OTL logfile created on: 2014-03-10 22:55:32 - Run 1 OTL by OldTimer - Version Folder = C:\Documents and Settings\x\Moje dokumenty\Downloads Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 958,48 Mb Total Physical Memory | 195,94 Mb Available Physical Memory | 20,44% Memory free 2,26 Gb Paging File | 1,36 Gb Available in Paging File | 60,29% Paging File free Paging file location(s): C:\pagefile.sys 1440 2880 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 11,72 Gb Total Space | 0,66 Gb Free Space | 5,62% Space Free | Partition Type: NTFS Drive D: | 31,40 Gb Total Space | 1,34 Gb Free Space | 4,27% Space Free | Partition Type: NTFS Drive E: | 31,40 Gb Total Space | 2,36 Gb Free Space | 7,51% Space Free | Partition Type: NTFS Drive H: | 28,81 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: PECECIK | User Name: x | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2014-03-10 22:54:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\x\Moje dokumenty\Downloads\OTL.exe PRC - [2014-03-03 20:40:20 | 000,070,848 | ---- | M] () -- C:\Program Files\Mobogenie\MgAssist.exe PRC - [2014-03-02 03:35:27 | 000,859,464 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe PRC - [2014-01-06 17:20:44 | 000,761,536 | ---- | M] () -- C:\Program Files\Mobogenie\DaemonProcess.exe PRC - [2013-11-18 15:32:40 | 003,780,064 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\BitGuard\2.7.1832.68\{16cdff19-861d-48e3-a751-d99a27784753}\BitGuard.exe PRC - [2012-09-22 03:32:40 | 000,655,744 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\Mobile Partner\OnlineUpdate\ouc.exe PRC - [2012-08-06 08:08:48 | 000,515,072 | ---- | M] () -- C:\Program Files\Mobile Partner\Mobile Partner.exe PRC - [2011-03-14 16:27:28 | 000,271,712 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\DatacardService\HWDeviceService.exe PRC - [2011-02-12 14:56:35 | 000,273,544 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe PRC - [2010-01-04 09:30:50 | 000,446,464 | ---- | M] () -- C:\Program Files\iPlus\iPlusChecker.exe PRC - [2009-09-10 14:45:00 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2014-03-03 20:40:20 | 000,070,848 | ---- | M] () -- C:\Program Files\Mobogenie\MgAssist.exe MOD - [2014-03-02 03:35:25 | 000,394,568 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\33.0.1750.146\ppgooglenaclpluginchrome.dll MOD - [2014-03-02 03:35:23 | 004,061,000 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\33.0.1750.146\pdf.dll MOD - [2014-03-02 03:35:17 | 001,647,432 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\33.0.1750.146\ffmpegsumo.dll MOD - [2014-03-02 03:35:15 | 000,051,016 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\33.0.1750.146\chrome_elf.dll MOD - [2014-01-06 17:20:46 | 000,088,256 | ---- | M] () -- C:\Program Files\Mobogenie\mgusb.exe MOD - [2014-01-06 17:20:44 | 000,761,536 | ---- | M] () -- C:\Program Files\Mobogenie\DaemonProcess.exe MOD - [2013-11-18 15:32:40 | 003,780,064 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\BitGuard\2.7.1832.68\{16cdff19-861d-48e3-a751-d99a27784753}\BitGuard.exe MOD - [2013-11-18 15:31:07 | 003,618,304 | ---- | M] () -- c:\Documents and Settings\All Users\Dane aplikacji\BitGuard\2.7.1832.68\{16cdff19-861d-48e3-a751-d99a27784753}\BitGuard.dll MOD - [2012-09-22 03:32:50 | 000,843,264 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\Mobile Partner\OnlineUpdate\QueryStrategy.dll MOD - [2012-09-22 03:32:40 | 000,655,744 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\Mobile Partner\OnlineUpdate\ouc.exe MOD - [2012-09-22 03:32:36 | 000,694,272 | ---- | M] () -- C:\Program Files\Mobile Partner\LiveUpdateInterface.dll MOD - [2012-08-06 08:08:48 | 000,515,072 | ---- | M] () -- C:\Program Files\Mobile Partner\Mobile Partner.exe MOD - [2012-08-06 08:08:42 | 000,119,296 | ---- | M] () -- C:\Program Files\Mobile Partner\ConnectMgrUIPlugin.dll MOD - [2012-08-06 08:07:18 | 000,493,568 | ---- | M] () -- C:\Program Files\Mobile Partner\NetInfoUIExPlugin.dll MOD - [2012-08-06 08:07:08 | 000,302,592 | ---- | M] () -- C:\Program Files\Mobile Partner\DiagnosisPlugin.dll MOD - [2012-08-06 08:06:58 | 000,330,752 | ---- | M] () -- C:\Program Files\Mobile Partner\MenuMgrPlugin.dll MOD - [2012-08-06 08:06:58 | 000,219,648 | ---- | M] () -- C:\Program Files\Mobile Partner\ToolBarMgrPlugin.dll MOD - [2012-08-06 08:06:50 | 000,359,936 | ---- | M] () -- C:\Program Files\Mobile Partner\NetConnectPlugin.dll MOD - [2012-08-06 08:06:44 | 000,270,848 | ---- | M] () -- C:\Program Files\Mobile Partner\XFramePlugin.dll MOD - [2012-08-06 08:06:42 | 000,117,248 | ---- | M] () -- C:\Program Files\Mobile Partner\LayoutPlugin.dll MOD - [2012-08-06 08:06:34 | 000,581,120 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceMgrUIPlugin.dll MOD - [2012-08-06 08:06:34 | 000,323,584 | ---- | M] () -- C:\Program Files\Mobile