OTL logfile created on: 2014-10-28 18:33:07 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Gosia\Downloads Windows Vista Home Basic Edition (Version = 6.0.6000) - Type = NTWorkstation Internet Explorer (Version = 7.0.6000.16982) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,99 Gb Total Physical Memory | 0,50 Gb Available Physical Memory | 24,97% Memory free 4,20 Gb Paging File | 2,42 Gb Available in Paging File | 57,73% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 148,05 Gb Total Space | 68,90 Gb Free Space | 46,54% Space Free | Partition Type: NTFS Computer Name: GOSIA-PC | User Name: Gosia | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 360 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2014-10-28 18:30:54 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Gosia\Downloads\OTL.exe PRC - [2014-10-22 23:20:02 | 000,230,792 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.3.25.5\GoogleCrashHandler.exe PRC - [2014-10-10 03:04:06 | 000,854,344 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe PRC - [2014-08-25 10:42:20 | 003,242,000 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgidsagent.exe PRC - [2014-08-25 10:41:34 | 001,417,160 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgfws.exe PRC - [2014-08-25 10:40:08 | 000,846,864 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgrsx.exe PRC - [2014-08-25 10:39:18 | 000,643,088 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgcsrvx.exe PRC - [2014-08-25 10:39:12 | 000,838,160 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgnsx.exe PRC - [2014-08-25 10:38:58 | 000,289,328 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgwdsvc.exe PRC - [2014-08-25 10:37:18 | 005,188,112 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgui.exe PRC - [2014-08-25 10:31:58 | 000,657,936 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgemcx.exe PRC - [2014-03-10 15:58:48 | 000,146,920 | ---- | M] (SaveSense) -- C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe PRC - [2013-01-22 20:12:22 | 002,923,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2010-03-10 13:26:48 | 000,189,728 | ---- | M] (Protexis Inc.) -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe PRC - [2007-09-28 19:22:00 | 000,247,088 | ---- | M] (BIT LEADER) -- C:\Program Files\lg_swupdate\GiljabiStart.exe PRC - [2007-07-06 13:44:04 | 000,565,248 | ---- | M] (MSI) -- C:\Program Files\LG Software\System Control Manager\MGSysCtrl.exe PRC - [2007-04-13 08:20:22 | 000,097,432 | ---- | M] () -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe PRC - [2007-02-12 16:43:44 | 000,065,536 | ---- | M] (O2Micro International) -- C:\Program Files\O2Micro Oz128 Driver\o2flash.exe PRC - [2007-02-04 12:02:14 | 000,079,400 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe PRC - [2006-11-02 10:44:59 | 000,068,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe PRC - [2006-10-05 04:10:12 | 000,009,216 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe PRC - [2006-03-02 16:43:24 | 000,040,960 | ---- | M] () -- C:\Program Files\LG Software\System Control Manager\edd.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2014-10-10 03:04:04 | 014,902,600 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\38.0.2125.104\PepperFlash\pepflashplayer.dll MOD - [2014-10-10 03:04:02 | 008,910,664 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\38.0.2125.104\pdf.dll MOD - [2014-10-10 03:03:53 | 001,681,224 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\38.0.2125.104\ffmpegsumo.dll MOD - [2014-02-10 12:44:24 | 004,592,128 | ---- | M] () -- C:\Users\Gosia\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libglesv2.dll MOD - [2014-02-10 12:44:24 | 000,112,128 | ---- | M] () -- C:\Users\Gosia\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libegl.dll MOD - [2013-02-04 22:38:06 | 000,998,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\22e348e7fee20fcb2013d3dfe016ae8e\System.Management.ni.dll MOD - [2013-02-04 11:27:22 | 001,712,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\bce81bf63e63ec436b4bc274c08f842d\Microsoft.VisualBasic.ni.dll MOD - [2013-02-04 10:50:14 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\cccf9e783368088a6d357cc45f446478\Accessibility.ni.dll MOD - [2013-02-04 10:50:11 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\23281812ddf7a1fab881b5322e577ac4\System.Runtime.Remoting.ni.dll MOD - [2013-02-04 10:49:47 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e6001d416f7c468334934a2c6a41c631\System.Configuration.ni.dll MOD - [2013-02-04 01:39:11 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\7208ffa39630e9b923331f9df0947a12\System.Xml.ni.dll MOD - [2013-02-04 01:38:12 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1941d7639299344ae28fb6b23da65247\System.Windows.Forms.ni.dll MOD - [2013-02-04 01:37:52 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6312464f64727a2a50d5ce3fd73ad1bb\System.Drawing.ni.dll MOD - [2013-02-04 01:35:26 | 007,868,416 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\52e1ea3c7491e05cda766d7b3ce3d559\System.ni.dll MOD - [2013-02-04 01:35:06 | 011,486,720 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\17f572b09facdc5fda9431558eb7a26e\mscorlib.ni.dll MOD - [2013-01-24 17:36:52 | 000,311,296 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pl_b77a5c561934e089\mscorlib.resources.dll MOD - [2013-01-24 17:36:50 | 000,208,896 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pl_b77a5c561934e089\System.resources.dll MOD - [2013-01-24 17:36:49 | 000,425,984 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_pl_b77a5c561934e089\System.Windows.Forms.resources.dll MOD - [2013-01-23 06:28:55 | 000,372,736 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll MOD - [2007-03-30 03:04:48 | 000,249,856 | ---- | M] () -- C:\Windows\System32\igfxTMM.dll MOD - [2007-03-21 14:05:54 | 000,098,304 | ---- | M] () -- C:\Windows\System32\MGHwCtrl.dll MOD - [2007-02-06 13:00:00 | 000,009,728 | ---- | M] () -- C:\Program Files\lg_swupdate\AxInterop.InetCtlsObjects.dll MOD - [2007-01-23 11:31:52 | 000,010,752 | ---- | M] () -- C:\Program Files\LG Software\System Control Manager\MGKBHook.dll MOD - [2006-01-18 13:50:18 | 000,290,816 | ---- | M] () -- C:\Program Files\LG Software\System Control Manager\CmSuppX.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [Auto | Stopped] -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon -- (CLTNetCnService) SRV - [2014-09-28 23:49:18 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2014-08-25 10:42:20 | 003,242,000 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2014\avgidsagent.exe -- (AVGIDSAgent) SRV - [2014-08-25 10:41:34 | 001,417,160 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2014\avgfws.exe -- (avgfws) SRV - [2014-08-25 10:38:58 | 000,289,328 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2014\avgwdsvc.exe -- (avgwd) SRV - [2014-03-10 15:58:48 | 000,146,920 | ---- | M] (SaveSense) [On_Demand | Stopped] -- C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe -- (savesenselivem) SRV - [2014-03-10 15:58:48 | 000,146,920 | ---- | M] (SaveSense) [Auto | Stopped] -- C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe -- (savesenselive) SRV - [2013-01-22 20:31:57 | 000,265,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2010-03-10 13:26:48 | 000,189,728 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2) SRV - [2007-04-13 08:20:22 | 000,097,432 | ---- | M] () [Auto | Running] -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC) SRV - [2007-02-12 16:43:44 | 000,065,536 | ---- | M] (O2Micro International) [Auto | Running] -- C:\Program Files\O2Micro Oz128 Driver\o2flash.exe -- (o2flash) SRV - [2006-10-05 04:10:12 | 000,009,216 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio) SRV - [2006-03-02 16:43:24 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\Program Files\LG Software\System Control Manager\edd.exe -- (NishService) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Gosia\AppData\Local\Temp\cpuz134\cpuz134_x32.sys -- (cpuz134) DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive) DRV - [2014-08-06 09:49:48 | 