OTL logfile created on: 2013-03-26 22:15:43 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\milosz\Desktop 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 6,00 Gb Total Physical Memory | 3,03 Gb Available Physical Memory | 50,53% Memory free 12,00 Gb Paging File | 8,77 Gb Available in Paging File | 73,11% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 931,51 Gb Total Space | 243,18 Gb Free Space | 26,11% Space Free | Partition Type: NTFS Drive D: | 931,51 Gb Total Space | 629,63 Gb Free Space | 67,59% Space Free | Partition Type: NTFS Drive E: | 165,76 Gb Total Space | 13,94 Gb Free Space | 8,41% Space Free | Partition Type: NTFS Drive F: | 100,00 Gb Total Space | 38,49 Gb Free Space | 38,49% Space Free | Partition Type: NTFS Drive G: | 200,00 Gb Total Space | 35,99 Gb Free Space | 18,00% Space Free | Partition Type: NTFS Drive I: | 4,15 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: MILOSZ-KOMPUTER | User Name: milosz | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2013-03-26 22:15:31 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\milosz\Desktop\OTL.exe PRC - [2013-03-03 00:03:00 | 001,151,152 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe PRC - [2013-03-03 00:03:00 | 000,968,880 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe PRC - [2013-02-20 15:05:14 | 001,259,768 | ---- | M] (Bogdan Sharkov) -- C:\Program Files (x86)\Clownfish\Clownfish.exe PRC - [2013-02-01 17:07:18 | 000,272,896 | ---- | M] (TrishTech.com) -- C:\Users\milosz\AppData\Local\Temp\Rar$EX00.961\PublicDNS.exe PRC - [2013-01-24 14:18:46 | 001,646,216 | ---- | M] (Ask) -- C:\Program Files (x86)\Ask.com\Updater\Updater.exe PRC - [2012-12-11 03:52:44 | 003,147,384 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgui.exe PRC - [2012-10-22 13:05:08 | 000,196,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe PRC - [2012-07-12 00:26:34 | 000,138,096 | ---- | M] (Facebook Inc.) -- C:\Users\milosz\AppData\Local\Facebook\Update\FacebookUpdate.exe PRC - [2012-04-22 15:05:00 | 001,816,064 | ---- | M] (Kobi Snir) -- C:\Program Files (x86)\Kobi Snir\CrazyPC Server\CrazyPCServer.exe PRC - [2012-04-17 16:19:40 | 003,671,872 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe PRC - [2012-01-05 22:49:16 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe PRC - [2011-09-05 18:04:58 | 002,904,984 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe PRC - [2011-03-17 22:07:00 | 000,019,872 | ---- | M] () -- C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe PRC - [2010-12-27 17:58:54 | 000,264,192 | ---- | M] (Microsoft) -- C:\Program Files (x86)\Thoro Software\Audio Setter Server\AudioSetterServer.exe PRC - [2010-11-22 14:50:26 | 000,066,560 | ---- | M] (Nalpeiron Ltd.) -- C:\Windows\SysWOW64\nlssrv32.exe PRC - [2009-12-02 21:23:38 | 000,209,768 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe PRC - [2009-12-02 21:23:32 | 000,483,688 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe PRC - [2009-08-05 16:58:52 | 000,186,976 | ---- | M] (F-Secure Corporation) -- C:\Program Files (x86)\Pakiet Bezpieczeństwa UPC\Common\FSMA32.EXE PRC - [2009-08-05 16:58:50 | 000,199,264 | ---- | M] (F-Secure Corporation) -- C:\Program Files (x86)\Pakiet Bezpieczeństwa UPC\Common\FSM32.EXE PRC - [2009-08-05 16:58:50 | 000,088,672 | ---- | M] (F-Secure Corporation) -- C:\Program Files (x86)\Pakiet Bezpieczeństwa UPC\Common\FSHDLL32.EXE PRC - [2008-01-07 11:04:10 | 000,057,344 | ---- | M] (Nalpeiron Ltd.) -- C:\Windows\SysWOW64\ASTSRV.EXE [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2013-03-03 00:03:00 | 001,151,152 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe MOD - [2013-03-03 00:03:00 | 000,156,848 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\14.2.0\SiteSafety.dll MOD - [2012-12-28 17:00:58 | 000,055,816 | ---- | M] () -- C:\Users\milosz\AppData\Local\Temp\e3c74ee6-7482-4280-b9c3-f233b390296e\CliSecureRT.dll MOD - [2011-12-06 15:29:43 | 000,767,488 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\dc1f0dbf1d3ba856eccec90b62b55d79\System.Runtime.Remoting.ni.dll MOD - [2011-09-27 06:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2011-09-27 06:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2011-09-09 17:07:16 | 001,159,168 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\6a6f4be744ed5bc5273cbcf0fcf303e3\System.Management.ni.dll MOD - [2011-09-09 17:06:02 | 001,776,640 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\035910922f160d304fb834aae41f45a6\System.Xaml.ni.dll MOD - [2011-09-07 17:42:27 | 017,629,184 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\7f91eecda3ff7ce478146b6458580c98\PresentationFramework.ni.dll MOD - [2011-09-07 17:42:16 | 011,057,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\3963e9ce8d44f50e8367e92a8e3e42e6\PresentationCore.ni.dll MOD - [2011-09-07 17:42:08 | 007,025,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\713647b987b140a17e3c4ffe4c721f85\System.Core.ni.dll MOD - [2011-09-07 17:42:08 | 003,779,072 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\d17606e813f01376bd0def23726ecc62\WindowsBase.ni.dll MOD - [2011-09-07 17:42:06 | 005,571,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\e997d0200c25f7db6bd32313d50b729d\System.Xml.ni.dll MOD - [2011-09-07 17:42:04 | 001,651,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\dd57bc19f5807c6dbe8f88d4a23277f6\System.Drawing.ni.dll MOD - [2011-09-07 17:42:04 | 000,450,048 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\3555f5f74c56fa92c0ab7a635af91bfa\PresentationFramework.Aero.ni.dll MOD - [2011-09-07 17:42:03 | 000,973,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\ac18c2dcd06bd2a0589bac94ccae5716\System.Configuration.ni.dll MOD - [2011-09-07 17:42:02 | 009,000,960 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\964da027ebca3b263a05cadb8eaa20a3\System.ni.dll MOD - [2011-09-07 17:41:58 | 014,415,872 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\246f1a5abb686b9dcdf22d3505b08cea\mscorlib.ni.dll MOD - [2011-09-05 18:05:16 | 000,019,968 | ---- | M] () -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\pl_PL\acrotray.pol MOD - [2011-03-17 22:07:00 | 000,019,872 | ---- | M] () -- C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2012-12-19 15:32:12 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service) SRV:[b]64bit:[/b] - [2012-04-06 03:16:02 | 000,236,544 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:[b]64bit:[/b] - [2011-08-05 11:53:12 | 000,467,680 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc) SRV:[b]64bit:[/b] - [2011-08-05 11:53:12 | 000,306,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\WMZuneComm.exe -- (WMZuneComm) SRV:[b]64bit:[/b] - [2011-08-05 11:53:06 | 008,277,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\ZuneNss.exe -- (ZuneNetworkSvc) SRV:[b]64bit:[/b] - [2009-07-14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:[b]64bit:[/b] - [2009-07-14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV:[b]64bit:[/b] - [2009-04-03 12:46:52 | 000,072,192 | ---- | M] (Nalpeiron Ltd.) [Disabled | Stopped] -- C:\Windows\SysNative\nlsInterface.exe -- (nlscc) SRV - [2013-03-20 18:07:42 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013-03-20 17:33:19 | 004,561,152 | ---- | M] () [Auto | Running] -- c:\program files (x86)\common files\akamai/netsession_win_ca0e279.dll -- (Akamai) SRV - [2013-03-14 18:54:13 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013-03-03 00:03:00 | 000,968,880 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe -- (vToolbarUpdater14.2.0) SRV - [2013-02-07 13:10:08 | 000,161,384 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012-11-15 23:34:30 | 005,814,904 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe -- (AVGIDSAgent) SRV - [2012-10-22 13:05:08 | 000,196,664 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe -- (avgwd) SRV - [2012-02-26 15:42:28 | 000,632,320 | ---- | M] (FileZilla Project) [Auto | Stopped] -- C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe -- (FileZilla Server) SRV - [2012-02-24 10:36:06 | 001,117,624 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Tools Security\pctsSvc.exe -- (sdCoreService) SRV - [2012-02-24 09:16:12 | 000,402,336 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Tools Security\pctsAuxs.exe -- (sdAuxService) SRV - [2012-01-05 22:49:16 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2011-12-14 12:59:20 | 002,984,832 | ---- | M] (TeamViewer GmbH) [Disabled | Stopped] -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7) SRV - [2011-06-29 14:59:18 | 000,155,344 | ---- | M] (Avanquest Software) [Disabled | Stopped] -- C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe -- (Sony Ericsson PCCompanion) SRV - [2011-05-21 14:51:21 | 000,403,240 | ---- | M] (Valve Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2011-03-01 15:47:56 | 002,296,696 | ---- | M] (TeamViewer GmbH) [Disabled | Stopped] -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6) SRV - [2010-11-22 14:50:26 | 000,066,560 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\Windows\SysWOW64\nlssrv32.exe -- (nlsX86cc) SRV - [2010-03-18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010-02-19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard) SRV - [2009-12-23 22:34:20 | 000,370,688 | ---- | M] (StarWind Software) [Disabled | Stopped] -- C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE) SRV - [2009-12-02 21:23:38 | 000,209,768 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa) SRV - [2009-12-02 21:23:32 | 000,483,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist) SRV - [2009-08-05 16:58:52 | 000,186,976 | ---- | M] (F-Secure Corporation) [Auto | Running] -- C:\Program Files (x86)\Pakiet Bezpieczeństwa UPC\Common\FSMA32.EXE -- (FSMA) SRV - [2009-06-21 16:03:51 | 000,655,624 | ---- | M] (Acresso Software Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2009-06-10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2009-02-10 16:01:49 | 000,116,104 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE -- (IJPLMSVC) SRV - [2008-09-23 07:20:16 | 000,575,488 | ---- | M] (Nokia.) [Disabled | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) SRV - [2008-01-07 11:04:10 | 000,057,344 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\Windows\SysWOW64\ASTSRV.EXE -- (astcc) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2013-03-03 00:03:00 | 000,039,768 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp) DRV:[b]64bit:[/b] - [2013-03-02 23:12:06 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:[b]64bit:[/b] - [2012-12-13 13:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64) DRV:[b]64bit:[/b] - [2012-11-15 23:33:24 | 000,111,968 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64) DRV:[b]64bit:[/b] - [2012-11-06 12:11:52 | 000,096,256 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService) DRV:[b]64bit:[/b] - [2012-10-22 13:02:44 | 000,154,464 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver) DRV:[b]64bit:[/b] - [2012-10-15 03:48:50 | 000,063,328 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA) DRV:[b]64bit:[/b] - [2012-10-02 03:30:38 | 000,185,696 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64) DRV:[b]64bit:[/b] - [2012-09-21 03:46:04 | 000,200,032 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia) DRV:[b]64bit:[/b] - [2012-09-21 03:46:00 | 000,225,120 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\avgloga.sys -- (Avgloga) DRV:[b]64bit:[/b] - [2012-09-14 03:05:18 | 000,040,800 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64) DRV:[b]64bit:[/b] - [2012-08-21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV:[b]64bit:[/b] - [2012-06-08 13:18:16 | 000,560,184 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd) DRV:[b]64bit:[/b] - [2012-04-09 09:13:58 | 000,057,472 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Stopped] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.2) DRV:[b]64bit:[/b] - [2012-04-09 09:13:58 | 000,057,472 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.01) DRV:[b]64bit:[/b] - [2012-04-09 09:13:58 | 000,057,472 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.0) DRV:[b]64bit:[/b] - [2012-04-06 06:22:40 | 011,174,400 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag) DRV:[b]64bit:[/b] - [2012-04-06 06:22:40 | 011,174,400 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:[b]64bit:[/b] - [2012-04-06 02:10:44 | 000,343,040 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:[b]64bit:[/b] - [2012-02-24 10:36:50 | 000,230,952 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\PCTSD64.sys -- (PCTSD) DRV:[b]64bit:[/b] - [2011-12-01 16:07:10 | 001,096,688 | ---- | M] (PC Tools) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\pctEFA64.sys -- (pctEFA) DRV:[b]64bit:[/b] - [2011-12-01 16:07:08 | 000,453,896 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pctDS64.sys -- (pctDS) DRV:[b]64bit:[/b] - [2011-11-14 15:12:28 | 000,367,912 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PCTCore64.sys -- (PCTCore) DRV:[b]64bit:[/b] - [2011-11-03 03:01:00 | 000,056,208 | ---- | M] (Rovi Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64) DRV:[b]64bit:[/b] - [2011-06-10 06:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:[b]64bit:[/b] - [2011-01-19 17:47:18 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\cpuz135_x64.sys -- (cpuz135) DRV:[b]64bit:[/b] - [2011-01-03 09:38:36 | 000,177,128 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdm.sys -- (ssadmdm) DRV:[b]64bit:[/b] - [2011-01-03 09:38:36 | 000,157,160 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadbus.sys -- (ssadbus) DRV:[b]64bit:[/b] - [2011-01-03 09:38:36 | 000,016,872 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdfl.sys -- (ssadmdfl) DRV:[b]64bit:[/b] - [2010-12-06 22:22:08 | 000,075,264 | ---- | M] (IPWireless) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lte_dev.sys -- (lte_dev) DRV:[b]64bit:[/b] - [2010-12-06 22:22:08 | 000,062,976 | ---- | M] (IPWireless) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lte_net.sys -- (lte_net) DRV:[b]64bit:[/b] - [2010-12-06 22:22:08 | 000,027,648 | ---- | M] (IPWireless) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lte_ctrl.sys -- (lte_ctrl) DRV:[b]64bit:[/b] - [2010-11-25 05:59:16 | 000,694,888 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTL8192su.sys -- (RTL8192su) DRV:[b]64bit:[/b] - [2010-11-21 04:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV:[b]64bit:[/b] - [2010-11-21 04:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2010-11-21 04:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub) DRV:[b]64bit:[/b] - [2010-11-21 04:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc) DRV:[b]64bit:[/b] - [2010-11-21 04:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc) DRV:[b]64bit:[/b] - [2010-11-21 04:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt) DRV:[b]64bit:[/b] - [2010-11-21 04:23:48 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser) DRV:[b]64bit:[/b] - [2010-11-21 04:23:47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2010-11-21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2010-11-21 04:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:[b]64bit:[/b] - [2010-11-21 04:23:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2010-11-02 20:11:28 | 000,358,888 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\asmtxhci.sys -- (asmtxhci) DRV:[b]64bit:[/b] - [2010-11-02 20:11:28 | 000,121,320 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\asmthub3.sys -- (asmthub3) DRV:[b]64bit:[/b] - [2010-10-26 10:30:04 | 000,011,392 | ---- | M] (IPWireless) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ipwltesw.sys -- (ipwltesw) DRV:[b]64bit:[/b] - [2010-05-25 04:07:58 | 000,253,728 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService) DRV:[b]64bit:[/b] - [2010-04-12 09:55:00 | 000,091,568 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\scdemu.sys -- (SCDEmu) DRV:[b]64bit:[/b] - [2010-02-18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64) DRV:[b]64bit:[/b] - [2009-12-02 21:23:38 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol) DRV:[b]64bit:[/b] - [2009-12-02 21:23:34 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir) DRV:[b]64bit:[/b] - [2009-12-02 21:23:32 | 