OTL logfile created on: 2012-08-12 13:59:01 - Run 2 OTL by OldTimer - Version 3.2.56.0 Folder = C:\Users\Dom\Desktop Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,50 Gb Total Physical Memory | 2,74 Gb Available Physical Memory | 78,29% Memory free 3,78 Gb Paging File | 2,97 Gb Available in Paging File | 78,72% Paging File free Paging file location(s): C:\pagefile.sys 288 2048 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 75,04 Gb Total Space | 14,47 Gb Free Space | 19,28% Space Free | Partition Type: NTFS Drive D: | 390,62 Gb Total Space | 356,21 Gb Free Space | 91,19% Space Free | Partition Type: NTFS Drive E: | 7,03 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: DOM-KOMPUTER | User Name: Dom | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-08-08 12:00:48 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Dom\Desktop\OTL.exe PRC - [2012-07-27 18:43:01 | 001,691,680 | ---- | M] (PerformerSoft LLC) -- C:\ProgramData\SearchAlgo Manager\2.2.509.39\c190e9c7-7f62-46de-bab3-8445c845b061\srchalgomngr.exe PRC - [2012-07-03 16:40:32 | 000,265,120 | ---- | M] () -- C:\Program Files\Common Files\WireHelpSvc.exe PRC - [2012-02-09 00:00:12 | 000,198,136 | ---- | M] (Nitro PDF Software) -- C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe PRC - [2011-06-24 06:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe PRC - [2011-05-09 17:15:56 | 000,027,760 | ---- | M] (VIA Technologies, Inc.) -- C:\Windows\System32\ViakaraokeSrv.exe PRC - [2011-04-15 11:43:20 | 002,280,312 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe PRC - [2010-12-19 15:01:28 | 000,803,432 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe PRC - [2010-12-19 14:19:08 | 000,378,984 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2010-11-20 14:17:36 | 000,179,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\schtasks.exe PRC - [2010-11-20 14:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2009-10-13 08:39:04 | 000,935,208 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012-07-27 18:43:01 | 002,039,328 | ---- | M] () -- C:\ProgramData\SearchAlgo Manager\2.2.509.39\c190e9c7-7f62-46de-bab3-8445c845b061\srchalgomngr.dll MOD - [2011-03-17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2012-08-04 11:24:27 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012-08-01 13:00:07 | 000,529,232 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2012-07-27 18:43:01 | 001,691,680 | ---- | M] (PerformerSoft LLC) [Auto | Running] -- C:\ProgramData\SearchAlgo Manager\2.2.509.39\c190e9c7-7f62-46de-bab3-8445c845b061\srchalgomngr.exe -- (SearchAlgo Manager) SRV - [2012-07-03 16:40:32 | 000,265,120 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\WireHelpSvc.exe -- (WireHelpSvc) SRV - [2012-05-03 08:31:10 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012-02-09 00:00:12 | 000,198,136 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe -- (NitroReaderDriverReadSpool2) SRV - [2011-06-12 11:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service) SRV - [2011-05-14 20:27:32 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc) SRV - [2011-05-09 17:15:56 | 000,027,760 | ---- | M] (VIA Technologies, Inc.) [Auto | Running] -- C:\Windows\System32\ViakaraokeSrv.exe -- (VIAKaraokeService) SRV - [2011-04-15 11:43:20 | 002,280,312 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6) SRV - [2010-12-19 14:19:08 | 000,378,984 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2009-10-13 08:39:04 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0) SRV - [2009-07-14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009-07-14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2007-02-13 18:27:12 | 000,407,184 | ---- | M] (Cenega Poland) [Auto | Stopped] -- C:\Windows\System32\pr2ajfae.exe -- (pr2ajfae) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva388.sys -- (XDva388) DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub) DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleNT.sys -- (EagleNT) DRV - [2012-07-03 16:40:26 | 000,836,496 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\ESLWireACD.sys -- (ESLWireAC) DRV - [2012-03-02 19:26:47 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV - [2012-02-04 11:25:05 | 000,278,984 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt) DRV - [2012-02-03 23:26:28 | 000,025,416 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt) DRV - [2011-11-15 05:50:16 | 000,112,096 | ---- | M] (Power Software Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\scdemu.sys -- (SCDEmu) DRV - [2011-06-22 15:38:26 | 000,024,504 | ---- | M] (Turtle Entertainment GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ESLvnic.sys -- (ESLvnic1) DRV - [2011-05-09 17:15:50 | 001,805,936 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\viahduaa.sys -- (VIAHdAudAddService) DRV - [2010-12-20 06:21:00 | 010,466,376 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2010-11-20 14:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2010-11-20 14:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2010-11-20 14:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2010-11-20 12:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010-11-20 12:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV - [2010-11-20 11:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2010-11-20 11:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2010-11-12 07:10:52 | 000,122,984 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA) DRV - [2009-07-16 05:36:30 | 000,013,216 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ASACPI.sys -- (MTsensor) DRV - [2009-07-14 01:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | System | Running] -- C:\Windows\System32\drivers\serial.sys -- (Serial) DRV - [2007-02-13 18:26:23 | 000,065,432 | ---- | M] (Cenega Poland) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\pe3ajfae.sys -- (pe3ajfae) DRV - [2007-02-13 18:25:27 | 000,052,128 | ---- | M] (Cenega Poland) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\ps6ajfae.sys -- (ps6ajfae) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKLM\..\URLSearchHook: - No CLSID value found IE - HKLM\..\URLSearchHook: {3B81079D-2AC9-425f-A494-A1C7D93AFA3C} - C:\Program Files\GadgetBox\gadgetBoxTB.dll (GadgetBox) IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{30F5AB16-9F1E-4E99-93F2-ECB9ABB0EC12}: "URL" = http://www.searchya.com/?q={searchTerms}&s=1&a=foxtab&chnl=ft-100&cd=2XzuyEtN2Y1L1Qzu0B0C0A0E0CyD0ByBtC0BtC0A0F0DyCtBtN0D0Tzu0CtBtCyDtN1L2XzutBtFtCtFtCtFtAtCtB&cr=420614754 IE - HKLM\..\SearchScopes\{4D066206-27C6-036F-A866-36302F641511}: "URL" = http://search.my-tools-app.com/?babsrc=home&s=web&as=0&isid=9848&q={searchTerms} IE - HKLM\..\SearchScopes\{AA74FE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://search.gboxapp.com/?q={searchTerms} IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://search.gboxapp.com/?q={searchTerms} IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&barid={B958B9F4-BE90-11E0-A4BF-00FF01000001} IE - HKLM\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/redirector/sredir?sredir=2685&query={searchTerms}&invocationType=tb50-ie-winamp-chromesbox-en-us&tb_uuid=20110507184006150&tb_oid=07-05-2011&tb_mrud=07-05-2011 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2790392 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.searchalgo.com?ch=10&cid=273 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKCU\..\URLSearchHook: - No CLSID value found IE - HKCU\..\URLSearchHook: {3B81079D-2AC9-425f-A494-A1C7D93AFA3C} - C:\Program Files\GadgetBox\gadgetBoxTB.dll (GadgetBox) IE - HKCU\..