OTL logfile created on: 2012-12-27 15:39:53 - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Artur\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,00 Gb Total Physical Memory | 1,84 Gb Available Physical Memory | 61,27% Memory free 6,00 Gb Paging File | 4,74 Gb Available in Paging File | 79,11% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 450,66 Gb Total Space | 366,86 Gb Free Space | 81,40% Space Free | Partition Type: NTFS Drive E: | 969,96 Mb Total Space | 969,95 Mb Free Space | 100,00% Space Free | Partition Type: FAT32 Drive F: | 3,72 Gb Total Space | 3,72 Gb Free Space | 100,00% Space Free | Partition Type: FAT32 Drive G: | 1,95 Gb Total Space | 1,95 Gb Free Space | 100,00% Space Free | Partition Type: FAT Drive I: | 1,86 Gb Total Space | 1,86 Gb Free Space | 100,00% Space Free | Partition Type: FAT Drive L: | 3,73 Gb Total Space | 1,72 Gb Free Space | 46,25% Space Free | Partition Type: FAT32 Drive S: | 298,09 Gb Total Space | 297,61 Gb Free Space | 99,84% Space Free | Partition Type: NTFS Drive W: | 3,73 Gb Total Space | 3,14 Gb Free Space | 84,00% Space Free | Partition Type: FAT32 Computer Name: ARTUR-KOMPUTER | User Name: Artur | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012-12-26 19:04:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Artur\Desktop\OTL.exe PRC - [2012-12-14 10:17:04 | 003,467,768 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe PRC - [2012-11-05 11:57:12 | 003,055,976 | ---- | M] () -- C:\Users\Artur\AppData\Local\tuto4pc_pl_1\supt4pc_pl_1.exe PRC - [2012-09-05 16:57:26 | 000,271,808 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe PRC - [2011-10-03 06:59:16 | 000,075,064 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe PRC - [2011-01-20 10:20:12 | 001,305,408 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe PRC - [2010-10-27 18:17:52 | 000,207,424 | ---- | M] (ArcSoft Inc.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe PRC - [2010-08-25 11:27:44 | 000,309,824 | ---- | M] (ArcSoft Inc.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac PRC - [2010-05-07 12:39:36 | 000,344,736 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe PRC - [2010-03-18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe PRC - [2010-01-29 00:27:36 | 000,243,232 | ---- | M] (Acer Group) -- C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe PRC - [2009-08-28 10:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe PRC - [2007-05-29 18:41:34 | 000,910,896 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe PRC - [2007-05-29 18:41:16 | 000,149,040 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe PRC - [2007-05-24 16:38:10 | 001,226,288 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe PRC - [2006-11-03 11:01:16 | 000,319,488 | ---- | M] (PixArt Imaging Incorporation) -- C:\Windows\PixArt\Pac207\Monitor.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2010-09-22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) SRV:[b]64bit:[/b] - [2010-01-29 00:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Running] -- C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe -- (Updater Service) SRV:[b]64bit:[/b] - [2010-01-13 15:04:08 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:[b]64bit:[/b] - [2009-07-14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2012-12-14 10:17:04 | 003,467,768 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8) SRV - [2012-11-29 09:26:17 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012-11-05 11:57:12 | 003,055,976 | ---- | M] () [Auto | Running] -- C:\Users\Artur\AppData\Local\tuto4pc_pl_1\supt4pc_pl_1.exe -- (supt4pc_pl_1) SRV - [2012-09-05 16:56:44 | 000,234,776 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe -- (McComponentHostService) SRV - [2011-10-03 06:59:16 | 000,075,064 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA) SRV - [2010-05-07 12:39:36 | 000,344,736 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe -- (AVP) SRV - [2010-03-18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010-03-18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon) SRV - [2010-01-15 22:08:38 | 000,935,208 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0) SRV - [2009-10-10 03:59:08 | 000,238,328 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\eMachines Games\eMachines Game Console\GameConsoleService.exe -- (GameConsoleService) SRV - [2009-08-28 10:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe -- (Greg_Service) SRV - [2009-06-10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2007-05-31 17:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm) SRV - [2007-05-31 17:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2012-09-11 13:11:53 | 000,164,864 | ---- | M] (ITE ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IT9135BDA.sys -- (IT9135BDA) DRV:[b]64bit:[/b] - [2012-03-08 17:40:52 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr) DRV:[b]64bit:[/b] - [2012-03-01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2011-08-15 13:30:17 | 000,254,528 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:[b]64bit:[/b] - [2011-03-11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2011-03-11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2010-11-20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2010-11-20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2010-05-07 12:28:02 | 000,560,216 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\Windows\SysNative\drivers\klif.sys -- (KLIF) DRV:[b]64bit:[/b] - [2010-05-07 00:19:14 | 000,460,888 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\kl2.sys -- (kl2) DRV:[b]64bit:[/b] - [2010-05-07 00:19:10 | 000,460,888 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\kl1.sys -- (KL1) DRV:[b]64bit:[/b] - [2010-04-22 19:07:36 | 000,027,736 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\klim6.sys -- (KLIM6) DRV:[b]64bit:[/b] - [2010-01-13 15:26:00 | 006,327,296 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag) DRV:[b]64bit:[/b] - [2010-01-13 15:26:00 | 006,327,296 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atipmdag.sys -- (amdkmdag) DRV:[b]64bit:[/b] - [2010-01-13 14:10:56 | 000,185,344 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:[b]64bit:[/b] - [2010-01-05 19:23:18 | 001,847,296 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athurx.sys -- (athur) DRV:[b]64bit:[/b] - [2009-11-05 15:15:40 | 000,291,328 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:[b]64bit:[/b] - [2009-11-02 20:27:10 | 000,022,544 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\klmouflt.sys -- (klmouflt) DRV:[b]64bit:[/b] - [2009-09-30 02:34:30 | 000,121,872 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService) DRV:[b]64bit:[/b] - [2009-08-13 07:38:24 | 000,029,184 | ---- | M] (CSR, plc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcp.sys -- (BthAvrcp) DRV:[b]64bit:[/b] - [2009-07-14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009-07-14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009-07-14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009-06-11 06:34:38 | 001,208,320 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem) DRV:[b]64bit:[/b] - [2009-06-10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009-06-10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009-06-10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009-06-10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:[b]64bit:[/b] - [2008-04-18 09:43:42 | 000,033,200 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Mac606.sys -- (Mac606) DRV:[b]64bit:[/b] - [2008-04-18 09:43:32 | 000,022,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HidNt.sys -- (HidNt) DRV:[b]64bit:[/b] - [2006-12-05 11:34:26 | 000,572,416 | ---- | M] (PixArt Imaging Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\PFC027.SYS -- (PAC207) DRV - [2009-07-14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) DRV - [2008-04-18 09:44:04 | 000,026,672 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\Mac606.sys -- (Mac606) DRV - [2008-04-18 09:43:54 | 000,018,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\HidNt.sys -- (HidNt) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=ACEW&l=0415&m=et1850&r=17361210t005pe436v1h5r48j1s88s IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=ACEW&l=0415&m=et1850&r=17361210t005pe436v1h5r48j1s88s IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACEW IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-3073149576-858336434-2965840880-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=ACEW&l=0415&m=et1850&r=17361210t005pe436v1h5r48j1s88s IE - HKU\S-1-5-21-3073149576-858336434-2965840880-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com IE - HKU\S-1-5-21-3073149576-858336434-2965840880-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com IE - HKU\S-1-5-21-3073149576-858336434-2965840880-1001\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-3073149576-858336434-2965840880-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-3073149576-858336434-2965840880-1001\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACEW_plPL412 IE - HKU\S-1-5-21-3073149576-858336434-2965840880-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKU\S-1-5-21-3073149576-858336434-2965840880-1001\..