OTL logfile created on: 2014-02-05 11:28:27 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = c:\users\monika\desktop\downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd
1,99 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 50,45% Memory free
4,22 Gb Paging File | 3,08 Gb Available in Paging File | 72,88% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 140,05 Gb Total Space | 39,32 Gb Free Space | 28,08% Space Free | Partition Type: NTFS
Drive D: | 9,00 Gb Total Space | 2,70 Gb Free Space | 30,01% Space Free | Partition Type: NTFS
Computer Name: DZIENNIKARKA | User Name: Monika | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014-02-04 23:34:08 | 000,602,112 | ---- | M] (OldTimer Tools) -- c:\users\monika\desktop\downloads\otl(1).exe
PRC - [2014-01-09 15:52:58 | 003,764,024 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014-01-09 15:52:58 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2013-12-18 19:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013-11-18 21:59:36 | 000,590,352 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgcsrvx.exe
PRC - [2013-11-11 22:02:14 | 003,478,544 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgidsagent.exe
PRC - [2013-11-07 22:03:50 | 004,956,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgui.exe
PRC - [2013-10-28 23:24:02 | 000,729,648 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgrsx.exe
PRC - [2013-09-06 18:30:16 | 000,273,296 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
PRC - [2011-06-17 12:04:16 | 000,224,096 | ---- | M] () -- C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe
PRC - [2011-03-14 16:27:28 | 000,271,712 | ---- | M] () -- C:\ProgramData\DatacardService\HWDeviceService.exe
PRC - [2011-03-14 16:27:28 | 000,236,384 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe
PRC - [2009-10-10 10:38:14 | 000,072,704 | ---- | M] (Autodesk) -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
PRC - [2008-10-29 07:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008-04-18 14:54:02 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008-01-21 03:33:00 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008-01-21 03:32:50 | 000,215,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\wmdSync.exe
PRC - [2007-12-11 13:15:04 | 000,012,800 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe
PRC - [2007-05-08 16:38:46 | 000,540,448 | ---- | M] (PDF Complete Inc) -- C:\Program Files\PDF Complete\pdfsvc.exe
PRC - [2007-02-06 08:44:24 | 000,069,632 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AEADISRV.EXE
PRC - [2007-01-09 23:52:36 | 000,145,184 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe
PRC - [2006-09-29 11:48:06 | 000,065,536 | ---- | M] () -- C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
========== Modules (No Company Name) ==========
MOD - [2014-01-09 15:53:04 | 019,336,120 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2011-11-01 23:26:32 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011-11-01 23:26:12 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2007-06-08 17:05:38 | 000,274,432 | ---- | M] () -- C:\Windows\System32\flcdlmsg.dll
========== Services (SafeList) ==========
SRV - [2014-01-09 15:52:58 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2013-12-18 19:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013-12-11 20:56:10 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013-11-11 22:02:14 | 003,478,544 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2014\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2013-09-24 01:33:08 | 000,348,008 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files\AVG\AVG2014\avgwdsvc.exe -- (avgwd)
SRV - [2013-09-06 18:29:38 | 000,235,216 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe -- (McComponentHostService)
SRV - [2013-09-05 09:34:30 | 000,171,680 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012-03-21 16:34:21 | 000,489,256 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011-11-10 14:17:31 | 000,167,264 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service)
SRV - [2011-06-17 12:04:16 | 000,224,096 | ---- | M] () [Auto | Stopped] -- C:\Program Files\T-Mobile\InternetManager_H\UpdateDog\ouc.exe -- (Internet Manager. RunOuc)
SRV - [2011-03-14 16:27:28 | 000,271,712 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\HWDeviceService.exe -- (HWDeviceService.exe)
SRV - [2009-10-10 10:38:14 | 000,072,704 | ---- | M] (Autodesk) [Auto | Running] -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe -- (Autodesk Licensing Service)
SRV - [2009-08-31 00:32:00 | 003,264,636 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc)
SRV - [2009-08-24 13:16:12 | 000,378,368 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- winhttp.dll -- (WinHttpAutoProxySvc)
SRV - [2008-11-11 09:38:06 | 000,620,544 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008-04-18 14:54:02 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
SRV - [2008-01-21 03:33:00 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008-01-21 03:32:50 | 000,365,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2008-01-21 03:32:50 | 000,167,936 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2007-12-11 13:15:04 | 000,012,800 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2007-06-08 17:06:42 | 000,172,131 | ---- | M] (Hewlett-Packard Ltd) [On_Demand | Stopped] -- C:\Windows\System32\flcdlock.exe -- (FLCDLOCK)
SRV - [2007-05-08 16:38:46 | 000,540,448 | ---- | M] (PDF Complete Inc) [Auto | Running] -- C:\Program Files\PDF Complete\pdfsvc.exe -- (pdfcDispatcher)
SRV - [2007-03-05 17:30:06 | 000,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -- (Com4Qlb)
SRV - [2007-02-06 08:44:24 | 000,069,632 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AEADISRV.EXE -- (AEADIFilters)
SRV - [2007-01-05 03:48:52 | 000,112,152 | R--- | M] (InterVideo) [Disabled | Stopped] -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