000,098,584 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86) DRV - [2014-07-21 20:03:22 | 000,200,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgidsdriverx.sys -- (AVGIDSDriver) DRV - [2014-06-30 11:43:12 | 000,121,624 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgdiskx.sys -- (Avgdiskx) DRV - [2014-06-17 15:22:02 | 000,188,696 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86) DRV - [2014-06-17 15:21:22 | 000,197,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix) DRV - [2014-06-17 15:18:00 | 000,241,944 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avglogx.sys -- (Avglogx) DRV - [2014-06-17 15:17:58 | 000,147,736 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avgidshx.sys -- (AVGIDSHX) DRV - [2014-06-17 15:06:22 | 000,027,416 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avgrkx86.sys -- (Avgrkx86) DRV - [2014-06-17 15:06:20 | 000,021,272 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgidsshimx.sys -- (AVGIDSShim) DRV - [2014-04-24 11:17:54 | 000,055,232 | ---- | M] (StdLib) [Kernel | System | Running] -- C:\Windows\System32\drivers\{c83c7c03-36f9-4f8f-aa6d-c837575d4eca}t.sys -- ({c83c7c03-36f9-4f8f-aa6d-c837575d4eca}t) DRV - [2013-11-13 09:59:20 | 000,376,920 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl) DRV - [2013-09-26 10:00:38 | 000,047,928 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgfwd6x.sys -- (Avgfwfd) DRV - [2009-01-13 09:45:00 | 000,954,368 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr) DRV - [2008-11-25 15:01:00 | 000,105,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea) DRV - [2008-11-25 15:01:00 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k) DRV - [2008-11-25 15:01:00 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k) DRV - [2007-04-03 10:04:28 | 000,039,680 | ---- | M] (O2Micro ) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\o2media.sys -- (O2MDRDR) DRV - [2007-04-02 16:11:08 | 000,035,712 | ---- | M] (O2Micro ) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\o2sd.sys -- (O2SDRDR) DRV - [2007-01-04 13:48:04 | 000,104,344 | ---- | M] (Analog Devices Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e4usbaw.sys -- (e4usbaw) DRV - [2007-01-04 13:47:48 | 000,069,656 | ---- | M] (Analog Deivces) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\e4ldr.sys -- (E4LOADER) DRV - [2006-11-28 07:11:00 | 001,161,888 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem) DRV - [2006-11-02 08:36:43 | 002,028,032 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300) DRV - [2006-11-02 08:30:56 | 000,044,544 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169) DRV - [2006-11-02 08:30:54 | 001,781,760 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw3v32.sys -- (NETw3v32) DRV - [2006-07-03 10:31:26 | 000,009,088 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\MGHwCtrl.sys -- (MGHwCtrl) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hp&ts=1394463553&from=cor&uid=HitachiXHTS542516K9A300_071224BB0300WCJ7HXUCX IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.sweet-page.com/web/?type=ds&ts=1394463553&from=cor&uid=HitachiXHTS542516K9A300_071224BB0300WCJ7HXUCX&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.sweet-page.com/web/?type=ds&ts=1394463553&from=cor&uid=HitachiXHTS542516K9A300_071224BB0300WCJ7HXUCX&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&st=home&tid=2938 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sweet-page.com/?type=hp&ts=1394463553&from=cor&uid=HitachiXHTS542516K9A300_071224BB0300WCJ7HXUCX IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&st=home&tid=2938 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?si=41460&st=home&tid=2938 IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.certified-toolbar.com?si=41460&st=bs&tid=2938&q={searchTerms} IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.sweet-page.com/web/?type=ds&ts=1394463553&from=cor&uid=HitachiXHTS542516K9A300_071224BB0300WCJ7HXUCX&q={searchTerms} IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www2.delta-search.com/?babsrc=HP_ss&mntrId=D6E10015AF704DD2&affID=119357&tsp=5009 IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sweet-page.com/?type=hp&ts=1394463553&from=cor&uid=HitachiXHTS542516K9A300_071224BB0300WCJ7HXUCX IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q= IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q= IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q= IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&st=home&tid=2938 IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/ IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q= IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q= IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=41460&tid=2938&st=bs&q= IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&st=home&tid=2938 IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?si=41460&st=home&tid=2938 IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\..\URLSearchHook: {D8278076-BC68-4484-9233-6E7F1628B56C} - No CLSID value found IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?FORM=UP97DF&PC=UP97&dt=072313&q={searchTerms}&src=IE-SearchBox IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.buenosearch.com/?q={searchTerms}&babsrc=SP_ss&mntrId=D6E10015AF704DD2&affID=127886&tsp=5180 IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://www.search.ask.com/web?tpid=ORJ-V7-SAT&o=APN11461&pf=V7&p2=%5EBE7%5EOSJ000%5EYY%5EPL&gct=sb&itbv=12.10.6.53&apn_uid=6AAFB0B1-AC35-474F-9FB3-0551CF6D6FF4&apn_ptnrs=BE7&apn_dtid=%5EOSJ000%5EYY%5EPL&apn_dbr=Opera.exe_0_12.17.1863.0&doi=2014-05-22&trgb=IE&q={searchTerms}&psv= IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.sweet-page.com/web/?type=ds&ts=1394463553&from=cor&uid=HitachiXHTS542516K9A300_071224BB0300WCJ7HXUCX&q={searchTerms} IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ITVI_plPL579 IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://www.yd.delta-search.com/?q={searchTerms}&affID=119535&tt=030213_yd&babsrc=SP_ss&mntrId=d6e1c958000000000000000000000000 IE - HKU\S-1-5-21-559585761-812252448-234664116-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.71.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.71.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.updaterss.com/SaveSenseLive Update;version=3: C:\Program Files\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll (SaveSense) FF - HKLM\Software\MozillaPlugins\@tools.updaterss.com/SaveSenseLive Update;version=9: C:\Program Files\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll (SaveSense) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\@vividas.com/npVividasPlayer: C:\Program Files\Vividas\Player\npVividasPlayer.dll ( ) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\quick_start@gmail.com: C:\Users\Gosia\AppData\Roaming\Mozilla\Firefox\Profiles\pcpq7n9y.default\extensions\quick_start@gmail.com [2013-05-20 18:12:14 | 000,003,714 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml [2014-03-10 15:59:16 | 000,000,573 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\sweet-page.xml [color=#E56717]========== Chrome ==========[/color] CHR - plugin: Error reading preferences file CHR - Extension: No name found = C:\Users\Gosia\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.8_0\ CHR - Extension: No name found = C:\Users\Gosia\AppData\Local\Google\Chrome\User Data\Default\Extensions\acfoobbgoakpihljnfedbcfaipcdlfhk\1.6.3_0\ CHR - Extension: No name found = C:\Users\Gosia\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\ CHR - Extension: No name found = C:\Users\Gosia\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\ CHR - Extension: No name found = C:\Users\Gosia\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\ CHR - Extension: No name found = C:\Users\Gosia\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\ CHR - Extension: No name found = C:\Users\Gosia\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.0_0\ CHR - Extension: No name found = C:\Users\Gosia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\ CHR - Extension: No name found = C:\Users\Gosia\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\ O1 HOSTS File: ([2006-09-18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.8.11.10\bh\BabylonToolbar.dll (Babylon BHO) O2 - BHO: (SaveSense) - {71e129ff-6c2a-4984-818c-7e2c998b8d99} - C:\Users\Gosia\AppData\Local\SaveSense\SaveSenseIE.dll (SaveSense) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.8.11.10\BabylonToolbarTlbr.dll (Babylon Ltd.) O3 - HKU\S-1-5-21-559585761-812252448-234664116-1000\..