OTL logfile created on: 2013-04-22 19:59:26 - Run 1
OTL by OldTimer - Version Folder = C:\Users\1\Documents
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
1,87 Gb Total Physical Memory | 1,11 Gb Available Physical Memory | 59,48% Memory free
4,80 Gb Paging File | 3,78 Gb Available in Paging File | 78,69% Paging File free
Paging file location(s): a:\pagefile.sys 2600 2700c:\pagef [Binary data over 200 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 140,94 Gb Total Space | 79,57 Gb Free Space | 56,45% Space Free | Partition Type: NTFS
Computer Name: 1-KOMPUTER | User Name: 1 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
PRC - [2013-04-22 19:33:49 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\1\Documents\OTL.exe
PRC - [2013-04-06 12:40:38 | 000,879,456 | ---- | M] (Opera Software) -- C:\Program Files\Opera\opera.exe
PRC - [2013-03-13 17:15:00 | 004,394,032 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2013\avgui.exe
PRC - [2013-02-27 23:42:12 | 004,937,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2013\avgidsagent.exe
PRC - [2013-02-26 23:41:54 | 000,763,440 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2013\avgrsx.exe
PRC - [2013-02-19 04:02:02 | 000,282,624 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2013\avgwdsvc.exe
PRC - [2013-02-19 04:00:58 | 000,448,560 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2013\avgcsrvx.exe
PRC - [2013-02-18 20:45:06 | 000,968,880 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe
PRC - [2013-01-15 19:47:10 | 000,465,216 | ---- | M] (IObit) -- C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe
PRC - [2012-12-10 18:29:46 | 002,254,768 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
PRC - [2012-12-10 18:29:44 | 001,435,568 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
PRC - [2012-07-02 16:15:14 | 000,380,328 | ---- | M] (cFos Software GmbH) -- C:\Program Files\cFosSpeed\spd.exe
PRC - [2012-01-09 20:17:44 | 000,821,592 | ---- | M] (IObit) -- A:\Programy\IObit\IObit Malware Fighter\IMFsrv.exe
PRC - [2011-02-25 07:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010-12-18 21:48:04 | 000,295,936 | ---- | M] (Mz Ultimate Tools) -- C:\Program Files\Mz Ultimate Tools\Mz RAM Booster\MzRAMBooster.exe
PRC - [2003-02-21 12:46:58 | 000,191,488 | ---- | M] () -- A:\Gry PC\gamma adjuster\GammaAdjuster.exe
MOD - [2013-03-17 14:09:45 | 014,717,144 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_11_6_602_180.dll
MOD - [2013-01-15 19:47:02 | 000,143,168 | ---- | M] () -- C:\Program Files\IObit\Advanced SystemCare 6\ASCExtMenu.dll
MOD - [2013-01-08 21:29:41 | 001,670,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\4a29fb5e489e57ccc97b19ca70db94a8\Microsoft.VisualBasic.ni.dll
MOD - [2013-01-07 18:57:44 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\413288993ff690e8251d2dbe32bee01f\System.Runtime.Remoting.ni.dll
MOD - [2013-01-07 18:56:57 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d040079bc7148afeca03c5abb6fc3c61\System.Windows.Forms.ni.dll
MOD - [2013-01-07 18:56:44 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\4e80768a2d88c7a333e43cbb7a6c0705\System.Drawing.ni.dll
MOD - [2013-01-07 18:56:12 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\25e672ea505e50ab058258ac72a54f02\System.Xml.ni.dll
MOD - [2013-01-07 18:56:02 | 007,988,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9dd758ac0bf7358ac6e4720610fcc63c\System.ni.dll
MOD - [2013-01-07 18:55:26 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\187d7c66735c533de851c76384f86912\mscorlib.ni.dll
MOD - [2011-09-19 09:07:38 | 000,058,368 | ---- | M] () -- C:\Windows\System32\bdmpega.acm
MOD - [2011-02-04 16:36:39 | 000,208,896 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.resources\\System.resources.dll
MOD - [2003-02-21 12:46:58 | 000,191,488 | ---- | M] () -- A:\Gry PC\gamma adjuster\GammaAdjuster.exe
SRV - [2013-03-17 14:09:45 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013-02-28 18:45:16 | 000,161,384 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013-02-27 23:42:12 | 004,937,264 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2013\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2013-02-19 04:02:02 | 000,282,624 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2013\avgwdsvc.exe -- (avgwd)
SRV - [2013-02-18 20:45:06 | 000,968,880 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe -- (vToolbarUpdater14.2.0)
SRV - [2013-01-26 10:57:26 | 000,115,608 | ---- | M] (Mozilla Foundation) [Disabled | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013-01-15 19:47:10 | 000,465,216 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe -- (AdvancedSystemCareService6)
SRV - [2012-12-10 18:29:44 | 001,435,568 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2012-09-05 17:56:44 | 000,234,776 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.0.285\McCHSvc.exe -- (McComponentHostService)
SRV - [2012-08-25 16:26:35 | 000,529,744 | ---- | M] (Valve Corporation) [Disabled | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012-08-03 15:32:42 | 000,397,848 | ---- | M] () [Disabled | Stopped] -- C:\ProgramData\IBUpdaterService\ibsvc.exe -- (IBUpdaterService)
SRV - [2012-08-01 16:50:14 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2012-07-17 16:25:28 | 000,580,648 | ---- | M] (WiseCleaner.com) [Auto | Stopped] -- C:\Program Files\Wise\Wise Care 365\BootTime.exe -- (WiseBootAssistant)
SRV - [2012-07-02 16:15:14 | 000,380,328 | ---- | M] (cFos Software GmbH) [Auto | Running] -- C:\Program Files\cFosSpeed\spd.exe -- (cFosSpeedS)
