OTL logfile created on: 2012-02-10 15:38:51 - Run 1
OTL by OldTimer - Version 3.2.31.0     Folder = C:\Documents and Settings\QWERTY\Moje dokumenty\Downloads
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
 
3,25 Gb Total Physical Memory | 1,94 Gb Available Physical Memory | 59,81% Memory free
5,09 Gb Paging File | 3,84 Gb Available in Paging File | 75,37% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48,83 Gb Total Space | 17,57 Gb Free Space | 35,98% Space Free | Partition Type: NTFS
Drive D: | 146,48 Gb Total Space | 5,49 Gb Free Space | 3,75% Space Free | Partition Type: NTFS
Drive E: | 195,31 Gb Total Space | 14,63 Gb Free Space | 7,49% Space Free | Partition Type: NTFS
Drive F: | 75,13 Gb Total Space | 11,00 Gb Free Space | 14,64% Space Free | Partition Type: NTFS
 
Computer Name: GEBSKI | User Name: QWERTY | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
[color=#E56717]========== Processes (SafeList) ==========[/color]
 
PRC - [2012-02-10 15:01:42 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\QWERTY\Moje dokumenty\Downloads\OTL (1).exe
PRC - [2012-02-05 15:27:05 | 000,141,904 | ---- | M] (ArcaBit) -- C:\Program Files\ArcaBit\Common\ArcaConfSV.exe
PRC - [2012-02-05 15:27:03 | 000,491,912 | ---- | M] (ArcaBit) -- C:\Program Files\ArcaBit\ArcaVir\AVMenu.exe
PRC - [2012-02-05 15:27:02 | 000,543,312 | ---- | M] () -- C:\Program Files\ArcaBit\ArcaAgent\ArcaRemoteSvc.exe
PRC - [2012-02-05 15:27:02 | 000,159,232 | ---- | M] (ArcaBit) -- C:\Program Files\ArcaBit\ArcaVir\ArcaMainSV.exe
PRC - [2012-02-05 15:27:02 | 000,125,520 | ---- | M] (ArcaBit) -- C:\Program Files\ArcaBit\ArcaUpdate\update.exe
PRC - [2012-01-20 06:35:36 | 001,047,024 | ---- | M] (Google Inc.) -- C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe
PRC - [2011-11-28 13:19:56 | 000,265,120 | ---- | M] () -- C:\Program Files\Common Files\WireHelpSvc.exe
PRC - [2011-10-25 15:59:16 | 000,244,960 | ---- | M] () -- C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe
PRC - [2011-09-14 12:10:36 | 000,129,616 | ---- | M] (ArcaBit) -- C:\Program Files\ArcaBit\Common\ArcaTasksService.exe
PRC - [2011-08-15 16:18:14 | 001,955,208 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
PRC - [2011-08-15 16:18:10 | 001,361,288 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
PRC - [2011-08-01 14:35:42 | 000,114,992 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\SweetIM.exe
PRC - [2010-10-07 09:04:26 | 012,661,344 | ---- | M] (GG Network S.A.) -- C:\Program Files\Gadu-Gadu 10\gg .exe
PRC - [2009-05-12 14:43:36 | 002,181,672 | ---- | M] (Gainward Co.) -- C:\Program Files\EXPERTool\TBPANEL.exe
PRC - [2008-04-14 23:51:18 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008-02-01 04:02:26 | 000,065,536 | ---- | M] (PostgreSQL Global Development Group) -- C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
PRC - [2008-02-01 04:00:54 | 003,661,824 | ---- | M] (PostgreSQL Global Development Group) -- C:\Program Files\PostgreSQL\8.3\bin\postgres.exe
 
 
[color=#E56717]========== Modules (No Company Name) ==========[/color]
 
MOD - [2012-02-05 15:27:02 | 000,543,312 | ---- | M] () -- C:\Program Files\ArcaBit\ArcaAgent\ArcaRemoteSvc.exe
MOD - [2012-01-20 06:35:35 | 000,411,120 | ---- | M] () -- C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\16.0.912.77\ppgooglenaclpluginchrome.dll
MOD - [2012-01-20 06:35:34 | 003,767,792 | ---- | M] () -- C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\16.0.912.77\pdf.dll
MOD - [2012-01-20 06:34:10 | 000,122,880 | ---- | M] () -- C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\16.0.912.77\avutil-51.dll
MOD - [2012-01-20 06:34:09 | 000,222,208 | ---- | M] () -- C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\16.0.912.77\avformat-53.dll
MOD - [2012-01-20 06:34:07 | 001,746,432 | ---- | M] () -- C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\16.0.912.77\avcodec-53.dll
MOD - [2012-01-20 03:14:40 | 008,593,056 | ---- | M] () -- C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\16.0.912.77\gcswf32.dll
MOD - [2011-11-28 13:19:56 | 000,265,120 | ---- | M] () -- C:\Program Files\Common Files\WireHelpSvc.exe
MOD - [2011-10-25 15:59:16 | 000,244,960 | ---- | M] () -- C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe
MOD - [2011-09-14 12:09:18 | 000,195,152 | ---- | M] () -- C:\Program Files\ArcaBit\ArcaVir\AVShell.dll
MOD - [2010-10-07 09:05:14 | 000,217,696 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\gglog.dll
MOD - [2010-10-07 09:05:14 | 000,123,488 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggipcradioproxy.dll
MOD - [2010-10-07 09:05:10 | 000,017,504 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggipc.dll
MOD - [2010-10-07 09:05:08 | 000,027,744 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggcrypto.dll
MOD - [2010-10-07 09:05:06 | 000,356,960 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\ggcommon.dll
MOD - [2010-08-06 20:01:42 | 002,404,352 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtCore4.dll
MOD - [2010-08-06 20:01:42 | 001,515,520 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtScript4.dll
MOD - [2010-08-06 20:01:42 | 001,040,384 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtNetwork4.dll
MOD - [2010-08-06 20:01:42 | 000,389,120 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtXml4.dll
MOD - [2010-08-06 20:01:42 | 000,323,584 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtSvg4.dll
MOD - [2010-08-06 20:01:40 | 013,553,664 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtWebKit4.dll
MOD - [2010-08-06 20:01:38 | 008,818,688 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtGui4.dll
MOD - [2010-08-06 20:01:22 | 003,334,144 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\QtXmlPatterns4.dll
MOD - [2010-08-06 20:00:32 | 000,311,296 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qtiff4.dll
MOD - [2010-08-06 20:00:32 | 000,274,432 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qmng4.dll
MOD - [2010-08-06 20:00:32 | 000,143,360 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qjpeg4.dll
MOD - [2010-08-06 20:00:32 | 000,027,648 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qgif4.dll
MOD - [2010-08-06 20:00:32 | 000,018,944 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\imageformats\qsvg4.dll
MOD - [2009-09-23 15:04:00 | 000,059,904 | ---- | M] () -- C:\Program Files\Gadu-Gadu 10\zlib1.dll
MOD - [2009-07-18 04:21:00 | 003,883,424 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2009-06-10 07:29:34 | 000,466,944 | ---- | M] () -- C:\WINDOWS\system32\nvshell.dll
MOD - [2009-06-10 07:29:32 | 001,507,328 | ---- | M] () -- C:\WINDOWS\system32\nview.dll
MOD - [2009-02-27 18:04:20 | 000,311,296 | ---- | M] () -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\pdfshell.POL
MOD - [2008-04-14 23:50:38 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2007-01-31 09:56:56 | 000,032,768 | ---- | M] () -- C:\Program Files\EXPERTool\TBPanelExt.dll
MOD - [1998-10-31 09:55:56 | 000,005,120 | ---- | M] () -- C:\Program Files\EXPERTool\TBMANAGE.DLL
 