\URLSearchHook: {687578b9-7132-4a7a-80e4-30ee31099e03} - No CLSID value found IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No CLSID value found IE - HKCU\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - SOFTWARE\Classes\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\InprocServer32 File not found IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847} IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} IE - HKCU\..\SearchScopes,DefaultScope = {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} IE - HKCU\..\SearchScopes\{024C138C-1A58-44F9-8B48-60BA3EEA9461}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3072253 IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&AF=108603&babsrc=SP_ss&mntrId=e662fd6200000000000000ff01000001 IE - HKCU\..\SearchScopes\{131283AF-4133-4890-8406-A4388D1BAE54}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=STC-PO&o=1738&src=kw&q={searchTerms}&locale=&apn_ptnrs=^AAU&apn_dtid=^YYYYYY^YY^PL&apn_uid=F347D0C6-C7D0-4BB7-ADC8-5C69EA7E7BBE&apn_sauid=99F47476-7FEA-48F4-97A1-066B6A553DEB IE - HKCU\..\SearchScopes\{30F5AB16-9F1E-4E99-93F2-ECB9ABB0EC12}: "URL" = http://www.searchya.com/?q={searchTerms}&s=1&a=foxtab&chnl=ft-100&cd=2XzuyEtN2Y1L1Qzu0B0C0A0E0CyD0ByBtC0BtC0A0F0DyCtBtN0D0Tzu0CtBtCyDtN1L2XzutBtFtCtFtCtFtAtCtB&cr=420614754 IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://www.searchalgo.com/search.html?ch=10&cid=273&q={searchTerms} IE - HKCU\..\SearchScopes\{4D066206-27C6-036F-A866-36302F641511}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&barid={B958B9F4-BE90-11E0-A4BF-00FF01000001} IE - HKCU\..\SearchScopes\{5E71BDD4-4013-48AD-89D0-E7B0C44ECBA2}: "URL" = http://search.softonic.com/MON00084/tb_v1?q={searchTerms}&SearchSource=4&cc= IE - HKCU\..\SearchScopes\{5F3BEBD5-F6C6-A4B8-EDD2-A6F5F61813A8}: "URL" = http://www.buzqo.com/s/?q={searchTerms}&iesrc={referrer:source?}&cfg=2-401-0-... IE - HKCU\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpro.com/search/browser/extractnow/{191FFD4B-9663-4539-A0EB-9A8CCEC9158D}?q={searchTerms} IE - HKCU\..\SearchScopes\{AA74FE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://search.gboxapp.com/?q={searchTerms} IE - HKCU\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://search.gboxapp.com/?q={searchTerms} IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredibar.com/mb119/?search={searchTerms}&loc=IB_DS&a=6Oys4Aa7iO&i=26 IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=nv1&chnl=nv1&cd=2XzuyEtN2Y1L1Qzu0B0C0A0E0CyD0ByBtC0BtC0A0F0DyCtBtN0D0Tzu0CtCzzzytN1L2XzutBtFtCtFtDtFtAtDtC&cr=1362061721 IE - HKCU\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/redirector/sredir?sredir=2685&query={searchTerms}&invocationType=tb50-ie-winamp-chromesbox-en-us&tb_uuid=20110507184006150&tb_oid=07-05-2011&tb_mrud=07-05-2011 IE - HKCU\..\SearchScopes\{FC6AD3DE-E187-4FFF-BC95-E709381B38CE}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2790392 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421; [color=#E56717]========== FireFox ==========[/color] FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@gamersfirst.com/LiveLauncher: C:\Program Files\GamersFirst\LIVE!\nplivelauncher.dll File not found FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_32: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nitropdf.com/NitroPDF: C:\Program Files\Nitro PDF\Reader 2\npnitromozilla.dll ( ) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox 4.0 Beta 9\components [2012-08-04 11:24:27 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox 4.0 Beta 9\plugins [2011-04-23 19:45:51 | 000,000,204 | ---- | M] () FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\SearchAlgo Manager\2.2.509.39\c190e9c7-7f62-46de-bab3-8445c845b061\FirefoxExtension [2012-07-27 18:43:01 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox 4.0 Beta 9\components [2012-08-04 11:24:27 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox 4.0 Beta 9\plugins [2011-04-23 19:45:51 | 000,000,204 | ---- | M] () [2011-11-23 20:07:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dom\AppData\Roaming\mozilla\Extensions [2012-07-07 13:42:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dom\AppData\Roaming\mozilla\Firefox\Profiles\extensions [2012-08-12 13:07:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dom\AppData\Roaming\mozilla\Firefox\Profiles\extensions\extensions [2012-08-12 13:28:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dom\AppData\Roaming\mozilla\Firefox\Profiles\dyr80y3u.default\extensions [2012-07-07 14:02:18 | 000,000,000 | ---D | M] (ADDICT-THING) -- C:\Users\Dom\AppData\Roaming\mozilla\Firefox\Profiles\dyr80y3u.default\extensions\4ff821c17eac4@4ff821c17eafd.info [2012-07-07 14:02:18 | 000,000,000 | ---D | M] (GadgetBox) -- C:\Users\Dom\AppData\Roaming\mozilla\Firefox\Profiles\dyr80y3u.default\extensions\gadget@gadgetbox [2012-02-11 23:11:18 | 000,000,000 | ---D | M] (MyTools extension) -- C:\Users\Dom\AppData\Roaming\mozilla\Firefox\Profiles\dyr80y3u.default\extensions\info@my-tools-app.com [2012-08-12 13:20:01 | 000,000,000 | ---D | M] (OneClickDownloader) -- C:\Users\Dom\AppData\Roaming\mozilla\Firefox\Profiles\dyr80y3u.default\extensions\OneClickDownload@OneClickDownload.com [2012-08-12 13:07:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dom\AppData\Roaming\mozilla\Firefox\Profiles\emj9toh0.default\extensions [2011-10-03 16:48:09 | 000,000,000 | ---D | M] ("Winamp Toolbar") -- C:\Users\Dom\AppData\Roaming\mozilla\Firefox\Profiles\emj9toh0.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} [2011-08-04 13:56:14 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Users\Dom\AppData\Roaming\mozilla\Firefox\Profiles\emj9toh0.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847} [2012-08-02 14:12:59 | 000,000,000 | ---D | M] (searchya.com) -- C:\Users\Dom\AppData\Roaming\mozilla\Firefox\Profiles\emj9toh0.default\extensions\ffxtlbr@searchya.com [2012-08-02 14:08:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dom\AppData\Roaming\mozilla\Firefox\Profiles\emj9toh0.default\extensions\staged [2012-08-02 14:12:59 | 000,000,000 | ---D | M] (searchya.com) -- C:\Users\Dom\AppData\Roaming\mozilla\Firefox\Profiles\extensions\extensions\ffxtlbr@searchya.com [2012-08-02 14:08:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dom\AppData\Roaming\mozilla\Firefox\Profiles\extensions\extensions\staged [2012-02-04 14:50:59 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2012-02-04 14:50:59 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\ffxtlbr@babylon.com [color=#E56717]========== Chrome ==========[/color] CHR - homepage: http://www.searchalgo.com?ch=10&cid=273 CHR - Extension: No name found = C:\Users\Dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaoeljheghbhpgohamdianlpdglflj\7.15.2.0\ CHR - Extension: No name found = C:\Users\Dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnkbppmdgdfccoihhajoeflficbpgcnm\1.0_0\ CHR - Extension: No name found = C:\Users\Dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpojpihgafjhbgkgaglhighomjceieff\ CHR - Extension: No name found = C:\Users\Dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpojpihgafjhbgkgaglhighomjceieff\1.4_0\ CHR - Extension: No name found = C:\Users\Dom\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.11.0.9874_0\ O1 HOSTS File: ([2009-06-10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (TinyBHO Class) - {00e71626-0bef-11dc-8314-0800200c9a66} - C:\Users\Dom\AppData\Roaming\DownloaderGold\ieplug.dll () O2 - BHO: (TinyBHO Class) - {00e71626-0bef-11dc-8314-0864264c9a64} - C:\Users\Dom\AppData\Roaming\DownloaderGold\ieplug.dll () O2 - BHO: (BFlix Class) - {0C9F4179-6CE2-4c6a-A3E5-67FF3592A12E} - C:\Program Files\BFlix\Bflix.dll (BFlix) O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - Reg