adam205 utworzono 30 grudnia 2012 utworzono 30 grudnia 2012 [color=#333333]Witam serdecznie,[/color] [color=#333333]Problem polega na tym, że prawdopodobnie komputer złapał jakiegoś wirusa, może inaczej - na pewno złapał, problem w tym, że nie wiem, czy dobrze sobie z nim poradziłem. Nie jestem raczej obyty w kwestii zabezpieczania komputera, dlatego po kolei opiszę co zrobiłem. [/color] [color=#333333]Wszystko zaczęło się - moim zdaniem - od użycia pen drive'a znajomego. Skopiowałem stamtąd to, co potrzebowałem po czym usunąłem sprzęt. Wszedłem akurat w folder w którym zainstalowane są wszystkie moje programy (nie jest to partycja systemowa) i ku mojemu zdziwieniu programy zaczęły nagle znikać. Z listy około 25 zostały 3: Avast, Daemon i iTunes. Na moich oczach wszystkie pozostałe znikały, jak się później okazało, dość profesjonalnie, bo zostały po nich jedynie ikony szybkiego uruchamiania (sprawdzone za pomocą Revo Uninstaller). [/color] [color=#333333]Nie wiedziałem za bardzo co mogę zrobić w tej kwestii, próbowałem przywracania systemu, jednak to nie pomogło. Usunąłem resztki tych programów po czym te niezbędne zainstalowałem ponownie. Wykonałem skan, najpierw Avastem później Malwarebytes'em, pierwszy nie wykazał nic, LOG z drugiego załączam poniżej. Proszę o poradę co powinienem zrobić teraz, tego, że powinienem skanować pen drive'a przed użyciem, już boleśnie się nauczyłem. Złączam też LOGi z OTL[/color] [color=#333333]Pozdrawiam,[/color] [color=#333333]Adam[/color] Malwarebytes: [url="http://www.wklej.org/id/910279/"]http://www.wklej.org/id/910279/[/url] [color=#333333]Raport OTL: [/color][url="http://www.wklej.org/id/910241/"]http://www.wklej.org/id/910241/[/url] [color=#333333]Raport Extras: [/color][url="http://www.wklej.org/id/910244/"]http://www.wklej.org/id/910244/[/url]
mac_iek13 komentarz 30 grudnia 2012 komentarz 30 grudnia 2012 przeskanuj tym programem http://www.dobreprogramy.pl/Dr.WEB-CureIt,Program,Windows,12976.html i usuń wszystko co znajdzie
adam205 komentarz 30 grudnia 2012 Autor komentarz 30 grudnia 2012 znalazło coś takiego: Adware,BGuard.3 - usunąłem
mac_iek13 komentarz 30 grudnia 2012 komentarz 30 grudnia 2012 i jeszcze tym przeskanuj http://www.dobreprogramy.pl/Spybot-Search-Destroy,Program,Windows,12546.html wydaje mi się że to będzie na tyle, jeszcze tylko zaktualizuj bazę wirusów i program avast
adam205 komentarz 30 grudnia 2012 Autor komentarz 30 grudnia 2012 nie mogę go pobrać ani z Dobrych Programów, ani z żadnego innego serwera, wygląda to tak, że po uruchomieniu pobierania mam maksymalną prędkość downloadu a w pewnym momencie wielkość pobranych danych zatrzymuje się i transfer spada co 0,1 kb/s co ok. 2 sek.. Nie jest to normalne i nie wiem czy nie ma związku z problemem w temacie..udało się ze starszą wersją, miałeś rację, Spybot znalazł takie szkodniki: - Babylon. Toolbar (4) - Complitly (14) - SweetIM (4) w sumie 22 wpisy w rejestrze. Kliknąłem żeby naprawiało i okazało się że 20 nie może naprawić. Zaleciło skanowanie po ponownym uruchomieniu. Właśnie je wykonuje. Masz może jakieś rady ? Dzięki za zaangażowanie, mi już ręce opadają a muszę pracować na nim...nie usunęło, nadal 20 wpisów których nie można naprawić.
adam205 komentarz 30 grudnia 2012 Autor komentarz 30 grudnia 2012 20 wpisów nie można było naprawić. Po restarcie i ponownym skanie było to samo, tylko że zaczęło od 20 problemów i żadnego nie naprawiło. W tej chwili próbuję jeszcze Ad-Aware...
mac_iek13 komentarz 30 grudnia 2012 komentarz 30 grudnia 2012 avasta jeszcze spróbuj zaktualizować i nim przeskanować
adam205 komentarz 31 grudnia 2012 Autor komentarz 31 grudnia 2012 Avast poddał się jeszcze przed tymi trzema.. Teraz idę spać bo i ja i komp mamy dość, jutro powalczymy chociaż trochę. Dziękijakieś propozycje ? od rana zrobiłem skan Ad-Awarem, po 3h znalazlo 4 bledy, usuniete.
Natsuki Kuga komentarz 1 stycznia 2013 komentarz 1 stycznia 2013 Spybot obecnie nie nadaje się do skanowania systemu pod kątem wirusów - nie jest na tyle skuteczny by sprostać dzisiejszym standardom. Autorze, pokaż nowe logi z OTL i log z RSIT (instrukcje znajdziesz w przyklejonych).
adam205 komentarz 1 stycznia 2013 Autor komentarz 1 stycznia 2013 log z RSIT: [log] Logfile of random's system information tool 1.09 (written by random/random) Run by Adam at 2013-01-01 15:56:49 Microsoft Windows 7 Home Premium Service Pack 1 System drive C: has 224 GB (73%) free of 305 GB Total RAM: 4074 MB (56% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 15:56:54, on 2013-01-01 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v8.00 (8.00.7601.17514) Boot mode: Normal Running processes: C:\ProgramData\DatacardService\DCSHelper.exe D:\Programy\Daemon Tools Pro\DTShellHlp.exe C:\Users\Adam\AppData\Local\Akamai\netsession_win.exe C:\Users\Adam\AppData\Local\Akamai\netsession_win.exe D:\Programy\Avast\AvastUI.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoDashboard.exe C:\Program Files (x86)\Memeo\AutoBackup\InstantBackup.exe C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe C:\Users\Adam\Desktop\RSIT.exe C:\Program Files (x86)\trend micro\Adam.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba.msn.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=PL&userid=ee3dca77-17dd-422c-adaa-c020d3ecccc3&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=PL&userid=ee3dca77-17dd-422c-adaa-c020d3ecccc3&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.soft-quick.info/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.soft-quick.info/ R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=PL&userid=ee3dca77-17dd-422c-adaa-c020d3ecccc3&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=PL&userid=ee3dca77-17dd-422c-adaa-c020d3ecccc3&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe, O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: VshareComplete - {222f31fb-a14e-4af2-bb14-997f28294370} - C:\Users\Adam\AppData\Roaming\VshareComplete\VshareComplete.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Programy\Avast\aswWebRepIE.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll O2 - BHO: IplexToALLPlayer - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - D:\Programy\ALLPlayer\Iplex\IplexToALLPlayer.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O3 - Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - (no file) O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Programy\Avast\aswWebRepIE.dll O4 - HKLM\..\Run: [avast5] "D:\Programy\Avast\avastUI.exe" /nogui O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [Memeo Instant Backup] C:\Program Files (x86)\Memeo\AutoBackup\MemeoLauncher2.exe --silent --no_ui O4 - HKLM\..\Run: [Memeo AutoSync] C:\Program Files (x86)\Memeo\AutoSync\MemeoLauncher2.exe --silent O4 - HKLM\..\Run: [Seagate Dashboard] C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoLauncher.exe --silent --no_ui O4 - HKLM\..\Run: [Ad-Aware Antivirus] "D:\Programy\Ad-Aware\AdAwareLauncher" --windows-run O4 - HKCU\..\Run: [Google Update] "C:\Users\Adam\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [ALLUpdate] "D:\Programy\ALLPlayer\ALLUpdate.exe" "sleep" O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Adam\AppData\Local\Akamai\netsession_win.exe" O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Programy\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'USŁUGA LOKALNA') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'USŁUGA LOKALNA') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'USŁUGA SIECIOWA') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'USŁUGA SIECIOWA') O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Wyślij &do programu OneNote - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105 O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL O9 - Extra button: Pokaż lub ukryj HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{A9E0C5C0-9E6A-410A-8719-DD8EAFE4AB0C}: NameServer = 213.158.199.1 213.158.199.5 O17 - HKLM\System\CCS\Services\Tcpip\..\{F3591DBC-AF36-469B-87F5-DC25CE0EB967}: NameServer = 213.158.199.1 213.158.199.5 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - AppInit_DLLs: c:\progra~2\contin~1\sprote~1.dll c:\progra~2\softqu~1\sprote~1.dll O23 - Service: Ad-Aware Service - Lavasoft Limited - D:\Programy\Ad-Aware\AdAwareService.exe O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Autodesk Network Licensing Service - Autodesk, Inc. - C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskNetSrv.exe O23 - Service: avast! Antivirus - AVAST Software - D:\Programy\Avast\AvastSvc.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe O23 - Service: HWDeviceService64.exe - Unknown owner - C:\ProgramData\DatacardService\HWDeviceService64.exe O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: Internet Manager. OUC (Internet Manager. RunOuc) - Unknown owner - D:\Programy\UpdateDog\ouc.exe (file missing) O23 - Service: Usługa iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: MemeoBackgroundService - Memeo - C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Ad-Aware (SBAMSvc) - GFI Software - D:\Programy\Ad-Aware\SBAMSvc.exe O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - D:\Programy\Spybot - Search & Destroy\SDWinSec.exe O23 - Service: Seagate Dashboard Service (SeagateDashboardService) - Memeo - C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing) O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 13809 bytes ======Scheduled tasks folder====== C:\Windows\tasks\Adobe Flash Player Updater.job C:\Windows\tasks\ContinueToSaveUpdaterTask{EE3D1E2A-0D0C-4142-BEAC-D554184FF8B1}.job C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-319703930-2572490357-2975701463-1000Core.job C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-319703930-2572490357-2975701463-1000UA.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}] HP Print Enhancer - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22 328248] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{222f31fb-a14e-4af2-bb14-997f28294370}] VshareComplete - C:\Users\Adam\AppData\Roaming\VshareComplete\VshareComplete.dll [2011-12-18 139768] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-09-24 449512] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] avast! WebRep - D:\Programy\Avast\aswWebRepIE.dll [2012-10-30 1227736] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}] Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-11-10 393600] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-09-24 155384] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF925EF3-7A87-44E4-9CAF-8D7B280BF616}] IplexToALLPlayer - D:\Programy\ALLPlayer\Iplex\IplexToALLPlayer.dll [2011-02-09 400384] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}] HP Smart BHO Class - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22 517688] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {ae07101b-46d4-4a98-af68-0333ea26e113} {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - D:\Programy\Avast\aswWebRepIE.dll [2012-10-30 1227736] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "avast5"=D:\Programy\Avast\avastUI.exe [2012-10-30 4297136] ""= [] "SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848] "Memeo Instant Backup"=C:\Program Files (x86)\Memeo\AutoBackup\MemeoLauncher2.exe [2011-05-04 136416] "Memeo AutoSync"=C:\Program Files (x86)\Memeo\AutoSync\MemeoLauncher2.exe [2011-05-05 144608] "Seagate Dashboard"=C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoLauncher.exe [2011-06-01 79112] "Ad-Aware Antivirus"=D:\Programy\Ad-Aware\AdAwareLauncher --windows-run [] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Google Update"=C:\Users\Adam\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-25 116648] "ALLUpdate"=D:\Programy\ALLPlayer\ALLUpdate.exe [2012-10-08 2991616] "Akamai NetSession Interface"=C:\Users\Adam\AppData\Local\Akamai\netsession_win.exe [2012-10-09 4441920] "SpybotSD TeaTimer"=D:\Programy\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="c:\progra~2\contin~1\sprote~1.dll c:\progra~2\softqu~1\sprote~1.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ad-Aware Service] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MSIServer] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SBAMSvc] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableLockWorkstation"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "EnableUIADesktopToggle"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "ForceActiveDesktopOn"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "vidc.uyvy"=msyuv.dll "vidc.yuy2"=msyuv.dll "vidc.yvyu"=msyuv.dll "vidc.iyuv"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "vidc.yvu9"=tsbyuv.dll "msacm.l3acm"=l3codeca.acm "vidc.cvid"=iccvid.dll "msacm.siren"=sirenacm.dll "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "wave3"=wdmaud.drv "midi3"=wdmaud.drv "mixer3"=wdmaud.drv "wave4"=wdmaud.drv "midi4"=wdmaud.drv "mixer4"=wdmaud.drv "wave2"=wdmaud.drv "midi2"=wdmaud.drv "mixer2"=wdmaud.drv "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "vidc.iv31"=ir32_32.dll "vidc.iv32"=ir32_32.dll "vidc.iv41"=ir41_32.ax "vidc.iv50"=ir50_32.dll "VIDC.XVID"=xvidvfw.dll "VIDC.YV12"=xvidvfw.dll "msacm.ac3acm"=ac3acm.acm "msacm.lameacm"=lameACM.acm "VIDC.FFDS"=ff_vfw.dll "vidc.VP60"=C:\Windows\system32\vp6vfw.dll "vidc.VP61"=C:\Windows\system32\vp6vfw.dll ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* .scr - open - C:\Windows\system32\notepad.exe "%1" .scr - install - .scr - config - ======List of files/folders created in the last 1 month====== 2013-01-01 15:51:58 ----D---- C:\Program Files (x86)\trend micro 2013-01-01 15:51:57 ----D---- C:\rsit 2012-12-31 00:12:36 ----D---- C:\ProgramData\Ad-Aware Antivirus 2012-12-31 00:12:23 ----D---- C:\Users\Adam\AppData\Roaming\LavasoftStatistics 2012-12-31 00:02:09 ----D---- C:\ProgramData\Lavasoft 2012-12-31 00:00:00 ----D---- C:\ProgramData\blekko toolbars 2012-12-30 23:59:54 ----D---- C:\Program Files (x86)\adawaretb 2012-12-30 23:59:53 ----D---- C:\Program Files (x86)\Toolbar Cleaner 2012-12-30 23:57:48 ----D---- C:\Users\Adam\AppData\Roaming\Ad-Aware Antivirus 2012-12-30 23:02:50 ----D---- C:\ProgramData\Spybot - Search & Destroy 2012-12-29 17:11:37 ----D---- C:\ProgramData\Applications 2012-12-29 15:59:10 ----HD---- C:\Program Files (x86)\InstallJammer Registry 2012-12-29 15:58:37 ----D---- C:\Program Files (x86)\Soldis PROJEKTANT 2012-12-29 15:41:09 ----D---- C:\ProgramData\WoW Worldwide Software LTD 2012-12-29 15:41:09 ----D---- C:\Program Files (x86)\SoftQuick 2012-12-29 15:40:58 ----D---- C:\ProgramData\Premium 2012-12-29 15:40:53 ----D---- C:\Program Files (x86)\ContinueToSave 2012-12-29 15:40:01 ----D---- C:\ProgramData\InstallMate 2012-12-29 15:39:31 ----D---- C:\Program Files (x86)\NapiProjekt 2012-12-29 12:52:01 ----D---- C:\Users\Adam\AppData\Roaming\Malwarebytes 2012-12-29 12:51:49 ----D---- C:\ProgramData\Malwarebytes 2012-12-22 01:53:19 ----A---- C:\Windows\SysWOW64\atmlib.dll 2012-12-22 01:53:16 ----A---- C:\Windows\SysWOW64\atmfd.dll 2012-12-15 16:22:56 ----D---- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2012-12-14 19:00:41 ----RD---- C:\Program Files (x86)\Skype 2012-12-14 19:00:41 ----D---- C:\Program Files (x86)\Common Files\Skype 2012-12-12 08:58:53 ----A---- C:\Windows\SysWOW64\tzres.dll 2012-12-12 08:58:36 ----A---- C:\Windows\SysWOW64\urlmon.dll 2012-12-12 08:58:36 ----A---- C:\Windows\SysWOW64\mshtml.dll 2012-12-12 08:58:36 ----A---- C:\Windows\SysWOW64\ieframe.dll 2012-12-12 08:58:35 ----A---- C:\Windows\SysWOW64\wininet.dll 2012-12-12 08:58:34 ----A---- C:\Windows\SysWOW64\mshtmled.dll 2012-12-12 08:58:34 ----A---- C:\Windows\SysWOW64\msfeeds.dll 2012-12-12 08:58:34 ----A---- C:\Windows\SysWOW64\ieui.dll 2012-12-12 08:58:34 ----A---- C:\Windows\SysWOW64\iertutil.dll 2012-12-12 08:58:33 ----A---- C:\Windows\SysWOW64\url.dll 2012-12-12 08:58:33 ----A---- C:\Windows\SysWOW64\jsproxy.dll 2012-12-12 08:58:23 ----A---- C:\Windows\SysWOW64\KernelBase.dll 2012-12-12 08:58:23 ----A---- C:\Windows\SysWOW64\kernel32.dll 2012-12-12 08:58:22 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2012-12-12 08:58:22 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2012-12-12 08:58:22 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2012-12-12 08:58:22 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2012-12-12 08:58:22 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2012-12-12 08:58:22 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2012-12-12 08:58:22 ----A---- C:\Windows\SysWOW64\wow32.dll 2012-12-12 08:58:22 ----A---- C:\Windows\SysWOW64\setup16.exe 2012-12-12 08:58:22 ----A---- C:\Windows\SysWOW64\ntvdm64.dll 2012-12-12 08:58:22 ----A---- C:\Windows\SysWOW64\instnm.exe 2012-12-12 08:58:21 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2012-12-12 08:58:21 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2012-12-12 08:58:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2012-12-12 08:58:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2012-12-12 08:58:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2012-12-12 08:58:17 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2012-12-12 08:58:17 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2012-12-12 08:58:17 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2012-12-12 08:58:17 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2012-12-12 08:58:17 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2012-12-12 08:58:17 ----A---- C:\Windows\SysWOW64\user.exe 2012-12-12 08:58:01 ----A---- C:\Windows\SysWOW64\dpnet.dll ======List of files/folders modified in the last 1 month====== 2013-01-01 15:56:03 ----D---- C:\Windows\Temp 2013-01-01 15:51:58 ----RD---- C:\Program Files (x86) 2013-01-01 14:27:12 ----D---- C:\Windows\System32 2013-01-01 14:27:12 ----D---- C:\Windows\inf 2013-01-01 14:25:24 ----SHD---- C:\System Volume Information 2013-01-01 14:13:45 ----A---- C:\Windows\SysWOW64\log.txt 2012-12-31 13:17:49 ----HD---- C:\ProgramData 2012-12-31 10:08:15 ----D---- C:\Windows\Prefetch 2012-12-31 00:11:49 ----D---- C:\Windows\SysWOW64 2012-12-31 00:02:16 ----SHD---- C:\Windows\Installer 2012-12-31 00:02:09 ----D---- C:\Program Files (x86)\Common Files\microsoft shared 2012-12-30 18:52:09 ----D---- C:\Autodesk 2012-12-30 11:06:35 ----D---- C:\Windows 2012-12-30 00:34:18 ----D---- C:\Program Files (x86)\Common Files\Autodesk Shared 2012-12-29 19:11:22 ----D---- C:\Users\Adam\AppData\Roaming\GanymedeNet 2012-12-29 15:40:59 ----D---- C:\Windows\Tasks 2012-12-29 15:39:25 ----D---- C:\Program Files (x86)\ALLMediaServer 2012-12-29 15:25:27 ----D---- C:\Windows\debug 2012-12-29 15:15:09 ----D---- C:\ProgramData\Nero 2012-12-29 15:15:09 ----D---- C:\Program Files (x86)\Common Files 2012-12-29 15:15:06 ----D---- C:\Windows\ehome 2012-12-29 14:55:47 ----RD---- C:\Program Files 2012-12-29 14:47:10 ----D---- C:\Program Files (x86)\StartSearch plugin 2012-12-29 12:32:01 ----D---- C:\ProgramData\DatacardService 2012-12-29 12:30:37 ----D---- C:\Windows\AppCompat 2012-12-29 12:30:37 ----D---- C:\Users\Adam\AppData\Roaming\uTorrent 2012-12-29 12:30:37 ----D---- C:\ProgramData\FLEXnet 2012-12-29 12:30:36 ----D---- C:\Windows\registration 2012-12-23 00:25:13 ----D---- C:\Users\Adam\AppData\Roaming\Skype 2012-12-22 11:40:41 ----D---- C:\Windows\winsxs 2012-12-15 16:22:56 ----D---- C:\Program Files (x86)\Common Files\Apple 2012-12-14 20:43:52 ----D---- C:\Windows\rescache 2012-12-14 19:00:51 ----D---- C:\ProgramData\Skype 2012-12-13 12:07:48 ----D---- C:\Windows\SysWOW64\pl-PL 2012-12-13 12:07:48 ----D---- C:\Windows\SysWOW64\migration 2012-12-13 12:07:48 ----D---- C:\Program Files (x86)\Internet Explorer 2012-12-13 12:07:36 ----D---- C:\Windows\AppPatch 2012-12-13 02:45:48 ----D---- C:\ProgramData\Microsoft Help 2012-12-11 22:28:13 ----A---- C:\Windows\SysWOW64\FlashPlayerApp.exe 2012-12-05 06:52:18 ----D---- C:\Users\Adam\AppData\Roaming\Autodesk ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 BMLoad;Bytemobile Boot Time Load Driver; C:\Windows\system32\drivers\BMLoad.sys [] R0 gfibto;gfibto; C:\Windows\system32\drivers\gfibto.sys [] R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [] R0 LPCFilter;LPC Lower Filter Driver; C:\Windows\system32\DRIVERS\LPCFilter.sys [] R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [] R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [] R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2011-03-18 29592] R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [] R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [] R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [] R1 aswSnx;aswSnx; C:\Windows\SysWOW64\drivers\aswSnx.sys [] R1 aswSP;aswSP; C:\Windows\SysWOW64\drivers\aswSP.sys [] R1 aswTdi;avast! Network Shield Support; C:\Windows\SysWOW64\drivers\aswTdi.sys [] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [] R1 tcpipBM;Bytemobile Kernel Network Provider; \??\C:\Windows\system32\drivers\tcpipBM.sys [] R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [] R2 aswFsBlk;aswFsBlk; C:\Windows\SysWOW64\drivers\aswFsBlk.sys [] R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [] R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [] R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [] R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [] R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [] R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [] R3 ROCKEYNT;Feitian ROCKEY4 Device Service; C:\Windows\system32\DRIVERS\Rockey4.sys [] R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [] R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver; C:\Windows\system32\DRIVERS\rtl8192Ce.sys [] R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [] R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [] R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [] S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [] S3 androidusb;SAMSUNG Android Composite ADB Interface Driver; C:\Windows\System32\Drivers\ssadadb.sys [] S3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [] S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [] S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [] S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [] S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [] S3 ew_usbenumfilter;huawei_CompositeFilter; C:\Windows\system32\DRIVERS\ew_usbenumfilter.sys [] S3 huawei_cdcacm;huawei_cdcacm; C:\Windows\system32\DRIVERS\ew_jucdcacm.sys [] S3 huawei_ext_ctrl;huawei_ext_ctrl; C:\Windows\system32\DRIVERS\ew_juextctrl.sys [] S3 huawei_wwanecm;huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [] S3 s0016bus;Sony Ericsson Device 0016 driver (WDM); C:\Windows\system32\DRIVERS\s0016bus.sys [] S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s0016mdfl.sys [] S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s0016mdm.sys [] S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s0016mgmt.sys [] S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS); C:\Windows\system32\DRIVERS\s0016nd5.sys [] S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s0016obex.sys [] S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM); C:\Windows\system32\DRIVERS\s0016unic.sys [] S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\ssadbus.sys [] S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\Windows\system32\DRIVERS\ssadmdfl.sys [] S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\Windows\system32\DRIVERS\ssadmdm.sys [] S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\Windows\system32\DRIVERS\ssadserd.sys [] S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [] S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [] S3 usbscan;Sterownik skanera USB; C:\Windows\system32\DRIVERS\usbscan.sys [] S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 Ad-Aware Service;Ad-Aware Service; D:\Programy\Ad-Aware\AdAwareService.exe [2012-12-14 1236968] R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960] R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-08-11 55184] R2 avast! Antivirus;avast! Antivirus; D:\Programy\Avast\AvastSvc.exe [2012-10-30 44808] R2 hpqddsvc;Usługa HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2009-07-14 20992] R2 HWDeviceService64.exe;HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [2011-03-14 346976] R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2010-08-04 1809920] R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-02-01 326168] R2 MemeoBackgroundService;MemeoBackgroundService; C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe [2011-05-04 25824] R2 NVSvc;NVIDIA Driver Helper Service; C:\Windows\system32\nvvsvc.exe [] R2 SBSDWSCService;SBSD Security Center Service; D:\Programy\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] R2 SeagateDashboardService;Seagate Dashboard Service; C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe [2011-06-01 14088] R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [] R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-01 2656280] R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976] R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 20992] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] S2 Internet Manager. RunOuc;Internet Manager. OUC; D:\Programy\UpdateDog\ouc.exe [] S2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992] S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992] S2 SBAMSvc;Ad-Aware; D:\Programy\Ad-Aware\SBAMSvc.exe [2012-09-20 3677000] S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-11 250808] S3 aspnet_state;„Usługa stanu ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376] S3 Autodesk Network Licensing Service;Autodesk Network Licensing Service; C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskNetSrv.exe [2008-06-13 1539224] S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-10-13 1431888] S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-11-09 1045256] S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2011-12-09 135584] S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632] S3 iPod Service;Usługa iPod; C:\Program Files\iPod\bin\iPodService.exe [2012-12-12 641504] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696] S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [] S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240] S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240] S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240] S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] -----------------EOF----------------- [/log] Logi z OTL: [log] OTL logfile created on: 1/1/2013 4:04:12 PM - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Adam\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000409 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3.98 Gb Total Physical Memory | 2.06 Gb Available Physical Memory | 51.81% Memory free 7.95 Gb Paging File | 5.79 Gb Available in Paging File | 72.80% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 298.09 Gb Total Space | 218.89 Gb Free Space | 73.43% Space Free | Partition Type: NTFS Drive D: | 297.69 Gb Total Space | 189.31 Gb Free Space | 63.59% Space Free | Partition Type: NTFS Computer Name: ADAM-TOSHIBA | User Name: Adam | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: Off | File Age = 60 Days [color=#E56717]========== Processes (All) ==========[/color] PRC - [2012/12/30 11:10:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Adam\Desktop\OTL.exe PRC - [2012/12/14 20:38:46 | 001,236,968 | ---- | M] (Lavasoft Limited) -- D:\Programy\Ad-Aware\AdAwareService.exe PRC - [2012/12/05 02:15:17 | 001,242,728 | ---- | M] (Google Inc.) -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe PRC - [2012/10/30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- D:\Programy\Avast\AvastUI.exe PRC - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- D:\Programy\Avast\AvastSvc.exe PRC - [2012/10/09 10:53:36 | 004,441,920 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Adam\AppData\Local\Akamai\netsession_win.exe PRC - [2012/08/11 15:43:06 | 000,055,184 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe PRC - [2012/07/27 12:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012/07/03 08:04:54 | 000,252,848 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe PRC - [2012/04/26 13:33:16 | 002,743,104 | ---- | M] (DT Soft Ltd) -- D:\Programy\Daemon Tools Pro\DTShellHlp.exe PRC - [2011/06/01 17:42:28 | 000,071,432 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoDashboard.exe PRC - [2011/06/01 17:42:28 | 000,014,088 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe PRC - [2011/06/01 17:16:54 | 002,260,992 | ---- | M] (Axentra Corporation) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe PRC - [2011/05/04 22:10:28 | 000,325,344 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\InstantBackup.exe PRC - [2011/03/14 16:27:28 | 000,236,384 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe PRC - [2011/02/01 12:24:42 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe PRC - [2011/02/01 12:24:40 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe PRC - [2010/08/04 16:11:34 | 001,809,920 | ---- | M] (Realsil Microelectronics Inc.) -- C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\svchost.exe [comLaunch] PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\svchost.exe [comLaunch] PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- D:\Programy\Spybot - Search & Destroy\SDWinSec.exe [color=#E56717]========== Modules (All) ==========[/color] MOD - [2012/12/30 11:10:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Adam\Desktop\OTL.exe MOD - [2012/12/11 18:58:39 | 000,043,272 | ---- | M] (AVAST Software) -- D:\Programy\Avast\defs\13010100\uiext.dll MOD - [2012/12/05 02:15:17 | 001,242,728 | ---- | M] (Google Inc.) -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe MOD - [2012/12/05 02:15:15 | 012,456,040 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll MOD - [2012/12/05 02:15:15 | 000,460,904 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll MOD - [2012/12/05 02:15:14 | 004,008,040 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll MOD - [2012/12/05 02:14:29 | 000,587,880 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\libglesv2.dll MOD - [2012/12/05 02:14:28 | 000,124,520 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\libegl.dll MOD - [2012/12/05 02:14:27 | 009,963,112 | ---- | M] (The ICU Project) -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\icudt.dll MOD - [2012/12/05 02:14:23 | 041,743,976 | ---- | M] (Google Inc.) -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\chrome.dll MOD - [2012/12/05 02:14:21 | 000,157,304 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\avutil-51.dll MOD - [2012/12/05 02:14:20 | 000,275,576 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\avformat-54.dll MOD - [2012/12/05 02:14:19 | 002,168,952 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\avcodec-54.dll MOD - [2012/11/15 19:49:39 | 001,670,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\4a29fb5e489e57ccc97b19ca70db94a8\Microsoft.VisualBasic.ni.dll MOD - [2012/11/15 19:12:47 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\17796f2951c17ebf92dd4b7c9b3ce556\System.ServiceProcess.ni.dll MOD - [2012/11/15 19:12:38 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\03cfab5534482e8fc313ead6edc19100\System.Web.ni.dll MOD - [2012/11/15 19:12:32 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\413288993ff690e8251d2dbe32bee01f\System.Runtime.Remoting.ni.dll MOD - [2012/11/15 19:12:31 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\3d4e9d4f6c945d6d3b7d423fdb6bd274\System.Data.ni.dll MOD - [2012/11/15 19:12:06 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d040079bc7148afeca03c5abb6fc3c61\System.Windows.Forms.ni.dll MOD - [2012/11/15 19:12:00 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\4e80768a2d88c7a333e43cbb7a6c0705\System.Drawing.ni.dll MOD - [2012/11/15 19:11:58 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\70705382a499703e7a595fada80b04e6\Accessibility.ni.dll MOD - [2012/11/15 19:11:45 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\25e672ea505e50ab058258ac72a54f02\System.Xml.ni.dll MOD - [2012/11/15 19:11:42 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c64ca3678261c8ffcd9e7efd1af6ed54\System.Configuration.ni.dll MOD - [2012/11/15 19:11:41 | 007,988,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9dd758ac0bf7358ac6e4720610fcc63c\System.ni.dll MOD - [2012/11/15 19:11:36 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\187d7c66735c533de851c76384f86912\mscorlib.ni.dll MOD - [2012/10/30 23:51:26 | 000,242,056 | ---- | M] (AVAST Software) -- D:\Programy\Avast\1045\uiLangRes.dll MOD - [2012/10/30 23:51:26 | 000,095,784 | ---- | M] (AVAST Software) -- D:\Programy\Avast\1045\Base.dll MOD - [2012/10/30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- D:\Programy\Avast\AvastUI.exe MOD - [2012/10/30 23:50:53 | 000,236,888 | ---- | M] (AVAST Software) -- D:\Programy\Avast\snxhk.dll MOD - [2012/10/30 23:50:51 | 006,439,048 | ---- | M] (AVAST Software) -- D:\Programy\Avast\CommonRes.dll MOD - [2012/10/30 23:50:47 | 000,476,360 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswSqLt.dll MOD - [2012/10/30 23:50:47 | 000,027,296 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswUtil.dll MOD - [2012/10/30 23:50:44 | 000,220,944 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswLog.dll MOD - [2012/10/30 23:50:44 | 000,217,848 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswProperty.dll MOD - [2012/10/30 23:50:44 | 000,126,160 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswJsFlt.dll MOD - [2012/10/30 23:50:44 | 000,051,000 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswEngLdr.dll MOD - [2012/10/30 23:50:41 | 002,162,488 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswAra.dll MOD - [2012/10/30 23:50:41 | 000,682,384 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswAux.dll MOD - [2012/10/30 23:50:41 | 000,347,616 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswCmnBS.dll MOD - [2012/10/30 23:50:41 | 000,191,568 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswCmnIS.dll MOD - [2012/10/30 23:50:41 | 000,191,080 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswData.dll MOD - [2012/10/30 23:50:41 | 000,099,416 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswCmnOS.dll MOD - [2012/10/30 23:50:38 | 000,153,976 | ---- | M] (AVAST Software) -- D:\Programy\Avast\ashTask.dll MOD - [2012/10/30 23:50:38 | 000,061,800 | ---- | M] (AVAST Software) -- D:\Programy\Avast\ashTaskEx.dll MOD - [2012/10/30 23:50:36 | 000,441,352 | ---- | M] (AVAST Software) -- D:\Programy\Avast\ashBase.dll MOD - [2012/10/30 23:50:30 | 000,368,752 | ---- | M] (AVAST Software) -- D:\Programy\Avast\Aavm4h.dll MOD - [2012/10/30 23:50:30 | 000,120,504 | ---- | M] (AVAST Software) -- D:\Programy\Avast\AavmRpch.dll MOD - [2012/10/27 07:26:55 | 000,981,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wininet.dll MOD - [2012/10/27 07:26:43 | 001,231,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\urlmon.dll MOD - [2012/10/27 07:23:15 | 002,073,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\iertutil.dll MOD - [2012/10/27 07:23:14 | 011,020,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ieframe.dll MOD - [2012/10/16 08:39:52 | 000,561,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\AppPatch\AcLayers.dll MOD - [2012/10/11 15:53:04 | 000,425,984 | ---- | M] () -- c:\progra~2\softqu~1\sprote~1.dll MOD - [2012/10/11 15:52:24 | 000,425,984 | ---- | M] () -- c:\progra~2\contin~1\sprote~1.dll MOD - [2012/10/09 18:40:31 | 000,044,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dhcpcsvc6.dll MOD - [2012/10/09 10:53:36 | 004,441,920 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Adam\AppData\Local\Akamai\netsession_win.exe MOD - [2012/10/04 17:47:41 | 000,274,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\KernelBase.dll MOD - [2012/10/04 17:47:40 | 001,114,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\kernel32.dll MOD - [2012/08/31 11:59:20 | 005,927,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll MOD - [2012/08/24 17:57:48 | 000,172,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wintrust.dll MOD - [2012/07/03 08:04:54 | 000,252,848 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe MOD - [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shell32.dll MOD - [2012/06/06 06:05:52 | 001,236,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msxml3.dll MOD - [2012/06/02 05:40:42 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\secur32.dll MOD - [2012/06/02 05:39:10 | 000,219,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ncrypt.dll MOD - [2012/06/02 05:36:29 | 001,159,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\crypt32.dll MOD - [2012/06/02 05:36:29 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptnet.dll MOD - [2012/06/02 05:34:09 | 000,096,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sspicli.dll MOD - [2012/05/05 08:46:52 | 000,043,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\srclient.dll MOD - [2012/04/26 13:33:16 | 002,743,104 | ---- | M] (DT Soft Ltd) -- D:\Programy\Daemon Tools Pro\DTShellHlp.exe MOD - [2012/04/26 13:32:38 | 005,740,864 | ---- | M] (DT Soft Ltd) -- D:\Programy\Daemon Tools Pro\DTCommonRes.dll MOD - [2012/04/26 13:32:14 | 004,057,920 | ---- | M] (DT Soft Ltd) -- D:\Programy\Daemon Tools Pro\Engine.dll MOD - [2012/04/21 05:21:01 | 001,625,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\GdiPlus.dll MOD - [2012/04/12 07:30:52 | 000,382,784 | ---- | M] (DT Soft Ltd.) -- D:\Programy\Daemon Tools Pro\imgengine.dll MOD - [2012/03/01 06:33:23 | 000,159,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\imagehlp.dll MOD - [2012/01/13 08:12:03 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\nlaapi.dll MOD - [2012/01/04 09:58:41 | 000,442,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntshrui.dll MOD - [2012/01/04 03:50:59 | 000,364,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll MOD - [2011/12/16 08:52:58 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msvcrt.dll MOD - [2011/11/17 06:38:39 | 001,292,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntdll.dll MOD - [2011/11/17 06:35:02 | 000,314,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\webio.dll MOD - [2011/10/01 00:29:42 | 003,781,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_4bf7e3e2bf9ada4c\mfc90u.dll MOD - [2011/10/01 00:29:34 | 000,653,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll MOD - [2011/10/01 00:29:34 | 000,569,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll MOD - [2011/10/01 00:11:20 | 000,632,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcr80.dll MOD - [2011/10/01 00:11:20 | 000,554,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcp80.dll MOD - [2011/08/27 05:26:27 | 000,571,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\oleaut32.dll MOD - [2011/08/27 05:26:27 | 000,233,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\oleacc.dll MOD - [2011/06/01 17:46:02 | 000,030,984 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SeagateSharePlusPlugin.dll MOD - [2011/06/01 17:46:00 | 000,036,616 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SharePlugin.dll MOD - [2011/06/01 17:46:00 | 000,031,496 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SyncPlugin.dll MOD - [2011/06/01 17:46:00 | 000,029,960 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SeagateSharePlugin.dll MOD - [2011/06/01 17:46:00 | 000,026,376 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.RebitPlugin.dll MOD - [2011/06/01 17:45:58 | 000,028,936 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.BackupPremiumPlugin.dll MOD - [2011/06/01 17:45:58 | 000,028,424 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SendPlugin.dll MOD - [2011/06/01 17:45:56 | 000,029,448 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.BackupPlugin.dll MOD - [2011/06/01 17:45:52 | 000,011,016 | ---- | M] (Softvision) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.FolderViewPlugin.resources.dll MOD - [2011/06/01 17:45:40 | 000,011,016 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.SeagateSharePlusPlugin.resources.dll MOD - [2011/06/01 17:45:30 | 000,011,016 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.SeagateSharePlugin.resources.dll MOD - [2011/06/01 17:45:18 | 000,011,016 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.SeagatePreferencesPlugin.resources.dll MOD - [2011/06/01 17:45:06 | 000,011,528 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.LoadContentPlugin.resources.dll MOD - [2011/06/01 17:44:56 | 000,015,624 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.AddUserPlugin.resources.dll MOD - [2011/06/01 17:44:44 | 000,011,016 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.AddComputersPlugin.resources.dll MOD - [2011/06/01 17:44:12 | 000,009,992 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.RebitPlugin.resources.dll MOD - [2011/06/01 17:44:00 | 000,009,992 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.SyncPlugin.resources.dll MOD - [2011/06/01 17:43:50 | 000,009,992 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.SharePlugin.resources.dll MOD - [2011/06/01 17:43:38 | 000,009,992 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.SendPlugin.resources.dll MOD - [2011/06/01 17:43:12 | 000,010,504 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.BackupPremiumPlugin.resources.dll MOD - [2011/06/01 17:43:02 | 000,010,504 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.BackupPlugin.resources.dll MOD - [2011/06/01 17:42:40 | 000,054,536 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\pl-PL\Memeo.Dashboard.UI.resources.dll MOD - [2011/06/01 17:42:32 | 000,013,576 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Dashboard.NasListener.dll MOD - [2011/06/01 17:42:30 | 000,031,496 | ---- | M] (Softvision) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Dashboard.HipServAdapter.dll MOD - [2011/06/01 17:42:30 | 000,021,768 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Dashboard.HelperAgentAdapter.dll MOD - [2011/06/01 17:42:28 | 000,071,432 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoDashboard.exe MOD - [2011/06/01 17:42:26 | 001,934,088 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Dashboard.UI.dll MOD - [2011/06/01 17:42:26 | 000,145,672 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Common.dll MOD - [2011/06/01 17:42:26 | 000,069,896 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Dashboard.Remote.dll MOD - [2011/06/01 17:42:26 | 000,037,128 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Dashboard.PluginCore.dll MOD - [2011/06/01 17:42:24 | 000,108,296 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Progress.dll MOD - [2011/06/01 17:42:16 | 000,023,040 | ---- | M] (Softvision) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.FolderViewPlugin.dll MOD - [2011/06/01 17:41:48 | 000,043,008 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.AddUserPlugin.dll MOD - [2011/06/01 17:41:44 | 000,032,768 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.LoadContentPlugin.dll MOD - [2011/06/01 17:41:38 | 000,019,968 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.AddComputersPlugin.dll MOD - [2011/06/01 17:41:32 | 000,023,040 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SeagatePreferencesPlugin.dll MOD - [2011/06/01 17:16:54 | 003,284,992 | ---- | M] (DevComponents.com) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\DevComponents.DotNetBar2.dll MOD - [2011/06/01 17:16:54 | 002,260,992 | ---- | M] (Axentra Corporation) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe MOD - [2011/06/01 17:16:54 | 001,028,096 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\LIBEAY32.dll MOD - [2011/06/01 17:16:54 | 000,978,432 | ---- | M] (GNU <www.gnu.org>) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\iconv.dll MOD - [2011/06/01 17:16:54 | 000,971,776 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\libxml2.dll