 
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
 
SRV - File not found [Auto | Stopped] --  -- (PavPrSrv)
SRV - [2012-02-05 15:27:05 | 000,141,904 | ---- | M] (ArcaBit) [Auto | Running] -- C:\Program Files\ArcaBit\Common\ArcaConfSV.exe -- (ABConfSV)
SRV - [2012-02-05 15:27:02 | 000,543,312 | ---- | M] () [Auto | Running] -- C:\Program Files\ArcaBit\ArcaAgent\ArcaRemoteSvc.exe -- (ArcaRemoteService)
SRV - [2012-02-05 15:27:02 | 000,159,232 | ---- | M] (ArcaBit) [Auto | Running] -- C:\Program Files\ArcaBit\ArcaVir\ArcaMainSV.exe -- (ABMainSV)
SRV - [2012-02-05 15:27:02 | 000,125,520 | ---- | M] (ArcaBit) [Auto | Running] -- C:\Program Files\ArcaBit\ArcaUpdate\update.exe -- (AVUpdate)
SRV - [2011-11-28 13:19:56 | 000,265,120 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\WireHelpSvc.exe -- (WireHelpSvc)
SRV - [2011-10-25 15:59:16 | 000,244,960 | ---- | M] () [Auto | Running] -- C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe -- (Updater Service for StartNow Toolbar)
SRV - [2011-09-26 16:49:42 | 000,186,960 | ---- | M] (ArcaBit) [Auto | Stopped] -- C:\Program Files\ArcaBit\ArcaTools\ArcaBackup\ArcaBackupService.exe -- (AVBackup)
SRV - [2011-09-14 12:10:36 | 000,129,616 | ---- | M] (ArcaBit) [Auto | Running] -- C:\Program Files\ArcaBit\Common\ArcaTasksService.exe -- (AVTasks2)
SRV - [2011-08-15 16:18:10 | 001,361,288 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2008-04-07 09:17:30 | 000,430,592 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008-02-01 04:02:26 | 000,065,536 | ---- | M] (PostgreSQL Global Development Group) [Auto | Running] -- C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe -- (pgsql-8.3)
 
 
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
 
DRV - [2011-11-28 13:19:46 | 000,836,496 | ---- | M] (<Turtle Entertainment>) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ESLWireACD.sys -- (ESLWireAC)
DRV - [2011-09-30 10:29:36 | 000,062,544 | ---- | M] (ArcaBit) [File_System | On_Demand | Running] -- C:\Program Files\ArcaBit\ArcaVir\ABFLT.sys -- (ABFLT)
DRV - [2011-06-22 14:38:26 | 000,024,504 | ---- | M] (Turtle Entertainment GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ESLvnic.sys -- (ESLvnic1)
DRV - [2010-11-23 07:43:58 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\gdrv.sys -- (gdrv)
DRV - [2010-10-26 13:04:30 | 000,051,280 | ---- | M] (ArcaBit) [Kernel | System | Running] -- C:\Program Files\ArcaBit\ArcaVir\ABTDI.sys -- (ABTDI)
DRV - [2010-04-27 16:57:28 | 000,066,632 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmXlCore.sys -- (WmXlCore)
DRV - [2010-04-27 16:57:28 | 000,015,048 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmVirHid.sys -- (WmVirHid)
DRV - [2010-04-27 16:57:22 | 000,022,856 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WmBEnum.sys -- (WmBEnum)
DRV - [2010-04-27 14:01:26 | 000,037,704 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\WmFilter.sys -- (WmFilter)
DRV - [2010-02-03 14:56:56 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2009-12-08 17:36:12 | 000,281,760 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt)
DRV - [2009-12-08 17:36:11 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2009-01-20 11:53:06 | 005,027,840 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008-10-30 14:14:20 | 000,117,888 | R--- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2007-11-29 10:39:52 | 000,008,064 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2007-11-29 10:39:42 | 000,016,896 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2007-11-29 10:39:42 | 000,008,064 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2007-11-29 10:39:40 | 000,019,328 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2007-09-17 15:53:26 | 000,021,632 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2007-04-16 15:46:34 | 000,033,792 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdPPM.sys -- (AmdPPM)
DRV - [2007-03-16 09:11:38 | 000,012,256 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\TBPanel.sys -- (TBPanel)
DRV - [2007-03-16 09:11:38 | 000,012,256 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\TBPanel.sys -- (Cardex)
DRV - [2003-09-08 09:06:36 | 000,255,360 | R--- | M] (D-Link) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AIRPLUS.sys -- (AIRPLUS)
 
