OTL logfile created on: 2014-03-05 18:57:54 - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Prezes\Desktop 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16660) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,94 Gb Total Physical Memory | 0,24 Gb Available Physical Memory | 12,47% Memory free 3,87 Gb Paging File | 0,84 Gb Available in Paging File | 21,61% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 120,47 Gb Total Space | 67,99 Gb Free Space | 56,44% Space Free | Partition Type: NTFS Drive D: | 70,01 Gb Total Space | 50,92 Gb Free Space | 72,73% Space Free | Partition Type: NTFS Drive F: | 200,10 Gb Total Space | 15,55 Gb Free Space | 7,77% Space Free | Partition Type: NTFS Computer Name: PREZES-KOMPUTER | User Name: Prezes | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - File not found -- PRC - [2014-03-05 18:56:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Prezes\Desktop\OTL.exe PRC - [2014-02-21 14:46:36 | 001,863,560 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe PRC - [2014-02-16 10:36:59 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2014-02-06 20:03:28 | 003,767,096 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe PRC - [2014-02-06 20:03:28 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe PRC - [2014-01-15 21:20:49 | 000,390,256 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe PRC - [2013-12-21 07:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2013-12-11 08:50:10 | 004,047,424 | ---- | M] (GG Network S.A.) -- C:\Users\Prezes\AppData\Local\GG\Application\gghub.exe PRC - [2013-12-11 08:50:10 | 000,132,672 | ---- | M] (GG Network S.A.) -- C:\Users\Prezes\AppData\Local\GG\Application\ggapp.exe PRC - [2013-12-11 08:50:10 | 000,076,352 | ---- | M] (GG Network S.A.) -- C:\Users\Prezes\AppData\Local\GG\Application\xulrunner\gghub.exe PRC - [2013-11-07 09:43:36 | 003,402,304 | ---- | M] (GG Network S.A.) -- C:\Users\Prezes\AppData\Local\GG\Application\ggdrive\ggdrive.exe PRC - [2012-07-19 14:18:38 | 002,568,120 | ---- | M] (WIBU-SYSTEMS AG) -- C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe PRC - [2012-05-30 20:00:09 | 000,389,215 | ---- | M] (THOMSON Telecom Belgium) -- C:\Program Files (x86)\Thomson\ST330\service\st330service.exe PRC - [2012-01-18 06:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe PRC - [2011-11-11 14:08:06 | 000,205,336 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe PRC - [2011-11-11 14:07:54 | 000,265,240 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe PRC - [2011-08-12 12:19:40 | 000,680,984 | ---- | M] () -- C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe PRC - [2011-08-06 13:24:08 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe PRC - [2010-11-16 14:37:30 | 000,230,912 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe PRC - [2010-05-11 16:43:48 | 006,061,400 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Logitech\Vid\Vid.exe PRC - [2010-03-25 13:39:22 | 000,490,280 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe PRC - [2010-02-02 17:31:56 | 000,279,296 | ---- | M] (Motorola) -- C:\Program Files (x86)\Motorola\MotoConnectService\MotoConnect.exe PRC - [2010-01-27 11:37:22 | 000,091,392 | ---- | M] () -- C:\Program Files (x86)\Motorola\MotoConnectService\MotoConnectService.exe PRC - [2009-09-23 16:45:50 | 001,287,176 | ---- | M] (Panda Security) -- C:\Program Files (x86)\Panda USB Vaccine\USBVaccine.exe PRC - [2008-12-10 00:10:14 | 000,024,636 | ---- | M] (Apache Software Foundation) -- F:\ET_BB\bin\EtkaWeb.exe PRC - [2007-09-02 13:58:52 | 000,495,616 | ---- | M] () -- C:\Program Files (x86)\RocketDock\RocketDock.exe PRC - [2007-08-29 02:19:28 | 044,814,336 | ---- | M] (Adobe Systems, Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Photoshop CS3\Photoshop.exe PRC - [2005-11-08 21:02:44 | 000,038,912 | ---- | M] (Felix 'SniperBeamer' Geyer) -- C:\Program Files (x86)\Thunderbird-Tray\TBTray.exe PRC - [2003-12-03 11:01:48 | 000,327,680 | ---- | M] (Aladdin Knowledge Systems Ltd.) -- C:\Windows\SysWOW64\HLS32SVC.EXE PRC - [2000-03-06 11:19:32 | 000,221,184 | ---- | M] (E-Color, Inc.) -- C:\Program Files (x86)\E-Color\True Internet Color\TICIcon.exe PRC - [1999-12-13 00:01:00 | 000,044,032 | ---- | M] (Creative Technology Ltd) -- C:\Windows\SysWOW64\CTSVCCDA.EXE [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2014-02-21 14:46:35 | 016,265,096 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll MOD - [2014-02-16 10:36:58 | 003,578,992 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2014-02-06 00:52:52 | 000,073,544 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2014-02-06 00:52:32 | 001,044,808 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2014-01-15 21:20:52 | 003,017,840 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll MOD - [2014-01-15 21:20:51 | 000,158,832 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll MOD - [2014-01-15 21:20:51 | 000,023,152 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll MOD - [2013-12-11 08:50:10 | 003,006,528 | ---- | M] () -- C:\Users\Prezes\AppData\Local\GG\Application\xulrunner\mozjs.dll MOD - [2013-12-11 08:50:10 | 000,141,888 | ---- | M] () -- C:\Users\Prezes\AppData\Local\GG\Application\ggdrive\zlib1.dll MOD - [2013-11-07 09:43:25 | 016,166,248 | ---- | M] () -- C:\Users\Prezes\AppData\Local\GG\Application\FMSBWChecker\Adobe AIR\Versions\1.0\Resources\NPSWF32.dll MOD - [2013-10-24 09:45:43 | 019,336,120 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll MOD - [2012-01-18 07:43:56 | 000,183,320 | ---- | M] () -- C:\Program Files (x86)\Common Files\logishrd\SharedBin\LVAPI11.dll MOD - [2011-11-11 14:09:20 | 000,336,408 | ---- | M] () -- C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll MOD - [2011-11-11 14:07:54 | 000,265,240 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe MOD - [2011-08-12 12:19:40 | 000,680,984 | ---- | M] () -- C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe MOD - [2010-05-11 16:45:18 | 000,138,072 | ---- | M] () -- C:\Program Files (x86)\Logitech\Vid\plugins\imageformats\qjpeg4.dll MOD - [2010-05-11 16:44:48 | 000,035,160 | ---- | M] () -- C:\Program Files (x86)\Logitech\Vid\plugins\imageformats\qico4.dll MOD - [2010-05-11 16:44:22 | 000,029,016 | ---- | M] () -- C:\Program Files (x86)\Logitech\Vid\plugins\imageformats\qgif4.dll MOD - [2010-05-11 16:42:22 | 000,027,480 | ---- | M] () -- C:\Program Files (x86)\Logitech\Vid\SDL.dll MOD - [2010-05-11 16:42:10 | 000,363,864 | ---- | M] () -- C:\Program Files (x86)\Logitech\Vid\QtXml4.dll MOD - [2010-05-11 16:42:00 | 011,311,960 | ---- | M] () -- C:\Program