OTL logfile created on: 2012-12-01 21:08:10 - Run 4 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\userx\Desktop Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,00 Gb Total Physical Memory | 0,79 Gb Available Physical Memory | 39,77% Memory free 4,00 Gb Paging File | 2,57 Gb Available in Paging File | 64,21% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 195,21 Gb Total Space | 22,96 Gb Free Space | 11,76% Space Free | Partition Type: NTFS Drive D: | 270,45 Gb Total Space | 88,77 Gb Free Space | 32,82% Space Free | Partition Type: NTFS Computer Name: USERX-KOMPUTER | User Name: userx | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-11-30 16:20:38 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\userx\Desktop\OTL.exe PRC - [2012-11-27 21:11:56 | 000,878,480 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe PRC - [2012-11-19 21:48:16 | 002,254,768 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe PRC - [2012-11-19 21:48:14 | 001,435,568 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe PRC - [2012-11-06 19:00:32 | 003,143,800 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2013\avgui.exe PRC - [2012-10-24 14:11:20 | 000,529,744 | ---- | M] (Valve Corporation) -- C:\Program Files\Common Files\Steam\SteamService.exe PRC - [2012-10-22 13:05:08 | 000,196,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2013\avgwdsvc.exe PRC - [2012-10-22 13:04:32 | 001,116,792 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2013\avgnsx.exe PRC - [2012-10-02 11:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe PRC - [2012-08-15 08:45:15 | 001,353,080 | ---- | M] (Valve Corporation) -- C:\Program Files\Steam\steam.exe PRC - [2012-08-03 15:06:06 | 001,086,376 | ---- | M] (Nokia) -- C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe PRC - [2012-08-01 15:07:16 | 000,724,888 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe PRC - [2012-08-01 15:07:06 | 000,174,488 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe PRC - [2012-08-01 15:07:00 | 000,126,872 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe PRC - [2012-08-01 15:06:58 | 000,148,888 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe PRC - [2012-07-27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2011-02-25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2010-11-20 13:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe PRC - [2009-07-08 01:53:36 | 000,472,112 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Pure Networks\Network Magic\nmapp.exe PRC - [2009-07-07 13:48:44 | 000,647,216 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe PRC - [2009-07-07 13:48:44 | 000,647,216 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012-11-27 21:12:02 | 000,835,584 | ---- | M] () -- C:\Program Files\Opera\gstreamer\gstreamer.dll MOD - [2012-11-27 21:12:02 | 000,312,832 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstoggdec.dll MOD - [2012-11-27 21:12:02 | 000,158,208 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstffmpegcolorspace.dll MOD - [2012-11-27 21:12:02 | 000,101,888 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwebmdec.dll MOD - [2012-11-27 21:12:02 | 000,096,256 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstcoreplugins.dll MOD - [2012-11-27 21:12:02 | 000,094,208 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstaudioresample.dll MOD - [2012-11-27 21:12:02 | 000,093,696 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstaudioconvert.dll MOD - [2012-11-27 21:12:02 | 000,073,728 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwavparse.dll MOD - [2012-11-27 21:12:02 | 000,067,072 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstdirectsound.dll MOD - [2012-11-27 21:12:02 | 000,062,976 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstdecodebin2.dll MOD - [2012-11-27 21:12:02 | 000,057,344 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstautodetect.dll MOD - [2012-11-27 21:12:02 | 000,038,912 | ---- | M] () -- C:\Program Files\Opera\gstreamer\plugins\gstwaveform.dll MOD - [2012-10-24 14:11:18 | 020,317,008 | ---- | M] () -- C:\Program Files\Steam\bin\libcef.dll MOD - [2012-10-24 14:11:13 | 001,099,616 | ---- | M] () -- C:\Program Files\Steam\bin\avcodec-53.dll MOD - [2012-10-24 14:11:13 | 000,902,480 | ---- | M] () -- C:\Program Files\Steam\bin\chromehtml.dll MOD - [2012-10-24 14:11:13 | 000,190,816 | ---- | M] () -- C:\Program Files\Steam\bin\avformat-53.dll MOD - [2012-10-24 14:11:13 | 000,123,232 | ---- | M] () -- C:\Program Files\Steam\bin\avutil-51.dll MOD - [2012-08-03 15:07:06 | 000,276,392 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\phonon4.dll MOD - [2012-08-03 15:06:50 | 002,652,584 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtXmlPatterns4.dll MOD - [2012-08-03 15:06:50 | 000,363,944 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtXml4.dll MOD - [2012-08-03 15:06:48 | 011,166,120 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtWebKit4.dll MOD - [2012-08-03 15:06:46 | 000,205,736 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtSql4.dll MOD - [2012-08-03 15:06:44 | 001,346,472 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtScript4.dll MOD - [2012-08-03 15:06:44 | 000,720,296 