x-kom hosting

Samoistne minimalizowanie się gier, wyskakujące strony z reklamami.

Majhau
utworzono
utworzono (edytowane)

Witajcie.

Młodszy brat słynie ze ściągania, co popadnie. Dzisiaj odkryłem, że co jakiś czas wyskakują strony z reklamami, co wcześniej nie miało miejsca. Główna fala uderzeniowa tego problemu skupiła się jednak na samoistnym minimalizowaniu się gier, spowolnieniu systemu. Obstawiam, że jest to infekcja wirusowa, gdyż dzień wcześniej wszystko było dobrze i wątpię w to, iż młody namieszał coś w systemie. Cóż, tak to bywa. Mam nadzieję, że mi pomożecie, wrzucam logi z OTL i RSIT.
[left]
[b]OTL:[/b][/left]

[left][log] OTL logfile created on: 12/20/2010 11:50:34 PM - Run 1
OTL by OldTimer - Version 3.2.17.4 Folder = C:\Users\Michał mistrz\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

4.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 38.00% Memory free
8.00 Gb Paging File | 5.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 256.00 Gb Total Space | 28.99 Gb Free Space | 11.32% Space Free | Partition Type: NTFS
Drive G: | 1.84 Gb Total Space | 0.85 Gb Free Space | 46.04% Space Free | Partition Type: FAT
Drive M: | 29.29 Gb Total Space | 9.30 Gb Free Space | 31.73% Space Free | Partition Type: NTFS

Computer Name: ACER | User Name: Michał mistrz | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 60 Days

[color=#E56717]========== Processes (All) ==========[/color]

PRC - [2010/12/20 23:47:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Michał mistrz\Downloads\OTL.exe
PRC - [2010/12/19 23:55:24 | 000,221,696 | ---- | M] (Windows (R) Codename Longhorn DDK provider) -- C:\Users\MICHAM~1\AppData\Local\Temp\Wcd.exe
PRC - [2010/12/19 23:54:53 | 000,218,624 | ---- | M] (Windows (R) Codename Longhorn DDK provider) -- C:\Users\MICHAM~1\AppData\Local\Temp\Wcc.exe
PRC - [2010/12/19 23:54:34 | 000,211,968 | ---- | M] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\Wvucia.exe
PRC - [2010/12/11 12:31:01 | 000,267,944 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2010/12/11 10:15:57 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
PRC - [2010/12/11 10:15:56 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2010/11/12 19:08:04 | 000,398,680 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Game Booster\GameBox.exe
PRC - [2010/11/05 17:53:56 | 000,327,000 | ---- | M] (Enigma Software Group USA, LLC.) -- C:\PROGRA~2\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
PRC - [2010/11/04 16:43:10 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010/11/04 16:43:10 | 000,135,336 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2010/11/04 06:54:54 | 000,673,040 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
PRC - [2010/10/28 13:42:24 | 000,304,304 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
PRC - [2010/07/12 17:32:48 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\Winamp\winampa.exe
PRC - [2010/07/10 16:41:11 | 000,075,064 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2010/02/24 02:44:53 | 000,200,704 | ---- | M] () -- C:\Windows\PLFSetI.exe
PRC - [2010/02/18 10:43:18 | 000,248,040 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
PRC - [2009/11/05 01:49:37 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009/11/02 00:39:48 | 001,094,736 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2009/10/01 05:01:32 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2009/10/01 05:01:30 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2009/09/25 00:42:32 | 000,261,888 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
PRC - [2009/09/25 00:42:28 | 000,062,720 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
PRC - [2009/08/28 10:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
PRC - [2009/07/25 17:22:36 | 000,376,320 | ---- | M] (Image-Line) -- C:\Program Files (x86)\Image-Line\FL Studio 9\FL.exe
PRC - [2009/07/04 03:47:12 | 000,240,160 | ---- | M] (Acer) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe
PRC - [2009/06/18 02:31:58 | 000,144,640 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
PRC - [2009/06/05 04:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009/06/05 04:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
PRC - [2007/05/28 17:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
PRC - [2006/02/28 11:42:38 | 000,229,376 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe


[color=#E56717]========== Modules (All) ==========[/color]

MOD - [2010/12/20 23:47:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Michał mistrz\Downloads\OTL.exe
MOD - [2010/08/21 06:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
MOD - [2010/07/27 15:03:24 | 012,867,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shell32.dll
MOD - [2010/06/29 06:02:02 | 001,413,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ole32.dll
MOD - [2010/04/07 08:10:36 | 000,571,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\oleaut32.dll
MOD - [2010/03/24 07:37:04 | 001,289,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntdll.dll
MOD - [2009/12/11 08:39:06 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\secur32.dll
MOD - [2009/12/11 08:36:33 | 000,096,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sspicli.dll
MOD - [2009/07/14 02:16:19 | 000,268,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\Wldap32.dll
MOD - [2009/07/14 02:16:17 | 001,123,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vssapi.dll
MOD - [2009/07/14 02:16:17 | 000,627,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\usp10.dll
MOD - [2009/07/14 02:16:17 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vsstrace.dll
MOD - [2009/07/14 02:16:17 | 000,021,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\version.dll
MOD - [2009/07/14 02:16:15 | 000,171,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\spp.dll
MOD - [2009/07/14 02:16:15 | 000,043,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\srclient.dll
MOD - [2009/07/14 02:16:14 | 001,668,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\setupapi.dll
MOD - [2009/07/14 02:16:14 | 000,350,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shlwapi.dll
MOD - [2009/07/14 02:16:14 | 000,179,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shdocvw.dll
MOD - [2009/07/14 02:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sechost.dll
MOD - [2009/07/14 02:16:12 | 000,988,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\propsys.dll
MOD - [2009/07/14 02:16:12 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\olepro32.dll
MOD - [2009/07/14 02:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\profapi.dll
MOD - [2009/07/14 02:16:12 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\psapi.dll
MOD - [2009/07/14 02:16:11 | 000,121,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntmarta.dll
MOD - [2009/07/14 02:15:50 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msvcrt.dll
MOD - [2009/07/14 02:15:43 | 000,828,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msctf.dll
MOD - [2009/07/14 02:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dwmapi.dll
MOD - [2009/07/14 02:15:11 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\devobj.dll
MOD - [2009/07/14 02:15:07 | 000,486,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\comdlg32.dll
MOD - [2009/07/14 02:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptbase.dll
MOD - [2009/07/14 02:15:03 | 000,522,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\clbcatq.dll
MOD - [2009/07/14 02:15:02 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cfgmgr32.dll
MOD - [2009/07/14 02:14:57 | 000,070,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\atl.dll
MOD - [2009/07/14 02:14:53 | 000,640,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\advapi32.dll
MOD - [2009/07/14 02:14:53 | 000,292,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\apphelp.dll
MOD - [2009/07/14 02:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx
MOD - [2009/07/14 02:14:08 | 000,319,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winspool.drv
MOD - [2009/07/14 02:11:24 | 000,833,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\user32.dll
MOD - [2009/07/14 02:11:24 | 000,245,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\uxtheme.dll
MOD - [2009/07/14 02:11:23 | 000,836,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\kernel32.dll
MOD - [2009/07/14 02:11:23 | 000,662,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rpcrt4.dll
MOD - [2009/07/14 02:11:23 | 000,269,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\KernelBase.dll
MOD - [2009/07/14 02:11:23 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\lpk.dll
MOD - [2009/07/14 02:11:21 | 000,310,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\gdi32.dll
MOD - [2009/07/14 02:11:21 | 000,119,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\imm32.dll


[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - File not found [Auto | Running] -- C:\Windows\SysNative\PnkBstrA.exe -- (PnkBstrA)
SRV:[b]64bit:[/b] - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:[b]64bit:[/b] - [2009/12/10 10:15:06 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:[b]64bit:[/b] - [2009/11/02 21:48:18 | 000,126,352 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV:[b]64bit:[/b] - [2009/09/30 23:44:58 | 000,844,320 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe -- (ePowerSvc)
SRV:[b]64bit:[/b] - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2009/07/04 03:47:12 | 000,240,160 | ---- | M] (Acer) [Auto | Running] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV:[b]64bit:[/b] - [2009/03/28 03:10:16 | 000,016,896 | ---- | M] (LSI Corporation) [Auto | Running] -- C:\Program Files\LSI SoftModem\agr64svc.exe -- (AgereModemAudio)
SRV - [2010/12/14 10:56:14 | 001,660,248 | ---- | M] (Doctor Web, Ltd.) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Doctor Web\Scanning Engine\dwengine.exe -- (DrWebEngine) Dr.Web Scanning Engine (DrWebEngine)
SRV - [2010/12/11 12:31:01 | 000,267,944 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010/11/14 19:37:49 | 000,403,240 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/11/05 17:53:56 | 000,327,000 | ---- | M] (Enigma Software Group USA, LLC.) [Auto | Running] -- C:\PROGRA~2\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE -- (SpyHunter 4 Service)
SRV - [2010/11/04 16:43:10 | 000,135,336 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010/07/10 16:41:11 | 000,075,064 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2010/07/01 23:03:38 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/10/01 05:01:32 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) Intel(R)
SRV - [2009/10/01 05:01:30 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) Intel(R)
SRV - [2009/09/25 00:42:28 | 000,062,720 | ---- | M] (NewTech Infosystems, Inc.) [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2009/08/28 10:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe -- (Greg_Service)
SRV - [2009/06/18 02:31:58 | 000,144,640 | ---- | M] (NewTech Infosystems, Inc.) [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe -- (NTISchedulerSvc)
SRV - [2009/06/18 02:31:46 | 000,050,432 | ---- | M] (NewTech InfoSystems, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe -- (NTIBackupSvc)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/05 04:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMON) Intel(R)
SRV - [2007/05/28 17:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) [Auto | Running] -- C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2010/12/13 14:04:28 | 000,150,520 | ---- | M] (Doctor Web, Ltd.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\dwprot.sys -- (DwProt)
DRV:[b]64bit:[/b] - [2010/11/23 10:46:54 | 000,083,120 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:[b]64bit:[/b] - [2010/09/23 00:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:[b]64bit:[/b] - [2010/07/19 13:41:54 | 000,103,416 | ---- | M] (Doctor Web, Ltd.) [File_System | Boot | Stopped] -- C:\Windows\SysNative\drivers\spiderg3.sys -- (SpiderG3)
DRV:[b]64bit:[/b] - [2010/07/13 00:25:24 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:[b]64bit:[/b] - [2010/07/13 00:25:24 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:[b]64bit:[/b] - [2010/07/10 16:21:33 | 000,828,912 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:[b]64bit:[/b] - [2010/07/05 23:18:55 | 000,034,032 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\seehcri.sys -- (seehcri)
DRV:[b]64bit:[/b] - [2010/07/05 23:18:29 | 000,027,176 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggsemc.sys -- (ggsemc)
DRV:[b]64bit:[/b] - [2010/07/05 23:18:29 | 000,013,352 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ggflt.sys -- (ggflt)
DRV:[b]64bit:[/b] - [2010/05/27 17:25:36 | 000,264,192 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:[b]64bit:[/b] - [2010/03/02 12:35:01 | 000,116,568 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:[b]64bit:[/b] - [2009/12/10 12:40:30 | 006,179,328 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:[b]64bit:[/b] - [2009/12/10 12:40:30 | 006,179,328 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:[b]64bit:[/b] - [2009/11/06 21:56:06 | 001,550,848 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:[b]64bit:[/b] - [2009/11/02 21:48:02 | 000,013,784 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
DRV:[b]64bit:[/b] - [2009/10/26 21:39:44 | 000,151,936 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:[b]64bit:[/b] - [2009/09/18 05:12:06 | 000,292,912 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:[b]64bit:[/b] - [2009/09/17 21:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel(R)
DRV:[b]64bit:[/b] - [2009/08/13 20:20:46 | 001,209,856 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem)
DRV:[b]64bit:[/b] - [2009/08/06 13:43:58 | 000,320,040 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a) Broadcom NetLink (TM)
DRV:[b]64bit:[/b] - [2009/07/22 23:06:26 | 000,040,448 | ---- | M] (Alcor Micro, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AmUStor.sys -- (AmUStor)
DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2009/07/14 02:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009/07/14 02:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009/06/25 03:23:24 | 000,205,472 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:[b]64bit:[/b] - [2009/06/20 03:09:57 | 000,054,272 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\L1E62x64.sys -- (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20)
DRV:[b]64bit:[/b] - [2009/06/10 21:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:[b]64bit:[/b] - [2009/06/10 21:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:[b]64bit:[/b] - [2009/06/10 21:34:38 | 001,311,232 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:[b]64bit:[/b] - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:[b]64bit:[/b] - [2009/06/05 03:54:36 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:[b]64bit:[/b] - [2009/05/06 01:46:08 | 000,018,432 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV:[b]64bit:[/b] - [2009/05/06 01:46:08 | 000,016,896 | ---- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)

[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0415&m=aspire_5740&r=27360610h116l0438z1j5t64i1d199
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0415&m=aspire_5740&r=27360610h116l0438z1j5t64i1d199
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0415&m=aspire_5740&r=27360610h116l0438z1j5t64i1d199
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0415&m=aspire_5740&r=27360610h116l0438z1j5t64i1d199
IE - HKLM\..\URLSearchHook: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll (Conduit Ltd.)


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local



IE - HKU\S-1-5-21-1070666057-106192516-1559153215-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0415&m=aspire_5740&r=27360610h116l0438z1j5t64i1d199
IE - HKU\S-1-5-21-1070666057-106192516-1559153215-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
IE - HKU\S-1-5-21-1070666057-106192516-1559153215-1000\..\URLSearchHook: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-1070666057-106192516-1559153215-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1070666057-106192516-1559153215-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.defaultthis.engineName: "Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.pl/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.6.9.134

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/12/12 20:19:16 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/12/12 20:19:16 | 000,000,000 | ---D | M]

[2010/06/30 11:30:41 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\mozilla\Extensions
[2010/12/20 22:41:15 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\mozilla\Firefox\Profiles\xa7uy0to.default\extensions
[2010/07/20 13:02:21 | 000,000,000 | ---D | M] (DVDVideoSoftTB Toolbar) -- C:\Users\Michał mistrz\AppData\Roaming\mozilla\Firefox\Profiles\xa7uy0to.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2010/07/29 21:57:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michał mistrz\AppData\Roaming\mozilla\Firefox\Profiles\xa7uy0to.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010/10/02 13:03:34 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\mozilla\Firefox\Profiles\xa7uy0to.default\extensions\toolbar@ask.com
[2010/07/20 13:03:05 | 000,000,873 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Roaming\Mozilla\FireFox\Profiles\xa7uy0to.default\searchplugins\conduit.xml
[2010/07/10 16:25:23 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions
[2010/06/30 14:22:46 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/06/30 14:22:35 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010/09/13 16:29:30 | 000,120,296 | ---- | M] ( ) -- C:\Program Files (x86)\mozilla firefox\plugins\npganymedenet.dll
[2010/07/12 17:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2010/10/21 21:46:54 | 000,002,767 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\allegro-pl.xml
[2010/10/21 21:46:54 | 000,001,406 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fbc-pl.xml
[2010/10/21 21:46:54 | 000,000,917 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\merlin-pl.xml
[2010/10/21 21:46:54 | 000,000,858 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\pwn-pl.xml
[2010/10/21 21:46:54 | 000,001,183 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-pl.xml
[2010/10/21 21:46:54 | 000,001,683 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wp-pl.xml

O1 HOSTS File: ([2010/12/20 14:50:12 | 000,000,808 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:[b]64bit:[/b] - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg64.dll (Google Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com)
O2 - BHO: (free-downloads.net Toolbar) - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll (Conduit Ltd.)
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\ProgramData\Gadu-Gadu 10\_userdata\ggbho.2.dll File not found
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (free-downloads.net Toolbar) - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:[b]64bit:[/b] - HKU\S-1-5-21-1070666057-106192516-1559153215-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKU\S-1-5-21-1070666057-106192516-1559153215-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\S-1-5-21-1070666057-106192516-1559153215-1000\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKU\S-1-5-21-1070666057-106192516-1559153215-1000\..\Toolbar\WebBrowser: (free-downloads.net Toolbar) - {ECDEE021-0D17-467F-A1FF-C7A115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll (Conduit Ltd.)
O4:[b]64bit:[/b] - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4:[b]64bit:[/b] - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (AlcorMicro Co., Ltd.)
O4:[b]64bit:[/b] - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe File not found
O4:[b]64bit:[/b] - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)
O4 - HKLM..\Run: [SpIDerAgent] C:\Program Files (x86)\DrWeb\SpIDerAgent.exe (Doctor Web, Ltd.)
O4 - HKLM..\Run: [SpIDerMail] C:\Program Files (x86)\DrWeb\spiderml.exe (Doctor Web, Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1070666057-106192516-1559153215-1000..\Run: [AlcoholAutomount] C:\Program Files (x86)\Alcohol Soft\Alcohol 120\axcmd.exe (Alcohol Soft Development Team)
O4 - HKU\S-1-5-21-1070666057-106192516-1559153215-1000..\Run: [ALLUpdate] C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe ()
O4 - HKU\S-1-5-21-1070666057-106192516-1559153215-1000..\Run: [DAEMON Tools Pro Agent] C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-1070666057-106192516-1559153215-1000..\Run: [JP595IR86O] C:\Users\MICHAM~1\AppData\Local\Temp\Wcc.exe (Windows (R) Codename Longhorn DDK provider)
O4 - HKU\S-1-5-21-1070666057-106192516-1559153215-1000..\Run: [NtWqIVLZEWZU] C:\Users\MICHAM~1\AppData\Local\Temp\Wcd.exe (Windows (R) Codename Longhorn DDK provider)
O4 - HKU\S-1-5-21-1070666057-106192516-1559153215-1000..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4:[b]64bit:[/b] - HKLM..\RunOnce: [DrWebScanner] C:\Program Files (x86)\DrWeb\drweb32w.exe (Doctor Web, Ltd.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:[b]64bit:[/b] - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Michał mistrz\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O8:[b]64bit:[/b] - Extra context menu item: Funkcja Google Sidewiki - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Michał mistrz\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O8 - Extra context menu item: Funkcja Google Sidewiki - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\DrWeb\drwebsp.dll (Doctor Web, Ltd.)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\DrWeb\drwebsp.dll (Doctor Web, Ltd.)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\DrWeb\drwebsp.dll (Doctor Web, Ltd.)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\DrWeb\drwebsp.dll (Doctor Web, Ltd.)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\DrWeb\drwebsp.dll (Doctor Web, Ltd.)
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files (x86)\DrWeb\drwebsp.dll (Doctor Web, Ltd.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\DrWeb\drwebsp.dll (Doctor Web, Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\DrWeb\drwebsp.dll (Doctor Web, Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\DrWeb\drwebsp.dll (Doctor Web, Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\DrWeb\drwebsp.dll (Doctor Web, Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\DrWeb\drwebsp.dll (Doctor Web, Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files (x86)\DrWeb\drwebsp.dll (Doctor Web, Ltd.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 0.0.0.0
O18:[b]64bit:[/b] - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:[b]64bit:[/b] - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:[b]64bit:[/b] - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:[b]64bit:[/b] - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/12/20 15:18:00 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - Unable to obtain root file information for disk G:\
O33 - MountPoints2\{1f23fbe1-d62d-11df-b0b3-efcb09ba6bf2}\Shell - "" = AutoRun
O33 - MountPoints2\{1f23fbe1-d62d-11df-b0b3-efcb09ba6bf2}\Shell\AutoRun\command - "" = F:\steambackup.exe -- File not found
O33 - MountPoints2\{735e89af-94db-11df-8678-00262d8ea1ab}\Shell - "" = AutoRun
O33 - MountPoints2\{735e89af-94db-11df-8678-00262d8ea1ab}\Shell\AutoRun\command - "" = F:\Autorun.exe -- File not found
O33 - MountPoints2\{fdca3cd8-8c36-11df-87cc-00262d8ea1ab}\Shell - "" = AutoRun
O33 - MountPoints2\{fdca3cd8-8c36-11df-87cc-00262d8ea1ab}\Shell\AutoRun\command - "" = E:\autorun.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*