\SearchScopes\{A57E58B6-A76B-49EE-A864-AB72755F28C5}: "URL" = http://mp3rocketsearch.com/?tmp=toolbar_Mp3Rocket_results&prt=mp3rockettb04ie&keywords={searchTerms} IE - HKU\S-1-5-21-3073149576-858336434-2965840880-1001\..\SearchScopes\{C6AC87A7-4AF1-42AB-B38D-2924D149341E}: "URL" = http://search.softonic.com/MON00085/tb_v1?q={searchTerms}&SearchSource=4&cc= IE - HKU\S-1-5-21-3073149576-858336434-2965840880-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..extensions.enabledAddons: %7Bb64982b1-d112-42b5-b1e4-d3867c4533f8%7D:2.3.796.11 FF - prefs.js..extensions.enabledAddons: %7B288479BE-1B9E-11E2-80EA-F3246188709B%7D:1.1 FF - prefs.js..extensions.enabledAddons: manishjain9%40hotmail.com_easiestyoutube:3.6 FF - prefs.js..extensions.enabledAddons: collector%40broceliand.fr:6.0.11 FF - prefs.js..extensions.enabledAddons: %7BF8A55C97-3DB6-4961-A81D-0DE0080E53CB%7D:0.9.5 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1 FF - user.js - File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Artur\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012-12-15 15:01:04 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\THBExt [2011-03-19 19:09:42 | 000,000,000 | ---D | M] [2012-12-15 15:01:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Artur\AppData\Roaming\mozilla\Extensions [2012-12-25 16:36:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Artur\AppData\Roaming\mozilla\Firefox\Profiles\lpojadgr.default\extensions [2012-12-15 17:54:59 | 000,000,000 | ---D | M] ("pearltrees") -- C:\Users\Artur\AppData\Roaming\mozilla\Firefox\Profiles\lpojadgr.default\extensions\collector@broceliand.fr [2012-12-15 16:29:46 | 000,029,026 | ---- | M] () (No name found) -- C:\Users\Artur\AppData\Roaming\mozilla\firefox\profiles\lpojadgr.default\extensions\manishjain9@hotmail.com_easiestyoutube.xpi [2012-12-15 16:27:32 | 000,002,716 | ---- | M] () (No name found) -- C:\Users\Artur\AppData\Roaming\mozilla\firefox\profiles\lpojadgr.default\extensions\{288479BE-1B9E-11E2-80EA-F3246188709B}.xpi [2012-12-25 16:36:03 | 000,804,627 | ---- | M] () (No name found) -- C:\Users\Artur\AppData\Roaming\mozilla\firefox\profiles\lpojadgr.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-12-15 17:56:21 | 000,105,386 | ---- | M] () (No name found) -- C:\Users\Artur\AppData\Roaming\mozilla\firefox\profiles\lpojadgr.default\extensions\{F8A55C97-3DB6-4961-A81D-0DE0080E53CB}.xpi [2012-11-15 11:54:58 | 000,007,027 | ---- | M] () (No name found) -- C:\Users\Artur\AppData\Roaming\mozilla\firefox\profiles\lpojadgr.default\extensions\collector@broceliand.fr\chrome\skin\images\info\premiumExpired.png [2012-11-21 19:23:16 | 000,000,269 | ---- | M] () (No name found) -- C:\Users\Artur\AppData\Roaming\mozilla\firefox\profiles\lpojadgr.default\extensions\collector@broceliand.fr\chrome\skin\images\new\padlockExpired.png [2012-12-15 19:57:03 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2012-12-15 19:57:04 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\Program Files (x86)\mozilla firefox\extensions\linkfilter@kaspersky.ru File not found (No name found) -- C:\PROGRAMDATA\BROWSER MANAGER\2.3.796.11\{16CDFF19-861D-48E3-A751-D99A27784753}\FIREFOXEXTENSION [2012-11-29 09:26:57 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2012-11-29 11:00:09 | 000,002,767 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\allegro-pl.xml [2012-11-29 11:00:09 | 000,001,406 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fbc-pl.xml [2011-05-05 19:24:51 | 000,002,048 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrchostpl.xml [2012-11-29 11:00:09 | 000,000,917 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\merlin-pl.xml [2012-11-29 11:00:09 | 000,000,858 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\pwn-pl.xml [2012-11-29 11:00:09 | 000,001,183 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-pl.xml [2012-11-29 11:00:09 | 000,001,683 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wp-pl.xml O1 HOSTS File: ([2009-06-10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:[b]64bit:[/b] - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\ievkbd.dll (Kaspersky Lab ZAO) O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2:[b]64bit:[/b] - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O2:[b]64bit:[/b] - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg64.dll (Google Inc.) O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2:[b]64bit:[/b] - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO) O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll (Kaspersky Lab ZAO) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll (Google Inc.) O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO) O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Users\Artur\AppData\Roaming\Nowe Gadu-Gadu\_userdata\ggbho.1.dll File not found O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Astroburn Toolbar) - {EFEED92A-A33D-4873-BA8F-32BAA631E54D} - C:\Program Files (x86)\Astroburn Toolbar\ABToolbar64.dll File not found O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3:[b]64bit:[/b] - HKU\S-1-5-21-3073149576-858336434-2965840880-1001\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O4:[b]64bit:[/b] - HKLM..