OTL logfile created on: 2010-11-21 00:25:49 - Run 1 OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\root\Downloads\Nowy folder 64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 9.0.7930.16406) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 5,00 Gb Total Physical Memory | 3,00 Gb Available Physical Memory | 66,00% Memory free 10,00 Gb Paging File | 8,00 Gb Available in Paging File | 81,00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 29,98 Gb Total Space | 1,36 Gb Free Space | 4,55% Space Free | Partition Type: NTFS Drive D: | 668,56 Gb Total Space | 6,99 Gb Free Space | 1,05% Space Free | Partition Type: NTFS Drive E: | 298,09 Gb Total Space | 16,81 Gb Free Space | 5,64% Space Free | Partition Type: NTFS Drive F: | 465,75 Gb Total Space | 5,79 Gb Free Space | 1,24% Space Free | Partition Type: NTFS Drive G: | 465,76 Gb Total Space | 8,67 Gb Free Space | 1,86% Space Free | Partition Type: NTFS Drive H: | 74,53 Gb Total Space | 17,43 Gb Free Space | 23,39% Space Free | Partition Type: NTFS Computer Name: ROOT-KOMPUTER | User Name: root | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - File not found -- C:\Windows\SysWow64\PrintDisp.exe PRC - File not found -- C:\Windows\SysWow64\PrintCtrl.exe PRC - [2010-11-21 00:23:03 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\root\Downloads\Nowy folder\OTL.exe PRC - [2010-10-28 15:59:50 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe PRC - [2010-10-28 15:59:49 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2010-10-28 02:11:28 | 003,792,943 | ---- | M] (FreeDownloadManager.ORG) -- C:\Program Files (x86)\Free Download Manager\fdm.exe PRC - [2010-10-05 18:34:55 | 000,075,064 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe PRC - [2010-09-24 14:36:59 | 001,960,744 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe PRC - [2010-09-24 14:36:58 | 006,811,944 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version5\TeamViewer.exe PRC - [2010-09-15 16:12:34 | 000,273,672 | ---- | M] (Microsoft Corp.) -- C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2317.0\mswinext.exe PRC - [2010-07-09 15:09:52 | 000,248,936 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2010-05-05 15:56:06 | 000,251,392 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe PRC - [2010-04-27 13:41:26 | 000,218,112 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\razertra.exe PRC - [2010-04-03 16:44:26 | 000,640,440 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe PRC - [2010-03-06 02:22:48 | 000,025,600 | ---- | M] (Creative Technology Ltd) -- C:\Windows\SysWOW64\Ctxfihlp.exe PRC - [2010-03-06 02:17:42 | 001,212,928 | ---- | M] (Creative Technology Ltd) -- C:\Windows\SysWOW64\CTxfispi.exe PRC - [2010-02-26 06:10:20 | 021,979,992 | ---- | M] () -- C:\Users\root\AppData\Roaming\Dropbox\bin\Dropbox.exe PRC - [2010-02-12 14:23:12 | 000,286,720 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe PRC - [2009-07-24 13:53:42 | 002,080,768 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files (x86)\Nuance\PDF Professional 6\PdfPro6Hook.exe PRC - [2009-07-07 12:13:38 | 000,241,789 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe PRC - [2009-06-30 15:49:06 | 000,134,944 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files (x86)\Nuance\PDF Professional 6\PDFProFiltSrv.exe PRC - [2009-06-17 12:44:11 | 000,085,160 | ---- | M] (Elaborate Bytes AG) -- C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe PRC - [2008-08-07 16:10:24 | 000,278,016 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Samsung PC Studio 7\LaunchApplication.exe PRC - [2008-04-07 08:17:30 | 000,430,592 | ---- | M] (Nokia.) -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe PRC - [2008-02-22 08:11:02 | 000,120,320 | ---- | M] () -- C:\Program Files (x86)\PC Connectivity Solution\Transports\NclRSSrv.exe PRC - [2007-12-19 10:58:24 | 000,163,840 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe PRC - [2007-10-30 23:14:54 | 000,924,160 | ---- | M] (Interactive Bugs for the Masses) -- E:\programy\router\DMT.exe [color=#E56717]========== Modules (SafeList) ==========[/color] MOD - [2010-11-21 00:23:03 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\root\Downloads\Nowy folder\OTL.exe MOD - [2010-08-21 06:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - File not found [Auto | Running] -- C:\Windows\SysNative\PnkBstrA.exe -- (PnkBstrA) SRV:[b]64bit:[/b] - File not found [Auto | Stopped] -- C:\Windows\SysNative\srvany.exe -- (KMService) SRV:[b]64bit:[/b] - [2010-10-10 16:39:48 | 001,436,424 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64) SRV:[b]64bit:[/b] - [2010-03-25 22:48:42 | 000,017,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc) SRV:[b]64bit:[/b] - [2009-10-28 18:59:48 | 000,065,536 | ---- | M] (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) [Auto | Running] -- C:\Windows\SysNative\PrintCtrl.exe -- (Printer Control) SRV:[b]64bit:[/b] - [2009-07-14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:[b]64bit:[/b] - [2009-07-14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV - [2010-11-14 11:52:17 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2010-10-07 21:02:58 | 000,008,192 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysWOW64\srvany.exe -- (KMService) SRV - [2010-10-05 18:34:55 | 000,075,064 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2010-10-03 11:20:32 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\DDLLicensing.exe -- (Creative Dolby Digital Live Pack Licensing Service) SRV - [2010-10-03 11:20:27 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service) SRV - [2010-09-24 14:36:59 | 001,960,744 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe -- (TeamViewer5) SRV - [2010-07-09 15:09:52 | 000,248,936 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2010-03-18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010-02-12 14:23:12 | 000,286,720 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService) SRV - [2009-06-30 15:49:06 | 000,134,944 | ---- | M] (Nuance Communications, Inc.) [Auto | Running] -- C:\Program Files (x86)\Nuance\PDF Professional 