OTL logfile created on: 2012-11-20 16:19:45 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = G:\ Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1023,48 Mb Total Physical Memory | 828,20 Mb Available Physical Memory | 80,92% Memory free 2,41 Gb Paging File | 2,33 Gb Available in Paging File | 96,78% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 74,55 Gb Total Space | 17,27 Gb Free Space | 23,16% Space Free | Partition Type: NTFS Drive G: | 1,85 Gb Total Space | 1,85 Gb Free Space | 99,77% Space Free | Partition Type: FAT32 Computer Name: SKOTEK | User Name: Wojtek | Logged in as Administrator. Boot Mode: SafeMode with Networking | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-11-20 15:23:52 | 000,602,112 | ---- | M] (OldTimer Tools) -- G:\OTL.exe PRC - [2008-04-14 18:21:16 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012-01-18 22:24:56 | 000,027,958 | ---- | M] () -- C:\Program Files\Common Files\logonInit.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012-11-08 21:28:08 | 000,711,112 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe -- (vToolbarUpdater13.2.0) SRV - [2012-10-30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Stopped] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2012-10-15 13:57:18 | 001,699,168 | ---- | M] (TuneUp Software) [Auto | Stopped] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc) SRV - [2012-10-04 14:06:46 | 000,188,760 | ---- | M] () [Auto | Stopped] -- C:\Program Files\IB Updater\ExtensionUpdaterService.exe -- (IB Updater) SRV - [2012-10-02 16:20:26 | 001,008,496 | ---- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\dmwu.exe -- (IBUpdaterService) SRV - [2012-08-22 19:03:18 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Stopped] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService) SRV - [2012-05-03 07:31:10 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | Boot | Stopped] -- System32\DRIVERS\viaagp1.sys -- (viaagp1) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2012-11-08 21:28:09 | 000,026,984 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtpx86.sys -- (avgtp) DRV - [2012-10-30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) [File_System | System | Stopped] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2012-10-30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP) DRV - [2012-10-30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2012-10-30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr) DRV - [2012-10-30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Stopped] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2) DRV - [2012-10-30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4) DRV - [2012-10-30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Stopped] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2012-09-19 10:50:50 | 000,010,088 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Stopped] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv) DRV - [2012-05-07 08:11:25 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV - [2012-04-06 18:02:55 | 000,717,296 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd) DRV - [2010-10-16 16:26:02 | 000,128,430 | ---- | M] (R-TT Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\R-Drive Image\R-ImageDisk.sys -- (R-ImageDisk) DRV - [2010-05-31 20:51:14 | 000,102,848 | ---- | M] (R-TT Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\R-Drive Image\DrvSnSht.sys -- (DrvSnSht) DRV - [2009-10-05 18:22:18 | 000,591,360 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8192su.sys -- (RTL8192su) DRV - [2009-05-05 09:58:30 | 000,013,976 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\videX32.sys -- (videX32) DRV - [2008-04-13 19:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx) DRV - [2008-04-13 19:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum) DRV - [2006-08-18 06:52:00 | 004,017,536 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM) DRV - [2004-08-03 21:32:32 | 000,084,480 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ac97via.sys -- (VIAudio) DRV - [2004-08-03 21:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) DRV - [2003-04-21 07:18:00 | 000,052,608 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvatabus.sys -- (nvatabus) DRV - [2003-03-19 08:51:00 | 000,018,688 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nv_agp.SYS -- (nv_agp) DRV - [2002-09-16 17:14:32 | 000,004,228 | ---- | M] (PowerQuest Corporation) [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\PQNTDRV.sys -- (PQNTDrv) DRV - [2001-10-18 