Partner\StatusBarMgrPlugin.dll MOD - [2012-08-06 08:06:20 | 000,818,688 | ---- | M] () -- C:\Program Files\Mobile Partner\AddrBookUIPlugin.dll MOD - [2012-08-06 08:06:06 | 000,097,792 | ---- | M] () -- C:\Program Files\Mobile Partner\NotifyServicePlugin.dll MOD - [2012-08-06 08:06:04 | 000,854,528 | ---- | M] () -- C:\Program Files\Mobile Partner\SMSUIPlugin.dll MOD - [2012-08-06 08:05:54 | 000,592,896 | ---- | M] () -- C:\Program Files\Mobile Partner\DialupUIPlugin.dll MOD - [2012-08-06 08:05:46 | 000,518,144 | ---- | M] () -- C:\Program Files\Mobile Partner\core.dll MOD - [2012-08-06 08:05:40 | 000,569,344 | ---- | M] () -- C:\Program Files\Mobile Partner\CallLogSrvPlugin.dll MOD - [2012-08-06 08:05:40 | 000,177,152 | ---- | M] () -- C:\Program Files\Mobile Partner\CallSrvPlugin.dll MOD - [2012-08-06 08:05:38 | 000,729,088 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceSrvPlugin.dll MOD - [2012-08-06 08:05:32 | 000,704,000 | ---- | M] () -- C:\Program Files\Mobile Partner\SmsAppPlugin.dll MOD - [2012-08-06 08:05:30 | 000,286,720 | ---- | M] () -- C:\Program Files\Mobile Partner\sdk.dll MOD - [2012-08-06 08:05:30 | 000,219,648 | ---- | M] () -- C:\Program Files\Mobile Partner\SmsSrvPlugin.dll MOD - [2012-08-06 08:05:28 | 000,157,184 | ---- | M] () -- C:\Program Files\Mobile Partner\STKSrvPlugin.dll MOD - [2012-08-06 08:05:28 | 000,142,336 | ---- | M] () -- C:\Program Files\Mobile Partner\USSDSrvPlugin.dll MOD - [2012-08-06 08:05:26 | 001,124,352 | ---- | M] () -- C:\Program Files\Mobile Partner\AddrBookPlugin.dll MOD - [2012-08-06 08:05:22 | 000,672,768 | ---- | M] () -- C:\Program Files\Mobile Partner\AddrBookSrvPlugin.dll MOD - [2012-08-06 08:05:22 | 000,241,152 | ---- | M] () -- C:\Program Files\Mobile Partner\NetSrvPlugin.dll MOD - [2012-08-06 08:05:20 | 000,646,144 | ---- | M] () -- C:\Program Files\Mobile Partner\AtCodec.dll MOD - [2012-08-06 08:05:20 | 000,583,168 | ---- | M] () -- C:\Program Files\Mobile Partner\PluginContainer.dll MOD - [2012-08-06 08:05:20 | 000,195,584 | ---- | M] () -- C:\Program Files\Mobile Partner\XCodec.dll MOD - [2012-08-06 08:05:20 | 000,062,976 | ---- | M] () -- C:\Program Files\Mobile Partner\OSCall.dll MOD - [2012-08-06 08:05:18 | 000,730,624 | ---- | M] () -- C:\Program Files\Mobile Partner\DeviceAppPlugin.dll MOD - [2012-08-06 08:05:18 | 000,702,464 | ---- | M] () -- C:\Program Files\Mobile Partner\NetInfoSrvPlugin.dll MOD - [2012-08-06 08:05:18 | 000,187,392 | ---- | M] () -- C:\Program Files\Mobile Partner\CallAppPlugin.dll MOD - [2012-08-06 08:05:16 | 000,168,960 | ---- | M] () -- C:\Program Files\Mobile Partner\ATR2SMgr.dll MOD - [2012-08-06 08:05:08 | 000,236,032 | ---- | M] () -- C:\Program Files\Mobile Partner\DialUpPlugin.dll MOD - [2012-08-06 08:05:06 | 000,201,216 | ---- | M] () -- C:\Program Files\Mobile Partner\NDISPlugin.dll MOD - [2012-08-06 08:05:04 | 000,405,504 | ---- | M] () -- C:\Program Files\Mobile Partner\Proxy.dll MOD - [2012-08-06 08:05:04 | 000,158,720 | ---- | M] () -- C:\Program Files\Mobile Partner\NetConnectSrvPlugin.dll MOD - [2012-08-06 08:05:02 | 000,164,864 | ---- | M] () -- C:\Program Files\Mobile Partner\OSDialup.dll MOD - [2012-08-06 08:05:02 | 000,155,136 | ---- | M] () -- C:\Program Files\Mobile Partner\DataServicePlugin.dll MOD - [2012-08-06 08:05:02 | 000,131,584 | ---- | M] () -- C:\Program Files\Mobile Partner\OSNDIS.dll MOD - [2012-08-06 08:05:00 | 000,157,184 | ---- | M] () -- C:\Program Files\Mobile Partner\Trace.dll MOD - [2012-08-06 08:05:00 | 000,102,400 | ---- | M] () -- C:\Program Files\Mobile Partner\OSAdapt.dll MOD - [2012-08-06 08:05:00 | 000,065,536 | ---- | M] () -- C:\Program Files\Mobile Partner\OSPowerMgr.dll MOD - [2012-08-06 08:04:58 | 000,628,224 | ---- | M] () -- C:\Program Files\Mobile Partner\Common.dll MOD - [2012-07-27 07:53:54 | 001,114,112 | ---- | M] () -- C:\Program Files\Mobile Partner\NDISAPI.dll MOD - [2012-06-06 02:22:00 | 000,224,256 | ---- | M] () -- C:\Program Files\Mobile Partner\tdpcvoice.dll MOD - [2012-06-06 02:22:00 | 000,155,648 | ---- | M] () -- C:\Program Files\Mobile Partner\Win7Support.dll MOD - [2012-06-06 02:21:18 | 000,370,176 | ---- | M] () -- C:\Program Files\Mobile Partner\plugins\imageformats\qtiff4.dll MOD - [2012-06-06 02:21:18 | 000,350,720 | ---- | M] () -- C:\Program Files\Mobile Partner\plugins\imageformats\qmng4.dll MOD - [2012-06-06 02:21:18 | 000,192,000 | ---- | M] () -- C:\Program Files\Mobile Partner\plugins\imageformats\qjpeg4.dll MOD - [2012-06-06 02:21:18 | 000,082,944 | ---- | M] () -- C:\Program Files\Mobile Partner\plugins\imageformats\qgif4.dll MOD - [2012-06-06 02:21:18 | 000,081,920 | ---- | M] () -- C:\Program Files\Mobile Partner\plugins\imageformats\qico4.dll MOD - [2012-01-27 22:45:18 | 008,527,008 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll MOD - [2011-03-14 16:27:28 | 000,271,712 