OTL logfile created on: 2013-10-04 14:13:43 - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Piotr\Pulpit Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,99 Gb Total Physical Memory | 1,36 Gb Available Physical Memory | 68,42% Memory free 3,83 Gb Paging File | 3,31 Gb Available in Paging File | 86,35% Paging File free Paging file location(s): D:\pagefile.sys 0 0 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 38,34 Gb Total Space | 16,63 Gb Free Space | 43,36% Space Free | Partition Type: NTFS Drive D: | 38,34 Gb Total Space | 25,39 Gb Free Space | 66,23% Space Free | Partition Type: NTFS Drive F: | 7,45 Gb Total Space | 1,10 Gb Free Space | 14,77% Space Free | Partition Type: FAT32 Computer Name: UG-7 | User Name: Piotr | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 360 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2013-10-04 13:58:16 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Piotr\Pulpit\OTL.exe PRC - [2013-09-18 14:48:46 | 007,201,280 | ---- | M] () -- D:\PS\mikropesel.exe PRC - [2012-05-08 15:26:40 | 000,524,800 | ---- | M] () -- C:\Program Files\CryptoTech\CryptoCard\CCMonitor.exe PRC - [2011-09-29 23:28:22 | 000,490,696 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files\Kaspersky Lab\Kaspersky Endpoint Security 8 for Windows\avp.exe PRC - [2008-04-14 19:21:16 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2002-09-20 16:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe PRC - [1998-10-17 08:00:00 | 000,983,040 | ---- | M] (Nico Mak Computing, Inc.) -- C:\Program Files\WinZip\WINZIP32.EXE [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2013-09-18 14:48:46 | 007,201,280 | ---- | M] () -- D:\PS\mikropesel.exe MOD - [2013-06-21 07:53:34 | 000,278,928 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Endpoint Security 8 for Windows\device_control_task.ppl MOD - [2013-06-21 07:53:11 | 000,311,696 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Endpoint Security 8 for Windows\network_services.dll MOD - [2013-06-21 07:53:09 | 001,221,008 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Endpoint Security 8 for Windows\enterprise_application_control.dll MOD - [2013-06-21 07:52:59 | 000,262,544 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Endpoint Security 8 for Windows\device_control.dll MOD - [2012-05-08 15:26:40 | 000,524,800 | ---- | M] () -- C:\Program Files\CryptoTech\CryptoCard\CCMonitor.exe MOD - [2011-09-29 23:26:46 | 000,463,248 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Endpoint Security 8 for Windows\WebControlTask.ppl MOD - [2011-09-29 23:25:46 | 000,143,760 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Endpoint Security 8 for Windows\sax_xml_parser.dll MOD - [2011-09-29 23:25:06 | 000,430,480 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Endpoint Security 8 for Windows\FileCategorizer.dll MOD - [2011-09-29 23:24:52 | 000,422,288 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Endpoint Security 8 for Windows\categorizer_facade.dll MOD - [2011-09-29 23:24:46 | 000,283,024 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Endpoint Security 8 for Windows\am_facade.dll MOD - [2003-08-29 11:12:52 | 000,094,274 | ---- | M] () -- C:\WINDOWS\system32\HPBHEALR.DLL MOD - [2001-10-28 18:42:30 | 000,116,224 | ---- | M] () -- C:\WINDOWS\system32\pdfcmnnt.dll MOD - [1999-11-12 05:11:00 | 000,589,312 | ---- | M] () -- C:\Program Files\Common Files\Borland Shared\BDE\IDAPI32.DLL MOD - [1999-11-12 05:11:00 | 000,464,896 | ---- | M] () -- C:\Program Files\Common Files\Borland Shared\BDE\IDSQL32.DLL MOD - [1999-11-12 05:11:00 | 000,255,488 | ---- | M] () -- C:\Program Files\Common Files\Borland Shared\BDE\IDPDX32.DLL MOD - [1999-11-12 05:11:00 | 000,139,264 | ---- | M] () -- C:\Program Files\Common Files\Borland Shared\BDE\IDBAT32.DLL MOD - [1999-11-12 05:11:00 | 000,116,736 | ---- | M] () -- C:\Program Files\Common Files\Borland Shared\BDE\IDR20009.DLL MOD - [1999-11-12 05:11:00 | 000,101,376 | ---- | M] () -- C:\Program Files\Common Files\Borland Shared\BDE\BANTAM.DLL MOD - [1998-10-17 08:00:00 | 000,033,792 | ---- | M] () -- C:\Program Files\WinZip\WZSHLEXT.DLL [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [Auto | Stopped] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.1.7\ToolbarUpdater.exe -- (vToolbarUpdater14.1.7) SRV - [2013-10-02 07:23:01 | 000,118,680 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2013-09-21 15:18:31 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2011-09-29 23:28:22 | 000,490,696 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\Program Files\Kaspersky Lab\Kaspersky Endpoint Security 8 for Windows\avp.exe -- (AVP) SRV - [2002-09-20 16:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- C:\Program Files\iSafe\iSafeNetFilter.sys -- (iSafeNetFilter) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\Piotr\USTAWI~1\Temp\fgtdapod.sys -- (fgtdapod) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys -- (esgiguard) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\aksusb.sys -- (aksusb) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\akshasp.sys -- (akshasp) DRV - [2013-06-21 07:53:45 | 000,584,496 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF) DRV - [2013-02-11 09:17:00 | 000,031,576 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtpx86.sys -- (avgtp) DRV - [2011-09-01 16:25:38 | 000,037,168 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klim5.sys -- (klim5) DRV - [2011-08-31 18:06:54 | 000,050,992 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\klfltdev.sys -- (KLFLTDEV) DRV - [2011-08-18 18:11:46 | 000,013,104 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\kl2.sys -- (kl2) DRV - [2011-08-18 18:11:42 | 000,135,984 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\kl1.sys -- (KL1) DRV - [2011-06-16 12:21:42 | 000,059,520 | ---- | M] (SCM Microsystems Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SCR3XX2K.sys -- (SCR3XX2K) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Reg Error: Value error. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = Reg Error: Value error. IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKLM\..\SearchScopes,DefaultScope = {0191A6B0-1154-4C22-9182-23A95BBE92D9} IE - HKLM\..\SearchScopes\{0191A6B0-1154-4C22-9182-23A95BBE92D9}: "URL" = http://www.google.com/search?q={searchTerms} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKLM\..\SearchScopes\{0FC53DB6-3C70-43CE-BE8F-2BBA988A00FC}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0191A6B0-1154-4C22-9182-23A95BBE92D9} IE - HKU\.DEFAULT\..\SearchScopes\{0191A6B0-1154-4C22-9182-23A95BBE92D9}: "URL" = http://www.google.com/search?q={searchTerms} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0191A6B0-1154-4C22-9182-23A95BBE92D9} IE - HKU\S-1-5-18\..\SearchScopes\{0191A6B0-1154-4C22-9182-23A95BBE92D9}: "URL" = http://www.google.com/search?q={searchTerms} IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0191A6B0-1154-4C22-9182-23A95BBE92D9} IE - HKU\S-1-5-19\..\SearchScopes\{0191A6B0-1154-4C22-9182-23A95BBE92D9}: "URL" = http://www.google.com/search?q={searchTerms} IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0191A6B0-1154-4C22-9182-23A95BBE92D9} IE - HKU\S-1-5-20\..\SearchScopes\{0191A6B0-1154-4C22-9182-23A95BBE92D9}: "URL" = http://www.google.com/search?q={searchTerms} IE - HKU\S-1-5-21-1715567821-1647877149-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank IE - HKU\S-1-5-21-1715567821-1647877149-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKU\S-1-5-21-1715567821-1647877149-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = MSN Search IE - HKU\S-1-5-21-1715567821-1647877149-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.msn.com/spresults.aspx?q={searchTerms} IE - HKU\S-1-5-21-1715567821-1647877149-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchgol.com/?babsrc=HP_ss&mntrId=988E0013D43AA19C&affID=125032&tsp=5025 IE - HKU\S-1-5-21-1715567821-1647877149-682003330-1003\..\SearchScopes,DefaultScope = {0191A6B0-1154-4C22-9182-23A95BBE92D9} IE - HKU\S-1-5-21-1715567821-1647877149-682003330-1003\..\SearchScopes\{0191A6B0-1154-4C22-9182-23A95BBE92D9}: "URL" = http://www.google.com/search?q={searchTerms}&rlz=1I7PRFA_plPL421 IE - HKU\S-1-5-21-1715567821-1647877149-682003330-1003\..\SearchScopes\{95DE2918-7A55-46A8-9023-164E1D33334A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=IE8SRC&src=IE-SearchBox IE - HKU\S-1-5-21-1715567821-1647877149-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1715567821-1647877149-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.order.1: "Google" FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=827316" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://www.searchgol.com/?babsrc=HP_ss&mntrId=988E0013D43AA19C&affID=125032&tsp=5025" FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:24.0 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 24.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 24.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013-10-02 07:22:05 | 000,000,000 | ---D | M] [2009-03-16 09:22:25 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Piotr\Dane aplikacji\Mozilla\Extensions [2013-10-04 12:02:28 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Piotr\Dane aplikacji\Mozilla\Firefox\Profiles\n7e4o7sp.default\extensions [2012-09-06 08:49:35 | 000,020,591 | ---- | M] () (No name found) -- C:\Documents and Settings\Piotr\Dane aplikacji\Mozilla\Firefox\Profiles\n7e4o7sp.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi [2013-10-02 07:57:38 | 000,007,911 | ---- | M] () -- C:\Documents and Settings\Piotr\Dane aplikacji\Mozilla\Firefox\Profiles\n7e4o7sp.default\searchplugins\Google.xml [2013-10-02 07:21:59 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2013-10-02 07:21:51 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions [2013-10-02 07:23:08 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2012-11-12 13:28:36 | 000,305,744 | ---- | M] (Cisco WebEx LLC) -- C:\Program Files\mozilla firefox\plugins\ieatgpc.dll [2012-11-12 13:27:35 | 000,225,360 | ---- | M] (Cisco WebEx LLC) -- C:\Program Files\mozilla firefox\plugins\npatgpc.dll [color=#E56717]========== Chrome ==========[/color] CHR - default_search_provider: () CHR - default_search_provider: search_url = CHR - default_search_provider: suggest_url = CHR - homepage: http://www.searchgol.com/?babsrc=HP_ss&mntrId=988E0013D43AA19C&affID=125032&tsp=5025 CHR - Extension: No name found = C:\Documents and Settings\Piotr\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0\ O1 HOSTS File: ([2004-08-04 14:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Endpoint Security 8 for Windows\avp.exe (Kaspersky Lab ZAO) O4 - HKLM..\Run: [CryptoCard Suite Cert Monitor] C:\Program Files\CryptoTech\CryptoCard\CCMonitor.exe () O4 - HKLM..