\Run: [Monitor] C:\Windows\PixArt\Pac207\Monitor.exe (PixArt Imaging Incorporation) O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4:[b]64bit:[/b] - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation) O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.) O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe (Kaspersky Lab ZAO) O4 - HKLM..\Run: [NBKeyScan] C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe (Nero AG) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-3073149576-858336434-2965840880-1001..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG) O4 - HKU\S-1-5-21-3073149576-858336434-2965840880-1001..\Run: [ChomikBox] C:\Program Files (x86)\ChomikBox\chomikbox.exe File not found O4 - HKU\S-1-5-21-3073149576-858336434-2965840880-1001..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd) O4 - HKU\S-1-5-21-3073149576-858336434-2965840880-1001..\Run: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent File not found O4 - HKU\S-1-5-21-3073149576-858336434-2965840880-1001..\Run: [Gadu-Gadu 10] C:\Program Files (x86)\Gadu-Gadu 10\gg.exe (GG Network S.A.) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - Startup: C:\Users\Artur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PC Clone EX.LNK = File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 60 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8:[b]64bit:[/b] - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found O8:[b]64bit:[/b] - Extra context menu item: Funkcja Google Sidewiki - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html File not found O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Funkcja Google Sidewiki - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html File not found O9:[b]64bit:[/b] - Extra Button: &Klawiatura wirtualna - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO) O9:[b]64bit:[/b] - Extra Button: &Sprawdzanie adresów internetowych - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO) O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation) O9 - Extra Button: &Klawiatura wirtualna - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: &Sprawdzanie adresów internetowych - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO) O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Java Plug-in 1.6.0_01) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5B2DC131-2B17-4864-921A-D1FC3032D408}: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A1704D19-241F-49BD-830F-3F1E855F18C9}: DhcpNameServer = 192.168.1.254 O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20:[b]64bit:[/b] - Winlogon\Notify\klogon: DllName - (%SystemRoot%\System32\klogon.dll) - C:\Windows\SysNative\klogon.dll (Kaspersky Lab ZAO) O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 0 O32 - AutoRun File - [2012-06-17 01:37:52 | 007,752,097 | ---- | M] () - L:\Autoerotique - WTF (Original Mix) [www.Club-Mp3.pl].mp3 -- [ FAT32 ] O33 - MountPoints2\{60785ce1-c72b-11e0-8de6-1078d27b53e4}\Shell - "" = AutoRun O33 - MountPoints2\{60785ce1-c72b-11e0-8de6-1078d27b53e4}\Shell\AutoRun\command - "" = J:\Autorun.exe O33 - MountPoints2\{d2529e45-6386-11e0-943e-1078d27b53e4}\Shell - "" = AutoRun O33 - MountPoints2\{d2529e45-6386-11e0-943e-1078d27b53e4}\Shell\AutoRun\command - "" = J:\USBAutoRun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012-12-27 13:10:04 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{A2294B8F-1DCA-4F16-9568-719FDE543444} [2012-12-27 10:31:16 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{FD560339-3F00-47BF-A732-85C34E4001F2} [2012-12-26 19:04:11 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Artur\Desktop\OTL.exe [2012-12-26 11:31:46 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{0EADF3EE-C11D-4C60-9B7F-34E837E45161} [2012-12-25 16:23:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TeamViewer [2012-12-25 11:29:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorrent [2012-12-25 11:28:50 