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\DatacardService\HWDeviceService.exe MOD - [2010-07-23 05:58:24 | 002,415,104 | ---- | M] () -- C:\Program Files\Mobile Partner\QtCore4.dll MOD - [2010-07-23 05:58:24 | 002,415,104 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\Mobile Partner\OnlineUpdate\QtCore4.dll MOD - [2010-02-10 15:43:38 | 009,515,520 | ---- | M] () -- C:\Program Files\Mobile Partner\QtGui4.dll MOD - [2010-02-10 15:10:26 | 001,148,416 | ---- | M] () -- C:\Program Files\Mobile Partner\QtNetwork4.dll MOD - [2010-02-10 15:10:26 | 001,148,416 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\Mobile Partner\OnlineUpdate\QtNetwork4.dll MOD - [2010-02-10 15:06:52 | 000,398,336 | ---- | M] () -- C:\Program Files\Mobile Partner\QtXml4.dll MOD - [2010-02-10 15:06:52 | 000,398,336 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\Mobile Partner\OnlineUpdate\QtXml4.dll MOD - [2010-01-04 09:30:50 | 000,446,464 | ---- | M] () -- C:\Program Files\iPlus\iPlusChecker.exe MOD - [2009-07-08 09:58:18 | 000,466,944 | ---- | M] () -- C:\WINDOWS\system32\nvshell.dll MOD - [2009-06-22 19:42:42 | 000,043,008 | ---- | M] () -- C:\Program Files\Mobile Partner\libgcc_s_dw2-1.dll MOD - [2009-06-22 19:42:42 | 000,043,008 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\Mobile Partner\OnlineUpdate\libgcc_s_dw2-1.dll MOD - [2009-02-27 19:04:20 | 000,311,296 | ---- | M] () -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\pdfshell.POL MOD - [2009-01-10 23:15:44 | 000,159,744 | ---- | M] () -- C:\WINDOWS\system32\mmfinfo.dll MOD - [2009-01-10 23:14:06 | 000,023,552 | ---- | M] () -- C:\WINDOWS\system32\mkunicode.dll MOD - [2009-01-10 11:32:40 | 000,011,362 | ---- | M] () -- C:\Program Files\Mobile Partner\mingwm10.dll MOD - [2009-01-10 11:32:40 | 000,011,362 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\Mobile Partner\OnlineUpdate\mingwm10.dll MOD - [2007-08-21 13:32:44 | 000,098,304 | ---- | M] () -- C:\WINDOWS\system32\redmonnt.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - [2014-03-03 20:40:20 | 000,070,848 | ---- | M] () [Auto | Running] -- C:\Program Files\Mobogenie\MgAssist.exe -- (MgAssistService) SRV - [2013-11-18 15:32:40 | 003,780,064 | ---- | M] () [Auto | Running] -- C:\Documents and Settings\All Users\Dane aplikacji\BitGuard\2.7.1832.68\{16cdff19-861d-48e3-a751-d99a27784753}\BitGuard.exe -- (BitGuard) SRV - [2013-04-04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2013-04-04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler) SRV - [2012-09-22 03:32:40 | 000,655,744 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Mobile Partner\UpdateDog\ouc.exe -- (Mobile Partner. RunOuc) SRV - [2011-03-14 16:27:28 | 000,271,712 | ---- | M] () [Auto | Running] -- C:\Documents and Settings\All Users\Dane aplikacji\DatacardService\HWDeviceService.exe -- (HWDeviceService.exe) SRV - [2008-04-07 08:17:30 | 000,430,592 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | Disabled | Stopped] -- System32\Drivers\sptd.sys -- (sptd) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbdev.sys -- (hwusbdev) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\gdrv.sys -- (gdrv) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2013-06-28 10:44:00 | 000,027,776 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgandnetmodem.sys -- (ANDNetModem) DRV - [2013-04-18 15:09:22 | 000,023,168 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgandnetdiag.sys -- (AndNetDiag) DRV - [2013-04-04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector) DRV - [2012-08-20 01:54:19 | 000,027,520 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ew_juextctrl.sys -- (huawei_ext_ctrl) DRV - [2012-08-20 01:54:18 | 000,096,000 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ew_jucdcacm.sys -- (huawei_cdcacm) DRV - [2012-08-20 01:54:18 | 000,076,544 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ew_jubusenum.sys -- (huawei_enumerator) DRV - [2012-08-20 01:54:18 | 000,069,760 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ew_jucdcecm.sys -- (huawei_cdcecm) DRV - [2012-04-20 07:14:21 | 000,249,472 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbnet.sys -- (ewusbnet) DRV - [2011-12-31 02:20:23 | 000,199,168 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard) DRV - [2010-07-27 02:52:02 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev) DRV - [2010-03-20 05:06:58 | 000,011,136 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ew_usbenumfilter.sys -- (ew_usbenumfilter) DRV - [2009-12-08 11:03:00 | 006,017,568 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) DRV - [2009-11-18 00:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt) DRV - [2009-11-18 00:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt) DRV - [2009-09-10 14:45:00 | 000,215,856 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\Si3132r5.sys -- (Si3132r5) DRV - [2009-09-10 14:45:00 | 000,212,520 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\Si3531.sys -- (Si3531) DRV - [2009-09-10 14:45:00 | 000,195,072 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\Si3114r5.sys -- (Si3114r5) DRV - [2009-09-10 14:45:00 | 000,100,736 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\nvatabus.sys -- (nvatabus) DRV - [2009-09-10 14:45:00 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx) DRV - [2009-09-10 14:45:00 | 000,074,672 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\si3132.sys -- (Si3132) DRV - [2009-09-10 14:45:00 | 000,069,248 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\si3124.sys -- (Si3124) DRV - [2009-09-10 14:45:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb) DRV - [2009-09-10 14:45:00 | 000,062,336 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\si3112.sys -- (Si3112) DRV - [2009-09-10 14:45:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx) DRV - [2009-07-01 04:53:34 | 000,013,824 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus) DRV - [2009-07-01 04:53:30 | 000,066,688 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD) DRV - [2009-06-30 10:31:00 | 000,164,896 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvgts.sys -- (nvgts) DRV - [2009-04-07 08:39:44 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\FsUsbExDisk.Sys -- (FsUsbExDisk) DRV - [2007-09-17 14:53:26 | 000,021,632 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd) DRV - [2006-07-24 16:05:00 | 000,005,632 | ---- | M] () [File_System | System | Running] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen) DRV - [2006-07-01 22:32:26 | 000,043,520 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8) DRV - [2004-04-08 11:06:08 | 000,070,400 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\prohlp02.sys -- (prohlp02) DRV - [2004-04-08 09:46:50 | 000,054,272 | ---- | M] (Protection Technology) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\prodrv06.sys -- (prodrv06) DRV - [2003-12-01 16:20:52 | 000,004,832 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfhlp01.sys -- (sfhlp01) DRV - [2003-09-06 13:22:08 | 000,006,944 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\prosync1.sys -- (prosync1) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?barid={A4056996-4755-4AE7-899B-C835AC1D870D} IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&barid={A4056996-4755-4AE7-899B-C835AC1D870D} IE - HKLM\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-839522115-484763869-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=112670&tt=4712_1&babsrc=HP_sst&mntrId=1467a05b000000000000001e101fbcad IE - HKU\S-1-5-21-839522115-484763869-1417001333-1003\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKU\S-1-5-21-839522115-484763869-1417001333-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-839522115-484763869-1417001333-1003\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=112670&tt=4712_1&babsrc=SP_sst&mntrId=1467a05b000000000000001e101fbcad IE - HKU\S-1-5-21-839522115-484763869-1417001333-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADFA_pl IE - HKU\S-1-5-21-839522115-484763869-1417001333-1003\..\SearchScopes\{85039B6F-5035-430B-87DD-7234D4C419D8}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=MPC2&o=41647997&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=8E&apn_dtid=YYYYYYM4PL&apn_uid=653fffd0-2127-479f-a275-76566b301c66&apn_sauid=1ED16C7F-85D9-4836-AC75-2145862D468A& IE - HKU\S-1-5-21-839522115-484763869-1417001333-1003\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search?q={searchTerms} IE - HKU\S-1-5-21-839522115-484763869-1417001333-1003\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678 IE - HKU\S-1-5-21-839522115-484763869-1417001333-1003\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&barid={A4056996-4755-4AE7-899B-C835AC1D870D} IE - HKU\S-1-5-21-839522115-484763869-1417001333-1003\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7 IE - HKU\S-1-5-21-839522115-484763869-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultengine: "Ask.com" FF - prefs.js..browser.search.defaultthis.engineName: " " FF - prefs.js..browser.search.defaulturl: "" FF - prefs.js..browser.search.selectedEngine: "SweetIM Search" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://home.sweetim.com/?barid={A4056996-4755-4AE7-899B-C835AC1D870D}" FF - prefs.js..extensions.enabledAddons: ffxtlbr@babylon.com:1.1.9 FF - prefs.js..extensions.enabledAddons: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}: FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.2 FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}: FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}: FF - prefs.js..browser.startup.homepage: "http://search.babylon.com/?babsrc=HP_Prot" FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "Search