:11:38 | 000,012,256 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\TBPanel.sys -- (TBPanel) DRV - [2006-07-24 16:05:00 | 000,005,632 | ---- | M] () [File_System | System | Stopped] -- C:\Windows\System32\drivers\StarOpen.sys -- (StarOpen) DRV - [2005-11-03 16:40:07 | 000,063,488 | ---- | M] (Protection Technology) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\sfvfs02.sys -- (sfvfs02) DRV - [2005-08-10 16:06:28 | 000,019,968 | ---- | M] (Protection Technology) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\sfsync02.sys -- (sfsync02) DRV - [2005-08-10 14:44:04 | 000,050,688 | ---- | M] (Protection Technology) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\sfdrv01.sys -- (sfdrv01) DRV - [2005-05-16 15:20:39 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfhlp02.sys -- (sfhlp02) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com IE - HKLM\..\URLSearchHook: {5c5b9468-d672-4eb7-b52f-b5afabf28c5b} - C:\Program Files\SFT_Polska\prxtbSFT_.dll (Conduit Ltd.) IE - HKLM\..\URLSearchHook: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.) IE - HKLM\..\URLSearchHook: {9d81af43-de53-48d0-a199-42c2a226b24c} - C:\Program Files\Softonic_Deutsch_FF\tbSoft.dll (Conduit Ltd.) IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{40439b93-f815-4122-8073-d03bed94c303}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50-ie-shoutcast-chromesbox-en-us IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3031817 IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms} IE - HKLM\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=112558&tt=190712_n_mont_3012_6&babsrc=HP_ss&mntrId=06622cf800000000000000241d9c9618 IE - HKCU\..\URLSearchHook: {5c5b9468-d672-4eb7-b52f-b5afabf28c5b} - C:\Program Files\SFT_Polska\prxtbSFT_.dll (Conduit Ltd.) IE - HKCU\..\URLSearchHook: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.) IE - HKCU\..\URLSearchHook: {9d81af43-de53-48d0-a199-42c2a226b24c} - C:\Program Files\Softonic_Deutsch_FF\tbSoft.dll (Conduit Ltd.) IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=112558&tt=190712_n_mont_3012_6&babsrc=SP_ss&mntrId=06622cf800000000000000241d9c9618 IE - HKCU\..\SearchScopes\{3A40E547-20FD-44a2-94D0-1C98342D1507}: "URL" = http://search.daum.net/search?nil_profile=ie&ref_code=ms&q={searchTerms} IE - HKCU\..\SearchScopes\{40439b93-f815-4122-8073-d03bed94c303}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50-ie-shoutcast-chromesbox-en-us IE - HKCU\..\SearchScopes\{41610CD6-FC22-4D01-9D3D-F6E129DC715A}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=STT&o=102866&src=kw&q={searchTerms}&locale=&apn_ptnrs=5N&apn_dtid=YYYYYYYYPL&apn_uid=5846DF0B-51CF-4559-AADD-81D8AFC4573E&apn_sauid=667AF0A8-3010-41F5-8A0F-D2EF09A5D1B6 IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rlz=1I7GPCK_plPL357&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKCU\..\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}: "URL" ={searchTerms} IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms} IE - HKCU\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;; [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultengine: "Ask.com" FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)" FF - prefs.js..browser.search.defaultthis.engineName: "SFT_Polska Customized Web Search" FF - prefs.js..browser.search.defaulturl: "" FF - prefs.js..browser.search.order.1: "Search the web (Babylon)" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT3031817&SearchSource=13" FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.3 FF - prefs.js..extensions.enabledItems: {6E19037A-12E3-4295-8915-ED48BC341614}:1.3.328.4 FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.5 FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.6.2 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - prefs.js..extensions.enabledItems: engine@conduit.com: FF - prefs.js..extensions.enabledItems: {9d81af43-de53-48d0-a199-42c2a226b24c}: FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26 FF - prefs.js..extensions.enabledItems: {5c5b9468-d672-4eb7-b52f-b5afabf28c5b}: FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29 FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3072253&SearchSource=2&q=" FF - prefs.js..network.proxy.type: 0 FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "Ask.com" FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3031817&SearchSource=3&q={searchTerms}" FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "Google" FF - prefs.js..browser.startup.homepage: "http://www.gazeta.pl/0,0.html?p=125" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_270.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.116.0: C:\Program Files\Battlelog Web Plugins\1.116.0\npesnlaunch.dll File not found FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.122.0: C:\Program Files\Battlelog Web Plugins\1.122.0\npesnlaunch.