OTL logfile created on: 2014-05-27 19:11:50 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\2\Moje dokumenty\Pobrane Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1015,30 Mb Total Physical Memory | 281,34 Mb Available Physical Memory | 27,71% Memory free 2,38 Gb Paging File | 1,38 Gb Available in Paging File | 58,09% Paging File free Paging file location(s): C:\pagefile.sys 1524 3048 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 78,12 Gb Total Space | 40,02 Gb Free Space | 51,23% Space Free | Partition Type: NTFS Drive D: | 33,66 Gb Total Space | 33,52 Gb Free Space | 99,56% Space Free | Partition Type: NTFS Computer Name: FD0DE886EBA84A5 | User Name: 2 | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2014-05-27 19:11:04 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\2\Moje dokumenty\Pobrane\OTL.exe PRC - [2014-05-25 01:49:35 | 001,004,864 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe PRC - [2014-05-24 09:06:06 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2014-04-14 20:08:53 | 000,182,696 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe PRC - [2013-10-16 02:40:00 | 000,214,512 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe PRC - [2012-10-02 13:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) -- C:\Documents and Settings\All Users\Dane aplikacji\Skype\Toolbars\Skype C2C Service\c2c_service.exe PRC - [2010-05-21 13:56:04 | 000,499,796 | ---- | M] (Atheros) -- C:\WINDOWS\system32\acs.exe PRC - [2010-05-21 13:55:40 | 000,561,263 | ---- | M] () -- C:\Program Files\TP-LINK\TP-LINK Wireless Client Utility\TWCU.exe PRC - [2009-09-17 03:30:12 | 001,933,381 | ---- | M] (Informer Technologies, Inc.) -- C:\Program Files\Software Informer\softinfo.exe PRC - [2008-04-14 19:21:16 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007-11-06 16:38:44 | 000,009,216 | ---- | M] (Agere Systems) -- C:\WINDOWS\system32\agrsmsvc.exe PRC - [2007-01-16 13:42:20 | 000,950,272 | ---- | M] ( ) -- C:\Program Files\SAGEM WiFi manager\WLANUTL.EXE PRC - [2006-07-10 18:33:48 | 000,675,840 | ---- | M] (Sonix) -- C:\WINDOWS\vsnp2std.exe PRC - [2006-07-07 16:04:32 | 000,258,048 | ---- | M] () -- C:\WINDOWS\tsnp2std.exe PRC - [2003-02-19 15:03:16 | 000,253,952 | ---- | M] () -- C:\Program Files\Labtec\Wireless Mouse\MulMouse.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2014-05-24 09:05:36 | 003,845,232 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll MOD - [2014-05-07 12:58:48 | 000,253,952 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\WindowsFormsIntegra#\360603d8efa82557e7fce70287cb242e\WindowsFormsIntegration.ni.dll MOD - [2014-05-07 12:57:42 | 018,109,440 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\dd733c6f1f9f50f3517d48da5bea80d2\System.ServiceModel.ni.dll MOD - [2014-05-07 09:19:28 | 001,801,728 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xaml\d116eda30a35c490e59221b0ebac6fcd\System.Xaml.ni.dll MOD - [2014-05-07 00:55:08 | 000,755,712 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\67939f4c3d18712bacf74bfc8c75ab40\PresentationFramework.Luna.ni.dll MOD - [2014-05-07 00:54:35 | 018,003,456 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\9aafa1869d136f77bc483f25d0795229\PresentationFramework.ni.dll MOD - [2014-05-07 00:52:09 | 011,451,904 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationCore\b307821c69c09ed0a2ee47122fdcdd4d\PresentationCore.ni.dll MOD - [2014-05-07 00:50:29 | 003,858,944 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\WindowsBase\49605239a73cd565e3a08048a31b442e\WindowsBase.ni.dll MOD - [2014-05-07 00:17:06 | 005,628,928 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\850fa7110c7423c324762c1ad3130219\System.Xml.ni.dll MOD - [2014-05-07 00:16:51 | 001,014,272 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\991c4e11f571a4074b9c4a5841222338\System.Configuration.ni.dll MOD - [2014-05-07 00:16:34 | 007,053,824 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\a4b5a1a06d2d7f77258943c8c228a5e0\System.Core.ni.dll MOD - [2014-05-07 00:16:05 | 009,099,776 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\4c906eb82e6f56aea01b2a7291fab7ea\System.ni.dll MOD - [2014-05-07 00:15:27 | 014,416,896 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\4e62d1d9b7dd2c2d14915abb73c22d50\mscorlib.ni.dll MOD - [2014-04-14 20:07:12 | 000,018,856 | ---- | M] () -- C:\Program Files\Java\jre7\bin\jp2native.dll MOD - [2013-06-17 12:35:10 | 000,478,400 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll MOD - [2013-05-08 14:52:14 | 001,270,464 | ---- | M] () -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\kpcengine.2.3.dll MOD - [2010-05-21 13:55:58 | 000,278,528 | ---- | M] () -- C:\Program Files\TP-LINK\TP-LINK Wireless Client Utility\twculoc.dll MOD - [2010-05-21 13:55:58 | 000,163,840 | ---- | M] () -- C:\Program Files\TP-LINK\TP-LINK Wireless Client Utility\oemresloc.dll MOD - [2010-05-21 13:55:54 | 000,077,824 | ---- | M] () -- C:\WINDOWS\system32\wgapiloc.dll MOD - [2010-05-21 13:55:40 | 000,561,263 | ---- | M] () -- C:\Program Files\TP-LINK\TP-LINK Wireless Client Utility\TWCU.exe MOD - [2010-05-21 13:55:40 | 000,422,000 | ---- | M] () -- C:\WINDOWS\system32\wgapi.dll MOD - [2008-04-14 19:20:37 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll MOD - [2008-03-29 17:42:20 | 000,159,744 | ---- | M] () -- C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll MOD - [2008-03-29 17:41:52 | 000,023,552 | ---- | M] () -- C:\Program Files\Haali\MatroskaSplitter\mkunicode.dll MOD - [2007-01-16 13:52:18 | 000,212,992 | ---- | M] () -- C:\Program Files\SAGEM WiFi manager\dot1x_dll.dll MOD - [2007-01-16 13:52:18 | 000,045,056 | ---- | M] () -- C:\Program Files\SAGEM WiFi manager\ZDWlan.dll MOD - [2006-07-07 16:04:32 | 000,258,048 | ---- | M] () -- C:\WINDOWS\tsnp2std.exe MOD - [2003-02-19 15:03:16 | 000,253,952 | ---- | M] () -- C:\Program Files\Labtec\Wireless Mouse\MulMouse.exe MOD - [2003-01-29 17:25:04 | 000,159,744 | ---- | M] () -- C:\Program Files\Labtec\Wireless Mouse\Function\Function.