 
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
 
 
[color=#E56717]========== Internet Explorer ==========[/color]
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wyborcza.pl/0.0.html?p=026
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1&cf=e20027e4-2f3b-11e1-9bc0-00ff01000001
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-1844237615-113007714-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://klit.startnow.com/?src=startpage&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.4.0&install_country=PL&install_date=20120208&user_guid=6A48BACBDBC84BAC978F1D48EA862AAB&machine_id=d09e3ae5808e3257c4cc4fdf058bbd98&browser=IE&os=win&os_version=5.1-x86-SP3
IE - HKU\S-1-5-21-1844237615-113007714-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.gazeta.pl/0,0.html?p=125
IE - HKU\S-1-5-21-1844237615-113007714-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1844237615-113007714-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = proxy.faith.pl:8080
 
 
[color=#E56717]========== FireFox ==========[/color]
 
FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaultthis.engineName: "BrotherSoft Extreme Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2776682&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://klit.startnow.com/?src=startpage&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.4.0&install_country=PL&install_date=20120208&user_guid=6A48BACBDBC84BAC978F1D48EA862AAB&machine_id=d09e3ae5808e3257c4cc4fdf058bbd98&browser=FF&os=win&os_version=5.1-x86-SP3"
FF - prefs.js..keyword.URL: "http://klit.startnow.com/s/?src=addrbar&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.4.0&install_country=PL&install_date=20120208&user_guid=6A48BACBDBC84BAC978F1D48EA862AAB&machine_id=d09e3ae5808e3257c4cc4fdf058bbd98&browser=FF&os=win&os_version=5.1-x86-SP3&q="
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.50826.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011-08-02 19:49:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011-12-25 22:03:30 | 000,000,000 | ---D | M]
 
[2011-08-02 19:50:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\QWERTY\Dane aplikacji\Mozilla\Extensions
[2012-02-08 21:37:49 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\QWERTY\Dane aplikacji\Mozilla\Firefox\Profiles\nw3nkhzj.default\extensions
[2011-12-22 17:35:51 | 000,000,000 | ---D | M] (BrotherSoft Extreme Community Toolbar) -- C:\Documents and Settings\QWERTY\Dane aplikacji\Mozilla\Firefox\Profiles\nw3nkhzj.default\extensions\{51a86bb3-6602-4c85-92a5-130ee4864f13}
[2012-02-08 21:37:49 | 000,000,000 | ---D | M] (StartNow Toolbar) -- C:\Documents and Settings\QWERTY\Dane aplikacji\Mozilla\Firefox\Profiles\nw3nkhzj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}
[2011-10-24 18:57:42 | 000,000,000 | ---D | M] (IncrediMail MediaBar 2 Toolbar) -- C:\Documents and Settings\QWERTY\Dane aplikacji\Mozilla\Firefox\Profiles\nw3nkhzj.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}
[2011-08-05 14:46:20 | 000,000,000 | ---D | M] (Babylon) -- C:\Documents and Settings\QWERTY\Dane aplikacji\Mozilla\Firefox\Profiles\nw3nkhzj.default\extensions\ffxtlbr@babylon.com
[2012-02-08 21:17:13 | 000,000,000 | ---D | M] (Iplex to ALLPlayer) -- C:\Documents and Settings\QWERTY\Dane aplikacji\Mozilla\Firefox\Profiles\nw3nkhzj.default\extensions\IplextoALL@ALLPlayer.org
[2011-12-21 16:36:52 | 000,000,941 | ---- | M] () -- C:\Documents and Settings\QWERTY\Dane aplikacji\Mozilla\Firefox\Profiles\nw3nkhzj.default\searchplugins\conduit.xml
[2011-10-24 18:55:06 | 000,002,207 | ---- | M] () -- C:\Documents and Settings\QWERTY\Dane aplikacji\Mozilla\Firefox\Profiles\nw3nkhzj.default\searchplugins\MyStart Search.xml
[2011-12-25 23:10:10 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\QWERTY\Dane aplikacji\Mozilla\Firefox\Profiles\nw3nkhzj.default\searchplugins\startsear.xml
[2012-02-08 21:37:48 | 000,001,390 | ---- | M] () -- C:\Documents and Settings\QWERTY\Dane aplikacji\Mozilla\Firefox\Profiles\nw3nkhzj.default\searchplugins\yahoo-zugo.xml
[2012-02-05 15:07:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012-01-22 17:47:38 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011-10-22 21:20:49 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2012-02-05 15:07:35 | 000,000,000 | ---D | M] (ArcaBit Ext.) -- C:\Program Files\Mozilla Firefox\extensions\arcabit@www.arcabit.pl
[2010-06-09 11:54:48 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
[2011-08-05 14:46:59 | 000,000,000 | ---D | M] (Babylon OCR) -- C:\Program Files\Mozilla Firefox\extensions\ocr@babylon.com
[2009-11-02 20:11:30 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011-06-16 05:51:12 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011-10-03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009-11-16 16:23:30 | 000,120,296 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npganymedenet.dll
[2011-10-27 14:45:50 | 000,083,456 | ---- | M] (LiveVDO ) -- C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll
[2010-01-01 09:00:00 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2012-02-08 21:09:37 | 000,002,310 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2010-01-01 09:00:00 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2010-01-01 09:00:00 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2010-01-01 09:00:00 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2010-01-01 09:00:00 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2010-01-01 09:00:00 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml
 