\Toolbar\WebBrowser: (no name) - {434D452D-5637-006A-76A7-7A786E7484D7} - No CLSID value found. O3 - HKU\S-1-5-21-559585761-812252448-234664116-1000\..\Toolbar\WebBrowser: (no name) - {4F524A2D-5637-2D53-4154-7A786E7484D7} - No CLSID value found. O3 - HKU\S-1-5-21-559585761-812252448-234664116-1000\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found. O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.) O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.) O4 - HKLM..\Run: [iPlusManager] C:\Program Files\iPlus\iPlusChecker.exe () O4 - HKLM..\Run: [LG Intelligent Update] C:\Program Files\lg_swupdate\giljabistart.exe (BIT LEADER) O4 - HKLM..\Run: [MGSysCtrl] C:\Program Files\LG Software\System Control Manager\MGSysCtrl.exe (MSI) O4 - HKLM..\Run: [mobilegeni daemon] C:\Program Files\Mobogenie\DaemonProcess.exe File not found O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation) O4 - HKU\S-1-5-21-559585761-812252448-234664116-1000..\Run: [IPLA!] C:\Program Files\ipla\ipla.exe (Redefine Sp z o.o.) O4 - HKU\S-1-5-21-559585761-812252448-234664116-1000..\Run: [Jet Screenshot] C:\Program Files\Jet Screenshot\jetScreenshot.exe (ArcticLine Software) O4 - HKU\S-1-5-21-559585761-812252448-234664116-1000..\Run: [LiveSupport] "C:\Program Files\LiveSupport\LiveSupport.exe" /noshow /log File not found O7 - HKU\S-1-5-21-559585761-812252448-234664116-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95 00 00 00 [binary data] O13 - gopher Prefix: missing O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FD0EEEA8-E3A1-4382-A732-6A89AB19DD52}: DhcpNameServer = 192.168.1.1 192.168.1.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img25.jpg O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img25.jpg O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006-09-18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{d3865cea-d104-11e2-91fd-fbb37fab426d}\Shell\AutoRun\command - "" = E:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\dll32.exe O33 - MountPoints2\{d3865cea-d104-11e2-91fd-fbb37fab426d}\Shell\open\command - "" = E:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\dll32.exe O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 360 Days ==========[/color] [2014-10-28 18:24:37 | 000,000,000 | ---D | C] -- C:\FRST [2014-10-28 17:30:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2014-10-28 17:29:56 | 000,272,808 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe [2014-10-28 17:29:30 | 000,096,680 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll [2014-10-28 17:29:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java [2014-10-28 17:29:29 | 000,175,528 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe [2014-10-28 17:29:29 | 000,175,528 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe [2014-10-28 17:28:45 | 000,000,000 | ---D | C] -- C:\Program Files\Java [2014-10-25 05:17:49 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java(1) [2014-10-25 05:15:41 | 000,000,000 | ---D | C] -- C:\Program Files\Java(3) [2014-10-25 05:02:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome [2014-09-29 21:39:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [2014-09-29 21:39:11 | 000,000,000 | R--D | C] -- C:\Program Files\Skype [2014-09-29 21:39:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype [2014-09-08 22:09:39 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Local\Avg [2014-08-29 18:55:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Avg_Update_0814avt [2014-08-26 15:30:08 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Local\Adobe [2014-08-06 09:49:48 | 000,098,584 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgmfx86.sys [2014-07-26 16:58:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2014-07-25 20:38:38 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Local\Opera Software [2014-07-25 20:38:32 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Roaming\Opera Software [2014-07-25 15:37:28 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Local\Babylon [2014-07-21 20:03:22 | 000,200,984 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgidsdriverx.sys [2014-07-14 19:15:10 | 000,000,000 | ---D | C] -- C:\Users\Gosia\Documents\czytelniczka-znakomita (1) [2014-07-14 18:52:34 | 000,000,000 | ---D | C] -- C:\Program Files\Audioteka.pl [2014-07-10 08:25:26 | 000,000,000 | ---D | C] -- C:\Users\Gosia\Desktop\U Padrego [2014-06-30 11:43:12 | 000,121,624 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgdiskx.sys [2014-06-17 15:22:02 | 000,188,696 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys [2014-06-17 15:21:22 | 000,197,400 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgtdix.sys [2014-06-17 15:18:00 | 000,241,944 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avglogx.sys [2014-06-17 15:17:58 | 000,147,736 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgidshx.sys [2014-06-17 15:06:22 | 000,027,416 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgrkx86.sys [2014-06-17 15:06:20 | 000,021,272 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgidsshimx.sys [2014-06-02 23:46:21 | 000,000,000 | ---D | C] -- C:\Users\Gosia\Documents\Pilica [2014-06-01 20:00:41 | 000,000,000 | ---D | C] -- C:\Users\Gosia\Documents\Rajd 2014 [2014-06-01 17:20:40 | 000,000,000 | ---D | C] -- C:\Users\Gosia\Documents\Zdjęcia z tabletu [2014-05-28 19:37:59 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Local\Deployment [2014-05-28 18:28:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Avg_Update_0214d [2014-05-27 17:27:11 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Roaming\AVG2014 [2014-05-27 17:24:58 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Roaming\TuneUp Software [2014-05-27 17:24:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG [2014-05-27 17:18:42 | 000,000,000 | -H-D | C] -- C:\$AVG [2014-05-27 17:18:42 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2014 [2014-05-27 17:16:41 | 000,000,000 | ---D | C] -- C:\Program Files\AVG [2014-05-27 17:15:29 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Local\MFAData [2014-05-27 17:15:29 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData [2014-05-27 17:15:29 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Local\Avg2014 [2014-05-21 20:31:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER [2014-04-25 19:07:48 | 000,055,232 | ---- | C] (StdLib) -- C:\Windows\System32\drivers\{c83c7c03-36f9-4f8f-aa6d-c837575d4eca}t.sys [2014-04-15 14:04:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PIT Format 2013 [2014-04-15 13:47:25 | 000,000,000 | ---D | C] -- C:\PIT Format 2013 [2014-04-07 18:44:42 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Roaming\Updater [2014-03-31 21:46:48 | 001,070,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSCOMCTL.OCX [2014-03-31 21:46:48 | 000,130,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSSTDFMT.DLL [2014-03-10 16:00:37 | 000,000,000 | ---D | C] -- C:\ProgramData\IePluginService [2014-03-10 16:00:36 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Roaming\SupTab [2014-03-10 16:00:35 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Roaming\Google [2014-03-10 16:00:34 | 000,000,000 | ---D | C] -- C:\Program Files\SupTab [2014-03-10 16:00:28 | 000,000,000 | ---D | C] -- C:\ProgramData\WPM [2014-03-10 15:59:39 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Roaming\sweet-page [2014-03-10 15:58:55 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Local\SaveSenseLive [2014-03-10 15:58:55 | 000,000,000 | ---D | C] -- C:\ProgramData\SaveSenseLive [2014-03-10 15:58:55 | 000,000,000 | ---D | C] -- C:\Program Files\SaveSenseLive [2014-03-10 15:58:41 