Error: Value error. File not found O2 - BHO: (Incredibar.com Helper Object) - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Program Files\Incredibar.com\incredibar\1.5.3.27\bh\incredibar.dll (Montera Technologeis LTD) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (no name) - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - No CLSID value found. O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (ADDICT-THING Class) - {AECEE380-806E-CE0D-E4BF-A1547C30A494} - C:\ProgramData\ADDICT-THING\bhoclass.dll () O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (MyTools Class) - {C3A44133-7EAD-434C-AC9E-7F1DA176BA8C} - C:\Program Files\MyTools\mytools.dll (MyTools) O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\DealBulldog Toolbar Toolbar\tbcore3.dll File not found O3 - HKLM\..\Toolbar: (DealBulldog Toolbar Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files\DealBulldog Toolbar Toolbar\tbcore3.dll File not found O3 - HKLM\..\Toolbar: (GagetBox) - {3B81079D-2AC9-425f-A494-A1C7D93AFA3C} - C:\Program Files\GadgetBox\gadgetBoxTB.dll (GadgetBox) O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - No CLSID value found. O3 - HKLM\..\Toolbar: (Incredibar Toolbar) - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files\Incredibar.com\incredibar\1.5.3.27\incredibarTlbr.dll (Montera Technologeis LTD) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {687578B9-7132-4A7A-80E4-30EE31099E03} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found. O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation) O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA) O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (Power Software Ltd) O4 - HKLM..\Run: [TaskTray] File not found O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Dom\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc) O4 - HKCU..\Run: [ares] C:\Program Files\Ares\Ares.exe (Ares Development Group) O4 - HKCU..\Run: [BitTorrent] C:\Program Files\BitTorrent\BitTorrent.exe (BitTorrent, Inc.) O4 - HKCU..\Run: [ChomikBox] C:\Program Files\ChomikBox\chomikbox.exe ( ) O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKCU..\Run: [DriverScanner] C:\Program Files\Uniblue\DriverScanner\launcher.exe (Uniblue Systems Limited) O4 - HKCU..\Run: [ESL Wire] C:\Program Files\EslWire\wire.exe (Turtle Entertainment GmbH) O4 - HKCU..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.) O4 - HKCU..\Run: [GG] C:\Users\Dom\AppData\Local\GG\Application\gghub.exe (GG Network S.A.) O4 - HKCU..\Run: [Optimizer Pro] C:\Program Files\Optimizer Pro\OptProLauncher.exe (PC Utilities Pro) O4 - HKCU..\Run: [Steam] D:\steam\steam.exe (Valve Corporation) O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149 O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32) O16 - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.100 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{19F1BF0C-58E7-4D5F-801D-76AACF2F5A5E}: DhcpNameServer = 192.168.1.100 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20 - AppInit_DLLs: (c:\progra~2\search~1\22509~1.39\c190e9~1\srchal~1.dll) - c:\ProgramData\SearchAlgo Manager\2.2.509.39\c190e9c7-7f62-46de-bab3-8445c845b061\srchalgomngr.dll () O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKCU Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009-06-10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2005-05-22 17:23:01 | 000,000,000 | ---D | M] - D:\autorun -- [ NTFS ] O32 - AutoRun File - [2010-03-11 20:29:00 | 000,000,000 | ---D | M] - E:\Autorun -- [ CDFS ] O32 - AutoRun File - [2009-11-14 07:15:13 | 024,319,488 | R--- | M] () - E:\autorun.dat -- [ CDFS ] O32 - AutoRun File - [2009-11-14 04:25:10 | 000,000,154 | R--- | M] () - E:\autorun.inf -- [ CDFS ] O33 - MountPoints2\{5714c79c-6d1f-11e0-aa3a-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{5714c79c-6d1f-11e0-aa3a-806e6f6e6963}\Shell\AutoRun\command - "" = E:\SaboteurLauncher.exe -- [2009-11-14 07:15:15 | 001,045,776 | R--- | M] (Electronic Arts) O33 - MountPoints2\{fe47ab6c-645c-11e1-9e78-00ff01000001}\Shell - "" = AutoRun O33 - MountPoints2\{fe47ab6c-645c-11e1-9e78-00ff01000001}\Shell\AutoRun\command - "" = G:\Autorun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-08-12 12:56:13 | 000,000,000 | ---D | C] -- C:\_OTL [2012-08-12 12:31:38 | 000,000,000 | ---D | C] -- C:\Users\Dom\Desktop\esl [2012-08-08 12:10:32 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Dom\Desktop\OTL.com [2012-08-08 12:08:26 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Dom\Desktop\OTL.scr [2012-08-08 12:06:11 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Dom\Desktop\OTL.exe [2012-08-02 14:18:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ExtractNow [2012-08-02 14:18:24 | 000,000,000 | ---D | C] -- C:\Program Files\ExtractNow [2012-08-02 14:10:09 | 000,000,000 | ---D | C] -- C:\Program Files\DownloadManager [2012-08-02 14:08:23 | 000,000,000 | ---D | C] -- C:\Program Files\SearchYa! [2012-07-28 17:25:32 | 000,000,000 | ---D | C] -- C:\Program Files\Gadu-Gadu 10 [2012-07-27 19:09:36 | 000,000,000 | ---D | C] -- C:\Users\Dom\Documents\Moje Gry [2012-07-27 18:43:04 | 000,000,000 | ---D | C] -- C:\Windows\System32\searchplugins [2012-07-27 18:43:01 | 000,000,000 | ---D | C] -- C:\ProgramData\SearchAlgo Manager [2012-07-16 21:15:26 | 000,000,000 | ---D | C] -- C:\Windows\rescache [2012-03-05 22:43:11 | 002,447,264 | ---- | C] (DownVision ) -- C:\Users\Dom\AppData\Local\setup.exe [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-08-12 13:31:28 | 000,001,030 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012-08-12 13:31:27 | 000,002,286 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2012-08-12 13:28:23 | 000,000,324 | ---- | M] () -- C:\Windows\tasks\DriverScanner.job [2012-08-12 13:20:49 | 000,010,416 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012-08-12 13:20:49 | 000,010,416 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012-08-12 13:13:42 | 000,000,372 | -H-- | M] () -- C:\Windows\tasks\OptimizerProUpdaterLogonTask.job [2012-08-12 13:13:41 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\OptimizerProUpdaterRefreshTask.job [2012-08-12 13:13:40 | 000,001,026 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012-08-12 13:13:35 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012-08-12 13:13:32 | 2817,826,816 | -HS- | M] () -- C:\hiberfil.sys [2012-08-09 11:13:16 | 000,006,922 | ---- | M] () -- C:\Users\Dom\Desktop\Nowy dokument dziennika.jnt [2012-08-09 11:03:14 | 000,139,264 | ---- | M] () -- C:\Users\Dom\Desktop\SystemLook.exe [2012-08-08 12:11:05 | 000,687,590 | ---- | M] () -- C:\Windows\System32\perfh015.dat [2012-08-08 12:11:05 | 000,606,992 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012-08-08 12:11:05 | 000,131,176 | ---- | M] () -- C:\Windows\System32\perfc015.dat [2012-08-08 12:11:05 | 000,103,370 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012-08-08 12:08:28 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Dom\Desktop\OTL.com [2012-08-08 12:06:12 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Dom\Desktop\OTL.scr [2012-08-08 12:00:48 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Dom\Desktop\OTL.exe [2012-08-02 14:18:24 | 000,000,949 | ---- | M] () -- C:\Users\Dom\Desktop\ExtractNow.lnk [2012-08-02 14:12:56 | 000,384,835 | ---- | M] () -- C:\Users\Dom\AppData\Local\speeddial.crx [2012-07-28 17:26:57 | 000,001,610 | ---- | M] () -- C:\Users\Dom\Desktop\GG dysk.lnk [2012-07-28 17:25:40 | 000,000,962 | ---- | M] () -- C:\Users\Public\Desktop\OpenFM.lnk [2012-07-28 17:25:40 | 000,000,933 | ---- | M] () -- C:\Users\Public\Desktop\Gadu-Gadu 10.lnk [2012-07-28 17:25:03 | 026,493,696 | ---- | M] () -- C:\Users\Dom\Desktop\gg10.exe [2012-07-28 07:14:10 | 000,000,892 | ---- | M] () -- C:\Users\Public\Desktop\ESL Wire.lnk [2012-07-27 18:42:05 | 000,001,135 | ---- | M] () -- C:\Users\Dom\Desktop\GG.lnk [2012-07-27 18:39:56 | 039,948,312 | ---- | M] () -- C:\Users\Dom\Desktop\ggsetup.exe [2012-07-23 12:52:05 | 002,733,770 | ---- | M] () -- C:\Users\Dom\Desktop\Syy By k[t]m.rar [2012-07-23 12:51:28 | 002,733,766 | ---- | M] () -- C:\Users\Dom\Desktop\SSY bY k[t]m.rar [2012-07-23 12:48:14 | 000,921,654 | ---- | M] () -- C:\Users\Dom\Desktop\de_dust20002.bmp [2012-07-20 17:32:14 | 000,000,873 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-08-09 11:11:57 | 000,006,922 | ---- | C] () -- C:\Users\Dom\Desktop\Nowy dokument dziennika.jnt [2012-08-09 11:08:12 | 000,139,264 | ---- | C] () -- C:\Users\Dom\Desktop\SystemLook.exe [2012-08-02 14:18:24 | 000,000,949 | ---- | C] () -- C:\Users\Dom\Desktop\ExtractNow.lnk [2012-08-02 14:08:26 | 000,384,835 | ---- | C] () -- C:\Users\Dom\AppData\Local\speeddial.crx [2012-07-28 17:25:40 | 000,000,962 | ---- | C] () -- C:\Users\Public\Desktop\OpenFM.lnk [2012-07-28 17:25:40 | 000,000,933 | ---- | C] () -- C:\Users\Public\Desktop\Gadu-Gadu 10.lnk [2012-07-28 17:25:34 | 000,000,929 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gadu-Gadu 10.lnk [2012-07-28 17:23:03 | 026,493,696 | ---- | C] () -- C:\Users\Dom\Desktop\gg10.exe [2012-07-27 18:42:05 | 000,001,143 | ---- | C] () -- C:\Users\Dom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GG.lnk [2012-07-27 18:42:05 | 000,001,135 | ---- | C] () -- C:\Users\Dom\Desktop\GG.lnk [2012-07-27 18:36:12 | 039,948,312 | ---- | C] () -- C:\Users\Dom\Desktop\ggsetup.exe [2012-07-23 12:52:04 | 002,733,770 | ---- | C] () -- C:\Users\Dom\Desktop\Syy By k[t]m.rar [2012-07-23 12:51:27 | 002,733,766 | ---- | C] () -- C:\Users\Dom\Desktop\SSY bY k[t]m.rar [2012-07-23 12:50:53 | 000,921,654 | ---- | C] () -- C:\Users\Dom\Desktop\de_dust20002.bmp [2012-02-22 23:43:27 | 000,022,328 | ---- | C] () -- C:\Users\Dom\AppData\Roaming\PnkBstrK.sys [2012-02-22 23:43:08 | 000,000,307 | ---- | C] () -- C:\Windows\game.ini [2012-02-03 23:26:29 | 000,278,984 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys [2012-02-03 23:26:28 | 000,025,416 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys [2012-02-03 16:44:22 | 000,122,880 | ---- | C] () -- C:\Windows\UnGins.exe [2012-01-11 22:54:41 | 000,001,315 | ---- | C] () -- C:\Windows\System32\.ini [2011-10-31 22:22:43 | 000,007,595 | ---- | C] () -- C:\Users\Dom\AppData\Local\Resmon.ResmonCfg [2011-08-18 21:47:12 | 000,066,872 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe [2011-08-18 21:46:58 | 000,022,328 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys [2011-08-18 21:45:10 | 000,103,736 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe [2011-07-14 21:59:02 | 000,265,120 | ---- | C] () -- C:\Program Files\Common Files\WireHelpSvc.exe [2011-06-24 00:14:21 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe [2011-06-24 00:10:56 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2011-05-06 14:17:45 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2011-04-23 13:12:16 | 000,050,688 | ---- | C] () -- C:\Windows\X-Shield.exe [2011-04-23 13:12:16 | 000,049,152 | ---- | C] () -- C:\Windows\X-ShieldCheck.exe [2011-04-22 17:29:56 | 001,474,832 | ---- | C] () -- C:\Windows\System32\drivers\sfi.dat [2011-04-22 17:25:42 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll [2011-04-22 17:23:00 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat [2011-04-22 16:37:33 | 000,073,728 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll [2011-04-22 16:35:38 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini [2011-04-22 16:35:36 | 000,015,491 | ---- | C] () -- C:\Windows\Ascd_tmp.ini < End of report >