OTL logfile created on: 2012-08-13 21:59:03 - Run 1 OTL by OldTimer - Version Folder = C:\Documents and Settings\Dariush\Pulpit Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,50 Gb Total Physical Memory | 0,87 Gb Available Physical Memory | 57,72% Memory free 2,86 Gb Paging File | 2,44 Gb Available in Paging File | 85,29% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 58,59 Gb Total Space | 13,86 Gb Free Space | 23,65% Space Free | Partition Type: NTFS Drive D: | 80,08 Gb Total Space | 3,30 Gb Free Space | 4,12% Space Free | Partition Type: NTFS Drive E: | 94,20 Gb Total Space | 34,07 Gb Free Space | 36,16% Space Free | Partition Type: NTFS Computer Name: DOM-E9CB13QCV9Q | User Name: Dariush | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-08-13 21:44:48 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dariush\Pulpit\OTL.exe PRC - [2011-05-06 22:23:57 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2008-04-14 23:51:18 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012-08-03 09:50:18 | 009,465,032 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_270.dll MOD - [2011-05-06 22:24:01 | 001,874,904 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll MOD - [2011-03-16 17:32:56 | 001,496,576 | ---- | M] () -- C:\Documents and Settings\Dariush\Dane aplikacji\Mozilla\Firefox\Profiles\34ckncjz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll MOD - [2011-03-16 17:32:36 | 000,343,552 | ---- | M] () -- C:\Documents and Settings\Dariush\Dane aplikacji\Mozilla\Firefox\Profiles\34ckncjz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff4.dll MOD - [2010-11-04 09:51:44 | 000,555,624 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\nView\nvShell.dll MOD - [2008-04-14 23:50:38 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll MOD - [2007-01-31 12:39:00 | 000,032,768 | ---- | M] () -- C:\Program Files\VDOTool\TBPanelExt.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - [2012-08-03 09:50:19 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012-07-05 22:07:00 | 000,161,704 | ---- | M] (Oracle Corporation) [Auto | Stopped] -- C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe -- (JavaQuickStarterService) SRV - [2012-04-12 10:31:34 | 000,784,792 | ---- | M] (Spigot, Inc.) [Auto | Stopped] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater) SRV - [2012-03-07 01:15:14 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Stopped] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- system32\drivers\InCDRm.sys -- (InCDRm) DRV - File not found [Kernel | System | Stopped] -- system32\drivers\InCDPass.sys -- (InCDPass) DRV - File not found [File_System | Disabled | Stopped] -- system32\drivers\InCDFs.sys -- (InCDFs) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\EagleXNt.sys -- (EagleXNt) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\EagleNT.sys -- (EagleNT) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2012-03-07 01:03:51 | 000,612,184 | ---- | M] (AVAST Software) [File_System | System | Stopped] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2012-03-07 01:03:38 | 000,337,880 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP) DRV - [2012-03-07 01:02:00 | 000,035,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr) DRV - [2012-03-07 01:01:53 | 000,053,848 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2012-03-07 01:01:39 | 000,095,704 | ---- | M] (AVAST Software) [File_System | Auto | Stopped] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2) DRV - [2012-03-07 01:01:30 | 000,020,696 | ---- | M] (AVAST Software) [File_System | Auto | Stopped] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2012-03-07 00:58:29 | 000,024,920 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4) DRV - [2012-01-15 19:29:54 | 000,239,168 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV - [2011-02-24 22:00:27 | 000,043,672 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\AFS2K.SYS -- (AFS2K) DRV - [2007-03-16 11:11:38 | 000,012,256 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Auto | Stopped] -- C:\WINDOWS\System32\drivers\TBPanel.sys -- (TBPanel) DRV - [2007-03-16 11:11:38 | 000,012,256 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\TBPanel.sys -- (Cardex) DRV - [2006-01-13 14:39:48 | 003,844,288 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) DRV - [2005-08-18 10:52:06 | 000,093,568 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvata.sys -- (nvata) DRV - [2005-04-05 20:22:30 | 000,012,928 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus) DRV - [2005-04-05 20:22:28 | 000,033,536 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD) DRV - [2005-03-09 16:53:00 | 000,043,008 | ---- | M] (Advanced Micro Devices) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8) DRV - [2001-08-17 22:51:32 | 000,018,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\irsir.sys -- (irsir) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/ IE - HKLM\..