SafeBootMin:[b]64bit:[/b] AppMgmt - Service
SafeBootMin:[b]64bit:[/b] Base - Driver Group
SafeBootMin:[b]64bit:[/b] Boot Bus Extender - Driver Group
SafeBootMin:[b]64bit:[/b] Boot file system - Driver Group
SafeBootMin:[b]64bit:[/b] File system - Driver Group
SafeBootMin:[b]64bit:[/b] Filter - Driver Group
SafeBootMin:[b]64bit:[/b] HelpSvc - Service
SafeBootMin:[b]64bit:[/b] MCODS - Reg Error: Value error.
SafeBootMin:[b]64bit:[/b] PCI Configuration - Driver Group
SafeBootMin:[b]64bit:[/b] PNP Filter - Driver Group
SafeBootMin:[b]64bit:[/b] Primary disk - Driver Group
SafeBootMin:[b]64bit:[/b] sacsvr - Service
SafeBootMin:[b]64bit:[/b] SCSI Class - Driver Group
SafeBootMin:[b]64bit:[/b] System Bus Extender - Driver Group
SafeBootMin:[b]64bit:[/b] vmms - Service
SafeBootMin:[b]64bit:[/b] WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: MCODS - Reg Error: Value error.
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet:[b]64bit:[/b] AppMgmt - Service
SafeBootNet:[b]64bit:[/b] Base - Driver Group
SafeBootNet:[b]64bit:[/b] Boot Bus Extender - Driver Group
SafeBootNet:[b]64bit:[/b] Boot file system - Driver Group
SafeBootNet:[b]64bit:[/b] File system - Driver Group
SafeBootNet:[b]64bit:[/b] Filter - Driver Group
SafeBootNet:[b]64bit:[/b] HelpSvc - Service
SafeBootNet:[b]64bit:[/b] McMPFSvc - Service
SafeBootNet:[b]64bit:[/b] MCODS - Reg Error: Value error.
SafeBootNet:[b]64bit:[/b] Messenger - Service
SafeBootNet:[b]64bit:[/b] NDIS Wrapper - Driver Group
SafeBootNet:[b]64bit:[/b] NetBIOSGroup - Driver Group
SafeBootNet:[b]64bit:[/b] NetDDEGroup - Driver Group
SafeBootNet:[b]64bit:[/b] Network - Driver Group
SafeBootNet:[b]64bit:[/b] NetworkProvider - Driver Group
SafeBootNet:[b]64bit:[/b] PCI Configuration - Driver Group
SafeBootNet:[b]64bit:[/b] PNP Filter - Driver Group
SafeBootNet:[b]64bit:[/b] PNP_TDI - Driver Group
SafeBootNet:[b]64bit:[/b] Primary disk - Driver Group
SafeBootNet:[b]64bit:[/b] rdsessmgr - Service
SafeBootNet:[b]64bit:[/b] sacsvr - Service
SafeBootNet:[b]64bit:[/b] SCSI Class - Driver Group
SafeBootNet:[b]64bit:[/b] Streams Drivers - Driver Group
SafeBootNet:[b]64bit:[/b] System Bus Extender - Driver Group
SafeBootNet:[b]64bit:[/b] TDI - Driver Group
SafeBootNet:[b]64bit:[/b] vmms - Service
SafeBootNet:[b]64bit:[/b] WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet:[b]64bit:[/b] WudfUsbccidDriver - Driver
SafeBootNet:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:[b]64bit:[/b] {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:[b]64bit:[/b] {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:[b]64bit:[/b] {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:[b]64bit:[/b] {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:[b]64bit:[/b] {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: McMPFSvc - Service
SafeBootNet: MCODS - Reg Error: Value error.
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

[color=#E56717]========== Files/Folders - Created Within 60 Days ==========[/color]

[2010/12/20 15:17:49 | 000,000,000 | ---D | C] -- C:\sh4ldr
[2010/12/20 15:17:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Enigma Software Group
[2010/12/20 15:17:13 | 000,000,000 | ---D | C] -- C:\Windows\3636C9237AD64DE3978A09609AEE8ECF.TMP
[2010/12/20 14:36:16 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\DoctorWeb
[2010/12/20 14:36:15 | 000,150,520 | ---- | C] (Doctor Web, Ltd.) -- C:\Windows\SysNative\drivers\dwprot.sys
[2010/12/20 14:36:10 | 000,103,416 | ---- | C] (Doctor Web, Ltd.) -- C:\Windows\SysNative\drivers\spiderg3.sys
[2010/12/20 14:35:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DrWeb
[2010/12/20 14:35:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Doctor Web
[2010/12/20 14:35:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Doctor Web
[2010/12/20 11:00:48 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\AppData\Local\Two Worlds II
[2010/12/20 10:51:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reality Pump
[2010/12/20 00:06:43 | 000,000,000 | ---D | C] -- C:\ProgramData\KONAMI
[2010/12/19 23:54:50 | 000,211,968 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\Wvucia.exe
[2010/12/16 14:54:51 | 000,000,000 | -HSD | C] -- C:\ProgramData\SecuROM
[2010/12/16 10:38:34 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\AppData\Roaming\ATI
[2010/12/16 10:38:34 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\AppData\Local\ATI
[2010/12/16 10:38:34 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2010/12/16 10:37:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
[2010/12/16 10:37:10 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2010/12/16 10:37:09 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
[2010/12/12 20:19:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2010/12/12 20:19:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2010/12/12 12:37:35 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\AppData\Roaming\SA-MP Audio Plugin
[2010/12/06 22:14:30 | 000,000,000 | ---D | C] -- C:\ProgramData\ALLConverter
[2010/12/06 22:14:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ALLConverter PRO
[2010/12/06 22:14:22 | 000,000,000 | ---D | C] -- C:\ProgramData\ALLPlayer
[2010/12/06 22:14:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NAPI-PROJEKT
[2010/12/06 22:14:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ALLPlayer
[2010/12/06 18:27:25 | 001,123,840 | ---- | C] (Karol Winnicki) -- C:\Users\Michał mistrz\Desktop\BESTplayer.exe
[2010/12/06 18:25:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xvid
[2010/12/06 18:23:14 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\AppData\Roaming\Apple Computer
[2010/12/03 22:57:29 | 000,000,000 | ---D | C] -- C:\ProgramData\FreeRIP
[2010/12/03 22:57:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FreeRIP3
[2010/12/01 18:22:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Counter-Strike Source
[2010/12/01 18:15:09 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2010/12/01 16:50:09 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\AppData\Local\THQ
[2010/12/01 16:16:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Saints Row 2
[2010/11/20 16:05:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VirtualDJ
[2010/11/20 14:45:04 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\Desktop\Kawałek
[2010/11/18 17:36:22 | 000,000,000 | ---D | C] -- C:\ProgramData\IObit
[2010/11/18 17:36:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IObit
[2010/11/14 19:23:55 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\AppData\Local\Activision
[2010/11/14 18:46:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Activision
[2010/11/14 00:47:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DAEMON Tools Pro
[2010/11/08 23:28:28 | 000,000,000 | ---D | C] -- C:\Windows\pl
[2010/11/08 23:26:51 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
[2010/11/08 23:26:45 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2010/11/08 23:26:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bing Bar Installer
[2010/11/08 22:27:26 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\AppData\Local\Apple Computer
[2010/11/08 22:25:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2010/11/08 22:25:07 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\AppData\Local\Apple
[2010/11/08 22:25:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2010/11/08 22:25:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2010/11/05 22:53:08 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\AppData\Local\119614890736297204
[2010/11/05 22:53:02 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\AppData\Local\119611678100759796
[2010/11/04 21:34:06 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\Documents\Square Enix
[2010/11/04 21:33:53 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\AppData\Local\119614890734593268
[2010/11/04 21:33:47 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\AppData\Local\119611678099055860
[2010/11/02 17:47:21 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\AppData\Roaming\Ahead
[2010/11/02 17:45:45 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\AppData\Roaming\Real
[2010/11/02 17:43:45 | 001,568,768 | ---- | C] (Pegasus Imaging Corp.) -- C:\Windows\SysWow64\imagX7.dll
[2010/11/02 17:43:45 | 000,476,320 | ---- | C] (Pegasus Imaging Corp.) -- C:\Windows\SysWow64\imagXpr7.dll
[2010/11/02 17:43:45 | 000,471,040 | ---- | C] (Pegasus Imaging Corp.) -- C:\Windows\SysWow64\imagXRA7.dll
[2010/11/02 17:43:45 | 000,364,544 | ---- | C] (Pegasus Imaging Corp.) -- C:\Windows\SysWow64\TwnLib4.dll
[2010/11/02 17:43:45 | 000,262,144 | ---- | C] (Pegasus Imaging Corp.) -- C:\Windows\SysWow64\imagXR7.dll
[2010/11/02 17:43:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Nero
[2010/11/02 17:43:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nero
[2010/11/02 17:43:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Ahead
[2010/11/01 16:41:51 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\AppData\Roaming\Steinberg
[2010/10/31 22:45:18 | 000,000,000 | ---D | C] -- C:\ATI
[2010/10/31 10:48:48 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\Documents\VirtualDJ
[2010/10/30 19:00:09 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\AppData\Local\AskToolbar
[2010/10/25 14:59:33 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\AppData\Local\Windows Live
[2010/10/23 14:48:26 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\Documents\FIFA 11
[2010/10/23 14:47:06 | 000,000,000 | ---D | C] -- C:\Users\Michał mistrz\AppData\Roaming\Leadertech
[2010/10/23 14:34:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\EA Sports
[2009/11/05 04:33:04 | 000,036,136 | ---- | C] (Oberon Media) -- C:\ProgramData\FullRemove.exe
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 60 Days ==========[/color]