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc) SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt) SRV - [2014-05-24 09:05:45 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2014-05-14 14:17:29 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2014-04-14 20:08:53 | 000,182,696 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService) SRV - [2013-10-23 08:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2013-10-16 02:40:00 | 000,214,512 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe -- (AVP) SRV - [2012-10-02 13:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\Documents and Settings\All Users\Dane aplikacji\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service) SRV - [2010-05-21 13:56:04 | 000,499,796 | ---- | M] (Atheros) [Auto | Running] -- C:\WINDOWS\system32\acs.exe -- (ACS) SRV - [2008-12-14 20:29:51 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2008-10-25 00:05:05 | 000,069,120 | ---- | M] (element5) [On_Demand | Stopped] -- C:\Program Files\Common Files\element5 Shared\Service\Licence Manager ESD.exe -- (License Management Service ESD) SRV - [2007-11-06 16:38:44 | 000,009,216 | ---- | M] (Agere Systems) [Auto | Running] -- C:\WINDOWS\system32\agrsmsvc.exe -- (AgereModemAudio) SRV - [2007-06-15 17:55:00 | 000,300,544 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) SRV - [2006-04-27 18:35:16 | 000,053,337 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe -- (MSCSPTISRV) SRV - [2006-04-27 18:27:06 | 000,049,241 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR) SRV - [2006-04-27 18:16:28 | 000,069,718 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe -- (SPTISRV) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\ZDPNDIS5.SYS -- (ZDPNDIS5) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\ZDCndis5.SYS -- (ZDCndis5) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\usbser_lowerflt.sys -- (upperdev) DRV - File not found [Kernel | On_Demand | Stopped] -- E:\NTGLM7X.sys -- (SetupNTGLM7X) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\PCANDIS5.SYS -- (PCANDIS5) DRV - File not found [Kernel | On_Demand | Stopped] -- E:\NTACCESS.sys -- (NTACCESS) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | On_Demand | Stopped] -- E:\INSTALL\GMSIPCI.SYS -- (GMSIPCI) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2014-05-25 01:54:48 | 000,144,992 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\kneps.sys -- (kneps) DRV - [2014-05-25 01:54:48 | 000,024,672 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klkbdflt.sys -- (klkbdflt) DRV - [2014-05-25 01:54:46 | 000,576,096 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF) DRV - [2014-05-25 01:54:43 | 000,135,776 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\kl1.sys -- (kl1) DRV - [2013-10-16 02:39:58 | 000,024,672 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klmouflt.sys -- (klmouflt) DRV - [2013-05-14 17:34:44 | 000,045,024 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\kltdi.sys -- (kltdi) DRV - [2013-04-19 11:44:54 | 000,036,448 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klim5.sys -- (klim5) DRV - [2013-04-12 15:34:48 | 000,014,432 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\klpd.sys -- (klpd) DRV - [2010-05-21 13:56:04 | 000,058,208 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wsimd.sys -- (WSIMD) DRV - [2010-01-05 03:31:32 | 001,714,176 | R--- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\athuw.sys -- (AR9271) DRV - [2007-11-06 16:38:44 | 001,161,888 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem) DRV - [2007-01-16 13:52:20 | 000,017,664 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ZDPSp50.sys -- (ZDPSp50) DRV - [2007-01-10 10:14:34 | 000,450,560 | ---- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WlanBZXP.sys -- (SG762_XP) DRV - [2006-08-04 16:30:12 | 011,985,280 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\snp2sxp.sys -- (SNP2STD) DRV - [2006-03-01 09:40:44 | 000,046,080 | ---- | M] (OrangeWare Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ousbehci.sys -- (ousbehci) DRV - [2006-02-26 23:46:20 | 000,081,408 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp) DRV - [2005-07-13 12:08:20 | 000,033,890 | ---- | M] (Service & Quality Technology.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Capt905c.sys -- (SQTECH905C) DRV - [2005-02-23 15:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc) DRV - [2005-01-07 18:07:16 | 000,145,920 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Hdaudio.sys -- (HdAudAddService) DRV - [2004-08-04 00:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) DRV - [2003-02-19 10:02:04 | 000,006,144 | ---- | M] (Waytech Development, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\UsbFltr.sys -- (UsbFltr) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.interia.pl/?utm_source=is IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Local Page = http://www.iesearch.com/ IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Local Page Restore = IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchgateway.net/search/ IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nasza-klasa.pl IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.searchgateway.net/search/ IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.searchgateway.net/search/ IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.interia.pl/?utm_source=is IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://search.bearshare.com/pl/ IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\..\URLSearchHook: {8532a8b7-c06a-41bb-936a-8ce73e4711ed} - C:\Program Files\gry\prxtbgr2.dll (Conduit Ltd.) IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\..\SearchScopes,DefaultScope = {E31E90F3-5A59-46A6-AA83-4A78AE62B39C} IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/web/{searchTerms}?babsrc=SP_ss&affID=103689&mntrId=bca25bbd0000000000000060b34ac75c IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\..\SearchScopes\{569332C2-1244-4B5E-B1E4-CE5014B859BB}: "URL" = http://www.nasza-klasa.pl/szukaj/profile?q={searchTerms} IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&rlz=1I7GGLL_en IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}: "URL" = http://search.bearshare.com/webResults.html?src=ieb&q={searchTerms} IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\..