OTL logfile created on: 11/20/2014 6:05:17 PM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Agata\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17420) Locale: 00000409 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 2.92 Gb Total Physical Memory | 0.88 Gb Available Physical Memory | 30.17% Memory free 5.83 Gb Paging File | 3.05 Gb Available in Paging File | 52.27% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 112.00 Gb Total Space | 58.16 Gb Free Space | 51.92% Space Free | Partition Type: NTFS Drive D: | 165.99 Gb Total Space | 89.76 Gb Free Space | 54.08% Space Free | Partition Type: NTFS Computer Name: AGATA-KOMPUTER | User Name: Agata | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2014/11/20 18:02:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Agata\Downloads\OTL.exe PRC - [2014/11/20 01:00:58 | 001,880,752 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_223.exe PRC - [2014/11/10 23:53:03 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe PRC - [2014/09/12 10:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2014/07/14 17:21:46 | 001,390,176 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe PRC - [2014/07/14 17:21:06 | 001,767,520 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe PRC - [2011/04/06 15:28:18 | 001,058,008 | ---- | M] (Auslogics) -- C:\Program Files (x86)\Auslogics\Auslogics BoostSpeed\BoostSpeed.exe PRC - [2010/11/26 23:55:42 | 000,648,032 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe PRC - [2010/11/26 23:55:42 | 000,398,176 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe PRC - [2010/06/15 17:08:28 | 000,861,696 | ---- | M] () -- C:\Windows\SysWOW64\atwtusb.exe PRC - [2010/05/06 07:44:44 | 001,749,504 | ---- | M] (SAMSUNG Electronics) -- C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe PRC - [2010/04/16 17:45:48 | 000,013,600 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe PRC - [2010/04/07 14:40:06 | 000,843,264 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe PRC - [2010/02/10 15:29:52 | 000,719,360 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe PRC - [2010/01/19 03:34:48 | 002,201,192 | ---- | M] (SEC) -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe PRC - [2009/07/24 18:38:50 | 000,189,728 | ---- | M] (Protexis Inc.) -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe PRC - [2009/03/05 10:54:50 | 000,311,296 | ---- | M] () -- C:\Windows\SysWOW64\Rezip.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2014/11/20 01:00:54 | 016,840,880 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll MOD - [2014/11/10 23:52:58 | 003,649,648 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll MOD - [2011/04/06 15:27:44 | 000,348,376 | ---- | M] () -- C:\Program Files (x86)\Auslogics\Auslogics BoostSpeed\madExcept_.bpl MOD - [2011/04/06 15:27:42 | 000,048,856 | ---- | M] () -- C:\Program Files (x86)\Auslogics\Auslogics BoostSpeed\madDisAsm_.bpl MOD - [2011/04/06 15:27:40 | 000,182,488 | ---- | M] () -- C:\Program Files (x86)\Auslogics\Auslogics BoostSpeed\madBasic_.bpl MOD - [2006/08/12 04:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2014/11/06 04:30:08 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService) SRV:[b]64bit:[/b] - [2014/08/22 14:14:34 | 000,368,624 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv) SRV:[b]64bit:[/b] - [2014/08/22 14:14:34 | 000,023,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc) SRV:[b]64bit:[/b] - [2013/05/27 06:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:[b]64bit:[/b] - [2010/05/05 07:15:12 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:[b]64bit:[/b] - [2010/04/16 17:45:48 | 000,937,248 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins) SRV - [2014/11/20 01:00:58 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2014/11/10 23:52:59 | 000,114,288 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2014/09/12 10:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2014/07/14 17:21:46 | 001,390,176 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc) SRV - [2014/07/14 17:21:06 | 001,767,520 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc) SRV - [2014/03/20 23:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2013/09/11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2013/02/04 17:43:22 | 000,155,824 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion) SRV - [2010/11/26 23:55:42 | 000,398,176 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider) SRV - [2010/10/22 12:08:18 | 001,039,360 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC) SRV - [2010/06/15 17:08:28 | 000,861,696 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\atwtusb.exe -- (WTService) SRV - [2009/07/24 18:38:50 | 000,189,728 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2) SRV - [2009/03/05 10:54:50 | 000,311,296 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\Rezip.exe -- (Rezip) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2014/07/17 17:05:06 | 000,125,584 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv) DRV:[b]64bit:[/b] - [2014/03/31 20:06:06 | 000,058,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr) DRV:[b]64bit:[/b] - [2013/10/02 03:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2013/04/25 21:31:54 | 000,027,760 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggsemc.sys -- (ggsemc) DRV:[b]64bit:[/b] - [2013/04/25 21:31:54 | 000,014,448 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggflt.sys -- (ggflt) DRV:[b]64bit:[/b] - [2012/08/23 15:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV:[b]64bit:[/b] - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2012/02/25 17:41:09 | 000,503,352 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd) DRV:[b]64bit:[/b] - [2011/09/06 00:00:04 | 000,029,184 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgandnetdiag64.sys -- (AndNetDiag) DRV:[b]64bit:[/b] - [2011/09/06 00:00:02 | 000,035,840 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgandnetmodem64.sys -- (ANDNetModem) DRV:[b]64bit:[/b] - [2011/07/05 12:55:30 | 004,745,280 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX) DRV:[b]64bit:[/b] - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2010/11/20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2010/05/05 07:47:10 | 006,789,632 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag) DRV:[b]64bit:[/b] - [2010/05/05 07:47:10 | 006,789,632 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:[b]64bit:[/b] - [2010/05/05 06:23:26 | 000,221,184 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:[b]64bit:[/b] - [2010/04/27 08:57:04 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:[b]64bit:[/b] - [2010/04/17 04:55:08 | 000,335,400 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (btwampfl) DRV:[b]64bit:[/b] - [2010/04/17 04:54:20 | 000,039,464 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap) DRV:[b]64bit:[/b] - [2010/04/17 04:54:20 | 000,021,544 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid) DRV:[b]64bit:[/b] - [2010/04/17 04:54:18 | 000,135,720 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt) DRV:[b]64bit:[/b] - [2010/04/17 04:54:18 | 000,102,440 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio) DRV:[b]64bit:[/b] - [2010/04/01 01:25:14 | 000,136,192 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD) DRV:[b]64bit:[/b] - [2010/03/31 01:35:26 | 000,013,824 | ---- | M] (SAMSUNG ELECTRONICS) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SABI.sys -- (SABI) DRV:[b]64bit:[/b] - [2010/02/27 01:32:12 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd) DRV:[b]64bit:[/b] - [2010/01/29 08:33:38 | 000,116,736 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService) DRV:[b]64bit:[/b] - [2009/09/28 10:22:00 | 000,395,264 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7) DRV:[b]64bit:[/b] - [2009/08/26 12:15:10 | 000,007,552 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\walvhid.sys -- (vhidmini) DRV:[b]64bit:[/b] - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009/07/14 01:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam) DRV:[b]64bit:[/b] - [2009/06/10 21:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:[b]64bit:[/b] - [2009/06/10 21:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:[b]64bit:[/b] - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:[b]64bit:[/b] - [2009/03/08 18:16:14 | 000,007,680 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\moufiltr.sys -- (moufiltr) DRV - [2010/07/14 20:35:30 | 000,015,144 | ---- | M] (Windows (R) 2003 DDK 3790 provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\rtport.sys -- (rtport) DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com IE - HKCU\..\SearchScopes,DefaultScope = IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaultenginename: "Google PL" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..extensions.enabledAddons: personas%40christopher.beard:1.7.3 FF - prefs.js..extensions.enabledAddons: pl%40dictionaries.addons.mozilla.org:1.0.20110621 FF - prefs.js..extensions.enabledAddons: %7BBD4B37E6-7AE7-48d7-A2D7-6FF5775924AB%7D:1.5.2.20 FF - prefs.js..extensions.enabledAddons: %7B46551EC9-40F0-4e47-8E18-8E5CF550CFB8%7D:1.4.3 FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.24 FF - prefs.js..extensions.enabledAddons: dlwrzuta%40helpstudent.pl:0.2.8 FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:33.1 FF - user.js - File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.25.2: C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2: C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014/11/10 23:52:51 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014/04/28 14:57:02 | 000,000,000 | ---D | M] [2010/09/08 22:33:18 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Agata\AppData\Roaming\mozilla\Extensions [2014/11/13 11:48:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Agata\AppData\Roaming\mozilla\Firefox\Profiles\qx00dnqw.default-1371035965449\extensions [2014/09/06 15:49:15 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Agata\AppData\Roaming\mozilla\Firefox\Profiles\qx00dnqw.default-1371035965449\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014/11/10 10:37:34 | 000,000,000 | ---D | M] (Bitdefender QuickScan) -- C:\Users\Agata\AppData\Roaming\mozilla\Firefox\Profiles\qx00dnqw.default-1371035965449\extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2013/06/13 00:16:15 | 000,000,000 | ---D | M] ("infoRSS") -- C:\Users\Agata\AppData\Roaming\mozilla\Firefox\Profiles\qx00dnqw.default-1371035965449\extensions\{f65bf62a-5ffc-4317-9612-38907a779583} [2013/06/13 00:16:15 | 000,000,000 | ---D | M] (Polski slownik poprawnej pisowni) -- C:\Users\Agata\AppData\Roaming\mozilla\Firefox\Profiles\qx00dnqw.default-1371035965449\extensions\pl@dictionaries.addons.mozilla.org [2014/11/11 16:37:55 | 000,132,639 | ---- | M] () (No name found) -- C:\Users\Agata\AppData\Roaming\mozilla\firefox\profiles\qx00dnqw.default-1371035965449\extensions\dlwrzuta@helpstudent.pl.xpi [2013/10/26 10:37:49 | 000,348,260 | ---- | M] () (No