OTL logfile created on: 2013-02-13 22:15:51 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = E:\pobieranie Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1023,23 Mb Total Physical Memory | 360,00 Mb Available Physical Memory | 35,18% Memory free 1,90 Gb Paging File | 1,29 Gb Available in Paging File | 67,57% Paging File free Paging file location(s): C:\pagefile.sys 1024 1024 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 9,77 Gb Total Space | 2,76 Gb Free Space | 28,21% Space Free | Partition Type: NTFS Drive D: | 7,25 Gb Total Space | 4,32 Gb Free Space | 59,51% Space Free | Partition Type: NTFS Drive E: | 54,86 Gb Total Space | 21,68 Gb Free Space | 39,52% Space Free | Partition Type: NTFS Drive V: | 1851,41 Gb Total Space | 1671,98 Gb Free Space | 90,31% Space Free | Partition Type: NTFS Drive Y: | 1851,41 Gb Total Space | 1671,98 Gb Free Space | 90,31% Space Free | Partition Type: NTFS Drive Z: | 1851,41 Gb Total Space | 1671,98 Gb Free Space | 90,31% Space Free | Partition Type: NTFS Computer Name: ZEBER | User Name: Administrator | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2013-02-13 22:13:06 | 000,602,112 | ---- | M] (OldTimer Tools) -- E:\pobieranie\OTL.exe PRC - [2013-02-13 22:00:22 | 000,170,912 | ---- | M] (Oracle Corporation) -- D:\java7\bin\jqs.exe PRC - [2013-02-07 23:38:48 | 000,917,400 | ---- | M] (Mozilla Corporation) -- D:\Mozilla Firefox\firefox.exe PRC - [2012-12-14 10:17:04 | 003,467,768 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe PRC - [2012-12-14 10:17:03 | 009,876,472 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version8\TeamViewer.exe PRC - [2012-12-14 10:08:24 | 000,190,968 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version8\tv_w32.exe PRC - [2012-11-14 22:04:15 | 000,036,640 | ---- | M] (Panda Security, S.L.) -- D:\Panda Security\Panda Cloud Antivirus\PSUAService.exe PRC - [2012-11-14 22:04:15 | 000,032,032 | ---- | M] (Panda Security, S.L.) -- D:\Panda Security\Panda Cloud Antivirus\PSUAMain.exe PRC - [2012-11-12 14:45:41 | 000,140,064 | ---- | M] (Panda Security, S.L.) -- D:\Panda Security\Panda Cloud Antivirus\PSANHost.exe PRC - [2012-10-21 20:55:56 | 003,776,824 | ---- | M] () -- D:\SpyShelter Personal Free\SpyShelter.exe PRC - [2012-03-23 14:25:24 | 000,087,040 | ---- | M] () -- C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe PRC - [2011-08-01 09:01:42 | 000,257,024 | ---- | M] (WDC) -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe PRC - [2011-03-07 14:33:08 | 000,089,456 | ---- | M] (Elaborate Bytes AG) -- D:\VirtualCloneDrive\VCDDaemon.exe PRC - [2010-11-03 15:58:56 | 003,652,696 | ---- | M] (Emsi Software GmbH) -- d:\Online Armor\oasrv.exe PRC - [2010-11-03 15:57:46 | 002,345,000 | ---- | M] (Emsi Software GmbH) -- D:\Online Armor\oaui.exe PRC - [2010-11-03 15:55:48 | 000,973,040 | ---- | M] (Emsi Software GmbH) -- D:\Online Armor\oahlp.exe PRC - [2010-11-03 15:52:30 | 000,380,784 | ---- | M] (Emsi Software GmbH) -- d:\Online Armor\oacat.exe PRC - [2010-03-04 22:38:00 | 000,071,096 | ---- | M] () -- d:\CDBurnerXP\NMSAccessU.exe PRC - [2009-10-05 18:05:12 | 002,158,592 | ---- | M] () -- C:\Program Files\Vtune\TBPANEL.exe PRC - [2008-04-14 22:51:18 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2013-02-07 23:38:46 | 003,023,256 | ---- | M] () -- D:\Mozilla Firefox\mozjs.dll MOD - [2012-10-21 20:56:40 | 000,333,112 | ---- | M] () -- D:\SpyShelter Personal Free\klhelper.dll MOD - [2012-10-21 20:55:56 | 003,776,824 | ---- | M] () -- D:\SpyShelter Personal Free\SpyShelter.exe MOD - [2012-03-23 14:25:24 | 000,087,040 | ---- | M] () -- C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe MOD - [2011-05-03 21:04:16 | 000,028,672 | ---- | M] () -- C:\WINDOWS\system32\SpyShelterShellExt.dll MOD - [2011-03-06 16:15:16 | 000,060,416 | ---- | M] () -- C:\WINDOWS\system32\antiwpa.dll MOD - [2010-07-04 22:32:38 | 000,010,752 | ---- | M] () -- d:\Unlocker\UnlockerCOM.dll MOD - [2010-03-04 22:38:00 | 000,071,096 | ---- | M] () -- d:\CDBurnerXP\NMSAccessU.exe MOD - [2009-10-05 18:05:12 | 002,158,592 | ---- | M] () -- C:\Program Files\Vtune\TBPANEL.exe MOD - [2008-04-14 22:50:38 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll MOD - [2001-10-28 17:42:30 | 000,116,224 | ---- | M] () -- C:\WINDOWS\system32\pdfcmnnt.dll MOD - [1998-10-31 04:55:56 | 000,005,120 | ---- | M] () -- C:\Program Files\Vtune\TBMANAGE.DLL [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt) SRV - [2013-02-13 22:00:22 | 000,170,912 | ---- | M] (Oracle Corporation) [Auto | Running] -- D:\java7\bin\jqs.exe -- (JavaQuickStarterService) SRV - [2013-02-07 23:38:46 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012-12-14 10:17:04 | 003,467,768 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8) SRV - [2012-11-14 22:04:15 | 000,036,640 | ---- | M] (Panda Security, S.L.) [Auto | Running] -- D:\Panda Security\Panda Cloud Antivirus\PSUAService.exe -- (PSUAService) SRV - [2012-11-12 14:45:41 | 000,140,064 | ---- | M] (Panda Security, S.L.) [Auto | Running] -- D:\Panda Security\Panda Cloud Antivirus\PSANHost.exe -- (NanoServiceMain) SRV - [2012-04-01 10:43:00 | 000,253,600 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012-03-23 14:25:24 | 000,087,040 | ---- | M] () [Auto | Running] -- C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service) SRV - [2011-08-01 09:01:42 | 000,257,024 | ---- | M] (WDC) [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe -- (WDDMService) SRV - [2010-11-03 15:58:56 | 003,652,696 | ---- | M] (Emsi Software GmbH) [Auto | Running] -- d:\Online Armor\oasrv.exe -- (SvcOnlineArmor) SRV - [2010-11-03 15:52:30 | 000,380,784 | ---- | M] (Emsi Software GmbH) [Auto | Running] -- d:\Online Armor\oacat.exe -- (OAcat) SRV - [2010-03-04 22:38:00 | 000,071,096 | ---- | M] () [Auto | Running] -- d:\CDBurnerXP\NMSAccessU.exe -- (NMSAccess) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2012-11-09 19:01:47 | 000,178,728 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\PSINKNC.sys -- (PSINKNC) DRV - [2012-11-09 19:01:47 | 000,123,560 | ---- | M] (Panda Security, S.L.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\PSINProt.sys -- (PSINProt) DRV - [2012-11-09 19:01:47 | 000,114,216 | ---- | M] (Panda Security, S.L.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\PSINProc.sys -- (PSINProc) DRV - [2012-11-09 19:01:46 | 000,149,288 | ---- | M] (Panda Security, S.L.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\PSINAflt.sys -- (PSINAflt) DRV - [2012-11-09 19:01:46 | 000,102,184 | ---- | M] (Panda Security, S.L.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\PSINFile.sys -- (PSINFile) DRV - [2012-11-09 11:23:58 | 000,276,520 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNSStrm.sys -- (NNSSTRM) DRV - [2012-11-09 11:23:58 | 000,133,928 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNStlsc.sys -- (NNSTLSC) DRV - [2012-11-09 11:23:57 | 000,370,216 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNSProt.sys -- (NNSPROT) DRV - [2012-11-09 11:23:57 | 000,191,528 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNSPrv.sys -- (NNSPRV) DRV - [2012-11-09 11:23:57 | 000,128,040 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNSSmtp.sys -- (NNSSMTP) DRV - [2012-11-09 11:23:56 | 000,125,480 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNSPop3.sys -- (NNSPOP3) DRV - [2012-11-09 11:23:56 | 000,063,400 | ---- | M] (Panda Security, S.L.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\NNSpihs.sys -- (NNSPIHS) DRV - [2012-11-09 11:23:55 | 000,163,112 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNSIds.sys -- (NNSIDS) DRV - [2012-11-09 11:23:55 | 000,139,176 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNSHttp.sys -- (NNSHTTP) DRV - [2012-11-09 11:23:55 | 000,133,544 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNSpicc.sys -- (NNSPICC) DRV - [2012-11-09 11:23:54 | 000,119,208 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NNSAlpc.sys -- (NNSALPC) DRV - [2012-11-07 09:00:12 | 000,046,672 | ---- | M] (Panda Security, S.L.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PSKMAD.sys -- (PSKMAD) DRV - [2012-10-22 12:08:35 | 000,038,824 | ---- | M] (Panda Security, S.L.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NNSNAHS.sys -- (NNSNAHS) DRV - [2012-10-21 20:57:14 | 000,154,936 | ---- | M] (SpyShelter) [Kernel | System | Running] -- d:\SpyShelter Personal Free\SpyShelter.sys -- (Spyshelter) DRV - [2010-11-03 15:57:12 | 000,038,856 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\oahlp32.sys -- (oahlpXX) DRV - [2010-11-03 15:55:12 | 000,029,272 | ---- | M] (Emsisoft) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\OAnet.sys -- (OAnet) DRV - [2010-11-03 15:55:12 | 000,025,000 | ---- | M] (Emsisoft) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\OAmon.sys -- (OAmon) DRV - [2010-11-03 15:52:36 | 000,202,064 | ---- | M] () [File_System | System | Running] -- C:\WINDOWS\system32\drivers\OADriver.sys -- (OADevice) DRV - [2010-07-04 20:51:26 | 000,004,096 | ---- | M] () [Kernel | Unavailable | Unknown] -- d:\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5) DRV - [2010-06-22 18:01:52 | 000,021,248 