\SearchScopes\{E31E90F3-5A59-46A6-AA83-4A78AE62B39C}: "URL" = http://www.fastbrowsersearch.com/results/results.aspx?q={searchTerms}&c=web&s=DSP&v=19&tid={2A260A44-2E75-425a-BF32-6D288A0527D8} IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\..\SearchScopes\{EC5F3F59-553B-4085-A506-C3C517F22750}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7 IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-507921405-1123561945-725345543-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "http://www.wp.pl/?homepage" FF - prefs.js..extensions.enabledAddons: ffxtlbr%40babylon.com:1.1.9 FF - prefs.js..extensions.enabledAddons: testpilot%40labs.mozilla.com:1.2.3 FF - prefs.js..extensions.enabledAddons: anti_banner%40kaspersky.com:14.0.0.4929 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:30.0 FF - prefs.js..extensions.enabledItems: fdm_ffext@freedownloadmanager.org:1.3.4 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:9.0.0.736 FF - prefs.js..network.proxy.type: 0 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1205146.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@ganymede/BOARDS,version=1.0: C:\Program Files\Ganymede\Plugins\BOARDS\NPBOARDS.dll (Ganymede Technologies) FF - HKLM\Software\MozillaPlugins\@ganymede/GanymedeNetPlugin,version=1.0: C:\Program Files\Ganymede\Plugins\npganymedenet.dll ( ) FF - HKLM\Software\MozillaPlugins\@ganymede/MARBLES,version=1.0: C:\Program Files\Ganymede\Plugins\MARBLES\NPMARBLES.dll (Ganymede Technologies) FF - HKLM\Software\MozillaPlugins\@ganymede/SOLITAIRE,version=1.0: C:\Program Files\Ganymede\Plugins\SOLITAIRE\NPSOLITAIRE.dll (Ganymede Technologies) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.55.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.55.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKLM\Software\MozillaPlugins\yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.) FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll File not found FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\url_advisor@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-05-25 02:00:03 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\virtual_keyboard@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-05-25 02:00:07 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\content_blocker@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-05-25 01:59:55 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\anti_banner@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-05-25 01:59:55 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\online_banking@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-05-25 02:00:00 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 30.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2014-05-24 09:03:24 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 30.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014-05-24 09:03:36 | 000,000,000 | ---D | M] [2008-09-07 00:28:24 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\2\Dane aplikacji\Mozilla\Extensions [2014-04-02 08:53:19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\2\Dane aplikacji\Mozilla\Firefox\Profiles\dyf6eu4l.default\extensions [2011-10-10 12:46:26 | 000,000,000 | ---D | M] (Babylon) -- C:\Documents and Settings\2\Dane aplikacji\Mozilla\Firefox\Profiles\dyf6eu4l.default\extensions\ffxtlbr@babylon.com [2011-12-24 10:01:44 | 000,010,043 | ---- | M] () (No name found) -- C:\Documents and Settings\2\Dane aplikacji\Mozilla\Firefox\Profiles\dyf6eu4l.default\extensions\IplextoALL@ALLPlayer.org.xpi [2013-11-20 20:59:09 | 000,619,291 | ---- | M] () (No name found) -- C:\Documents and Settings\2\Dane aplikacji\Mozilla\Firefox\Profiles\dyf6eu4l.default\extensions\testpilot@labs.mozilla.com.xpi [2012-02-02 10:17:36 | 000,020,591 | ---- | M] () (No name found) -- C:\Documents and Settings\2\Dane aplikacji\Mozilla\Firefox\Profiles\dyf6eu4l.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi [2008-08-18 00:27:18 | 000,001,622 | ---- | M] () -- C:\Documents and Settings\2\Dane aplikacji\Mozilla\Firefox\Profiles\dyf6eu4l.default\searchplugins\ask.xml [2011-03-13 16:50:40 | 000,001,244 | ---- | M] () -- C:\Documents and Settings\2\Dane aplikacji\Mozilla\Firefox\Profiles\dyf6eu4l.default\searchplugins\winamp-search.xml [2014-05-24 09:03:27 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2014-05-24 09:03:27 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-05-24 09:03:26 | 000,000,000 | ---D | M] (Blokowanie banerów) -- C:\Program Files\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru [2014-05-24 09:03:27 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru [2014-05-24 09:03:23 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions [2014-05-24 09:03:23 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2014-05-25 01:59:55 | 000,000,000 | ---D | M] (Chặn quảng cáo) -- C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 14.0.0\FFEXT\ANTI_BANNER@KASPERSKY.COM [2011-07-15 13:24:52 | 000,932,008 | ---- | M] (Ganymede Technologies) -- C:\Program Files\mozilla firefox\plugins\NPBOARDS.dll [2009-11-16 17:23:30 | 000,120,296 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npganymedenet.dll [2011-07-15 13:24:16 | 000,665,784 | ---- | M] (Ganymede Technologies) -- C:\Program Files\mozilla firefox\plugins\NPMARBLES.dll [2011-07-15 13:23:34 | 000,510,120 | ---- | M] (Ganymede Technologies) -- C:\Program Files\mozilla firefox\plugins\NPSOLITAIRE.dll [color=#E56717]========== Chrome ==========[/color] CHR - default_search_provider: (Enabled) CHR - default_search_provider: search_url = CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter}, CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\35.0.1916.114\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: Shockwave for Director (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\35.0.1916.114\pdf.dll CHR - plugin: Babylon Chrome Plugin (Enabled) = C:\Documents and Settings\2\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.0_0\BabylonChromePI.dll CHR - plugin: Skype Toolbars (Enabled) = C:\Documents and Settings\2\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll CHR - plugin: Ganymede Boards Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPBOARDS.dll CHR - plugin: GanymedeNet.Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npganymedenet.dll CHR - plugin: Ganymede Marbles Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPMARBLES.dll CHR - plugin: Ganymede Solitaire Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPSOLITAIRE.dll CHR - plugin: Microsoft® DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll CHR - plugin: Microsoft® DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.1739.5352\npCIDetect13.dll CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll CHR - plugin: Yahoo! activeX Plug-in Bridge (Enabled) = C:\Program Files\Yahoo!\Common\npyaxmpb.dll CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - plugin: Default Plug-in (Enabled) = default_plugin CHR - Extension: No name found = C:\Documents and Settings\2\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\14.0.0.4651_0\ CHR - Extension: Skype Toolbars = C:\Documents and Settings\2\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.0_0\ CHR - Extension: Skype Toolbars = C:\Documents and Settings\2\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.9_0\ CHR - Extension: No name found = C:\Documents and Settings\2\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\14.0.0.4651_0\ CHR - Extension: No name found = C:\Documents and Settings\2\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\14.0.0.4651_0\ CHR - Extension: No name found = C:\Documents and Settings\2\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\14.0.0.4917_0\ CHR - Extension: Adobe Acrobat = C:\Documents and Settings\2\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.3.0.11079_1\ CHR - Extension: Adobe Acrobat = C:\Documents and Settings\2\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\7.2.15747.10003_0\ CHR - Extension: No name found = C:\Documents and Settings\2\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\ CHR - Extension: No name found = C:\Documents and Settings\2\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\14.0.0.4651_0\ O1 HOSTS File: ([2006-03-02 14:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (gry Toolbar) - {8532a8b7-c06a-41bb-936a-8ce73e4711ed} - C:\Program Files\gry\prxtbgr2.dll (Conduit Ltd.) O2 - BHO: (BrowserHelper Class) - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll (Make The Web Better, LLC) O2 - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) O2 - BHO: (Search Assistant) - {F0626A63-410B-45E2-99A1-3F2475B2D695} - C:\Program Files\SGPSA\BHO.dll (MTWB) O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10\_userdata\ggbho.2.dll (GG Network S.A.) O2 - BHO: (IEButton Class) - {F81D52BF-F2F1-4F49-BF5F-05664E803039} - C:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll (UnH Solutions) O2 - BHO: (Fast Browser Search Toolbar Helper) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll () O3 - HKLM\..\Toolbar: (Fast Browser Search Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll () O3 - HKLM\..\Toolbar: (gry Toolbar) - {8532a8b7-c06a-41bb-936a-8ce73e4711ed} - C:\Program Files\gry\prxtbgr2.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare) O3 - HKU\S-1-5-21-507921405-1123561945-725345543-1005\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O3 - HKU\S-1-5-21-507921405-1123561945-725345543-1005\..\Toolbar\ShellBrowser: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare) O3 - HKU\S-1-5-21-507921405-1123561945-725345543-1005\..\Toolbar\WebBrowser: (Fast Browser Search Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll () O3 - HKU\S-1-5-21-507921405-1123561945-725345543-1005\..\Toolbar\WebBrowser: (gry Toolbar) - {8532A8B7-C06A-41BB-936A-8CE73E4711ED} - C:\Program Files\gry\prxtbgr2.dll (Conduit Ltd.) O3:HKU - HKU\S-1-5-21-507921405-1123561945-725345543-1005\..\Toolbar\WebBrowser: (gry Toolbar) - {8532A8B7-C06A-41BB-936A-8CE73E4711ED} - C:\Documents and Settings\2\Ustawienia lokalne\Dane aplikacji\gry\prxtbgr0.dll (ClientConnect Ltd.) O3 - HKU\S-1-5-21-507921405-1123561945-725345543-1005\..\Toolbar\WebBrowser: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare) O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\HdAShCut.exe (Windows (R) Server 2003 DDK provider) O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found O4 - HKLM..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe (PixArt Imaging Incorporation) O4 - HKLM..\Run: [NWEReboot] File not found O4 - HKLM..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe (Sonix) O4 - HKLM..\Run: [TaskTray] File not found O4 - HKLM..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe () O4 - HKLM..\Run: [TWCU] C:\Program Files\TP-LINK\TP-LINK Wireless Client Utility\TWCU.exe () O4 - HKU\S-1-5-21-507921405-1123561945-725345543-1005..\Run: [ALLUpdate] "C:\Program Files\ALLPlayer\ALLUpdate.exe" "sleep" File not found O4 - HKU\S-1-5-21-507921405-1123561945-725345543-1005..\Run: [fsm] File not found O4 - HKU\S-1-5-21-507921405-1123561945-725345543-1005..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.) O4 - HKU\S-1-5-21-507921405-1123561945-725345543-1005..\Run: [GG] C:\Documents and Settings\2\Ustawienia lokalne\Dane aplikacji\GG\Application\gghub.exe (GG Network S.A.) O4 - HKU\S-1-5-21-507921405-1123561945-725345543-1005..\Run: [PCSpeedUp] "C:\Program Files\Przyspiesz Komputer\PCSpeedUp.exe" File not found O4 - HKU\S-1-5-21-507921405-1123561945-725345543-1005..\Run: [Software Informer] C:\Program Files\Software Informer\softinfo.exe (Informer Technologies, Inc.) O4 - HKU\S-1-5-21-507921405-1123561945-725345543-1005..