000,269,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay) DRV:[b]64bit:[/b] - [2009-12-02 21:23:26 | 000,721,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs) DRV:[b]64bit:[/b] - [2009-09-10 14:31:56 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard) DRV:[b]64bit:[/b] - [2009-07-24 14:52:14 | 000,114,560 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbdev.sys -- (hwusbdev) DRV:[b]64bit:[/b] - [2009-07-14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009-07-14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009-07-14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2009-07-14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009-07-14 01:06:43 | 000,060,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\61883.sys -- (61883) DRV:[b]64bit:[/b] - [2009-07-14 01:06:43 | 000,048,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\avc.sys -- (Avc) DRV:[b]64bit:[/b] - [2009-07-14 01:06:40 | 000,017,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\avcstrm.sys -- (AVCSTRM) DRV:[b]64bit:[/b] - [2009-07-14 01:06:39 | 000,056,448 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mstape.sys -- (MSTAPE) DRV:[b]64bit:[/b] - [2009-06-10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009-06-10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009-06-10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009-06-10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:[b]64bit:[/b] - [2009-03-18 16:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi) DRV:[b]64bit:[/b] - [2009-02-09 07:38:44 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltx64j.sys -- (UsbserFilt) DRV:[b]64bit:[/b] - [2009-02-09 07:38:34 | 000,018,944 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbx64.sys -- (nmwcdx64) DRV:[b]64bit:[/b] - [2009-02-09 07:38:34 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys -- (upperdev) DRV:[b]64bit:[/b] - [2009-02-09 07:38:32 | 000,025,088 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbox64.sys -- (nmwcdcx64) DRV:[b]64bit:[/b] - [2008-08-28 11:44:42 | 000,025,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd) DRV - [2009-07-14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) DRV - [2006-05-09 06:02:06 | 000,013,056 | ---- | M] (DiBcom S.A.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\modrc.sys -- (MODRC) DRV - [2005-09-20 16:27:20 | 000,010,368 | ---- | M] (InterVideo, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\iviaspi.sys -- (Iviaspi) DRV - [1998-08-21 16:09:08 | 000,039,840 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\usbaudio.sys -- (usbaudio) DRV - [1998-08-21 16:08:00 | 000,027,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\usbhub.sys -- (usbhub) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2410} IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}: "URL" = http://www.searchqu.com//web?src=ieb&appid=0&systemid=410&sr=0&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=vlt2&from=vlt2&uid=WDC_WD5000AAKS-07A7B2_WD-WMASY604305743057&ts=1352919410 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.v9.com/?utm_source=b&utm_medium=vlt2&from=vlt2&uid=WDC_WD5000AAKS-07A7B2_WD-WMASY604305743057&ts=1352919410 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddr&s={searchTerms}&f=4 IE - HKLM\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBit2.dll (Conduit Ltd.) IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2410} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://startsear.ch/?aff=1&q={searchTerms} IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}: "URL" = http://www.searchqu.com//web?src=ieb&appid=0&systemid=410&sr=0&q={searchTerms} IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2790392 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=vlt2&from=vlt2&uid=WDC_WD5000AAKS-07A7B2_WD-WMASY604305743057&ts=1352919410 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.pl/ IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBit2.dll (Conduit Ltd.) IE - HKCU\..\SearchScopes,DefaultScope = {0D7562AE-8EF6-416d-A838-AB665251703A} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://startsear.ch/?aff=1&q={searchTerms} IE - HKCU\..\SearchScopes\{23FE0004-6493-4A51-A33F-A90A4CE139C3}: "URL" = http://start.facemoods.com/?a=ddr&s={searchTerms}&f=4 IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2410}: "URL" = http://www.searchqu.com//web?src=ieb&appid=0&systemid=410&sr=0&q={searchTerms} IE - HKCU\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms} IE - HKCU\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB9}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms} IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2790392 IE - HKCU\..\SearchScopes\{F9DDA418-37A8-4557-9E84-CF41380F9D52}: "URL" = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=244506&p={searchTerms} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1:9421; [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultengine: "Web Search" FF - prefs.js..browser.search.defaultenginename: "Web Search" FF - prefs.js..browser.search.defaultthis.engineName: "Conduit Engine Customized Web Search" FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=ConduitEngine&SearchSource=3&q={searchTerms}" FF - prefs.js..browser.search.order.1: "Web Search" FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=244506" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.startup.homepage: "about:home" FF - prefs.js..extensions.enabledAddons: exif_viewer@mozilla.doslash.org:2.00 FF - prefs.js..extensions.enabledAddons: ffxtlbr@Facemoods.com:1.2.1 FF - prefs.js..extensions.enabledAddons: IplextoALL@ALLPlayer.org:0.7.0 FF - prefs.js..extensions.enabledAddons: tineye@ideeinc.com:1.1 FF - prefs.js..extensions.enabledAddons: {340c2bbc-ce74-4362-90b5-7c26312808ef}:1.7 FF - prefs.js..extensions.enabledAddons: {5c7beb8b-4d7f-4dd0-8257-9bf98570cbd2}:1.1 FF - prefs.js..extensions.enabledAddons: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:17.0.0 FF - prefs.js..extensions.enabledAddons: {88c7f2aa-f93f-432c-8f0e-b7d85967a527}:3.18.0.7 FF - prefs.js..extensions.enabledAddons: toolbar@ask.com:3.15.15.100013 FF - prefs.js..extensions.enabledItems: engine@conduit.com:3.2.5.2 FF - prefs.js..extensions.enabledItems: {88c7f2aa-f93f-432c-8f0e-b7d85967a527}:3.2.5.2 FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.1.4.0024 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: {340c2bbc-ce74-4362-90b5-7c26312808ef}:1.7 FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.15.1.22229 FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:4.0.2 FF - prefs.js..extensions.enabledItems: tineye@ideeinc.com:1.1 FF - prefs.js..extensions.enabledItems: exif_viewer@mozilla.doslash.org:1.60 FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0 FF - prefs.js..extensions.enabledItems: {5c7beb8b-4d7f-4dd0-8257-9bf98570cbd2}:1.1 FF - prefs.js..extensions.enabledItems: ffxtlbr@Facemoods.com:1.2.1 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29 FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442 FF - prefs.js..extensions.enabledItems: web2pdfextension@web2pdf.adobedotcom:1.0 FF - prefs.js..extensions.enabledItems: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9}:6.1 FF - prefs.js..extensions.enabledItems: IplextoALL@ALLPlayer.org:0.1.0 FF - prefs.js..keyword.URL: "chrome://browser-region/locale/region.properties" FF - prefs.js..network.proxy.type: 0 FF - user.js - File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\14.2.0\\npsitesafety.dll () FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.110.0: C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll File not found FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.2: C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\milosz\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2012-02-24 19:08:40 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-03-20 21:06:54 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012-12-06 20:12:14 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013-03-20 21:07:03 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.4\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013-03-20 18:07:38 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.4\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\milosz\AppData\Roaming\IDM\idmmzcc5 [2011-08-30 14:52:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\milosz\AppData\Roaming\mozilla\Extensions [2011-02-18 19:44:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\milosz\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2011-03-22 15:50:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\milosz\AppData\Roaming\mozilla\Extensions\celtx@celtx.com [2013-03-09 12:14:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\milosz\AppData\Roaming\mozilla\Firefox\Profiles\83p7ycno.default\extensions [2011-03-13 18:33:01 | 000,000,000 | ---D | M] (Firefox Sync) -- C:\Users\milosz\AppData\Roaming\mozilla\Firefox\Profiles\83p7ycno.