SRV - [2012-06-11 12:33:26 | 000,724,376 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2012-01-09 20:17:44 | 000,821,592 | ---- | M] (IObit) [Auto | Running] -- A:\Programy\IObit\IObit Malware Fighter\IMFsrv.exe -- (IMFservice)
SRV - [2011-06-06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010-12-28 10:00:34 | 001,296,728 | ---- | M] (www.BitComet.com) [Disabled | Stopped] -- C:\Program Files\BitComet\tools\BitCometService.exe -- (BITCOMET_HELPER_SERVICE)
SRV - [2010-02-19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009-07-14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009-07-14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\Windows\system32\mseow.sys -- (mseow)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\Windows\system32\gmzioaj.sys -- (gmzioaj)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Garena Plus\Room\safedrv.sys -- (GGSAFERDriver)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ProgramData\MTA San Andreas All\1.3\temp\FairplayKD.sys -- (FairplayKD)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleXNt.sys -- (EagleXNt)
DRV - [2013-03-01 10:32:20 | 000,022,328 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgidsshimx.sys -- (AVGIDSShim)
DRV - [2013-02-26 23:40:46 | 000,208,184 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgidsdriverx.sys -- (AVGIDSDriver)
DRV - [2013-02-18 20:45:06 | 000,033,112 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtpx86.sys -- (avgtp)
DRV - [2013-02-08 04:37:58 | 000,096,568 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2013-02-08 04:37:56 | 000,245,048 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\avglogx.sys -- (Avglogx)
DRV - [2013-02-08 04:37:52 | 000,060,216 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\avgidshx.sys -- (AVGIDSHX)
DRV - [2013-02-08 04:37:44 | 000,170,808 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2013-02-08 04:37:40 | 000,039,224 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avgrkx86.sys -- (Avgrkx86)
DRV - [2013-01-07 18:27:51 | 000,049,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2013-01-07 18:27:51 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV - [2013-01-07 18:27:51 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2012-12-02 21:46:19 | 000,685,816 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2012-10-05 14:54:34 | 000,023,456 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DrvAgent32.sys -- (DrvAgent32)
DRV - [2012-09-05 17:34:00 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2012-08-01 18:16:48 | 001,414,656 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2012-07-05 13:53:38 | 000,019,832 | ---- | M] (IObit.com) [Kernel | On_Demand | Stopped] -- A:\Programy\IObit\IObit Malware Fighter\Drivers\win7_x86\UrlFilter.sys -- (UrlFilter)
DRV - [2012-07-05 13:53:36 | 000,030,640 | ---- | M] (IObit.com) [Kernel | On_Demand | Stopped] -- A:\Programy\IObit\IObit Malware Fighter\Drivers\win7_x86\RegFilter.sys -- (RegFilter)
DRV - [2012-07-02 16:15:18 | 000,975,272 | ---- | M] (cFos Software GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\cfosspeed6.sys -- (cFosSpeed)
DRV - [2012-06-11 12:33:46 | 000,019,072 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2012-01-05 18:07:20 | 000,020,336 | ---- | M] (IObit) [File_System | On_Demand | Stopped] -- A:\Programy\IObit\IObit Malware Fighter\Drivers\win7_x86\FileMonitor.sys -- (FileMonitor)
DRV - [2011-12-29 13:37:44 | 000,028,464 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\LPCFilter.sys -- (LPCFilter)
DRV - [2011-05-13 04:21:06 | 000,136,808 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2011-05-13 04:21:06 | 000,121,064 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadbus.sys -- (ssadbus)
DRV - [2011-05-13 04:21:06 | 000,114,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadserd.sys -- (ssadserd)
DRV - [2011-05-13 04:21:06 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdfl.sys -- (ssadmdfl)
DRV - [2011-05-13 04:21:04 | 000,030,312 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadadb.sys -- (androidusb)
DRV - [2010-11-26 18:02:20 | 000,015,672 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\SmartDefragDriver.sys -- (SmartDefragDriver)
DRV - [2010-11-09 15:35:30 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\cpuz135_x32.sys -- (cpuz135)
DRV - [2010-11-04 15:18:04 | 000,102,728 | ---- | M] (Matrox Graphics Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\MxEFUF32.sys -- (MxEFUF)
DRV - [2010-11-01 07:08:46 | 000,014,416 | ---- | M] (OpenLibSys.org) [File_System | On_Demand | Stopped] -- C:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys -- (WinRing0_1_2_0)
DRV - [2010-03-16 10:58:38 | 000,014,400 | ---- | M] (SR Research Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ebinfiltr.sys -- (ebinfiltr)
DRV - [2009-09-21 17:58:28 | 001,218,048 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009-08-22 20:25:00 | 000,009,088 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner32.sys -- (RivaTuner32)
DRV - [2009-07-23 22:02:56 | 000,043,008 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2009-07-14 00:13:48 | 001,035,776 | ---- | M] (LSI Corp) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2009-03-18 17:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2008-12-26 12:56:04 | 000,017,792 | ---- | M] (Avnex) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vcsvad.sys -- (VCSVADHWSer)