\Run: [SsAAD.exe] C:\Program Files\Sony\SonicStage\SSAAD.exe () O4 - Startup: C:\Documents and Settings\1\Menu Start\Programy\Autostart\IMVU.lnk = File not found O4 - Startup: C:\Documents and Settings\2\Menu Start\Programy\Autostart\GameAIR.lnk = File not found O4 - Startup: C:\Documents and Settings\2\Menu Start\Programy\Autostart\Spis treści programu OneNote.onetoc2 () O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ Labtec Mouse Software 2.0.lnk = C:\Program Files\Labtec\Wireless Mouse\MulMouse.exe () O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Program sieciowy dla SAGEM Wi-Fi 11g USB adapter.lnk = C:\Program Files\SAGEM WiFi manager\WLANUTL.EXE ( ) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-507921405-1123561945-725345543-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.) O8 - Extra context menu item: Dodaj do listy blokowanych banerów - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ie_banner_deny.htm () O8 - Extra context menu item: Funkcja Google Sidewiki - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html File not found O8 - Extra context menu item: Pobierz plik wideo w FDM - C:\Program Files\Free Download Manager\dlfvideo.htm () O8 - Extra context menu item: Pobierz w FDM - C:\Program Files\Free Download Manager\dllink.htm () O8 - Extra context menu item: Pobierz wszystkie pliki w FDM - C:\Program Files\Free Download Manager\dlall.htm () O8 - Extra context menu item: Pobierz zaznaczone pliki w FDM - C:\Program Files\Free Download Manager\dlselected.htm () O8 - Extra context menu item: Save Flash - C:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll (UnH Solutions) O8 - Extra context menu item: Save YouTube Video - C:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll (UnH Solutions) O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm () O9 - Extra Button: &Klawiatura wirtualna - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: &Sprawdzanie adresów internetowych - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\1\Menu Start\Programy\IMVU\Run IMVU.lnk File not found O9 - Extra Button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm () O9 - Extra 'Tools' menuitem : Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm () O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.) O16 - DPF: {18506D80-11D4-9B80-82C2-0080C8D7ED4A} http://cached.gamedesire.com/g_bin/pl/roulette_2_0_0_30.cab (GameDesire Roulette) O16 - DPF: {1A781DED-4153-C22D-3213-A3211E29DF13} http://cached.gamedesire.com/g_bin/pl/cards_2_0_0_80.cab (GameDesire Card Games) O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {2A781DED-4153-C22D-9812-CEA98A32981C} http://cached.gamedesire.com/g_bin/pl/cardsmakao_2_0_0_32.cab (GameDesire Makao) O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} http://67.15.101.33/g_bin/pl/boards_2_0_0_35.cab (Ganymede Board Games) O16 - DPF: {41ACD49D-791A-1974-0981-AA9872721044} http://cached.gamedesire.com/g_bin/pl/boards_2_0_0_38.cab (Ganymede Board Games) O16 - DPF: {4539348E-11D5-01D7-9A39-0080C8D85044} http://cached.gamedesire.com/g_bin/pl/slots90_2_0_0_38.cab (GameDesire Slots 90th) O16 - DPF: {83AFB5CA-11D4-ED35-A452-0080C8D85045} http://cached.gamedesire.com/g_bin/pl/poker_2_0_0_52.cab (GameDesire Poker Games) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_11-windows-i586.cab (Java Plug-in 10.55.2) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {A6212120-11D5-01D4-9A39-0080C8D85044} http://cached.gamedesire.com/g_bin/pl/slots70_2_0_0_38.cab (GameDesire Slots 70th) O16 - DPF: {A9ED6AA2-4D71-D9D4-9586-E293E2E3580B} http://cached.gamedesire.com/g_bin/pl/marbles_2_0_0_36.cab (GameDesire Marbles&Diamonds&Runes) O16 - DPF: {AC120B1D-4111-9411-AF52-118052D85D45} http://cached.gamedesire.com/g_bin/pl/darts_2_0_0_48.cab (GameDesire Darts Games) O16 - DPF: {AD7013FF-4F36-1D9A-94A6-3CD408A663F9} http://cached.gamedesire.com/g_bin/pl/breakout_2_0_0_32.cab (GameDesire BreakOut) O16 - DPF: {BFA1F11D-AFE1-3121-4112-894323212DAC} http://cached.gamedesire.com/g_bin/pl/words_2_0_0_54.cab (GameDesire Word Games) O16 - DPF: {BFA1F11D-AFE1-3121-4112-983219421AEF} http://cached.gamedesire.com/g_bin/pl/wordssingle_2_0_0_52.cab (GameDesire 1Player Word Games) O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} http://game.zylom.com/activex/zylomgamesplayer.cab (Zylom Games Player) O16 - DPF: {C186F386-6FC6-414C-AB53-975FB0EB15C1} http://v.netlogstatic.com/v5.00/3099//s/e/Aurigma/ImageUploaderPHP/PhotoUploader.cab (Photo Uploader Control) O16 - DPF: {CAFEEFAC-0017-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_11-windows-i586.cab (Java Plug-in 1.7.0_11) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_11-windows-i586.cab (Java Plug-in 10.55.2) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Reg Error: Key error.) O16 - DPF: {E23FABEE-33DA-12E3-DA12-195DAC123984} http://cached.gamedesire.com/g_bin/pl/mahjong_2_0_0_34.cab (GameDesire Mahjong) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1A95BA81-AE87-432E-AE14-F7BA3F5E9C2D}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4FFBD654-0066-4A0A-9221-C48CF31DAAEC}: DhcpNameServer = 192.168.1.1 0.0.0.0 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\klogon: DllName - (C:\WINDOWS\system32\klogon.dll) - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO) O24 - Desktop Components:0 () - http://www.photofunia.com/output/5/2/h/G/0/hG0pmzZZPekB8qouW3cC8g.gif O24 - Desktop Components:1 () - http://www.photofunia.com/output/5/2/Z/S/N/ZSNIFZJkDAtnZn9XLPw0Ig.gif O24 - Desktop Components:2 () - http://static.nasza-klasa.pl/script/mootools:512f O24 - Desktop Components:3 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\2\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\2\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008-03-11 16:58:41 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2012-06-13 16:55:23 | 000,000,089 | ---- | M] () - D:\AUTORUN.INF -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2014-05-24 17:17:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Kaspersky Internet Security [2014-05-24 17:13:24 | 000,000,000 | ---D | C] -- C:\Program Files\Kaspersky Lab [2014-05-24 17:13:02 | 000,576,096 | ---- | C] (Kaspersky Lab ZAO) -- C:\WINDOWS\System32\drivers\klif.sys [2014-05-24 17:13:02 | 000,093,792 | ---- | C] (Kaspersky Lab ZAO) -- C:\WINDOWS\System32\drivers\klflt.sys [2014-05-24 09:03:22 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2014-05-15 15:07:22 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER [2014-05-11 20:09:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\2\Pulpit\Porządek na pulpicie [2014-05-08 11:18:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\2\Moje dokumenty\Pobrane [2014-04-29 11:17:10 | 000,264,616 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe [2014-04-29 11:17:10 | 000,145,408 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl [2014-04-29 11:16:36 | 000,175,528 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe [2014-04-29 11:16:36 