OTL logfile created on: 2013-08-09 14:38:13 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\S1\Pulpit Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,99 Gb Total Physical Memory | 1,31 Gb Available Physical Memory | 65,77% Memory free 3,84 Gb Paging File | 3,23 Gb Available in Paging File | 84,10% Paging File free Paging file location(s): C:\pagefile.sys 2046 2046 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 232,88 Gb Total Space | 169,30 Gb Free Space | 72,70% Space Free | Partition Type: NTFS Computer Name: MAGDA | User Name: S1 | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2013-08-09 14:36:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\S1\Pulpit\OTL.exe PRC - [2013-08-09 14:16:11 | 000,182,184 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe PRC - [2013-07-30 13:04:18 | 002,285,232 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe PRC - [2013-07-30 13:04:15 | 000,161,968 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\loggingserver.exe PRC - [2013-07-26 12:11:20 | 002,847,696 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\Browser Manager\2.6.1519.190\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe PRC - [2013-06-07 13:33:51 | 000,879,456 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe PRC - [2013-05-28 15:05:16 | 000,163,328 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe PRC - [2013-05-09 10:58:30 | 004,858,968 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe PRC - [2013-05-09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe PRC - [2012-08-06 13:23:54 | 000,210,944 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\GBox\GBox.exe PRC - [2012-07-16 16:31:32 | 007,445,416 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version7\TeamViewer.exe PRC - [2012-07-16 16:31:32 | 002,673,064 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe PRC - [2011-08-09 20:29:52 | 002,051,472 | ---- | M] (Bandoo Media Inc.) -- C:\Program Files\Bandoo\Bandoo.exe PRC - [2010-11-27 00:55:42 | 000,398,176 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe PRC - [2008-04-14 19:21:28 | 000,060,928 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Outlook Express\msimn.exe PRC - [2008-04-14 19:21:16 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007-12-10 12:40:42 | 001,269,248 | ---- | M] () -- C:\WINDOWS\system32\Rmm.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2013-08-09 11:15:26 | 002,092,544 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\13080901\algo.dll MOD - [2013-07-30 13:04:21 | 000,521,904 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\log4cplusU.dll MOD - [2013-07-30 13:04:21 | 000,145,072 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.4.0\SiteSafety.dll MOD - [2013-07-30 13:04:18 | 002,285,232 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe MOD - [2013-07-30 13:04:15 | 000,161,968 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\loggingserver.exe MOD - [2013-07-26 12:11:20 | 002,847,696 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\Browser Manager\2.6.1519.190\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe MOD - [2013-07-26 12:10:11 | 002,691,536 | ---- | M] () -- c:\Documents and Settings\All Users\Dane aplikacji\Browser Manager\2.6.1519.190\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll MOD - [2013-06-01 10:27:09 | 000,240,448 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\Setup\setiface.dll MOD - [2012-08-06 13:23:54 | 000,210,944 | ---- | M] () -- C:\Documents and Settings\All Users\Dane aplikacji\GBox\GBox.exe MOD - [2011-10-04 22:42:36 | 000,086,016 | ---- | M] () -- C:\WINDOWS\system32\custmon32i.dll MOD - [2010-11-08 17:15:40 | 000,296,448 | ---- | M] () -- C:\Program Files\Notepad++\NppShell_04.dll MOD - [2009-02-03 04:15:28 | 003,771,296 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll MOD - [2009-01-09 18:10:52 | 000,139,264 | ---- | M] () -- C:\Program Files\Brother\BrUtilities\BrLogAPI.dll MOD - [2008-07-23 00:17:48 | 000,021,240 | ---- | M] () -- C:\WINDOWS\system32\solidlocalmon.dll MOD - [2008-04-14 19:20:37 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll MOD - [2007-12-10 12:40:42 | 001,269,248 | ---- | M] () -- C:\WINDOWS\system32\Rmm.exe MOD - [2007-07-02 19:43:14 | 000,394,752 | ---- | M] () -- C:\WINDOWS\system32\pfilehak.dll MOD - [2002-11-26 14:43:18 | 000,106,496 | ---- | M] () -- C:\WINDOWS\system32\BrMuSNMP.dll MOD - [2001-10-29 01:42:30 | 000,116,224 | ---- | M] () -- C:\WINDOWS\system32\pdfmonnt.