12:00:00 | 000,006,144 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\viaidexp.sys -- (ViaIde) DRV - [2001-08-18 00:54:18 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb) DRV - [2001-08-18 00:54:18 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx) DRV - [2001-08-17 21:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=idg&from=idg&uid=58981375_1696_E81E2EA0&ts=1352503477 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si=41460&tid=592&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=41460&tid=592&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si=41460&tid=592&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&home=true&tid=592 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.v9.com/?utm_source=b&utm_medium=idg&from=idg&uid=58981375_1696_E81E2EA0&ts=1352503477 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.v9.com/web/?q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si=41460&tid=592&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=41460&tid=592&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=41460&tid=592&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.v9.com/web/?q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&home=true&tid=592 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?si=41460&home=true&tid=592 IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847} IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.certified-toolbar.com?si=41460&bs=true&tid=592&q={searchTerms} IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.certified-toolbar.com?si=41460&bs=true&tid=592&q={searchTerms} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=idg&from=idg&uid=58981375_1696_E81E2EA0&ts=1352503477 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si=41460&tid=592&bs=true&q= IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=41460&tid=592&bs=true&q= IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si=41460&tid=592&bs=true&q= IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&home=true&tid=592 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredibar.com/mb128?a=6PQQi9UYsQ&i=26 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si=41460&tid=592&bs=true&q= IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=41460&tid=592&bs=true&q= IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=41460&tid=592&bs=true&q= IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&home=true&tid=592 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?si=41460&home=true&tid=592 IE - HKCU\..\URLSearchHook: {113342cd-3031-4ee9-9288-2c58857d3a3d} - C:\Program Files\Xfire_New\prxtbXfir.dll (Conduit Ltd.) IE - HKCU\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - SOFTWARE\Classes\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6}\InprocServer32 File not found IE - HKCU\..\URLSearchHook: {b12785f5-d8d0-4530-a3ea-5c4263b85bef} - C:\Program Files\Hero_Fighter\prxtbHero.dll (Conduit Ltd.) IE - HKCU\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.) IE - HKCU\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86} IE - HKCU\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.v9.com/web/?q={searchTerms} IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = https://isearch.avg.com/search?cid={FB1275D2-C120-4779-A60E-5C3EFD828531}&mid=12cc7e14ca6447d09a9fd1582d251615-06ce4fc639803a2e3563922518183d8e94088cb9&lang=pl&ds=cv011&pr=sa&d=2012-07-23 02:31:54&v=12.1.0.20&sap=dsp&q={searchTerms} IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3248869 IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.certified-toolbar.com?si=41460&bs=true&tid=592&q={searchTerms} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultengine: "Web Search" FF - prefs.js..browser.search.defaultenginename: "MyStart Search" FF - prefs.js..browser.search.defaulturl: "" FF - prefs.js..browser.search.order.1: "Web Search" FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=937811&ilc=12" FF - prefs.js..browser.search.selectedEngine: "MyStart Search" FF - prefs.js..browser.search.useDBForOrder: false FF - prefs.js..browser.startup.homepage: "http://mystart.incredibar.com/mb128?a=6PQQi9UYsQ&i=26" FF - prefs.js..extensions.enabledAddons: ffxtlbr@babylon.com:1.2.0 FF - prefs.js..extensions.enabledAddons: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.16.0.3 FF - prefs.js..extensions.enabledAddons: {890a3e16-521d-4d00-bdf9-e07218d09c8d}:1.5 FF - prefs.js..extensions.enabledAddons: ffxtlbra@softonic.com:1.5.1 FF - prefs.js..extensions.enabledAddons: {7473b6bd-4691-4744-a82b-7854eb3d70b6}:10.13.40.15 FF - prefs.js..keyword.URL: "http://mystart.incredibar.com/mb128/?loc=IB_DS&a=6PQQi9UYsQ&&i=26&search=" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\System32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\13.2.0\\npsitesafety.