the web (Babylon)" FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\WINDOWS\system32\C2MP\npdivx32.dll (DivX,Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version= C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version= C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version= C:\Documents and Settings\All Users\Dane aplikacji\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version= C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Dane aplikacji\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011-02-12 14:56:48 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010-09-10 17:20:47 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\x\Dane aplikacji\Mozilla\Extensions [2014-03-10 21:31:32 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\x\Dane aplikacji\Mozilla\Firefox\Profiles\p8yb89ra.default\extensions [2010-09-11 13:01:58 | 000,000,000 | ---D | M] (Winamp Toolbar) -- C:\Documents and Settings\x\Dane aplikacji\Mozilla\Firefox\Profiles\p8yb89ra.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} [2012-01-13 19:04:22 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Documents and Settings\x\Dane aplikacji\Mozilla\Firefox\Profiles\p8yb89ra.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} [2011-05-07 13:05:45 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\x\Dane aplikacji\Mozilla\Firefox\Profiles\p8yb89ra.default\extensions\engine@conduit.com [2011-11-17 19:25:44 | 000,002,333 | ---- | M] () -- C:\Documents and Settings\x\Dane aplikacji\Mozilla\Firefox\Profiles\p8yb89ra.default\searchplugins\askcom.xml [2012-11-19 20:53:03 | 000,002,537 | ---- | M] () -- C:\Documents and Settings\x\Dane aplikacji\Mozilla\Firefox\Profiles\p8yb89ra.default\searchplugins\browsemngr.xml [2012-01-11 11:53:08 | 000,000,925 | ---- | M] () -- C:\Documents and Settings\x\Dane aplikacji\Mozilla\Firefox\Profiles\p8yb89ra.default\searchplugins\conduit.xml [2012-03-07 17:00:57 | 000,003,969 | ---- | M] () -- C:\Documents and Settings\x\Dane aplikacji\Mozilla\Firefox\Profiles\p8yb89ra.default\searchplugins\sweetim.xml [2010-09-11 13:05:36 | 000,001,250 | ---- | M] () -- C:\Documents and Settings\x\Dane aplikacji\Mozilla\Firefox\Profiles\p8yb89ra.default\searchplugins\winamp-search.xml [2010-11-08 19:29:10 | 000,001,979 | ---- | M] () -- C:\Documents and Settings\x\Dane aplikacji\Mozilla\Firefox\Profiles\p8yb89ra.default\searchplugins\wrzuta.xml File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\X\DANE APLIKACJI\MOZILLA\FIREFOX\PROFILES\P8YB89RA.DEFAULT\EXTENSIONS\FFXTLBR@BABYLON.COM [color=#E56717]========== Chrome ==========[/color] CHR - default_search_provider: Search the web (Babylon) (Enabled) CHR - default_search_provider: search_url = http://search.babylon.com/?q={searchTerms}&affID=112670&tt=4712_1&babsrc=SP_sst&mntrId=1467a05b000000000000001e101fbcad CHR - default_search_provider: suggest_url = , CHR - plugin: Widevine Content Decryption Module (Enabled) = C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\WidevineCDM\\_platform_specific\win_x86\widevinecdmadapter.dll CHR - plugin: Shockwave Flash (Disabled) = C:\Program Files\Google\Chrome\Application\33.0.1750.146\PepperFlash\pepflashplayer.dll CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\33.0.1750.146\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\33.0.1750.146\pdf.dll CHR - plugin: Java Deployment Toolkit (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Microsoft® DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll CHR - plugin: Microsoft® DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Dane aplikacji\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\Facebook\Video\Skype\npFacebookVideoCalling.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll CHR - plugin: BonanzaDealsLive Update (Enabled) = C:\Program Files\BonanzaDealsLive\Update\\npGoogleUpdate3.dll CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\\npGoogleUpdate3.dll CHR - plugin: Java(TM) Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - plugin: DivX Web Player (Enabled) = C:\WINDOWS\system32\C2MP\npdivx32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll CHR - Extension: Dokumenty Google = C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\ CHR - Extension: Dysk Google = C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\ CHR - Extension: YouTube = C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\ CHR - Extension: Szukaj w Google = C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\\ CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.3_0\ CHR - Extension: Google Wallet = C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\\ CHR - Extension: Gmail = C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2009-09-10 14:45:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: localhost O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dane aplikacji\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) O3 - HKLM\..