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - [2013-08-09 14:16:11 | 000,182,184 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService) SRV - [2013-07-30 13:04:16 | 001,616,048 | ---- | M] (AVG Secure Search) [Auto | Stopped] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe -- (vToolbarUpdater15.4.0) SRV - [2013-07-26 12:11:20 | 002,847,696 | ---- | M] () [Auto | Running] -- C:\Documents and Settings\All Users\Dane aplikacji\Browser Manager\2.6.1519.190\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe -- (Browser Manager) SRV - [2013-05-28 15:05:16 | 000,163,328 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013-05-09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus) SRV - [2012-07-16 16:31:32 | 002,673,064 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7) SRV - [2011-09-20 12:26:07 | 000,189,688 | ---- | M] (Solid Documents, LLC) [Auto | Stopped] -- C:\WINDOWS\Installer\MSI12E.tmp -- (SCPDFV4ReadSpool) SRV - [2011-08-09 20:29:52 | 002,051,472 | ---- | M] (Bandoo Media Inc.) [Auto | Running] -- C:\Program Files\Bandoo\Bandoo.exe -- (Bandoo Coordinator) SRV - [2010-11-27 00:55:42 | 000,398,176 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider) SRV - [2009-07-27 16:38:43 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [Disabled | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2008-09-23 09:20:16 | 000,575,488 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) SRV - [2007-12-10 12:40:42 | 001,269,248 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\Rmm.exe -- (RMMANAGER) SRV - [2006-10-12 13:37:36 | 000,184,320 | ---- | M] (VoyagerSoft, LLC) [Auto | Stopped] -- C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe -- (ScReadSpool) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\igxpmp32.sys -- (ialm) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbmdm.sys -- (hwdatacard) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ew_jubusenum.sys -- (huawei_enumerator) DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\ANDROIDUSB.sys -- (HTCAND32) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbnet.sys -- (ewusbnet) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\S1\USTAWI~1\Temp\catchme.sys -- (catchme) DRV - [2013-07-30 13:04:23 | 000,037,664 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtpx86.sys -- (avgtp) DRV - [2013-06-28 06:58:26 | 000,770,344 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2013-06-28 06:58:26 | 000,369,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP) DRV - [2013-06-28 06:58:26 | 000,175,176 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswVmm.sys -- (aswVmm) DRV - [2013-05-09 10:59:10 | 000,056,080 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2013-05-09 10:59:10 | 000,049,376 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswRvrt.sys -- (aswRvrt) DRV - [2013-05-09 10:59:09 | 000,066,336 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswMonFlt.sys -- (aswMonFlt) DRV - [2013-05-09 10:59:09 | 000,049,760 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr) DRV - [2013-05-09 10:59:08 | 000,029,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2012-10-31 00:51:56 | 000,020,624 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswKbd.sys -- (aswKbd) DRV - [2009-02-09 09:37:56 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt) DRV - [2009-02-09 09:37:48 | 000,007,808 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev) DRV - [2009-02-09 09:37:46 | 000,022,016 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc) DRV - [2009-02-09 09:37:46 | 000,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd) DRV - [2008-08-26 11:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd) DRV - [2008-05-07 19:31:16 | 000,106,368 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp) DRV - [2008-03-26 18:37:26 | 004,713,472 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) DRV - [2004-07-14 12:54:42 | 000,676,864 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (Hardlock) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=33953&home=true&tid=2958 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://websearch.pu-results.info/?pid=708&r=2013/04/02&hid=1368701990&lg=EN&cc=PL IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?si=33953&home=true&tid=2958 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?si=33953&home=true&tid=2958 IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://www.searchqu.com/web?src=ieb&appid=102&systemid=406&sr=0&q={searchTerms} IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.certified-toolbar.com?si=33953&bs=true&tid=2958&q={searchTerms} IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.pu-results.info/?l=1&q={searchTerms}&pid=708&r=2013/04/02&hid=1368701990&lg=EN&cc=PL IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.certified-toolbar.com?si=33953&bs=true&tid=2958&q={searchTerms} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://search.babylon.com/?affID=110824&tt=4612_4&babsrc=HP_ss&mntrId=b84bc036000000000000001fd09f618c IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q= IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q= IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q= IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://isearch.avg.com/?cid={8EAC5 [Binary data over 200 bytes] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=33953&home=true&tid=2958 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://websearch.pu-results.info/?pid=708&r=2013/04/02&hid=1368701990&lg=EN&cc=PL IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q= IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q= IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=33953&tid=2958&bs=true&q= IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?si=33953&home=true&tid=2958 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?si=33953&home=true&tid=2958 IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKCU\..