OTL logfile created on: 2013-02-08 22:09:24 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Krzysiekk\Moje dokumenty\Downloads Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,50 Gb Total Physical Memory | 3,08 Gb Available Physical Memory | 87,87% Memory free 5,34 Gb Paging File | 5,15 Gb Available in Paging File | 96,39% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 117,19 Gb Total Space | 91,99 Gb Free Space | 78,49% Space Free | Partition Type: NTFS Drive D: | 117,19 Gb Total Space | 80,38 Gb Free Space | 68,59% Space Free | Partition Type: NTFS Drive E: | 117,19 Gb Total Space | 18,00 Gb Free Space | 15,36% Space Free | Partition Type: NTFS Drive F: | 114,19 Gb Total Space | 29,74 Gb Free Space | 26,04% Space Free | Partition Type: NTFS Computer Name: STACHYRA-BE1A9E | User Name: Krzysiekk | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2013-02-08 21:28:13 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Krzysiekk\Moje dokumenty\Downloads\OTL.exe PRC - [2008-10-31 07:24:28 | 000,095,528 | ---- | M] (Sunbelt Software, Inc.) -- C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe PRC - [2008-04-15 13:00:00 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012-01-08 14:41:12 | 000,093,696 | ---- | M] () -- C:\Program Files\FileZilla FTP Client\fzshellext.dll MOD - [2008-12-03 08:39:45 | 000,466,944 | ---- | M] () -- C:\WINDOWS\system32\nvshell.dll MOD - [2007-01-31 09:56:56 | 000,032,768 | ---- | M] () -- C:\Program Files\EXPERTool\TBPanelExt.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ) SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt) SRV - [2012-11-09 11:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012-10-02 12:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Disabled | Stopped] -- C:\Documents and Settings\All Users\Dane aplikacji\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service) SRV - [2012-09-30 12:41:37 | 000,161,768 | ---- | M] (Oracle Corporation) [Disabled | Stopped] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService) SRV - [2012-07-02 20:09:07 | 000,224,416 | ---- | M] (Beijing ELEX Technology Co., Ltd.) [Disabled | Stopped] -- C:\Program Files\Software Plate\svcgdp.exe -- (svcgdp) SRV - [2010-06-25 18:07:20 | 000,117,264 | ---- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) SRV - [2008-10-31 07:24:28 | 001,365,288 | ---- | M] (Sunbelt Software, Inc.) [Auto | Stopped] -- C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe -- (SPF4) SRV - [2008-10-31 07:24:28 | 000,095,528 | ---- | M] (Sunbelt Software, Inc.) [Auto | Running] -- C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe -- (SbPF.Launcher) SRV - [2007-03-06 09:35:02 | 000,198,168 | ---- | M] (InterVideo Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe -- (Capture Device Service) SRV - [2007-03-03 12:48:28 | 000,067,056 | ---- | M] (Ulead Systems, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\KRZYSI~1\USTAWI~1\Temp\kwndrpob.sys -- (kwndrpob) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Documents and Settings\Krzysiek\Pulpit\Intelligent Aimbot Gold Edition\Intelligent Aimbot Gold Edition Cracked\glynnharr.sys -- (glynnxxGE) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\EagleXNt.sys -- (EagleXNt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\KRZYSI~1\USTAWI~1\Temp\catchme.sys -- (catchme) DRV - [2012-09-18 14:41:10 | 006,191,760 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) DRV - [2012-07-29 11:35:44 | 000,015,600 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\gdrv.sys -- (gdrv) DRV - [2010-06-25 18:07:14 | 000,035,088 | ---- | M] (CACE Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF) DRV - [2009-11-18 04:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt) DRV - [2009-11-18 04:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt) DRV - [2008-12-26 11:56:04 | 000,017,792 | ---- | M] (Avnex) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vcsvad.sys -- (VCSVADHWSer) DRV - [2008-10-31 07:09:06 | 000,270,888 | R--- | M] (Sunbelt Software, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\SbFw.sys -- (SbFw) DRV - [2008-06-21 04:54:54 | 000,066,600 | R--- | M] (Sunbelt Software, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\sbhips.sys -- (sbhips) DRV - [2008-06-21 04:54:54 | 000,065,576 | ---- | M] (Sunbelt Software, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SbFwIm.sys -- (SBFWIMCL) DRV - [2007-03-16 09:11:38 | 000,012,256 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\TBPanel.sys -- (TBPanel) DRV - [2007-03-16 09:11:38 | 000,012,256 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\TBPanel.sys -- (Cardex) DRV - [2006-11-27 15:33:54 | 000,019,968 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus) DRV - [2006-11-27 15:33:50 | 000,058,368 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD) DRV - [2006-10-18 15:31:38 | 000,105,472 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvata.sys -- (nvata) DRV - [2006-06-18 22:51:32 | 000,043,520 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-854245398-1682526488-682003330-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://isearch.avg.com/?cid={C89521A8-9469-4182-92C9-E79170EDFCF7}&mid=da4c270aae444fc3999f78156b592a05-88faf2631067f094c9ab41ae3212ad0a4a83c3d0&lang=pl&ds=ik011&pr=&d=2012-09-05 13:49:52&v=12.2.0.5&sap=hp IE - HKU\S-1-5-21-854245398-1682526488-682003330-1004\..\URLSearchHook: {687578b9-7132-4a7a-80e4-30ee31099e03} - No CLSID value found IE - HKU\S-1-5-21-854245398-1682526488-682003330-1004\..\SearchScopes,DefaultScope = {DEC5EEC5-6F7C-4D3A-99B2-C600E0373F27} IE - HKU\S-1-5-21-854245398-1682526488-682003330-1004\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=113480&tt=010812_rbt_3112_4&babsrc=SP_ss&mntrId=b86c1331000000000000001fd0b3cc68 IE - HKU\S-1-5-21-854245398-1682526488-682003330-1004\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = https://isearch.avg.com/search?cid={C89521A8-9469-4182-92C9-E79170EDFCF7}&mid=da4c270aae444fc3999f78156b592a05-88faf2631067f094c9ab41ae3212ad0a4a83c3d0&lang=pl&ds=AVG&pr=pr&d=2012-09-21 15:37:29&v=12.2.5.34&sap=dsp&q={searchTerms} IE - HKU\S-1-5-21-854245398-1682526488-682003330-1004\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3072253 IE - HKU\S-1-5-21-854245398-1682526488-682003330-1004\..\SearchScopes\{DEC5EEC5-6F7C-4D3A-99B2-C600E0373F27}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 IE - HKU\S-1-5-21-854245398-1682526488-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-854245398-1682526488-682003330-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://isearch.avg.com/?cid={C89521A8-9469-4182-92C9-E79170EDFCF7}&mid=da4c270aae444fc3999f78156b592a05-88faf2631067f094c9ab41ae3212ad0a4a83c3d0&lang=pl&ds=AVG&pr=pr&d=2012-09-21 15:37:29&v=12.2.5.34&sap=hp IE - HKU\S-1-5-21-854245398-1682526488-682003330-1008\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233} IE - HKU\S-1-5-21-854245398-1682526488-682003330-1008\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC IE - HKU\S-1-5-21-854245398-1682526488-682003330-1008\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = https://isearch.avg.com/search?cid={C89521A8-9469-4182-92C9-E79170EDFCF7}&mid=da4c270aae444fc3999f78156b592a05-88faf2631067f094c9ab41ae3212ad0a4a83c3d0&lang=pl&ds=AVG&pr=pr&d=2012-09-21 15:37:29&v=12.2.5.34&sap=dsp&q={searchTerms} IE - HKU\S-1-5-21-854245398-1682526488-682003330-1008\..\SearchScopes\{AEE28A2D-A1A1-4FD3-8927-56443B2721F6}: "URL" = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 IE - HKU\S-1-5-21-854245398-1682526488-682003330-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\Documents and Settings\All Users\Dane aplikacji\NexonEU\NGM\npNxGameeu.dll (Nexon) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Krzysiekk\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Krzysiekk\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll File not found [2012-10-18 21:18:11 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\Mozilla\Extensions [2012-07-29 11:31:53 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [color=#E56717]========== Chrome ==========[/color] CHR - homepage: http://www.google.com/ CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}, CHR - homepage: http://www.google.com/ CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Krzysiekk\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Krzysiekk\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\24.0.1312.57\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Krzysiekk\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Krzysiekk\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\24.0.1312.57\pdf.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Acrobat 6.0\Reader\Browser\nppdf32.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Krzysiekk\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.111\npGoogleUpdate3.dll CHR - plugin: AVG SiteSafety plugin (Enabled) = C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6\\npsitesafety.dll CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll O1 HOSTS File: ([2012-12-27 12:15:18 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Yahoo! Companion BHO) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll (Yahoo! Inc.) O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (&Yahoo! Companion) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll (Yahoo! Inc.) O3 - HKU\S-1-5-21-854245398-1682526488-682003330-1004\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found. O3 - HKU\S-1-5-21-854245398-1682526488-682003330-1004\..