name found) -- C:\Users\Agata\AppData\Roaming\mozilla\firefox\profiles\qx00dnqw.default-1371035965449\extensions\personas@christopher.beard.xpi [2014/05/11 09:21:40 | 000,293,729 | ---- | M] () (No name found) -- C:\Users\Agata\AppData\Roaming\mozilla\firefox\profiles\qx00dnqw.default-1371035965449\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi [2013/10/02 00:50:48 | 000,255,492 | ---- | M] () (No name found) -- C:\Users\Agata\AppData\Roaming\mozilla\firefox\profiles\qx00dnqw.default-1371035965449\extensions\{BD4B37E6-7AE7-48d7-A2D7-6FF5775924AB}.xpi [2014/11/13 11:48:32 | 000,979,699 | ---- | M] () (No name found) -- C:\Users\Agata\AppData\Roaming\mozilla\firefox\profiles\qx00dnqw.default-1371035965449\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013/08/27 23:33:24 | 000,001,728 | ---- | M] () -- C:\Users\Agata\AppData\Roaming\mozilla\firefox\profiles\qx00dnqw.default-1371035965449\searchplugins\google-pl.xml [2014/11/10 23:52:51 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions [2014/11/10 23:53:04 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} O1 HOSTS File: ([2011/12/22 15:11:00 | 000,000,833 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:[b]64bit:[/b] - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) O2 - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4:[b]64bit:[/b] - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.) O4:[b]64bit:[/b] - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation) O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKCU..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 2 O8:[b]64bit:[/b] - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found O8:[b]64bit:[/b] - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found O8:[b]64bit:[/b] - Extra context menu item: Wyślij obraz do urządzenia &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O8:[b]64bit:[/b] - Extra context menu item: Wyślij stronę do urządzenia &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Wyślij obraz do urządzenia &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm () O8 - Extra context menu item: Wyślij stronę do urządzenia &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9:[b]64bit:[/b] - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) O9:[b]64bit:[/b] - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9:[b]64bit:[/b] - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) O9 - Extra Button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: Wyślij do interfejsu Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : Wyślij do urządzenia &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm () O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.178.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A8A3C5F9-E5DC-43E3-821F-22660015189D}: DhcpNameServer = 192.168.178.1 O18:[b]64bit:[/b] - Protocol\Handler\gopher - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\msdaipp - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\msdaipp\oledb - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\ms-itss - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\mso-offdap - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\mso-offdap11 - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation) O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2013/06/12 11:40:07 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (MACHINE BootExecut) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2014/11/20 17:19:40 | 000,000,000 | ---D | C] -- C:\FRST [2014/11/19 22:39:53 | 000,000,000 | ---D | C] -- C:\Users\Agata\Desktop\Mama lot [2014/11/17 14:21:47 | 000,000,000 | ---D | C] -- C:\Users\Agata\AppData\Local\Adobe [2014/11/17 12:38:48 | 000,000,000 | ---D | C] -- C:\Users\Agata\AppData\Local\ATI [2014/11/12 03:41:12 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll [2014/11/12 03:41:12 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll [2014/11/12 03:41:11 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe [2014/11/12 03:41:11 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe [2014/11/12 03:41:11 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll [2014/11/12 03:41:11 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll [2014/11/12 03:41:11 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll [2014/11/12 03:41:10 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll [2014/11/12 03:41:10 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll [2014/11/12 03:41:08 | 002,051,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl [2014/11/12 03:41:08 | 000,708,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll [2014/11/12 03:41:08 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll [2014/11/12 03:41:07 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll [2014/11/12 03:41:07 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe [2014/11/12 03:41:07 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll [2014/11/12 03:41:06 | 000,968,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe [2014/11/12 03:41:06 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll [2014/11/12 03:41:06 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2014/11/12 03:41:06 | 000,316,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll [2014/11/12 03:41:05 | 000,799,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll [2014/11/12 03:41:05 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll [2014/11/12 03:41:04 | 002,124,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl [2014/11/12 03:41:03 | 