[color=#E56717]========== Chrome  ==========[/color]
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\16.0.912.77\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\16.0.912.77\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Kaspersky Anti-Virus (Enabled) = C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\12.0.0.374_0\plugin/npVKPlugin.dll
CHR - plugin: Kaspersky Anti-Virus (Enabled) = C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\12.0.0.374_0\plugin/npABPlugin.dll
CHR - plugin: Kaspersky Anti-Virus (Enabled) = C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\12.0.0.397_0\plugin/npUrlAdvisor.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: GanymedeNet.Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npganymedenet.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.50826.0\npctrl.dll
CHR - plugin: Panda ActiveScan 2.0 (Enabled) = C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Szukaj w Google = C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: vshare plugin = C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\
CHR - Extension: Skype Click to Call = C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
CHR - Extension: LiveVDO plugin = C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pbiamblgmkgbcgbcgejjgebalncpmhnp\1.3_0\
CHR - Extension: Gmail = C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
Hosts file not found
O2 - BHO: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (Babylon BHO)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\prxtbXfi0.dll (Conduit Ltd.)
O2 - BHO: (StartNow Toolbar Helper) - {6E13D095-45C3-4271-9475-F3B48227DD9F} - C:\Program Files\StartNow Toolbar\Toolbar32.dll ()
O2 - BHO: (IE5BarLauncherBHO Class) - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files\vShare.tv plugin\BarLcher.dll (VShare Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Softonic-Polska Toolbar) - {c86eb8a9-ccc2-4b6c-b75d-73576ed591bf} - C:\Program Files\Softonic-Polska\prxtbSof0.dll (Conduit Ltd.)
O2 - BHO: (IncrediMail MediaBar 2 Toolbar) - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files\IncrediMail_MediaBar_2\tbIncr.dll (Conduit Ltd.)
O2 - BHO: (IplexToALLPlayer) - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - C:\Program Files\ALLPlayer\Iplex\IplexToALLPlayer.dll (ALLCinema Ltd.)
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10\_userdata\ggbho.2.dll File not found
O3 - HKLM\..\Toolbar: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (StartNow Toolbar) - {5911488E-9D1E-40ec-8CBB-06B231CC153F} - C:\Program Files\StartNow Toolbar\Toolbar32.dll ()
O3 - HKLM\..\Toolbar: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\prxtbXfi0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files\vShare.tv plugin\BarLcher.dll (VShare Inc.)
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (Babylon Ltd.)
O3 - HKLM\..\Toolbar: (Softonic-Polska Toolbar) - {c86eb8a9-ccc2-4b6c-b75d-73576ed591bf} - C:\Program Files\Softonic-Polska\prxtbSof0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (IncrediMail MediaBar 2 Toolbar) - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files\IncrediMail_MediaBar_2\tbIncr.dll (Conduit Ltd.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (XfireXO Toolbar) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - C:\Program Files\XfireXO\prxtbXfi0.dll (Conduit Ltd.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Softonic-Polska Toolbar) - {C86EB8A9-CCC2-4B6C-B75D-73576ED591BF} - C:\Program Files\Softonic-Polska\prxtbSof0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (XfireXO Toolbar) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - C:\Program Files\XfireXO\prxtbXfi0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Softonic-Polska Toolbar) - {C86EB8A9-CCC2-4B6C-B75D-73576ED591BF} - C:\Program Files\Softonic-Polska\prxtbSof0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-1844237615-113007714-1417001333-1003\..\Toolbar\WebBrowser: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKU\S-1-5-21-1844237615-113007714-1417001333-1003\..\Toolbar\WebBrowser: (XfireXO Toolbar) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - C:\Program Files\XfireXO\prxtbXfi0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-1844237615-113007714-1417001333-1003\..\Toolbar\WebBrowser: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files\vShare.tv plugin\BarLcher.dll (VShare Inc.)
O3 - HKU\S-1-5-21-1844237615-113007714-1417001333-1003\..\Toolbar\WebBrowser: (Softonic-Polska Toolbar) - {C86EB8A9-CCC2-4B6C-B75D-73576ED591BF} - C:\Program Files\Softonic-Polska\prxtbSof0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-1844237615-113007714-1417001333-1003\..\Toolbar\WebBrowser: (IncrediMail MediaBar 2 Toolbar) - {D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} - C:\Program Files\IncrediMail_MediaBar_2\tbIncr.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AvMenu] C:\Program Files\ArcaBit\ArcaVir\AVMenu.exe (ArcaBit)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe (HP)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
O4 - HKLM..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKU\S-1-5-21-1844237615-113007714-1417001333-1003..\Run: [ALLUpdate] C:\Program Files\ALLPlayer\ALLUpdate.exe ()
O4 - HKU\S-1-5-21-1844237615-113007714-1417001333-1003..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent File not found
O4 - HKU\S-1-5-21-1844237615-113007714-1417001333-1003..\Run: [ESL Wire] "C:\Program Files\EslWire\wire.exe" --tray File not found
O4 - HKU\S-1-5-21-1844237615-113007714-1417001333-1003..\Run: [fsm]  File not found
O4 - HKU\S-1-5-21-1844237615-113007714-1417001333-1003..\Run: [Gadu-Gadu 10] C:\Program Files\Gadu-Gadu 10\gg .exe (GG Network S.A.)
O4 - HKU\S-1-5-21-1844237615-113007714-1417001333-1003..\Run: [GAINWARD] C:\Program Files\EXPERTool\TBPanel.exe (Gainward Co.)
O4 - HKU\S-1-5-21-1844237615-113007714-1417001333-1003..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe (Take-Two Interactive Software, Inc.)
O4 - HKU\.DEFAULT..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found
O4 - HKU\S-1-5-18..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found
O4 - HKU\S-1-5-19..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found
O4 - HKU\S-1-5-20..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found
O4 - HKU\S-1-5-21-1844237615-113007714-1417001333-1005..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 File not found
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-21-1844237615-113007714-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-21-1844237615-113007714-1417001333-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Download All using 4shared Desktop - C:\Program Files\4shared Desktop\down_all.htm File not found
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: ArcaVir >> - {40525A66-DB98-480D-BCF9-7AF88C1AF438} - C:\Program Files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll (ArcaBit sp. z o.o)
O9 - Extra 'Tools' menuitem : ArcaVir >> - {40525A66-DB98-480D-BCF9-7AF88C1AF438} - C:\Program Files\ArcaBit\WebExtensions\ie\ArcaIEExt.dll (ArcaBit sp. z o.o)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\QWERTY\Pulpit\PartyPoker.lnk ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\QWERTY\Pulpit\PartyPoker.lnk ()
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{33FCD612-12C5-484E-89A0-568AF3628B32}: DhcpNameServer = 178.159.128.2 8.8.8.8
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files\vShare\vshare_toolbar.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (c:\windows\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-10-11 15:32:33 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{c61be316-fa07-11de-b827-00134648d5b2}\Shell\AutoRun\command - "" = DRIVE\file.exe
O33 - MountPoints2\{c61be316-fa07-11de-b827-00134648d5b2}\Shell\open\command - "" = DRIVE\file.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
 
