OTL logfile created on: 2013-09-01 12:51:44 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Karolina\Pulpit Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2,99 Gb Total Physical Memory | 2,12 Gb Available Physical Memory | 70,80% Memory free 4,83 Gb Paging File | 3,97 Gb Available in Paging File | 82,21% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 100,00 Gb Total Space | 44,34 Gb Free Space | 44,34% Space Free | Partition Type: NTFS Drive E: | 132,88 Gb Total Space | 10,57 Gb Free Space | 7,95% Space Free | Partition Type: NTFS Drive G: | 7,51 Gb Total Space | 7,43 Gb Free Space | 98,90% Space Free | Partition Type: FAT32 Computer Name: KAROLINA | User Name: Karolina | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2013-08-31 22:22:23 | 000,212,992 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Documents and Settings\Karolina\Ustawienia lokalne\Temp\RtkBtMnt.exe PRC - [2013-08-31 17:24:56 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Karolina\Pulpit\OTL.exe PRC - [2013-05-28 14:20:30 | 021,172,832 | ---- | M] (Redefine Sp z o.o.) -- C:\Program Files\ipla\ipla.exe PRC - [2013-05-24 22:21:44 | 001,125,456 | ---- | M] (BitTorrent Inc.) -- C:\Program Files\BitTorrent\BitTorrent.exe PRC - [2013-05-24 12:29:38 | 000,844,168 | ---- | M] (Samsung) -- C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe PRC - [2013-05-09 10:58:30 | 004,858,968 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe PRC - [2013-05-09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe PRC - [2013-04-19 01:45:32 | 001,090,912 | ---- | M] (Nokia) -- C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe PRC - [2013-04-18 11:06:42 | 000,737,616 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe PRC - [2013-04-18 11:06:32 | 000,179,024 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe PRC - [2013-04-18 11:06:22 | 000,150,864 | ---- | M] (Nokia) -- C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe PRC - [2013-04-18 10:10:38 | 000,578,560 | ---- | M] (Samsung Electronics) -- C:\Program Files\Samsung\Kies\kiesairmessage.exe PRC - [2008-04-15 14:00:00 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2013-08-06 19:41:16 | 002,091,520 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\13080601\algo.dll MOD - [2013-05-28 14:20:32 | 000,392,200 | ---- | M] () -- C:\Program Files\ipla\jabberoo.dll MOD - [2013-05-28 14:20:32 | 000,068,104 | ---- | M] () -- C:\Program Files\ipla\ziplib.dll MOD - [2013-05-28 14:10:56 | 000,294,400 | ---- | M] () -- C:\Program Files\ipla\MediaFileScanner.dll MOD - [2013-05-13 12:21:38 | 032,644,096 | ---- | M] () -- C:\Program Files\ipla\libcef.dll MOD - [2013-04-19 01:46:32 | 000,276,832 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\phonon4.dll MOD - [2013-04-19 01:46:32 | 000,093,024 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\qjson.dll MOD - [2013-04-19 01:46:16 | 002,653,024 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtXmlPatterns4.dll MOD - [2013-04-19 01:46:16 | 000,364,384 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtXml4.dll MOD - [2013-04-19 01:46:14 | 011,166,560 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtWebKit4.dll MOD - [2013-04-19 01:46:12 | 001,346,912 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtScript4.dll MOD - [2013-04-19 01:46:12 | 000,206,176 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtSql4.dll MOD - [2013-04-19 01:46:10 | 001,014,624 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtNetwork4.dll MOD - [2013-04-19 01:46:10 | 000,720,736 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtOpenGL4.dll MOD - [2013-04-19 01:46:08 | 008,507,232 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtGui4.dll MOD - [2013-04-19 01:46:08 | 000,520,544 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtMultimediaKit1.dll MOD - [2013-04-19 01:46:06 | 002,480,992 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtDeclarative4.dll MOD - [2013-04-19 01:46:06 | 002,354,016 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\QtCore4.dll MOD - [2013-04-19 01:46:02 | 000,446,304 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\sqldrivers\qsqlite4.dll MOD - [2013-04-19 01:45:58 | 000,207,200 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\Imageformats\qjpeg4.dll MOD - [2013-04-19 01:45:58 | 000,035,680 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\Imageformats\qico4.dll MOD - [2013-04-19 01:45:56 | 000,033,120 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\Imageformats\qgif4.dll MOD - [2013-04-19 01:45:28 | 000,438,624 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\NService.dll MOD - [2013-04-19 01:44:48 | 000,606,560 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\CommonUpdateChecker.dll MOD - [2013-04-15 13:26:16 | 000,391,600 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\ssoengine.dll MOD - [2013-04-15 13:26:16 | 000,059,280 | ---- | M] () -- C:\Program Files\Nokia\Nokia Suite\securestorage.dll MOD - [2011-09-27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2011-09-27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2010-03-15 12:28:22 | 000,141,824 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll MOD - [2008-04-15 14:00:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll MOD - [2008-03-29 16:42:20 | 000,159,744 | ---- | M] () -- C:\Program Files\SubEdit-Player\codec\MatroskaSplitter\mmfinfo.dll MOD - [2008-03-29 16:41:52 | 000,023,552 | ---- | M] () -- C:\Program Files\SubEdit-Player\codec\MatroskaSplitter\mkunicode.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [Auto | Stopped] -- C:\PROGRA~1\ZWINKY~2\bar\1.bin\5qbarsvc.exe -- (Zwinky_5qService) SRV - File not found [Auto | Stopped] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe -- (vToolbarUpdater13.2.0) SRV - [2013-05-09 10:58:30 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus) SRV - [2013-04-18 11:06:42 | 000,737,616 | ---- | M] (Nokia) [On_Demand | Running] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer) SRV - [2013-03-01 03:48:58 | 000,118,520 | ---- | M] (Riverbed Technology, Inc.) [On_Demand | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) SRV - [2011-01-19 22:12:16 | 000,068,096 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe -- (Macromedia Licensing Service) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\UIUSYS.SYS -- (UIUSys) DRV - File not found [File_System | On_Demand | Stopped] -- -- (StarOpen) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\catchme.sys -- (catchme) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\btwhid.sys -- (btwhid) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\btwdndis.sys -- (BTWDNDIS) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\btport.sys -- (BTDriver) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\btaudio.sys -- (btaudio) DRV - [2013-06-27 21:24:01 | 000,770,344 