\Toolbar\WebBrowser: (&Yahoo! Companion) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll (Yahoo! Inc.) O3 - HKU\S-1-5-21-854245398-1682526488-682003330-1008\..\Toolbar\WebBrowser: (no name) - {00000000-5736-4205-0008-F7ED0776FB27} - No CLSID value found. O3 - HKU\S-1-5-21-854245398-1682526488-682003330-1008\..\Toolbar\WebBrowser: (&Yahoo! Companion) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll (Yahoo! Inc.) O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKU\S-1-5-21-854245398-1682526488-682003330-1004..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun File not found O4 - HKU\S-1-5-21-854245398-1682526488-682003330-1004..\Run: [FastDow] C:\FastDow\FastDow.exe File not found O4 - HKU\S-1-5-21-854245398-1682526488-682003330-1004..\Run: [GAINWARD] C:\Program Files\EXPERTool\TBPanel.exe (Gainward Co.) O4 - HKU\S-1-5-21-854245398-1682526488-682003330-1004..\Run: [GG] C:\Documents and Settings\Mariusz\Ustawienia lokalne\Dane aplikacji\GG\Application\gghub.exe (GG Network S.A.) O4 - HKU\S-1-5-21-854245398-1682526488-682003330-1004..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe () O4 - HKU\S-1-5-21-854245398-1682526488-682003330-1004..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.) O4 - HKU\S-1-5-21-854245398-1682526488-682003330-1008..\Run: [Steam] E:\Steam\steam.exe (Valve Corporation) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-854245398-1682526488-682003330-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-854245398-1682526488-682003330-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-854245398-1682526488-682003330-1008\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-854245398-1682526488-682003330-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-21-854245398-1682526488-682003330-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-21-854245398-1682526488-682003330-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{748EA3A3-6B72-4779-A845-C70029EE2F2F}: NameServer = 217.172.224.92,81.15.136.251 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\Krzysiekk\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Krzysiekk\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2012-07-29 11:12:33 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2013-02-08 12:20:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\TERA [2013-02-06 11:14:03 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer [2013-02-04 23:51:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Krzysiekk\Pulpit\gmp_win32 [2013-02-04 21:56:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Krzysiekk\Menu Start\Programy\Gothic Multiplayer [2013-02-04 20:00:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Krzysiekk\Menu Start\Programy\JoWood [2013-02-04 19:57:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\JoWood [2013-02-03 11:27:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\RightClick [2013-02-03 11:26:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\BetterSoft [2013-02-03 11:26:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Browse2save [2013-02-03 11:25:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\InstallMate [2013-02-02 20:15:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\ts3overlay [2013-01-31 14:53:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\BANDISOFT [2013-01-31 14:53:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Krzysiekk\Moje dokumenty\Bandicam [2013-01-31 14:53:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Bandicam [2013-01-31 14:53:18 | 000,000,000 | ---D | C] -- C:\Program Files\Bandicam [2013-01-28 14:17:57 | 000,270,888 | R--- | C] (Sunbelt Software, Inc.) -- C:\WINDOWS\System32\drivers\SbFw.sys [2013-01-28 14:17:57 | 000,065,576 | ---- | C] (Sunbelt Software, Inc.) -- C:\WINDOWS\System32\drivers\SbFwIm.sys [2013-01-28 14:17:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Sunbelt Software [2013-01-28 14:17:54 | 000,000,000 | ---D | C] -- C:\Program Files\Sunbelt Software [2013-01-28 13:38:58 | 000,000,000 | ---D | C] -- C:\Program Files\BreakPoint Software [2013-01-27 12:18:51 | 001,691,480 | ---- | C] (Creative) -- C:\WINDOWS\System32\drivers\Ambfilt.sys [2013-01-27 12:18:51 | 001,395,800 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\drivers\Monfilt.sys [2013-01-27 12:18:51 | 000,359,016 | ---- | C] (Realtek Semiconductor Crop.) -- C:\WINDOWS\vncutil.exe [2013-01-27 12:18:51 | 000,068,752 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\RtkCoInstIIXP.dll [2013-01-27 12:18:51 | 000,011,368 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\RtkCoLDRXP.dll [2013-01-27 12:18:50 | 000,129,640 | ---- | C] (Realtek Semiconductor) -- C:\WINDOWS\RtkAudioService.exe [2013-01-26 15:58:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\Mumble [2013-01-21 00:28:42 | 000,000,000 | ---D | C] -- C:\Program Files\WinPcap [2013-01-21 00:28:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\WinPcap [2013-01-17 11:14:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Krzysiekk\Pulpit\Senthia.pl [2013-01-16 20:36:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Last.fm [2013-01-14 23:46:52 | 000,000,000 | ---D | C] -- C:\Program Files\Notepad++ [2013-01-14 23:46:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Krzysiekk\Menu Start\Programy\Notepad++ [2013-01-14 23:46:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Notepad++ [2013-01-11 13:07:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\World of Tanks - Common Test [2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2013-02-08 21:56:00 | 000,001,140 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1682526488-682003330-1004UA.job [2013-02-08 21:31:00 | 000,001,038 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2013-02-08 21:12:40 | 000,000,566 | -H-- | M] () -- C:\WINDOWS\tasks\schedule!567381930.job [2013-02-08 21:10:58 | 000,203,188 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml [2013-02-08 21:10:57 | 000,001,034 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2013-02-08 21:10:51 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2013-02-08 21:10:49 | 2145,386,496 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP [2013-02-08 14:01:55 | 003,284,366 | ---- | M] () -- C:\Documents and Settings\Krzysiekk\Pulpit\m36.rar [2013-02-08 12:20:12 | 000,000,723 | ---- | M] () -- C:\Documents and Settings\Krzysiekk\Pulpit\TERA.lnk [2013-02-06 22:56:00 | 000,001,088 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1682526488-682003330-1004Core.job [2013-02-06 11:25:09 | 000,296,456 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2013-02-04 21:56:23 | 000,000,660 | ---- | M] () -- C:\Documents and Settings\Krzysiekk\Pulpit\Gothic Multiplayer.lnk [2013-02-04 20:00:28 | 000,000,703 | ---- | M] () -- C:\Documents and Settings\Krzysiekk\Pulpit\GMPA.lnk [2013-02-04 06:15:37 | 000,000,672 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\FIFA 13.lnk [2013-02-03 18:08:27 | 000,002,334 | ---- | M] () -- C:\Documents and Settings\Krzysiekk\Pulpit\Google Chrome.lnk [2013-02-02 10:42:18 | 000,678,175 | ---- | M] () -- C:\Documents and Settings\Krzysiekk\Pulpit\m36s.rar [2013-02-02 10:27:11 | 000,115,422 | ---- | M] () -- C:\Documents and Settings\Krzysiekk\Pulpit\m36q.rar [2013-01-31 15:04:29 | 000,017,920 | ---- | M] () -- C:\Documents and Settings\Krzysiekk\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2013-01-27 12:04:57 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2013-01-26 15:59:00 | 000,002,391 | ---- | M] () -- C:\Documents and Settings\Krzysiekk\Moje dokumenty\MumbleAutomaticCertificateBackup.p12 [2013-01-21 18:28:59 | 000,002,267 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Skype.lnk [2013-01-18 23:52:51 | 000,000,339 | RHS- | M] () -- C:\boot.ini [2013-01-18 23:49:40 | 000,697,864 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe [2013-01-18 23:49:38 | 000,074,248 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl [2013-01-16 20:36:23 | 000,000,668 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Last.fm Scrobbler.lnk [2013-01-10 08:00:12 | 000,574,156 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2013-01-10 08:00:12 | 000,510,472 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2013-01-10 08:00:12 | 000,113,664 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2013-01-10 08:00:12 | 000,090,190 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2013-02-08 14:01:54 | 003,284,366 | ---- | C] () -- C:\Documents and Settings\Krzysiekk\Pulpit\m36.rar [2013-02-08 12:20:12 | 000,000,723 | ---- | C] () -- C:\Documents and Settings\Krzysiekk\Pulpit\TERA.lnk [2013-02-05 22:51:40 | 000,001,140 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1682526488-682003330-1004UA.job [2013-02-05 22:51:40 | 000,001,088 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-854245398-1682526488-682003330-1004Core.job [2013-02-04 21:56:23 | 000,000,660 | ---- | C] () -- C:\Documents and Settings\Krzysiekk\Pulpit\Gothic Multiplayer.lnk [2013-02-04 20:00:29 | 