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\htcnprot.sys -- (htcnprot) DRV - [2010-06-14 08:32:54 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\FsUsbExDisk.Sys -- (FsUsbExDisk) DRV - [2009-08-24 08:14:30 | 000,044,544 | ---- | M] (AzureWave Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\azvusb.sys -- (azvusb) DRV - [2009-08-21 21:24:10 | 000,057,248 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvhda32.sys -- (NVHDA) DRV - [2009-06-10 15:49:32 | 000,024,576 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ANDROIDUSB.sys -- (HTCAND32) DRV - [2008-06-26 12:43:06 | 000,819,072 | ---- | M] (DiBcom SA) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mod7700.sys -- (mod7700) DRV - [2008-04-14 01:15:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum) DRV - [2008-04-13 23:16:24 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MPE.sys -- (MPE) DRV - [2007-10-25 16:26:10 | 000,005,632 | ---- | M] () [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen) DRV - [2007-10-19 12:22:04 | 000,013,824 | ---- | M] (DiBcom S.A.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\modrc.sys -- (MODRC) DRV - [2007-03-16 10:11:38 | 000,012,256 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\TBPanel.sys -- (TBPanel) DRV - [2006-07-01 23:32:26 | 000,043,520 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8) DRV - [2006-04-17 09:31:26 | 004,262,912 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) DRV - [2005-07-29 10:11:04 | 000,012,928 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus) DRV - [2005-07-29 10:11:02 | 000,034,048 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-507921405-1637723038-682003330-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-21-507921405-1637723038-682003330-500\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-507921405-1637723038-682003330-500\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC IE - HKU\S-1-5-21-507921405-1637723038-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "www.google.pl" FF - prefs.js..extensions.enabledAddons: fastdial%40telega.phpnet.us:4.3.1 FF - prefs.js..extensions.enabledAddons: ietab%40ip.cn:2.0.0.0 FF - prefs.js..extensions.enabledAddons: tempomail%40ingetic..maxime.robache:1.0.15 FF - prefs.js..extensions.enabledAddons: %7Bc36177c0-224a-11da-8cd6-0800200c9a91%7D:3.9.81 FF - prefs.js..extensions.enabledAddons: %7B8b86149f-01fb-4842-9dd8-4d7eb02fd055%7D:0.25.1 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.2 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 FF - prefs.js..extensions.enabledItems: tempomail@ingetic..maxime.robache:1.0.14 FF - prefs.js..extensions.enabledItems: {5F590AA2-1221-4113-A6F4-A4BB62414FAC}:0.45.6.20100202.1 FF - prefs.js..extensions.enabledItems: {8b86149f-01fb-4842-9dd8-4d7eb02fd055}:0.22.0 FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.8 FF - prefs.js..extensions.enabledItems: {e968fc70-8f95-4ab9-9e79-304de2a71ee1}:0.7.3 FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: autofillForms@blueimp.net:0.9.8.0 FF - prefs.js..extensions.enabledItems: fastdial@telega.phpnet.us:3.4 FF - prefs.js..extensions.enabledItems: {c36177c0-224a-11da-8cd6-0800200c9a91}:3.9.6 FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3 FF - prefs.js..extensions.enabledItems: ietab@ip.cn:1.98.20110322 FF - prefs.js..extensions.enabledItems: {c50ca3c4-5656-43c2-a061-13e717f73fc8}:4.0.2 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_228.dll () FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: d:\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll File not found FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: D:\java7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Components: D:\Mozilla Firefox\components [2013-02-07 23:38:50 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Plugins: D:\Mozilla Firefox\plugins [2012-03-04 01:28:28 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Extensions [2013-01-31 23:51:31 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\k061z7jj.default\extensions [2012-03-04 01:32:13 | 000,000,000 | ---D | M] (Screengrab) -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\k061z7jj.