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Roaming\uTorrent [2012-12-25 09:14:33 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{D689627E-D58A-49ED-BBCE-6E1672984C4A} [2012-12-24 09:27:22 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{BB147419-F414-490D-AB35-518E37C222D2} [2012-12-23 14:18:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlazeHDTV 6.0 [2012-12-23 11:24:24 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{CE097122-DBBF-4BE6-94CC-C1621EF54BF0} [2012-12-22 13:20:31 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{538741F5-963E-4A0D-8132-BD44884ECD5D} [2012-12-21 19:14:41 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{9988BBC8-12EB-4CD5-9B8C-A71102612098} [2012-12-21 19:10:49 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll [2012-12-21 19:10:49 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll [2012-12-21 19:10:48 | 000,367,616 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll [2012-12-21 19:10:48 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll [2012-12-21 19:01:16 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{8292D929-F47B-4D71-9A33-32EDAD7E7FD3} [2012-12-20 15:18:35 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{36D55F39-90C2-4EC2-A284-2862AA43B27B} [2012-12-19 15:56:09 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\Midway [2012-12-19 15:53:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Midway Home Entertainment [2012-12-19 15:29:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Midway Home Entertainment [2012-12-19 15:24:51 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{A4B90434-2649-4797-87B2-80E439796C47} [2012-12-19 14:51:03 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{5D1915F9-7DED-49FB-9907-ED6C809D4AD4} [2012-12-18 14:34:38 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{4FFC8085-32C6-406E-8BEE-E271A8B17BD6} [2012-12-17 14:33:37 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{DD447A65-2C57-47E0-BF2A-6694D1EF92D2} [2012-12-16 16:00:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\THQ [2012-12-16 15:27:51 | 000,000,000 | ---D | C] -- C:\Users\Artur\Documents\Eidos [2012-12-16 15:26:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Eidos [2012-12-16 15:15:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Eidos [2012-12-16 13:54:24 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{9E0E860F-7ACA-4E54-B44F-540C6C6F7C3B} [2012-12-16 10:11:56 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{185E3604-BA84-468A-AE83-F3CE05E45A8C} [2012-12-15 19:57:14 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{751E73E7-F86B-463B-A157-FEADCA9D2FB1} [2012-12-15 16:48:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus [2012-12-15 16:23:20 | 000,916,456 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\deployJava1.dll [2012-12-15 16:23:19 | 001,034,216 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\npDeployJava1.dll [2012-12-15 16:23:19 | 000,289,768 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\javaws.exe [2012-12-15 16:23:01 | 000,189,416 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\javaw.exe [2012-12-15 16:23:01 | 000,188,904 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\java.exe [2012-12-15 16:23:01 | 000,108,008 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\WindowsAccessBridge-64.dll [2012-12-15 16:22:46 | 000,000,000 | ---D | C] -- C:\Program Files\Java [2012-12-15 16:21:31 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\Macromedia [2012-12-15 16:21:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight [2012-12-15 16:21:05 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight [2012-12-15 16:21:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight [2012-12-15 16:18:56 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee Security Scan [2012-12-15 16:18:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\McAfee Security Scan [2012-12-15 15:01:19 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Roaming\Mozilla [2012-12-15 15:01:19 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\Mozilla [2012-12-15 15:01:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla [2012-12-15 15:01:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service [2012-12-15 14:56:17 | 000,697,272 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2012-12-15 14:56:17 | 000,073,656 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2012-12-15 14:56:14 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed [2012-12-15 12:09:51 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{152831EC-EED0-40E9-85C1-996AABF90BB0} [2012-12-15 