MOD - [2011/06/01 17:16:54 | 000,241,664 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\libupnp.dll MOD - [2011/06/01 17:16:54 | 000,212,992 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\SSLEAY32.dll MOD - [2011/06/01 17:16:54 | 000,208,896 | ---- | M] (The cURL library, http://curl.haxx.se/) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\libcurl.dll MOD - [2011/06/01 17:16:54 | 000,086,070 | ---- | M] (Open Source Software community project) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\pthreadVC2.dll MOD - [2011/06/01 17:16:54 | 000,075,264 | ---- | M] (Zlib) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\zlib1.dll MOD - [2011/05/24 11:40:05 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\devobj.dll MOD - [2011/05/24 11:39:38 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cfgmgr32.dll MOD - [2011/05/17 08:27:52 | 000,413,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll MOD - [2011/05/04 22:15:12 | 000,032,768 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\pl-PL\Tanagra.Utility.resources.dll MOD - [2011/05/04 22:15:12 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\pl-PL\InstantBackup.resources.dll MOD - [2011/05/04 22:15:10 | 000,069,632 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\pl-PL\Memeo.Client.UI.resources.dll MOD - [2011/05/04 22:15:08 | 000,053,248 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\pl-PL\Tanagra.DataClad.resources.dll MOD - [2011/05/04 22:15:06 | 000,015,872 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\pl-PL\Memeo.Client.resources.dll MOD - [2011/05/04 22:15:02 | 000,069,632 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\pl-PL\Tanagra.BMU.resources.dll MOD - [2011/05/04 22:10:50 | 000,087,264 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\providers\Tanagra.BMU.Providers.FileCopyBackupProvider.dll MOD - [2011/05/04 22:10:50 | 000,079,072 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\providers\Tanagra.BMU.Providers.HardDiskBackupProvider.dll MOD - [2011/05/04 22:10:48 | 002,896,608 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\Memeo.Client.UI.dll MOD - [2011/05/04 22:10:46 | 000,230,624 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Memeo.Client.dll MOD - [2011/05/04 22:10:46 | 000,027,360 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\Memeo.Client.DriveDetection.dll MOD - [2011/05/04 22:10:44 | 000,020,704 | ---- | M] (Stan Schultes, VBNetExpert.com) -- C:\Program Files (x86)\Memeo\AutoBackup\XMLSettings.dll MOD - [2011/05/04 22:10:42 | 001,668,320 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Tanagra.Utility.dll MOD - [2011/05/04 22:10:42 | 000,025,824 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Tanagra.Third-party.Security.dll MOD - [2011/05/04 22:10:40 | 002,794,720 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Tanagra.BMU.dll MOD - [2011/05/04 22:10:40 | 001,561,824 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Tanagra.DataClad.dll MOD - [2011/05/04 22:10:40 | 000,296,160 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Tanagra.DataClad.DataAccess.dll MOD - [2011/05/04 22:10:40 | 000,054,496 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Tanagra.Interop.dll MOD - [2011/05/04 22:10:38 | 000,074,976 | ---- | M] (Finisar Corporation) -- C:\Program Files (x86)\Memeo\AutoBackup\SQLite.NET.dll MOD - [2011/05/04 22:10:38 | 000,067,808 | ---- | M] (Newtonsoft) -- C:\Program Files (x86)\Memeo\AutoBackup\Newtonsoft.Json.dll MOD - [2011/05/04 22:10:28 | 000,325,344 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\InstantBackup.exe MOD - [2011/03/14 16:27:28 | 000,236,384 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe MOD - [2011/03/03 06:38:01 | 000,270,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dnsapi.dll MOD - [2011/02/21 17:40:04 | 010,059,368 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWOW64\nvd3dum.dll MOD - [2010/11/21 04:25:15 | 000,172,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\spp.dll MOD - [2010/11/21 04:25:11 | 003,207,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mf.dll MOD - [2010/11/21 04:25:11 | 000,488,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\evr.dll MOD - [2010/11/21 04:24:51 | 000,080,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\davclnt.dll MOD - [2010/11/21 04:24:43 | 000,481,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mscms.dll MOD - [2010/11/21 04:24:33 | 001,010,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\WindowsCodecs.dll MOD - [2010/11/21 04:24:33 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\credssp.dll MOD - [2010/11/21 04:24:32 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\IPHLPAPI.DLL MOD - [2010/11/21 04:24:28 | 000,640,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\advapi32.dll MOD - [2010/11/21 04:24:26 | 001,128,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vssapi.dll MOD - [2010/11/21 04:24:26 | 000,572,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll MOD - [2010/11/21 04:24:25 | 000,119,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\imm32.dll MOD - [2010/11/21 04:24:23 | 001,828,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d9.dll MOD - [2010/11/21 04:24:23 | 001,493,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ExplorerFrame.dll MOD - [2010/11/21 04:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\user32.dll MOD - [2010/11/21 04:24:16 | 000,626,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\usp10.dll MOD - [2010/11/21 04:24:16 | 000,380,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sxs.dll MOD - [2010/11/21 04:24:16 | 000,269,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\Wldap32.dll MOD - [2010/11/21 04:24:16 | 000,257,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msv1_0.dll MOD - [2010/11/21 04:24:16 | 000,194,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winmm.dll MOD - [2010/11/21 04:24:16 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\srvcli.dll MOD - [2010/11/21 04:24:16 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\userenv.dll MOD - [2010/11/21 04:24:16 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\netutils.dll MOD - [2010/11/21 04:24:14 | 000,592,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msftedit.dll MOD - [2010/11/21 04:24:14 | 000,311,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\gdi32.dll MOD - [2010/11/21 04:24:14 | 000,295,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\apphelp.dll MOD - [2010/11/21 04:24:14 | 000,046,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\RpcRtRemote.dll MOD - [2010/11/21 04:24:11 | 000,663,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rpcrt4.dll MOD - [2010/11/21 04:24:09 | 000,854,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dbghelp.dll MOD - [2010/11/21 04:24:09 | 000,530,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll MOD - [2010/11/21 04:24:09 | 000,232,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mswsock.dll MOD - [2010/11/21 04:24:08 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll MOD - [2010/11/21 04:24:08 | 000,988,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\propsys.dll MOD - [2010/11/21 04:24:08 | 000,351,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winhttp.dll MOD - [2010/11/21 04:24:08 | 000,320,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winspool.drv MOD - [2010/11/21 04:24:08 | 000,236,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\pdh.dll MOD - [2010/11/21 04:24:08 | 000,216,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\FWPUCLNT.DLL MOD - [2010/11/21 04:24:07 | 000,179,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shdocvw.dll MOD - [2010/11/21 04:24:03 | 000,189,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sqmapi.dll MOD - [2010/11/21 04:24:03 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\olepro32.dll MOD - [2010/11/21 04:24:02 | 000,034,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cscapi.dll MOD - [2010/11/21 04:24:02 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msdmo.dll MOD - [2010/11/21 04:24:01 | 001,414,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ole32.dll MOD - [2010/11/21 04:24:01 | 000,297,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mscoree.dll MOD - [2010/11/21 04:24:01 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rtutils.dll MOD - [2010/11/21 04:24:00 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntlanman.dll MOD - [2010/11/21 04:23:55 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll MOD - [2010/11/21 04:23:55 | 000,206,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ws2_32.dll MOD - [2010/11/21 04:23:55 | 000,156,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winsta.dll MOD - [2010/11/21 04:23:54 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\samcli.dll MOD - [2010/11/21 04:23:54 | 000,040,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wtsapi32.dll MOD - [2010/11/21 04:23:51 | 001,667,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\setupapi.dll MOD - [2010/11/21 04:23:51 | 000,213,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\MMDevAPI.dll MOD - [2010/11/21 04:23:51 | 000,047,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wkscli.dll MOD - [2010/11/21 04:23:48 | 000,485,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\comdlg32.dll MOD - [2010/11/21 04:23:48 | 000,350,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shlwapi.dll MOD - [2010/11/21 04:23:48 | 000,034,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msasn1.dll MOD - [2010/11/13 03:03:49 | 000,311,296 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pl_b77a5c561934e089\mscorlib.resources.dll MOD - [2010/09/21 13:03:14 | 000,145,280 | ---- | M] (Microsoft Corp.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL MOD - [2010/05/26 11:41:02 | 002,106,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\D3DCompiler_43.dll MOD - [2010/05/26 11:41:02 | 001,998,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\D3DX9_43.dll MOD - [2010/03/22 23:59:46 | 000,504,293 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\sqlite3.DLL MOD - [2010/03/22 23:59:32 | 000,013,824 | ---- | M] ( ) -- C:\Program Files (x86)\Memeo\AutoBackup\Interop.eWebControl.dll MOD - [2010/03/22 23:58:22 | 000,143,360 | ---- | M] (Digital River, Inc.) -- C:\Program Files (x86)\Common Files\Memeo\eWebControl365.dll MOD - [2009/07/14 02:17:54 | 000,249,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\bcryptprimitives.dll MOD - [2009/07/14 02:17:54 | 000,242,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rsaenh.dll MOD - [2009/07/14 02:16:20 | 000,308,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\Wpc.dll MOD - [2009/07/14 02:16:20 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wsock32.dll MOD - [2009/07/14 02:16:20 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wship6.dll MOD - [2009/07/14 02:16:20 | 000,009,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\WSHTCPIP.DLL MOD - [2009/07/14 02:16:19 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winrnr.dll MOD - [2009/07/14 02:16:19 | 000,016,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winnsi.dll MOD - [2009/07/14 02:16:18 | 000,262,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wevtapi.dll MOD - [2009/07/14 02:16:17 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vsstrace.dll MOD - [2009/07/14 02:16:17 | 000,021,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\version.dll MOD - [2009/07/14 02:16:15 | 000,027,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\slc.dll MOD - [2009/07/14 02:16:14 | 000,007,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shfolder.dll MOD - [2009/07/14 02:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sechost.dll MOD - [2009/07/14 02:16:13 | 000,060,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\samlib.dll MOD - [2009/07/14 02:16:13 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\SensApi.dll MOD - [2009/07/14 02:16:12 | 000,325,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rasapi32.dll MOD - [2009/07/14 02:16:12 | 000,145,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\powrprof.dll MOD - [2009/07/14 02:16:12 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rasman.dll MOD - [2009/07/14 02:16:12 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\pnrpnsp.dll MOD - [2009/07/14 02:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\profapi.dll MOD - [2009/07/14 02:16:12 | 000,028,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\perfos.dll MOD - [2009/07/14 02:16:12 | 000,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rasadhlp.dll MOD - [2009/07/14 02:16:12 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\psapi.dll MOD - [2009/07/14 02:16:11 | 000,121,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntmarta.dll MOD - [2009/07/14 02:16:11 | 000,008,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\nsi.dll MOD - [2009/07/14 02:16:02 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\NapiNSP.dll MOD - [2009/07/14 02:15:48 | 000,035,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mssprxy.dll MOD - [2009/07/14 02:15:46 | 002,134,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msmpeg2vdec.dll MOD - [2009/07/14 02:15:44 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msimg32.dll MOD - [2009/07/14 02:15:43 | 000,828,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msctf.dll MOD - [2009/07/14 02:15:41 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mpr.dll MOD - [2009/07/14 02:15:39 | 000,352,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mfplat.dll MOD - [2009/07/14 02:15:36 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\linkinfo.dll MOD - [2009/07/14 02:15:35 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ksuser.dll MOD - [2009/07/14 02:15:22 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\gpapi.dll MOD - [2009/07/14 02:15:21 | 000,462,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\FirewallAPI.dll MOD - [2009/07/14 02:15:13 | 000,717,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dui70.dll MOD - [2009/07/14 02:15:13 | 000,453,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dsound.dll MOD - [2009/07/14 02:15:13 | 000,181,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\duser.dll MOD - [2009/07/14 02:15:13 | 000,088,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dxva2.dll MOD - [2009/07/14 02:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dwmapi.dll MOD - [2009/07/14 02:15:13 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\drprov.dll MOD - [2009/07/14 02:15:11 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dhcpcsvc.dll MOD - [2009/07/14 02:15:10 | 000,066,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\devenum.dll MOD - [2009/07/14 02:15:08 | 000,019,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\davhlpr.dll MOD - [2009/07/14 02:15:08 | 000,011,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d8thk.dll MOD - [2009/07/14 02:15:07 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptsp.dll MOD - [2009/07/14 02:15:07 | 000,058,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptdll.dll MOD - [2009/07/14 02:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptbase.dll MOD - [2009/07/14 02:15:03 | 000,522,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\clbcatq.dll MOD - [2009/07/14 02:14:58 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\avrt.dll MOD - [2009/07/14 02:14:57 | 000,070,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\atl.dll MOD - [2009/07/14 02:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx MOD - [2009/07/14 02:11:24 | 000,245,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\uxtheme.dll MOD - [2009/07/14 02:11:23 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\lpk.dll MOD - [2009/07/14 02:11:20 | 000,080,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\bcrypt.dll MOD - [2009/07/14 02:09:53 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\security.dll MOD - [2009/06/10 22:23:08 | 000,074,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2012/10/13 19:43:55 | 001,431,888 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64) SRV:[b]64bit:[/b] - [2010/10/20 13:41:00 | 000,138,656 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\SysNative\TODDSrv.exe -- (TODDSrv) SRV:[b]64bit:[/b] - [2010/09/22 17:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) SRV:[b]64bit:[/b] - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2012/12/14 20:38:46 | 001,236,968 | ---- | M] (Lavasoft Limited) [Auto | Running] -- D:\Programy\Ad-Aware\AdAwareService.exe -- (Ad-Aware Service) SRV - [2012/12/11 22:28:13 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012/11/09 11:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- D:\Programy\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2012/09/20 05:39:12 | 003,677,000 | ---- | M] (GFI Software) [Auto | Stopped] -- D:\Programy\Ad-Aware\SBAMSvc.exe -- (SBAMSvc) SRV - [2012/07/27 12:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011/12/09 14:39:52 | 000,135,584 | ---- | M] (Futuremark Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service) SRV - [2011/11/09 20:44:27 | 001,045,256 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2011/06/01 17:42:28 | 000,014,088 | ---- | M] (Memeo) [Auto | Running] -- C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe -- (SeagateDashboardService) SRV - [2011/05/04 22:10:32 | 000,025,824 | ---- | M] (Memeo) [Auto | Running] -- C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe -- (MemeoBackgroundService) SRV - [2011/03/14 16:27:34 | 000,346,976 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\HWDeviceService64.exe -- (HWDeviceService64.exe) SRV - [2011/02/01 12:24:42 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) SRV - [2011/02/01 12:24:40 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) SRV - [2010/08/04 16:11:34 | 001,809,920 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe -- (IconMan_R) SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2008/06/13 03:05:48 | 001,539,224 | ---- | M] (Autodesk, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskNetSrv.exe -- (Autodesk Network Licensing Service) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2012/12/31 00:01:23 | 000,014,456 | ---- | M] (GFI Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\gfibto.sys -- (gfibto) DRV:[b]64bit:[/b] - [2012/11/24 20:32:32 | 000,303,616 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt) DRV:[b]64bit:[/b] - [2012/10/30 23:51:56 | 000,059,728 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi) DRV:[b]64bit:[/b] - [2012/10/30 23:51:55 | 000,984,144 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx) DRV:[b]64bit:[/b] - [2012/10/30 23:51:55 | 000,370,288 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP) DRV:[b]64bit:[/b] - [2012/10/30 23:51:55 | 000,071,600 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt) DRV:[b]64bit:[/b] - [2012/10/30 23:51:53 | 000,025,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk) DRV:[b]64bit:[/b] - [2012/10/15 17:59:28 | 000,054,072 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr) DRV:[b]64bit:[/b] - [2012/08/21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV:[b]64bit:[/b] - [2012/07/12 18:46:00 | 000,560,184 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd) DRV:[b]64bit:[/b] - [2012/07/12 18:42:35 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:[b]64bit:[/b] - [2012/07/07 13:40:50 | 000,039,552 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\tcpipBM.sys -- (tcpipBM) DRV:[b]64bit:[/b] - [2012/07/07 13:40:49 | 000,212,992 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_juwwanecm.sys -- (huawei_wwanecm) DRV:[b]64bit:[/b] - [2012/07/07 13:40:49 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys -- (ew_hwusbdev) DRV:[b]64bit:[/b] - [2012/07/07 13:40:49 | 000,098,816 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_jucdcacm.sys -- (huawei_cdcacm) DRV:[b]64bit:[/b] - [2012/07/07 13:40:49 | 000,086,016 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ew_jubusenum.sys -- (huawei_enumerator) DRV:[b]64bit:[/b] - [2012/07/07 13:40:49 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_juextctrl.sys -- (huawei_ext_ctrl) DRV:[b]64bit:[/b] - [2012/07/07 13:40:49 | 000,013,952 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_usbenumfilter.sys -- (ew_usbenumfilter) DRV:[b]64bit:[/b] - [2012/07/07 13:40:48 | 000,016,512 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\BMLoad.sys -- (BMLoad) DRV:[b]64bit:[/b] - [2012/06/30 15:35:48 | 000,043,168 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt) DRV:[b]64bit:[/b] - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2011/11/09 20:44:38 | 000,036,904 | ---- | M] (Feitian Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rockey4.sys -- (ROCKEYNT) DRV:[b]64bit:[/b] - [2011/05/13 02:21:04 | 000,177,640 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdm.sys -- (ssadmdm) DRV:[b]64bit:[/b] - [2011/05/13 02:21:04 | 000,146,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadserd.sys -- (ssadserd) DRV:[b]64bit:[/b] - [2011/05/13 02:21:02 | 000,157,672 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadbus.sys -- (ssadbus) DRV:[b]64bit:[/b] - [2011/05/13 02:21:02 | 000,036,328 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadadb.sys -- (androidusb) DRV:[b]64bit:[/b] - [2011/05/13 02:21:02 | 000,016,872 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdfl.sys -- (ssadmdfl) DRV:[b]64bit:[/b] - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2011/02/03 18:59:06 | 001,413,680 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP) DRV:[b]64bit:[/b] - [2011/01/13 19:58:30 | 000,413,800 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:[b]64bit:[/b] - [2011/01/12 16:51:44 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:[b]64bit:[/b] - [2011/01/05 00:08:58 | 001,109,096 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtl8192ce.sys -- (RTL8192Ce) DRV:[b]64bit:[/b] - [2010/11/21 04:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2010/11/21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2010/11/21 04:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:[b]64bit:[/b] - [2010/11/11 14:10:50 | 000,155,752 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA) DRV:[b]64bit:[/b] - [2010/10/19 15:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:[b]64bit:[/b] - [2010/07/20 16:43:22 | 000,247,400 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR) DRV:[b]64bit:[/b] - [2010/03/22 09:55:20 | 000,046,192 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\LPCFilter.sys -- (LPCFilter) DRV:[b]64bit:[/b] - [2009/07/30 19:22:04 | 000,027,784 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tdcmdpst.sys -- (tdcmdpst) DRV:[b]64bit:[/b] - [2009/07/14 15:31:18 | 000,026,840 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TVALZ_O.SYS -- (TVALZ) DRV:[b]64bit:[/b] - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009/06/20 03:09:57 | 001,394,688 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr) DRV:[b]64bit:[/b] - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:[b]64bit:[/b] - [2008/05/16 11:33:06 | 000,158,760 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016mdm.sys -- (s0016mdm) DRV:[b]64bit:[/b] - [2008/05/16 11:33:06 | 000,151,592 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016unic.sys -- (s0016unic) DRV:[b]64bit:[/b] - [2008/05/16 11:33:06 | 000,137,256 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016mgmt.sys -- (s0016mgmt) DRV:[b]64bit:[/b] - [2008/05/16 11:33:06 | 000,136,744 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016obex.sys -- (s0016obex) DRV:[b]64bit:[/b] - [2008/05/16 11:33:06 | 000,034,344 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016nd5.sys -- (s0016nd5) DRV:[b]64bit:[/b] - [2008/05/16 11:33:04 | 000,019,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016mdfl.sys -- (s0016mdfl) DRV:[b]64bit:[/b] - [2008/05/16 11:32:56 | 000,115,240 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016bus.sys -- (s0016bus) DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {D526343C-369F-4282-8F7D-0AE1527D1FE5} IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{D526343C-369F-4282-8F7D-0AE1527D1FE5}: "URL" = http://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://websearch.soft-quick.info/ IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5} IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=PL&userid=ee3dca77-17dd-422c-adaa-c020d3ecccc3&affid=110774&searchtype=ds&babsrc=lnkry&q={searchTerms} IE - HKLM\..\SearchScopes\{7F58A7B2-6E52-456D-87F4-C77C7EBFA5A0}: "URL" = http://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.soft-quick.info/?l=1&q={searchTerms} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba.msn.com IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=PL&userid=ee3dca77-17dd-422c-adaa-c020d3ecccc3&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=PL&userid=ee3dca77-17dd-422c-adaa-c020d3ecccc3&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://websearch.soft-quick.info/ IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=PL&userid=ee3dca77-17dd-422c-adaa-c020d3ecccc3&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=PL&userid=ee3dca77-17dd-422c-adaa-c020d3ecccc3&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5} IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=PL&userid=ee3dca77-17dd-422c-adaa-c020d3ecccc3&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms} IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\..\SearchScopes\{711DE046-A996-446D-8872-2FA584763384}: "URL" = http://startsear.ch/?aff=1&src=sp&cf=a33a8b64-19b1-11e1-b314-b870f45d63bf&q={searchTerms} IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.soft-quick.info/?l=1&q={searchTerms} IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "http://websearch.soft-quick.info/" FF - prefs.js..extensions.enabledAddons: wrc@avast.com:7.0.1426 FF - prefs.js..network.proxy.type: 0 FF - prefs.js..browser.search.order.1: "WebSearch" FF - prefs.js..browser.search.defaultenginename: "WebSearch" FF - prefs.js..browser.search.selectedEngine: "WebSearch" FF - prefs.js..browser.search.defaulturl: "http://websearch.soft-quick.info/?l=1&q=" FF - prefs.js..browser.search.order.1,S: S", "WebSearch" FF - prefs.js..browser.search.defaultenginename,S: S", "WebSearch" FF - prefs.js..browser.search.selectedEngine,S: S", "WebSearch" FF - prefs.js..keyword.URL: "http://websearch.soft-quick.info/?l=1&q=" FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Programy\iTunes\Mozilla Plugins\npitunes.dll File not found FF - HKLM\Software\MozillaPlugins\@ganymede/GanymedeNetPlugin,version=1.0: D:\Programy\Bilard z WP\Ganymede\Plugins\npganymedenet.dll ( ) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@playstation.com/PsndlCheck,version=1.00: File not found FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Adam\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Adam\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: D:\Programy\Avast\WebRep\FF [2012/11/03 16:20:34 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/05/29 10:35:30 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/05/29 10:35:30 | 000,000,000 | ---D | M] [2012/01/29 02:02:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Adam\AppData\Roaming\mozilla\Extensions [2012/12/29 14:54:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\oq3gcry8.default\extensions [2012/10/09 15:16:21 | 000,000,000 | ---D | M] (OneClickDownloader) -- C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\oq3gcry8.default\extensions\OneClickDownload@OneClickDownload.com [2012/05/19 10:07:52 | 000,010,043 | ---- | M] () (No name found) -- C:\Users\Adam\AppData\Roaming\mozilla\firefox\profiles\oq3gcry8.default\extensions\IplextoALL@ALLPlayer.org.xpi [2012/10/04 16:57:36 | 000,214,514 | ---- | M] () (No name found) -- C:\Users\Adam\AppData\Roaming\mozilla\firefox\profiles\oq3gcry8.default\extensions\TorrentHandler@TorrentHandler.com.xpi [2012/03/15 22:47:45 | 000,634,964 | ---- | M] () (No name found) -- C:\Users\Adam\AppData\Roaming\mozilla\firefox\profiles\oq3gcry8.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012/12/29 15:41:09 | 000,000,553 | ---- | M] () -- C:\Users\Adam\AppData\Roaming\mozilla\firefox\profiles\oq3gcry8.default\searchplugins\WebSearch.xml [2012/11/03 16:20:34 | 000,000,000 | ---D | M] (avast! WebRep) -- D:\PROGRAMY\AVAST\WEBREP\FF [color=#E56717]========== Chrome ==========[/color] CHR - homepage: http://websearch.soft-quick.info/ CHR - Extension: No name found = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\ CHR - Extension: No name found = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\ CHR - Extension: No name found = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\dealelfklnopdjdoiejlibpajkggonpn\1.1_0\ CHR - Extension: No name found = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlfienamagdnkekbbbocojppncdambda\1.1_0\ CHR - Extension: No name found = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlfienamagdnkekbbbocojppncdambda\1.1_1\ CHR - Extension: No name found = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\hphibigbodkkohoglgfkddblldpfohjl\1.2_0\ CHR - Extension: No name found = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\ CHR - Extension: No name found = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_1\ CHR - Extension: No name found = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbiamblgmkgbcgbcgejjgebalncpmhnp\1.3_0\ CHR - Extension: No name found = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbiamblgmkgbcgbcgejjgebalncpmhnp\1.3_1\ CHR - Extension: No name found = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\ O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:[b]64bit:[/b] - BHO: (VshareComplete) - {222f31fb-a14e-4af2-bb14-997f28294370} - C:\Users\Adam\AppData\Roaming\VshareComplete\64\VshareComplete64.dll (SimplyGen) O2:[b]64bit:[/b] - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Programy\Avast\aswWebRepIE64.dll (AVAST Software) O2 - BHO: (VshareComplete) - {222f31fb-a14e-4af2-bb14-997f28294370} - C:\Users\Adam\AppData\Roaming\VshareComplete\VshareComplete.dll (SimplyGen) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Programy\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (IplexToALLPlayer) - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - D:\Programy\ALLPlayer\Iplex\IplexToALLPlayer.dll (ALLCinema Ltd.) O3:[b]64bit:[/b] - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Programy\Avast\aswWebRepIE64.dll (AVAST Software) O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found. O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Programy\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [Ad-Aware Antivirus] D:\Programy\Ad-Aware\AdAwareLauncher.exe (Lavasoft Limited) O4 - HKLM..\Run: [avast5] D:\Programy\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [Memeo AutoSync] C:\Program Files (x86)\Memeo\AutoSync\MemeoLauncher2.exe (Memeo Inc.) O4 - HKLM..\Run: [Memeo Instant Backup] C:\Program Files (x86)\Memeo\AutoBackup\MemeoLauncher2.exe (Memeo Inc.) O4 - HKLM..\Run: [Seagate Dashboard] C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoLauncher.exe () O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-319703930-2572490357-2975701463-1000..\Run: [Akamai NetSession Interface] C:\Users\Adam\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) O4 - HKU\S-1-5-21-319703930-2572490357-2975701463-1000..\Run: [ALLUpdate] D:\Programy\ALLPlayer\ALLUpdate.exe (ALLCinema) O4 - HKU\S-1-5-21-319703930-2572490357-2975701463-1000..\Run: [SpybotSD TeaTimer] D:\Programy\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0 O8:[b]64bit:[/b] - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found O8:[b]64bit:[/b] - Extra context menu item: Wyślij &do programu OneNote - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105 File not found O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Wyślij &do programu OneNote - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105 File not found O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL (Microsoft Corporation) O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.9.2) O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.9.2) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.50.50.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A9E0C5C0-9E6A-410A-8719-DD8EAFE4AB0C}: DhcpNameServer = 213.158.199.1 213.158.199.5 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A9E0C5C0-9E6A-410A-8719-DD8EAFE4AB0C}: NameServer = 213.158.199.1 213.158.199.5 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D2441D73-E10C-46A3-B0DC-2D2F5D69E4AC}: DhcpNameServer = 10.50.50.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F3591DBC-AF36-469B-87F5-DC25CE0EB967}: DhcpNameServer = 213.158.199.1 213.158.199.5 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F3591DBC-AF36-469B-87F5-DC25CE0EB967}: NameServer = 213.158.199.1 213.158.199.5 O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - AppInit_DLLs: (c:\progra~2\contin~1\sprote~1.dll) - c:\progra~2\contin~1\sprote~1.dll () O20 - AppInit_DLLs: (c:\progra~2\softqu~1\sprote~1.dll) - c:\progra~2\softqu~1\sprote~1.dll () O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2012/12/30 18:52:09 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ] O32 - AutoRun File - [2012/10/13 19:42:40 | 000,000,000 | ---D | M] - C:\AUTODESK_COM_FOLDER -- [ NTFS ] O33 - MountPoints2\{1842d44a-c82a-11e1-a13a-b870f45d63bf}\Shell - "" = AutoRun O33 - MountPoints2\{1842d44a-c82a-11e1-a13a-b870f45d63bf}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{1842d46a-c82a-11e1-a13a-b870f45d63bf}\Shell - "" = AutoRun O33 - MountPoints2\{1842d46a-c82a-11e1-a13a-b870f45d63bf}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{2fceb299-266a-11e2-ae97-b870f45d63bf}\Shell - "" = AutoRun O33 - MountPoints2\{2fceb299-266a-11e2-ae97-b870f45d63bf}\Shell\AutoRun\command - "" = G:\AutoRun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk - C:\PROGRA~2\HP\DIGITA~1\bin\hpqtra08.exe - (Hewlett-Packard Co.) MsConfig:64bit - StartUpFolder: C:^Users^Adam^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk - - File not found MsConfig:64bit - StartUpReg: [b]Adobe ARM[/b] - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) MsConfig:64bit - StartUpReg: [b]Adobe Reader Speed Launcher[/b] - hkey= - key= - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) MsConfig:64bit - StartUpReg: [b]ALLUpdate[/b] - hkey= - key= - D:\Programy\ALLPlayer\ALLUpdate.exe (ALLCinema) MsConfig:64bit - StartUpReg: [b]DAEMON Tools Lite[/b] - hkey= - key= - File not found MsConfig:64bit - StartUpReg: [b]Google Update[/b] - hkey= - key= - C:\Users\Adam\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.) MsConfig:64bit - StartUpReg: [b]SunJavaUpdateSched[/b] - hkey= - key= - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) MsConfig:64bit - StartUpReg: [b]SVPWUTIL[/b] - hkey= - key= - File not found MsConfig:64bit - StartUpReg: [b]TCrdMain[/b] - hkey= - key= - File not found MsConfig:64bit - StartUpReg: [b]TOPI.EXE[/b] - hkey= - key= - File not found MsConfig:64bit - StartUpReg: [b]Toshiba Registration[/b] - hkey= - key= - C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe (Toshiba Europe GmbH) MsConfig:64bit - StartUpReg: [b]Toshiba TEMPRO[/b] - hkey= - key= - File not found MsConfig:64bit - StartUpReg: [b]ToshibaServiceStation[/b] - hkey= - key= - File not found MsConfig:64bit - StartUpReg: [b]TosReelTimeMonitor[/b] - hkey= - key= - File not found MsConfig:64bit - StartUpReg: [b]TosVolRegulator[/b] - hkey= - key= - C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation) MsConfig:64bit - StartUpReg: [b]TPwrMain[/b] - hkey= - key= - File not found MsConfig:64bit - State: "startup" - Reg Error: Key error. SafeBootMin:[b]64bit:[/b] AppMgmt - Service SafeBootMin:[b]64bit:[/b] Base - Driver Group SafeBootMin:[b]64bit:[/b] Boot Bus Extender - Driver Group SafeBootMin:[b]64bit:[/b] Boot file system - Driver Group SafeBootMin:[b]64bit:[/b] File system - Driver Group SafeBootMin:[b]64bit:[/b] Filter - Driver Group SafeBootMin:[b]64bit:[/b] HelpSvc - Service SafeBootMin:[b]64bit:[/b] MCODS - Reg Error: Value error. SafeBootMin:[b]64bit:[/b] PCI Configuration - Driver Group SafeBootMin:[b]64bit:[/b] PNP Filter - Driver Group SafeBootMin:[b]64bit:[/b] Primary disk - Driver Group SafeBootMin:[b]64bit:[/b] sacsvr - Service SafeBootMin:[b]64bit:[/b] SCSI Class - Driver Group SafeBootMin:[b]64bit:[/b] System Bus Extender - Driver Group SafeBootMin:[b]64bit:[/b] vmms - Service SafeBootMin:[b]64bit:[/b] WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootMin:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootMin: Ad-Aware Service - D:\Programy\Ad-Aware\AdAwareService.exe (Lavasoft Limited) SafeBootMin: AppMgmt - Service SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: MCODS - Reg Error: Value error. SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: sacsvr - Service SafeBootMin: SBAMSvc - D:\Programy\Ad-Aware\SBAMSvc.exe (GFI Software) SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vmms - Service SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet:[b]64bit:[/b] AppMgmt - Service SafeBootNet:[b]64bit:[/b] Base - Driver Group SafeBootNet:[b]64bit:[/b] Boot Bus Extender - Driver Group SafeBootNet:[b]64bit:[/b] Boot file system - Driver Group SafeBootNet:[b]64bit:[/b] File system - Driver Group SafeBootNet:[b]64bit:[/b] Filter - Driver Group SafeBootNet:[b]64bit:[/b] HelpSvc - Service SafeBootNet:[b]64bit:[/b] MCODS - Reg Error: Value error. SafeBootNet:[b]64bit:[/b] Messenger - Service SafeBootNet:[b]64bit:[/b] NDIS Wrapper - Driver Group SafeBootNet:[b]64bit:[/b] NetBIOSGroup - Driver Group SafeBootNet:[b]64bit:[/b] NetDDEGroup - Driver Group SafeBootNet:[b]64bit:[/b] Network - Driver Group SafeBootNet:[b]64bit:[/b] NetworkProvider - Driver Group SafeBootNet:[b]64bit:[/b] PCI Configuration - Driver Group SafeBootNet:[b]64bit:[/b] PNP Filter - Driver Group SafeBootNet:[b]64bit:[/b] PNP_TDI - Driver Group SafeBootNet:[b]64bit:[/b] Primary disk - Driver Group SafeBootNet:[b]64bit:[/b] rdsessmgr - Service SafeBootNet:[b]64bit:[/b] sacsvr - Service SafeBootNet:[b]64bit:[/b] SCSI Class - Driver Group SafeBootNet:[b]64bit:[/b] Streams Drivers - Driver Group SafeBootNet:[b]64bit:[/b] System Bus Extender - Driver Group SafeBootNet:[b]64bit:[/b] TDI - Driver Group SafeBootNet:[b]64bit:[/b] vmms - Service SafeBootNet:[b]64bit:[/b] WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootNet:[b]64bit:[/b] WudfUsbccidDriver - Driver SafeBootNet:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet:[b]64bit:[/b] {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet:[b]64bit:[/b] {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet:[b]64bit:[/b] {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet:[b]64bit:[/b] {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet:[b]64bit:[/b] {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: Ad-Aware Service - D:\Programy\Ad-Aware\AdAwareService.exe (Lavasoft Limited) SafeBootNet: AppMgmt - Service SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - Service SafeBootNet: MCODS - Reg Error: Value error. SafeBootNet: Messenger - Service SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SBAMSvc - D:\Programy\Ad-Aware\SBAMSvc.exe (GFI Software) SafeBootNet: SCSI Class - Driver Group SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vmms - Service SafeBootNet: WudfUsbccidDriver - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices [color=#E56717]========== Files/Folders - Created Within 60 Days ==========[/color] [2013/01/01 15:51:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\trend micro [2013/01/01 15:51:57 | 000,000,000 | ---D | C] -- C:\rsit [2012/12/31 16:26:25 | 000,000,000 | ---D | C] -- C:\Users\Adam\Desktop\6fe84fe7ac7805a731ff8c0f08034a71 [2012/12/31 16:26:08 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR [2012/12/31 16:26:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR [2012/12/31 00:12:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Ad-Aware Antivirus [2012/12/31 00:12:23 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\LavasoftStatistics [2012/12/31 00:02:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus [2012/12/31 00:02:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft [2012/12/31 00:01:23 | 000,047,496 | ---- | C] (GFI Software) -- C:\Windows\SysNative\sbbd.exe [2012/12/31 00:01:23 | 000,014,456 | ---- | C] (GFI Software) -- C:\Windows\SysNative\drivers\gfibto.sys [2012/12/31 00:00:00 | 000,000,000 | ---D | C] -- C:\ProgramData\blekko toolbars [2012/12/30 23:59:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\adawaretb [2012/12/30 23:59:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Toolbar Cleaner [2012/12/30 23:57:48 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\Ad-Aware Antivirus [2012/12/30 23:02:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy [2012/12/30 20:59:50 | 000,000,000 | ---D | C] -- C:\Users\Adam\Doctor Web [2012/12/30 11:10:17 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Adam\Desktop\OTL.exe [2012/12/29 17:11:42 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Local\Akamai [2012/12/29 17:11:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Applications [2012/12/29 15:59:10 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallJammer Registry [2012/12/29 15:59:06 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Soldis [2012/12/29 15:58:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Soldis PROJEKTANT [2012/12/29 15:41:09 | 000,000,000 | ---D | C] -- C:\ProgramData\WoW Worldwide Software LTD [2012/12/29 15:41:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SoftQuick [2012/12/29 15:40:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Premium [2012/12/29 15:40:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ContinueToSave [2012/12/29 15:40:01 | 000,000,000 | ---D | C] -- C:\ProgramData\InstallMate [2012/12/29 15:39:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt [2012/12/29 15:39:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NapiProjekt [2012/12/29 12:52:01 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\Malwarebytes [2012/12/29 12:51:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012/12/29 12:51:47 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2012/12/15 16:23:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2012/12/15 16:22:56 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes [2012/12/15 16:22:56 | 000,000,000 | ---D | C] -- C:\Program Files\iPod [2012/12/15 16:22:56 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 [2012/12/14 19:00:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [2012/12/14 19:00:41 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype [2012/12/14 19:00:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype [2012/11/27 17:33:47 | 000,000,000 | ---D | C] -- C:\Users\Adam\Documents\Autodesk [2012/11/24 16:28:34 | 000,000,000 | ---D | C] -- C:\Users\Adam\Desktop\Pobrane [2012/11/23 17:56:22 | 000,000,000 | ---D | C] -- C:\ProgramData\MemeoCommon [2012/11/23 17:50:44 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\Memeo [2012/11/23 17:50:27 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\Seagate [2012/11/23 17:50:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate Dashboard [2012/11/23 17:49:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Memeo [2012/11/23 17:49:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Memeo [2012/11/23 17:49:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Memeo [2012/11/23 17:49:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Seagate [2012/11/17 16:18:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [color=#E56717]========== Files - Modified Within 60 Days ==========[/color] [2013/01/01 16:07:00 | 006,553,600 | -HS- | M] () -- C:\Users\Adam\ntuser.dat [2013/01/01 