\Toolbar: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found. O3 - HKU\S-1-5-21-839522115-484763869-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O3 - HKU\S-1-5-21-839522115-484763869-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O3 - HKU\S-1-5-21-839522115-484763869-1417001333-1003\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found. O4 - HKLM..\Run: [iPlusManager] C:\Program Files\iPlus\iPlusChecker.exe () O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found O4 - HKLM..\Run: [mobilegeni daemon] C:\Program Files\Mobogenie\DaemonProcess.exe () O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe () O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.) O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.) O4 - HKU\S-1-5-21-839522115-484763869-1417001333-1003..\Run: [Facebook Update] C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\Facebook\Update\FacebookUpdate.exe (Facebook Inc.) O4 - HKU\S-1-5-21-839522115-484763869-1417001333-1003..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.) O4 - HKU\S-1-5-21-839522115-484763869-1417001333-1003..\Run: [IPLA!] C:\Program Files\ipla\ipla.exe (Redefine Sp z o.o.) O4 - HKU\S-1-5-21-839522115-484763869-1417001333-1003..\Run: [MSConfig] C:\Documents and Settings\x\nrimovzj.exe (Daniel Pistelli) O4 - HKU\S-1-5-21-839522115-484763869-1417001333-1003..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-839522115-484763869-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Search the Web - C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html File not found O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation) O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{294CA503-9D04-4103-8261-E8E6630F140C}: DhcpNameServer = O20 - AppInit_DLLs: (c:\docume~1\alluse~1\daneap~1\bitguard\271832~1.68\{16cdf~1\bitguard.dll) - c:\Documents and Settings\All Users\Dane aplikacji\BitGuard\2.7.1832.68\{16cdff19-861d-48e3-a751-d99a27784753}\BitGuard.dll () O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O30 - LSA: Authentication Packages - (nwprovau) - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2010-09-10 23:00:23 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2011-03-15 00:27:22 | 000,148,320 | R--- | M] () - H:\AutoRun.exe -- [ CDFS ] O32 - AutoRun File - [2008-10-01 10:12:34 | 000,000,045 | R--- | M] () - H:\AUTORUN.INF -- [ CDFS ] O33 - MountPoints2\{0530887e-bcfd-11df-8066-6cf049d09004}\Shell - "" = AutoRun O33 - MountPoints2\{0530887e-bcfd-11df-8066-6cf049d09004}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{1ee22890-204f-11e1-8345-001e101f5adc}\Shell - "" = AutoRun O33 - MountPoints2\{1ee22890-204f-11e1-8345-001e101f5adc}\Shell\AutoRun\command - "" = J:\RunGame.exe O33 - MountPoints2\{3802155c-c14a-11e2-992b-6cf049d09004}\Shell - "" = AutoRun O33 - MountPoints2\{3802155c-c14a-11e2-992b-6cf049d09004}\Shell\AutoRun\command - "" = K:\AutoRun.exe O33 - MountPoints2\{3b191c80-317d-11e1-8374-001e101f9308}\Shell - "" = AutoRun O33 - MountPoints2\{3b191c80-317d-11e1-8374-001e101f9308}\Shell\AutoRun\command - "" = M:\AutoRun.exe O33 - MountPoints2\{746aeaf0-8d6a-11e2-98b2-6cf049d09004}\Shell - "" = AutoRun O33 - MountPoints2\{746aeaf0-8d6a-11e2-98b2-6cf049d09004}\Shell\AutoRun\command - "" = H:\AutoRun.exe -- [2011-03-15 00:27:22 | 000,148,320 | R--- | M] () O33 - MountPoints2\{7983b582-34a4-11e1-837e-001e101f4bce}\Shell - "" = AutoRun O33 - MountPoints2\{7983b582-34a4-11e1-837e-001e101f4bce}\Shell\AutoRun\command - "" = K:\AutoRun.exe O33 - MountPoints2\{8bcbbc2f-1965-11e3-afff-6cf049d09004}\Shell - "" = AutoRun O33 - MountPoints2\{8bcbbc2f-1965-11e3-afff-6cf049d09004}\Shell\AutoRun\command - "" = H:\LGAutoRun.exe O33 - MountPoints2\{8daafcd0-9caf-11e3-b028-6cf049d09004}\Shell - "" = AutoRun O33 - MountPoints2\{8daafcd0-9caf-11e3-b028-6cf049d09004}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RECYCLER\S-0-7-73-313979278-2344835155-148054291-098\urgklo.exe O33 - MountPoints2\{9123c88a-4c86-11e2-982e-001e101f4c53}\Shell\AutoRun\command - "" = J:\RunClubSanDisk.exe O33 - MountPoints2\{949827b2-711f-11e1-9727-001e101f731c}\Shell - "" = AutoRun O33 - MountPoints2\{949827b2-711f-11e1-9727-001e101f731c}\Shell\AutoRun\command - "" = G:\RunGame.exe O33 - MountPoints2\{b3a4db70-9ed3-11e2-98d9-6cf049d09004}\Shell - "" = AutoRun O33 - MountPoints2\{b3a4db70-9ed3-11e2-98d9-6cf049d09004}\Shell\AutoRun\command - "" = H:\AutoRun.exe -- [2011-03-15 00:27:22 | 000,148,320 | R--- | M] () O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2014-03-10 22:41:54 | 000,000,000 | ---D | C] -- C:\FRST [2014-03-03 20:50:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\x\Dane