6\PDFProFiltSrv.exe -- (PDFProFiltSrv) SRV - [2009-06-10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2008-04-07 08:17:30 | 000,430,592 | ---- | M] (Nokia.) [On_Demand | Running] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2010-07-14 09:04:52 | 000,064,000 | ---- | M] (XECUTER) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ck3pro64.sys -- (ck3pro64) DRV:[b]64bit:[/b] - [2010-04-19 16:04:44 | 000,012,032 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dadder.sys -- (DAdderFltr) DRV:[b]64bit:[/b] - [2010-03-06 03:53:22 | 001,561,176 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ha20x2k.sys -- (ha20x2k) DRV:[b]64bit:[/b] - [2010-03-06 03:53:08 | 000,118,360 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\emupia2k.sys -- (emupia) DRV:[b]64bit:[/b] - [2010-03-06 03:53:00 | 000,213,080 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctsfm2k.sys -- (ctsfm2k) DRV:[b]64bit:[/b] - [2010-03-06 03:52:52 | 000,015,960 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctprxy2k.sys -- (ctprxy2k) DRV:[b]64bit:[/b] - [2010-03-06 03:52:44 | 000,179,288 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctoss2k.sys -- (ossrv) DRV:[b]64bit:[/b] - [2010-03-06 03:52:36 | 000,684,376 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctaud2k.sys -- (ctaud2k) Creative Audio Driver (WDM) DRV:[b]64bit:[/b] - [2010-03-06 03:52:26 | 000,580,696 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctac32k.sys -- (ctac32k) DRV:[b]64bit:[/b] - [2010-03-06 03:52:16 | 001,417,304 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTEXFIFX.sys -- (CTEXFIFX.SYS) DRV:[b]64bit:[/b] - [2010-03-06 03:52:16 | 001,417,304 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTEXFIFX.sys -- (CTEXFIFX) DRV:[b]64bit:[/b] - [2010-03-06 03:52:06 | 000,094,808 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTHWIUT.sys -- (CTHWIUT.SYS) DRV:[b]64bit:[/b] - [2010-03-06 03:52:06 | 000,094,808 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTHWIUT.sys -- (CTHWIUT) DRV:[b]64bit:[/b] - [2010-03-06 03:51:58 | 000,202,840 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CT20XUT.sys -- (CT20XUT.SYS) DRV:[b]64bit:[/b] - [2010-03-06 03:51:58 | 000,202,840 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CT20XUT.sys -- (CT20XUT) DRV:[b]64bit:[/b] - [2010-02-04 01:05:36 | 000,159,136 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdm.sys -- (ssadmdm) DRV:[b]64bit:[/b] - [2010-02-04 01:05:36 | 000,125,344 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadbus.sys -- (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) DRV:[b]64bit:[/b] - [2010-02-04 01:05:36 | 000,036,256 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadadb.sys -- (androidusb) DRV:[b]64bit:[/b] - [2010-02-04 01:05:36 | 000,016,800 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdfl.sys -- (ssadmdfl) SAMSUNG Android USB Modem (Filter) DRV:[b]64bit:[/b] - [2010-01-20 06:52:58 | 000,171,008 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nmwcdsax64.sys -- (nmwcdsax64) DRV:[b]64bit:[/b] - [2010-01-20 06:52:58 | 000,017,408 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nmwcdsacmx64.sys -- (nmwcdsacmx64) DRV:[b]64bit:[/b] - [2010-01-20 06:52:58 | 000,017,408 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nmwcdsacjx64.sys -- (nmwcdsacjx64) DRV:[b]64bit:[/b] - [2010-01-20 06:52:58 | 000,012,288 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nmwcdsacx64.sys -- (nmwcdsacx64) DRV:[b]64bit:[/b] - [2009-12-21 20:50:00 | 000,007,552 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vHidDev.sys -- (vhidmini) DRV:[b]64bit:[/b] - [2009-12-17 23:25:17 | 000,034,472 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO) DRV:[b]64bit:[/b] - [2009-08-09 22:25:45 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone) DRV:[b]64bit:[/b] - [2009-07-14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2009-07-14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2009-07-14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009-07-14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009-07-14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2009-07-14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009-06-20 03:09:57 | 000,054,272 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1E62x64.sys -- (L1E) Sterownik miniportu NDIS dla kontrolera Ethernet Atheros AR8121/AR8113/AR8114 PCI-E (NDIS6.20) DRV:[b]64bit:[/b] - [2009-06-10 21:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs) DRV:[b]64bit:[/b] - [2009-06-10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009-06-10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009-06-10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009-06-10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:[b]64bit:[/b] - [2007-09-17 14:53:34 | 000,029,184 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd) DRV:[b]64bit:[/b] - [2007-03-20 10:33:28 | 000,016,896 | ---- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\libusb0.sys -- (libusb0) DRV:[b]64bit:[/b] - [2005-03-29 00:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1728382927-2229636757-2884115149-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/ IE - HKU\S-1-5-21-1728382927-2229636757-2884115149-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "http://www.google.pl/" FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.1 FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.63 FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.48.3 FF - prefs.js..extensions.enabledItems: {57068FBE-1506-42ee-AB02-BD183E7999E4}:4.0 FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:3.6 FF - prefs.js..extensions.enabledItems: {daf44bf7-a45e-4450-979c-91cf07434c3d}:1.5.6 FF - prefs.js..extensions.enabledItems: {4BBDD651-70CF-4821-84F8-2B918CF89CA3}:6.3.3.2 FF - prefs.js..extensions.enabledItems: {340c2bbc-ce74-4362-90b5-7c26312808ef}:1.5.1 FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.9 FF - prefs.js..extensions.enabledItems: {bee6eb20-01e0-ebd1-da83-080329fb9a3a}:0.1 FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.5 FF - prefs.js..extensions.enabledItems: {5C46D283-ABDE-4dce-B83C-08881401921C}:2.1.2 FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6 FF - prefs.js..extensions.enabledItems: webmaster@keep-tube.com:1.2 FF - prefs.js..extensions.enabledItems: locationbar2@design-noir.de:1.0.5 FF - prefs.js..extensions.enabledItems: {B17C1C5A-04B1-11DB-9804-B622A1EF5492}:1.2.1 FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe30}:0.6.9.3 FF - prefs.js..extensions.enabledItems: SkipScreen@SkipScreen:0.5.14amo FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.0.11 FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.4 FF - prefs.js..extensions.enabledItems: tabprogressbar@studio17.wordpress.com:0.6 FF - prefs.js..extensions.enabledItems: {54BB9F3F-07E5-486c-9B39-C7398B99391C}:3.1.2009110201 FF - prefs.js..extensions.enabledItems: tineye@ideeinc.com:1.0 FF - prefs.js..extensions.enabledItems: {d33c2f7c-b1e6-4d46-ab0e-be1f6d05c904}:2.0.2 FF - prefs.js..extensions.enabledItems: gmailnoads@mywebber.com:3.2.0 FF - prefs.js..extensions.enabledItems: {37fa1426-b82d-11db-8314-0800200c9a66}:2.6.4 FF - prefs.js..extensions.enabledItems: youtube2mp3@mondayx.de:1.0.7 FF - prefs.js..extensions.enabledItems: YoutubeDownloader@PeterOlayev.com:1.5 FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe41}:1.0.9 FF - prefs.js..extensions.enabledItems: {dc5d9a10-2736-11da-8cd6-0800200c9a66}:1.4.8 FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.86 FF - prefs.js..extensions.enabledItems: CLEO@guid.customsoftwareconsult.com:4.3 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21 FF - prefs.js..extensions.enabledItems: elemhidehelper@adblockplus.org:1.1 FF - prefs.js..extensions.enabledItems: adblockpopups@jessehakanen.net:0.1.9 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: fdm_ffext@freedownloadmanager.org:1.4.2 FF - HKLM\software\mozilla\Firefox\Extensions\\msntoolbar@msn.com: C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2317.0\Firefox [2010-10-12 19:44:07 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010-10-12 19:44:13 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2010-10-12 19:44:18 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010-11-13 09:27:57 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010-11-14 11:51:38 | 000,000,000 | ---D | M] [2010-10-03 09:31:25 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\mozilla\Extensions [2010-11-20 21:53:25 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions [2010-11-18 22:38:11 | 000,000,000 | ---D | M] (Session Manager) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30} [2010-10-04 16:37:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe41} [2010-11-18 22:38:11 | 000,000,000 | ---D | M] (FlashGot) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34} [2010-11-10 19:33:21 | 000,000,000 | ---D | M] (Firefox Sync) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef} [2010-11-17 20:55:01 | 000,000,000 | ---D | M] (WebMail Notifier) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{37fa1426-b82d-11db-8314-0800200c9a66} [2010-10-04 16:37:22 | 000,000,000 | ---D | M] (Stylish) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8} [2010-10-23 17:44:50 | 000,000,000 | ---D | M] (FEBE) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3} [2010-10-04 16:37:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{54BB9F3F-07E5-486c-9B39-C7398B99391C} [2010-10-04 16:37:23 | 000,000,000 | ---D | M] (Compact Menu 2) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{57068FBE-1506-42ee-AB02-BD183E7999E4} [2010-10-14 20:36:01 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2} [2010-10-16 22:31:31 | 000,000,000 | ---D | M] (Google Shortcuts) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{5C46D283-ABDE-4dce-B83C-08881401921C} [2010-10-04 16:37:23 | 000,000,000 | ---D | M] (FireFTP) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f} [2010-10-04 16:37:22 | 000,000,000 | ---D | M] (Password Exporter) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492} [2010-10-04 16:37:23 | 000,000,000 | ---D | M] (Flash and Video Download) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2010-10-04 16:37:23 | 000,000,000 | ---D | M] (Easy Youtube Video Downloader) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b} [2010-11-06 07:33:04 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2010-10-04 16:37:21 | 000,000,000 | ---D | M] (Tiny Menu) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{d33c2f7c-b1e6-4d46-ab0e-be1f6d05c904} [2010-10-04 16:37:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3} [2010-10-04 16:37:23 | 000,000,000 | ---D | M] (Extended Statusbar) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{daf44bf7-a45e-4450-979c-91cf07434c3d} [2010-10-04 16:37:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{dc572301-7619-498c-a57d-39143191b318} [2010-10-04 16:37:21 | 000,000,000 | ---D | M] (Tabs Menu) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{dc5d9a10-2736-11da-8cd6-0800200c9a66} [2010-10-04 16:37:23 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2010-10-04 16:37:22 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781} [2010-11-10 19:33:17 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\adblockpopups@jessehakanen.net [2010-10-04 16:37:21 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\CLEO@guid.customsoftwareconsult.com [2010-11-04 14:14:40 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\elemhidehelper@adblockplus.org [2010-11-02 14:15:27 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\gmailnoads@mywebber.com [2010-10-04 16:37:22 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\locationbar2@design-noir.de [2010-11-12 23:05:48 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\SkipScreen@SkipScreen [2010-10-04 16:37:21 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\tabprogressbar@studio17.wordpress.com [2010-10-04 16:37:21 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\tineye@ideeinc.com [2010-10-04 16:37:22 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\webmaster@keep-tube.com [2010-10-04 16:37:21 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\youtube2mp3@mondayx.de [2010-10-04 