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2013-06-27 21:24:01 | 000,369,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP) DRV - [2013-06-27 21:24:01 | 000,175,176 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswVmm.sys -- (aswVmm) DRV - [2013-05-09 10:59:10 | 000,056,080 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2013-05-09 10:59:10 | 000,049,376 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswRvrt.sys -- (aswRvrt) DRV - [2013-05-09 10:59:09 | 000,066,336 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswMonFlt.sys -- (aswMonFlt) DRV - [2013-05-09 10:59:09 | 000,049,760 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr) DRV - [2013-05-09 10:59:08 | 000,029,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2013-04-03 09:58:16 | 000,181,912 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssudmdm.sys -- (ssudmdm) DRV - [2013-04-03 09:58:16 | 000,083,864 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ssudbus.sys -- (dg_ssudbus) DRV - [2013-03-01 03:48:42 | 000,036,600 | ---- | M] (Riverbed Technology, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF) DRV - [2013-01-23 10:31:50 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc) DRV - [2013-01-23 10:31:50 | 000,018,560 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd) DRV - [2013-01-23 10:31:50 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt) DRV - [2013-01-23 10:31:50 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev) DRV - [2012-11-20 11:07:11 | 000,026,984 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtpx86.sys -- (avgtp) DRV - [2012-10-31 00:51:56 | 000,020,624 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswKbd.sys -- (aswKbd) DRV - [2012-10-17 14:53:46 | 000,019,072 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd) DRV - [2010-06-17 11:34:58 | 000,069,168 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\si3112.sys -- (Si3112) DRV - [2010-06-17 11:34:57 | 000,210,736 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\Si3531.sys -- (Si3531) DRV - [2010-06-17 11:34:56 | 000,217,128 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\Si3132r5.sys -- (Si3132r5) DRV - [2010-06-17 11:34:56 | 000,080,424 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\si3132.sys -- (Si3132) DRV - [2010-06-17 11:34:55 | 000,069,248 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\si3124.sys -- (Si3124) DRV - [2010-06-17 11:34:54 | 000,211,496 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\Si3114r5.sys -- (Si3114r5) DRV - [2010-06-04 02:29:04 | 001,606,368 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\athw.sys -- (AR5416) DRV - [2010-04-30 17:56:24 | 006,032,928 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) DRV - [2010-04-28 08:44:02 | 000,054,760 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr) DRV - [2009-11-18 08:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt) DRV - [2009-11-18 08:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt) DRV - [2009-08-27 00:10:26 | 000,213,544 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k) DRV - [2008-08-12 10:02:06 | 000,016,512 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ASPI32.SYS -- (Aspi32) DRV - [2007-05-02 04:52:00 | 000,290,816 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tifm21.sys -- (tifm21) DRV - [2006-12-23 03:56:44 | 000,988,800 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV) DRV - [2006-12-23 03:56:00 | 000,209,664 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL) DRV - [2006-12-23 03:55:56 | 000,730,112 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.v9.com/?utm_source=b&utm_medium=idg&from=idg&uid=ST9250315AS_6VCKJGG8____6VCKJGG8&ts=1354548559 IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5} IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=ds&q={searchTerms}&installDate=04/04/2013 IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKLM\..\SearchScopes\{5a15c091-f3c2-4c8f-8964-e3434a2a4a95}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^ZJ^xpt249^YY^pl&si=begin-download&ptb=ED147F04-8A39-4FE4-BF0D-CD9C6635E2FE&ind=2013062216&n=77fce448&psa=&st=sb&searchfor={searchTerms} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=ds&q={searchTerms}&installDate=04/04/2013 IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=ds&q={searchTerms}&installDate=04/04/2013 IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=hp&installDate=04/04/2013 IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=ds&q={searchTerms}&installDate=04/04/2013 IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=ds&q={searchTerms}&installDate=04/04/2013 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5} IE - HKU\S-1-5-19\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=ds&q={searchTerms}&installDate=04/04/2013 IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=ds&q={searchTerms}&installDate=04/04/2013 IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=ds&q={searchTerms}&installDate=04/04/2013 IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=hp&installDate=04/04/2013 IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=ds&q={searchTerms}&installDate=04/04/2013 IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=ds&q={searchTerms}&installDate=04/04/2013 IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5} IE - HKU\S-1-5-20\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=ds&q={searchTerms}&installDate=04/04/2013 IE - HKU\S-1-5-21-515967899-287218729-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=idg&from=idg&uid=ST9250315AS_6VCKJGG8____6VCKJGG8&ts=1354548559 IE - HKU\S-1-5-21-515967899-287218729-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie IE - HKU\S-1-5-21-515967899-287218729-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=ds&q={searchTerms}&installDate=04/04/2013 IE - HKU\S-1-5-21-515967899-287218729-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=ds&q={searchTerms}&installDate=04/04/2013 IE - HKU\S-1-5-21-515967899-287218729-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=hp&installDate=04/04/2013 IE - HKU\S-1-5-21-515967899-287218729-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=ds&q={searchTerms}&installDate=04/04/2013 IE - HKU\S-1-5-21-515967899-287218729-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=ds&q={searchTerms}&installDate=04/04/2013 IE - HKU\S-1-5-21-515967899-287218729-1801674531-1003\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKU\S-1-5-21-515967899-287218729-1801674531-1003\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=ds&q={searchTerms}&installDate=04/04/2013 IE - HKU\S-1-5-21-515967899-287218729-1801674531-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.v9.com/web/?q={searchTerms} IE - HKU\S-1-5-21-515967899-287218729-1801674531-1003\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=120665&babsrc=SP_ss_gin2g&mntrId=B89B0017C4161A04 IE - HKU\S-1-5-21-515967899-287218729-1801674531-1003\..