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version= C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version= C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version= C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version= C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version= C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6E19037A-12E3-4295-8915-ED48BC341614}: C:\Program Files\RelevantKnowledge [2012-01-25 01:36:41 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012-04-14 12:11:15 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fbphotozoom@installdaddy.com: C:\Program Files\fbphotozoom\fbphotozoom15.xpi [2012-03-27 19:21:48 | 000,102,423 | ---- | M] () FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-07-18 11:06:04 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012-07-22 21:08:03 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-07-18 11:06:04 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012-07-22 21:08:03 | 000,000,000 | ---D | M] [2010-07-01 00:00:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robert\AppData\Roaming\mozilla\Extensions [2010-04-09 15:48:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robert\AppData\Roaming\mozilla\Extensions\IMVUClientXUL@imvu.com [2012-08-08 01:24:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\009fxs6e.default\extensions [2011-06-04 00:16:34 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\009fxs6e.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2012-07-16 12:54:47 | 000,000,000 | ---D | M] (SFT_Polska Community Toolbar) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\009fxs6e.default\extensions\{5c5b9468-d672-4eb7-b52f-b5afabf28c5b} [2012-07-18 11:06:11 | 000,000,000 | ---D | M] (uTorrentControl2 Community Toolbar) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\009fxs6e.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03} [2012-07-16 12:54:49 | 000,000,000 | ---D | M] (ST Deutsch FF Community Toolbar) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\009fxs6e.default\extensions\{9d81af43-de53-48d0-a199-42c2a226b24c} [2012-07-25 23:48:51 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\009fxs6e.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2012-07-25 23:46:17 | 000,000,000 | ---D | M] (Flash and Video Download) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\009fxs6e.default\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2011-09-29 22:45:07 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\009fxs6e.default\extensions\engine@conduit.com [2012-06-03 16:16:23 | 000,000,000 | ---D | M] (Iplex to ALLPlayer) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\009fxs6e.default\extensions\IplextoALL@ALLPlayer.org [2011-09-29 22:45:07 | 000,000,000 | ---D | M] (Personas) -- C:\Users\Robert\AppData\Roaming\mozilla\Firefox\Profiles\009fxs6e.default\extensions\personas@christopher.beard [2011-09-29 15:15:29 | 000,002,569 | ---- | M] () -- C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\009fxs6e.default\searchplugins\askcom.xml [2011-08-04 10:31:04 | 000,000,923 | ---- | M] () -- C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\009fxs6e.default\searchplugins\conduit.xml [2012-03-27 19:22:21 | 000,003,916 | ---- | M] () -- C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\009fxs6e.default\searchplugins\sweetim.xml [2012-07-22 21:08:05 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2012-04-28 23:00:16 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2012-07-22 21:08:05 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2012-08-08 01:24:11 | 000,012,619 | ---- | M] () (No name found) -- C:\USERS\ROBERT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\009FXS6E.DEFAULT\EXTENSIONS\{B9BFAF1C-A63F-47CD-8B9A-29526CED9060}.XPI [2012-07-18 11:06:03 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2012-06-20 18:55:43 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2012-07-23 17:13:14 | 000,002,363 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml [2012-06-20 18:55:43 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2012-06-20 18:55:43 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2012-06-20 18:55:43 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2012-06-20 18:55:43 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2012-06-20 18:55:43 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2009-06-10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\\bh\BabylonToolbar.dll (Babylon BHO) O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O2 - BHO: (SFT_Polska Toolbar) - {5c5b9468-d672-4eb7-b52f-b5afabf28c5b} - C:\Program Files\SFT_Polska\prxtbSFT_.dll (Conduit Ltd.) O2 - BHO: (uTorrentControl2 Toolbar) - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Softonic Deutsch FF Toolbar) - {9d81af43-de53-48d0-a199-42c2a226b24c} - C:\Program Files\Softonic_Deutsch_FF\tbSoft.dll (Conduit Ltd.) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (IplexToALLPlayer) - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - C:\Program Files\ALLPlayer\Iplex\IplexToALLPlayer.dll (ALLCinema Ltd.) O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (SFT_Polska Toolbar) - {5c5b9468-d672-4eb7-b52f-b5afabf28c5b} - C:\Program Files\SFT_Polska\prxtbSFT_.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (uTorrentControl2 Toolbar) - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\\BabylonToolbarTlbr.dll (Babylon Ltd.) O3 - HKLM\..\Toolbar: (Softonic Deutsch FF Toolbar) - {9d81af43-de53-48d0-a199-42c2a226b24c} - C:\Program Files\Softonic_Deutsch_FF\tbSoft.