OTL logfile created on: 2014-03-09 18:46:58 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\admin\Moje dokumenty\Pobieranie Windows XP Home Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 1,99 Gb Total Physical Memory | 0,74 Gb Available Physical Memory | 37,19% Memory free 3,32 Gb Paging File | 2,37 Gb Available in Paging File | 71,27% Paging File free Paging file location(s): C:\pagefile.sys 1521 1521 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 37,25 Gb Total Space | 18,04 Gb Free Space | 48,44% Space Free | Partition Type: NTFS Drive E: | 37,24 Gb Total Space | 7,49 Gb Free Space | 20,11% Space Free | Partition Type: NTFS Computer Name: USER | User Name: admin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2014-03-09 18:44:16 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\admin\Moje dokumenty\Pobieranie\OTL.exe PRC - [2014-03-09 18:20:33 | 001,145,344 | ---- | M] (Farbar) -- C:\Documents and Settings\admin\Moje dokumenty\Pobieranie\FRST.exe PRC - [2014-03-09 14:42:12 | 000,111,904 | ---- | M] () -- C:\Program Files\Surftastic\bin\utilSurftastic.exe PRC - [2014-03-07 21:57:30 | 000,111,904 | ---- | M] () -- C:\Program Files\Surftastic\updateSurftastic.exe PRC - [2014-02-26 07:44:20 | 000,508,016 | ---- | M] (Cherished Technololgy LIMITED) -- C:\Documents and Settings\All Users\Dane aplikacji\IePluginService\PluginService.exe PRC - [2014-02-23 11:14:39 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2014-02-05 11:54:50 | 000,390,256 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Thunderbird\thunderbird.exe PRC - [2014-01-22 12:19:38 | 003,788,816 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgidsagent.exe PRC - [2014-01-22 12:17:36 | 004,962,320 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgui.exe PRC - [2013-12-05 12:48:12 | 000,680,976 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgemcx.exe PRC - [2013-11-25 22:03:56 | 000,591,888 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgcsrvx.exe PRC - [2013-11-25 22:00:24 | 000,892,944 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgnsx.exe PRC - [2013-11-13 22:03:10 | 000,729,616 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgrsx.exe PRC - [2013-09-24 01:33:08 | 000,348,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgwdsvc.exe PRC - [2012-12-17 14:27:26 | 001,927,096 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe PRC - [2012-12-17 14:27:24 | 001,724,344 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe PRC - [2008-04-14 18:21:16 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2006-03-04 17:40:30 | 000,882,176 | ---- | M] () -- C:\Program Files\Kalendarz XP\Kalendarz.exe PRC - [2005-03-31 10:18:49 | 000,790,528 | ---- | M] (sms-express.com) -- C:\Program Files\Gadu-Gadu\gg.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2014-03-09 14:42:12 | 000,111,904 | ---- | M] () -- C:\Program Files\Surftastic\bin\utilSurftastic.exe MOD - [2014-03-07 21:57:30 | 000,111,904 | ---- | M] () -- C:\Program Files\Surftastic\updateSurftastic.exe MOD - [2014-02-23 11:14:38 | 003,578,992 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll MOD - [2014-02-13 07:21:31 | 000,212,992 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8cd995f00848816e3ec49dc326e3d49b\System.ServiceProcess.ni.dll MOD - [2014-02-13 07:21:17 | 000,998,400 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\5c157466d360a10b2c97e94b41ddc588\System.Management.ni.dll MOD - [2014-02-13 07:19:20 | 000,978,944 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\4b6e70acd99dc22e29b7fc8f9ac340c4\System.Configuration.ni.dll MOD - [2014-02-13 07:11:22 | 005,462,016 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\7faf645dc46781225cb722edf9e1e738\System.Xml.ni.dll MOD - [2014-02-13 07:11:10 | 012,434,432 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1cdfe1998ad6794db3237006906c6fa2\System.Windows.Forms.ni.dll MOD - [2014-02-13 07:10:40 | 001,593,344 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\424bff3295c6e7539cc6df62b9425bd0\System.Drawing.ni.dll MOD - [2014-02-13 07:07:25 | 007,977,984 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\4b0455ae94e3cecca4bb3ba8c96828c9\System.ni.dll MOD - [2014-02-13 07:07:03 | 011,497,984 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\dae02331a443fb52216ca83292cb2f21\mscorlib.ni.dll MOD - [2014-02-05 11:54:54 | 003,019,376 | ---- | M] () -- C:\Program Files\Mozilla Thunderbird\mozjs.dll MOD - [2014-02-05 11:54:54 | 000,158,832 | ---- | M] () -- C:\Program Files\Mozilla Thunderbird\nsldap32v60.dll MOD - [2014-02-05 11:54:54 | 000,023,152 | ---- | M] () -- C:\Program Files\Mozilla Thunderbird\nsldappr32v60.dll MOD - [2013-12-18 19:43:08 | 000,300,544 | ---- | M] () -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.POL MOD - [2008-09-16 20:18:06 | 000,132,608 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll MOD - [2006-03-04 17:40:30 | 000,882,176 | ---- | M] () -- C:\Program Files\Kalendarz XP\Kalendarz.exe MOD - [2005-03-31 16:07:49 | 000,405,504 | ---- | M] () -- C:\Program Files\Gadu-Gadu\update.dll MOD - [2003-11-24 08:39:46 | 000,036,864 | ---- | M] () -- C:\Program Files\Gadu-Gadu\Crypto.dll MOD - [2003-06-23 08:18:42 | 000,786,432 | ---- | M] () -- C:\Program Files\Gadu-Gadu\libeay32.dll MOD - [2003-06-23 08:18:42 | 000,159,744 | ---- | M] () -- C:\Program Files\Gadu-Gadu\ssleay32.dll MOD - [2001-01-26 15:23:56 | 000,057,856 | ---- | M] () -- C:\WINDOWS\system32\spool\prtprocs\w32x86\LMPRINT.DLL MOD - [2000-07-07 17:42:56 | 000,032,768 | ---- | M] () -- C:\Program Files\Gadu-Gadu\ggwhook.