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671} [2012-03-04 01:32:13 | 000,000,000 | ---D | M] (SmoothWheel (mozdev.org)) -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\k061z7jj.default\extensions\{5F590AA2-1221-4113-A6F4-A4BB62414FAC} [2013-01-25 20:17:17 | 000,000,000 | ---D | M] (All-in-One Gestures) -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\k061z7jj.default\extensions\{8b86149f-01fb-4842-9dd8-4d7eb02fd055} [2012-11-24 16:02:06 | 000,000,000 | ---D | M] (Fast Dial) -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\k061z7jj.default\extensions\fastdial@telega.phpnet.us [2012-05-10 06:45:42 | 000,000,000 | ---D | M] (IE Tab Plus) -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\k061z7jj.default\extensions\ietab@ip.cn [2012-12-08 22:41:53 | 000,149,045 | ---- | M] () (No name found) -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\k061z7jj.default\extensions\autofillForms@blueimp.net.xpi [2011-08-25 19:36:48 | 000,006,135 | ---- | M] () (No name found) -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\k061z7jj.default\extensions\tempomail@ingetic..maxime.robache.xpi [2012-07-11 21:49:42 | 000,177,357 | ---- | M] () (No name found) -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\k061z7jj.default\extensions\{c36177c0-224a-11da-8cd6-0800200c9a91}.xpi [2013-01-31 23:51:31 | 000,817,973 | ---- | M] () (No name found) -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\k061z7jj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2010-06-29 01:06:04 | 000,002,084 | ---- | M] () -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\k061z7jj.default\searchplugins\anagramator.xml [2012-09-30 20:01:34 | 000,006,421 | ---- | M] () -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\k061z7jj.default\searchplugins\bitcoca.xml [2012-07-24 19:19:16 | 000,002,600 | ---- | M] () -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\k061z7jj.default\searchplugins\kickasstorrents.xml [2010-12-28 03:08:50 | 000,001,115 | ---- | M] () -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\k061z7jj.default\searchplugins\rapidshare-filefinder.xml [2013-02-07 23:27:28 | 000,001,345 | ---- | M] () -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\k061z7jj.default\searchplugins\slownik-alt.xml [2010-12-28 03:09:10 | 000,001,679 | ---- | M] () -- C:\Documents and Settings\Administrator\Dane aplikacji\Mozilla\Firefox\Profiles\k061z7jj.default\searchplugins\thepiratebayorg.xml O1 HOSTS File: ([2012-10-12 21:05:16 | 000,000,774 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 activate.adobe.com O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\java7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\java7\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No CLSID value found. O4 - HKLM..\Run: [@OnlineArmor GUI] D:\Online Armor\oaui.exe (Emsi Software GmbH) O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [KeePass 2 PreLoad] d:\KeePass Password Safe 2\KeePass.exe (Dominik Reichl) O4 - HKLM..\Run: [NPSStartup] File not found O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe () O4 - HKLM..\Run: [PSUAMain] D:\Panda Security\Panda Cloud Antivirus\PSUAMain.exe (Panda Security, S.L.) O4 - HKLM..\Run: [SpyShelter] d:\SpyShelter Personal Free\SpyShelter.exe () O4 - HKLM..\Run: [VirtualCloneDrive] d:\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG) O4 - HKU\S-1-5-21-507921405-1637723038-682003330-500..\Run: [TBPanel] C:\Program Files\Vtune\TBPanel.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-507921405-1637723038-682003330-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O7 - HKU\S-1-5-21-507921405-1637723038-682003330-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-21-507921405-1637723038-682003330-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutorunSetting = 1 O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - D:\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab (Reg Error: Value error.) O16 - DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{923B0E2E-530A-4315-95CF-316D7D8E704B}: DhcpNameServer = 192.168.0.1 O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\Antiwpa: DllName - (antiwpa.dll) - C:\WINDOWS\System32\antiwpa.dll () O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - d:\Online Armor\oaevent.dll (Emsi Software GmbH) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2012-03-04 01:00:03 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2009-06-24 21:57:30 | 000,000,000 | R--D | M] - E:\autorun.inf -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2013-02-13 22:01:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2013-02-13 22:00:43 | 000,262,560 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe [2013-02-13 22:00:43 | 000,143,872 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl [2013-02-13 22:00:37 | 000,094,112 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll [2013-02-13 22:00:36 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe [2013-02-13 22:00:35 