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe [2014-04-29 11:16:36 | 000,094,632 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll [2014-04-29 11:16:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Java [2011-12-28 09:28:36 | 028,942,625 | ---- | C] (ALLPlayer ) -- C:\Documents and Settings\2\ALLPLAYERPL[1].EXE [27 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\Documents and Settings\2\*.tmp files -> C:\Documents and Settings\2\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2014-05-27 19:33:02 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2014-05-27 19:03:18 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2014-05-27 17:38:37 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2014-05-27 17:38:36 | 000,000,214 | ---- | M] () -- C:\WINDOWS\tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — logowanie.job [2014-05-27 17:37:24 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2014-05-27 00:07:24 | 001,353,838 | ---- | M] () -- C:\Documents and Settings\2\Pulpit\WP_20140526_001.jpg [2014-05-27 00:07:22 | 001,351,388 | ---- | M] () -- C:\Documents and Settings\2\Pulpit\WP_20140526_002.jpg [2014-05-25 01:54:48 | 000,144,992 | ---- | M] (Kaspersky Lab ZAO) -- C:\WINDOWS\System32\drivers\kneps.sys [2014-05-25 01:54:48 | 000,024,672 | ---- | M] (Kaspersky Lab ZAO) -- C:\WINDOWS\System32\drivers\klkbdflt.sys [2014-05-25 01:54:46 | 000,576,096 | ---- | M] (Kaspersky Lab ZAO) -- C:\WINDOWS\System32\drivers\klif.sys [2014-05-25 01:54:44 | 000,093,792 | ---- | M] (Kaspersky Lab ZAO) -- C:\WINDOWS\System32\drivers\klflt.sys [2014-05-25 01:54:43 | 000,135,776 | ---- | M] (Kaspersky Lab ZAO) -- C:\WINDOWS\System32\drivers\kl1.sys [2014-05-24 17:19:32 | 000,001,999 | ---- | M] () -- C:\Documents and Settings\2\Pulpit\Bezpieczne pieniądze.lnk [2014-05-24 17:16:44 | 000,000,889 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Kaspersky Internet Security.lnk [2014-05-21 15:01:18 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat [2014-05-18 09:32:50 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2014-05-14 14:17:28 | 000,692,400 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe [2014-05-14 14:17:28 | 000,070,832 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl [2014-05-14 10:17:29 | 000,062,976 | ---- | M] () -- C:\Documents and Settings\2\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2014-05-08 15:42:37 | 000,000,208 | ---- | M] () -- C:\WINDOWS\tasks\Powiadomienie o zakończeniu obsługi systemu Microsoft Windows XP — co miesiąc.job [2014-05-07 00:43:59 | 000,542,822 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2014-05-07 00:43:59 | 000,482,330 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2014-05-07 00:43:59 | 000,099,372 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2014-05-07 00:43:59 | 000,080,212 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2014-04-30 10:12:53 | 006,022,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll [27 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\Documents and Settings\2\*.tmp files -> C:\Documents and Settings\2\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2014-05-27 00:06:45 | 001,353,838 | ---- | C] () -- C:\Documents and Settings\2\Pulpit\WP_20140526_001.jpg [2014-05-27 00:06:43 | 001,351,388 | ---- | C] () -- C:\Documents and Settings\2\Pulpit\WP_20140526_002.jpg [2014-05-24 17:19:32 | 000,001,999 | ---- | C] () -- C:\Documents and Settings\2\Pulpit\Bezpieczne pieniądze.lnk [2014-05-24 17:17:20 | 000,000,889 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Kaspersky Internet Security.lnk [2014-05-08 02:32:57 | 000,231,890 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-S-1-5-21-507921405-1123561945-725345543-1005-0.dat [2014-05-06 02:34:16 | 000,231,890 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\WPFFontCache_v0400-System.dat [2013-12-09 21:55:03 | 000,466,052 | ---- | C] () -- C:\WINDOWS\U2v242.exe [2013-10-20 21:21:34 | 000,258,048 | ---- | C] () -- C:\WINDOWS\tsnp2std.exe [2013-10-20 21:21:33 | 000,015,497 | ---- | C] () -- C:\WINDOWS\snp2std.ini [2013-10-20 21:21:31 | 000,024,832 | ---- | C] () -- C:\WINDOWS\System32\drivers\sncamd.sys [2013-10-20 21:21:29 | 011,985,280 | ---- | C] () -- C:\WINDOWS\System32\drivers\snp2sxp.sys [2013-10-20 21:21:26 | 000,147,456 | ---- | C] ( ) -- C:\WINDOWS\rsnp2std.dll [2013-10-20 20:55:14 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2std.dll [2013-05-25 16:04:26 | 000,359,424 | ---- | C] () -- C:\WINDOWS\callvers.exe [2012-06-11 21:18:45 | 000,262,216 | ---- | C] () -- C:\WINDOWS\System32\IPTests.dll [2012-06-11 21:15:11 | 000,422,000 | ---- | C] () -- C:\WINDOWS\System32\wgapi.dll [2012-06-11 21:15:11 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\wgapiloc.dll [2012-05-01 12:49:33 | 000,017,408 | ---- | C] () -- C:\Documents and Settings\2\Ustawienia lokalne\Dane aplikacji\WebpageIcons.db [2010-06-07 12:43:19 | 000,000,035 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\mainhst.zgh [2010-04-21 17:54:07 | 000,016,384 | ---- | C] () -- C:\Program Files\uik.dat [2010-04-21 17:53:13 | 000,000,004 | ---- | C] () -- C:\Program Files\is.dat [2010-03-13 19:57:33 | 003,772,683 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\cien_melodia.ogg [2010-03-13 19:57:33 | 000,010,463 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\cien_tekst.xml [2010-03-13 19:57:32 | 005,455,991 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\cien_podklad.ogg [2010-03-13 19:37:15 | 003,645,064 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\przybyli_ulani_melo.ogg [2010-03-13 19:37:15 | 000,023,075 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\przybyli_ulani.xml [2010-03-13 19:37:14 | 006,820,779 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\przybyli_ulani_podklad.ogg [2010-03-13 19:29:15 | 003,311,956 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\Gleboka_studzienka_melo.ogg [2010-03-13 19:29:15 | 000,013,868 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\Gleboka_studzienka.xml [2010-03-13 19:29:14 | 007,146,576 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\Gleboka_studzienka_podklad.ogg [2010-03-13 19:24:12 | 000,027,125 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\malgoska_tekst.xml [2010-03-13 19:24:11 | 005,057,290 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\malgoska_melodia.ogg [2010-03-13 19:24:06 | 007,605,121 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\malgoska_podklad.ogg [2010-03-13 19:20:51 | 005,556,748 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\ukraina_melodia.ogg [2010-03-13 19:20:51 | 000,033,111 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\ukraina_tekst.xml [2010-03-13 19:20:49 | 009,125,381 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\ukraina_podklad.ogg [2010-03-13 19:12:39 | 000,036,536 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\agnieszka_tekst.xml [2010-03-13 19:12:38 | 004,458,099 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\agnieszka_melodia.ogg [2010-03-13 19:12:37 | 006,039,910 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\agnieszka_podklad.ogg [2010-03-13 19:08:37 | 000,020,420 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\zero_tekst.xml [2010-03-13 19:08:36 | 005,153,111 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\zero_melodia.ogg [2010-03-13 19:08:35 | 006,924,206 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\zero_podklad.ogg [2010-03-13 19:01:55 | 000,018,450 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\przezyj_tekst.xml [2010-03-13 19:01:54 | 006,166,126 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\przezyj_melodia.ogg [2010-03-13 19:01:53 | 008,204,987 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\przezyj_podklad.ogg [2010-03-13 18:57:13 | 000,021,964 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\irlandia_tekst.xml [2010-03-13 18:57:12 | 005,863,438 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\irlandia_melodia.ogg [2010-03-13 18:57:06 | 008,005,311 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\irlandia_podklad.ogg [2010-03-13 18:56:50 | 000,025,574 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\kropla_tekst.xml [2010-03-13 18:56:49 | 007,080,141 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\kropla_podklad.ogg [2010-03-13 18:56:49 | 004,740,267 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\kropla_melodia.ogg [2010-01-24 20:16:56 | 006,155,624 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\bohema_podklad.ogg [2010-01-24 20:16:56 | 004,457,592 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\bohema_melodia.ogg [2010-01-24 20:16:56 | 000,019,296 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\bohema_tekst.xml [2010-01-21 22:49:27 | 003,730,759 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\wlosy_melodia.ogg [2010-01-21 22:49:27 | 000,028,067 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\wlosy_tekst.xml [2010-01-21 22:49:26 | 006,230,213 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\wlosy_podklad.ogg [2010-01-21 22:45:24 | 004,056,067 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\szal_melodia.ogg [2010-01-21 22:45:24 | 000,009,872 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\szal_tekst.xml [2010-01-21 22:45:23 | 005,581,660 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\szal_podklad.ogg [2010-01-14 21:53:40 | 003,577,058 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\przepijemy_melo.ogg [2010-01-14 21:53:40 | 000,023,843 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\przepijemy.xml [2010-01-14 21:53:39 | 008,517,520 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\przepijemy_podklad.ogg [2010-01-14 21:46:26 | 004,018,353 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\Granica_melo.ogg [2010-01-14 21:46:26 | 000,014,807 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\Granica.xml [2010-01-14 21:46:25 | 007,992,809 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\Granica_podklad.ogg [2010-01-14 21:42:22 | 000,017,560 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\goralu.xml [2010-01-14 21:42:21 | 005,833,417 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\goralu_melo.ogg [2010-01-14 21:42:20 | 009,412,272 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\goralu_podklad.ogg [2010-01-14 21:38:43 | 005,124,712 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\pytaj_melodia.ogg [2010-01-14 21:38:43 | 000,022,722 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\pytaj_tekst.xml [2010-01-14 21:38:38 | 007,524,267 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\pytaj_podklad.ogg [2010-01-14 21:29:58 | 003,926,146 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\pomaluj_melodia.ogg [2010-01-14 21:29:58 | 000,028,566 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\pomaluj_tekst.xml [2010-01-14 21:29:57 | 005,947,054 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\pomaluj_podklad.ogg [2010-01-14 21:19:53 | 000,023,535 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\zawsze_tekst.xml [2010-01-14 21:19:52 | 008,106,488 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\zawsze_podklad.ogg [2010-01-14 21:19:52 | 005,213,182 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\zawsze_melodia.ogg [2010-01-14 21:13:58 | 003,397,418 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\dzieci_melodia.ogg [2010-01-14 21:13:58 | 000,032,431 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\dzieci_tekst.xml [2010-01-14 21:13:57 | 004,609,428 | ---- | C] () -- C:\Documents and Settings\2\Dane aplikacji\dzieci_podklad.ogg [2009-10-04 21:58:09 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\2\Zdjęcie013.jpg [2009-09-02 08:02:43 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\2\Y2Y2 [2009-06-17 15:17:02 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\2\Y¤Y¤ [2009-04-26 21:08:33 | 000,129,024 | ---- | C] () -- C:\Program Files\UNWISE.EXE [2008-11-07 19:29:46 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\2\4hwjm0637y5a4ehgqpb.jpg [2008-11-07 19:29:40 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\2\3hwno10odps04np202.jpg [2008-11-07 19:29:32 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\2\2pwqm4t11n0fdk01qqzg.jpg [2008-11-07 19:28:54 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\2\1tuqnfvu5syzy69z93hm.jpg [2008-11-07 19:28:44 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\2\1gjssjk21bxetjdwz88r.jpg [2008-11-07 19:28:05 