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Roaming\SaveSense [2014-03-10 15:58:32 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense [2014-03-10 15:58:24 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Local\SaveSense [2014-02-27 23:24:59 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Local\Skype [2014-02-12 23:16:16 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Roaming\Podatnik.info [2014-02-12 22:27:15 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Roaming\DigitalSites [2014-02-06 15:41:45 | 000,000,000 | ---D | C] -- C:\ProgramData\ipla [2014-02-06 15:41:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ipla [2014-01-19 00:00:31 | 000,000,000 | ---D | C] -- C:\Users\Gosia\Documents\asex [2014-01-19 00:00:11 | 000,000,000 | ---D | C] -- C:\Program Files\All Sound Editor XP [2014-01-18 23:58:41 | 000,000,000 | ---D | C] -- C:\Users\Gosia\Documents\asrv [2014-01-18 23:40:40 | 000,000,000 | ---D | C] -- C:\My Recordings [2014-01-18 23:33:48 | 001,355,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvbvm50.dll [2014-01-18 23:33:47 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\comdlg32.ocx [2014-01-18 22:46:07 | 000,000,000 | ---D | C] -- C:\Users\Gosia\Documents\Padre [2014-01-18 22:12:01 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP [2014-01-18 22:06:02 | 000,000,000 | ---D | C] -- C:\Program Files\RegClean Pro [2014-01-18 22:02:09 | 000,000,000 | ---D | C] -- C:\Users\Gosia\.android [2014-01-18 22:02:01 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Local\cache [2014-01-18 22:01:56 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Roaming\newnext.me [2014-01-18 22:01:54 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Local\genienext [2014-01-18 22:01:53 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Local\Mobogenie [2014-01-18 22:01:16 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie [2014-01-18 22:00:03 | 000,000,000 | ---D | C] -- C:\Program Files\BonanzaDeals [2013-12-12 16:43:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth [2013-11-21 19:35:09 | 000,000,000 | ---D | C] -- C:\Users\Gosia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard [2013-01-24 21:43:44 | 000,957,248 | ---- | C] (Microsoft Corporation) -- C:\Users\Gosia\SaveAsPDFandXPS.exe [2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ] [color=#E56717]========== Files - Modified Within 360 Days ==========[/color] [2014-10-28 18:27:00 | 000,000,292 | ---- | M] () -- C:\Windows\tasks\Digital Sites.job [2014-10-28 18:27:00 | 000,000,286 | ---- | M] () -- C:\Windows\tasks\DSite.job [2014-10-28 18:25:00 | 000,001,036 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2014-10-28 18:04:01 | 000,000,918 | ---- | M] () -- C:\Windows\tasks\SaveSenseLiveUpdateTaskMachineUA.job [2014-10-28 17:59:00 | 000,000,292 | ---- | M] () -- C:\Windows\tasks\SaveSense.job [2014-10-28 17:56:22 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job [2014-10-28 17:56:20 | 000,001,200 | ---- | M] () -- C:\Windows\tasks\HDvid Codec V1-updater.job [2014-10-28 17:56:20 | 000,001,194 | ---- | M] () -- C:\Windows\tasks\HDvid Codec V1-codedownloader.job [2014-10-28 17:56:20 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\HDvid Codec V1-enabler.job [2014-10-28 17:56:20 | 000,001,032 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2014-10-28 17:56:20 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\SaveSenseLiveUpdateTaskMachineCore.job [2014-10-28 17:56:08 | 000,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl [2014-10-28 17:55:42 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2014-10-28 17:55:41 | 000,003,072 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2014-10-28 17:55:34 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2014-10-28 17:55:24 | 2138,345,472 | -HS- | M] () -- C:\hiberfil.sys [2014-10-28 17:55:19 | 194,173,381 | ---- | M] () -- C:\Windows\MEMORY.DMP [2014-10-28 17:48:55 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat [2014-10-28 17:28:59 | 000,096,680 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll [2014-10-28 17:28:57 | 000,272,808 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe [2014-10-28 17:28:57 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe [2014-10-28 17:28:57 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe [2014-10-28 16:49:33 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2014-10-28 14:56:12 | 000,610,142 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2014-10-28 14:56:12 | 000,535,568 | ---- | M] () -- C:\Windows\System32\perfh015.dat [2014-10-28 14:56:12 | 000,103,924 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2014-10-28 14:56:12 | 000,086,416 | ---- | M] () -- C:\Windows\System32\perfc015.dat [2014-10-25 21:42:09 | 000,001,356 | ---- | M] () -- C:\Users\Gosia\AppData\Local\d3d9caps.dat [2014-10-25 05:02:20 | 000,001,983 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2014-10-08 22:44:58 | 000,745,744 | ---- | M] () -- C:\Users\Gosia\Desktop\LIST.pdf [2014-10-05 21:39:39 | 000,216,775 | ---- | M] () -- C:\Users\Gosia\Desktop\ODP_26.10.14.pdf [2014-09-30 13:22:41 | 000,000,155 | ---- | M] () -- C:\Windows\Reimage.ini [2014-09-29 21:39:12 | 000,001,880 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk [2014-09-29 07:46:49 | 000,000,754 | ---- | M] () -- C:\Users\Public\Desktop\ipla.lnk [2014-09-28 23:49:17 | 000,701,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe [2014-09-28 23:49:17 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [2014-09-28 23:15:07 | 000,043,457 | ---- | M] () -- C:\Windows\System32\ScanResults.xml [2014-09-28 23:09:38 | 000,000,464 | ---- | M] () -- C:\Windows\System32\ScannerSettings [2014-09-10 08:22:15 | 000,000,878 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2014.lnk [2014-09-09 23:59:04 | 000,000,098 | ---- | M] () -- C:\Users\Gosia\AppData\Roaming\WB.CFG [2014-08-06 09:49:48 | 000,098,584 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgmfx86.sys [2014-07-21 20:03:22 | 000,200,984 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgidsdriverx.sys [2014-07-14 18:58:09 | 112,212,619 | ---- | M] () -- C:\Users\Gosia\Documents\czytelniczka-znakomita (1).zip [2014-06-30 11:43:12 | 000,121,624 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgdiskx.sys [2014-06-17 15:22:02 | 000,188,696 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys [2014-06-17 15:21:22 | 000,197,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgtdix.sys [2014-06-17 15:18:00 | 000,241,944 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avglogx.sys [2014-06-17 15:17:58 | 000,147,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgidshx.sys [2014-06-17 15:06:22 | 000,027,416 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgrkx86.sys [2014-06-17 15:06:20 | 000,021,272 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgidsshimx.sys [2014-05-28 18:28:37 | 000,000,314 | ---- | M] () -- C:\Windows\tasks\0214dUpdateInfo.job [2014-05-23 19:07:40 | 000,000,016 | ---- | M] () -- C:\Windows\System32\coh.cache [2014-04-24 11:17:54 | 000,055,232 | ---- | M] (StdLib) -- C:\Windows\System32\drivers\{c83c7c03-36f9-4f8f-aa6d-c837575d4eca}t.sys [2014-04-22 13:44:59 | 002,260,689 | ---- | M] () -- C:\Users\Gosia\Documents\potwierdzenie.jpg [2014-04-17 09:21:41 | 000,199,271 | ---- | M] () -- C:\Users\Gosia\Documents\Regulamin_składania_wniosków_na_przejazdy_grupowe.pdf [2014-04-15 14:04:25 | 000,000,648 | ---- | M] () -- C:\Users\Public\Desktop\PIT Format 2013.lnk [2014-04-07 16:40:00 | 000,007,680 | ---- | M] () -- C:\Users\Gosia\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2014-04-04 23:30:57 | 006,099,968 | ---- | M] () -- C:\Users\Gosia\Desktop\Noaptebuna1.pps [2014-03-31 21:46:48 | 001,070,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MSCOMCTL.OCX [2014-03-31 21:46:48 | 000,130,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MSSTDFMT.DLL [2014-03-31 08:35:10 | 000,231,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe [2014-01-31 12:07:14 | 000,001,893 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk [2014-01-29 10:05:47 | 000,000,005 | ---- | M] () -- C:\Users\Gosia\AppData\Roaming\WBPU-TTL.DAT [2014-01-21 19:14:47 | 000,002,120 | ---- | M] () -- C:\Users\Public\Desktop\MP210 series On-screen Manual.lnk [2014-01-18 23:02:15 | 000,001,648 | ---- | M] () -- C:\Windows\System32\ASOROSet.bin [2014-01-17 22:14:29 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\UMDF\Msft_User_WpdMtpDr_01_00_00.Wdf [2013-12-12 16:43:21 | 000,002,079 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk [2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2014-10-25 19:09:45 | 2138,345,472 | -HS- | C] () -- C:\hiberfil.sys [2014-10-25 05:02:20 | 000,001,983 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk [2014-10-08 22:44:58 | 000,745,744 | ---- | C] () -- C:\Users\Gosia\Desktop\LIST.pdf [2014-10-05 21:39:34 | 000,216,775 | ---- | C] () -- C:\Users\Gosia\Desktop\ODP_26.10.14.pdf [2014-08-16 19:08:53 | 000,043,457 | ---- | C] () -- C:\Windows\System32\ScanResults.xml [2014-08-16 19:03:58 | 000,000,464 | ---- | C] () -- C:\Windows\System32\ScannerSettings [2014-08-13 23:34:19 | 000,000,155 | ---- | C] () -- C:\Windows\Reimage.ini [2014-07-14 18:57:18 | 112,212,619 | ---- | C] () -- C:\Users\Gosia\Documents\czytelniczka-znakomita (1).zip [2014-05-28 18:28:34 | 000,000,314 | ---- | C] () -- C:\Windows\tasks\0214dUpdateInfo.job [2014-05-27 17:24:58 | 000,000,878 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2014.lnk [2014-04-22 13:44:55 | 002,260,689 | ---- | C] () -- C:\Users\Gosia\Documents\potwierdzenie.jpg [2014-04-17 09:21:41 | 000,199,271 | ---- | C] () -- C:\Users\Gosia\Documents\Regulamin_składania_wniosków_na_przejazdy_grupowe.pdf [2014-04-15 14:04:25 | 000,000,648 | ---- | C] () -- C:\Users\Public\Desktop\PIT Format 2013.lnk [2014-04-04 23:30:57 | 006,099,968 | ---- | C] () -- C:\Users\Gosia\Desktop\Noaptebuna1.pps [2014-03-10 15:59:38 | 000,000,918 | ---- | C] () -- C:\Windows\tasks\SaveSenseLiveUpdateTaskMachineUA.job [2014-03-10 15:59:35 | 000,000,914 | ---- | C] () -- C:\Windows\tasks\SaveSenseLiveUpdateTaskMachineCore.job [2014-03-10 15:58:42 | 000,000,292 | ---- | C] () -- C:\Windows\tasks\SaveSense.job [2014-02-27 23:23:43 | 000,001,880 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk [2014-02-12 22:27:16 | 000,000,292 | ---- | C] () -- C:\Windows\tasks\Digital Sites.job [2014-02-06 15:41:31 | 000,000,754 | ---- | C] () -- C:\Users\Public\Desktop\ipla.lnk [2014-01-21 19:14:48 | 000,002,120 | ---- | C] () -- C:\Users\Public\Desktop\MP210 series On-screen Manual.lnk [2014-01-18 22:57:31 | 000,001,648 | ---- | C] () -- C:\Windows\System32\ASOROSet.bin [2013-12-12 16:43:20 | 000,002,079 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk [2013-09-18 19:02:55 | 004,583,169 | ---- | C] () -- C:\Windows\System32\Empik_empikfoto.pl_uninstaller.exe [2013-07-27 09:27:22 | 000,000,098 | ---- | C] () -- C:\Users\Gosia\AppData\Roaming\WB.CFG [2013-07-23 09:53:16 | 000,362,029 | ---- | C] () -- C:\Windows\System32\sqlite3.dll [2013-07-09 16:27:18 | 000,000,005 | ---- | C] () -- C:\Users\Gosia\AppData\Roaming\WBPU-TTL.DAT [2013-07-09 15:28:00 | 000,086,016 | ---- | C] () -- C:\Windows\System32\custmon32i.dll [2013-03-17 17:06:18 | 011,589,032 | ---- | C] () -- C:\Windows\System32\HS7Setup.exe [2013-03-04 12:10:59 | 000,000,412 | ---- | C] () -- C:\Windows\MAXLINK.INI [2013-02-07 19:51:28 | 000,015,360 | ---- | C] () -- C:\Windows\Launcher.exe [2013-02-04 00:02:15 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll [2013-01-25 00:45:52 | 003,448,819 | ---- | C] () -- C:\Users\Gosia\FileScoutInstall.zip [2013-01-24 18:56:35 | 000,679,528 | ---- | C] () -- C:\Users\Gosia\Adobe-Reader(12627).exe [2013-01-22 11:12:46 | 000,098,304 | ---- | C] () -- C:\Windows\System32\MGHwCtrl.dll [2013-01-22 11:12:46 | 000,032,768 | ---- | C] () -- C:\Windows\System32\MGFPCtrl.dll [2013-01-22 11:12:46 | 000,024,576 | ---- | C] () -- C:\Windows\System32\MGPwrShm.dll [2013-01-22 11:05:55 | 000,045,056 | ---- | C] () -- C:\Windows\UncompAVIToWMV2.exe [2013-01-22 10:57:03 | 000,910,304 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll [2013-01-22 10:57:03 | 000,249,856 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll [2013-01-22 10:57:02 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1244.dll [2013-01-22 10:48:40 | 000,010,563 | ---- | C] () -- C:\Windows\lg_up.ini [2013-01-22 10:09:53 | 000,000,995 | ---- | C] () -- C:\Windows\lgcenter.ini [2013-01-22 04:25:00 | 000,007,680 | ---- | C] () -- C:\Users\Gosia\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2013-01-22 03:03:30 | 000,000,168 | ---- | C] () -- C:\Windows\adidsl.ini [2013-01-22 03:03:30 | 000,000,021 | ---- | C] () -- C:\Windows\Fast800.ini [2013-01-22 03:02:12 | 000,253,008 | ---- | C] () -- C:\Windows\adirasx64.exe [2013-01-22 03:02:12 | 000,194,128 | ---- | C] () -- C:\Windows\adiras.exe [2013-01-22 03:02:12 | 000,001,094 | ---- | C] () -- C:\Windows\adiras.ini [2013-01-22 03:02:11 | 000,127,456 | ---- | C] () -- C:\Windows\System32\IPDETECT.EXE [2013-01-22 03:02:09 | 000,152,126 | ---- | C] () -- C:\Windows\System32\drivers\L1E9P2.BIN [2013-01-22 03:02:09 | 000,024,576 | ---- | C] () -- C:\Windows\enddisk32.exe [2013-01-22 03:02:08 | 000,046,892 | ---- | C] () -- C:\Windows\System32\ADADIX16.DLL [2013-01-22 03:02:07 | 000,152,220 | ---- | C] () -- C:\Windows\System32\drivers\L1E4I2.BIN [2013-01-22 03:02:07 | 000,152,220 | ---- | C] () -- C:\Windows\System32\drivers\L1E4I1.BIN [2013-01-22 03:02:07 | 000,152,220 | ---- | C] () -- C:\Windows\System32\drivers\L1E4I0.BIN [2013-01-22 03:02:07 | 000,152,132 | ---- | C] () -- C:\Windows\System32\drivers\L1E4P2.BIN [2013-01-22 03:02:07 | 000,152,132 | ---- | C] () -- C:\Windows\System32\drivers\L1E4P1.BIN [2013-01-22 03:02:07 | 000,152,132 | ---- | C] () -- C:\Windows\System32\drivers\L1E4P0.BIN [2013-01-22 03:02:07 | 000,152,126 | ---- | C] () -- C:\Windows\System32\drivers\L1E9P1.BIN [2013-01-22 03:02:07 | 000,152,126 | ---- | C] () -- C:\Windows\System32\drivers\L1E9P0.BIN [2013-01-22 03:02:07 | 000,152,126 | ---- | C] () -- C:\Windows\System32\drivers\L1E9I2.BIN [2013-01-22 03:02:07 | 000,152,126 | ---- | C] () -- C:\Windows\System32\drivers\L1E9I1.BIN [2013-01-22 03:02:07 | 000,152,126 | ---- | C] () -- C:\Windows\System32\drivers\L1E9I0.BIN [2013-01-22 03:02:07 | 000,152,036 | ---- | C] () -- C:\Windows\System32\drivers\L1E4D2.BIN [2013-01-22 03:02:07 | 000,152,034 | ---- | C] () -- C:\Windows\System32\drivers\L1E4D1.BIN [2013-01-22 03:02:07 | 000,152,034 | ---- | C] () -- C:\Windows\System32\drivers\L1E4D0.BIN [2013-01-22 03:02:07 | 000,022,395 | ---- | C] () -- C:\Windows\System32\drivers\fpga.bin [2013-01-22 02:06:10 | 000,000,184 | ---- | C] () -- C:\Windows\wininit.ini [2013-01-22 02:02:39 | 000,000,100 | ---- | C] () -- C:\Windows\Kit.ini [2013-01-22 01:55:57 | 000,001,356 | ---- | C] () -- C:\Users\Gosia\AppData\Local\d3d9caps.dat [color=#E56717]========== ZeroAccess Check ==========[/color] [2006-11-02 13:51:16 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2013-01-22 20:16:08 | 011,315,712 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2013-01-22 20:05:02 | 000,614,912 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2006-11-02 10:46:13 | 000,348,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2014-07-03 19:49:10 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software [2013-03-17 18:04:01 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\ArcticLine [2014-05-27 17:27:11 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\AVG2014 [2013-07-09 16:11:01 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\BabSolution [2013-02-05 08:55:11 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\Babylon [2014-04-22 13:37:04 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\Canon [2014-02-12 22:27:15 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\DigitalSites [2013-07-09 15:27:34 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\DSite [2013-04-07 18:45:37 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1 [2014-07-22 23:12:46 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\Greenshot [2013-01-22 02:01:03 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\InterTrust [2014-10-28 