[2012-02-08 21:38:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QWERTY\Dane aplikacji\Media Player Classic
[2012-02-08 21:37:49 | 000,000,000 | ---D | C] -- C:\Program Files\StartNow Toolbar
[2012-02-08 21:37:23 | 000,232,448 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\WINDOWS\System32\mp3fhg.acm
[2012-02-08 21:37:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\K-Lite Codec Pack
[2012-02-08 21:37:22 | 000,151,552 | ---- | C] (fccHandler) -- C:\WINDOWS\System32\ac3acm.acm
[2012-02-08 21:37:19 | 000,000,000 | ---D | C] -- C:\Program Files\K-Lite Codec Pack
[2012-02-08 21:17:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\NapiProjekt
[2012-02-08 21:17:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\ALLConverter PRO
[2012-02-08 21:17:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\ALLConverter
[2012-02-08 21:17:27 | 000,000,000 | ---D | C] -- C:\Program Files\NapiProjekt
[2012-02-08 21:17:27 | 000,000,000 | ---D | C] -- C:\Program Files\ALLConverter PRO
[2012-02-08 21:17:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\ALLPlayer
[2012-02-08 21:17:13 | 000,000,000 | ---D | C] -- C:\Program Files\ALLPlayer
[2012-02-08 21:09:49 | 000,000,000 | ---D | C] -- C:\Program Files\BabylonToolbar
[2012-02-08 21:09:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Babylon
[2012-02-08 21:09:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Babylon
[2012-02-08 21:09:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QWERTY\Dane aplikacji\Babylon
[2012-02-08 20:59:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QWERTY\Dane aplikacji\BESTplayer
[2012-02-07 16:04:10 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2012-02-07 16:04:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QWERTY\Menu Start\Programy\HiJackThis
[2012-02-07 15:02:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QWERTY\Moje dokumenty\Crysis2
[2012-02-07 15:01:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Solidshield
[2012-02-07 14:55:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\Electronic Arts
[2012-02-05 15:07:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\ArcaVir
[2012-02-05 15:07:07 | 000,000,000 | ---D | C] -- C:\Program Files\ArcaBit
[2012-02-05 15:07:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\ArcaBit
[2012-01-22 17:47:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Skype
[2012-01-22 13:46:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\PokerTH
[2012-01-20 21:08:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\PostgreSQL 8.3
[2012-01-20 21:07:57 | 000,000,000 | ---D | C] -- C:\Program Files\PostgreSQL
[2012-01-20 21:06:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\PokerStrategy.com
[2012-01-20 21:06:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QWERTY\Moje dokumenty\PokerStrategy.com
[2012-01-20 21:06:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\PokerStrategy.com
[2012-01-20 21:06:35 | 000,000,000 | ---D | C] -- C:\Program Files\PokerStrategy.com
[2012-01-20 18:36:05 | 017,683,674 | ---- | C] (Name of your company) -- C:\Documents and Settings\QWERTY\Pulpit\PokerTH-0.7.1-win-installer.exe
[2012-01-19 20:10:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QWERTY\Moje dokumenty\FIFA 12
[2012-01-19 20:09:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\EA Core
[2012-01-14 19:58:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QWERTY\Menu Start\Programy\PartyPoker
[2012-01-14 17:20:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QWERTY\P5JavaClientSettings
[2012-01-14 17:19:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\P5
[2012-01-14 17:19:44 | 000,000,000 | ---D | C] -- C:\Betfair JPC
[2012-01-14 16:59:05 | 000,000,000 | ---D | C] -- C:\Poker
[2012-01-14 16:35:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QWERTY\Dane aplikacji\Mozilla-Cache
[2012-01-14 16:35:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\QWERTY\Menu Start\Programy\Games
[2012-01-14 16:32:45 | 000,000,000 | ---D | C] -- C:\Program Files\PartyGaming
[2011-08-05 14:42:15 | 003,461,616 | ---- | C] (DownVision                                                  ) -- C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\setup.exe
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
 