12:01:05 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{1883F501-E97A-4B99-B237-238301B55BCE} [2012-12-15 10:01:23 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{F1F68029-56CE-456A-9857-2106BAAA29D7} [2012-12-14 12:12:12 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{8D8F9B41-EC65-4168-9C53-15FD14898536} [2012-12-14 10:38:27 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{FBD4377A-C956-459A-BE9A-6D5891558CC6} [2012-12-13 09:06:46 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{0A1AFFEA-2A9C-4A17-ADD5-CBC82E2BF703} [2012-12-12 08:29:00 | 000,735,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll [2012-12-12 08:28:59 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2012-12-12 08:28:59 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2012-12-12 08:28:59 | 000,097,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll [2012-12-12 08:28:59 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll [2012-12-12 08:28:58 | 000,134,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll [2012-12-12 08:28:58 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll [2012-12-12 08:28:48 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll [2012-12-12 08:28:48 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll [2012-12-12 08:28:48 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe [2012-12-12 08:28:48 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll [2012-12-12 08:28:47 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll [2012-12-12 08:28:47 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll [2012-12-12 08:28:47 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe [2012-12-12 08:28:47 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll [2012-12-12 08:28:47 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll [2012-12-12 08:28:47 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll [2012-12-12 08:28:47 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll [2012-12-12 08:28:46 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe [2012-12-12 08:28:46 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll [2012-12-12 08:28:46 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll [2012-12-12 08:28:46 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll [2012-12-12 08:28:46 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll [2012-12-12 08:28:46 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll [2012-12-12 08:28:46 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll [2012-12-12 08:28:46 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll [2012-12-12 08:28:46 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll [2012-12-12 08:28:46 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll [2012-12-12 08:28:46 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll [2012-12-12 08:28:46 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll [2012-12-12 08:28:46 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll [2012-12-12 08:28:46 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll [2012-12-12 08:28:46 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll [2012-12-12 08:28:46 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll [2012-12-12 08:28:46 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll [2012-12-12 08:28:46 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll [2012-12-12 08:28:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll [2012-12-12 08:28:45 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe [2012-12-12 08:28:33 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dpnet.dll [2012-12-12 08:28:33 | 000,376,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dpnet.dll [2012-12-12 08:18:13 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{4D9F409B-0934-484C-8EBD-FC650D2B88BB} [2012-12-11 08:56:32 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{04795C13-E77D-40D1-BCB4-4FE0B6870668} [2012-12-10 12:32:39 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{C391482A-7ADA-4FF1-AEA5-D21EA76AB12C} [2012-12-10 09:22:50 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{621C0954-2C68-40E7-B1D8-7E83CE1D2635} [2012-12-10 08:40:10 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{751C3A3A-AFFA-43B4-BA93-DEB2429D0985} [2012-12-09 18:44:21 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{8FE76696-EFA1-4572-8202-A98905D49B0A} [2012-12-09 12:11:30 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{71E5425A-7910-4650-A83E-E7106281FA7A} [2012-12-09 11:19:15 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{E211D4F6-48FD-479A-A1E6-DA13453E3F5F} [2012-12-08 