17:58:12 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\ipla [2014-07-22 23:12:46 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\iPlus [2014-07-22 23:12:46 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\IrfanView [2013-01-23 08:54:40 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\IsolatedStorage [2013-07-09 16:18:00 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\Mobipocket [2014-05-27 17:51:46 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\newnext.me [2014-05-27 06:33:36 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\Opera [2014-07-25 20:38:32 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\Opera Software [2014-05-27 19:31:02 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\PDF Writer Packages [2014-03-08 14:32:16 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\PerformerSoft [2014-07-22 23:12:48 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\PhotoFiltre 7 [2014-02-12 23:20:12 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\Podatnik.info [2014-03-10 15:58:41 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\SaveSense [2013-03-04 12:10:32 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\ScanSoft [2013-02-17 17:28:12 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\Solvusoft [2014-07-22 23:12:48 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\SupTab [2014-09-09 15:24:12 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\sweet-page [2014-09-30 13:19:43 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\Systweak [2014-05-27 17:24:58 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\TuneUp Software [2013-08-17 20:16:11 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\Ulead Systems [2014-04-07 18:45:51 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\Updater [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Files - Unicode (All) ==========[/color] [2013-12-11 18:50:44 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\Ꮘƈ繀Ƣ [2013-12-11 18:50:44 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\Ꮘƈ繀Ƣ [2013-12-11 18:50:44 | 000,000,000 | ---D | C](C:\ProgramData\????) -- C:\ProgramData\Ꮘƈ繀Ƣ [2013-12-06 14:26:28 | 000,000,000 | ---D | M](C:\ProgramData\?5?5) -- C:\ProgramData\㾐5㯨5 [2013-12-06 14:26:28 | 000,000,000 | ---D | M](C:\ProgramData\?5?5) -- C:\ProgramData\㾐5㯨5 [2013-12-06 14:26:28 | 000,000,000 | ---D | C](C:\ProgramData\?5?5) -- C:\ProgramData\㾐5㯨5 [2013-12-04 09:51:43 | 000,000,000 | ---D | M](C:\ProgramData\?I??) -- C:\ProgramData\ᏈƗ繀Ƨ [2013-12-04 09:51:43 | 000,000,000 | ---D | M](C:\ProgramData\?I??) -- C:\ProgramData\ᏈƗ繀Ƨ [2013-12-04 09:51:43 | 000,000,000 | ---D | C](C:\ProgramData\?I??) -- C:\ProgramData\ᏈƗ繀Ƨ [2013-12-03 09:37:00 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐Ž㯨Ž [2013-12-03 09:37:00 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐Ž㯨Ž [2013-12-03 09:37:00 | 000,000,000 | ---D | C](C:\ProgramData\????) -- C:\ProgramData\㾐Ž㯨Ž [2013-12-02 17:54:30 | 000,000,000 | ---D | M](C:\ProgramData\?1?1) -- C:\ProgramData\㾐½㯨½ [2013-12-02 17:54:30 | 000,000,000 | ---D | M](C:\ProgramData\?1?1) -- C:\ProgramData\㾐½㯨½ [2013-12-02 17:54:30 | 000,000,000 | ---D | C](C:\ProgramData\?1?1) -- C:\ProgramData\㾐½㯨½ [2013-11-30 10:30:35 | 000,000,000 | ---D | M](C:\ProgramData\?%?%) -- C:\ProgramData\㾐%㯨% [2013-11-30 10:30:35 | 000,000,000 | ---D | M](C:\ProgramData\?%?%) -- C:\ProgramData\㾐%㯨% [2013-11-30 10:30:35 | 000,000,000 | ---D | C](C:\ProgramData\?%?%) -- C:\ProgramData\㾐%㯨% [2013-11-27 09:38:53 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƦ繀Ƥ [2013-11-27 09:38:53 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƦ繀Ƥ [2013-11-27 09:38:53 | 000,000,000 | ---D | C](C:\ProgramData\????) -- C:\ProgramData\ᏈƦ繀Ƥ [2013-11-21 09:03:23 | 000,000,000 | ---D | M](C:\ProgramData\?G?G) -- C:\ProgramData\㾐Ĝ㯨Ĝ [2013-11-21 09:03:23 | 000,000,000 | ---D | M](C:\ProgramData\?G?G) -- C:\ProgramData\㾐Ĝ㯨Ĝ [2013-11-21 09:03:23 | 000,000,000 | ---D | C](C:\ProgramData\?G?G) -- C:\ProgramData\㾐Ĝ㯨Ĝ [2013-11-20 18:40:03 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈLJ繀Dž [2013-11-20 18:40:03 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈLJ繀Dž [2013-11-20 18:40:03 | 000,000,000 | ---D | C](C:\ProgramData\????) -- C:\ProgramData\ᏈLJ繀Dž [2013-11-19 11:10:08 | 000,000,000 | ---D | M](C:\ProgramData\?e?e) -- C:\ProgramData\㾐ĕ㯨ĕ [2013-11-19 11:10:08 | 000,000,000 | ---D | M](C:\ProgramData\?e?e) -- C:\ProgramData\㾐ĕ㯨ĕ [2013-11-19 11:10:08 | 000,000,000 | ---D | C](C:\ProgramData\?e?e) -- C:\ProgramData\㾐ĕ㯨ĕ [2013-11-13 20:37:59 | 000,000,000 | ---D | M](C:\ProgramData\???G) -- C:\ProgramData\ᏈƷ繀Ġ [2013-11-13 20:37:59 | 000,000,000 | ---D | M](C:\ProgramData\???G) -- C:\ProgramData\ᏈƷ繀Ġ [2013-11-13 20:37:59 | 000,000,000 | ---D | C](C:\ProgramData\???G) -- C:\ProgramData\ᏈƷ繀Ġ [2013-11-12 22:32:24 | 000,000,000 | ---D | M](C:\ProgramData\?N?N) -- C:\ProgramData\㾐N㯨N [2013-11-12 22:32:24 | 000,000,000 | ---D | M](C:\ProgramData\?N?N) -- C:\ProgramData\㾐N㯨N [2013-11-12 22:32:24 | 000,000,000 | ---D | C](C:\ProgramData\?N?N) -- C:\ProgramData\㾐N㯨N [2013-11-12 03:09:35 | 000,000,000 | ---D | M](C:\ProgramData\?˜?˜) -- C:\ProgramData\㾐˜㯨˜ [2013-11-12 03:09:35 | 000,000,000 | ---D | M](C:\ProgramData\?˜?˜) -- C:\ProgramData\㾐˜㯨˜ [2013-11-12 03:09:35 | 000,000,000 | ---D | C](C:\ProgramData\?˜?˜) -- C:\ProgramData\㾐˜㯨˜ [2013-11-10 13:06:56 | 000,000,000 | ---D | M](C:\ProgramData\?9?9) -- C:\ProgramData\㾐9㯨9 [2013-11-10 13:06:56 | 000,000,000 | ---D | M](C:\ProgramData\?9?9) -- C:\ProgramData\㾐9㯨9 [2013-11-10 13:06:56 | 000,000,000 | ---D | C](C:\ProgramData\?9?9) -- C:\ProgramData\㾐9㯨9 [2013-11-06 08:12:05 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƳ繀Þ [2013-11-06 08:12:05 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƳ繀Þ [2013-11-06 08:12:05 | 000,000,000 | ---D | C](C:\ProgramData\????) -- C:\ProgramData\ᏈƳ繀Þ [2013-11-02 20:23:42 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐ʼn㯨ʼn [2013-11-02 20:23:42 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐ʼn㯨ʼn [2013-11-02 20:23:42 | 000,000,000 | ---D | C](C:\ProgramData\????) -- C:\ProgramData\㾐ʼn㯨ʼn [2013-10-30 08:12:01 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƧ繀ƻ [2013-10-30 08:12:01 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƧ繀ƻ [2013-10-30 07:12:02 | 000,000,000 | ---D | M](C:\ProgramData\?z??) -- C:\ProgramData\Ꮘƶ繀ƴ [2013-10-30 07:12:02 | 000,000,000 | ---D | M](C:\ProgramData\?z??) -- C:\ProgramData\Ꮘƶ繀ƴ [2013-10-27 20:13:52 | 000,000,000 | ---D | M](C:\ProgramData\?I?I) -- C:\ProgramData\㾐Ĭ㯨Ĭ [2013-10-27 20:13:52 | 000,000,000 | ---D | M](C:\ProgramData\?I?I) -- C:\ProgramData\㾐Ĭ㯨Ĭ [2013-10-27 06:53:38 | 000,000,000 | ---D | M](C:\ProgramData\?Ş?Ş) -- C:\ProgramData\㾐Ş㯨Ş [2013-10-27 06:53:38 | 000,000,000 | ---D | M](C:\ProgramData\?Ş?Ş) -- C:\ProgramData\㾐Ş㯨Ş [2013-10-25 08:12:27 | 000,000,000 | ---D | M](C:\ProgramData\???g) -- C:\ProgramData\Ꮘƛ繀ģ [2013-10-25 08:12:27 | 000,000,000 | ---D | M](C:\ProgramData\???g) -- C:\ProgramData\Ꮘƛ繀ģ [2013-10-17 19:48:29 | 000,000,000 | ---D | M](C:\ProgramData\?¸?¸) -- C:\ProgramData\㾐¸㯨¸ [2013-10-17 19:48:29 | 000,000,000 | ---D | M](C:\ProgramData\?¸?¸) -- C:\ProgramData\㾐¸㯨¸ [2013-10-16 20:33:38 | 000,000,000 | ---D | M](C:\ProgramData\???c) -- C:\ProgramData\ᏈƝ繀c [2013-10-16 20:33:38 | 000,000,000 | ---D | M](C:\ProgramData\???c) -- C:\ProgramData\ᏈƝ繀c [2013-10-10 19:46:37 | 000,000,000 | ---D | M](C:\ProgramData\?R?R) -- C:\ProgramData\㾐Ŗ㯨Ŗ [2013-10-10 19:46:37 | 000,000,000 | ---D | M](C:\ProgramData\?R?R) -- C:\ProgramData\㾐Ŗ㯨Ŗ [2013-10-09 07:41:53 | 000,000,000 | ---D | M](C:\ProgramData\???U) -- C:\ProgramData\ᏈƱ繀Ư [2013-10-09 07:41:53 | 000,000,000 | ---D | M](C:\ProgramData\???U) -- C:\ProgramData\ᏈƱ繀Ư [2013-10-08 07:28:45 | 000,000,000 | ---D | M](C:\ProgramData\?A?A) -- C:\ProgramData\㾐À㯨À [2013-10-08 07:28:45 | 000,000,000 | ---D | M](C:\ProgramData\?A?A) -- C:\ProgramData\㾐À㯨À [2013-10-03 14:59:31 | 000,000,000 | ---D | M](C:\ProgramData\?Á?Á) -- C:\ProgramData\㾐Á㯨Á [2013-10-03 14:59:31 | 000,000,000 | ---D | M](C:\ProgramData\?Á?Á) -- C:\ProgramData\㾐Á㯨Á [2013-10-02 08:55:44 | 000,000,000 | ---D | M](C:\ProgramData\???