001,155,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll [2014/11/12 03:41:02 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe [2014/11/12 03:41:01 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll [2014/11/12 03:41:01 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll [2014/11/12 03:41:00 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2014/11/12 03:41:00 | 000,490,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll [2014/11/12 03:40:59 | 001,359,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll [2014/11/12 03:40:59 | 000,814,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll [2014/11/12 03:40:59 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll [2014/11/12 03:40:58 | 006,040,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll [2014/11/12 03:40:58 | 000,580,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2014/11/12 03:40:57 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll [2014/11/12 03:40:57 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll [2014/11/12 03:14:35 | 000,304,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\generaltel.dll [2014/11/12 03:14:35 | 000,228,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll [2014/11/12 03:14:34 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll [2014/11/12 03:14:27 | 001,460,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll [2014/11/12 03:14:27 | 000,681,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\adtschema.dll [2014/11/12 03:14:27 | 000,681,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\adtschema.dll [2014/11/12 03:14:26 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msaudite.dll [2014/11/12 03:14:26 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msaudite.dll [2014/11/12 03:09:25 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3r.dll [2014/11/12 03:09:25 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3r.dll [2014/11/12 03:09:24 | 000,878,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IMJP10K.DLL [2014/11/12 03:09:24 | 000,701,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IMJP10K.DLL [2014/11/12 03:09:22 | 000,500,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AUDIOKSE.dll [2014/11/12 03:09:22 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AUDIOKSE.dll [2014/11/12 03:09:21 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioEng.dll [2014/11/12 03:09:21 | 000,296,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll [2014/11/12 03:09:21 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDump.dll [2014/11/12 03:09:15 | 000,309,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll [2014/11/12 03:09:04 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\packager.dll [2014/11/12 03:09:03 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\packager.dll [2014/11/12 03:09:00 | 003,241,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msi.dll [2014/11/12 03:08:57 | 000,861,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll [2014/11/11 17:53:48 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP [2014/11/10 23:52:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2014/11/10 00:08:50 | 000,000,000 | ---D | C] -- C:\Users\Agata\AppData\Local\{4ED33221-0A73-41D4-9E50-0D0EADB3E2E3} [2014/11/02 20:51:29 | 000,000,000 | ---D | C] -- C:\Users\Agata\GRÓB rzeźba [2014/11/01 01:42:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2014/11/20 17:53:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2014/11/20 09:42:45 | 000,022,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2014/11/20 09:42:45 | 000,022,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2014/11/20 09:30:06 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl [2014/11/20 09:29:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2014/11/20 09:29:38 | 3131,179,008 | -HS- | M] () -- C:\hiberfil.sys [2014/11/20 01:00:58 | 000,701,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2014/11/20 01:00:58 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2014/11/15 00:10:47 | 000,064,000 | ---- | M] () -- C:\Users\Agata\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2014/11/12 17:24:34 | 000,310,746 | ---- | M] () -- C:\Users\Agata\Desktop\20110729012947622.jpg [2014/11/12 16:50:42 | 000,009,726 | ---- | M] () -- C:\Users\Agata\sweater1.gif [2014/11/12 16:50:36 | 000,002,077 | ---- | M] () -- C:\Users\Agata\sweater2.gif [2014/11/12 10:28:58 | 000,649,968 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2014/11/11 21:03:04 | 000,057,627 | ---- | M] () -- C:\Users\Agata\11053_759561684111016_8643547848153444818_n.jpg [2014/11/10 14:49:04 | 000,001,143 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk [2014/11/06 05:03:50 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll [2014/11/06 04:47:03 | 000,066,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll [2014/11/06 04:46:12 | 000,580,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2014/11/06 04:46:12 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll [2014/11/06 04:44:28 | 000,088,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll [2014/11/06 04:35:59 | 000,034,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll [2014/11/06 04:31:48 | 000,633,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2014/11/06 04:30:22 | 000,144,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe [2014/11/06 04:30:08 | 000,114,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe [2014/11/06 04:29:18 | 000,814,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll [2014/11/06 