Files (x86)\Logitech\Vid\QtWebKit4.dll MOD - [2010-05-11 16:41:48 | 000,200,024 | ---- | M] () -- C:\Program Files (x86)\Logitech\Vid\QtSql4.dll MOD - [2010-05-11 16:41:36 | 000,475,480 | ---- | M] () -- C:\Program Files (x86)\Logitech\Vid\QtOpenGL4.dll MOD - [2010-05-11 16:41:24 | 000,969,048 | ---- | M] () -- C:\Program Files (x86)\Logitech\Vid\QtNetwork4.dll MOD - [2010-05-11 16:41:14 | 007,704,408 | ---- | M] () -- C:\Program Files (x86)\Logitech\Vid\QtGui4.dll MOD - [2010-05-11 16:41:02 | 002,141,016 | ---- | M] () -- C:\Program Files (x86)\Logitech\Vid\QtCore4.dll MOD - [2010-05-11 16:40:50 | 000,291,672 | ---- | M] () -- C:\Program Files (x86)\Logitech\Vid\phonon4.dll MOD - [2010-05-07 18:37:40 | 000,126,808 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QJpeg4.dll MOD - [2010-05-07 18:37:40 | 000,027,480 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\imageformats\QGif4.dll MOD - [2010-05-07 18:36:54 | 000,340,824 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtXml4.dll MOD - [2010-05-07 18:35:56 | 007,954,776 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtGui4.dll MOD - [2010-05-07 18:35:44 | 002,143,576 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\QtCore4.dll MOD - [2007-09-02 13:58:52 | 000,495,616 | ---- | M] () -- C:\Program Files (x86)\RocketDock\RocketDock.exe MOD - [2007-09-02 13:57:36 | 000,069,632 | ---- | M] () -- C:\Program Files (x86)\RocketDock\RocketDock.dll MOD - [2007-05-03 18:37:20 | 002,342,912 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Photoshop CS3\Photoshop.dll MOD - [2007-05-03 18:36:30 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Photoshop CS3\QuickTimeGlue.dll MOD - [2007-05-03 18:36:26 | 000,393,216 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Photoshop CS3\AdobeXMP.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2014-02-06 20:03:28 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV:[b]64bit:[/b] - [2011-10-18 10:36:10 | 004,883,400 | ---- | M] (SafeNet Inc.) [Auto | Running] -- C:\Windows\SysNative\hasplms.exe -- (hasplms) SRV:[b]64bit:[/b] - [2009-08-18 01:36:20 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:[b]64bit:[/b] - [2009-07-14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:[b]64bit:[/b] - [2009-07-14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV:[b]64bit:[/b] - [2009-07-14 02:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\CISVC.EXE -- (CISVC) SRV - [2014-02-21 14:46:37 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2014-01-20 20:02:42 | 000,146,920 | ---- | M] (SaveSense) [On_Demand | Stopped] -- C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe -- (savesenselivem) SRV - [2014-01-20 20:02:42 | 000,146,920 | ---- | M] (SaveSense) [Auto | Stopped] -- C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe -- (savesenselive) SRV - [2013-12-21 07:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2013-09-05 10:34:30 | 000,171,680 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012-07-19 14:18:38 | 002,568,120 | ---- | M] (WIBU-SYSTEMS AG) [Auto | Running] -- C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe -- (CodeMeter.exe) SRV - [2012-05-30 20:00:09 | 000,389,215 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)/Thomson/ST330/service/st330service.exe -- (st330service) SRV - [2012-01-18 06:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv) SRV - [2011-08-06 13:24:08 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2010-11-16 14:38:16 | 000,339,456 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\HWDeviceService64.exe -- (HWDeviceService64.exe) SRV - [2010-03-25 13:39:22 | 000,490,280 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate) SRV - [2010-03-18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2010-01-27 11:37:22 | 000,091,392 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Motorola\MotoConnectService\MotoConnectService.exe -- (MotoConnect Service) SRV - [2009-06-10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2008-12-10 00:10:14 | 000,024,636 | ---- | M] (Apache Software Foundation) [Auto | Running] -- F:\ET_BB\bin\EtkaWeb.exe -- (EtkaWebServer) SRV - [2003-12-03 11:01:48 | 000,327,680 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Auto | Running] -- C:\Windows\SysWOW64\HLS32SVC.EXE -- (HLServer) SRV - [1999-12-13 00:01:00 | 000,044,032 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Windows\SysWOW64\CTSVCCDA.EXE -- (Creative Service for CDROM Access) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2014-02-24 15:56:16 | 000,254,976 | ---- | M] (Jungo) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\PYCH_CoreDriver.sys -- (PYCH_CoreDriver) DRV:[b]64bit:[/b] - [2014-02-24 15:56:10 | 000,254,976 | ---- | M] (Jungo) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\windrvr6.sys -- (WinDriver6) DRV:[b]64bit:[/b] - [2014-02-06 20:03:33 | 001,038,072 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx) DRV:[b]64bit:[/b] - [2014-02-06 20:03:33 | 000,421,704 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsp.sys -- (aswSP) DRV:[b]64bit:[/b] - [2014-02-06 20:03:33 | 000,080,184 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\aswstm.sys -- (aswStm) DRV:[b]64bit:[/b] - [2014-02-06 20:03:33 | 000,078,648 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt) DRV:[b]64bit:[/b] - [2013-12-26 20:43:22 | 000,207,904 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm) DRV:[b]64bit:[/b] - [2013-10-24 09:45:45 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt) DRV:[b]64bit:[/b] - [2013-10-24 09:45:44 | 000,092,544 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr) DRV:[b]64bit:[/b] - [2012-08-21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV:[b]64bit:[/b] - [2012-07-16 21:35:16 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:[b]64bit:[/b] - [2012-05-30 20:00:06 | 000,054,272 | ---- | M] (THOMSON Telecom Belgium) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stppp.sys -- (stppp) DRV:[b]64bit:[/b] - [2012-05-30 18:27:39 | 000,058,880 | ---- | M] (THOMSON Telecom Belgium) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\steth.sys -- (STETH) DRV:[b]64bit:[/b] - [2012-05-30 18:27:39 | 000,047,616 | ---- | M] (THOMSON Telecom Belgium) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\st330.sys -- (ST330) DRV:[b]64bit:[/b] - [2012-05-30 18:27:39 | 000,024,576 | ---- | M] (THOMSON Telecom Belgium) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stbus.sys -- (STBUS) DRV:[b]64bit:[/b] - [2012-01-18 07:44:36 | 004,865,568 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LVUVC64.sys -- (LVUVC64) DRV:[b]64bit:[/b] - [2012-01-18 07:44:28 | 000,351,136 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64) DRV:[b]64bit:[/b] - [2012-01-18 07:44:14 | 000,025,632 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvbflt64.sys -- (CompFilter64) DRV:[b]64bit:[/b] - [2011-12-15 18:29:42 | 000,031,232 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901) DRV:[b]64bit:[/b] - [2011-10-18 10:36:10 | 000,078,208 | ---- | M] (SafeNet Inc.) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aksdf.sys -- (aksdf) DRV:[b]64bit:[/b] - [2011-10-04 12:53:46 | 000,139,720 | ---- | M] (SafeNet Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aksfridge.sys -- (aksfridge) DRV:[b]64bit:[/b] - [2011-09-28 15:31:30 | 000,321,536 | ---- | M] (SafeNet Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\hardlock.sys -- (hardlock) DRV:[b]64bit:[/b] - [2011-04-11 17:35:14 | 001,579,520 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr) DRV:[b]64bit:[/b] - [2010-12-21 06:55:02 | 000,161,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sscemdm.sys -- (sscemdm) DRV:[b]64bit:[/b] - [2010-12-21 06:55:02 | 000,129,024 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssceserd.sys -- (ssceserd) DRV:[b]64bit:[/b] - [2010-12-21 06:55:02 | 000,127,488 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sscebus.sys -- (sscebus) DRV:[b]64bit:[/b] - [2010-12-21 06:55:02 | 000,018,944 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sscemdfl.sys -- (sscemdfl) DRV:[b]64bit:[/b] - [2010-11-21 04:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV:[b]64bit:[/b] - [2010-11-21 04:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2010-11-21 04:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub) DRV:[b]64bit:[/b] - [2010-11-21 04:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc) DRV:[b]64bit:[/b] - [2010-11-21 04:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc) DRV:[b]64bit:[/b] - [2010-11-21 04:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt) DRV:[b]64bit:[/b] - [2010-11-21 04:23:47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2010-11-21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2010-11-21 04:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:[b]64bit:[/b] - [2010-11-21 04:23:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2010-10-09 13:49:52 | 000,085,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ew_jubusenum.sys -- (huawei_enumerator) DRV:[b]64bit:[/b] - [2010-08-31 17:09:00 | 000,256,000 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbnet.sys -- (ewusbnet) DRV:[b]64bit:[/b] - [2010-08-07 16:49:04 | 000,121,600 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard) DRV:[b]64bit:[/b] - [2010-07-27 08:52:16 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys -- (ew_hwusbdev) DRV:[b]64bit:[/b] - [2010-05-14 23:01:02 | 000,068,064 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvsels64.sys -- (lvsels64) DRV:[b]64bit:[/b] - [2010-05-07 18:43:30 | 000,030,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2Mon) DRV:[b]64bit:[/b] - [2010-05-07 18:43:30 | 000,030,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2M64) DRV:[b]64bit:[/b] - [2009-10-27 12:10:18 | 000,030,208 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\motmodem.sys -- (motmodem) DRV:[b]64bit:[/b] - [2009-08-18 02:48:48 | 006,037,504 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag) DRV:[b]64bit:[/b] - [2009-07-14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009-07-14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009-07-14 02:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2009-07-14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009-06-10 21:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:[b]64bit:[/b] - [2009-06-10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009-06-10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009-06-10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009-06-10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:[b]64bit:[/b] - [2006-08-21 13:24:38 | 000,097,792 | ---- | M] (T0r0) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\nshe.sys -- (NSHE) DRV:[b]64bit:[/b] - [2005-03-29 00:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor) DRV - [2010-07-28 13:34:31 | 000,097,792 | R--- | M] (Tecar Forum) [Kernel | Auto | Stopped] -- C:\Windows\SysWOW64\drivers\NSHE.SYS -- (NSHE) DRV - [2009-07-14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1655922889-1840272266-2703523318-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve IE - HKU\S-1-5-21-1655922889-1840272266-2703523318-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKU\S-1-5-21-1655922889-1840272266-2703523318-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-1655922889-1840272266-2703523318-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR IE - HKU\S-1-5-21-1655922889-1840272266-2703523318-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1655922889-1840272266-2703523318-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "http://interia.pl/" FF - prefs.js..extensions.enabledAddons: %7B1018e4d6-728f-4b20-ad56-37578a4de76b%7D:4.2.17 FF - prefs.js..extensions.enabledAddons: %7B8b337819-d1e8-48d3-8178-168ae8c99c36%7D:3.0 FF - prefs.js..extensions.enabledAddons: %7BB64D9B05-48E1-4CEB-BF58-E0643994E900%7D:4.5.3.1206 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:27.0.1 FF - user.js - File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.) FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.updaterss.com/SaveSenseLive Update;version=3: C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll (SaveSense) FF - HKLM\Software\MozillaPlugins\@tools.updaterss.com/SaveSenseLive Update;version=9: C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll (SaveSense) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Prezes\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-02-06 20:03:34 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013-08-28 12:29:31 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014-01-16 21:24:36 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 24.2.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013-10-11 08:03:50 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 24.2.