000,000,703 | ---- | C] () -- C:\Documents and Settings\Krzysiekk\Pulpit\GMPA.lnk [2013-02-03 11:27:00 | 000,000,566 | -H-- | C] () -- C:\WINDOWS\tasks\schedule!567381930.job [2013-02-02 10:39:30 | 000,678,175 | ---- | C] () -- C:\Documents and Settings\Krzysiekk\Pulpit\m36s.rar [2013-02-02 10:27:11 | 000,115,422 | ---- | C] () -- C:\Documents and Settings\Krzysiekk\Pulpit\m36q.rar [2013-01-27 12:18:51 | 000,025,816 | ---- | C] () -- C:\WINDOWS\System32\drivers\RTAIODAT.DAT [2013-01-26 15:59:00 | 000,002,391 | ---- | C] () -- C:\Documents and Settings\Krzysiekk\Moje dokumenty\MumbleAutomaticCertificateBackup.p12 [2013-01-16 20:36:23 | 000,000,668 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Last.fm Scrobbler.lnk [2012-12-21 12:51:53 | 000,138,464 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys [2012-12-21 12:51:48 | 000,111,928 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe [2012-12-21 12:51:41 | 000,066,872 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe [2012-11-20 22:07:49 | 000,013,507 | ---- | C] () -- C:\Documents and Settings\Krzysiekk\Ustawienia lokalne\Dane aplikacji\recently-used.xbel [2012-10-15 14:01:15 | 000,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini [2012-09-22 17:45:06 | 000,453,782 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-S-1-5-21-854245398-1682526488-682003330-1008-0.dat [2012-09-20 19:53:39 | 000,017,920 | ---- | C] () -- C:\Documents and Settings\Krzysiekk\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-09-15 14:47:49 | 000,210,456 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll [2012-09-15 14:47:49 | 000,206,360 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll [2012-09-15 14:47:49 | 000,198,168 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll [2012-09-15 14:47:49 | 000,198,168 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll [2012-09-15 14:47:49 | 000,194,072 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll [2012-09-15 14:47:49 | 000,026,136 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll [2012-09-06 16:27:59 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe [2012-09-06 16:27:59 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe [2012-09-06 16:27:59 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2012-09-06 16:27:59 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2012-09-06 16:27:59 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2012-08-10 14:10:23 | 000,396,014 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-S-1-5-21-854245398-1682526488-682003330-1005-0.dat [2012-08-10 14:10:23 | 000,286,846 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-System.dat [2012-08-06 09:48:01 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2012-07-30 05:05:03 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2012-07-29 22:01:34 | 000,008,192 | ---- | C] () -- C:\WINDOWS\d3dx.dat [2012-07-29 13:04:46 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2012-07-29 13:03:44 | 000,296,456 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012-07-29 11:36:51 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe [2012-07-29 11:17:37 | 000,001,732 | ---- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin [2012-07-29 11:13:48 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2012-07-29 11:10:30 | 000,021,856 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2011-09-19 08:07:46 | 000,015,360 | ---- | C] () -- C:\WINDOWS\System32\bdmjpeg.dll [2011-09-19 08:07:32 | 000,058,368 | ---- | C] () -- C:\WINDOWS\System32\bdmpegv.dll [color=#E56717]========== ZeroAccess Check ==========[/color] [2012-08-13 12:17:08 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2012-04-20 20:30:26 | 001,510,400 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009-02-09 11:53:44 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2008-04-15 13:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2012-08-06 13:32:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Age of Empires 3 [2012-08-10 11:38:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ashampoo [2012-10-24 22:38:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\AVG2013 [2012-07-29 11:31:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Babylon [2013-02-03 11:26:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\BetterSoft [2013-02-03 11:27:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Browse2save [2012-08-01 17:16:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite [2012-07-29 11:43:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10 [2012-10-18 21:17:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\GG [2013-02-03 