[2010/12/20 23:48:29 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempAQ3388.html
[2010/12/20 23:47:52 | 000,000,308 | -H-- | M] () -- C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/12/20 23:40:00 | 000,001,048 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/20 23:36:00 | 000,000,370 | ---- | M] () -- C:\Windows\tasks\Dr.Web Update.job
[2010/12/20 23:34:05 | 000,000,308 | -H-- | M] () -- C:\Windows\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2010/12/20 17:40:00 | 000,001,044 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/20 16:08:51 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempIS4916.html
[2010/12/20 15:18:00 | 000,000,000 | ---- | M] () -- C:\autoexec.bat
[2010/12/20 15:17:50 | 000,002,336 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\SpyHunter.lnk
[2010/12/20 14:50:12 | 000,000,808 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2010/12/20 14:36:14 | 000,000,312 | ---- | M] () -- C:\Windows\tasks\Dr.Web Daily scan.job
[2010/12/20 14:36:06 | 000,000,992 | ---- | M] () -- C:\Users\Public\Desktop\Skaner Dr.Web.lnk
[2010/12/20 11:51:44 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/12/20 11:51:44 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/12/20 11:44:34 | 000,000,262 | -H-- | M] () -- C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/12/20 11:44:04 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/12/20 11:44:00 | 3111,518,208 | -HS- | M] () -- C:\hiberfil.sys
[2010/12/20 11:43:12 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempirY888.html
[2010/12/20 10:54:34 | 000,001,247 | ---- | M] () -- C:\Users\Public\Desktop\Two Worlds II.lnk
[2010/12/20 00:23:22 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempGf3180.html
[2010/12/19 23:54:34 | 000,211,968 | ---- | M] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\Wvucia.exe
[2010/12/19 15:36:55 | 001,549,696 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010/12/19 15:36:55 | 000,697,912 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat
[2010/12/19 15:36:55 | 000,616,008 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010/12/19 15:36:55 | 000,134,990 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat
[2010/12/19 15:36:55 | 000,106,388 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010/12/19 13:18:01 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Temprp4664.html
[2010/12/18 22:48:43 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TemptT4296.html
[2010/12/18 18:52:08 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempwl4808.html
[2010/12/18 17:59:16 | 001,055,633 | ---- | M] () -- C:\Users\Michał mistrz\Documents\Bez_nazwy.wma
[2010/12/18 15:07:51 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempYr2552.html
[2010/12/17 23:46:30 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempgZ3828.html
[2010/12/16 23:40:34 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempeq4800.html
[2010/12/16 19:48:16 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempDh3220.html
[2010/12/16 19:48:16 | 000,002,089 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempYY3220.html
[2010/12/16 19:33:15 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2010/12/16 19:30:47 | 000,005,632 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/16 17:44:16 | 000,318,162 | ---- | M] () -- C:\Users\Michał mistrz\Documents\DSC00546.JPG
[2010/12/16 17:30:09 | 004,477,748 | ---- | M] () -- C:\Users\Michał mistrz\Documents\DSC00531.JPG
[2010/12/16 10:30:01 | 002,268,360 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2010/12/15 23:59:35 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempLg3520.html
[2010/12/15 18:34:22 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempic4824.html
[2010/12/15 13:46:40 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempXu3544.html
[2010/12/14 22:04:33 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Temppq4948.html
[2010/12/14 20:49:03 | 000,313,469 | ---- | M] () -- C:\Users\Michał mistrz\Documents\Gra.mp3
[2010/12/14 20:44:00 | 004,510,892 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\basiwowowoneew2.mp3
[2010/12/13 20:38:12 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempoB3356.html
[2010/12/13 20:38:12 | 000,002,089 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempVF3356.html
[2010/12/13 20:38:01 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempdK1336.html
[2010/12/13 16:42:16 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempJv5016.html
[2010/12/13 14:04:28 | 000,150,520 | ---- | M] (Doctor Web, Ltd.) -- C:\Windows\SysNative\drivers\dwprot.sys
[2010/12/13 00:03:57 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempzT4616.html
[2010/12/12 23:25:31 | 000,006,541 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\logo.png
[2010/12/12 21:04:32 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempud4732.html
[2010/12/12 20:19:10 | 000,001,881 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/12/12 15:26:51 | 000,163,390 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\logo.psd
[2010/12/11 23:13:21 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempUX3760.html
[2010/12/11 20:47:24 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Temprt2512.html
[2010/12/11 20:10:59 | 000,782,000 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\wokallolbaku.mp3
[2010/12/11 13:58:55 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempcQ4840.html
[2010/12/11 13:58:55 | 000,002,089 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TemppT4840.html
[2010/12/11 12:40:48 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempJQ4908.html
[2010/12/10 15:16:40 | 000,646,297 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\hehehehe.mp3
[2010/12/10 14:02:38 | 000,563,826 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\wokalheh.mp3
[2010/12/10 13:51:44 | 004,510,892 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\basiwowowoneew3.mp3
[2010/12/10 09:54:36 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempan1796.html
[2010/12/09 22:46:25 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Temppk3880.html
[2010/12/09 22:16:32 | 001,539,203 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\jajeczkochujconew3.mp3
[2010/12/09 17:49:25 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempLt5052.html
[2010/12/08 22:23:41 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempqG4396.html
[2010/12/07 22:56:50 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Temprv4764.html
[2010/12/07 18:09:08 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempGj1584.html
[2010/12/06 22:14:30 | 000,001,134 | ---- | M] () -- C:\Users\Public\Desktop\ALLConverter PRO.lnk
[2010/12/06 22:14:27 | 000,001,085 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\Napi-projekt.lnk
[2010/12/06 22:14:25 | 000,001,055 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\ALLPlayer V4.5.lnk
[2010/12/06 18:27:34 | 001,123,840 | ---- | M] (Karol Winnicki) -- C:\Users\Michał mistrz\Desktop\BESTplayer.exe
[2010/12/06 14:56:32 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempDj4756.html
[2010/12/06 14:56:32 | 000,002,089 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempfE4756.html
[2010/12/05 22:56:00 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempJC2616.html
[2010/12/05 14:27:49 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempCj4468.html
[2010/12/04 23:05:28 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempKa4812.html
[2010/12/04 20:24:15 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempZC2076.html
[2010/12/04 15:13:43 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempaK2664.html
[2010/12/04 13:04:13 | 000,000,733 | ---- | M] () -- C:\Windows\cdplayer.ini
[2010/12/04 12:37:09 | 000,001,302 | ---- | M] () -- C:\ProgramData\ss.ini
[2010/12/04 01:21:53 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempLR4652.html
[2010/12/03 22:57:29 | 000,001,043 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\FreeRIP.lnk
[2010/12/03 21:09:31 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempqn3392.html
[2010/12/03 17:44:51 | 002,726,349 | ---- | M] () -- C:\Users\Michał mistrz\Documents\SL278754.JPG
[2010/12/02 22:25:50 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempZK4708.html
[2010/12/02 16:51:15 | 000,170,163 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\Dzwonek2.mp3
[2010/12/01 23:21:03 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempmG3812.html
[2010/12/01 18:24:54 | 000,002,191 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\Counter-Strike Source.lnk
[2010/11/30 22:23:19 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempSX4532.html
[2010/11/30 22:15:12 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempaU5024.html
[2010/11/29 22:14:53 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempdD4148.html
[2010/11/29 18:42:15 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempAV5016.html
[2010/11/28 23:03:33 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempgv5076.html
[2010/11/28 20:49:21 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempgC4324.html
[2010/11/28 17:25:40 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempgG4352.html
[2010/11/28 14:22:11 | 000,003,449 | ---- | M] () -- C:\Users\Michał mistrz\Documents\Frik(1).rtf
[2010/11/28 10:43:01 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempAI4596.html
[2010/11/28 10:43:01 | 000,002,089 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TemphO4596.html
[2010/11/28 00:28:25 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempYU5632.html
[2010/11/27 20:09:53 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempCf4616.html
[2010/11/27 16:12:02 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempcs4208.html
[2010/11/26 23:52:57 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Temprjp800.html
[2010/11/25 23:20:04 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempoIr756.html
[2010/11/25 19:03:28 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempXm4224.html
[2010/11/25 10:05:57 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TemprAA812.html
[2010/11/25 01:58:26 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempak4304.html
[2010/11/24 19:34:58 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempov4988.html
[2010/11/23 22:30:36 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempyW3212.html
[2010/11/23 18:18:05 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempHD4168.html
[2010/11/23 10:54:08 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempJb4216.html
[2010/11/23 10:46:54 | 000,083,120 | ---- | M] (Avira GmbH) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2010/11/22 23:20:53 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempCd4320.html
[2010/11/22 19:40:37 | 000,002,472 | ---- | M] () -- C:\Users\Michał mistrz\Documents\Frik.rtf
[2010/11/22 15:17:11 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempGG4288.html
[2010/11/21 23:16:08 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempJd4320.html
[2010/11/21 19:46:49 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempoI3508.html
[2010/11/21 19:46:49 | 000,002,089 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Temptj3508.html
[2010/11/21 05:49:04 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempEj3924.html
[2010/11/20 16:50:22 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TemprG2664.html
[2010/11/20 16:50:22 | 000,002,089 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempza2664.html
[2010/11/20 16:05:54 | 000,001,075 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\Virtual DJ Pro.lnk
[2010/11/20 08:26:50 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempTV2420.html
[2010/11/19 19:59:34 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempxk4492.html
[2010/11/18 22:25:07 | 002,242,034 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\Wykurwoza.mp3
[2010/11/18 17:36:24 | 000,001,120 | ---- | M] () -- C:\Users\Public\Desktop\Switch to Gaming Mode.lnk
[2010/11/18 17:36:24 | 000,001,108 | ---- | M] () -- C:\Users\Public\Desktop\Game Booster.lnk
[2010/11/17 19:03:41 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempzr3276.html
[2010/11/17 16:33:35 | 000,002,050 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/11/16 22:23:03 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TemptK4116.html
[2010/11/15 22:39:46 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TemplB1520.html
[2010/11/15 21:45:57 | 000,044,192 | ---- | M] () -- C:\Users\Michał mistrz\Documents\sssssss.jpg
[2010/11/15 20:55:30 | 000,017,409 | ---- | M] () -- C:\Users\Michał mistrz\Documents\sss.jpg
[2010/11/14 22:34:30 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempAG4804.html
[2010/11/14 18:56:08 | 000,002,246 | ---- | M] () -- C:\Users\Public\Desktop\Call of Duty - Black Ops Call MP.lnk
[2010/11/14 18:45:26 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempZu4332.html
[2010/11/14 13:42:11 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempmL3912.html
[2010/11/14 01:49:05 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempeY3096.html
[2010/11/14 00:47:28 | 000,001,968 | ---- | M] () -- C:\Users\Public\Desktop\DAEMON Tools Pro.lnk
[2010/11/13 23:05:22 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TemprD5004.html
[2010/11/13 12:53:17 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempJi5052.html
[2010/11/13 12:53:17 | 000,002,089 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TemprF5052.html
[2010/11/13 12:38:53 | 000,001,216 | ---- | M] () -- C:\Users\Public\Desktop\Alcohol 120%.lnk
[2010/11/13 12:37:11 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempuf4344.html
[2010/11/13 12:37:11 | 000,002,089 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempDZ4344.html
[2010/11/13 12:03:05 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempKG3940.html
[2010/11/12 23:17:59 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempzo4128.html
[2010/11/12 14:36:11 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempEQ2492.html
[2010/11/12 13:33:12 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempGg3956.html
[2010/11/12 12:21:02 | 005,271,578 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\jajco3.mp3
[2010/11/12 12:08:30 | 000,081,411 | ---- | M] () -- C:\Users\Michał mistrz\Documents\PURPY HAHAHAHA.jpg
[2010/11/12 00:28:55 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempdz2204.html
[2010/11/12 00:28:55 | 000,002,089 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempFn2204.html
[2010/11/11 16:11:14 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempqN4980.html
[2010/11/11 15:21:04 | 001,004,215 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\jajco2.mp3
[2010/11/11 14:44:02 | 000,001,346 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\kl2 — skrót.lnk
[2010/11/11 00:01:39 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempad1284.html
[2010/11/10 18:47:41 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempTZB912.html
[2010/11/09 23:11:23 | 007,831,578 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\jajco.mp3
[2010/11/09 23:11:15 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempwW4936.html
[2010/11/08 22:50:03 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempGL3880.html
[2010/11/08 22:19:53 | 000,001,300 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\Media Player Classic.lnk
[2010/11/08 19:57:27 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempOQ2016.html
[2010/11/07 22:48:05 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Temptz4032.html
[2010/11/07 16:29:56 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempSc4276.html
[2010/11/06 23:34:13 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Templt4248.html
[2010/11/06 21:21:48 | 000,007,602 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Resmon.ResmonCfg
[2010/11/06 10:27:52 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempoR3120.html
[2010/11/06 10:27:52 | 000,002,089 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempEc3120.html
[2010/11/05 23:36:45 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Temphq3704.html
[2010/11/04 23:47:31 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempGb1832.html
[2010/11/04 16:32:44 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempUO1148.html
[2010/11/04 16:06:29 | 000,466,456 | ---- | M] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll
[2010/11/04 16:06:29 | 000,444,952 | ---- | M] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll
[2010/11/03 22:35:04 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempWZ4428.html
[2010/11/03 10:19:01 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempHe4768.html
[2010/11/03 00:12:15 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempLU3588.html
[2010/11/02 19:05:42 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempns5012.html
[2010/11/02 17:43:53 | 000,001,986 | ---- | M] () -- C:\Users\Public\Desktop\Nero Express.lnk
[2010/11/01 18:37:37 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempjO4388.html
[2010/11/01 14:10:44 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempTCt256.html
[2010/11/01 11:47:09 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempdp3872.html
[2010/11/01 11:47:09 | 000,002,089 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempcH3872.html
[2010/10/31 22:47:24 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempoW4276.html
[2010/10/31 22:47:24 | 000,002,089 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempDR4276.html
[2010/10/31 20:59:48 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempdE3804.html
[2010/10/31 20:59:48 | 000,002,089 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempoM3804.html
[2010/10/31 19:22:05 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Temptp3720.html
[2010/10/31 15:09:03 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempTx4608.html
[2010/10/31 11:36:06 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempUU4388.html
[2010/10/31 11:07:01 | 007,812,772 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\bigl2.mp3
[2010/10/30 19:23:18 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempOG4604.html
[2010/10/30 19:23:18 | 000,002,089 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempOk4604.html
[2010/10/30 18:02:24 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempNg4984.html
[2010/10/29 22:57:33 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempuA4896.html
[2010/10/29 15:48:03 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempka4200.html
[2010/10/29 15:48:03 | 000,002,089 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempvn4200.html
[2010/10/28 22:14:19 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempvm1652.html
[2010/10/28 20:43:20 | 000,002,009 | ---- | M] () -- C:\Users\Michał mistrz\Desktop\Crysis 64bit.lnk
[2010/10/28 15:00:17 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempbCv480.html
[2010/10/27 22:32:34 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempDt1872.html
[2010/10/27 22:01:02 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempNQ4356.html
[2010/10/27 19:35:56 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempJE4624.html
[2010/10/27 15:37:24 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempLt4692.html
[2010/10/26 21:45:39 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempJkS800.html
[2010/10/26 20:39:51 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Tempze4140.html
[2010/10/26 19:06:06 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempDZ4264.html
[2010/10/26 14:14:17 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempDa4604.html
[2010/10/25 21:37:38 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\Temphb2416.html
[2010/10/25 19:31:12 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempRC4176.html
[2010/10/25 19:31:12 | 000,002,089 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempFR4176.html
[2010/10/25 15:39:40 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempQZ4472.html
[2010/10/24 21:46:28 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempLy4820.html
[2010/10/24 14:39:51 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempVw4812.html
[2010/10/24 10:04:35 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempPo1264.html
[2010/10/24 10:04:35 | 000,002,089 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempXq1264.html
[2010/10/24 08:14:53 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempPq4712.html
[2010/10/23 19:09:39 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempAKz352.html
[2010/10/23 15:55:20 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TemptG4128.html
[2010/10/22 22:52:08 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempAI1688.html
[2010/10/22 16:30:09 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempwJ5032.html
[2010/10/22 09:01:19 | 000,002,432 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Local\TempDN2300.html
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2010/12/20 22:14:15 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempAQ3388.html
[2010/12/20 15:18:00 | 000,000,000 | ---- | C] () -- C:\autoexec.bat
[2010/12/20 15:17:50 | 000,002,336 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\SpyHunter.lnk
[2010/12/20 14:36:14 | 000,000,312 | ---- | C] () -- C:\Windows\tasks\Dr.Web Daily scan.job
[2010/12/20 14:36:11 | 000,000,370 | ---- | C] () -- C:\Windows\tasks\Dr.Web Update.job
[2010/12/20 14:36:06 | 000,000,992 | ---- | C] () -- C:\Users\Public\Desktop\Skaner Dr.Web.lnk
[2010/12/20 11:46:09 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempIS4916.html
[2010/12/20 11:42:57 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempirY888.html
[2010/12/20 10:54:34 | 000,001,247 | ---- | C] () -- C:\Users\Public\Desktop\Two Worlds II.lnk
[2010/12/19 23:55:26 | 000,000,308 | -H-- | C] () -- C:\Windows\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
[2010/12/19 23:54:56 | 000,000,308 | -H-- | C] () -- C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/12/19 23:54:39 | 000,000,262 | -H-- | C] () -- C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/12/19 22:16:36 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempGf3180.html
[2010/12/19 11:05:58 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temprp4664.html
[2010/12/18 21:18:45 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemptT4296.html
[2010/12/18 17:59:16 | 001,055,633 | ---- | C] () -- C:\Users\Michał mistrz\Documents\Bez_nazwy.wma
[2010/12/18 17:27:33 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempwl4808.html
[2010/12/18 10:29:22 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempYr2552.html
[2010/12/17 11:45:16 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempgZ3828.html
[2010/12/16 22:15:59 | 000,013,835 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\MyWinLockerInstaller.txt-20101216.log
[2010/12/16 19:53:26 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempeq4800.html
[2010/12/16 17:43:44 | 000,318,162 | ---- | C] () -- C:\Users\Michał mistrz\Documents\DSC00546.JPG
[2010/12/16 17:25:47 | 004,477,748 | ---- | C] () -- C:\Users\Michał mistrz\Documents\DSC00531.JPG
[2010/12/16 10:57:17 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempDh3220.html
[2010/12/16 10:57:17 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempYY3220.html
[2010/12/15 19:33:35 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempLg3520.html
[2010/12/15 13:49:15 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempic4824.html
[2010/12/15 12:59:36 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempXu3544.html
[2010/12/14 20:43:39 | 004,510,892 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\basiwowowoneew2.mp3
[2010/12/14 11:05:54 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temppq4948.html
[2010/12/13 20:38:12 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempoB3356.html
[2010/12/13 20:38:12 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempVF3356.html
[2010/12/13 20:37:04 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempdK1336.html
[2010/12/13 14:20:40 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempJv5016.html
[2010/12/12 23:25:30 | 000,006,541 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\logo.png
[2010/12/12 22:09:12 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempzT4616.html
[2010/12/12 20:19:10 | 000,001,881 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/12/12 15:26:49 | 000,163,390 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\logo.psd
[2010/12/12 10:47:56 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempud4732.html
[2010/12/11 21:59:35 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempUX3760.html
[2010/12/11 20:08:12 | 000,782,000 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\wokallolbaku.mp3
[2010/12/11 18:21:13 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temprt2512.html
[2010/12/11 13:58:55 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempcQ4840.html
[2010/12/11 13:58:55 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemppT4840.html
[2010/12/10 15:16:37 | 000,646,297 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\hehehehe.mp3
[2010/12/10 14:02:35 | 000,563,826 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\wokalheh.mp3
[2010/12/10 13:51:25 | 004,510,892 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\basiwowowoneew3.mp3
[2010/12/10 12:31:20 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempJQ4908.html
[2010/12/10 09:15:10 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempan1796.html
[2010/12/09 22:16:25 | 001,539,203 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\jajeczkochujconew3.mp3
[2010/12/09 20:18:05 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temppk3880.html
[2010/12/09 14:25:10 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempLt5052.html
[2010/12/08 19:02:24 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempqG4396.html
[2010/12/07 20:23:54 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temprv4764.html
[2010/12/07 17:07:01 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempGj1584.html
[2010/12/06 22:14:30 | 000,001,134 | ---- | C] () -- C:\Users\Public\Desktop\ALLConverter PRO.lnk
[2010/12/06 22:14:27 | 000,001,085 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\Napi-projekt.lnk
[2010/12/06 22:14:25 | 000,001,055 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\ALLPlayer V4.5.lnk
[2010/12/06 22:14:22 | 000,797,184 | ---- | C] () -- C:\Windows\SysWow64\ac3filter.ax
[2010/12/06 22:14:22 | 000,258,048 | ---- | C] () -- C:\Windows\SysWow64\libFLAC.dll
[2010/12/06 18:25:45 | 000,790,528 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2010/12/06 18:25:45 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2010/12/06 18:25:45 | 000,077,824 | ---- | C] () -- C:\Windows\SysWow64\xvid.ax
[2010/12/06 14:56:32 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempDj4756.html
[2010/12/06 14:56:32 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempfE4756.html
[2010/12/05 16:25:40 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempJC2616.html
[2010/12/05 12:09:11 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempCj4468.html
[2010/12/04 21:39:53 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempKa4812.html
[2010/12/04 17:32:50 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempZC2076.html
[2010/12/04 10:35:33 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempaK2664.html
[2010/12/03 23:48:25 | 000,000,733 | ---- | C] () -- C:\Windows\cdplayer.ini
[2010/12/03 22:57:32 | 000,001,302 | ---- | C] () -- C:\ProgramData\ss.ini
[2010/12/03 22:57:29 | 000,001,043 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\FreeRIP.lnk
[2010/12/03 22:55:25 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempLR4652.html
[2010/12/03 17:43:12 | 002,726,349 | ---- | C] () -- C:\Users\Michał mistrz\Documents\SL278754.JPG
[2010/12/03 16:53:53 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempqn3392.html
[2010/12/02 16:49:03 | 000,170,163 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\Dzwonek2.mp3
[2010/12/02 16:12:48 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempZK4708.html
[2010/12/01 18:24:54 | 000,002,191 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\Counter-Strike Source.lnk
[2010/12/01 16:09:45 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempmG3812.html
[2010/11/30 22:15:20 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempSX4532.html
[2010/11/30 17:10:29 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempaU5024.html
[2010/11/29 21:16:05 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempdD4148.html
[2010/11/29 16:18:18 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempAV5016.html
[2010/11/28 22:15:31 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempgv5076.html
[2010/11/28 20:12:14 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempgC4324.html
[2010/11/28 15:07:41 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempgG4352.html
[2010/11/28 14:22:10 | 000,003,449 | ---- | C] () -- C:\Users\Michał mistrz\Documents\Frik(1).rtf
[2010/11/28 10:43:01 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempAI4596.html
[2010/11/28 10:43:01 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemphO4596.html
[2010/11/27 20:41:46 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempYU5632.html
[2010/11/27 18:24:50 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempCf4616.html
[2010/11/27 09:57:57 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempcs4208.html
[2010/11/26 10:26:05 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temprjp800.html
[2010/11/25 21:56:53 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempoIr756.html
[2010/11/25 15:20:51 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempXm4224.html
[2010/11/25 09:43:09 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemprAA812.html
[2010/11/24 22:02:54 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempak4304.html
[2010/11/24 16:36:24 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempov4988.html
[2010/11/23 21:04:34 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempyW3212.html
[2010/11/23 17:01:49 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempHD4168.html
[2010/11/23 10:42:55 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempJb4216.html
[2010/11/22 19:40:36 | 000,002,472 | ---- | C] () -- C:\Users\Michał mistrz\Documents\Frik.rtf
[2010/11/22 16:55:37 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempCd4320.html
[2010/11/22 14:24:44 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempGG4288.html
[2010/11/21 22:02:40 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempJd4320.html
[2010/11/21 10:49:02 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempoI3508.html
[2010/11/21 10:49:02 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temptj3508.html
[2010/11/20 20:12:58 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempEj3924.html
[2010/11/20 16:05:54 | 000,001,075 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\Virtual DJ Pro.lnk
[2010/11/20 09:46:10 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemprG2664.html
[2010/11/20 09:46:10 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempza2664.html
[2010/11/19 22:56:51 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempTV2420.html
[2010/11/19 14:15:17 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempxk4492.html
[2010/11/18 22:20:12 | 002,242,034 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\Wykurwoza.mp3
[2010/11/18 17:36:24 | 000,001,120 | ---- | C] () -- C:\Users\Public\Desktop\Switch to Gaming Mode.lnk
[2010/11/18 17:36:24 | 000,001,108 | ---- | C] () -- C:\Users\Public\Desktop\Game Booster.lnk
[2010/11/17 16:33:05 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempzr3276.html
[2010/11/16 16:52:14 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemptK4116.html
[2010/11/15 21:45:57 | 000,044,192 | ---- | C] () -- C:\Users\Michał mistrz\Documents\sssssss.jpg
[2010/11/15 20:55:30 | 000,017,409 | ---- | C] () -- C:\Users\Michał mistrz\Documents\sss.jpg
[2010/11/15 15:53:21 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemplB1520.html
[2010/11/14 22:32:45 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempAG4804.html
[2010/11/14 18:56:08 | 000,002,246 | ---- | C] () -- C:\Users\Public\Desktop\Call of Duty - Black Ops Call MP.lnk
[2010/11/14 15:04:36 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempZu4332.html
[2010/11/14 11:43:19 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempmL3912.html
[2010/11/14 00:47:28 | 000,001,968 | ---- | C] () -- C:\Users\Public\Desktop\DAEMON Tools Pro.lnk
[2010/11/14 00:38:23 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempeY3096.html
[2010/11/13 20:38:03 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemprD5004.html
[2010/11/13 12:53:17 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempJi5052.html
[2010/11/13 12:53:17 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemprF5052.html
[2010/11/13 12:38:53 | 000,001,216 | ---- | C] () -- C:\Users\Public\Desktop\Alcohol 120%.lnk
[2010/11/13 12:08:02 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempuf4344.html
[2010/11/13 12:08:02 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempDZ4344.html
[2010/11/13 10:07:27 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempKG3940.html