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtOpenGL4.dll MOD - [2012-08-03 15:06:42 | 008,506,792 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtGui4.dll MOD - [2012-08-03 15:06:42 | 001,013,672 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtNetwork4.dll MOD - [2012-08-03 15:06:42 | 000,520,104 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtMultimediaKit1.dll MOD - [2012-08-03 15:06:40 | 002,480,552 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtDeclarative4.dll MOD - [2012-08-03 15:06:40 | 002,353,576 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtCore4.dll MOD - [2012-08-03 15:06:36 | 000,445,864 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\sqldrivers\qsqlite4.dll MOD - [2012-08-03 15:06:32 | 000,206,760 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\Imageformats\qjpeg4.dll MOD - [2012-08-03 15:06:32 | 000,035,240 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\Imageformats\qico4.dll MOD - [2012-08-03 15:06:30 | 000,032,680 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\Imageformats\qgif4.dll MOD - [2012-08-03 15:06:02 | 000,437,672 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\NService.dll MOD - [2012-08-03 15:05:24 | 000,604,072 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\CommonUpdateChecker.dll MOD - [2012-07-02 10:29:08 | 000,391,600 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\ssoengine.dll MOD - [2012-07-02 10:29:08 | 000,059,280 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\securestorage.dll MOD - [2012-07-02 10:28:20 | 000,110,080 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\mediaservice\dsengine.dll MOD - [2009-10-28 04:40:14 | 003,885,984 | ---- | M] () -- C:\Program Files\Opera\program\plugins\NPSWF32.dll MOD - [2009-07-13 16:37:04 | 000,152,112 | ---- | M] () -- C:\Program Files\Common Files\Pure Networks Shared\Platform\CAntiVirusCOM.dll MOD - [2009-07-13 16:37:04 | 000,098,304 | ---- | M] () -- C:\Program Files\Common Files\Pure Networks Shared\Platform\CFirewallCOM.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - [2012-11-19 21:48:14 | 001,435,568 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc) SRV - [2012-11-09 11:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012-10-24 14:11:20 | 000,529,744 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2012-10-22 13:05:08 | 000,196,664 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2013\avgwdsvc.exe -- (avgwd) SRV - [2012-10-09 19:19:29 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012-10-02 11:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service) SRV - [2012-08-01 15:07:16 | 000,724,888 | ---- | M] (Nokia) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) SRV - [2012-07-27 21:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2010-06-21 08:49:02 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc) SRV - [2009-12-15 21:07:16 | 000,025,832 | ---- | M] (BioWare) [On_Demand | Stopped] -- C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe -- (DAUpdaterSvc) SRV - [2009-07-14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc) SRV - [2009-07-14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc) SRV - [2009-07-14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2009-07-07 13:48:44 | 000,647,216 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe -- (nmservice) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (VGPU) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (tsusbhub) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (Synth3dVsc) DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV - File not found [Kernel | On_Demand | Unknown] -- -- (avxvwcx0) DRV - [2012-10-18 19:20:00 | 000,466,008 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd) DRV - [2012-10-15 03:48:52 | 000,055,776 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\avgidshx.sys -- (AVGIDSHX) DRV - [2012-09-21 03:46:06 | 000,164,832 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix) DRV - [2012-09-21 03:46:00 | 000,177,376 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\avglogx.sys -- (Avglogx) DRV - [2012-06-27 14:18:52 | 000,019,072 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd) DRV - [2012-02-09 21:43:00 | 010,816,832 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2012-01-09 16:28:20 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc) DRV - [2012-01-09 16:28:20 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd) DRV - [2012-01-09 16:28:20 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt) DRV - [2012-01-09 16:28:20 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev) DRV - [2010-11-20 13:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus) DRV - [2010-11-20 13:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt) DRV - [2010-11-20 13:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc) DRV - [2010-11-20 11:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV - [2010-11-20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb) DRV - [2010-11-20 10:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID) DRV - [2010-11-20 10:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap) DRV - [2010-06-26 12:04:36 | 000,281,760 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt) DRV - [2010-06-26 