DRV - [2007-11-09 05:00:52 | 000,023,640 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\TVALZ_O.SYS -- (TVALZ)
DRV - [2007-07-15 03:37:04 | 000,027,992 | ---- | M] (EnTech Taiwan) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\pstrip.sys -- (PStrip)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=idg&from=idg&uid=WDC_WD2500BEVT-24A23T0_WD-WXE1A50E8975E8975&ts=1350915088
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.v9.com/?utm_source=b&utm_medium=idg&from=idg&uid=WDC_WD2500BEVT-24A23T0_WD-WXE1A50E8975E8975&ts=1350915088
IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDY&co=PL&userid=a1b48d25-41a6-4a81-83f7-041d3035388d&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10011&barid={932E8245-EF97-11E1-B341-001636E517B0}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.v9.com/?utm_source=b&utm_medium=idg&from=idg&uid=WDC_WD2500BEVT-24A23T0_WD-WXE1A50E8975E8975&ts=1350915088
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDY&co=PL&userid=a1b48d25-41a6-4a81-83f7-041d3035388d&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDY&co=PL&userid=a1b48d25-41a6-4a81-83f7-041d3035388d&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.v9.com/?utm_source=b&utm_medium=idg&from=idg&uid=WDC_WD2500BEVT-24A23T0_WD-WXE1A50E8975E8975&ts=1350915088
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDY&co=PL&userid=a1b48d25-41a6-4a81-83f7-041d3035388d&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDY&co=PL&userid=a1b48d25-41a6-4a81-83f7-041d3035388d&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE - HKCU\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDY&co=PL&userid=a1b48d25-41a6-4a81-83f7-041d3035388d&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.v9.com/web/?q={searchTerms}
IE - HKCU\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.v9.com/web/?q={searchTerms}
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={70B915DA-9864-441E-BADD-4054F6A5AE3C}&mid=c129b2926a484ecf849f2a0a57be5a4a-737d6be3d3d76da21980eded92fe6334dfb0c32a&lang=pl&ds=is015&pr=sa&d=2012-09-28 20:55:15&v={searchTerms}
IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10011&barid={932E8245-EF97-11E1-B341-001636E517B0}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.pah.org.pl/pajacyk/dziekujemy"
FF - prefs.js..extensions.enabledAddons: battlefieldheroespatcher%40ea.com:
FF - prefs.js..extensions.enabledAddons: battlefieldplay4free%40ea.com:
FF - prefs.js..extensions.enabledAddons: %7BDDC359D1-844A-42a7-9AA1-88A850A938A8%7D:2.0.15
FF - prefs.js..extensions.enabledAddons: bytubed%40cs213.cse.iitk.ac.in:1.1.1
FF - prefs.js..extensions.enabledAddons: %7BACAA314B-EEBA-48e4-AD47-84E31C44796C%7D:
FF - prefs.js..extensions.enabledAddons: toolbar%40ask.com:
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.1
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=ORJ&o=100000027&locale=en_US&apn_uid=09DD9307-79BE-4CCD-BE0D-D1F909FCEC43&apn_ptnrs=^U3&apn_sauid=A3031538-0F14-41C7-B751-AA56DE6FB939&apn_dtid=^YYYYYY^YY^PL&&q="
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: ""
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\14.2.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3503.0728: File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\1\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\1\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\1\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\1\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\1\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\1\AppData\Local\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\ [2013-02-18 20:45:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}: C:\Program Files\Common Files\DVDVideoSoft\plugins\ff\ [2013-01-27 15:23:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013-01-26 10:57:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
[2012-08-02 18:33:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\1\AppData\Roaming\mozilla\Extensions
[2013-02-03 09:08:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\1\AppData\Roaming\mozilla\Firefox\Profiles\5zueojl7.default\extensions
[2012-09-24 19:13:01 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- C:\Users\1\AppData\Roaming\mozilla\Firefox\Profiles\5zueojl7.default\extensions\[email protected]
[2012-10-19 18:57:58 | 000,000,000 | ---D | M] (Battlefield Play4Free) -- C:\Users\1\AppData\Roaming\mozilla\Firefox\Profiles\5zueojl7.default\extensions\[email protected]
[2013-01-14 19:33:23 | 000,000,000 | ---D | M] (BYTubeD - Bulk YouTube video Downloader) -- C:\Users\1\AppData\Roaming\mozilla\Firefox\Profiles\5zueojl7.default\extensions\[email protected]
[2012-08-26 18:04:07 | 000,000,000 | ---D | M] (Yontoo) -- C:\Users\1\AppData\Roaming\mozilla\Firefox\Profiles\5zueojl7.default\extensions\[email protected]
[2013-02-03 10:01:47 | 000,000,000 | ---D | M] ("Ask Toolbar") -- C:\Users\1\AppData\Roaming\mozilla\Firefox\Profiles\5zueojl7.default\extensions\[email protected]
[2012-09-21 23:03:06 | 000,005,403 | ---- | M] () (No name found) -- C:\Users\1\AppData\Roaming\mozilla\firefox\profiles\5zueojl7.default\extensions\[email protected]
[2013-01-27 16:59:17 | 000,242,487 | ---- | M] () (No name found) -- C:\Users\1\AppData\Roaming\mozilla\firefox\profiles\5zueojl7.default\extensions\[email protected]
[2013-01-30 21:28:12 | 000,204,940 | ---- | M] () (No name found) -- C:\Users\1\AppData\Roaming\mozilla\firefox\profiles\5zueojl7.default\extensions\[email protected]