[2010/11/12 20:55:27 | 000,313,469 | ---- | C] () -- C:\Users\Michał mistrz\Documents\Gra.mp3
[2010/11/12 20:24:16 | 003,831,949 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\Jamglue_-_Big_L_-_Put_It_On_(Acapella).mp3
[2010/11/12 19:45:54 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempzo4128.html
[2010/11/12 14:33:03 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempEQ2492.html
[2010/11/12 12:20:41 | 005,271,578 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\jajco3.mp3
[2010/11/12 12:08:28 | 000,081,411 | ---- | C] () -- C:\Users\Michał mistrz\Documents\PURPY HAHAHAHA.jpg
[2010/11/12 10:00:48 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempGg3956.html
[2010/11/11 23:00:08 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempdz2204.html
[2010/11/11 23:00:08 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempFn2204.html
[2010/11/11 15:20:59 | 001,004,215 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\jajco2.mp3
[2010/11/11 14:44:02 | 000,001,346 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\kl2 — skrót.lnk
[2010/11/11 09:59:36 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempqN4980.html
[2010/11/10 23:30:34 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempad1284.html
[2010/11/10 17:22:16 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempTZB912.html
[2010/11/09 23:10:44 | 007,831,578 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\jajco.mp3
[2010/11/09 17:49:52 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempwW4936.html
[2010/11/08 22:19:53 | 000,001,300 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\Media Player Classic.lnk
[2010/11/08 22:14:23 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2010/11/08 21:19:03 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempGL3880.html
[2010/11/08 15:14:08 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempOQ2016.html
[2010/11/07 19:31:10 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temptz4032.html
[2010/11/07 10:36:03 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempSc4276.html
[2010/11/06 21:21:48 | 000,007,602 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Resmon.ResmonCfg
[2010/11/06 20:17:51 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Templt4248.html
[2010/11/06 12:20:20 | 000,510,976 | ---- | C] () -- C:\Windows\SysWow64\synsoacc.dll
[2010/11/06 10:27:52 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempoR3120.html
[2010/11/06 10:27:52 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempEc3120.html
[2010/11/05 16:33:52 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temphq3704.html
[2010/11/04 21:48:43 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempGb1832.html
[2010/11/04 15:36:47 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempUO1148.html
[2010/11/03 16:43:38 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempWZ4428.html
[2010/11/03 10:07:42 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempHe4768.html
[2010/11/02 20:37:22 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempLU3588.html
[2010/11/02 17:43:53 | 000,001,986 | ---- | C] () -- C:\Users\Public\Desktop\Nero Express.lnk
[2010/11/02 17:03:55 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempns5012.html
[2010/11/01 16:26:20 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempjO4388.html
[2010/11/01 16:04:41 | 000,000,091 | ---- | C] () -- C:\ProgramData\PS.log
[2010/11/01 11:56:34 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempTCt256.html
[2010/11/01 10:37:53 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempdp3872.html
[2010/11/01 10:37:53 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempcH3872.html
[2010/10/31 21:22:19 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempoW4276.html
[2010/10/31 21:22:19 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempDR4276.html
[2010/10/31 20:59:48 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempdE3804.html
[2010/10/31 20:59:48 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempoM3804.html
[2010/10/31 18:11:13 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temptp3720.html
[2010/10/31 11:36:17 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempTx4608.html
[2010/10/31 11:06:24 | 007,812,772 | ---- | C] () -- C:\Users\Michał mistrz\Desktop\bigl2.mp3
[2010/10/31 09:18:27 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempUU4388.html
[2010/10/30 19:23:18 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempOG4604.html
[2010/10/30 19:23:18 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempOk4604.html
[2010/10/30 10:11:36 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempNg4984.html
[2010/10/29 19:33:32 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempuA4896.html
[2010/10/29 15:48:03 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempka4200.html
[2010/10/29 15:48:03 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempvn4200.html
[2010/10/28 19:58:09 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempvm1652.html
[2010/10/28 13:44:20 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempbCv480.html
[2010/10/27 22:02:37 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempDt1872.html
[2010/10/27 21:22:55 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempNQ4356.html
[2010/10/27 16:39:52 | 000,005,632 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/27 15:52:57 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempJE4624.html
[2010/10/27 15:31:54 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempLt4692.html
[2010/10/26 21:45:05 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempJkS800.html
[2010/10/26 20:24:04 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempze4140.html
[2010/10/26 17:49:30 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempDZ4264.html
[2010/10/26 12:51:26 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempDa4604.html
[2010/10/25 19:44:48 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temphb2416.html
[2010/10/25 19:31:12 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempRC4176.html
[2010/10/25 19:31:12 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempFR4176.html
[2010/10/25 15:00:49 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempQZ4472.html
[2010/10/24 19:48:24 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempLy4820.html
[2010/10/24 11:38:06 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempVw4812.html
[2010/10/24 10:04:35 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempPo1264.html
[2010/10/24 10:04:35 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempXq1264.html
[2010/10/23 23:42:43 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempPq4712.html
[2010/10/23 18:04:12 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempAKz352.html
[2010/10/23 09:54:24 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemptG4128.html
[2010/10/22 21:26:25 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempAI1688.html
[2010/10/22 13:08:32 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempwJ5032.html
[2010/10/22 08:52:27 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempDN2300.html
[2010/10/21 16:22:02 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempSW5108.html
[2010/10/21 16:22:02 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempgl5108.html
[2010/10/21 16:05:51 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempoY3652.html
[2010/10/20 15:51:10 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempDM3460.html
[2010/10/19 15:16:55 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempXq4584.html
[2010/10/19 15:16:55 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temptl4584.html
[2010/10/18 13:18:44 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemphF3924.html
[2010/10/17 10:31:48 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempRy3228.html
[2010/10/16 16:36:21 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempwv1040.html
[2010/10/16 14:29:11 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempiq1080.html
[2010/10/16 14:29:11 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempcr1080.html
[2010/10/16 11:25:56 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempaW2920.html
[2010/10/15 18:02:39 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempAO4176.html
[2010/10/15 15:22:30 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempCP2320.html
[2010/10/15 15:22:30 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempdy2320.html
[2010/10/14 19:00:05 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempEv4436.html
[2010/10/14 11:30:26 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempUe3236.html
[2010/10/14 11:08:43 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temphp3792.html
[2010/10/14 11:08:43 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempiw3792.html
[2010/10/14 08:49:19 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempdN1504.html
[2010/10/14 01:36:44 | 000,179,263 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2010/10/13 22:05:18 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempFW1816.html
[2010/10/13 19:06:51 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempwb3528.html
[2010/10/13 15:21:53 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempfK3144.html
[2010/10/12 20:05:05 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temppr4308.html
[2010/10/11 19:17:50 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemplG2864.html
[2010/10/11 14:26:53 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempKi3612.html
[2010/10/11 13:28:23 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempkh3184.html
[2010/10/10 18:50:14 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempYj4476.html
[2010/10/10 10:23:07 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempSI2772.html
[2010/10/09 19:46:25 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempSp4280.html
[2010/10/09 11:22:31 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempxT4388.html
[2010/10/09 11:22:31 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemppW4388.html
[2010/10/09 09:32:33 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempSi4304.html
[2010/10/08 15:21:43 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemptO3972.html
[2010/10/07 22:23:27 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempRh4504.html
[2010/10/07 15:46:56 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempwv4820.html
[2010/10/07 14:12:22 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempNO4020.html
[2010/10/07 14:12:22 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempWm4020.html
[2010/10/06 17:55:39 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempSX4336.html
[2010/10/06 15:28:38 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempRs4448.html
[2010/10/05 20:55:52 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempBS4516.html
[2010/10/05 20:55:52 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempOo4516.html
[2010/10/05 16:02:40 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemplL4700.html
[2010/10/04 19:12:54 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempLg2728.html
[2010/10/04 13:21:46 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempfG5000.html
[2010/10/04 13:21:46 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempRs5000.html
[2010/10/03 09:37:41 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temppl4368.html
[2010/10/02 11:19:50 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempLL3280.html
[2010/10/01 20:34:37 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempbGz780.html
[2010/10/01 18:10:26 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempEe5048.html
[2010/10/01 18:10:26 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempFT5048.html
[2010/10/01 16:58:16 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempTa4872.html
[2010/10/01 13:39:52 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempBp3608.html
[2010/09/30 19:07:39 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempfL3520.html
[2010/09/30 16:55:43 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempiE4020.html
[2010/09/30 16:46:33 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempIt1084.html
[2010/09/30 15:41:31 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempXN2924.html
[2010/09/29 16:51:09 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempNa4224.html
[2010/09/29 16:49:35 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempbe3544.html
[2010/09/29 16:49:35 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempmw3544.html
[2010/09/28 18:12:52 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempxt3432.html
[2010/09/28 18:04:15 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempJY4284.html
[2010/09/28 15:27:37 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempJTO348.html
[2010/09/27 13:15:22 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempNl4116.html
[2010/09/27 12:00:23 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempES2708.html
[2010/09/26 10:49:47 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempfI4556.html
[2010/09/25 14:47:48 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempze4968.html
[2010/09/25 08:27:29 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempzW4832.html
[2010/09/24 20:54:03 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempEs4816.html
[2010/09/24 20:54:03 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempzC4816.html
[2010/09/23 19:32:32 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempRaW268.html
[2010/09/22 20:16:31 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempXr2548.html
[2010/09/21 15:36:02 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempYW1804.html
[2010/09/20 19:11:04 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempzCl740.html
[2010/09/20 19:11:04 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempFMa740.html
[2010/09/20 13:28:14 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempkv2520.html
[2010/09/19 20:35:50 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempqY1344.html
[2010/09/19 20:35:50 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempGx1344.html
[2010/09/19 12:27:42 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempYB3908.html
[2010/09/19 09:00:27 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempwW1500.html
[2010/09/18 22:27:04 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemplH4668.html
[2010/09/18 18:20:17 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempOF4908.html
[2010/09/18 15:12:08 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempyS4968.html
[2010/09/18 14:14:05 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Templt3968.html
[2010/09/18 09:09:56 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempEX3784.html
[2010/09/17 19:54:50 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temppw3904.html
[2010/09/17 19:54:50 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempDO3904.html
[2010/09/17 14:18:28 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempTV4900.html
[2010/09/17 14:18:28 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempSi4900.html
[2010/09/16 18:17:00 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempkl3320.html
[2010/09/16 18:17:00 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempct3320.html
[2010/09/16 14:52:17 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempce4296.html
[2010/09/15 19:51:31 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempMb3024.html
[2010/09/14 20:40:37 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempQh2136.html
[2010/09/14 15:25:56 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempcO4904.html
[2010/09/14 15:25:56 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempRP4904.html
[2010/09/13 19:08:14 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempSl2968.html
[2010/09/13 13:29:48 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temppp2484.html
[2010/09/12 20:41:52 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempAV2304.html
[2010/09/12 09:18:50 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempAS1376.html
[2010/09/11 21:41:12 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempga4732.html
[2010/09/11 21:41:12 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempaM4732.html
[2010/09/10 21:24:29 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempMR1044.html
[2010/09/10 15:44:43 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempRH3916.html
[2010/09/09 21:32:50 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempIf4292.html
[2010/09/09 21:32:50 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempEi4292.html
[2010/09/09 12:59:38 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempBp4976.html
[2010/09/08 16:08:31 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempjJ2548.html
[2010/09/07 16:11:08 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempuY2328.html
[2010/09/06 21:56:19 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempxM4464.html
[2010/09/06 19:25:22 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempDV4236.html
[2010/09/06 19:25:22 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempug4236.html
[2010/09/06 15:51:43 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempaa4476.html
[2010/09/06 15:51:43 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempEy4476.html
[2010/09/05 17:53:54 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempok1100.html
[2010/09/05 13:34:15 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Templf3200.html
[2010/09/05 09:23:48 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempcI4144.html
[2010/09/04 20:40:59 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempYp3660.html
[2010/09/04 16:08:32 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempvh1228.html
[2010/09/04 16:08:32 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempfl1228.html
[2010/09/04 09:04:46 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempRq2748.html
[2010/09/04 09:04:46 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempyK2748.html
[2010/09/03 20:23:59 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempge4524.html
[2010/09/02 19:27:39 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempxA2108.html
[2010/09/02 13:17:33 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempyc2320.html
[2010/09/01 19:09:42 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempnO1700.html
[2010/09/01 17:37:00 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempkO3772.html
[2010/08/31 17:01:49 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempsE4756.html
[2010/08/31 08:59:38 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temphx4852.html
[2010/08/30 18:54:14 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempvt3208.html
[2010/08/30 09:16:32 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempLV3628.html
[2010/08/30 09:16:32 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempaS3628.html
[2010/08/29 19:53:55 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempKn2908.html
[2010/08/29 19:23:05 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempTx2496.html
[2010/08/29 11:51:44 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempMo1264.html
[2010/08/29 11:51:44 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempGj1264.html
[2010/08/29 09:31:38 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temprt1492.html
[2010/08/29 09:31:38 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempVv1492.html
[2010/08/28 20:53:22 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempMh2056.html
[2010/08/28 14:40:35 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempGH1572.html
[2010/08/28 10:54:50 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempnO2856.html
[2010/08/27 19:33:14 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempNv2500.html
[2010/08/27 18:35:47 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempmb3864.html
[2010/08/27 11:38:26 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempfU1832.html
[2010/08/26 22:45:13 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempFs2208.html
[2010/08/26 22:45:13 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempSn2208.html
[2010/08/26 09:38:49 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempvi5192.html
[2010/08/25 22:07:02 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempXV5880.html
[2010/08/25 12:43:22 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemprX2624.html
[2010/08/25 09:51:27 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempxF2612.html
[2010/08/24 22:03:31 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempAm2444.html
[2010/08/24 09:24:57 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempum4372.html
[2010/08/23 21:37:20 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempcc3400.html
[2010/08/23 21:37:20 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempjz3400.html
[2010/08/23 10:25:48 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempKI4684.html
[2010/08/21 23:06:04 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempKI4520.html
[2010/08/21 23:06:04 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempFr4520.html
[2010/08/21 10:27:50 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempNp1376.html
[2010/08/21 10:27:50 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemplK1376.html
[2010/08/20 21:55:08 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempoc3628.html
[2010/08/20 21:55:08 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempKV3628.html
[2010/08/19 23:23:39 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempTN4528.html
[2010/08/19 23:23:39 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempmV4528.html
[2010/08/19 12:52:38 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempiK4748.html
[2010/08/19 12:52:38 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempaD4748.html
[2010/08/19 10:09:18 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempRg2860.html
[2010/08/19 10:09:18 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempCs2860.html
[2010/08/18 09:20:01 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemphQ4280.html
[2010/08/18 09:20:01 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempok4280.html
[2010/08/17 16:59:18 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempZVr284.html
[2010/08/17 09:24:52 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempBE4672.html
[2010/08/16 17:12:55 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempYL3604.html
[2010/08/16 08:41:47 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempet2088.html
[2010/08/15 21:01:47 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempEj2600.html
[2010/08/15 17:53:05 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempdM1580.html
[2010/08/14 10:02:42 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempEm3408.html
[2010/08/14 10:02:01 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempKN4288.html
[2010/08/14 10:02:01 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempeM4288.html
[2010/08/13 20:10:02 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempsXg860.html
[2010/08/13 12:47:23 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempVm1572.html
[2010/08/13 08:45:34 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempHw1608.html
[2010/08/12 12:52:27 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempWP2692.html
[2010/08/12 12:52:27 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempwB2692.html
[2010/08/12 10:20:27 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempFY2128.html
[2010/08/12 10:20:27 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempde2128.html
[2010/08/11 21:04:01 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempRG4624.html
[2010/08/11 21:04:01 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempmp4624.html
[2010/08/11 12:01:27 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempvx4604.html
[2010/08/10 20:10:33 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemprR4952.html
[2010/08/10 11:42:23 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempPX4984.html
[2010/08/09 21:46:17 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempmh2232.html
[2010/08/09 11:04:21 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempyV2272.html
[2010/08/08 22:41:55 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempye2272.html
[2010/08/08 22:14:03 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Templt5064.html
[2010/08/08 22:14:03 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempsI5064.html
[2010/08/08 22:13:00 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempuQ1440.html
[2010/08/08 22:13:00 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempPi1440.html
[2010/08/08 10:46:50 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemprC2884.html
[2010/08/08 10:46:50 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempPA2884.html
[2010/08/07 20:46:00 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempVf2164.html
[2010/08/07 20:46:00 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempwq2164.html
[2010/08/07 11:10:31 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempSB4396.html
[2010/08/06 10:58:43 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempSE4192.html
[2010/08/05 21:58:48 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempGV2864.html
[2010/08/05 10:53:36 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempgk4876.html
[2010/08/04 22:05:41 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempez2056.html
[2010/08/04 11:18:54 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempfp5092.html
[2010/08/04 11:18:54 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempPn5092.html
[2010/08/03 17:09:42 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempSl3592.html
[2010/08/03 09:34:50 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempIJ2940.html
[2010/08/02 13:52:39 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempBj5056.html
[2010/08/02 13:52:39 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempdc5056.html
[2010/08/01 22:01:12 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempNq1560.html
[2010/08/01 10:49:18 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempeB4620.html
[2010/08/01 10:49:18 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempwl4620.html
[2010/07/31 21:13:34 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempAb2240.html
[2010/07/31 13:14:43 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempne4480.html
[2010/07/31 13:14:43 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemplV4480.html
[2010/07/31 10:38:47 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemphU2304.html
[2010/07/30 13:59:36 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temprq2892.html
[2010/07/30 09:37:57 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemphH3076.html
[2010/07/29 21:51:28 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempRR1688.html
[2010/07/29 12:40:44 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempjo4852.html
[2010/07/28 09:20:13 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempMJv352.html
[2010/07/27 22:35:47 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempLp4600.html
[2010/07/27 09:44:03 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempMl4832.html
[2010/07/26 22:05:24 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempde4060.html
[2010/07/26 11:22:50 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempsF3320.html
[2010/07/26 11:22:50 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempBW3320.html
[2010/07/25 22:04:30 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempca1484.html
[2010/07/25 02:40:06 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempLx3612.html
[2010/07/24 10:31:48 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempet4712.html
[2010/07/23 20:12:38 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempVd4720.html
[2010/07/22 09:05:45 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempfx1452.html
[2010/07/22 09:05:45 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempFE1452.html
[2010/07/21 21:24:59 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempoK3916.html
[2010/07/21 12:57:19 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempgk3064.html
[2010/07/20 23:14:01 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temppj3876.html
[2010/07/20 10:52:56 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temppm4892.html
[2010/07/19 19:39:13 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempbw4648.html
[2010/07/19 09:56:05 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempov2960.html
[2010/07/18 22:24:06 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempeU3888.html
[2010/07/18 21:07:57 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempII3032.html
[2010/07/18 15:02:53 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemplF3292.html
[2010/07/18 14:02:53 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempNz4380.html
[2010/07/18 09:16:55 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempmk2032.html
[2010/07/17 11:54:51 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempNC2088.html
[2010/07/17 11:54:51 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempPp2088.html
[2010/07/16 22:34:31 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempqB3860.html
[2010/07/16 12:47:48 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempvtg576.html
[2010/07/16 09:59:30 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempnE3672.html
[2010/07/15 20:13:03 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempKE3700.html
[2010/07/15 09:24:57 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempOv5552.html
[2010/07/14 19:29:58 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemppK4452.html
[2010/07/14 09:17:50 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempvOY784.html
[2010/07/13 20:59:05 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempVe2148.html
[2010/07/13 20:59:05 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temprc2148.html
[2010/07/13 09:28:40 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempKg4220.html
[2010/07/12 10:14:46 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempuyK352.html
[2010/07/12 09:07:51 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TemplE3844.html
[2010/07/11 18:55:09 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempQh4692.html
[2010/07/11 12:02:03 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempbj4968.html
[2010/07/11 10:20:31 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Templk4952.html
[2010/07/10 08:53:25 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempNN3080.html
[2010/07/09 22:15:04 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempwZ5108.html
[2010/07/09 20:13:35 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempyF4848.html
[2010/07/09 09:26:34 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempRw3000.html
[2010/07/08 21:38:02 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempae3672.html
[2010/07/08 13:53:23 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempUO3620.html
[2010/07/08 10:54:06 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempuR2316.html
[2010/07/07 23:14:50 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempfi3228.html
[2010/07/07 09:13:06 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempMa4748.html
[2010/07/06 21:04:29 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempsD2332.html
[2010/07/06 15:16:14 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempIM2024.html
[2010/07/06 11:29:09 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempqA3620.html
[2010/07/05 22:09:52 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempSJ2740.html
[2010/07/05 19:06:36 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempRE4332.html
[2010/07/05 08:47:59 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempSw4492.html
[2010/07/04 22:14:22 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempPy3824.html
[2010/07/04 11:18:56 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempZi3100.html
[2010/07/04 11:18:56 | 000,002,089 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempPB3100.html
[2010/07/03 14:34:33 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempfv1184.html
[2010/07/03 14:34:30 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempOn1184.html
[2010/07/02 22:05:30 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Tempcz2728.html
[2010/07/01 21:56:14 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\TempYT2400.html
[2010/06/30 21:51:55 | 000,002,432 | ---- | C] () -- C:\Users\Michał mistrz\AppData\Local\Temprby768.html
[2010/02/24 02:46:56 | 000,008,235 | ---- | C] () -- C:\ProgramData\ArcadeDeluxe3.log
[2010/02/24 02:44:57 | 000,000,188 | ---- | C] () -- C:\Windows\PidList.ini
[2010/02/24 02:24:48 | 000,001,282 | ---- | C] () -- C:\Windows\WPatchProgress.ini
[2009/11/05 04:32:42 | 000,192,484 | ---- | C] () -- C:\Program Files (x86)\Common Files\Acer GameZone online.ico
[2009/11/05 01:21:23 | 000,000,193 | ---- | C] () -- C:\Windows\Prelaunch.ini
[2009/11/05 01:21:23 | 000,000,169 | ---- | C] () -- C:\Windows\WisLangCode.ini
[2009/11/05 01:21:23 | 000,000,147 | ---- | C] () -- C:\Windows\WisPriority.ini
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll

[color=#E56717]========== LOP Check ==========[/color]

[2010/07/04 21:30:23 | 000,000,000 | -HSD | M] -- C:\Users\Michał mistrz\AppData\Roaming\.#
[2010/08/17 12:42:46 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\Ableton
[2010/12/11 20:07:35 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\Audacity
[2010/10/07 14:39:02 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\BlackBean
[2010/07/21 18:49:41 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\DAEMON Tools
[2010/07/01 23:01:11 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\DAEMON Tools Lite
[2010/10/13 15:33:36 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\DAEMON Tools Pro
[2010/07/05 10:44:43 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\DVDVideoSoftIEHelpers
[2010/11/18 17:34:54 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\FileZilla
[2010/12/13 20:37:03 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\Gadu-Gadu 10
[2010/07/04 21:23:47 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\GameConsole
[2010/09/27 16:47:00 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\GanymedeNet
[2010/07/15 10:56:55 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\GHISLER
[2010/10/23 14:47:06 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\Leadertech
[2010/07/12 09:08:20 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\OpenFM
[2010/12/12 12:37:35 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\SA-MP Audio Plugin
[2010/07/13 00:18:48 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\Starbreeze
[2010/11/01 16:41:51 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\Steinberg
[2010/08/26 18:31:34 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\Ubisoft
[2010/07/03 14:51:18 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\Uniblue
[2010/12/20 14:36:14 | 000,000,312 | ---- | M] () -- C:\Windows\Tasks\Dr.Web Daily scan.job
[2010/12/20 23:36:00 | 000,000,370 | ---- | M] () -- C:\Windows\Tasks\Dr.Web Update.job
[2010/11/09 12:20:46 | 000,032,608 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010/12/20 23:47:52 | 000,000,308 | -H-- | M] () -- C:\Windows\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2010/12/20 11:44:34 | 000,000,262 | -H-- | M] () -- C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/12/20 23:34:05 | 000,000,308 | -H-- | M] () -- C:\Windows\Tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job

[color=#E56717]========== Purity Check ==========[/color]



[color=#E56717]========== Custom Scans ==========[/color]


[color=#A23BEC]< %systemdrive%\*.* >[/color]
[2010/12/20 15:18:00 | 000,000,000 | ---- | M] () -- C:\autoexec.bat
[2009/07/14 02:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
[2009/07/27 21:40:53 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | ---- | M] () -- C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | ---- | M] () -- C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | ---- | M] () -- C:\globdata.ini
[2010/12/20 11:44:00 | 3111,518,208 | -HS- | M] () -- C:\hiberfil.sys
[2007/11/07 08:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | ---- | M] () -- C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll
[2006/12/01 22:37:14 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\msdia80.dll
[2010/12/20 11:44:01 | 4148,690,944 | -HS- | M] () -- C:\pagefile.sys
[2010/01/28 11:35:54 | 000,003,919 | RHS- | M] () -- C:\Patch.rev
[2010/06/30 09:56:03 | 000,000,208 | RHS- | M] () -- C:\Preload.rev
[2010/02/24 02:44:49 | 000,003,239 | ---- | M] () -- C:\RHDSetup.log
[2007/11/07 08:00:40 | 000,005,686 | ---- | M] () -- C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | ---- | M] () -- C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | ---- | M] () -- C:\VC_RED.MSI


[color=#A23BEC]< MD5 for: AGP440.SYS >[/color]
[2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys
[2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys

[color=#A23BEC]< MD5 for: ATAPI.SYS >[/color]
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys
[2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys

[color=#A23BEC]< MD5 for: BEEP.SYS >[/color]
[2009/07/14 01:00:13 | 000,006,656 | ---- | M] (Microsoft Corporation) MD5=16A47CE2DECC9B099349A5F840654746 -- C:\Windows\winsxs\amd64_microsoft-windows-beepsys_31bf3856ad364e35_6.1.7600.16385_none_201592fa214e4f02\beep.sys

[color=#A23BEC]< MD5 for: CDROM.SYS >[/color]
[2009/07/14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\SysWow64\DriverStore\FileRepository\cdrom.inf_amd64_neutral_8363d00ecae4322d\cdrom.sys
[2009/07/14 00:19:54 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=83D2D75E1EFB81B3450C18131443F7DB -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7600.16385_none_bb9e4d89bd7870f1\cdrom.sys

[color=#A23BEC]< MD5 for: NDIS.SYS >[/color]
[2009/07/14 02:48:27 | 000,947,776 | ---- | M] (Microsoft Corporation) MD5=CAD515DBD07D082BB317D9928CE8962C -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7600.16385_none_03bc1d6e35c013bf\ndis.sys

[color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color]
[2009/07/14 02:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 08:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 07:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 146 bytes -> C:\ProgramData\Temp:AB689DEA
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:93DE1838

< End of report >
[/log][/left]

[left][b]RSIT :[/b][/left]

[left][log] info.txt logfile of random's system information tool 1.08 2010-12-20 23:58:24

======Uninstall list======

-->MsiExec /X{54194F60-988C-4D03-B922-C2B00EFDA39A}
2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-002A-0000-1000-0000000FF1CE} /uninstall {E64BA721-2310-4B55-BE5A-2925F9706192}
2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-002A-0409-1000-0000000FF1CE} /uninstall {DE5A002D-8122-4278-A7EE-3121E7EA254E}
2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {DE5A002D-8122-4278-A7EE-3121E7EA254E}
2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {DE5A002D-8122-4278-A7EE-3121E7EA254E}
2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {90120000-0116-0409-1000-0000000FF1CE} /uninstall {DE5A002D-8122-4278-A7EE-3121E7EA254E}
2007 Microsoft Office Suite Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Acer Backup Manager-->C:\Program Files (x86)\InstallShield Installation Information\{72B776E5-4530-4C4B-9453-751DF87D9D93}\setup.exe -runfromtemp -l0x0409
Acer Crystal Eye webcam Ver:1.1.124.1120-->"C:\Program Files (x86)\InstallShield Installation Information\{D0ACE89D-EC7F-470F-80BE-4C98ED366B32}\setup.exe" -runfromtemp -l0x0409 -removeonly
Acer ePower Management-->"C:\Program Files (x86)\InstallShield Installation Information\{3DB0448D-AD82-4923-B305-D001E521A964}\setup.exe" -runfromtemp -l0x415 -removeonly
Acer eRecovery Management-->"C:\Program Files (x86)\InstallShield Installation Information\{7F811A54-5A09-4579-90E1-C93498E230D9}\setup.exe" -runfromtemp -l0x415 -removeonly
Acer GridVista-->C:\Windows\GVUni.exe GridV.UNI
Acer Registration-->C:\Program Files (x86)\Acer\Registration\Uninstall.exe
Acer ScreenSaver-->C:\Program Files (x86)\Acer\Screensaver\Uninstall.exe
Acer Updater-->"C:\Program Files (x86)\InstallShield Installation Information\{EE171732-BEB4-4576-887D-CB62727F01CA}\setup.exe" -runfromtemp -l0x415 -removeonly
Acrobat.com-->MsiExec.exe /X{287ECFA4-719A-2143-A09B-D6A12DE54E40}
Adobe AIR-->c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3-->MsiExec.exe /I{6D12B99F-EAAA-49D8-8E2F-74FA7459CCB2}
Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps-->MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color - Photoshop Specific-->MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings-->MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
Adobe Color EU Recommended Settings-->MsiExec.exe /I{BD087F50-46B2-43E4-BD73-5DB3DC20B47C}
Adobe Color JA Extra Settings-->MsiExec.exe /I{D92B72E2-C854-4738-8ED6-4C3661CC17AE}
Adobe Color NA Extra Settings-->MsiExec.exe /I{6179A7D2-A668-4F1D-BC9A-DCC6A10C7871}
Adobe Default Language CS3-->MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
Adobe Flash Player 10 ActiveX-->C:\Windows\SysWOW64\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10l_Plugin.exe -maintain plugin
Adobe Fonts All-->MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3-->MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop CS3-->C:\Program Files (x86)\Common Files\Adobe\Installers\678cd98c8365a5647f9a2e539d120a8\Setup.exe
Adobe Photoshop CS3-->MsiExec.exe /I{78EFD06D-7583-42F1-9E77-671D8782EB70}
Adobe Reader 9.4.1 MUI-->MsiExec.exe /I{AC76BA86-7AD7-FFFF-7B44-A91000000001}
Adobe Setup-->MsiExec.exe /I{CBF4DADD-974D-49C8-BC83-C6F31554001E}
Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe Type Support-->MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP Panels CS3-->MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
Aktualizacja produktu Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-0415-0000-0000000FF1CE} /uninstall {04E205D6-88B1-4652-B162-42DF2C3B1228}
Aktualizacja produktu Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-0415-0000-0000000FF1CE} /uninstall {442ECBCF-94A7-48CC-8CD9-D31FFFD5FA86}
Aktualizacja produktu Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-0415-0000-0000000FF1CE} /uninstall {128A36ED-21BE-4547-9FFE-5B85AEC735DD}
Alcor Micro USB Card Reader-->C:\Program Files (x86)\InstallShield Installation Information\{DBCE1208-433D-4D3E-A26A-CB1B5E71A8F5}\setup.exe -runfromtemp -l0x0409
ALLConverter PRO 1.0-->"C:\Program Files (x86)\ALLConverter PRO\unins000.exe"
ALLPlayer V4.X-->"C:\Program Files (x86)\ALLPlayer\unins000.exe"
Apple Application Support-->MsiExec.exe /I{EE6097DD-05F4-4178-9719-D3170BF098E8}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
ASIO4ALL-->C:\Program Files (x86)\ASIO4ALL v2\uninstall.exe
Ask Toolbar-->MsiExec.exe /I{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Assassin's Creed-->C:\Program Files (x86)\InstallShield Installation Information\{8CFA9151-6404-409A-AF22-4632D04582FD}\setup.exe -runfromtemp -l0x0015 -removeonly
Audacity 1.3.12 (Unicode)-->"C:\Program Files (x86)\Audacity 1.3 Beta (Unicode)\unins000.exe"
Audiorealism Bassline Pro v1.0.1-->C:\MICHA~1\VSTPLU~1\AUDIOR~1\BASSLI~1\UNINST~1\UNWISE.EXE C:\MICHA~1\VSTPLU~1\AUDIOR~1\BASSLI~1\UNINST~1\INSTALL.LOG
Avira AntiVir Personal - Free Antivirus-->C:\Program Files (x86)\Avira\AntiVir Desktop\setup.exe /REMOVE
Backup Manager Basic-->C:\Program Files (x86)\InstallShield Installation Information\{72B776E5-4530-4C4B-9453-751DF87D9D93}\setup.exe -runfromtemp -l0x0409
Bing Bar-->C:\Program Files (x86)\Bing Bar Installer\InstallManager.exe /UNINSTALL
Broomstick Bass 1.0.0-->"C:\Program Files (x86)\Bornemark\BroomstickBass\uninstall-bb.exe"
Call of Duty: Black Ops-->"C:\Program Files (x86)\Activision\Call of Duty - Black Ops\unins000.exe"
Catalyst Control Center - Branding-->MsiExec.exe /I{34A0D249-747E-4D6C-803D-329C120C6B79}
Chicken Invaders 2-->"C:\Program Files (x86)\Acer GameZone\Chicken Invaders 2\Uninstall.exe" "C:\Program Files (x86)\Acer GameZone\Chicken Invaders 2\install.log"
Collab-->C:\Program Files (x86)\Image-Line\Collab\uninstall.exe
D3DX10-->MsiExec.exe /X{E09C4DB7-630C-4F06-A631-8EA7239923AF}
Driver Cleaner 3-->C:\Program Files (x86)\Driver Cleaner\Uninst.exe
eSobi v2-->C:\Program Files (x86)\InstallShield Installation Information\{15D967B5-A4BE-42AE-9E84-64CD062B25AA}\setup.exe -runfromtemp -l0x0409
EVEREST Home Edition v2.20-->"C:\Program Files (x86)\Lavalys\EVEREST Home Edition\unins000.exe"
FIFA 11-->MsiExec.exe /X{3FEA6CD1-EA13-4CE7-A74E-A74A4A0A7B5C}
FileZilla Client 3.3.4.1-->C:\Program Files (x86)\FileZilla FTP Client\uninstall.exe
FL Studio 9-->C:\Program Files (x86)\Image-Line\FL Studio 9\uninstall.exe
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych-->MsiExec.exe /I{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}
Free Audio CD Burner version 1.4-->"C:\Program Files (x86)\DVDVideoSoft\Free Audio CD Burner\unins000.exe"
Free YouTube to MP3 Converter version 3.7-->"C:\Program Files (x86)\DVDVideoSoft\Free YouTube to MP3 Converter\unins000.exe"
free-downloads.net Toolbar-->C:\PROGRA~2\FREE-D~1.NET\UNWISE.EXE /U C:\PROGRA~2\FREE-D~1.NET\INSTALL.LOG
FreeRIP v3.5-->"C:\Program Files (x86)\FreeRIP3\unins000.exe"
Gadu-Gadu 10-->C:\Program Files (x86)\Gadu-Gadu 10\Uninstall.exe
Galeria fotografii usługi Windows Live-->MsiExec.exe /X{CB3F59BB-7858-41A1-A7EA-4B8A6FC7D431}
Game Booster-->"C:\Program Files (x86)\IObit\Game Booster\unins000.exe"
GameDesire-Pool & Snooker-->C:\Program Files (x86)\Ganymede\billiards_uninstall.exe
Google Toolbar for Internet Explorer-->"C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_4079369A224CB572.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Gordon's Gate Flash Driver 1.1.0.12-->C:\Program Files (x86)\Sony Ericsson\Gordons Gate\uninst.exe
Grand Theft Auto IV-->"C:\Program Files (x86)\InstallShield Installation Information\{579BA58C-F33D-4970-9953-B94B43768AC3}\setup.exe" -runfromtemp -l0x0009 -removeonly
Grand Theft Auto IV-->MsiExec.exe /I{5454083B-1308-4485-BF17-1110000B8301}
GTA San Andreas-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\setup.exe" -l0x9 -removeonly
Hardcore-->C:\Program Files (x86)\Image-Line\Hardcore\uninstall.exe
Identity Card-->C:\Program Files (x86)\Acer\Identity Card\Uninstall.exe
IL Download Manager-->C:\Program Files (x86)\Image-Line\Downloader\uninstall.exe
Intel(R) Management Engine Components-->C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\Uninstall\setup.exe -uninstall
Intel(R) Turbo Boost Technology Driver-->C:\Program Files (x86)\Intel\Intel(R) Turbo Boost Technology Driver\Uninstall\setup.exe -uninstall -iips
Java(TM) 6 Update 20-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216020FF}
JDownloader-->C:\Program Files (x86)\JDownloader\uninstall.exe
Junk Mail filter update-->MsiExec.exe /I{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}
LAME v3.98.2 for Audacity-->"C:\Program Files (x86)\Lame for Audacity\unins000.exe"
Launch Manager-->C:\Windows\UNINST32.EXE LManager.UNI
Live 8.0.1-->C:\PROGRA~2\Ableton\LIVE80~1.1\Install\UNWISE.EXE C:\PROGRA~2\Ableton\LIVE80~1.1\Install\INSTALL.LOG
Livebox Reconnect 2.0 Pro-->C:\Program Files (x86)\Livebox Reconnect 2.0 Pro\Uninstal.exe
Medal of Honor (TM)-->MsiExec.exe /X{415030B8-3E8B-462A-8C03-41D95AA3AB3B}
Merriam Websters Spell Jam-->"C:\Program Files (x86)\Acer GameZone\Merriam Websters Spell Jam\Uninstall.exe" "C:\Program Files (x86)\Acer GameZone\Merriam Websters Spell Jam\install.log"
Mesh Runtime-->MsiExec.exe /I{8C6D6116-B724-4810-8F2D-D047E6B7D68E}
Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{1FDA5A37-B22D-43FF-B582-B8964050DC13}
Microsoft Games for Windows - LIVE-->MsiExec.exe /X{86A4C6D9-29EE-4719-AFA1-BA3341862B83}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-0415-0000-0000000FF1CE} /uninstall {79EB535E-76E4-4356-8146-A24EE55AB69D}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0415-0000-0000000FF1CE} /uninstall {79EB535E-76E4-4356-8146-A24EE55AB69D}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0415-0000-0000000FF1CE} /uninstall {79EB535E-76E4-4356-8146-A24EE55AB69D}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-0415-0000-0000000FF1CE} /uninstall {79EB535E-76E4-4356-8146-A24EE55AB69D}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-0415-0000-0000000FF1CE} /uninstall {79EB535E-76E4-4356-8146-A24EE55AB69D}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0415-0000-0000000FF1CE} /uninstall {79EB535E-76E4-4356-8146-A24EE55AB69D}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-002A-0415-1000-0000000FF1CE} /uninstall {D45F91DE-F0FC-4D5F-9A0C-FDE5B251AAC6}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0044-0415-0000-0000000FF1CE} /uninstall {79EB535E-76E4-4356-8146-A24EE55AB69D}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0415-0000-0000000FF1CE} /uninstall {D45F91DE-F0FC-4D5F-9A0C-FDE5B251AAC6}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-0415-0000-0000000FF1CE} /uninstall {79EB535E-76E4-4356-8146-A24EE55AB69D}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00BA-0415-0000-0000000FF1CE} /uninstall {79EB535E-76E4-4356-8146-A24EE55AB69D}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0100-0415-0000-0000000FF1CE} /uninstall {79EB535E-76E4-4356-8146-A24EE55AB69D}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0101-0415-0000-0000000FF1CE} /uninstall {79EB535E-76E4-4356-8146-A24EE55AB69D}
Microsoft Office Access MUI (Polish) 2007-->MsiExec.exe /X{90120000-0015-0415-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Excel MUI (Polish) 2007-->MsiExec.exe /X{90120000-0016-0415-0000-0000000FF1CE}
Microsoft Office Groove MUI (Polish) 2007-->MsiExec.exe /X{90120000-00BA-0415-0000-0000000FF1CE}
Microsoft Office Home and Student 2007-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Polish) 2007-->MsiExec.exe /X{90120000-0044-0415-0000-0000000FF1CE}
Microsoft Office Language Pack 2007 - Polish/Polski-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall OMUI.PL-PL /dll OSETUP.DLL
Microsoft Office O MUI (Polish) 2007-->MsiExec.exe /X{90120000-0100-0415-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (Polish) 2007-->MsiExec.exe /X{90120000-00A1-0415-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Polish) 2007-->MsiExec.exe /X{90120000-001A-0415-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Polish) 2007-->MsiExec.exe /X{90120000-0018-0415-0000-0000000FF1CE}
Microsoft Office PowerPoint Viewer 2007 (Polish)-->MsiExec.exe /X{95120000-00AF-0415-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Polish) 2007-->MsiExec.exe /X{90120000-001F-0415-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Proofing (Polish) 2007-->MsiExec.exe /X{90120000-002C-0415-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0415-0000-0000000FF1CE} /uninstall {E9EA2604-8AC9-47D2-8F4B-6BF60787A357}
Microsoft Office Publisher MUI (Polish) 2007-->MsiExec.exe /X{90120000-0019-0415-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (Polish) 2007-->MsiExec.exe /X{90120000-006E-0415-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0017-0415-0000-0000000FF1CE} /uninstall {A740A405-DDE4-461F-AC66-6C79E81C87BE}
Microsoft Office SharePoint Designer MUI (Polish) 2007-->MsiExec.exe /X{90120000-0017-0415-0000-0000000FF1CE}
Microsoft Office Suite Activation Assistant-->MsiExec.exe /X{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (Polish) 2007-->MsiExec.exe /X{90120000-001B-0415-0000-0000000FF1CE}
Microsoft Office X MUI (Polish) 2007-->MsiExec.exe /X{90120000-0101-0415-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319-->MsiExec.exe /X{196BB40D-1578-3D01-B289-BEFC77A11A1E}
Microsoft Windows Media Video 9 VCM-->RunDll32 advpack.dll,LaunchINFSection C:\Windows\INF\wmv9vcm.inf, Uninstall
Microsoft Works-->MsiExec.exe /I{44E42AAA-432F-4E03-8D7D-C8DB4FEE526A}
MIKSOFT Mobile Media Converter-->"C:\Program Files (x86)\MIKSOFT\Mobile Media Converter\unins000.exe"
Mozilla Firefox (3.6.13)-->C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
MSVCRT_amd64-->MsiExec.exe /I{D0B44725-3666-492D-BEF6-587A14BD9BD9}
MSVCRT-->MsiExec.exe /I{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
Narzędzie do przekazywania usługi Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Nero 7 Lite-->"C:\Program Files (x86)\Nero\unins000.exe"
Norton Online Backup-->MsiExec.exe /X{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}
NTI Backup Now 5-->C:\Program Files (x86)\InstallShield Installation Information\{12EFA1A4-AC3B-443C-8143-237EDE760403}\setup.exe -runfromtemp -l0x0409
NTI Media Maker 8-->C:\Program Files (x86)\InstallShield Installation Information\{2413930C-8309-47A6-BC61-5EF27A4222BC}\setup.exe -runfromtemp -l0x0409
NVIDIA PhysX-->MsiExec.exe /X{54194F60-988C-4D03-B922-C2B00EFDA39A}
OpenAL-->"C:\Program Files (x86)\OpenAL\oalinst.exe" /U
Pakiet zgodności dla systemu Office 2007-->MsiExec.exe /X{90120000-0020-0415-0000-0000000FF1CE}
PDF Settings-->MsiExec.exe /I{293D5729-7C01-4FA4-A4DE-BB6A1587BBB9}
Poczta usługi Windows Live-->MsiExec.exe /I{64376910-1860-4CEF-8B34-AA5D205FC5F1}
Podstawowe programy Windows Live-->C:\Program Files (x86)\Windows Live\Installer\wlarp.exe
Podstawowe programy Windows Live-->MsiExec.exe /I{7A9D47BA-6D50-4087-866F-0800D8B89383}
PoiZone-->C:\Program Files (x86)\Image-Line\PoiZone\uninstall.exe
Pomocnik Messenger-->MsiExec.exe /I{BD8DA595-F501-4ABE-85A0-5C23E82472A0}
Pro Evolution Soccer 2011-->MsiExec.exe /X{9773450C-E2F3-46C3-9464-1D7EDE5EFB63}
PunkBuster Services-->C:\Windows\system32\pbsvc.exe -u
QuickTime-->MsiExec.exe /I{57752979-A1C9-4C02-856B-FBB27AC4E02C}
Real Alternative 2.0.2-->"C:\Program Files (x86)\Real Alternative\unins000.exe"
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
Saints Row 2-->"C:\Program Files (x86)\Saints Row 2\unins000.exe"
Sawer-->C:\Program Files (x86)\Image-Line\Sawer\uninstall.exe
Security Update for 2007 Microsoft Office System (KB2288621)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5C497F0B-2061-4CC9-A61C-6B45B867354D}
Security Update for 2007 Microsoft Office System (KB2288931)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {CD769337-C8AC-46DB-A7DC-643E50089263}
Security Update for 2007 Microsoft Office System (KB2289158)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {210B16C0-CEBD-4DE9-B474-04A7E8735E16}
Security Update for 2007 Microsoft Office System (KB2344875)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {6FC5C4C1-D7AE-44C3-94B7-6424FC3E752F}
Security Update for 2007 Microsoft Office System (KB2345043)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {536FB502-775F-4494-BACE-C02CC90B7A5B}
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB976321)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7F207DCA-3399-40CB-A968-6E5991B1421A}
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)-->c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {FD8D7C9A-E56A-3E7B-BA6D-FE68F13296E3} /parameterfolder Client
Security Update for Microsoft Office Excel 2007 (KB2345035)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {B23002DD-34EC-4988-B810-A5E2A0BF04F1}
Security Update for Microsoft Office InfoPath 2007 (KB979441)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {8CCB781A-CF6B-4FCB-B6D8-59C64DF5C6DB}
Security Update for Microsoft Office PowerPoint 2007 (KB982158)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F5B70033-E79C-4569-90BF-BC9B4E4F3F46}
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3DED0A62-44C8-4E00-A785-5212F297A9D9}
Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
Security Update for Microsoft Office Word 2007 (KB2344993)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7A5B74FA-7A92-4FC9-821A-2DD5D4E73E48}
Sony Ericsson Themes Creator 3.06-->C:\Program Files (x86)\Sony Ericsson\Themes Creator\Uninstall.exe
SpyHunter-->MsiExec.exe /X{3636C923-7AD6-4DE3-978A-09609AEE8ECF}
Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
Steinberg Hypersonic v1.0-->C:\MICHA~1\VSTPLU~1\HYPERS~1\HYPERS~1\UNINST~1\HYPERS~1\UNWISE.EXE C:\MICHA~1\VSTPLU~1\HYPERS~1\HYPERS~1\UNINST~1\HYPERS~1\INSTALL.LOG
System Requirements Lab CYRI-->MsiExec.exe /I{AB49B509-8FCA-45E6-9FB9-9E4AEEB8F148}
System Requirements Lab-->C:\Program Files (x86)\SystemRequirementsLab\Uninstall.exe
System Requirements Lab-->MsiExec.exe /I{9E1BAB75-EB78-440D-94C0-A3857BE2E733}
Total Commander (Remove or Repair)-->c:\totalcmd\tcuninst.exe
Toxic Biohazard-->C:\Program Files (x86)\Image-Line\Toxic Biohazard\uninstall.exe
Two Worlds II-->C:\Program Files (x86)\Reality Pump\Two Worlds II\Uninstall.exe
Uniblue DriverScanner-->"C:\Program Files (x86)\Uniblue\DriverScanner\unins000.exe"
Uninstall 1.0.0.1-->"C:\Program Files (x86)\Common Files\DVDVideoSoft\unins000.exe"
Update for 2007 Microsoft Office System (KB2284654)-->msiexec /package {90120000-002A-0000-1000-0000000FF1CE} /uninstall {FB166E7C-8AA6-48C8-B726-1F25BEE7825A}
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft Office 2007 Help for Common Features (KB963673)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {AB365889-0395-4FAD-B702-CA5985D53D42}
Update for Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {199DF7B6-169C-448C-B511-1054101BE9C9}
Update for Microsoft Office OneNote 2007 (KB980729)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {329050A9-EF80-40F9-B633-74508F54C1FF}
Update for Microsoft Office OneNote 2007 Help (KB963670)-->msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {2744EF05-38E1-4D5D-B333-E021EDAEA245}
Update for Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {397B1D4F-ED7B-4ACA-A637-43B670843876}
Update for Microsoft Office Script Editor Help (KB963671)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {CD11C6A2-FFC6-4271-8EAB-79C3582F505C}
Update for Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {80E762AA-C921-4839-9D7D-DB62A72C0726}
Update Service-->C:\Program Files (x86)\Sony Ericsson\Update Service\uninst.exe
Virtual DJ Pro Full - Atomix Productions-->C:\PROGRA~2\VIRTUA~1\UNWISE.EXE C:\PROGRA~2\VIRTUA~1\INSTALL.LOG
Welcome Center-->C:\Program Files (x86)\Acer\Welcome Center\Uninstall.exe
Winamp-->"C:\Program Files (x86)\Winamp\UninstWA.exe"
Windows Live Communications Platform-->MsiExec.exe /I{D45240D3-B6B3-4FF9-B243-54ECE3E10066}
Windows Live Installer-->MsiExec.exe /I{0B0F231F-CE6A-483D-AA23-77B364F75917}
Windows Live Mail-->MsiExec.exe /I{9D56775A-93F3-44A3-8092-840E3826DE30}
Windows Live Mesh-->MsiExec.exe /I{BF35168D-F6F9-4202-BA87-86B5E3C9BF7A}
Windows Live Mesh-->MsiExec.exe /I{DECDCB7C-58CC-4865-91AF-627F9798FE48}
Windows Live Messenger Companion Core-->MsiExec.exe /I{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}
Windows Live Messenger-->MsiExec.exe /X{2C7E8AA1-9C03-4606-BF34-5D99D07964DA}
Windows Live Messenger-->MsiExec.exe /X{EB4DF488-AAEF-406F-A341-CB2AAA315B90}
Windows Live Movie Maker-->MsiExec.exe /X{92EA4134-10D1-418A-91E1-5A0453131A38}
Windows Live Movie Maker-->MsiExec.exe /X{F80E5450-3EF3-4270-B26C-6AC53BEC5E76}
Windows Live Photo Common-->MsiExec.exe /X{0654EA5D-308A-4196-882B-5C09744A5D81}
Windows Live Photo Common-->MsiExec.exe /X{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}
Windows Live Photo Gallery-->MsiExec.exe /X{3336F667-9049-4D46-98B6-4C743EEBC5B1}
Windows Live PIMT Platform-->MsiExec.exe /I{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}
Windows Live SOXE Definitions-->MsiExec.exe /I{200FEC62-3C34-4D60-9CE8-EC372E01C08F}
Windows Live SOXE-->MsiExec.exe /I{682B3E4F-696A-42DE-A41C-4C07EA1678B4}
Windows Live Sync-->MsiExec.exe /X{2E522ED6-01E2-4207-82D5-B3BFB31B8BD4}
Windows Live UX Platform Language Pack-->MsiExec.exe /I{543E6ACA-51B7-4283-82F2-57C0582A53C5}
Windows Live UX Platform-->MsiExec.exe /I{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}
Windows Live Writer Resources-->MsiExec.exe /X{26E3C07C-7FF7-4362-9E99-9E49E383CF16}
Windows Live Writer-->MsiExec.exe /X{A726AE06-AAA3-43D1-87E3-70F510314F04}
Windows Live Writer-->MsiExec.exe /X{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}
Windows Live Writer-->MsiExec.exe /X{E55E0C35-AC3C-4683-BA2F-834348577B80}
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
Xvid 1.2.2 final uninstall-->"C:\Program Files (x86)\Xvid\unins000.exe"