11:27:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\InstallMate [2012-09-15 14:47:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\InterVideo [2012-08-19 08:03:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Last.fm [2012-10-24 22:38:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\MFAData [2012-11-25 21:44:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\MTA San Andreas All [2012-11-30 13:02:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Nexon [2012-11-30 12:39:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\NexonEU [2012-12-04 15:06:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Orbit [2013-01-24 14:46:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Origin [2012-12-25 14:45:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PMB Files [2012-11-11 19:54:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Remedy [2013-02-03 11:27:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\RightClick [2012-10-07 16:35:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Solidshield [2012-09-15 14:50:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Ulead Systems [2013-02-08 14:00:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\Audacity [2012-09-19 22:50:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\Avnex [2013-01-31 14:53:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\BANDISOFT [2012-12-28 15:54:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\DAEMON Tools Lite [2012-12-28 15:54:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\FileZilla [2012-09-16 13:07:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\Gadu-Gadu 10 [2012-09-16 11:05:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\GameRanger [2013-02-08 20:41:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\GG [2012-09-16 12:28:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\LolClient [2013-01-03 12:43:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\Mount&Blade Warband [2013-02-04 21:51:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\Mumble [2012-11-17 11:48:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\Origin [2013-02-03 17:53:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\TS3Client [2013-02-02 20:16:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\ts3overlay [2012-10-24 22:38:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\TuneUp Software [2012-09-16 10:49:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\Ulead Systems [2012-12-28 15:54:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Krzysiekk\Dane aplikacji\uTorrent [2012-11-24 18:27:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mariusz\Dane aplikacji\.minecraft [2012-11-23 18:00:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mariusz\Dane aplikacji\Ashampoo [2012-09-05 12:49:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mariusz\Dane aplikacji\AVG Secure Search [2012-07-29 11:31:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mariusz\Dane aplikacji\Babylon [2012-07-29 11:31:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mariusz\Dane aplikacji\BabylonToolbar [2012-08-01 17:16:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mariusz\Dane aplikacji\DAEMON Tools Lite [2012-12-23 07:54:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mariusz\Dane aplikacji\fltk.org [2012-07-29 11:43:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mariusz\Dane aplikacji\Gadu-Gadu 10 [2013-02-08 15:21:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mariusz\Dane aplikacji\GG [2012-09-11 17:56:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mariusz\Dane aplikacji\NapiProjekt [2012-08-01 17:15:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mariusz\Dane aplikacji\OpenCandy [2013-01-20 17:05:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mariusz\Dane aplikacji\TeamViewer [2013-02-08 15:58:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mariusz\Dane aplikacji\TS3Client [2012-12-16 15:57:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mariusz\Dane aplikacji\ts3overlay [2012-09-21 14:37:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mariusz\Dane aplikacji\TuneUp Software [2013-01-02 11:53:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mariusz\Dane aplikacji\Ulead Systems [2013-01-24 12:40:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mariusz\Dane aplikacji\Unity [2013-02-08 15:22:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mariusz\Dane aplikacji\uTorrent [2012-08-12 09:46:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Mariusz\Dane aplikacji\wargaming.net [color=#E56717]========== Purity Check ==========[/color] < End of report >