aplikacji\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1 [2014-03-03 20:50:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\x\Dane aplikacji\e-Deklaracje [2014-03-03 20:50:25 | 000,000,000 | ---D | C] -- C:\Program Files\e-Deklaracje [2014-03-03 20:49:50 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR [2014-03-02 20:43:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\x\Pulpit\mp3 [2014-03-02 20:38:47 | 035,004,416 | -H-- | C] (Daniel Pistelli) -- C:\Documents and Settings\x\nrimovzj.exe [2014-02-28 19:43:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\x\Pulpit\Nowy folder [2014-02-23 22:31:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\x\Dane aplikacji\TuneUp Software [2014-02-23 22:30:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\TuneUp Software [2014-02-23 22:29:52 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Dane aplikacji\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} [2014-02-23 22:29:52 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Common Files [2014-02-23 22:27:23 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\x\Recent [2014-02-23 21:38:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Logs [2014-02-23 21:25:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\ESET [2014-02-23 20:51:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\x\Dane aplikacji\Malwarebytes [2014-02-23 20:50:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes' Anti-Malware [2014-02-23 20:50:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes [2014-02-23 20:50:36 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2014-02-23 20:50:36 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2014-02-23 20:10:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\ESET [2014-02-23 19:55:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\x\Dane aplikacji\BinarySense [2014-02-23 19:55:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Licenses [2014-02-23 19:55:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP [2014-02-23 18:50:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\x\Local Settings [2011-12-11 23:19:28 | 002,161,160 | ---- | C] (DownVision ) -- C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\setup.exe [6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2014-03-10 23:01:45 | 002,359,350 | ---- | M] () -- C:\Documents and Settings\x\Pulpit\blad.bmp [2014-03-10 22:59:24 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-839522115-484763869-1417001333-1003.job [2014-03-10 22:59:17 | 000,000,270 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-839522115-484763869-1417001333-1003.job [2014-03-10 22:50:23 | 000,001,022 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2014-03-10 22:50:08 | 000,237,301 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml [2014-03-10 22:50:01 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2014-03-10 22:33:03 | 000,001,026 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2014-03-10 21:25:15 | 000,000,986 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-839522115-484763869-1417001333-1003UA.job [2014-03-10 21:08:16 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2014-03-07 12:25:02 | 000,000,964 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-839522115-484763869-1417001333-1003Core.job [2014-03-05 19:38:56 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini [2014-03-05 17:24:32 | 000,311,296 | ---- | M] () -- C:\Documents and Settings\x\dbupwj.exe [2014-03-03 20:50:29 | 000,000,670 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\e-Deklaracje.lnk [2014-03-02 20:38:50 | 035,004,416 | -H-- | M] (Daniel Pistelli) -- C:\Documents and Settings\x\nrimovzj.exe [2014-02-23 20:50:42 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk [6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2014-03-10 23:01:45 | 002,359,350 | ---- | C] () -- C:\Documents and Settings\x\Pulpit\blad.bmp [2014-03-05 17:24:32 | 000,311,296 | ---- | C] () -- C:\Documents and Settings\x\dbupwj.exe [2014-03-03 20:50:29 | 000,000,676 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Start\Programy\e-Deklaracje.lnk [2014-03-03 20:50:29 | 000,000,670 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\e-Deklaracje.lnk [2014-02-23 20:50:42 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Malwarebytes Anti-Malware.lnk [2014-02-23 20:29:37 | 000,000,270 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-839522115-484763869-1417001333-1003.job [2013-02-24 17:52:55 | 000,114,176 | ---- | C] () -- C:\Documents and Settings\x\Dane aplikacji\BabMaint.exe [2012-12-05 12:09:50 | 000,000,092 | ---- | C] () -- C:\WINDOWS\LEXSTAT.INI [2011-12-11 23:34:38 | 000,070,712 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat [2011-06-07 20:18:30 | 000,000,869 | ---- | C] () -- C:\Documents and Settings\x\.recently-used.xbel [2011-02-18 16:40:48 