\SearchScopes\{5a15c091-f3c2-4c8f-8964-e3434a2a4a95}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^ZJ^xpt249^YY^pl&si=begin-download&ptb=ED147F04-8A39-4FE4-BF0D-CD9C6635E2FE&ind=2013062216&n=77fce448&psa=&st=sb&searchfor={searchTerms} IE - HKU\S-1-5-21-515967899-287218729-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\13.2.0\\npsitesafety.dll File not found FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: e:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nokia.com/EnablerPlugin: C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Karolina\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Karolina\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\facebook.com/fbDesktopPlugin: C:\Documents and Settings\Karolina\Ustawienia lokalne\Dane aplikacji\Facebook\Messenger\2.1.4651.0\npFbDesktopPlugin.dll (Facebook, Inc.) [2011-02-28 14:13:48 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Karolina\Dane aplikacji\Mozilla\Extensions [2011-02-28 14:13:48 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Karolina\Dane aplikacji\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2012-11-16 22:52:23 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Karolina\Dane aplikacji\Mozilla\Firefox\Profiles\0\extensions [2012-10-30 11:27:22 | 000,214,909 | ---- | M] () (No name found) -- C:\Documents and Settings\Karolina\Dane aplikacji\Mozilla\Firefox\Profiles\0\extensions\onlinehdtv@onlinehd.tv.xpi [2011-02-22 16:43:32 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2011-01-19 14:59:48 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2011-01-19 15:42:22 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} [2010-11-12 19:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll [color=#E56717]========== Chrome ==========[/color] CHR - homepage: {make_chrome_default_for_user:true},variations_seed:Cig0MTljNTI5YmVjYTMxMDQzODdlMmUyNTU4YmM1YzA3NTIyMzNjM2U2EpoBCghBc3luY0RucxjEyeaPBTgAQgpTeXN0ZW1EbnNBSg4KClN5c3RlbURuc0EQGUoOCgpTeXN0ZW1EbnNCEBlKGAoTQXN5bmNEbnNOb0ZhbGxiYWNrQRCQA0oYChNBc3luY0Ruc05vRmFsbGJhY2tCEJADSg0KCUFzeW5jRG5zQRBLSg0KCUFzeW5jRG5zQhBLUggSBDI2LiooAxJuCghBc3luY0RucxjEyeaPBTgAQgpTeXN0ZW1EbnNBSg4KClN5c3RlbURuc0EQGUoOCgpTeXN0ZW1EbnNCEBlKDQoJQXN5bmNEbnNBEBlKDQoJQXN5bmNEbnNCEBlSEBIEMjkuKiAAIAEoACgBKAISagoIQXN5bmNEbnMYxIzDjgU4AEIKU3lzdGVtRG5zQUoOCgpTeXN0ZW1EbnNBEDJKDgoKU3lzdGVtRG5zQhAySg0KCUFzeW5jRG5zQRAySg0KCUFzeW5jRG5zQhAyUgwSBDI4LiogAigBKAISPAoIQXN5bmNEbnMYxMnmjwU4AEIKU3lzdGVtRG5zQUoOCgpTeXN0ZW1EbnNBEAFSDBIEMjYuKiADKAEoAhKPAQoaQXV0b2NvbXBsZXRlRHluYW1pY1RyaWFsXzAYgMPQjAU4AUITTGl2ZVNwZWxsaW5nQ29udHJvbEogChZMaXZlU3BlbGxpbmdFeHBlcmltZW50ELYHGIaEygFKHAoTTGl2ZVNwZWxsaW5nQ29udHJvbBAyGIeEygFSFBIEMjYuKiAAIAEgAiADKAAoASgCEtIBChpBdXRvY29tcGxldGVEeW5hbWljVHJpYWxfMRiAhNyPBTgBQg5EZWZhdWx0Q29udHJvbEodChREaXNhYmxlZFByb3ZpZGVyc18xNhAKGJeEygFKGwoSTmF2U3VnZ2VzdERlbW90aW9uEAoYmYTKAUoiChlOYXZTdWdnZXN0RGVtb3Rpb25Db250cm9sEAoYmoTKAUoYCg5EZWZhdWx0Q29udHJvbBDiBxibhMoBUhwSDDI2LjAuMTQxMC4xORoEMjguKiADKAAoASgCWI3Qj48CEn4KGkF1dG9jb21wbGV0ZUR5bmFtaWNUcmlhbF8yGICn4Y8FOAFCDkRlZmF1bHRDb250cm9sSh0KFEVuYWJsZUN1cnNvclBvc2l0aW9uEAEYlYTKAUoXCg5EZWZhdWx0Q29udHJvbBAEGJaEygFSEBIEMjguKiABIAIoACgBKAISygEKGkF1dG9jb21wbGV0ZUR5bmFtaWNUcmlhbF8zGICE3I8FOAFCDkRlZmF1bHRDb250cm9sSiEKGEVuYWJsZVplcm9TdWdnZXN0UXVlcmllcxAAGJGEygFKHgoVRW5hYmxlWmVyb1N1Z2dlc3RVcmxzEAAYkoTKAUolChxFbmFibGVaZXJvU3VnZ2VzdFF1ZXJpZXNVcmxzEAAYk4TKAUoYCg5EZWZhdWx0Q29udHJvbBDoBxiUhMoBUhASBDI5LiogACABKAAoASgCEpIBChhDYWNoZVNlbnNpdGl2aXR5QW5hbHlzaXMYxMfyjgU4AEICTm9KDAoIQ29udHJvbEEQBUoMCghDb250cm9sQhAFSggKBDEwMEEQBUoICgQxMDBCEAVKCAoEMjAwQRAFSggKBDIwMEIQBUoICgQ0MDBBEAVKCAoENDAwQhAFSgYKAk5vEDxSChIEMjguKiACKAQSmgEKGENhY2hlU2Vuc2l0aXZpdHlBbmFseXNpcxjEyv2KBTgAQgJOb0oGCgJObxAkSgwKCENvbnRyb2xBEAhKDAoIQ29udHJvbEIQCEoICgQxMDBBEAhKCAoEMTAwQhAISggKBDIwMEEQCEoICgQyMDBCEAhKCAoENDAwQRAISggKBDQwMEIQCFISEgQyNS4qIAAgASACKAAoASgCEp0BChhDYWNoZVNlbnNpdGl2aXR5QW5hbHlzaXMYxLLTigU4AEICTm9KBwoCTm8Q4AdKDAoIQ29udHJvbEEQAUoMCghDb250cm9sQhABSggKBDEwMEEQAUoICgQxMDBCEAFKCAoEMjAwQRABSggKBDIwMEIQAUoICgQ0MDBBEAFKCAoENDAwQhABUhQIgKe+igUSBDI1LiogAygAKAEoAhJICg9EM0QxMUV4cGVyaW1lbnQYgJKIlgU4AUIIRGlzYWJsZWRKDAoIRGlzYWJsZWQQAEoLCgdFbmFibGVkEGRSCBIEMjkuKigAElQKG0RhdGFDb21wcmVzc2lvblByb3h5Um9sbG91dBjEgpe0BTgBQgdFbmFibGVkSgwKCERpc2FibGVkEABKDAoHRW5hYmxlZBDoB1IIIAAgASACKAQSUQobRGF0YUNvbXByZXNzaW9uUHJveHlSb2xsb3V0GMSCl7QFOAFCCERpc2FibGVkSg0KCERpc2FibGVkEN4HSgsKB0VuYWJsZWQQClIEIAMoBBJUChtEYXRhQ29tcHJlc3Npb25Qcm94eVJvbGxvdXQYxIKXtAU4AUIHRW5hYmxlZEoMCghEaXNhYmxlZBAASgwKB0VuYWJsZWQQ6AdSCCAAIAEgAigFElEKG0RhdGFDb21wcmVzc2lvblByb3h5Um9sbG91dBjEgpe0BTgBQghEaXNhYmxlZEoMCghEaXNhYmxlZBAASgwKB0VuYWJsZWQQ6AdSBCADKAUSRAoRRG5zUHJvYmUtQXR0ZW1wdHMYgLWNlgU4AUIHZGVmYXVsdEoLCgdkZWZhdWx0EFpKBQoBMRAKUgoSBDI1LiogACABEkcKD0Ruc1Byb2JlLUVuYWJsZRiAtY2WBTgBQgdkaXNhYmxlSgsKB2Rpc2FibGUQAEoKCgZlbmFibGUQZFIKEgQyNS4qIAAgARJjCiNVTUEtRHluYW1pYy1CaW5hcnktVW5pZm9ybWl0eS1UcmlhbBiAnJKlBTgBQgdkZWZhdWx0ShAKB2RlZmF1bHQQARiptskBShEKCGdyb3VwXzAxEAEYqrbJAVIGIAAgASACEl8KI1VNQS1EeW5hbWljLUJpbmFyeS1Vbmlmb3JtaXR5LVRyaWFsGICckqUFOAFCB2RlZmF1bHRKEAoHZGVmYXVsdBBjGKm2yQFKEQoIZ3JvdXBfMDEQARiqtskBUgIgAxJXChRGb3JjZUNvbXBvc2l0aW5nTW9kZRiAkoiWBTgBQgdkaXNhYmxlSgsKB2Rpc2FibGUQZEoLCgdlbmFibGVkEABKCgoGdGhyZWFkEABSCBIEMjQuKigCElcKFEZvcmNlQ29tcG9zaXRpbmdNb2RlGICSiJYFOAFCB2Rpc2FibGVKCwoHZGlzYWJsZRAASgsKB2VuYWJsZWQQAEoKCgZ0aHJlYWQQZFIIEgQyOC4qKAESWQoURm9yY2VDb21wb3NpdGluZ01vZGUYgJKIlgU4AUIHZGlzYWJsZUoLCgdkaXNhYmxlEGRKCwoHZW5hYmxlZBAASgoKBnRocmVhZBAAUgoaBDI3LiogAygBElcKFEZvcmNlQ29tcG9zaXRpbmdNb2RlGICSiJYFOAFCB2Rpc2FibGVKCwoHZGlzYWJsZRAASgsKB2VuYWJsZWQQAEoKCgZ0aHJlYWQQZFIIEgQyNC4qKAASWQoURm9yY2VDb21wb3NpdGluZ01vZGUYgJKIlgU4AUIHZGlzYWJsZUoLCgdkaXNhYmxlEABKCwoHZW5hYmxlZBAySgoKBnRocmVhZBAyUgoSBDI0LiogAygAErcBCglHb29nbGVOb3c4AUIHRGVmYXVsdEoLCgdEZWZhdWx0EGRKCgoGRW5hYmxlEABKCwoHQ29udHJvbBAASjMKD0Rpc2FibGVkVmlhRmxhZxAAKh5kaXNhYmxlLWdvb2dsZS1ub3ctaW50ZWdyYXRpb25KMQoORW5hYmxlZFZpYUZsYWcQACodZW5hYmxlLWdvb2dsZS1ub3ctaW50ZWdyYXRpb25SESAAIAEoACgBKAMyBWVuLVVTEosBCg1Ib3N0Q2FjaGVTaXplGMTNiIcFOABCB0RlZmF1bHRKCwoHRGVmYXVsdBAASggKBDEwMEEQCkoICgQxMDBCEApKCAoEMzAwQRAKSggKBDMwMEIQCkoJCgUxMDAwQRAKSgkKBTEwMDBCEApKCQoFMzAwMEEQCkoJCgUzMDAwQhAKUggSBDI1LiooAxKTAQoNSG9zdENhY2hlU2l6ZRjErPeHBTgAQgdEZWZhdWx0SgsKB0RlZmF1bHQQAEoICgQxMDBBEApKCAoEMTAwQhAKSggKBDMwMEEQCkoICgQzMDBCEApKCQoFMTAwMEEQCkoJCgUxMDAwQhAKSgkKBTMwMDBBEApKCQoFMzAwMEIQClIQEgQyNS4qIAAgASgAKAEoAhJECg1JbmZpbml0ZUNhY2hlGMS0jZYFOAFCAk5vSgcKAk5vENQHSgcKA1llcxAKSgsKB0NvbnRyb2wQClIIIAIoACgBKAISRgoNSW5maW5pdGVDYWNoZRjEtI2WBTgBQgJOb0oHCgJObxCEB0oHCgNZZXMQMkoLCgdDb250cm9sEDJSCiAAIAEoACgBKAISRAoNSW5maW5pdGVDYWNoZRjEtI2WBTgBQgJOb0oHCgJObxDmB0oHCgNZZXMQAUoLCgdDb250cm9sEAFSCCADKAAoASgCEt8ECgxJbnN0YW50RHVtbXkYgITcjwU4AUIMRGVmYXVsdEdyb3VwSi8KIUR1bW15R3JvdXAxIGNoYW5uZWw6c3RhYmxlIG1vZHM6MRABGMeFygEgx4XKAUovCiFEdW1teUdyb3VwMiBjaGFubmVsOnN0YWJsZSBtb2RzOjEQARjIhcoBIMiFygFKLwohRHVtbXlHcm91cDMgY2hhbm5lbDpzdGFibGUgbW9kczoxEAEYyYXKASDJhcoBSi8KIUR1bW15R3JvdXA0IGNoYW5uZWw6c3RhYmxlIG1vZHM6MRABGMqFygEgyoXKAUovCiFEdW1teUdyb3VwNSBjaGFubmVsOnN0YWJsZSBtb2RzOjkQCRjLhcoBIMuFygFKLwohRHVtbXlHcm91cDYgY2hhbm5lbDpzdGFibGUgbW9kczo5EAkYzIXKASDMhcoBSi8KIUR1bW15R3JvdXA3IGNoYW5uZWw6c3RhYmxlIG1vZHM6ORAJGM2FygEgzYXKAUovCiFEdW1teUdyb3VwOCBjaGFubmVsOnN0YWJsZSBtb2RzOjkQCRjOhcoBIM6FygFKMQojRHVtbXlHcm91cDkgY2hhbm5lbDpzdGFibGUgbW9kczoxMDAQZBjPhcoBIM+FygFKMgokRHVtbXlHcm91cDEwIGNoYW5uZWw6c3RhYmxlIG1vZHM6MTAwEGQY0IXKASDQhcoBSioKG0R1bW15UGFkZGluZyBjaGFubmVsOnN0YWJsZRD4BRjRhcoBINGFygFKEAoMRGVmYXVsdEdyb3VwEABSDBIEMjcuKiADKAAoARKkAgoPSW5zdGFudEV4dGVuZGVkGIDB\/5AFOAFCDERlZmF1bHRHcm91cEo+Ci9Hcm91cDEgdXNlX3JlbW90ZV9udHBfb25fc3RhcnR1cDoxIGNoYW5uZWw6YmV0YRD6ARi9hcoBIL2FygFKRwo4R3JvdXAyIGVzcHY6MjA1IHVzZV9yZW1vdGVfbnRwX29uX3N0YXJ0dXA6MSBjaGFubmVsOmJldGEQ+gEYvoXKASC+hcoBSiQKFUNvbnRyb2wxIGNoYW5uZWw6YmV0YRD6ARi\/hcoBIL+FygFKJAoVQ29udHJvbDIgY2hhbm5lbDpiZXRhEPoBGMCFygEgwIXKAUoQCgxEZWZhdWx0R3JvdXAQAFIOEgQyOS4qIAIoACgBKANY2o+ihwkSpgIKD0luc3RhbnRFeHRlbmRlZBiA6r2OBTgBQgxEZWZhdWx0R3JvdXBKQAoxR3JvdXAxIHVzZV9yZW1vdGVfbnRwX29uX3N0YXJ0dXA6MSBjaGFubmVsOmNhbmFyeRD6ARjng8oBIOeDygFKSQo6R3JvdXAyIGVzcHY6MjA1IHVzZV9yZW1vdGVfbnRwX29uX3N0YXJ0dXA6MSBjaGFubmVsOmNhbmFyeRD6ARiEhMoBIISEygFKJgoXQ29udHJvbDEgY2hhbm5lbDpjYW5hcnkQ+gEY6IPKASDog8oBSiYKF0NvbnRyb2wyIGNoYW5uZWw6Y2FuYXJ5EPoBGIKEygEggoTKAUoQCgxEZWZhdWx0R3JvdXAQAFIOEgQyOC4qIAAoACgBKAMSsQIKD0luc3RhbnRFeHRlbmRlZBiAhNyPBTgBQgxEZWZhdWx0R3JvdXBKJQoXQ29udHJvbDEgbTI5ZGV2MjpuYXRpdmUQARjWhcoBINaFygFKJQoXQ29udHJvbDIgbTI5ZGV2MjpuYXRpdmUQARjXhcoBINeFygFKPwoxR3JvdXAxIG0yOWRldjI6bmF0aXZlIHVzZV9yZW1vdGVfbnRwX29uX3N0YXJ0dXA6MRABGNiFygEg2IXKAUpICjpHcm91cDIgbTI5ZGV2MjpuYXRpdmUgdXNlX3JlbW90ZV9udHBfb25fc3RhcnR1cDoxIGVzcHY6MjA1EAEY2YXKASDZhcoBShAKDERlZmF1bHRHcm91cBAAUhcSCTI5LjAuMTUzNRoEMjkuKiABKAAoA1jpib\/HChKLAwoPSW5zdGFudEV4dGVuZGVkGICE3I8FOAFCDERlZmF1bHRHcm91cEpRCkNHcm91cDEgZXNwdjoyMDUgdXNlX3JlbW90ZV9udHBfb25fc3RhcnR1cDoxIGNoYW5uZWw6c3RhYmxlIERJU0FCTEVEEAEYwYXKASDBhcoBSlEKQ0dyb3VwMiBlc3B2OjIwNSB1c2VfcmVtb3RlX250cF9vbl9zdGFydHVwOjEgY2hhbm5lbDpzdGFibGUgRElTQUJMRUQQCRjFhcoBIMWFygFKJgoXUGFkZGluZzEgY2hhbm5lbDpzdGFibGUQ6gMYwoXKASDChcoBSiUKF0NvbnRyb2wxIGNoYW5uZWw6c3RhYmxlEAEYw4XKASDDhcoBSiUKF0NvbnRyb2wyIGNoYW5uZWw6c3RhYmxlEAkYxoXKASDGhcoBSiYKF1BhZGRpbmcyIGNoYW5uZWw6c3RhYmxlEOoDGMSFygEgxIXKAUoQCgxEZWZhdWx0R3JvdXAQAFIMEgQyNy4qIAMoACgBEo4CChZJbnRlcnN0aXRpYWxNYWx3YXJlMzEwGMDpw5MFOAFCB0RlZmF1bHRKFwoTY29uZDFNYWx3YXJlQ29udHJvbBADShcKE2NvbmQyTWFsd2FyZU5vQnJhbmQQA0oXChNjb25kNU1hbHdhcmVPbmVTdGVwEANKFwoTY29uZDdNYWx3YXJlRmVhck1zZxADShkKFWNvbmQ5TWFsd2FyZUNvbGxhYk1zZxADShkKFWNvbmQxMU1hbHdhcmVRdWVzdGlvbhADShcKE2NvbmQxM01hbHdhcmVHb0JhY2sQA0oMCgdEZWZhdWx0ELMBUiIIwNmjjAUSBDI5LiooACgBKAIoAzIFZW4tVVMyBWVuLUdCEpcCChdJbnRlcnN0aXRpYWxQaGlzaGluZzU2NBjA6cOTBTgBQgdEZWZhdWx0ShgKFGNvbmQzUGhpc2hpbmdDb250cm9sEANKGAoUY29uZDRQaGlzaGluZ05vQnJhbmQQA0oYChRjb25kNlBoaXNoaW5nT25lU3RlcBADShgKFGNvbmQ4UGhpc2hpbmdGZWFyTXNnEANKGwoXY29uZDEwUGhpc2hpbmdDb2xsYWJNc2cQA0oaChZjb25kMTJQaGlzaGluZ1F1ZXN0aW9uEANKGAoUY29uZDE0UGhpc2hpbmdHb0JhY2sQA0oMCgdEZWZhdWx0ELMBUiIIwNmjjAUSBDI5LiooACgBKAIoAzIFZW4tVVMyBWVuLUdCEqQCChJJbnRlcnN0aXRpYWxTU0w1MTcYwOnDkwU4AUIHRGVmYXVsdEoZChVDb25kaXRpb24xNVNTTENvbnRyb2wQA0oZChVDb25kaXRpb24xNlNTTEZpcmVmb3gQA0oeChpDb25kaXRpb24xN1NTTEZhbmN5RmlyZWZveBADShoKFkNvbmRpdGlvbjE4U1NMTm9JbWFnZXMQA0obChdDb25kaXRpb24xOVNTTFBvbGljZW1hbhADShsKF0NvbmRpdGlvbjIwU1NMU3RvcGxpZ2h0EANKGAoUQ29uZGl0aW9uMjFTU0xCYWRndXkQA0oMCgdEZWZhdWx0ELMBUikIwNmjjAUSCzI5LjAuMTU0My4qKAAoASgCKAMyBWVuLVVTMgVlbi1HQhJRChFNYW5hZ2VkTW9kZUxhdW5jaBiA88eSBTgBQghJbmFjdGl2ZUoKCgZBY3RpdmUQZEoMCghJbmFjdGl2ZRAAUhASBDI5LiogACABKAAoASgCEk0KEU1hbmFnZWRNb2RlTGF1bmNoGIDzx5IFOAFCCEluYWN0aXZlSgoKBkFjdGl2ZRBkSgwKCEluYWN0aXZlEABSDBIEMjkuKiAAIAEoAxKwAgoYTW9zdFZpc2l0ZWRUaWxlUGxhY2VtZW50GICtmo0FOAFCB0RlZmF1bHRKFgoST25lRWlnaHRfQV9GbGlwcGVkEANKFgoST25lRWlnaHRfQl9GbGlwcGVkEANKFgoST25lRWlnaHRfQ19GbGlwcGVkEANKFgoST25lRWlnaHRfRF9GbGlwcGVkEANKFQoRT25lRm91cl9BX0ZsaXBwZWQQA0oVChFPbmVGb3VyX0JfRmxpcHBlZBADShUKEU9uZUZvdXJfQ19GbGlwcGVkEANKFQoRT25lRm91cl9EX0ZsaXBwZWQQA0oLCgdDb250cm9sEANKFAoQRG9udFNob3dPcGVuVGFicxADSgsKB0RlZmF1bHQQRlIXEgsyOC4wLjE0OTYuMCABKAAoASgCKAMSlAEKFE1vdXNlRXZlbnRQcmVjb25uZWN0GMS0jZYFOABCCERpc2FibGVkSg0KCU1vdXNlRG93bhAKSg0KCU1vdXNlT3ZlchAAShIKDlRhcFVuY29uZmlybWVkEABKCwoHVGFwRG93bhAASgsKB0NvbnRyb2wQCkoMCghEaXNhYmxlZBBQUhASBDI5LiogACABKAAoASgCEl0KDE5ld01lbnVTdHlsZRiA0J+NBTgBQgdEZWZhdWx0SgsKB0RlZmF1bHQQAEoNCghOZXdTdHlsZRDmB0oMCghPbGRTdHlsZRACUhISBDI2LioaBDI3LiogAygAKAMSfgoMTmV3TWVudVN0eWxlGICn4Y8FOAFCB0RlZmF1bHRKCwoHRGVmYXVsdBA8SgwKCENvbXBhY3QxEApKDAoIQ29tcGFjdDIQCkoSCg5IaWdoZXJDb250cmFzdBAKShAKDENvbnRyb2xHcm91cBAKUg4SBDI4LiogASAAKAAoAxJ+CgxOZXdNZW51U3R5bGUYgP6ikgU4AUIHRGVmYXVsdEoLCgdEZWZhdWx0EGBKDAoIQ29tcGFjdDEQAUoMCghDb21wYWN0MhABShIKDkhpZ2hlckNvbnRyYXN0EAFKEAoMQ29udHJvbEdyb3VwEAFSDhIEMjkuKiADIAIoACgDElcKDE5ld1RhYkJ1dHRvbhiAtY2WBTgBQgdkZWZhdWx0SgsKB2RlZmF1bHQQYkoLCgdDb250cm9sEAFKCAoEUGx1cxABUhISDDIxLjAuMTE4MC4xNSADKAASzQEKHk9tbmlib3hSZXBsYWNlSFVQQW5kTmV3U2NvcmluZxjAhbOQBTgBQghTdGFuZGFyZEoMCghTdGFuZGFyZBA8Sg0KCVN0YW5kYXJkMhAKSh0KGUhRUC1wb3N0cGVyaW9kLVJlcGxhY2VIVVAQCkoOCgpOZXdTY29yaW5nEApKNAowSFFQLXBvc3RwZXJpb2QtUmVwbGFjZUhVUF9OZXctcG9zdHBlcmlvZC1TY29yaW5nEApSFwjAn4uHBRILMjguMC4xNDk5LiogASACEmkKF09tbmlib3hTaG9ydGN1dHNTY29yaW5nGMTClpcFOAFCCFN0YW5kYXJkSgwKCFN0YW5kYXJkEFpKFQoRTWF4UmVsZXZhbmNlXzEzOTkQClIXCMSAro4FEgsyOS4wLjE1NDcuMCABIAISZQoQT21uaWJveFN0b3BUaW1lchjA0ZmTBTgBQghTdGFuZGFyZEoSCghTdGFuZGFyZBD0Axi3hcoBShYKDFVzZVN0b3BUaW1lchD0Axi4hcoBUhMIwMzUiwUSCzI4LjAuMTQ4OC4wEmYKF1ByZXJlbmRlckxvY2FsUHJlZGljdG9yGMSHoYwFOABCCERpc2FibGVkSg0KCERpc2FibGVkENQHSgsKB0VuYWJsZWQQCkoLCgdDb250cm9sEApSEBIEMjUuKiADIAIoACgBKAISZgoXUHJlcmVuZGVyTG9jYWxQcmVkaWN0b3IYxLSNlgU4AEIIRGlzYWJsZWRKDAoIRGlzYWJsZWQQZEoMCgdFbmFibGVkEKAGSgsKB0NvbnRyb2wQZFIQEgQyNS4qIAAgASgAKAEoAhJwCi5QcmVyZW5kZXJMb2NhbFByZWRpY3Rvck1heENvbmN1cnJlbnRQcmVyZW5kZXJzGMS0jZYFOAFCATFKBQoBMRAUSgUKATIQFEoFCgEzEBRKBQoBNBAUSgUKATUQFFIQEgQyOS4qIAAgASgAKAEoAhJxCjtQcmVyZW5kZXJMb2NhbFByZWRpY3RvclByZXJlbmRlclByaW9yaXR5SGFsZkxpZmVUaW1lU2Vjb25kcxjEtI2WBTgBQgEwSgUKATAQMkoGCgIzMBAZSgYKAjYwEBlSEBIEMjkuKiAAIAEoACgBKAISbgoqUHJlcmVuZGVyTG9jYWxQcmVkaWN0b3JQcmVyZW5kZXJUVExTZWNvbmRzGMS0jZYFOAFCAzE4MEoHCgMxODAQNEoHCgMxMjAQEEoHCgMyNDAQEEoGCgI2MBAQUhASBDI5LiogACABKAAoASgCEqUBCg9Qcm9ncmVzc2l2ZVNjYW4YxLSNlgU4AUIIRGlzYWJsZWRKFQoRMzNQZXJjZW50XzRNaW5NYXgQHkoVChE1MFBlcmNlbnRfNE1pbk1heBAeShUKETUwUGVyY2VudF84TWluTWF4EB5KFgoSMTAwUGVyY2VudF84TWluTWF4EB5KDAoIRnVsbFNjYW4QHkoNCghEaXNhYmxlZBDSBlIGIAAgASgDEpkBCgRRVUlDGMTnpogFOABCCERpc2FibGVkSgsKB0VuYWJsZWQQCkoLCgdDb250cm9sEApKDAoIRGlzYWJsZWQQUEoeCg1FbmFibGVkQnlGbGFnEAAqC2VuYWJsZS1xdWljSiAKDkRpc2FibGVkQnlGbGFnEAAqDGRpc2FibGUtcXVpY1IVEgsyOS4wLjE1NDYuMCAAKAAoASgCEjYKDlNCSW50ZXJzdGl0aWFsGMDSjYkFOAFCAlYxSgYKAlYxEAFKBgoCVjIQY1IIKAAoASgCKAMSqgEKGFNlbmRGZWVkYmFja0xpbmtMb2NhdGlvbjgBQgdkZWZhdWx0ShAKB2RlZmF1bHQQKBiphcoBShAKB2NvbnRyb2wQDxj4hMoBShEKCGFsdC10ZXh0EA8Y\/ITKAUoVCgxhbHQtbG9jYXRpb24QDxiChcoBSh4KFWFsdC10ZXh0LWFuZC1sb2NhdGlvbhAPGIiFygFSFRILMjcuMC4