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.6.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.6.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\avg@toolbar: C:\Documents and Settings\All Users\Dane aplikacji\AVG Secure Search\FireFoxExt\13.2.0.5 [2012-11-08 21:28:16 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\5055898d81109@5055898d81142.com: C:\Documents and Settings\Wojtek\Dane aplikacji\Mozilla\Firefox\Profiles\cftpsngq.default\extensions\5055898d81109@5055898d81142.com [2012-09-16 09:08:31 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-11-20 12:48:38 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\IB Updater\Firefox [2012-11-20 12:55:32 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012-01-26 18:05:47 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\firefox@mozilla.com: C:\Documents and Settings\Wojtek\Dane aplikacji\firefox@mozilla.com [2012-01-17 21:26:21 | 000,000,000 | ---D | M] [2012-01-17 20:37:00 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Wojtek\Dane aplikacji\Mozilla\Extensions [2012-11-20 15:01:52 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Wojtek\Dane aplikacji\Mozilla\Firefox\Profiles\cftpsngq.default\extensions [2012-11-20 12:25:52 | 000,000,000 | ---D | M] (uTorrentControl_v2) -- C:\Documents and Settings\Wojtek\Dane aplikacji\Mozilla\Firefox\Profiles\cftpsngq.default\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6} [2012-11-20 12:10:38 | 000,000,000 | ---D | M] (DownTango Launcher) -- C:\Documents and Settings\Wojtek\Dane aplikacji\Mozilla\Firefox\Profiles\cftpsngq.default\extensions\{890a3e16-521d-4d00-bdf9-e07218d09c8d} [2012-11-20 12:25:52 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Documents and Settings\Wojtek\Dane aplikacji\Mozilla\Firefox\Profiles\cftpsngq.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} [2012-09-16 09:08:31 | 000,000,000 | ---D | M] (Download and Sa) -- C:\Documents and Settings\Wojtek\Dane aplikacji\Mozilla\Firefox\Profiles\cftpsngq.default\extensions\5055898d81109@5055898d81142.com [2012-04-04 17:22:45 | 000,000,000 | ---D | M] (Babylon) -- C:\Documents and Settings\Wojtek\Dane aplikacji\Mozilla\Firefox\Profiles\cftpsngq.default\extensions\ffxtlbr@babylon.com [2012-11-20 12:56:04 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Documents and Settings\Wojtek\Dane aplikacji\Mozilla\Firefox\Profiles\cftpsngq.default\extensions\ffxtlbr@incredibar.com [2012-11-20 12:25:47 | 000,000,000 | ---D | M] (softonic.com) -- C:\Documents and Settings\Wojtek\Dane aplikacji\Mozilla\Firefox\Profiles\cftpsngq.default\extensions\ffxtlbra@softonic.com [2012-03-05 17:25:53 | 000,000,000 | ---D | M] (Bflix) -- C:\Documents and Settings\Wojtek\Dane aplikacji\Mozilla\Firefox\Profiles\cftpsngq.default\extensions\info@thebflix.com [2012-07-31 12:59:18 | 000,221,380 | ---- | M] () (No name found) -- C:\Documents and Settings\Wojtek\Dane aplikacji\Mozilla\Firefox\Profiles\cftpsngq.default\extensions\gophoto@gophoto.it.xpi [2012-11-20 12:54:27 | 000,213,316 | ---- | M] () (No name found) -- C:\Documents and Settings\Wojtek\Dane aplikacji\Mozilla\Firefox\Profiles\cftpsngq.default\extensions\torntv@torntv.com.xpi [2012-11-20 12:55:10 | 000,002,203 | ---- | M] () -- C:\Documents and Settings\Wojtek\Dane aplikacji\Mozilla\Firefox\Profiles\cftpsngq.default\searchplugins\MyStart Search.xml [2012-09-09 17:03:49 | 000,003,997 | ---- | M] () -- C:\Documents and Settings\Wojtek\Dane aplikacji\Mozilla\Firefox\Profiles\cftpsngq.default\searchplugins\sweetim.xml [2012-10-19 16:19:20 | 000,003,267 | ---- | M] () -- C:\Documents and Settings\Wojtek\Dane aplikacji\Mozilla\Firefox\Profiles\cftpsngq.default\searchplugins\Web Search.xml [2011-03-22 19:38:12 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll [2012-10-19 16:19:20 | 000,003,267 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Web Search.xml [color=#E56717]========== Chrome ==========[/color] CHR - homepage: http://home.sweetim.com/?crg=3.1010000.10011&barid={EE995C82-A43E-11E1-B8E5-00116BC1FFE6} CHR - default_search_provider: SweetIM Search (Enabled) CHR - default_search_provider: search_url = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10011&barid={EE995C82-A43E-11E1-B8E5-00116BC1FFE6} CHR - default_search_provider: suggest_url = CHR - homepage: http://home.sweetim.com/?crg=3.1010000.10011&barid={EE995C82-A43E-11E1-B8E5-00116BC1FFE6} CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.64\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.64\pdf.