18:54:17 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{0E391359-A7C8-4097-94AF-0D57A5E52484} [2012-12-08 12:46:12 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{41841DB2-949B-4034-857B-900D8DF39CF5} [2012-12-08 10:02:10 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{42127C72-8B4F-458D-9286-8C162897C89D} [2012-12-08 09:18:35 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{C05BDF81-F842-4754-B586-5FDFC2A18D4E} [2012-12-07 18:08:20 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{5F55A682-CDE0-44D7-B6A5-DEA83B889E95} [2012-12-07 15:24:19 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{DEAA50F6-2387-489E-8DD8-F85DBE2FB333} [2012-12-07 14:42:44 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{7FC37D3E-913B-432C-9959-37ACD7ECBD66} [2012-12-06 14:36:37 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{1243A6AC-4015-404B-8346-A7E328314C9A} [2012-12-04 14:40:32 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{1460425A-8B75-48CC-B1E3-4AC15BC8E7FB} [2012-12-03 18:35:19 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{88CE8FCA-8EF0-45AB-8282-6237ED2E0D70} [2012-12-03 14:39:29 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{B81CC6BE-F837-4C1B-93D9-3B6CF0853181} [2012-12-02 11:17:52 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{D69737AE-34EA-41FC-A41E-C2E3101D8B53} [2012-12-01 08:26:30 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{34633FE1-9D6C-4D9E-AC55-A110BF2C0662} [2012-11-30 10:38:18 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{5B6812C4-24CF-468C-8115-D774E8460D89} [2012-11-29 11:58:34 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{22A366D6-5222-4885-B9E1-030B09267BC4} [2012-11-29 10:08:55 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{39711C4C-48C4-43D8-8907-B60861162E1C} [2012-11-28 09:03:52 | 000,000,000 | ---D | C] -- C:\Users\Artur\AppData\Local\{A3D68671-4E2F-4323-8980-7F901F03315D} [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012-12-27 15:43:34 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012-12-27 15:43:34 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012-12-27 15:42:41 | 001,549,932 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2012-12-27 15:42:41 | 000,697,896 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat [2012-12-27 15:42:41 | 000,616,032 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2012-12-27 15:42:41 | 000,135,006 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat [2012-12-27 15:42:41 | 000,106,412 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2012-12-27 15:36:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012-12-27 15:35:50 | 2415,321,088 | -HS- | M] () -- C:\hiberfil.sys [2012-12-26 19:37:43 | 000,550,017 | ---- | M] () -- C:\Users\Artur\Desktop\AdwCleaner.exe [2012-12-26 19:04:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Artur\Desktop\OTL.exe [2012-12-25 17:35:15 | 000,312,416 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2012-12-25 16:23:10 | 000,001,171 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk [2012-12-25 11:29:12 | 000,000,952 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk [2012-12-23 14:18:00 | 000,002,103 | ---- | M] () -- C:\Users\Public\Desktop\BlazeHDTV 6.0.lnk [2012-12-19 16:36:39 | 000,002,182 | ---- | M] () -- C:\Users\Artur\Desktop\SAS Secure Tomorrow.lnk [2012-12-19 15:54:01 | 000,002,460 | ---- | M] () -- C:\Users\Public\Desktop\Stranglehold.lnk [2012-12-18 19:29:10 | 000,002,804 | ---- | M] () -- C:\Users\Artur\Desktop\Skaner — skrót.lnk [2012-12-16 18:11:22 | 000,046,080 | ---- | M] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll [2012-12-16 17:06:29 | 000,002,092 | ---- | M] () -- C:\Users\Artur\Desktop\Najemnicy.lnk [2012-12-16 16:05:55 | 000,000,212 | ---- | M] () -- C:\Users\Artur\Desktop\Juiced2_HIN.lnk [2012-12-16 15:45:03 | 000,367,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll [2012-12-16 15:26:26 | 000,002,171 | ---- | M] () -- C:\Users\Public\Desktop\Uruchom grę Conflict Global Storm.lnk [2012-12-16 15:13:28 | 000,295,424 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll [2012-12-16 15:13:20 | 000,034,304 | ---- | M] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll [2012-12-15 16:48:59 | 000,002,055 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk [2012-12-15 16:48:59 | 000,002,055 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2012-12-15 16:22:49 | 000,108,008 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\WindowsAccessBridge-64.dll [2012-12-15 16:22:48 | 001,034,216 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\npDeployJava1.dll [2012-12-15 16:22:48 | 000,916,456 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\deployJava1.dll [2012-12-15 16:22:48 | 000,289,768 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\javaws.exe [2012-12-15 16:22:48 | 000,189,416 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\javaw.exe [2012-12-15 16:22:48 | 000,188,904 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\java.exe [2012-12-15 16:18:52 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2012-12-15 16:18:52 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2012-12-15 15:01:10 | 000,001,156 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-12-26 19:37:36 | 000,550,017 | ---- | C] () -- C:\Users\Artur\Desktop\AdwCleaner.exe [2012-12-25 16:23:10 | 000,001,183 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk [2012-12-25 16:23:10 | 000,001,171 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 8.lnk [2012-12-25 11:29:12 | 000,000,952 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk [2012-12-23 14:18:00 | 000,002,103 | ---- | C] () -- C:\Users\Public\Desktop\BlazeHDTV 6.0.lnk [2012-12-19 16:36:39 | 000,002,182 | ---- | C] () -- C:\Users\Artur\Desktop\SAS Secure Tomorrow.lnk [2012-12-19 15:54:01 | 000,002,460 | ---- | C] () -- C:\Users\Public\Desktop\Stranglehold.lnk [2012-12-18 19:29:10 | 000,002,804 | ---- | C] () -- C:\Users\Artur\Desktop\Skaner — skrót.lnk [2012-12-16 17:06:29 | 000,002,092 | ---- | C] () -- C:\Users\Artur\Desktop\Najemnicy.lnk [2012-12-16 16:05:55 | 000,000,212 | ---- | C] () -- C:\Users\Artur\Desktop\Juiced2_HIN.lnk [2012-12-16 15:26:26 | 000,002,171 | ---- | C] () -- C:\Users\Public\Desktop\Uruchom grę Conflict Global Storm.lnk [2012-12-15 16:18:55 | 000,002,055 | ---- | C] () -- C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk [2012-12-15 16:18:55 | 000,002,055 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2012-12-15 15:01:10 | 000,001,168 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [2012-12-15 15:01:10 | 000,001,156 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2012-09-10 11:46:34 | 000,000,014 | ---- | C] () -- C:\Windows\SysWow64\SysInfo_6.dll [2012-04-06 08:37:44 | 000,000,408 | ---- | C] () -- C:\Windows\wininit.ini [2011-10-03 06:59:18 | 000,215,128 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe [2011-10-03 06:59:16 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe [2011-10-03 06:59:16 | 000,075,064 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe [2011-09-28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat [2011-03-19 19:06:02 | 016,416,768 | ---- | C] () -- C:\Users\Artur\kavkis.msi [2011-01-17 10:37:42 | 000,026,672 | ---- | C] () -- C:\Windows\SysWow64\drivers\Mac606.sys [2011-01-17 10:37:41 | 000,064,048 | ---- | C] () -- C:\Windows\SysWow64\Hidhlp.dll [2011-01-17 10:37:41 | 000,049,152 | ---- | C] () -- C:\Windows\SysWow64\iFT33C2.dll [color=#E56717]========== ZeroAccess Check ==========[/color] [2009-07-14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012-06-09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012-06-09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== LOP Check ==========[/color] [2011-08-15 14:01:03 | 000,000,000 | ---D | M] -- C:\Users\Artur\AppData\Roaming\DAEMON Tools Lite [2011-12-11 09:49:50 | 000,000,000 | ---D | M] -- C:\Users\Artur\AppData\Roaming\Gadu-Gadu 10 [2012-06-10 12:22:54 | 000,000,000 | ---D | M] -- C:\Users\Artur\AppData\Roaming\Leadertech [2011-04-10 17:51:51 | 000,000,000 | ---D | M] -- C:\Users\Artur\AppData\Roaming\LG Electronics [2011-05-07 04:17:40 | 000,000,000 | ---D | M] -- C:\Users\Artur\AppData\Roaming\MP3Rocket [2010-12-28 15:25:22 | 000,000,000 | ---D | M] -- C:\Users\Artur\AppData\Roaming\Nowe Gadu-Gadu [2010-12-28 11:49:53 | 000,000,000 | ---D | M] -- C:\Users\Artur\AppData\Roaming\OEM [2011-01-09 15:10:20 | 000,000,000 | ---D | M] -- C:\Users\Artur\AppData\Roaming\OpenFM [2010-12-28 13:15:44 | 000,000,000 | ---D | M] -- C:\Users\Artur\AppData\Roaming\Skinux [2010-12-29 15:12:31 | 000,000,000 | ---D | M] -- C:\Users\Artur\AppData\Roaming\Tific [2010-12-28 18:47:15 | 000,000,000 | ---D | M] -- C:\Users\Artur\AppData\Roaming\Uniblue [2012-11-10 11:00:23 | 000,000,000 | ---D | M] -- C:\Users\Artur\AppData\Roaming\Unity [2012-12-25 13:02:34 | 000,000,000 | ---D | M] -- C:\Users\Artur\AppData\Roaming\uTorrent [2010-12-28 18:38:25 | 000,000,000 | ---D | M] -- C:\Users\Artur\AppData\Roaming\WildTangent [2011-01-10 17:50:01 | 000,000,000 | ---D | M] -- C:\Users\Artur\AppData\Roaming\Windows Live Writer [color=#E56717]========== Purity Check ==========[/color] < End of report >