\SearchScopes,DefaultScope = {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.delta-search.com/?q={searchTerms}&affID=119370&tt=4612_4&babsrc=SP_ss&mntrId=b84bc036000000000000001fd09f618c IE - HKCU\..\SearchScopes\{4553A6E3-0ED3-432D-81E0-ED16979E26BD}: "URL" = http://www.google.pl/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={8EAC5B4E-4A89-4582-877F-ACA51BD9C768}&mid=3baf23bc5dae47d08ef8d156967b887f-7ba5b7314b03629ff3c309ed922f2a15b3d9d974&lang=pl&ds=xn011&pr=sa&d=2013-01-31 11:50:11&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms} IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://www.searchqu.com/web?src=ieb&appid=102&systemid=406&sr=0&q={searchTerms} IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.certified-toolbar.com?si=33953&bs=true&tid=2958&q={searchTerms} IE - HKCU\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.pu-results.info/?l=1&q={searchTerms}&pid=708&r=2013/04/02&hid=1368701990&lg=EN&cc=PL IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredimail.com/mb68/?search={searchTerms}&loc=search_box&u=92260065915456187 IE - HKCU\..\SearchScopes\{E062D4CE-5C3D-4AE1-8485-F4065B339F7A}: "URL" = http://start.funmoods.com/results.php?f=4&a=ironto&q={searchTerms} IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.certified-toolbar.com?si=33953&bs=true&tid=2958&q={searchTerms} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search" FF - prefs.js..browser.search.order.1: "Delta Search" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.startup.homepage: "http://www.delta-search.com/?affID=119370&tt=4612_4&babsrc=HP_ss&mntrId=b84bc036000000000000001fd09f618c" FF - prefs.js..extensions.enabledItems: wrc@avast.com:8.0.1489 FF - prefs.js..extensions.enabledItems: ffxtlbr@babylon.com:1.5.0 FF - prefs.js..extensions.enabledItems: rtanq.attefh@i-huwayai.co.uk:3.8 FF - prefs.js..extensions.enabledItems: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB}:1.29 FF - prefs.js..extensions.enabledItems: {EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}:2.0 FF - prefs.js..extensions.enabledItems: ffxtlbr@delta.com:1.5.0 FF - prefs.js..extensions.enabledItems: ffxtlbr@funmoods.com:1.5.0 FF - prefs.js..extensions.enabledItems: {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}:2.7.2.0 FF - prefs.js..extensions.enabledItems: xiu.aws@ioqh-ia.com:1.0 FF - prefs.js..extensions.enabledItems: ffxtlbr@searchya.com:1.5.0 FF - prefs.js..extensions.enabledItems: plugin@yontoo.com:1.20.00 FF - prefs.js..keyword.URL: "http://www.delta-search.com/?affID=119370&tt=4612_4&babsrc=KW_ss&mntrId=b84bc036000000000000001fd09f618c&q=" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.4.0\\npsitesafety.dll () FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@vizlight.pl/deLight3D,version=1.4: C:\Program Files\deLight3D\npdelight3d.dll (vizLight) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\avg@toolbar: C:\Documents and Settings\All Users\Dane aplikacji\AVG Secure Search\FireFoxExt\15.4.0.5 [2013-07-30 13:05:04 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2013-06-01 10:28:52 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\rtanq.attefh@i-huwayai.co.uk: C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\extensions\rtanq.attefh@i-huwayai.co.uk [2013-04-02 10:47:14 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\xiu.aws@ioqh-ia.com: C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\extensions\xiu.aws@ioqh-ia.com [2013-04-02 10:49:48 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011-02-28 13:01:03 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013-08-09 14:16:30 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\ffox@bandoo.com: C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\extensions\ffox@bandoo.com [2011-09-22 13:51:00 | 000,000,000 | ---D | M] [2011-09-22 13:50:14 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Extensions [2013-07-26 09:18:35 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\extensions [2011-10-04 07:04:32 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2011-09-22 13:50:10 | 000,000,000 | ---D | M] (Searchqu Toolbar) -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7} [2012-07-03 12:54:36 | 000,000,000 | ---D | M] (BitComet Video Downloader) -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB} [2012-07-03 12:54:36 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}-trash [2011-09-20 12:14:44 | 000,000,000 | ---D | M] (IncrediMail MediaBar 2 Toolbar) -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} [2011-09-20 12:12:19 | 000,000,000 | ---D | M] (DealPly) -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} [2012-08-06 13:23:26 | 000,000,000 | ---D | M] ("BcoolApp") -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\extensions\crossriderapp11825@crossrider.com [2011-09-22 13:51:00 | 000,000,000 | ---D | M] (Bandoo for Firefox) -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\extensions\ffox@bandoo.com [2011-09-22 13:11:02 | 000,000,000 | ---D | M] (Babylon Toolbar) -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\extensions\ffxtlbr@babylon.com [2013-02-12 13:35:51 | 000,000,000 | ---D | M] (Delta Toolbar) -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\extensions\ffxtlbr@delta.com [2012-04-05 11:36:19 | 000,000,000 | ---D | M] (Funmoods.com) -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\extensions\ffxtlbr@funmoods.com [2012-02-02 13:40:58 | 000,000,000 | ---D | M] (searchya.com) -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\extensions\ffxtlbr@searchya.com [2013-02-19 12:11:01 | 000,000,000 | ---D | M] (Yontoo) -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\extensions\plugin@yontoo.com [2013-04-02 10:47:14 | 000,000,000 | ---D | M] (BerOwsae22savaee) -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\extensions\rtanq.attefh@i-huwayai.co.uk [2013-04-02 10:49:48 | 000,000,000 | ---D | M] (Searchh-NeWoTTab) -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\extensions\xiu.aws@ioqh-ia.com [2013-05-06 08:35:17 | 000,006,523 | ---- | M] () -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\searchplugins\babylon.xml [2011-02-28 13:00:58 | 000,001,706 | ---- | M] () -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\searchplugins\browsemngr.xml [2013-02-19 12:11:24 | 000,001,294 | ---- | M] () -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\searchplugins\delta.xml [2012-04-05 11:36:10 | 000,001,800 | ---- | M] () -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\searchplugins\funmoods.xml [2012-08-06 13:26:30 | 000,000,487 | ---- | M] () -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\searchplugins\GadgetBox.xml [2011-09-20 12:11:12 | 000,002,207 | ---- | M] () -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\searchplugins\MyStart Search.xml [2011-09-22 13:49:58 | 000,002,524 | ---- | M] () -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\searchplugins\SearchResults.xml [2012-02-02 13:40:51 | 000,001,463 | ---- | M] () -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\searchplugins\searchya.xml [2012-04-30 12:05:34 | 000,003,987 | ---- | M] () -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\searchplugins\sweetim.xml [2012-11-14 08:46:30 | 000,003,269 | ---- | M] () -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\searchplugins\Web Search.xml [2013-04-29 06:57:34 | 000,007,830 | ---- | M] () -- C:\Documents and Settings\S1\Dane aplikacji\Mozilla\Firefox\Profiles\rumcc3vd.default\searchplugins\WebSearch.xml [2013-07-26 08:46:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2013-06-01 10:28:52 | 000,000,000 | ---D | M] (avast! Online Security) -- C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST5\WEBREP\FF [2011-09-09 06:49:04 | 001,037,112 | ---- | M] (BitComet) -- C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll [2011-02-28 13:00:58 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml [2013-07-30 13:05:25 | 000,003,717 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml [2013-02-19 12:10:43 | 000,006,520 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml [2011-02-28 13:00:58 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml [2011-02-28 13:00:58 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml [2011-02-28 13:00:58 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml [2011-09-22 13:49:58 | 000,002,524 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\SearchResults.xml [2012-11-14 08:46:30 | 000,003,269 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Web Search.xml [2011-02-28 13:00:58 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml [2011-02-28 13:00:58 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml [color=#E56717]========== Chrome ==========[/color] CHR - default_search_provider: () CHR - default_search_provider: search_url = CHR - default_search_provider: suggest_url = CHR - homepage: http://websearch.pu-results.info/?pid=708&r=2013/04/02&hid=1368701990&lg=EN&cc=PL CHR - Extension: No name found = C:\Documents and Settings\S1\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\bhboogdnkjgjkfhdfgoobnckmnedkfdm\1\ CHR - Extension: No name found = C:\Documents and Settings\S1\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\dloejdefkancmfajekobpfoacecnhpgp\1.0.0.0_0\ CHR - Extension: No name found = C:\Documents and Settings\S1\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.3_0\ CHR - Extension: No name found = C:\Documents and Settings\S1\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\fbdcdpgkcpcooefoikgmmjfnpegjeidl\1\ CHR - Extension: No name found = C:\Documents and Settings\S1\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki\2.1.3_0\ CHR - Extension: No name found = C:\Documents and Settings\S1\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\gaiilaahiahdejapggenmdmafpmbipje\3.5.3.0_0\ CHR - Extension: No name found = C:\Documents and