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.64\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\System32\Macromed\Flash\NPSWF32.dll CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U30 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - Extension: YouTube = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\ CHR - Extension: Hero Fighter = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\clnaanfmjbkkkgkoeblihgbmcgekacpc\2.3.15.10_0\ CHR - Extension: Szukaj w Google = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\ CHR - Extension: IB Updater = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.530_0\ CHR - Extension: DownTango Launcher = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ejdabpabkmacjiiooccecnpakonoibah\1.4_0\ CHR - Extension: uTorrentControl_v2 = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\2.3.15.10_0\ CHR - Extension: avast! WebRep = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\ CHR - Extension: Download and Sa = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ioiebjjimdojkhinaaafbmelimjideoa\7.1_0\ CHR - Extension: Torntv = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\jbpkiefagocgkmemidfngdkamloieekf\1.0_0\ CHR - Extension: SweetIM for Facebook = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.1.0.1_0\ CHR - Extension: 1Click Downloader = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\jplinpmadfkdgipabgcdchbdikologlh\1.5_0\ CHR - Extension: AVG Secure Search = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\13.2.0.5_0\ CHR - Extension: AVG Secure Search = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\13.2.0.5_0\.bak CHR - Extension: Yontoo = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0\ CHR - Extension: SweetPacks Chrome Extension = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.0.0.1_0\ CHR - Extension: GoPhoto.it = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk\1.4_0\ CHR - Extension: Gmail = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\ CHR - Extension: YouTube = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\ CHR - Extension: Hero Fighter = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\clnaanfmjbkkkgkoeblihgbmcgekacpc\2.3.15.10_0\ CHR - Extension: Szukaj w Google = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\ CHR - Extension: IB Updater = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.530_0\ CHR - Extension: DownTango Launcher = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ejdabpabkmacjiiooccecnpakonoibah\1.4_0\ CHR - Extension: uTorrentControl_v2 = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\2.3.15.10_0\ CHR - Extension: avast! WebRep = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\ CHR - Extension: Download and Sa = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ioiebjjimdojkhinaaafbmelimjideoa\7.1_0\ CHR - Extension: Torntv = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\jbpkiefagocgkmemidfngdkamloieekf\1.0_0\ CHR - Extension: SweetIM for Facebook = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.1.0.1_0\ CHR - Extension: 1Click Downloader = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\jplinpmadfkdgipabgcdchbdikologlh\1.5_0\ CHR - Extension: AVG Secure Search = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\13.2.0.5_0\ CHR - Extension: AVG Secure Search = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\13.2.0.5_0\.bak CHR - Extension: Yontoo = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0\ CHR - Extension: SweetPacks Chrome Extension = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj\1.0.0.1_0\ CHR - Extension: GoPhoto.it = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk\1.4_0\ CHR - Extension: Gmail = C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\ O1 HOSTS File: ([2001-10-30 13:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Xfire New Toolbar) - {113342cd-3031-4ee9-9288-2c58857d3a3d} - C:\Program Files\Xfire_New\prxtbXfir.dll (Conduit Ltd.) O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) O2 - BHO: (IB Updater) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\IB Updater\Extension32.dll () O2 - BHO: (Incredibar.com Helper Object) - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll (Montera Technologeis LTD) O2 - BHO: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll File not found O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll () O2 - BHO: (Little Fighter 2 Toolbar Helper) - {AE90C38C-97CF-4696-B290-C7973DC9675E} - C:\Program Files\Little Fighter 2 Toolbar\v3.3.0.2\Little_Fighter_2_Toolbar.dll () O2 - BHO: (Hero Fighter Toolbar) - {b12785f5-d8d0-4530-a3ea-5c4263b85bef} - C:\Program Files\Hero_Fighter\prxtbHero.dll (Conduit Ltd.) O2 - BHO: (DownTango Launcher) - {b52d0735-ec19-448a-abde-e01b5bd275d2} - C:\Documents and Settings\Wojtek\Dane aplikacji\DownTangoLauncherToolbar\DownTangoLauncherToolbar.dll (Simplytech Ltd.) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (SweetPacks Browser Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo\YontooIEClient.dll (Yontoo LLC) O3 - HKLM\..\Toolbar: (Xfire New Toolbar) - {113342cd-3031-4ee9-9288-2c58857d3a3d} - C:\Program Files\Xfire_New\prxtbXfir.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll File not found O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll () O3 - HKLM\..\Toolbar: (Hero Fighter Toolbar) - {b12785f5-d8d0-4530-a3ea-5c4263b85bef} - C:\Program Files\Hero_Fighter\prxtbHero.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (DownTango Launcher) - {b52d0735-ec19-448a-abde-e01b5bd275d2} - C:\Documents and Settings\Wojtek\Dane aplikacji\DownTangoLauncherToolbar\DownTangoLauncherToolbar.dll (Simplytech Ltd.) O3 - HKLM\..\Toolbar: (Little Fighter 2 Toolbar) - {C3CD744D-2FAE-4640-8297-16B5DA423104} - C:\Program Files\Little Fighter 2 Toolbar\v3.3.0.2\Little_Fighter_2_Toolbar.dll () O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O3 - HKLM\..\Toolbar: (Incredibar Toolbar) - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll (Montera Technologeis LTD) O3 - HKCU\..\Toolbar\WebBrowser: (Xfire New Toolbar) - {113342CD-3031-4EE9-9288-2C58857D3A3D} - C:\Program Files\Xfire_New\prxtbXfir.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentControl_v2 Toolbar) - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll File not found O3 - HKCU\..\Toolbar\WebBrowser: (Hero Fighter Toolbar) - {B12785F5-D8D0-4530-A3EA-5C4263B85BEF} - C:\Program Files\Hero_Fighter\prxtbHero.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (Little Fighter 2 Toolbar) - {C3CD744D-2FAE-4640-8297-16B5DA423104} - C:\Program Files\Little Fighter 2 Toolbar\v3.3.0.2\Little_Fighter_2_Toolbar.dll () O3 - HKCU\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe () O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\LevelOne Wireless LAN Utility.lnk = C:\Program Files\LevelOne\LevelOne Wireless LAN Utility\RtWLan.exe (Realtek Semiconductor Corp.) O4 - Startup: C:\Documents and Settings\Wojtek\Menu Start\Programy\Autostart\ctfmon.lnk = C:\Documents and Settings\All Users\Dane aplikacji\lsass.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation) O15 - HKCU\..Trusted Domains: ([]msn in Mój komputer) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.100.252 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8421EB9B-1D97-41AA-B6D6-E8787EB09DCC}: DhcpNameServer = 192.168.100.252 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\13.2.0\ViProtocol.dll () O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: GinaDLL - (C:\WINDOWS\SYSTEM32\RtlGina\RtlGina.DLL) - C:\WINDOWS\system32\RtlGina\RtlGina.dll (Realtek) O20 - Winlogon\Notify\LogonInit: DllName - (logonInit.dll) - C:\Program Files\Common Files\logonInit.dll () O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2012-01-17 19:57:59 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-11-20 14:59:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\CCleaner [2012-11-20 14:59:09 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2012-11-20 14:49:01 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC [2012-11-20 14:38:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss [2012-11-20 13:08:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wojtek\Dane aplikacji\Incredibar.com [2012-11-20 12:56:03 | 000,000,000 | ---D | C] -- C:\Program Files\Incredibar.com [2012-11-20 12:55:47 | 000,773,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr100.dll [2012-11-20 12:55:47 | 000,632,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr80.dll [2012-11-20 12:55:47 | 000,554,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp80.dll [2012-11-20 12:55:47 | 000,479,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcm80.dll [2012-11-20 12:55:47 | 000,421,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp100.dll [2012-11-20 12:55:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ARFC [2012-11-20 12:55:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\WNLT [2012-11-20 12:55:29 | 000,000,000 | ---D | C] -- C:\Program Files\IB Updater [2012-11-20 12:54:32 | 000,000,000 | ---D | C] -- C:\Program Files\Gophoto.it [2012-11-20 12:54:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wojtek\Menu Start\Programy\TornTV.com [2012-11-20 12:54:23 | 000,000,000 | ---D | C] -- C:\Program Files\TornTV.com [2012-11-20 12:49:14 | 000,361,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys [2012-11-20 12:49:14 | 000,021,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys [2012-11-20 12:49:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\avast! Free Antivirus [2012-11-20 12:49:08 | 000,035,928 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys [2012-11-20 12:49:07 | 000,738,504 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys [2012-11-20 12:49:07 | 000,054,232 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys [2012-11-20 12:49:06 | 000,097,608 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys [2012-11-20 12:49:06 | 000,089,752 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys [2012-11-20 12:49:05 | 000,025,256 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys [2012-11-20 12:48:28 | 000,041,224 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr [2012-11-20 12:48:26 | 000,227,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe [2012-11-20 12:47:56 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software [2012-11-20 12:47:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\AVAST Software [2012-11-20 12:42:18 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie7 [2012-11-20 12:42:05 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$ [2012-11-20 12:41:36 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$ [2012-11-20 12:34:57 | 000,000,000 | ---D | C] -- C:\583b785b92ab324da0 [2012-11-20 12:34:43 | 014,794,272 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Wojtek\Pulpit\IE7-WindowsXP-x86-plk.exe [2012-11-20 12:12:37 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Dane aplikacji\lsass.exe [2012-11-20 12:05:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Mozilla [2012-11-20 12:04:40 | 018,993,344 | ---- | C] (Mozilla) -- C:\Documents and Settings\Wojtek\Pulpit\Firefox Setup 16.0.2.exe [2012-11-15 00:17:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\SimplyTech [2012-11-10 11:18:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Dane aplikacji\Xfire [2012-11-10 00:52:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Dane aplikacji\TuneUp Software [2012-11-10 00:45:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles [2012-11-10 00:45:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\PunkBuster [2012-11-10 00:10:08 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Wojtek\UserData [2012-11-10 00:10:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Dane aplikacji\Xfire [2012-11-10 00:09:38 | 000,031,584 | ---- | C] (TuneUp Software) -- C:\WINDOWS\System32\TURegOpt.exe [2012-11-10 00:09:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\TuneUp Utilities 2013 [2012-11-10 00:09:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wojtek\Dane aplikacji\TuneUp Software [2012-11-10 00:09:04 | 000,000,000 | ---D | C] -- C:\Program Files\TuneUp Utilities 2013 [2012-11-10 00:09:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\TuneUp Software [2012-11-10 00:08:40 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Dane aplikacji\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} [2012-11-10 00:07:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wojtek\Dane aplikacji\Xfire [2012-11-10 00:07:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Xfire [2012-11-10 00:07:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wojtek\Ustawienia lokalne\Dane aplikacji\Xfire_New [2012-11-10 00:07:30 | 000,000,000 | ---D | C] -- C:\Program Files\Xfire [2012-11-10 00:07:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wojtek\Dane aplikacji\OpenCandy [2012-11-10 00:07:28 | 000,000,000 | ---D | C] -- C:\Program Files\Xfire_New [2012-11-08 21:28:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\cache [2012-10-27 15:35:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wojtek\Pulpit\Nowy folder [9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [8 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ] [14 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-11-20 16:22:47 | 000,435,310 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2012-11-20 16:22:47 | 000,393,554 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2012-11-20 