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{B64D9B05-48E1-4CEB-BF58-E0643994E900}: C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ [2014-01-20 20:02:15 | 000,000,000 | ---D | M] [2011-06-11 21:19:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Prezes\AppData\Roaming\mozilla\Extensions [2011-06-11 21:19:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Prezes\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2014-01-20 20:02:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Prezes\AppData\Roaming\mozilla\Firefox\Profiles\7dfo94el.default-1378114659463\extensions [2014-01-16 21:53:54 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\Prezes\AppData\Roaming\mozilla\Firefox\Profiles\7dfo94el.default-1378114659463\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b} [2014-01-20 20:02:31 | 000,000,000 | ---D | M] (SaveSense) -- C:\Users\Prezes\AppData\Roaming\mozilla\Firefox\Profiles\7dfo94el.default-1378114659463\extensions\{8b337819-d1e8-48d3-8178-168ae8c99c36} [2013-09-02 10:38:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Prezes\AppData\Roaming\mozilla\Firefox\Profiles\ly96ibmg.default\extensions [2013-09-02 10:38:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Prezes\AppData\Roaming\mozilla\Firefox\Profiles\ly96ibmg.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2013-06-13 08:59:39 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions [2012-05-26 22:28:55 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-06-13 08:59:39 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions [2014-02-16 10:37:00 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2014-01-20 20:02:15 | 000,000,000 | ---D | M] ("Download videos and MP3s from YouTube") -- C:\PROGRAM FILES (X86)\COMMON FILES\DVDVIDEOSOFT\PLUGINS\FF [color=#E56717]========== Chrome ==========[/color] CHR - default_search_provider: () CHR - default_search_provider: search_url = CHR - default_search_provider: suggest_url = CHR - homepage: CHR - Extension: No name found = C:\Users\Prezes\AppData\Local\Google\Chrome\User Data\Default\Extensions\khcceooakamlehbimaepcldnnlnkcmfk\3.5.0.0_0\ CHR - Extension: No name found = C:\Users\Prezes\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0\ CHR - Extension: No name found = C:\Users\Prezes\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\ O1 HOSTS File: ([2011-10-29 12:50:17 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2:[b]64bit:[/b] - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) O2:[b]64bit:[/b] - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2:[b]64bit:[/b] - BHO: (DVDVideoSoft IE Extension) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.) O2 - BHO: (SaveSense) - {0f21b1e5-5afc-43c9-9c66-515046e92ec2} - C:\Program Files (x86)\SaveSense\SaveSenseIE.dll (SaveSense) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (DVDVideoSoft IE Extension) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.) O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Users\Prezes\AppData\Roaming\Nowe Gadu-Gadu\_userdata\ggbho.1.dll (GG Network S.A.) O3:[b]64bit:[/b] - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O3:[b]64bit:[/b] - HKLM\..\Toolbar: (avast! Online Security) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O3 - HKLM\..\Toolbar: (&Save Flash) - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files (x86)\Save Flash\SaveFlash.dll (PilotGroup LLC) O3 - HKLM\..\Toolbar: (avast! Online Security) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O4:[b]64bit:[/b] - HKLM..\Run: [Eraser] C:\Program Files\Eraser\Eraser.exe (The Eraser Project) O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software) O4 - HKLM..\Run: [E-Color Registration] c:\program files (x86)\E-Color\Registration\SonnReg.exe (E-Color, Inc.) O4 - HKLM..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.) O4 - HKU\S-1-5-21-1655922889-1840272266-2703523318-1001..\Run: [Logitech Vid] C:\Program Files (x86)\Logitech\Vid\Vid.exe (Logitech Inc.) O4 - HKU\S-1-5-21-1655922889-1840272266-2703523318-1001..\Run: [Logitech Vid HD] C:\Program Files (x86)\Logitech\Vid\vid.exe (Logitech Inc.) O4 - HKU\S-1-5-21-1655922889-1840272266-2703523318-1001..\Run: [RocketDock] C:\Program Files (x86)\RocketDock\RocketDock.exe () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data] O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-1655922889-1840272266-2703523318-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-1655922889-1840272266-2703523318-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95 00 00 00 [binary data] O8:[b]64bit:[/b] - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found O8:[b]64bit:[/b] - Extra context menu item: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm () O8:[b]64bit:[/b] - Extra context menu item: Free YouTube to MP3 Converter - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm () O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.) O8 - Extra context menu item: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm () O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm () O9:[b]64bit:[/b] - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.) O9:[b]64bit:[/b] - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.) O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm () O9 - Extra 'Tools' menuitem : Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm () O9 - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.) O9 - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.) O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O15 - HKU\S-1-5-21-1655922889-1840272266-2703523318-1001\..Trusted Domains: ebay.de ([www] https in Trusted sites) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Java Plug-in 10.25.2) O16 - DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Java Plug-in 1.7.0_17) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab (Java Plug-in 10.25.2) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{667CEF77-DFC6-4BA7-A4F1-CE1E8F86A6E7}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7D624F4F-E9DA-49D3-A2FE-98BCC052A68B}: DhcpNameServer = 192.168.1.1 O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\skype-ie-addon-data - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2011-07-10 14:55:36 | 000,000,000 | R--D | M] - C:\Autorun.inf -- [ NTFS ] O32 - AutoRun File - [2011-05-08 21:57:59 | 000,000,000 | ---- | M] () - D:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2011-07-10 14:55:40 | 000,000,000 | R--D | M] - D:\Autorun.inf -- [ NTFS ] O32 - AutoRun File - [2011-07-10 14:55:43 | 000,000,000 | R--D | M] - F:\Autorun.inf -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2014-03-05 18:47:50 | 000,000,000 | ---D | C] -- C:\FRST [2014-02-24 15:56:50 | 000,254,976 | ---- | C] (Jungo) -- C:\Windows\SysNative\drivers\windrvr6.sys [2014-02-24 15:56:50 | 000,254,976 | ---- | C] (Jungo) -- C:\Windows\SysNative\drivers\PYCH_CoreDriver.sys [2014-02-24 15:56:50 | 000,158,208 | ---- | C] (Jungo) -- C:\Windows\SysWow64\wdapi1021.dll [2014-02-24 15:56:50 | 000,158,208 | ---- | C] (Jungo) -- C:\Windows\SysNative\wdapi1021.dll [2014-02-24 15:56:50 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ClonePlus_Drivers_64bit [2014-02-24 15:56:24 | 000,000,000 | ---D | C] -- C:\Users\Prezes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PYCH International Electronics [2014-02-24 15:49:51 | 000,143,360 | ---- | C] (Jungo) -- C:\Windows\SysNative\wdapi921.dll [2014-02-24 15:49:47 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ClonePlus_Driver [2014-02-24 15:49:11 | 000,000,000 | ---D | C] -- C:\Users\Prezes\AppData\Local\Apps [2014-02-24 15:49:10 | 000,000,000 | ---D | C] -- C:\Users\Prezes\AppData\Local\Deployment [2014-02-19 18:35:40 | 000,000,000 | ---D | C] -- C:\Users\Prezes\Desktop\drzewa [2014-02-18 15:18:46 | 000,000,000 | ---D | C] -- C:\Users\Prezes\Desktop\ciagnik [2014-02-10 19:47:41 | 000,000,000 | ---D | C] -- C:\Users\Prezes\AppData\Local\Apple Computer [2014-02-10 19:47:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2014-02-10 19:46:56 | 000,033,240 | ---- | C] (GEAR Software Inc.) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys [2014-02-10 19:46:56 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE [2014-02-10 19:46:07 | 000,000,000 | ---D | C] -- C:\Program Files\iPod [2014-02-10 19:46:05 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes [2014-02-10 19:46:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes [2014-02-10 19:46:05 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 [2014-02-10 19:43:03 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple [2014-02-10 19:42:28 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour [2014-02-10 15:02:54 | 148,896,080 | ---- | C] (Apple Inc.) -- C:\Users\Prezes\Desktop\iTunes64Setup.exe [2014-02-10 14:39:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PodTrans Pro [2014-02-10 14:39:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iMobie [2014-02-10 14:38:59 | 015,347,792 | ---- | C] (iMobie Inc. ) -- C:\Users\Prezes\Desktop\podtrans-pro-setup.exe [2014-02-10 14:20:49 | 000,000,000 | ---D | C] -- C:\Users\Prezes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CopyTrans Suite [2014-02-10 14:20:44 | 000,000,000 | ---D | C] -- C:\Users\Prezes\AppData\Roaming\WindSolutions [2014-02-10 14:20:37 | 000,000,000 | ---D | C] -- C:\ProgramData\WindSolutions [2014-02-10 14:20:12 | 004,473,792 | ---- | C] (WindSolutions) -- C:\Users\Prezes\Desktop\Install_CopyTrans_Suite.exe [2014-02-06 18:38:21 | 000,000,000 | ---D | C] -- C:\Users\Prezes\AppData\Local\Logitech® Webcam Software [2014-02-06 18:28:06 | 000,000,000 | ---D | C] -- C:\Users\Prezes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\INTERIA.PL [2014-02-06 18:12:55 | 000,000,000 | ---D | C] -- C:\Users\Prezes\Documents\Projekty masek wideo [2014-02-06 17:53:09 | 000,000,000 | ---D | C] -- C:\ProgramData\LogiShrd [2014-02-06 17:51:28 | 000,000,000 | ---D | C] -- C:\Users\Prezes\Documents\SightSpeed Recordings [2014-02-06 17:51:13 | 000,000,000 | ---D | C] -- C:\Users\Prezes\AppData\Local\LogiShrd [2014-02-06 17:48:59 | 000,000,000 | ---D | C] -- C:\Users\Prezes\AppData\Roaming\Leadertech [2014-02-06 17:44:22 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\logishrd [2014-02-06 17:44:21 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\logishrd [2014-02-06 17:43:39 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Logishrd [2014-02-06 17:43:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Logitech [2014-02-06 17:43:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\LWS [2014-02-06 17:41:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech [2014-02-06 17:41:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Logitech [2014-02-06 17:41:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\LogiShrd [2014-02-04 15:50:53 | 000,278,408 | ---- | C] (Hotger) -- C:\Users\Prezes\Desktop\firefox_plugin.exe [2014-02-03 21:00:31 | 000,000,000 | ---D | C] -- C:\Users\Prezes\Desktop\test [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2014-03-05 19:02:04 | 000,000,296 | ---- | M] () -- C:\Windows\tasks\SaveSense.job [2014-03-05 18:56:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Prezes\Desktop\OTL.exe [2014-03-05 18:47:05 | 002,157,056 | ---- | M] (Farbar) -- C:\Users\Prezes\Desktop\FRST64.exe [2014-03-05 18:46:03 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2014-03-05 18:28:10 | 000,001,044 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2014-03-05 18:18:29 | 000,001,048 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2014-03-05 18:08:12 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\SaveSenseLiveUpdateTaskMachineUA.job [2014-03-05 07:52:26 | 000,039,360 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2014-03-05 07:52:26 | 000,039,360 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2014-03-05 07:44:44 | 000,000,000 | -H-- | M] () -- C:\ProgramData\cm-lock [2014-03-05 07:43:41 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl [2014-03-05 07:43:13 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\SaveSenseLiveUpdateTaskMachineCore.job [2014-03-05 07:42:57 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2014-03-05 07:42:51 | 1558,847,488 | -HS- | M] () -- C:\hiberfil.sys [2014-03-03 22:51:42 | 006,494,927 | ---- | M] () -- C:\Users\Prezes\Desktop\Stefan Ossowiecki - Świat mego ducha i wizje przyszłości.pdf [2014-03-01 22:09:16 | 000,019,639 | ---- | M] () -- C:\Users\Prezes\Desktop\bibliografia1.odt [2014-03-01 20:54:33 | 001,145,495 | ---- | M] () -- C:\Users\Prezes\Desktop\bibliografia.pdf [2014-02-28 23:00:14 | 027,407,801 | ---- | M] () -- C:\Users\Prezes\Desktop\104968 Opt.pdf [2014-02-27 09:38:55 | 000,013,626 | ---- | M] () -- C:\Users\Prezes\Desktop\wypowiedzenie_umowy_tv_nc.odt [2014-02-27 09:30:41 | 000,108,615 | ---- | M] () -- C:\Users\Prezes\Desktop\Regulamin swiadczenia uslug.pdf [2014-02-26 10:48:10 | 000,178,401 | ---- | M] () -- C:\Users\Prezes\Desktop\serwis_ekspres_do_kawy.JPG [2014-02-25 19:30:52 | 001,689,752 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2014-02-25 19:30:52 | 000,747,188 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat [2014-02-25 19:30:52 | 000,665,118 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2014-02-25 19:30:52 | 000,153,996 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat [2014-02-25 19:30:52 | 000,125,072 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2014-02-24 15:56:24 | 000,000,322 | ---- | M] () -- C:\Users\Prezes\Desktop\Clone+ Update.appref-ms [2014-02-24 15:56:16 | 