[2013-02-01 15:42:42 | 000,817,973 | ---- | M] () (No name found) -- C:\Users\1\AppData\Roaming\mozilla\firefox\profiles\5zueojl7.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013-01-14 19:33:22 | 000,698,867 | ---- | M] () (No name found) -- C:\Users\1\AppData\Roaming\mozilla\firefox\profiles\5zueojl7.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2013-01-15 20:24:20 | 000,190,000 | ---- | M] () (No name found) -- C:\Users\1\AppData\Roaming\mozilla\firefox\profiles\5zueojl7.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
[2013-03-17 22:21:42 | 000,002,575 | ---- | M] () -- C:\Users\1\AppData\Roaming\mozilla\firefox\profiles\5zueojl7.default\searchplugins\askcom.xml
[2012-08-26 18:03:40 | 000,003,915 | ---- | M] () -- C:\Users\1\AppData\Roaming\mozilla\firefox\profiles\5zueojl7.default\searchplugins\sweetim.xml
[2012-09-07 15:02:42 | 000,002,469 | ---- | M] () -- C:\Users\1\AppData\Roaming\mozilla\firefox\profiles\5zueojl7.default\searchplugins\Web Search.xml
[2013-01-26 10:57:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013-01-26 10:57:14 | 000,000,000 | ---D | M] ("BitAccelerator") -- C:\Program Files\Mozilla Firefox\extensions\{5ddeb737-082c-48fb-8c06-aa4b38d61e5f}
[2013-01-27 15:23:29 | 000,000,000 | ---D | M] ("DVDVideoSoft YouTube MP3 and Video Download") -- C:\PROGRAM FILES\COMMON FILES\DVDVIDEOSOFT\PLUGINS\FF
[2013-01-26 10:57:27 | 000,262,552 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012-06-28 17:42:00 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2013-01-05 17:46:00 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2013-02-18 20:45:31 | 000,003,716 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012-08-11 14:04:57 | 000,002,360 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2013-01-05 17:46:01 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2013-01-05 17:46:01 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2013-01-05 17:46:01 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2012-10-22 16:11:30 | 000,000,402 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\v9.xml
[2013-01-05 17:46:01 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2013-01-05 17:46:00 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.v9.com/?utm_source=b&utm_medium=idg&from=idg&uid=WDC_WD2500BEVT-24A23T0_WD-WXE1A50E8975E8975&ts=1350915088
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\1\AppData\Local\Google\Chrome\Application\21.0.1180.60\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\1\AppData\Local\Google\Chrome\Application\26.0.1410.64\gcswf32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\1\AppData\Local\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\1\AppData\Local\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Users\1\AppData\Local\Google\Update\\npGoogleUpdate3.dll
CHR - Extension: James White = C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkeidgmehkdjmpjodpjkepolokanalkm\3_0\
CHR - Extension: Battlefield Heroes = C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh\\
CHR - Extension: Adblock Plus = C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.4_0\
CHR - Extension: Tampermonkey = C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo\2.12.3124.188_0\
CHR - Extension: BitAccelerator = C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Extensions\kngjfmklipimnkegmcilmbhchklgjgfl\1.1_0\
CHR - Extension: AVG Security Toolbar = C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\\
CHR - Extension: DVDVideoSoft Browser Extension = C:\Users\1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\\
O1 HOSTS File: ([2012-11-04 12:49:05 | 000,000,888 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts:
O1 - Hosts: activation.cloud.techsmith.com
O2 - BHO: (Claro LTD Helper Object) - {000F18F2-09EB-4A59-82B2-5AE4184C39C3} - C:\Program Files\Claro LTD\claro\\bh\claro.dll (Montera Technologeis LTD)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [GammaAdjuster] A:\Gry PC\gamma adjuster\GammaAdjuster.exe ()
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [bfcadfccsacfsfdsf] C:\ProgramData\bfcadfccsacfsfdsf.exe (ICQ, LLC.)
O4 - HKCU..\Run: [Ceujmgywnzatxwwn.exe] C:\Users\1\AppData\Roaming\Ceujmgywnzatxwwn.exe ()
O4 - HKCU..\Run: [MzRAMBooster] C:\Program Files\Mz Ultimate Tools\Mz RAM Booster\MzRAMBooster.exe (Mz Ultimate Tools)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O8 - Extra context menu item: &P&obierz &za pomocą BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Free YouTube Download - C:\Users\1\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Pobierz wszystko za pomocą BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll (BitComet)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0D25B12F-707F-486E-A618-1E8FFA0178FC}: DhcpNameServer =
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\14.2.0\ViProtocol.dll ()
O18 - Protocol\Handler\wlpg - No CLSID value found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\Windows\System32\ati2evxx.dll (ATI Technologies Inc.)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-06-10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{f874c611-f75b-11e1-a6fd-001636e517b0}\Shell - "" = AutoRun
O33 - MountPoints2\{f874c611-f75b-11e1-a6fd-001636e517b0}\Shell\AutoRun\command - "" = E:\Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
[2013-04-22 19:34:55 | 000,000,000 | ---D | C] -- C:\_OTL
[2013-04-22 19:33:49 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\1\Documents\OTL.exe
[2013-04-22 16:14:51 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013-04-22 16:12:21 | 000,000,000 | ---D | C] -- C:\Users\1\AppData\Roaming\AVG2013