16:37:21 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\mozilla\Firefox\Profiles\mzk03xpq.default\extensions\YoutubeDownloader@PeterOlayev.com [2010-11-20 21:53:25 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions [2010-10-04 17:03:15 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [2010-11-05 15:30:09 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2010-09-15 04:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2010-09-14 22:29:36 | 000,002,767 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\allegro-pl.xml [2010-09-14 22:29:36 | 000,001,406 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fbc-pl.xml [2010-09-14 22:29:36 | 000,000,917 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\merlin-pl.xml [2010-09-14 22:29:36 | 000,000,858 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\pwn-pl.xml [2010-09-14 22:29:36 | 000,001,183 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-pl.xml [2010-09-14 22:29:36 | 000,001,683 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2010-11-14 11:57:19 | 000,000,854 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 activate.adobe.com O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll (Zeon Corporation) O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL (Microsoft Corporation) O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll () O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2317.0\npwinext.dll (Microsoft Corporation) O2 - BHO: (ZeonIEEventHelper Class) - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation) O2 - BHO: (FlashFXP Helper for Internet Explorer) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~2\FlashFXP\IEFlash.dll (IniCom Networks, Inc.) O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2317.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2317.0\npwinext.dll (Microsoft Corporation) O3 - HKLM\..\Toolbar: (Nuance PDF) - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation) O4:[b]64bit:[/b] - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation) O4:[b]64bit:[/b] - HKLM..\Run: [PrintDisp] C:\Windows\SysNative\PrintDisp.exe (ActMask Co.,Ltd - http://www.all2pdf.com) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.) O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [Bing Bar] C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2317.0\mswinext.exe (Microsoft Corp.) O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\SysWow64\Ctxfihlp.exe (Creative Technology Ltd) O4 - HKLM..\Run: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe () O4 - HKLM..\Run: [Nuance PDF Professional 6-reminder] C:\Program Files (x86)\Nuance\PDF Professional 6\Ereg\Ereg.exe (Nuance Communications, Inc.) O4 - HKLM..\Run: [PDF6 Registry Controller] C:\Program Files (x86)\Nuance\PDF Professional 6\RegistryController.exe (Nuance Communications, Inc.) O4 - HKLM..\Run: [PDFHook] C:\Program Files (x86)\Nuance\PDF Professional 6\pdfpro6hook.exe (Nuance Communications, Inc.) O4 - HKLM..\Run: [SamsungPCSuiteTrayApplication] C:\Program Files (x86)\Samsung\Samsung PC Studio 7\LaunchApplication.exe (Samsung) O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.) O4 - HKLM..\Run: [VirtualCloneDrive] C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG) O4 - HKLM..\Run: [VolPanel] C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd) O4 - HKU\.DEFAULT..\Run: [Samsung.PCSync] C:\Program Files (x86)\Samsung\Samsung PC Studio 7\PcSync2.exe (Time Information Services Ltd.) O4 - HKU\S-1-5-18..\Run: [Samsung.PCSync] C:\Program Files (x86)\Samsung\Samsung PC Studio 7\PcSync2.exe (Time Information Services Ltd.) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-1728382927-2229636757-2884115149-1001..\Run: [Free Download Manager] C:\Program Files (x86)\Free Download Manager\fdm.exe (FreeDownloadManager.ORG) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found O4 - Startup: C:\Users\root\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\root\AppData\Roaming\Dropbox\bin\Dropbox.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O8:[b]64bit:[/b] - Extra context menu item: Append the content of the link to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation) O8:[b]64bit:[/b] - Extra context menu item: Append the content of the selected links to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation) O8:[b]64bit:[/b] - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8:[b]64bit:[/b] - Extra context menu item: Append to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation) O8:[b]64bit:[/b] - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8:[b]64bit:[/b] - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8:[b]64bit:[/b] - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8:[b]64bit:[/b] - Extra context menu item: Create PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation) O8:[b]64bit:[/b] - Extra context menu item: Create PDF file from the content of the link - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation) O8:[b]64bit:[/b] - Extra context menu item: Create PDF files from the selected links - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation) O8:[b]64bit:[/b] - Extra context menu item: Open with Nuance PDF Converter 6.0 - C:\Program Files (x86)\Nuance\PDF Professional 6\cnvres_eng.dll () O8:[b]64bit:[/b] - Extra context menu item: Open with PDF Professional 6 - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll (Zeon Corporation) O8:[b]64bit:[/b] - Extra context menu item: Pobierz plik wideo we Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm () O8:[b]64bit:[/b] - Extra context menu item: Pobierz w Free Download Manager - C:\Program Files (x86)\Free Download Manager\dllink.htm () O8:[b]64bit:[/b] - Extra context menu item: Pobierz wszystkie pliki w Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlall.htm () O8:[b]64bit:[/b] - Extra context menu item: Pobierz zaznaczone w Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlselected.htm () O8 - Extra context menu item: Append the content of the link to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation) O8 - Extra context menu item: Append the content of the selected