ő) -- C:\ProgramData\ᏈƲ繀ő [2013-10-02 08:55:44 | 000,000,000 | ---D | M](C:\ProgramData\???ő) -- C:\ProgramData\ᏈƲ繀ő [2013-09-24 18:09:38 | 000,000,000 | ---D | M](C:\ProgramData\?l?l) -- C:\ProgramData\㾐ļ㯨ļ [2013-09-24 18:09:38 | 000,000,000 | ---D | M](C:\ProgramData\?l?l) -- C:\ProgramData\㾐ļ㯨ļ [2013-09-18 14:16:12 | 000,000,000 | ---D | M](C:\ProgramData\?F?o) -- C:\ProgramData\ᏈƑ繀ơ [2013-09-18 14:16:12 | 000,000,000 | ---D | M](C:\ProgramData\?F?o) -- C:\ProgramData\ᏈƑ繀ơ [2013-09-11 10:29:40 | 000,000,000 | ---D | M](C:\ProgramData\???6) -- C:\ProgramData\Ꮘǁ繀6 [2013-09-11 10:29:40 | 000,000,000 | ---D | M](C:\ProgramData\???6) -- C:\ProgramData\Ꮘǁ繀6 [2013-09-06 14:22:46 | 000,000,000 | ---D | M](C:\ProgramData\?i?i) -- C:\ProgramData\㾐ı㯨ı [2013-09-06 14:22:46 | 000,000,000 | ---D | M](C:\ProgramData\?i?i) -- C:\ProgramData\㾐ı㯨ı [2013-09-04 08:14:28 | 000,000,000 | ---D | M](C:\ProgramData\?l??) -- C:\ProgramData\Ꮘƚ繀ƪ [2013-09-04 08:14:28 | 000,000,000 | ---D | M](C:\ProgramData\?l??) -- C:\ProgramData\Ꮘƚ繀ƪ [2013-08-31 12:29:30 | 000,000,000 | ---D | M](C:\ProgramData\?ę?ę) -- C:\ProgramData\㾐ę㯨ę [2013-08-31 12:29:30 | 000,000,000 | ---D | M](C:\ProgramData\?ę?ę) -- C:\ProgramData\㾐ę㯨ę [2013-08-28 17:34:37 | 000,000,000 | ---D | M](C:\ProgramData\?u?A) -- C:\ProgramData\Ꮘư繀Ǎ [2013-08-28 17:34:37 | 000,000,000 | ---D | M](C:\ProgramData\?u?A) -- C:\ProgramData\Ꮘư繀Ǎ [2013-08-24 20:16:47 | 000,000,000 | ---D | M](C:\ProgramData\?$?$) -- C:\ProgramData\㾐$㯨$ [2013-08-24 20:16:47 | 000,000,000 | ---D | M](C:\ProgramData\?$?$) -- C:\ProgramData\㾐$㯨$ [2013-08-24 12:38:11 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƲ繀nj [2013-08-24 12:38:11 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƲ繀nj [2013-08-23 15:11:38 | 000,000,000 | ---D | M](C:\ProgramData\?0?0) -- C:\ProgramData\㾐0㯨0 [2013-08-23 15:11:38 | 000,000,000 | ---D | M](C:\ProgramData\?0?0) -- C:\ProgramData\㾐0㯨0 [2013-08-22 09:37:08 | 000,000,000 | ---D | M](C:\ProgramData\?U?Ö) -- C:\ProgramData\ᏈƯ繀Ö [2013-08-22 09:37:08 | 000,000,000 | ---D | M](C:\ProgramData\?U?Ö) -- C:\ProgramData\ᏈƯ繀Ö [2013-08-21 13:48:32 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐›㯨› [2013-08-21 13:48:32 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐›㯨› [2013-08-14 08:17:13 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\Ꮘƙ繀ƴ [2013-08-14 08:17:13 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\Ꮘƙ繀ƴ [2013-08-08 10:29:21 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐†㯨† [2013-08-08 10:29:21 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐†㯨† [2013-08-07 07:33:31 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\Ꮘƕ繀Ƴ [2013-08-07 07:33:31 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\Ꮘƕ繀Ƴ [2013-08-05 11:12:55 | 000,000,000 | ---D | M](C:\ProgramData\?8?8) -- C:\ProgramData\㾐8㯨8 [2013-08-05 11:12:55 | 000,000,000 | ---D | M](C:\ProgramData\?8?8) -- C:\ProgramData\㾐8㯨8 [2013-07-31 07:31:50 | 000,000,000 | ---D | M](C:\ProgramData\???h) -- C:\ProgramData\Ꮘƨ繀ĥ [2013-07-31 07:31:50 | 000,000,000 | ---D | M](C:\ProgramData\???h) -- C:\ProgramData\Ꮘƨ繀ĥ [2013-07-26 08:54:24 | 000,000,000 | ---D | M](C:\ProgramData\?ü?ü) -- C:\ProgramData\㾐ü㯨ü [2013-07-26 08:54:24 | 000,000,000 | ---D | M](C:\ProgramData\?ü?ü) -- C:\ProgramData\㾐ü㯨ü [2013-07-24 08:17:23 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\Ꮘƅ繀Ɩ [2013-07-24 08:17:23 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\Ꮘƅ繀Ɩ [2013-07-20 11:37:27 | 000,000,000 | ---D | M](C:\ProgramData\?G?G) -- C:\ProgramData\㾐Ğ㯨Ğ [2013-07-20 11:37:27 | 000,000,000 | ---D | M](C:\ProgramData\?G?G) -- C:\ProgramData\㾐Ğ㯨Ğ [2013-07-17 13:34:41 | 000,000,000 | ---D | M](C:\ProgramData\?ř?ř) -- C:\ProgramData\㾐ř㯨ř [2013-07-17 13:34:41 | 000,000,000 | ---D | M](C:\ProgramData\?ř?ř) -- C:\ProgramData\㾐ř㯨ř [2013-07-17 07:12:01 | 000,000,000 | ---D | M](C:\ProgramData\???S) -- C:\ProgramData\ᏈƢ繀Ŝ [2013-07-17 07:12:01 | 000,000,000 | ---D | M](C:\ProgramData\???S) -- C:\ProgramData\ᏈƢ繀Ŝ [2013-07-11 04:36:50 | 000,000,000 | ---D | M](C:\ProgramData\?Ĺ?Ĺ) -- C:\ProgramData\㾐Ĺ㯨Ĺ [2013-07-11 04:36:50 | 000,000,000 | ---D | M](C:\ProgramData\?Ĺ?Ĺ) -- C:\ProgramData\㾐Ĺ㯨Ĺ [2013-07-10 17:40:12 | 000,000,000 | ---D | M](C:\ProgramData\?O?U) -- C:\ProgramData\ᏈƟ繀Ư [2013-07-10 17:40:12 | 000,000,000 | ---D | M](C:\ProgramData\?O?U) -- C:\ProgramData\ᏈƟ繀Ư [2013-07-10 07:07:11 | 000,000,000 | ---D | M](C:\ProgramData\?ľ?ľ) -- C:\ProgramData\㾐ľ㯨ľ [2013-07-10 07:07:11 | 000,000,000 | ---D | M](C:\ProgramData\?ľ?ľ) -- C:\ProgramData\㾐ľ㯨ľ [2013-07-03 09:30:58 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƖ繀Ɣ [2013-07-03 09:30:58 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƖ繀Ɣ [2013-06-29 13:16:00 | 000,000,000 | ---D | M](C:\ProgramData\?ň?ň) -- C:\ProgramData\㾐ň㯨ň [2013-06-29 13:16:00 | 000,000,000 | ---D | M](C:\ProgramData\?ň?ň) -- C:\ProgramData\㾐ň㯨ň [2013-06-26 07:12:02 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƋ繀Ɯ [2013-06-26 07:12:02 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƋ繀Ɯ [2013-06-20 00:02:59 | 000,000,000 | ---D | M](C:\ProgramData\???U) -- C:\ProgramData\ᏈƔ繀Ư [2013-06-20 00:02:59 | 000,000,000 | ---D | M](C:\ProgramData\???U) -- C:\ProgramData\ᏈƔ繀Ư [2013-06-19 07:07:14 | 000,000,000 | ---D | M](C:\ProgramData\?s?s) -- C:\ProgramData\㾐s㯨s [2013-06-19 07:07:14 | 000,000,000 | ---D | M](C:\ProgramData\?s?s) -- C:\ProgramData\㾐s㯨s [2013-06-18 11:57:11 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐‹㯨‹ [2013-06-18 11:57:11 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐‹㯨‹ [2013-06-17 07:55:38 | 000,000,000 | ---D | M](C:\ProgramData\?}?}) -- C:\ProgramData\㾐}㯨} [2013-06-17 07:55:38 | 000,000,000 | ---D | M](C:\ProgramData\?}?}) -- C:\ProgramData\㾐}㯨} [2013-06-15 21:33:16 | 000,000,000 | ---D | M](C:\ProgramData\?o?o) -- C:\ProgramData\㾐ŏ㯨ŏ [2013-06-15 21:33:16 | 000,000,000 | ---D | M](C:\ProgramData\?o?o) -- C:\ProgramData\㾐ŏ㯨ŏ [2013-06-12 07:12:01 | 000,000,000 | ---D | M](C:\ProgramData\???Ă) -- C:\ProgramData\ᏈƏ繀Ă [2013-06-12 07:12:01 | 000,000,000 | ---D | M](C:\ProgramData\???Ă) -- C:\ProgramData\ᏈƏ繀Ă [2013-06-10 07:29:55 | 000,000,000 | ---D | M](C:\ProgramData\?Š?Š) -- C:\ProgramData\㾐Š㯨Š [2013-06-10 07:29:55 | 000,000,000 | ---D | M](C:\ProgramData\?Š?Š) -- C:\ProgramData\㾐Š㯨Š [2013-06-08 06:05:05 | 000,000,000 | ---D | M](C:\ProgramData\?×?×) -- C:\ProgramData\㾐×㯨× [2013-06-08 06:05:05 | 000,000,000 | ---D | M](C:\ProgramData\?×?×) -- C:\ProgramData\㾐×㯨× [2013-06-06 06:37:09 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐’㯨’ [2013-06-06 06:37:09 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐’㯨’ [2013-06-05 07:12:02 | 000,000,000 | ---D | M](C:\ProgramData\?O?C) -- C:\ProgramData\ᏈƠ繀Ĉ [2013-06-05 07:12:02 | 000,000,000 | ---D | M](C:\ProgramData\?O?C) -- C:\ProgramData\ᏈƠ繀Ĉ [2013-06-04 22:33:16 | 000,000,000 | ---D | M](C:\ProgramData\?s?s) -- C:\ProgramData\㾐ŝ㯨ŝ [2013-06-04 22:33:16 | 000,000,000 | ---D | M](C:\ProgramData\?s?s) -- C:\ProgramData\㾐ŝ㯨ŝ [2013-06-04 08:54:13 | 000,000,000 | ---D | M](C:\ProgramData\?Ţ?Ţ) -- C:\ProgramData\㾐Ţ㯨Ţ [2013-06-04 08:54:13 | 000,000,000 | ---D | M](C:\ProgramData\?Ţ?Ţ) -- C:\ProgramData\㾐Ţ㯨Ţ [2013-06-03 10:00:11 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƩ繀ƿ [2013-06-03 10:00:11 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƩ繀ƿ [2013-05-28 10:54:32 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐㯨 [2013-05-28 10:54:32 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐㯨 [2013-05-24 22:18:17 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐Š㯨Š [2013-05-24 22:18:17 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐Š㯨Š [2013-05-23 12:30:30 | 000,000,000 | ---D | M](C:\ProgramData\???O) -- C:\ProgramData\Ꮘƞ繀Õ [2013-05-23 12:30:30 | 000,000,000 | ---D | M](C:\ProgramData\???O) -- C:\ProgramData\Ꮘƞ繀Õ [2013-05-22 20:43:50 | 000,000,000 | ---D | M](C:\ProgramData\?Đ?Đ) -- C:\ProgramData\㾐Đ㯨Đ [2013-05-22 20:43:50 | 000,000,000 | ---D | M](C:\ProgramData\?Đ?Đ) -- C:\ProgramData\㾐Đ㯨Đ [2013-05-22 07:50:42 | 000,000,000 | ---D | M](C:\ProgramData\?ß?