xNDUzLiogAigAKAIoARKmAQoYU2VuZEZlZWRiYWNrTGlua0xvY2F0aW9uOAFCB2RlZmF1bHRKEAoHZGVmYXVsdBAoGKmFygFKEAoHY29udHJvbBAPGPmEygFKEQoIYWx0LXRleHQQDxj\/hMoBShUKDGFsdC1sb2NhdGlvbhAPGIWFygFKHgoVYWx0LXRleHQtYW5kLWxvY2F0aW9uEA8Yi4XKAVIREgsyNy4wLjE0NTMuKiACKAMSqgEKGFNlbmRGZWVkYmFja0xpbmtMb2NhdGlvbjgBQgdkZWZhdWx0ShAKB2RlZmF1bHQQKBiphcoBShAKB2NvbnRyb2wQDxj4hMoBShEKCGFsdC10ZXh0EA8Y+oTKAUoVCgxhbHQtbG9jYXRpb24QDxiAhcoBSh4KFWFsdC10ZXh0LWFuZC1sb2NhdGlvbhAPGIaFygFSFRILMjcuMC4xNDUzLiogASgAKAIoARKmAQoYU2VuZEZlZWRiYWNrTGlua0xvY2F0aW9uOAFCB2RlZmF1bHRKEAoHZGVmYXVsdBAoGKmFygFKEAoHY29udHJvbBAPGPmEygFKEQoIYWx0LXRleHQQDxj9hMoBShUKDGFsdC1sb2NhdGlvbhAPGIOFygFKHgoVYWx0LXRleHQtYW5kLWxvY2F0aW9uEA8YiYXKAVIREgsyNy4wLjE0NTMuKiABKAMSqgEKGFNlbmRGZWVkYmFja0xpbmtMb2NhdGlvbjgBQgdkZWZhdWx0ShAKB2RlZmF1bHQQPBiphcoBShAKB2NvbnRyb2wQChj4hMoBShEKCGFsdC10ZXh0EAoY+4TKAUoVCgxhbHQtbG9jYXRpb24QChiBhcoBSh4KFWFsdC10ZXh0LWFuZC1sb2NhdGlvbhAKGIeFygFSFRILMjcuMC4xNDUzLiogAygAKAIoARKmAQoYU2VuZEZlZWRiYWNrTGlua0xvY2F0aW9uOAFCB2RlZmF1bHRKEAoHZGVmYXVsdBA8GKmFygFKEAoHY29udHJvbBAKGPmEygFKEQoIYWx0LXRleHQQChj+hMoBShUKDGFsdC1sb2NhdGlvbhAKGISFygFKHgoVYWx0LXRleHQtYW5kLWxvY2F0aW9uEAoYioXKAVIREgsyNy4wLjE0NTMuKiADKAMSdQoUU2hvd0FwcExhdW5jaGVyUHJvbW84AUIHRGVmYXVsdEogChdTaG93UHJvbW9VbnRpbERpc21pc3NlZBAyGJ6GygFKGwoSUmVzZXRTaG93UHJvbW9QcmVmEDIYn4bKAUoLCgdEZWZhdWx0EABSBiAAIAEoABJiChNTaG93UHJvZmlsZVN3aXRjaGVyGMDK4IoFOAFCB2RlZmF1bHRKCwoHZGVmYXVsdBBQSgsKB2NvbnRyb2wQCkoOCgpBbHdheXNTaG93EApSEBIEMjYuKiAAIAEoACgBKAISVwoPU2lkZWxvYWRXaXBlb3V0GMScnYsFOAFCCERpc2FibGVkSgwKCERpc2FibGVkEABKCwoHRW5hYmxlZBBkUhcSCzI1LjAuMTM2MC4qIAAgASACIAMoABJ3ChpTaWduSW5Ub0Nocm9tZUNvbmZpcm1hdGlvbhjAyuCKBTgBQgdkZWZhdWx0SgsKB2RlZmF1bHQQUEoUChBjb250cm9sX0RJU0FCTEVEEApKEwoPQnViYmxlX0RJU0FCTEVEEApSEBIEMjYuKiAAIAEoACgBKAIShAEKEFNpbXBsZUNhY2hlVHJpYWwYxLSNlgU4AUIMRXhwZXJpbWVudE5vShAKDEV4cGVyaW1lbnRObxBkShEKDUV4cGVyaW1lbnRZZXMQAEoSCg5FeHBlcmltZW50WWVzMhAAShUKEUV4cGVyaW1lbnRDb250cm9sEABSChIEMjguKiACKAQShgEKEFNpbXBsZUNhY2hlVHJpYWwYxLSNlgU4AUIMRXhwZXJpbWVudE5vShAKDEV4cGVyaW1lbnRObxAAShEKDUV4cGVyaW1lbnRZZXMQUEoSCg5FeHBlcmltZW50WWVzMhAKShUKEUV4cGVyaW1lbnRDb250cm9sEApSDBIEMjguKiAAIAEoBBKVAwoeU3BlY3VsYXRpdmVSZXNvdXJjZVByZWZldGNoaW5nGICc44oFOAFCCERpc2FibGVkSgwKCERpc2FibGVkEChKEAoMTGVhcm5pbmdIb3N0EApKDwoLTGVhcm5pbmdVUkwQCkoMCghMZWFybmluZxAKShMKD1ByZWZldGNoaW5nSG9zdBAKShIKDlByZWZldGNoaW5nVVJMEApKDwoLUHJlZmV0Y2hpbmcQCkocChhQcmVmZXRjaGluZ0xvd0NvbmZpZGVuY2UQAEodChlQcmVmZXRjaGluZ0hpZ2hDb25maWRlbmNlEABKHAoYUHJlZmV0Y2hpbmdNb3JlUmVzb3VyY2VzEABKEwoPTGVhcm5pbmdTbWFsbERCEABKFgoSUHJlZmV0Y2hpbmdTbWFsbERCEABKIwofUHJlZmV0Y2hpbmdTbWFsbERCTG93Q29uZmlkZW5jZRAASiQKIFByZWZldGNoaW5nU21hbGxEQkhpZ2hDb25maWRlbmNlEABSFRILMjUuMC4xMzY0LiogAigAKAEoAhKXAwoeU3BlY3VsYXRpdmVSZXNvdXJjZVByZWZldGNoaW5nGICc44oFOAFCCERpc2FibGVkSgwKCERpc2FibGVkEChKEAoMTGVhcm5pbmdIb3N0EApKDwoLTGVhcm5pbmdVUkwQCkoMCghMZWFybmluZxAKShMKD1ByZWZldGNoaW5nSG9zdBAKShIKDlByZWZldGNoaW5nVVJMEApKDwoLUHJlZmV0Y2hpbmcQCkocChhQcmVmZXRjaGluZ0xvd0NvbmZpZGVuY2UQAEodChlQcmVmZXRjaGluZ0hpZ2hDb25maWRlbmNlEABKHAoYUHJlZmV0Y2hpbmdNb3JlUmVzb3VyY2VzEABKEwoPTGVhcm5pbmdTbWFsbERCEABKFgoSUHJlZmV0Y2hpbmdTbWFsbERCEABKIwofUHJlZmV0Y2hpbmdTbWFsbERCTG93Q29uZmlkZW5jZRAASiQKIFByZWZldGNoaW5nU21hbGxEQkhpZ2hDb25maWRlbmNlEABSFxILMjUuMC4xMzY0LiogACABKAAoASgCElIKClNwZWxsY2hlY2sYxNu0jQU4AUIHRGVmYXVsdEoLCgdEZWZhdWx0EGRKDwoLU3VnZ2VzdGlvbnMQAFIVEgsyNi4wLjE0MDMuMCACIAEgACgAElQKClNwZWxsY2hlY2sYxNu0jQU4AUIHRGVmYXVsdEoLCgdEZWZhdWx0EGRKDwoLU3VnZ2VzdGlvbnMQAFIXEgsyNi4wLjE0MDMuMCADIAIgASgCKAMSTgoKU3BlbGxjaGVjaxjE27SNBTgBQgdEZWZhdWx0SgsKB0RlZmF1bHQQZEoPCgtTdWdnZXN0aW9ucxAAUhESCzI2LjAuMTQwMy4wIAMoABJPCg1FbmFibGVTdGFnZTNEGICI\/oYFOAFCB2VuYWJsZWRKDAoHZW5hYmxlZBC2B0oPCgtibGFja2xpc3RlZBAyUg4SBDIyLiogACABIAIoABJRCg1FbmFibGVTdGFnZTNEGICI\/oYFOAFCB2VuYWJsZWRKDAoHZW5hYmxlZBDoB0oPCgtibGFja2xpc3RlZBAAUhASBDIyLioaBDIyLiogAygAEmgKDUVuYWJsZVN0YWdlM0QYgN+\/iQU4AUIPZW5hYmxlZF9kZWZhdWx0ShMKD2VuYWJsZWRfZGVmYXVsdBAASgwKB2VuYWJsZWQQ6AdKDwoLYmxhY2tsaXN0ZWQQAFIKEgQyMy4qIAMoABKrAgoLVGFiRXZpY3Rpb24YgP6ikgU4AUIHRGVmYXVsdEoLCgdEZWZhdWx0EABKCwoHQ29udHJvbBAKShEKDU1lbW9yeUtlZXBBbGwQAUoTCg9NZW1vcnlFdmljdEhhbGYQCkoTCg9NZW1vcnlLZWVwVGhyZWUQCkoUChBNZW1vcnlFdmljdFRocmVlEApKGAoUQmFja2dyb3VuZGluZ0tlZXBBbGwQCkoaChZCYWNrZ3JvdW5kaW5nRXZpY3RIYWxmEApKGAoUQmFja2dyb3VuZGluZ0tlZXBPbmUQCkobChdCYWNrZ3JvdW5kaW5nRXZpY3RUaHJlZRAKShIKDk5vUHJlcmVuZGVyaW5nEApKDwoLTm9RdWlja2JhY2sQClIMEgQyOS4qIAAgAigFEk4KE1Rlc3QwUGVyY2VudERlZmF1bHQYgJySpQU4AUIHZGVmYXVsdEoLCgdkZWZhdWx0EABKDAoIZ3JvdXBfMDEQZEoLCgdkb2dmb29kEAAS2gEKHFVNQS1EeW5hbWljLVVuaWZvcm1pdHktVHJpYWwYgJySpQU4AUIHRGVmYXVsdEoUCgZHcm91cDEQARi\/tskBIL+2yQFKFAoGR3JvdXAyEAkYwLbJASDAtskBShUKBkdyb3VwMxDqAxjBtskBIMG2yQFKFAoGR3JvdXA0EAEYwrbJASDCtskBShQKBkdyb3VwNRAJGMO2yQEgw7bJAUoVCgZHcm91cDYQ6gMYxLbJASDEtskBShUKB0RlZmF1bHQQABjFtskBIMW2yQFSDBIEMjcuKiADKAAoARK9AQofVU1BLVVuaWZvcm1pdHktVHJpYWwtMTAtUGVyY2VudBiAnJKlBTgBQgdkZWZhdWx0SgsKB2RlZmF1bHQQAUoMCghncm91cF8wMRABSgwKCGdyb3VwXzAyEAFKDAoIZ3JvdXBfMDMQAUoMCghncm91cF8wNBABSgwKCGdyb3VwXzA1EAFKDAoIZ3JvdXBfMDYQAUoMCghncm91cF8wNxABSgwKCGdyb3VwXzA4EAFKDAoIZ3JvdXBfMDkQARKmDwoeVU1BLVVuaWZvcm1pdHktVHJpYWwtMS1QZXJjZW50GICckqUFOAFCB2RlZmF1bHRKEAoHZGVmYXVsdBABGKC1yQFKEQoIZ3JvdXBfMDEQARihtckBShEKCGdyb3VwXzAyEAEYorXJAUoRCghncm91cF8wMxABGKO1yQFKEQoIZ3JvdXBfMDQQARiktckBShEKCGdyb3VwXzA1EAEYpbXJAUoRCghncm91cF8wNhABGKa1yQFKEQoIZ3JvdXBfMDcQARintckBShEKCGdyb3VwXzA4EAEYqLXJAUoRCghncm91cF8wORABGKm1yQFKEQoIZ3JvdXBfMTAQARiqtckBShEKCGdyb3VwXzExEAEYq7XJAUoRCghncm91cF8xMhABGKy1yQFKEQoIZ3JvdXBfMTMQARittckBShEKCGdyb3VwXzE0EAEYrrXJAUoRCghncm91cF8xNRABGK+1yQFKEQoIZ3JvdXBfMTYQARiwtckBShEKCGdyb3VwXzE3EAEYsbXJAUoRCghncm91cF8xOBABGLK1yQFKEQoIZ3JvdXBfMTkQARiztckBShEKCGdyb3VwXzIwEAEYtLXJAUoRCghncm91cF8yMRABGLW1yQFKEQoIZ3JvdXBfMjIQARi2tckBShEKCGdyb3VwXzIzEAEYt7XJAUoRCghncm91cF8yNBABGLi1yQFKEQoIZ3JvdXBfMjUQARi5tckBShEKCGdyb3VwXzI2EAEYurXJAUoRCghncm91cF8yNxABGLu1yQFKEQoIZ3JvdXBfMjgQARi8tckBShEKCGdyb3VwXzI5EAEYvbXJAUoRCghncm91cF8zMBABGL61yQFKEQoIZ3JvdXBfMzEQARi\/tckBShEKCGdyb3VwXzMyEAEYwLXJAUoRCghncm91cF8zMxABGMG1yQFKEQoIZ3JvdXBfMzQQARjCtckBShEKCGdyb3VwXzM1EAEYw7XJAUoRCghncm91cF8zNhABGMS1yQFKEQoIZ3JvdXBfMzcQARjFtckBShEKCGdyb3VwXzM4EAEYxrXJAUoRCghncm91cF8zORABGMe1yQFKEQoIZ3JvdXBfNDAQARjItckBShEKCGdyb3VwXzQxEAEYybXJAUoRCghncm91cF80MhABGMq1yQFKEQoIZ3JvdXBfNDMQARjLtckBShEKCGdyb3VwXzQ0EAEYzLXJAUoRCghncm91cF80NRABGM21yQFKEQoIZ3JvdXBfNDYQARjOtckBShEKCGdyb3VwXzQ3EAEYz7XJAUoRCghncm91cF80OBABGNC1yQFKEQoIZ3JvdXBfNDkQARjRtckBShEKCGdyb3VwXzUwEAEY0rXJAUoRCghncm91cF81MRABGNO1yQFKEQoIZ3JvdXBfNTIQARjUtckBShEKCGdyb3VwXzUzEAEY1bXJAUoRCghncm91cF81NBABGNa1yQFKEQoIZ3JvdXBfNTUQARjXtckBShEKCGdyb3VwXzU2EAEY2LXJAUoRCghncm91cF81NxABGNm1yQFKEQoIZ3JvdXBfNTgQARjatckBShEKCGdyb3VwXzU5EAEY27XJAUoRCghncm91cF82MBABGNy1yQFKEQoIZ3JvdXBfNjEQARjdtckBShEKCGdyb3VwXzYyEAEY3rXJAUoRCghncm91cF82MxABGN+1yQFKEQoIZ3JvdXBfNjQQARjgtckBShEKCGdyb3VwXzY1EAEY4bXJAUoRCghncm91cF82NhABGOK1yQFKEQoIZ3JvdXBfNjcQARjjtckBShEKCGdyb3VwXzY4EAEY5LXJAUoRCghncm91cF82ORABGOW1yQFKEQoIZ3JvdXBfNzAQARjmtckBShEKCGdyb3VwXzcxEAEY57XJAUoRCghncm91cF83MhABGOi1yQFKEQoIZ3JvdXBfNzMQARjptckBShEKCGdyb3VwXzc0EAEY6rXJAUoRCghncm91cF83NRABGOu1yQFKEQoIZ3JvdXBfNzYQARjstckBShEKCGdyb3VwXzc3EAEY7bXJAUoRCghncm91cF83OBABGO61yQFKEQoIZ3JvdXBfNzkQARjvtckBShEKCGdyb3VwXzgwEAEY8LXJAUoRCghncm91cF84MRABGPG1yQFKEQoIZ3JvdXBfODIQARjytckBShEKCGdyb3VwXzgzEAEY87XJAUoRCghncm91cF84NBABGPS1yQFKEQoIZ3JvdXBfODUQARj1tckBShEKCGdyb3VwXzg2EAEY9rXJAUoRCghncm91cF84NxABGPe1yQFKEQoIZ3JvdXBfODgQARj4tckBShEKCGdyb3VwXzg5EAEY+bXJAUoRCghncm91cF85MBABGPq1yQFKEQoIZ3JvdXBfOTEQARj7tckBShEKCGdyb3VwXzkyEAEY\/LXJAUoRCghncm91cF85MxABGP21yQFKEQoIZ3JvdXBfOTQQARj+tckBShEKCGdyb3VwXzk1EAEY\/7XJAUoRCghncm91cF85NhABGIC2yQFKEQoIZ3JvdXBfOTcQARiBtskBShEKCGdyb3VwXzk4EAEYgrbJAUoRCghncm91cF85ORABGIO2yQFSCCgAKAEoAigDEq4LCh5VTUEtVW5pZm9ybWl0eS1UcmlhbC0xLVBlcmNlbnQYgJySpQU4AUIHZGVmYXVsdEoLCgdkZWZhdWx0EAFKDAoIZ3JvdXBfMDEQAUoMCghncm91cF8wMhABSgwKCGdyb3VwXzAzEAFKDAoIZ3JvdXBfMDQQAUoMCghncm91cF8wNRABSgwKCGdyb3VwXzA2EAFKDAoIZ3JvdXBfMDcQAUoMCghncm91cF8wOBABSgwKCGdyb3VwXzA5EAFKDAoIZ3JvdXBfMTAQAUoMCghncm91cF8xMRABSgwKCGdyb3VwXzEyEAFKDAoIZ3JvdXBfMTMQAUoMCghncm91cF8xNBABSgwKCGdyb3VwXzE1EAFKDAoIZ3JvdXBfMTYQAUoMCghncm91cF8xNxABSgwKCGdyb3VwXzE4EAFKDAoIZ3JvdXBfMTkQAUoMCghncm91cF8yMBABSgwKCGdyb3VwXzIxEAFKDAoIZ3JvdXBfMjIQAUoMCghncm91cF8yMxABSgwKCGdyb3VwXzI0EAFKDAoIZ3JvdXBfMjUQAUoMCghncm91cF8yNhABSgwKCGdyb3VwXzI3EAFKDAoIZ3JvdXBfMjgQAUoMCghncm91cF8yORABSgwKCGdyb3VwXzMwEAFKDAoIZ3JvdXBfMzEQAUoMCghncm91cF8zMhABSgwKCGdyb3VwXzMzEAFKDAoIZ3JvdXBfMzQQAUoMCghncm91cF8zNRABSgwKCGdyb3VwXzM2EAFKDAoIZ3JvdXBfMzcQAUoMCghncm91cF8zOBABSgwKCGdyb3VwXzM5EAFKDAoIZ3JvdXBfNDAQAUoMCghncm91cF80MRABSgwKCGdyb3VwXzQyEAFKDAoIZ3JvdXBfNDMQAUoMCghncm91cF80NBABSgwKCGdyb3VwXzQ1EAFKDAoIZ3JvdXBfNDYQAUoMCghncm91cF80NxABSgwKCGdyb3VwXzQ4EAFKDAoIZ3JvdXBfNDkQAUoMCghncm91cF81MBABSgwKCGdyb3VwXzUxEAFKDAoIZ3JvdXBfNTIQAUoMCghncm91cF81MxABSgwKCGdyb3VwXzU0EAFKDAoIZ3JvdXBfNTUQAUoMCghncm91cF81NhABSgwKCGdyb3VwXzU3EAFKDAoIZ3JvdXBfNTgQAUoMCghncm91cF81ORABSgwKCGdyb3VwXzYwEAFKDAoIZ3JvdXBfNjEQAUoMCghncm91cF82MhABSgwKCGdyb3VwXzYzEAFKDAoIZ3JvdXBfNjQQAUoMCghncm91cF82NRABSgwKCGdyb3VwXzY2EAFKDAoIZ3JvdXBfNjcQAUoMCghncm91cF82OBABSgwKCGdyb3VwXzY5EAFKDAoIZ3JvdXBfNzAQAUoMCghncm91cF83MRABSgwKCGdyb3VwXzcyEAFKDAoIZ3JvdXBfNzMQAUoMCghncm91cF83NBABSgwKCGdyb3VwXzc1EAFKDAoIZ3JvdXBfNzYQAUoMCghncm91cF83NxABSgwKCGdyb3VwXzc4EAFKDAoIZ3JvdXBfNzkQAUoMCghncm91cF84MBABSgwKCGdyb3VwXzgxEAFKDAoIZ3JvdXBfODIQAUoMCghncm91cF84MxABSgwKCGdyb3VwXzg0EAFKDAoIZ3JvdXBfODUQAUoMCghncm91cF84NhABSgwKCGdyb3VwXzg3EAFKDAoIZ3JvdXBfODgQAUoMCghncm91cF84ORABSgwKCGdyb3VwXzkwEAFKDAoIZ3JvdXBfOTEQAUoMCghncm91cF85MhABSgwKCGdyb3VwXzkzEAFKDAoIZ3JvdXBfOTQQAUoMCghncm91cF85NRABSgwKCGdyb3VwXzk2EAFKDAoIZ3JvdXBfOTcQAUoMCghncm91cF85OBABSgwKCGdyb3VwXzk5EAFSBCgEKAUSdwofVU1BLVVuaWZvcm1pdHktVHJpYWwtMjAtUGVyY2VudBiAnJKlBTgBQgdkZWZhdWx0SgsKB2RlZmF1bHQQAUoMCghncm91cF8wMRABSgwKCGdyb3VwXzAyEAFKDAoIZ3JvdXBfMDMQAUoMCghncm91cF8wNBABEk0KH1VNQS1Vbmlmb3JtaXR5LVRyaWFsLTUwLVBlcmNlbnQYgJySpQU4AUIHZGVmYXVsdEoLCgdkZWZhdWx0EAFKDAoIZ3JvdXBfMDEQARK2AwoeVU1BLVVuaWZvcm1pdHktVHJpYWwtNS1QZXJjZW50GICckqUFOAFCB2RlZmF1bHRKEAoHZGVmYXVsdBABGIS2yQFKEQoIZ3JvdXBfMDEQARiFtskBShEKCGdyb3VwXzAyEAEYhrbJAUoRCghncm91cF8wMxABGIe2yQFKEQoIZ3JvdXBfMDQQARiItskBShEKCGdyb3VwXzA1EAEYibbJAUoRCghncm91cF8wNhABGIq2yQFKEQoIZ3JvdXBfMDcQARiLtskBShEKCGdyb3VwXzA4EAEYjLbJAUoRCghncm91cF8wORABGI22yQFKEQoIZ3JvdXBfMTAQARiOtskBShEKCGdyb3VwXzExEAEYj7bJAUoRCghncm91cF8xMhABGJC2yQFKEQoIZ3JvdXBfMTMQARiRtskBShEKCGdyb3VwXzE0EAEYkrbJAUoRCghncm91cF8xNRABGJO2yQFKEQoIZ3JvdXBfMTYQARiUtskBShEKCGdyb3VwXzE3EAEYlbbJAUoRCghncm91cF8xOBABGJa2yQFKEQoIZ3JvdXBfMTkQARiXtskBUggoACgBKAIoAxLOAgoeVU1BLVVuaWZvcm1pdHktVHJpYWwtNS1QZXJjZW50GICckqUFOAFCB2RlZmF1bHRKCwoHZGVmYXVsdBABSgwKCGdyb3VwXzAxEAFKDAoIZ3JvdXBfMDIQAUoMCghncm91cF8wMxABSgwKCGdyb3VwXzA0EAFKDAoIZ3JvdXBfMDUQAUoMCghncm91cF8wNhABSgwKCGdyb3VwXzA3EAFKDAoIZ3JvdXBfMDgQAUoMCghncm91cF8wORABSgwKCGdyb3VwXzEwEAFKDAoIZ3JvdXBfMTEQAUoMCghncm91cF8xMhABSgwKCGdyb3VwXzEzEAFKDAoIZ3JvdXBfMTQQAUoMCghncm91cF8xNRABSgwKCGdyb3VwXzE2EAFKDAoIZ3JvdXBfMTcQAUoMCghncm91cF8xOBABSgwKCGdyb3VwXzE5EAFSBCgEKAU=,homepage: http://feed.snap.do/?publisher=QuickObrw&dpid=QuickObrw&co=PL&userid=3a732a9b-54b2-4c4d-b4c6-be738cdd24bf&searchtype=hp&installDate=04/04/2013 CHR - Extension: No name found = C:\Documents and Settings\Karolina\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.1\ O1 HOSTS File: ([2013-08-06 23:11:51 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.8.3.8\bh\BabylonToolbar.dll File not found O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software) O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [PDF3 Registry Controller] C:\Program Files\ScanSoft\PDF Converter 3.0\RegistryController.exe (ScanSoft, Inc.) O4 - HKLM..\Run: [Zwinky Search Scope Monitor] "C:\PROGRA~1\ZWINKY~2\bar\1.bin\5qsrchmn.exe" /m=2 /w /h File not found O4 - HKLM..\Run: [Zwinky_5q Browser Plugin Loader] C:\PROGRA~1\ZWINKY~2\bar\1.bin\5qbrmon.exe File not found O4 - HKU\S-1-5-21-515967899-287218729-1801674531-1003..\Run: [] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung) O4 - HKU\S-1-5-21-515967899-287218729-1801674531-1003..\Run: [BitTorrent] C:\Program Files\BitTorrent\BitTorrent.exe (BitTorrent Inc.) O4 - HKU\S-1-5-21-515967899-287218729-1801674531-1003..\Run: [GG] C:\Documents and Settings\Karolina\Ustawienia lokalne\Dane aplikacji\GG\Application\gghub.exe (GG Network S.A.) O4 - HKU\S-1-5-21-515967899-287218729-1801674531-1003..\Run: [IPLA!] C:\Program Files\ipla\ipla.exe (Redefine Sp z o.o.) O4 - HKU\S-1-5-21-515967899-287218729-1801674531-1003..\Run: [KiesAirMessage] C:\Program Files\Samsung\Kies\KiesAirMessage.exe (Samsung Electronics) O4 - HKU\S-1-5-21-515967899-287218729-1801674531-1003..\Run: [NokiaSuite.exe] C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe (Nokia) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-515967899-287218729-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: &Search - http://tbedits.zwinky.com/one-toolbaredits/menusearch.jhtml?s=207521081&p2=^ZJ^xpt249^YY^pl&si=begin-download&a=ED147F04-8A39-4FE4-BF0D-CD9C6635E2FE&n=2013062216&cv=3 File not found O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.) O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 File not found O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://E:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000 File not found O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Open with Scansoft PDF Converter 3.0 - C:\Program Files\ScanSoft\PDF Converter 3.0\IEShellExt.dll (ScanSoft, Inc.) O8 - Extra context menu item: Se&nd to OneNote - res://E:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105 File not found O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1362948600375 (MUWebControl Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 217.113.224.135 217.113.224.36 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{77D6046B-E1CE-4FAB-BE6C-21A3D24836A3}: DhcpNameServer = 217.113.224.135 217.113.224.36 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9E646697-148D-4C9A-883C-4862F7EE66FF}: DhcpNameServer = 192.168.0.