16:22:47 | 000,085,590 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2012-11-20 16:22:47 | 000,068,834 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2012-11-20 16:18:29 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012-11-20 16:17:20 | 095,023,320 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\dsgsdgdsgdsgw.pad [2012-11-20 16:17:06 | 000,000,316 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2012-11-20 16:16:41 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml [2012-11-20 16:16:37 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2012-11-20 16:16:35 | 000,000,528 | -H-- | M] () -- C:\WINDOWS\tasks\OptimizerPro1UpdaterTask{6FDF0913-39DD-413A-BFBE-F163BC56C9C1}.job [2012-11-20 16:16:35 | 000,000,332 | ---- | M] () -- C:\WINDOWS\tasks\Protected Search.job [2012-11-20 14:59:32 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat [2012-11-20 14:59:10 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\CCleaner.lnk [2012-11-20 14:39:05 | 000,000,211 | -HS- | M] () -- C:\boot.ini [2012-11-20 13:33:00 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2012-11-20 12:56:08 | 000,000,447 | ---- | M] () -- C:\user.js [2012-11-20 12:54:25 | 000,000,686 | ---- | M] () -- C:\Documents and Settings\Wojtek\Pulpit\TornTV.lnk [2012-11-20 12:53:34 | 000,244,432 | ---- | M] () -- C:\Documents and Settings\Wojtek\Pulpit\TEKSA_SKA_MASAKRA_PI_MECHANICZN_2003_HORROR_LEKTOR_PL_DVDRIP_XVID_AXK_.exe [2012-11-20 12:49:15 | 000,001,689 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\avast! Free Antivirus.lnk [2012-11-20 12:49:06 | 000,002,644 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT [2012-11-20 12:41:44 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2012-11-20 12:34:48 | 014,794,272 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Wojtek\Pulpit\IE7-WindowsXP-x86-plk.exe [2012-11-20 12:12:40 | 000,001,054 | ---- | M] () -- C:\Documents and Settings\Wojtek\Menu Start\Programy\Autostart\ctfmon.lnk [2012-11-20 12:12:37 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Dane aplikacji\lsass.exe [2012-11-20 12:04:52 | 018,993,344 | ---- | M] (Mozilla) -- C:\Documents and Settings\Wojtek\Pulpit\Firefox Setup 16.0.2.exe [2012-11-20 10:03:21 | 000,137,464 | ---- | M] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys [2012-11-20 10:02:45 | 000,214,520 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.xtr [2012-11-19 11:11:09 | 000,002,228 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012-11-10 00:33:15 | 000,735,889 | ---- | M] () -- C:\Documents and Settings\Wojtek\Pulpit\pbsetup(Pobierz.pl).zip [2012-11-10 00:25:26 | 039,195,984 | ---- | M] () -- C:\Documents and Settings\Wojtek\Pulpit\CallofDuty2Patchv1_3.zip [2012-11-10 00:09:37 | 000,001,747 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\TuneUp Utilities 2013.lnk [2012-11-10 00:07:37 | 000,000,009 | ---- | M] () -- C:\end [2012-11-10 00:07:36 | 000,000,650 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Xfire.lnk [2012-11-10 00:07:06 | 009,670,480 | ---- | M] () -- C:\Documents and Settings\Wojtek\Pulpit\xfire_installer_45862.exe [2012-11-09 08:44:29 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk [2012-11-08 21:28:09 | 000,026,984 | ---- | M] (AVG Technologies) -- C:\WINDOWS\System32\drivers\avgtpx86.sys [2012-10-30 23:51:58 | 000,738,504 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys [2012-10-30 23:51:58 | 000,361,032 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys [2012-10-30 23:51:58 | 000,054,232 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys [2012-10-30 23:51:58 | 000,035,928 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys [2012-10-30 23:51:57 | 000,097,608 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys [2012-10-30 23:51:57 | 000,089,752 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys [2012-10-30 23:51:56 | 000,025,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys [2012-10-30 23:51:56 | 000,021,256 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys [2012-10-30 23:51:07 | 000,041,224 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr [2012-10-30 23:50:59 | 000,227,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe [2012-10-27 15:10:20 | 874,181,411 | ---- | M] () -- C:\Documents and Settings\Wojtek\Pulpit\Metin5_Client_S1_2012.05_sierpien.rar [2012-10-27 10:12:28 | 000,042,440 | ---- | M] () -- C:\WINDOWS\System32\xfcodec.dll [9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [8 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ] [14 