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\2\0t2lnl1trftcmdrrsh.jpg [2008-10-26 00:32:44 | 000,000,286 | ---- | C] () -- C:\Documents and Settings\2\Ahmbed.gz [2008-10-03 16:22:47 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\2\DSC00105.JPG [2008-10-03 16:21:19 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\2\DSC00103.JPG [2008-10-03 16:20:29 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\2\DSC00096.JPG [2008-10-03 16:19:08 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\2\DSC00090.JPG [2008-10-03 16:18:18 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\2\DSC00088.JPG [2008-10-03 16:18:03 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\2\DSC00087.JPG [2008-08-31 22:55:38 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\2\Photo-0291.jpg [2008-08-31 22:55:19 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\2\Photo-0289.jpg [2008-04-19 23:08:31 | 000,062,976 | ---- | C] () -- C:\Documents and Settings\2\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008-03-14 22:08:54 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat [2002-07-01 16:13:30 | 000,000,243 | -HS- | C] () -- C:\Documents and Settings\2\Dane aplikacji\system16driver.dat [2002-07-01 16:13:30 | 000,000,224 | -HS- | C] () -- C:\Documents and Settings\2\Dane aplikacji\maildriver32.dat [color=#E56717]========== ZeroAccess Check ==========[/color] [2008-03-12 15:05:16 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2009-07-18 18:05:06 | 001,509,888 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009-02-09 12:53:44 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008-04-14 19:20:57 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2008-05-15 10:28:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\1\Dane aplikacji\Kingston [2009-02-01 07:54:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\1\Dane aplikacji\PC Suite [2009-06-26 11:54:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\Ancient Quest of Saqqarah__cminion [2009-02-01 00:54:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\Ashampoo [2011-10-10 12:46:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\Babylon [2010-12-21 16:31:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\BabylonToolbar [2009-12-08 08:35:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\EnchantedCavern [2013-10-01 09:22:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\Free Download Manager [2010-12-26 13:46:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\FUJIFILM [2008-12-20 22:25:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\Gadu-Gadu [2010-12-25 02:41:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\Gadu-Gadu 10 [2010-04-16 01:01:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\gameair.4374F677980F5CCC5823BFA1032EF5473D41C9C7.1 [2013-10-16 20:05:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\GanymedeNet [2014-05-27 17:43:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\GG [2014-05-27 19:07:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\go [2010-12-24 23:58:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\ipla [2012-11-02 14:15:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\Jardinains 2! [2009-02-01 02:58:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\LimeWire [2009-06-26 11:39:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\MagicMatch [2009-01-11 01:25:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\Nokia [2010-03-17 15:55:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\Nowe Gadu-Gadu [2009-09-06 23:33:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\OpenFM [2009-01-11 01:05:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\PC Suite [2014-05-26 14:01:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\PriceGong [2008-03-13 18:59:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\PWNEncy2006 [2010-11-11 03:44:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\RDRM [2010-01-12 12:40:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\Reg-Tool [2009-06-26 11:39:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\Saqqarah [2014-05-27 17:42:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\Software Informer [2009-01-09 06:43:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\StoneLoops [2009-01-09 06:43:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\StoneLoops! [2011-02-25 09:54:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\Uniblue [2010-06-07 12:43:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\2\Dane aplikacji\ZipGenius [2010-04-11 11:33:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\AlawarWrapper [2009-02-01 00:54:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ashampoo [2011-10-10 12:46:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Babylon [2011-07-18 12:42:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Easy Driver Pro [2011-06-19 21:05:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Easybits GO [2008-10-25 00:05:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\element5 [2013-01-15 19:34:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Free Download Manager [2008-06-26 23:30:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\FreeDownloadManager.ORG [2010-03-18 23:40:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10 [2009-12-02 01:41:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\GameHouse [2013-01-14 15:14:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\GG [2009-12-30 18:57:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\HipSoft [2009-01-11 01:03:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Installations [2010-11-11 03:44:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ipla [2010-07-05 01:06:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\OpenFM [2009-01-11 01:14:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PC Suite [2009-12-18 01:10:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP [2012-06-11 15:04:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TP-LINK [2009-11-11 14:55:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\WinZip [2009-12-02 01:40:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Zylom [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:20C3AB27 < End of report >