[2013-04-22 16:09:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013-04-22 16:09:57 | 000,000,000 | ---D | C] -- C:\Users\1\AppData\Roaming\TuneUp Software
[2013-04-22 16:08:56 | 000,000,000 | -H-D | C] -- C:\$AVG
[2013-04-22 16:08:56 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2013
[2013-04-22 16:08:19 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2013-04-22 16:07:16 | 000,000,000 | ---D | C] -- C:\Users\1\AppData\Local\MFAData
[2013-04-22 16:07:16 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2013-04-22 16:07:16 | 000,000,000 | ---D | C] -- C:\Users\1\AppData\Local\Avg2013
[2013-04-22 15:59:46 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
[2013-04-22 15:11:09 | 000,182,784 | ---- | C] (ICQ, LLC.) -- C:\ProgramData\bfcadfccsacfsfdsf.exe
[2013-04-20 22:42:13 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2013-04-20 22:42:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013-04-20 22:42:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2013-04-13 19:08:34 | 000,519,168 | ---- | C] (TroyaN) -- C:\Users\1\Desktop\Tak.exe
[2013-04-09 20:43:21 | 000,000,000 | ---D | C] -- C:\Windows\System32\RTCOM
[2013-04-09 20:42:41 | 001,783,056 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\WavesLib.dll
[2013-04-09 20:42:41 | 001,725,784 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\WavesGUILib.dll
[2013-04-09 20:42:40 | 001,379,760 | ---- | C] (TOSHIBA Corporation) -- C:\Windows\System32\tosade.dll
[2013-04-09 20:42:40 | 000,819,648 | ---- | C] (TOSHIBA Corporation) -- C:\Windows\System32\tadefxapo2.dll
[2013-04-09 20:42:40 | 000,345,328 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSXT.dll
[2013-04-09 20:42:40 | 000,185,584 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSTSHD.dll
[2013-04-09 20:42:40 | 000,173,296 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSHP360.dll
[2013-04-09 20:42:40 | 000,140,528 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\System32\SRSWOW.dll
[2013-04-09 20:42:40 | 000,134,584 | ---- | C] (TOSHIBA Corporation) -- C:\Windows\System32\tadefxapo.dll
[2013-04-09 20:42:40 | 000,058,264 | ---- | C] (TOSHIBA CORPORATION.) -- C:\Windows\System32\TepeqAPO.dll
[2013-04-09 20:42:39 | 002,417,808 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkPgExt.dll
[2013-04-09 20:42:39 | 001,497,704 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RTSndMgr.cpl
[2013-04-09 20:42:39 | 000,645,776 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkApoApi.dll
[2013-04-09 20:42:39 | 000,214,368 | ---- | C] (Synopsys, Inc.) -- C:\Windows\System32\SFNHK.dll
[2013-04-09 20:42:39 | 000,192,104 | ---- | C] (Sony Corporation) -- C:\Windows\System32\SFSS_APO.dll
[2013-04-09 20:42:39 | 000,087,696 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkCoInstII.dll
[2013-04-09 20:42:39 | 000,074,080 | ---- | C] (Synopsys, Inc.) -- C:\Windows\System32\SFCOM.dll
[2013-04-09 20:42:39 | 000,068,960 | ---- | C] (Synopsys, Inc.) -- C:\Windows\System32\SFAPO.dll
[2013-04-09 20:42:39 | 000,013,416 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkCoLDR.dll
[2013-04-09 20:42:38 | 007,783,768 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioRealtek.dll
[2013-04-09 20:42:38 | 007,161,696 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEP32A.dll
[2013-04-09 20:42:38 | 005,096,448 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RCoRes.dat
[2013-04-09 20:42:38 | 003,173,008 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtkAPO.dll
[2013-04-09 20:42:38 | 001,185,112 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioRealtek2.dll
[2013-04-09 20:42:38 | 000,359,768 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEP32A.dll
[2013-04-09 20:42:38 | 000,351,072 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EED32A.dll
[2013-04-09 20:42:38 | 000,350,552 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxVolumeSDAPO.dll
[2013-04-09 20:42:38 | 000,295,768 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DHT32.dll
[2013-04-09 20:42:38 | 000,295,768 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RP3DAA32.dll
[2013-04-09 20:42:38 | 000,170,840 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEED32A.dll
[2013-04-09 20:42:38 | 000,105,824 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEL32A.dll
[2013-04-09 20:42:38 | 000,091,488 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEA32A.dll
[2013-04-09 20:42:38 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEL32A.dll
[2013-04-09 20:42:38 | 000,064,856 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\System32\RTEEG32A.dll
[2013-04-09 20:42:38 | 000,061,792 | ---- | C] (Dolby Laboratories) -- C:\Windows\System32\R4EEG32A.dll
[2013-04-09 20:42:37 | 001,836,376 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioEQ.dll
[2013-04-09 20:42:37 | 000,709,976 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPOShell.dll
[2013-04-09 20:42:37 | 000,357,712 | ---- | C] (Knowles Acoustics ) -- C:\Windows\System32\KAAPORT.dll
[2013-04-09 20:42:37 | 000,259,928 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO30.dll
[2013-04-09 20:42:37 | 000,232,792 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO20.dll
[2013-04-09 20:42:37 | 000,132,368 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\System32\MaxxAudioAPO.dll
[2013-04-09 20:42:35 | 002,193,472 | ---- | C] (Fortemedia Corporation) -- C:\Windows\System32\FMAPO.dll