\Run: [tuto4pc_pl_17] File not found O4 - HKLM..\Run: [upt4pc_pl_17.exe] C:\Documents and Settings\Piotr\Ustawienia lokalne\Dane aplikacji\tuto4pc_pl_17\upt4pc_pl_17.exe -runhelper File not found O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 [2012-04-30 10:35:16 | 000,000,000 | ---D | M] O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 [2012-04-30 10:35:16 | 000,000,000 | ---D | M] O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 [2012-04-30 10:35:16 | 000,000,000 | ---D | M] O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1715567821-1647877149-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221 O7 - HKU\S-1-5-21-1715567821-1647877149-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 32 O7 - HKU\S-1-5-21-1715567821-1647877149-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1 [2012-04-30 10:35:16 | 000,000,000 | ---D | M] O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool) O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.) O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine) O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125052713734 (WUWebControl Class) O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} http://www.mks.com.pl/skaner/SkanerOnline.cab (MksSkanerOnline Class) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1371640959859 (MUWebControl Class) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.204.152.34 194.204.159.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{54740A30-0474-485E-8128-2C30FDACD140}: DhcpNameServer = 194.204.152.34 194.204.159.1 O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation) O20 - Winlogon\Notify\klogon: DllName - (C:\WINDOWS\system32\klogon.dll) - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO) O24 - Desktop Components:0 () - http://pejzaze.onet.pl/_i/hiszpania_plaze/012.jpg O24 - Desktop Components:1 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\Piotr\Moje dokumenty\Moje obrazy\tapety\WYSPA.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Piotr\Moje dokumenty\Moje obrazy\tapety\WYSPA.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2005-08-26 12:22:31 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{046ee6d9-3001-11df-bc9c-0013d43aa19c}\Shell\AutoRun\command - "" = CAROBNJAK//jellena.exe O33 - MountPoints2\{046ee6d9-3001-11df-bc9c-0013d43aa19c}\Shell\open\command - "" = CAROBNJAK//jellena.exe O33 - MountPoints2\{0f1b2e66-d756-11df-bd54-0013d43aa19c}\Shell - "" = AutoRun O33 - MountPoints2\{0f1b2e66-d756-11df-bd54-0013d43aa19c}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL nJSIj.ExE O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 360 Days ==========[/color] [2013-10-04 14:12:13 | 001,087,213 | ---- | C] (Farbar) -- C:\Documents and Settings\Piotr\Pulpit\FRST.exe [2013-10-04 14:12:13 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Piotr\Pulpit\OTL.exe [2013-10-04 12:40:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Dane aplikacji\BabSolution [2013-10-04 12:39:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Babylon [2013-10-04 11:35:29 | 000,000,000 | ---D | C] -- C:\Program Files\BonanzaDealsLive [2013-10-04 11:35:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Ustawienia lokalne\Dane aplikacji\BonanzaDealsLive [2013-10-04 11:35:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\BonanzaDealsLive [2013-10-04 11:35:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Ustawienia lokalne\Dane aplikacji\eorezo [2013-10-04 11:35:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Dane aplikacji\MetaCrawler [2013-10-04 11:34:24 | 000,000,000 | ---D | C] -- C:\Program Files\BonanzaDeals [2013-10-04 11:33:35 | 000,000,000 | ---D | C] -- C:\Program Files\metaCrawler [2013-10-04 11:33:28 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Piotr\Moje dokumenty\OTL.exe [2013-10-02 08:37:46 | 000,000,000 | ---D | C] -- C:\Ps131002 [2013-10-02 08:36:35 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Piotr\Recent [2013-10-02 07:21:49 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2013-09-27 13:28:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Pulpit\skróty [2013-09-27 13:10:14 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Installer Clean Up [2013-09-27 12:34:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Dane aplikacji\eCyber [2013-09-27 12:33:19 | 000,000,000 | ---D | C] -- C:\Program Files\iSafe [2013-09-27 12:33:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Dane aplikacji\iSafe [2013-08-30 08:06:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Moje dokumenty\KODEKS QWYBORCZY [2013-08-28 15:10:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Google Chrome [2013-08-28 15:09:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\CCleaner [2013-08-28 15:09:44 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2013-08-28 15:02:46 | 004,454,952 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\Piotr\Pulpit\ccsetup405.exe [2013-08-24 18:51:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Adobe [2013-08-24 11:22:41 | 000,014,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhid.sys [2013-08-14 10:03:39 | 000,000,000 | ---D | C] -- C:\Config.Msi [2013-08-09 03:56:32 | 000,389,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\themeui.dll [2013-08-02 10:27:42 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro [2013-08-02 10:27:40 | 000,000,000 | ---D | C] -- C:\rsit [2013-06-28 13:40:04 | 