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\LauncherAccess.dt [2010-09-11 12:14:52 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\x\Dane aplikacji\$_hpcst$.hpc [2010-09-10 18:23:45 | 000,036,864 | ---- | C] () -- C:\Documents and Settings\x\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [color=#E56717]========== ZeroAccess Check ==========[/color] [2011-12-11 23:32:47 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2009-09-10 14:45:00 | 001,499,136 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009-09-10 14:45:00 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2009-09-10 14:45:00 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2012-01-19 15:05:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\AlawarWrapper [2011-12-11 04:42:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Babylon [2014-01-01 13:00:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\BitGuard [2014-02-23 22:29:52 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Common Files [2011-12-06 22:16:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite [2013-03-15 13:26:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\DatacardService [2010-09-10 18:36:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10 [2012-01-19 15:05:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\InterAction studios [2013-10-08 12:28:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ipla [2014-02-23 19:55:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Licenses [2014-02-23 21:38:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Logs [2013-03-15 13:26:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Mobile Partner [2011-05-31 22:09:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\OpenFM [2010-09-11 12:17:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PC Suite [2012-11-07 16:00:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\RDRM [2012-11-20 14:47:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\SweetIM [2014-02-23 21:50:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP [2014-02-23 22:31:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TuneUp Software [2011-12-13 23:21:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Wru [2014-02-23 22:42:24 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Dane aplikacji\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} [2014-03-08 02:59:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\AIMP [2013-01-10 22:47:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\BabSolution [2011-12-11 04:42:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\Babylon [2014-02-23 19:55:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\BinarySense [2010-09-10 18:07:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\Codeton [2013-08-20 18:40:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\DAEMON Tools Lite [2014-03-03 20:50:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\e-Deklaracje [2014-03-03 20:50:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1 [2011-10-06 09:56:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\Gadu-Gadu 10 [2013-08-17 14:17:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\Grupa IMAGE [2011-05-05 16:13:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\gtk-2.0 [2014-03-10 22:51:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\ipla [2010-09-10 18:05:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\iPlus [2013-09-09 17:30:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\LG Electronics [2011-12-12 00:33:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\Need for Speed World [2011-05-07 10:45:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\OpenFM [2010-09-10 17:28:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\OpenOffice.org [2010-09-11 12:17:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\PC Suite [2014-01-06 15:01:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\PhotoScape [2011-01-14 19:46:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\RDRM [2012-11-18 20:25:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\Samsung [2011-10-10 15:26:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\SecondLife [2012-11-19 20:54:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\Systweak [2014-02-23 22:31:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\TuneUp Software [2014-03-10 22:51:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\uTorrent [2011-12-13 23:21:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\Wru [2010-09-11 14:09:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\x\Dane aplikacji\XnView [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 1658665 bytes -> C:\Documents and Settings\x\Local Settings:init @Alternate Data Stream - 1655032 bytes -> C:\WINDOWS\Temp:temp @Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:55B41E6A < End of report >