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef} [2011-09-01 14:02:29 | 000,000,000 | ---D | M] (nopremium.pl - wspomaganie pobierania) -- C:\Users\milosz\AppData\Roaming\mozilla\Firefox\Profiles\83p7ycno.default\extensions\{5c7beb8b-4d7f-4dd0-8257-9bf98570cbd2} [2013-03-09 12:14:54 | 000,000,000 | ---D | M] (BitTorrentBar Community Toolbar) -- C:\Users\milosz\AppData\Roaming\mozilla\Firefox\Profiles\83p7ycno.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527} [2011-08-30 14:52:21 | 000,000,000 | ---D | M] (Searchqu Toolbar) -- C:\Users\milosz\AppData\Roaming\mozilla\Firefox\Profiles\83p7ycno.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7} [2012-06-30 15:17:33 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\milosz\AppData\Roaming\mozilla\Firefox\Profiles\83p7ycno.default\extensions\DTToolbar@toolbarnet.com [2011-09-01 16:09:30 | 000,000,000 | ---D | M] (Facemoods) -- C:\Users\milosz\AppData\Roaming\mozilla\Firefox\Profiles\83p7ycno.default\extensions\ffxtlbr@Facemoods.com [2011-04-19 13:20:47 | 000,000,000 | ---D | M] (TinEye Reverse Image Search) -- C:\Users\milosz\AppData\Roaming\mozilla\Firefox\Profiles\83p7ycno.default\extensions\tineye@ideeinc.com [2013-03-05 15:34:48 | 000,000,000 | ---D | M] ("Nero Toolbar") -- C:\Users\milosz\AppData\Roaming\mozilla\Firefox\Profiles\83p7ycno.default\extensions\toolbar@ask.com [2013-03-09 12:14:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\milosz\AppData\Roaming\mozilla\Firefox\Profiles\83p7ycno.default\extensions\trash [2012-09-04 18:31:21 | 000,230,013 | ---- | M] () (No name found) -- C:\Users\milosz\AppData\Roaming\mozilla\firefox\profiles\83p7ycno.default\extensions\exif_viewer@mozilla.doslash.org.xpi [2012-06-30 15:17:21 | 000,010,043 | ---- | M] () (No name found) -- C:\Users\milosz\AppData\Roaming\mozilla\firefox\profiles\83p7ycno.default\extensions\IplextoALL@ALLPlayer.org.xpi [2013-01-08 21:18:28 | 000,030,502 | ---- | M] () (No name found) -- C:\Users\milosz\AppData\Roaming\mozilla\firefox\profiles\83p7ycno.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi [2010-10-10 15:46:56 | 000,004,669 | ---- | M] () (No name found) -- C:\Users\milosz\AppData\Roaming\mozilla\firefox\profiles\83p7ycno.default\extensions\ffxtlbr@Facemoods.com\content\xpiInstallLgc.js [2011-02-18 20:33:39 | 000,000,913 | ---- | M] () -- C:\Users\milosz\AppData\Roaming\mozilla\firefox\profiles\83p7ycno.default\searchplugins\conduit.xml [2011-02-20 12:07:19 | 000,002,059 | ---- | M] () -- C:\Users\milosz\AppData\Roaming\mozilla\firefox\profiles\83p7ycno.default\searchplugins\daemon-search.xml [2011-08-30 14:52:18 | 000,002,503 | ---- | M] () -- C:\Users\milosz\AppData\Roaming\mozilla\firefox\profiles\83p7ycno.default\searchplugins\SearchResults.xml [2011-07-11 19:04:02 | 000,000,633 | ---- | M] () -- C:\Users\milosz\AppData\Roaming\mozilla\firefox\profiles\83p7ycno.default\searchplugins\startsear.xml [2012-06-30 15:16:58 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2012-02-05 16:55:22 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2012-09-21 19:29:59 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2011-03-19 04:58:26 | 000,067,216 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npContribute.dll [2007-09-23 15:49:46 | 000,139,776 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\plugins\npImagine.dll [2011-08-31 11:38:58 | 000,082,944 | ---- | M] (vShare.tv ) -- C:\Program Files (x86)\mozilla firefox\plugins\npvsharetvplg.dll [2012-06-30 15:16:50 | 000,002,767 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\allegro-pl.xml [2012-06-30 15:16:50 | 000,001,406 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fbc-pl.xml [2011-09-01 16:09:31 | 000,002,046 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrchddr.xml [2012-06-30 15:16:50 | 000,000,917 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\merlin-pl.xml [2012-06-30 15:16:50 | 000,000,858 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\pwn-pl.xml [2011-08-30 14:52:18 | 000,002,503 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\SearchResults.xml [2012-06-30 15:16:50 | 000,001,183 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-pl.xml [2012-06-30 15:16:50 | 000,001,683 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wp-pl.xml [color=#E56717]========== Chrome ==========[/color] CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}, CHR - homepage: http://google.pl/ CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\PepperFlash\pepflashplayer.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\pdf.dll CHR - plugin: Adobe Contribute CS5.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npContribute.dll CHR - plugin: Imagine Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npImagine.dll CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll CHR - plugin: vShare.tv plug-in (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npvsharetvplg.dll CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll CHR - plugin: ESN Sonar API (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL CHR - plugin: AVG SiteSafety plugin (Enabled) = C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\14.2.0\\npsitesafety.dll CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll CHR - plugin: Java(TM) Platform SE 7 U4 (Enabled) = C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll CHR - plugin: Uplay PC (Enabled) = C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\milosz\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll CHR - plugin: Java Deployment Toolkit 7.0.40.255 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll CHR - Extension: Funmoods = C:\Users\milosz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\2.1.0_0\ CHR - Extension: vshare plugin = C:\Users\milosz\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\ CHR - Extension: Skype Click to Call = C:\Users\milosz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\ O1 HOSTS File: ([2011-12-22 16:11:00 | 000,000,833 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:[b]64bit:[/b] - BHO: (Expressivo) - {85F685C3-20D9-4943-95E4-EB4224056C3F} - C:\Program Files (x86)\ivo\Expressivo\integr\ih-iexplorer\IH_iexplorer_x64.dll (IVO Software Sp. z o.o.) O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.) O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) O2 - BHO: (CescrtHlpr Object) - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.5\bh\facemoods.dll (facemoods.com BHO) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) O2 - BHO: (IE5BarLauncherBHO Class) - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll (VShare Inc.) O2 - BHO: (Expressivo) - {85F685C3-20D9-4943-95E4-EB4224056C3F} - C:\Program Files (x86)\ivo\Expressivo\integr\ih-iexplorer\IH_iexplorer.dll (IVO Software Sp. z o.o.) O2 - BHO: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBit2.dll (Conduit Ltd.) O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll () O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIA6EB~1\Datamngr\ToolBar\searchqudtx.dll () O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (IplexToALLPlayer) - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - C:\PROGRA~2\ALLPLA~1\Iplex\IPLEXT~1.DLL (ALLCinema Ltd.) O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3:[b]64bit:[/b] - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll () O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Expressivo) - {85F685C3-20D9-4943-95E4-EB4224056C3F} - C:\Program Files (x86)\ivo\Expressivo\integr\ih-iexplorer\IH_iexplorer_x64.dll (IVO Software Sp. z o.o.) O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.) O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) O3 - HKLM\..