004,396,440 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\Piotr\Moje dokumenty\ccsetup403.exe [2013-06-20 14:17:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Kaspersky Endpoint Security 8 for Windows [2013-06-20 14:15:53 | 000,584,496 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys [2013-06-20 07:17:07 | 000,000,000 | ---D | C] -- C:\Ps111012 [2013-06-20 07:17:02 | 000,000,000 | ---D | C] -- C:\Ps110504 [2013-06-20 07:16:38 | 000,000,000 | ---D | C] -- C:\Ps110126 [2013-06-20 07:16:32 | 000,000,000 | ---D | C] -- C:\Ps100423 [2013-06-20 07:16:26 | 000,000,000 | ---D | C] -- C:\Ps100105 [2013-06-20 07:16:20 | 000,000,000 | ---D | C] -- C:\Ps091120 [2013-06-20 07:16:15 | 000,000,000 | ---D | C] -- C:\Ps091103 [2013-06-20 07:16:08 | 000,000,000 | ---D | C] -- C:\Ps091022 [2013-06-20 07:16:02 | 000,000,000 | ---D | C] -- C:\Ps091009 [2013-06-20 07:15:56 | 000,000,000 | ---D | C] -- C:\Ps091002 [2013-06-20 07:15:50 | 000,000,000 | ---D | C] -- C:\Ps090921 [2013-06-20 07:15:44 | 000,000,000 | ---D | C] -- C:\Ps090915 [2013-06-20 07:15:38 | 000,000,000 | ---D | C] -- C:\Ps090520 [2013-06-20 07:15:29 | 000,000,000 | ---D | C] -- C:\ps090424 [2013-06-20 07:13:53 | 000,000,000 | ---D | C] -- C:\Ps110405 [2013-06-20 07:13:49 | 000,000,000 | ---D | C] -- C:\Ps110331 [2013-06-20 07:12:19 | 000,000,000 | ---D | C] -- C:\Ps090216 [2013-06-20 07:12:14 | 000,000,000 | ---D | C] -- C:\Ps090116 [2013-06-20 07:12:10 | 000,000,000 | ---D | C] -- C:\Ps080728 [2013-06-20 07:12:06 | 000,000,000 | ---D | C] -- C:\Ps080312 [2013-06-20 07:12:03 | 000,000,000 | ---D | C] -- C:\Ps080130 [2013-06-20 07:12:00 | 000,000,000 | ---D | C] -- C:\Ps080125 [2013-06-19 14:47:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Ustawienia lokalne\Dane aplikacji\ApplicationHistory [2013-06-19 13:34:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTEMP [2013-06-18 09:38:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Moje dokumenty\REFERENDUM [2013-06-13 12:00:58 | 002,051,696 | ---- | C] (Bitdefender SRL) -- C:\Documents and Settings\Piotr\Ustawienia lokalne\Dane aplikacji\qs64.dll [2013-06-13 12:00:58 | 000,733,224 | ---- | C] (Bitdefender SRL) -- C:\Documents and Settings\Piotr\Ustawienia lokalne\Dane aplikacji\qs.dll [2013-06-10 12:35:37 | 000,000,000 | ---D | C] -- C:\Program Files\GridinSoft Trojan Killer [2013-06-10 12:30:09 | 000,015,648 | ---- | C] (GridinSoft LLC. All rights reserved.) -- C:\Documents and Settings\Piotr\Pulpit\russkil.exe [2013-06-10 11:45:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Mozilla [2013-06-10 11:45:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Dane aplikacji\Mozilla [2013-06-04 11:51:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Dane aplikacji\Malwarebytes [2013-06-04 11:51:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes [2013-06-04 09:22:59 | 000,563,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\qedit.dll [2013-06-03 11:52:37 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group [2013-06-03 11:52:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard [2013-06-03 11:46:21 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC [2013-05-31 12:07:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Moje dokumenty\Oświata [2013-04-23 08:50:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Dane aplikacji\McAfee [2013-04-10 14:23:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Moje dokumenty\ADRESY Internetowe [2013-04-03 10:18:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Pulpit\Uchwały 3.04.2013 [2013-03-28 11:49:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Moje dokumenty\Druki GOFIN [2013-03-28 11:48:42 | 000,000,000 | ---D | C] -- C:\Program Files\GOFIN [2013-03-28 11:48:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\GOFIN [2013-03-27 00:53:48 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cryptdlg.dll [2013-03-26 15:05:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Pulpit\uchwały sesja XXV [2013-03-22 08:25:56 | 000,012,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usb8023x.sys [2013-03-22 08:25:56 | 000,012,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usb8023.sys [2013-03-05 13:46:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Pulpit\Publikacja 5.03.2013 [2013-02-27 08:11:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Pulpit\zgrane_27.02.2013 [2013-02-13 14:48:47 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Piotr\Menu Start\Programy\Narzędzia administracyjne [2013-01-23 11:08:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\cache [2013-01-22 12:20:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Dane aplikacji\Media Player Classic [2013-01-22 12:18:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\K-Lite Codec Pack [2013-01-22 12:18:00 | 000,000,000 | ---D | C] -- C:\Program Files\K-Lite Codec Pack [2013-01-22 11:51:52 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Piotr\Moje dokumenty\Moje wideo [2013-01-22 11:42:39 | 000,031,576 | ---- | C] (AVG Technologies) -- C:\WINDOWS\System32\drivers\avgtpx86.sys [2013-01-22 11:39:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\SubEdit-Player [2013-01-22 11:39:24 | 000,000,000 | ---D | C] -- C:\Program Files\SubEdit-Player [2013-01-04 08:35:52 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Piotr\Moje dokumenty\Kopia Moja muzyka [2012-12-06 08:24:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel [2012-12-05 15:25:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Ustawienia lokalne\Dane aplikacji\Microsoft_Corporation [2012-12-05 14:34:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\WindowsPowerShell [2012-12-05 14:34:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\winrm [2012-12-05 14:34:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy [2012-12-05 14:34:34 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$968930Uinstall_KB968930$ [2012-12-05 14:28:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Microsoft SQL Server 2008 R2 [2012-12-05 14:18:16 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server [2012-11-12 13:29:49 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Piotr\Moje dokumenty\cache [2012-11-12 13:24:56 | 000,867,240 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\npDeployJava1.dll [2012-11-02 04:03:58 | 000,375,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dpnet.dll [2012-10-31 11:11:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\PDFCreator [2012-10-31 11:11:21 | 000,137,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSMAPI32.OCX [2012-10-31 11:11:20 | 000,662,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSCOMCT2.OCX [2012-10-31 11:11:17 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSMPIDE.DLL [2012-10-31 11:11:16 | 000,000,000 | ---D | C] -- C:\Program Files\PDFCreator [2012-10-29 10:58:36 | 000,000,000 | ---D | C] -- C:\Program Files\Przeglądarka Aktów Prawnych XML [2012-10-23 13:58:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Piotr\Pulpit\instrukcja [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\Documents and Settings\Piotr\Pulpit\*.tmp files -> C:\Documents and Settings\Piotr\Pulpit\*.tmp -> ] [color=#E56717]========== Files - Modified Within 360 Days ==========[/color] [2013-10-04 14:18:11 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2013-10-04 14:16:16 | 000,001,034 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2013-10-04 14:07:00 | 000,368,554 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\gmer.zip [2013-10-04 13:58:16 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Piotr\Pulpit\OTL.exe [2013-10-04 13:57:34 | 001,087,213 | ---- | M] (Farbar) -- C:\Documents and Settings\Piotr\Pulpit\FRST.exe [2013-10-04 12:40:53 | 000,000,266 | ---- | M] () -- C:\WINDOWS\tasks\EPUpdater.job [2013-10-04 12:39:17 | 000,368,554 | ---- | M] () -- C:\Documents and Settings\Piotr\Moje dokumenty\gmer.zip [2013-10-04 12:08:25 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2013-10-04 12:08:19 | 000,001,030 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2013-10-04 12:08:01 | 000,000,308 | ---- | M] () -- C:\WINDOWS\tasks\Tixq.job [2013-10-04 12:07:57 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2013-10-04 11:35:12 | 000,000,426 | ---- | M] () -- C:\WINDOWS\tasks\At1.job [2013-10-04 11:33:42 | 000,356,754 | ---- | M] () -- C:\Documents and Settings\Piotr\Ustawienia lokalne\Dane aplikacji\metacrawler-speeddial.crx [2013-10-04 11:33:28 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Piotr\Moje dokumenty\OTL.exe [2013-10-04 11:32:02 | 000,611,880 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\OTL_3.2.70.2 (25180).exe [2013-10-04 09:53:13 | 000,002,539 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\Microsoft Office Word 2003.lnk [2013-09-25 12:59:47 | 001,836,889 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\mikropesel1358.zip [2013-09-22 08:26:35 | 000,001,858 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk [2013-09-21 15:18:28 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe [2013-09-21 15:18:28 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl [2013-09-11 10:37:08 | 000,205,712 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2013-09-10 07:14:03 | 000,002,451 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\Edytor Aktów Prawnych XML.lnk [2013-08-28 15:09:50 | 000,000,727 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\CCleaner.lnk [2013-08-28 15:02:59 | 004,454,952 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Piotr\Pulpit\ccsetup405.exe [2013-08-24 18:53:19 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat [2013-08-24 18:52:28 | 000,001,779 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Adobe Reader XI.lnk [2013-08-24 15:26:28 | 000,001,237 | ---- | M] () -- C:\WINDOWS\wincmd.ini [2013-08-14 10:05:50 | 000,500,074 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2013-08-14 10:05:50 | 000,441,248 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2013-08-14 10:05:50 | 000,089,380 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2013-08-14 10:05:50 | 000,071,566 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2013-08-09 03:56:32 | 000,389,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\themeui.dll [2013-08-08 11:35:56 | 002,006,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll [2013-08-08 08:09:48 | 001,878,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\win32k.sys [2013-08-08 08:09:48 | 001,878,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\win32k.sys [2013-08-08 08:05:54 | 006,017,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll [2013-08-08 08:05:54 | 001,469,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\inetcpl.cpl [2013-08-08 08:05:54 | 001,469,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetcpl.cpl [2013-08-08 08:05:54 | 001,215,488 