[2060-08-18 19:02:32 | 002,023,424 | ---- | M] (Inprise Corporation) -- C:\WINDOWS\System32\VCL50.BPL
[2060-08-18 19:02:22 | 001,496,064 | ---- | M] (Inprise Corporation) -- C:\WINDOWS\System32\CC3250MT.DLL
[2060-08-18 19:02:12 | 000,248,832 | ---- | M] (Inprise Corporation) -- C:\WINDOWS\System32\VCLX50.BPL
[2060-08-18 18:40:44 | 000,909,824 | ---- | M] (Inprise Corporation) -- C:\WINDOWS\System32\cp3245mt.dll
[2060-08-18 18:40:44 | 000,024,064 | ---- | M] (Inprise Corporation) -- C:\WINDOWS\System32\borlndmm.dll
[2012-02-10 15:12:01 | 000,001,136 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-113007714-1417001333-1003UA.job
[2012-02-10 15:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\tasks\At16.job
[2012-02-10 14:49:58 | 000,235,610 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2012-02-10 14:49:53 | 000,000,308 | ---- | M] () -- C:\WINDOWS\tasks\systems.job
[2012-02-10 14:49:53 | 000,000,308 | ---- | M] () -- C:\WINDOWS\tasks\fbagent.job
[2012-02-10 14:49:52 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012-02-10 14:49:50 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012-02-09 17:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\tasks\At18.job
[2012-02-09 16:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\tasks\At17.job
[2012-02-09 14:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\tasks\At15.job
[2012-02-08 23:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\tasks\At24.job
[2012-02-08 22:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\tasks\At23.job
[2012-02-08 21:50:41 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012-02-08 21:17:30 | 000,000,663 | ---- | M] () -- C:\Documents and Settings\QWERTY\Pulpit\NapiProjekt.lnk
[2012-02-08 21:17:29 | 000,000,779 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\ALLConverter PRO.lnk
[2012-02-08 21:17:21 | 000,000,700 | ---- | M] () -- C:\Documents and Settings\QWERTY\Pulpit\ALLPlayer V5.0.lnk
[2012-02-08 21:12:00 | 000,001,084 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-113007714-1417001333-1003Core.job
[2012-02-08 21:09:50 | 000,000,237 | ---- | M] () -- C:\user.js
[2012-02-08 21:00:11 | 000,107,520 | ---- | M] () -- C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012-02-08 21:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\tasks\At22.job
[2012-02-08 20:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\tasks\At21.job
[2012-02-08 19:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\tasks\At20.job
[2012-02-08 18:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\tasks\At19.job
[2012-02-07 15:24:50 | 000,000,655 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\ESL Wire.lnk
[2012-02-07 14:54:41 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\EA Download Manager.lnk
[2012-02-07 14:54:11 | 000,001,506 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Crysis® 2.lnk
[2012-02-07 09:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\tasks\At10.job
[2012-02-06 19:00:00 | 000,079,360 | ---- | M] () -- C:\WINDOWS\System32\ff_vfw.dll
[2012-02-05 13:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\tasks\At14.job
[2012-02-05 12:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\tasks\At13.job
[2012-02-03 10:29:56 | 000,042,392 | ---- | M] () -- C:\WINDOWS\System32\xfcodec.dll
[2012-01-29 19:27:47 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Skype.lnk
[2012-01-26 15:57:56 | 000,002,317 | ---- | M] () -- C:\Documents and Settings\QWERTY\Pulpit\Google Chrome.lnk
[2012-01-22 20:13:27 | 000,962,248 | ---- | M] () -- C:\Documents and Settings\QWERTY\Pulpit\Wto.rar
[2012-01-22 20:11:22 | 005,027,958 | ---- | M] () -- C:\Documents and Settings\QWERTY\Pulpit\bez tytułu.bmp
[2012-01-20 21:07:47 | 000,000,387 | ---- | M] () -- C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\postgresinstall.bat
[2012-01-20 21:06:44 | 000,002,004 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\PokerStrategy.com Elephant.lnk
[2012-01-20 18:37:58 | 017,683,674 | ---- | M] (Name of your company) -- C:\Documents and Settings\QWERTY\Pulpit\PokerTH-0.7.1-win-installer.exe
[2012-01-20 16:58:53 | 000,555,448 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2012-01-20 16:58:53 | 000,493,190 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012-01-20 16:58:53 | 000,104,478 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2012-01-20 16:58:53 | 000,083,734 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012-01-19 18:08:17 | 000,000,588 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\FIFA 12.lnk
[2012-01-15 02:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\tasks\At3.job
[2012-01-15 01:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\tasks\At2.job
[2012-01-15 00:56:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[2012-01-14 19:58:23 | 000,001,656 | ---- | M] () -- C:\Documents and Settings\QWERTY\Pulpit\PartyPoker.lnk
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
 
[color=#E56717]========== Files Created - No Company Name ==========[/color]
 