======System event log======

Computer Name: acer
Event Code: 7036
Message: Usługa Klient DHCP weszła w stan uruchomienia.
Record Number: 67637
Source Name: Service Control Manager
Time Written: 20100917131530.291640-000
Event Type: Informacje
User:

Computer Name: acer
Event Code: 51046
Message: Usługa klienta DHCPv6 została uruchomiona
Record Number: 67636
Source Name: Microsoft-Windows-DHCPv6-Client
Time Written: 20100917131530.291640-000
Event Type: Informacje
User: ZARZĄDZANIE NT\USŁUGA LOKALNA

Computer Name: acer
Event Code: 50036
Message: Usługa klienta DHCPv4 została uruchomiona
Record Number: 67635
Source Name: Microsoft-Windows-Dhcp-Client
Time Written: 20100917131530.276040-000
Event Type: Informacje
User: ZARZĄDZANIE NT\USŁUGA LOKALNA

Computer Name: acer
Event Code: 7036
Message: Usługa Pomoc TCP/IP NetBIOS weszła w stan uruchomienia.
Record Number: 67634
Source Name: Service Control Manager
Time Written: 20100917131530.276040-000
Event Type: Informacje
User:

Computer Name: acer
Event Code: 7036
Message: Usługa Usługa interfejsu magazynu sieciowego weszła w stan uruchomienia.
Record Number: 67633
Source Name: Service Control Manager
Time Written: 20100917131530.276040-000
Event Type: Informacje
User:

=====Application event log=====

Computer Name: WIN-4SCIJNHR8EH
Event Code: 9009
Message: Menedżer okien pulpitu zakończył działanie; kod (0x40010004).
Record Number: 313
Source Name: Desktop Window Manager
Time Written: 20100224015913.000000-000
Event Type: Informacje
User:

Computer Name: WIN-4SCIJNHR8EH
Event Code: 258
Message: Defragmentator dysku pomyślnie zakończył pracę (defragmentation): PQSERVICE
Record Number: 312
Source Name: Microsoft-Windows-Defrag
Time Written: 20100224015808.000000-000
Event Type: Informacje
User:

Computer Name: WIN-4SCIJNHR8EH
Event Code: 1003
Message: Usługa Windows Search została uruchomiona.

Record Number: 311
Source Name: Microsoft-Windows-Search
Time Written: 20100224015759.000000-000
Event Type: Informacje
User:

Computer Name: WIN-4SCIJNHR8EH
Event Code: 1013
Message: Usługa Windows Search została normalnie zatrzymana.

Record Number: 310
Source Name: Microsoft-Windows-Search
Time Written: 20100224015758.000000-000
Event Type: Informacje
User:

Computer Name: WIN-4SCIJNHR8EH
Event Code: 103
Message: Windows (2320) Windows: Aparat bazy danych zatrzymał wystąpienie (0).
Record Number: 309
Source Name: ESENT
Time Written: 20100224015758.000000-000
Event Type: Informacje
User:

=====Security event log=====

Computer Name: WIN-4SCIJNHR8EH
Event Code: 4624
Message: Użytkownik pomyślnie zalogował się na koncie.

Podmiot:
Identyfikator zabezpieczeń: S-1-5-18
Nazwa konta: WIN-4SCIJNHR8EH$
Domena konta: WORKGROUP
Identyfikator logowania: 0x3e7

Typ logowania: 5

Nowe logowanie:
Identyfikator zabezpieczeń: S-1-5-18
Nazwa konta: SYSTEM
Domena konta: NT AUTHORITY
Identyfikator logowania: 0x3e7
Identyfikator GUID logowania: {00000000-0000-0000-0000-000000000000}

Informacje o procesie:
Identyfikator procesu: 0x238
Nazwa procesu: C:\Windows\System32\services.exe

Informacje o sieci:
Nazwa stacji roboczej:
Adres źródłowy sieci: -
Port źródłowy: -

Szczegółowe informacje o uwierzytelnianiu:
Proces logowania: Advapi
Pakiet uwierzytelniania: Negotiate
Usługi przejściowe: -
Nazwa pakietu (tylko NTLM): -
Długość klucza: 0

To zdarzenie jest generowane w momencie utworzenia sesji logowania. Jest ono generowane na komputerze, do którego został uzyskany dostęp.

Pola podmiotu wskazują konto w systemie lokalnym, które zażądało logowania. Najczęściej jest to usługa, na przykład usługa Serwer, lub proces lokalny taki jak Winlogon.exe lub Services.exe.

Pole typu logowania wskazuje rodzaj zaistniałego logowania. Najczęstsze typy to 2 (interakcyjne) i 3 (sieciowe).

Pola nowego logowania wskazują konto, dla którego zostało utworzone nowe logowanie, czyli konto, które zostało zalogowane.

Pola sieci wskazują lokalizację, z której pochodziło zdalne żądanie logowania. Nazwa stacji roboczej nie zawsze jest dostępna i w niektórych przypadkach może być pusta.

Pola informacji o uwierzytelnianiu zawierają szczegółowe informacje o tym konkretnym żądaniu logowania.
- Identyfikator GUID logowania to unikatowy identyfikator, za pomocą którego można skorelować to zdarzenie ze zdarzeniem centrum dystrybucji kluczy.
- Usługi przejściowe wskazują, które usługi pośrednie uczestniczyły w tym żądaniu logowania.
- Nazwa pakietu wskazuje, który protokół podrzędny spośród protokołów NTLM został użyty.
- Długość klucza wskazuje długość wygenerowanego klucza sesji. Jeśli nie zażądano klucza sesji, jest to wartość 0.
Record Number: 76
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100224015800.636862-000
Event Type: Sukcesy inspekcji
User:

Computer Name: WIN-4SCIJNHR8EH
Event Code: 4672
Message: Przypisano specjalne uprawnienia do nowego logowania.

Podmiot:
Identyfikator zabezpieczeń: S-1-5-18
Nazwa konta: SYSTEM
Domena konta: NT AUTHORITY
Identyfikator logowania: 0x3e7

Uprawnienia: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 75
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100224015759.076860-000
Event Type: Sukcesy inspekcji
User:

Computer Name: WIN-4SCIJNHR8EH
Event Code: 4624
Message: Użytkownik pomyślnie zalogował się na koncie.