15:51:15 | 000,781,383 | ---- | M] () -- C:\Users\Adam\Desktop\RSIT.exe [2013/01/01 15:37:09 | 000,025,120 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013/01/01 15:37:09 | 000,025,120 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013/01/01 15:28:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013/01/01 15:15:00 | 000,001,054 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-319703930-2572490357-2975701463-1000UA.job [2013/01/01 14:27:12 | 001,663,484 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013/01/01 14:27:12 | 000,738,208 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat [2013/01/01 14:27:12 | 000,652,376 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013/01/01 14:27:12 | 000,154,864 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat [2013/01/01 14:27:12 | 000,121,308 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013/01/01 14:24:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013/01/01 14:10:31 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\ContinueToSaveUpdaterTask{EE3D1E2A-0D0C-4142-BEAC-D554184FF8B1}.job [2013/01/01 14:10:27 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2013/01/01 14:10:10 | 3203,735,552 | -HS- | M] () -- C:\hiberfil.sys [2012/12/31 16:59:06 | 001,541,955 | -H-- | M] () -- C:\Users\Adam\AppData\Local\IconCache.db [2012/12/31 00:01:23 | 000,047,496 | ---- | M] (GFI Software) -- C:\Windows\SysNative\sbbd.exe [2012/12/31 00:01:23 | 000,014,456 | ---- | M] (GFI Software) -- C:\Windows\SysNative\drivers\gfibto.sys [2012/12/30 23:02:54 | 000,000,878 | ---- | M] () -- C:\Users\Adam\Desktop\Spybot - Search & Destroy.lnk [2012/12/30 19:15:18 | 000,001,002 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-319703930-2572490357-2975701463-1000Core.job [2012/12/30 19:02:43 | 107,644,520 | ---- | M] () -- C:\Users\Adam\Desktop\launch.exe [2012/12/30 14:47:10 | 2115,971,400 | ---- | M] () -- C:\Users\Adam\Desktop\Autodesk_Robot_Structural_Analysis_Professional_2012_Multilingual_Win_32-64bit.exe [2012/12/30 11:10:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Adam\Desktop\OTL.exe [2012/12/29 15:59:10 | 000,001,945 | ---- | M] () -- C:\Users\Public\Desktop\Soldis PROJEKTANT 7.0.lnk [2012/12/29 12:34:58 | 000,524,288 | -HS- | M] () -- C:\Users\Adam\ntuser.dat{d9cb46bd-51a4-11e2-9dff-b870f45d63bf}.TMContainer00000000000000000002.regtrans-ms [2012/12/29 12:34:58 | 000,524,288 | -HS- | M] () -- C:\Users\Adam\ntuser.dat{d9cb46bd-51a4-11e2-9dff-b870f45d63bf}.TMContainer00000000000000000001.regtrans-ms [2012/12/29 12:34:58 | 000,065,536 | -HS- | M] () -- C:\Users\Adam\ntuser.dat{d9cb46bd-51a4-11e2-9dff-b870f45d63bf}.TM.blf [2012/12/22 11:40:23 | 000,519,784 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2012/12/15 16:23:54 | 000,001,539 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk [2012/12/14 16:49:28 | 000,024,176 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2012/12/14 16:40:06 | 000,521,288 | ---- | M] () -- C:\Users\Adam\Desktop\obciazenia jednostkowe.pdf [2012/11/24 20:32:32 | 000,303,616 | ---- | M] () -- C:\Windows\SysNative\drivers\atksgt.sys [2012/11/23 17:50:22 | 000,001,224 | ---- | M] () -- C:\Users\Public\Desktop\Seagate Dashboard.lnk [2012/11/15 20:15:27 | 000,147,832 | ---- | M] () -- C:\Users\Adam\AppData\Local\GDIPFONTCACHEV1.DAT [2012/11/03 16:20:34 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2013/01/01 15:51:10 | 000,781,383 | ---- | C] () -- C:\Users\Adam\Desktop\RSIT.exe [2012/12/30 23:02:54 | 000,000,878 | ---- | C] () -- C:\Users\Adam\Desktop\Spybot - Search & Destroy.lnk [2012/12/30 18:54:53 | 107,644,520 | ---- | C] () -- C:\Users\Adam\Desktop\launch.exe [2012/12/30 12:05:49 | 2115,971,400 | ---- | C] () -- C:\Users\Adam\Desktop\Autodesk_Robot_Structural_Analysis_Professional_2012_Multilingual_Win_32-64bit.exe [2012/12/29 15:59:10 | 000,001,945 | ---- | C] () -- C:\Users\Public\Desktop\Soldis PROJEKTANT 7.0.lnk [2012/12/29 15:40:59 | 000,000,416 | -H-- | C] () -- C:\Windows\tasks\ContinueToSaveUpdaterTask{EE3D1E2A-0D0C-4142-BEAC-D554184FF8B1}.job [2012/12/29 14:47:22 | 001,541,955 | -H-- | C] () -- C:\Users\Adam\AppData\Local\IconCache.db [2012/12/29 12:31:41 | 000,524,288 | -HS- | C] () -- C:\Users\Adam\ntuser.dat{d9cb46bd-51a4-11e2-9dff-b870f45d63bf}.TMContainer00000000000000000002.regtrans-ms [2012/12/29 12:31:41 | 000,524,288 | -HS- | C] () -- C:\Users\Adam\ntuser.dat{d9cb46bd-51a4-11e2-9dff-b870f45d63bf}.TMContainer00000000000000000001.regtrans-ms [2012/12/29 12:31:41 | 000,065,536 | -HS- | C] () -- C:\Users\Adam\ntuser.dat{d9cb46bd-51a4-11e2-9dff-b870f45d63bf}.TM.blf [2012/12/15 16:23:54 | 000,001,539 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk [2012/12/14 16:40:04 | 000,521,288 | ---- | C] () -- C:\Users\Adam\Desktop\obciazenia jednostkowe.pdf [2012/11/23 17:50:22 | 000,001,224 | ---- | C] () -- C:\Users\Public\Desktop\Seagate Dashboard.lnk [2012/11/14 22:28:49 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf [2012/11/14 22:21:32 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf [2012/05/29 10:30:53 | 000,174,742 | ---- | C] () -- C:\Windows\hpoins45.dat [2012/05/18 13:34:13 | 000,644,608 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll [2012/05/18 13:34:13 | 000,258,048 | ---- | C] () -- C:\Windows\SysWow64\libFLAC.dll [2012/04/01 16:02:50 | 000,000,287 | ---- | C] () -- C:\Windows\game.ini [2012/02/25 22:21:02 | 000,007,599 | ---- | C] () -- C:\Users\Adam\AppData\Local\Resmon.ResmonCfg [2012/01/09 19:33:48 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll [2012/01/09 19:33:48 | 000,079,360 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll [2012/01/08 11:20:00 | 000,339,968 | ---- | C] () -- C:\Windows\SysWow64\pythoncom25.dll [2012/01/08 11:20:00 | 000,114,688 | ---- | C] () -- C:\Windows\SysWow64\pywintypes25.dll [2012/01/07 21:16:00 | 000,354,304 | ---- | C] () -- C:\Windows\SysWow64\pythoncom27.dll [2012/01/07 21:16:00 | 000,110,080 | ---- | C] () -- C:\Windows\SysWow64\pywintypes27.dll [2012/01/07 21:16:00 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\pythoncomloader27.dll [2011/12/15 19:17:34 | 000,003,584 | ---- | C] () -- C:\Users\Adam\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011/10/22 20:01:23 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll [2011/10/03 22:23:24 | 001,639,622 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2011/09/30 21:40:54 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2011/09/26 20:56:04 | 000,147,832 | ---- | C] () -- C:\Users\Adam\AppData\Local\GDIPFONTCACHEV1.DAT [2011/09/26 20:54:04 | 000,524,288 | -HS- | C] () -- C:\Users\Adam\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms [2011/09/26 20:54:04 | 000,524,288 | -HS- | C] () -- C:\Users\Adam\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms [2011/09/26 20:54:04 | 000,065,536 | -HS- | C] () -- C:\Users\Adam\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf [2011/09/26 20:54:04 | 000,000,020 | -HS- | C] () -- C:\Users\Adam\ntuser.ini [2011/09/26 20:54:03 | 006,553,600 | -HS- | C] () -- C:\Users\Adam\ntuser.dat [2011/04/23 13:55:12 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI [2011/04/23 13:43:55 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe [2011/02/03 18:56:58 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll [color=#E56717]========== ZeroAccess Check ==========[/color] [2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== LOP Check ==========[/color] [2012/12/31 00:31:14 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Ad-Aware Antivirus [2012/03/17 13:05:01 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Atari [2012/12/05 06:52:18 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Autodesk [2012/08/04 10:35:00 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\DAEMON Tools Lite [2012/11/24 00:54:07 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\DAEMON Tools Pro [2012/01/06 11:25:21 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\eu.myphotobook.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1 [2012/07/03 19:50:20 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Gadu-Gadu 10 [2012/12/29 19:11:22 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\GanymedeNet [2012/03/17 11:17:25 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Kalypso Media [2012/03/17 10:59:24 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Leadertech [2012/11/24 00:38:25 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Memeo [2012/05/30 17:49:47 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\NapiProjekt [2012/07/18 13:29:59 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\ObviousIdea [2012/07/12 18:42:10 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\OpenCandy [2011/11/15 12:03:00 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\OpenOffice.org [2012/10/22 19:30:18 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\PROCAD [2012/07/07 13:41:45 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Programy [2011/10/30 20:56:01 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Scilab [2012/11/23 17:50:27 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Seagate [2012/03/29 19:06:37 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\SoftGrid Client [2012/09/14 11:06:09 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Sony [2011/09/26 23:25:59 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Toshiba [2011/10/04 09:57:56 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\TOSHIBA Online Product Information [2011/10/03 22:23:55 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\TP [2012/12/29 12:30:37 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\uTorrent [2012/01/24 20:43:21 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\VshareComplete [2012/08/15 18:59:37 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\wargaming.net [2011/12/02 08:07:12 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\ZWSoft [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Custom Scans ==========[/color] [color=#A23BEC]< %systemdrive%\*.* >[/color] [2012/11/12 20:40:02 | 000,000,000 | ---- | M] () -- C:\1Clickfoldertest.txt [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1028.txt [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1031.txt [2007/11/07 07:00:40 | 000,010,134 | ---- | M] () -- C:\eula.1033.txt [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1036.txt [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1040.txt [2007/11/07 07:00:40 | 000,000,118 | ---- | M] () -- C:\eula.1041.txt [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1042.txt [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.2052.txt [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.3082.txt [2007/11/07 07:00:40 | 000,001,110 | ---- | M] () -- C:\globdata.ini [2013/01/01 14:10:10 | 3203,735,552 | -HS- | M] () -- C:\hiberfil.sys [2007/11/07 07:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe [2007/11/07 07:00:40 | 000,000,843 | ---- | M] () -- C:\install.ini [2007/11/07 07:03:18 | 000,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll [2007/11/07 07:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll [2007/11/07 07:03:18 | 000,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll [2007/11/07 07:03:18 | 000,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll [2007/11/07 07:03:18 | 000,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll [2007/11/07 07:03:18 | 000,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll [2007/11/07 07:03:18 | 000,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll [2007/11/07 07:03:18 | 000,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll [2007/11/07 07:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll [2012/04/10 14:55:40 | 000,032,915 | ---- | M] () -- C:\M1319.log [2013/01/01 14:10:14 | 4271,648,768 | -HS- | M] () -- C:\pagefile.sys [2011/04/23 13:41:54 | 000,002,234 | ---- | M] () -- C:\RHDSetup.log [2011/03/28 17:49:43 | 000,000,070 | -H-- | M] () -- C:\SWSTAMP.TXT [2012/01/02 13:48:44 | 000,001,495 | ---- | M] () -- C:\user.js [2007/11/07 07:00:40 | 000,005,686 | ---- | M] () -- C:\vcredist.bmp [2007/11/07 07:09:22 | 001,442,522 | ---- | M] () -- C:\VC_RED.cab [2007/11/07 07:12:28 | 000,232,960 | ---- | M] () -- C:\VC_RED.MSI [color=#A23BEC]< MD5 for: AGP440.SYS >[/color] [2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys [2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys [2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys [color=#A23BEC]< MD5 for: ATAPI.SYS >[/color] [2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys [2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys [2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys [color=#A23BEC]< MD5 for: BEEP.SYS >[/color] [2009/07/14 01:00:13 | 000,006,656 | ---- | M] (Microsoft Corporation) MD5=16A47CE2DECC9B099349A5F840654746 -- C:\Windows\SysNative\drivers\beep.sys [2009/07/14 01:00:13 | 000,006,656 | ---- | M] (Microsoft Corporation) MD5=16A47CE2DECC9B099349A5F840654746 -- C:\Windows\winsxs\amd64_microsoft-windows-beepsys_31bf3856ad364e35_6.1.7600.16385_none_201592fa214e4f02\beep.sys [color=#A23BEC]< MD5 for: CDROM.SYS >[/color] [2010/11/21 04:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\drivers\cdrom.sys [2010/11/21 04:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys [2010/11/21 04:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys [color=#A23BEC]< MD5 for: NDIS.SYS >[/color] [2012/08/22 19:06:07 | 000,950,128 | ---- | M] (Microsoft Corporation) MD5=5E74508FCB5820B29EEAFE24E6035BCF -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.22097_none_06232d534c0a8d67\ndis.sys [2012/08/22 19:12:40 | 000,950,128 | ---- | M] (Microsoft Corporation) MD5=760E38053BF56E501D562B70AD796B88 -- C:\Windows\SysNative\drivers\ndis.sys [2012/08/22 19:12:40 | 000,950,128 | ---- | M] (Microsoft Corporation) MD5=760E38053BF56E501D562B70AD796B88 -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.17939_none_05dc9a6832ba428a\ndis.sys [2010/11/21 04:23:55 | 000,951,680 | ---- | M] (Microsoft Corporation) MD5=79B47FD40D9A817E932F9D26FAC0A81C -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.17514_none_05ed313632ae9759\ndis.sys [color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color] [2010/11/21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe [2010/11/21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe < End of report > OTL Extras logfile created on: 1/1/2013 4:04:12 PM - Run 2 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Adam\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000409 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3.98 Gb Total Physical Memory | 2.06 Gb Available Physical Memory | 51.81% Memory free 7.95 Gb Paging File | 5.79 Gb Available in Paging File | 72.80% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 298.09 Gb Total Space | 218.89 Gb Free Space | 73.43% Space Free | Partition Type: NTFS Drive D: | 297.69 Gb Total Space | 189.31 Gb Free Space | 63.59% Space Free | Partition Type: NTFS Computer Name: ADAM-TOSHIBA | User Name: Adam | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: Off | File Age = 60 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~4\Office12\ONENOTE.EXE "%L" Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~4\Office12\ONENOTE.EXE "%L" Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{094CFB76-5066-4C4B-AA60-DACF135B28C3}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{12CA7623-3E3F-4163-AF39-7FF34AA30D2C}" = rport=10243 | protocol=6 | dir=out | app=system | "{212D3D2F-E8A7-4CBA-ADB8-70317C3F7CE5}" = lport=445 | protocol=6 | dir=in | app=system | "{21F7CEBE-0D9C-495D-90B6-4C2B01D45184}" = lport=138 | protocol=17 | dir=in | app=system | "{519160B0-69B7-4B5E-BDD0-FEA142035D25}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{55D9B36A-4B99-4D0A-AA72-2C78DE7BEA95}" = lport=137 | protocol=17 | dir=in | app=system | "{5F2BD67A-751C-4BEB-9C1B-546AFDAF3566}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{65CD3B7A-03ED-4257-92EA-D8366B085935}" = lport=2869 | protocol=6 | dir=in | app=system | "{74FBE3B2-8C8D-416A-B4C1-F95FF2E8C4AB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{818D6C54-2918-470F-8D60-E3201A6C2D79}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{907EE603-9C1A-4044-B82D-46A475A62D06}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{918146C0-E442-4457-A33D-ABBA0784845F}" = lport=10243 | protocol=6 | dir=in | app=system | "{9B04C10D-B0DC-40B0-BAC8-DD40A5EDF009}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{A6B3F750-DD94-430A-B8C2-DBA86B7881C1}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{AC07E7FF-1906-4277-85C8-3A42542FB12B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{BFEAFAD9-79F1-4401-9CAD-72AFEF4276A5}" = rport=139 | protocol=6 | dir=out | app=system | "{CAE9E3EC-A56E-4D64-913C-BBEFFF030FBF}" = rport=137 | protocol=17 | dir=out | app=system | "{D44B3782-F6E3-4F07-BEC1-CA6FCAA8EF38}" = rport=138 | protocol=17 | dir=out | app=system | "{DB4165A7-AA3E-4C26-8D3F-F12F484D770C}" = rport=445 | protocol=6 | dir=out | app=system | "{E19A50B5-0464-4A6D-86A9-BAC3C4318305}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{E4D18DB3-A97F-4787-9E84-4B25BE40E4A5}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{F0E68969-A195-419C-A2FE-2E3B7726E061}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{F988C693-8A5D-467B-8C7F-520547BAF434}" = lport=139 | protocol=6 | dir=in | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0720C203-F64C-4138-832C-C316F4477579}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqcopy2.exe | "{128E6BBC-98B8-4F3C-B2EE-D2EB7EEA5CA3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{18F6CD47-17CC-40DA-BA09-4AC68BE0A9CE}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{19D486B0-1410-4E3B-995A-A44F10DC7371}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{2238DCA3-ACB6-42BF-9139-A8C670F1003B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe | "{25E1E729-0B50-4DAF-98AF-B0B6ACA969B1}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{261838AB-481A-44AE-B692-C756715AD704}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe | "{28F6A0DA-5523-4888-AB08-5F114F842AC9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{2A89A8EF-1F5F-4C05-BC9F-231FF0B8F1D1}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe | "{2EE8C41B-7930-47D6-8780-951B5C7D9994}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe | "{3059DE52-517B-476A-97A7-02642B4445C8}" = protocol=6 | dir=out | app=system | "{36D2E2F9-72DD-4B7B-8708-290D1BD0FAA4}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe | "{3D04F373-162D-4CE8-AFD5-A290F1746FFD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{3D8FB1DF-CB9E-4A21-BB81-814867C8D92B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{4813F9E4-9E56-487A-9E6F-DEABF6716244}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{5D621279-2987-4DEB-932C-3A81D455BF4B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe | "{60BA7020-5735-4274-AA33-CE12ABCF6B5F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{706DE1A9-29BA-4259-A346-2C2C1D692757}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{76D41A3F-FAE2-4E77-8B57-5983731999ED}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{7E018989-3D49-4769-9E5A-956B3804C83D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{825B0FC9-C8B4-4595-8D77-70667B9130C1}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{84E2008C-92AF-4D56-89BF-5653C5FA68E9}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe | "{89FBDF2A-4024-4409-9BC7-2164275BA25B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe | "{93FD57D8-A1DD-44C1-A863-210E30978CCC}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{968B58F1-6C47-4789-848A-80C57F20FB23}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe | "{9828B130-E990-4C39-83EE-508576F8318B}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{9D138229-E2FF-42AB-926A-EE0044C7E6CB}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe | "{A292D33C-D73C-4087-A004-86C92D99920A}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{BEAF98C9-2C09-443E-BFEF-14183E486DF8}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe | "{CA77A647-C547-47FB-B290-20252985D5B8}" = dir=in | app=c:\program files (x86)\seagate\seagate dashboard\hipservagent\hipservagent.exe | "{D0C10F8E-B6F4-4EB0-B688-2F77D6F1B19F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{D2F899D7-CA22-4C64-A3A3-6DA14C44EF9A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{D71F5A0C-592C-4480-96E3-0C86ABEF5F1E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{D8A7E1A4-99EC-433B-944C-F581533131A5}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe | "{E4AEEE9C-9B17-4ED2-AD55-03425AF64318}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{E673AC68-B661-48EE-83CD-B492DE4BA6CB}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe | "{E9D24D47-6A57-40A4-939E-AC1E085FA583}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{EDF670B0-21C2-4FCF-9240-65683366954E}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{F74124FD-E31A-4739-8142-766695981DC9}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{FA53E896-DBDD-4A1A-AD63-336638E55015}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{FCC9F8E6-D5B3-45C8-BEFD-E36FA961A218}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "TCP Query User{31081F40-F8E9-454B-BD21-567123C26069}C:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe" = protocol=6 | dir=in | app=c:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe | "TCP Query User{65C7CB83-2B07-478E-850D-BB7A96F92436}C:\users\adam\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\adam\appdata\local\akamai\netsession_win.exe | "TCP Query User{7D63A7DA-4A0D-40DD-AF06-627327FEFC6A}C:\program files (x86)\allmediaserver\mediaserver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\allmediaserver\mediaserver.exe | "TCP Query User{C671ACF3-C9D0-4E8D-A592-462BBABD87BC}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe | "TCP Query User{D0CCD619-292C-47EA-B6A5-3A9EF45A2C50}C:\program files (x86)\1clickdownload\1clickdownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\1clickdownload\1clickdownloader.exe | "TCP Query User{D40871D4-8EA3-4419-B9EF-DD32A6B409E8}C:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe" = protocol=6 | dir=in | app=c:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe | "TCP Query User{E60E4261-01E5-4B3B-9D06-555F0CDFC4D0}C:\users\adam\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\adam\appdata\local\akamai\netsession_win.exe | "UDP Query User{12527538-DE98-49AC-AE11-3DCA33E53A3D}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe | "UDP Query User{2613D914-28CB-4089-A263-EE761064D391}C:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe" = protocol=17 | dir=in | app=c:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe | "UDP Query User{2D23835C-E028-4E5E-BDD0-B69673F6A8E7}C:\users\adam\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\adam\appdata\local\akamai\netsession_win.exe | "UDP Query User{528FDE88-C913-4254-920E-A0AA1F7A44E9}C:\program files (x86)\allmediaserver\mediaserver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\allmediaserver\mediaserver.exe | "UDP Query User{985B1D64-5C17-4C83-B09F-FADFBA7C062B}C:\program files (x86)\1clickdownload\1clickdownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\1clickdownload\1clickdownloader.exe | "UDP Query User{9CA09DDF-2238-4B9F-B07E-B1D017A943CC}C:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe" = protocol=17 | dir=in | app=c:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe | "UDP Query User{E4EFA3CA-6B1F-4B7E-A729-A57DB6C10996}C:\users\adam\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\adam\appdata\local\akamai\netsession_win.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{0E5D76AD-A3FB-48D5-8400-8903B10317D3}" = iTunes "{19F09425-3C20-4730-9E2A-FC2E17C9F362}" = Windows Live Remote Service Resources "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant "{230C483A-BCB8-4AA1-AC28-6CDAED005E71}" = Autodesk Robot Structural Analysis Professional 2012 - Polish regional settings "{2426E29F-9E8C-4C0B-97FC-0DB690C1ED98}" = Windows Live Remote Client Resources "{2A8EEE2F-4A9E-43D8-AA07-EC8A316B2DEB}" = Autodesk Revit Architecture 2010 x64 "{2F304EF4-0C31-47F4-8557-0641AAE4197C}" = Windows Live Remote Client Resources "{34384A2A-2CA2-4446-AB0E-1F360BA2AAC5}" = Windows Live Remote Service Resources "{3921492E-82D2-4180-8124-E347AD2F2DB4}" = Windows Live Remote Client Resources "{4200F74C-623C-7FFF-9D14-2A1E99E3D5BA}" = ContinueToSave "{480F28F0-8BCE-404A-A52E-0DBB7D1CE2EF}" = Windows Live Remote Service Resources "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5141AA6E-5FAC-4473-BFFB-BEE69DDC7F2B}" = Windows Live Remote Service Resources "{5151E2DB-0748-4FD1-86A2-72E2F94F8BE7}" = Windows Live Remote Service Resources "{5783F2D7-9001-0415-0102-0060B0CE6BBA}" = AutoCAD 2011 - Polski "{5783F2D7-9001-0415-1102-0060B0CE6BBA}" = AutoCAD 2011 Language Pack - Polski "{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator "{5F44A3A1-5D24-4708-8776-66B42B174C64}" = Windows Live Remote Client Resources "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6051912A-F7B8-445C-A99D-81AA4C118836}" = HP Deskjet Ink Advant K209a-z All-in-One Driver Software 14.0 Rel. 6 "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{8E5DA9A6-7A9F-3A6F-BC5C-D6CBCA6A29C7}" = Microsoft .NET Framework 4 Extended PLK Language Pack "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2007 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{A49402DD-2781-3782-B0CF-52BDA349E3F3}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{AC0A533B-5E29-4081-8D1E-31BE65320527}" = Autodesk Robot Structural Analysis Professional 2012 "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 267.21 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 267.21 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 267.21 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.1.13.1 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64 "{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector "{D0CB24F4-084F-40DE-B6B9-A03626E682F0}" = iCloud "{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{DBEDAF67-C5A3-4C91-951D-31F3FE63AF3F}" = Windows Live Remote Client Resources "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORMCLauncher "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer "AutoCAD 2011 - Polski" = AutoCAD 2011 - Polski "Autodesk Revit Architecture 2010 x64" = Autodesk Revit Architecture 2010 x64 "Autodesk Robot Structural Analysis Professional 2012" = Autodesk Robot Structural Analysis Professional 2012 "CCleaner" = CCleaner "ContinueToSave" = "HP Imaging Device Functions" = HP Imaging Device Functions 14.0 "HP Smart Web Printing" = HP Smart Web Printing 4.60 "HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0 "HPExtendedCapabilities" = HP Customer Participation Program 14.0 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft .NET Framework 4 Extended PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Extended "Shop for HP Supplies" = Shop for HP Supplies "SynTPDeinstKey" = Synaptics Pointing Device Driver "WinRAR archiver" = WinRAR 4.20 (64-bitowy) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0654EA5D-308A-4196-882B-5C09744A5D81}" = Windows Live Photo Common "{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan "{09922FFE-D153-44AE-8B60-EA3CB8088F93}" = Windows Live UX Platform Language Pack "{0A50CB27-D2D5-4B7D-A001-30B1782A450B}" = DJ_AIO_06_K209a-z_SW_Min "{0A9256E0-C924-46DE-921B-F6C4548A1C64}" = Windows Live Messenger "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0C1931EB-8339-4837-8BEC-75029BF42734}" = Windows Live UX Platform Language Pack "{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1 "{11778DA1-0495-4ED9-972F-F9E0B0367CD5}" = Windows Live Writer "{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver "{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery "{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant "{1727CD47-A408-11d2-AFAD-00C04F72FB3E}" = VBA (2720) "{17F99FCE-8F03-4439-860A-25C5A5434E18}" = Windows Live Essentials "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{1DA6D447-C54D-4833-84D4-3EA31CAECE9B}" = Windows Live UX Platform Language Pack "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{1FC83EAE-74C8-4C72-8400-2D8E40A017DE}" = Windows Live Writer "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 29 "{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 9 "{26E3C07C-7FF7-4362-9E99-9E49E383CF16}" = Windows Live Writer Resources "{2819e172-81d5-4113-88bd-4605b02344e0}" = Ad-Aware Antivirus "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections "{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox "{299C0434-4F4E-341F-A916-4E07AEB35E79}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime "{2C303EE0-A595-3543-A71A-931C7AC40EDE}" = Microsoft Primary Interoperability Assemblies 2005 "{2C7E8AA1-9C03-4606-BF34-5D99D07964DA}" = Windows Live Messenger "{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update "{2FB9EA69-51D4-4913-9AD5-762C034DE811}" = Status "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{34C4F5AF-D757-4E6A-ABCA-65AB5A50A1A8}" = Windows Live Messenger "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{4264C020-850B-4F08-ACBE-98205D9C336C}" = Windows Live Writer "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4B28D47A-5FF0-45F8-8745-11DC2A1C9D0F}" = Windows Live Writer "{50300123-F8FC-4B50-B449-E847D04F1BA2}" = Windows Live Messenger "{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion "{5275D81E-83AD-4DE4-BC2B-6E6BA3A33244}" = Windows Live Writer Resources "{55D9E026-DCB0-46FF-B60A-68B972228CF6}" = Autodesk Design Review 2010 "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack "{5A3ECDDA-562C-4281-BFE5-A4C8F32EACA3}" = K209a-z "{5DCF0E4B-F8EA-4229-A0BD-5CA6D4AFB749}" = SolutionCenter "{5E627606-53B9-42D1-97E1-D03F6229E248}" = Windows Live UX Platform Language Pack "{5f6460bd-391e-43ce-bcf3-130ef02f8cb2}_is1" = VshareComplete "{60C3C026-DB53-4DAB-8B97-7C1241F9A847}" = Windows Live Movie Maker "{64376910-1860-4CEF-8B34-AA5D205FC5F1}" = Poczta usługi Windows Live "{6491AB99-A11E-41FD-A5E7-32DE8A097B8E}" = Windows Live Essentials "{64B2D6B3-71AC-45A7-A6A1-2E07ABF58341}" = Windows Live Movie Maker "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6ABE832B-A5C7-44C1-B697-3E123B7B4D5B}" = Windows Live Mesh "{6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94}" = TOSHIBA Resolution+ Plug-in for Windows Media Player "{6D2F0A26-ECEA-49CE-833C-9A6125F3D5E8}" = Doplnok programu Messenger "{6E29C4F7-C2C2-4B18-A15C-E09B92065F15}" = Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz "{6EE9F44A-B8C7-4CDB-B2A9-441AF2AE315A}" = Windows Live Messenger "{6F37D92B-41AA-44B7-80D2-457ABDE11896}" = Windows Live Photo Common "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{7272F232-A7E0-4B2B-A5D2-71B7C5E2379C}" = Windows Live Fotótár "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{7496FD31-E5CB-4AE4-82D3-31099558BF6A}" = Windows Live Mesh "{74E8A7F6-575D-42C7-9178-E87D1B3BEFE8}" = Windows Live UX Platform Language Pack "{75B7F766-7998-44d8-A202-F1EC76A121BA}" = Memeo AutoSync "{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{78906B56-0E81-42A7-AC25-F54C946E1538}" = Windows Live Photo Common "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core "{7A9D47BA-6D50-4087-866F-0800D8B89383}" = Podstawowe programy Windows Live "{7CB529B2-6C74-4878-9C3F-C29C3C3BBDC6}" = Windows Live Writer Resources "{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger "{80E8C65A-8F70-4585-88A2-ABC54BABD576}" = Windows Live Mesh "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{84267681-BF16-40B6-9564-27BC57D7D71C}" = Windows Live Photo Common "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8E666407-AC41-46a2-9692-6C7BFCBFDD37}" = Memeo Instant Backup "{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg "{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}_HOMESTUDENTR_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}_HOMESTUDENTR_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}_HOMESTUDENTR_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-001F-0415-0000-0000000FF1CE}_HOMESTUDENTR_{9CC96D78-9E1D-46E0-AF4D-3EB440CD4619}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002A-0415-1000-0000000FF1CE}_HOMESTUDENTR_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}_HOMESTUDENTR_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}_HOMESTUDENTR_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{94B4E2D8-A184-415C-BF9E-F699D76466BD}" = Heroes of Might and Magic IV - Złota Edycja "{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}" = FARO LS 1.1.406.58 "{96403552-88D1-429F-9C92-388B814B885E}" = Messenger Companion "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader "{97F77D62-5110-4FA3-A2D3-410B92D31199}" = Windows Live Fotogaléria "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE466FF-70B7-4DA8-807C-DB4C3610FDAA}" = Copy "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D3D8C60-A55F-4fed-B2B9-173001290E16}" = Realtek WLAN Driver "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{9DEABCB6-B759-4D52-92F8-51B34A2B4D40}" = Autodesk Material Library 2011 "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer "{AB78C965-5C67-409B-8433-D7B5BDB12073}" = Windows Live Writer Resources "{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply "{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.4) MUI "{AD001A69-88CC-4766-B2DB-3C1DFAB9AC72}" = Windows Live Mesh "{ADE85655-8D1E-4E4B-BF88-5E312FB2C74F}" = Windows Live Mail "{ADFE4AED-7F8E-4658-8D6E-742B15B9F120}" = Windows Live Photo Common "{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime "{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}" = Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych "{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B44F3823-52DD-45CA-A916-8B320778715D}" = Messenger Companion "{B6190387-0036-4BEB-8D74-A0AFC5F14706}" = Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení "{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX "{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2 "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations "{BD8DA595-F501-4ABE-85A0-5C23E82472A0}" = Pomocnik Messenger "{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo "{BF022D76-9F72-4203-B8FA-6522DC66DFDA}" = Windows Live Movie Maker "{BF35168D-F6F9-4202-BA87-86B5E3C9BF7A}" = Windows Live Mesh "{C00C2A91-6CB3-483F-80B3-2958E29468F1}" = Συλλογή φωτογραφιών του Windows Live "{C29FC15D-E84B-4EEC-8505-4DED94414C59}" = Windows Live Writer Resources "{C2FD7DB5-FE30-49B6-8A2F-C5652E053C31}" = Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia "{C3A11907-930D-41AC-A135-CC3B12F92011}" = Seagate Dashboard "{C454280F-3C3E-4929-B60E-9E6CED5717E7}" = Windows Live Mail "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{C8421D85-CA0E-4E93-A9A9-B826C4FB88EA}" = Windows Live Mail "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget "{CB3F59BB-7858-41A1-A7EA-4B8A6FC7D431}" = Galeria fotografii usługi Windows Live "{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Obsługa programów Apple "{CD1E078C-A6B9-47DA-B035-6365C85C7832}" = Autodesk Material Library 2011 Base Image library "{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime "{E55E0C35-AC3C-4683-BA2F-834348577B80}" = Windows Live Writer "{E5F05232-96B6-4552-A480-785A60A94B21}" = System Requirements Lab CYRI "{EA17F4FC-FDBF-4CF8-A529-2D983132D053}" = Skype™ 6.0 "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F3ECEB0A-82A0-4DB9-BB44-393A66BA0871}" = Messenger kísérő "{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}" = Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις "{F80E5450-3EF3-4270-B26C-6AC53BEC5E76}" = Windows Live Movie Maker "{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm "{FA6CF94F-DACF-4FE7-959D-55C421B91B17}" = Windows Live Mail "{FB3D07AE-73D0-47A9-AC12-6F50BF8B6202}" = Windows Live Movie Maker "{FB79FDB7-4DE1-453D-99FE-9A880F57380E}" = Windows Live Fotogalerie "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "{FE62C88B-425B-4BDE-8B70-CD5AE3B83176}" = Windows Live Essentials "{FE77909E-B782-4554-A92A-4D887CEF0ACC}_is1" = ALLMediaServer "{FEEF7F78-5876-438B-B554-C4CC426A4302}" = Windows Live Essentials "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "ALLPlayer_is1" = ALLPlayer V5.X "Autodesk Design Review 2010" = Autodesk Design Review 2010 "avast" = avast! Free Antivirus "E94B1101-7675-4E37-9CB2-2E38A872154A" = Soldis PROJEKTANT "GameDesire-Pool & Snooker" = GameDesire-Pool & Snooker "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "InstallShield_{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver "InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORMCLauncher "LiveVDO plugin" = LiveVDO plugin 1.3 "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 1.70.0.1100 "NapiProjekt_is1" = NapiProjekt 2.0.0 (build 2151) "NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver "Revo Uninstaller" = Revo Uninstaller 1.94 "SP_a8235b05" = Search Assistant SoftQuick 1.66 "SP_e14dcdfa" = "vShare plugin" = vShare plugin 1.3 "vShare.tv plugin" = vShare.tv plugin 1.3 "WinLiveSuite" = Podstawowe programy Windows Live "wxPython2.8-unicode-py25_is1" = wxPython 2.8.4.0 (unicode) for Python 2.5 "YDP Flash Speech Recognition Support" = YDP Flash Speech Recognition Support 1.0 [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Akamai" = Akamai NetSession Interface "Google Chrome" = Google Chrome [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 9/14/2012 5:26:00 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/14/2012 5:50:58 AM | Computer Name = Adam-TOSHIBA | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: ISAdmin.exe, wersja: 14.0.0.162, sygnatura czasowa: 0x4626b2f4 Nazwa modułu powodującego błąd: unknown, wersja: 0.0.0.0, sygnatura czasowa: 0x00000000 Kod wyjątku: 0xc000041d Przesunięcie błędu: 0x74a44f0d Identyfikator procesu powodującego błąd: 0x1030 Godzina uruchomienia aplikacji powodującej błąd: 0x01cd925e574f0388 Ścieżka aplikacji powodującej błąd: C:\Users\Adam\AppData\Local\Temp\pftFD15.tmp\ISAdmin.exe Ścieżka modułu powodującego błąd: unknown Identyfikator raportu: aefa5b22-fe51-11e1-99e8-b870f45d63bf Error - 9/15/2012 4:39:11 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/15/2012 5:35:12 PM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/16/2012 4:57:07 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/16/2012 5:06:09 AM | Computer Name = Adam-TOSHIBA | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: setup.exe_Sony PC Companion, wersja: 17.0.0.717, sygnatura czasowa: 0x4cab8cfa Nazwa modułu powodującego błąd: wer.dll, wersja: 6.1.7601.17514, sygnatura czasowa: 0x4ce7ba29 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x00052140 Identyfikator procesu powodującego błąd: 0x5c4 Godzina uruchomienia aplikacji powodującej błąd: 0x01cd93e98fbd0fb3 Ścieżka aplikacji powodującej błąd: C:\Users\Adam\AppData\Local\Temp\{4FCEB9B4-7DBD-4616-85D3-474129838BA8}\setup.exe Ścieżka modułu powodującego błąd: C:\Windows\SysWOW64\wer.dll Identyfikator raportu: c0c7921c-ffdd-11e1-9afd-b870f45d63bf Error - 9/16/2012 12:22:31 PM | Computer Name = Adam-TOSHIBA | Source = Application Hang | ID = 1002 Description = Program ALLPlayer.exe w wersji 5.1.0.0 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: d60 Godzina rozpoczęcia: 01cd94276fc009d3 Godzina zakończenia: 89 Ścieżka aplikacji: D:\Programy\ALLPlayer\ALLPlayer.exe Identyfikator raportu: b51a3d35-001a-11e2-9afd-b870f45d63bf Error - 9/17/2012 9:26:47 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/18/2012 5:29:08 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/18/2012 1:55:17 PM | Computer Name = Adam-TOSHIBA | Source = Application Hang | ID = 1002 Description = Program ALLPlayer.exe w wersji 5.1.0.0 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: e48 Godzina rozpoczęcia: 01cd95c6b978bdcb Godzina zakończenia: 69 Ścieżka aplikacji: D:\Programy\ALLPlayer\ALLPlayer.exe Identyfikator raportu: fdf908bc-01b9-11e2-9e3c-b870f45d63bf Error - 9/19/2012 6:37:41 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/20/2012 6:54:32 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/21/2012 3:41:10 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = [ OSession Events ] Error - 5/4/2012 6:44:51 PM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6612.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 28 seconds with 0 seconds of active time. This session ended with a crash. Error - 11/9/2012 6:05:13 AM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 1426 seconds with 1200 seconds of active time. This session ended with a crash. Error - 11/9/2012 6:06:04 AM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 22 seconds with 0 seconds of active time. This session ended with a crash. Error - 11/9/2012 6:10:35 AM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 226 seconds with 180 seconds of active time. This session ended with a crash. Error - 11/9/2012 6:11:39 AM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 34 seconds with 0 seconds of active time. This session ended with a crash. Error - 11/9/2012 6:13:37 AM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 69 seconds with 0 seconds of active time. This session ended with a crash. Error - 11/9/2012 6:16:33 AM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 130 seconds with 60 seconds of active time. This session ended with a crash. Error - 11/9/2012 2:37:33 PM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 27 seconds with 0 seconds of active time. This session ended with a crash. Error - 12/16/2012 6:40:06 PM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 5327 seconds with 2700 seconds of active time. This session ended with a crash. [ System Events ] Error - 12/30/2012 4:50:42 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7022 Description = Usługa Intel(R) Management and Security Application User Notification Service zawiesiła się podczas uruchamiania. Error - 12/30/2012 6:25:10 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi atksgt z powodu następującego błędu: %%577 Error - 12/30/2012 6:25:22 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Internet Manager. OUC z powodu następującego błędu: %%2 Error - 12/30/2012 6:32:33 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7022 Description = Usługa Windows Update zawiesiła się podczas uruchamiania. Error - 12/30/2012 6:34:40 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7022 Description = Usługa Intel(R) Management and Security Application User Notification Service zawiesiła się podczas uruchamiania. Error - 12/31/2012 5:04:38 AM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi atksgt z powodu następującego błędu: %%577 Error - 12/31/2012 5:04:38 AM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Internet Manager. OUC z powodu następującego błędu: %%2 Error - 1/1/2013 9:10:34 AM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi atksgt z powodu następującego błędu: %%577 Error - 1/1/2013 9:10:52 AM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Internet Manager. OUC z powodu następującego błędu: %%2 Error - 1/1/2013 9:16:35 AM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7022 Description = Usługa Windows Update zawiesiła się podczas uruchamiania. < End of report > [/log]wykonałem kopię zapasową na dysku zewnętrznym przed złapaniem tej 'infekcji', więc może najlepszym pomysłem byłby przywrócenie plików z tej kopii ? Dysk to Seagate GoFlex Desk a kopia wykonana została programem załączonym do dysku - Memeo Instant Backup. Boję się tylko żeby nie zainfekowało mi dysku, bo wtedy będzie już koniec. Proszę o porady, w miarę szybko, sami dobrze wiecie jak liczy się czas przy zawirusowanym komputerze, a muszę zacząć pracować na nim.... Może po prostu format zrobić?