[2013-04-09 20:42:35 | 001,509,480 | ---- | C] (DTS) -- C:\Windows\System32\DTSS2SpeakerDLL.dll
[2013-04-09 20:42:35 | 001,292,904 | ---- | C] (DTS) -- C:\Windows\System32\DTSS2HeadphoneDLL.dll
[2013-04-09 20:42:35 | 001,220,200 | ---- | C] (DTS) -- C:\Windows\System32\DTSBoostDLL.dll
[2013-04-09 20:42:35 | 000,654,952 | ---- | C] (DTS) -- C:\Windows\System32\DTSBassEnhancementDLL.dll
[2013-04-09 20:42:35 | 000,631,400 | ---- | C] (DTS) -- C:\Windows\System32\DTSSymmetryDLL.dll
[2013-04-09 20:42:35 | 000,601,704 | ---- | C] (DTS) -- C:\Windows\System32\DTSVoiceClarityDLL.dll
[2013-04-09 20:42:35 | 000,458,344 | ---- | C] (DTS) -- C:\Windows\System32\DTSNeoPCDLL.dll
[2013-04-09 20:42:35 | 000,421,744 | ---- | C] (DTS) -- C:\Windows\System32\DTSU2PLFX32.dll
[2013-04-09 20:42:35 | 000,398,192 | ---- | C] (DTS) -- C:\Windows\System32\DTSU2PGFX32.dll
[2013-04-09 20:42:35 | 000,389,736 | ---- | C] (DTS) -- C:\Windows\System32\DTSGainCompensatorDLL.dll
[2013-04-09 20:42:35 | 000,375,400 | ---- | C] (DTS) -- C:\Windows\System32\DTSLimiterDLL.dll
[2013-04-09 20:42:35 | 000,335,216 | ---- | C] (DTS) -- C:\Windows\System32\DTSU2PREC32.dll
[2013-04-09 20:42:35 | 000,218,728 | ---- | C] (DTS) -- C:\Windows\System32\DTSGFXAPONS.dll
[2013-04-09 20:42:35 | 000,218,728 | ---- | C] (DTS) -- C:\Windows\System32\DTSGFXAPO.dll
[2013-04-09 20:42:35 | 000,218,216 | ---- | C] (DTS) -- C:\Windows\System32\DTSLFXAPO.dll
[2013-04-09 20:42:35 | 000,176,736 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\System32\AERTACap.dll
[2013-04-09 20:42:35 | 000,095,840 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\System32\AERTARen.dll
[2013-04-02 15:35:56 | 000,086,016 | ---- | C] (MindVision Software) -- C:\Windows\unvise32.exe
[2013-04-02 15:35:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\POD-Bot 2.5
[2013-04-02 15:35:53 | 000,000,000 | ---D | C] -- C:\Users\1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\POD-Bot 2.5
[2013-03-27 13:36:03 | 000,000,000 | ---D | C] -- C:\Program Files\Ventrilo
[2013-04-22 20:03:41 | 000,182,784 | ---- | M] (ICQ, LLC.) -- C:\ProgramData\bfcadfccsacfsfdsf.exe
[2013-04-22 20:03:39 | 000,182,784 | ---- | M] (ICQ, LLC.) -- C:\ProgramData\bfcadfccsacfsfdsf.exe
[2013-04-22 19:52:28 | 000,103,424 | RH-- | M] () -- C:\Users\1\AppData\Roaming\Ceujmgywnzatxwwn.exe
[2013-04-22 19:44:24 | 000,021,264 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013-04-22 19:44:24 | 000,021,264 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013-04-22 19:42:17 | 000,661,062 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013-04-22 19:42:17 | 000,125,252 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013-04-22 19:42:17 | 000,026,954 | ---- | M] () -- C:\Windows\System32\perfh015.dat
[2013-04-22 19:42:17 | 000,012,646 | ---- | M] () -- C:\Windows\System32\perfc015.dat
[2013-04-22 19:36:01 | 003,702,536 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013-04-22 19:35:48 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013-04-22 19:35:33 | 1508,462,592 | -HS- | M] () -- C:\hiberfil.sys
[2013-04-22 19:33:49 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\1\Documents\OTL.exe
[2013-04-22 19:29:48 | 000,103,424 | ---- | M] () -- C:\Users\1\AppData\Roaming\42CE.exe
[2013-04-22 19:26:24 | 000,103,424 | RH-- | M] () -- C:\Users\1\AppData\Roaming\Vattlndlblsewagb.exe
[2013-04-22 19:24:00 | 000,103,424 | RH-- | M] () -- C:\Users\1\AppData\Roaming\Isjwlfosmicqgbrq.exe
[2013-04-22 19:09:00 | 000,103,424 | RH-- | M] () -- C:\Users\1\AppData\Roaming\Wpdehzkkewqgochs.exe
[2013-04-22 19:06:52 | 000,216,538 | ---- | M] () -- C:\Users\1\Desktop\krzysiubobr.jpg
[2013-04-22 19:06:52 | 000,006,428 | ---- | M] () -- C:\Users\1\.recently-used.xbel
[2013-04-22 17:23:54 | 000,103,424 | RH-- | M] () -- C:\Users\1\AppData\Roaming\Knaimcwyyxunfcfk.exe
[2013-04-22 16:38:18 | 000,103,424 | RH-- | M] () -- C:\Users\1\AppData\Roaming\Isynqidzpmpkcskv.exe
[2013-04-22 16:09:58 | 000,000,965 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2013.lnk
[2013-04-22 15:34:00 | 000,117,996 | ---- | M] () -- C:\Users\1\Desktop\kon-dom.jpg
[2013-04-22 14:30:09 | 000,975,558 | ---- | M] () -- C:\Users\1\Desktop\gaddemjuson.jpg
[2013-04-22 09:58:22 | 001,398,249 | ---- | M] () -- C:\Users\1\Desktop\2013-04-22 09.58.22.jpg
[2013-04-22 09:08:14 | 001,045,118 | ---- | M] () -- C:\Users\1\Desktop\2013-04-22 09.08.15.jpg
[2013-04-21 17:05:53 | 002,466,286 | ---- | M] () -- C:\Users\1\Desktop\nafejsa.jpg
[2013-04-21 16:53:04 | 000,223,321 | ---- | M] () -- C:\Users\1\Desktop\avatarnaskajp.jpg
[2013-04-21 16:26:39 | 001,644,157 | ---- | M] () -- C:\Users\1\Desktop\Bez nazwy.xcf
[2013-04-21 13:20:27 | 000,001,069 | ---- | M] () -- C:\Users\Public\Desktop\GIMP 2.lnk
[2013-04-20 13:13:52 | 000,000,213 | ---- | M] () -- C:\Users\1\Desktop\Left 4 Dead.url
[2013-04-19 21:20:34 | 000,011,830 | ---- | M] () -- C:\Users\1\AppData\Local\recently-used.xbel
[2013-04-14 12:18:59 | 000,006,662 | ---- | M] () -- C:\Users\1\AppData\Roaming\PStrip.ini
[2013-04-14 08:56:30 | 000,006,662 | ---- | M] () -- C:\Users\1\AppData\Roaming\PStrip.bak
[2013-04-14 08:27:49 | 000,006,662 | ---- | M] () -- C:\Users\1\AppData\Roaming\PStrip.bko
[2013-04-13 19:08:16 | 000,519,168 | ---- | M] (TroyaN) -- C:\Users\1\Desktop\Tak.exe
[2013-04-13 18:47:46 | 000,096,256 | ---- | M] () -- C:\Users\1\AppData\Roaming\chrtmp
[2013-04-08 15:55:25 | 000,001,099 | ---- | M] () -- C:\Users\1\Desktop\GammaAdjuster — skrót.lnk
[2013-04-08 15:52:49 | 000,006,685 | ---- | M] () -- C:\Users\1\AppData\Roaming\PStrip.bk!