links to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation) O8 - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Append to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation) O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) O8 - Extra context menu item: Create PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation) O8 - Extra context menu item: Create PDF file from the content of the link - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation) O8 - Extra context menu item: Create PDF files from the selected links - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation) O8 - Extra context menu item: Open with Nuance PDF Converter 6.0 - C:\Program Files (x86)\Nuance\PDF Professional 6\cnvres_eng.dll () O8 - Extra context menu item: Open with PDF Professional 6 - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll (Zeon Corporation) O8 - Extra context menu item: Pobierz plik wideo we Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm () O8 - Extra context menu item: Pobierz w Free Download Manager - C:\Program Files (x86)\Free Download Manager\dllink.htm () O8 - Extra context menu item: Pobierz wszystkie pliki w Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlall.htm () O8 - Extra context menu item: Pobierz zaznaczone w Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlselected.htm () O13 - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1 O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O20:[b]64bit:[/b] - AppInit_DLLs: (acaptuser64.dll) - C:\Windows\SysNative\acaptuser64.dll (Adobe Systems, Inc.) O20 - AppInit_DLLs: (acaptuser32.dll) - C:\Windows\SysWow64\acaptuser32.dll (Adobe Systems Incorporated) O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2010-10-23 10:03:25 | 000,000,000 | ---D | M] - D:\Autodesk -- [ NTFS ] O32 - AutoRun File - [2009-06-10 22:42:20 | 000,000,024 | ---- | M] () - D:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2010-10-30 20:04:35 | 000,000,000 | ---D | M] - E:\Autodesk AutoCAD 2011 x64(64bit) MultiLanguage Incl. Keygen -- [ NTFS ] O32 - AutoRun File - [2010-10-02 19:06:51 | 000,000,000 | ---- | M] () - E:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{36735570-de9d-11df-968f-00e012345678}\Shell - "" = AutoRun O33 - MountPoints2\{36735570-de9d-11df-968f-00e012345678}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -- File not found O33 - MountPoints2\{b06e2d51-cec7-11df-8b15-002618b06469}\Shell - "" = AutoRun O33 - MountPoints2\{b06e2d51-cec7-11df-8b15-002618b06469}\Shell\AutoRun\command - "" = I:\AUTORUN.EXE -- File not found O33 - MountPoints2\{f6919673-efcb-11df-9563-00e012345678}\Shell - "" = AutoRun O33 - MountPoints2\{f6919673-efcb-11df-9563-00e012345678}\Shell\AutoRun\command - "" = J:\setup.exe -- File not found O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2010-11-14 22:50:11 | 000,000,000 | ---D | C] -- C:\Users\root\AppData\Local\Zeon [2010-11-14 12:01:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PDF Password Remover v3.1 [2010-11-14 11:52:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Macrovision Shared [2010-11-14 11:51:54 | 000,024,416 | R--- | C] (Adobe Systems Inc.) -- C:\Windows\SysNative\AdobePDFUI.dll [2010-11-14 11:50:11 | 000,112,056 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\acaptuser32.dll [2010-11-14 11:49:00 | 000,052,568 | R--- | C] (Adobe Systems Inc) -- C:\Windows\SysNative\AdobePDF.dll [2010-11-14 11:32:31 | 000,000,000 | ---D | C] -- C:\Users\root\Desktop\produkt-nr-416_pliki [2010-11-14 11:32:19 | 000,000,000 | ---D | C] -- C:\Users\root\Desktop\produkt-nr-415_pliki [2010-11-13 20:51:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Void Realms [2010-11-13 14:11:03 | 000,000,000 | ---D | C] -- C:\Users\root\AppData\Local\ElevatedDiagnostics [2010-11-13 12:48:46 | 000,000,000 | ---D | C] -- C:\Users\root\AppData\Local\GHISLER [2010-11-13 09:31:33 | 000,000,000 | ---D | C] -- C:\totalcmd [2010-11-13 09:31:33 | 000,000,000 | ---D | C] -- C:\Users\root\AppData\Roaming\GHISLER [2010-11-12 21:53:36 | 000,000,000 | ---D | C] -- C:\Users\root\Desktop\prace [2010-11-12 19:54:23 | 000,000,000 | ---D | C] -- C:\Downloads [2010-11-12 14:05:42 | 000,000,000 | ---D | C] -- C:\Users\root\AppData\Roaming\Free Download Manager [2010-11-12 14:05:40 | 000,000,000 | ---D | C] -- C:\ProgramData\FreeDownloadManager.ORG [2010-11-12 14:05:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Free Download Manager [2010-11-09 18:42:08 | 000,000,000 | ---D | C] -- C:\Users\root\AppData\Roaming\Multimedia Player [2010-11-09 14:40:57 | 000,000,000 | ---D | C] -- C:\Users\root\AppData\Roaming\abgx360 [2010-11-09 14:24:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\abgx360 [2010-11-06 17:53:28 | 000,035,892 | ---- | C] (Prolific Technology Inc.) -- C:\Windows\SysWow64\SER9PL.sys [2010-11-06 17:52:31 | 000,064,000 | ---- | C] (XECUTER) -- C:\Windows\SysNative\drivers\ck3pro64.sys [2010-11-06 15:54:44 | 000,000,000 | ---D | C] -- C:\Users\root\Desktop\szkola [2010-11-06 15:07:32 | 000,000,000 | ---D | C] -- C:\Users\root\AppData\Roaming\PSX LIBRE [2010-11-06 14:57:09 | 000,000,000 | ---D | C] -- C:\Users\root\Desktop\GUFinder [2010-11-05 15:30:09 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe [2010-11-05 15:30:09 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe [2010-11-05 15:30:09 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe [2010-11-04 15:20:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinSCP [2010-11-03 23:03:13 | 000,000,000 | ---D | C] -- C:\Users\root\Desktop\03.11.2010 [2010-11-01 17:58:46 | 000,000,000 | R--D | C] -- C:\Users\root\Podcasts [2010-11-01 17:58:46 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft [2010-11-01 17:57:20 | 000,758,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PortableDeviceApi.dll [2010-11-01 17:57:20 | 000,547,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PortableDeviceApi.dll [2010-11-01 09:32:26 | 000,650,752 | ---- | C] (Xbox 360 Scene) -- C:\Users\root\Desktop\XVal.exe [2010-10-31 13:46:03 | 000,000,000 | R--D | C] -- C:\Users\root\Documents\My Dropbox [2010-10-31 13:25:24 | 000,000,000 | ---D | C] -- C:\Users\root\AppData\Roaming\Dropbox [2010-10-29 20:29:11 | 000,000,000 | -HSD | C] -- C:\RECYCLER [2010-10-29 18:58:23 | 000,000,000 | ---D | C] -- C:\Users\root\AppData\Roaming\Xbins [2010-10-29 14:04:25 | 000,000,000 | ---D | C] -- C:\Users\root\Desktop\xecuter_ck3pro_v1.2.25(3) [2010-10-28 14:49:27 | 000,000,000 | ---D | C] -- C:\Users\root\Desktop\OS772V2_public_paintkit [2010-10-27 13:09:11 | 000,961,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CPFilters.dll [2010-10-27 13:09:11 | 000,641,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CPFilters.dll [2010-10-27 13:09:11 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdri.dll [2010-10-27 13:09:11 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MSNP.ax [2010-10-27 13:09:11 | 000,258,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mpg2splt.ax [2010-10-27 13:09:11 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSNP.ax [2010-10-27 13:09:11 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mpg2splt.ax [2010-10-27 13:09:06 | 000,027,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Diskdump.sys [2010-10-23 17:40:19 | 000,000,000 | ---D | C] -- C:\Users\root\Desktop\1 [2010-10-23 13:16:43 | 000,000,000 | ---D | C] -- C:\Users\root\AppData\Roaming\U3 [2010-10-23 13:01:17 | 000,000,000 | ---D | C] -- C:\Windows\Minidump [2010-10-23 08:16:56 | 000,000,000 | ---D | C] -- C:\Users\root\AppData\Roaming\PingTesterDataBas [2010-10-03 11:21:23 | 000,060,928 | ---- | C] ( ) -- C:\Windows\SysWow64\a3d.dll [2010-02-03 23:00:00 | 000,139,264 | ---- | C] ( ) -- C:\Windows\sipr3260.dll [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2010-11-21 00:26:26 | 003,670,016 | -HS- | M] () -- C:\Users\root\NTUSER.DAT [2010-11-20 21:48:15 | 000,014,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2010-11-20 21:48:15 | 000,014,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2010-11-20 21:41:04 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2010-11-20 21:40:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2010-11-20 21:40:52 | 4025,786,368 | -HS- | M] () -- C:\hiberfil.sys [2010-11-20 20:38:29 | 000,062,644 | ---- | M] () -- C:\Windows\SysNative\BMXStateBkp-{00000006-00000000-00000000-00001102-00000005-00211102}.rfx [2010-11-20 20:38:29 | 000,062,644 | ---- | M] () -- C:\Windows\SysNative\BMXState-{00000006-00000000-00000000-00001102-00000005-00211102}.rfx [2010-11-20 20:38:29 | 000,000,788 | ---- | M] () -- C:\Windows\SysNative\DVCState-{00000006-00000000-00000000-00001102-00000005-00211102}.rfx [2010-11-20 20:38:09 | 010,083,779 | -H-- | M] () -- C:\Users\root\AppData\Local\IconCache.db [2010-11-20 20:07:07 | 001,549,696 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2010-11-20 20:07:07 | 000,697,674 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat [2010-11-20 20:07:07 | 000,615,810 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2010-11-20 20:07:07 | 000,134,784 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat [2010-11-20 20:07:07 | 000,106,190 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2010-11-20 10:32:46 | 003,657,216 | ---- | M] () -- C:\Users\root\Desktop\Prawa pracodawcy i pracownika.ppt [2010-11-20 10:22:08 | 000,019,967 | ---- | M] () -- C:\Users\root\Desktop\filmiki.docx [2010-11-18 20:13:38 | 000,097,280 | ---- | M] () -- C:\Users\root\Documents\Egzamin specjalistyczny.doc [2010-11-17 21:43:51 | 000,058,801 | ---- | M] () -- C:\Users\root\Documents\Egzamin specjalistyczny.docx [2010-11-15 16:24:36 | 000,033,109 | ---- | M] () -- C:\Users\root\Desktop\psgroove_minimus_at90usb162_16mhz_firmware3.41.hex [2010-11-14 12:16:21 | 000,426,576 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2010-11-14 12:08:11 | 000,307,222 | ---- | M] () -- C:\Users\root\Desktop\Kwiatkowski_Zoltowski1.pdf [2010-11-14 12:07:41 | 000,438,734 | ---- | M] () -- C:\Windows\SysWow64\muzika.xm [2010-11-14 12:04:42 | 000,119,680 | ---- | M] () -- C:\Users\root\AppData\Local\GDIPFONTCACHEV1.DAT [2010-11-14 12:01:51 | 000,001,044 | ---- | M] () -- C:\Users\root\Desktop\PDF Password Remover v3.1.lnk [2010-11-14 11:52:15 | 000,002,027 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Acrobat 9 Pro Extended.lnk [2010-11-14 11:43:25 | 000,001,254 | ---- | M] () -- C:\Users\Public\Desktop\Virtual CloneDrive.lnk [2010-11-14 11:32:32 | 000,017,965 | ---- | M] () -- C:\Users\root\Desktop\produkt-nr-416.html [2010-11-14 11:32:20 | 000,019,197 | ---- | M] () -- C:\Users\root\Desktop\produkt-nr-415.html [2010-11-14 10:49:25 | 000,306,711 | ---- | M] () -- C:\Users\root\Desktop\Kwiatkowski_Zoltowski.pdf [2010-11-13 20:51:27 | 000,003,051 | ---- | M] () -- C:\Users\root\Desktop\Power Admin.lnk [2010-11-13 20:43:44 | 001,236,343 | ---- | M] () -- C:\Users\root\Desktop\ws28bi-2.pdf [2010-11-13 14:29:14 | 000,087,798 | ---- | M] () -- C:\Users\root\Desktop\1311352681_2.jpg [2010-11-13 12:50:16 | 000,632,632 | ---- | M] () -- C:\Users\root\Desktop\All Music.m3u8 [2010-11-13 12:49:44 | 002,608,178 | ---- | M] () -- C:\Users\root\Desktop\All Music.fpl [2010-11-13 09:31:34 | 000,000,632 | ---- | M] () -- C:\Users\root\Desktop\Total Commander.lnk [2010-11-12 21:50:45 | 001,824,888 | ---- | M] () -- C:\Users\root\Desktop\Transport kombinowany1.pptx [2010-11-12 21:38:51 | 013,220,352 | ---- | M] () -- C:\Users\root\Desktop\Transport kombinowany.pps [2010-11-12 21:38:21 | 001,806,537 | ---- | M] () -- C:\Users\root\Desktop\Transport kombinowany.pptx [2010-11-12 21:35:32 | 000,201,106 | ---- | M] () -- C:\Users\root\Desktop\obraz2(228).jpg [2010-11-12 21:33:27 | 000,058,053 | ---- | M] () -- C:\Users\root\Desktop\4af6f8bb832a8_o.jpg [2010-11-12 21:20:41 | 000,110,029 | ---- | M] () -- C:\Users\root\Desktop\kontener.gif [2010-11-12 16:28:05 | 000,350,652 | ---- | M] () -- C:\Users\root\Desktop\TransportKombinowany.pdf [2010-11-12 16:16:23 | 001,878,085 | ---- | M] () -- C:\Users\root\Desktop\Prawo pracodawcy i pracownika.xml [2010-11-12 16:16:05 | 001,058,946 | ---- | M] () -- C:\Users\root\Desktop\Prawo pracodawcy i pracownika.potx [2010-11-12 16:13:40 | 035,150,056 | ---- | M] () -- C:\Users\root\Desktop\Prawo