OTL logfile created on: 2012-12-20 08:41:02 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = J:\Ukash 64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 8.0.7600.16385) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 4,00 Gb Total Physical Memory | 3,43 Gb Available Physical Memory | 85,69% Memory free 7,99 Gb Paging File | 7,46 Gb Available in Paging File | 93,27% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 244,14 Gb Total Space | 111,81 Gb Free Space | 45,79% Space Free | Partition Type: NTFS Drive D: | 221,62 Gb Total Space | 135,55 Gb Free Space | 61,16% Space Free | Partition Type: NTFS Drive J: | 7,24 Gb Total Space | 4,15 Gb Free Space | 57,34% Space Free | Partition Type: FAT32 Computer Name: PATRYK-PC | User Name: Patryk | Logged in as Administrator. Boot Mode: SafeMode | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-10-29 08:17:40 | 000,602,112 | ---- | M] (OldTimer Tools) -- J:\Ukash\OTL_vin7.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2011-01-12 15:44:02 | 000,042,360 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv) SRV:[b]64bit:[/b] - [2011-01-12 15:41:42 | 000,810,144 | ---- | M] (ESET) [Auto | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -- (ekrn) SRV:[b]64bit:[/b] - [2009-07-14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:[b]64bit:[/b] - [2009-07-14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV - [2012-12-13 18:32:21 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012-10-02 23:21:00 | 001,258,856 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService) SRV - [2012-10-02 12:15:38 | 000,382,824 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2012-07-02 16:25:14 | 002,232,504 | ---- | M] (Giraffic) [Auto | Stopped] -- C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe -- (Giraffic) SRV - [2012-06-11 10:33:26 | 000,724,376 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) SRV - [2012-01-01 18:32:58 | 000,054,784 | ---- | M] (Macrovision) [Auto | Stopped] -- C:\Windows\SysWOW64\drivers\CDAC11BA.EXE -- (C-DillaCdaC11BA) SRV - [2010-03-18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009-06-10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2012-07-03 16:25:16 | 000,189,288 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA) DRV:[b]64bit:[/b] - [2012-06-11 10:33:46 | 000,026,112 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd) DRV:[b]64bit:[/b] - [2012-01-09 16:28:20 | 000,019,968 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbx64.sys -- (nmwcd) DRV:[b]64bit:[/b] - [2012-01-09 16:28:20 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys -- (UsbserFilt) DRV:[b]64bit:[/b] - [2012-01-09 16:28:20 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys -- (upperdev) DRV:[b]64bit:[/b] - [2012-01-09 16:28:18 | 000,027,136 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbox64.sys -- (nmwcdc) DRV:[b]64bit:[/b] - [2011-01-26 11:10:26 | 000,254,528 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:[b]64bit:[/b] - [2010-12-21 14:04:06 | 000,170,640 | ---- | M] (ESET) [File_System | Auto | Stopped] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm) DRV:[b]64bit:[/b] - [2010-12-21 14:04:06 | 000,141,264 | ---- | M] (ESET) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv) DRV:[b]64bit:[/b] - [2010-12-21 12:47:38 | 000,125,296 | ---- | M] (ESET) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr) DRV:[b]64bit:[/b] - [2010-12-21 06:55:02 | 000,161,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bmdm.sys -- (ss_bmdm) DRV:[b]64bit:[/b] - [2010-12-21 06:55:02 | 000,128,000 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bserd.sys -- (ss_bserd) DRV:[b]64bit:[/b] - [2010-12-21 06:55:02 | 000,127,488 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bbus.sys -- (ss_bbus) DRV:[b]64bit:[/b] - [2010-12-21 06:55:02 | 000,018,944 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ss_bmdfl.sys -- (ss_bmdfl) DRV:[b]64bit:[/b] - [2010-11-10 02:45:54 | 004,162,784 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64) DRV:[b]64bit:[/b] - [2010-01-11 11:05:20 | 001,290,752 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService) DRV:[b]64bit:[/b] - [2009-07-17 04:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor) DRV:[b]64bit:[/b] - [2009-07-14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2009-07-14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2009-07-14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009-07-14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009-07-14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2009-07-14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2009-07-14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009-07-14 01:06:32 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser) DRV:[b]64bit:[/b] - [2009-06-10 21:35:53 | 000,051,712 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rtnic64.sys -- (RTL8023x64) DRV:[b]64bit:[/b] - [2009-06-10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009-06-10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009-06-10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009-06-10 21:34:18 | 000,057,344 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C) DRV:[b]64bit:[/b] - [2009-06-10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:[b]64bit:[/b] - [2009-05-07 21:30:28 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie) DRV:[b]64bit:[/b] - [2008-02-15 