\SearchScopes,DefaultScope = {6BD63EF5-F376-4104-B390-F6E1E3BEDAAC} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKLM\..\SearchScopes\{6BD63EF5-F376-4104-B390-F6E1E3BEDAAC}: "URL" = http://startsear.ch/?q={searchTerms} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1645522239-1336601894-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.onet.pl/ IE - HKU\S-1-5-21-1645522239-1336601894-839522115-1003\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) IE - HKU\S-1-5-21-1645522239-1336601894-839522115-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-1645522239-1336601894-839522115-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC IE - HKU\S-1-5-21-1645522239-1336601894-839522115-1003\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&AF=109980&babsrc=SP_ss&mntrId=ac5adbfa000000000000000feaf4aff0 IE - HKU\S-1-5-21-1645522239-1336601894-839522115-1003\..\SearchScopes\{6BD63EF5-F376-4104-B390-F6E1E3BEDAAC}: "URL" = http://startsear.ch/?q={searchTerms} IE - HKU\S-1-5-21-1645522239-1336601894-839522115-1003\..\SearchScopes\{BDF620F5-1AD7-4B6D-8C4E-971407F23361}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=F0763DA5-CDF7-4D63-BB3B-5E7CE5DEC90E&apn_sauid=2320297F-575E-427A-B4C1-9046C835491D IE - HKU\S-1-5-21-1645522239-1336601894-839522115-1003\..\SearchScopes\{E29150B4-3A9B-48C9-83A5-9E13CB38B975}: "URL" = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms} IE - HKU\S-1-5-21-1645522239-1336601894-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1645522239-1336601894-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultengine: "Ask.com" FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)" FF - prefs.js..browser.search.order.1: "Ask.com" FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=937811&ilc=12" FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)" FF - prefs.js..browser.startup.homepage: "http://search.babylon.com/?babsrc=HP_Prot" FF - prefs.js..extensions.enabledItems: dealio@mybrowserbar.com:4.1 FF - prefs.js..extensions.enabledItems: wtxpcom@mybrowserbar.com:4.1 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=ORJ&o=100000027&locale=en_US&apn_uid=F0763DA5-CDF7-4D63-BB3B-5E7CE5DEC90E&apn_ptnrs=U3&apn_sauid=2320297F-575E-427A-B4C1-9046C835491D&apn_dtid=OSJ000YYPL&&q=" FF - prefs.js..network.proxy.http: "" FF - prefs.js..network.proxy.http_port: 8080 FF - prefs.js..network.proxy.share_proxy_settings: true FF - prefs.js..network.proxy.type: 0 FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_270.dll () FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2011-02-10 15:16:42 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-05-20 18:43:15 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011-05-06 22:24:24 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012-07-13 23:52:57 | 000,000,000 | ---D | M] [2011-02-10 01:22:44 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dariush\Dane aplikacji\Mozilla\Extensions [2012-08-13 21:42:28 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dariush\Dane aplikacji\Mozilla\Firefox\Profiles\34ckncjz.default\extensions [2011-05-26 22:22:25 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\Dariush\Dane aplikacji\Mozilla\Firefox\Profiles\34ckncjz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2012-08-07 15:03:39 | 000,000,000 | ---D | M] ("SavingsApp") -- C:\Documents and Settings\Dariush\Dane aplikacji\Mozilla\Firefox\Profiles\34ckncjz.default\extensions\crossriderapp4639@crossrider.com [2012-03-02 13:31:15 | 000,000,000 | ---D | M] (Babylon) -- C:\Documents and Settings\Dariush\Dane aplikacji\Mozilla\Firefox\Profiles\34ckncjz.default\extensions\ffxtlbr@babylon.com [2012-08-13 21:42:28 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dariush\Dane aplikacji\Mozilla\Firefox\Profiles\34ckncjz.default\extensions\staged [2012-07-30 02:50:15 | 000,002,568 | ---- | M] () -- C:\Documents and Settings\Dariush\Dane aplikacji\Mozilla\Firefox\Profiles\34ckncjz.default\searchplugins\askcom.xml [2011-12-27 14:24:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2011-10-01 21:32:45 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2010-04-22 19:16:04 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010-12-03 15:11:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2005-01-02 21:04:11 | 000,089,388 | ---- | M] () (No name found) -- C:\DOCUMENTS AND SETTINGS\DARIUSH\DANE APLIKACJI\MOZILLA\FIREFOX\PROFILES\34CKNCJZ.DEFAULT\EXTENSIONS\{DD05FD3D-18DF-4CE4-AE53-E795339C5F01}.XPI [2012-05-20 