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt) SRV - [2014-03-09 14:42:12 | 000,111,904 | ---- | M] () [Auto | Running] -- C:\Program Files\Surftastic\bin\utilSurftastic.exe -- (Util Surftastic) SRV - [2014-03-07 21:57:30 | 000,111,904 | ---- | M] () [Auto | Running] -- C:\Program Files\Surftastic\updateSurftastic.exe -- (Update Surftastic) SRV - [2014-02-26 07:44:20 | 000,508,016 | ---- | M] (Cherished Technololgy LIMITED) [Auto | Running] -- C:\Documents and Settings\All Users\Dane aplikacji\IePluginService\PluginService.exe -- (IePluginService) SRV - [2014-02-23 11:14:38 | 000,118,896 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2014-02-23 11:13:46 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2014-01-22 12:19:38 | 003,788,816 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2014\avgidsagent.exe -- (AVGIDSAgent) SRV - [2013-10-23 08:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2013-09-24 01:33:08 | 000,348,008 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2014\avgwdsvc.exe -- (avgwd) SRV - [2012-12-17 14:27:24 | 001,724,344 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc) SRV - [2012-05-04 18:29:46 | 000,161,664 | ---- | M] (Oracle Corporation) [Disabled | Stopped] -- C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe -- (JavaQuickStarterService) SRV - [2012-03-12 10:05:33 | 000,232,288 | ---- | M] () [Disabled | Stopped] -- C:\Documents and Settings\All Users\Dane aplikacji\MobileBrServ\mbbService.exe -- (Mobile Broadband HL Service) SRV - [2006-08-11 15:52:28 | 000,155,648 | ---- | M] (Dell Inc.) [Disabled | Stopped] -- C:\Program Files\Dell\OpenManage\Client\Iap.exe -- (Iap) SRV - [2004-08-04 13:00:00 | 000,003,584 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\System32\regedt32.exe -- (.EsetTrialReset) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbmdm.sys -- (hwdatacard) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys -- (esgiguard) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - [2014-01-19 21:46:54 | 000,022,808 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgidsshimx.sys -- (AVGIDSShim) DRV - [2013-11-25 21:56:22 | 000,210,712 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgidsdriverx.sys -- (AVGIDSDriver) DRV - [2013-11-25 21:56:22 | 000,149,272 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\avgidshx.sys -- (AVGIDSHX) DRV - [2013-11-25 21:49:18 | 000,120,600 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgdiskx.sys -- (Avgdiskx) DRV - [2013-10-31 23:00:28 | 000,176,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86) DRV - [2013-10-31 22:30:08 | 000,222,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\avglogx.sys -- (Avglogx) DRV - [2013-10-01 00:49:38 | 000,102,712 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86) DRV - [2013-09-10 00:43:20 | 000,027,448 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\avgrkx86.sys -- (Avgrkx86) DRV - [2013-08-01 15:08:52 | 000,193,848 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix) DRV - [2012-11-16 16:51:36 | 000,010,088 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv) DRV - [2011-03-27 21:29:22 | 000,436,792 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd) DRV - [2009-11-19 13:04:32 | 000,009,856 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc) DRV - [2006-06-22 16:40:28 | 000,018,432 | ---- | M] (Dell Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\omci.sys -- (omci) DRV - [2006-03-27 15:02:06 | 000,074,752 | ---- | M] (Novatel Wireless Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NWADIenum.sys -- (NWADI) DRV - [2005-07-21 17:12:34 | 000,134,272 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k) DRV - [2004-09-17 09:02:54 | 000,732,928 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com/?type=hp&ts=1394368732&from=amt&uid=ST3808110AS_5LR4DKQKXXXX5LR4DKQK IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.awesomehp.com/web/?type=ds&ts=1394368732&from=amt&uid=ST3808110AS_5LR4DKQKXXXX5LR4DKQK&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=ds&ts=1394368732&from=amt&uid=ST3808110AS_5LR4DKQKXXXX5LR4DKQK&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.awesomehp.com/?type=hp&ts=1394368732&from=amt&uid=ST3808110AS_5LR4DKQKXXXX5LR4DKQK IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.awesomehp.com/web/?type=ds&ts=1394368732&from=amt&uid=ST3808110AS_5LR4DKQKXXXX5LR4DKQK&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.awesomehp.com/web/?type=ds&ts=1394368732&from=amt&uid=ST3808110AS_5LR4DKQKXXXX5LR4DKQK&q={searchTerms} IE - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.awesomehp.com/web/?type=ds&ts=1394368732&from=amt&uid=ST3808110AS_5LR4DKQKXXXX5LR4DKQK&q={searchTerms} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-425070134-1683481979-3785275989-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.awesomehp.com/?type=hp&ts=1394368732&from=amt&uid=ST3808110AS_5LR4DKQKXXXX5LR4DKQK IE - HKU\S-1-5-21-425070134-1683481979-3785275989-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.awesomehp.com/?type=hp&ts=1394368732&from=amt&uid=ST3808110AS_5LR4DKQKXXXX5LR4DKQK IE - HKU\S-1-5-21-425070134-1683481979-3785275989-1006\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-425070134-1683481979-3785275989-1006\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-425070134-1683481979-3785275989-1006\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=U3&apn_dtid=OSJ000YYPL&apn_uid=EAF864AB-1247-49DE-BE9F-C6D68D196AA1&apn_sauid=248275AC-BB0B-422B-AD5F-5D1DEA3A8EA5 IE - HKU\S-1-5-21-425070134-1683481979-3785275989-1006\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://www.awesomehp.com/web/?type=ds&ts=1394368732&from=amt&uid=ST3808110AS_5LR4DKQKXXXX5LR4DKQK&q={searchTerms} IE - HKU\S-1-5-21-425070134-1683481979-3785275989-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "www.google.pl" FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:27.0.1 FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\quick_start@gmail.com: C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Firefox\Profiles\gzbcmyh2.default\extensions\quick_start@gmail.com FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014-02-23 11:14:27 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\avgthb@avg.com: C:\Program Files\AVG\AVG2012\Thunderbird\ [2010-12-24 11:35:26 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Extensions [2010-12-24 11:35:26 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\admin\Dane aplikacji\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2014-02-23 11:14:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions [2014-03-09 15:38:49 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2011-10-27 14:45:50 | 000,083,456 | ---- | M] (LiveVDO ) -- C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll O1 HOSTS File: ([2014-01-03 23:47:31 | 000,000,994 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 127.0.0.1 secure.tune-up.com O1 - Hosts: 127.0.0.1 secure.tune-up.com O1 - Hosts: 127.0.0.1 secure.tune-up.com O1 - Hosts: 127.0.0.1 secure.tune-up.com O1 - Hosts: 127.0.0.1 secure.tune-up.com O1 - Hosts: 127.0.0.1 secure.tune-up.com O2 - BHO: (IETabPage Class) - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files\SupTab\SupTab.dll (Thinknice Co. Limited) O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found. O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) O2 - BHO: (IE5BarLauncherBHO Class) - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files\StartSearch plugin\ssBarLcher.dll (StartSearch Inc.) O2 - BHO: (Surftastic) - {c6673938-a52b-4dc6-af05-783e7e2c8b65} - C:\Program Files\Surftastic\SurftasticBHO.dll (Surftastic) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) O3 - HKLM\..\Toolbar: (StartSearchToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files\StartSearch plugin\ssBarLcher.dll (StartSearch Inc.) O3 - HKU\S-1-5-21-425070134-1683481979-3785275989-1006\..\Toolbar\WebBrowser: (StartSearchToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files\StartSearch plugin\ssBarLcher.dll (StartSearch Inc.) O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found O4 - HKU\S-1-5-21-425070134-1683481979-3785275989-1006..\Run: [Gadu-Gadu] C:\Program Files\Gadu-Gadu\gg.exe (sms-express.com) O4 - Startup: C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Kalendarz XP.lnk = C:\Program Files\Kalendarz XP\Kalendarz.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-425070134-1683481979-3785275989-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.204.152.34 194.204.159.