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\13.2.0\ViProtocol.dll File not found O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\Karolina\Dane aplikacji\IrfanView\IrfanView_Wallpaper.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Karolina\Dane aplikacji\IrfanView\IrfanView_Wallpaper.bmp O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation) O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2011-01-19 14:48:43 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2013-09-01 12:50:07 | 001,085,269 | ---- | C] (Farbar) -- C:\Documents and Settings\Karolina\Pulpit\FRST.exe [2013-09-01 12:50:05 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Karolina\Pulpit\OTL.exe [2013-08-21 23:58:32 | 000,000,000 | ---D | C] -- C:\_OTL [2013-08-11 19:27:21 | 000,000,000 | ---D | C] -- C:\FRST [2013-08-06 23:26:49 | 000,000,000 | --SD | C] -- C:\ComboFix [2013-08-06 23:13:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp [2013-08-06 23:06:24 | 000,000,000 | -HSD | C] -- C:\cmdcons [2013-08-06 22:57:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\CSC [2013-08-06 21:46:13 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe [2013-08-06 21:46:13 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe [2013-08-06 21:46:13 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe [2013-08-06 21:46:13 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe [2013-08-06 21:29:53 | 000,000,000 | ---D | C] -- C:\Qoobox [2013-08-06 21:28:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2013-09-01 07:44:00 | 000,000,366 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job [2013-08-31 22:22:26 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2013-08-31 22:21:47 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2013-08-31 17:24:56 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Karolina\Pulpit\OTL.exe [2013-08-31 17:23:06 | 001,085,269 | ---- | M] (Farbar) -- C:\Documents and Settings\Karolina\Pulpit\FRST.exe [2013-08-06 23:11:51 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2013-08-06 23:06:30 | 000,000,327 | -HS- | M] () -- C:\boot.ini [2013-08-06 23:05:55 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat [2013-08-06 22:40:12 | 000,516,938 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2013-08-06 22:40:11 | 000,436,284 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2013-08-06 22:40:11 | 000,094,916 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2013-08-06 22:40:11 | 000,069,180 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2013-08-05 22:49:08 | 000,207,360 | ---- | M] () -- C:\Documents and Settings\Karolina\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2013-08-05 22:19:31 | 000,026,104 | ---- | M] () -- C:\Documents and Settings\Karolina\Pulpit\premiera.jpg [2013-08-05 22:07:17 | 000,119,886 | ---- | M] () -- C:\Documents and Settings\Karolina\Pulpit\123.png [2013-08-02 22:35:38 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Google Chrome.lnk [color=#E56717]========== Files Created - No Company Name ==========[/color] [2013-08-06 23:06:30 | 000,000,211 | ---- | C] () -- C:\Boot.bak [2013-08-06 23:06:25 | 000,262,400 | RHS- | C] () -- C:\cmldr [2013-08-06 21:46:13 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe [2013-08-06 21:46:13 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe [2013-08-06 21:46:13 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2013-08-06 21:46:13 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2013-08-06 21:46:13 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2013-08-06 00:15:04 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2013-08-05 22:19:31 | 000,026,104 | ---- | C] () -- C:\Documents and Settings\Karolina\Pulpit\premiera.jpg [2013-08-05 22:07:17 | 000,119,886 | ---- | C] () -- C:\Documents and Settings\Karolina\Pulpit\123.png [2013-06-27 21:24:03 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys.sum [2013-06-26 21:55:02 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswSP.sys.sum [2013-06-26 21:55:02 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswSnx.sys.sum [2013-04-18 19:07:00 | 000,030,568 | ---- | C] () -- C:\WINDOWS\MusiccityDownload.exe [2013-04-18 19:06:46 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll [2013-04-18 19:06:46 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll [2013-04-18 19:06:46 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll [2013-04-18 19:06:46 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll [2013-04-04 00:34:06 | 000,723,230 | ---- | C] () -- C:\WINDOWS\unins000.exe [2013-04-04 00:34:06 | 000,438,116 | ---- | C] () -- C:\WINDOWS\unins000.dat [2013-03-20 10:45:05 | 000,175,176 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys [2013-03-20 10:45:05 | 000,049,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswRvrt.sys [2013-03-07 12:03:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\DVDConverter.INI [2013-03-07 12:01:55 | 000,000,067 | ---- | C] () -- C:\WINDOWS\#1 DVD Ripper.INI [2013-03-01 03:47:36 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll [2013-01-18 17:30:17 | 000,000,094 | ---- | C] () -- C:\WINDOWS\optHTML.ini [2012-11-23 14:07:23 | 000,076,674 | ---- | C] () -- C:\Documents and Settings\Karolina\100_9081.jpg [2012-09-10 22:06:21 | 000,000,204 | ---- | C] () -- C:\WINDOWS\pdf2word.INI [2012-07-13 17:33:57 | 000,000,144 | ---- | C] () -- C:\Documents and Settings\Karolina\Dane aplikacji\default.rss [2012-07-13 17:20:41 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2012-07-13 16:58:31 | 000,000,039 | ---- | C] () -- C:\WINDOWS\Irremote.ini [2012-07-13 14:33:46 | 000,000,004 | ---- | C] () -- C:\WINDOWS\System32\micr0st.dll [2012-06-25 23:07:55 | 000,109,256 | ---- | C] () -- C:\WINDOWS\System32\EasyHook64.dll [2012-06-25 23:07:55 | 000,090,824 | ---- | C] () -- C:\WINDOWS\System32\EasyHook32.dll [2012-06-09 22:50:46 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2012-06-09 22:50:46 | 000,216,064 | ---- | C] ( ) -- C:\WINDOWS\System32\lagarith.dll [2012-06-09 22:50:45 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2012-06-09 22:50:34 | 000,079,872 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2012-05-18 21:56:20 | 000,000,724 | ---- | C] () -- C:\Documents and Settings\Karolina\Dane aplikacji\burnaware.ini [2012-05-02 21:37:09 | 002,392,064 | ---- | C] () -- C:\WINDOWS\System32\videotrans.dll [2012-05-02 21:37:09 | 000,215,040 | ---- | C] () -- C:\WINDOWS\System32\videoformat.dll [2012-05-02 21:37:09 | 000,017,920 | ---- | C] () -- C:\WINDOWS\System32\videocore.dll [2012-05-02 21:37:08 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\imgscaler.dll [2012-05-02 21:37:08 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\img_utils.dll [2012-05-02 21:37:03 | 000,128,512 