18:43:15 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF [2012-04-15 17:36:51 | 000,000,000 | ---D | M] (Widgi Toolbar Platform) -- C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM [2010-11-21 18:51:40 | 000,000,000 | ---D | M] (Dealio Toolbar) -- C:\PROGRAM FILES\DEALIO TOOLBAR\FF [2012-04-15 14:51:10 | 000,000,000 | ---D | M] (YouTube Downloader Toolbar) -- C:\PROGRAM FILES\YOUTUBE DOWNLOADER TOOLBAR\FF [2011-05-06 22:23:57 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll [2008-11-11 09:38:54 | 000,663,552 | ---- | M] (BitComet) -- C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll [2009-12-18 02:31:54 | 000,063,488 | ---- | M] (Nullsoft) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll [2010-01-01 10:00:00 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2012-03-02 13:31:00 | 000,002,310 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml [2010-01-01 10:00:00 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2010-03-28 18:56:18 | 000,002,035 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fcmdSrchFxt.xml [2010-01-01 10:00:00 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2010-01-01 10:00:00 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2010-01-01 10:00:00 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2010-01-01 10:00:00 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml [color=#E56717]========== Chrome ==========[/color] CHR - homepage: http://www.google.com CHR - homepage: http://www.google.com CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.75\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.75\pdf.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.75\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll CHR - plugin: BitCometAgent (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll CHR - plugin: Java Deployment Toolkit (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\\npGoogleUpdate3.dll CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll CHR - Extension: SavingsApp = C:\Documents and Settings\Dariush\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\bbohlimhkgnnphbdkghkbcjojoafohoa\1.17.11_0\ CHR - Extension: YouTube = C:\Documents and Settings\Dariush\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\ CHR - Extension: Szukaj w Google = C:\Documents and Settings\Dariush\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\\ CHR - Extension: avast! WebRep = C:\Documents and Settings\Dariush\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1426_0\ CHR - Extension: Gmail = C:\Documents and Settings\Dariush\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2001-10-26 17:45:16 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: localhost O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (SavingsApp) - {11111111-1111-1111-1111-110011461139} - C:\Program Files\SavingsApp\SavingsApp.dll (215 Apps) O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\\bh\BabylonToolbar.dll File not found O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) O2 - BHO: (IE5BarLauncherBHO Class) - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files\vShare.tv plugin\ssBarLcher.dll (StartSearch Inc.) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.) O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (StartSearchToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files\vShare.tv plugin\ssBarLcher.dll (StartSearch Inc.) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\\BabylonToolbarTlbr.dll File not found O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O3 - HKU\S-1-5-21-1645522239-1336601894-839522115-1003\..\Toolbar\WebBrowser: (StartSearchToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files\vShare.tv plugin\ssBarLcher.dll (StartSearch Inc.) O3 - HKU\S-1-5-21-1645522239-1336601894-839522115-1003\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [Gainward] C:\Program Files\VDOTool\TBPanel.exe (Palit Microsystems, Inc.) O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe (Hewlett-Packard) O4 - HKLM..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe (Hewlett-Packard) O4 - HKLM..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe (Hewlett-Packard) O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe () O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.) O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft) O4 - HKU\S-1-5-21-1645522239-1336601894-839522115-1003..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe (Nero AG) O4 - HKU\S-1-5-21-1645522239-1336601894-839522115-1003..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg.exe (GG Network S.A.) O4 - HKU\S-1-5-21-1645522239-1336601894-839522115-1003..