[2012-02-08 21:37:23 | 000,243,200 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2012-02-08 21:37:22 | 000,175,616 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2012-02-08 21:37:21 | 000,079,360 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2012-02-08 21:17:30 | 000,000,663 | ---- | C] () -- C:\Documents and Settings\QWERTY\Pulpit\NapiProjekt.lnk
[2012-02-08 21:17:29 | 000,000,779 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\ALLConverter PRO.lnk
[2012-02-08 21:17:21 | 000,000,700 | ---- | C] () -- C:\Documents and Settings\QWERTY\Pulpit\ALLPlayer V5.0.lnk
[2012-02-08 21:17:15 | 000,797,184 | ---- | C] () -- C:\WINDOWS\System32\ac3filter.ax
[2012-02-08 21:17:15 | 000,650,752 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2012-02-08 21:17:15 | 000,258,048 | ---- | C] () -- C:\WINDOWS\System32\libFLAC.dll
[2012-02-08 21:09:50 | 000,000,237 | ---- | C] () -- C:\user.js
[2012-02-07 14:54:41 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\EA Download Manager.lnk
[2012-02-07 14:54:11 | 000,001,506 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Crysis® 2.lnk
[2012-02-03 10:29:56 | 000,042,392 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll
[2012-01-29 14:58:05 | 022,237,696 | ---- | C] () -- C:\Documents and Settings\QWERTY\Pulpit\pokerth.exe
[2012-01-22 20:13:26 | 000,962,248 | ---- | C] () -- C:\Documents and Settings\QWERTY\Pulpit\Wto.rar
[2012-01-22 20:11:22 | 005,027,958 | ---- | C] () -- C:\Documents and Settings\QWERTY\Pulpit\bez tytułu.bmp
[2012-01-20 21:07:47 | 000,000,387 | ---- | C] () -- C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\postgresinstall.bat
[2012-01-20 21:06:44 | 000,002,004 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\PokerStrategy.com Elephant.lnk
[2012-01-19 18:08:17 | 000,000,588 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\FIFA 12.lnk
[2012-01-14 19:58:23 | 000,001,656 | ---- | C] () -- C:\Documents and Settings\QWERTY\Pulpit\PartyPoker.lnk
[2011-10-24 18:55:06 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\redmonnt.dll
[2011-09-11 10:54:37 | 000,017,408 | ---- | C] () -- C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\WebpageIcons.db
[2011-09-10 14:26:48 | 000,000,112 | ---- | C] () -- C:\Documents and Settings\All Users\Dane aplikacji\b87ychq8.dat
[2011-07-20 10:29:53 | 000,265,120 | ---- | C] () -- C:\Program Files\Common Files\WireHelpSvc.exe
[2011-07-07 19:32:03 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011-02-07 15:35:53 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2010-07-15 22:42:28 | 001,482,736 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat
[2010-07-08 13:05:19 | 000,138,160 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010-07-08 13:05:19 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\QWERTY\Dane aplikacji\PnkBstrK.sys
[2010-07-08 13:04:53 | 000,271,200 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2010-07-08 13:04:51 | 002,250,024 | ---- | C] () -- C:\WINDOWS\System32\pbsvc.exe
[2010-07-08 13:04:51 | 000,075,136 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2010-05-26 22:19:57 | 000,000,560 | ---- | C] () -- C:\Program Files\Global.sw
[2010-04-02 16:17:34 | 000,179,091 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2010-03-31 18:04:11 | 000,000,269 | ---- | C] () -- C:\WINDOWS\game.ini
[2010-03-13 11:31:31 | 000,002,596 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Config.nt.bak
[2010-03-13 11:31:31 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Autoexec.nt.bak
[2010-03-13 11:31:31 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\hosts.bak
[2010-03-04 20:21:46 | 000,037,068 | ---- | C] () -- C:\Documents and Settings\QWERTY\Dane aplikacji\M,S,Bigos.dpit
[2010-03-04 20:16:20 | 000,037,068 | ---- | C] () -- C:\Documents and Settings\QWERTY\Dane aplikacji\Drugi Urząd Skarbowy 33-100 TarnóM.S.Bigos.dpit
[2010-03-04 19:40:01 | 000,032,858 | ---- | C] () -- C:\Documents and Settings\QWERTY\Dane aplikacji\tomek.dpit
[2010-02-24 18:06:10 | 000,039,768 | ---- | C] () -- C:\Documents and Settings\QWERTY\Dane aplikacji\pity gebscy.dpit
[2010-02-24 17:54:46 | 000,039,768 | ---- | C] () -- C:\Documents and Settings\QWERTY\Dane aplikacji\Drugi Urząd Skarbowy 33-100 Tarnów, al. Solidarności 5-9B__2010-02-24 17-54-35.dpit
[2010-02-22 19:40:22 | 000,039,510 | ---- | C] () -- C:\Documents and Settings\QWERTY\Dane aplikacji\Drugi Urząd Skarbowy 33-100 Tarnów, al. Solidarności 5-9B__2010-02-22 19-40-05.dpit
[2010-01-12 18:19:28 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2010-01-10 14:15:47 | 000,089,088 | ---- | C] () -- C:\WINDOWS\System32\Zlib.dll
[2010-01-10 14:14:27 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2009-12-27 17:09:18 | 000,000,421 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009-12-11 17:48:36 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009-12-08 17:36:12 | 000,281,760 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2009-12-08 17:36:11 | 000,025,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2009-12-01 19:47:22 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\QWERTY\Dane aplikacji\$_hpcst$.hpc
[2009-11-26 22:23:40 | 000,107,520 | ---- | C] () -- C:\Documents and Settings\QWERTY\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-11-08 11:41:22 | 000,000,008 | ---- | C] () -- C:\Documents and Settings\QWERTY\Dane aplikacji\NMM-MetaData.db
[2009-10-25 15:49:26 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009-10-19 12:58:26 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2009-10-13 13:27:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009-10-11 17:22:05 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009-10-11 17:18:55 | 000,155,912 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009-10-11 17:15:38 | 000,040,636 | R--- | C] () -- C:\WINDOWS\System32\drivers\WLANGEN.bin
[2009-10-11 17:15:38 | 000,000,964 | R--- | C] () -- C:\WINDOWS\System32\drivers\RADIO11.bin
[2009-10-11 17:15:38 | 000,000,936 | R--- | C] () -- C:\WINDOWS\System32\drivers\RADIO0d.bin
[2009-10-11 17:15:38 | 000,000,912 | R--- | C] () -- C:\WINDOWS\System32\drivers\RADIO15.bin
[2009-10-11 15:34:13 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009-10-11 15:29:07 | 000,021,856 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009-07-03 04:11:18 | 001,580,550 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2009-07-03 04:11:18 | 000,007,274 | ---- | C] () -- C:\WINDOWS\cadx2.ini
[2009-06-10 07:29:34 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2009-06-10 07:29:34 | 001,657,376 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2009-06-10 07:29:34 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2009-06-10 07:29:34 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2009-06-10 07:29:34 | 000,449,056 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2009-06-10 07:29:34 | 000,436,768 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2009-06-10 07:29:32 | 001,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008-04-15 00:16:20 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2007-03-29 23:00:40 | 000,203,264 | R--- | C] () -- C:\WINDOWS\System32\CddbCdda.dll
[2006-12-31 08:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2001-10-26 20:15:16 | 000,555,448 | ---- | C] () -- C:\WINDOWS\System32\perfh015.dat
[2001-10-26 20:15:16 | 000,313,828 | ---- | C] () -- C:\WINDOWS\System32\perfi015.dat
[2001-10-26 20:15:16 | 000,104,478 | ---- | C] () -- C:\WINDOWS\System32\perfc015.dat
[2001-10-26 20:15:16 | 000,034,990 | ---- | C] () -- C:\WINDOWS\System32\perfd015.dat
[2001-08-23 17:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001-08-23 17:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001-08-18 01:30:24 | 000,493,190 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001-08-18 01:30:24 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001-08-18 01:30:24 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001-08-18 01:30:22 | 000,083,734 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001-08-18 01:15:38 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001-07-22 02:36:48 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001-07-22 02:36:04 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001-07-22 02:24:16 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
 