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-11-20 14:59:10 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\CCleaner.lnk [2012-11-20 13:00:52 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2012-11-20 12:56:04 | 000,000,447 | ---- | C] () -- C:\user.js [2012-11-20 12:55:47 | 001,008,496 | ---- | C] () -- C:\WINDOWS\System32\dmwu.exe [2012-11-20 12:55:47 | 000,028,160 | ---- | C] () -- C:\WINDOWS\System32\ImHttpComm.dll [2012-11-20 12:54:25 | 000,000,686 | ---- | C] () -- C:\Documents and Settings\Wojtek\Pulpit\TornTV.lnk [2012-11-20 12:53:32 | 000,244,432 | ---- | C] () -- C:\Documents and Settings\Wojtek\Pulpit\TEKSA_SKA_MASAKRA_PI_MECHANICZN_2003_HORROR_LEKTOR_PL_DVDRIP_XVID_AXK_.exe [2012-11-20 12:49:15 | 000,001,689 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\avast! Free Antivirus.lnk [2012-11-20 12:49:06 | 000,000,316 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2012-11-20 12:12:40 | 000,001,054 | ---- | C] () -- C:\Documents and Settings\Wojtek\Menu Start\Programy\Autostart\ctfmon.lnk [2012-11-20 12:12:38 | 095,023,320 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\dsgsdgdsgdsgw.pad [2012-11-10 00:46:07 | 000,137,464 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys [2012-11-10 00:46:00 | 000,214,520 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe [2012-11-10 00:45:57 | 000,214,520 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.xtr [2012-11-10 00:45:52 | 000,075,064 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe [2012-11-10 00:33:15 | 000,735,889 | ---- | C] () -- C:\Documents and Settings\Wojtek\Pulpit\pbsetup(Pobierz.pl).zip [2012-11-10 00:24:43 | 039,195,984 | ---- | C] () -- C:\Documents and Settings\Wojtek\Pulpit\CallofDuty2Patchv1_3.zip [2012-11-10 00:09:37 | 000,001,753 | ---- | C] () -- C:\Documents and Settings\All Users\Menu Start\Programy\TuneUp Utilities 2013.lnk [2012-11-10 00:09:37 | 000,001,747 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\TuneUp Utilities 2013.lnk [2012-11-10 00:07:36 | 000,000,650 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Xfire.lnk [2012-11-10 00:06:50 | 009,670,480 | ---- | C] () -- C:\Documents and Settings\Wojtek\Pulpit\xfire_installer_45862.exe [2012-10-27 14:23:41 | 874,181,411 | ---- | C] () -- C:\Documents and Settings\Wojtek\Pulpit\Metin5_Client_S1_2012.05_sierpien.rar [2012-10-27 10:12:28 | 000,042,440 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll [2012-10-19 16:19:09 | 000,015,432 | ---- | C] () -- C:\WINDOWS\Launcher.exe [2012-08-07 12:43:48 | 000,558,133 | ---- | C] () -- C:\WINDOWS\System32\sqlite3.dll [2012-05-26 18:34:18 | 000,000,287 | ---- | C] () -- C:\WINDOWS\game.ini [2012-05-07 22:13:43 | 000,000,059 | ---- | C] () -- C:\Documents and Settings\Wojtek\Dane aplikacji\bynacam_config.ini [2012-05-03 10:32:31 | 000,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini [2012-04-30 08:54:56 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe [2012-04-30 08:54:31 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini [2012-04-30 08:54:07 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll [2012-04-30 08:50:47 | 000,032,768 | R--- | C] () -- C:\WINDOWS\System32\idecoi.dll [2012-03-05 19:59:03 | 000,529,408 | ---- | C] () -- C:\Documents and Settings\Wojtek\Dane aplikacji\bnjup.exe [2012-01-18 23:01:23 | 000,000,005 | ---- | C] () -- C:\Program Files\Common Files\userInit.dll [2012-01-18 22:24:56 | 000,027,958 | ---- | C] () -- C:\Program Files\Common Files\logonInit.dll [2012-01-18 21:19:43 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat [2012-01-17 21:26:16 | 000,589,824 | ---- | C] () -- C:\Documents and Settings\Wojtek\Dane aplikacji\_tk.old [2012-01-17 20:06:19 | 000,451,072 | ---- | C] () -- C:\WINDOWS\System32\ISSRemoveSP.exe [2012-01-17 20:01:15 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2012-01-17 19:53:39 | 000,023,624 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2012-01-17 19:52:03 | 000,167,424 | ---- | C] () -- C:\WINDOWS\System32\comsnap.dll [2012-01-17 19:45:45 | 000,004,473 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2012-01-17 19:43:58 | 000,099,048 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [color=#E56717]========== ZeroAccess Check ==========[/color] [2012-01-18 23:13:12 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2010-04-16 17:09:01 | 001,509,888 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009-02-09 11:53:44 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008-04-14 18:20:57 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both < End of report >