\Run: [InstallIQUpdater] C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC) O4 - HKU\S-1-5-21-1645522239-1336601894-839522115-1003..\Run: [tbtrlvyylkfgyrh] C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\tbtrlvyy.exe (Origin PC) O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated) O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-1645522239-1336601894-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Pobierz wszystkie VIdeo za pomocą BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com) O8 - Extra context menu item: Pobierz wszystko za pomocą BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com) O8 - Extra context menu item: Pobierz za pomocą BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com) O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.) O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F6C55493-142A-47B3-B0A1-849DEE768DE9}: DhcpNameServer = O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Idylla.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009-01-09 14:04:05 | 000,000,050 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-08-13 21:44:48 | 000,596,992 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Dariush\Pulpit\OTL.exe [2012-08-13 19:35:04 | 000,089,088 | ---- | C] (Origin PC) -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\tbtrlvyy.exe [2012-08-13 19:35:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\omtrdyksldwvhpi [2012-08-13 19:34:50 | 000,089,088 | ---- | C] (Origin PC) -- C:\Documents and Settings\Dariush\ms.exe [2012-08-07 15:03:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dariush\Ustawienia lokalne\Dane aplikacji\SavingsApp [2012-08-07 15:03:40 | 000,000,000 | -HSD | C] -- C:\WINDOWS\System32\AI_RecycleBin [2012-08-07 15:03:26 | 000,000,000 | ---D | C] -- C:\Program Files\W3i [2012-08-07 15:03:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\W3i [2012-08-07 15:03:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programy\InstallIQ Updater [2012-08-07 15:03:21 | 000,000,000 | ---D | C] -- C:\Program Files\Przyspiesz Komputer [2012-08-07 15:03:19 | 000,000,000 | ---D | C] -- C:\Program Files\SavingsApp [2012-08-07 15:02:40 | 000,000,000 | ---D | C] -- C:\Program Files\Free Offers from Freeze.com [2012-07-31 00:41:07 | 000,000,000 | RH-D | C] -- C:\AHCache [2012-07-21 18:00:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dariush\Moje dokumenty\S Y G N A [2012-07-16 16:06:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dariush\Dane aplikacji\TuneUp Software [2012-07-16 16:06:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\TuneUp Software [2012-07-16 16:06:23 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\{32364CEA-7855-4A3C-B674-53D8E9B97936} [2012-07-16 16:06:23 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Common Files [2012-07-16 16:04:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programy\DVDVideoSoft [2012-07-16 16:04:16 | 000,000,000 | ---D | C] -- C:\Program Files\DVDVideoSoft [2012-07-16 16:04:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DVDVideoSoft [2012-07-16 16:03:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dariush\Dane aplikacji\DVDVideoSoft [2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-08-13 21:44:48 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dariush\Pulpit\OTL.exe [2012-08-13 21:40:51 | 000,457,680 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2012-08-13 21:40:51 | 000,400,408 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012-08-13 21:40:51 | 000,077,472 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2012-08-13 21:40:51 | 000,060,628 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2012-08-13 21:36:29 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012-08-13 21:14:00 | 000,000,238 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job [2012-08-13 21:13:36 | 000,000,558 | ---- | M] () -- C:\WINDOWS\DFC.INI [2012-08-13 20:50:00 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2012-08-13 20:22:01 | 000,001,038 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2012-08-13 19:43:43 | 000,001,034 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2012-08-13 19:43:43 | 000,000,290 | ---- | M] () -- C:\WINDOWS\tasks\Express Files Updater.job [2012-08-13 19:43:41 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2012-08-13 19:35:04 | 000,000,051 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\pivmyjshtkvuumy [2012-08-13 19:34:50 | 000,089,088 | ---- | M] (Origin PC) -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\tbtrlvyy.exe [2012-08-13 19:34:50 | 000,089,088 | ---- | M] (Origin PC) -- C:\Documents and Settings\Dariush\ms.exe [2012-08-13 19:32:16 | 001,006,574 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2012-08-13 16:23:06 | 006,291,456 | -H-- | M] () -- C:\Documents and Settings\Dariush\NTUSER.DAT [2012-08-13 16:23:06 | 000,000,188 | -HS- | M] () -- C:\Documents and Settings\Dariush\ntuser.ini [2012-08-13 12:07:42 | 000,116,224 | ---- | M] () -- C:\Documents and Settings\Dariush\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012-08-11 11:19:01 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012-08-09 11:37:33 | 000,001,869 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Pulpit\Google Chrome.lnk [2012-08-08 11:48:07 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini [2012-08-03 09:50:19 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe [2012-08-03 09:50:18 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl [2012-07-31 22:08:47 | 000,184,466 | ---- | M] () -- C:\Documents and Settings\Dariush\Moje dokumenty\PeaceSells - screen gildijny.JPG [2012-07-30 13:08:39 | 000,017,179 | ---- | M] () -- C:\Documents and Settings\Dariush\Moje dokumenty\pryszczotelli.jpg [2012-07-28 15:11:30 | 000,000,122 | ---- | M] () -- C:\Documents and Settings\Dariush\default.pls [2012-07-20 16:58:54 | 000,002,267 | ---- | M] () -- C:\Documents and Settings\Dariush\Pulpit\Skype.lnk [2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-08-13 19:34:57 | 000,000,051 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\pivmyjshtkvuumy [2012-07-31 22:08:47 | 000,184,466 | ---- | C] () -- C:\Documents and Settings\Dariush\Moje dokumenty\PeaceSells - screen gildijny.JPG [2012-07-30 12:33:18 | 000,017,179 | ---- | C] () -- C:\Documents and Settings\Dariush\Moje dokumenty\pryszczotelli.jpg [2012-06-03 21:12:44 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\Bez tytułu.png [2012-05-31 20:05:03 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\hmmmm.gif [2012-05-24 19:35:00 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\f388fb5884.jpeg [2012-05-21 21:16:24 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\Frontflipek.wmv [2012-05-20 23:09:29 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\20120520057.mp4 [2012-05-12 21:37:12 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\20120512041.mp4 [2012-05-10 21:51:04 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\533435_323861431018172_100001829543854_739293_15541348_n.jpg [2012-05-08 21:46:56 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\bnthhrt.jpg [2012-05-08 21:43:49 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\gtreyh.jpg [2012-05-08 21:40:02 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\r3r4r3.jpg [2012-05-08 21:37:35 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\254203_153832224687761_100001829543854_298815_3099466_n.jpg [2012-05-06 21:56:45 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\Zdjęcie0839.jpg [2012-04-07 13:48:08 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\DSC00495.jpg [2012-03-05 19:27:53 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\600px-History_of_NATO_enlargement.svg.png [2012-02-22 23:30:01 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\Jaa xd.jpg [2012-01-29 16:54:18 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\ulala.jpg [2012-01-27 15:26:30 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\IMAG0108.jpg [2012-01-26 23:01:38 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\DSC00003.JPG [2012-01-26 22:01:23 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\hmmm.png [2012-01-26 22:00:26 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\hm.png [2012-01-26 21:59:23 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\TakieTam.png [2012-01-26 21:40:35 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\hmm.png [2012-01-25 16:41:06 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\IMAG0100.jpg [2012-01-25 16:40:54 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\IMAG0102.jpg [2012-01-25 16:40:41 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\IMAG0103.jpg [2012-01-25 16:40:29 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\IMAG0104.jpg [2012-01-25 16:40:21 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\IMAG0105.jpg [2012-01-25 16:40:10 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\IMAG0106.jpg [2012-01-21 00:28:07 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI [2012-01-10 16:24:33 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI [2011-12-31 18:25:11 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\V-Unit-V na sylwestra(Pij i tancz)prod.Dj San Antonio.mp3 [2011-12-16 16:32:37 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\Streyker - Zabij Zadzwoń.mp3 [2011-12-15 21:41:15 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\1215_202614.jpg [2011-12-08 17:56:35 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\locale_pl.epk [2011-11-14 17:49:48 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\mrau.mp3 [2011-10-30 23:42:05 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\V-Unit - V dla silowni (Klata plecy barki).mp3 [2011-09-29 13:40:19 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\Ustawienia lokalne\Dane aplikacji\{1B93D310-8987-4378-90EE-56A12ACC8B04} [2011-09-29 13:33:42 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\Ustawienia lokalne\Dane aplikacji\{3F29619C-78E3-4E1B-A049-AA98A0C55751} [2011-08-21 15:41:32 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\0924_142448.jpg [2011-08-14 16:03:09 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\xxx.jpg.jpg [2011-08-08 12:34:53 | 000,000,122 | ---- | C] () -- C:\Documents and Settings\Dariush\default.pls [2011-07-29 20:33:35 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\0729_183759.jpg [2011-07-22 14:04:35 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\IMG020.jpg [2011-07-11 10:43:00 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2011-07-08 13:24:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Irremote.ini [2011-04-04 15:38:02 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini [2011-04-04 15:37:51 | 000,631,808 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2011-04-04 15:37:51 | 000,243,200 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2011-04-04 15:37:51 | 000,080,896 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2011-04-04 15:37:51 | 000,000,590 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest [2011-03-15 18:05:15 | 000,116,224 | ---- | C] () -- C:\Documents and Settings\Dariush\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011-02-24 21:57:48 | 000,019,861 | ---- | C] () -- C:\WINDOWS\HPHins02.dat [2011-02-24 21:57:48 | 000,004,308 | ---- | C] () -- C:\WINDOWS\hphmdl02.dat [2011-02-24 21:41:28 | 000,000,421 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2011-02-21 20:29:40 | 000,252,080 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin [2011-02-21 20:29:37 | 000,252,080 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin [2011-02-21 20:29:37 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin [2011-02-21 20:29:23 | 002,292,678 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin [2011-02-10 13:28:20 | 000,000,016 | ---- | C] () -- C:\WINDOWS\System32\nvModes.dat [2011-02-10 13:27:57 | 000,000,558 | ---- | C] () -- C:\WINDOWS\DFC.INI [2011-02-10 13:22:53 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll [2011-02-10 13:22:08 | 000,928,096 | ---- | C] () -- C:\WINDOWS\System32\nvucode.bin [2011-02-10 01:48:27 | 000,084,512 | ---- | C] () -- C:\Documents and Settings\Dariush\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT [2011-02-10 01:22:41 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat [2011-02-10 00:53:31 | 000,733,696 | ---- | C] () -- C:\WINDOWS\System32\qedwipes.dll [2011-02-10 00:53:31 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2011-02-10 00:53:31 | 000,014,336 | ---- | C] () -- C:\WINDOWS\System32\msdmo.dll [2011-02-10 00:53:30 | 000,070,656 | ---- | C] () -- C:\WINDOWS\System32\amstream.dll [2011-02-10 00:33:40 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe [2011-02-10 00:33:17 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini [2011-02-10 00:33:09 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll [2011-02-10 00:25:38 | 006,395,296 | -H-- | C] () -- C:\Documents and Settings\Dariush\Ustawienia lokalne\Dane aplikacji\IconCache.db [2011-02-09 23:41:58 | 000,000,188 | -HS- | C] () -- C:\Documents and Settings\Dariush\ntuser.ini [2011-02-09 23:41:57 | 006,291,456 | -H-- | C] () -- C:\Documents and Settings\Dariush\NTUSER.DAT [2011-02-09 23:32:01 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2011-02-09 23:30:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\control.ini [2011-02-09 23:29:15 | 000,000,488 | RH-- | C] () -- C:\WINDOWS\System32\logonui.exe.manifest [2011-02-09 23:29:09 | 000,000,749 | RH-- | C] () -- C:\WINDOWS\System32\cdplayer.exe.manifest [2011-02-09 23:27:59 | 000,021,856 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2011-02-09 23:27:56 | 000,000,037 | ---- | C] () -- C:\WINDOWS\vbaddin.ini [2011-02-09 23:27:56 | 000,000,036 | ---- | C] () -- C:\WINDOWS\vb.ini [2011-02-09 23:27:38 | 000,026,717 | ---- | C] () -- C:\WINDOWS\System32\tslabels.ini [2011-02-09 23:27:37 | 000,003,813 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.ini [2011-02-09 23:15:49 | 001,006,574 | ---- | C] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2011-02-09 23:15:49 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2011-02-09 23:15:02 | 000,300,440 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2005-01-13 