[2013-03-27 08:22:19 | 000,000,990 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3838626967-3587868773-1472854575-1000Core1ce2ab36f84c811.job
[2013-04-22 19:52:27 | 000,103,424 | RH-- | C] () -- C:\Users\1\AppData\Roaming\Ceujmgywnzatxwwn.exe
[2013-04-22 19:35:37 | 003,702,536 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2013-04-22 19:29:48 | 000,103,424 | ---- | C] () -- C:\Users\1\AppData\Roaming\42CE.exe
[2013-04-22 19:26:24 | 000,103,424 | RH-- | C] () -- C:\Users\1\AppData\Roaming\Vattlndlblsewagb.exe
[2013-04-22 19:24:00 | 000,103,424 | RH-- | C] () -- C:\Users\1\AppData\Roaming\Isjwlfosmicqgbrq.exe
[2013-04-22 19:08:59 | 000,103,424 | RH-- | C] () -- C:\Users\1\AppData\Roaming\Wpdehzkkewqgochs.exe
[2013-04-22 19:06:52 | 000,216,538 | ---- | C] () -- C:\Users\1\Desktop\krzysiubobr.jpg
[2013-04-22 19:06:52 | 000,006,428 | ---- | C] () -- C:\Users\1\.recently-used.xbel
[2013-04-22 17:23:54 | 000,103,424 | RH-- | C] () -- C:\Users\1\AppData\Roaming\Knaimcwyyxunfcfk.exe
[2013-04-22 16:38:18 | 000,103,424 | RH-- | C] () -- C:\Users\1\AppData\Roaming\Isynqidzpmpkcskv.exe
[2013-04-22 16:09:58 | 000,000,965 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2013.lnk
[2013-04-22 15:34:00 | 000,117,996 | ---- | C] () -- C:\Users\1\Desktop\kon-dom.jpg
[2013-04-22 14:30:08 | 000,975,558 | ---- | C] () -- C:\Users\1\Desktop\gaddemjuson.jpg
[2013-04-22 09:58:23 | 001,398,249 | ---- | C] () -- C:\Users\1\Desktop\2013-04-22 09.58.22.jpg
[2013-04-22 09:08:15 | 001,045,118 | ---- | C] () -- C:\Users\1\Desktop\2013-04-22 09.08.15.jpg
[2013-04-21 17:05:52 | 002,466,286 | ---- | C] () -- C:\Users\1\Desktop\nafejsa.jpg
[2013-04-21 16:26:39 | 001,644,157 | ---- | C] () -- C:\Users\1\Desktop\Bez nazwy.xcf
[2013-04-21 13:34:33 | 000,223,321 | ---- | C] () -- C:\Users\1\Desktop\avatarnaskajp.jpg
[2013-04-21 13:20:27 | 000,001,069 | ---- | C] () -- C:\Users\Public\Desktop\GIMP 2.lnk
[2013-04-20 13:13:52 | 000,000,213 | ---- | C] () -- C:\Users\1\Desktop\Left 4 Dead.url
[2013-04-19 21:20:34 | 000,011,830 | ---- | C] () -- C:\Users\1\AppData\Local\recently-used.xbel
[2013-04-09 20:42:38 | 000,293,889 | ---- | C] () -- C:\Windows\System32\drivers\RTAIODAT.DAT
[2013-04-08 15:55:25 | 000,001,099 | ---- | C] () -- C:\Users\1\Desktop\GammaAdjuster — skrót.lnk
[2013-03-27 08:22:19 | 000,000,990 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3838626967-3587868773-1472854575-1000Core1ce2ab36f84c811.job
[2013-03-24 17:34:57 | 000,096,256 | ---- | C] () -- C:\Users\1\AppData\Roaming\chrtmp
[2013-02-23 22:30:15 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2013-02-03 19:51:35 | 001,213,520 | ---- | C] () -- C:\Users\1\ts3_recording_13_02_03_18_51_34.wav
[2013-02-03 19:50:56 | 002,284,880 | ---- | C] () -- C:\Users\1\ts3_recording_13_02_03_18_50_55.wav
[2013-02-01 20:54:36 | 002,476,880 | ---- | C] () -- C:\Users\1\ts3_recording_13_02_01_19_54_32.wav
[2013-01-21 17:03:06 | 001,099,056 | ---- | C] () -- C:\Users\1\ts3_recording_13_01_21_16_3_4.wav
[2013-01-18 22:36:46 | 000,000,132 | ---- | C] () -- C:\Users\1\AppData\Roaming\Preferencje Adobe CS5 dla formatu PNG
[2013-01-13 23:29:16 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2012-12-25 19:22:04 | 000,000,652 | ---- | C] () -- C:\Windows\eReg.dat
[2012-12-19 16:45:04 | 000,180,224 | ---- | C] () -- C:\Windows\System32\clinfo.exe
[2012-12-04 17:53:14 | 000,552,233 | ---- | C] () -- C:\Users\1\Laboratory_Clinical_Art.wal
[2012-11-14 21:01:54 | 000,000,158 | ---- | C] () -- C:\Users\1\.gtkrc-2.0
[2012-11-06 18:57:53 | 000,000,089 | ---- | C] () -- C:\Users\1\AppData\Local\fusioncache.dat