16:20:02 | 000,442,912 | ---- | M] (Realtek) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL85n64.sys -- (RTL85n64) DRV:[b]64bit:[/b] - [2007-04-03 13:57:40 | 000,130,824 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s116unic.sys -- (s116unic) DRV:[b]64bit:[/b] - [2007-04-03 13:57:38 | 000,031,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s116nd5.sys -- (s116nd5) DRV:[b]64bit:[/b] - [2007-04-03 13:57:36 | 000,144,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s116mdm.sys -- (s116mdm) DRV:[b]64bit:[/b] - [2007-04-03 13:57:36 | 000,019,720 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s116mdfl.sys -- (s116mdfl) DRV:[b]64bit:[/b] - [2007-04-03 13:57:34 | 000,108,296 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s116bus.sys -- (s116bus) DRV - [2012-01-01 18:32:59 | 000,012,464 | ---- | M] (Macrovision Europe Ltd) [Kernel | Auto | Stopped] -- C:\Windows\SysWOW64\drivers\CDAC15BA.SYS -- (CdaC15BA) DRV - [2009-07-14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://searchfunmoods.com/?f=1&a=iron2&ir=iron2&cd=2XzuyEtN2Y1L1QzutDtD0EtDyDtB0ByCzz0A0B0D0FzyzytBtN0D0Tzu0CtAyEzztN1L2XzutBtFtBtFtCtFyEtDyB&cr=1618201955 IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=iron2&ir=iron2&cd=2XzuyEtN2Y1L1QzutDtD0EtDyDtB0ByCzz0A0B0D0FzyzytBtN0D0Tzu0CtAyEzztN1L2XzutBtFtBtFtCtFyEtDyB&cr=1618201955 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&home=true&tid=2937 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.certified-toolbar.com?si=41460&home=true&tid=2937 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&home=true&tid=2937 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?si=41460&home=true&tid=2937 IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - SOFTWARE\Classes\CLSID\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\InprocServer32 File not found IE - HKLM\..\URLSearchHook: {fcbf663e-8530-46f8-a880-ac5abe9d2b23} - C:\Program Files (x86)\MobileScoop\prxtbMob0.dll (Conduit Ltd.) IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{34A7A37F-1F1F-E278-B667-768B6E94ACD3}: "URL" = http://search.certified-toolbar.com?si=41460&bs=true&tid=2937&q={searchTerms} IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.certified-toolbar.com?si=41460&bs=true&tid=2937&q={searchTerms} IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&crg=3.1010000&st=10&q={searchTerms} IE - HKLM\..\SearchScopes\{F63C586C-20D0-4036-A027-A806707B3CC8}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=7f84d67d-2374-11e1-8ab4-faf99a404a8f&q={searchTerms} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&home=true&tid=2937 IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.certified-toolbar.com?si=41460&home=true&tid=2937 IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q= IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&home=true&tid=2937 IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?si=41460&home=true&tid=2937 IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - SOFTWARE\Classes\CLSID\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\InprocServer32 File not found IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files (x86)\CheatEngine DB Toolbar Toolbar\tbhelper.dll () IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\URLSearchHook: {fcbf663e-8530-46f8-a880-ac5abe9d2b23} - C:\Program Files (x86)\MobileScoop\prxtbMob0.dll (Conduit Ltd.) IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.certified-toolbar.com?si=41460&bs=true&tid=2937&q={searchTerms} IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=STT&o=102866&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=5N&apn_dtid=YYYYYYYYPL&apn_uid=64D4D34F-61C4-4282-8617-6FBA58E04954&apn_sauid=FCED4A36-8145-4F5B-9DEB-00D591AB32B5 IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\SearchScopes\{34A7A37F-1F1F-E278-B667-768B6E94ACD3}: "URL" = http://search.certified-toolbar.com?si=41460&bs=true&tid=2937&q={searchTerms} IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpro.com/search/browser/cheatengine/{7E7D0F2C-F8EB-4388-90C1-E3185F2EE947}?q={searchTerms} IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\SearchScopes\{A245A75F-1FA0-4AAB-99EA-AC25908E1044}: "URL" = http://search.babylon.com/?q={searchTerms}&AF=100888&babsrc=SP_ss&mntrId=f6daf99200000000000000e052b68abd IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms} IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://startsear.ch/?aff=2&src=sp&cf=7f84d67d-2374-11e1-8ab4-faf99a404a8f&q={searchTerms} IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&crg=3.1010000&st=10&q={searchTerms} IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\SearchScopes\{F63C586C-20D0-4036-A027-A806707B3CC8}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=112061&tt=2912_6&babsrc=SP_ss&mntrId=f6daf99200000000000000e052b68abd IE - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..CT1605787.browser.search.defaultthis.engineName: true FF - prefs.js..browser.search.defaultengine: "Web Search" FF - prefs.js..browser.search.defaultenginename: "Web Search" FF - prefs.js..browser.search.defaultthis.engineName: "Veoh Web Player Customized Web Search" FF - prefs.js..browser.search.defaulturl: "" FF - prefs.js..browser.search.order.1: "Web Search" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: false FF - prefs.js..browser.startup.homepage: "http://www.onet.pl/" FF - prefs.js..extensions.enabledAddons: player%40vividas.com:4.1.3 FF - prefs.js..extensions.enabledAddons: secureLogin%40blueimp.net:0.9.9 FF - prefs.js..extensions.enabledAddons: zacz3k%40gmail.com:1.5 FF - prefs.js..extensions.enabledAddons: %7Bdd05fd3d-18df-4ce4-ae53-e795339c5f01%7D:1.21 FF - prefs.js..extensions.enabledAddons: ffxtlbr%40funmoods.com:1.5.1 FF - prefs.js..extensions.enabledAddons: bbrs_002%40blabbers.com:1.0.5 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1 FF - prefs.js..keyword.URL: "http://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=" FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=3&q={searchTerms}" FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Patryk\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Patryk\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ShopperReports@ShopperReports.com: C:\Program Files (x86)\ShopperReports3\bin\3.2.7.0\firefox\firefoxtoolbar\extensions [2011-09-30 17:52:22 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012-12-13 18:32:21 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012-12-13 18:32:18 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011-04-13 19:17:07 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012-12-13 18:32:21 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012-12-13 18:32:18 | 000,000,000 | ---D | M] [2011-04-10 19:37:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\Extensions [2012-12-13 20:55:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\Firefox\Profiles\3dr5j90j.default\extensions [2012-12-02 09:42:08 | 000,000,000 | ---D | M] (DownTango Launcher) -- C:\Users\Patryk\AppData\Roaming\mozilla\Firefox\Profiles\3dr5j90j.default\extensions\{411beae9-8c58-477c-8903-201536f61512} [2012-07-17 08:38:37 | 000,000,000 | ---D | M] (CheatEngine DB Toolbar Toolbar) -- C:\Users\Patryk\AppData\Roaming\mozilla\Firefox\Profiles\3dr5j90j.default\extensions\{75656794-AB59-4712-BFBC-5D816D56F3BC} [2012-01-06 18:31:37 | 000,000,000 | ---D | M] (Veoh Web Player Community Toolbar) -- C:\Users\Patryk\AppData\Roaming\mozilla\Firefox\Profiles\3dr5j90j.default\extensions\{cd90bf73-20f6-44ef-993d-bb920303bd2e} [2011-11-19 18:51:51 | 000,000,000 | ---D | M] (DealPly) -- C:\Users\Patryk\AppData\Roaming\mozilla\Firefox\Profiles\3dr5j90j.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} [2012-07-04 21:54:49 | 000,000,000 | ---D | M] (MobileScoop) -- C:\Users\Patryk\AppData\Roaming\mozilla\Firefox\Profiles\3dr5j90j.default\extensions\{fcbf663e-8530-46f8-a880-ac5abe9d2b23} [2012-07-17 08:38:11 | 000,000,000 | ---D | M] (Browser Companion Helper) -- C:\Users\Patryk\AppData\Roaming\mozilla\Firefox\Profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com [2012-12-13 20:55:08 | 000,000,000 | ---D | M] (Funmoods.com) -- C:\Users\Patryk\AppData\Roaming\mozilla\Firefox\Profiles\3dr5j90j.default\extensions\ffxtlbr@funmoods.com [2012-07-13 14:51:23 | 000,000,000 | ---D | M] (Iplex to ALLPlayer) -- C:\Users\Patryk\AppData\Roaming\mozilla\Firefox\Profiles\3dr5j90j.default\extensions\IplextoALL@ALLPlayer.org [2011-10-15 21:06:16 | 000,000,000 | ---D | M] (Vividas player plugin) -- C:\Users\Patryk\AppData\Roaming\mozilla\Firefox\Profiles\3dr5j90j.default\extensions\player@vividas.com [2012-03-01 18:47:36 | 000,083,513 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\secureLogin@blueimp.net.xpi [2011-11-17 15:47:52 | 000,013,509 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\zacz3k@gmail.com.xpi [2011-08-18 18:36:03 | 000,090,116 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\{dd05fd3d-18df-4ce4-ae53-e795339c5f01}.xpi [2012-12-16 21:24:14 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\02fe2325436851daade8c8e65d6cb964_expire [2012-12-16 20:21:46 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\0324adea3b6ec02af09ea4ae9424591b_expire [2012-12-17 16:32:35 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\1e83ed2cc66a4167bf6be40f3f550a41_expire [2012-10-31 12:45:41 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\26472ededcbbc56ca845ced16540454a_expire [2012-09-02 18:37:08 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\2881548a1fb3f73f1ae0cd6050b37dd3_expire [2012-12-16 21:24:14 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\292124057d00cb0fa73db6b90d079658_expire [2012-07-25 10:20:37 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\2de83530857cb3f3e3820351e2e71d9c_expire [2012-08-12 21:24:49 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\2e74403c227112bec523796d5a77d77e_expire [2012-08-28 19:21:16 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\4ad053d40dfa5cab7948e9251df6e3d9_expire [2012-12-15 21:15:47 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\4d3d10bd28ff623813254a49b26be41f_expire [2012-12-16 21:24:19 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\52681fd86c5d22affe5632454e6bfd94_expire [2012-09-04 14:13:43 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\61e2ae11ba3d1cbe8887ea80f192e299_expire [2012-12-16 21:24:17 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\6aaaeec79282f00863247307ab6ef7c0_expire [2012-08-12 21:46:52 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\6ae5302aef7c4978dd8de914f15298c3_expire [2012-08-19 15:48:01 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\6fd9df863946504e045c48b69bf47304_expire [2012-10-21 11:45:31 