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\urlmon.dll [2013-08-08 08:05:54 | 000,920,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wininet.dll [2013-08-08 08:05:54 | 000,759,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vgx.dll [2013-08-08 08:05:54 | 000,630,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeeds.dll [2013-08-08 08:05:54 | 000,630,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll [2013-08-08 08:05:54 | 000,611,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mstime.dll [2013-08-08 08:05:54 | 000,611,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstime.dll [2013-08-08 08:05:54 | 000,522,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsdbgui.dll [2013-08-08 08:05:54 | 000,206,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\occache.dll [2013-08-08 08:05:54 | 000,184,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iepeers.dll [2013-08-08 08:05:54 | 000,184,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iepeers.dll [2013-08-08 08:05:54 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\url.dll [2013-08-08 08:05:54 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\url.dll [2013-08-08 08:05:54 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtmled.dll [2013-08-08 08:05:54 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeedsbs.dll [2013-08-08 08:05:54 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll [2013-08-08 08:05:54 | 000,043,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\licmgr10.dll [2013-08-08 08:05:54 | 000,043,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\licmgr10.dll [2013-08-08 08:05:54 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\jsproxy.dll [2013-08-08 08:05:54 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsproxy.dll [2013-08-08 08:05:53 | 011,113,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll [2013-08-08 08:05:53 | 000,743,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll [2013-08-08 08:05:53 | 000,387,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iedkcs32.dll [2013-08-08 08:05:53 | 000,387,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedkcs32.dll [2013-08-08 08:05:53 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\corpol.dll [2013-08-08 08:05:53 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\corpol.dll [2013-08-08 02:04:27 | 000,385,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\html.iec [2013-08-08 02:04:27 | 000,174,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ie4uinit.exe [2013-08-08 02:04:27 | 000,174,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ie4uinit.exe [2013-08-05 15:30:18 | 001,289,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ole32.dll [2013-08-03 01:48:38 | 001,543,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wmvdecod.dll [2013-07-15 14:34:36 | 000,002,465 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\Przeglądarka Aktów Prawnych XML.lnk [2013-07-10 12:37:48 | 000,406,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usp10.dll [2013-07-04 09:34:02 | 002,194,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ntoskrnl.exe [2013-07-04 09:34:02 | 002,194,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe [2013-07-04 09:34:02 | 002,071,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ntkrnlpa.exe [2013-07-04 09:34:02 | 002,071,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlpa.exe [2013-07-04 09:33:59 | 002,151,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe [2013-07-04 09:33:59 | 002,030,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe [2013-07-04 09:11:18 | 000,000,430 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\mikropesel.exe.lnk [2013-07-04 08:54:25 | 000,013,030 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\PDOXUSRS.NET [2013-07-04 08:43:41 | 000,000,427 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\KOPIA BAZY.lnk [2013-07-03 14:34:21 | 002,226,699 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\Mikropesel1357.zip [2013-06-28 13:40:04 | 004,396,440 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Piotr\Moje dokumenty\ccsetup403.exe [2013-06-21 07:53:46 | 000,116,189 | ---- | M] () -- C:\WINDOWS\System32\drivers\klin.dat [2013-06-21 07:53:46 | 000,098,168 | ---- | M] () -- C:\WINDOWS\System32\drivers\klick.dat [2013-06-21 07:53:45 | 000,584,496 | ---- | M] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys [2013-06-19 15:24:17 | 000,867,240 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\npDeployJava1.dll [2013-06-19 15:24:17 | 000,789,416 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll [2013-06-19 14:47:53 | 000,000,130 | ---- | M] () -- C:\Documents and Settings\Piotr\Ustawienia lokalne\Dane aplikacji\fusioncache.dat [2013-06-19 13:01:02 | 000,000,320 | -HS- | M] () -- C:\boot.ini [2013-06-13 12:00:58 | 002,051,696 | ---- | M] (Bitdefender SRL) -- C:\Documents and Settings\Piotr\Ustawienia lokalne\Dane aplikacji\qs64.dll [2013-06-13 12:00:58 | 000,733,224 | ---- | M] (Bitdefender SRL) -- C:\Documents and Settings\Piotr\Ustawienia lokalne\Dane aplikacji\qs.dll [2013-06-10 12:21:44 | 000,015,648 | ---- | M] (GridinSoft LLC. All rights reserved.) -- C:\Documents and Settings\Piotr\Pulpit\russkil.exe [2013-06-04 09:39:25 | 000,010,956 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\P0614032.120 [2013-06-04 09:22:59 | 000,563,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\qedit.dll [2013-05-28 