\Toolbar: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll (VShare Inc.) O3 - HKLM\..\Toolbar: (Expressivo) - {85F685C3-20D9-4943-95E4-EB4224056C3F} - C:\Program Files (x86)\ivo\Expressivo\integr\ih-iexplorer\IH_iexplorer.dll (IVO Software Sp. z o.o.) O3 - HKLM\..\Toolbar: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files (x86)\BitTorrentBar\prxtbBit2.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll () O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WIA6EB~1\Datamngr\ToolBar\searchqudtx.dll () O3 - HKLM\..\Toolbar: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.5\facemoodsTlbr.dll (facemoods.com) O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found. O3:[b]64bit:[/b] - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll () O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll () O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) O3 - HKCU\..\Toolbar\WebBrowser: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll (VShare Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (BitTorrentBar Toolbar) - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - C:\Program Files (x86)\BitTorrentBar\prxtbBit2.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) O4:[b]64bit:[/b] - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4:[b]64bit:[/b] - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.) O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation) O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask) O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [FileZilla Server Interface] C:\Program Files (x86)\FileZilla Server\FileZilla Server Interface.exe (FileZilla Project) O4 - HKLM..\Run: [F-Secure Manager] C:\Program Files (x86)\Pakiet Bezpieczeństwa UPC\Common\FSM32.EXE (F-Secure Corporation) O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe () O4 - HKCU..\Run: [AdobeBridge] File not found O4 - HKCU..\Run: [ALLUpdate] C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe () O4 - HKCU..\Run: [Clownfish] C:\Program Files (x86)\Clownfish\Clownfish.exe (Bogdan Sharkov) O4 - HKCU..\Run: [CrazyPC] C:\Program Files (x86)\Kobi Snir\CrazyPC Server\CrazyPCServer.exe (Kobi Snir) O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKCU..\Run: [Facebook Update] C:\Users\milosz\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.) O4 - HKCU..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe () O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutorun = 158 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O8:[b]64bit:[/b] - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found O8:[b]64bit:[/b] - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8:[b]64bit:[/b] - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8:[b]64bit:[/b] - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8:[b]64bit:[/b] - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8:[b]64bit:[/b] - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.) O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL (Microsoft Corporation) O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O15 - HKCU\..Trusted Ranges: Range1979 ([http] in Zaufane witryny) O16:[b]64bit:[/b] - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25) O16:[b]64bit:[/b] - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25) O16:[b]64bit:[/b] - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.4.1) O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.4.1) O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{606954E7-1FBE-491A-A331-F34B869A5AD7}: NameServer = 208.67.222.222,208.67.220.220 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6BB007D7-E81C-410F-97EE-A12F94E59AAA}: NameServer = 198.153.192.40,198.153.194.40 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EECA040E-1FF4-4828-851B-E6E94BEB7937}: DhcpNameServer = 62.179.1.62 62.179.1.63 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EECA040E-1FF4-4828-851B-E6E94BEB7937}: NameServer = 198.153.192.40,198.153.194.40 O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\skype-ie-addon-data - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\viprotocol - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\14.2.0\ViProtocol.dll () O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (C:\PROGRA~2\WIA6EB~1\Datamngr\datamngr.dll) - C:\PROGRA~2\WIA6EB~1\Datamngr\datamngr.dll (Bandoo Media, inc) O20 - AppInit_DLLs: (C:\PROGRA~2\WIA6EB~1\Datamngr\IEBHO.dll) - C:\PROGRA~2\WIA6EB~1\Datamngr\IEBHO.dll (Bandoo Media, inc) O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2013-03-02 13:12:32 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2012-07-17 00:33:02 | 000,000,032 | -H-- | M] () - D:\Autorun.inf -- [ NTFS ] O32 - AutoRun File - [2006-09-18 22:43:36 | 000,000,024 | ---- | M] () - E:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2009-02-12 19:21:43 | 000,000,094 | R--- | M] () - I:\autorun.inf -- [ CDFS ] O33 - MountPoints2\{3d8014ee-838c-11e2-b710-001fd0ad4e65}\Shell - "" = AutoRun O33 - MountPoints2\{3d8014ee-838c-11e2-b710-001fd0ad4e65}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\Instalator.exe O33 - MountPoints2\{76eb5eef-c969-11e0-8df6-001fd0ad4e65}\Shell - "" = AutoRun O33 - MountPoints2\{76eb5eef-c969-11e0-8df6-001fd0ad4e65}\Shell\AutoRun\command - "" = L:\AutoRun.exe O33 - MountPoints2\{76eb5efd-c969-11e0-8df6-001fd0ad4e65}\Shell - "" = AutoRun O33 - MountPoints2\{76eb5efd-c969-11e0-8df6-001fd0ad4e65}\Shell\AutoRun\command - "" = L:\AutoRun.exe O33 - MountPoints2\{76eb5f1a-c969-11e0-8df6-001fd0ad4e65}\Shell - "" = AutoRun O33 - MountPoints2\{76eb5f1a-c969-11e0-8df6-001fd0ad4e65}\Shell\AutoRun\command - "" = L:\AutoRun.exe O33 - MountPoints2\{8b9d1326-3b78-11e0-b828-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{8b9d1326-3b78-11e0-b828-806e6f6e6963}\Shell\AutoRun\command - "" = autorun.exe O33 - MountPoints2\{9ce62540-b164-11e1-b5b2-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{9ce62540-b164-11e1-b5b2-806e6f6e6963}\Shell\AutoRun\command - "" = I:\talk-now\talknow.exe \talk-now\data\startup.ast O33 - MountPoints2\{9ce62540-b164-11e1-b5b2-806e6f6e6963}\Shell\install\command - "" = I:\install.exe \data\startup.ast O33 - MountPoints2\{9ce62540-b164-11e1-b5b2-806e6f6e6963}\Shell\readme\command - "" = notepad \data\readme.txt O33 - MountPoints2\{a0b3e9bb-a3e8-11e0-9123-001fd0ad4e65}\Shell - "" = AutoRun O33 - MountPoints2\{a0b3e9bb-a3e8-11e0-9123-001fd0ad4e65}\Shell\AutoRun\command - "" = L:\NokiaPCIA_Autorun.exe O33 - MountPoints2\{a400460f-ca2b-11e0-9673-001fd0ad4e65}\Shell - "" = AutoRun O33 - MountPoints2\{a400460f-ca2b-11e0-9673-001fd0ad4e65}\Shell\AutoRun\command - "" = L:\AutoRun.exe O33 - MountPoints2\{b3e52a1d-12a1-11e1-8c71-001fd0ad4e65}\Shell - "" = AutoRun O33 - MountPoints2\{b3e52a1d-12a1-11e1-8c71-001fd0ad4e65}\Shell\AutoRun\command - "" = N:\LaunchU3.exe -a O33 - MountPoints2\J\Shell - "" = AutoRun O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a O33 - MountPoints2\L\Shell - "" = AutoRun O33 - MountPoints2\L\Shell\AutoRun\command - "" = L:\LaunchU3.exe -a O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2013-03-26 22:15:28 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\milosz\Desktop\OTL.exe [2013-03-26 18:37:00 | 000,000,000 | ---D | C] -- C:\Users\milosz\Doctor Web [2013-03-23 19:07:44 | 000,000,000 | ---D | C] -- C:\Users\milosz\Desktop\7tv [2013-03-23 12:03:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Asmedia Technology [2013-03-23 12:03:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ASM104xUSB3 [2013-03-21 02:17:13 | 000,000,000 | ---D | C] -- C:\Users\milosz\Desktop\gotowe [2013-03-20 21:07:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle ES2 [2013-03-20 20:34:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS6 [2013-03-20 19:00:50 | 000,000,000 | ---D | C] -- C:\Users\milosz\CS5.5 Master Collection [2013-03-20 18:07:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird [2013-03-20 17:59:47 | 000,000,000 | ---D | C] -- C:\Users\milosz\Desktop\2013.03.19 Koncert muzyczny [2013-03-16 18:23:48 | 000,000,000 | ---D | C] -- C:\Users\milosz\Desktop\gfg [2013-03-16 17:58:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome [2013-03-16 17:55:54 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Secure Search [2013-03-16 17:40:48 | 000,000,000 | ---D | C] -- C:\Users\milosz\Desktop\SourceMM [WINDOWS] - www.Grajkownia.com [2013-03-16 17:38:20 | 000,000,000 | ---D | C] -- C:\Users\milosz\Desktop\Paczka admina - www.Grajkownia.com [2013-03-15 21:42:41 | 000,000,000 | ---D | C] -- C:\Users\milosz\Desktop\heheszky [2013-03-08 15:56:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG [2013-03-06 00:14:54 | 000,000,000 | ---D | C] -- C:\Users\milosz\Desktop\add2 [2013-03-06 00:08:51 | 000,000,000 | ---D | C] -- C:\Users\milosz\Desktop\add [2013-03-06 00:07:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMX Mod X [2013-03-06 00:07:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMX Mod X [2013-03-06 00:06:11 | 000,000,000 | ---D | C] -- C:\Users\milosz\Desktop\kab [2013-03-06 00:02:16 | 000,000,000 | ---D | C] -- C:\Users\milosz\Desktop\quick [2013-03-05 21:08:05 | 000,000,000 | ---D | C] -- C:\Users\milosz\Desktop\USB Drive Boot Files [2013-03-05 16:01:00 | 001,096,688 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctEFA64.sys [2013-03-05 16:01:00 | 000,453,896 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctDS64.sys [2013-03-05 16:00:59 | 000,339,608 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctgntdi64.sys [2013-03-05 16:00:59 | 000,145,432 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctwfpfilter64.sys [2013-03-05 16:00:52 | 000,367,912 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\PCTCore64.sys [2013-03-05 16:00:50 | 000,230,952 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\PCTSD64.sys [2013-03-05 16:00:50 | 000,014,776 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctBTFix64.sys [2013-03-05 16:00:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security [2013-03-05 16:00:48 | 000,092,896 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctplsg64.sys [2013-03-05 16:00:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PC Tools Security [2013-03-05 16:00:40 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools [2013-03-05 16:00:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PC Tools [2013-03-04 23:36:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CesarFTP [2013-03-04 23:36:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CesarFTP [2013-03-04 23:21:17 | 000,000,000 | ---D | C] -- C:\Users\milosz\AppData\Roaming\FileZilla [2013-03-04 23:21:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FileZilla FTP Client [2013-03-04 23:06:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla Server [2013-03-04 23:06:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FileZilla Server [2013-03-03 11:21:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner [2013-03-03 00:14:30 | 000,000,000 | ---D | C] -- C:\Users\milosz\AppData\Local\AVG Secure Search [2013-03-03 00:13:58 | 000,000,000 | ---D | C] -- C:\Users\milosz\AppData\Roaming\AVG2013 [2013-03-03 00:13:57 | 000,000,000 | ---D | C] -- C:\Users\milosz\AppData\Local\Avg2013 [2013-03-03 00:03:53 | 000,039,768 | ---- | C] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys [2013-03-03 00:03:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVG Secure Search [2013-03-03 00:03:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG Secure Search [2013-03-03 00:00:35 | 000,000,000 | -H-D | C] -- C:\$AVG [2013-03-03 00:00:32 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2013 [2013-03-02 23:59:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG [2013-03-02 23:48:57 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files [2013-03-02 23:48:57 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData [2013-03-02 23:12:06 | 000,283,200 | ---- | C] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys [2013-03-02 22:57:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pakiet Bezpieczeństwa UPC [2013-03-02 22:54:55 | 000,000,000 | ---D | C] -- C:\ProgramData\fssg [2013-03-02 22:49:39 | 000,000,000 | ---D | C] -- C:\ProgramData\f-secure [2013-03-02 18:34:13 | 000,000,000 | ---D | C] -- C:\Windows\Simple Port Forwarding [2013-03-02 18:34:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Simple Port Forwarding [2013-03-02 18:16:22 | 000,000,000 | ---D | C] -- C:\Users\milosz\Desktop\cfg [2013-03-02 17:04:19 | 000,000,000 | ---D | C] -- C:\Users\milosz\Desktop\addons [2013-03-02 17:01:40 | 000,000,000 | ---D | C] -- C:\Users\milosz\Desktop\ddons [2013-03-02 15:15:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PFConfig [2013-03-02 14:49:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Portforward.com [2013-03-02 14:49:13 | 000,000,000 | ---D | C] -- C:\Users\milosz\Desktop\PFPortChecker [2013-03-02 14:45:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Ask [2013-03-02 13:22:40 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2013-03-02 13:12:03 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group [2013-03-02 11:47:25 | 000,000,000 | ---D | C] -- C:\css [2013-02-27 17:52:36 | 000,000,000 | ---D | C] -- C:\Users\milosz\Desktop\whwhwh [2013-02-27 17:46:10 | 000,000,000 | ---D | C] -- C:\Users\milosz\Documents\Skype Voice Records [2013-02-27 17:46:10 | 000,000,000 | ---D | C] -- C:\Users\milosz\Documents\Clownfish Avatars [2013-02-27 17:46:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clownfish [2013-02-27 17:46:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Clownfish [2009-12-07 14:12:48 | 132,493,312 | ---- | C] (SoftMaker Software GmbH) -- C:\Users\milosz\AppData\Roaming\ofw2010.exe [5 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ] [5 C:\*.tmp files -> C:\*.tmp -> ] [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [10 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2013-03-26 22:15:31 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\milosz\Desktop\OTL.exe [2013-03-26 22:01:00 | 000,001,048 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013-03-26 21:54:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013-03-26 21:45:05 | 000,168,365 | ---- | M] () -- C:\Users\milosz\Desktop\public_dns_server_tool_2.0.zip [2013-03-26 20:33:48 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013-03-26 20:33:48 | 000,021,072 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013-03-26 20:25:40 | 000,001,044 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013-03-26 20:25:37 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl [2013-03-26 20:25:34 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013-03-26 20:25:31 | 535,683,071 | -HS- | M] () -- C:\hiberfil.sys [2013-03-26 19:31:00 | 000,001,082 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2664957750-3405693087-2689903079-1000UA.job [2013-03-26 19:29:54 | 000,980,480 | ---- | M] () -- C:\Users\milosz\Desktop\MicrosoftFixit50267.msi [2013-03-26 19:29:30 | 000,000,855 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.old [2013-03-26 18:36:48 | 114,074,520 | ---- | M] () -- C:\Users\milosz\Desktop\drweb-cureit.exe [2013-03-26 18:33:44 | 000,640,072 | ---- | M] () -- C:\Users\milosz\Desktop\Dr.WEB-CureIt(12976).exe [2013-03-26 17:54:07 | 001,368,453 | ---- | M] () -- C:\Windows\SysNative\drivers\Cat.DB [2013-03-24 18:05:35 | 004,970,680 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2013-03-24 01:31:04 | 000,001,060 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2664957750-3405693087-2689903079-1000Core.job [2013-03-23 21:34:17 | 000,001,496 | ---- | M] () -- C:\Users\milosz\AppData\Local\Adobe Zapisz dla Internetu 13.0 Prefs [2013-03-23 19:30:14 | 000,013,150 | ---- | M] () -- C:\Users\milosz\Desktop\7tvCDR.cdr [2013-03-23 19:26:17 | 000,153,190 | ---- | M] () -- C:\Users\milosz\Desktop\7tv.cpt [2013-03-23 18:59:25 | 000,026,819 | ---- | M] () -- C:\Users\milosz\Desktop\7tv.JPG [2013-03-23 18:49:45 | 000,000,021 | ---- | M] () -- C:\Windows\SurCode.INI [2013-03-22 18:59:30 | 001,670,628 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013-03-22 18:59:30 | 000,740,314 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat [2013-03-22 18:59:30 | 000,654,522 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013-03-22 18:59:30 | 000,155,342 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat [2013-03-22 18:59:30 | 000,121,794 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013-03-21 17:12:53 | 000,118,452 | -H-- | M] () -- C:\Windows\SysWow64\mlfcache.dat [2013-03-20 21:07:04 | 000,002,026 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk [2013-03-16 19:33:26 | 000,000,928 | ---- | M] () -- C:\Users\milosz\Desktop\srcds — skrót.lnk [2013-03-15 21:59:14 | 000,067,833 | ---- | M] () -- C:\Users\milosz\Documents\Bez_nazwy (2).wma [2013-03-08 15:56:25 | 000,000,995 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2013.lnk [2013-03-08 15:52:08 | 000,000,004 | ---- | M] () -- C:\Users\milosz\AppData\Roaming\skype.ini [2013-03-06 00:07:31 | 000,001,156 | ---- | M] () -- C:\Users\milosz\Desktop\AMX Mod X Studio.lnk [2013-03-05 23:06:33 | 000,001,881 | ---- | M] () -- C:\Users\milosz\Desktop\admins_simple.ini [2013-03-05 21:12:40 | 000,000,448 | RHS- | M] () -- C:\ProgramData\ntuser.pol [2013-03-05 20:16:55 | 000,002,534 | ---- | M] () -- C:\Users\milosz\Desktop\Windows 7 USB DVD Download Tool.lnk [2013-03-05 20:01:32 | 000,001,329 | ---- | M] () -- C:\Users\milosz\Desktop\Szkoła Hakerów - Odtwarzacz filmów instruktażowych.lnk [2013-03-05 20:01:31 | 000,001,855 | ---- | M] () -- C:\Windows\SysWow64\odtwarzacz.csh [2013-03-05 16:00:50 | 000,002,098 | ---- | M] () -- C:\Users\Public\Desktop\PC Tools Spyware Doctor.lnk [2013-03-04 23:36:11 | 000,000,947 | ---- | M] () -- C:\Users\milosz\Desktop\CesarFTP.lnk [2013-03-04 23:11:12 | 000,001,850 | ---- | M] () -- C:\Users\milosz\Documents\certificate.crt [2013-03-04 23:06:14 | 000,002,087 | ---- | M] () -- C:\Users\Public\Desktop\FileZilla Server Interface.lnk [2013-03-03 11:21:34 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2013-03-03 00:03:00 | 000,039,768 | ---- | M] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys [2013-03-02 23:24:14 | 000,001,190 | ---- | M] () -- C:\Users\milosz\Desktop\PFPortChecker.lnk [2013-03-02 23:12:06 | 000,283,200 | ---- | M] (DT Soft Ltd) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys [2013-03-02 23:00:58 | 000,118,149 | ---- | M] () -- C:\Users\milosz\Desktop\wmpChrome (1).crx [2013-03-02 22:59:01 | 001,704,348 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2013-03-02 18:37:53 | 000,001,974 | ---- | M] () -- C:\Users\milosz\Desktop\Simple Port Forwarding.lnk [2013-03-02 15:15:01 | 000,001,051 | ---- | M] () -- C:\Users\milosz\Desktop\PFConfig.lnk [2013-03-02 14:55:11 | 000,001,059 | ---- | M] () -- C:\server.cfg [2013-03-02 13:12:32 | 000,000,000 | ---- | M] () -- C:\autoexec.bat [2013-02-27 17:46:05 | 000,001,905 | ---- | M] () -- C:\Users\milosz\Desktop\Clownfish.lnk [2013-02-24 22:47:17 | 000,001,064 | ---- | M] () -- C:\Users\milosz\Desktop\server.cfg [5 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ] [5 C:\*.tmp files -> C:\*.tmp -> ] [2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [10 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2013-03-26 21:45:04 | 000,168,365 | ---- | C] () -- C:\Users\milosz\Desktop\public_dns_server_tool_2.0.zip [2013-03-26 19:29:51 | 000,980,480 | ---- | C] () -- C:\Users\milosz\Desktop\MicrosoftFixit50267.msi [2013-03-26 18:36:17 | 114,074,520 | ---- | C] () -- C:\Users\milosz\Desktop\drweb-cureit.exe [2013-03-26 18:33:40 | 000,640,072 | ---- | C] () -- C:\Users\milosz\Desktop\Dr.WEB-CureIt(12976).exe [2013-03-23 21:34:17 | 000,001,496 | ---- | C] () -- C:\Users\milosz\AppData\Local\Adobe Zapisz dla Internetu 13.0 Prefs [2013-03-23 19:30:13 | 000,013,150 | ---- | C] () -- C:\Users\milosz\Desktop\7tvCDR.cdr [2013-03-23 19:26:16 | 000,153,190 | ---- | C] () -- C:\Users\milosz\Desktop\7tv.cpt [2013-03-23 18:59:23 | 000,026,819 | ---- | C] () -- C:\Users\milosz\Desktop\7tv.JPG [2013-03-20 21:07:04 | 000,002,465 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller X.lnk [2013-03-20 21:07:04 | 000,002,453 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat X Pro.lnk [2013-03-20 21:07:04 | 000,002,026 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk [2013-03-20 20:38:06 | 000,000,997 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk [2013-03-20 19:00:43 | 000,000,744 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Download Assistant.lnk [2013-03-15 21:59:14 | 000,067,833 | ---- | C] () -- C:\Users\milosz\Documents\Bez_nazwy (2).wma [2013-03-06 00:07:31 | 000,001,156 | ---- | C] () -- C:\Users\milosz\Desktop\AMX Mod X Studio.lnk [2013-03-05 23:06:28 | 000,001,881 | ---- | C] () -- C:\Users\milosz\Desktop\admins_simple.ini [2013-03-05 21:12:40 | 000,000,448 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2013-03-05 20:16:55 | 000,002,534 | ---- | C] () -- C:\Users\milosz\Desktop\Windows 7 USB DVD Download Tool.lnk [2013-03-05 20:01:32 | 000,001,329 | ---- | C] () -- C:\Users\milosz\Desktop\Szkoła Hakerów - Odtwarzacz filmów instruktażowych.lnk [2013-03-05 16:01:02 | 001,368,453 | ---- | C] () -- C:\Windows\SysNative\drivers\Cat.DB [2013-03-05 16:00:50 | 000,002,098 | ---- | C] () -- C:\Users\Public\Desktop\PC Tools Spyware Doctor.lnk [2013-03-04 23:36:11 | 000,000,947 | ---- | C] () -- C:\Users\milosz\Desktop\CesarFTP.lnk [2013-03-04 23:11:12 | 000,001,850 | ---- | C] () -- C:\Users\milosz\Documents\certificate.crt [2013-03-04 23:06:14 | 000,002,087 | ---- | C] () -- C:\Users\Public\Desktop\FileZilla Server Interface.lnk [2013-03-03 11:21:34 | 000,000,822 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2013-03-03 00:04:30 | 000,000,995 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2013.lnk [2013-03-02 23:00:57 | 000,118,149 | ---- | C] () -- C:\Users\milosz\Desktop\wmpChrome (1).crx [2013-03-02 18:34:14 | 000,001,974 | ---- | C] () -- C:\Users\milosz\Desktop\Simple Port Forwarding.lnk [2013-03-02 17:38:06 | 009,433,681 | ---- | C] () -- C:\creep.mp3 [2013-03-02 17:34:13 | 005,169,132 | ---- | C] () -- C:\sopy.m4a [2013-03-02 15:15:01 | 000,001,051 | ---- | C] () -- C:\Users\milosz\Desktop\PFConfig.lnk [2013-03-02 14:56:30 | 000,000,928 | ---- | C] () -- C:\Users\milosz\Desktop\srcds — skrót.lnk [2013-03-02 14:55:11 | 000,001,059 | ---- | C] () -- C:\server.cfg [2013-03-02 14:49:13 | 000,001,190 | ---- | C] () -- C:\Users\milosz\Desktop\PFPortChecker.lnk [2013-03-02 13:12:32 | 000,000,000 | ---- | C] () -- C:\autoexec.bat [2013-03-02 11:45:24 | 000,000,004 | ---- | C] () -- C:\Users\milosz\AppData\Roaming\skype.ini [2013-02-27 17:46:05 | 000,001,905 | ---- | C] () -- C:\Users\milosz\Desktop\Clownfish.lnk [2013-02-24 22:47:17 | 000,001,064 | ---- | C] () -- C:\Users\milosz\Desktop\server.cfg [2013-01-23 18:54:14 | 000,000,061 | -HS- | C] () -- C:\Windows\cnerolf.bin [2013-01-06 23:51:53 | 000,000,589 | ---- | C] () -- C:\Windows\tlknw11.ini [2012-11-14 21:28:12 | 000,000,459 | ---- | C] () -- C:\Users\milosz\Filmy (F) — skrót.lnk [2012-05-24 19:58:32 | 000,000,024 | ---- | C] () -- C:\Windows\mskl2.ini [2012-05-04 14:40:19 | 000,258,048 | ---- | C] () -- C:\Windows\SysWow64\libFLAC.dll [2012-03-09 05:31:26 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat [2012-03-09 05:31:26 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat [2012-02-19 13:32:26 | 000,000,093 | ---- | C] () -- C:\Users\milosz\AppData\Roaming\Movies2iPhone.ini [2012-02-10 21:05:01 | 000,008,192 | ---- | C] () -- C:\Users\milosz\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-01-31 06:00:24 | 000,016,896 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll [2012-01-27 19:47:22 | 000,110,456 | ---- | C] () -- C:\Users\milosz\g2ax_customer_downloadhelper_win32_x86.exe [2011-12-11 09:43:08 | 000,280,904 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe [2011-12-11 09:42:41 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe [2011-12-05 15:47:36 | 004,070,912 | ---- | C] () -- C:\Windows\SysWow64\PhotoLooksRenderer.dll [2011-12-04 