ß) -- C:\ProgramData\㾐ß㯨ß [2013-05-22 07:50:42 | 000,000,000 | ---D | M](C:\ProgramData\?ß?ß) -- C:\ProgramData\㾐ß㯨ß [2013-05-15 07:12:17 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\Ꮘƥ繀ƣ [2013-05-15 07:12:17 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\Ꮘƥ繀ƣ [2013-05-13 08:29:55 | 000,000,000 | ---D | M](C:\ProgramData\?J?J) -- C:\ProgramData\㾐Ĵ㯨Ĵ [2013-05-13 08:29:55 | 000,000,000 | ---D | M](C:\ProgramData\?J?J) -- C:\ProgramData\㾐Ĵ㯨Ĵ [2013-05-09 14:41:54 | 000,000,000 | ---D | M](C:\ProgramData\?i?i) -- C:\ProgramData\㾐ī㯨ī [2013-05-09 14:41:54 | 000,000,000 | ---D | M](C:\ProgramData\?i?i) -- C:\ProgramData\㾐ī㯨ī [2013-05-08 22:30:40 | 000,000,000 | ---D | M](C:\ProgramData\?ˆ?ˆ) -- C:\ProgramData\㾐ˆ㯨ˆ [2013-05-08 22:30:40 | 000,000,000 | ---D | M](C:\ProgramData\?ˆ?ˆ) -- C:\ProgramData\㾐ˆ㯨ˆ [2013-05-02 21:27:18 | 000,000,000 | ---D | M](C:\ProgramData\?o?o) -- C:\ProgramData\㾐õ㯨õ [2013-05-02 21:27:18 | 000,000,000 | ---D | M](C:\ProgramData\?o?o) -- C:\ProgramData\㾐õ㯨õ [2013-05-01 22:21:38 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƋ繀ƛ [2013-05-01 22:21:38 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƋ繀ƛ [2013-04-29 09:28:55 | 000,000,000 | ---D | M](C:\ProgramData\?ś?ś) -- C:\ProgramData\㾐ś㯨ś [2013-04-29 09:28:55 | 000,000,000 | ---D | M](C:\ProgramData\?ś?ś) -- C:\ProgramData\㾐ś㯨ś [2013-04-28 22:07:25 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐Ŀ㯨Ŀ [2013-04-28 22:07:25 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐Ŀ㯨Ŀ [2013-04-25 21:27:11 | 000,000,000 | ---D | M](C:\ProgramData\????rogram Files) -- C:\ProgramData\胀Ɠ跘Ɠrogram Files [2013-04-25 21:27:11 | 000,000,000 | ---D | M](C:\ProgramData\????rogram Files) -- C:\ProgramData\胀Ɠ跘Ɠrogram Files [2013-04-25 21:27:10 | 000,000,000 | ---D | M](C:\ProgramData\?H?H574F14BCÄH?H) -- C:\ProgramData\㻈Ħ㮠Ħ574F14BCÄĦ㓠Ħ [2013-04-25 21:27:10 | 000,000,000 | ---D | M](C:\ProgramData\?H?H574F14BCÄH?H) -- C:\ProgramData\㻈Ħ㮠Ħ574F14BCÄĦ㓠Ħ [2013-04-25 21:25:23 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƊ縨Ʀ [2013-04-25 21:25:23 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƊ縨Ʀ [2013-04-24 21:23:15 | 000,000,000 | ---D | M](C:\ProgramData\?O?O) -- C:\ProgramData\㾐Ò㯨Ò [2013-04-24 21:23:15 | 000,000,000 | ---D | M](C:\ProgramData\?O?O) -- C:\ProgramData\㾐Ò㯨Ò [2013-04-24 08:40:48 | 000,000,000 | ---D | M](C:\ProgramData\?N?N) -- C:\ProgramData\㾐Ņ㯨Ņ [2013-04-24 08:40:48 | 000,000,000 | ---D | M](C:\ProgramData\?N?N) -- C:\ProgramData\㾐Ņ㯨Ņ [2013-04-24 07:43:07 | 000,000,000 | ---D | M](C:\ProgramData\?O??) -- C:\ProgramData\ᏈƠ繀ƹ [2013-04-24 07:43:07 | 000,000,000 | ---D | M](C:\ProgramData\?O??) -- C:\ProgramData\ᏈƠ繀ƹ [2013-04-23 14:25:05 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐ŋ㯨ŋ [2013-04-23 14:25:05 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐ŋ㯨ŋ [2013-04-22 10:29:33 | 000,000,000 | ---D | M](C:\ProgramData\?Ń?Ń) -- C:\ProgramData\㾐Ń㯨Ń [2013-04-22 10:29:33 | 000,000,000 | ---D | M](C:\ProgramData\?Ń?Ń) -- C:\ProgramData\㾐Ń㯨Ń [2013-04-22 07:48:33 | 000,000,000 | ---D | M](C:\ProgramData\?O?O) -- C:\ProgramData\㾐Œ㯨Œ [2013-04-22 07:48:33 | 000,000,000 | ---D | M](C:\ProgramData\?O?O) -- C:\ProgramData\㾐Œ㯨Œ [2013-04-20 19:42:18 | 000,000,000 | ---D | M](C:\ProgramData\?ő?ő) -- C:\ProgramData\㾐ő㯨ő [2013-04-20 19:42:18 | 000,000,000 | ---D | M](C:\ProgramData\?ő?ő) -- C:\ProgramData\㾐ő㯨ő [2013-04-18 15:53:59 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐Œ㯨Œ [2013-04-18 15:53:59 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\㾐Œ㯨Œ [2013-04-18 06:49:49 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƱ繀ǁ [2013-04-18 06:49:49 | 000,000,000 | ---D | M](C:\ProgramData\????) -- C:\ProgramData\ᏈƱ繀ǁ [2013-04-17 08:35:28 | 000,000,000 | ---D | M](C:\ProgramData\?4?4) -- C:\ProgramData\㾐4㯨4 [2013-04-17 08:35:28 | 000,000,000 | ---D | M](C:\ProgramData\?4?4) -- C:\ProgramData\㾐4㯨4 [2013-04-15 07:42:02 | 000,000,000 | ---D | M](C:\ProgramData\???ő) -- C:\ProgramData\ᏈƜ繀ő [2013-04-15 07:42:02 | 000,000,000 | ---D | M](C:\ProgramData\???ő) -- C:\ProgramData\ᏈƜ繀ő [2013-04-14 15:27:51 | 000,000,000 | ---D | M](C:\ProgramData\?Ł?Ł) -- C:\ProgramData\㾐Ł㯨Ł [2013-04-14 15:27:51 | 000,000,000 | ---D | M](C:\ProgramData\?Ł?Ł) -- C:\ProgramData\㾐Ł㯨Ł [2013-04-13 15:54:39 | 000,000,000 | ---D | M](C:\ProgramData\?b?b) -- C:\ProgramData\㺈ƀ㬸ƀ [2013-04-13 15:54:39 | 000,000,000 | ---D | M](C:\ProgramData\?b?b) -- C:\ProgramData\㺈ƀ㬸ƀ (C:\ProgramData\?z??) -- C:\ProgramData\Ꮘƶ繀ƴ (C:\ProgramData\?ü?ü) -- C:\ProgramData\㾐ü㯨ü (C:\ProgramData\?U?Ö) -- C:\ProgramData\ᏈƯ繀Ö (C:\ProgramData\?u?A) -- C:\ProgramData\Ꮘư繀Ǎ (C:\ProgramData\?Ţ?Ţ) -- C:\ProgramData\㾐Ţ㯨Ţ (C:\ProgramData\?ś?ś) -- C:\ProgramData\㾐ś㯨ś (C:\ProgramData\?ß?ß) -- C:\ProgramData\㾐ß㯨ß (C:\ProgramData\?Ş?Ş) -- C:\ProgramData\㾐Ş㯨Ş (C:\ProgramData\?Š?Š) -- C:\ProgramData\㾐Š㯨Š (C:\ProgramData\?s?s) -- C:\ProgramData\㾐ŝ㯨ŝ (C:\ProgramData\?s?s) -- C:\ProgramData\㾐s㯨s (C:\ProgramData\?ř?ř) -- C:\ProgramData\㾐ř㯨ř (C:\ProgramData\?R?R) -- C:\ProgramData\㾐Ŗ㯨Ŗ (C:\ProgramData\?O?U) -- C:\ProgramData\ᏈƟ繀Ư (C:\ProgramData\?ő?ő) -- C:\ProgramData\㾐ő㯨ő (C:\ProgramData\?o?o) -- C:\ProgramData\㾐õ㯨õ (C:\ProgramData\?o?o) -- C:\ProgramData\㾐ŏ㯨ŏ (C:\ProgramData\?O?O) -- C:\ProgramData\㾐Ò㯨Ò (C:\ProgramData\?O?O) -- C:\ProgramData\㾐Œ㯨Œ (C:\ProgramData\?O?C) -- C:\ProgramData\ᏈƠ繀Ĉ (C:\ProgramData\?O??) -- C:\ProgramData\ᏈƠ繀ƹ (C:\ProgramData\?Ń?Ń) -- C:\ProgramData\㾐Ń㯨Ń (C:\ProgramData\?ň?ň) -- C:\ProgramData\㾐ň㯨ň (C:\ProgramData\?N?N) -- C:\ProgramData\㾐Ņ㯨Ņ (C:\ProgramData\?Ł?Ł) -- C:\ProgramData\㾐Ł㯨Ł (C:\ProgramData\?ľ?ľ) -- C:\ProgramData\㾐ľ㯨ľ (C:\ProgramData\?Ĺ?Ĺ) -- C:\ProgramData\㾐Ĺ㯨Ĺ (C:\ProgramData\?l?l) -- C:\ProgramData\㾐ļ㯨ļ (C:\ProgramData\?l??) -- C:\ProgramData\Ꮘƚ繀ƪ (C:\ProgramData\?J?J) -- C:\ProgramData\㾐Ĵ㯨Ĵ (C:\ProgramData\?i?i) -- C:\ProgramData\㾐ī㯨ī (C:\ProgramData\?I?I) -- C:\ProgramData\㾐Ĭ㯨Ĭ (C:\ProgramData\?i?i) -- C:\ProgramData\㾐ı㯨ı (C:\ProgramData\?H?H574F14BCÄH?H) -- C:\ProgramData\㻈Ħ㮠Ħ574F14BCÄĦ㓠Ħ (C:\ProgramData\?G?G) -- C:\ProgramData\㾐Ğ㯨Ğ (C:\ProgramData\?F?o) -- C:\ProgramData\ᏈƑ繀ơ (C:\ProgramData\?ę?ę) -- C:\ProgramData\㾐ę㯨ę (C:\ProgramData\?Đ?Đ) -- C:\ProgramData\㾐Đ㯨Đ (C:\ProgramData\?b?b) -- C:\ProgramData\㺈ƀ㬸ƀ (C:\ProgramData\?Á?Á) -- C:\ProgramData\㾐Á㯨Á (C:\ProgramData\?A?A) -- C:\ProgramData\㾐À㯨À (C:\ProgramData\?8?8) -- C:\ProgramData\㾐8㯨8 (C:\ProgramData\?4?4) -- C:\ProgramData\㾐4㯨4 (C:\ProgramData\?0?0) -- C:\ProgramData\㾐0㯨0 (C:\ProgramData\?ˆ?ˆ) -- C:\ProgramData\㾐ˆ㯨ˆ (C:\ProgramData\?×?×) -- C:\ProgramData\㾐×㯨× (C:\ProgramData\?¸?¸) -- C:\ProgramData\㾐¸㯨¸ (C:\ProgramData\?}?}) -- C:\ProgramData\㾐}㯨} (C:\ProgramData\???U) -- C:\ProgramData\ᏈƱ繀Ư (C:\ProgramData\???U) -- C:\ProgramData\ᏈƔ繀Ư (C:\ProgramData\???S) -- C:\ProgramData\ᏈƢ繀Ŝ (C:\ProgramData\???ő) -- C:\ProgramData\ᏈƲ繀ő (C:\ProgramData\???O) -- C:\ProgramData\Ꮘƞ繀Õ (C:\ProgramData\???ő) -- C:\ProgramData\ᏈƜ繀ő (C:\ProgramData\???h) -- C:\ProgramData\Ꮘƨ繀ĥ (C:\ProgramData\???g) -- C:\ProgramData\Ꮘƛ繀ģ (C:\ProgramData\???c) -- C:\ProgramData\ᏈƝ繀c (C:\ProgramData\???Ă) -- C:\ProgramData\ᏈƏ繀Ă (C:\ProgramData\???6) -- C:\ProgramData\Ꮘǁ繀6 (C:\ProgramData\????rogram Files) -- C:\ProgramData\胀Ɠ跘Ɠrogram Files (C:\ProgramData\????) -- C:\ProgramData\㾐ŋ㯨ŋ (C:\ProgramData\????) -- C:\ProgramData\㾐Ŀ㯨Ŀ (C:\ProgramData\????) -- C:\ProgramData\㾐›㯨› (C:\ProgramData\????) -- C:\ProgramData\㾐’㯨’ (C:\ProgramData\????) -- C:\ProgramData\㾐㯨 (C:\ProgramData\????) -- C:\ProgramData\㾐Œ㯨Œ (C:\ProgramData\????) -- C:\ProgramData\㾐‹㯨‹ (C:\ProgramData\????) -- C:\ProgramData\㾐Š㯨Š (C:\ProgramData\????) -- C:\ProgramData\㾐†㯨† (C:\ProgramData\????) -- C:\ProgramData\ᏈƲ繀nj (C:\ProgramData\????) -- C:\ProgramData\ᏈƱ繀ǁ (C:\ProgramData\????) -- C:\ProgramData\ᏈƩ繀ƿ (C:\ProgramData\????) -- C:\ProgramData\ᏈƧ繀ƻ (C:\ProgramData\????) -- C:\ProgramData\Ꮘƥ繀ƣ (C:\ProgramData\????) -- C:\ProgramData\Ꮘƙ繀ƴ (C:\ProgramData\????) -- C:\ProgramData\ᏈƖ繀Ɣ (C:\ProgramData\????) -- C:\ProgramData\Ꮘƕ繀Ƴ (C:\ProgramData\????) -- C:\ProgramData\ᏈƋ繀Ɯ (C:\ProgramData\????) -- C:\ProgramData\ᏈƋ繀ƛ (C:\ProgramData\????) -- C:\ProgramData\ᏈƊ縨Ʀ (C:\ProgramData\????) -- C:\ProgramData\Ꮘƅ繀Ɩ (C:\ProgramData\?$?$) -- C:\ProgramData\㾐$㯨$ < End of report >