Ten post jest popularny. Natsuki Kuga komentarz 2 stycznia 2013 Ten post jest popularny. komentarz 2 stycznia 2013 [quote name='adam205' timestamp='1357064933' post='1661016'] Boję się tylko żeby nie zainfekowało mi dysku, bo wtedy będzie już koniec. Proszę o porady, w miarę szybko, sami dobrze wiecie jak liczy się czas przy zawirusowanym komputerze, a muszę zacząć pracować na nim.... Może po prostu format zrobić? [/quote] Tak by się stało w przypadku infekcji plików wykonywalnych, a tu takowej nie ma. Spokojnie, żaden format dysku tu nie jest potrzebny. Zaktualizuj Avasta do wersji 7, odinstaluj Spybota. Do OTL wklej: [code] :OTL IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://websearch.soft-quick.info/ IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperba...q={searchTerms} IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.sof...q={searchTerms} IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperba...q={searchTerms} IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.helperba...q={searchTerms} IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://websearch.soft-quick.info/ IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.helperba...q={searchTerms} IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.helperba...q={searchTerms} IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5} IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperba...q={searchTerms} IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\..\SearchScopes\{711DE046-A996-446D-8872-2FA584763384}: "URL" = http://startsear.ch/...q={searchTerms} IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.sof...q={searchTerms} FF - prefs.js..browser.startup.homepage: "http://websearch.soft-quick.info/" FF - prefs.js..browser.search.order.1: "WebSearch" FF - prefs.js..browser.search.defaultenginename: "WebSearch" FF - prefs.js..browser.search.selectedEngine: "WebSearch" FF - prefs.js..browser.search.defaulturl: "http://websearch.soft-quick.info/?l=1&q=" FF - prefs.js..browser.search.order.1,S: S", "WebSearch" FF - prefs.js..browser.search.defaultenginename,S: S", "WebSearch" FF - prefs.js..browser.search.selectedEngine,S: S", "WebSearch" FF - prefs.js..keyword.URL: "http://websearch.soft-quick.info/?l=1&q=" CHR - homepage: http://websearch.soft-quick.info/ O3:64bit: - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found. O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4 - HKLM..\Run: [] File not found :Commands [emptytemp] [/code] [b]Wykonaj skrypt,[/b] pokaż raport. Użyj [url="http://download.bleepingcomputer.com/dl/1e5bdaa465f479e8f8e0d58ce650e203/50e1462e/windows/security/security-utilities/a/adwcleaner/AdwCleaner.exe"][b]AdwCleaner[/b][/url] z opcji [b]Delete.[/b] Pokaż raport. Po wykonaniu pokaż nowe logi z OTL i RSIT. 2
adam205 komentarz 2 stycznia 2013 Autor komentarz 2 stycznia 2013 Logi z RSiT: [log] Logfile of random's system information tool 1.09 (written by random/random) Run by Adam at 2013-01-02 20:01:52 Microsoft Windows 7 Home Premium Service Pack 1 System drive C: has 224 GB (73%) free of 305 GB Total RAM: 4074 MB (53% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 20:01:55, on 2013-01-02 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v8.00 (8.00.7601.17514) Boot mode: Normal Running processes: C:\ProgramData\DatacardService\DCSHelper.exe D:\Programy\Daemon Tools Pro\DTShellHlp.exe C:\Users\Adam\AppData\Local\Akamai\netsession_win.exe C:\Users\Adam\AppData\Local\Akamai\netsession_win.exe D:\Programy\Avast\AvastUI.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoDashboard.exe C:\Program Files (x86)\Memeo\AutoBackup\InstantBackup.exe C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Adam\Desktop\RSIT.exe C:\Program Files (x86)\trend micro\Adam.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba.msn.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe, O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Programy\Avast\aswWebRepIE.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll O2 - BHO: IplexToALLPlayer - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - D:\Programy\ALLPlayer\Iplex\IplexToALLPlayer.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Programy\Avast\aswWebRepIE.dll O4 - HKLM\..\Run: [avast5] "D:\Programy\Avast\avastUI.exe" /nogui O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [Memeo Instant Backup] C:\Program Files (x86)\Memeo\AutoBackup\MemeoLauncher2.exe --silent --no_ui O4 - HKLM\..\Run: [Memeo AutoSync] C:\Program Files (x86)\Memeo\AutoSync\MemeoLauncher2.exe --silent O4 - HKLM\..\Run: [Seagate Dashboard] C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoLauncher.exe --silent --no_ui O4 - HKCU\..\Run: [Google Update] "C:\Users\Adam\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [ALLUpdate] "D:\Programy\ALLPlayer\ALLUpdate.exe" "sleep" O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Adam\AppData\Local\Akamai\netsession_win.exe" O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'USŁUGA LOKALNA') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'USŁUGA LOKALNA') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'USŁUGA SIECIOWA') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'USŁUGA SIECIOWA') O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Wyślij &do programu OneNote - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105 O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL O9 - Extra button: Pokaż lub ukryj HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{A9E0C5C0-9E6A-410A-8719-DD8EAFE4AB0C}: NameServer = 213.158.199.1 213.158.199.5 O17 - HKLM\System\CCS\Services\Tcpip\..\{F3591DBC-AF36-469B-87F5-DC25CE0EB967}: NameServer = 213.158.199.1 213.158.199.5 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Autodesk Network Licensing Service - Autodesk, Inc. - C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskNetSrv.exe O23 - Service: avast! Antivirus - AVAST Software - D:\Programy\Avast\AvastSvc.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe O23 - Service: HWDeviceService64.exe - Unknown owner - C:\ProgramData\DatacardService\HWDeviceService64.exe O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: Internet Manager. OUC (Internet Manager. RunOuc) - Unknown owner - D:\Programy\UpdateDog\ouc.exe (file missing) O23 - Service: Usługa iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: MemeoBackgroundService - Memeo - C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Seagate Dashboard Service (SeagateDashboardService) - Memeo - C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing) O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 12496 bytes ======Scheduled tasks folder====== C:\Windows\tasks\Adobe Flash Player Updater.job C:\Windows\tasks\ContinueToSaveUpdaterTask{EE3D1E2A-0D0C-4142-BEAC-D554184FF8B1}.job C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-319703930-2572490357-2975701463-1000Core.job C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-319703930-2572490357-2975701463-1000UA.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}] HP Print Enhancer - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22 328248] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-09-24 449512] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] avast! WebRep - D:\Programy\Avast\aswWebRepIE.dll [2012-10-30 1227736] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}] Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-11-10 393600] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-09-24 155384] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF925EF3-7A87-44E4-9CAF-8D7B280BF616}] IplexToALLPlayer - D:\Programy\ALLPlayer\Iplex\IplexToALLPlayer.dll [2011-02-09 400384] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}] HP Smart BHO Class - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22 517688] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - D:\Programy\Avast\aswWebRepIE.dll [2012-10-30 1227736] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "avast5"=D:\Programy\Avast\avastUI.exe [2012-10-30 4297136] "SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848] "Memeo Instant Backup"=C:\Program Files (x86)\Memeo\AutoBackup\MemeoLauncher2.exe [2011-05-04 136416] "Memeo AutoSync"=C:\Program Files (x86)\Memeo\AutoSync\MemeoLauncher2.exe [2011-05-05 144608] "Seagate Dashboard"=C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoLauncher.exe [2011-06-01 79112] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Google Update"=C:\Users\Adam\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-25 116648] "ALLUpdate"=D:\Programy\ALLPlayer\ALLUpdate.exe [2012-10-08 2991616] "Akamai NetSession Interface"=C:\Users\Adam\AppData\Local\Akamai\netsession_win.exe [2012-10-09 4441920] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableLockWorkstation"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "EnableUIADesktopToggle"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoActiveDesktop"=1 "NoActiveDesktopChanges"=1 "ForceActiveDesktopOn"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "vidc.uyvy"=msyuv.dll "vidc.yuy2"=msyuv.dll "vidc.yvyu"=msyuv.dll "vidc.iyuv"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "vidc.yvu9"=tsbyuv.dll "msacm.l3acm"=l3codeca.acm "vidc.cvid"=iccvid.dll "msacm.siren"=sirenacm.dll "wave1"=wdmaud.drv "midi1"=wdmaud.drv "mixer1"=wdmaud.drv "wave3"=wdmaud.drv "midi3"=wdmaud.drv "mixer3"=wdmaud.drv "wave4"=wdmaud.drv "midi4"=wdmaud.drv "mixer4"=wdmaud.drv "wave2"=wdmaud.drv "midi2"=wdmaud.drv "mixer2"=wdmaud.drv "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "vidc.iv31"=ir32_32.dll "vidc.iv32"=ir32_32.dll "vidc.iv41"=ir41_32.ax "vidc.iv50"=ir50_32.dll "VIDC.XVID"=xvidvfw.dll "VIDC.YV12"=xvidvfw.dll "msacm.ac3acm"=ac3acm.acm "msacm.lameacm"=lameACM.acm "VIDC.FFDS"=ff_vfw.dll "vidc.VP60"=C:\Windows\system32\vp6vfw.dll "vidc.VP61"=C:\Windows\system32\vp6vfw.dll ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* .scr - open - C:\Windows\system32\notepad.exe "%1" .scr - install - .scr - config - ======List of files/folders created in the last 1 month====== 2013-01-02 19:43:24 ----A---- C:\AdwCleaner[S1].txt 2013-01-02 19:34:04 ----D---- C:\_OTL 2013-01-02 00:20:19 ----D---- C:\Users\Adam\AppData\Roaming\e-academy Inc 2013-01-01 15:51:58 ----D---- C:\Program Files (x86)\trend micro 2013-01-01 15:51:57 ----D---- C:\rsit 2012-12-31 00:12:36 ----D---- C:\ProgramData\Ad-Aware Antivirus 2012-12-31 00:12:23 ----D---- C:\Users\Adam\AppData\Roaming\LavasoftStatistics 2012-12-31 00:02:09 ----D---- C:\ProgramData\Lavasoft 2012-12-30 23:59:53 ----D---- C:\Program Files (x86)\Toolbar Cleaner 2012-12-30 23:57:48 ----D---- C:\Users\Adam\AppData\Roaming\Ad-Aware Antivirus 2012-12-30 23:02:50 ----D---- C:\ProgramData\Spybot - Search & Destroy 2012-12-29 17:11:37 ----D---- C:\ProgramData\Applications 2012-12-29 15:59:10 ----HD---- C:\Program Files (x86)\InstallJammer Registry 2012-12-29 15:58:37 ----D---- C:\Program Files (x86)\Soldis PROJEKTANT 2012-12-29 15:41:09 ----D---- C:\ProgramData\WoW Worldwide Software LTD 2012-12-29 15:41:09 ----D---- C:\Program Files (x86)\SoftQuick 2012-12-29 15:40:53 ----D---- C:\Program Files (x86)\ContinueToSave 2012-12-29 15:39:31 ----D---- C:\Program Files (x86)\NapiProjekt 2012-12-29 12:52:01 ----D---- C:\Users\Adam\AppData\Roaming\Malwarebytes 2012-12-29 12:51:49 ----D---- C:\ProgramData\Malwarebytes 2012-12-22 01:53:19 ----A---- C:\Windows\SysWOW64\atmlib.dll 2012-12-22 01:53:16 ----A---- C:\Windows\SysWOW64\atmfd.dll 2012-12-15 16:22:56 ----D---- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2012-12-14 19:00:41 ----RD---- C:\Program Files (x86)\Skype 2012-12-14 19:00:41 ----D---- C:\Program Files (x86)\Common Files\Skype 2012-12-12 08:58:53 ----A---- C:\Windows\SysWOW64\tzres.dll 2012-12-12 08:58:36 ----A---- C:\Windows\SysWOW64\urlmon.dll 2012-12-12 08:58:36 ----A---- C:\Windows\SysWOW64\mshtml.dll 2012-12-12 08:58:36 ----A---- C:\Windows\SysWOW64\ieframe.dll 2012-12-12 08:58:35 ----A---- C:\Windows\SysWOW64\wininet.dll 2012-12-12 08:58:34 ----A---- C:\Windows\SysWOW64\mshtmled.dll 2012-12-12 08:58:34 ----A---- C:\Windows\SysWOW64\msfeeds.dll 2012-12-12 08:58:34 ----A---- C:\Windows\SysWOW64\ieui.dll 2012-12-12 08:58:34 ----A---- C:\Windows\SysWOW64\iertutil.dll 2012-12-12 08:58:33 ----A---- C:\Windows\SysWOW64\url.dll 2012-12-12 08:58:33 ----A---- C:\Windows\SysWOW64\jsproxy.dll 2012-12-12 08:58:23 ----A---- C:\Windows\SysWOW64\KernelBase.dll 2012-12-12 08:58:23 ----A---- C:\Windows\SysWOW64\kernel32.dll 2012-12-12 08:58:22 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2012-12-12 08:58:22 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2012-12-12 08:58:22 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2012-12-12 08:58:22 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2012-12-12 08:58:22 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2012-12-12 08:58:22 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2012-12-12 08:58:22 ----A---- C:\Windows\SysWOW64\wow32.dll 2012-12-12 08:58:22 ----A---- C:\Windows\SysWOW64\setup16.exe 2012-12-12 08:58:22 ----A---- C:\Windows\SysWOW64\ntvdm64.dll 2012-12-12 08:58:22 ----A---- C:\Windows\SysWOW64\instnm.exe 2012-12-12 08:58:21 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2012-12-12 08:58:21 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2012-12-12 08:58:20 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2012-12-12 08:58:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2012-12-12 08:58:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2012-12-12 08:58:19 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2012-12-12 08:58:17 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2012-12-12 08:58:17 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2012-12-12 08:58:17 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2012-12-12 08:58:17 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2012-12-12 08:58:17 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2012-12-12 08:58:17 ----A---- C:\Windows\SysWOW64\user.exe 2012-12-12 08:58:01 ----A---- C:\Windows\SysWOW64\dpnet.dll ======List of files/folders modified in the last 1 month====== 2013-01-02 20:01:54 ----D---- C:\Windows\Temp 2013-01-02 20:01:03 ----D---- C:\Windows\Prefetch 2013-01-02 19:58:56 ----SHD---- C:\Windows\Installer 2013-01-02 19:58:21 ----D---- C:\Windows\System32 2013-01-02 19:55:47 ----SHD---- C:\System Volume Information 2013-01-02 19:50:06 ----A---- C:\Windows\SysWOW64\log.txt 2013-01-02 19:43:29 ----RD---- C:\Program Files (x86) 2013-01-02 19:43:29 ----RD---- C:\Program Files 2013-01-02 19:43:27 ----HD---- C:\ProgramData 2013-01-02 19:34:27 ----D---- C:\Windows 2013-01-01 23:43:20 ----D---- C:\Windows\inf 2012-12-31 00:11:49 ----D---- C:\Windows\SysWOW64 2012-12-31 00:02:09 ----D---- C:\Program Files (x86)\Common Files\microsoft shared 2012-12-30 18:52:09 ----D---- C:\Autodesk 2012-12-30 00:34:18 ----D---- C:\Program Files (x86)\Common Files\Autodesk Shared 2012-12-29 19:11:22 ----D---- C:\Users\Adam\AppData\Roaming\GanymedeNet 2012-12-29 15:40:59 ----D---- C:\Windows\Tasks 2012-12-29 15:39:25 ----D---- C:\Program Files (x86)\ALLMediaServer 2012-12-29 15:25:27 ----D---- C:\Windows\debug 2012-12-29 15:15:09 ----D---- C:\ProgramData\Nero 2012-12-29 15:15:09 ----D---- C:\Program Files (x86)\Common Files 2012-12-29 15:15:06 ----D---- C:\Windows\ehome 2012-12-29 12:32:01 ----D---- C:\ProgramData\DatacardService 2012-12-29 12:30:37 ----D---- C:\Windows\AppCompat 2012-12-29 12:30:37 ----D---- C:\Users\Adam\AppData\Roaming\uTorrent 2012-12-29 12:30:37 ----D---- C:\ProgramData\FLEXnet 2012-12-29 12:30:36 ----D---- C:\Windows\registration 2012-12-23 00:25:13 ----D---- C:\Users\Adam\AppData\Roaming\Skype 2012-12-22 11:40:41 ----D---- C:\Windows\winsxs 2012-12-15 16:22:56 ----D---- C:\Program Files (x86)\Common Files\Apple 2012-12-14 20:43:52 ----D---- C:\Windows\rescache 2012-12-14 19:00:51 ----D---- C:\ProgramData\Skype 2012-12-13 12:07:48 ----D---- C:\Windows\SysWOW64\pl-PL 2012-12-13 12:07:48 ----D---- C:\Windows\SysWOW64\migration 2012-12-13 12:07:48 ----D---- C:\Program Files (x86)\Internet Explorer 2012-12-13 12:07:36 ----D---- C:\Windows\AppPatch 2012-12-13 02:45:48 ----D---- C:\ProgramData\Microsoft Help 2012-12-11 22:28:13 ----A---- C:\Windows\SysWOW64\FlashPlayerApp.exe 2012-12-05 06:52:18 ----D---- C:\Users\Adam\AppData\Roaming\Autodesk ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 BMLoad;Bytemobile Boot Time Load Driver; C:\Windows\system32\drivers\BMLoad.sys [] R0 gfibto;gfibto; C:\Windows\system32\drivers\gfibto.sys [] R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [] R0 LPCFilter;LPC Lower Filter Driver; C:\Windows\system32\DRIVERS\LPCFilter.sys [] R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [] R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [] R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2011-03-18 29592] R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [] R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [] R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [] R1 aswSnx;aswSnx; C:\Windows\SysWOW64\drivers\aswSnx.sys [] R1 aswSP;aswSP; C:\Windows\SysWOW64\drivers\aswSP.sys [] R1 aswTdi;avast! Network Shield Support; C:\Windows\SysWOW64\drivers\aswTdi.sys [] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [] R1 tcpipBM;Bytemobile Kernel Network Provider; \??\C:\Windows\system32\drivers\tcpipBM.sys [] R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [] R2 aswFsBlk;aswFsBlk; C:\Windows\SysWOW64\drivers\aswFsBlk.sys [] R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [] R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [] R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [] R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [] R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [] R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [] R3 ROCKEYNT;Feitian ROCKEY4 Device Service; C:\Windows\system32\DRIVERS\Rockey4.sys [] R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [] R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver; C:\Windows\system32\DRIVERS\rtl8192Ce.sys [] R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [] R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [] R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [] S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [] S3 androidusb;SAMSUNG Android Composite ADB Interface Driver; C:\Windows\System32\Drivers\ssadadb.sys [] S3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [] S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [] S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [] S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [] S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [] S3 ew_usbenumfilter;huawei_CompositeFilter; C:\Windows\system32\DRIVERS\ew_usbenumfilter.sys [] S3 huawei_cdcacm;huawei_cdcacm; C:\Windows\system32\DRIVERS\ew_jucdcacm.sys [] S3 huawei_ext_ctrl;huawei_ext_ctrl; C:\Windows\system32\DRIVERS\ew_juextctrl.sys [] S3 huawei_wwanecm;huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [] S3 s0016bus;Sony Ericsson Device 0016 driver (WDM); C:\Windows\system32\DRIVERS\s0016bus.sys [] S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s0016mdfl.sys [] S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s0016mdm.sys [] S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s0016mgmt.sys [] S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS); C:\Windows\system32\DRIVERS\s0016nd5.sys [] S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s0016obex.sys [] S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM); C:\Windows\system32\DRIVERS\s0016unic.sys [] S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\ssadbus.sys [] S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\Windows\system32\DRIVERS\ssadmdfl.sys [] S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\Windows\system32\DRIVERS\ssadmdm.sys [] S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\Windows\system32\DRIVERS\ssadserd.sys [] S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [] S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [] S3 usbscan;Sterownik skanera USB; C:\Windows\system32\DRIVERS\usbscan.sys [] S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960] R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-08-11 55184] R2 avast! Antivirus;avast! Antivirus; D:\Programy\Avast\AvastSvc.exe [2012-10-30 44808] R2 hpqddsvc;Usługa HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2009-07-14 20992] R2 HWDeviceService64.exe;HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [2011-03-14 346976] R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2010-08-04 1809920] R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-02-01 326168] R2 MemeoBackgroundService;MemeoBackgroundService; C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe [2011-05-04 25824] R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992] R2 NVSvc;NVIDIA Driver Helper Service; C:\Windows\system32\nvvsvc.exe [] R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992] R2 SeagateDashboardService;Seagate Dashboard Service; C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe [2011-06-01 14088] R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [] R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-01 2656280] R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976] R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 20992] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] S2 Internet Manager. RunOuc;Internet Manager. OUC; D:\Programy\UpdateDog\ouc.exe [] S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-11 250808] S3 aspnet_state;„Usługa stanu ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376] S3 Autodesk Network Licensing Service;Autodesk Network Licensing Service; C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskNetSrv.exe [2008-06-13 1539224] S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-10-13 1431888] S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-11-09 1045256] S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2011-12-09 135584] S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632] S3 iPod Service;Usługa iPod; C:\Program Files\iPod\bin\iPodService.exe [2012-12-12 641504] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696] S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [] S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240] S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240] S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240] S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] -----------------EOF----------------- [/log] Logi z OTL: [log] OTL logfile created on: 1/2/2013 8:04:33 PM - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Adam\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000409 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3.98 Gb Total Physical Memory | 2.12 Gb Available Physical Memory | 53.24% Memory free 7.95 Gb Paging File | 5.85 Gb Available in Paging File | 73.51% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 298.09 Gb Total Space | 218.62 Gb Free Space | 73.34% Space Free | Partition Type: NTFS Drive D: | 297.69 Gb Total Space | 189.67 Gb Free Space | 63.71% Space Free | Partition Type: NTFS Computer Name: ADAM-TOSHIBA | User Name: Adam | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: Off | File Age = 60 Days [color=#E56717]========== Processes (All) ==========[/color] PRC - [2012/12/30 11:10:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Adam\Desktop\OTL.exe PRC - [2012/12/05 02:15:17 | 001,242,728 | ---- | M] (Google Inc.) -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe PRC - [2012/10/30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- D:\Programy\Avast\AvastUI.exe PRC - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- D:\Programy\Avast\AvastSvc.exe PRC - [2012/10/09 10:53:36 | 004,441,920 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Adam\AppData\Local\Akamai\netsession_win.exe PRC - [2012/08/11 15:43:06 | 000,055,184 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe PRC - [2012/07/27 12:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012/07/03 08:04:54 | 000,252,848 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe PRC - [2012/04/26 13:33:16 | 002,743,104 | ---- | M] (DT Soft Ltd) -- D:\Programy\Daemon Tools Pro\DTShellHlp.exe PRC - [2011/06/01 17:42:28 | 000,071,432 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoDashboard.exe PRC - [2011/06/01 17:42:28 | 000,014,088 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe PRC - [2011/06/01 17:16:54 | 002,260,992 | ---- | M] (Axentra Corporation) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe PRC - [2011/05/04 22:10:28 | 000,325,344 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\InstantBackup.exe PRC - [2011/03/14 16:27:28 | 000,236,384 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe PRC - [2011/02/01 12:24:42 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe PRC - [2011/02/01 12:24:40 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe PRC - [2010/08/04 16:11:34 | 001,809,920 | ---- | M] (Realsil Microelectronics Inc.) -- C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\svchost.exe [comLaunch] PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\svchost.exe [comLaunch] [color=#E56717]========== Modules (All) ==========[/color] MOD - [2012/12/30 11:10:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Adam\Desktop\OTL.exe MOD - [2012/12/11 18:58:39 | 000,043,272 | ---- | M] (AVAST Software) -- D:\Programy\Avast\defs\13010200\uiext.dll MOD - [2012/12/05 02:15:17 | 001,242,728 | ---- | M] (Google Inc.) -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe MOD - [2012/12/05 02:15:15 | 012,456,040 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll MOD - [2012/12/05 02:15:15 | 000,460,904 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll MOD - [2012/12/05 02:15:14 | 004,008,040 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll MOD - [2012/12/05 02:14:29 | 000,587,880 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\libglesv2.dll MOD - [2012/12/05 02:14:28 | 000,124,520 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\libegl.dll MOD - [2012/12/05 02:14:27 | 009,963,112 | ---- | M] (The ICU Project) -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\icudt.dll MOD - [2012/12/05 02:14:23 | 041,743,976 | ---- | M] (Google Inc.) -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\chrome.dll MOD - [2012/12/05 02:14:21 | 000,157,304 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\avutil-51.dll MOD - [2012/12/05 02:14:20 | 000,275,576 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\avformat-54.dll MOD - [2012/12/05 02:14:19 | 002,168,952 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\avcodec-54.dll MOD - [2012/11/15 19:49:39 | 001,670,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\4a29fb5e489e57ccc97b19ca70db94a8\Microsoft.VisualBasic.ni.dll MOD - [2012/11/15 19:12:47 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\17796f2951c17ebf92dd4b7c9b3ce556\System.ServiceProcess.ni.dll MOD - [2012/11/15 19:12:38 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\03cfab5534482e8fc313ead6edc19100\System.Web.ni.dll MOD - [2012/11/15 19:12:32 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\413288993ff690e8251d2dbe32bee01f\System.Runtime.Remoting.ni.dll MOD - [2012/11/15 19:12:31 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\3d4e9d4f6c945d6d3b7d423fdb6bd274\System.Data.ni.dll MOD - [2012/11/15 19:12:06 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d040079bc7148afeca03c5abb6fc3c61\System.Windows.Forms.ni.dll MOD - [2012/11/15 19:12:00 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\4e80768a2d88c7a333e43cbb7a6c0705\System.Drawing.ni.dll MOD - [2012/11/15 19:11:58 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\70705382a499703e7a595fada80b04e6\Accessibility.ni.dll MOD - [2012/11/15 19:11:45 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\25e672ea505e50ab058258ac72a54f02\System.Xml.ni.dll MOD - [2012/11/15 19:11:42 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c64ca3678261c8ffcd9e7efd1af6ed54\System.Configuration.ni.dll MOD - [2012/11/15 19:11:41 | 007,988,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9dd758ac0bf7358ac6e4720610fcc63c\System.ni.dll MOD - [2012/11/15 19:11:36 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\187d7c66735c533de851c76384f86912\mscorlib.ni.dll MOD - [2012/10/30 23:51:26 | 000,242,056 | ---- | M] (AVAST Software) -- D:\Programy\Avast\1045\uiLangRes.dll MOD - [2012/10/30 23:51:26 | 000,095,784 | ---- | M] (AVAST Software) -- D:\Programy\Avast\1045\Base.dll MOD - [2012/10/30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- D:\Programy\Avast\AvastUI.exe MOD - [2012/10/30 23:50:53 | 000,236,888 | ---- | M] (AVAST Software) -- D:\Programy\Avast\snxhk.dll MOD - [2012/10/30 23:50:51 | 006,439,048 | ---- | M] (AVAST Software) -- D:\Programy\Avast\CommonRes.dll MOD - [2012/10/30 23:50:47 | 000,476,360 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswSqLt.dll MOD - [2012/10/30 23:50:47 | 000,027,296 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswUtil.dll MOD - [2012/10/30 23:50:44 | 000,220,944 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswLog.dll MOD - [2012/10/30 23:50:44 | 000,217,848 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswProperty.dll MOD - [2012/10/30 23:50:44 | 000,126,160 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswJsFlt.dll MOD - [2012/10/30 23:50:44 | 000,051,000 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswEngLdr.dll MOD - [2012/10/30 23:50:41 | 002,162,488 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswAra.dll MOD - [2012/10/30 23:50:41 | 000,682,384 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswAux.dll MOD - [2012/10/30 23:50:41 | 000,347,616 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswCmnBS.dll MOD - [2012/10/30 23:50:41 | 000,191,568 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswCmnIS.dll MOD - [2012/10/30 23:50:41 | 000,191,080 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswData.dll MOD - [2012/10/30 23:50:41 | 000,099,416 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswCmnOS.dll MOD - [2012/10/30 23:50:38 | 000,153,976 | ---- | M] (AVAST Software) -- D:\Programy\Avast\ashTask.dll MOD - [2012/10/30 23:50:38 | 000,061,800 | ---- | M] (AVAST Software) -- D:\Programy\Avast\ashTaskEx.dll MOD - [2012/10/30 23:50:36 | 000,441,352 | ---- | M] (AVAST Software) -- D:\Programy\Avast\ashBase.dll MOD - [2012/10/30 23:50:30 | 000,368,752 | ---- | M] (AVAST Software) -- D:\Programy\Avast\Aavm4h.dll MOD - [2012/10/30 23:50:30 | 000,120,504 | ---- | M] (AVAST Software) -- D:\Programy\Avast\AavmRpch.dll MOD - [2012/10/27 07:26:55 | 000,981,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wininet.dll MOD - [2012/10/27 07:26:43 | 001,231,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\urlmon.dll MOD - [2012/10/27 07:23:15 | 002,073,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\iertutil.dll MOD - [2012/10/27 07:23:14 | 011,020,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ieframe.dll MOD - [2012/10/16 08:39:52 | 000,561,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\AppPatch\AcLayers.dll MOD - [2012/10/09 18:40:31 | 000,044,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dhcpcsvc6.dll MOD - [2012/10/09 10:53:36 | 004,441,920 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Adam\AppData\Local\Akamai\netsession_win.exe MOD - [2012/10/04 17:47:41 | 000,274,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\KernelBase.dll MOD - [2012/10/04 17:47:40 | 001,114,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\kernel32.dll MOD - [2012/08/31 11:59:20 | 005,927,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll MOD - [2012/08/24 17:57:48 | 000,172,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wintrust.dll MOD - [2012/07/03 08:04:54 | 000,252,848 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe MOD - [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shell32.dll MOD - [2012/06/06 06:05:52 | 001,236,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msxml3.dll MOD - [2012/06/02 05:40:42 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\secur32.dll MOD - [2012/06/02 05:39:10 | 000,219,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ncrypt.dll MOD - [2012/06/02 05:36:29 | 001,159,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\crypt32.dll MOD - [2012/06/02 05:36:29 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptnet.dll MOD - [2012/06/02 05:34:09 | 000,096,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sspicli.dll MOD - [2012/05/05 08:46:52 | 000,043,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\srclient.dll MOD - [2012/04/26 13:33:16 | 002,743,104 | ---- | M] (DT Soft Ltd) -- D:\Programy\Daemon Tools Pro\DTShellHlp.exe MOD - [2012/04/26 13:32:38 | 005,740,864 | ---- | M] (DT Soft Ltd) -- D:\Programy\Daemon Tools Pro\DTCommonRes.dll MOD - [2012/04/26 13:32:14 | 004,057,920 | ---- | M] (DT Soft Ltd) -- D:\Programy\Daemon Tools Pro\Engine.dll MOD - [2012/04/21 05:21:01 | 001,625,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\GdiPlus.dll MOD - [2012/04/12 07:30:52 | 000,382,784 | ---- | M] (DT Soft Ltd.) -- D:\Programy\Daemon Tools Pro\imgengine.dll MOD - [2012/03/01 06:33:23 | 000,159,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\imagehlp.dll MOD - [2012/01/13 08:12:03 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\nlaapi.dll MOD - [2012/01/04 09:58:41 | 000,442,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntshrui.dll MOD - [2012/01/04 03:50:59 | 000,364,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll MOD - [2011/12/16 08:52:58 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msvcrt.dll MOD - [2011/11/17 06:38:39 | 001,292,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntdll.dll MOD - [2011/11/17 06:35:02 | 000,314,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\webio.dll MOD - [2011/10/01 00:29:42 | 003,781,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_4bf7e3e2bf9ada4c\mfc90u.dll MOD - [2011/10/01 00:29:34 | 000,653,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll MOD - [2011/10/01 00:29:34 | 000,569,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll MOD - [2011/10/01 00:11:20 | 000,632,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcr80.dll MOD - [2011/10/01 00:11:20 | 000,554,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcp80.dll MOD - [2011/08/27 05:26:27 | 000,571,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\oleaut32.dll MOD - [2011/08/27 05:26:27 | 000,233,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\oleacc.dll MOD - [2011/06/01 17:46:02 | 000,030,984 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SeagateSharePlusPlugin.dll MOD - [2011/06/01 17:46:00 | 000,036,616 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SharePlugin.dll MOD - [2011/06/01 17:46:00 | 000,031,496 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SyncPlugin.dll MOD - [2011/06/01 17:46:00 | 000,029,960 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SeagateSharePlugin.dll MOD - [2011/06/01 17:46:00 | 000,026,376 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.RebitPlugin.dll MOD - [2011/06/01 17:45:58 | 000,028,936 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.BackupPremiumPlugin.dll MOD - [2011/06/01 17:45:58 | 000,028,424 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SendPlugin.dll MOD - [2011/06/01 17:45:56 | 000,029,448 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.BackupPlugin.dll MOD - [2011/06/01 17:45:52 | 000,011,016 | ---- | M] (Softvision) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.FolderViewPlugin.resources.dll MOD - [2011/06/01 17:45:40 | 000,011,016 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.SeagateSharePlusPlugin.resources.dll MOD - [2011/06/01 17:45:30 | 000,011,016 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.SeagateSharePlugin.resources.dll MOD - [2011/06/01 17:45:18 | 000,011,016 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.SeagatePreferencesPlugin.resources.dll MOD - [2011/06/01 17:45:06 | 000,011,528 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.LoadContentPlugin.resources.dll MOD - [2011/06/01 17:44:56 | 000,015,624 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.AddUserPlugin.resources.dll MOD - [2011/06/01 17:44:44 | 000,011,016 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.AddComputersPlugin.resources.dll MOD - [2011/06/01 17:44:12 | 000,009,992 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.RebitPlugin.resources.dll MOD - [2011/06/01 17:44:00 | 000,009,992 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.SyncPlugin.resources.dll MOD - [2011/06/01 17:43:50 | 000,009,992 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.SharePlugin.resources.dll MOD - [2011/06/01 17:43:38 | 000,009,992 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.SendPlugin.resources.dll MOD - [2011/06/01 17:43:12 | 000,010,504 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.BackupPremiumPlugin.resources.dll MOD - [2011/06/01 17:43:02 | 000,010,504 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.BackupPlugin.resources.dll MOD - [2011/06/01 17:42:40 | 000,054,536 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\pl-PL\Memeo.Dashboard.UI.resources.dll MOD - [2011/06/01 17:42:32 | 000,013,576 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Dashboard.NasListener.dll MOD - [2011/06/01 17:42:30 | 000,031,496 | ---- | M] (Softvision) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Dashboard.HipServAdapter.dll MOD - [2011/06/01 17:42:30 | 000,021,768 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Dashboard.HelperAgentAdapter.dll MOD - [2011/06/01 17:42:28 | 000,071,432 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoDashboard.exe MOD - [2011/06/01 17:42:26 | 001,934,088 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Dashboard.UI.dll MOD - [2011/06/01 17:42:26 | 000,145,672 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Common.dll MOD - [2011/06/01 17:42:26 | 000,069,896 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Dashboard.Remote.dll MOD - [2011/06/01 17:42:26 | 000,037,128 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Dashboard.PluginCore.dll MOD - [2011/06/01 17:42:24 | 000,108,296 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Progress.dll MOD - [2011/06/01 17:42:16 | 000,023,040 | ---- | M] (Softvision) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.FolderViewPlugin.dll MOD - [2011/06/01 17:41:48 | 000,043,008 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.AddUserPlugin.dll MOD - [2011/06/01 17:41:44 | 000,032,768 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.LoadContentPlugin.dll MOD - [2011/06/01 17:41:38 | 000,019,968 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.AddComputersPlugin.dll MOD - [2011/06/01 17:41:32 | 000,023,040 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SeagatePreferencesPlugin.dll MOD - [2011/06/01 17:16:54 | 003,284,992 | ---- | M] (DevComponents.com) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\DevComponents.DotNetBar2.dll MOD - [2011/06/01 17:16:54 | 002,260,992 | ---- | M] (Axentra Corporation) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe MOD - [2011/06/01 17:16:54 | 001,028,096 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\LIBEAY32.dll MOD - [2011/06/01 17:16:54 | 000,978,432 | ---- | M] (GNU <www.gnu.org>) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\iconv.dll MOD - [2011/06/01 17:16:54 | 000,971,776 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\libxml2.dll MOD - [2011/06/01 17:16:54 | 000,241,664 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\libupnp.dll MOD - [2011/06/01 17:16:54 | 000,212,992 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\SSLEAY32.dll MOD - [2011/06/01 17:16:54 | 000,208,896 | ---- | M] (The cURL library, http://curl.haxx.se/) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\libcurl.dll MOD - [2011/06/01 17:16:54 | 000,086,070 | ---- | M] (Open Source Software community project) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\pthreadVC2.dll MOD - [2011/06/01 17:16:54 | 000,075,264 | ---- | M] (Zlib) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\zlib1.dll MOD - [2011/05/24 11:40:05 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\devobj.dll MOD - [2011/05/24 11:39:38 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cfgmgr32.dll MOD - [2011/05/17 08:27:52 | 000,413,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll MOD - [2011/05/04 22:15:12 | 000,032,768 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\pl-PL\Tanagra.Utility.resources.dll MOD - [2011/05/04 22:15:12 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\pl-PL\InstantBackup.resources.dll MOD - [2011/05/04 22:15:10 | 000,069,632 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\pl-PL\Memeo.Client.UI.resources.dll MOD - [2011/05/04 22:15:08 | 000,053,248 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\pl-PL\Tanagra.DataClad.resources.dll MOD - [2011/05/04 22:15:06 | 000,015,872 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\pl-PL\Memeo.Client.resources.dll MOD - [2011/05/04 22:15:02 | 000,069,632 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\pl-PL\Tanagra.BMU.resources.dll MOD - [2011/05/04 22:10:50 | 000,087,264 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\providers\Tanagra.BMU.Providers.FileCopyBackupProvider.dll MOD - [2011/05/04 22:10:50 | 000,079,072 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\providers\Tanagra.BMU.Providers.HardDiskBackupProvider.dll MOD - [2011/05/04 22:10:48 | 002,896,608 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\Memeo.Client.UI.dll MOD - [2011/05/04 22:10:46 | 000,230,624 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Memeo.Client.dll MOD - [2011/05/04 22:10:46 | 000,027,360 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\Memeo.Client.DriveDetection.dll MOD - [2011/05/04 22:10:44 | 000,020,704 | ---- | M] (Stan Schultes, VBNetExpert.com) -- C:\Program Files (x86)\Memeo\AutoBackup\XMLSettings.dll MOD - [2011/05/04 22:10:42 | 001,668,320 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Tanagra.Utility.dll MOD - [2011/05/04 22:10:42 | 000,025,824 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Tanagra.Third-party.Security.dll MOD - [2011/05/04 22:10:40 | 002,794,720 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Tanagra.BMU.dll MOD - [2011/05/04 22:10:40 | 001,561,824 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Tanagra.DataClad.dll MOD - [2011/05/04 22:10:40 | 000,296,160 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Tanagra.DataClad.DataAccess.dll MOD - [2011/05/04 22:10:40 | 000,054,496 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Tanagra.Interop.dll MOD - [2011/05/04 22:10:38 | 000,074,976 | ---- | M] (Finisar Corporation) -- C:\Program Files (x86)\Memeo\AutoBackup\SQLite.NET.dll MOD - [2011/05/04 22:10:38 | 000,067,808 | ---- | M] (Newtonsoft) -- C:\Program Files (x86)\Memeo\AutoBackup\Newtonsoft.Json.dll MOD - [2011/05/04 22:10:28 | 000,325,344 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\InstantBackup.exe MOD - [2011/03/14 16:27:28 | 000,236,384 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe MOD - [2011/03/03 06:38:01 | 000,270,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dnsapi.dll MOD - [2011/02/21 17:40:04 | 010,059,368 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWOW64\nvd3dum.dll MOD - [2010/11/21 04:25:15 | 000,172,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\spp.dll MOD - [2010/11/21 04:25:11 | 003,207,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mf.dll MOD - [2010/11/21 04:25:11 | 000,488,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\evr.dll MOD - [2010/11/21 04:24:51 | 000,080,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\davclnt.dll MOD - [2010/11/21 04:24:43 | 000,481,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mscms.dll MOD - [2010/11/21 04:24:33 | 001,010,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\WindowsCodecs.dll MOD - [2010/11/21 04:24:33 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\credssp.dll MOD - [2010/11/21 04:24:32 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\IPHLPAPI.DLL MOD - [2010/11/21 04:24:28 | 000,640,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\advapi32.dll MOD - [2010/11/21 04:24:26 | 001,128,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vssapi.dll MOD - [2010/11/21 04:24:26 | 000,572,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll MOD - [2010/11/21 04:24:25 | 000,119,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\imm32.dll MOD - [2010/11/21 04:24:23 | 001,828,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d9.dll MOD - [2010/11/21 04:24:23 | 001,493,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ExplorerFrame.dll MOD - [2010/11/21 04:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\user32.dll MOD - [2010/11/21 04:24:16 | 000,626,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\usp10.dll MOD - [2010/11/21 04:24:16 | 000,380,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sxs.dll MOD - [2010/11/21 04:24:16 | 000,269,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\Wldap32.dll MOD - [2010/11/21 04:24:16 | 000,257,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msv1_0.dll MOD - [2010/11/21 04:24:16 | 000,194,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winmm.dll MOD - [2010/11/21 04:24:16 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\srvcli.dll MOD - [2010/11/21 04:24:16 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\userenv.dll MOD - [2010/11/21 04:24:16 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\netutils.dll MOD - [2010/11/21 04:24:14 | 000,592,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msftedit.dll MOD - [2010/11/21 04:24:14 | 000,311,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\gdi32.dll MOD - [2010/11/21 04:24:14 | 000,295,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\apphelp.dll MOD - [2010/11/21 04:24:14 | 000,046,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\RpcRtRemote.dll MOD - [2010/11/21 04:24:11 | 000,663,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rpcrt4.dll MOD - [2010/11/21 04:24:09 | 000,854,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dbghelp.dll MOD - [2010/11/21 04:24:09 | 000,530,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll MOD - [2010/11/21 04:24:09 | 000,232,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mswsock.dll MOD - [2010/11/21 04:24:08 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll MOD - [2010/11/21 04:24:08 | 000,988,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\propsys.dll MOD - [2010/11/21 04:24:08 | 000,351,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winhttp.dll MOD - [2010/11/21 04:24:08 | 000,320,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winspool.drv MOD - [2010/11/21 04:24:08 | 000,236,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\pdh.dll MOD - [2010/11/21 04:24:08 | 000,216,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\FWPUCLNT.DLL MOD - [2010/11/21 04:24:07 | 000,179,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shdocvw.dll MOD - [2010/11/21 04:24:03 | 000,189,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sqmapi.dll MOD - [2010/11/21 04:24:03 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\olepro32.dll MOD - [2010/11/21 04:24:02 | 000,034,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cscapi.dll MOD - [2010/11/21 04:24:02 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msdmo.dll MOD - [2010/11/21 04:24:01 | 001,414,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ole32.dll MOD - [2010/11/21 04:24:01 | 000,297,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mscoree.dll MOD - [2010/11/21 04:24:01 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rtutils.dll MOD - [2010/11/21 04:24:00 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntlanman.dll MOD - [2010/11/21 04:23:55 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll MOD - [2010/11/21 04:23:55 | 000,206,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ws2_32.dll MOD - [2010/11/21 04:23:55 | 000,156,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winsta.dll MOD - [2010/11/21 04:23:54 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\samcli.dll MOD - [2010/11/21 04:23:54 | 000,040,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wtsapi32.dll MOD - [2010/11/21 04:23:51 | 001,667,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\setupapi.dll MOD - [2010/11/21 04:23:51 | 000,213,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\MMDevAPI.dll MOD - [2010/11/21 04:23:51 | 000,047,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wkscli.dll MOD - [2010/11/21 04:23:48 | 000,485,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\comdlg32.dll MOD - [2010/11/21 04:23:48 | 000,350,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shlwapi.dll MOD - [2010/11/21 04:23:48 | 000,034,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msasn1.dll MOD - [2010/11/13 03:03:49 | 000,311,296 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pl_b77a5c561934e089\mscorlib.resources.dll MOD - [2010/09/21 13:03:14 | 000,145,280 | ---- | M] (Microsoft Corp.