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentControl2 Toolbar) - {687578B9-7132-4A7A-80E4-30EE31099E03} - C:\Program Files\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (Softonic Deutsch FF Toolbar) - {9D81AF43-DE53-48D0-A199-42C2A226B24C} - C:\Program Files\Softonic_Deutsch_FF\tbSoft.dll (Conduit Ltd.) O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (ALWIL Software) O4 - HKLM..\Run: [FastAccess Web Alert] C:\Program Files\Creative\Creative Live! Cam\Live! Central 3\FAInstaller\FAtry.exe (Microsoft) O4 - HKLM..\Run: [File System Monitor] C:\Windows\System32\avp.exe () O4 - HKLM..\Run: [Google Updater] C:\Program Files\Google\Google Updater\GoogleUpdater.exe (Google) O4 - HKLM..\Run: [l33t] C:\Windows\system\iexplore.exe () O4 - HKLM..\Run: [Live! Central 3] C:\Program Files\Creative\Creative Live! Cam\Live! Central 3\CTLVCentral3.exe (Creative Technology Ltd) O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.) O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG) O4 - HKLM..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.) O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.) O4 - HKLM..\Run: [V0700Mon.exe] C:\Windows\V0700Mon.exe (Creative Technology Ltd.) O4 - HKLM..\Run: [VDownloader] C:\Program Files\VDownloader\VDownloader.exe (Vitzo) O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft) O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Robert\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc) O4 - HKCU..\Run: [ALLUpdate] C:\Program Files\ALLPlayer\ALLUpdate.exe () O4 - HKCU..\Run: [Clownfish] C:\Program Files\Clownfish\Clownfish.exe () O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKCU..\Run: [IPLA!] C:\Program Files\ipla\ipla.exe (Redefine Sp z o.o.) O4 - HKCU..\Run: [kmbtuccwyubgtbj] C:\ProgramData\kmbtuccw.exe () O4 - HKCU..\Run: [Komunikator] C:\Program Files\Tlen.pl\tlen.exe (o2.pl Sp. z o.o.) O4 - HKCU..\Run: [Livestation] C:\Program Files\Livestation\Livestation.exe -startup File not found O4 - HKCU..\Run: [MSIDLL] rundll32.exe msifha32.dll,DlbkirTT File not found O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe () O4 - HKCU..\Run: [PKTray] C:\Program Files\Przyspiesz Komputer\PKTray.exe File not found O4 - HKCU..\Run: [TBPanel] C:\Program Files\Vtune\TBPanel.exe () O4 - HKCU..\Run: [UpdateMyDrivers] C:\Program Files\SmartTweak Software\UpdateMyDrivers\UpdateMyDrivers.exe /ot /as /ss File not found O4 - HKCU..\Run: [uTorrent] D:\Torrenty Gotowe\uTorrent.exe (BitTorrent, Inc.) O4 - HKCU..\Run: [VeohPlugin] C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks) O4 - HKCU..\Run: [Windows Service Host] svcservice.exe File not found O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1158612 -"Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; Media Center PC 6.0; OfficeLiveConnector.1.5; OfficeLivePatch.1.3; Tablet PC 2.0; .NET CLR 3.5.30729; .NET CLR 3.0.30729)" -"http://pl.playmillion.com/lp/002-pl/" File not found O4 - Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wucault.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: ati2sgav = "C:\Windows\system32\ati2sgav.exe" () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0 O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.) O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O13 - gopher Prefix: missing O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33) O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E3FB7B30-FB33-40AC-84BC-2EE41820589C}: DhcpNameServer = O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOBCA7~1\GO36F4~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009-06-10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{040a24e7-ebd5-11de-88ed-00241d9c9618}\Shell - "" = AutoRun O33 - MountPoints2\{040a24e7-ebd5-11de-88ed-00241d9c9618}\Shell\AutoRun\command - "" = K:\LaunchU3.exe -a O33 - MountPoints2\{186c76ef-9b8e-11e1-9520-00241d9c9618}\Shell - "" = AutoRun O33 - MountPoints2\{186c76ef-9b8e-11e1-9520-00241d9c9618}\Shell\AutoRun\command - "" = K:\Startme.exe O33 - MountPoints2\{266c9c65-09e6-11df-968a-00241d9c9618}\Shell - "" = AutoRun O33 - MountPoints2\{266c9c65-09e6-11df-968a-00241d9c9618}\Shell\AutoRun\command - "" = K:\LaunchU3.exe -a O33 - MountPoints2\{e958a89d-de8e-11df-93ca-00241d9c9618}\Shell - "" = AutoRun O33 - MountPoints2\{e958a89d-de8e-11df-93ca-00241d9c9618}\Shell\AutoRun\command - "" = K:\LaunchU3.exe -a O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-08-08 18:24:11 | 000,000,000 | ---D | C] -- C:\ProgramData\zrlbctgwytuvejw [2012-08-08 02:56:16 | 000,000,000 | ---D | C] -- C:\Users\Robert\AppData\Local\._Revolution_ [2012-08-08 02:56:11 | 000,000,000 | ---D | C] -- C:\Users\Robert\AppData\Roaming\Stykz [2012-08-08 02:56:11 | 000,000,000 | ---D | C] -- C:\Users\Robert\Documents\Animations [2012-08-07 16:57:12 | 000,000,000 | ---D | C] -- C:\Users\Robert\AppData\Roaming\Blender Foundation [2012-08-07 01:39:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blender Foundation [2012-08-07 01:39:48 | 000,000,000 | ---D | C] -- C:\Program Files\Blender Foundation [2012-08-06 07:16:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi [2012-08-06 07:16:38 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn Hamachi [2012-08-03 20:59:14 | 000,000,000 | ---D | C] -- C:\Users\Robert\Documents\Inversion