pracodawcy i pracownika.wmv [2010-11-12 15:58:26 | 001,060,247 | ---- | M] () -- C:\Users\root\Desktop\Prawo pracodawcy i pracownika.pptx [2010-11-12 15:13:02 | 000,048,548 | ---- | M] () -- C:\Users\root\Desktop\struktura_sm_m.gif [2010-11-12 14:05:42 | 000,000,981 | ---- | M] () -- C:\Users\root\Desktop\Free Download Manager.lnk [2010-11-11 19:50:37 | 000,033,880 | ---- | M] () -- C:\Users\root\Desktop\Prawa pracodawcy i pracownika.docx [2010-11-11 15:41:00 | 000,043,841 | ---- | M] () -- C:\Users\root\Desktop\130650_Full_MedRes.jpg [2010-11-10 19:45:52 | 000,003,083 | ---- | M] () -- C:\Users\root\Desktop\resetdma.vbs [2010-11-06 19:35:40 | 002,484,072 | ---- | M] () -- C:\Windows\SysWow64\abgx360.exe [2010-11-06 17:26:54 | 000,004,608 | ---- | M] () -- C:\Users\root\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010-11-06 09:34:04 | 000,490,111 | ---- | M] () -- C:\Users\root\Desktop\Recykling.pdf [2010-11-04 18:56:43 | 000,000,600 | ---- | M] () -- C:\Users\root\AppData\Roaming\winscp.rnd [2010-11-04 15:20:24 | 000,001,793 | ---- | M] () -- C:\Users\root\Desktop\WinSCP.lnk [2010-11-04 06:22:52 | 099,289,451 | ---- | M] () -- C:\Users\root\Desktop\SystemUpdate12611.zip [2010-10-31 13:46:04 | 000,001,023 | ---- | M] () -- C:\Users\root\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2010-10-31 13:46:03 | 000,001,043 | ---- | M] () -- C:\Users\root\Desktop\Dropbox.lnk [2010-10-30 10:44:34 | 000,000,543 | ---- | M] () -- C:\Windows\NGO.cer [2010-10-29 18:59:55 | 003,605,407 | ---- | M] () -- C:\Users\root\Desktop\Hitachi_iXtreme_v1.51_with_readme-FINAL.rar [2010-10-29 14:05:46 | 000,262,144 | ---- | M] () -- C:\Users\root\Documents\BENQ-OFW.bin [2010-10-29 13:38:16 | 006,157,767 | ---- | M] () -- C:\Users\root\Desktop\Created_by_ModTraders.co.uk_benq.mp4 [2010-10-28 16:19:08 | 000,001,021 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [color=#E56717]========== Files Created - No Company Name ==========[/color] [2010-11-20 20:14:33 | 000,004,095 | ---- | C] () -- C:\Users\root\Desktop\cdak_1024x768.exe [2010-11-20 17:02:49 | 000,033,109 | ---- | C] () -- C:\Users\root\Desktop\psgroove_minimus_at90usb162_16mhz_firmware3.41.hex [2010-11-20 10:32:45 | 003,657,216 | ---- | C] () -- C:\Users\root\Desktop\Prawa pracodawcy i pracownika.ppt [2010-11-17 22:42:37 | 005,610,704 | ---- | C] () -- C:\Users\root\Desktop\2010-09-15 10.11.04.3gp [2010-11-17 22:42:37 | 002,207,914 | ---- | C] () -- C:\Users\root\Desktop\2010-09-16 08.47.15.3gp [2010-11-17 21:44:06 | 000,097,280 | ---- | C] () -- C:\Users\root\Documents\Egzamin specjalistyczny.doc [2010-11-17 20:53:45 | 000,058,801 | ---- | C] () -- C:\Users\root\Documents\Egzamin specjalistyczny.docx [2010-11-14 12:08:11 | 000,307,222 | ---- | C] () -- C:\Users\root\Desktop\Kwiatkowski_Zoltowski1.pdf [2010-11-14 12:07:41 | 000,438,734 | ---- | C] () -- C:\Windows\SysWow64\muzika.xm [2010-11-14 12:01:51 | 000,001,044 | ---- | C] () -- C:\Users\root\Desktop\PDF Password Remover v3.1.lnk [2010-11-14 11:51:39 | 000,002,027 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Acrobat 9 Pro Extended.lnk [2010-11-14 11:43:25 | 000,001,254 | ---- | C] () -- C:\Users\Public\Desktop\Virtual CloneDrive.lnk [2010-11-14 11:32:31 | 000,017,965 | ---- | C] () -- C:\Users\root\Desktop\produkt-nr-416.html [2010-11-14 11:32:19 | 000,019,197 | ---- | C] () -- C:\Users\root\Desktop\produkt-nr-415.html [2010-11-14 10:49:25 | 000,306,711 | ---- | C] () -- C:\Users\root\Desktop\Kwiatkowski_Zoltowski.pdf [2010-11-13 20:51:27 | 000,003,051 | ---- | C] () -- C:\Users\root\Desktop\Power Admin.lnk [2010-11-13 20:43:44 | 001,236,343 | ---- | C] () -- C:\Users\root\Desktop\ws28bi-2.pdf [2010-11-13 14:29:13 | 000,087,798 | ---- | C] () -- C:\Users\root\Desktop\1311352681_2.jpg [2010-11-13 12:50:16 | 000,632,632 | ---- | C] () -- C:\Users\root\Desktop\All Music.m3u8 [2010-11-13 12:49:44 | 002,608,178 | ---- | C] () -- C:\Users\root\Desktop\All Music.fpl [2010-11-13 10:58:50 | 000,019,967 | ---- | C] () -- C:\Users\root\Desktop\filmiki.docx [2010-11-13 09:31:34 | 000,000,632 | ---- | C] () -- C:\Users\root\Desktop\Total Commander.lnk [2010-11-13 09:31:33 | 000,000,545 | ---- | C] () -- C:\Windows\UC.PIF [2010-11-13 09:31:33 | 000,000,545 | ---- | C] () -- C:\Windows\RAR.PIF [2010-11-13 09:31:33 | 000,000,545 | ---- | C] () -- C:\Windows\PKZIP.PIF [2010-11-13 09:31:33 | 000,000,545 | ---- | C] () -- C:\Windows\PKUNZIP.PIF [2010-11-13 09:31:33 | 000,000,545 | ---- | C] () -- C:\Windows\NOCLOSE.PIF [2010-11-13 09:31:33 | 000,000,545 | ---- | C] () -- C:\Windows\LHA.PIF [2010-11-13 09:31:33 | 000,000,545 | ---- | C] () -- C:\Windows\ARJ.PIF [2010-11-12 21:41:13 | 001,824,888 | ---- | C] () -- C:\Users\root\Desktop\Transport kombinowany1.pptx [2010-11-12 21:38:45 | 013,220,352 | ---- | C] () -- C:\Users\root\Desktop\Transport kombinowany.pps [2010-11-12 21:35:32 | 000,201,106 | ---- | C] () -- C:\Users\root\Desktop\obraz2(228).jpg [2010-11-12 21:33:26 | 000,058,053 | ---- | C] () -- C:\Users\root\Desktop\4af6f8bb832a8_o.jpg [2010-11-12 21:20:39 | 000,110,029 | ---- | C] () -- C:\Users\root\Desktop\kontener.gif [2010-11-12 16:40:23 | 001,806,537 | ---- | C] () -- C:\Users\root\Desktop\Transport kombinowany.pptx [2010-11-12 16:28:05 | 000,350,652 | ---- | C] () -- C:\Users\root\Desktop\TransportKombinowany.pdf [2010-11-12 16:16:22 | 001,878,085 | ---- | C] () -- C:\Users\root\Desktop\Prawo pracodawcy i pracownika.xml [2010-11-12 16:09:01 | 035,150,056 | ---- | C] () -- C:\Users\root\Desktop\Prawo pracodawcy i pracownika.wmv [2010-11-12 16:06:03 | 001,058,946 | ---- | C] () -- C:\Users\root\Desktop\Prawo pracodawcy i pracownika.potx [2010-11-12 15:13:01 | 000,048,548 | ---- | C] () -- C:\Users\root\Desktop\struktura_sm_m.gif [2010-11-12 14:05:42 | 000,000,981 | ---- | C] () -- C:\Users\root\Desktop\Free Download Manager.lnk [2010-11-11 18:27:57 | 001,060,247 | ---- | C] () -- C:\Users\root\Desktop\Prawo pracodawcy i pracownika.pptx [2010-11-11 18:09:02 | 000,033,880 | ---- | C] () -- C:\Users\root\Desktop\Prawa pracodawcy i pracownika.docx [2010-11-11 15:40:59 | 000,043,841 | ---- | C] () -- C:\Users\root\Desktop\130650_Full_MedRes.jpg [2010-11-10 19:45:50 | 000,003,083 | ---- | C] () -- C:\Users\root\Desktop\resetdma.vbs [2010-11-06 19:35:40 | 002,484,072 | ---- | C] () -- C:\Windows\SysWow64\abgx360.exe [2010-11-06 17:53:28 | 000,026,719 | ---- | C] () -- C:\Windows\SysWow64\SERSPL.VXD [2010-11-06 09:34:04 | 000,490,111 | ---- | C] () -- C:\Users\root\Desktop\Recykling.pdf [2010-11-04 15:20:25 | 000,000,600 | ---- | C] () -- C:\Users\root\AppData\Roaming\winscp.rnd [2010-11-04 15:20:24 | 000,001,793 | ---- | C] () -- C:\Users\root\Desktop\WinSCP.lnk [2010-11-04 06:09:27 | 099,289,451 | ---- | C] () -- C:\Users\root\Desktop\SystemUpdate12611.zip [2010-10-31 13:46:04 | 000,001,023 | ---- | C] () -- C:\Users\root\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2010-10-31 13:46:03 | 000,001,043 | ---- | C] () -- C:\Users\root\Desktop\Dropbox.lnk [2010-10-31 12:35:53 | 005,654,528 | ---- | C] () -- C:\System.nfo [2010-10-30 10:44:34 | 000,000,543 | ---- | C] () -- C:\Windows\NGO.cer [2010-10-29 18:59:39 | 003,605,407 | ---- | C] () -- C:\Users\root\Desktop\Hitachi_iXtreme_v1.51_with_readme-FINAL.rar [2010-10-29 14:05:46 | 000,262,144 | ---- | C] () -- C:\Users\root\Documents\BENQ-OFW.bin [2010-10-29 13:38:15 | 006,157,767 | ---- | C] () -- C:\Users\root\Desktop\Created_by_ModTraders.co.uk_benq.mp4 [2010-10-28 16:19:08 | 000,001,021 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2010-10-16 16:59:37 | 000,004,608 | ---- | C] () -- C:\Users\root\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010-10-13 12:56:10 | 000,000,366 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2010-10-13 12:18:37 | 001,391,616 | ---- | C] () -- C:\Windows\SysWow64\ActPDF.dll [2010-10-10 16:11:09 | 000,004,096 | -H-- | C] () -- C:\Users\root\AppData\Local\keyfile3.drm [2010-10-07 14:57:56 | 000,000,600 | ---- | C] () -- C:\Users\root\AppData\Local\PUTTY.RND [2010-10-03 11:22:52 | 000,177,664 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL [2010-10-03 11:22:52 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL [2010-10-03 11:21:25 | 000,002,560 | ---- | C] () -- C:\Windows\SysWow64\CTXFIRES.DLL [2010-10-03 11:21:23 | 000,021,164 | ---- | C] () -- C:\Windows\SysWow64\instwdm.ini [2010-10-03 11:21:23 | 000,000,285 | ---- | C] () -- C:\Windows\SysWow64\kill.ini [2010-10-03 11:21:23 | 000,000,054 | ---- | C] () -- C:\Windows\SysWow64\ctzapxx.ini [2010-10-03 10:16:38 | 000,119,680 | ---- | C] () -- C:\Users\root\AppData\Local\GDIPFONTCACHEV1.DAT [2010-10-03 09:34:01 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI [2010-10-03 09:23:51 | 010,083,779 | -H-- | C] () -- C:\Users\root\AppData\Local\IconCache.db [2010-09-01 23:53:48 | 000,108,032 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll [2010-06-23 11:35:52 | 000,790,528 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll [2010-06-23 11:35:52 | 000,134,144 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll [2009-08-16 09:08:36 | 000,178,176 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll [2009-07-14 05:54:24 | 000,000,174 | -HS- | C] () -- C:\Program Files\desktop.ini [2009-07-14 05:54:24 | 000,000,174 | -HS- | C] () -- C:\Program Files (x86)\desktop.ini [2009-07-14 03:35:42 | 000,001,405 | ---- | C] () -- C:\Windows\msdfmap.ini [2009-07-14 03:34:57 | 000,000,403 | ---- | C] () -- C:\Windows\win.ini [2009-07-14 03:34:57 | 000,000,219 | ---- | C] () -- C:\Windows\system.ini [2009-07-14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009-07-13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll [color=#E56717]========== LOP Check ==========[/color] [2010-10-04 16:45:04 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\.wtw [2010-11-09 16:29:55 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\abgx360 [2010-10-10 16:50:30 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\Autodesk [2010-11-21 00:27:23 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\Azureus [2010-10-19 18:44:10 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\BESTplayer [2010-11-20 21:41:45 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\Dropbox [2010-10-07 16:04:48 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\FileZilla [2010-10-07 16:05:55 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\FlashFXP [2010-10-04 14:52:08 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\foobar2000 [2010-11-21 00:27:28 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\Free Download Manager [2010-11-13 09:31:33 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\GHISLER [2010-10-13 12:18:20 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\Iceni [2010-10-04 18:39:42 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\ImgBurn [2010-11-09 18:42:08 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\Multimedia Player [2010-10-04 18:19:22 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\Notepad++ [2010-10-13 12:57:23 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\Nuance [2010-10-05 18:28:28 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\PC Suite [2010-10-13 13:59:54 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\PDF Writer [2010-10-23 08:21:32 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\PingTesterDataBas [2010-11-06 15:07:32 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\PSX LIBRE [2010-10-03 09:33:42 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\Razer [2010-10-14 13:40:30 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\Samsung [2010-10-03 09:34:01 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\Shark007 [2010-10-13 13:51:54 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\Softland [2010-10-08 23:28:54 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\TeamViewer [2010-10-10 13:12:03 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\Win7codecs [2010-10-29 18:58:23 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\Xbins [2010-10-13 12:56:10 | 000,000,000 | ---D | M] -- C:\Users\root\AppData\Roaming\Zeon [2010-11-07 18:14:00 | 000,032,592 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT [color=#E56717]========== Purity Check ==========[/color] < End of report >