000,254,976 | ---- | M] (Jungo) -- C:\Windows\SysNative\drivers\PYCH_CoreDriver.sys [2014-02-24 15:56:14 | 000,158,208 | ---- | M] (Jungo) -- C:\Windows\SysWow64\wdapi1021.dll [2014-02-24 15:56:14 | 000,158,208 | ---- | M] (Jungo) -- C:\Windows\SysNative\wdapi1021.dll [2014-02-24 15:56:10 | 000,254,976 | ---- | M] (Jungo) -- C:\Windows\SysNative\drivers\windrvr6.sys [2014-02-24 15:49:50 | 000,143,360 | ---- | M] (Jungo) -- C:\Windows\SysNative\wdapi921.dll [2014-02-24 15:32:38 | 001,566,626 | ---- | M] () -- C:\Users\Prezes\Desktop\Instrukcja_obslugi_Clone+_Home_Edition_150.pdf [2014-02-24 15:29:36 | 000,484,808 | ---- | M] () -- C:\Users\Prezes\Desktop\setup.exe [2014-02-24 12:28:39 | 000,052,417 | ---- | M] () -- C:\Users\Prezes\Desktop\faktura_ORI kwiecien2.pdf [2014-02-24 12:28:24 | 000,051,572 | ---- | M] () -- C:\Users\Prezes\Desktop\faktura_ORI kwiecien.pdf [2014-02-23 18:34:26 | 000,615,141 | ---- | M] () -- C:\Users\Prezes\Desktop\lista_obrusow2.pdf [2014-02-23 18:33:50 | 000,687,002 | ---- | M] () -- C:\Users\Prezes\Desktop\lista_obrusow2.odt [2014-02-23 12:44:36 | 000,029,569 | ---- | M] () -- C:\Users\Prezes\Desktop\jansen.odt [2014-02-23 12:41:22 | 001,781,934 | ---- | M] () -- C:\Users\Prezes\Desktop\113_AW_2_OT-4351-27_analiza_ekonomiczna_Zytiga_rak_gruczolu_krokowego_2013.04.30.pdf [2014-02-23 12:37:32 | 000,598,196 | ---- | M] () -- C:\Users\Prezes\Desktop\Zytiga ChPL 16.01.2014_3.pdf [2014-02-23 12:36:57 | 000,189,278 | ---- | M] () -- C:\Users\Prezes\Desktop\Zytiga UdP 16.01.2014_1.pdf [2014-02-22 15:37:46 | 000,013,986 | ---- | M] () -- C:\Users\Prezes\Desktop\groby.odt [2014-02-21 14:46:36 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2014-02-21 14:46:36 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2014-02-21 11:15:22 | 000,119,832 | ---- | M] () -- C:\Users\Prezes\Desktop\Potwierdzenie_TC.pdf [2014-02-20 08:49:32 | 000,044,678 | ---- | M] () -- C:\Users\Prezes\Desktop\PRO-0705-02-14___oe4723.pdf [2014-02-19 22:22:50 | 000,019,326 | ---- | M] () -- C:\Users\Prezes\Desktop\serwis do kawy1.odt [2014-02-18 21:13:31 | 000,342,714 | ---- | M] () -- C:\Users\Prezes\Desktop\PURIZOL-Oferta cenowa na natrysk izolacji poliuretanowej 2013.pdf [2014-02-18 16:57:44 | 000,080,227 | ---- | M] () -- C:\Users\Prezes\Desktop\Przewodnik-po-ofercie-smart-HD.pdf [2014-02-18 15:28:41 | 001,359,654 | ---- | M] () -- C:\Users\Prezes\Desktop\ciagnik_Jasia3.jpg [2014-02-18 15:27:19 | 001,179,919 | ---- | M] () -- C:\Users\Prezes\Desktop\ciagnik_Jasia2.jpg [2014-02-18 15:27:03 | 001,330,936 | ---- | M] () -- C:\Users\Prezes\Desktop\ciagnik_Jasia1.jpg [2014-02-18 15:26:45 | 001,042,909 | ---- | M] () -- C:\Users\Prezes\Desktop\ciagnik_Jasia.jpg [2014-02-16 21:38:41 | 000,163,214 | ---- | M] () -- C:\Users\Prezes\Desktop\recaro3.jpg [2014-02-16 21:29:51 | 000,098,053 | ---- | M] () -- C:\Users\Prezes\Desktop\100_0559.jpg [2014-02-16 21:29:13 | 000,286,400 | ---- | M] () -- C:\Users\Prezes\Desktop\86E826DF-35D5-421D-9B98-29037BD4EBD3-6427-0000023213940F3C_zps26602571.jpg [2014-02-14 17:44:58 | 000,309,427 | ---- | M] () -- C:\Users\Prezes\Desktop\1391433585_by_piksel169_500.jpg [2014-02-14 09:56:41 | 000,119,884 | ---- | M] () -- C:\Users\Prezes\Desktop\Potwierdzenie_zwrotuSV410.pdf [2014-02-14 09:29:21 | 000,023,459 | ---- | M] () -- C:\Users\Prezes\Desktop\6581671093_1.jpg [2014-02-14 09:29:21 | 000,023,436 | ---- | M] () -- C:\Users\Prezes\Desktop\6581671093_2.jpg [2014-02-14 09:26:50 | 000,134,996 | ---- | M] () -- C:\Users\Prezes\Desktop\bilety.JPG [2014-02-14 00:02:11 | 000,000,142 | ---- | M] () -- C:\Users\Prezes\AppData\Roaming\WB.CFG [2014-02-13 23:59:25 | 000,101,404 | ---- | M] () -- C:\Users\Prezes\Desktop\ciagnik.JPG [2014-02-13 12:02:01 | 000,147,499 | ---- | M] () -- C:\Users\Prezes\Desktop\Wpis_CEIDG.pdf [2014-02-13 11:53:07 | 000,015,641 | ---- | M] () -- C:\Users\Prezes\Desktop\czarny_etui_logo.JPG [2014-02-13 11:52:44 | 000,242,140 | ---- | M] () -- C:\Users\Prezes\Desktop\info1.jpg [2014-02-13 11:50:28 | 000,185,043 | ---- | M] () -- C:\Users\Prezes\Desktop\wisniowe_etui_logo.JPG [2014-02-13 11:27:55 | 000,119,887 | ---- | M] () -- C:\Users\Prezes\Desktop\Potwierdzenie_zaglowki.pdf [2014-02-12 19:17:05 | 000,073,717 | ---- | M] () -- C:\Users\Prezes\Desktop\1391881964_hqko0k_600.jpg [2014-02-12 19:16:36 | 000,075,799 | ---- | M] () -- C:\Users\Prezes\Desktop\1392062740_5cd3cv_600.jpg [2014-02-12 19:12:58 | 000,119,228 | ---- | M] () -- C:\Users\Prezes\Desktop\1392039263_qhmp90_600.jpg [2014-02-12 14:46:28 | 000,199,851 | ---- | M] () -- C:\Users\Prezes\Desktop\Sendit-LP-2014-02-12.pdf [2014-02-10 19:47:13 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk [2014-02-10 15:05:45 | 148,896,080 | ---- | M] (Apple Inc.) -- C:\Users\Prezes\Desktop\iTunes64Setup.exe [2014-02-10 14:39:49 | 000,001,250 | ---- | M] () -- C:\Users\Public\Desktop\PodTrans Pro.lnk [2014-02-10 14:39:12 | 015,347,792 | ---- | M] (iMobie Inc. ) -- C:\Users\Prezes\Desktop\podtrans-pro-setup.exe [2014-02-10 14:20:49 | 000,001,388 | ---- | M] () -- C:\Users\Prezes\Desktop\CopyTrans Control Center.lnk [2014-02-10 14:20:16 | 004,473,792 | ---- | M] (WindSolutions) -- C:\Users\Prezes\Desktop\Install_CopyTrans_Suite.exe [2014-02-10 13:31:39 | 000,200,881 | ---- | M] () -- C:\Users\Prezes\Desktop\Sendit-LP-2014-02-10.pdf [2014-02-06 20:04:03 | 000,001,926 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2014-02-06 20:03:33 | 001,038,072 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys [2014-02-06 20:03:33 | 000,421,704 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswsp.sys [2014-02-06 20:03:33 | 000,080,184 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswstm.sys [2014-02-06 20:03:33 | 000,078,648 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys [2014-02-06 20:03:32 | 000,334,136 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe [2014-02-06 20:03:32 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr [2014-02-06 19:13:37 | 334,630,492 | ---- | M] () -- C:\Windows\MEMORY.DMP [2014-02-06 18:30:25 | 000,001,624 | ---- | M] () -- C:\Users\Public\Desktop\Logitech Webcam Software .lnk [2014-02-06 18:28:06 | 000,001,142 | ---- | M] () -- C:\Users\Prezes\Desktop\logitech.lnk [2014-02-06 18:02:00 | 000,050,434 | ---- | M] () -- C:\Users\Prezes\Desktop\Greek_Mask.LVF [2014-02-06 17:50:06 | 000,000,996 | ---- | M] () -- C:\Users\Public\Desktop\Logitech Vid.lnk [2014-02-05 16:56:10 | 007,754,821 | ---- | M] () -- C:\Users\Prezes\Desktop\E-500_MANUAL_PL.pdf [2014-02-05 16:53:30 | 016,326,314 | ---- | M] () -- C:\Users\Prezes\Desktop\EVOLT_E-500_Advanced_Manual_EN.pdf [2014-02-05 16:52:50 | 016,326,314 | ---- | M] () -- C:\Users\Prezes\Desktop\EVOLT_E-500_Advanced_Manual_EN(1).pdf [2014-02-04 16:45:22 | 010,678,891 | ---- | M] () -- C:\Users\Prezes\Desktop\Exaited - Nie Unikaj.mp3 [2014-02-04 15:51:13 | 008,281,916 | ---- | M] () -- C:\Users\Prezes\Desktop\DDK RPK OD ZAWSZE NA ZAWSZE.mp3 [2014-02-04 15:50:54 | 000,278,408 | ---- | M] (Hotger) -- C:\Users\Prezes\Desktop\firefox_plugin.exe [2014-02-04 15:35:32 | 000,131,591 | ---- | M] () -- C:\Users\Prezes\Desktop\1391276508_by_katalika_600.jpg [2014-02-04 15:31:01 | 000,077,709 | ---- | M] () -- C:\Users\Prezes\Desktop\1391285446_by_RAFALOSKAR_600.jpg [2014-02-04 15:30:31 | 000,316,147 | ---- | M] () -- C:\Users\Prezes\Desktop\1391362430_qyaeap_600.jpg [2014-02-04 15:26:44 | 000,119,914 | ---- | M] () -- C:\Users\Prezes\Desktop\1391368032_tefsog_600.jpg [2014-02-04 15:08:22 | 000,119,829 | ---- | M] () -- C:\Users\Prezes\Desktop\Potwierdzenie_c330.pdf [color=#E56717]========== Files Created - No Company Name ==========[/color] [2014-03-05 07:44:44 | 000,000,000 | -H-- | C] () -- C:\ProgramData\cm-lock [2014-03-03 22:51:33 | 006,494,927 | ---- | C] () -- C:\Users\Prezes\Desktop\Stefan Ossowiecki - Świat mego ducha i wizje przyszłości.pdf [2014-03-01 21:45:37 | 000,019,639 | ---- | C] () -- C:\Users\Prezes\Desktop\bibliografia1.odt [2014-03-01 20:54:44 | 001,145,495 | ---- | C] () -- C:\Users\Prezes\Desktop\bibliografia.pdf [2014-02-28 22:59:36 | 027,407,801 | ---- | C] () -- C:\Users\Prezes\Desktop\104968 Opt.pdf [2014-02-27 09:30:49 | 000,108,615 | ---- | C] () -- C:\Users\Prezes\Desktop\Regulamin swiadczenia uslug.pdf [2014-02-26 10:48:50 | 000,178,401 | ---- | C] () -- C:\Users\Prezes\Desktop\serwis_ekspres_do_kawy.JPG [2014-02-25 15:27:43 | 000,013,626 | ---- | C] () -- C:\Users\Prezes\Desktop\wypowiedzenie_umowy_tv_nc.odt [2014-02-24 15:56:24 | 000,000,322 | ---- | C] () -- C:\Users\Prezes\Desktop\Clone+ Update.appref-ms [2014-02-24 15:32:42 | 001,566,626 | ---- | C] () -- C:\Users\Prezes\Desktop\Instrukcja_obslugi_Clone+_Home_Edition_150.pdf [2014-02-24 15:29:31 | 000,484,808 | ---- | C] () -- C:\Users\Prezes\Desktop\setup.exe [2014-02-24 12:28:37 | 000,052,417 | ---- | C] () -- C:\Users\Prezes\Desktop\faktura_ORI kwiecien2.pdf [2014-02-24 12:28:20 | 000,051,572 | ---- | C] () -- C:\Users\Prezes\Desktop\faktura_ORI kwiecien.pdf [2014-02-23 18:34:24 | 000,615,141 | ---- | C] () -- C:\Users\Prezes\Desktop\lista_obrusow2.pdf [2014-02-23 18:29:07 | 004,558,869 | ---- | C] () -- C:\Users\Prezes\Desktop\urządzenia gastronomiczne.pdf [2014-02-23 18:28:04 | 010,162,499 | ---- | C] () -- C:\Users\Prezes\Desktop\urządzenia gastronomiczne_bez_cen_propozycja_rodis1982.odt [2014-02-23 18:25:59 | 000,687,002 | ---- | C] () -- C:\Users\Prezes\Desktop\lista_obrusow2.odt [2014-02-23 12:43:27 | 000,029,569 | ---- | C] () -- C:\Users\Prezes\Desktop\jansen.odt [2014-02-23 12:41:26 | 001,781,934 | ---- | C] () -- C:\Users\Prezes\Desktop\113_AW_2_OT-4351-27_analiza_ekonomiczna_Zytiga_rak_gruczolu_krokowego_2013.04.30.pdf [2014-02-23 12:37:37 | 000,598,196 | ---- | C] () -- C:\Users\Prezes\Desktop\Zytiga ChPL 16.01.2014_3.pdf [2014-02-23 12:37:09 | 000,189,278 | ---- | C] () -- C:\Users\Prezes\Desktop\Zytiga UdP 16.01.2014_1.pdf [2014-02-22 15:37:33 | 000,013,986 | ---- | C] () -- C:\Users\Prezes\Desktop\groby.odt [2014-02-21 11:15:33 | 000,119,832 | ---- | C] () -- C:\Users\Prezes\Desktop\Potwierdzenie_TC.pdf [2014-02-20 08:49:30 | 000,044,678 | ---- | C] () -- C:\Users\Prezes\Desktop\PRO-0705-02-14___oe4723.pdf [2014-02-19 22:21:16 | 000,019,326 | ---- | C] () -- C:\Users\Prezes\Desktop\serwis do kawy1.odt [2014-02-18 21:13:31 | 000,342,714 | ---- | C] () -- C:\Users\Prezes\Desktop\PURIZOL-Oferta cenowa na natrysk izolacji poliuretanowej 2013.pdf [2014-02-18 16:57:48 | 000,080,227 | ---- | C] () -- C:\Users\Prezes\Desktop\Przewodnik-po-ofercie-smart-HD.pdf [2014-02-18 15:28:40 | 001,359,654 | ---- | C] () -- C:\Users\Prezes\Desktop\ciagnik_Jasia3.jpg [2014-02-18 15:27:19 | 001,179,919 | ---- | C] () -- C:\Users\Prezes\Desktop\ciagnik_Jasia2.jpg [2014-02-18 15:27:03 | 001,330,936 | ---- | C] () -- C:\Users\Prezes\Desktop\ciagnik_Jasia1.jpg [2014-02-18 15:26:44 | 001,042,909 | ---- | C] () -- C:\Users\Prezes\Desktop\ciagnik_Jasia.jpg [2014-02-16 21:38:41 | 000,163,214 | ---- | C] () -- C:\Users\Prezes\Desktop\recaro3.jpg [2014-02-16 21:29:50 | 000,098,053 | ---- | C] () -- C:\Users\Prezes\Desktop\100_0559.jpg [2014-02-16 21:29:07 | 000,286,400 | ---- | C] () -- C:\Users\Prezes\Desktop\86E826DF-35D5-421D-9B98-29037BD4EBD3-6427-0000023213940F3C_zps26602571.jpg [2014-02-14 17:44:56 | 000,309,427 | ---- | C] () -- C:\Users\Prezes\Desktop\1391433585_by_piksel169_500.jpg [2014-02-14 09:56:51 | 000,119,884 | ---- | C] () -- C:\Users\Prezes\Desktop\Potwierdzenie_zwrotuSV410.pdf [2014-02-14 09:29:15 | 000,023,436 | ---- | C] () -- C:\Users\Prezes\Desktop\6581671093_2.jpg [2014-02-14 09:29:14 | 000,023,459 | ---- | C] () -- C:\Users\Prezes\Desktop\6581671093_1.jpg [2014-02-14 09:26:50 | 000,134,996 | ---- | C] () -- C:\Users\Prezes\Desktop\bilety.JPG [2014-02-13 23:59:24 | 000,101,404 | ---- | C] () -- C:\Users\Prezes\Desktop\ciagnik.JPG [2014-02-13 12:02:10 | 000,147,499 | ---- | C] () -- C:\Users\Prezes\Desktop\Wpis_CEIDG.pdf [2014-02-13 11:53:07 | 000,015,641 | ---- | C] () -- C:\Users\Prezes\Desktop\czarny_etui_logo.JPG [2014-02-13 11:52:44 | 000,242,140 | ---- | C] () -- C:\Users\Prezes\Desktop\info1.jpg [2014-02-13 11:50:17 | 000,185,043 | ---- | C] () -- C:\Users\Prezes\Desktop\wisniowe_etui_logo.JPG [2014-02-13 11:28:15 | 000,119,887 | ---- | C] () -- C:\Users\Prezes\Desktop\Potwierdzenie_zaglowki.pdf [2014-02-12 19:17:05 | 000,073,717 | ---- | C] () -- C:\Users\Prezes\Desktop\1391881964_hqko0k_600.jpg [2014-02-12 19:16:36 | 000,075,799 | ---- | C] () -- C:\Users\Prezes\Desktop\1392062740_5cd3cv_600.jpg [2014-02-12 19:12:54 | 000,119,228 | ---- | C] () -- C:\Users\Prezes\Desktop\1392039263_qhmp90_600.jpg [2014-02-12 14:46:30 | 000,199,851 | ---- | C] () -- C:\Users\Prezes\Desktop\Sendit-LP-2014-02-12.pdf [2014-02-10 19:47:13 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk [2014-02-10 14:39:49 | 000,001,250 | ---- | C] () -- C:\Users\Public\Desktop\PodTrans Pro.lnk [2014-02-10 14:20:49 | 000,001,388 | ---- | C] () -- C:\Users\Prezes\Desktop\CopyTrans Control Center.lnk [2014-02-10 13:31:45 | 000,200,881 | ---- | C] () -- C:\Users\Prezes\Desktop\Sendit-LP-2014-02-10.pdf [2014-02-06 18:28:06 | 000,001,142 | ---- | C] () -- C:\Users\Prezes\Desktop\logitech.lnk [2014-02-06 18:02:09 | 000,050,434 | ---- | C] () -- C:\Users\Prezes\Desktop\Greek_Mask.LVF [2014-02-06 17:50:06 | 000,000,996 | ---- | C] () -- C:\Users\Public\Desktop\Logitech Vid.lnk [2014-02-06 17:41:58 | 000,001,624 | ---- | C] () -- C:\Users\Public\Desktop\Logitech Webcam Software .lnk [2014-02-05 16:56:14 | 007,754,821 | ---- | C] () -- C:\Users\Prezes\Desktop\E-500_MANUAL_PL.pdf [2014-02-05 16:52:49 | 016,326,314 | ---- | C] () -- C:\Users\Prezes\Desktop\EVOLT_E-500_Advanced_Manual_EN(1).pdf [2014-02-05 16:52:42 | 016,326,314 | ---- | C] () -- C:\Users\Prezes\Desktop\EVOLT_E-500_Advanced_Manual_EN.pdf [2014-02-04 16:45:25 | 010,678,891 | ---- | C] () -- C:\Users\Prezes\Desktop\Exaited - Nie Unikaj.mp3 [2014-02-04 15:51:10 | 008,281,916 | ---- | C] () -- C:\Users\Prezes\Desktop\DDK RPK OD ZAWSZE NA ZAWSZE.mp3 [2014-02-04 15:35:32 | 000,131,591 | ---- | C] () -- C:\Users\Prezes\Desktop\1391276508_by_katalika_600.jpg [2014-02-04 15:31:01 | 000,077,709 | ---- | C] () -- C:\Users\Prezes\Desktop\1391285446_by_RAFALOSKAR_600.jpg [2014-02-04 15:30:30 | 000,316,147 | ---- | C] () -- C:\Users\Prezes\Desktop\1391362430_qyaeap_600.jpg [2014-02-04 15:26:44 | 000,119,914 | ---- | C] () -- C:\Users\Prezes\Desktop\1391368032_tefsog_600.jpg [2014-02-04 15:06:37 | 000,119,829 | ---- | C] () -- C:\Users\Prezes\Desktop\Potwierdzenie_c330.pdf [2014-02-01 00:02:11 | 000,195,072 | ---- | C] () -- C:\Windows\SysWow64\upd.exe [2014-01-20 21:02:03 | 000,000,142 | ---- | C] () -- C:\Users\Prezes\AppData\Roaming\WB.CFG [2012-05-30 16:43:51 | 000,000,040 | ---- | C] () -- C:\Windows\wininit.ini [2012-04-21 21:53:55 | 002,463,976 | ---- | C] () -- C:\Windows\SysWow64\NPSWF32.dll [2012-04-12 18:51:07 | 000,000,756 | ---- | C] () -- C:\Users\Prezes\.recently-used.xbel [2011-10-08 18:25:41 | 000,009,728 | ---- | C] () -- C:\Users\Prezes\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011-07-31 14:42:18 | 000,453,954 | ---- | C] () -- C:\Users\Prezes\.linkassistant.properties [2011-07-31 12:20:07 | 002,744,105 | ---- | C] () -- C:\Users\Prezes\.websiteauditor.properties [2011-07-31 12:19:57 | 000,210,061 | ---- | C] () -- C:\Users\Prezes\.ranktracker.properties [2011-07-30 21:29:57 | 000,500,862 | ---- | C] () -- C:\Users\Prezes\.spyglass.properties [color=#E56717]========== ZeroAccess Check ==========[/color] [2009-07-14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2010-11-21 04:23:55 | 014,174,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2010-11-21 04:24:02 | 012,872,192 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== LOP Check ==========[/color] [2011-11-05 10:23:39 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\.wtw [2013-02-17 22:52:53 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\Analysis Lotto [2013-07-24 21:22:55 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\Audacity [2013-10-24 09:52:18 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\AVAST Software [2013-12-03 23:38:44 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\ColorCop [2012-07-16 21:36:59 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\DAEMON Tools Lite [2014-01-20 20:32:05 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\DVDVideoSoft [2011-10-14 23:37:02 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\Echo Software [2012-02-22 16:38:33 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\EurekaLog [2011-10-28 20:32:42 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\EXIF Date Changer [2014-03-05 17:51:58 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\FileZilla [2011-09-07 01:59:18 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\FlexLoader.346A729E60C8ACAB5B256CEBF2755FFA037052EC.1 [2011-10-08 18:49:19 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\Full [2012-06-13 19:18:39 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\Gadu-Gadu 10 [2014-03-05 18:31:14 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\GG [2011-06-15 12:53:59 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\GHISLER [2011-11-13 20:36:18 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\gtk-2.0 [2011-10-10 18:13:28 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\inkscape [2011-06-12 19:59:54 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\INTERIAPL [2012-02-04 17:08:11 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\Krzysztof Mortka [2011-09-28 18:30:58 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\ldw_data [2014-02-06 17:48:59 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\Leadertech [2014-01-20 20:22:42 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\MAGIX [2011-09-07 01:43:28 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\marwer.pl [2014-01-22 12:35:44 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\Notepad++ [2012-10-21 18:26:31 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\Nowe Gadu-Gadu [2014-01-20 20:02:13 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\OpenCandy [2011-06-14 20:30:02 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\OpenOffice.org [2011-10-17 14:36:38 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\PLAY ONLINE [2013-06-18 20:17:04 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\ProgeCAD [2011-10-03 12:15:17 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\Samsung [2014-01-20 20:02:34 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\SaveSense [2011-11-02 03:35:24 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\SeoAdministrator [2011-07-02 19:36:00 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\TAXCARE [2013-12-15 18:10:33 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\Thunderbird [2012-11-23 13:19:10 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\TP-LINK [2013-09-01 16:14:01 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\Unity [2013-09-15 22:16:50 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\uTorrent [2012-08-15 21:48:24 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\wargaming.net [2012-02-18 21:15:11 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\Win7codecs [2014-02-10 15:02:00 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\WindSolutions [2014-03-03 16:08:48 | 000,000,000 | ---D | M] -- C:\Users\Prezes\AppData\Roaming\XnView [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 981 bytes -> C:\Users\Prezes\Desktop\[Place z Allegro za uslugi] Zakonczenie transakcji w Allegro.eml:OECustomProperty @Alternate Data Stream - 224 bytes -> C:\ProgramData\TEMP:8927A071 @Alternate Data Stream - 172 bytes -> C:\ProgramData\TEMP:CF54F1CA @Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:E8BE05FA < End of report >