Saves [2012-08-03 11:25:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Namco Bandai Games [2012-07-31 23:59:28 | 000,000,000 | ---D | C] -- C:\Users\Robert\AppData\Roaming\EurekaLog [2012-07-30 23:49:14 | 000,000,000 | ---D | C] -- C:\Users\Robert\Documents\Activision [2012-07-30 23:45:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision [2012-07-26 00:03:27 | 000,000,000 | ---D | C] -- C:\Program Files\WinPcap [2012-07-26 00:03:27 | 000,000,000 | ---D | C] -- C:\Users\Robert\AppData\Roaming\VDownloader [2012-07-26 00:03:27 | 000,000,000 | ---D | C] -- C:\Users\Robert\AppData\Local\VDownloader [2012-07-26 00:03:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VDownloader [2012-07-25 20:31:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3 [2012-07-25 00:04:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Creative [2012-07-25 00:03:51 | 000,000,000 | ---D | C] -- C:\Users\Robert\AppData\Roaming\Creative [2012-07-24 23:59:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative [2012-07-24 23:59:09 | 000,000,000 | ---D | C] -- C:\Program Files\Creative [2012-07-24 23:58:50 | 000,150,176 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\System32\drivers\CtClsFlt.sys [2012-07-24 23:58:50 | 000,134,144 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\System32\drivers\CtAudDrv.sys [2012-07-24 23:17:05 | 000,303,104 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\System32\CTAFX32.dll [2012-07-24 23:17:04 | 000,322,528 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\System32\drivers\V0700Vid.sys [2012-07-24 23:17:04 | 000,114,688 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\System32\V0700Ext.ax [2012-07-24 23:17:04 | 000,102,400 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\System32\V0700Ext.crl [2012-07-24 23:17:04 | 000,045,056 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\System32\V0700Pin.dll [2012-07-24 23:17:04 | 000,028,672 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\V0700Mon.exe [2012-07-24 23:17:04 | 000,024,576 | ---- | C] (Creative Technology Ltd.) -- C:\Windows\System32\CtCamPin.crl [2012-07-24 23:17:04 | 000,000,000 | ---D | C] -- C:\Windows\CtDrvInstall [2012-07-24 23:16:23 | 000,000,000 | ---D | C] -- C:\Creative Live! Cam [2012-07-24 19:10:28 | 000,000,000 | ---D | C] -- C:\Users\Robert\Documents\MAGIX [2012-07-24 19:08:36 | 000,000,000 | ---D | C] -- C:\Users\Robert\Documents\MAGIX_MusicEditor [2012-07-24 19:07:30 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\MAGIX_Music_Maker_MX_Premium_Download_Version [2012-07-24 19:07:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX [2012-07-24 18:54:54 | 000,000,000 | ---D | C] -- C:\Users\Robert\Desktop\Dubstep Vol. 3 [2012-07-24 18:28:54 | 000,917,504 | ---- | C] (MAGIX AG) -- C:\Windows\System32\MXRestore.exe [2012-07-24 18:28:54 | 000,114,688 | ---- | C] (PoINT Software & Systems GmbH) -- C:\Windows\System32\DLLCDA32.dll [2012-07-24 18:28:54 | 000,065,536 | ---- | C] (PoINT Software & Systems GmbH) -- C:\Windows\System32\DLLPTL32.dll [2012-07-24 18:28:54 | 000,061,440 | ---- | C] (PoINT Software & Systems GmbH) -- C:\Windows\System32\DLLCDF32.dll [2012-07-24 18:28:54 | 000,057,344 | ---- | C] (PoINT Software & Systems GmbH) -- C:\Windows\System32\DLLTPO32.dll [2012-07-24 18:28:54 | 000,053,248 | ---- | C] (PoINT Software & Systems GmbH) -- C:\Windows\System32\DLLPRJ32.dll [2012-07-24 18:28:54 | 000,045,056 | ---- | C] (PoINT Software & Systems GmbH) -- C:\Windows\System32\DLLIMG32.dll [2012-07-24 18:28:54 | 000,040,960 | ---- | C] (PoINT Software & Systems GmbH) -- C:\Windows\System32\DLLRD32.dll [2012-07-24 18:28:54 | 000,032,768 | ---- | C] (PoINT Software & Systems GmbH) -- C:\Windows\System32\DLLMSC32.dll [2012-07-24 18:28:54 | 000,032,768 | ---- | C] (PoINT Software & Systems GmbH) -- C:\Windows\System32\DLLISO32.dll [2012-07-24 18:28:54 | 000,032,768 | ---- | C] (PoINT Software & Systems GmbH) -- C:\Windows\System32\DLLDIR32.dll [2012-07-24 18:28:54 | 000,024,576 | ---- | C] (PoINT Software & Systems GmbH) -- C:\Windows\System32\TTIC32.dll [2012-07-24 18:28:54 | 000,024,576 | ---- | C] (PoINT Software & Systems GmbH) -- C:\Windows\System32\TTI32.dll [2012-07-24 18:28:54 | 000,024,576 | ---- | C] (PoINT Software & Systems GmbH) -- C:\Windows\System32\DLLIX.dll [2012-07-24 18:28:38 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml4a.dll [2012-07-24 18:28:34 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\MAGIX_MusicMaker16Premium_Download_Version [2012-07-24 18:28:22 | 000,000,000 | ---D | C] -- C:\ProgramData\MAGIX [2012-07-24 18:28:04 | 000,000,000 | ---D | C] -- C:\Program Files\MAGIX [2012-07-24 18:27:38 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MAGIX Services [2012-07-24 18:07:08 | 000,000,000 | ---D | C] -- C:\Users\Robert\Documents\MAGIX Downloads [2012-07-24 18:07:07 | 000,000,000 | ---D | C] -- C:\Users\Robert\AppData\Roaming\MAGIX [2012-07-23 17:34:37 | 000,000,000 | ---D | C] -- C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps [2012-07-23 17:29:04 | 000,106,496 | ---- | C] (Capturix Software Technologies) -- C:\Windows\System32\CSCE.OCX [2012-07-23 17:29:03 | 000,458,752 | ---- | C] (Capturix Software Technologies) -- C:\Windows\System32\CVCE.OCX [2012-07-23 17:29:03 | 000,208,896 | ---- | C] (Capturix Software Technologies) -- C:\Windows\System32\CUHJC.OCX [2012-07-23 17:29:03 | 000,122,880 | ---- | C] (CAPTURIX) -- C:\Windows\System32\capturixsndmail.ocx [2012-07-23 17:29:03 | 000,098,304 | ---- | C] (CAPTURIX) -- C:\Windows\System32\CapJpegsrv.OCX [2012-07-23 17:29:03 | 000,034,304 | ---- | C] (Microsoft) -- C:\Windows\System32\NTSVC.OCX [2012-07-23 17:29:03 | 000,032,768 | ---- | C] (*) -- C:\Windows\System32\CVSIOCTRL.OCX [2012-07-23 17:29:02 | 001,069,056 | ---- | C] (Fath Software ( www.fathsoft.com )) -- C:\Windows\System32\videocapx.ocx [2012-07-23 17:29:02 | 000,962,612 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFC42D.dll [2012-07-23 17:29:02 | 000,827,445 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MFCO42D.dll [2012-07-23 17:29:02 | 000,516,173 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSVCP60D.dll [2012-07-23 17:29:02 | 000,434,252 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSVCRTD.dll [2012-07-23 17:29:02 | 000,416,528 | ---- | C] (Microsoft Corporation ) -- C:\Windows\System32\COMCT332.OCX [2012-07-23 17:29:02 | 000,352,256 | ---- | C] (Intel Corporation) -- C:\Windows\System32\ijl15.dll [2012-07-23 17:29:02 | 000,204,800 | ---- | C] (IDS Imaging Development Systems GmbH) -- C:\Windows\System32\falcon.dll [2012-07-23 17:29:02 | 000,185,384 | ---- | C] (Catalyst Development Corporation) -- C:\Windows\System32\cstcpapi.DLL [2012-07-23 17:29:02 | 000,180,224 | ---- | C] (VADIAN.NET AG) -- C:\Windows\System32\aspsms.dll [2012-07-23 17:29:02 | 000,104,072 | ---- | C] (Catalyst Development Corporation) -- C:\Windows\System32\CSWSK32.OCX [2012-07-23 17:29:02 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\INETDE.DLL [2012-07-23 17:29:02 | 000,000,000 | ---D | C] -- C:\Windows\System32\Fonts [2012-07-23 17:29:01 | 001,454,080 | ---- | C] (Fath Software) -- C:\Windows\System32\imagex.ocx [2012-07-23 17:29:01 | 000,430,080 | ---- | C] (Capturix Software Technologies) -- C:\Windows\System32\CapturixFrameWork.ocx [2012-07-23 17:29:01 | 000,421,888 | ---- | C] (Capturix Software Technologies) -- C:\Windows\System32\CapturixFrameWorkDLL.dll [2012-07-23 17:29:01 | 000,180,224 | ---- | C] (Capturix Software Technologies) -- C:\Windows\System32\CVSNETCAMS.OCX [2012-07-23 17:29:01 | 000,124,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSWINSCK.OCX [2012-07-23 17:29:01 | 000,103,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mscomm32.ocx [2012-07-23 17:29:01 | 000,024,576 | ---- | C] (Capturix Software Technologies) -- C:\Windows\System32\CAPTURIXLNG.DLL [2012-07-23 17:24:42 | 000,000,000 | ---D | C] -- C:\Users\Robert\Documents\EatCam Webcam Recorder [2012-07-23 17:22:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Capture WebCam [2012-07-23 17:13:23 | 000,000,000 | ---D | C] -- C:\Users\Robert\AppData\Roaming\BabylonToolbar [2012-07-23 17:13:20 | 000,000,000 | ---D | C] -- C:\Program Files\BabylonToolbar [2012-07-23 17:13:09 | 000,000,000 | ---D | C] -- C:\Users\Robert\AppData\Roaming\Babylon [2012-07-23 17:13:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon [2012-07-23 17:13:06 | 000,000,000 | ---D | C] -- C:\Users\Robert\AppData\Roaming\YourFileDownloader [2012-07-23 16:39:23 | 000,000,000 | ---D | C] -- C:\Users\Robert\Desktop\fraps [2012-07-22 21:08:03 | 000,476,976 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\npdeployJava1.dll [2012-07-21 09:11:38 | 000,065,536 | ---- | C] (Beepa P/L) -- C:\Windows\System32\frapsvid.dll [2012-07-17 08:53:18 | 000,000,000 | ---D | C] -- C:\Users\Robert\Desktop\DT [2012-07-17 08:50:09 | 000,000,000 | R--D | C] -- C:\Users\Robert\Desktop\' [2012-07-12 21:55:36 | 000,000,000 | ---D | C] -- C:\Users\Robert\Documents\Yu-Gi-Oh! ONLINE 3 [2012-07-12 18:26:54 | 000,000,000 | ---D | C] -- C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AP Tuner 3.08 [2012-07-12 18:26:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AP Tuner 3.08 [2012-07-12 18:26:54 | 000,000,000 | ---D | C] -- C:\Program Files\AP Tuner [3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-08-08 18:50:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012-08-08 18:50:15 | 2414,731,264 | -HS- | M] () -- C:\hiberfil.sys [2012-08-08 18:40:06 | 000,014,832 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012-08-08 18:40:06 | 000,014,832 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012-08-08 18:33:25 | 000,001,032 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012-08-08 18:24:11 | 000,000,051 | ---- | M] () -- C:\ProgramData\afdszqotgarursa [2012-08-08 18:24:06 | 000,061,440 | ---- | M] () -- C:\Users\Robert\ms.exe [2012-08-08 18:24:06 | 000,061,440 | ---- | M] () -- C:\ProgramData\kmbtuccw.exe [2012-08-08 18:23:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012-08-08 17:46:00 | 000,001,036 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012-08-08 16:18:34 | 000,000,972 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job [2012-08-08 01:47:06 | 000,140,800 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2012-08-08 01:46:55 | 000,283,304 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr [2012-08-08 01:46:36 | 000,280,904 | ---- | M] () -- C:\Windows\System32\PnkBstrB.ex0 [2012-08-08 00:27:28 | 534,677,062 | ---- | M] () -- C:\Users\Robert\Desktop\Huge 30 min Best Epic Fails Compilation May 2012 - FailingEveryDay.mp4 [2012-08-07 14:28:39 | 000,000,362 | ---- | M] () -- C:\Windows\tasks\At1.job [2012-08-07 01:39:57 | 000,002,014 | ---- | M] () -- C:\Users\Public\Desktop\Blender.lnk [2012-08-06 23:48:03 | 022,658,948 | ---- | M] () -- C:\Users\Robert\Desktop\Naruto Shippuden Sha La La.mp4 [2012-08-06 23:47:45 | 024,230,736 | ---- | M] () -- C:\Users\Robert\Desktop\Naruto Shippuden Opening 8 Diver Full.mp4 [2012-08-05 03:28:53 | 000,001,093 | ---- | M] () -- C:\Users\Robert\Desktop\Play Saints Row III DirectX 11.lnk [2012-08-03 11:27:58 | 000,001,183 | ---- | M] () -- C:\Users\Robert\Desktop\Inversion — skrót.lnk [2012-08-02 23:23:11 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe [2012-08-02 23:23:11 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [2012-08-01 17:45:16 | 000,762,158 | ---- | M] () -- C:\Windows\System32\perfh015.dat [2012-08-01 17:45:16 | 000,673,456 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012-08-01 17:45:16 | 000,163,454 | ---- | M] () -- C:\Windows\System32\perfc015.dat [2012-08-01 17:45:16 | 000,126,628 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012-08-01 00:54:06 | 000,025,384 | ---- | M] () -- C:\Users\Robert\Desktop\vlog intro.veg [2012-07-31 16:16:19 | 000,020,480 | ---- | M] () -- C:\Users\Robert\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-07-31 16:14:40 | 000,027,680 | ---- | M] () -- C:\Users\Robert\Desktop\New3.MP3.sfk [2012-07-31 00:20:22 | 000,000,713 | ---- | M] () -- C:\Users\Robert\Desktop\prototype2 — skrót.lnk [2012-07-29 17:13:31 | 000,147,351 | ---- | M] () -- C:\Users\Robert\Desktop\fairy tail main tabs.pdf [2012-07-26 17:01:20 | 000,000,010 | ---- | M] () -- C:\Windows\GSetup.ini [2012-07-26 13:45:11 | 000,801,437 | ---- | M] () -- C:\Users\Robert\Desktop\New3.MP3 [2012-07-26 13:34:06 | 001,121,176 | ---- | M] () -- C:\Users\Robert\Desktop\new2.MP3 [2012-07-26 00:03:18 | 000,001,843 | ---- | M] () -- C:\Users\Public\Desktop\VDownloader.lnk [2012-07-25 22:59:36 | 001,845,290 | ---- | M] () -- C:\Users\Robert\Desktop\marek.MP3 [2012-07-25 20:14:53 | 000,000,991 | ---- | M] () -- C:\Users\Robert\AppData\Local\recently-used.xbel [2012-07-25 20:00:53 | 000,401,992 | ---- | M] () -- C:\Users\Robert\Desktop\marek.MMM [2012-07-24 23:19:58 | 002,485,680 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012-07-24 22:46:01 | 001,291,494 | ---- | M] () -- C:\Users\Robert\Desktop\New.MP3 [2012-07-24 19:10:24 | 000,001,817 | ---- | M] () -- C:\Users\Robert\Desktop\MusicMaker — skrót.lnk [2012-07-23 17:34:37 | 000,000,616 | ---- | M] () -- C:\Users\Robert\Desktop\Fraps.lnk [2012-07-23 17:13:20 | 000,000,318 | ---- | M] () -- C:\user.js [2012-07-22 21:07:55 | 000,476,976 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\npdeployJava1.dll [2012-07-22 21:07:55 | 000,157,488 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe [2012-07-22 21:07:55 | 000,149,296 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe [2012-07-22 21:07:55 | 000,149,296 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe [2012-07-22 21:07:54 | 000,472,880 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll [2012-07-21 20:16:26 | 000,000,812 | ---- | M] () -- C:\Users\Robert\Desktop\kind.m3u [2012-07-21 09:11:38 | 000,065,536 | ---- | M] (Beepa P/L) -- C:\Windows\System32\frapsvid.dll [2012-07-20 00:26:44 | 021,570,934 | ---- | M] () -- C:\Users\Robert\Desktop\07 - Strange Girl.flac [2012-07-20 00:26:41 | 038,590,069 | ---- | M] () -- C:\Users\Robert\Desktop\01 Boku ha, Tori ni Naru..flac [2012-07-20 00:26:25 | 036,633,331 | ---- | M] () -- C:\Users\Robert\Desktop\13 - Masquerade.flac [2012-07-18 11:37:44 | 004,869,317 | ---- | M] () -- C:\Users\Robert\Desktop\Sick Bubblegum (Skrillex Remix) [Picture DL Link]_(ALLConverter).mp3 [2012-07-17 09:46:51 | 000,000,861 | ---- | M] () -- C:\Users\Robert\Desktop\BattlefrontII — skrót.lnk [2012-07-12 21:42:39 | 004,829,918 | ---- | M] () -- C:\Users\Robert\Desktop\Renai Circulation Full [Lyrics and Translation].flv [2012-07-12 18:27:01 | 000,001,984 | ---- | M] () -- C:\Users\Robert\Desktop\Tuner.lnk [2012-07-11 18:40:18 | 023,946,278 | ---- | M] () -- C:\Users\Robert\Desktop\Learning To Breathe - Switchfoot (w_ lyrics).flv [2012-07-11 18:38:47 | 011,645,178 | ---- | M] () -- C:\Users\Robert\Desktop\Switchfoot - Meant To Live.flv [2012-07-11 00:39:06 | 039,562,821 | ---- | M] () -- C:\Users\Robert\Desktop\70209549.mp4 [2012-07-10 00:32:02 | 000,104,960 | ---- | M] () -- C:\Users\Robert\Desktop\clouds21.jpg [3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-08-08 18:24:11 | 000,061,440 | ---- | C] () -- C:\ProgramData\kmbtuccw.exe [2012-08-08 18:24:09 | 000,000,051 | ---- | C] () -- C:\ProgramData\afdszqotgarursa [2012-08-08 18:24:05 | 000,061,440 | ---- | C] () -- C:\Users\Robert\ms.exe [2012-08-08 00:27:28 | 534,677,062 | ---- | C] () -- C:\Users\Robert\Desktop\Huge 30 min Best Epic Fails Compilation May 2012 - FailingEveryDay.mp4 [2012-08-07 01:39:57 | 000,002,014 | ---- | C] () -- C:\Users\Public\Desktop\Blender.lnk [2012-08-06 23:48:03 | 022,658,948 | ---- | C] () -- C:\Users\Robert\Desktop\Naruto