12:04:35 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt) DRV - [2010-04-07 16:38:54 | 001,500,160 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athur.sys -- (athur) DRV - [2009-07-07 13:48:44 | 000,027,696 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\purendis.sys -- (purendis) DRV - [2009-07-07 13:48:44 | 000,026,672 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\pnarp.sys -- (pnarp) DRV - [2009-03-18 15:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi) DRV - [2008-05-13 15:00:16 | 000,035,840 | ---- | M] (CACE Technologies) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\npf_devolo.sys -- (NPF_devolo) DRV - [2006-12-22 19:05:34 | 000,449,536 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athrusb.sys -- (athrusb) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-4252676272-2371586129-3660312933-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve IE - HKU\S-1-5-21-4252676272-2371586129-3660312933-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-21-4252676272-2371586129-3660312933-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-4252676272-2371586129-3660312933-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\S-1-5-21-4252676272-2371586129-3660312933-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-4252676272-2371586129-3660312933-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421; [color=#E56717]========== FireFox ==========[/color] FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: File not found O1 HOSTS File: ([2009-06-10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [HF_G_Jul] "C:\Program Files\AVG Secure Search\HF_G_Jul.exe" /DoAction File not found O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.) O4 - HKLM..\Run: [nmapp] C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Cisco Systems, Inc.) O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.) O4 - HKLM..\Run: [ROC_ROC_JULY_P1] "C:\Program Files\AVG Secure Search\ROC_ROC_JULY_P1.exe" / /PROMPT /CMPID=ROC_JULY_P1 File not found O4 - HKLM..\Run: [ROC_roc_ssl_v12] "C:\Program Files\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12 File not found O4 - HKU\S-1-5-21-4252676272-2371586129-3660312933-1000..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKU\S-1-5-21-4252676272-2371586129-3660312933-1000..\Run: [EADM] C:\Program Files\Origin\Origin.exe (Electronic Arts) O4 - HKU\S-1-5-21-4252676272-2371586129-3660312933-1000..\Run: [NokiaSuite.exe] C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe (Nokia) O4 - HKU\S-1-5-21-4252676272-2371586129-3660312933-1000..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKU\S-1-5-21-4252676272-2371586129-3660312933-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-4252676272-2371586129-3660312933-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2 O7 - HKU\S-1-5-21-4252676272-2371586129-3660312933-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1 O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O13 - gopher Prefix: missing O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} http://www.battlefieldheroes.com/static/updater/BFHUpdater_5.0.134.0.cab (Battlefield Heroes Updater) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.204.152.34 194.204.159.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3CC5168A-45B0-4962-9440-FA41690CA357}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7EE72E8F-C170-4AD2-8253-39F43A05D7BC}: DhcpNameServer = 194.204.152.34 194.204.159.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ADCF92E8-24E9-4F17-B2C9-8D3AA8B53B57}: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll File not found O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.) O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation) O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009-06-10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{1e47be23-7d09-11df-88c8-6cf0492e336c}\Shell - "" = AutoRun O33 - MountPoints2\{1e47be23-7d09-11df-88c8-6cf0492e336c}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a O33 - MountPoints2\{349f3cc0-1a90-11e2-bfc6-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{349f3cc0-1a90-11e2-bfc6-806e6f6e6963}\Shell\AutoRun\command - "" = F:\setup.exe O33 - MountPoints2\{e52a3c69-7d0f-11df-abb5-6cf0492e336c}\Shell - "" = AutoRun O33 - MountPoints2\{e52a3c69-7d0f-11df-abb5-6cf0492e336c}\Shell\AutoRun\command - "" = I:\Launch.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-12-01 19:20:01 | 000,000,000 | ---D | C] -- C:\_OTL [2012-11-30 17:42:23 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_43.dll [2012-11-30 17:42:23 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_7.dll [2012-11-30 17:42:23 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_43.dll [2012-11-30 17:42:23 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_43.dll [2012-11-30 17:42:23 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_7.dll [2012-11-30 17:42:23 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_5.dll [2012-11-30 17:42:22 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_43.dll [2012-11-30 16:20:38 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\userx\Desktop\OTL.exe [2012-11-28 21:41:30 | 000,047,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\WdfLdr.sys [2012-11-28 21:41:30 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Wdfres.dll [2012-11-28 21:40:47 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFx.dll [2012-11-28 21:40:47 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFPlatform.dll [2012-11-28 21:40:47 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFCoinstaller.dll [2012-11-28 21:39:05 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netcorehc.dll [2012-11-28 21:39:05 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncsi.dll [2012-11-28 21:39:04 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netevent.dll [2012-11-28 21:38:49 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dhcpcore6.dll [2012-11-28 16:03:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [2012-11-28 16:03:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype [2012-11-26 22:14:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autonomiczny składnik AVG LinkScanner [2012-11-26 22:08:31 | 000,000,000 | -H-D | C] -- C:\$AVG [2012-11-26 20:26:50 | 000,000,000 | ---D | C] -- C:\Users\userx\AppData\Local\Avg2013 [2012-11-23 15:15:51 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dhcpcsvc6.dll [2012-11-21 20:24:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi [2012-11-21 20:24:34 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn Hamachi [2012-11-18 21:45:43 | 000,000,000 | ---D | C] -- C:\Users\userx\AppData\Local\Diagnostics [2012-11-17 19:49:28 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2012-11-14 00:14:42 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2012-11-14 00:14:41 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2012-11-14 00:14:41 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll [2012-11-14 00:14:41 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2012-11-14 00:14:41 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2012-11-14 00:14:38 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll [2012-11-14 00:14:38 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll [2012-11-14 00:14:37 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl [2012-11-13 23:52:50 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\synceng.dll [2012-11-13 23:52:48 | 002,345,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2012-11-08 19:24:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG [2012-11-06 23:04:31 | 000,000,000 | ---D | C] -- C:\Users\userx\AppData\Roaming\AVG2013 [2012-11-06 22:56:46 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2013 [2012-11-06 22:44:09 | 000,000,000 | ---D | C] -- C:\Users\userx\AppData\Local\MFAData [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-12-01 21:03:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012-12-01 21:03:17 | 1609,424,896 | -HS- | M] () -- C:\hiberfil.sys [2012-12-01 21:02:46 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012-12-01 21:02:46 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012-12-01 20:19:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012-12-01 19:27:37 | 000,533,705 | ---- | M] () -- C:\Users\userx\Desktop\AdwCleaner.exe [2012-11-30 16:20:38 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\userx\Desktop\OTL.exe [2012-11-29 21:27:04 | 000,300,200 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2012-11-28 16:03:30 | 000,002,505 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk [2012-11-26 22:14:11 | 000,000,925 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2013.lnk [2012-11-23 14:52:45 | 000,747,698 | ---- | M] () -- C:\Windows\System32\perfh015.dat [2012-11-23 14:52:45 | 000,723,636 | ---- | M] () -- C:\Windows\System32\perfh019.dat [2012-11-23 14:52:45 | 000,661,064 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2012-11-23 14:52:45 | 000,160,290 | ---- | M] () -- C:\Windows\System32\perfc015.dat [2012-11-23 14:52:45 | 000,154,294 | ---- | M] () -- C:\Windows\System32\perfc019.dat [2012-11-23 14:52:45 | 000,125,254 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2012-11-21 20:24:37 | 000,000,856 | ---- | M] () -- C:\Users\Public\Desktop\LogMeIn Hamachi.lnk [2012-11-18 21:24:12 | 000,009,509 | ---- | M] () -- C:\Users\userx\Desktop\o co chodzi.png [2012-11-18 15:02:30 | 000,008,629 | ---- | M] () -- C:\Users\userx\Desktop\ADRES FIZYCZNY.odt [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-12-01 19:27:37 | 000,533,705 | ---- | C] () -- C:\Users\userx\Desktop\AdwCleaner.exe [2012-11-28 21:41:30 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf [2012-11-28 21:40:47 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf [2012-11-18 21:24:11 | 000,009,509 | ---- | C] () -- C:\Users\userx\Desktop\o co chodzi.png [2012-11-06 22:58:50 | 000,000,925 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2013.lnk [2012-08-01 12:07:56 | 000,000,640 | RHS- | C] () -- C:\Users\userx\ntuser.pol [2012-07-21 19:46:07 | 000,000,093 | ---- | C] () -- C:\Users\userx\AppData\Local\fusioncache.dat [2012-07-15 14:46:28 | 003,130,440 | ---- | C] () -- C:\Windows\System32\pbsvc_blr.exe [2012-06-09 09:53:15 | 002,580,552 | ---- | C] () -- C:\Windows\System32\pbsvc.exe [2012-05-26 16:37:28 | 000,336,704 | ---- | C] () -- C:\Windows\System32\perfi019.dat [2012-05-26 16:37:27 | 000,723,636 | ---- | C] () -- C:\Windows\System32\perfh019.dat [2012-05-26 16:37:27 | 000,154,294 | ---- | C] () -- C:\Windows\System32\perfc019.dat [2012-05-26 16:37:27 | 000,039,446 | ---- | C] () -- C:\Windows\System32\perfd019.dat [2012-03-15 21:00:23 | 000,001,512 | ---- | C] () -- C:\Users\userx\.recently-used.xbel [2011-09-28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat [2011-05-27 12:53:02 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat [2011-05-23 21:33:11 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe [2011-05-23 21:31:59 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe [2011-05-20 15:49:30 | 000,138,056 | ---- | C] () -- C:\Users\userx\AppData\Roaming\PnkBstrK.sys [2011-05-20 15:48:53 | 000,000,319 | ---- | C] () -- C:\Windows\game.ini [2011-01-09 10:47:02 | 000,000,000 | ---- | C] () -- C:\Windows\PowerReg.dat [2010-11-30 10:17:20 | 000,028,026 | ---- | C] () -- C:\Users\userx\AppData\Roaming\OFMissionEditorConfig.xml [2010-10-14 12:08:05 | 000,015,360 | ---- | C] () -- C:\Users\userx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [color=#E56717]========== ZeroAccess Check ==========[/color] [2009-07-14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012-06-09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2009-07-14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2012-11-08 19:24:28 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software [2012-11-08 19:24:28 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software [2012-08-14 16:23:35 | 000,000,000 | ---D | M] -- C:\Users\Gość\AppData\Roaming\Origin [2012-08-02 22:43:38 | 000,000,000 | ---D | M] -- C:\Users\Gość\AppData\Roaming\PC Suite [2011-06-03 14:33:27 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\.minecraft [2012-03-18 15:34:39 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\Audacity [2012-08-29 07:37:51 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\AVG [2012-11-26 20:23:16 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\AVG2013 [2012-07-12 14:14:25 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\BESTplayer [2012-07-12 14:16:31 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\Cool Record Edit Pro [2012-10-20 20:45:57 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\DAEMON Tools Lite [2012-01-25 23:55:50 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\FreeScreenToVideo [2010-12-12 15:48:09 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\Gadu-Gadu [2010-10-14 16:36:04 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\Gadu-Gadu 10 [2012-07-12 21:07:59 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\GameRanger [2012-03-18 17:09:58 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\Get from YouTube [2010-11-30 10:37:43 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\GHISLER [2011-06-22 12:10:58 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\go [2012-07-27 15:14:36 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\GoPlayer [2011-07-12 22:31:36 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\gtk-2.0 [2011-01-26 14:05:47 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\ipla [2010-09-04 13:07:32 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\Leadertech [2011-01-24 09:17:49 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\LolClient [2012-05-25 19:07:07 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\LolClient2 [2012-07-26 18:44:07 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\Moje pliki Bitwy o Śródziemie™ II [2012-07-26 18:36:22 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\Moje pliki gry Władca Pierścieni, Król Nazguli [2012-08-18 15:40:12 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\NapiProjekt [2012-01-16 23:11:52 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\Nokia [2011-05-15 13:00:49 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\Nokia Ovi Suite [2012-05-05 10:36:04 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\Nokia Suite [2010-12-12 13:05:15 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\Nowe Gadu-Gadu [2010-06-28 09:55:14 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\Off Road [2012-03-15 22:50:41 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\OnLive App [2010-06-21 09:31:51 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\OpenOffice.org [2012-01-17 14:42:25 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\Opera [2012-12-01 19:24:49 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\Origin [2012-09-12 18:48:58 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\PC Suite [2011-01-26 13:59:56 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\RDRM [2010-12-03 19:49:24 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\Soldat [2011-01-05 23:05:54 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\The Creative Assembly [2012-10-27 13:14:47 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\TS3Client [2012-01-21 19:47:35 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\TuneUp Software [2012-12-01 02:04:54 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\uTorrent [2010-12-05 10:33:36 | 000,000,000 | ---D | M] -- C:\Users\userx\AppData\Roaming\VitySoft [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:0B4227B4 < End of report >