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe [2013-02-13 21:57:27 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator\Recent [2013-02-11 22:19:24 | 000,046,672 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\PSKMAD.sys [2013-01-21 20:42:40 | 000,000,000 | ---D | C] -- C:\Program Files\Dropbox [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2013-02-13 22:04:21 | 000,253,748 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml [2013-02-13 22:03:27 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2013-02-13 22:03:22 | 1073,008,640 | -HS- | M] () -- C:\hiberfil.sys [2013-02-13 22:00:24 | 000,094,112 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll [2013-02-13 22:00:19 | 000,262,560 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe [2013-02-13 22:00:18 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe [2013-02-13 22:00:18 | 000,143,872 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl [2013-02-13 22:00:17 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe [2013-02-13 22:00:16 | 000,861,088 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\npdeployJava1.dll [2013-02-13 22:00:16 | 000,782,240 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll [2013-02-11 18:52:30 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2013-02-10 19:22:44 | 000,000,457 | ---- | M] () -- C:\Documents and Settings\Administrator\Pulpit\filmy.lnk [2013-02-02 21:37:37 | 000,000,459 | ---- | M] () -- C:\Documents and Settings\Administrator\Pulpit\Muzyka.lnk [2013-01-23 21:26:53 | 000,013,030 | ---- | M] () -- C:\PDOXUSRS.NET [2013-01-21 20:42:23 | 000,001,038 | ---- | M] () -- C:\Documents and Settings\Administrator\Pulpit\Dropbox.lnk [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2012-10-04 22:28:57 | 000,000,116 | ---- | C] () -- C:\WINDOWS\wininit.ini [2012-07-30 20:03:31 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\0x0304A000.sfl [2012-07-05 23:33:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PanelExe.INI [2012-07-05 23:33:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\EngineExe.INI [2012-07-05 22:50:47 | 000,038,481 | ---- | C] () -- C:\Documents and Settings\Administrator\Dane aplikacji\Wartości oddzielone przecinkami (Windows).ADR [2012-07-05 22:28:54 | 000,038,482 | ---- | C] () -- C:\Documents and Settings\Administrator\Dane aplikacji\Wartości oddzielone przecinkami (DOS).ADR [2012-07-05 21:57:06 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDevice.Dll [2012-07-05 21:57:06 | 000,036,608 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDisk.Sys [2012-07-05 21:57:00 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Administrator\Dane aplikacji\$_hpcst$.hpc [2012-04-29 18:15:34 | 000,711,240 | ---- | C] () -- C:\WINDOWS\is-LEHIQ.exe [2012-03-30 20:04:05 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\PsisDecd.dll [2012-03-09 21:01:12 | 000,999,640 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat [2012-03-04 10:24:44 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\Helper Scripts [2012-03-04 10:24:44 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Administrator\Dane aplikacji\Guitars [2012-03-04 10:24:44 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\PKP_DLdw.DAT [2012-03-04 10:24:44 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\Hybrid Morph [2012-03-04 10:23:16 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\Halftone [2012-03-04 10:23:16 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Administrator\Dane aplikacji\Guides [2012-03-04 10:23:16 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\PKP_DLdu.DAT [2012-03-04 10:23:16 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\Horn Section [2012-03-04 03:13:47 | 000,060,416 | ---- | C] () -- C:\WINDOWS\System32\antiwpa.dll [2012-03-04 02:30:39 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll [2012-03-04 02:27:08 | 000,434,176 | ---- | C] () -- C:\WINDOWS\System32\ZSHP1018.EXE [2012-03-04 02:10:36 | 000,175,616 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2012-03-04 02:04:18 | 000,000,138 | ---- | C] () -- C:\Documents and Settings\Administrator\Ustawienia lokalne\Dane aplikacji\fusioncache.dat [2012-03-04 01:50:31 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2012-03-04 01:49:17 | 000,200,936 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2012-03-04 01:33:52 | 000,202,064 | ---- | C] () -- C:\WINDOWS\System32\drivers\OADriver.sys [2012-03-04 01:33:52 | 000,038,856 | ---- | C] () -- C:\WINDOWS\System32\drivers\oahlp32.sys [2012-03-04 01:31:04 | 001,740,800 | ---- | C] () -- C:\WINDOWS\System32\Osklauncher.exe [2012-03-04 