Shippuden Sha La La.mp4 [2012-08-06 23:47:45 | 024,230,736 | ---- | C] () -- C:\Users\Robert\Desktop\Naruto Shippuden Opening 8 Diver Full.mp4 [2012-08-05 07:24:53 | 000,000,717 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS4.lnk [2012-08-05 02:07:32 | 000,001,093 | ---- | C] () -- C:\Users\Robert\Desktop\Play Saints Row III DirectX 11.lnk [2012-08-03 11:28:01 | 000,001,183 | ---- | C] () -- C:\Users\Robert\Desktop\Inversion — skrót.lnk [2012-07-31 16:14:36 | 000,025,384 | ---- | C] () -- C:\Users\Robert\Desktop\vlog intro.veg [2012-07-31 16:13:34 | 000,027,680 | ---- | C] () -- C:\Users\Robert\Desktop\New3.MP3.sfk [2012-07-31 00:20:25 | 000,000,713 | ---- | C] () -- C:\Users\Robert\Desktop\prototype2 — skrót.lnk [2012-07-29 17:13:29 | 000,147,351 | ---- | C] () -- C:\Users\Robert\Desktop\fairy tail main tabs.pdf [2012-07-26 17:01:20 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini [2012-07-26 13:45:10 | 000,801,437 | ---- | C] () -- C:\Users\Robert\Desktop\New3.MP3 [2012-07-26 13:34:04 | 001,121,176 | ---- | C] () -- C:\Users\Robert\Desktop\new2.MP3 [2012-07-26 00:03:18 | 000,001,843 | ---- | C] () -- C:\Users\Public\Desktop\VDownloader.lnk [2012-07-26 00:03:17 | 000,444,283 | ---- | C] () -- C:\Program Files\Common Files\WinPcapNmap.exe [2012-07-25 22:59:33 | 001,845,290 | ---- | C] () -- C:\Users\Robert\Desktop\marek.MP3 [2012-07-25 20:14:53 | 000,000,991 | ---- | C] () -- C:\Users\Robert\AppData\Local\recently-used.xbel [2012-07-25 20:00:53 | 000,401,992 | ---- | C] () -- C:\Users\Robert\Desktop\marek.MMM [2012-07-24 23:59:50 | 000,057,656 | ---- | C] () -- C:\Windows\System32\drivers\FilterPC.bmp [2012-07-24 23:59:50 | 000,024,995 | ---- | C] () -- C:\Windows\System32\drivers\FilterPC.jpg [2012-07-24 23:17:04 | 000,057,656 | ---- | C] () -- C:\Windows\System32\drivers\V0700PC.bmp [2012-07-24 23:17:04 | 000,004,387 | ---- | C] () -- C:\Windows\VF0700.uns [2012-07-24 22:45:59 | 001,291,494 | ---- | C] () -- C:\Users\Robert\Desktop\New.MP3 [2012-07-24 19:10:24 | 000,001,817 | ---- | C] () -- C:\Users\Robert\Desktop\MusicMaker — skrót.lnk [2012-07-24 18:28:54 | 000,038,492 | ---- | C] () -- C:\Windows\System32\DLLAV32.lib [2012-07-24 18:28:04 | 000,120,200 | ---- | C] () -- C:\Windows\System32\DLLDEV32i.dll [2012-07-23 17:29:02 | 001,003,520 | ---- | C] () -- C:\Windows\System32\ltmm_n.dll [2012-07-23 17:29:02 | 000,040,448 | ---- | C] () -- C:\Windows\System32\RegOBJ.dll [2012-07-23 17:29:01 | 000,999,424 | ---- | C] () -- C:\Windows\System32\FathMail.dll [2012-07-23 17:13:20 | 000,000,318 | ---- | C] () -- C:\user.js [2012-07-23 16:39:59 | 000,000,616 | ---- | C] () -- C:\Users\Robert\Desktop\Fraps.lnk [2012-07-20 13:04:15 | 021,570,934 | ---- | C] () -- C:\Users\Robert\Desktop\07 - Strange Girl.flac [2012-07-20 13:04:13 | 036,633,331 | ---- | C] () -- C:\Users\Robert\Desktop\13 - Masquerade.flac [2012-07-20 13:02:30 | 038,590,069 | ---- | C] () -- C:\Users\Robert\Desktop\01 Boku ha, Tori ni Naru..flac [2012-07-18 11:37:29 | 004,869,317 | ---- | C] () -- C:\Users\Robert\Desktop\Sick Bubblegum (Skrillex Remix) [Picture DL Link]_(ALLConverter).mp3 [2012-07-17 09:46:55 | 000,000,861 | ---- | C] () -- C:\Users\Robert\Desktop\BattlefrontII — skrót.lnk [2012-07-14 01:30:47 | 000,000,812 | ---- | C] () -- C:\Users\Robert\Desktop\kind.m3u [2012-07-14 01:28:43 | 004,280,664 | ---- | C] () -- C:\Users\Robert\Desktop\Code Geass Soundtrack - Innocent days_(ALLConverter).mp3 [2012-07-14 01:28:34 | 005,015,854 | ---- | C] () -- C:\Users\Robert\Desktop\Code Geass Soundtrack - Continued Story_(ALLConverter).mp3 [2012-07-14 01:28:20 | 005,119,508 | ---- | C] () -- C:\Users\Robert\Desktop\code geass Stories-Hitomi_(ALLConverter).mp3 [2012-07-12 21:40:34 | 004,829,918 | ---- | C] () -- C:\Users\Robert\Desktop\Renai Circulation Full [Lyrics and Translation].flv [2012-07-12 18:27:01 | 000,001,984 | ---- | C] () -- C:\Users\Robert\Desktop\Tuner.lnk [2012-07-11 18:37:06 | 023,946,278 | ---- | C] () -- C:\Users\Robert\Desktop\Learning To Breathe - Switchfoot (w_ lyrics).flv [2012-07-11 18:36:31 | 011,645,178 | ---- | C] () -- C:\Users\Robert\Desktop\Switchfoot - Meant To Live.flv [2012-07-11 00:38:47 | 039,562,821 | ---- | C] () -- C:\Users\Robert\Desktop\70209549.mp4 [2012-07-10 00:32:01 | 000,104,960 | ---- | C] () -- C:\Users\Robert\Desktop\clouds21.jpg [2012-06-27 14:01:16 | 000,283,097 | ---- | C] () -- C:\Windows\System32\drivers\RTAIODAT.DAT [2012-05-15 02:21:50 | 000,423,744 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe [2012-04-22 22:12:22 | 004,424,704 | ---- | C] () -- C:\Windows\System32\ffmpeg.dll [2012-04-22 20:43:13 | 000,000,067 | ---- | C] () -- C:\Windows\ABC_mru.ini [2012-04-09 01:40:36 | 000,079,360 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll [2012-04-09 01:39:46 | 000,260,608 | ---- | C] () -- C:\Windows\System32\TomsMoComp_ff.dll [2012-04-09 01:39:32 | 000,158,720 | ---- | C] () -- C:\Windows\System32\ff_unrar.dll [2012-04-09 01:39:32 | 000,099,840 | ---- | C] () -- C:\Windows\System32\ff_wmv9.dll [2012-04-09 01:39:30 | 001,525,248 | ---- | C] () -- C:\Windows\System32\ff_samplerate.dll [2012-04-09 01:39:30 | 000,146,944 | ---- | C] () -- C:\Windows\System32\ff_libmad.dll [2012-04-09 