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL MOD - [2010/05/26 11:41:02 | 002,106,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\D3DCompiler_43.dll MOD - [2010/05/26 11:41:02 | 001,998,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\D3DX9_43.dll MOD - [2010/03/22 23:59:46 | 000,504,293 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\sqlite3.DLL MOD - [2010/03/22 23:59:32 | 000,013,824 | ---- | M] ( ) -- C:\Program Files (x86)\Memeo\AutoBackup\Interop.eWebControl.dll MOD - [2010/03/22 23:58:22 | 000,143,360 | ---- | M] (Digital River, Inc.) -- C:\Program Files (x86)\Common Files\Memeo\eWebControl365.dll MOD - [2009/07/14 02:17:54 | 000,249,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\bcryptprimitives.dll MOD - [2009/07/14 02:17:54 | 000,242,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rsaenh.dll MOD - [2009/07/14 02:16:20 | 000,308,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\Wpc.dll MOD - [2009/07/14 02:16:20 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wsock32.dll MOD - [2009/07/14 02:16:20 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wship6.dll MOD - [2009/07/14 02:16:20 | 000,009,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\WSHTCPIP.DLL MOD - [2009/07/14 02:16:19 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winrnr.dll MOD - [2009/07/14 02:16:19 | 000,016,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winnsi.dll MOD - [2009/07/14 02:16:18 | 000,262,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wevtapi.dll MOD - [2009/07/14 02:16:17 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vsstrace.dll MOD - [2009/07/14 02:16:17 | 000,021,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\version.dll MOD - [2009/07/14 02:16:15 | 000,027,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\slc.dll MOD - [2009/07/14 02:16:14 | 000,007,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shfolder.dll MOD - [2009/07/14 02:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sechost.dll MOD - [2009/07/14 02:16:13 | 000,060,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\samlib.dll MOD - [2009/07/14 02:16:13 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\SensApi.dll MOD - [2009/07/14 02:16:12 | 000,325,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rasapi32.dll MOD - [2009/07/14 02:16:12 | 000,145,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\powrprof.dll MOD - [2009/07/14 02:16:12 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rasman.dll MOD - [2009/07/14 02:16:12 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\pnrpnsp.dll MOD - [2009/07/14 02:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\profapi.dll MOD - [2009/07/14 02:16:12 | 000,028,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\perfos.dll MOD - [2009/07/14 02:16:12 | 000,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rasadhlp.dll MOD - [2009/07/14 02:16:12 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\psapi.dll MOD - [2009/07/14 02:16:11 | 000,121,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntmarta.dll MOD - [2009/07/14 02:16:11 | 000,008,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\nsi.dll MOD - [2009/07/14 02:16:02 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\NapiNSP.dll MOD - [2009/07/14 02:15:48 | 000,035,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mssprxy.dll MOD - [2009/07/14 02:15:46 | 002,134,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msmpeg2vdec.dll MOD - [2009/07/14 02:15:44 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msimg32.dll MOD - [2009/07/14 02:15:43 | 000,828,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msctf.dll MOD - [2009/07/14 02:15:41 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mpr.dll MOD - [2009/07/14 02:15:39 | 000,352,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mfplat.dll MOD - [2009/07/14 02:15:36 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\linkinfo.dll MOD - [2009/07/14 02:15:35 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ksuser.dll MOD - [2009/07/14 02:15:22 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\gpapi.dll MOD - [2009/07/14 02:15:21 | 000,462,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\FirewallAPI.dll MOD - [2009/07/14 02:15:13 | 000,717,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dui70.dll MOD - [2009/07/14 02:15:13 | 000,453,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dsound.dll MOD - [2009/07/14 02:15:13 | 000,181,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\duser.dll MOD - [2009/07/14 02:15:13 | 000,088,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dxva2.dll MOD - [2009/07/14 02:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dwmapi.dll MOD - [2009/07/14 02:15:13 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\drprov.dll MOD - [2009/07/14 02:15:11 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dhcpcsvc.dll MOD - [2009/07/14 02:15:10 | 000,066,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\devenum.dll MOD - [2009/07/14 02:15:08 | 000,019,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\davhlpr.dll MOD - [2009/07/14 02:15:08 | 000,011,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d8thk.dll MOD - [2009/07/14 02:15:07 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptsp.dll MOD - [2009/07/14 02:15:07 | 000,058,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptdll.dll MOD - [2009/07/14 02:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptbase.dll MOD - [2009/07/14 02:15:03 | 000,522,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\clbcatq.dll MOD - [2009/07/14 02:14:58 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\avrt.dll MOD - [2009/07/14 02:14:57 | 000,070,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\atl.dll MOD - [2009/07/14 02:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx MOD - [2009/07/14 02:11:24 | 000,245,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\uxtheme.dll MOD - [2009/07/14 02:11:23 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\lpk.dll MOD - [2009/07/14 02:11:20 | 000,080,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\bcrypt.dll MOD - [2009/07/14 02:09:53 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\security.dll MOD - [2009/06/10 22:23:08 | 000,074,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2012/10/13 19:43:55 | 001,431,888 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64) SRV:[b]64bit:[/b] - [2010/10/20 13:41:00 | 000,138,656 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\SysNative\TODDSrv.exe -- (TODDSrv) SRV:[b]64bit:[/b] - [2010/09/22 17:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) SRV:[b]64bit:[/b] - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2012/12/11 22:28:13 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012/11/09 11:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- D:\Programy\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2012/07/27 12:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011/12/09 14:39:52 | 000,135,584 | ---- | M] (Futuremark Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service) SRV - [2011/11/09 20:44:27 | 001,045,256 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2011/06/01 17:42:28 | 000,014,088 | ---- | M] (Memeo) [Auto | Running] -- C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe -- (SeagateDashboardService) SRV - [2011/05/04 22:10:32 | 000,025,824 | ---- | M] (Memeo) [Auto | Running] -- C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe -- (MemeoBackgroundService) SRV - [2011/03/14 16:27:34 | 000,346,976 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\HWDeviceService64.exe -- (HWDeviceService64.exe) SRV - [2011/02/01 12:24:42 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) SRV - [2011/02/01 12:24:40 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) SRV - [2010/08/04 16:11:34 | 001,809,920 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe -- (IconMan_R) SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2008/06/13 03:05:48 | 001,539,224 | ---- | M] (Autodesk, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskNetSrv.exe -- (Autodesk Network Licensing Service) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2012/12/31 00:01:23 | 000,014,456 | ---- | M] (GFI Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\gfibto.sys -- (gfibto) DRV:[b]64bit:[/b] - [2012/11/24 20:32:32 | 000,303,616 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt) DRV:[b]64bit:[/b] - [2012/10/30 23:51:56 | 000,059,728 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi) DRV:[b]64bit:[/b] - [2012/10/30 23:51:55 | 000,984,144 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx) DRV:[b]64bit:[/b] - [2012/10/30 23:51:55 | 000,370,288 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP) DRV:[b]64bit:[/b] - [2012/10/30 23:51:55 | 000,071,600 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt) DRV:[b]64bit:[/b] - [2012/10/30 23:51:53 | 000,025,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk) DRV:[b]64bit:[/b] - [2012/10/15 17:59:28 | 000,054,072 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr) DRV:[b]64bit:[/b] - [2012/08/21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV:[b]64bit:[/b] - [2012/07/12 18:46:00 | 000,560,184 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd) DRV:[b]64bit:[/b] - [2012/07/12 18:42:35 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:[b]64bit:[/b] - [2012/07/07 13:40:50 | 000,039,552 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\tcpipBM.sys -- (tcpipBM) DRV:[b]64bit:[/b] - [2012/07/07 13:40:49 | 000,212,992 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_juwwanecm.sys -- (huawei_wwanecm) DRV:[b]64bit:[/b] - [2012/07/07 13:40:49 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys -- (ew_hwusbdev) DRV:[b]64bit:[/b] - [2012/07/07 13:40:49 | 000,098,816 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_jucdcacm.sys -- (huawei_cdcacm) DRV:[b]64bit:[/b] - [2012/07/07 13:40:49 | 000,086,016 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ew_jubusenum.sys -- (huawei_enumerator) DRV:[b]64bit:[/b] - [2012/07/07 13:40:49 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_juextctrl.sys -- (huawei_ext_ctrl) DRV:[b]64bit:[/b] - [2012/07/07 13:40:49 | 000,013,952 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_usbenumfilter.sys -- (ew_usbenumfilter) DRV:[b]64bit:[/b] - [2012/07/07 13:40:48 | 000,016,512 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\BMLoad.sys -- (BMLoad) DRV:[b]64bit:[/b] - [2012/06/30 15:35:48 | 000,043,168 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt) DRV:[b]64bit:[/b] - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2011/11/09 20:44:38 | 000,036,904 | ---- | M] (Feitian Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rockey4.sys -- (ROCKEYNT) DRV:[b]64bit:[/b] - [2011/05/13 02:21:04 | 000,177,640 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdm.sys -- (ssadmdm) DRV:[b]64bit:[/b] - [2011/05/13 02:21:04 | 000,146,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadserd.sys -- (ssadserd) DRV:[b]64bit:[/b] - [2011/05/13 02:21:02 | 000,157,672 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadbus.sys -- (ssadbus) DRV:[b]64bit:[/b] - [2011/05/13 02:21:02 | 000,036,328 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadadb.sys -- (androidusb) DRV:[b]64bit:[/b] - [2011/05/13 02:21:02 | 000,016,872 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdfl.sys -- (ssadmdfl) DRV:[b]64bit:[/b] - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2011/02/03 18:59:06 | 001,413,680 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP) DRV:[b]64bit:[/b] - [2011/01/13 19:58:30 | 000,413,800 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:[b]64bit:[/b] - [2011/01/12 16:51:44 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:[b]64bit:[/b] - [2011/01/05 00:08:58 | 001,109,096 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtl8192ce.sys -- (RTL8192Ce) DRV:[b]64bit:[/b] - [2010/11/21 04:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2010/11/21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2010/11/21 04:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:[b]64bit:[/b] - [2010/11/11 14:10:50 | 000,155,752 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA) DRV:[b]64bit:[/b] - [2010/10/19 15:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:[b]64bit:[/b] - [2010/07/20 16:43:22 | 000,247,400 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR) DRV:[b]64bit:[/b] - [2010/03/22 09:55:20 | 000,046,192 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\LPCFilter.sys -- (LPCFilter) DRV:[b]64bit:[/b] - [2009/07/30 19:22:04 | 000,027,784 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tdcmdpst.sys -- (tdcmdpst) DRV:[b]64bit:[/b] - [2009/07/14 15:31:18 | 000,026,840 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TVALZ_O.SYS -- (TVALZ) DRV:[b]64bit:[/b] - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009/06/20 03:09:57 | 001,394,688 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr) DRV:[b]64bit:[/b] - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:[b]64bit:[/b] - [2008/05/16 11:33:06 | 000,158,760 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016mdm.sys -- (s0016mdm) DRV:[b]64bit:[/b] - [2008/05/16 11:33:06 | 000,151,592 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016unic.sys -- (s0016unic) DRV:[b]64bit:[/b] - [2008/05/16 11:33:06 | 000,137,256 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016mgmt.sys -- (s0016mgmt) DRV:[b]64bit:[/b] - [2008/05/16 11:33:06 | 000,136,744 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016obex.sys -- (s0016obex) DRV:[b]64bit:[/b] - [2008/05/16 11:33:06 | 000,034,344 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016nd5.sys -- (s0016nd5) DRV:[b]64bit:[/b] - [2008/05/16 11:33:04 | 000,019,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016mdfl.sys -- (s0016mdfl) DRV:[b]64bit:[/b] - [2008/05/16 11:32:56 | 000,115,240 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016bus.sys -- (s0016bus) DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{D526343C-369F-4282-8F7D-0AE1527D1FE5}: "URL" = http://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{7F58A7B2-6E52-456D-87F4-C77C7EBFA5A0}: "URL" = http://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba.msn.com IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "" FF - prefs.js..extensions.enabledAddons: wrc@avast.com:7.0.1426 FF - prefs.js..network.proxy.type: 0 FF - prefs.js..browser.search.order.1: "" FF - prefs.js..browser.search.defaultenginename: "" FF - prefs.js..browser.search.selectedEngine: "" FF - prefs.js..browser.search.defaulturl: "" FF - prefs.js..browser.search.order.1,: "" FF - prefs.js..browser.search.defaultenginename,: "" FF - prefs.js..browser.search.selectedEngine,: "" FF - user.js - File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Programy\iTunes\Mozilla Plugins\npitunes.dll File not found FF - HKLM\Software\MozillaPlugins\@ganymede/GanymedeNetPlugin,version=1.0: D:\Programy\Bilard z WP\Ganymede\Plugins\npganymedenet.dll ( ) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@playstation.com/PsndlCheck,version=1.00: File not found FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Adam\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Adam\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: D:\Programy\Avast\WebRep\FF [2012/11/03 16:20:34 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/05/29 10:35:30 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/05/29 10:35:30 | 000,000,000 | ---D | M] [2012/01/29 02:02:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Adam\AppData\Roaming\mozilla\Extensions [2013/01/02 19:43:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\oq3gcry8.default\extensions [2012/05/19 10:07:52 | 000,010,043 | ---- | M] () (No name found) -- C:\Users\Adam\AppData\Roaming\mozilla\firefox\profiles\oq3gcry8.default\extensions\IplextoALL@ALLPlayer.org.xpi [2012/10/04 16:57:36 | 000,214,514 | ---- | M] () (No name found) -- C:\Users\Adam\AppData\Roaming\mozilla\firefox\profiles\oq3gcry8.default\extensions\TorrentHandler@TorrentHandler.com.xpi [2012/03/15 22:47:45 | 000,634,964 | ---- | M] () (No name found) -- C:\Users\Adam\AppData\Roaming\mozilla\firefox\profiles\oq3gcry8.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012/11/03 16:20:34 | 000,000,000 | ---D | M] (avast! WebRep) -- D:\PROGRAMY\AVAST\WEBREP\FF [color=#E56717]========== Chrome ==========[/color] CHR - homepage: http://websearch.soft-quick.info/ CHR - homepage: http://websearch.soft-quick.info/ CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll CHR - plugin: LiveVDO plug-in (Enabled) = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbiamblgmkgbcgbcgejjgebalncpmhnp\1.3_0\chvsharetvplg.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll CHR - plugin: Google Update (Enabled) = C:\Users\Adam\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll CHR - plugin: GanymedeNet.Detector (Enabled) = D:\Programy\Bilard z WP\Ganymede\Plugins\npganymedenet.dll CHR - Extension: YouTube = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\ CHR - Extension: Szukaj w Google = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\ CHR - Extension: Fast save = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\dealelfklnopdjdoiejlibpajkggonpn\1.1_0\ CHR - Extension: Torrent Handler = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\hphibigbodkkohoglgfkddblldpfohjl\1.2_0\ CHR - Extension: avast! WebRep = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\ CHR - Extension: Gmail = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\ O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:[b]64bit:[/b] - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Programy\Avast\aswWebRepIE64.dll (AVAST Software) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Programy\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (IplexToALLPlayer) - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - D:\Programy\ALLPlayer\Iplex\IplexToALLPlayer.dll (ALLCinema Ltd.) O3:[b]64bit:[/b] - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Programy\Avast\aswWebRepIE64.dll (AVAST Software) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Programy\Avast\aswWebRepIE.dll (AVAST Software) O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [avast5] D:\Programy\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [Memeo AutoSync] C:\Program Files (x86)\Memeo\AutoSync\MemeoLauncher2.exe (Memeo Inc.) O4 - HKLM..\Run: [Memeo Instant Backup] C:\Program Files (x86)\Memeo\AutoBackup\MemeoLauncher2.exe (Memeo Inc.) O4 - HKLM..\Run: [Seagate Dashboard] C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoLauncher.exe () O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-319703930-2572490357-2975701463-1000..\Run: [Akamai NetSession Interface] C:\Users\Adam\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) O4 - HKU\S-1-5-21-319703930-2572490357-2975701463-1000..\Run: [ALLUpdate] D:\Programy\ALLPlayer\ALLUpdate.exe (ALLCinema) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0 O8:[b]64bit:[/b] - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found O8:[b]64bit:[/b] - Extra context menu item: Wyślij &do programu OneNote - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105 File not found O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Wyślij &do programu OneNote - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105 File not found O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL (Microsoft Corporation) O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.9.2) O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.9.2) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.21.99.95 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A9E0C5C0-9E6A-410A-8719-DD8EAFE4AB0C}: DhcpNameServer = 213.158.199.1 213.158.199.5 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A9E0C5C0-9E6A-410A-8719-DD8EAFE4AB0C}: NameServer = 213.158.199.1 213.158.199.5 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D2441D73-E10C-46A3-B0DC-2D2F5D69E4AC}: DhcpNameServer = 62.21.99.95 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F3591DBC-AF36-469B-87F5-DC25CE0EB967}: DhcpNameServer = 213.158.199.1 213.158.199.5 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F3591DBC-AF36-469B-87F5-DC25CE0EB967}: NameServer = 213.158.199.1 213.158.199.5 O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2012/12/30 18:52:09 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ] O32 - AutoRun File - [2012/10/13 19:42:40 | 000,000,000 | ---D | M] - C:\AUTODESK_COM_FOLDER -- [ NTFS ] O33 - MountPoints2\{1842d44a-c82a-11e1-a13a-b870f45d63bf}\Shell - "" = AutoRun O33 - MountPoints2\{1842d44a-c82a-11e1-a13a-b870f45d63bf}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{1842d46a-c82a-11e1-a13a-b870f45d63bf}\Shell - "" = AutoRun O33 - MountPoints2\{1842d46a-c82a-11e1-a13a-b870f45d63bf}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{2fceb299-266a-11e2-ae97-b870f45d63bf}\Shell - "" = AutoRun O33 - MountPoints2\{2fceb299-266a-11e2-ae97-b870f45d63bf}\Shell\AutoRun\command - "" = G:\AutoRun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk - C:\PROGRA~2\HP\DIGITA~1\bin\hpqtra08.exe - (Hewlett-Packard Co.) MsConfig:64bit - StartUpFolder: C:^Users^Adam^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk - - File not found MsConfig:64bit - StartUpReg: [b]Adobe ARM[/b] - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) MsConfig:64bit - StartUpReg: [b]Adobe Reader Speed Launcher[/b] - hkey= - key= - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) MsConfig:64bit - StartUpReg: [b]ALLUpdate[/b] - hkey= - key= - D:\Programy\ALLPlayer\ALLUpdate.exe (ALLCinema) MsConfig:64bit - StartUpReg: [b]DAEMON Tools Lite[/b] - hkey= - key= - File not found MsConfig:64bit - StartUpReg: [b]Google Update[/b] - hkey= - key= - C:\Users\Adam\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.) MsConfig:64bit - StartUpReg: [b]SunJavaUpdateSched[/b] - hkey= - key= - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) MsConfig:64bit - StartUpReg: [b]SVPWUTIL[/b] - hkey= - key= - File not found MsConfig:64bit - StartUpReg: [b]TCrdMain[/b] - hkey= - key= - File not found MsConfig:64bit - StartUpReg: [b]TOPI.EXE[/b] - hkey= - key= - File not found MsConfig:64bit - StartUpReg: [b]Toshiba Registration[/b] - hkey= - key= - C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe (Toshiba Europe GmbH) MsConfig:64bit - StartUpReg: [b]Toshiba TEMPRO[/b] - hkey= - key= - File not found MsConfig:64bit - StartUpReg: [b]ToshibaServiceStation[/b] - hkey= - key= - File not found MsConfig:64bit - StartUpReg: [b]TosReelTimeMonitor[/b] - hkey= - key= - File not found MsConfig:64bit - StartUpReg: [b]TosVolRegulator[/b] - hkey= - key= - C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation) MsConfig:64bit - StartUpReg: [b]TPwrMain[/b] - hkey= - key= - File not found MsConfig:64bit - State: "startup" - Reg Error: Key error. SafeBootMin:[b]64bit:[/b] AppMgmt - Service SafeBootMin:[b]64bit:[/b] Base - Driver Group SafeBootMin:[b]64bit:[/b] Boot Bus Extender - Driver Group SafeBootMin:[b]64bit:[/b] Boot file system - Driver Group SafeBootMin:[b]64bit:[/b] File system - Driver Group SafeBootMin:[b]64bit:[/b] Filter - Driver Group SafeBootMin:[b]64bit:[/b] HelpSvc - Service SafeBootMin:[b]64bit:[/b] MCODS - Reg Error: Value error. SafeBootMin:[b]64bit:[/b] PCI Configuration - Driver Group SafeBootMin:[b]64bit:[/b] PNP Filter - Driver Group SafeBootMin:[b]64bit:[/b] Primary disk - Driver Group SafeBootMin:[b]64bit:[/b] sacsvr - Service SafeBootMin:[b]64bit:[/b] SCSI Class - Driver Group SafeBootMin:[b]64bit:[/b] System Bus Extender - Driver Group SafeBootMin:[b]64bit:[/b] vmms - Service SafeBootMin:[b]64bit:[/b] WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootMin:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootMin: AppMgmt - Service SafeBootMin: Base - Driver Group SafeBootMin: Boot Bus Extender - Driver Group SafeBootMin: Boot file system - Driver Group SafeBootMin: File system - Driver Group SafeBootMin: Filter - Driver Group SafeBootMin: HelpSvc - Service SafeBootMin: MCODS - Reg Error: Value error. SafeBootMin: PCI Configuration - Driver Group SafeBootMin: PNP Filter - Driver Group SafeBootMin: Primary disk - Driver Group SafeBootMin: sacsvr - Service SafeBootMin: SCSI Class - Driver Group SafeBootMin: System Bus Extender - Driver Group SafeBootMin: vmms - Service SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet:[b]64bit:[/b] AppMgmt - Service SafeBootNet:[b]64bit:[/b] Base - Driver Group SafeBootNet:[b]64bit:[/b] Boot Bus Extender - Driver Group SafeBootNet:[b]64bit:[/b] Boot file system - Driver Group SafeBootNet:[b]64bit:[/b] File system - Driver Group SafeBootNet:[b]64bit:[/b] Filter - Driver Group SafeBootNet:[b]64bit:[/b] HelpSvc - Service SafeBootNet:[b]64bit:[/b] MCODS - Reg Error: Value error. SafeBootNet:[b]64bit:[/b] Messenger - Service SafeBootNet:[b]64bit:[/b] NDIS Wrapper - Driver Group SafeBootNet:[b]64bit:[/b] NetBIOSGroup - Driver Group SafeBootNet:[b]64bit:[/b] NetDDEGroup - Driver Group SafeBootNet:[b]64bit:[/b] Network - Driver Group SafeBootNet:[b]64bit:[/b] NetworkProvider - Driver Group SafeBootNet:[b]64bit:[/b] PCI Configuration - Driver Group SafeBootNet:[b]64bit:[/b] PNP Filter - Driver Group SafeBootNet:[b]64bit:[/b] PNP_TDI - Driver Group SafeBootNet:[b]64bit:[/b] Primary disk - Driver Group SafeBootNet:[b]64bit:[/b] rdsessmgr - Service SafeBootNet:[b]64bit:[/b] sacsvr - Service SafeBootNet:[b]64bit:[/b] SCSI Class - Driver Group SafeBootNet:[b]64bit:[/b] Streams Drivers - Driver Group SafeBootNet:[b]64bit:[/b] System Bus Extender - Driver Group SafeBootNet:[b]64bit:[/b] TDI - Driver Group SafeBootNet:[b]64bit:[/b] vmms - Service SafeBootNet:[b]64bit:[/b] WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SafeBootNet:[b]64bit:[/b] WudfUsbccidDriver - Driver SafeBootNet:[b]64bit:[/b] {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet:[b]64bit:[/b] {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet:[b]64bit:[/b] {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet:[b]64bit:[/b] {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet:[b]64bit:[/b] {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet:[b]64bit:[/b] {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet:[b]64bit:[/b] {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet:[b]64bit:[/b] {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet:[b]64bit:[/b] {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet:[b]64bit:[/b] {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet:[b]64bit:[/b] {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet:[b]64bit:[/b] {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet:[b]64bit:[/b] {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet:[b]64bit:[/b] {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet:[b]64bit:[/b] {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet:[b]64bit:[/b] {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet:[b]64bit:[/b] {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet:[b]64bit:[/b] {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet:[b]64bit:[/b] {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet:[b]64bit:[/b] {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet:[b]64bit:[/b] {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet:[b]64bit:[/b] {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices SafeBootNet: AppMgmt - Service SafeBootNet: Base - Driver Group SafeBootNet: Boot Bus Extender - Driver Group SafeBootNet: Boot file system - Driver Group SafeBootNet: File system - Driver Group SafeBootNet: Filter - Driver Group SafeBootNet: HelpSvc - Service SafeBootNet: MCODS - Reg Error: Value error. SafeBootNet: Messenger - Service SafeBootNet: NDIS Wrapper - Driver Group SafeBootNet: NetBIOSGroup - Driver Group SafeBootNet: NetDDEGroup - Driver Group SafeBootNet: Network - Driver Group SafeBootNet: NetworkProvider - Driver Group SafeBootNet: PCI Configuration - Driver Group SafeBootNet: PNP Filter - Driver Group SafeBootNet: PNP_TDI - Driver Group SafeBootNet: Primary disk - Driver Group SafeBootNet: rdsessmgr - Service SafeBootNet: sacsvr - Service SafeBootNet: SCSI Class - Driver Group SafeBootNet: Streams Drivers - Driver Group SafeBootNet: System Bus Extender - Driver Group SafeBootNet: TDI - Driver Group SafeBootNet: vmms - Service SafeBootNet: WudfUsbccidDriver - Driver SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices [color=#E56717]========== Files/Folders - Created Within 60 Days ==========[/color] [2013/01/02 19:34:04 | 000,000,000 | ---D | C] -- C:\_OTL [2013/01/02 00:20:19 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\e-academy Inc [2013/01/02 00:20:19 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Local\e-academy Inc [2013/01/01 15:51:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\trend micro [2013/01/01 15:51:57 | 000,000,000 | ---D | C] -- C:\rsit [2012/12/31 16:26:25 | 000,000,000 | ---D | C] -- C:\Users\Adam\Desktop\6fe84fe7ac7805a731ff8c0f08034a71 [2012/12/31 16:26:08 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR [2012/12/31 16:26:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR [2012/12/31 00:12:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Ad-Aware Antivirus [2012/12/31 00:12:23 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\LavasoftStatistics [2012/12/31 00:02:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft [2012/12/31 00:01:23 | 000,014,456 | ---- | C] (GFI Software) -- C:\Windows\SysNative\drivers\gfibto.sys [2012/12/30 23:59:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Toolbar Cleaner [2012/12/30 23:57:48 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\Ad-Aware Antivirus [2012/12/30 23:02:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy [2012/12/30 20:59:50 | 000,000,000 | ---D | C] -- C:\Users\Adam\Doctor Web [2012/12/30 11:10:17 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Adam\Desktop\OTL.exe [2012/12/29 17:11:42 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Local\Akamai [2012/12/29 17:11:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Applications [2012/12/29 15:59:10 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallJammer Registry [2012/12/29 15:59:06 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Soldis [2012/12/29 15:58:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Soldis PROJEKTANT [2012/12/29 15:41:09 | 000,000,000 | ---D | C] -- C:\ProgramData\WoW Worldwide Software LTD [2012/12/29 15:41:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SoftQuick [2012/12/29 15:40:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ContinueToSave [2012/12/29 15:39:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt [2012/12/29 15:39:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NapiProjekt [2012/12/29 12:52:01 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\Malwarebytes [2012/12/29 12:51:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012/12/29 12:51:47 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2012/12/15 16:23:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2012/12/15 16:22:56 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes [2012/12/15 16:22:56 | 000,000,000 | ---D | C] -- C:\Program Files\iPod [2012/12/15 16:22:56 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 [2012/12/14 19:00:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [2012/12/14 19:00:41 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype [2012/12/14 19:00:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype [2012/11/27 17:33:47 | 000,000,000 | ---D | C] -- C:\Users\Adam\Documents\Autodesk [2012/11/24 16:28:34 | 000,000,000 | ---D | C] -- C:\Users\Adam\Desktop\Pobrane [2012/11/23 17:56:22 | 000,000,000 | ---D | C] -- C:\ProgramData\MemeoCommon [2012/11/23 17:50:44 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\Memeo [2012/11/23 17:50:27 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\Seagate [2012/11/23 17:50:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate Dashboard [2012/11/23 17:49:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Memeo [2012/11/23 17:49:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Memeo [2012/11/23 17:49:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Memeo [2012/11/23 17:49:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Seagate [2012/11/17 16:18:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime [color=#E56717]========== Files - Modified Within 60 Days ==========[/color] [2013/01/02 20:09:03 | 006,553,600 | -HS- | M] () -- C:\Users\Adam\ntuser.dat [2013/01/02 20:02:26 | 000,025,120 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013/01/02 20:02:26 | 000,025,120 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013/01/02 19:46:46 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\ContinueToSaveUpdaterTask{EE3D1E2A-0D0C-4142-BEAC-D554184FF8B1}.job [2013/01/02 19:46:41 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2013/01/02 19:46:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013/01/02 19:46:30 | 3203,735,552 | -HS- | M] () -- C:\hiberfil.sys [2013/01/02 19:44:17 | 001,645,938 | -H-- | M] () -- C:\Users\Adam\AppData\Local\IconCache.db [2013/01/02 19:42:19 | 000,551,997 | ---- | M] () -- C:\Users\Adam\Desktop\AdwCleaner.exe [2013/01/02 19:28:06 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013/01/02 19:27:56 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt [2013/01/02 19:15:08 | 000,001,054 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-319703930-2572490357-2975701463-1000UA.job [2013/01/02 19:15:03 | 000,001,002 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-319703930-2572490357-2975701463-1000Core.job [2013/01/02 12:27:51 | 000,121,928 | ---- | M] () -- C:\Users\Adam\Desktop\bookmarks_02.01.2013.html [2013/01/02 00:24:02 | 000,000,183 | ---- | M] () -- C:\Users\Adam\Desktop\100151449280.sdx [2013/01/02 00:23:35 | 000,003,109 | ---- | M] () -- C:\Users\Adam\Desktop\Shortcut to SecureDownloadManager.exe.lnk [2013/01/01 23:43:21 | 001,663,484 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013/01/01 23:43:21 | 000,738,208 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat [2013/01/01 23:43:21 | 000,652,376 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013/01/01 23:43:21 | 000,154,864 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat [2013/01/01 23:43:21 | 000,121,308 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013/01/01 15:51:15 | 000,781,383 | ---- | M] () -- C:\Users\Adam\Desktop\RSIT.exe [2012/12/31 00:01:23 | 000,014,456 | ---- | M] (GFI Software) -- C:\Windows\SysNative\drivers\gfibto.sys [2012/12/30 19:02:43 | 107,644,520 | ---- | M] () -- C:\Users\Adam\Desktop\launch.exe [2012/12/30 11:10:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Adam\Desktop\OTL.exe [2012/12/29 15:59:10 | 000,001,945 | ---- | M] () -- C:\Users\Public\Desktop\Soldis PROJEKTANT 7.0.lnk [2012/12/29 12:34:58 | 000,524,288 | -HS- | M] () -- C:\Users\Adam\ntuser.dat{d9cb46bd-51a4-11e2-9dff-b870f45d63bf}.TMContainer00000000000000000002.regtrans-ms [2012/12/29 12:34:58 | 000,524,288 | -HS- | M] () -- C:\Users\Adam\ntuser.dat{d9cb46bd-51a4-11e2-9dff-b870f45d63bf}.TMContainer00000000000000000001.regtrans-ms [2012/12/29 12:34:58 | 000,065,536 | -HS- | M] () -- C:\Users\Adam\ntuser.dat{d9cb46bd-51a4-11e2-9dff-b870f45d63bf}.TM.blf [2012/12/22 11:40:23 | 000,519,784 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2012/12/15 16:23:54 | 000,001,539 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk [2012/12/14 16:49:28 | 000,024,176 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2012/11/24 20:32:32 | 000,303,616 | ---- | M] () -- C:\Windows\SysNative\drivers\atksgt.sys [2012/11/23 17:50:22 | 000,001,224 | ---- | M] () -- C:\Users\Public\Desktop\Seagate Dashboard.lnk [2012/11/15 20:15:27 | 000,147,832 | ---- | M] () -- C:\Users\Adam\AppData\Local\GDIPFONTCACHEV1.DAT [color=#E56717]========== Files Created - No Company Name ==========[/color] [2013/01/02 19:42:13 | 000,551,997 | ---- | C] () -- C:\Users\Adam\Desktop\AdwCleaner.exe [2013/01/02 12:27:51 | 000,121,928 | ---- | C] () -- C:\Users\Adam\Desktop\bookmarks_02.01.2013.html [2013/01/02 00:24:02 | 000,000,183 | ---- | C] () -- C:\Users\Adam\Desktop\100151449280.sdx [2013/01/02 00:23:35 | 000,003,109 | ---- | C] () -- C:\Users\Adam\Desktop\Shortcut to SecureDownloadManager.exe.lnk [2013/01/01 15:51:10 | 000,781,383 | ---- | C] () -- C:\Users\Adam\Desktop\RSIT.exe [2012/12/30 18:54:53 | 107,644,520 | ---- | C] () -- C:\Users\Adam\Desktop\launch.exe [2012/12/29 15:59:10 | 000,001,945 | ---- | C] () -- C:\Users\Public\Desktop\Soldis PROJEKTANT 7.0.lnk [2012/12/29 15:40:59 | 000,000,416 | -H-- | C] () -- C:\Windows\tasks\ContinueToSaveUpdaterTask{EE3D1E2A-0D0C-4142-BEAC-D554184FF8B1}.job [2012/12/29 14:47:22 | 001,645,938 | -H-- | C] () -- C:\Users\Adam\AppData\Local\IconCache.db [2012/12/29 12:31:41 | 000,524,288 | -HS- | C] () -- C:\Users\Adam\ntuser.dat{d9cb46bd-51a4-11e2-9dff-b870f45d63bf}.TMContainer00000000000000000002.regtrans-ms [2012/12/29 12:31:41 | 000,524,288 | -HS- | C] () -- C:\Users\Adam\ntuser.dat{d9cb46bd-51a4-11e2-9dff-b870f45d63bf}.TMContainer00000000000000000001.regtrans-ms [2012/12/29 12:31:41 | 000,065,536 | -HS- | C] () -- C:\Users\Adam\ntuser.dat{d9cb46bd-51a4-11e2-9dff-b870f45d63bf}.TM.blf [2012/12/15 16:23:54 | 000,001,539 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk [2012/11/23 17:50:22 | 000,001,224 | ---- | C] () -- C:\Users\Public\Desktop\Seagate Dashboard.lnk [2012/11/14 22:28:49 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf [2012/11/14 22:21:32 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf [2012/05/29 10:30:53 | 000,174,742 | ---- | C] () -- C:\Windows\hpoins45.dat [2012/05/18 13:34:13 | 000,644,608 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll [2012/05/18 13:34:13 | 000,258,048 | ---- | C] () -- C:\Windows\SysWow64\libFLAC.dll [2012/04/01 16:02:50 | 000,000,287 | ---- | C] () -- C:\Windows\game.ini [2012/02/25 22:21:02 | 000,007,599 | ---- | C] () -- C:\Users\Adam\AppData\Local\Resmon.ResmonCfg [2012/01/09 19:33:48 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll [2012/01/09 19:33:48 | 000,079,360 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll [2012/01/08 11:20:00 | 000,339,968 | ---- | C] () -- C:\Windows\SysWow64\pythoncom25.dll [2012/01/08 11:20:00 | 000,114,688 | ---- | C] () -- C:\Windows\SysWow64\pywintypes25.dll [2012/01/07 21:16:00 | 000,354,304 | ---- | C] () -- C:\Windows\SysWow64\pythoncom27.dll [2012/01/07 21:16:00 | 000,110,080 | ---- | C] () -- C:\Windows\SysWow64\pywintypes27.dll [2012/01/07 21:16:00 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\pythoncomloader27.dll [2011/12/15 19:17:34 | 000,003,584 | ---- | C] () -- C:\Users\Adam\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011/10/22 20:01:23 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll [2011/10/03 22:23:24 | 001,639,622 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2011/09/30 21:40:54 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2011/09/26 20:56:04 | 000,147,832 | ---- | C] () -- C:\Users\Adam\AppData\Local\GDIPFONTCACHEV1.DAT [2011/09/26 20:54:04 | 000,524,288 | -HS- | C] () -- C:\Users\Adam\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms [2011/09/26 20:54:04 | 000,524,288 | -HS- | C] () -- C:\Users\Adam\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms [2011/09/26 20:54:04 | 000,065,536 | -HS- | C] () -- C:\Users\Adam\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf [2011/09/26 20:54:04 | 000,000,020 | -HS- | C] () -- C:\Users\Adam\ntuser.ini [2011/09/26 20:54:03 | 006,553,600 | -HS- | C] () -- C:\Users\Adam\ntuser.dat [2011/04/23 13:55:12 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI [2011/04/23 13:43:55 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe [2011/02/03 18:56:58 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll [color=#E56717]========== ZeroAccess Check ==========[/color] [2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== LOP Check ==========[/color] [2012/12/31 00:31:14 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Ad-Aware Antivirus [2012/03/17 13:05:01 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Atari [2012/12/05 06:52:18 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Autodesk [2012/08/04 10:35:00 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\DAEMON Tools Lite [2012/11/24 00:54:07 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\DAEMON Tools Pro [2013/01/02 00:20:19 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\e-academy Inc [2012/01/06 11:25:21 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\eu.myphotobook.