Settings\S1\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\haocganpkafanhkfldbbmhcpaelmkejg\3\ CHR - Extension: No name found = C:\Documents and Settings\S1\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\kcmilhmkaganinonedmjidmceoppaajg\1.8\ CHR - Extension: No name found = C:\Documents and Settings\S1\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\maeiepphbmmcgpcnalhdnobgijjphace\1.23.39_0\crossrider CHR - Extension: No name found = C:\Documents and Settings\S1\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\maeiepphbmmcgpcnalhdnobgijjphace\1.23.39_0\ CHR - Extension: No name found = C:\Documents and Settings\S1\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.3.0.11_0\ O1 HOSTS File: ([2004-08-04 17:00:00 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (BcoolApp) - {11111111-1111-1111-1111-110111181125} - C:\Program Files\BcoolApp\BcoolApp.dll (BcoolTeam) O2 - BHO: (Ironsource LTD Helper Object) - {25927741-5E5B-4D27-8D8B-9188FE64373F} - C:\Program Files\Ironsource\searchya\1.5.11.5\bh\searchya.dll (Montera Technologeis LTD) O2 - BHO: (Solid Converter PDF) - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll (VoyagerSoft, LLC) O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.8.3.8\bh\BabylonToolbar.dll (Babylon BHO) O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet) O2 - BHO: (BerOwsae22savaee) - {5852DAFF-365F-1B74-E7CD-A3BE841D2936} - C:\Documents and Settings\All Users\Dane aplikacji\BerOwsae22savaee\515a9acb0431f.dll () O2 - BHO: (Funmoods Helper Object) - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - C:\Program Files\Funmoods\funmoods\1.5.11.16\bh\funmoods.dll (Funmoods BHO) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software) O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\15.4.0.5\AVG Secure Search_toolbar.dll (AVG Secure Search) O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll () O2 - BHO: (SearchCore for Browsers) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files\SearchCore for Browsers\SearchCore for Browsers\BrowserConnection.dll (Bandoo Media, inc) O2 - BHO: (DealPly) - {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - C:\Program Files\DealPly\DealPlyIE.dll (DealPly Technologies Ltd) O2 - BHO: (delta Helper Object) - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.10.0\bh\delta.dll (Delta-search.com) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (Searchh-NeWoTTab) - {DC1A802B-F0AD-44D7-7917-BE9BD4887885} - C:\Documents and Settings\All Users\Dane aplikacji\Searchh-NeWoTTab\515a9b631cc80.dll () O2 - BHO: (BandooIEPlugin Class) - {EB5CEE80-030A-4ED8-8E20-454E9C68380F} - C:\Program Files\Bandoo\Plugins\IE\ieplugin.dll (Bandoo Media Inc.) O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo\YontooIEClient.dll (Yontoo LLC) O3 - HKLM\..\Toolbar: (Solid Converter PDF) - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll (VoyagerSoft, LLC) O3 - HKLM\..\Toolbar: (SearchYa Toolbar) - {33AA308B-B565-4376-AC66-59EE9B6AD13E} - C:\Program Files\Ironsource\searchya\1.5.11.5\searchyaTlbr.dll (Montera Technologeis LTD) O3 - HKLM\..\Toolbar: (Delta Toolbar) - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.10.0\deltaTlbr.dll (Delta-search.com) O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\15.4.0.5\AVG Secure Search_toolbar.dll (AVG Secure Search) O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files\Windows iLivid Toolbar\Datamngr\ToolBar\searchqudtx.dll () O3 - HKLM\..\Toolbar: (Funmoods Toolbar) - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - C:\Program Files\Funmoods\funmoods\1.5.11.16\funmoodsTlbr.dll (Funmoods) O3 - HKLM\..\Toolbar: (no name) - {D0F4A166-B8D4-48b8-9D63-80849FE137CB} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.) O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation) O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe () O4 - HKCU..\Run: [RivChat] C:\Program Files\RivChat2\RivChat.exe () O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) O4 - Startup: C:\Documents and Settings\S1\Menu Start\Programy\Autostart\Dropbox.lnk = C:\Documents and Settings\S1\Dane aplikacji\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data] O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8 - Extra context menu item: &P&obierz &za pomocą BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com) O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.) O8 - Extra context menu item: Pobierz wszystko za pomocą BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com) O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet) O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 10.25.2) O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16) O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 10.25.2) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 8.8.8.8 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5901389F-B8A7-4FA3-B50F-2191A5BF45FB}: NameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6C41B38B-778E-4008-B015-8142E83640D4}: DhcpNameServer = 8.8.8.8 O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.4.0\ViProtocol.dll (AVG Secure Search) O20 - AppInit_DLLs: (c:\docume~1\alluse~1\daneap~1\browse~1\261519~1.190\{16cdf~1\browse~1.dll) - c:\Documents and Settings\All Users\Dane aplikacji\Browser Manager\2.6.1519.190\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll () O20 - AppInit_DLLs: (c:\progra~1\bandoo\bndhook.dll) - c:\Program Files\Bandoo\BndHook.dll (Discordia Limited) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O20 - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - File not found O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\S1\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\S1\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008-08-29 21:34:25 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2011-05-24 07:44:34 | 000,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2013-08-09 14:36:50 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\S1\Pulpit\OTL.exe [2013-08-09 14:16:39 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2013-08-09 14:16:30 | 000,867,240 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\npDeployJava1.dll [2013-08-09 14:16:30 | 000,789,416 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll [2013-08-09 14:16:30 | 000,263,592 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe [2013-08-09 14:16:24 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe [2013-08-09 14:16:24 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe [2013-08-09 14:16:24 | 000,094,632 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll [2013-08-08 07:34:23 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2013-08-06 11:31:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S1\Pulpit\Marek(2) [2013-08-06 10:02:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S1\Pulpit\odlewnia [2013-08-06 08:19:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S1\Pulpit\Marek1 [2013-08-06 08:14:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S1\Pulpit\Maryla [2013-08-06 08:14:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S1\Pulpit\Marek [2013-07-30 13:07:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\S1\Pulpit\materace [2013-07-15 14:59:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MRT [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2013-08-09 14:36:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\S1\Pulpit\OTL.exe [2013-08-09 14:31:01 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2013-08-09 14:26:38 | 000,045,902 | ---- | M] () -- C:\Documents and Settings\S1\Dane aplikacji\logf_0.acfgp [2013-08-09 14:25:44 | 000,000,186 | ---- | M] () -- C:\WINDOWS\System32\dcrm.dat [2013-08-09 14:19:06 | 000,003,856 | ---- | M] () -- C:\WINDOWS\wincmd.ini [2013-08-09 14:16:12 | 000,094,632 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll [2013-08-09 14:16:10 | 000,263,592 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe [2013-08-09 14:16:10 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe [2013-08-09 14:16:10 | 000,144,896 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl [2013-08-09 14:16:09 | 000,867,240 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\npDeployJava1.dll [2013-08-09 14:16:09 | 000,789,416 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll [2013-08-09 14:16:09 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe [2013-08-09 13:35:29 | 000,001,700 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\avast! Free Antivirus.lnk [2013-08-09 13:35:27 | 000,002,596 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT [2013-08-09 13:35:27 | 000,000,318 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2013-08-09 13:34:50 | 000,001,170 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2013-08-09 13:34:18 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2013-08-09 13:34:17 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job [2013-08-09 13:34:17 | 000,000,350 | ---- | M] () -- C:\WINDOWS\tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job [2013-08-09 13:34:16 | 000,000,464 | -H-- | M] () -- C:\WINDOWS\tasks\GBoxUpdaterTask{9EA26AFB-3563-483A-8B0C-974847D054D4}.job [2013-08-09 13:34:14 | 000,000,324 | ---- | M] () -- C:\WINDOWS\tasks\Protected Search.job [2013-08-09 13:33:48 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2013-08-07 13:38:07 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat [2013-08-06 14:53:48 | 000,001,770 | -H-- | M] () -- C:\Documents and Settings\S1\Moje dokumenty\Default.rdp [2013-08-06 14:31:28 | 000,005,726 | ---- | M] () -- C:\Documents and Settings\S1\Pulpit\logo-wiatr_i_woda.png [2013-08-06 13:50:07 | 001,370,462 | ---- | M] () -- C:\Documents and Settings\S1\Pulpit\Magazyn Wiatr 08-2013.pdf [2013-08-06 08:03:10 | 011,163,563 | ---- | M] () -- C:\Documents and Settings\S1\Pulpit\MagazynWiatr_08_2013.pdf [2013-08-01 10:22:18 | 000,036,352 | ---- | M] () -- C:\Documents and Settings\S1\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2013-07-30 13:08:04 | 000,060,118 | ---- | M] () -- C:\Documents and Settings\S1\Dane aplikacji\logf_3137.acfgp [2013-07-30 13:04:23 | 000,037,664 | ---- | M] (AVG Technologies) -- C:\WINDOWS\System32\drivers\avgtpx86.sys [2013-07-15 13:14:10 | 000,035,328 | ---- | M] () -- C:\Documents and Settings\S1\Moje dokumenty\Rescue.asd [2013-07-12 07:05:10 | 000,392,776 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2013-07-11 15:15:59 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2013-07-11 15:14:32 | 000,494,412 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2013-07-11 15:14:32 | 000,435,832 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2013-07-11 15:14:32 | 000,085,572 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2013-07-11 15:14:32 | 000,068,728 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2013-08-06 14:31:27 | 000,005,726 | ---- | C] () -- C:\Documents and Settings\S1\Pulpit\logo-wiatr_i_woda.png [2013-08-06 13:50:07 | 001,370,462 | ---- | C] () -- C:\Documents and Settings\S1\Pulpit\Magazyn Wiatr 08-2013.pdf [2013-08-06 08:03:08 | 011,163,563 | ---- | C] () -- C:\Documents and Settings\S1\Pulpit\MagazynWiatr_08_2013.pdf [2013-07-15 15:02:02 | 000,219,832 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat [2013-07-15 13:14:10 | 000,035,328 | ---- | C] () -- C:\Documents and Settings\S1\Moje dokumenty\Rescue.asd [2013-06-28 06:58:26 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys.sum [2013-06-27 06:57:48 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswSnx.sys.sum [2013-06-27 06:57:47 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswSP.sys.sum [2013-05-27 11:51:59 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat [2013-02-28 14:06:24 | 000,175,176 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys [2013-02-28 14:06:23 | 000,049,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswRvrt.sys [2013-02-12 13:35:15 | 001,031,168 | ---- | C] () -- C:\WINDOWS\PdfCreatorAddonWord.dll [2013-01-07 14:56:50 | 000,000,861 | ---- | C] () -- C:\Documents and Settings\S1\Ustawienia lokalne\Dane aplikacji\recently-used.xbel [2012-11-14 08:46:17 | 000,015,432 | ---- | C] () -- C:\WINDOWS\Launcher.exe [2012-06-14 15:03:49 | 000,000,127 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI [2012-04-05 11:33:13 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\custmon32i.dll [2012-02-15 07:59:15 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2012-01-09 14:30:00 | 000,000,404 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI [2012-01-09 14:29:31 | 000,000,050 | ---- | C] () -- C:\WINDOWS\System32\bridf08b.dat [2012-01-09 14:29:26 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\BrMuSNMP.dll [2012-01-04 14:08:52 | 000,031,767 | ---- | C] () -- C:\WINDOWS\maxlink.ini [2011-09-22 14:25:05 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfmonnt.dll [2011-09-22 14:24:59 | 000,000,164 | ---- | C] () -- C:\WINDOWS\System32\psconv.ini [2011-09-22 13:38:25 | 000,180,624 | ---- | C] () -- C:\WINDOWS\System32\Primomonnt.dll [2011-09-21 10:00:25 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2011-09-20 12:13:06 | 000,021,240 | ---- | C] () -- C:\WINDOWS\System32\solidlocalmon.dll [2011-09-20 12:13:06 | 000,013,560 | ---- | C] () -- C:\WINDOWS\System32\solidlocalui.dll [2011-09-20 12:11:39 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\redmonnt.dll [2011-07-25 11:58:44 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\S1\Ustawienia lokalne\Dane aplikacji\{83AE2BB3-126D-4CDE-8849-053F391C4EA1} [2009-08-10 08:27:28 | 000,060,004 | ---- | C] () -- C:\Documents and Settings\S1\Dane aplikacji\logf_16179.acfgp [2009-08-10 08:26:33 | 000,060,054 | ---- | C] () -- C:\Documents and Settings\S1\Dane aplikacji\logf_31869.acfgp [2009-08-10 08:25:44 | 000,060,472 | ---- | C] () -- C:\Documents and Settings\S1\Dane aplikacji\logf_67165.acfgp [2009-08-10 08:24:36 | 000,060,126 | ---- | C] () -- C:\Documents and Settings\S1\Dane aplikacji\logf_27292.acfgp [2009-08-10 08:23:32 | 000,060,164 | ---- | C] () -- C:\Documents and Settings\S1\Dane aplikacji\logf_20258.acfgp [2009-08-10 08:22:27 | 000,060,100 | ---- | C] () -- C:\Documents and Settings\S1\Dane aplikacji\logf_86104.acfgp [2009-08-10 08:21:24 | 000,060,118 | ---- | C] () -- C:\Documents and Settings\S1\Dane aplikacji\logf_3137.acfgp [2009-08-06 08:27:35 | 000,036,352 | ---- | C] () -- C:\Documents and Settings\S1\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009-07-29 08:55:38 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\S1\Dane aplikacji\$_hpcst$.hpc [2009-07-27 16:13:49 | 000,045,902 | ---- | C] () -- C:\Documents and Settings\S1\Dane aplikacji\logf_0.acfgp [2009-03-25 12:12:17 | 000,000,033 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\system.dat [color=#E56717]========== ZeroAccess Check ==========[/color] [2009-07-27 16:30:30 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2008-04-14 19:20:47 | 001,499,136 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009-02-09 12:53:44 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008-04-14 19:20:57 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2008-09-01 14:58:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Actina Data Manager [2010-12-12 14:57:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software [2009-08-24 08:27:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Autodesk [2013-06-27 10:56:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\AVG Secure Search [2011-09-22 13:10:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Babylon [2011-09-22 13:50:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Bandoo [2013-06-28 10:15:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\BerOwsae22savaee [2011-09-23 06:55:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\boost_interprocess [2013-08-09 13:33:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Browser Manager [2013-01-31 12:49:46 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Common Files [2012-07-17 14:23:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\DatacardService [2012-08-07 11:53:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\GBox [2011-09-20 12:14:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\IM [2011-09-20 12:14:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\IncrediMail [2012-11-05 12:46:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Installations [2013-04-03 08:22:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\InstallMate [2012-08-06 13:23:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\OptimizerPro [2012-11-05 12:47:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PC Suite [2012-08-06 13:23:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Premium [2012-01-04 14:08:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ScanSoft [2013-06-28 10:15:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Searchh-NeWoTTab [2011-09-22 13:10:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Smart Soft [2013-04-02 10:49:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\SoftSafe [2011-05-24 07:46:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\SolidDocuments [2012-11-12 14:27:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\SweetIM [2013-02-19 12:10:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Tarma Installer [2013-04-03 07:37:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP [2013-01-31 15:14:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\.oit [2012-07-24 09:56:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\AgerWebEdytor [2009-08-24 08:27:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\Autodesk [2013-01-31 12:50:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\AVG Secure Search [2011-09-22 13:10:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\Babylon [2011-09-22 13:33:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\BabylonToolbar [2011-09-22 13:51:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\Bandoo [2013-03-26 15:58:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\BitComet [2009-11-16 13:38:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\Bitstream [2013-02-11 13:29:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\DealPly [2013-02-20 11:29:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\Delta [2013-08-09 13:37:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\Dropbox [2013-02-19 12:10:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\DSite [2012-02-20 09:02:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\e-pity [2013-06-17 07:00:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\File Scout [2010-02-05 12:53:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\Foxit Software [2011-09-22 13:10:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\Free PDF to Word Converter [2013-04-09 08:03:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\Funmoods [2013-01-31 12:54:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\IGC [2012-11-05 12:48:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\Ironsource [2011-08-30 12:45:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\klavaro [2011-01-12 11:52:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\Notepad++ [2012-06-25 12:45:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\OpenCandy [2009-07-31 07:36:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\OpenOffice.org [2012-06-14 12:16:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\Opera [2012-11-05 12:46:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\PC Suite [2013-02-19 12:14:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\PDF Converter Packages [2012-11-12 15:29:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\PDFConverterPackages [2012-06-25 12:45:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\pdfforge [2011-09-22 13:50:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\searchquband [2011-10-11 09:28:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\searchqutoolbar [2013-08-07 08:15:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\SolidDocuments [2012-02-02 13:40:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\SumatraPDF [2010-12-12 14:39:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\Teleca [2009-09-11 07:16:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\S1\Dane aplikacji\Thunderbird [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:373E1720 < End of report >