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll [2012-02-24 00:16:59 | 000,000,529 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2012-02-15 21:53:26 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll [2012-02-07 23:35:16 | 000,058,584 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat [2011-06-23 00:17:55 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Karolina\Dane aplikacji\winscp.rnd [2011-01-19 22:09:32 | 000,207,360 | ---- | C] () -- C:\Documents and Settings\Karolina\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [color=#E56717]========== ZeroAccess Check ==========[/color] [2011-01-19 14:57:53 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2008-04-15 14:00:00 | 001,499,136 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010-06-17 10:33:11 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = %systemroot%\system32\wbem\wbemess.dll -- [2008-04-15 14:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2013-05-24 14:11:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\188F1432-103A-4ffb-80F1-36B633C5C9E1 [2013-04-28 22:54:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\4Media [2011-01-19 15:17:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Alwil Software [2012-04-04 15:43:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ashampoo [2011-02-18 00:00:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Blumentals [2011-01-19 14:59:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Canneverbe Limited [2012-11-07 15:35:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite [2011-07-12 09:32:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10 [2012-11-13 17:41:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\GG [2013-06-12 12:14:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ipla [2012-05-29 13:53:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Nokia [2012-05-18 18:52:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\NokiaInstallerCache [2012-08-26 21:45:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\OpenFM [2012-11-06 00:13:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PC Drivers HeadQuarters Inc [2012-02-18 22:42:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PC Suite [2012-02-24 02:01:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PITy [2013-06-26 22:43:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\RDRM [2012-11-21 15:53:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\regid.1986-12.com.adobe [2013-05-24 12:25:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Samsung [2012-11-28 14:06:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ScanSoft [2013-04-17 16:45:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TuneUp Software [2013-05-16 22:28:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\YTD Video Downloader [2013-04-17 16:44:56 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Dane aplikacji\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} [2012-11-21 15:27:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\.BitTornado [2013-04-28 22:54:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\4Media [2012-04-04 15:44:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\Ashampoo [2012-06-25 22:50:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\avidemux [2013-09-01 12:56:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\BitTorrent [2011-01-19 14:59:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\Canneverbe Limited [2012-11-22 16:07:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\com.adobe.WidgetBrowser [2011-10-09 15:24:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\DAEMON Tools Lite [2011-07-07 16:30:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\EurekaLog [2011-01-19 14:56:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\Foxit Software [2012-09-05 20:36:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\Gadu-Gadu 10 [2013-04-28 22:53:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\GetRightToGo [2013-08-31 22:26:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\GG [2012-12-21 23:19:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\GHISLER [2012-06-11 09:47:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\GrabPro [2013-03-27 01:53:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\gtk-2.0 [2013-08-31 22:23:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\ipla [2012-10-29 15:57:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\IrfanView [2012-11-22 22:25:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\KONICA MINOLTA [2011-05-28 00:16:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\nasz-album [2013-02-05 12:54:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\Nokia [2012-02-18 23:00:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\Nokia Suite [2013-02-19 12:30:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\Notepad++ [2012-02-21 22:03:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\OpenFM [2011-01-19 15:46:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\OpenOffice.org [2013-03-23 23:54:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\Opera [2012-06-23 00:02:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\Orbit [2012-02-18 23:00:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\PC Suite [2012-06-22 23:06:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\PowerISO [2013-05-24 12:27:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\Samsung [2011-02-12 23:27:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\Softland [2013-02-06 13:21:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\TeamViewer [2011-02-28 14:13:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\Thunderbird [2013-01-18 17:26:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\Tonbrand [2013-04-17 16:45:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\TuneUp Software [2013-02-06 13:21:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\uTorrent [2013-04-11 23:48:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\WinAVI [2011-02-21 12:34:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\Windows Desktop Search [2011-02-28 15:12:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\Windows Live Writer [2011-02-21 12:55:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\Windows Search [2013-06-12 22:24:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\XBMC [2012-10-30 11:26:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\YCanPDF [2013-06-22 22:17:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karolina\Dane aplikacji\Zwinky_5q [2011-02-09 00:36:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\Foxit Software [2011-02-12 23:27:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\Softland [2013-04-17 16:45:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\TuneUp Software [color=#E56717]========== Purity Check ==========[/color] < End of report >