[color=#E56717]========== LOP Check ==========[/color]
 
[2012-02-08 15:49:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ArcaBit
[2012-02-08 21:09:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Babylon
[2010-10-14 16:31:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Codemasters
[2011-10-23 13:00:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Lite
[2012-01-19 20:09:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\EA Core
[2012-02-07 14:54:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Electronic Arts
[2011-07-20 10:28:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ESL Wire
[2011-08-02 19:13:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\G DATA
[2010-02-04 21:00:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Gadu-Gadu 10
[2011-08-04 20:14:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Guitar Pro 6
[2011-10-24 18:57:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\IM
[2011-10-24 18:57:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\IncrediMail
[2009-11-08 11:31:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Installations
[2009-11-08 17:14:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ipla
[2010-12-27 12:57:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\lOlFk04300
[2011-06-19 14:00:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\OpenFM
[2011-08-02 19:19:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Panda Security
[2009-10-14 20:11:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\PC Suite
[2012-02-07 15:02:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Solidshield
[2011-11-03 19:37:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\SweetIM
[2010-11-22 17:48:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TEMP
[2010-06-25 09:58:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Ubisoft
[2011-08-04 18:05:25 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\{3FC66E2C-85B6-4398-82FB-C13C51DE9DD8}
[2010-06-09 12:19:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Dane aplikacji\Nokia
[2010-06-09 12:19:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\elephant\Dane aplikacji\Nokia
[2011-08-02 19:21:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\pandasecuritytb
[2011-08-02 19:21:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dane aplikacji\SurfSecret Privacy Suite
[2011-09-10 16:30:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Dane aplikacji\pandasecuritytb
[2011-09-10 14:30:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Dane aplikacji\SurfSecret Privacy Suite
[2010-10-20 15:45:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\2K Sports
[2012-02-08 21:09:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\Babylon
[2012-02-08 20:59:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\BESTplayer
[2009-12-08 17:56:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\DAEMON Tools Lite
[2009-12-08 17:57:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\DAEMON Tools Pro
[2011-10-23 14:57:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\Dev-Cpp
[2010-05-24 12:55:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\EurekaLog
[2009-10-12 15:37:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\Gadu-Gadu
[2011-12-09 18:51:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\Gadu-Gadu 10
[2010-12-13 16:15:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\GameRanger
[2011-05-09 15:31:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\GanymedeNet
[2011-12-22 17:35:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\GetRightToGo
[2011-12-22 17:29:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\gtk-2.0
[2011-12-22 19:01:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\Guitar Pro 6
[2010-02-08 15:17:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\ipla
[2009-10-16 20:08:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\Leadertech
[2011-11-29 12:09:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\Mikrotik
[2010-05-09 20:55:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\MuPAD
[2011-06-26 10:16:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\Need for Speed World
[2009-11-08 11:42:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\Nokia
[2009-11-08 11:51:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\Nokia Multimedia Player
[2009-12-12 13:56:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\Nowe Gadu-Gadu
[2010-07-13 10:39:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\OpenFM
[2011-07-27 23:42:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\OwnRooms
[2011-09-11 10:43:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\Panda Security
[2009-11-26 23:12:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\PC Suite
[2011-04-09 19:06:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\PhotoScape
[2012-01-01 15:12:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\pokerth
[2012-02-01 20:05:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\PriceGong
[2011-09-11 10:49:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\Software Informer
[2010-10-08 18:48:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\SurfSecret Privacy Suite
[2011-07-09 00:32:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\TeamViewer
[2012-01-17 20:28:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\TS3Client
[2011-08-04 12:33:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\ts3overlay
[2011-06-20 08:37:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\Ubisoft
[2010-12-13 16:14:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\UpdateStar Drivers
[2010-06-25 12:19:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\URSoft
[2012-02-08 20:52:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\uTorrent
[2010-11-29 22:15:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\QWERTY\Dane aplikacji\vShare
[2012-01-15 00:56:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At1.job
[2012-02-07 09:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At10.job
[2011-12-29 10:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At11.job
[2011-12-30 11:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At12.job
[2012-02-05 12:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At13.job
[2012-02-05 13:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At14.job
[2012-02-09 14:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At15.job
[2012-02-10 15:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At16.job
[2012-02-09 16:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At17.job
[2012-02-09 17:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At18.job
[2012-02-08 18:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At19.job
[2012-01-15 01:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At2.job
[2012-02-08 19:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At20.job
[2012-02-08 20:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At21.job
[2012-02-08 21:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At22.job
[2012-02-08 22:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At23.job
[2012-02-08 23:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At24.job
[2012-01-15 02:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At3.job
[2011-12-26 03:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At4.job
[2011-11-30 04:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At5.job
[2011-09-10 16:30:19 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At6.job
[2011-09-10 16:30:19 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At7.job
[2011-11-09 07:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At8.job
[2011-11-23 08:00:00 | 000,000,424 | ---- | M] () -- C:\WINDOWS\Tasks\At9.job
[2012-02-10 14:49:53 | 000,000,308 | ---- | M] () -- C:\WINDOWS\Tasks\fbagent.job
[2012-02-10 14:49:53 | 000,000,308 | ---- | M] () -- C:\WINDOWS\Tasks\systems.job
 
[color=#E56717]========== Purity Check ==========[/color]
 
 
 
[color=#E56717]========== Alternate Data Streams ==========[/color]
 
@Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:1CE11B51
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:2FC64B8C

< End of report >