[2012-11-06 16:39:51 | 000,087,040 | ---- | C] () -- C:\Windows\UnGins.exe
[2012-11-06 15:53:30 | 001,426,411 | ---- | C] () -- C:\Users\1\AppData\Local\Tempmusic.ogg
[2012-11-04 12:40:29 | 000,006,656 | ---- | C] () -- C:\Users\1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012-11-02 12:54:53 | 000,000,025 | ---- | C] () -- C:\Users\1\AppData\Roaming\mta.ini.ini
[2012-10-28 21:21:14 | 001,970,176 | ---- | C] () -- C:\Windows\System32\d3dx9.dll
[2012-10-16 18:49:39 | 000,073,728 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2012-10-16 18:23:16 | 000,110,602 | ---- | C] () -- C:\Windows\System32\xcdsfx32.bin
[2012-10-11 14:36:24 | 000,001,654 | ---- | C] () -- C:\Users\1\AppData\Roaming\SvcTraceViewer.exe.settings
[2012-10-07 15:16:10 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2012-09-28 19:11:40 | 000,123,392 | ---- | C] () -- C:\Windows\System32\tmb1-v32.dll
[2012-09-24 19:44:18 | 000,138,904 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2012-09-24 19:44:18 | 000,138,904 | ---- | C] () -- C:\Users\1\AppData\Roaming\PnkBstrK.sys
[2012-09-24 19:43:46 | 000,281,872 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2012-09-24 19:43:43 | 000,076,888 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2012-09-24 16:08:59 | 000,015,672 | ---- | C] () -- C:\Windows\System32\drivers\SmartDefragDriver.sys
[2012-09-10 15:03:22 | 000,071,040 | ---- | C] () -- C:\Windows\System32\deformerdll.dll
[2012-09-10 15:02:56 | 000,192,512 | ---- | C] () -- C:\Windows\System32\binkw32.dll
[2012-09-10 15:01:57 | 000,389,632 | ---- | C] () -- C:\Windows\System32\granny2.dll
[2012-09-04 16:18:42 | 000,003,153 | ---- | C] () -- C:\Program Files\visit-nosteam-forum.html
[2012-09-04 16:18:42 | 000,000,077 | ---- | C] () -- C:\Program Files\update-l4d.bat
[2012-09-02 18:09:06 | 000,045,270 | ---- | C] () -- C:\Users\1\AppData\Roaming\room_v3.dat
[2012-08-31 09:08:23 | 000,001,065 | ---- | C] () -- C:\Windows\winamp.ini
[2012-08-24 07:20:01 | 000,006,685 | ---- | C] () -- C:\Users\1\AppData\Roaming\PStrip.bk!
[2012-08-24 07:19:11 | 000,006,662 | ---- | C] () -- C:\Users\1\AppData\Roaming\PStrip.bko
[2012-08-23 22:17:53 | 000,006,662 | ---- | C] () -- C:\Users\1\AppData\Roaming\PStrip.bak
[2012-08-23 20:50:05 | 000,006,662 | ---- | C] () -- C:\Users\1\AppData\Roaming\PStrip.ini
[2012-08-23 20:25:18 | 000,007,607 | ---- | C] () -- C:\Users\1\AppData\Local\Resmon.ResmonCfg
[2012-08-22 09:29:09 | 000,003,972 | ---- | C] () -- C:\Windows\System32\drivers\PciBus.sys
[2012-08-12 15:37:52 | 000,081,938 | ---- | C] () -- C:\Users\1\AppData\Roaming\.mineshaftersquaredminecraft.jar
[2012-08-12 15:37:52 | 000,076,964 | ---- | C] () -- C:\Users\1\AppData\Roaming\.mineshaftersquaredminecraft_modified.jar
[2012-08-10 21:52:15 | 000,001,126 | ---- | C] () -- C:\Program Files\Camtasia Studio 8.lnk
[2012-08-09 15:57:15 | 000,000,163 | ---- | C] () -- C:\Windows\AutoScreenRecorder.INI
[2012-07-12 16:25:22 | 000,639,488 | ---- | C] () -- C:\Windows\System32\ficvdec_x86.dll
[2011-09-19 09:07:46 | 000,015,360 | ---- | C] () -- C:\Windows\System32\bdmjpeg.dll
[2011-09-19 09:07:32 | 000,058,368 | ---- | C] () -- C:\Windows\System32\bdmpegv.dll
[2003-04-09 05:28:44 | 000,233,472 | R--- | C] () -- C:\Users\1\AppData\Roaming\MafiaSetup.exe
[2009-07-14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
"" = %SystemRoot%\system32\shell32.dll -- [2012-06-09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 23:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009-07-14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
< End of report >