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1 [2012/07/03 19:50:20 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Gadu-Gadu 10 [2012/12/29 19:11:22 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\GanymedeNet [2012/03/17 11:17:25 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Kalypso Media [2012/03/17 10:59:24 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Leadertech [2012/11/24 00:38:25 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Memeo [2012/05/30 17:49:47 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\NapiProjekt [2012/07/18 13:29:59 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\ObviousIdea [2011/11/15 12:03:00 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\OpenOffice.org [2012/10/22 19:30:18 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\PROCAD [2012/07/07 13:41:45 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Programy [2011/10/30 20:56:01 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Scilab [2012/11/23 17:50:27 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Seagate [2012/03/29 19:06:37 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\SoftGrid Client [2012/09/14 11:06:09 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Sony [2011/09/26 23:25:59 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Toshiba [2011/10/04 09:57:56 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\TOSHIBA Online Product Information [2011/10/03 22:23:55 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\TP [2012/12/29 12:30:37 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\uTorrent [2012/08/15 18:59:37 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\wargaming.net [2011/12/02 08:07:12 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\ZWSoft [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Custom Scans ==========[/color] [color=#A23BEC]< %systemdrive%\*.* >[/color] [2012/11/12 20:40:02 | 000,000,000 | ---- | M] () -- C:\1Clickfoldertest.txt [2013/01/02 19:43:46 | 000,006,245 | ---- | M] () -- C:\AdwCleaner[S1].txt [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1028.txt [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1031.txt [2007/11/07 07:00:40 | 000,010,134 | ---- | M] () -- C:\eula.1033.txt [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1036.txt [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1040.txt [2007/11/07 07:00:40 | 000,000,118 | ---- | M] () -- C:\eula.1041.txt [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1042.txt [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.2052.txt [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.3082.txt [2007/11/07 07:00:40 | 000,001,110 | ---- | M] () -- C:\globdata.ini [2013/01/02 19:46:30 | 3203,735,552 | -HS- | M] () -- C:\hiberfil.sys [2007/11/07 07:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe [2007/11/07 07:00:40 | 000,000,843 | ---- | M] () -- C:\install.ini [2007/11/07 07:03:18 | 000,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll [2007/11/07 07:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll [2007/11/07 07:03:18 | 000,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll [2007/11/07 07:03:18 | 000,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll [2007/11/07 07:03:18 | 000,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll [2007/11/07 07:03:18 | 000,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll [2007/11/07 07:03:18 | 000,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll [2007/11/07 07:03:18 | 000,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll [2007/11/07 07:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll [2012/04/10 14:55:40 | 000,032,915 | ---- | M] () -- C:\M1319.log [2013/01/02 19:46:31 | 4271,648,768 | -HS- | M] () -- C:\pagefile.sys [2011/04/23 13:41:54 | 000,002,234 | ---- | M] () -- C:\RHDSetup.log [2011/03/28 17:49:43 | 000,000,070 | -H-- | M] () -- C:\SWSTAMP.TXT [2007/11/07 07:00:40 | 000,005,686 | ---- | M] () -- C:\vcredist.bmp [2007/11/07 07:09:22 | 001,442,522 | ---- | M] () -- C:\VC_RED.cab [2007/11/07 07:12:28 | 000,232,960 | ---- | M] () -- C:\VC_RED.MSI [color=#A23BEC]< MD5 for: AGP440.SYS >[/color] [2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\drivers\AGP440.sys [2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys [2009/07/14 02:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 -- C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys [color=#A23BEC]< MD5 for: ATAPI.SYS >[/color] [2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys [2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys [2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys [color=#A23BEC]< MD5 for: BEEP.SYS >[/color] [2009/07/14 01:00:13 | 000,006,656 | ---- | M] (Microsoft Corporation) MD5=16A47CE2DECC9B099349A5F840654746 -- C:\Windows\SysNative\drivers\beep.sys [2009/07/14 01:00:13 | 000,006,656 | ---- | M] (Microsoft Corporation) MD5=16A47CE2DECC9B099349A5F840654746 -- C:\Windows\winsxs\amd64_microsoft-windows-beepsys_31bf3856ad364e35_6.1.7600.16385_none_201592fa214e4f02\beep.sys [color=#A23BEC]< MD5 for: CDROM.SYS >[/color] [2010/11/21 04:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\drivers\cdrom.sys [2010/11/21 04:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\SysNative\DriverStore\FileRepository\cdrom.inf_amd64_neutral_0b3d0d1942ab684b\cdrom.sys [2010/11/21 04:23:47 | 000,147,456 | ---- | M] (Microsoft Corporation) MD5=F036CE71586E93D94DAB220D7BDF4416 -- C:\Windows\winsxs\amd64_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_bdcf6151ba66f48b\cdrom.sys [color=#A23BEC]< MD5 for: NDIS.SYS >[/color] [2012/08/22 19:06:07 | 000,950,128 | ---- | M] (Microsoft Corporation) MD5=5E74508FCB5820B29EEAFE24E6035BCF -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.22097_none_06232d534c0a8d67\ndis.sys [2012/08/22 19:12:40 | 000,950,128 | ---- | M] (Microsoft Corporation) MD5=760E38053BF56E501D562B70AD796B88 -- C:\Windows\SysNative\drivers\ndis.sys [2012/08/22 19:12:40 | 000,950,128 | ---- | M] (Microsoft Corporation) MD5=760E38053BF56E501D562B70AD796B88 -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.17939_none_05dc9a6832ba428a\ndis.sys [2010/11/21 04:23:55 | 000,951,680 | ---- | M] (Microsoft Corporation) MD5=79B47FD40D9A817E932F9D26FAC0A81C -- C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.17514_none_05ed313632ae9759\ndis.sys [color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color] [2010/11/21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe [2010/11/21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe < End of report > [/log] EXTRAS: [log] OTL Extras logfile created on: 1/2/2013 8:04:33 PM - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Adam\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000409 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3.98 Gb Total Physical Memory | 2.12 Gb Available Physical Memory | 53.24% Memory free 7.95 Gb Paging File | 5.85 Gb Available in Paging File | 73.51% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 298.09 Gb Total Space | 218.62 Gb Free Space | 73.34% Space Free | Partition Type: NTFS Drive D: | 297.69 Gb Total Space | 189.67 Gb Free Space | 63.71% Space Free | Partition Type: NTFS Computer Name: ADAM-TOSHIBA | User Name: Adam | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: Off | File Age = 60 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~4\Office12\ONENOTE.EXE "%L" Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~4\Office12\ONENOTE.EXE "%L" Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{094CFB76-5066-4C4B-AA60-DACF135B28C3}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{12CA7623-3E3F-4163-AF39-7FF34AA30D2C}" = rport=10243 | protocol=6 | dir=out | app=system | "{212D3D2F-E8A7-4CBA-ADB8-70317C3F7CE5}" = lport=445 | protocol=6 | dir=in | app=system | "{21F7CEBE-0D9C-495D-90B6-4C2B01D45184}" = lport=138 | protocol=17 | dir=in | app=system | "{519160B0-69B7-4B5E-BDD0-FEA142035D25}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{55D9B36A-4B99-4D0A-AA72-2C78DE7BEA95}" = lport=137 | protocol=17 | dir=in | app=system | "{5F2BD67A-751C-4BEB-9C1B-546AFDAF3566}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{65CD3B7A-03ED-4257-92EA-D8366B085935}" = lport=2869 | protocol=6 | dir=in | app=system | "{74FBE3B2-8C8D-416A-B4C1-F95FF2E8C4AB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{818D6C54-2918-470F-8D60-E3201A6C2D79}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{907EE603-9C1A-4044-B82D-46A475A62D06}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{918146C0-E442-4457-A33D-ABBA0784845F}" = lport=10243 | protocol=6 | dir=in | app=system | "{9B04C10D-B0DC-40B0-BAC8-DD40A5EDF009}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{A6B3F750-DD94-430A-B8C2-DBA86B7881C1}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{AC07E7FF-1906-4277-85C8-3A42542FB12B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{BFEAFAD9-79F1-4401-9CAD-72AFEF4276A5}" = rport=139 | protocol=6 | dir=out | app=system | "{CAE9E3EC-A56E-4D64-913C-BBEFFF030FBF}" = rport=137 | protocol=17 | dir=out | app=system | "{D44B3782-F6E3-4F07-BEC1-CA6FCAA8EF38}" = rport=138 | protocol=17 | dir=out | app=system | "{DB4165A7-AA3E-4C26-8D3F-F12F484D770C}" = rport=445 | protocol=6 | dir=out | app=system | "{E19A50B5-0464-4A6D-86A9-BAC3C4318305}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{E4D18DB3-A97F-4787-9E84-4B25BE40E4A5}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{F0E68969-A195-419C-A2FE-2E3B7726E061}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{F988C693-8A5D-467B-8C7F-520547BAF434}" = lport=139 | protocol=6 | dir=in | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0720C203-F64C-4138-832C-C316F4477579}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqcopy2.exe | "{128E6BBC-98B8-4F3C-B2EE-D2EB7EEA5CA3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{18F6CD47-17CC-40DA-BA09-4AC68BE0A9CE}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{19D486B0-1410-4E3B-995A-A44F10DC7371}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{2238DCA3-ACB6-42BF-9139-A8C670F1003B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe | "{25E1E729-0B50-4DAF-98AF-B0B6ACA969B1}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{261838AB-481A-44AE-B692-C756715AD704}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe | "{28F6A0DA-5523-4888-AB08-5F114F842AC9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{2A89A8EF-1F5F-4C05-BC9F-231FF0B8F1D1}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe | "{2EE8C41B-7930-47D6-8780-951B5C7D9994}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe | "{3059DE52-517B-476A-97A7-02642B4445C8}" = protocol=6 | dir=out | app=system | "{36D2E2F9-72DD-4B7B-8708-290D1BD0FAA4}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe | "{3D04F373-162D-4CE8-AFD5-A290F1746FFD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{3D8FB1DF-CB9E-4A21-BB81-814867C8D92B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{4813F9E4-9E56-487A-9E6F-DEABF6716244}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{5D621279-2987-4DEB-932C-3A81D455BF4B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe | "{60BA7020-5735-4274-AA33-CE12ABCF6B5F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{706DE1A9-29BA-4259-A346-2C2C1D692757}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{76D41A3F-FAE2-4E77-8B57-5983731999ED}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{7E018989-3D49-4769-9E5A-956B3804C83D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{825B0FC9-C8B4-4595-8D77-70667B9130C1}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{84E2008C-92AF-4D56-89BF-5653C5FA68E9}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe | "{89FBDF2A-4024-4409-9BC7-2164275BA25B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe | "{93FD57D8-A1DD-44C1-A863-210E30978CCC}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{968B58F1-6C47-4789-848A-80C57F20FB23}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe | "{9828B130-E990-4C39-83EE-508576F8318B}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{9D138229-E2FF-42AB-926A-EE0044C7E6CB}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe | "{A292D33C-D73C-4087-A004-86C92D99920A}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{BEAF98C9-2C09-443E-BFEF-14183E486DF8}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe | "{CA77A647-C547-47FB-B290-20252985D5B8}" = dir=in | app=c:\program files (x86)\seagate\seagate dashboard\hipservagent\hipservagent.exe | "{D0C10F8E-B6F4-4EB0-B688-2F77D6F1B19F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{D2F899D7-CA22-4C64-A3A3-6DA14C44EF9A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{D71F5A0C-592C-4480-96E3-0C86ABEF5F1E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{D8A7E1A4-99EC-433B-944C-F581533131A5}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe | "{E4AEEE9C-9B17-4ED2-AD55-03425AF64318}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{E673AC68-B661-48EE-83CD-B492DE4BA6CB}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe | "{E9D24D47-6A57-40A4-939E-AC1E085FA583}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{EDF670B0-21C2-4FCF-9240-65683366954E}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{F74124FD-E31A-4739-8142-766695981DC9}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{FA53E896-DBDD-4A1A-AD63-336638E55015}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{FCC9F8E6-D5B3-45C8-BEFD-E36FA961A218}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "TCP Query User{31081F40-F8E9-454B-BD21-567123C26069}C:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe" = protocol=6 | dir=in | app=c:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe | "TCP Query User{65C7CB83-2B07-478E-850D-BB7A96F92436}C:\users\adam\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\adam\appdata\local\akamai\netsession_win.exe | "TCP Query User{7D63A7DA-4A0D-40DD-AF06-627327FEFC6A}C:\program files (x86)\allmediaserver\mediaserver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\allmediaserver\mediaserver.exe | "TCP Query User{C671ACF3-C9D0-4E8D-A592-462BBABD87BC}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe | "TCP Query User{D0CCD619-292C-47EA-B6A5-3A9EF45A2C50}C:\program files (x86)\1clickdownload\1clickdownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\1clickdownload\1clickdownloader.exe | "TCP Query User{D40871D4-8EA3-4419-B9EF-DD32A6B409E8}C:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe" = protocol=6 | dir=in | app=c:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe | "TCP Query User{E60E4261-01E5-4B3B-9D06-555F0CDFC4D0}C:\users\adam\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\adam\appdata\local\akamai\netsession_win.exe | "UDP Query User{12527538-DE98-49AC-AE11-3DCA33E53A3D}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe | "UDP Query User{2613D914-28CB-4089-A263-EE761064D391}C:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe" = protocol=17 | dir=in | app=c:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe | "UDP Query User{2D23835C-E028-4E5E-BDD0-B69673F6A8E7}C:\users\adam\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\adam\appdata\local\akamai\netsession_win.exe | "UDP Query User{528FDE88-C913-4254-920E-A0AA1F7A44E9}C:\program files (x86)\allmediaserver\mediaserver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\allmediaserver\mediaserver.exe | "UDP Query User{985B1D64-5C17-4C83-B09F-FADFBA7C062B}C:\program files (x86)\1clickdownload\1clickdownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\1clickdownload\1clickdownloader.exe | "UDP Query User{9CA09DDF-2238-4B9F-B07E-B1D017A943CC}C:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe" = protocol=17 | dir=in | app=c:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe | "UDP Query User{E4EFA3CA-6B1F-4B7E-A729-A57DB6C10996}C:\users\adam\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\adam\appdata\local\akamai\netsession_win.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{0E5D76AD-A3FB-48D5-8400-8903B10317D3}" = iTunes "{19F09425-3C20-4730-9E2A-FC2E17C9F362}" = Windows Live Remote Service Resources "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant "{230C483A-BCB8-4AA1-AC28-6CDAED005E71}" = Autodesk Robot Structural Analysis Professional 2012 - Polish regional settings "{2426E29F-9E8C-4C0B-97FC-0DB690C1ED98}" = Windows Live Remote Client Resources "{2A8EEE2F-4A9E-43D8-AA07-EC8A316B2DEB}" = Autodesk Revit Architecture 2010 x64 "{2F304EF4-0C31-47F4-8557-0641AAE4197C}" = Windows Live Remote Client Resources "{34384A2A-2CA2-4446-AB0E-1F360BA2AAC5}" = Windows Live Remote Service Resources "{3921492E-82D2-4180-8124-E347AD2F2DB4}" = Windows Live Remote Client Resources "{4200F74C-623C-7FFF-9D14-2A1E99E3D5BA}" = ContinueToSave "{480F28F0-8BCE-404A-A52E-0DBB7D1CE2EF}" = Windows Live Remote Service Resources "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5141AA6E-5FAC-4473-BFFB-BEE69DDC7F2B}" = Windows Live Remote Service Resources "{5151E2DB-0748-4FD1-86A2-72E2F94F8BE7}" = Windows Live Remote Service Resources "{5783F2D7-9001-0415-0102-0060B0CE6BBA}" = AutoCAD 2011 - Polski "{5783F2D7-9001-0415-1102-0060B0CE6BBA}" = AutoCAD 2011 Language Pack - Polski "{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator "{5F44A3A1-5D24-4708-8776-66B42B174C64}" = Windows Live Remote Client Resources "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6051912A-F7B8-445C-A99D-81AA4C118836}" = HP Deskjet Ink Advant K209a-z All-in-One Driver Software 14.0 Rel. 6 "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{8E5DA9A6-7A9F-3A6F-BC5C-D6CBCA6A29C7}" = Microsoft .NET Framework 4 Extended PLK Language Pack "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2007 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{A49402DD-2781-3782-B0CF-52BDA349E3F3}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{AC0A533B-5E29-4081-8D1E-31BE65320527}" = Autodesk Robot Structural Analysis Professional 2012 "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 267.21 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 267.21 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 267.21 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.1.13.1 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64 "{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector "{D0CB24F4-084F-40DE-B6B9-A03626E682F0}" = iCloud "{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{DBEDAF67-C5A3-4C91-951D-31F3FE63AF3F}" = Windows Live Remote Client Resources "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORMCLauncher "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer "AutoCAD 2011 - Polski" = AutoCAD 2011 - Polski "Autodesk Revit Architecture 2010 x64" = Autodesk Revit Architecture 2010 x64 "Autodesk Robot Structural Analysis Professional 2012" = Autodesk Robot Structural Analysis Professional 2012 "CCleaner" = CCleaner "ContinueToSave" = "HP Imaging Device Functions" = HP Imaging Device Functions 14.0 "HP Smart Web Printing" = HP Smart Web Printing 4.60 "HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0 "HPExtendedCapabilities" = HP Customer Participation Program 14.0 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft .NET Framework 4 Extended PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Extended "Shop for HP Supplies" = Shop for HP Supplies "SynTPDeinstKey" = Synaptics Pointing Device Driver "WinRAR archiver" = WinRAR 4.20 (64-bitowy) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0654EA5D-308A-4196-882B-5C09744A5D81}" = Windows Live Photo Common "{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan "{09922FFE-D153-44AE-8B60-EA3CB8088F93}" = Windows Live UX Platform Language Pack "{0A50CB27-D2D5-4B7D-A001-30B1782A450B}" = DJ_AIO_06_K209a-z_SW_Min "{0A9256E0-C924-46DE-921B-F6C4548A1C64}" = Windows Live Messenger "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0C1931EB-8339-4837-8BEC-75029BF42734}" = Windows Live UX Platform Language Pack "{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1 "{11778DA1-0495-4ED9-972F-F9E0B0367CD5}" = Windows Live Writer "{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver "{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery "{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant "{1727CD47-A408-11d2-AFAD-00C04F72FB3E}" = VBA (2720) "{17F99FCE-8F03-4439-860A-25C5A5434E18}" = Windows Live Essentials "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{1DA6D447-C54D-4833-84D4-3EA31CAECE9B}" = Windows Live UX Platform Language Pack "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{1FC83EAE-74C8-4C72-8400-2D8E40A017DE}" = Windows Live Writer "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 29 "{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 9 "{26E3C07C-7FF7-4362-9E99-9E49E383CF16}" = Windows Live Writer Resources "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections "{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox "{299C0434-4F4E-341F-A916-4E07AEB35E79}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime "{2C303EE0-A595-3543-A71A-931C7AC40EDE}" = Microsoft Primary Interoperability Assemblies 2005 "{2C7E8AA1-9C03-4606-BF34-5D99D07964DA}" = Windows Live Messenger "{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update "{2FB9EA69-51D4-4913-9AD5-762C034DE811}" = Status "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{34C4F5AF-D757-4E6A-ABCA-65AB5A50A1A8}" = Windows Live Messenger "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{4264C020-850B-4F08-ACBE-98205D9C336C}" = Windows Live Writer "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4A5667B2-5D13-46C2-85B5-9D46A6096F61}" = Secure Download Manager "{4B28D47A-5FF0-45F8-8745-11DC2A1C9D0F}" = Windows Live Writer "{50300123-F8FC-4B50-B449-E847D04F1BA2}" = Windows Live Messenger "{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion "{5275D81E-83AD-4DE4-BC2B-6E6BA3A33244}" = Windows Live Writer Resources "{55D9E026-DCB0-46FF-B60A-68B972228CF6}" = Autodesk Design Review 2010 "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack "{5A3ECDDA-562C-4281-BFE5-A4C8F32EACA3}" = K209a-z "{5DCF0E4B-F8EA-4229-A0BD-5CA6D4AFB749}" = SolutionCenter "{5E627606-53B9-42D1-97E1-D03F6229E248}" = Windows Live UX Platform Language Pack "{5f6460bd-391e-43ce-bcf3-130ef02f8cb2}_is1" = VshareComplete "{60C3C026-DB53-4DAB-8B97-7C1241F9A847}" = Windows Live Movie Maker "{64376910-1860-4CEF-8B34-AA5D205FC5F1}" = Poczta usługi Windows Live "{6491AB99-A11E-41FD-A5E7-32DE8A097B8E}" = Windows Live Essentials "{64B2D6B3-71AC-45A7-A6A1-2E07ABF58341}" = Windows Live Movie Maker "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6ABE832B-A5C7-44C1-B697-3E123B7B4D5B}" = Windows Live Mesh "{6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94}" = TOSHIBA Resolution+ Plug-in for Windows Media Player "{6D2F0A26-ECEA-49CE-833C-9A6125F3D5E8}" = Doplnok programu Messenger "{6E29C4F7-C2C2-4B18-A15C-E09B92065F15}" = Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz "{6EE9F44A-B8C7-4CDB-B2A9-441AF2AE315A}" = Windows Live Messenger "{6F37D92B-41AA-44B7-80D2-457ABDE11896}" = Windows Live Photo Common "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{7272F232-A7E0-4B2B-A5D2-71B7C5E2379C}" = Windows Live Fotótár "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{7496FD31-E5CB-4AE4-82D3-31099558BF6A}" = Windows Live Mesh "{74E8A7F6-575D-42C7-9178-E87D1B3BEFE8}" = Windows Live UX Platform Language Pack "{75B7F766-7998-44d8-A202-F1EC76A121BA}" = Memeo AutoSync "{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{78906B56-0E81-42A7-AC25-F54C946E1538}" = Windows Live Photo Common "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core "{7A9D47BA-6D50-4087-866F-0800D8B89383}" = Podstawowe programy Windows Live "{7CB529B2-6C74-4878-9C3F-C29C3C3BBDC6}" = Windows Live Writer Resources "{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger "{80E8C65A-8F70-4585-88A2-ABC54BABD576}" = Windows Live Mesh "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{84267681-BF16-40B6-9564-27BC57D7D71C}" = Windows Live Photo Common "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8E666407-AC41-46a2-9692-6C7BFCBFDD37}" = Memeo Instant Backup "{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg "{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}_HOMESTUDENTR_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}_HOMESTUDENTR_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}_HOMESTUDENTR_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-001F-0415-0000-0000000FF1CE}_HOMESTUDENTR_{9CC96D78-9E1D-46E0-AF4D-3EB440CD4619}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002A-0415-1000-0000000FF1CE}_HOMESTUDENTR_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}_HOMESTUDENTR_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}_HOMESTUDENTR_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{94B4E2D8-A184-415C-BF9E-F699D76466BD}" = Heroes of Might and Magic IV - Złota Edycja "{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}" = FARO LS 1.1.406.58 "{96403552-88D1-429F-9C92-388B814B885E}" = Messenger Companion "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader "{97F77D62-5110-4FA3-A2D3-410B92D31199}" = Windows Live Fotogaléria "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE466FF-70B7-4DA8-807C-DB4C3610FDAA}" = Copy "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D3D8C60-A55F-4fed-B2B9-173001290E16}" = Realtek WLAN Driver "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{9DEABCB6-B759-4D52-92F8-51B34A2B4D40}" = Autodesk Material Library 2011 "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer "{AB78C965-5C67-409B-8433-D7B5BDB12073}" = Windows Live Writer Resources "{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply "{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.4) MUI "{AD001A69-88CC-4766-B2DB-3C1DFAB9AC72}" = Windows Live Mesh "{ADE85655-8D1E-4E4B-BF88-5E312FB2C74F}" = Windows Live Mail "{ADFE4AED-7F8E-4658-8D6E-742B15B9F120}" = Windows Live Photo Common "{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime "{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}" = Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych "{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR "{B44F3823-52DD-45CA-A916-8B320778715D}" = Messenger Companion "{B6190387-0036-4BEB-8D74-A0AFC5F14706}" = Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení "{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX "{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2 "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations "{BD8DA595-F501-4ABE-85A0-5C23E82472A0}" = Pomocnik Messenger "{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo "{BF022D76-9F72-4203-B8FA-6522DC66DFDA}" = Windows Live Movie Maker "{BF35168D-F6F9-4202-BA87-86B5E3C9BF7A}" = Windows Live Mesh "{C00C2A91-6CB3-483F-80B3-2958E29468F1}" = Συλλογή φωτογραφιών του Windows Live "{C29FC15D-E84B-4EEC-8505-4DED94414C59}" = Windows Live Writer Resources "{C2FD7DB5-FE30-49B6-8A2F-C5652E053C31}" = Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia "{C3A11907-930D-41AC-A135-CC3B12F92011}" = Seagate Dashboard "{C454280F-3C3E-4929-B60E-9E6CED5717E7}" = Windows Live Mail "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{C8421D85-CA0E-4E93-A9A9-B826C4FB88EA}" = Windows Live Mail "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget "{CB3F59BB-7858-41A1-A7EA-4B8A6FC7D431}" = Galeria fotografii usługi Windows Live "{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Obsługa programów Apple "{CD1E078C-A6B9-47DA-B035-6365C85C7832}" = Autodesk Material Library 2011 Base Image library "{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime "{E55E0C35-AC3C-4683-BA2F-834348577B80}" = Windows Live Writer "{E5F05232-96B6-4552-A480-785A60A94B21}" = System Requirements Lab CYRI "{EA17F4FC-FDBF-4CF8-A529-2D983132D053}" = Skype™ 6.0 "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F3ECEB0A-82A0-4DB9-BB44-393A66BA0871}" = Messenger kísérő "{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}" = Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις "{F80E5450-3EF3-4270-B26C-6AC53BEC5E76}" = Windows Live Movie Maker "{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm "{FA6CF94F-DACF-4FE7-959D-55C421B91B17}" = Windows Live Mail "{FB3D07AE-73D0-47A9-AC12-6F50BF8B6202}" = Windows Live Movie Maker "{FB79FDB7-4DE1-453D-99FE-9A880F57380E}" = Windows Live Fotogalerie "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "{FE62C88B-425B-4BDE-8B70-CD5AE3B83176}" = Windows Live Essentials "{FE77909E-B782-4554-A92A-4D887CEF0ACC}_is1" = ALLMediaServer "{FEEF7F78-5876-438B-B554-C4CC426A4302}" = Windows Live Essentials "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "ALLPlayer_is1" = ALLPlayer V5.X "Autodesk Design Review 2010" = Autodesk Design Review 2010 "avast" = avast! Free Antivirus "E94B1101-7675-4E37-9CB2-2E38A872154A" = Soldis PROJEKTANT "GameDesire-Pool & Snooker" = GameDesire-Pool & Snooker "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "InstallShield_{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver "InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORMCLauncher "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 1.70.0.1100 "NapiProjekt_is1" = NapiProjekt 2.0.0 (build 2151) "NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver "Revo Uninstaller" = Revo Uninstaller 1.94 "SP_a8235b05" = Search Assistant SoftQuick 1.66 "SP_e14dcdfa" = "vShare plugin" = vShare plugin 1.3 "vShare.tv plugin" = vShare.tv plugin 1.3 "WinLiveSuite" = Podstawowe programy Windows Live "wxPython2.8-unicode-py25_is1" = wxPython 2.8.4.0 (unicode) for Python 2.5 "YDP Flash Speech Recognition Support" = YDP Flash Speech Recognition Support 1.0 [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Akamai" = Akamai NetSession Interface "Google Chrome" = Google Chrome [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 9/13/2012 6:15:30 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/14/2012 5:26:00 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/14/2012 5:50:58 AM | Computer Name = Adam-TOSHIBA | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: ISAdmin.exe, wersja: 14.0.0.162, sygnatura czasowa: 0x4626b2f4 Nazwa modułu powodującego błąd: unknown, wersja: 0.0.0.0, sygnatura czasowa: 0x00000000 Kod wyjątku: 0xc000041d Przesunięcie błędu: 0x74a44f0d Identyfikator procesu powodującego błąd: 0x1030 Godzina uruchomienia aplikacji powodującej błąd: 0x01cd925e574f0388 Ścieżka aplikacji powodującej błąd: C:\Users\Adam\AppData\Local\Temp\pftFD15.tmp\ISAdmin.exe Ścieżka modułu powodującego błąd: unknown Identyfikator raportu: aefa5b22-fe51-11e1-99e8-b870f45d63bf Error - 9/15/2012 4:39:11 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/15/2012 5:35:12 PM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/16/2012 4:57:07 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/16/2012 5:06:09 AM | Computer Name = Adam-TOSHIBA | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: setup.exe_Sony PC Companion, wersja: 17.0.0.717, sygnatura czasowa: 0x4cab8cfa Nazwa modułu powodującego błąd: wer.dll, wersja: 6.1.7601.17514, sygnatura czasowa: 0x4ce7ba29 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x00052140 Identyfikator procesu powodującego błąd: 0x5c4 Godzina uruchomienia aplikacji powodującej błąd: 0x01cd93e98fbd0fb3 Ścieżka aplikacji powodującej błąd: C:\Users\Adam\AppData\Local\Temp\{4FCEB9B4-7DBD-4616-85D3-474129838BA8}\setup.exe Ścieżka modułu powodującego błąd: C:\Windows\SysWOW64\wer.dll Identyfikator raportu: c0c7921c-ffdd-11e1-9afd-b870f45d63bf Error - 9/16/2012 12:22:31 PM | Computer Name = Adam-TOSHIBA | Source = Application Hang | ID = 1002 Description = Program ALLPlayer.exe w wersji 5.1.0.0 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: d60 Godzina rozpoczęcia: 01cd94276fc009d3 Godzina zakończenia: 89 Ścieżka aplikacji: D:\Programy\ALLPlayer\ALLPlayer.exe Identyfikator raportu: b51a3d35-001a-11e2-9afd-b870f45d63bf Error - 9/17/2012 9:26:47 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/18/2012 5:29:08 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/18/2012 1:55:17 PM | Computer Name = Adam-TOSHIBA | Source = Application Hang | ID = 1002 Description = Program ALLPlayer.exe w wersji 5.1.0.0 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: e48 Godzina rozpoczęcia: 01cd95c6b978bdcb Godzina zakończenia: 69 Ścieżka aplikacji: D:\Programy\ALLPlayer\ALLPlayer.exe Identyfikator raportu: fdf908bc-01b9-11e2-9e3c-b870f45d63bf Error - 9/19/2012 6:37:41 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/20/2012 6:54:32 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = [ OSession Events ] Error - 5/4/2012 6:44:51 PM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6612.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 28 seconds with 0 seconds of active time. This session ended with a crash. Error - 11/9/2012 6:05:13 AM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 1426 seconds with 1200 seconds of active time. This session ended with a crash. Error - 11/9/2012 6:06:04 AM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 22 seconds with 0 seconds of active time. This session ended with a crash. Error - 11/9/2012 6:10:35 AM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 226 seconds with 180 seconds of active time. This session ended with a crash. Error - 11/9/2012 6:11:39 AM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 34 seconds with 0 seconds of active time. This session ended with a crash. Error - 11/9/2012 6:13:37 AM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 69 seconds with 0 seconds of active time. This session ended with a crash. Error - 11/9/2012 6:16:33 AM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 130 seconds with 60 seconds of active time. This session ended with a crash. Error - 11/9/2012 2:37:33 PM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 27 seconds with 0 seconds of active time. This session ended with a crash. Error - 12/16/2012 6:40:06 PM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 5327 seconds with 2700 seconds of active time. This session ended with a crash. [ System Events ] Error - 1/2/2013 1:42:38 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7022 Description = Usługa Windows Update zawiesiła się podczas uruchamiania. Error - 1/2/2013 2:36:18 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi atksgt z powodu następującego błędu: %%577 Error - 1/2/2013 2:36:36 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Internet Manager. OUC z powodu następującego błędu: %%2 Error - 1/2/2013 2:39:21 PM | Computer Name = Adam-TOSHIBA | Source = DCOM | ID = 10010 Description = Error - 1/2/2013 2:42:42 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7022 Description = Usługa Windows Update zawiesiła się podczas uruchamiania. Error - 1/2/2013 2:44:55 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7043 Description = Usługa Windows Update nie została poprawnie zamknięta po odebraniu kodu sterującego przed zamknięciem. Error - 1/2/2013 2:46:47 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi atksgt z powodu następującego błędu: %%577 Error - 1/2/2013 2:46:59 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Internet Manager. OUC z powodu następującego błędu: %%2 Error - 1/2/2013 2:49:37 PM | Computer Name = Adam-TOSHIBA | Source = DCOM | ID = 10010 Description = Error - 1/2/2013 2:53:16 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7022 Description = Usługa Windows Update zawiesiła się podczas uruchamiania. < End of report > [/log] Raport z AdwCleaner'a: [log] # AdwCleaner v2.104 - Log utworzony 02/01/2013 o 19:43:24 # Aktualizacja 29/12/2012 przez Xplode # System operacyjny : Windows 7 Home Premium Service Pack 1 (64 bits) # Użytkownik : Adam - ADAM-TOSHIBA # Tryb uruchomienia : Normalny # Ścieżka : C:\Users\Adam\Desktop\AdwCleaner.exe # Opcja [Usuń] ***** [Usługi] ***** ***** [Pliki / Foldery] ***** Folder Usunięto : C:\Program Files (x86)\1ClickDownload Folder Usunięto : C:\Program Files (x86)\adawaretb Folder Usunięto : C:\Program Files (x86)\StartSearch plugin Folder Usunięto : C:\Program Files (x86)\vShare.tv plugin Folder Usunięto : C:\Program Files (x86)\VshareComplete Folder Usunięto : C:\Program Files\Babylon Folder Usunięto : C:\ProgramData\blekko toolbars Folder Usunięto : C:\ProgramData\InstallMate Folder Usunięto : C:\ProgramData\Premium Folder Usunięto : C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlfienamagdnkekbbbocojppncdambda Folder Usunięto : C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbiamblgmkgbcgbcgejjgebalncpmhnp Folder Usunięto : C:\Users\Adam\AppData\LocalLow\adawaretb Folder Usunięto : C:\Users\Adam\AppData\Roaming\Mozilla\Firefox\Profiles\oq3gcry8.default\extensions\OneClickDownload@OneClickDownload.com Folder Usunięto : C:\Users\Adam\AppData\Roaming\OpenCandy Folder Usunięto : C:\Users\Adam\AppData\Roaming\VshareComplete Plik Usunięto : C:\user.js Plik Usunięto : C:\Users\Adam\AppData\Roaming\Mozilla\Firefox\Profiles\oq3gcry8.default\searchplugins\WebSearch.xml ***** [Rejestr] ***** Dane Usunięto : HKLM\..\Windows [AppInit_DLLs] = c:\progra~2\contin~1\sprote~1.dll Dane Usunięto : HKLM\..\Windows [AppInit_DLLs] = c:\progra~2\softqu~1\sprote~1.dll Klucz Usunięto : HKCU\Software\1ClickDownload Klucz Usunięto : HKCU\Software\AppDataLow\SProtector Klucz Usunięto : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD} Klucz Usunięto : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} Klucz Usunięto : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183} Klucz Usunięto : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{222F31FB-A14E-4AF2-BB14-997F28294370} Klucz Usunięto : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{222F31FB-A14E-4AF2-BB14-997F28294370} Klucz Usunięto : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0} Klucz Usunięto : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1B48071-416D-474E-A13B-BE5456E7FC31} Klucz Usunięto : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113} Klucz Usunięto : HKCU\Software\Softonic Klucz Usunięto : HKCU\Software\StartSearch Klucz Usunięto : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Klucz Usunięto : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Klucz Usunięto : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Klucz Usunięto : HKLM\SOFTWARE\Classes\Prod.cap Klucz Usunięto : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO Klucz Usunięto : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO.1 Klucz Usunięto : HKLM\SOFTWARE\Classes\TypeLib\{79D60450-56C5-4A8C-9321-6D5BC2A81E5A} Klucz Usunięto : HKLM\SOFTWARE\Classes\TypeLib\{99C22A61-21BA-4F81-85FF-CDC9EB5DB10B} Klucz Usunięto : HKLM\Software\Iminent Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Tracing\Babylon_RASAPI32 Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Tracing\Babylon_RASMANCS Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183} Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1B48071-416D-474E-A13B-BE5456E7FC31} Klucz Usunięto : HKLM\Software\SP Global Klucz Usunięto : HKLM\Software\SProtector Klucz Usunięto : HKLM\Software\SweetIM Klucz Usunięto : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{222F31FB-A14E-4AF2-BB14-997F28294370} Klucz Usunięto : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{8F97BFF8-488B-4107-BCEE-B161AB4E4183} Klucz Usunięto : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A1B48071-416D-474E-A13B-BE5456E7FC31} Klucz Usunięto : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E} Klucz Usunięto : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb Klucz Usunięto : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dlfienamagdnkekbbbocojppncdambda Klucz Usunięto : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pbiamblgmkgbcgbcgejjgebalncpmhnp Klucz Usunięto : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco Klucz Usunięto : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{222F31FB-A14E-4AF2-BB14-997F28294370} Klucz Usunięto : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\LiveVDO plugin Klucz Usunięto : HKLM\SOFTWARE\Classes\CLSID\{222F31FB-A14E-4AF2-BB14-997F28294370} Klucz Usunięto : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E} Klucz Usunięto : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{222F31FB-A14E-4AF2-BB14-997F28294370} Klucz Usunięto : HKLM\SOFTWARE\Software ***** [Przeglądarki Internetowe] ***** -\\ Internet Explorer v8.0.7601.17514 [OK] Rejestr w porządku. -\\ Mozilla Firefox v [Nie udało się określić wersji] Plik : C:\Users\Adam\AppData\Roaming\Mozilla\Firefox\Profiles\oq3gcry8.default\prefs.js C:\Users\Adam\AppData\Roaming\Mozilla\Firefox\Profiles\oq3gcry8.default\user.js ... Usunięto ! [OK] Plik w porządku. -\\ Google Chrome v23.0.1271.97 Plik : C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Plik w porządku. ************************* AdwCleaner[S1].txt - [6124 octets] - [02/01/2013 19:43:24] ########## EOF - C:\AdwCleaner[S1].txt - [6184 octets] ########## [/log] Raport z OTL po wklejeniu Twoich komend: [log] All processes killed ========== OTL ========== HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}\ not found. HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar| /E : value set successfully! HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully! HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Search\\Default_Search_URL| /E : value set successfully! HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully! HKEY_USERS\S-1-5-21-319703930-2572490357-2975701463-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_USERS\S-1-5-21-319703930-2572490357-2975701463-1000\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5}\ not found. Registry key HKEY_USERS\S-1-5-21-319703930-2572490357-2975701463-1000\Software\Microsoft\Internet Explorer\SearchScopes\{711DE046-A996-446D-8872-2FA584763384}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{711DE046-A996-446D-8872-2FA584763384}\ not found. Registry key HKEY_USERS\S-1-5-21-319703930-2572490357-2975701463-1000\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}\ not found. Prefs.js: "http://websearch.soft-quick.info/" removed from browser.startup.homepage Prefs.js: "WebSearch" removed from browser.search.order.1 Prefs.js: "WebSearch" removed from browser.search.defaultenginename Prefs.js: "WebSearch" removed from browser.search.selectedEngine Prefs.js: "http://websearch.soft-quick.info/?l=1&q=" removed from browser.search.defaulturl Prefs.js: S", "WebSearch" removed from browser.search.order.1,S Prefs.js: S", "WebSearch" removed from browser.search.defaultenginename,S Prefs.js: S", "WebSearch" removed from browser.search.selectedEngine,S Prefs.js: "http://websearch.soft-quick.info/?l=1&q=" removed from keyword.URL Use Chrome's Settings page to change the HomePage. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}\ deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Adam ->Temp folder emptied: 1029124 bytes ->Temporary Internet Files folder emptied: 2195087 bytes ->Java cache emptied: 6652580 bytes ->FireFox cache emptied: 55293516 bytes ->Google Chrome cache emptied: 19444773 bytes ->Flash cache emptied: 545 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 56504 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 2335 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 68032 bytes RecycleBin emptied: 2150447736 bytes Total Files Cleaned = 2,132.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 01022013_193404 Files\Folders moved on Reboot... C:\Users\Adam\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot. PendingFileRenameOperations files... Registry entries deleted on Reboot... [/log]
Natsuki Kuga komentarz 2 stycznia 2013 komentarz 2 stycznia 2013 Jeszcze to do zrobienia: [quote name='Natsuki Kuga' timestamp='1357135385' post='1661804'] Zaktualizuj Avasta do wersji 7, odinstaluj Spybota. [/quote] Do OTL wklej: [code] :OTL CHR - homepage: http://websearch.soft-quick.info/ CHR - homepage: http://websearch.soft-quick.info/ [/code] [b]Wykonaj skrypt,[/b] pokaż raport. Po wykonaniu zrób nowy log z OTL.