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E3559496-1DC4-4E8E-93ED-98AF18AFDEA2}: DhcpNameServer = 194.204.152.34 194.204.159.1 O18 - Protocol\Handler\linkscanner - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008-12-05 12:02:58 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{521bca40-8667-11de-90e0-00123fbda102}\Shell\AutoRun\command - "" = D:\wbj.exe O33 - MountPoints2\{521bca40-8667-11de-90e0-00123fbda102}\Shell\open\Command - "" = D:\wbj.exe O33 - MountPoints2\{c8982841-9ea6-11e1-a00a-001372cda397}\Shell - "" = AutoRun O33 - MountPoints2\{c8982841-9ea6-11e1-a00a-001372cda397}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{d991f278-8450-11df-b48f-001372cda397}\Shell - "" = AutoRun O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2014\avgrsx.exe /sync /restart) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2014-03-09 18:25:56 | 000,000,000 | ---D | C] -- C:\FRST [2014-03-09 16:19:08 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2014-03-09 16:15:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin\Pulpit\Stare dane programu Firefox [2014-03-09 15:46:29 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group [2014-03-09 13:39:30 | 000,000,000 | ---D | C] -- C:\Program Files\Mobogenie [2014-03-09 13:39:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\IePluginService [2014-03-09 13:39:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin\Dane aplikacji\SupTab [2014-03-09 13:39:15 | 000,000,000 | ---D | C] -- C:\Program Files\SupTab [2014-03-09 13:39:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\WPM [2014-03-09 13:38:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin\Dane aplikacji\13038 [2014-03-09 13:38:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\Lollipop [2014-03-09 13:37:58 | 000,000,000 | ---D | C] -- C:\Program Files\Surftastic [2014-02-23 11:14:24 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox [2014-02-23 10:50:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\admin\Dane aplikacji\Thunderbird [8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [6 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ] [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2014-03-09 19:13:01 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job [2014-03-09 18:48:25 | 000,001,034 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2014-03-09 17:39:26 | 000,001,030 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2014-03-09 17:39:26 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\AmiUpdXp.job [2014-03-09 17:39:21 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2014-03-09 17:27:31 | 000,306,320 | ---- | M] (BitDefender S.R.L.) -- C:\WINDOWS\System32\drivers\TrufosAlt.sys [2014-03-09 11:34:29 | 000,002,527 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\ACDSee 6.0.lnk [2014-03-08 09:41:59 | 000,246,784 | ---- | M] () -- C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2014-03-07 17:55:53 | 000,000,732 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\AVG 2014.lnk [2014-03-07 12:52:56 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Skype.lnk [2014-02-25 07:43:19 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2014-02-23 11:13:46 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe [2014-02-23 11:13:45 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl [2014-02-13 07:15:36 | 000,526,270 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat [2014-02-13 07:15:36 | 000,444,466 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2014-02-13 07:15:36 | 000,099,984 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat [2014-02-13 07:15:36 | 000,072,532 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2014-02-13 07:09:03 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [6 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ] [5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2014-03-09 13:38:38 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\AmiUpdXp.job [2014-01-30 10:18:26 | 000,011,761 | ---- | C] () -- C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\unins000.msg [2014-01-30 10:18:25 | 000,707,504 | ---- | C] () -- C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\unins000.exe [2014-01-30 10:18:25 | 000,003,209 | ---- | C] () -- C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\unins000.dat [2014-01-12 07:42:41 | 000,271,784 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2013-08-05 17:41:12 | 000,000,036 | ---- | C] () -- C:\WINDOWS\avgui.INI [2011-03-27 19:38:14 | 000,005,504 | ---- | C] () -- C:\Documents and Settings\admin\ryw32.lc [2010-06-14 23:34:44 | 000,017,650 | ---- | C] () -- C:\Documents and Settings\admin\Menu Start.rar [2010-03-26 17:34:12 | 000,246,784 | ---- | C] () -- C:\Documents and Settings\admin\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [color=#E56717]========== ZeroAccess Check ==========[/color] [2010-01-05 12:55:24 | 000,005,044 | ---- | M] () -- C:\Documents and Settings\admin\Pulpit\Stare dane programu Firefox\gzbcmyh2.default\extensions\{ca0849e8-2c76-42ae-9abe-34e14d337acf}\skin\L.png [2010-01-05 12:55:24 | 000,005,044 | ---- | M] () -- C:\Documents and Settings\admin\Pulpit\Stare dane programu Firefox\gzbcmyh2.default\extensions\{ca0849e8-2c76-42ae-9abe-34e14d337acf}(2)\skin(2)\L.png [2010-02-01 08:41:29 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shdocvw.dll -- [2008-04-14 18:20:47 | 001,499,136 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009-02-09 11:53:44 | 000,473,600 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] "" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008-04-14 18:20:57 | 000,273,920 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [color=#E56717]========== LOP Check ==========[/color] [2014-03-09 13:39:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\13038 [2009-11-19 13:07:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\ACD Systems [2010-02-09 05:48:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\Audacity [2013-09-27 16:41:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\AVG2014 [2010-11-10 10:06:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\BESTplayer [2011-05-21 17:11:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\BitTorrent [2014-01-30 10:24:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\e-Deklaracje [2014-01-30 10:21:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\e-Deklaracje.A1909296681C7ACEFE45687D3A64758C8659BF46.1 [2012-02-24 01:41:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\f-secure [2010-02-25 08:02:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\Gadu-Gadu 10 [2012-03-08 21:37:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\GetRightToGo [2010-03-25 23:39:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\maxup [2011-12-17 15:29:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\NapiProjekt [2010-02-14 21:42:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\Nowe Gadu-Gadu [2009-11-19 07:16:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\OpenFM [2012-06-26 15:44:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\Oracle [2010-03-04 09:35:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\Softland [2014-03-09 13:39:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\SupTab [2014-02-23 10:50:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\Thunderbird [2013-08-05 17:43:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\TuneUp Software [2012-02-21 08:02:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\admin\Dane aplikacji\VoipStunt [2014-01-12 15:49:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ACD Systems [2013-01-23 17:14:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\AVG January 2013 Campaign [2014-03-09 13:39:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\AVG2014 [2012-02-24 06:29:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\boost_interprocess [2011-11-19 13:33:59 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Common Files [2010-09-02 08:18:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\F-Secure [2010-02-25 08:02:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10 [2014-03-09 13:39:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\IePluginService [2014-01-11 22:54:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\InstallMate [2010-02-25 08:05:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ipla [2014-03-09 15:28:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\MFAData [2013-03-13 15:00:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\MobileBrServ [2009-11-19 07:17:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\OpenFM [2014-01-11 22:54:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\SoftWarehouse [2010-04-26 06:10:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP [2014-01-03 23:47:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TuneUp Software [2014-03-09 13:39:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\WPM [2013-03-03 17:08:46 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Dane aplikacji\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16} [2013-03-03 17:08:46 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Dane aplikacji\{32364CEA-7855-4A3C-B674-53D8E9B97936} [2013-09-26 09:41:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Dane aplikacji\TuneUp Software [2010-02-09 19:41:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ja1\Dane aplikacji\Audacity [2010-02-09 20:23:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ja1\Dane aplikacji\Nowe Gadu-Gadu [2010-03-04 09:35:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\Softland [2010-10-04 06:51:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Dane aplikacji\Softland [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Files - Unicode (All) ==========[/color] [2010-11-20 15:37:49 | 001,574,200 | ---- | M] ()(C:\Documents and Settings\admin\Moje dokumenty\???? ??. Beyond Shopping, ????.pdf) -- C:\Documents and Settings\admin\Moje dokumenty\부러움을 사다. Beyond Shopping, 신세계몰.pdf [2010-11-20 15:25:17 | 001,574,200 | ---- | C] ()(C:\Documents and Settings\admin\Moje dokumenty\???? ??. Beyond Shopping, ????.pdf) -- C:\Documents and Settings\admin\Moje dokumenty\부러움을 사다. Beyond Shopping, 신세계몰.pdf [color=#E56717]========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========[/color] [C:\WINDOWS\$NtUninstallKB59812$] -> Error: Cannot create file handle -> Unknown point type [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 194 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:8927A071 < End of report >