10:12:20 | 000,001,456 | ---- | C] () -- C:\Users\milosz\AppData\Local\Adobe Save for Web 12.0 Prefs [2011-11-16 16:16:22 | 004,131,840 | ---- | C] () -- C:\Windows\SysWow64\LS3Renderer.dll [2011-09-13 00:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat [2011-08-30 14:52:17 | 000,484,352 | ---- | C] () -- C:\Windows\SysWow64\lame_enc.dll [2011-08-29 09:39:22 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\CmdLineExt03.dll [2011-08-23 09:19:52 | 000,118,452 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat [2011-08-18 08:57:33 | 000,187,125 | ---- | C] () -- C:\Users\milosz\raty.zip [2011-08-18 08:56:19 | 000,293,899 | ---- | C] () -- C:\Users\milosz\raty.jpg [2011-08-09 11:42:17 | 000,034,308 | ---- | C] () -- C:\Windows\SysWow64\BASSMOD.dll [2011-08-04 12:08:04 | 000,000,014 | ---- | C] () -- C:\Windows\SysWow64\systeminfo.dll [2011-07-15 22:31:56 | 000,000,000 | ---- | C] () -- C:\Users\milosz\AppData\Local\{D507F0CA-6B7A-4365-872F-97D3BC61D6A5} [2011-07-12 14:35:10 | 000,000,000 | ---- | C] () -- C:\Users\milosz\AppData\Local\{CB9BFAAB-80C5-4C4E-BCAA-16D3E6DB7C9E} [2011-06-28 11:46:36 | 000,000,116 | ---- | C] () -- C:\Windows\NeroDigital.ini [2011-06-27 11:00:47 | 000,000,021 | ---- | C] () -- C:\Windows\SurCode.INI [2011-06-19 18:04:15 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat [2011-05-25 19:43:32 | 001,704,348 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2011-04-26 13:38:05 | 000,007,867 | ---- | C] () -- C:\Windows\Irremote.ini [2011-04-26 13:37:56 | 000,001,024 | ---- | C] () -- C:\Users\milosz\.rnd [2011-04-08 21:23:53 | 000,000,000 | ---- | C] () -- C:\Users\milosz\AppData\Roaming\chrtmp [2011-04-08 21:17:23 | 000,000,048 | ---- | C] () -- C:\Users\milosz\AppData\Local\73648-88365-27475-00IP7-22847 [2011-04-07 18:23:09 | 000,000,008 | -HS- | C] () -- C:\Users\milosz\AppData\Local\systemCurUses [2011-04-07 18:23:09 | 000,000,006 | -HS- | C] () -- C:\Users\milosz\AppData\Local\systemHdID [2011-03-28 22:06:40 | 000,000,264 | ---- | C] () -- C:\Users\milosz\AppData\Roaming\default.rss [2011-02-20 14:49:14 | 000,007,597 | ---- | C] () -- C:\Users\milosz\AppData\Local\Resmon.ResmonCfg [color=#E56717]========== ZeroAccess Check ==========[/color] [2009-07-14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2010-11-21 04:23:55 | 014,174,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2010-11-21 04:24:02 | 012,872,192 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== LOP Check ==========[/color] [2011-09-26 19:43:00 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Ashampoo [2012-04-30 00:08:02 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\ASkySoft [2011-09-26 19:45:19 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Astroburn Lite [2013-03-03 00:13:58 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\AVG2013 [2012-05-01 21:15:26 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\BlackBean [2011-07-15 22:38:47 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Canon [2012-02-24 20:52:00 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\com.adobe.dmp.contentviewer [2012-02-20 22:47:18 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant [2011-04-07 19:38:59 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\DAEMON Tools [2012-06-08 22:13:57 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\DAEMON Tools Lite [2011-04-07 19:38:59 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\DAEMON Tools Pro [2012-02-15 20:25:34 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\DMCache [2012-06-10 13:24:46 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\EurekaLog [2011-08-31 11:57:09 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\EXIF Date Changer [2011-04-20 20:16:50 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Expressivo [2013-03-04 23:38:40 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\FileZilla [2011-03-11 14:58:27 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Fonts [2012-09-23 01:49:58 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\foobar2000 [2011-08-30 14:52:30 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\FreeAudioPack [2011-06-26 18:51:14 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\FreeFLVConverter [2011-03-08 15:54:36 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Gadu-Gadu 10 [2013-02-23 00:44:13 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\GHISLER [2011-03-22 15:50:46 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Greyfirst [2012-12-08 12:22:13 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\HandBrake [2011-06-11 22:09:28 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\HDRsoft [2013-03-17 21:55:30 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\HLSW [2011-09-26 20:41:22 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\ImgBurn [2011-05-03 11:24:31 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Jubler [2011-03-11 15:32:48 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Leadertech [2012-11-01 18:50:52 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Milestone [2010-05-31 08:21:07 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\MPEG Streamclip [2012-05-04 14:42:13 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\NapiProjekt [2011-11-12 13:28:01 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\NeatImage SL [2011-03-28 18:48:44 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\NeatVideo SV 64 [2012-06-18 18:50:20 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Need for Speed World [2011-02-24 16:49:47 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\OpenOffice.org [2013-01-17 14:58:30 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Origin [2011-02-18 21:14:53 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\PACE Anti-Piracy [2011-07-01 18:19:55 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\PC Suite [2011-12-17 21:21:29 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\PhotoScape [2011-03-09 19:08:25 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Publish Providers [2012-02-20 22:56:18 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Red Giant Link [2011-02-19 16:30:04 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\RigNRoll_pol [2011-04-30 12:54:00 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Samsung [2012-10-02 19:41:45 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\SharePod [2011-11-26 09:23:44 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\SoftGrid Client [2011-04-12 17:33:34 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Sony [2012-02-14 22:08:54 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Sony Creative Software Inc [2011-08-28 23:46:25 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Sports Interactive [2011-02-18 19:55:46 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1 [2011-05-26 11:16:59 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\TeamViewer [2011-11-12 12:01:57 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\The Creative Assembly [2012-12-11 19:17:38 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Theta [2010-06-02 05:42:59 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Thinstall [2011-02-18 19:44:29 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Thunderbird [2011-05-25 19:44:37 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\TP [2011-02-26 11:56:36 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\Ubisoft [2013-03-26 20:25:46 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\uTorrent [2012-12-27 12:09:23 | 000,000,000 | ---D | M] -- C:\Users\milosz\AppData\Roaming\XBMC [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 166 bytes -> C:\ProgramData\TEMP:DFC5A2B2 @Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:8E236DBE @Alternate Data Stream - 1312 bytes -> C:\ProgramData\Microsoft:RJHbM0Nw4pwWg0DtNIkJ6c2FsXAm @Alternate Data Stream - 1198 bytes -> C:\Users\milosz\AppData\Local\Temp:m6Twxls7AdpPsecMwzqwboYP @Alternate Data Stream - 1101 bytes -> C:\ProgramData\Microsoft:4z4x60iw7PwXQV0vNcULVQ @Alternate Data Stream - 1093 bytes -> C:\Users\milosz\AppData\Local\qrVfe2l1lgE:IwXV4noSItk57K1PzB7kuCK1 < End of report >