03:59:28 | 000,590,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rpcrt4.dll [2013-05-24 10:55:14 | 000,348,160 | RHS- | M] () -- C:\WINDOWS\System32\qosnamek.dll [2013-05-23 14:10:15 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Piotr\Pulpit\~$M.GMINNY.rtf [2013-05-21 11:56:49 | 000,826,773 | ---- | M] () -- C:\Documents and Settings\Piotr\Moje dokumenty\ustwa o opłacie skarbowej.rtf [2013-04-16 10:26:10 | 001,480,054 | ---- | M] () -- C:\Documents and Settings\Piotr\Moje dokumenty\protokół XIII 11 + zał.pdf [2013-04-11 09:09:09 | 000,000,350 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\Klient Urzędowej Poczty Elektronicznej - 1 .appref-ms [2013-04-11 08:57:12 | 000,002,313 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Menedżer CryptoCard Suite.lnk [2013-04-10 14:17:47 | 001,830,352 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\mikropesel_XP.zip [2013-04-03 13:30:03 | 000,081,883 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\wniosek.pdf [2013-03-27 11:12:55 | 000,002,309 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Menedżer komponentu technicznego.lnk [2013-03-27 00:53:48 | 000,605,184 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\crypt32.dll [2013-03-27 00:53:48 | 000,075,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cryptdlg.dll [2013-03-27 00:53:48 | 000,075,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\cryptdlg.dll [2013-03-08 10:36:07 | 000,293,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\winsrv.dll [2013-03-08 10:36:07 | 000,293,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winsrv.dll [2013-02-27 09:58:32 | 002,067,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lhmstscx.dll [2013-02-12 02:32:23 | 000,012,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usb8023x.sys [2013-02-12 02:32:23 | 000,012,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usb8023.sys [2013-02-12 02:32:23 | 000,012,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usb8023.sys [2013-02-11 09:17:00 | 000,031,576 | ---- | M] (AVG Technologies) -- C:\WINDOWS\System32\drivers\avgtpx86.sys [2013-01-29 14:46:10 | 000,017,635 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\uchwały.zip [2013-01-26 05:55:40 | 000,552,448 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oleaut32.dll [2013-01-23 08:16:32 | 000,000,848 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\Internet Explorer.lnk [2013-01-22 13:17:01 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini [2013-01-22 11:39:27 | 000,000,842 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\SubEdit-Player.lnk [2013-01-22 09:11:33 | 000,001,703 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Sprawozdania DW.lnk [2013-01-08 10:17:57 | 000,039,632 | ---- | M] () -- C:\WINDOWS\hplj1010.his [2013-01-08 10:17:57 | 000,005,083 | ---- | M] () -- C:\WINDOWS\hplj1010.ini [2013-01-07 13:40:39 | 000,013,824 | ---- | M] () -- C:\Documents and Settings\Piotr\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2013-01-02 08:49:48 | 001,295,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\quartz.dll [2013-01-02 08:49:47 | 000,148,992 | ---- | M] () -- C:\WINDOWS\System32\mpg2splt.ax [2013-01-02 08:49:47 | 000,148,992 | ---- | M] () -- C:\WINDOWS\System32\dllcache\mpg2splt.ax [2012-12-16 14:23:59 | 000,290,560 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\dllcache\atmfd.dll [2012-12-16 14:23:59 | 000,290,560 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\atmfd.dll [2012-12-13 14:21:50 | 001,778,550 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\mikropesel_XP2.zip [2012-11-06 04:00:55 | 001,371,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxml6.dll [2012-11-05 10:25:27 | 000,000,449 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\Skrót do sesja_26.10.2012.lnk [2012-11-02 08:28:16 | 001,789,234 | ---- | M] () -- C:\Documents and Settings\Piotr\Pulpit\mikropesel_XP1.zip [2012-11-02 04:03:58 | 000,375,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dpnet.dll [2012-11-02 04:03:58 | 000,375,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dpnet.dll [2012-10-31 11:11:43 | 000,000,751 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\PDFCreator.lnk [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\Documents and Settings\Piotr\Pulpit\*.tmp files -> C:\Documents and Settings\Piotr\Pulpit\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2013-10-04 14:12:13 | 000,368,554 | ---- | C] () -- C:\Documents and Settings\Piotr\Pulpit\gmer.zip [2013-10-04 12:40:51 | 000,000,266 | ---- | C] () -- C:\WINDOWS\tasks\EPUpdater.job [2013-10-04 12:39:17 | 000,368,554 | ---- | C] () -- C:\Documents and Settings\Piotr\Moje dokumenty\gmer.zip [2013-10-04 11:35:11 | 000,000,426 | ---- | C] () -- C:\WINDOWS\tasks\At1.job [2013-10-04 11:34:44 | 000,356,754 | ---- | C] () -- C:\Documents and Settings\Piotr\Ustawienia lokalne\Dane aplikacji\metacrawler-speeddial.crx [2013-10-04 11:31:17 | 000,611,880 | ---- | C] () -- C:\Documents and Settings\Piotr\Pulpit\OTL_3.2.70.2 (25180).exe [2013-09-27 13:10:14 | 000,002,323 | ---- | C] () -- C:\Documents and Settings\Piotr\Menu Start\Programy\Windows Install Clean Up.lnk [2013-09-25 12:59:36 | 001,836,889 | ---- | C] () -- C:\Documents and Settings\Piotr\Pulpit\mikropesel1358.zip [2013-08-28 15:10:46 | 000,001,858 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk [2013-08-28 15:09:50 | 000,000,727 