adam205 komentarz 2 stycznia 2013 Autor komentarz 2 stycznia 2013 Spybot został odinstalowany a bieżąca wersja Avasta to 7.0.1474 - zrobiłem to już wcześniej ale możliwe że dopiero po LOGach Raport po wklejeniu: [log] ========== OTL ========== Use Chrome's Settings page to change the HomePage. Use Chrome's Settings page to change the HomePage. OTL by OldTimer - Version 3.2.69.0 log created on 01022013_225203 [/log] LOGi: [log] OTL logfile created on: 1/2/2013 10:53:35 PM - Run 4 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Adam\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000409 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3.98 Gb Total Physical Memory | 1.82 Gb Available Physical Memory | 45.79% Memory free 7.95 Gb Paging File | 5.45 Gb Available in Paging File | 68.54% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 298.09 Gb Total Space | 218.36 Gb Free Space | 73.25% Space Free | Partition Type: NTFS Drive D: | 297.69 Gb Total Space | 189.67 Gb Free Space | 63.71% Space Free | Partition Type: NTFS Computer Name: ADAM-TOSHIBA | User Name: Adam | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: Off | File Age = 60 Days [color=#E56717]========== Processes (All) ==========[/color] PRC - [2012/12/30 11:10:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Adam\Desktop\OTL.exe PRC - [2012/12/05 02:15:17 | 001,242,728 | ---- | M] (Google Inc.) -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe PRC - [2012/10/30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- D:\Programy\Avast\AvastUI.exe PRC - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- D:\Programy\Avast\AvastSvc.exe PRC - [2012/10/09 10:53:36 | 004,441,920 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Adam\AppData\Local\Akamai\netsession_win.exe PRC - [2012/08/11 15:43:06 | 000,055,184 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe PRC - [2012/07/27 12:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012/07/03 08:04:54 | 000,252,848 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe PRC - [2012/05/14 19:55:06 | 003,150,928 | ---- | M] (VS Revo Group) -- D:\Programy\Revo Uninstaller\Revouninstaller.exe PRC - [2012/04/26 13:33:16 | 002,743,104 | ---- | M] (DT Soft Ltd) -- D:\Programy\Daemon Tools Pro\DTShellHlp.exe PRC - [2011/06/01 17:42:28 | 000,071,432 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoDashboard.exe PRC - [2011/06/01 17:42:28 | 000,014,088 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe PRC - [2011/06/01 17:16:54 | 002,260,992 | ---- | M] (Axentra Corporation) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe PRC - [2011/05/04 22:10:28 | 000,325,344 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\InstantBackup.exe PRC - [2011/03/14 16:27:28 | 000,236,384 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe PRC - [2011/02/01 12:24:42 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe PRC - [2011/02/01 12:24:40 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe PRC - [2010/08/04 16:11:34 | 001,809,920 | ---- | M] (Realsil Microelectronics Inc.) -- C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\svchost.exe [comLaunch] PRC - [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\svchost.exe [comLaunch] [color=#E56717]========== Modules (All) ==========[/color] MOD - [2012/12/30 11:10:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Adam\Desktop\OTL.exe MOD - [2012/12/11 18:58:39 | 000,043,272 | ---- | M] (AVAST Software) -- D:\Programy\Avast\defs\13010200\uiext.dll MOD - [2012/12/05 02:15:17 | 001,242,728 | ---- | M] (Google Inc.) -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\chrome.exe MOD - [2012/12/05 02:15:15 | 012,456,040 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll MOD - [2012/12/05 02:15:15 | 000,460,904 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll MOD - [2012/12/05 02:15:14 | 004,008,040 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll MOD - [2012/12/05 02:14:29 | 000,587,880 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\libglesv2.dll MOD - [2012/12/05 02:14:28 | 000,124,520 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\libegl.dll MOD - [2012/12/05 02:14:27 | 009,963,112 | ---- | M] (The ICU Project) -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\icudt.dll MOD - [2012/12/05 02:14:23 | 041,743,976 | ---- | M] (Google Inc.) -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\chrome.dll MOD - [2012/12/05 02:14:21 | 000,157,304 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\avutil-51.dll MOD - [2012/12/05 02:14:20 | 000,275,576 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\avformat-54.dll MOD - [2012/12/05 02:14:19 | 002,168,952 | ---- | M] () -- C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\avcodec-54.dll MOD - [2012/11/15 19:49:39 | 001,670,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\4a29fb5e489e57ccc97b19ca70db94a8\Microsoft.VisualBasic.ni.dll MOD - [2012/11/15 19:12:47 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\17796f2951c17ebf92dd4b7c9b3ce556\System.ServiceProcess.ni.dll MOD - [2012/11/15 19:12:38 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\03cfab5534482e8fc313ead6edc19100\System.Web.ni.dll MOD - [2012/11/15 19:12:32 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\413288993ff690e8251d2dbe32bee01f\System.Runtime.Remoting.ni.dll MOD - [2012/11/15 19:12:31 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\3d4e9d4f6c945d6d3b7d423fdb6bd274\System.Data.ni.dll MOD - [2012/11/15 19:12:06 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d040079bc7148afeca03c5abb6fc3c61\System.Windows.Forms.ni.dll MOD - [2012/11/15 19:12:00 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\4e80768a2d88c7a333e43cbb7a6c0705\System.Drawing.ni.dll MOD - [2012/11/15 19:11:58 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\70705382a499703e7a595fada80b04e6\Accessibility.ni.dll MOD - [2012/11/15 19:11:45 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\25e672ea505e50ab058258ac72a54f02\System.Xml.ni.dll MOD - [2012/11/15 19:11:42 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c64ca3678261c8ffcd9e7efd1af6ed54\System.Configuration.ni.dll MOD - [2012/11/15 19:11:41 | 007,988,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9dd758ac0bf7358ac6e4720610fcc63c\System.ni.dll MOD - [2012/11/15 19:11:36 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\187d7c66735c533de851c76384f86912\mscorlib.ni.dll MOD - [2012/10/30 23:51:26 | 000,242,056 | ---- | M] (AVAST Software) -- D:\Programy\Avast\1045\uiLangRes.dll MOD - [2012/10/30 23:51:26 | 000,095,784 | ---- | M] (AVAST Software) -- D:\Programy\Avast\1045\Base.dll MOD - [2012/10/30 23:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- D:\Programy\Avast\AvastUI.exe MOD - [2012/10/30 23:50:53 | 000,236,888 | ---- | M] (AVAST Software) -- D:\Programy\Avast\snxhk.dll MOD - [2012/10/30 23:50:51 | 006,439,048 | ---- | M] (AVAST Software) -- D:\Programy\Avast\CommonRes.dll MOD - [2012/10/30 23:50:47 | 000,476,360 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswSqLt.dll MOD - [2012/10/30 23:50:47 | 000,027,296 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswUtil.dll MOD - [2012/10/30 23:50:44 | 000,220,944 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswLog.dll MOD - [2012/10/30 23:50:44 | 000,217,848 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswProperty.dll MOD - [2012/10/30 23:50:44 | 000,126,160 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswJsFlt.dll MOD - [2012/10/30 23:50:44 | 000,051,000 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswEngLdr.dll MOD - [2012/10/30 23:50:41 | 002,162,488 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswAra.dll MOD - [2012/10/30 23:50:41 | 000,682,384 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswAux.dll MOD - [2012/10/30 23:50:41 | 000,347,616 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswCmnBS.dll MOD - [2012/10/30 23:50:41 | 000,191,568 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswCmnIS.dll MOD - [2012/10/30 23:50:41 | 000,191,080 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswData.dll MOD - [2012/10/30 23:50:41 | 000,099,416 | ---- | M] (AVAST Software) -- D:\Programy\Avast\aswCmnOS.dll MOD - [2012/10/30 23:50:38 | 000,153,976 | ---- | M] (AVAST Software) -- D:\Programy\Avast\ashTask.dll MOD - [2012/10/30 23:50:38 | 000,061,800 | ---- | M] (AVAST Software) -- D:\Programy\Avast\ashTaskEx.dll MOD - [2012/10/30 23:50:36 | 000,441,352 | ---- | M] (AVAST Software) -- D:\Programy\Avast\ashBase.dll MOD - [2012/10/30 23:50:30 | 000,368,752 | ---- | M] (AVAST Software) -- D:\Programy\Avast\Aavm4h.dll MOD - [2012/10/30 23:50:30 | 000,120,504 | ---- | M] (AVAST Software) -- D:\Programy\Avast\AavmRpch.dll MOD - [2012/10/27 07:26:55 | 000,981,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wininet.dll MOD - [2012/10/27 07:26:43 | 001,231,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\urlmon.dll MOD - [2012/10/27 07:23:15 | 002,073,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\iertutil.dll MOD - [2012/10/27 07:23:14 | 011,020,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ieframe.dll MOD - [2012/10/16 08:39:52 | 000,561,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\AppPatch\AcLayers.dll MOD - [2012/10/09 18:40:31 | 000,044,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dhcpcsvc6.dll MOD - [2012/10/09 10:53:36 | 004,441,920 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Adam\AppData\Local\Akamai\netsession_win.exe MOD - [2012/10/04 17:47:41 | 000,274,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\KernelBase.dll MOD - [2012/10/04 17:47:40 | 001,114,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\kernel32.dll MOD - [2012/08/31 11:59:20 | 005,927,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll MOD - [2012/08/24 17:57:48 | 000,172,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wintrust.dll MOD - [2012/07/03 08:04:54 | 000,252,848 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe MOD - [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shell32.dll MOD - [2012/06/06 06:05:52 | 001,236,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msxml3.dll MOD - [2012/06/02 05:40:42 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\secur32.dll MOD - [2012/06/02 05:39:10 | 000,219,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ncrypt.dll MOD - [2012/06/02 05:36:29 | 001,159,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\crypt32.dll MOD - [2012/06/02 05:36:29 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptnet.dll MOD - [2012/06/02 05:34:09 | 000,096,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sspicli.dll MOD - [2012/05/14 19:55:06 | 003,150,928 | ---- | M] (VS Revo Group) -- D:\Programy\Revo Uninstaller\Revouninstaller.exe MOD - [2012/05/05 08:46:52 | 000,043,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\srclient.dll MOD - [2012/04/26 13:33:16 | 002,743,104 | ---- | M] (DT Soft Ltd) -- D:\Programy\Daemon Tools Pro\DTShellHlp.exe MOD - [2012/04/26 13:32:38 | 005,740,864 | ---- | M] (DT Soft Ltd) -- D:\Programy\Daemon Tools Pro\DTCommonRes.dll MOD - [2012/04/26 13:32:14 | 004,057,920 | ---- | M] (DT Soft Ltd) -- D:\Programy\Daemon Tools Pro\Engine.dll MOD - [2012/04/21 05:21:01 | 001,625,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\GdiPlus.dll MOD - [2012/04/12 07:30:52 | 000,382,784 | ---- | M] (DT Soft Ltd.) -- D:\Programy\Daemon Tools Pro\imgengine.dll MOD - [2012/04/07 12:26:29 | 002,342,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msi.dll MOD - [2012/03/01 06:33:23 | 000,159,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\imagehlp.dll MOD - [2012/01/13 08:12:03 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\nlaapi.dll MOD - [2012/01/04 09:58:41 | 000,442,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntshrui.dll MOD - [2012/01/04 03:50:59 | 000,364,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll MOD - [2011/12/16 08:52:58 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msvcrt.dll MOD - [2011/11/17 06:38:39 | 001,292,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntdll.dll MOD - [2011/11/17 06:35:02 | 000,314,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\webio.dll MOD - [2011/10/01 00:29:42 | 003,781,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_4bf7e3e2bf9ada4c\mfc90u.dll MOD - [2011/10/01 00:29:34 | 000,653,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll MOD - [2011/10/01 00:29:34 | 000,569,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll MOD - [2011/10/01 00:11:20 | 000,632,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcr80.dll MOD - [2011/10/01 00:11:20 | 000,554,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcp80.dll MOD - [2011/08/27 05:26:27 | 000,571,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\oleaut32.dll MOD - [2011/08/27 05:26:27 | 000,233,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\oleacc.dll MOD - [2011/06/01 17:46:02 | 000,030,984 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SeagateSharePlusPlugin.dll MOD - [2011/06/01 17:46:00 | 000,036,616 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SharePlugin.dll MOD - [2011/06/01 17:46:00 | 000,031,496 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SyncPlugin.dll MOD - [2011/06/01 17:46:00 | 000,029,960 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SeagateSharePlugin.dll MOD - [2011/06/01 17:46:00 | 000,026,376 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.RebitPlugin.dll MOD - [2011/06/01 17:45:58 | 000,028,936 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.BackupPremiumPlugin.dll MOD - [2011/06/01 17:45:58 | 000,028,424 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SendPlugin.dll MOD - [2011/06/01 17:45:56 | 000,029,448 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.BackupPlugin.dll MOD - [2011/06/01 17:45:52 | 000,011,016 | ---- | M] (Softvision) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.FolderViewPlugin.resources.dll MOD - [2011/06/01 17:45:40 | 000,011,016 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.SeagateSharePlusPlugin.resources.dll MOD - [2011/06/01 17:45:30 | 000,011,016 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.SeagateSharePlugin.resources.dll MOD - [2011/06/01 17:45:18 | 000,011,016 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.SeagatePreferencesPlugin.resources.dll MOD - [2011/06/01 17:45:06 | 000,011,528 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.LoadContentPlugin.resources.dll MOD - [2011/06/01 17:44:56 | 000,015,624 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.AddUserPlugin.resources.dll MOD - [2011/06/01 17:44:44 | 000,011,016 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.AddComputersPlugin.resources.dll MOD - [2011/06/01 17:44:12 | 000,009,992 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.RebitPlugin.resources.dll MOD - [2011/06/01 17:44:00 | 000,009,992 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.SyncPlugin.resources.dll MOD - [2011/06/01 17:43:50 | 000,009,992 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.SharePlugin.resources.dll MOD - [2011/06/01 17:43:38 | 000,009,992 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.SendPlugin.resources.dll MOD - [2011/06/01 17:43:12 | 000,010,504 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.BackupPremiumPlugin.resources.dll MOD - [2011/06/01 17:43:02 | 000,010,504 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\pl-PL\Memeo.Dashboard.BackupPlugin.resources.dll MOD - [2011/06/01 17:42:40 | 000,054,536 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\pl-PL\Memeo.Dashboard.UI.resources.dll MOD - [2011/06/01 17:42:32 | 000,013,576 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Dashboard.NasListener.dll MOD - [2011/06/01 17:42:30 | 000,031,496 | ---- | M] (Softvision) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Dashboard.HipServAdapter.dll MOD - [2011/06/01 17:42:30 | 000,021,768 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Dashboard.HelperAgentAdapter.dll MOD - [2011/06/01 17:42:28 | 000,071,432 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoDashboard.exe MOD - [2011/06/01 17:42:26 | 001,934,088 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Dashboard.UI.dll MOD - [2011/06/01 17:42:26 | 000,145,672 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Common.dll MOD - [2011/06/01 17:42:26 | 000,069,896 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Dashboard.Remote.dll MOD - [2011/06/01 17:42:26 | 000,037,128 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Dashboard.PluginCore.dll MOD - [2011/06/01 17:42:24 | 000,108,296 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Progress.dll MOD - [2011/06/01 17:42:16 | 000,023,040 | ---- | M] (Softvision) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.FolderViewPlugin.dll MOD - [2011/06/01 17:41:48 | 000,043,008 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.AddUserPlugin.dll MOD - [2011/06/01 17:41:44 | 000,032,768 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.LoadContentPlugin.dll MOD - [2011/06/01 17:41:38 | 000,019,968 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.AddComputersPlugin.dll MOD - [2011/06/01 17:41:32 | 000,023,040 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SeagatePreferencesPlugin.dll MOD - [2011/06/01 17:16:54 | 003,284,992 | ---- | M] (DevComponents.com) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\DevComponents.DotNetBar2.dll MOD - [2011/06/01 17:16:54 | 002,260,992 | ---- | M] (Axentra Corporation) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe MOD - [2011/06/01 17:16:54 | 001,028,096 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\LIBEAY32.dll MOD - [2011/06/01 17:16:54 | 000,978,432 | ---- | M] (GNU <www.gnu.org>) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\iconv.dll MOD - [2011/06/01 17:16:54 | 000,971,776 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\libxml2.dll MOD - [2011/06/01 17:16:54 | 000,241,664 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\libupnp.dll MOD - [2011/06/01 17:16:54 | 000,212,992 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\SSLEAY32.dll MOD - [2011/06/01 17:16:54 | 000,208,896 | ---- | M] (The cURL library, http://curl.haxx.se/) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\libcurl.dll MOD - [2011/06/01 17:16:54 | 000,086,070 | ---- | M] (Open Source Software community project) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\pthreadVC2.dll MOD - [2011/06/01 17:16:54 | 000,075,264 | ---- | M] (Zlib) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\zlib1.dll MOD - [2011/05/24 11:40:05 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\devobj.dll MOD - [2011/05/24 11:39:38 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cfgmgr32.dll MOD - [2011/05/17 08:27:52 | 000,413,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll MOD - [2011/05/04 22:15:12 | 000,032,768 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\pl-PL\Tanagra.Utility.resources.dll MOD - [2011/05/04 22:15:12 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\pl-PL\InstantBackup.resources.dll MOD - [2011/05/04 22:15:10 | 000,069,632 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\pl-PL\Memeo.Client.UI.resources.dll MOD - [2011/05/04 22:15:08 | 000,053,248 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\pl-PL\Tanagra.DataClad.resources.dll MOD - [2011/05/04 22:15:06 | 000,015,872 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\pl-PL\Memeo.Client.resources.dll MOD - [2011/05/04 22:15:02 | 000,069,632 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\pl-PL\Tanagra.BMU.resources.dll MOD - [2011/05/04 22:10:50 | 000,087,264 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\providers\Tanagra.BMU.Providers.FileCopyBackupProvider.dll MOD - [2011/05/04 22:10:50 | 000,079,072 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\providers\Tanagra.BMU.Providers.HardDiskBackupProvider.dll MOD - [2011/05/04 22:10:48 | 002,896,608 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\Memeo.Client.UI.dll MOD - [2011/05/04 22:10:46 | 000,230,624 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Memeo.Client.dll MOD - [2011/05/04 22:10:46 | 000,027,360 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\Memeo.Client.DriveDetection.dll MOD - [2011/05/04 22:10:44 | 000,020,704 | ---- | M] (Stan Schultes, VBNetExpert.com) -- C:\Program Files (x86)\Memeo\AutoBackup\XMLSettings.dll MOD - [2011/05/04 22:10:42 | 001,668,320 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Tanagra.Utility.dll MOD - [2011/05/04 22:10:42 | 000,025,824 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Tanagra.Third-party.Security.dll MOD - [2011/05/04 22:10:40 | 002,794,720 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Tanagra.BMU.dll MOD - [2011/05/04 22:10:40 | 001,561,824 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Tanagra.DataClad.dll MOD - [2011/05/04 22:10:40 | 000,296,160 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Tanagra.DataClad.DataAccess.dll MOD - [2011/05/04 22:10:40 | 000,054,496 | ---- | M] (Memeo Inc.) -- C:\Program Files (x86)\Memeo\AutoBackup\Tanagra.Interop.dll MOD - [2011/05/04 22:10:38 | 000,074,976 | ---- | M] (Finisar Corporation) -- C:\Program Files (x86)\Memeo\AutoBackup\SQLite.NET.dll MOD - [2011/05/04 22:10:38 | 000,067,808 | ---- | M] (Newtonsoft) -- C:\Program Files (x86)\Memeo\AutoBackup\Newtonsoft.Json.dll MOD - [2011/05/04 22:10:28 | 000,325,344 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\InstantBackup.exe MOD - [2011/03/14 16:27:28 | 000,236,384 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe MOD - [2011/03/03 06:38:01 | 000,270,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dnsapi.dll MOD - [2011/02/21 17:40:04 | 010,059,368 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWOW64\nvd3dum.dll MOD - [2010/11/21 04:25:15 | 000,172,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\spp.dll MOD - [2010/11/21 04:25:11 | 003,207,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mf.dll MOD - [2010/11/21 04:25:11 | 000,488,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\evr.dll MOD - [2010/11/21 04:24:51 | 000,080,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\davclnt.dll MOD - [2010/11/21 04:24:43 | 000,481,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mscms.dll MOD - [2010/11/21 04:24:33 | 001,010,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\WindowsCodecs.dll MOD - [2010/11/21 04:24:33 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\credssp.dll MOD - [2010/11/21 04:24:32 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\IPHLPAPI.DLL MOD - [2010/11/21 04:24:28 | 000,640,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\advapi32.dll MOD - [2010/11/21 04:24:26 | 001,128,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vssapi.dll MOD - [2010/11/21 04:24:26 | 000,572,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll MOD - [2010/11/21 04:24:25 | 000,119,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\imm32.dll MOD - [2010/11/21 04:24:23 | 001,828,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d9.dll MOD - [2010/11/21 04:24:23 | 001,493,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ExplorerFrame.dll MOD - [2010/11/21 04:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\user32.dll MOD - [2010/11/21 04:24:16 | 000,626,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\usp10.dll MOD - [2010/11/21 04:24:16 | 000,380,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sxs.dll MOD - [2010/11/21 04:24:16 | 000,269,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\Wldap32.dll MOD - [2010/11/21 04:24:16 | 000,257,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msv1_0.dll MOD - [2010/11/21 04:24:16 | 000,194,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winmm.dll MOD - [2010/11/21 04:24:16 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\srvcli.dll MOD - [2010/11/21 04:24:16 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\userenv.dll MOD - [2010/11/21 04:24:16 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\netutils.dll MOD - [2010/11/21 04:24:14 | 000,592,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msftedit.dll MOD - [2010/11/21 04:24:14 | 000,311,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\gdi32.dll MOD - [2010/11/21 04:24:14 | 000,295,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\apphelp.dll MOD - [2010/11/21 04:24:14 | 000,046,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\RpcRtRemote.dll MOD - [2010/11/21 04:24:11 | 000,663,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rpcrt4.dll MOD - [2010/11/21 04:24:09 | 000,854,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dbghelp.dll MOD - [2010/11/21 04:24:09 | 000,530,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll MOD - [2010/11/21 04:24:09 | 000,232,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mswsock.dll MOD - [2010/11/21 04:24:08 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll MOD - [2010/11/21 04:24:08 | 000,988,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\propsys.dll MOD - [2010/11/21 04:24:08 | 000,351,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winhttp.dll MOD - [2010/11/21 04:24:08 | 000,320,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winspool.drv MOD - [2010/11/21 04:24:08 | 000,236,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\pdh.dll MOD - [2010/11/21 04:24:08 | 000,216,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\FWPUCLNT.DLL MOD - [2010/11/21 04:24:07 | 000,179,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shdocvw.dll MOD - [2010/11/21 04:24:03 | 000,189,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sqmapi.dll MOD - [2010/11/21 04:24:03 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\olepro32.dll MOD - [2010/11/21 04:24:02 | 000,034,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cscapi.dll MOD - [2010/11/21 04:24:02 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msdmo.dll MOD - [2010/11/21 04:24:01 | 001,414,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ole32.dll MOD - [2010/11/21 04:24:01 | 000,297,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mscoree.dll MOD - [2010/11/21 04:24:01 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rtutils.dll MOD - [2010/11/21 04:24:00 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntlanman.dll MOD - [2010/11/21 04:23:55 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll MOD - [2010/11/21 04:23:55 | 000,206,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ws2_32.dll MOD - [2010/11/21 04:23:55 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\AudioSes.dll MOD - [2010/11/21 04:23:55 | 000,156,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winsta.dll MOD - [2010/11/21 04:23:54 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\samcli.dll MOD - [2010/11/21 04:23:54 | 000,040,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wtsapi32.dll MOD - [2010/11/21 04:23:51 | 001,667,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\setupapi.dll MOD - [2010/11/21 04:23:51 | 000,213,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\MMDevAPI.dll MOD - [2010/11/21 04:23:51 | 000,047,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wkscli.dll MOD - [2010/11/21 04:23:48 | 000,485,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\comdlg32.dll MOD - [2010/11/21 04:23:48 | 000,350,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shlwapi.dll MOD - [2010/11/21 04:23:48 | 000,034,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msasn1.dll MOD - [2010/11/13 03:03:49 | 000,311,296 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pl_b77a5c561934e089\mscorlib.resources.dll MOD - [2010/09/21 13:03:14 | 000,145,280 | ---- | M] (Microsoft Corp.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL MOD - [2010/05/26 11:41:02 | 002,106,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\D3DCompiler_43.dll MOD - [2010/05/26 11:41:02 | 001,998,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\D3DX9_43.dll MOD - [2010/03/22 23:59:46 | 000,504,293 | ---- | M] () -- C:\Program Files (x86)\Memeo\AutoBackup\sqlite3.DLL MOD - [2010/03/22 23:59:32 | 000,013,824 | ---- | M] ( ) -- C:\Program Files (x86)\Memeo\AutoBackup\Interop.eWebControl.dll MOD - [2010/03/22 23:58:22 | 000,143,360 | ---- | M] (Digital River, Inc.) -- C:\Program Files (x86)\Common Files\Memeo\eWebControl365.dll MOD - [2009/07/14 02:17:54 | 000,249,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\bcryptprimitives.dll MOD - [2009/07/14 02:17:54 | 000,242,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rsaenh.dll MOD - [2009/07/14 02:16:20 | 000,308,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\Wpc.dll MOD - [2009/07/14 02:16:20 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wsock32.dll MOD - [2009/07/14 02:16:20 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wship6.dll MOD - [2009/07/14 02:16:20 | 000,009,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\WSHTCPIP.DLL MOD - [2009/07/14 02:16:19 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winrnr.dll MOD - [2009/07/14 02:16:19 | 000,016,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winnsi.dll MOD - [2009/07/14 02:16:18 | 000,262,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wevtapi.dll MOD - [2009/07/14 02:16:17 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vsstrace.dll MOD - [2009/07/14 02:16:17 | 000,021,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\version.dll MOD - [2009/07/14 02:16:15 | 000,027,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\slc.dll MOD - [2009/07/14 02:16:14 | 000,007,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shfolder.dll MOD - [2009/07/14 02:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sechost.dll MOD - [2009/07/14 02:16:13 | 000,060,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\samlib.dll MOD - [2009/07/14 02:16:13 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\SensApi.dll MOD - [2009/07/14 02:16:12 | 000,325,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rasapi32.dll MOD - [2009/07/14 02:16:12 | 000,145,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\powrprof.dll MOD - [2009/07/14 02:16:12 | 000,103,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\oledlg.dll MOD - [2009/07/14 02:16:12 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rasman.dll MOD - [2009/07/14 02:16:12 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\pnrpnsp.dll MOD - [2009/07/14 02:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\profapi.dll MOD - [2009/07/14 02:16:12 | 000,028,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\perfos.dll MOD - [2009/07/14 02:16:12 | 000,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rasadhlp.dll MOD - [2009/07/14 02:16:12 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\psapi.dll MOD - [2009/07/14 02:16:11 | 000,121,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntmarta.dll MOD - [2009/07/14 02:16:11 | 000,008,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\nsi.dll MOD - [2009/07/14 02:16:02 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\NapiNSP.dll MOD - [2009/07/14 02:15:48 | 000,035,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mssprxy.dll MOD - [2009/07/14 02:15:46 | 002,134,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msmpeg2vdec.dll MOD - [2009/07/14 02:15:44 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msimg32.dll MOD - [2009/07/14 02:15:43 | 000,828,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msctf.dll MOD - [2009/07/14 02:15:41 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mpr.dll MOD - [2009/07/14 02:15:41 | 000,054,784 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Defender\MpOav.dll MOD - [2009/07/14 02:15:39 | 000,352,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mfplat.dll MOD - [2009/07/14 02:15:36 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\linkinfo.dll MOD - [2009/07/14 02:15:35 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ksuser.dll MOD - [2009/07/14 02:15:22 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\gpapi.dll MOD - [2009/07/14 02:15:21 | 000,462,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\FirewallAPI.dll MOD - [2009/07/14 02:15:14 | 000,189,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\EhStorShell.dll MOD - [2009/07/14 02:15:13 | 000,717,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dui70.dll MOD - [2009/07/14 02:15:13 | 000,453,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dsound.dll MOD - [2009/07/14 02:15:13 | 000,181,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\duser.dll MOD - [2009/07/14 02:15:13 | 000,088,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dxva2.dll MOD - [2009/07/14 02:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dwmapi.dll MOD - [2009/07/14 02:15:13 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\drprov.dll MOD - [2009/07/14 02:15:11 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dhcpcsvc.dll MOD - [2009/07/14 02:15:10 | 000,066,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\devenum.dll MOD - [2009/07/14 02:15:08 | 000,019,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\davhlpr.dll MOD - [2009/07/14 02:15:08 | 000,011,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d8thk.dll MOD - [2009/07/14 02:15:07 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptsp.dll MOD - [2009/07/14 02:15:07 | 000,058,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptdll.dll MOD - [2009/07/14 02:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptbase.dll MOD - [2009/07/14 02:15:03 | 000,522,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\clbcatq.dll MOD - [2009/07/14 02:14:58 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\avrt.dll MOD - [2009/07/14 02:14:57 | 000,070,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\atl.dll MOD - [2009/07/14 02:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx MOD - [2009/07/14 02:11:24 | 000,245,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\uxtheme.dll MOD - [2009/07/14 02:11:23 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\lpk.dll MOD - [2009/07/14 02:11:20 | 000,080,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\bcrypt.dll MOD - [2009/07/14 02:09:53 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\security.dll MOD - [2009/06/10 22:23:08 | 000,074,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - [2012/10/13 19:43:55 | 001,431,888 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64) SRV:[b]64bit:[/b] - [2010/10/20 13:41:00 | 000,138,656 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\SysNative\TODDSrv.exe -- (TODDSrv) SRV:[b]64bit:[/b] - [2010/09/22 17:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) SRV:[b]64bit:[/b] - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2012/12/11 22:28:13 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012/11/09 11:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate) SRV - [2012/10/30 23:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- D:\Programy\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2012/07/27 12:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011/12/09 14:39:52 | 000,135,584 | ---- | M] (Futuremark Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service) SRV - [2011/11/09 20:44:27 | 001,045,256 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2011/06/01 17:42:28 | 000,014,088 | ---- | M] (Memeo) [Auto | Running] -- C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe -- (SeagateDashboardService) SRV - [2011/05/04 22:10:32 | 000,025,824 | ---- | M] (Memeo) [Auto | Running] -- C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe -- (MemeoBackgroundService) SRV - [2011/03/14 16:27:34 | 000,346,976 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\HWDeviceService64.exe -- (HWDeviceService64.exe) SRV - [2011/02/01 12:24:42 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS) SRV - [2011/02/01 12:24:40 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS) SRV - [2010/08/04 16:11:34 | 001,809,920 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe -- (IconMan_R) SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2008/06/13 03:05:48 | 001,539,224 | ---- | M] (Autodesk, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskNetSrv.exe -- (Autodesk Network Licensing Service) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2012/12/31 00:01:23 | 000,014,456 | ---- | M] (GFI Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\gfibto.sys -- (gfibto) DRV:[b]64bit:[/b] - [2012/11/24 20:32:32 | 000,303,616 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt) DRV:[b]64bit:[/b] - [2012/10/30 23:51:56 | 000,059,728 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi) DRV:[b]64bit:[/b] - [2012/10/30 23:51:55 | 000,984,144 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx) DRV:[b]64bit:[/b] - [2012/10/30 23:51:55 | 000,370,288 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP) DRV:[b]64bit:[/b] - [2012/10/30 23:51:55 | 000,071,600 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt) DRV:[b]64bit:[/b] - [2012/10/30 23:51:53 | 000,025,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk) DRV:[b]64bit:[/b] - [2012/10/15 17:59:28 | 000,054,072 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr) DRV:[b]64bit:[/b] - [2012/08/21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV:[b]64bit:[/b] - [2012/07/12 18:46:00 | 000,560,184 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd) DRV:[b]64bit:[/b] - [2012/07/12 18:42:35 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01) DRV:[b]64bit:[/b] - [2012/07/07 13:40:50 | 000,039,552 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\tcpipBM.sys -- (tcpipBM) DRV:[b]64bit:[/b] - [2012/07/07 13:40:49 | 000,212,992 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_juwwanecm.sys -- (huawei_wwanecm) DRV:[b]64bit:[/b] - [2012/07/07 13:40:49 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys -- (ew_hwusbdev) DRV:[b]64bit:[/b] - [2012/07/07 13:40:49 | 000,098,816 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_jucdcacm.sys -- (huawei_cdcacm) DRV:[b]64bit:[/b] - [2012/07/07 13:40:49 | 000,086,016 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ew_jubusenum.sys -- (huawei_enumerator) DRV:[b]64bit:[/b] - [2012/07/07 13:40:49 | 000,028,672 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_juextctrl.sys -- (huawei_ext_ctrl) DRV:[b]64bit:[/b] - [2012/07/07 13:40:49 | 000,013,952 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_usbenumfilter.sys -- (ew_usbenumfilter) DRV:[b]64bit:[/b] - [2012/07/07 13:40:48 | 000,016,512 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\BMLoad.sys -- (BMLoad) DRV:[b]64bit:[/b] - [2012/06/30 15:35:48 | 000,043,168 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt) DRV:[b]64bit:[/b] - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2011/11/09 20:44:38 | 000,036,904 | ---- | M] (Feitian Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rockey4.sys -- (ROCKEYNT) DRV:[b]64bit:[/b] - [2011/05/13 02:21:04 | 000,177,640 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdm.sys -- (ssadmdm) DRV:[b]64bit:[/b] - [2011/05/13 02:21:04 | 000,146,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadserd.sys -- (ssadserd) DRV:[b]64bit:[/b] - [2011/05/13 02:21:02 | 000,157,672 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadbus.sys -- (ssadbus) DRV:[b]64bit:[/b] - [2011/05/13 02:21:02 | 000,036,328 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadadb.sys -- (androidusb) DRV:[b]64bit:[/b] - [2011/05/13 02:21:02 | 000,016,872 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdfl.sys -- (ssadmdfl) DRV:[b]64bit:[/b] - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2011/02/03 18:59:06 | 001,413,680 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP) DRV:[b]64bit:[/b] - [2011/01/13 19:58:30 | 000,413,800 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:[b]64bit:[/b] - [2011/01/12 16:51:44 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor) DRV:[b]64bit:[/b] - [2011/01/05 00:08:58 | 001,109,096 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtl8192ce.sys -- (RTL8192Ce) DRV:[b]64bit:[/b] - [2010/11/21 04:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2010/11/21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2010/11/21 04:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:[b]64bit:[/b] - [2010/11/11 14:10:50 | 000,155,752 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA) DRV:[b]64bit:[/b] - [2010/10/19 15:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) DRV:[b]64bit:[/b] - [2010/07/20 16:43:22 | 000,247,400 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR) DRV:[b]64bit:[/b] - [2010/03/22 09:55:20 | 000,046,192 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\LPCFilter.sys -- (LPCFilter) DRV:[b]64bit:[/b] - [2009/07/30 19:22:04 | 000,027,784 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tdcmdpst.sys -- (tdcmdpst) DRV:[b]64bit:[/b] - [2009/07/14 15:31:18 | 000,026,840 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TVALZ_O.SYS -- (TVALZ) DRV:[b]64bit:[/b] - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009/06/20 03:09:57 | 001,394,688 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr) DRV:[b]64bit:[/b] - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:[b]64bit:[/b] - [2008/05/16 11:33:06 | 000,158,760 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016mdm.sys -- (s0016mdm) DRV:[b]64bit:[/b] - [2008/05/16 11:33:06 | 000,151,592 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016unic.sys -- (s0016unic) DRV:[b]64bit:[/b] - [2008/05/16 11:33:06 | 000,137,256 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016mgmt.sys -- (s0016mgmt) DRV:[b]64bit:[/b] - [2008/05/16 11:33:06 | 000,136,744 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016obex.sys -- (s0016obex) DRV:[b]64bit:[/b] - [2008/05/16 11:33:06 | 000,034,344 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016nd5.sys -- (s0016nd5) DRV:[b]64bit:[/b] - [2008/05/16 11:33:04 | 000,019,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016mdfl.sys -- (s0016mdfl) DRV:[b]64bit:[/b] - [2008/05/16 11:32:56 | 000,115,240 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s0016bus.sys -- (s0016bus) DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{D526343C-369F-4282-8F7D-0AE1527D1FE5}: "URL" = http://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{7F58A7B2-6E52-456D-87F4-C77C7EBFA5A0}: "URL" = http://www.bing.com/search?q={searchTerms}&form=TSHMDF&pc=MATM&src=IE-SearchBox IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba.msn.com IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\..\SearchScopes,DefaultScope = IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.startup.homepage: "" FF - prefs.js..extensions.enabledAddons: wrc@avast.com:7.0.1426 FF - prefs.js..network.proxy.type: 0 FF - prefs.js..browser.search.order.1: "" FF - prefs.js..browser.search.defaultenginename: "" FF - prefs.js..browser.search.selectedEngine: "" FF - prefs.js..browser.search.defaulturl: "" FF - prefs.js..browser.search.order.1,: "" FF - prefs.js..browser.search.defaultenginename,: "" FF - prefs.js..browser.search.selectedEngine,: "" FF - user.js - File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Programy\iTunes\Mozilla Plugins\npitunes.dll File not found FF - HKLM\Software\MozillaPlugins\@ganymede/GanymedeNetPlugin,version=1.0: D:\Programy\Bilard z WP\Ganymede\Plugins\npganymedenet.dll ( ) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@playstation.com/PsndlCheck,version=1.00: File not found FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Adam\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Adam\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: D:\Programy\Avast\WebRep\FF [2012/11/03 16:20:34 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/05/29 10:35:30 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com: C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/05/29 10:35:30 | 000,000,000 | ---D | M] [2012/01/29 02:02:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Adam\AppData\Roaming\mozilla\Extensions [2013/01/02 19:43:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\oq3gcry8.default\extensions [2012/05/19 10:07:52 | 000,010,043 | ---- | M] () (No name found) -- C:\Users\Adam\AppData\Roaming\mozilla\firefox\profiles\oq3gcry8.default\extensions\IplextoALL@ALLPlayer.org.xpi [2012/10/04 16:57:36 | 000,214,514 | ---- | M] () (No name found) -- C:\Users\Adam\AppData\Roaming\mozilla\firefox\profiles\oq3gcry8.default\extensions\TorrentHandler@TorrentHandler.com.xpi [2012/03/15 22:47:45 | 000,634,964 | ---- | M] () (No name found) -- C:\Users\Adam\AppData\Roaming\mozilla\firefox\profiles\oq3gcry8.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012/11/03 16:20:34 | 000,000,000 | ---D | M] (avast! WebRep) -- D:\PROGRAMY\AVAST\WEBREP\FF [color=#E56717]========== Chrome ==========[/color] CHR - homepage: http://websearch.soft-quick.info/ CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter} CHR - homepage: http://websearch.soft-quick.info/ CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Adam\AppData\Local\Google\Chrome\Application\23.0.1271.97\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll CHR - plugin: LiveVDO plug-in (Enabled) = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbiamblgmkgbcgbcgejjgebalncpmhnp\1.3_0\chvsharetvplg.dll CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll CHR - plugin: Google Update (Enabled) = C:\Users\Adam\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll CHR - plugin: GanymedeNet.Detector (Enabled) = D:\Programy\Bilard z WP\Ganymede\Plugins\npganymedenet.dll CHR - Extension: YouTube = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\ CHR - Extension: Szukaj w Google = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\ CHR - Extension: Fast save = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\dealelfklnopdjdoiejlibpajkggonpn\1.1_0\ CHR - Extension: Torrent Handler = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\hphibigbodkkohoglgfkddblldpfohjl\1.2_0\ CHR - Extension: avast! WebRep = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1474_0\ CHR - Extension: Gmail = C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\ O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:[b]64bit:[/b] - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Programy\Avast\aswWebRepIE64.dll (AVAST Software) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Programy\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (IplexToALLPlayer) - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - D:\Programy\ALLPlayer\Iplex\IplexToALLPlayer.dll (ALLCinema Ltd.) O3:[b]64bit:[/b] - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Programy\Avast\aswWebRepIE64.dll (AVAST Software) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Programy\Avast\aswWebRepIE.dll (AVAST Software) O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [avast5] D:\Programy\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [Memeo AutoSync] C:\Program Files (x86)\Memeo\AutoSync\MemeoLauncher2.exe (Memeo Inc.) O4 - HKLM..\Run: [Memeo Instant Backup] C:\Program Files (x86)\Memeo\AutoBackup\MemeoLauncher2.exe (Memeo Inc.) O4 - HKLM..\Run: [Seagate Dashboard] C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoLauncher.exe () O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-319703930-2572490357-2975701463-1000..\Run: [Akamai NetSession Interface] C:\Users\Adam\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) O4 - HKU\S-1-5-21-319703930-2572490357-2975701463-1000..