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\7a02c05c2e726d428ef32f1e1c7e8cea_expire [2012-07-25 10:20:37 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\7acafe2d3e4c14a116bde4e028813ba7_expire [2012-12-17 16:05:09 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\9f6015e7e7ab284b2d697b3713c2f02f_expire [2012-12-16 21:24:18 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\a0a560c746cc38a757b5705856e77144_expire [2012-09-04 14:13:43 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\b19c92781ed65a27c2fd1d7d061567dd_expire [2012-08-27 15:19:16 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\b5bc7084382de95cb69790e5d10db338_expire [2012-09-09 20:55:23 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\b7e28810c05e9164eefdd62ff9b944ad_expire [2012-08-13 13:01:42 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\bbec825517444bcb0fe2af4511be24e9_expire [2012-09-20 14:38:49 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\c9bdd22246d2567d7b7d2917712723e5_expire [2012-10-26 17:37:54 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\cbb647c72e5b13b52d1392c603dcfde6_expire [2012-08-19 15:48:01 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\cbb69a449d3e39b3a3781ffb1d7fa52b_expire [2012-10-26 17:37:54 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\cee249aeb0617d07fbb275931854d233_expire [2012-08-26 14:42:36 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\d83bb387de1d7c4401815e133de06c6b_expire [2012-12-16 21:24:19 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\d89bfd841403290d610bcf662008b443_expire [2012-08-15 22:08:10 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\dc6668d28979688b1e2066d1dcaef0f6_expire [2012-10-31 12:45:41 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\df4525cd4117d8ae1c7453b139759242_expire [2012-09-20 14:38:48 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\e02b35320e5111f1b626466c13c70a0a_expire [2012-08-26 11:52:05 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\e7215b147326809c45f6cf0952274624_expire [2012-11-17 22:49:14 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\e802b97776da1ba5efcdbff37a189915_expire [2012-12-16 21:24:17 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\e919434ec29526b28593c426e4264271_expire [2012-11-17 22:49:13 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\ece5f266221b5245c6e3d7e27ddee963_expire [2012-10-21 11:45:31 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\ece71b71690fad200cbed95871ef4bb2_expire [2012-12-16 21:24:18 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\f03527c67e08602d2e4c18ae7867300d_expire [2012-11-27 16:20:23 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\f33f7907cfe35040b9fdade918fdf0e5_expire [2012-12-17 16:05:09 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\f88997811d2da1fb251068ed3d7c6dde_expire [2012-12-15 21:15:47 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\fa74672918974682c82b8d91dfbe0d6b_expire [2012-12-15 21:15:47 | 000,000,013 | ---- | M] () (No name found) -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\extensions\bbrs_002@blabbers.com\chrome\content\cache\ff4d692d5e7cccbc4b3e9ef4062b1c6f_expire [2012-07-04 22:06:11 | 000,000,915 | ---- | M] () -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\searchplugins\conduit.xml [2012-12-13 20:55:10 | 000,002,337 | ---- | M] () -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\searchplugins\Funmoods.xml [2012-10-15 17:55:55 | 000,000,792 | ---- | M] () -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\searchplugins\startsear.xml [2012-05-16 20:27:57 | 000,003,948 | ---- | M] () -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\searchplugins\sweetim.xml [2012-12-02 09:42:03 | 000,003,269 | ---- | M] () -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\searchplugins\Web Search.xml [2011-08-10 20:40:52 | 000,001,565 | ---- | M] () -- C:\Users\Patryk\AppData\Roaming\mozilla\firefox\profiles\3dr5j90j.default\searchplugins\web-search.xml [2012-12-13 18:32:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2012-12-13 18:32:21 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2011-09-16 11:57:06 | 000,189,088 | ---- | M] ( ) -- C:\Program Files (x86)\mozilla firefox\plugins\npVividasPlayer.dll [2011-10-27 14:45:50 | 000,083,456 | ---- | M] (LiveVDO ) -- C:\Program Files (x86)\mozilla firefox\plugins\npvsharetvplg.dll [2012-06-24 12:40:11 | 000,002,767 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\allegro-pl.xml [2012-07-17 08:38:07 | 000,002,349 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml [2012-06-24 12:40:11 | 000,001,406 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fbc-pl.xml [2012-06-24 12:40:11 | 000,000,917 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\merlin-pl.xml [2012-06-24 12:40:11 | 000,000,858 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\pwn-pl.xml [2012-12-02 09:42:03 | 000,003,269 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\Web Search.xml [2012-06-24 12:40:11 | 000,001,183 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-pl.xml [2012-06-24 12:40:11 | 000,001,683 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wp-pl.xml [color=#E56717]========== Chrome ==========[/color] CHR - homepage: http://search.certified-toolbar.com?si=41460&home=true&tid=2937 CHR - homepage: http://search.certified-toolbar.com?si=41460&home=true&tid=2937 CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Users\Patryk\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Patryk\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Patryk\AppData\Local\Google\Chrome\Application\23.0.1271.97\gcswf32.dll CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll CHR - plugin: vShare.tv plug-in (Enabled) = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\chvsharetvplg.dll CHR - plugin: vShare.tv plug-in (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npvsharetvplg.dll CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll CHR - plugin: Vividas Player Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npVividasPlayer.dll CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files (x86)\Veetle\Player\npvlc.dll CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files (x86)\Veetle\plugins\npVeetle.dll CHR - plugin: Google Update (Enabled) = C:\Users\Patryk\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll CHR - Extension: YouTube = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\ CHR - Extension: Browser Companion Helper = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf\1.0.5_0\ CHR - Extension: Nowa karta = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\6.0_0\ CHR - Extension: Szukaj w Google = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\ CHR - Extension: Babylon Toolbar = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.7_0\ CHR - Extension: MobileScoop = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\fhlkamjopkamckcfiolblkngeeocmloo\2.3.18.20_0\ CHR - Extension: DealPly = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaiilaahiahdejapggenmdmafpmbipje\3.0.7.2_0\ CHR - Extension: DownTango Launcher = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\gladcbhcbkdeddbidiblppadjdjalidb\2.1_0\ CHR - Extension: Twojanuta.pl = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\golpmdddnmkckjiopggcbempclljlbjk\1.2_0\ CHR - Extension: Default = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkacjpbfdknhflllbcmjibkdeoafencn\1.1_0\ CHR - Extension: Kino5 - Bypass Megavideo Limit = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnkeikbmmeggmmbmilcfapmgckglglbj\2.2_0\ CHR - Extension: Live Score - Football = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\jelkadmmpmpageimebbniocpnldggllm\1.2.11_0\ CHR - Extension: vshare plugin = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\ CHR - Extension: Giant Savings = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndkhncnongaclekkbelchmeafffimifj\1.20.43_0\crossrider CHR - Extension: Giant Savings = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndkhncnongaclekkbelchmeafffimifj\1.20.43_0\ CHR - Extension: LiveVDO plugin = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbiamblgmkgbcgbcgejjgebalncpmhnp\1.3_0\ CHR - Extension: Gmail = C:\Users\Patryk\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\ O1 HOSTS File: ([2009-06-10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2 - BHO: (Browser Companion Helper) - {00cbb66b-1d3b-46d3-9577-323a336acb50} - C:\Program Files (x86)\BrowserCompanion\jsloader.dll ( ) O2 - BHO: (ShopperReports) - {100EB1FD-D03E-47fd-81F3-EE91287F9465} - C:\Program Files (x86)\ShopperReports3\bin\3.2.7.0\ShopperReports.dll (SmartShopper Inc.) O2 - BHO: (Giant Savings) - {11111111-1111-1111-1111-110011441179} - C:\Program Files (x86)\Giant Savings\Giant Savings.dll (215 Apps) O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (Babylon BHO) O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O2 - BHO: (Funmoods Helper Object) - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - C:\Program Files (x86)\Funmoods\1.5.23.22\bh\escort.dll (Funmoods BHO) O2 - BHO: (IE5BarLauncherBHO Class) - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll (StartSearch Inc.) O2 - BHO: (Browser Companion Helper Verifier) - {963B125B-8B21-49A2-A3A8-E37092276531} - C:\Program Files (x86)\BrowserCompanion\updatebhoWin32.dll ( ) O2 - BHO: (DealPly) - {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - C:\Program Files (x86)\DealPly\DealPlyIE.dll (DealPly Technologies Ltd) O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll File not found O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) O2 - BHO: (IplexToALLPlayer) - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - C:\PROGRA~2\ALLPLA~1\Iplex\IPLEXT~1.DLL (ALLCinema Ltd.) O2 - BHO: (DownTango Launcher) - {e327b07a-0e11-4fd4-bef2-b2c5605b59c6} - C:\Users\Patryk\AppData\Roaming\DownTangoFTToolbar\DownTangoFTToolbar.dll (Simplytech Ltd.) O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files (x86)\CheatEngine DB Toolbar Toolbar\tbcore3.dll () O2 - BHO: (MobileScoop Toolbar) - {fcbf663e-8530-46f8-a880-ac5abe9d2b23} - C:\Program Files (x86)\MobileScoop\prxtbMob0.dll (Conduit Ltd.) O3:[b]64bit:[/b] - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll () O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKLM\..\Toolbar: (CheatEngine DB Toolbar Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files (x86)\CheatEngine DB Toolbar Toolbar\tbcore3.dll () O3 - HKLM\..\Toolbar: (StartSearchToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll (StartSearch Inc.) O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (Babylon Ltd.) O3 - HKLM\..