Podmiot:
Identyfikator zabezpieczeń: S-1-5-18
Nazwa konta: WIN-4SCIJNHR8EH$
Domena konta: WORKGROUP
Identyfikator logowania: 0x3e7

Typ logowania: 5

Nowe logowanie:
Identyfikator zabezpieczeń: S-1-5-18
Nazwa konta: SYSTEM
Domena konta: NT AUTHORITY
Identyfikator logowania: 0x3e7
Identyfikator GUID logowania: {00000000-0000-0000-0000-000000000000}

Informacje o procesie:
Identyfikator procesu: 0x238
Nazwa procesu: C:\Windows\System32\services.exe

Informacje o sieci:
Nazwa stacji roboczej:
Adres źródłowy sieci: -
Port źródłowy: -

Szczegółowe informacje o uwierzytelnianiu:
Proces logowania: Advapi
Pakiet uwierzytelniania: Negotiate
Usługi przejściowe: -
Nazwa pakietu (tylko NTLM): -
Długość klucza: 0

To zdarzenie jest generowane w momencie utworzenia sesji logowania. Jest ono generowane na komputerze, do którego został uzyskany dostęp.

Pola podmiotu wskazują konto w systemie lokalnym, które zażądało logowania. Najczęściej jest to usługa, na przykład usługa Serwer, lub proces lokalny taki jak Winlogon.exe lub Services.exe.

Pole typu logowania wskazuje rodzaj zaistniałego logowania. Najczęstsze typy to 2 (interakcyjne) i 3 (sieciowe).

Pola nowego logowania wskazują konto, dla którego zostało utworzone nowe logowanie, czyli konto, które zostało zalogowane.

Pola sieci wskazują lokalizację, z której pochodziło zdalne żądanie logowania. Nazwa stacji roboczej nie zawsze jest dostępna i w niektórych przypadkach może być pusta.

Pola informacji o uwierzytelnianiu zawierają szczegółowe informacje o tym konkretnym żądaniu logowania.
- Identyfikator GUID logowania to unikatowy identyfikator, za pomocą którego można skorelować to zdarzenie ze zdarzeniem centrum dystrybucji kluczy.
- Usługi przejściowe wskazują, które usługi pośrednie uczestniczyły w tym żądaniu logowania.
- Nazwa pakietu wskazuje, który protokół podrzędny spośród protokołów NTLM został użyty.
- Długość klucza wskazuje długość wygenerowanego klucza sesji. Jeśli nie zażądano klucza sesji, jest to wartość 0.
Record Number: 74
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100224015759.076860-000
Event Type: Sukcesy inspekcji
User:

Computer Name: WIN-4SCIJNHR8EH
Event Code: 4738
Message: Zmieniono konto użytkownika.

Podmiot:
Identyfikator zabezpieczeń: S-1-5-21-1070666057-106192516-1559153215-500
Nazwa konta: Administrator
Domena konta: WIN-4SCIJNHR8EH
Identyfikator logowania: 0x49892

Konto docelowe:
Identyfikator zabezpieczeń: S-1-5-21-1070666057-106192516-1559153215-500
Nazwa konta: Administrator
Domena konta: WIN-4SCIJNHR8EH

Zmienione atrybuty:
Nazwa konta SAM: -
Wyświetlana nazwa: -
Nazwa główna użytkownika: -
Katalog macierzysty: -
Dysk macierzysty: -
Ścieżka skryptów: -
Ścieżka profilu: -
Stacje robocze użytkownika: -
Hasło ostatnio ustawiono: -
Konto wygasa: -
Identyfikator grupy podstawowej: -
Dozwolone delegowanie do: -
Stara wartość UAC: 0x211
Nowa wartość UAC: 0x211
Kontrola konta użytkownika: -
Parametry użytkownika: -
Historia identyfikatora SID: -
Godziny logowania: -

Informacje dodatkowe:
Uprawnienia: -
Record Number: 73
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100224015757.345256-000
Event Type: Sukcesy inspekcji
User:

Computer Name: WIN-4SCIJNHR8EH
Event Code: 1102
Message: Dziennik inspekcji został wyczyszczony.
Podmiot:
Identyfikator zabezpieczeń: S-1-5-21-1070666057-106192516-1559153215-500
Nazwa konta: Administrator
Nazwa domeny: WIN-4SCIJNHR8EH
Identyfikator logowania: 0x49892
Record Number: 72
Source Name: Microsoft-Windows-Eventlog
Time Written: 20100224015755.520053-000
Event Type: Sukcesy inspekcji
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\QuickTime\QTSystem\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=4
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 37 Stepping 2, GenuineIntel
"PROCESSOR_REVISION"=2502
"Pathtem"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\
"NTIPath"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\;
"CLASSPATH"=.;C:\Program Files (x86)\Java\jre6\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files (x86)\Java\jre6\lib\ext\QTJava.zip

-----------------EOF-----------------
[/log][/left]

[log] Logfile of random's system information tool 1.08 (written by random/random)
Run by Michał mistrz at 2010-12-20 23:58:12
Microsoft Windows 7 Home Premium
System drive C: has 30 GB (11%) free of 262 GB
Total RAM: 3957 MB (40% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:58:22, on 2010-12-20
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal

Running processes:
C:\Windows\Wvucia.exe
C:\Program Files (x86)\IObit\Game Booster\GameBox.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\PLFSetI.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\MICHAM~1\AppData\Local\Temp\Wcd.exe
C:\Users\MICHAM~1\AppData\Local\Temp\Wcc.exe
C:\Users\Michał mistrz\Downloads\RSIT.exe
C:\Program Files (x86)\trend micro\Michał mistrz.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0415&m=aspire_5740&r=27360610h116l0438z1j5t64i1d199
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0415&m=aspire_5740&r=27360610h116l0438z1j5t64i1d199
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0415&m=aspire_5740&r=27360610h116l0438z1j5t64i1d199
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Pomocnik logowania za pomocą identyfikatora Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
O2 - BHO: IEPluginBHO - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\ProgramData\Gadu-Gadu 10\_userdata\ggbho.2.dll (file missing)
O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SpIDerMail] "C:\Program Files (x86)\DrWeb\spiderml.exe" -autorun
O4 - HKLM\..\Run: [SpIDerAgent] "C:\Program Files (x86)\DrWeb\SpIDerAgent.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ALLUpdate] "C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe" "sleep"
O4 - HKCU\..\Run: [JP595IR86O] C:\Users\MICHAM~1\AppData\Local\Temp\Wcc.exe
O4 - HKCU\..\Run: [NtWqIVLZEWZU] C:\Users\MICHAM~1\AppData\Local\Temp\Wcd.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'USŁUGA SIECIOWA')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Michał mistrz\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
O8 - Extra context menu item: Funkcja Google Sidewiki - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agr64svc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Dr.Web Scanning Engine (DrWebEngine) (DrWebEngine) - Doctor Web, Ltd. - C:\Program Files (x86)\Common Files\Doctor Web\Scanning Engine\dwengine.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
O23 - Service: Usługa Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SpyHunter 4 Service - Enigma Software Group USA, LLC. - C:\PROGRA~2\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TurboBoost - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Updater Service - Acer - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 14456 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Dr.Web Daily scan.job
C:\Windows\tasks\Dr.Web Update.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
C:\Windows\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-23 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocnik logowania za pomocą identyfikatora Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-23 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2010-12-20 297648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll [2010-10-28 843832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-06-10 1233288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-06-30 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
free-downloads.net Toolbar - C:\Program Files (x86)\free-downloads.net\tbfree.dll [2009-12-31 2349080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D}]
IEPluginBHO Class - C:\ProgramData\Gadu-Gadu 10\_userdata\ggbho.2.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{ecdee021-0d17-467f-a1ff-c7a115230949} - free-downloads.net Toolbar - C:\Program Files (x86)\free-downloads.net\tbfree.dll [2009-12-31 2349080]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-06-10 1233288]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2010-12-20 297648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"BackupManagerTray"=C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [2009-09-25 261888]
"NortonOnlineBackupReminder"=C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe [2009-07-25 588648]
"LManager"=C:\Program Files (x86)\Launch Manager\LManager.exe [2009-11-02 1094736]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-21 932288]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe [2010-07-12 74752]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2010-11-04 281768]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-12-09 98304]
"SpIDerMail"=C:\Program Files (x86)\DrWeb\spiderml.exe [2010-10-07 1561840]
"SpIDerAgent"=C:\Program Files (x86)\DrWeb\SpIDerAgent.exe [2010-11-11 1377008]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-11-05 39408]
"AlcoholAutomount"=C:\Program Files (x86)\Alcohol Soft\Alcohol 120\axcmd.exe [2009-04-24 203928]
"DAEMON Tools Pro Agent"=C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [2010-04-15 427328]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"ALLUpdate"=C:\Program Files (x86)\ALLPlayer\ALLUpdate.exe [2010-11-02 1432064]
"JP595IR86O"=C:\Users\MICHAM~1\AppData\Local\Temp\Wcc.exe [2010-12-19 218624]
"NtWqIVLZEWZU"=C:\Users\MICHAM~1\AppData\Local\Temp\Wcd.exe [2010-12-19 221696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.reg - open - "regedit.exe" "%1"

======List of files/folders created in the last 2 months======

2010-12-20 23:58:12 ----D---- C:\rsit
2010-12-20 23:58:12 ----D---- C:\Program Files (x86)\trend micro
2010-12-20 15:18:00 ----A---- C:\autoexec.bat
2010-12-20 15:17:49 ----D---- C:\sh4ldr
2010-12-20 15:17:49 ----D---- C:\Program Files (x86)\Enigma Software Group
2010-12-20 15:17:13 ----D---- C:\Windows\3636C9237AD64DE3978A09609AEE8ECF.TMP
2010-12-20 14:35:58 ----D---- C:\ProgramData\Doctor Web
2010-12-20 14:35:58 ----D---- C:\Program Files (x86)\DrWeb
2010-12-20 14:35:58 ----D---- C:\Program Files (x86)\Common Files\Doctor Web
2010-12-20 10:51:25 ----D---- C:\Program Files (x86)\Reality Pump
2010-12-20 00:06:43 ----D---- C:\ProgramData\KONAMI
2010-12-19 23:54:50 ----A---- C:\Windows\Wvucia.exe
2010-12-16 14:54:51 ----SHD---- C:\ProgramData\SecuROM
2010-12-16 10:38:34 ----D---- C:\Users\Michał mistrz\AppData\Roaming\ATI
2010-12-16 10:38:34 ----D---- C:\ProgramData\ATI
2010-12-16 10:37:41 ----D---- C:\Program Files (x86)\ATI Technologies
2010-12-15 21:18:30 ----A---- C:\Windows\SysWOW64\tzres.dll
2010-12-15 21:18:27 ----A---- C:\Windows\SysWOW64\taskschd.dll
2010-12-15 21:18:27 ----A---- C:\Windows\SysWOW64\taskeng.exe
2010-12-15 21:18:27 ----A---- C:\Windows\SysWOW64\taskcomp.dll
2010-12-15 21:18:27 ----A---- C:\Windows\SysWOW64\schtasks.exe
2010-12-15 21:18:24 ----A---- C:\Windows\SysWOW64\atmlib.dll
2010-12-15 21:18:24 ----A---- C:\Windows\SysWOW64\atmfd.dll
2010-12-15 21:18:23 ----A---- C:\Windows\SysWOW64\webio.dll
2010-12-15 21:18:11 ----A---- C:\Windows\SysWOW64\iertutil.dll
2010-12-15 21:18:10 ----A---- C:\Windows\SysWOW64\mstime.dll
2010-12-15 21:18:10 ----A---- C:\Windows\SysWOW64\mshtml.dll
2010-12-15 21:18:09 ----A---- C:\Windows\SysWOW64\ieframe.dll
2010-12-15 21:18:08 ----A---- C:\Windows\SysWOW64\wininet.dll
2010-12-15 21:18:08 ----A---- C:\Windows\SysWOW64\urlmon.dll
2010-12-15 21:18:07 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2010-12-15 21:18:07 ----A---- C:\Windows\SysWOW64\msfeedssync.exe
2010-12-15 21:18:07 ----A---- C:\Windows\SysWOW64\msfeedsbs.dll
2010-12-15 21:18:07 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2010-12-15 21:18:07 ----A---- C:\Windows\SysWOW64\licmgr10.dll
2010-12-15 21:18:07 ----A---- C:\Windows\SysWOW64\ieui.dll
2010-12-15 21:18:07 ----A---- C:\Windows\SysWOW64\iepeers.dll
2010-12-15 21:18:07 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2010-12-15 21:18:06 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2010-12-12 20:19:05 ----D---- C:\ProgramData\Apple Computer
2010-12-12 20:19:05 ----D---- C:\Program Files (x86)\QuickTime
2010-12-12 12:37:35 ----D---- C:\Users\Michał mistrz\AppData\Roaming\SA-MP Audio Plugin
2010-12-06 22:14:30 ----D---- C:\ProgramData\ALLConverter
2010-12-06 22:14:29 ----D---- C:\Program Files (x86)\ALLConverter PRO
2010-12-06 22:14:22 ----D---- C:\ProgramData\ALLPlayer
2010-12-06 22:14:22 ----A---- C:\Windows\SysWOW64\libFLAC.dll
2010-12-06 22:14:21 ----D---- C:\Program Files (x86)\NAPI-PROJEKT
2010-12-06 22:14:17 ----D---- C:\Program Files (x86)\ALLPlayer
2010-12-06 18:25:45 ----D---- C:\Program Files (x86)\Xvid
2010-12-06 18:25:45 ----A---- C:\Windows\SysWOW64\xvidvfw.dll
2010-12-06 18:25:45 ----A---- C:\Windows\SysWOW64\xvidcore.dll
2010-12-06 18:23:14 ----D---- C:\Users\Michał mistrz\AppData\Roaming\Apple Computer
2010-12-03 23:48:25 ----A---- C:\Windows\cdplayer.ini
2010-12-03 22:57:32 ----A---- C:\ProgramData\ss.ini
2010-12-03 22:57:29 ----D---- C:\ProgramData\FreeRIP
2010-12-03 22:57:28 ----D---- C:\Program Files (x86)\FreeRIP3
2010-12-01 18:22:44 ----D---- C:\Program Files (x86)\Counter-Strike Source
2010-12-01 16:16:51 ----D---- C:\Program Files (x86)\Saints Row 2
2010-11-20 16:05:49 ----D---- C:\Program Files (x86)\VirtualDJ
2010-11-18 20:59:18 ----A---- C:\Windows\SysWOW64\XAudio2_7.dll
2010-11-18 20:59:18 ----A---- C:\Windows\SysWOW64\XAPOFX1_5.dll
2010-11-18 20:59:17 ----A---- C:\Windows\SysWOW64\xactengine3_7.dll
2010-11-18 20:59:16 ----A---- C:\Windows\SysWOW64\D3DCompiler_43.dll
2010-11-18 20:59:15 ----A---- C:\Windows\SysWOW64\d3dcsx_43.dll
2010-11-18 20:59:14 ----A---- C:\Windows\SysWOW64\d3dx11_43.dll
2010-11-18 20:59:14 ----A---- C:\Windows\SysWOW64\d3dx10_43.dll
2010-11-18 20:59:12 ----A---- C:\Windows\SysWOW64\D3DX9_43.dll
2010-11-18 17:36:22 ----D---- C:\ProgramData\IObit
2010-11-18 17:36:22 ----D---- C:\Program Files (x86)\IObit
2010-11-14 18:46:47 ----D---- C:\Program Files (x86)\Activision
2010-11-14 00:47:26 ----D---- C:\Program Files (x86)\DAEMON Tools Pro
2010-11-08 23:28:28 ----D---- C:\Windows\pl
2010-11-08 23:26:28 ----D---- C:\Program Files (x86)\Bing Bar Installer
2010-11-08 22:25:13 ----D---- C:\Program Files (x86)\Common Files\Apple
2010-11-08 22:25:06 ----D---- C:\ProgramData\Apple
2010-11-08 22:25:06 ----D---- C:\Program Files (x86)\Apple Software Update
2010-11-08 22:14:23 ----A---- C:\Windows\NeroDigital.ini
2010-11-06 12:20:20 ----A---- C:\Windows\SysWOW64\synsoacc.dll
2010-11-04 16:06:29 ----RA---- C:\Windows\SysWOW64\tmp612D.tmp
2010-11-04 16:06:27 ----A---- C:\Windows\SysWOW64\XAudio2_6.dll
2010-11-04 16:06:27 ----A---- C:\Windows\SysWOW64\XAPOFX1_4.dll
2010-11-04 16:06:27 ----A---- C:\Windows\SysWOW64\xactengine3_6.dll
2010-11-04 16:06:27 ----A---- C:\Windows\SysWOW64\X3DAudio1_7.dll
2010-11-04 16:06:26 ----A---- C:\Windows\SysWOW64\XAudio2_5.dll
2010-11-04 16:06:25 ----A---- C:\Windows\SysWOW64\xactengine3_5.dll
2010-11-04 16:06:25 ----A---- C:\Windows\SysWOW64\D3DCompiler_42.dll
2010-11-04 16:06:22 ----A---- C:\Windows\SysWOW64\d3dcsx_42.dll
2010-11-04 16:06:21 ----A---- C:\Windows\SysWOW64\d3dx11_42.dll
2010-11-04 16:06:21 ----A---- C:\Windows\SysWOW64\d3dx10_42.dll
2010-11-04 16:06:20 ----A---- C:\Windows\SysWOW64\D3DX9_42.dll
2010-11-04 16:06:17 ----A---- C:\Windows\SysWOW64\d3dx10_41.dll
2010-11-04 16:06:17 ----A---- C:\Windows\SysWOW64\D3DCompiler_41.dll
2010-11-04 16:06:15 ----A---- C:\Windows\SysWOW64\D3DX9_41.dll
2010-11-04 16:06:14 ----A---- C:\Windows\SysWOW64\XAudio2_4.dll
2010-11-04 16:06:14 ----A---- C:\Windows\SysWOW64\XAPOFX1_3.dll
2010-11-04 16:06:14 ----A---- C:\Windows\SysWOW64\xactengine3_4.dll
2010-11-04 16:06:14 ----A---- C:\Windows\SysWOW64\X3DAudio1_6.dll
2010-11-04 16:06:12 ----A---- C:\Windows\SysWOW64\d3dx10_40.dll
2010-11-04 16:06:12 ----A---- C:\Windows\SysWOW64\D3DCompiler_40.dll
2010-11-04 16:06:10 ----A---- C:\Windows\SysWOW64\D3DX9_40.dll
2010-11-04 16:06:09 ----A---- C:\Windows\SysWOW64\XAudio2_3.dll
2010-11-04 16:06:09 ----A---- C:\Windows\SysWOW64\XAPOFX1_2.dll
2010-11-04 16:06:09 ----A---- C:\Windows\SysWOW64\xactengine3_3.dll
2010-11-04 16:06:09 ----A---- C:\Windows\SysWOW64\X3DAudio1_5.dll
2010-11-04 16:06:08 ----A---- C:\Windows\SysWOW64\XAudio2_2.dll
2010-11-04 16:06:08 ----A---- C:\Windows\SysWOW64\XAPOFX1_1.dll
2010-11-04 16:06:08 ----A---- C:\Windows\SysWOW64\xactengine3_2.dll
2010-11-04 16:06:06 ----A---- C:\Windows\SysWOW64\d3dx10_39.dll
2010-11-04 16:06:06 ----A---- C:\Windows\SysWOW64\D3DCompiler_39.dll
2010-11-04 16:06:05 ----A---- C:\Windows\SysWOW64\D3DX9_39.dll
2010-11-04 16:06:04 ----A---- C:\Windows\SysWOW64\XAudio2_1.dll
2010-11-04 16:06:04 ----A---- C:\Windows\SysWOW64\XAPOFX1_0.dll
2010-11-04 16:06:04 ----A---- C:\Windows\SysWOW64\xactengine3_1.dll
2010-11-04 16:06:03 ----A---- C:\Windows\SysWOW64\X3DAudio1_4.dll
2010-11-04 16:06:02 ----A---- C:\Windows\SysWOW64\d3dx10_38.dll
2010-11-04 16:06:02 ----A---- C:\Windows\SysWOW64\D3DCompiler_38.dll
2010-11-04 16:06:00 ----A---- C:\Windows\SysWOW64\D3DX9_38.dll
2010-11-04 16:05:59 ----A---- C:\Windows\SysWOW64\XAudio2_0.dll
2010-11-04 16:05:59 ----A---- C:\Windows\SysWOW64\xactengine3_0.dll
2010-11-04 16:05:59 ----A---- C:\Windows\SysWOW64\X3DAudio1_3.dll
2010-11-04 16:05:57 ----A---- C:\Windows\SysWOW64\d3dx10_37.dll
2010-11-04 16:05:57 ----A---- C:\Windows\SysWOW64\D3DCompiler_37.dll
2010-11-04 16:05:55 ----A---- C:\Windows\SysWOW64\xactengine2_10.dll
2010-11-04 16:05:55 ----A---- C:\Windows\SysWOW64\D3DX9_37.dll
2010-11-04 16:05:53 ----A---- C:\Windows\SysWOW64\d3dx10_36.dll
2010-11-04 16:05:53 ----A---- C:\Windows\SysWOW64\D3DCompiler_36.dll
2010-11-04 16:05:50 ----A---- C:\Windows\SysWOW64\d3dx9_36.dll
2010-11-04 16:05:49 ----A---- C:\Windows\SysWOW64\xactengine2_9.dll
2010-11-04 16:05:48 ----A---- C:\Windows\SysWOW64\d3dx10_35.dll
2010-11-04 16:05:48 ----A---- C:\Windows\SysWOW64\D3DCompiler_35.dll
2010-11-04 16:05:46 ----A---- C:\Windows\SysWOW64\d3dx9_35.dll
2010-11-04 16:05:45 ----A---- C:\Windows\SysWOW64\xactengine2_8.dll
2010-11-04 16:05:45 ----A---- C:\Windows\SysWOW64\X3DAudio1_2.dll
2010-11-04 16:05:43 ----A---- C:\Windows\SysWOW64\d3dx10_34.dll
2010-11-04 16:05:43 ----A---- C:\Windows\SysWOW64\D3DCompiler_34.dll
2010-11-04 16:05:41 ----A---- C:\Windows\SysWOW64\d3dx9_34.dll
2010-11-04 16:05:40 ----A---- C:\Windows\SysWOW64\xinput1_3.dll
2010-11-04 16:05:39 ----A---- C:\Windows\SysWOW64\xactengine2_7.dll
2010-11-04 16:05:38 ----A---- C:\Windows\SysWOW64\d3dx10_33.dll
2010-11-04 16:05:38 ----A---- C:\Windows\SysWOW64\D3DCompiler_33.dll
2010-11-04 16:05:36 ----A---- C:\Windows\SysWOW64\xactengine2_6.dll
2010-11-04 16:05:36 ----A---- C:\Windows\SysWOW64\d3dx9_33.dll
2010-11-04 16:05:35 ----A---- C:\Windows\SysWOW64\xactengine2_5.dll
2010-11-04 16:05:35 ----A---- C:\Windows\SysWOW64\d3dx10.dll
2010-11-04 16:05:33 ----A---- C:\Windows\SysWOW64\d3dx9_32.dll
2010-11-04 16:05:32 ----A---- C:\Windows\SysWOW64\xactengine2_4.dll
2010-11-04 16:05:32 ----A---- C:\Windows\SysWOW64\x3daudio1_1.dll
2010-11-04 16:05:31 ----A---- C:\Windows\SysWOW64\d3dx9_31.dll
2010-11-04 16:05:30 ----A---- C:\Windows\SysWOW64\xinput1_2.dll
2010-11-04 16:05:30 ----A---- C:\Windows\SysWOW64\xactengine2_3.dll
2010-11-04 16:05:29 ----A---- C:\Windows\SysWOW64\xinput1_1.dll
2010-11-04 16:05:29 ----A---- C:\Windows\SysWOW64\xactengine2_2.dll
2010-11-04 16:05:28 ----A---- C:\Windows\SysWOW64\xactengine2_1.dll
2010-11-04 16:05:22 ----A---- C:\Windows\SysWOW64\d3dx9_30.dll
2010-11-04 16:05:21 ----A---- C:\Windows\SysWOW64\xactengine2_0.dll
2010-11-04 16:05:21 ----A---- C:\Windows\SysWOW64\x3daudio1_0.dll
2010-11-04 16:05:20 ----A---- C:\Windows\SysWOW64\d3dx9_29.dll
2010-11-04 16:05:19 ----A---- C:\Windows\SysWOW64\d3dx9_28.dll
2010-11-04 16:05:17 ----A---- C:\Windows\SysWOW64\d3dx9_27.dll
2010-11-04 16:05:15 ----A---- C:\Windows\SysWOW64\d3dx9_26.dll
2010-11-04 16:05:12 ----A---- C:\Windows\SysWOW64\d3dx9_24.dll
2010-11-02 17:47:21 ----D---- C:\Users\Michał mistrz\AppData\Roaming\Ahead
2010-11-02 17:45:45 ----D---- C:\Users\Michał mistrz\AppData\Roaming\Real
2010-11-02 17:43:45 ----A---- C:\Windows\SysWOW64\TwnLib4.dll
2010-11-02 17:43:45 ----A---- C:\Windows\SysWOW64\imagXRA7.dll
2010-11-02 17:43:45 ----A---- C:\Windows\SysWOW64\imagXR7.dll
2010-11-02 17:43:45 ----A---- C:\Windows\SysWOW64\imagXpr7.dll
2010-11-02 17:43:45 ----A---- C:\Windows\SysWOW64\imagX7.dll
2010-11-02 17:43:44 ----D---- C:\ProgramData\Nero
2010-11-02 17:43:44 ----D---- C:\Program Files (x86)\Nero
2010-11-02 17:43:44 ----D---- C:\Program Files (x86)\Common Files\Ahead
2010-11-01 16:41:51 ----D---- C:\Users\Michał mistrz\AppData\Roaming\Steinberg
2010-10-31 22:45:18 ----D---- C:\ATI
2010-10-27 15:36:42 ----A---- C:\Windows\SysWOW64\CPFilters.dll
2010-10-25 14:58:54 ----A---- C:\Windows\SysWOW64\WMVDECOD.DLL
2010-10-25 14:58:54 ----A---- C:\Windows\SysWOW64\mfreadwrite.dll
2010-10-25 14:58:53 ----A---- C:\Windows\SysWOW64\mf.dll
2010-10-23 14:47:06 ----D---- C:\Users\Michał mistrz\AppData\Roaming\Leadertech
2010-10-23 14:34:38 ----D---- C:\Program Files (x86)\EA Sports
2010-10-21 15:58:13 ----D---- C:\Program Files (x86)\NVIDIA Corporation