\Run: [ALLUpdate] D:\Programy\ALLPlayer\ALLUpdate.exe (ALLCinema) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0 O8:[b]64bit:[/b] - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found O8:[b]64bit:[/b] - Extra context menu item: Wyślij &do programu OneNote - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105 File not found O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Wyślij &do programu OneNote - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105 File not found O9 - Extra Button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL (Microsoft Corporation) O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.9.2) O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 10.9.2) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.21.99.95 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A9E0C5C0-9E6A-410A-8719-DD8EAFE4AB0C}: DhcpNameServer = 213.158.199.1 213.158.199.5 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A9E0C5C0-9E6A-410A-8719-DD8EAFE4AB0C}: NameServer = 213.158.199.1 213.158.199.5 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D2441D73-E10C-46A3-B0DC-2D2F5D69E4AC}: DhcpNameServer = 62.21.99.95 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F3591DBC-AF36-469B-87F5-DC25CE0EB967}: DhcpNameServer = 213.158.199.1 213.158.199.5 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F3591DBC-AF36-469B-87F5-DC25CE0EB967}: NameServer = 213.158.199.1 213.158.199.5 O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\skype4com - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2012/12/30 18:52:09 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ] O32 - AutoRun File - [2012/10/13 19:42:40 | 000,000,000 | ---D | M] - C:\AUTODESK_COM_FOLDER -- [ NTFS ] O33 - MountPoints2\{1842d44a-c82a-11e1-a13a-b870f45d63bf}\Shell - "" = AutoRun O33 - MountPoints2\{1842d44a-c82a-11e1-a13a-b870f45d63bf}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{1842d46a-c82a-11e1-a13a-b870f45d63bf}\Shell - "" = AutoRun O33 - MountPoints2\{1842d46a-c82a-11e1-a13a-b870f45d63bf}\Shell\AutoRun\command - "" = F:\AutoRun.exe O33 - MountPoints2\{2fceb299-266a-11e2-ae97-b870f45d63bf}\Shell - "" = AutoRun O33 - MountPoints2\{2fceb299-266a-11e2-ae97-b870f45d63bf}\Shell\AutoRun\command - "" = G:\AutoRun.exe O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) [color=#E56717]========== Files/Folders - Created Within 60 Days ==========[/color] [2013/01/02 19:34:04 | 000,000,000 | ---D | C] -- C:\_OTL [2013/01/02 00:20:19 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\e-academy Inc [2013/01/02 00:20:19 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Local\e-academy Inc [2013/01/01 15:51:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\trend micro [2013/01/01 15:51:57 | 000,000,000 | ---D | C] -- C:\rsit [2012/12/31 16:26:25 | 000,000,000 | ---D | C] -- C:\Users\Adam\Desktop\6fe84fe7ac7805a731ff8c0f08034a71 [2012/12/31 16:26:08 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR [2012/12/31 16:26:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR [2012/12/31 00:12:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Ad-Aware Antivirus [2012/12/31 00:12:23 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\LavasoftStatistics [2012/12/31 00:02:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft [2012/12/31 00:01:23 | 000,014,456 | ---- | C] (GFI Software) -- C:\Windows\SysNative\drivers\gfibto.sys [2012/12/30 23:59:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Toolbar Cleaner [2012/12/30 23:57:48 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\Ad-Aware Antivirus [2012/12/30 23:02:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy [2012/12/30 20:59:50 | 000,000,000 | ---D | C] -- C:\Users\Adam\Doctor Web [2012/12/30 11:10:17 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Adam\Desktop\OTL.exe [2012/12/29 17:11:42 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Local\Akamai [2012/12/29 17:11:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Applications [2012/12/29 15:59:10 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallJammer Registry [2012/12/29 15:59:06 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Soldis [2012/12/29 15:58:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Soldis PROJEKTANT [2012/12/29 15:41:09 | 000,000,000 | ---D | C] -- C:\ProgramData\WoW Worldwide Software LTD [2012/12/29 15:41:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SoftQuick [2012/12/29 15:40:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ContinueToSave [2012/12/29 15:39:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NapiProjekt [2012/12/29 15:39:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NapiProjekt [2012/12/29 12:52:01 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\Malwarebytes [2012/12/29 12:51:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012/12/29 12:51:47 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2012/12/15 16:23:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes [2012/12/15 16:22:56 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes [2012/12/15 16:22:56 | 000,000,000 | ---D | C] -- C:\Program Files\iPod [2012/12/15 16:22:56 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 [2012/12/14 19:00:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype [2012/12/14 19:00:41 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype [2012/12/14 19:00:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype [2012/11/27 17:33:47 | 000,000,000 | ---D | C] -- C:\Users\Adam\Documents\Autodesk [2012/11/24 16:28:34 | 000,000,000 | ---D | C] -- C:\Users\Adam\Desktop\Pobrane [2012/11/23 17:56:22 | 000,000,000 | ---D | C] -- C:\ProgramData\MemeoCommon [2012/11/23 17:50:44 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\Memeo [2012/11/23 17:50:27 | 000,000,000 | ---D | C] -- C:\Users\Adam\AppData\Roaming\Seagate [2012/11/23 17:50:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate Dashboard [2012/11/23 17:49:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Memeo [2012/11/23 17:49:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Memeo [2012/11/23 17:49:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Memeo [2012/11/23 17:49:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Seagate [2012/11/17 16:18:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime [color=#E56717]========== Files - Modified Within 60 Days ==========[/color] [2013/01/02 22:53:48 | 006,553,600 | -HS- | M] () -- C:\Users\Adam\ntuser.dat [2013/01/02 22:28:00 | 000,000,930 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013/01/02 22:15:00 | 000,001,054 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-319703930-2572490357-2975701463-1000UA.job [2013/01/02 20:02:26 | 000,025,120 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013/01/02 20:02:26 | 000,025,120 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013/01/02 19:46:46 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\ContinueToSaveUpdaterTask{EE3D1E2A-0D0C-4142-BEAC-D554184FF8B1}.job [2013/01/02 19:46:41 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2013/01/02 19:46:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013/01/02 19:46:30 | 3203,735,552 | -HS- | M] () -- C:\hiberfil.sys [2013/01/02 19:44:17 | 001,645,938 | -H-- | M] () -- C:\Users\Adam\AppData\Local\IconCache.db [2013/01/02 19:42:19 | 000,551,997 | ---- | M] () -- C:\Users\Adam\Desktop\AdwCleaner.exe [2013/01/02 19:27:56 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt [2013/01/02 19:15:03 | 000,001,002 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-319703930-2572490357-2975701463-1000Core.job [2013/01/02 12:27:51 | 000,121,928 | ---- | M] () -- C:\Users\Adam\Desktop\bookmarks_02.01.2013.html [2013/01/02 00:24:02 | 000,000,183 | ---- | M] () -- C:\Users\Adam\Desktop\100151449280.sdx [2013/01/02 00:23:35 | 000,003,109 | ---- | M] () -- C:\Users\Adam\Desktop\Shortcut to SecureDownloadManager.exe.lnk [2013/01/01 23:43:21 | 001,663,484 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013/01/01 23:43:21 | 000,738,208 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat [2013/01/01 23:43:21 | 000,652,376 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013/01/01 23:43:21 | 000,154,864 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat [2013/01/01 23:43:21 | 000,121,308 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013/01/01 15:51:15 | 000,781,383 | ---- | M] () -- C:\Users\Adam\Desktop\RSIT.exe [2012/12/31 00:01:23 | 000,014,456 | ---- | M] (GFI Software) -- C:\Windows\SysNative\drivers\gfibto.sys [2012/12/30 19:02:43 | 107,644,520 | ---- | M] () -- C:\Users\Adam\Desktop\launch.exe [2012/12/30 11:10:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Adam\Desktop\OTL.exe [2012/12/29 15:59:10 | 000,001,945 | ---- | M] () -- C:\Users\Public\Desktop\Soldis PROJEKTANT 7.0.lnk [2012/12/29 12:34:58 | 000,524,288 | -HS- | M] () -- C:\Users\Adam\ntuser.dat{d9cb46bd-51a4-11e2-9dff-b870f45d63bf}.TMContainer00000000000000000002.regtrans-ms [2012/12/29 12:34:58 | 000,524,288 | -HS- | M] () -- C:\Users\Adam\ntuser.dat{d9cb46bd-51a4-11e2-9dff-b870f45d63bf}.TMContainer00000000000000000001.regtrans-ms [2012/12/29 12:34:58 | 000,065,536 | -HS- | M] () -- C:\Users\Adam\ntuser.dat{d9cb46bd-51a4-11e2-9dff-b870f45d63bf}.TM.blf [2012/12/22 11:40:23 | 000,519,784 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2012/12/15 16:23:54 | 000,001,539 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk [2012/12/14 16:49:28 | 000,024,176 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2012/11/24 20:32:32 | 000,303,616 | ---- | M] () -- C:\Windows\SysNative\drivers\atksgt.sys [2012/11/23 17:50:22 | 000,001,224 | ---- | M] () -- C:\Users\Public\Desktop\Seagate Dashboard.lnk [2012/11/15 20:15:27 | 000,147,832 | ---- | M] () -- C:\Users\Adam\AppData\Local\GDIPFONTCACHEV1.DAT [color=#E56717]========== Files Created - No Company Name ==========[/color] [2013/01/02 19:42:13 | 000,551,997 | ---- | C] () -- C:\Users\Adam\Desktop\AdwCleaner.exe [2013/01/02 12:27:51 | 000,121,928 | ---- | C] () -- C:\Users\Adam\Desktop\bookmarks_02.01.2013.html [2013/01/02 00:24:02 | 000,000,183 | ---- | C] () -- C:\Users\Adam\Desktop\100151449280.sdx [2013/01/02 00:23:35 | 000,003,109 | ---- | C] () -- C:\Users\Adam\Desktop\Shortcut to SecureDownloadManager.exe.lnk [2013/01/01 15:51:10 | 000,781,383 | ---- | C] () -- C:\Users\Adam\Desktop\RSIT.exe [2012/12/30 18:54:53 | 107,644,520 | ---- | C] () -- C:\Users\Adam\Desktop\launch.exe [2012/12/29 15:59:10 | 000,001,945 | ---- | C] () -- C:\Users\Public\Desktop\Soldis PROJEKTANT 7.0.lnk [2012/12/29 15:40:59 | 000,000,416 | -H-- | C] () -- C:\Windows\tasks\ContinueToSaveUpdaterTask{EE3D1E2A-0D0C-4142-BEAC-D554184FF8B1}.job [2012/12/29 14:47:22 | 001,645,938 | -H-- | C] () -- C:\Users\Adam\AppData\Local\IconCache.db [2012/12/29 12:31:41 | 000,524,288 | -HS- | C] () -- C:\Users\Adam\ntuser.dat{d9cb46bd-51a4-11e2-9dff-b870f45d63bf}.TMContainer00000000000000000002.regtrans-ms [2012/12/29 12:31:41 | 000,524,288 | -HS- | C] () -- C:\Users\Adam\ntuser.dat{d9cb46bd-51a4-11e2-9dff-b870f45d63bf}.TMContainer00000000000000000001.regtrans-ms [2012/12/29 12:31:41 | 000,065,536 | -HS- | C] () -- C:\Users\Adam\ntuser.dat{d9cb46bd-51a4-11e2-9dff-b870f45d63bf}.TM.blf [2012/12/15 16:23:54 | 000,001,539 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk [2012/11/23 17:50:22 | 000,001,224 | ---- | C] () -- C:\Users\Public\Desktop\Seagate Dashboard.lnk [2012/11/14 22:28:49 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf [2012/11/14 22:21:32 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf [2012/05/29 10:30:53 | 000,174,742 | ---- | C] () -- C:\Windows\hpoins45.dat [2012/05/18 13:34:13 | 000,644,608 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll [2012/05/18 13:34:13 | 000,258,048 | ---- | C] () -- C:\Windows\SysWow64\libFLAC.dll [2012/04/01 16:02:50 | 000,000,287 | ---- | C] () -- C:\Windows\game.ini [2012/02/25 22:21:02 | 000,007,599 | ---- | C] () -- C:\Users\Adam\AppData\Local\Resmon.ResmonCfg [2012/01/09 19:33:48 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll [2012/01/09 19:33:48 | 000,079,360 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll [2012/01/08 11:20:00 | 000,339,968 | ---- | C] () -- C:\Windows\SysWow64\pythoncom25.dll [2012/01/08 11:20:00 | 000,114,688 | ---- | C] () -- C:\Windows\SysWow64\pywintypes25.dll [2012/01/07 21:16:00 | 000,354,304 | ---- | C] () -- C:\Windows\SysWow64\pythoncom27.dll [2012/01/07 21:16:00 | 000,110,080 | ---- | C] () -- C:\Windows\SysWow64\pywintypes27.dll [2012/01/07 21:16:00 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\pythoncomloader27.dll [2011/12/15 19:17:34 | 000,003,584 | ---- | C] () -- C:\Users\Adam\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011/10/22 20:01:23 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll [2011/10/03 22:23:24 | 001,639,622 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2011/09/30 21:40:54 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2011/09/26 20:56:04 | 000,147,832 | ---- | C] () -- C:\Users\Adam\AppData\Local\GDIPFONTCACHEV1.DAT [2011/09/26 20:54:04 | 000,524,288 | -HS- | C] () -- C:\Users\Adam\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms [2011/09/26 20:54:04 | 000,524,288 | -HS- | C] () -- C:\Users\Adam\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms [2011/09/26 20:54:04 | 000,065,536 | -HS- | C] () -- C:\Users\Adam\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf [2011/09/26 20:54:04 | 000,000,020 | -HS- | C] () -- C:\Users\Adam\ntuser.ini [2011/09/26 20:54:03 | 006,553,600 | -HS- | C] () -- C:\Users\Adam\ntuser.dat [2011/04/23 13:55:12 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI [2011/04/23 13:43:55 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe [2011/02/03 18:56:58 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll [color=#E56717]========== ZeroAccess Check ==========[/color] [2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== LOP Check ==========[/color] [2012/12/31 00:31:14 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Ad-Aware Antivirus [2012/03/17 13:05:01 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Atari [2012/12/05 06:52:18 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Autodesk [2012/08/04 10:35:00 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\DAEMON Tools Lite [2012/11/24 00:54:07 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\DAEMON Tools Pro [2013/01/02 00:20:19 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\e-academy Inc [2012/01/06 11:25:21 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\eu.myphotobook.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1 [2012/07/03 19:50:20 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Gadu-Gadu 10 [2012/12/29 19:11:22 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\GanymedeNet [2012/03/17 11:17:25 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Kalypso Media [2012/03/17 10:59:24 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Leadertech [2012/11/24 00:38:25 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Memeo [2012/05/30 17:49:47 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\NapiProjekt [2012/07/18 13:29:59 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\ObviousIdea [2011/11/15 12:03:00 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\OpenOffice.org [2012/10/22 19:30:18 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\PROCAD [2012/07/07 13:41:45 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Programy [2011/10/30 20:56:01 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Scilab [2012/11/23 17:50:27 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Seagate [2012/03/29 19:06:37 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\SoftGrid Client [2012/09/14 11:06:09 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Sony [2011/09/26 23:25:59 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\Toshiba [2011/10/04 09:57:56 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\TOSHIBA Online Product Information [2011/10/03 22:23:55 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\TP [2012/12/29 12:30:37 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\uTorrent [2012/08/15 18:59:37 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\wargaming.net [2011/12/02 08:07:12 | 000,000,000 | ---D | M] -- C:\Users\Adam\AppData\Roaming\ZWSoft [color=#E56717]========== Purity Check ==========[/color] < End of report > [/log] [log] OTL Extras logfile created on: 1/2/2013 10:53:35 PM - Run 4 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Adam\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000409 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd 3.98 Gb Total Physical Memory | 1.82 Gb Available Physical Memory | 45.79% Memory free 7.95 Gb Paging File | 5.45 Gb Available in Paging File | 68.54% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 298.09 Gb Total Space | 218.36 Gb Free Space | 73.25% Space Free | Partition Type: NTFS Drive D: | 297.69 Gb Total Space | 189.67 Gb Free Space | 63.71% Space Free | Partition Type: NTFS Computer Name: ADAM-TOSHIBA | User Name: Adam | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: Off | File Age = 60 Days [color=#E56717]========== Extra Registry (SafeList) ==========[/color] [color=#E56717]========== File Associations ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) [color=#E56717]========== Shell Spawning ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~4\Office12\ONENOTE.EXE "%L" Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [napiprojekt] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" () Directory [napiprojekt0] -- "C:\Program Files (x86)\NapiProjekt\napisy.exe" "%1" -pobierz_ang () Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~4\Office12\ONENOTE.EXE "%L" Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [color=#E56717]========== Security Center Settings ==========[/color] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 [b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] [color=#E56717]========== Firewall Settings ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [color=#E56717]========== Authorized Applications List ==========[/color] [color=#E56717]========== Vista Active Open Ports Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{094CFB76-5066-4C4B-AA60-DACF135B28C3}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{12CA7623-3E3F-4163-AF39-7FF34AA30D2C}" = rport=10243 | protocol=6 | dir=out | app=system | "{212D3D2F-E8A7-4CBA-ADB8-70317C3F7CE5}" = lport=445 | protocol=6 | dir=in | app=system | "{21F7CEBE-0D9C-495D-90B6-4C2B01D45184}" = lport=138 | protocol=17 | dir=in | app=system | "{519160B0-69B7-4B5E-BDD0-FEA142035D25}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{55D9B36A-4B99-4D0A-AA72-2C78DE7BEA95}" = lport=137 | protocol=17 | dir=in | app=system | "{5F2BD67A-751C-4BEB-9C1B-546AFDAF3566}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{65CD3B7A-03ED-4257-92EA-D8366B085935}" = lport=2869 | protocol=6 | dir=in | app=system | "{74FBE3B2-8C8D-416A-B4C1-F95FF2E8C4AB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{818D6C54-2918-470F-8D60-E3201A6C2D79}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{907EE603-9C1A-4044-B82D-46A475A62D06}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{918146C0-E442-4457-A33D-ABBA0784845F}" = lport=10243 | protocol=6 | dir=in | app=system | "{9B04C10D-B0DC-40B0-BAC8-DD40A5EDF009}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{A6B3F750-DD94-430A-B8C2-DBA86B7881C1}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{AC07E7FF-1906-4277-85C8-3A42542FB12B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{BFEAFAD9-79F1-4401-9CAD-72AFEF4276A5}" = rport=139 | protocol=6 | dir=out | app=system | "{CAE9E3EC-A56E-4D64-913C-BBEFFF030FBF}" = rport=137 | protocol=17 | dir=out | app=system | "{D44B3782-F6E3-4F07-BEC1-CA6FCAA8EF38}" = rport=138 | protocol=17 | dir=out | app=system | "{DB4165A7-AA3E-4C26-8D3F-F12F484D770C}" = rport=445 | protocol=6 | dir=out | app=system | "{E19A50B5-0464-4A6D-86A9-BAC3C4318305}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{E4D18DB3-A97F-4787-9E84-4B25BE40E4A5}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{F0E68969-A195-419C-A2FE-2E3B7726E061}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{F988C693-8A5D-467B-8C7F-520547BAF434}" = lport=139 | protocol=6 | dir=in | app=system | [color=#E56717]========== Vista Active Application Exception List ==========[/color] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{0720C203-F64C-4138-832C-C316F4477579}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqcopy2.exe | "{128E6BBC-98B8-4F3C-B2EE-D2EB7EEA5CA3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{18F6CD47-17CC-40DA-BA09-4AC68BE0A9CE}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{19D486B0-1410-4E3B-995A-A44F10DC7371}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{2238DCA3-ACB6-42BF-9139-A8C670F1003B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe | "{25E1E729-0B50-4DAF-98AF-B0B6ACA969B1}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{261838AB-481A-44AE-B692-C756715AD704}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe | "{28F6A0DA-5523-4888-AB08-5F114F842AC9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{2A89A8EF-1F5F-4C05-BC9F-231FF0B8F1D1}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe | "{2EE8C41B-7930-47D6-8780-951B5C7D9994}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe | "{3059DE52-517B-476A-97A7-02642B4445C8}" = protocol=6 | dir=out | app=system | "{36D2E2F9-72DD-4B7B-8708-290D1BD0FAA4}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe | "{3D04F373-162D-4CE8-AFD5-A290F1746FFD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{3D8FB1DF-CB9E-4A21-BB81-814867C8D92B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{4813F9E4-9E56-487A-9E6F-DEABF6716244}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{5D621279-2987-4DEB-932C-3A81D455BF4B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe | "{60BA7020-5735-4274-AA33-CE12ABCF6B5F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{706DE1A9-29BA-4259-A346-2C2C1D692757}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{76D41A3F-FAE2-4E77-8B57-5983731999ED}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{7E018989-3D49-4769-9E5A-956B3804C83D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{825B0FC9-C8B4-4595-8D77-70667B9130C1}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{84E2008C-92AF-4D56-89BF-5653C5FA68E9}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe | "{89FBDF2A-4024-4409-9BC7-2164275BA25B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe | "{93FD57D8-A1DD-44C1-A863-210E30978CCC}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{968B58F1-6C47-4789-848A-80C57F20FB23}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe | "{9828B130-E990-4C39-83EE-508576F8318B}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{9D138229-E2FF-42AB-926A-EE0044C7E6CB}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe | "{A292D33C-D73C-4087-A004-86C92D99920A}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{BEAF98C9-2C09-443E-BFEF-14183E486DF8}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe | "{CA77A647-C547-47FB-B290-20252985D5B8}" = dir=in | app=c:\program files (x86)\seagate\seagate dashboard\hipservagent\hipservagent.exe | "{D0C10F8E-B6F4-4EB0-B688-2F77D6F1B19F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{D2F899D7-CA22-4C64-A3A3-6DA14C44EF9A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{D71F5A0C-592C-4480-96E3-0C86ABEF5F1E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{D8A7E1A4-99EC-433B-944C-F581533131A5}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe | "{E4AEEE9C-9B17-4ED2-AD55-03425AF64318}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{E673AC68-B661-48EE-83CD-B492DE4BA6CB}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe | "{E9D24D47-6A57-40A4-939E-AC1E085FA583}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{EDF670B0-21C2-4FCF-9240-65683366954E}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{F74124FD-E31A-4739-8142-766695981DC9}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{FA53E896-DBDD-4A1A-AD63-336638E55015}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{FCC9F8E6-D5B3-45C8-BEFD-E36FA961A218}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "TCP Query User{31081F40-F8E9-454B-BD21-567123C26069}C:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe" = protocol=6 | dir=in | app=c:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe | "TCP Query User{65C7CB83-2B07-478E-850D-BB7A96F92436}C:\users\adam\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\adam\appdata\local\akamai\netsession_win.exe | "TCP Query User{7D63A7DA-4A0D-40DD-AF06-627327FEFC6A}C:\program files (x86)\allmediaserver\mediaserver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\allmediaserver\mediaserver.exe | "TCP Query User{C671ACF3-C9D0-4E8D-A592-462BBABD87BC}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe | "TCP Query User{D0CCD619-292C-47EA-B6A5-3A9EF45A2C50}C:\program files (x86)\1clickdownload\1clickdownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\1clickdownload\1clickdownloader.exe | "TCP Query User{D40871D4-8EA3-4419-B9EF-DD32A6B409E8}C:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe" = protocol=6 | dir=in | app=c:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe | "TCP Query User{E60E4261-01E5-4B3B-9D06-555F0CDFC4D0}C:\users\adam\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\adam\appdata\local\akamai\netsession_win.exe | "UDP Query User{12527538-DE98-49AC-AE11-3DCA33E53A3D}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe | "UDP Query User{2613D914-28CB-4089-A263-EE761064D391}C:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe" = protocol=17 | dir=in | app=c:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe | "UDP Query User{2D23835C-E028-4E5E-BDD0-B69673F6A8E7}C:\users\adam\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\adam\appdata\local\akamai\netsession_win.exe | "UDP Query User{528FDE88-C913-4254-920E-A0AA1F7A44E9}C:\program files (x86)\allmediaserver\mediaserver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\allmediaserver\mediaserver.exe | "UDP Query User{985B1D64-5C17-4C83-B09F-FADFBA7C062B}C:\program files (x86)\1clickdownload\1clickdownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\1clickdownload\1clickdownloader.exe | "UDP Query User{9CA09DDF-2238-4B9F-B07E-B1D017A943CC}C:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe" = protocol=17 | dir=in | app=c:\users\adam\desktop\pobrane\left 4 dead 2 v2.0.2.7 full-rip {blaze69}\left 4 dead 2\left4dead2.exe | "UDP Query User{E4EFA3CA-6B1F-4B7E-A729-A57DB6C10996}C:\users\adam\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\adam\appdata\local\akamai\netsession_win.exe | [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{0E5D76AD-A3FB-48D5-8400-8903B10317D3}" = iTunes "{19F09425-3C20-4730-9E2A-FC2E17C9F362}" = Windows Live Remote Service Resources "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant "{230C483A-BCB8-4AA1-AC28-6CDAED005E71}" = Autodesk Robot Structural Analysis Professional 2012 - Polish regional settings "{2426E29F-9E8C-4C0B-97FC-0DB690C1ED98}" = Windows Live Remote Client Resources "{2A8EEE2F-4A9E-43D8-AA07-EC8A316B2DEB}" = Autodesk Revit Architecture 2010 x64 "{2F304EF4-0C31-47F4-8557-0641AAE4197C}" = Windows Live Remote Client Resources "{34384A2A-2CA2-4446-AB0E-1F360BA2AAC5}" = Windows Live Remote Service Resources "{3921492E-82D2-4180-8124-E347AD2F2DB4}" = Windows Live Remote Client Resources "{4200F74C-623C-7FFF-9D14-2A1E99E3D5BA}" = ContinueToSave "{480F28F0-8BCE-404A-A52E-0DBB7D1CE2EF}" = Windows Live Remote Service Resources "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5141AA6E-5FAC-4473-BFFB-BEE69DDC7F2B}" = Windows Live Remote Service Resources "{5151E2DB-0748-4FD1-86A2-72E2F94F8BE7}" = Windows Live Remote Service Resources "{5783F2D7-9001-0415-0102-0060B0CE6BBA}" = AutoCAD 2011 - Polski "{5783F2D7-9001-0415-1102-0060B0CE6BBA}" = AutoCAD 2011 Language Pack - Polski "{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator "{5F44A3A1-5D24-4708-8776-66B42B174C64}" = Windows Live Remote Client Resources "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{6051912A-F7B8-445C-A99D-81AA4C118836}" = HP Deskjet Ink Advant K209a-z All-in-One Driver Software 14.0 Rel. 6 "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{8E5DA9A6-7A9F-3A6F-BC5C-D6CBCA6A29C7}" = Microsoft .NET Framework 4 Extended PLK Language Pack "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0415-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Polish) 2007 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{A49402DD-2781-3782-B0CF-52BDA349E3F3}" = Microsoft .NET Framework 4 Client Profile PLK Language Pack "{AC0A533B-5E29-4081-8D1E-31BE65320527}" = Autodesk Robot Structural Analysis Professional 2012 "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 267.21 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 267.21 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 267.21 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.1.13.1 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64 "{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector "{D0CB24F4-084F-40DE-B6B9-A03626E682F0}" = iCloud "{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{DBEDAF67-C5A3-4C91-951D-31F3FE63AF3F}" = Windows Live Remote Client Resources "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORMCLauncher "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer "AutoCAD 2011 - Polski" = AutoCAD 2011 - Polski "Autodesk Revit Architecture 2010 x64" = Autodesk Revit Architecture 2010 x64 "Autodesk Robot Structural Analysis Professional 2012" = Autodesk Robot Structural Analysis Professional 2012 "CCleaner" = CCleaner "ContinueToSave" = "HP Imaging Device Functions" = HP Imaging Device Functions 14.0 "HP Smart Web Printing" = HP Smart Web Printing 4.60 "HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0 "HPExtendedCapabilities" = HP Customer Participation Program 14.0 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Client Profile PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Microsoft .NET Framework 4 Extended PLK Language Pack" = Polski pakiet językowy dla programu Microsoft .NET Framework 4 Extended "Shop for HP Supplies" = Shop for HP Supplies "SynTPDeinstKey" = Synaptics Pointing Device Driver "WinRAR archiver" = WinRAR 4.20 (64-bitowy) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0654EA5D-308A-4196-882B-5C09744A5D81}" = Windows Live Photo Common "{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan "{09922FFE-D153-44AE-8B60-EA3CB8088F93}" = Windows Live UX Platform Language Pack "{0A50CB27-D2D5-4B7D-A001-30B1782A450B}" = DJ_AIO_06_K209a-z_SW_Min "{0A9256E0-C924-46DE-921B-F6C4548A1C64}" = Windows Live Messenger "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0C1931EB-8339-4837-8BEC-75029BF42734}" = Windows Live UX Platform Language Pack "{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1 "{11778DA1-0495-4ED9-972F-F9E0B0367CD5}" = Windows Live Writer "{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver "{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery "{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant "{1727CD47-A408-11d2-AFAD-00C04F72FB3E}" = VBA (2720) "{17F99FCE-8F03-4439-860A-25C5A5434E18}" = Windows Live Essentials "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{1DA6D447-C54D-4833-84D4-3EA31CAECE9B}" = Windows Live UX Platform Language Pack "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{1FC83EAE-74C8-4C72-8400-2D8E40A017DE}" = Windows Live Writer "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 29 "{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 9 "{26E3C07C-7FF7-4362-9E99-9E49E383CF16}" = Windows Live Writer Resources "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections "{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox "{299C0434-4F4E-341F-A916-4E07AEB35E79}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime "{2C303EE0-A595-3543-A71A-931C7AC40EDE}" = Microsoft Primary Interoperability Assemblies 2005 "{2C7E8AA1-9C03-4606-BF34-5D99D07964DA}" = Windows Live Messenger "{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update "{2FB9EA69-51D4-4913-9AD5-762C034DE811}" = Status "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{34C4F5AF-D757-4E6A-ABCA-65AB5A50A1A8}" = Windows Live Messenger "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology "{4264C020-850B-4F08-ACBE-98205D9C336C}" = Windows Live Writer "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4A5667B2-5D13-46C2-85B5-9D46A6096F61}" = Secure Download Manager "{4B28D47A-5FF0-45F8-8745-11DC2A1C9D0F}" = Windows Live Writer "{50300123-F8FC-4B50-B449-E847D04F1BA2}" = Windows Live Messenger "{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion "{5275D81E-83AD-4DE4-BC2B-6E6BA3A33244}" = Windows Live Writer Resources "{55D9E026-DCB0-46FF-B60A-68B972228CF6}" = Autodesk Design Review 2010 "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack "{5A3ECDDA-562C-4281-BFE5-A4C8F32EACA3}" = K209a-z "{5DCF0E4B-F8EA-4229-A0BD-5CA6D4AFB749}" = SolutionCenter "{5E627606-53B9-42D1-97E1-D03F6229E248}" = Windows Live UX Platform Language Pack "{5f6460bd-391e-43ce-bcf3-130ef02f8cb2}_is1" = VshareComplete "{60C3C026-DB53-4DAB-8B97-7C1241F9A847}" = Windows Live Movie Maker "{64376910-1860-4CEF-8B34-AA5D205FC5F1}" = Poczta usługi Windows Live "{6491AB99-A11E-41FD-A5E7-32DE8A097B8E}" = Windows Live Essentials "{64B2D6B3-71AC-45A7-A6A1-2E07ABF58341}" = Windows Live Movie Maker "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6ABE832B-A5C7-44C1-B697-3E123B7B4D5B}" = Windows Live Mesh "{6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94}" = TOSHIBA Resolution+ Plug-in for Windows Media Player "{6D2F0A26-ECEA-49CE-833C-9A6125F3D5E8}" = Doplnok programu Messenger "{6E29C4F7-C2C2-4B18-A15C-E09B92065F15}" = Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz "{6EE9F44A-B8C7-4CDB-B2A9-441AF2AE315A}" = Windows Live Messenger "{6F37D92B-41AA-44B7-80D2-457ABDE11896}" = Windows Live Photo Common "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{7272F232-A7E0-4B2B-A5D2-71B7C5E2379C}" = Windows Live Fotótár "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{7496FD31-E5CB-4AE4-82D3-31099558BF6A}" = Windows Live Mesh "{74E8A7F6-575D-42C7-9178-E87D1B3BEFE8}" = Windows Live UX Platform Language Pack "{75B7F766-7998-44d8-A202-F1EC76A121BA}" = Memeo AutoSync "{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{78906B56-0E81-42A7-AC25-F54C946E1538}" = Windows Live Photo Common "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core "{7A9D47BA-6D50-4087-866F-0800D8B89383}" = Podstawowe programy Windows Live "{7CB529B2-6C74-4878-9C3F-C29C3C3BBDC6}" = Windows Live Writer Resources "{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger "{80E8C65A-8F70-4585-88A2-ABC54BABD576}" = Windows Live Mesh "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{84267681-BF16-40B6-9564-27BC57D7D71C}" = Windows Live Photo Common "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver "{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8E666407-AC41-46a2-9692-6C7BFCBFDD37}" = Memeo Instant Backup "{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg "{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting "{90120000-0016-0415-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2007 "{90120000-0016-0415-0000-0000000FF1CE}_HOMESTUDENTR_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-0018-0415-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2007 "{90120000-0018-0415-0000-0000000FF1CE}_HOMESTUDENTR_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001B-0415-0000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2007 "{90120000-001B-0415-0000-0000000FF1CE}_HOMESTUDENTR_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007 "{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007 "{90120000-001F-0415-0000-0000000FF1CE}_HOMESTUDENTR_{9CC96D78-9E1D-46E0-AF4D-3EB440CD4619}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) "{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002A-0415-1000-0000000FF1CE}_HOMESTUDENTR_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-002C-0415-0000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2007 "{90120000-006E-0415-0000-0000000FF1CE}_HOMESTUDENTR_{0C8AB602-A234-45AB-B355-4C863C1D2FA8}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90120000-00A1-0415-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2007 "{90120000-00A1-0415-0000-0000000FF1CE}_HOMESTUDENTR_{01CC3B2D-70DB-49DC-839A-A923D2A39EA4}" = Microsoft Office 2007 Service Pack 3 (SP3) "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3) "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{94B4E2D8-A184-415C-BF9E-F699D76466BD}" = Heroes of Might and Magic IV - Złota Edycja "{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}" = FARO LS 1.1.406.58 "{96403552-88D1-429F-9C92-388B814B885E}" = Messenger Companion "{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader "{97F77D62-5110-4FA3-A2D3-410B92D31199}" = Windows Live Fotogaléria "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE466FF-70B7-4DA8-807C-DB4C3610FDAA}" = Copy "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D3D8C60-A55F-4fed-B2B9-173001290E16}" = Realtek WLAN Driver "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{9DEABCB6-B759-4D52-92F8-51B34A2B4D40}" = Autodesk Material Library 2011 "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer "{AB78C965-5C67-409B-8433-D7B5BDB12073}" = Windows Live Writer Resources "{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply "{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.4) MUI "{AD001A69-88CC-4766-B2DB-3C1DFAB9AC72}" = Windows Live Mesh "{ADE85655-8D1E-4E4B-BF88-5E312FB2C74F}" = Windows Live Mail "{ADFE4AED-7F8E-4658-8D6E-742B15B9F120}" = Windows Live Photo Common "{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime "{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}" = Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych "{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR "{B44F3823-52DD-45CA-A916-8B320778715D}" = Messenger Companion "{B6190387-0036-4BEB-8D74-A0AFC5F14706}" = Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení "{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX "{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2 "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations "{BD8DA595-F501-4ABE-85A0-5C23E82472A0}" = Pomocnik Messenger "{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo "{BF022D76-9F72-4203-B8FA-6522DC66DFDA}" = Windows Live Movie Maker "{BF35168D-F6F9-4202-BA87-86B5E3C9BF7A}" = Windows Live Mesh "{C00C2A91-6CB3-483F-80B3-2958E29468F1}" = Συλλογή φωτογραφιών του Windows Live "{C29FC15D-E84B-4EEC-8505-4DED94414C59}" = Windows Live Writer Resources "{C2FD7DB5-FE30-49B6-8A2F-C5652E053C31}" = Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia "{C3A11907-930D-41AC-A135-CC3B12F92011}" = Seagate Dashboard "{C454280F-3C3E-4929-B60E-9E6CED5717E7}" = Windows Live Mail "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{C8421D85-CA0E-4E93-A9A9-B826C4FB88EA}" = Windows Live Mail "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget "{CB3F59BB-7858-41A1-A7EA-4B8A6FC7D431}" = Galeria fotografii usługi Windows Live "{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Obsługa programów Apple "{CD1E078C-A6B9-47DA-B035-6365C85C7832}" = Autodesk Material Library 2011 Base Image library "{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime "{E55E0C35-AC3C-4683-BA2F-834348577B80}" = Windows Live Writer "{E5F05232-96B6-4552-A480-785A60A94B21}" = System Requirements Lab CYRI "{EA17F4FC-FDBF-4CF8-A529-2D983132D053}" = Skype™ 6.0 "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F3ECEB0A-82A0-4DB9-BB44-393A66BA0871}" = Messenger kísérő "{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}" = Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις "{F80E5450-3EF3-4270-B26C-6AC53BEC5E76}" = Windows Live Movie Maker "{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm "{FA6CF94F-DACF-4FE7-959D-55C421B91B17}" = Windows Live Mail "{FB3D07AE-73D0-47A9-AC12-6F50BF8B6202}" = Windows Live Movie Maker "{FB79FDB7-4DE1-453D-99FE-9A880F57380E}" = Windows Live Fotogalerie "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "{FE62C88B-425B-4BDE-8B70-CD5AE3B83176}" = Windows Live Essentials "{FE77909E-B782-4554-A92A-4D887CEF0ACC}_is1" = ALLMediaServer "{FEEF7F78-5876-438B-B554-C4CC426A4302}" = Windows Live Essentials "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "ALLPlayer_is1" = ALLPlayer V5.X "Autodesk Design Review 2010" = Autodesk Design Review 2010 "avast" = avast! Free Antivirus "E94B1101-7675-4E37-9CB2-2E38A872154A" = Soldis PROJEKTANT "GameDesire-Pool & Snooker" = GameDesire-Pool & Snooker "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "InstallShield_{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver "InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORMCLauncher "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 1.70.0.1100 "NapiProjekt_is1" = NapiProjekt 2.0.0 (build 2151) "NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver "Revo Uninstaller" = Revo Uninstaller 1.94 "SP_a8235b05" = Search Assistant SoftQuick 1.66 "SP_e14dcdfa" = "vShare plugin" = vShare plugin 1.3 "vShare.tv plugin" = vShare.tv plugin 1.3 "WinLiveSuite" = Podstawowe programy Windows Live "wxPython2.8-unicode-py25_is1" = wxPython 2.8.4.0 (unicode) for Python 2.5 "YDP Flash Speech Recognition Support" = YDP Flash Speech Recognition Support 1.0 [color=#E56717]========== HKEY_USERS Uninstall List ==========[/color] [HKEY_USERS\S-1-5-21-319703930-2572490357-2975701463-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Akamai" = Akamai NetSession Interface "Google Chrome" = Google Chrome [color=#E56717]========== Last 20 Event Log Errors ==========[/color] [ Application Events ] Error - 9/13/2012 6:15:30 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/14/2012 5:26:00 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/14/2012 5:50:58 AM | Computer Name = Adam-TOSHIBA | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: ISAdmin.exe, wersja: 14.0.0.162, sygnatura czasowa: 0x4626b2f4 Nazwa modułu powodującego błąd: unknown, wersja: 0.0.0.0, sygnatura czasowa: 0x00000000 Kod wyjątku: 0xc000041d Przesunięcie błędu: 0x74a44f0d Identyfikator procesu powodującego błąd: 0x1030 Godzina uruchomienia aplikacji powodującej błąd: 0x01cd925e574f0388 Ścieżka aplikacji powodującej błąd: C:\Users\Adam\AppData\Local\Temp\pftFD15.tmp\ISAdmin.exe Ścieżka modułu powodującego błąd: unknown Identyfikator raportu: aefa5b22-fe51-11e1-99e8-b870f45d63bf Error - 9/15/2012 4:39:11 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/15/2012 5:35:12 PM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/16/2012 4:57:07 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/16/2012 5:06:09 AM | Computer Name = Adam-TOSHIBA | Source = Application Error | ID = 1000 Description = Nazwa aplikacji powodującej błąd: setup.exe_Sony PC Companion, wersja: 17.0.0.717, sygnatura czasowa: 0x4cab8cfa Nazwa modułu powodującego błąd: wer.dll, wersja: 6.1.7601.17514, sygnatura czasowa: 0x4ce7ba29 Kod wyjątku: 0xc0000005 Przesunięcie błędu: 0x00052140 Identyfikator procesu powodującego błąd: 0x5c4 Godzina uruchomienia aplikacji powodującej błąd: 0x01cd93e98fbd0fb3 Ścieżka aplikacji powodującej błąd: C:\Users\Adam\AppData\Local\Temp\{4FCEB9B4-7DBD-4616-85D3-474129838BA8}\setup.exe Ścieżka modułu powodującego błąd: C:\Windows\SysWOW64\wer.dll Identyfikator raportu: c0c7921c-ffdd-11e1-9afd-b870f45d63bf Error - 9/16/2012 12:22:31 PM | Computer Name = Adam-TOSHIBA | Source = Application Hang | ID = 1002 Description = Program ALLPlayer.exe w wersji 5.1.0.0 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: d60 Godzina rozpoczęcia: 01cd94276fc009d3 Godzina zakończenia: 89 Ścieżka aplikacji: D:\Programy\ALLPlayer\ALLPlayer.exe Identyfikator raportu: b51a3d35-001a-11e2-9afd-b870f45d63bf Error - 9/17/2012 9:26:47 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/18/2012 5:29:08 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/18/2012 1:55:17 PM | Computer Name = Adam-TOSHIBA | Source = Application Hang | ID = 1002 Description = Program ALLPlayer.exe w wersji 5.1.0.0 zatrzymał interakcję z systemem Windows i został zamknięty. Aby zobaczyć, czy jest dostępnych więcej informacji dotyczących tego problemu, sprawdź historię problemu w panelu sterowania Centrum akcji. Identyfikator procesu: e48 Godzina rozpoczęcia: 01cd95c6b978bdcb Godzina zakończenia: 69 Ścieżka aplikacji: D:\Programy\ALLPlayer\ALLPlayer.exe Identyfikator raportu: fdf908bc-01b9-11e2-9e3c-b870f45d63bf Error - 9/19/2012 6:37:41 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = Error - 9/20/2012 6:54:32 AM | Computer Name = Adam-TOSHIBA | Source = WinMgmt | ID = 10 Description = [ OSession Events ] Error - 5/4/2012 6:44:51 PM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6612.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 28 seconds with 0 seconds of active time. This session ended with a crash. Error - 11/9/2012 6:05:13 AM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 1426 seconds with 1200 seconds of active time. This session ended with a crash. Error - 11/9/2012 6:06:04 AM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 22 seconds with 0 seconds of active time. This session ended with a crash. Error - 11/9/2012 6:10:35 AM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 226 seconds with 180 seconds of active time. This session ended with a crash. Error - 11/9/2012 6:11:39 AM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 34 seconds with 0 seconds of active time. This session ended with a crash. Error - 11/9/2012 6:13:37 AM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 69 seconds with 0 seconds of active time. This session ended with a crash. Error - 11/9/2012 6:16:33 AM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 130 seconds with 60 seconds of active time. This session ended with a crash. Error - 11/9/2012 2:37:33 PM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 27 seconds with 0 seconds of active time. This session ended with a crash. Error - 12/16/2012 6:40:06 PM | Computer Name = Adam-TOSHIBA | Source = Microsoft Office 12 Sessions | ID = 7001 Description = ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 5327 seconds with 2700 seconds of active time. This session ended with a crash. [ System Events ] Error - 1/2/2013 1:42:38 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7022 Description = Usługa Windows Update zawiesiła się podczas uruchamiania. Error - 1/2/2013 2:36:18 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi atksgt z powodu następującego błędu: %%577 Error - 1/2/2013 2:36:36 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Internet Manager. OUC z powodu następującego błędu: %%2 Error - 1/2/2013 2:39:21 PM | Computer Name = Adam-TOSHIBA | Source = DCOM | ID = 10010 Description = Error - 1/2/2013 2:42:42 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7022 Description = Usługa Windows Update zawiesiła się podczas uruchamiania. Error - 1/2/2013 2:44:55 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7043 Description = Usługa Windows Update nie została poprawnie zamknięta po odebraniu kodu sterującego przed zamknięciem. Error - 1/2/2013 2:46:47 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi atksgt z powodu następującego błędu: %%577 Error - 1/2/2013 2:46:59 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7000 Description = Nie można uruchomić usługi Internet Manager. OUC z powodu następującego błędu: %%2 Error - 1/2/2013 2:49:37 PM | Computer Name = Adam-TOSHIBA | Source = DCOM | ID = 10010 Description = Error - 1/2/2013 2:53:16 PM | Computer Name = Adam-TOSHIBA | Source = Service Control Manager | ID = 7022 Description = Usługa Windows Update zawiesiła się podczas uruchamiania. < End of report > [/log]
Natsuki Kuga komentarz 3 stycznia 2013 komentarz 3 stycznia 2013 [quote] Use Chrome's Settings page to change the HomePage.[/quote] Musisz ręcznie podmienić stronę startową w Chrome na nieszkodliwą (np. Google). Czy występują jeszcze jakieś problemy? 1
adam205 komentarz 3 stycznia 2013 Autor komentarz 3 stycznia 2013 Cały czas mam Google ustawione :) wydaje mi się że wszystko jest w porządku, spróbuje zainstalować utracone programy jak tylko posprzątam ten bałagan. A na podstawie LOGów dobrze to wszystko wygląda ?
Natsuki Kuga komentarz 5 stycznia 2013 komentarz 5 stycznia 2013 W logach jest już ok. W OTL kliknij [b]Sprzątanie[/b], w AdwCleanerze [b]Uninstall,[/b] inne programy tu użyte też możesz usunąć. Na sam koniec wyłącz i włącz Przywracanie systemu (http://windows.microsoft.com/pl-PL/windows7/Turn-System-Restore-on-or-off).
adam205 komentarz 7 stycznia 2013 Autor komentarz 7 stycznia 2013 niestety napotkałem problem podczas wyłączania Przywracania systemu:http://zapodaj.net/69e0d631e564e.png.html
Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!
Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.