01:31:04 | 000,054,784 | ---- | C] () -- C:\WINDOWS\System32\inject_logon_dll.dll [2012-03-04 01:31:04 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\SpyShelterShellExt.dll [2012-03-04 01:19:05 | 000,000,008 | ---- | C] () -- C:\WINDOWS\System32\nvModes.dat [2012-03-04 01:13:11 | 000,135,168 | R--- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll [2012-03-04 01:13:11 | 000,040,960 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe [2012-03-04 01:11:33 | 000,004,716 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini [2012-03-04 01:11:30 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS [2012-03-04 01:03:03 | 005,242,880 | ---- | C] () -- C:\Documents and Settings\Administrator\NTUSER.bak [2012-03-04 01:01:47 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2012-03-04 00:57:21 | 000,021,856 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [color=#E56717]========== ZeroAccess Check ==========[/color] [2012-03-04 02:03:40 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2008-04-14 22:50:48 | 001,499,136 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2008-04-14 22:50:32 | 000,472,064 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008-04-14 22:50:58 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2012-04-08 17:59:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\.anki [2013-02-13 21:57:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\AIMP3 [2012-10-12 19:59:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\calibre [2012-03-04 02:37:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\Canneverbe Limited [2013-02-13 21:53:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\Dropbox [2012-10-04 21:47:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\FileZilla [2012-03-31 15:09:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\Foxit Software [2012-04-03 21:52:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\Gadu-Gadu [2013-02-13 21:51:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\KeePass [2013-02-03 22:53:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\Might & Magic Heroes VI [2012-07-05 22:16:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\Mobile Action [2012-04-07 21:14:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\mplayer [2012-03-04 17:18:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\NapiProjekt [2012-03-04 01:34:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\OnlineArmor [2012-03-09 20:23:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\Origin [2012-12-15 21:42:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\Outlook [2012-03-04 02:15:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\Panda Security [2012-03-04 02:30:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\pdfforge [2012-03-04 11:04:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\PhotoScape [2012-07-11 21:49:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\Samsung [2012-12-22 19:46:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\SpyShelter [2012-04-07 19:15:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\SuperMemo World [2013-02-13 21:57:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\uTorrent [2012-09-26 00:11:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Dane aplikacji\WDC [2012-03-04 02:37:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Canneverbe Limited [2012-10-04 21:41:19 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Common Files [2012-03-09 21:09:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\EA Core [2012-03-09 21:09:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Electronic Arts [2012-03-04 10:24:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\EnterNHelp [2012-10-25 18:25:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Licenses [2012-03-04 10:23:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Nikon [2012-03-04 01:40:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\OnlineArmor [2012-03-09 21:30:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Origin [2012-03-04 02:15:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Panda Security [2012-03-30 20:34:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PCTV Systems [2012-07-05 21:57:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Samsung [2012-04-07 19:16:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\SuperMemo World [2013-02-13 22:23:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP [2012-03-04 10:24:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Ultima_T15 [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:C43ED645 < End of report >