01:39:28 | 000,212,480 | ---- | C] () -- C:\Windows\System32\ff_libdts.dll [2012-04-09 01:39:28 | 000,115,200 | ---- | C] () -- C:\Windows\System32\ff_liba52.dll [2012-04-09 01:39:26 | 000,328,704 | ---- | C] () -- C:\Windows\System32\ff_libfaad2.dll [2012-03-29 16:21:26 | 000,172,032 | ---- | C] () -- C:\Windows\System32\libbluray.dll [2012-03-29 16:21:18 | 006,582,226 | ---- | C] () -- C:\Windows\System32\avcodec-lav-54.dll [2012-03-29 16:21:18 | 001,152,365 | ---- | C] () -- C:\Windows\System32\avformat-lav-54.dll [2012-03-29 16:21:18 | 000,374,152 | ---- | C] () -- C:\Windows\System32\swscale-lav-2.dll [2012-03-29 16:21:18 | 000,207,872 | ---- | C] () -- C:\Windows\System32\avutil-lav-51.dll [2012-03-29 16:21:18 | 000,144,523 | ---- | C] () -- C:\Windows\System32\avfilter-lav-2.dll [2012-03-25 17:02:43 | 000,000,037 | ---- | C] () -- C:\Windows\Grappler.ini [2012-03-25 17:02:35 | 000,012,800 | ---- | C] () -- C:\Windows\ioctrl.dll [2012-03-18 00:29:19 | 000,140,800 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2012-03-18 00:27:57 | 000,283,304 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe [2012-03-18 00:27:56 | 000,076,888 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe [2012-03-16 23:54:14 | 000,007,597 | ---- | C] () -- C:\Users\Robert\AppData\Local\Resmon.ResmonCfg [2011-12-07 21:32:24 | 000,216,064 | ---- | C] ( ) -- C:\Windows\System32\Lagarith.dll [2011-09-28 18:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat [2011-09-28 07:19:35 | 000,108,032 | ---- | C] () -- C:\Windows\System32\sh33w32.dll [2011-09-28 06:57:44 | 000,063,488 | ---- | C] () -- C:\Users\Robert\xobglu16.dll [2011-09-28 06:57:44 | 000,023,552 | ---- | C] () -- C:\Users\Robert\xobglu32.dll [2011-09-08 16:00:52 | 000,150,528 | ---- | C] () -- C:\Windows\System32\mkx.dll [2011-09-08 16:00:48 | 000,142,336 | ---- | C] () -- C:\Windows\System32\mp4.dll [2011-09-08 16:00:42 | 000,123,392 | ---- | C] () -- C:\Windows\System32\ogm.dll [2011-09-08 16:00:38 | 000,249,856 | ---- | C] () -- C:\Windows\System32\dxr.dll [2011-09-08 16:00:34 | 000,113,152 | ---- | C] () -- C:\Windows\System32\dsmux.exe [2011-09-08 16:00:24 | 000,154,624 | ---- | C] () -- C:\Windows\System32\ts.dll [2011-09-08 16:00:10 | 000,137,728 | ---- | C] () -- C:\Windows\System32\mkv2vfr.exe [2011-09-08 16:00:06 | 000,358,400 | ---- | C] () -- C:\Windows\System32\gdsmux.exe [2011-09-08 15:59:54 | 000,080,384 | ---- | C] () -- C:\Windows\System32\mkzlib.dll [2011-09-08 15:59:52 | 000,024,576 | ---- | C] () -- C:\Windows\System32\mkunicode.dll [2011-05-30 15:42:50 | 000,240,640 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll [2011-05-23 09:46:30 | 000,645,632 | ---- | C] () -- C:\Windows\System32\xvidcore.dll [2011-03-03 13:39:56 | 000,109,568 | ---- | C] () -- C:\Windows\System32\avi.dll [2011-03-03 13:38:10 | 000,097,792 | ---- | C] () -- C:\Windows\System32\avs.dll [2011-03-03 13:37:50 | 000,093,184 | ---- | C] () -- C:\Windows\System32\avss.dll [2011-02-12 21:49:00 | 000,050,176 | ---- | C] () -- C:\Windows\System32\defrag32.exe [2011-02-12 21:49:00 | 000,022,016 | ---- | C] () -- C:\Windows\System32\avp.exe [2011-02-12 21:49:00 | 000,022,016 | ---- | C] () -- C:\Windows\System32\Av1Setup.exe [2010-11-11 00:23:40 | 000,402,271 | ---- | C] () -- C:\Windows\Bid For Power Uninstaller.exe [2010-10-31 21:39:17 | 000,258,048 | ---- | C] () -- C:\Windows\System32\libFLAC.dll [2010-08-18 21:56:38 | 000,000,151 | ---- | C] () -- C:\Windows\System32\Registration.ini [2010-08-12 16:39:30 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys [2010-06-03 09:36:59 | 000,000,088 | RHS- | C] () -- C:\ProgramData\6DA6A436FB.sys [2010-06-03 09:36:58 | 000,002,516 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys [2010-04-06 13:04:35 | 000,020,480 | ---- | C] () -- C:\Users\Robert\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010-03-19 18:34:09 | 000,138,056 | ---- | C] () -- C:\Users\Robert\AppData\Roaming\PnkBstrK.sys [2009-12-08 23:45:51 | 000,000,048 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [color=#E56717]========== Files - Unicode (All) ==========[/color] [2012-07-11 19:08:16 | 143,732,396 | ---- | M] ()(C:\Users\Robert\Desktop\?Bestamvsofalltime ? Written in the Spirals AMV.mp4) -- C:\Users\Robert\Desktop\√Bestamvsofalltime ▪ Written in the Spirals AMV.mp4 [2012-07-11 19:06:39 | 143,732,396 | ---- | C] ()(C:\Users\Robert\Desktop\?Bestamvsofalltime ? Written in the Spirals AMV.mp4) -- C:\Users\Robert\Desktop\√Bestamvsofalltime ▪ Written in the Spirals AMV.mp4 [2012-06-28 15:57:52 | 008,344,072 | ---- | M] ()(C:\Users\Robert\Desktop\????? ed---take off.flv) -- C:\Users\Robert\Desktop\青之驅魔師 ed---take off.flv [2012-06-28 15:55:39 | 008,344,072 | ---- | C] ()(C:\Users\Robert\Desktop\????? ed---take off.flv) -- C:\Users\Robert\Desktop\青之驅魔師 ed---take off.flv [2012-06-28 15:55:26 | 009,190,195 | ---- | M] ()(C:\Users\Robert\Desktop\ROOKiEZ is PUNK_D _ IN MY WORLD ??????/045.flv) -- C:\Users\Robert\Desktop\ROOKiEZ is PUNK_D _ IN MY WORLD を歌ってみた/045.flv [2012-06-28 15:53:08 | 009,190,195 | ---- | C] ()(C:\Users\Robert\Desktop\ROOKiEZ is PUNK_D _ IN MY WORLD ??????/045.flv) -- C:\Users\Robert\Desktop\ROOKiEZ is PUNK_D _ IN MY WORLD を歌ってみた/045.flv < End of report >