16:16:22 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\Ustawienia lokalne\Dane aplikacji\{B554C1F0-B740-4681-81D5-B9E5856C1366} [2005-01-13 16:16:22 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\Ustawienia lokalne\Dane aplikacji\{98CC50A2-A8AE-428C-96B1-C17765CE3FD2} [2004-08-25 15:04:10 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\Streyker - Kobiety.mp3 [2004-08-24 16:04:33 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\The Streyk _ NO ARTI - Błędy (Finall DEMO ver 5 ).mp3 [2004-08-24 15:29:32 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Dariush\DEMO ver 4.mp3 [color=#E56717]========== LOP Check ==========[/color] [2010-09-05 10:13:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software [2009-01-08 17:54:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ashampoo [2011-01-21 23:44:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Electronic Arts [2010-01-29 22:35:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10 [2008-08-31 21:34:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Locktime [2008-08-07 11:36:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\MailFrontier [2009-01-09 14:02:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\muvee Technologies [2010-01-14 20:03:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PC Suite [2009-12-24 13:27:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Pinnacle [2010-01-11 15:02:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP [2008-06-30 09:12:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TP-LINK [2011-02-01 13:00:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Ulead Systems [2008-07-26 14:44:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Winferno [2012-07-14 00:07:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Ask [2011-05-28 17:07:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\AVAST Software [2012-03-02 13:30:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Babylon [2012-07-16 16:06:23 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Common Files [2012-01-15 19:15:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\DAEMON Tools Lite [2011-02-10 15:36:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Gadu-Gadu 10 [2011-02-10 18:25:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\ipla [2012-08-13 19:35:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\omtrdyksldwvhpi [2012-07-16 16:07:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\TuneUp Software [2012-08-07 15:03:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\W3i [2012-07-16 16:06:23 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\{32364CEA-7855-4A3C-B674-53D8E9B97936} [2012-03-02 13:30:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\Babylon [2012-03-02 13:33:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\BabylonToolbar [2011-02-10 01:53:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\DAEMON Tools [2012-01-15 19:42:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\DAEMON Tools Lite [2011-02-10 01:59:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\Dealio [2012-07-16 16:04:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\DVDVideoSoft [2011-02-10 17:53:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\Gadu-Gadu [2012-07-05 21:29:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\Gadu-Gadu 10 [2012-02-28 23:24:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\Image-Line [2011-02-10 18:28:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\ipla [2011-04-15 13:44:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\Leawo [2012-07-16 16:04:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\OpenCandy [2012-07-13 23:53:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\Oracle [2011-02-10 18:25:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\RDRM [2011-03-28 14:57:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\Search Settings [2012-05-19 21:17:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\SynthMaker [2012-07-16 16:06:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\TuneUp Software [2011-04-14 22:35:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\WinAVI [2011-05-20 12:12:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\WinMacro [2011-03-28 14:57:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dariush\Dane aplikacji\YouTube Downloader [2011-02-08 18:36:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\GameTracker [2012-08-13 19:43:43 | 000,000,290 | ---- | M] () -- C:\WINDOWS\Tasks\Express Files Updater.job [2012-08-13 21:14:00 | 000,000,238 | ---- | M] () -- C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:671329E4 @Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:DFC5A2B2 < End of report >