\Toolbar: (Funmoods Toolbar) - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - C:\Program Files (x86)\Funmoods\1.5.23.22\escorTlbr.dll (Funmoods) O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll File not found O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKLM\..\Toolbar: (DownTango Launcher) - {e327b07a-0e11-4fd4-bef2-b2c5605b59c6} - C:\Users\Patryk\AppData\Roaming\DownTangoFTToolbar\DownTangoFTToolbar.dll (Simplytech Ltd.) O3 - HKLM\..\Toolbar: (MobileScoop Toolbar) - {fcbf663e-8530-46f8-a880-ac5abe9d2b23} - C:\Program Files (x86)\MobileScoop\prxtbMob0.dll (Conduit Ltd.) O3:[b]64bit:[/b] - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll () O3 - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\Toolbar\WebBrowser: (CheatEngine DB Toolbar Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files (x86)\CheatEngine DB Toolbar Toolbar\tbcore3.dll () O3 - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\Toolbar\WebBrowser: (StartSearchToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\StartSearch plugin\ssBarLcher.dll (StartSearch Inc.) O3 - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000\..\Toolbar\WebBrowser: (MobileScoop Toolbar) - {FCBF663E-8530-46F8-A880-AC5ABE9D2B23} - C:\Program Files (x86)\MobileScoop\prxtbMob0.dll (Conduit Ltd.) O4:[b]64bit:[/b] - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET) O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA) O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.) O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe () O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000..\Run: [ALLUpdate] C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe () O4 - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000..\Run: [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe (Samsung) O4 - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe () O4 - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000..\Run: [TBPanel] C:\Program Files (x86)\Vtune\TBPanel.exe () O4 - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000..\Run: [VeohPlugin] C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-21-1817071798-2848442691-1526699400-1000..\RunOnce: [F6E2F948F010F9920000F6E2026CFFA4] C:\ProgramData\F6E2F948F010F9920000F6E2026CFFA4\F6E2F948F010F9920000F6E2026CFFA4.exe () O4 - Startup: C:\Users\Patryk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tcbhn.lnk = C:\Users\Patryk\AppData\Roaming\BrowserCompanion\tcbhn.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8:[b]64bit:[/b] - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files (x86)\ShopperReports3\bin\3.2.7.0\ShopperReports.dll (SmartShopper Inc.) O9 - Extra Button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files (x86)\ShopperReports3\bin\3.2.7.0\ShopperReports.dll (SmartShopper Inc.) O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{482701BB-6AA8-4899-82B6-370983768D73}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8843F084-AAA2-475E-BF7A-66FC86FB9D59}: NameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BB3C9E87-208A-4DB8-AEED-B61DFFA21DB9}: DhcpNameServer = 192.168.1.1 192.168.2.1 O18:[b]64bit:[/b] - Protocol\Handler\base64 - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\chrome - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\prox - No CLSID value found O18 - Protocol\Handler\base64 {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd) O18 - Protocol\Handler\chrome {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd) O18 - Protocol\Handler\prox {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{2aa26b85-2923-11e0-b257-bcaec515cd8c}\Shell - "" = AutoRun O33 - MountPoints2\{2aa26b85-2923-11e0-b257-bcaec515cd8c}\Shell\AutoRun\command - "" = F:\autorun.exe O33 - MountPoints2\{9a4b97e4-43df-11e0-a48f-f464ae6d4d80}\Shell - "" = AutoRun O33 - MountPoints2\{9a4b97e4-43df-11e0-a48f-f464ae6d4d80}\Shell\AutoRun\command - "" = G:\autorun.exe O33 - MountPoints2\{9a4b97f1-43df-11e0-a48f-f464ae6d4d80}\Shell - "" = AutoRun O33 - MountPoints2\{9a4b97f1-43df-11e0-a48f-f464ae6d4d80}\Shell\AutoRun\command - "" = H:\setup.exe O33 - MountPoints2\{b5393d2f-1d3a-11e2-af9e-e43488461f8e}\Shell - "" = AutoRun O33 - MountPoints2\{b5393d2f-1d3a-11e2-af9e-e43488461f8e}\Shell\AutoRun\command - "" = I:\SJ2_setup.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-12-17 19:43:37 | 000,000,000 | ---D | C] -- C:\Users\Patryk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Progressive Protection [2012-12-17 19:40:46 | 000,000,000 | ---D | C] -- C:\ProgramData\F6E2F948F010F9920000F6E2026CFFA4 [2012-12-13 20:37:23 | 000,000,000 | ---D | C] -- C:\Users\Patryk\AppData\Roaming\PDFReaderPackages [2012-12-13 20:37:22 | 000,000,000 | ---D | C] -- C:\Users\Patryk\AppData\Roaming\Funmoods [2012-12-13 20:36:47 | 000,000,000 | ---D | C] -- C:\Users\Patryk\AppData\Roaming\SumatraPDF [2012-12-13 20:35:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Funmoods [2012-12-13 18:32:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2012-12-11 21:20:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IQ Publishing [2012-12-11 15:40:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Codemasters [2012-12-11 15:40:43 | 000,000,000 | ---D | C] -- C:\Users\Patryk\Documents\My Games [2012-12-11 15:19:24 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft [2012-12-10 23:14:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Ripple Sound [2012-12-10 23:14:15 | 003,485,696 | ---- | C] (Intel