04:23:57 | 006,040,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll [2014/11/06 04:20:18 | 000,968,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe [2014/11/06 04:16:23 | 000,490,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll [2014/11/06 04:13:36 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll [2014/11/06 04:12:44 | 000,047,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll [2014/11/06 04:10:58 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll [2014/11/06 04:07:29 | 000,077,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll [2014/11/06 04:03:56 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll [2014/11/06 04:02:05 | 000,199,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll [2014/11/06 04:00:56 | 000,478,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2014/11/06 04:00:51 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll [2014/11/06 03:59:36 | 000,115,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe [2014/11/06 03:58:38 | 000,620,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll [2014/11/06 03:57:38 | 000,316,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll [2014/11/06 03:42:36 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll [2014/11/06 03:41:26 | 000,800,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll [2014/11/06 03:41:26 | 000,716,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe [2014/11/06 03:39:39 | 001,359,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll [2014/11/06 03:38:25 | 002,124,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl [2014/11/06 03:37:58 | 000,168,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll [2014/11/06 03:36:47 | 000,076,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll [2014/11/06 03:21:25 | 002,051,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl [2014/11/06 03:20:37 | 001,155,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll [2014/11/06 02:53:19 | 000,799,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll [2014/11/06 02:47:17 | 000,708,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll [2014/11/05 18:56:54 | 000,304,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\generaltel.dll [2014/11/05 18:56:36 | 000,228,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll [2014/11/05 18:52:22 | 000,424,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll [2014/11/05 14:40:41 | 000,058,555 | ---- | M] () -- C:\Users\Agata\schwein_sorten.jpg [2014/11/05 14:36:22 | 000,913,835 | ---- | M] () -- C:\Users\Agata\rindfleisch_gross.jpg [2014/11/03 13:41:10 | 000,082,433 | ---- | M] () -- C:\Users\Agata\Desktop\10-en-b7921a5c81f6b646a2964b36a7ba2fb7.jpg [2014/11/03 10:38:02 | 000,105,625 | ---- | M] () -- C:\Users\Agata\Desktop\t-DmBwiynlxIMnT4Jseg7g.jpg [2014/11/01 09:06:33 | 001,670,590 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2014/11/01 09:06:33 | 000,740,688 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat [2014/11/01 09:06:33 | 000,654,480 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2014/11/01 09:06:33 | 000,156,230 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat [2014/11/01 09:06:33 | 000,122,352 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2014/11/01 01:41:00 | 000,098,216 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll [2014/10/31 17:08:59 | 000,030,111 | ---- | M] () -- C:\Users\Agata\a39_n.jpg [2014/10/28 15:23:03 | 000,003,021 | ---- | M] () -- C:\Users\Agata\AppData\Local\recently-used.xbel [2014/10/25 02:57:59 | 000,077,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\packager.dll [2014/10/25 02:32:37 | 000,067,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\packager.dll [2014/10/22 15:52:05 | 000,620,854 | ---- | M] () -- C:\Users\Agata\vicolo+pitigliano.jpg [color=#E56717]========== Files Created - No Company Name ==========[/color] [2014/11/12 17:16:00 | 000,310,746 | ---- | C] () -- C:\Users\Agata\Desktop\20110729012947622.jpg [2014/11/12 16:50:42 | 000,009,726 | ---- | C] () -- C:\Users\Agata\sweater1.gif [2014/11/12 16:50:36 | 000,002,077 | ---- | C] () -- C:\Users\Agata\sweater2.gif [2014/11/11 21:03:04 | 000,057,627 | ---- | C] () -- C:\Users\Agata\11053_759561684111016_8643547848153444818_n.jpg [2014/11/05 14:40:41 | 000,058,555 | ---- | C] () -- C:\Users\Agata\schwein_sorten.jpg [2014/11/05 14:36:22 | 000,913,835 | ---- | C] () -- C:\Users\Agata\rindfleisch_gross.jpg [2014/11/03 10:46:16 | 000,082,433 | ---- | C] () -- C:\Users\Agata\Desktop\10-en-b7921a5c81f6b646a2964b36a7ba2fb7.jpg [2014/11/03 10:38:02 | 000,105,625 | ---- | C] () -- C:\Users\Agata\Desktop\t-DmBwiynlxIMnT4Jseg7g.jpg [2014/10/31 17:08:59 | 000,030,111 | ---- | C] () -- C:\Users\Agata\a39_n.jpg [2014/10/28 15:23:03 | 000,003,021 | ---- | C] () -- C:\Users\Agata\AppData\Local\recently-used.xbel [2014/10/22 15:52:05 | 000,620,854 | ---- | C] () -- C:\Users\Agata\vicolo+pitigliano.jpg [2014/10/16 12:50:39 | 000,066,490 | ---- | C] () -- C:\Users\Agata\Obrazek1a.jpg [2014/10/07 22:00:27 | 000,024,058 | ---- | C] () -- C:\Users\Agata\motyle2.jpg [2014/10/07 22:00:09 | 000,030,627 | ---- | C] () -- C:\Users\Agata\motyle1.jpg [2014/10/07 21:58:29 | 000,005,917 | ---- | C] () -- C:\Users\Agata\motyle3.jpg [2014/10/07 21:57:39 | 000,030,114 | ---- | C] () -- C:\Users\Agata\motyle4.jpg [2014/09/27 22:24:19 | 000,061,434 | ---- | C] () -- C:\Users\Agata\beauty-girl-face-icon-vector-475504.jpg [2014/09/23 10:14:46 | 000,150,041 | ---- | C] () -- C:\Users\Agata\tlo.jpg [2014/09/23 10:14:46 | 000,007,804 | ---- | C] () -- C:\Users\Agata\3.gif [2014/09/23 10:14:46 | 000,002,675 | ---- | C] () -- C:\Users\Agata\mgielkapodpis.gif [2014/09/17 12:48:25 | 000,805,150 | ---- | C] () -- C:\Users\Agata\cc_20140917_134813.reg [2014/09/11 14:40:30 | 000,204,803 | ---- | C] () -- C:\Users\Agata\tata mamy.jpg [2014/09/10 15:40:10 | 002,885,621 | ---- | C] () -- C:\Users\Agata\Tylko_mnie_kochaj_podkład mp3.mp3 [2014/09/09 18:04:31 | 046,514,288 | ---- | C] () -- C:\Users\Agata\Dieta dominiki.rar [2014/08/27 01:22:35 | 000,708,405 | ---- | C] () -- C:\Users\Agata\177530_herbaciane-roze-nuty.jpg [2014/08/13 14:52:40 | 000,088,999 | ---- | C] () -- C:\Users\Agata\408083_forest-drawing-iii.jpg [2014/08/13 14:46:45 | 000,634,305 | ---- | C] () -- C:\Users\Agata\Las.jpg [2014/08/07 23:39:48 | 000,626,832 | ---- | C] () -- C:\Users\Agata\CAM00235.jpg [2014/08/07 23:39:37 | 000,595,806 | ---- | C] () -- C:\Users\Agata\CAM00234.jpg [2014/08/07 23:39:19 | 000,443,065 | ---- | C] () -- C:\Users\Agata\CAM00233.jpg [2014/08/07 23:39:04 | 000,460,047 | ---- | C] () -- C:\Users\Agata\CAM00232.jpg [2014/08/04 17:03:07 | 000,519,021 | ---- | C] () -- C:\Users\Agata\Silna nowa.JPG [2014/08/03 23:08:25 | 000,082,642 | ---- | C] () -- C:\Users\Agata\Stara_chata.jpg [2014/07/11 14:04:08 | 000,516,424 | ---- | C] () -- C:\Users\Agata\Skanowanie — Zapraszamy!.jpg [2014/07/10 22:39:36 | 000,000,266 | RHS- | C] () -- C:\ProgramData\ntuser.pol [2014/06/25 21:09:24 | 000,273,742 | ---- | C] () -- C:\Users\Agata\wax_seal_by_luciananedelea-d6cyoyt.jpg [2014/06/24 23:03:25 | 000,002,954 | ---- | C] () -- C:\Users\Agata\AppData\Roaming\wklnhst.dat [2014/05/29 12:03:10 | 000,009,443 | ---- | C] () -- C:\Users\Agata\like.jpg [2014/05/29 11:24:05 | 000,009,677 | ---- | C] () -- C:\Users\Agata\big.jpg [2014/05/09 19:37:45 | 000,181,777 | ---- | C] () -- C:\Users\Agata\beautiful-woman-fine-art-painting-portrait-stained-glass-lightbulbs-ideas-long-hair-feminine.jpg [2014/04/28 14:53:11 | 000,219,370 | ---- | C] () -- C:\Windows\hpoins21.dat [2014/04/28 14:53:11 | 000,005,474 | ---- | C] () -- C:\Windows\hpomdl21.dat [2014/03/31 20:47:41 | 000,308,872 | ---- | C] () -- C:\Users\Agata\skanowanie0036.jpg [2014/03/26 19:26:17 | 001,421,486 | ---- | C] () -- C:\Users\Agata\yorki 005.jpg [2014/03/26 18:52:20 | 001,074,130 | ---- | C] () -- C:\Users\Agata\Pass.jpg [2014/03/26 18:40:14 | 001,685,902 | ---- | C] () -- C:\Users\Agata\yorki 004.jpg [2014/03/26 18:38:58 | 001,436,451 | ---- | C] () -- C:\Users\Agata\yorki 003.jpg [2014/03/26 18:38:17 | 001,520,495 | ---- | C] () -- C:\Users\Agata\yorki 002.jpg [2014/03/26 18:36:21 | 001,150,173 | ---- | C] () -- C:\Users\Agata\York.jpg [2014/03/26 18:34:13 | 001,421,694 | ---- | C] () -- C:\Users\Agata\yorki 001.jpg [2014/03/26 00:17:45 | 001,110,939 | ---- | C] () -- C:\Users\Agata\Nowy-6.png [2014/03/01 16:07:03 | 000,026,336 | ---- | C] () -- C:\Users\Agata\Love-Couples-sexy-.jpg [2014/02/11 05:47:38 | 001,151,864 | ---- | C] () -- C:\Windows\SysWow64\Websteroids.B324755F3F87.dll [2014/02/02 12:02:03 | 000,038,846 | ---- | C] () -- C:\Users\Agata\SDC11362.JPG [2014/01/31 15:56:22 | 001,598,008 | ---- | C] () -- C:\Users\Agata\skanowanie0030.jpg [2014/01/05 01:45:39 | 000,189,510 | ---- | C] () -- C:\Users\Agata\1234851_439657902815588_1477310836_n.jpg [2014/01/01 19:57:53 | 000,139,048 | ---- | C] () -- C:\Users\Agata\skanowanie0032.jpg [2014/01/01 19:56:38 | 000,341,530 | ---- | C] () -- C:\Users\Agata\skanowanie0031.jpg [2014/01/01 19:56:12 | 000,500,629 | ---- | C] () -- C:\Users\Agata\skanowanie0035.jpg [2014/01/01 19:55:43 | 000,161,580 | ---- | C] () -- C:\Users\Agata\skanowanie0033.jpg [2014/01/01 19:55:04 | 000,303,878 | ---- | C] () -- C:\Users\Agata\skanowanie0034.jpg [2013/12/09 13:46:29 | 000,135,115 | ---- | C] () -- C:\Users\Agata\mmm.jpg [2013/12/09 13:43:24 | 000,062,358 | ---- | C] () -- C:\Users\Agata\aga.jpg [2013/12/09 13:20:27 | 000,040,460 | ---- | C] () -- C:\Users\Agata\Snapshot_20131209_1.jpg [2013/11/25 18:42:07 | 000,219,370 | ---- | C] () -- C:\Windows\hpoins21.dat.temp [2013/11/25 18:42:07 | 000,005,474 | ---- | C] () -- C:\Windows\hpomdl21.dat.temp [2013/11/17 22:05:05 | 000,071,451 | ---- | C] () -- C:\Users\Agata\ccc34de20f.jpg [2013/11/17 22:03:29 | 000,072,004 | ---- | C] () -- C:\Users\Agata\Wiesława Koprowska.jpg [2013/11/01 00:44:53 | 005,774,209 | ---- | C] () -- C:\Users\Agata\Track8.mp3 [2013/11/01 00:44:51 | 002,128,897 | ---- | C] () -- C:\Users\Agata\Track10.mp3 [2013/10/27 23:14:41 | 000,068,108 | ---- | C] () -- C:\Users\Agata\Candle-icon.png [2013/10/27 23:13:04 | 000,070,605 | ---- | C] () -- C:\Users\Agata\rose-icon.png [2013/10/27 23:03:02 | 000,077,131 | ---- | C] () -- C:\Users\Agata\candles-icon.png [2013/09/07 21:44:25 | 000,220,472 | ---- | C] () -- C:\Users\Agata\Track05.mp3 [2013/09/07 21:40:42 | 004,943,684 | ---- | C] () -- C:\Users\Agata\Blues.mp3 [2013/09/07 21:37:10 | 001,804,098 | ---- | C] () -- C:\Users\Agata\graj Katarynko03.mp3 [2013/09/07 15:49:17 | 001,222,929 | ---- | C] () -- C:\Users\Agata\AudioRecorderUserGuide.pdf [2013/08/31 00:16:46 | 003,131,658 | ---- | C] () -- C:\Users\Agata\Earth_fog_155635.jpg [2013/08/26 17:43:54 | 000,341,107 | ---- | C] () -- C:\Users\Agata\koty.JPG [2013/08/22 14:46:05 | 003,394,003 | ---- | C] () -- C:\Users\Agata\jesienne 008.mp3 [2013/08/22 14:10:10 | 003,393,827 | ---- | C] () -- C:\Users\Agata\J.mp3 [2013/08/22 14:07:44 | 002,970,434 | ---- | C] () -- C:\Users\Agata\jesienne wok.mp3 [2013/08/20 12:53:46 | 000,240,285 | ---- | C] () -- C:\Users\Agata\ccc.jpg [2013/08/16 19:34:30 | 000,268,965 | ---- | C] () -- C:\Users\Agata\tk1.jpg [2013/08/16 19:16:10 | 000,181,232 | ---- | C] () -- C:\Users\Agata\forsycja-tlo-wiosenne1.jpg [2013/08/13 21:00:36 | 000,095,879 | ---- | C] () -- C:\Users\Agata\1005860_362484837207508_1654256157_n.jpg [2013/07/03 22:09:43 | 000,073,454 | ---- | C] () -- C:\Users\Agata\domi.jpg [2013/06/23 17:21:51 | 003,491,851 | ---- | C] () -- C:\Users\Agata\01 Ścieżka 1.mp3 [2013/06/23 17:21:13 | 003,088,612 | ---- | C] () -- C:\Users\Agata\02 Ścieżka 2.mp3 [2013/06/23 17:19:52 | 003,426,382 | ---- | C] () -- C:\Users\Agata\04 Ścieżka 4.mp3 [2013/06/23 17:19:08 | 004,389,235 | ---- | C] () -- C:\Users\Agata\05 Ścieżka 5.mp3 [2013/06/23 17:15:50 | 004,196,164 | ---- | C] () -- C:\Users\Agata\09 Ścieżka 9.mp3 [2013/06/22 20:04:37 | 000,078,682 | ---- | C] () -- C:\Users\Agata\stolik ze skrzynek.jpg [2013/06/16 21:02:31 | 000,007,452 | ---- | C] () -- C:\Users\Agata\D49B7~1.JPG [2013/06/14 16:50:34 | 000,010,727 | ---- | C] () -- C:\Users\Agata\ser.png [2013/06/14 16:26:31 | 000,019,624 | ---- | C] () -- C:\Users\Agata\r.png [2013/05/28 18:53:06 | 000,549,269 | ---- | C] () -- C:\Users\Agata\DSC00366.jpg [2013/05/28 18:52:45 | 000,618,404 | ---- | C] () -- C:\Users\Agata\DSC00367.jpg [2013/05/28 18:51:17 | 000,607,903 | ---- | C] () -- C:\Users\Agata\DSC00371.jpg [2013/05/11 16:52:21 | 000,645,632 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll [2013/05/11 16:52:21 | 000,240,640 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll [2013/04/14 19:05:55 | 001,053,764 | ---- | C] () -- C:\Users\Agata\GoGEAR_Vibe_Polski.pdf [2013/03/21 16:42:34 | 000,159,734 | ---- | C] () -- C:\Users\Agata\Rysunek1.jpg [2013/03/14 12:37:45 | 000,024,310 | ---- | C] () -- C:\Users\Agata\Ja.bmp [2013/03/14 12:34:48 | 000,044,328 | ---- | C] () -- C:\Users\Agata\051207_194828.jpg [2013/02/19 23:13:26 | 000,088,624 | ---- | C] () -- C:\Users\Agata\stojak-do-bombki-spiral_5283.jpg [2013/01/23 16:29:55 | 001,991,715 | ---- | C] () -- C:\Users\Agata\DSC00298.jpg [2012/12/20 01:35:20 | 005,124,118 | ---- | C] () -- C:\Users\Agata\Nie załuj.mp3 [2012/12/20 01:33:20 | 005,606,119 | ---- | C] () -- C:\Users\Agata\Oliver Koletzki feat. Fran - Hypnotized.mp3 [2012/12/20 01:31:06 | 009,594,210 | ---- | C] () -- C:\Users\Agata\radioh.mp3 [2012/12/20 01:27:25 | 003,491,409 | ---- | C] () -- C:\Users\Agata\Triggerfinger I Follow Rivers.mp3 [2012/12/20 01:26:02 | 002,156,669 | ---- | C] () -- C:\Users\Agata\1643998809.mp3 [2012/12/20 01:25:10 | 006,412,712 | ---- | C] () -- C:\Users\Agata\beth hart & joe bonamassa - i'll take care of you.mp3 [2012/12/20 01:25:02 | 004,315,312 | ---- | C] () -- C:\Users\Agata\Andy_Powell_Emily_Taylor_-_The_Best_You_ve_Had_a.mp3 [2012/12/20 01:22:28 | 009,018,727 | ---- | C] () -- C:\Users\Agata\Je veux - Zaz.mp3 [2012/12/20 01:19:00 | 005,160,356 | ---- | C] () -- C:\Users\Agata\lady2287144.mp3 [2012/12/20 01:16:56 | 008,760,637 | ---- | C] () -- C:\Users\Agata\Les passant Zaz.mp3 [2012/12/20 01:13:31 | 004,981,156 | ---- | C] () -- C:\Users\Agata\miss2287162.mp3 [2012/12/20 01:11:33 | 005,828,736 | ---- | C] () -- C:\Users\Agata\missing3272164.mp3 [2012/11/23 23:23:33 | 000,579,631 | ---- | C] () -- C:\Users\Agata\DSC00274.jpg [2012/11/23 23:19:49 | 000,662,323 | ---- | C] () -- C:\Users\Agata\DSC00279.jpg [2012/11/23 23:19:12 | 000,469,466 | ---- | C] () -- C:\Users\Agata\DSC00284.jpg [2012/10/03 19:03:24 | 000,990,904 | ---- | C] () -- C:\Users\Agata\DSC00223.jpg [2012/10/03 19:02:42 | 001,297,418 | ---- | C] () -- C:\Users\Agata\DSC00218.jpg [2012/10/03 19:02:03 | 000,512,111 | ---- | C] () -- C:\Users\Agata\DSC00224.jpg [2012/10/03 18:57:37 | 000,968,357 | ---- | C] () -- C:\Users\Agata\DSC00214.jpg [2012/09/14 12:21:18 | 000,000,036 | ---- | C] () -- C:\Users\Agata\AppData\Local\housecall.guid.cache [2012/08/29 21:24:56 | 000,247,765 | ---- | C] () -- C:\Users\Agata\1315661039-852.jpg [2012/07/21 13:29:05 | 000,226,062 | ---- | C] () -- C:\Users\Agata\po-wniosek-paszportowy.pdf [2012/07/21 13:26:06 | 000,254,758 | ---- | C] () -- C:\Users\Agata\wzor wniosku- osoba dorosla 2 popr.jpg [2012/06/19 21:29:23 | 000,434,387 | ---- | C] () -- C:\Users\Agata\30 Second To Mars-Closer To The Edge 2.mp3 [2012/06/03 22:17:56 | 002,421,508 | ---- | C] () -- C:\Users\Agata\sony kamera.pdf [2012/05/27 13:09:28 | 000,042,356 | ---- | C] () -- C:\Users\Agata\makip.jpg [2012/05/27 13:03:41 | 001,015,779 | ---- | C] () -- C:\Users\Agata\maskowanie corelphoto.pdf [2012/05/27 11:49:53 | 000,156,887 | ---- | C] () -- C:\Users\Agata\tata boszkowo.jpg [2012/05/25 19:14:26 | 003,485,810 | ---- | C] () -- C:\Users\Agata\Ewa_Bem_-_Caly_Swiat.mp3 [2012/05/18 00:59:20 | 006,635,300 | ---- | C] () -- C:\Users\Agata\samba.mp3 [2012/05/16 14:58:47 | 005,660,171 | ---- | C] () -- C:\Users\Agata\Krzysztof_Krawczyk_-_Bo_jeste_Ty_KARAOKE.mp3 [2012/05/07 13:48:26 | 000,041,601 | ---- | C] () -- C:\Users\Agata\tata.jpg [2012/05/07 13:29:43 | 000,109,056 | ---- | C] () -- C:\Users\Agata\Thumbs_1.db [2012/05/07 12:47:39 | 003,730,734 | ---- | C] () -- C:\Users\Agata\BEZ CIEBIE-Ochman.mp3 [2012/05/02 00:02:14 | 000,007,607 | ---- | C] () -- C:\Users\Agata\AppData\Local\Resmon.ResmonCfg [2012/03/16 15:57:16 | 000,067,584 | ---- | C] () -- C:\Users\Agata\AppData\Roaming\chrtmp [2011/12/06 10:31:43 | 008,354,304 | ---- | C] () -- C:\Users\Agata\Karykatury.PPS [2011/11/12 20:23:32 | 001,125,954 | ---- | C] () -- C:\Users\Agata\Zakładowy Fundusz świadczeń socjalnych.pdf [2011/09/23 09:48:44 | 000,107,608 | ---- | C] () -- C:\Users\Agata\znicze_pap_470.jpeg [2011/08/26 20:01:14 | 000,036,366 | -HS- | C] () -- C:\Users\Agata\Folder.jpg [2011/08/26 20:01:14 | 000,012,709 | -HS- | C] () -- C:\Users\Agata\AlbumArt_{0B2BC450-B747-49EF-A485-12F8408155AB}_Large.jpg [2011/08/26 20:01:14 | 000,007,551 | -HS- | C] () -- C:\Users\Agata\AlbumArtSmall.jpg [2011/08/26 20:01:14 | 000,002,557 | -HS- | C] () -- C:\Users\Agata\AlbumArt_{0B2BC450-B747-49EF-A485-12F8408155AB}_Small.jpg [2011/06/22 15:59:13 | 000,070,870 | ---- | C] () -- C:\Users\Agata\Webers-Schokoladenkuchen.pdf [2011/06/06 14:38:00 | 000,089,987 | ---- | C] () -- C:\Users\Agata\babuszka.jpg [2011/04/27 16:20:41 | 000,107,841 | ---- | C] () -- C:\Users\Agata\dgd.jpg [2011/02/02 15:33:55 | 001,802,958 | ---- | C] () -- C:\Users\Agata\Painter 11 instrukcja obslugi.PDF [2010/12/15 17:19:55 | 000,497,283 | ---- | C] () -- C:\Users\Agata\DSC00272.JPG [2010/12/15 17:16:58 | 000,376,816 | ---- | C] () -- C:\Users\Agata\DSC00283.JPG [2010/11/30 01:59:39 | 000,392,519 | ---- | C] () -- C:\Users\Agata\DSC00276.JPG [2010/10/23 18:26:56 | 000,139,056 | ---- | C] () -- C:\Users\Agata\Default.wav [2010/10/23 18:26:56 | 000,079,626 | ---- | C] () -- C:\Users\Agata\Sea.wav [2010/10/23 18:26:56 | 000,078,800 | ---- | C] () -- C:\Users\Agata\Small Waterfall.wav [2010/10/23 18:26:56 | 000,065,212 | ---- | C] () -- C:\Users\Agata\Big Waterfall.wav [2010/10/23 18:26:56 | 000,057,680 | ---- | C] () -- C:\Users\Agata\Cricket.wav [2010/10/23 18:26:56 | 000,006,508 | ---- | C] () -- C:\Users\Agata\Frog.wav [2010/09/29 20:12:21 | 000,424,925 | ---- | C] () -- C:\Users\Agata\DSC00260.JPG [2010/09/27 00:34:10 | 000,000,088 | RHS- | C] () -- C:\ProgramData\B6FAD94ED4.sys [2010/09/27 00:34:09 | 000,005,642 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys [2010/09/07 18:18:12 | 000,064,000 | ---- | C] () -- C:\Users\Agata\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/09/01 18:47:06 | 000,334,112 | ---- | C] () -- C:\Users\Agata\DSC00218_1.JPG [2010/09/01 18:46:34 | 000,352,165 | ---- | C] () -- C:\Users\Agata\DSC00219.JPG [2010/09/01 18:46:11 | 000,276,266 | ---- | C] () -- C:\Users\Agata\DSC00220.JPG [2010/08/31 22:29:40 | 003,506,886 | ---- | C] () -- C:\Users\Agata\IMG_1374.jpg [2010/08/31 12:38:57 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2010/08/30 18:31:05 | 000,050,928 | ---- | C] () -- C:\Users\Agata\draw.jpg [2010/08/30 16:29:23 | 000,131,368 | ---- | C] () -- C:\ProgramData\FullRemove.exe [color=#E56717]========== ZeroAccess Check ==========[/color] [2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2014/06/25 03:05:42 | 014,175,744 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2014/06/25 02:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== LOP Check ==========[/color] [2011/05/23 15:24:19 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\AnvSoft [2014/11/08 23:41:51 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\Audacity [2013/06/06 13:58:53 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\Auslogics [2011/05/31 09:58:31 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\Canneverbe Limited [2014/07/10 16:34:04 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant [2013/11/23 14:08:42 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\com.adobe.formscentral.FormsCentralForAcrobat [2010/11/20 17:46:04 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\FreeAudioPack [2010/11/20 17:46:22 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\FreeCDRipper [2010/11/20 16:07:34 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\FreeFox [2014/07/11 14:22:41 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\FRITZ! [2012/08/14 18:15:48 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\Gadu-Gadu 10 [2014/05/10 14:46:42 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\GG [2014/10/10 13:11:28 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\ipla [2013/10/29 19:54:41 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\IsolatedStorage [2014/09/17 23:50:53 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\Mp3tag [2014/05/17 23:04:51 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\MPC-HC [2010/08/31 23:59:48 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\OpenFM [2014/06/06 08:53:41 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\Opera Software [2014/04/21 00:24:54 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\Oracle [2014/11/09 10:41:40 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\QuickScan [2010/11/18 01:12:16 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\RDRM [2013/11/23 17:23:06 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\SolidDocuments [2011/02/19 18:44:33 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\SoundSpectrum [2013/01/26 11:49:28 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\Synaptics [2011/03/20 14:03:03 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\TeamViewer [2013/06/01 13:43:37 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\Template [2014/06/27 21:17:50 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\Thinstall [2010/10/12 15:09:31 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\Video DVD Maker FREE [2010/10/27 22:50:05 | 000,000,000 | ---D | M] -- C:\Users\Agata\AppData\Roaming\Windows Live Writer [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Alternate Data Streams ==========[/color] @Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:07BF512B < End of report >