======List of files/folders modified in the last 2 months======

2010-12-20 23:58:22 ----D---- C:\Windows\Prefetch
2010-12-20 23:58:12 ----RD---- C:\Program Files (x86)
2010-12-20 23:47:49 ----D---- C:\Windows\Tasks
2010-12-20 22:34:32 ----D---- C:\Users\Michał mistrz\AppData\Roaming\Winamp
2010-12-20 18:09:18 ----SHD---- C:\System Volume Information
2010-12-20 17:40:01 ----D---- C:\Windows\Temp
2010-12-20 15:17:55 ----SHD---- C:\Windows\Installer
2010-12-20 15:17:50 ----SD---- C:\Users\Michał mistrz\AppData\Roaming\Microsoft
2010-12-20 15:17:13 ----D---- C:\Windows
2010-12-20 15:17:12 ----D---- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2010-12-20 14:35:58 ----HD---- C:\ProgramData
2010-12-20 14:35:58 ----D---- C:\Program Files (x86)\Common Files
2010-12-20 11:44:19 ----A---- C:\Windows\SysWOW64\log.txt
2010-12-20 10:50:51 ----RSD---- C:\Windows\assembly
2010-12-19 22:25:11 ----D---- C:\Program Files (x86)\JDownloader
2010-12-19 15:36:55 ----D---- C:\Windows\System32
2010-12-19 15:36:55 ----D---- C:\Windows\inf
2010-12-18 10:25:40 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2010-12-16 23:31:32 ----D---- C:\ProgramData\OpenFM
2010-12-16 22:28:31 ----D---- C:\Windows\winsxs
2010-12-16 22:17:25 ----D---- C:\Windows\SysWOW64
2010-12-16 14:54:27 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2010-12-16 14:54:27 ----D---- C:\Program Files (x86)\Rockstar Games
2010-12-16 12:31:56 ----D---- C:\Windows\rescache
2010-12-16 10:37:10 ----RD---- C:\Program Files
2010-12-16 10:29:12 ----D---- C:\Windows\SysWOW64\pl-PL
2010-12-16 10:29:09 ----D---- C:\Program Files (x86)\Windows Mail
2010-12-16 10:29:08 ----D---- C:\Windows\SysWOW64\migration
2010-12-16 10:29:08 ----D---- C:\Program Files (x86)\Internet Explorer
2010-12-16 00:11:05 ----D---- C:\Program Files (x86)\Microsoft Works
2010-12-16 00:10:43 ----D---- C:\ProgramData\Microsoft Help
2010-12-15 22:49:52 ----D---- C:\Michał
2010-12-13 20:37:03 ----D---- C:\Users\Michał mistrz\AppData\Roaming\Gadu-Gadu 10
2010-12-12 14:57:54 ----RSD---- C:\Windows\Fonts
2010-12-11 20:07:35 ----D---- C:\Users\Michał mistrz\AppData\Roaming\Audacity
2010-12-11 10:15:58 ----D---- C:\Program Files (x86)\Mozilla Firefox
2010-11-18 17:34:54 ----D---- C:\Users\Michał mistrz\AppData\Roaming\FileZilla
2010-11-16 22:23:57 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2010-11-16 18:37:21 ----D---- C:\Program Files (x86)\Real Alternative
2010-11-15 20:47:24 ----D---- C:\Windows\SysWOW64\directx
2010-11-15 20:47:16 ----HD---- C:\Windows\msdownld.tmp
2010-11-15 19:03:14 ----D---- C:\Program Files (x86)\SystemRequirementsLab
2010-11-14 20:49:04 ----D---- C:\Program Files (x86)\Steam
2010-11-14 19:38:01 ----D---- C:\Program Files (x86)\Common Files\Steam
2010-11-11 20:26:01 ----AD---- C:\ProgramData\Temp
2010-11-09 13:32:14 ----D---- C:\Windows\Microsoft.NET
2010-11-08 23:30:32 ----D---- C:\Windows\SysWOW64\en-US
2010-11-08 23:30:30 ----D---- C:\Program Files (x86)\Microsoft.NET
2010-11-08 23:28:33 ----D---- C:\Program Files (x86)\Windows Live
2010-11-08 23:27:05 ----SD---- C:\ProgramData\Microsoft
2010-11-08 23:26:34 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2010-11-08 23:26:18 ----D---- C:\Windows\SoftwareDistribution
2010-11-04 16:06:29 ----D---- C:\Program Files (x86)\OpenAL
2010-11-04 16:06:29 ----A---- C:\Windows\SysWOW64\wrap_oal.dll
2010-11-04 16:06:29 ----A---- C:\Windows\SysWOW64\OpenAL32.dll
2010-11-01 16:09:21 ----D---- C:\Program Files (x86)\Acer GameZone
2010-11-01 10:48:07 ----D---- C:\Program Files (x86)\Syncrosoft
2010-10-31 23:22:43 ----D---- C:\AMD
2010-10-31 23:22:41 ----D---- C:\ProgramData\Symantec
2010-10-31 23:22:39 ----D---- C:\Windows\registration
2010-10-31 23:22:39 ----D---- C:\Windows\AppCompat
2010-10-28 15:00:50 ----D---- C:\Windows\AppPatch
2010-10-27 22:34:36 ----D---- C:\Windows\ehome
2010-10-23 14:21:19 ----D---- C:\Program Files (x86)\Ubisoft
2010-10-21 15:58:08 ----D---- C:\Program Files (x86)\AGEIA Technologies

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 DwProt;DrWeb Protection; C:\Windows\system32\drivers\dwprot.sys []
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys []
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys []
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys []
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys []
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys []
R2 TurboB;Turbo Boost UI Monitor driver; C:\Windows\system32\DRIVERS\TurboB.sys []
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys []
R3 AmUStor;AM USB Stroage Driver; C:\Windows\system32\drivers\AmUStor.SYS []
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys []
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 DKbFltr;Dritek Keyboard Filter Driver (64-bit); C:\Windows\SysWOW64\Drivers\DKbFltr.sys [2009-03-26 25608]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys []
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys []
R3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys []
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\Windows\system32\DRIVERS\seehcri.sys []
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys []
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys []
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys []
S0 SpiderG3;DrWeb file system scanner; C:\Windows\system32\drivers\spiderg3.sys []
S3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
S3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys []
S3 anombxw5;anombxw5; C:\Windows\SysWOW64\drivers\anombxw5.sys []
S3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl664.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys []
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys []
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys []
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys []
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys []
S3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20); C:\Windows\system32\DRIVERS\L1E62x64.sys []
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agr64svc.exe [2009-03-28 16896]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe []
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2010-11-04 135336]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2010-12-11 267944]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2009-09-30 844320]
R2 Greg_Service;GRegService; C:\Program Files (x86)\Acer\Registration\GregHSRW.exe [2009-08-28 1150496]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-06-05 354840]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-10-01 268824]
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-09-25 62720]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-06-18 144640]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2010-07-10 75064]
R2 SpyHunter 4 Service;SpyHunter 4 Service; C:\PROGRA~2\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [2010-11-05 327000]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2320920]
R2 Updater Service;Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 DrWebEngine;Dr.Web Scanning Engine (DrWebEngine); C:\Program Files (x86)\Common Files\Doctor Web\Scanning Engine\dwengine.exe [2010-12-14 1660248]
S2 gupdate;Usługa Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-06-30 135664]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-07-01 654848]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-11-05 182768]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-06-18 50432]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2010-11-14 403240]
S3 TurboBoost;TurboBoost; C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2009-11-02 126352]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

-----------------EOF-----------------
[/log]

Tomek01
komentarz
komentarz

W trybie awaryjnym uruchom OTL. W oknie Custom scan/fixes wklej:
[code]:Processes
Explorer.exe

:OTL
PRC - [2010/12/19 23:55:24 | 000,221,696 | ---- | M] (Windows ® Codename Longhorn DDK provider) -- C:\Users\MICHAM~1\AppData\Local\Temp\Wcd.exe
PRC - [2010/12/19 23:54:53 | 000,218,624 | ---- | M] (Windows ® Codename Longhorn DDK provider) -- C:\Users\MICHAM~1\AppData\Local\Temp\Wcc.exe
PRC - [2010/12/19 23:54:34 | 000,211,968 | ---- | M] (Windows ® Codename Longhorn DDK provider) -- C:\Windows\Wvucia.exe
IE - HKLM\..\URLSearchHook: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-1070666057-106192516-1559153215-1000\..\URLSearchHook: {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll (Conduit Ltd.)
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}"
FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.6.9.134
[2010/07/20 13:02:21 | 000,000,000 | ---D | M] (DVDVideoSoftTB Toolbar) -- C:\Users\Michał mistrz\AppData\Roaming\mozilla\Firefox\Profiles\xa7uy0to.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2010/07/29 21:57:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Michał mistrz\AppData\Roaming\mozilla\Firefox\Profiles\xa7uy0to.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010/10/02 13:03:34 | 000,000,000 | ---D | M] -- C:\Users\Michał mistrz\AppData\Roaming\mozilla\Firefox\Profiles\xa7uy0to.default\extensions\toolbar@ask.com
[2010/07/20 13:03:05 | 000,000,873 | ---- | M] () -- C:\Users\Michał mistrz\AppData\Roaming\Mozilla\FireFox\Profiles\xa7uy0to.default\searchplugins\conduit.xml
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com)
O2 - BHO: (free-downloads.net Toolbar) - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll (Conduit Ltd.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (free-downloads.net Toolbar) - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1070666057-106192516-1559153215-1000\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKU\S-1-5-21-1070666057-106192516-1559153215-1000\..\Toolbar\WebBrowser: (free-downloads.net Toolbar) - {ECDEE021-0D17-467F-A1FF-C7A115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKU\S-1-5-21-1070666057-106192516-1559153215-1000..\Run: [JP595IR86O] C:\Users\MICHAM~1\AppData\Local\Temp\Wcc.exe (Windows ® Codename Longhorn DDK provider)
O4 - HKU\S-1-5-21-1070666057-106192516-1559153215-1000..\Run: [NtWqIVLZEWZU] C:\Users\MICHAM~1\AppData\Local\Temp\Wcd.exe (Windows ® Codename Longhorn DDK provider)
O4:64bit: - HKLM..\RunOnce: [DrWebScanner] C:\Program Files (x86)\DrWeb\drweb32w.exe (Doctor Web, Ltd.)
@Alternate Data Stream - 146 bytes -> C:\ProgramData\Temp:AB689DEA
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:93DE1838

:Files
C:\Windows\Wvucia.exe
C:\Users\MICHAM~1\AppData\Local\Temp\Wcd.exe
C:\Users\MICHAM~1\AppData\Local\Temp\Wcc.exe
C:\Users\Michał mistrz\AppData\Local\119614890736297204
C:\Users\Michał mistrz\AppData\Local\119611678100759796
C:\Users\Michał mistrz\AppData\Local\119614890734593268
C:\Users\Michał mistrz\AppData\Local\119611678099055860
C:\Users\Michał mistrz\AppData\Local\AskToolbar
C:\Users\Michał mistrz\AppData\Local\Temp*.html
C:\Windows\tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
C:\Windows\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
C:\Users\Michał mistrz\AppData\Roaming\.#
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\Tasks\Dr.Web Daily scan.job
C:\Windows\Tasks\Dr.Web Update.job
C:\Program Files (x86)\free-downloads.net
C:\Program Files (x86)\Ask.com

:Reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{ecdee021-0d17-467f-a1ff-c7a115230949}=-
{D4027C7F-154A-4066-A1AD-4243D8127440}=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"JP595IR86O"=-
"NtWqIVLZEWZU"=-

:Commands
[emptytemp]
[start explorer]
[Reboot][/code]

Klikasz run fix, komputer uruchamia się ponownie.
Wrzuć log z usuwania oraz nowe logi: OTL i RSIT

Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!

Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.

×
×
  • Dodaj nową pozycję...

Powiadomienie o plikach cookie

Strona wykorzystuje pliki cookies w celu prawidłowego świadczenia usług i wygody użytkowników. Warunki przechowywania i dostępu do plików cookies możesz zmienić w ustawieniach przeglądarki.