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\CCleaner.lnk [2013-08-28 15:04:35 | 000,001,034 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2013-08-28 15:04:35 | 000,001,030 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2013-08-24 18:53:19 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2013-08-24 18:52:26 | 000,001,779 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Adobe Reader XI.lnk [2013-08-24 18:52:24 | 000,002,347 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Start\Programy\Adobe Reader XI.lnk [2013-07-04 09:11:18 | 000,000,430 | ---- | C] () -- C:\Documents and Settings\Piotr\Pulpit\mikropesel.exe.lnk [2013-07-03 14:34:21 | 002,226,699 | ---- | C] () -- C:\Documents and Settings\Piotr\Pulpit\Mikropesel1357.zip [2013-06-20 14:17:22 | 000,116,189 | ---- | C] () -- C:\WINDOWS\System32\drivers\klin.dat [2013-06-20 14:17:22 | 000,098,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\klick.dat [2013-06-19 14:47:53 | 000,000,130 | ---- | C] () -- C:\Documents and Settings\Piotr\Ustawienia lokalne\Dane aplikacji\fusioncache.dat [2013-06-19 13:32:47 | 000,225,262 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msimain.sdb [2013-06-04 09:39:22 | 000,010,956 | ---- | C] () -- C:\Documents and Settings\Piotr\Pulpit\P0614032.120 [2013-05-24 10:55:15 | 000,000,308 | ---- | C] () -- C:\WINDOWS\tasks\Tixq.job [2013-05-24 10:55:14 | 000,348,160 | RHS- | C] () -- C:\WINDOWS\System32\qosnamek.dll [2013-05-23 14:10:15 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Piotr\Pulpit\~$M.GMINNY.rtf [2013-05-21 11:56:49 | 000,826,773 | ---- | C] () -- C:\Documents and Settings\Piotr\Moje dokumenty\ustwa o opłacie skarbowej.rtf [2013-04-26 08:37:43 | 001,480,054 | ---- | C] () -- C:\Documents and Settings\Piotr\Moje dokumenty\protokół XIII 11 + zał.pdf [2013-04-11 09:09:09 | 000,000,350 | ---- | C] () -- C:\Documents and Settings\Piotr\Pulpit\Klient Urzędowej Poczty Elektronicznej - 1 .appref-ms [2013-04-03 13:30:03 | 000,081,883 | ---- | C] () -- C:\Documents and Settings\Piotr\Pulpit\wniosek.pdf [2013-02-13 08:29:15 | 000,148,992 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mpg2splt.ax [2013-01-29 14:46:10 | 000,017,635 | ---- | C] () -- C:\Documents and Settings\Piotr\Pulpit\uchwały.zip [2013-01-23 08:16:32 | 000,000,848 | ---- | C] () -- C:\Documents and Settings\Piotr\Pulpit\Internet Explorer.lnk [2013-01-22 12:18:52 | 000,178,688 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2013-01-22 11:39:26 | 000,000,842 | ---- | C] () -- C:\Documents and Settings\Piotr\Pulpit\SubEdit-Player.lnk [2013-01-22 09:11:33 | 000,001,703 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Sprawozdania DW.lnk [2013-01-14 10:02:09 | 000,013,030 | ---- | C] () -- C:\Documents and Settings\Piotr\Pulpit\PDOXUSRS.NET [2013-01-08 10:17:00 | 000,250,086 | ---- | C] () -- C:\WINDOWS\hplj1010.hi1 [2013-01-08 10:16:59 | 000,017,922 | ---- | C] () -- C:\WINDOWS\hplj1010.bu1 [2012-12-13 14:21:32 | 001,778,550 | ---- | C] () -- C:\Documents and Settings\Piotr\Pulpit\mikropesel_XP2.zip [2012-11-05 10:25:27 | 000,000,449 | ---- | C] () -- C:\Documents and Settings\Piotr\Pulpit\Skrót do sesja_26.10.2012.lnk [2012-11-02 08:28:06 | 001,789,234 | ---- | C] () -- C:\Documents and Settings\Piotr\Pulpit\mikropesel_XP1.zip [2012-10-31 11:11:43 | 000,000,751 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\PDFCreator.lnk [2012-10-31 11:11:20 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll [2012-10-29 10:59:11 | 000,002,465 | ---- | C] () -- C:\Documents and Settings\Piotr\Pulpit\Przeglądarka Aktów Prawnych XML.lnk [2012-02-16 11:16:04 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2006-02-23 09:29:21 | 000,013,824 | ---- | C] () -- C:\Documents and Settings\Piotr\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [color=#E56717]========== ZeroAccess Check ==========[/color] [2009-11-04 10:43:42 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] "ThreadingModel" = Both "" = C:\RECYCLER\S-1-5-21-1715567821-1647877149-682003330-1003\$bff9f685edafa35acfdd511cf1823462\n. [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2008-04-14 19:20:47 | 001,499,136 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = fastprox.dll -- [2009-02-09 12:53:44 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008-04-14 19:20:57 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2013-10-04 12:39:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Babylon [2013-10-04 11:35:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\BonanzaDealsLive [2010-01-07 10:18:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piotr\Dane aplikacji\.szafir [2013-10-04 12:40:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piotr\Dane aplikacji\BabSolution [2013-09-27 12:34:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piotr\Dane aplikacji\eCyber [2013-09-30 09:20:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piotr\Dane aplikacji\iSafe [2010-01-07 10:18:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piotr\Dane aplikacji\KIR [2011-12-22 11:14:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piotr\Dane aplikacji\Legalis [2013-10-04 11:35:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piotr\Dane aplikacji\MetaCrawler [2009-03-13 11:46:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Piotr\Dane aplikacji\Thinstall [color=#E56717]========== Purity Check ==========[/color] < End of report >