Corporation) -- C:\Windows\SysWow64\mkl_p4.dll [2012-12-10 23:14:15 | 002,793,472 | ---- | C] (Intel Corporation) -- C:\Windows\SysWow64\mkl_p3.dll [2012-12-10 23:14:15 | 002,441,216 | ---- | C] (Intel Corporation) -- C:\Windows\SysWow64\mkl_def.dll [2012-12-10 23:14:15 | 002,174,976 | ---- | C] (Intel Corporation) -- C:\Windows\SysWow64\mkl_lapack32.dll [2012-12-10 23:14:15 | 002,125,824 | ---- | C] (Intel Corporation) -- C:\Windows\SysWow64\mkl_lapack64.dll [2012-12-10 23:14:15 | 000,872,448 | ---- | C] (Blue Ripple Sound Limited) -- C:\Windows\SysWow64\rapture3d_oal.dll [2012-12-10 23:14:15 | 000,839,680 | ---- | C] (Intel Corporation) -- C:\Windows\SysWow64\mkl_vml_p4.dll [2012-12-10 23:14:15 | 000,532,480 | ---- | C] (Intel Corporation) -- C:\Windows\SysWow64\mkl_vml_p3.dll [2012-12-10 23:14:15 | 000,512,000 | ---- | C] (Intel Corporation) -- C:\Windows\SysWow64\mkl_vml_def.dll [2012-12-10 23:14:15 | 000,184,320 | ---- | C] (Intel Corporation) -- C:\Windows\SysWow64\libguide40.dll [2012-12-10 23:14:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BRS [2012-12-10 23:14:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows - LIVE [2012-12-10 23:13:43 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\xlive [2012-12-10 23:13:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Games for Windows - LIVE [2012-12-10 23:02:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Codemasters [2012-12-09 15:47:18 | 000,000,000 | ---D | C] -- C:\Users\Patryk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SopCast [2012-12-09 15:47:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SopCast [2012-12-09 15:47:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SopCast [2012-12-02 11:00:23 | 000,000,000 | ---D | C] -- C:\Users\Patryk\AppData\Roaming\NVIDIA [2012-12-02 10:58:02 | 000,466,520 | ---- | C] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll [2012-12-02 10:58:02 | 000,445,016 | ---- | C] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll [2012-12-02 10:58:02 | 000,122,968 | ---- | C] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysNative\OpenAL32.dll [2012-12-02 10:58:02 | 000,109,144 | ---- | C] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysWow64\OpenAL32.dll [2012-12-02 10:58:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenAL [2012-12-02 10:57:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Symulator Jazdy 2 [2012-12-02 09:43:01 | 000,000,000 | ---D | C] -- C:\Users\Patryk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DownTango [2012-12-02 09:42:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Protected Search [2012-12-02 09:42:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Protected Search [2012-12-02 09:42:06 | 000,000,000 | ---D | C] -- C:\Users\Patryk\AppData\Roaming\DownTangoFTToolbar [2012-12-02 09:42:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DownTangoFTToolbar [2012-12-02 09:41:31 | 000,000,000 | ---D | C] -- C:\Users\Patryk\AppData\Local\DownTango [2012-12-02 09:41:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Red Sky [4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-12-20 08:37:03 | 001,578,586 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2012-12-20 08:37:03 | 000,707,268 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat [2012-12-20 08:37:03 | 000,632,708 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2012-12-20 08:37:03 | 000,140,282 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat [2012-12-20 08:37:03 | 000,110,342 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2012-12-20 08:32:53 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012-12-20 08:32:45 | 3219,787,776 | -HS- | M] () -- C:\hiberfil.sys [2012-12-20 08:22:00 | 000,001,062 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1817071798-2848442691-1526699400-1000UA.job [2012-12-17 19:43:37 | 000,002,064 | ---- | M] () -- C:\Users\Patryk\Desktop\System Progressive Protection.lnk [2012-12-17 16:21:00 | 000,001,010 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1817071798-2848442691-1526699400-1000Core.job [2012-12-13 20:35:42 | 000,368,102 | ---- | M] () -- C:\Users\Patryk\AppData\Local\funmoods-speeddial_sf.crx [2012-12-13 20:35:42 | 000,031,465 | ---- | M] () -- C:\Users\Patryk\AppData\Local\funmoods.crx [2012-12-13 19:56:08 | 000,255,386 | ---- | M] () -- C:\Users\Patryk\Desktop\TM IV-5.pdf [2012-12-13 16:25:33 | 000,008,044 | ---- | M] () -- C:\Users\Patryk\Desktop\Dudek.pdf [2012-12-11 21:20:15 | 000,000,941 | ---- | M] () -- C:\Users\Public\Desktop\International Volleyball 2010.lnk [2012-12-11 21:19:36 | 000,018,416 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012-12-11 21:19:36 | 000,018,416 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012-12-11 15:34:01 | 000,466,520 | ---- | M] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll [2012-12-11 15:34:01 | 000,445,016 | ---- | M] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll [2012-12-11 15:34:01 | 000,122,968 | ---- | M] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysNative\OpenAL32.dll [2012-12-11 15:34:01 | 000,109,144 | ---- | M] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysWow64\OpenAL32.dll [2012-12-09 15:47:18 | 000,000,995 | ---- | M] () -- C:\Users\Patryk\Desktop\SopCast.lnk [2012-12-02 10:57:36 | 000,000,935 | ---- | M] () -- C:\Users\Patryk\Desktop\Symulator Jazdy 2.lnk [2012-12-02 09:43:01 | 000,001,147 | ---- | M] () -- C:\Users\Patryk\Desktop\DownTango.lnk [2012-12-02 09:41:27 | 000,000,014 | ---- | M] () -- C:\end [2012-12-02 09:36:10 | 004,841,336 | ---- | M] () -- C:\Users\Patryk\Desktop\Symulator_Jazdy_2_PL_downloader.exe [4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-12-17 19:43:37 | 000,002,064 | ---- | C] () -- C:\Users\Patryk\Desktop\System Progressive Protection.lnk [2012-12-13 20:36:55 | 000,368,102 | ---- | C] () -- C:\Users\Patryk\AppData\Local\funmoods-speeddial_sf.crx [2012-12-13 20:36:28 | 000,031,465 | ---- | C] () -- C:\Users\Patryk\AppData\Local\funmoods.crx [2012-12-13 19:56:08 | 000,255,386 | ---- | C] () -- C:\Users\Patryk\Desktop\TM IV-5.pdf [2012-12-13 16:25:31 | 000,008,044 | ---- | C] () -- C:\Users\Patryk\Desktop\Dudek.pdf [2012-12-11 21:20:15 | 000,000,941 | ---- | C] () -- C:\Users\Public\Desktop\International Volleyball 2010.lnk [2012-12-09 15:47:18 | 000,000,995 | ---- | C] () -- C:\Users\Patryk\Desktop\SopCast.lnk [2012-12-02 10:57:36 | 000,000,935 | ---- | C] () -- C:\Users\Patryk\Desktop\Symulator Jazdy 2.lnk [2012-12-02 09:43:01 | 000,001,147 | ---- | C] () -- C:\Users\Patryk\Desktop\DownTango.lnk [2012-12-02 09:42:06 | 000,015,432 | ---- | C] () -- C:\Windows\Launcher.exe [2012-12-02 09:41:26 | 000,000,014 | ---- | C] () -- C:\end [2012-12-02 09:35:18 | 004,841,336 | ---- | C] () -- C:\Users\Patryk\Desktop\Symulator_Jazdy_2_PL_downloader.exe [2012-10-03 14:36:40 | 003,780,472 | ---- | C] () -- C:\Users\Patryk\slon mikser - szczerze feat. dj show.mp3 [2012-07-13 14:51:26 | 000,644,608 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll [2012-07-13 14:51:26 | 000,258,048 | ---- | C] () -- C:\Windows\SysWow64\libFLAC.dll [2012-03-28 21:11:08 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe [2012-03-28 21:11:06 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll [2012-03-28 21:11:06 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll [2012-03-28 21:11:06 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll [2012-03-28 21:11:06 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll [2011-12-09 14:09:45 | 000,000,167 | ---- | C] () -- C:\Windows\usdthank.ini [2011-12-09 14:09:45 | 000,000,031 | ---- | C] () -- C:\Windows\idc.ini [2011-11-30 19:12:19 | 000,021,840 | ---- | C] () -- C:\Windows\SysWow64\SIntfNT.dll [2011-11-30 19:12:19 | 000,017,212 | ---- | C] () -- C:\Windows\SysWow64\SIntf32.dll [2011-11-30 19:12:19 | 000,012,067 | ---- | C] () -- C:\Windows\SysWow64\SIntf16.dll [2011-07-25 19:04:12 | 001,610,156 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2011-01-26 17:18:05 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\pxhpinst.exe [2011-01-25 21:44:01 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini [2011-01-25 21:43:58 | 000,028,463 | ---- | C] () -- C:\Windows\Ascd_tmp.ini [color=#E56717]========== ZeroAccess Check ==========[/color] [2009-07-14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2010-07-27 15:59:11 | 014,162,944 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2010-07-27 15:03:24 | 012,867,584 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009-07-14 02:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== LOP Check ==========[/color] [2011-12-16 15:52:52 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Autodesk [2011-11-19 18:51:28 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Babylon [2012-07-04 21:16:47 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\BabylonToolbar [2012-12-20 08:31:23 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\BrowserCompanion [2011-01-26 11:13:31 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\DAEMON Tools Lite [2012-12-02 09:42:06 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\DownTangoFTToolbar [2012-12-13 20:37:22 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Funmoods [2011-05-31 21:20:52 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Gadu-Gadu 10 [2011-05-06 19:23:41 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\GameRanger [2011-01-26 10:42:33 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Leadertech [2012-10-31 15:24:33 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\LolClient [2012-07-13 14:43:15 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\NapiProjekt [2012-09-29 10:03:43 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Nokia [2011-12-10 22:42:36 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\OpenCandy [2012-09-29 10:03:41 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\PC Suite [2012-12-13 20:37:23 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\PDFReaderPackages [2011-07-18 10:15:51 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\PhotoScape [2012-05-08 19:50:25 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Samsung [2011-09-30 17:52:20 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\ShopperReports3 [2011-03-01 12:19:38 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Sports Interactive [2012-12-13 20:37:01 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\SumatraPDF [2011-02-05 12:07:33 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\TeamViewer [2012-05-08 20:47:22 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\Temp [2012-12-11 21:49:08 | 000,000,000 | ---D | M] -- C:\Users\Patryk\AppData\Roaming\uTorrent [color=#E56717]========== Purity Check ==========[/color] < End of report >