SRV - [2006-09-29 11:48:06 | 000,065,536 | ---- | M] () [Auto | Running] -- C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe -- (mi-raysat_3dsmax9_32)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\XDva406.sys -- (XDva406)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\XDva405.sys -- (XDva405)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\XDva404.sys -- (XDva404)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\XDva403.sys -- (XDva403)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\XDva401.sys -- (XDva401)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\XDva400.sys -- (XDva400)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\XDva399.sys -- (XDva399)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\XDva386.sys -- (XDva386)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\XDva359.sys -- (XDva359)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\XDva349.sys -- (XDva349)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\XDva347.sys -- (XDva347)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\XDva346.sys -- (XDva346)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\XDva327.sys -- (XDva327)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\XDva321.sys -- (XDva321)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\XDva317.sys -- (XDva317)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\drivers\EagleXNt.sys -- (EagleXNt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\windows\system32\drivers\EagleNT.sys -- (EagleNT)
DRV - [2014-01-09 15:53:09 | 000,775,952 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2014-01-09 15:53:09 | 000,410,528 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2014-01-09 15:53:09 | 000,180,248 | ---- | M] () [Kernel | Boot | Running] -- C:\windows\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2014-01-09 15:53:09 | 000,057,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2014-01-09 15:53:09 | 000,049,944 | ---- | M] () [Kernel | Boot | Running] -- C:\windows\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2014-01-09 15:53:08 | 000,067,824 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2014-01-09 15:53:08 | 000,054,832 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2013-11-05 21:50:48 | 000,120,600 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgdiskx.sys -- (Avgdiskx)
DRV - [2013-11-04 21:57:30 | 000,209,176 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgidsdriverx.sys -- (AVGIDSDriver)
DRV - [2013-10-31 23:00:28 | 000,176,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2013-10-31 22:30:08 | 000,222,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avglogx.sys -- (Avglogx)
DRV - [2013-10-24 22:28:32 | 000,147,768 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avgidshx.sys -- (AVGIDSHX)
DRV - [2013-10-01 00:49:38 | 000,102,712 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2013-09-17 00:57:26 | 000,022,840 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgidsshimx.sys -- (AVGIDSShim)
DRV - [2013-09-10 00:43:20 | 000,027,448 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avgrkx86.sys -- (Avgrkx86)
DRV - [2013-08-01 16:08:52 | 000,193,848 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2012-08-20 01:54:19 | 000,027,520 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_juextctrl.sys -- (huawei_ext_ctrl)
DRV - [2012-08-20 01:54:18 | 000,096,000 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_jucdcacm.sys -- (huawei_cdcacm)
DRV - [2012-08-20 01:54:18 | 000,076,544 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2012-08-20 01:54:18 | 000,069,760 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_jucdcecm.sys -- (huawei_cdcecm)
DRV - [2012-01-11 22:01:52 | 000,239,168 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2011-05-24 16:30:02 | 000,076,488 | ---- | M] (www.wiselogic.co.kr) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\XDva385.sys -- (XDva385)
DRV - [2010-07-27 02:52:02 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2010-06-14 09:32:54 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2010-03-20 05:06:58 | 000,011,136 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_usbenumfilter.sys -- (ew_usbenumfilter)
DRV - [2010-02-25 01:03:16 | 000,014,904 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CPQBTTN.sys -- (HBtnKey)
DRV - [2009-03-18 16:35:40 | 000,026,176 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2008-09-15 07:56:34 | 000,008,064 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2008-09-15 07:56:24 | 000,022,016 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2008-09-15 07:56:24 | 000,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2008-09-15 07:56:24 | 000,008,064 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2008-08-26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008-07-14 10:22:40 | 000,055,176 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfetdik.sys -- (mfetdik)
DRV - [2008-07-14 10:22:20 | 000,034,152 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MfeRKDK.sys -- (MfeRKDK)
DRV - [2008-07-14 10:21:50 | 000,207,688 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2008-07-14 10:21:34 | 000,035,240 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MfeBOPK.sys -- (MfeBOPK)
DRV - [2008-07-14 10:21:28 | 000,079,240 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MfeAVFK.sys -- (MfeAVFK)
DRV - [2008-02-29 17:13:38 | 001,202,560 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2008-01-21 03:32:52 | 000,045,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tpm.sys -- (TPM)
DRV - [2007-06-19 00:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2007-06-08 16:49:46 | 000,030,008 | ---- | M] (Hewlett-Packard Development Company L.P.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DAMDrv.sys -- (DAMDrv)
DRV - [2007-05-24 15:07:18 | 000,223,616 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express)
DRV - [2006-12-05 11:34:42 | 000,507,136 | ---- | M] (PixArt Imaging Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PFC027.SYS -- (PAC207)
DRV - [2005-08-10 13:44:04 | 000,050,688 | ---- | M] (Protection Technology) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\sfdrv01.sys -- (sfdrv01)
DRV - [2005-05-16 14:20:39 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sfhlp02.sys -- (sfhlp02)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q= {searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{7321541E-F83A-4D84-AF9B-1DCF1814EF82}: "URL" =
http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1602&query= {searchTerms}&invocationType=tb50hpcmnbie7-pl-pl
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1254071835-2048258796-2156354930-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com
IE - HKU\S-1-5-21-1254071835-2048258796-2156354930-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com
IE - HKU\S-1-5-21-1254071835-2048258796-2156354930-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.com/ie
IE - HKU\S-1-5-21-1254071835-2048258796-2156354930-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKU\S-1-5-21-1254071835-2048258796-2156354930-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
IE - HKU\S-1-5-21-1254071835-2048258796-2156354930-1004\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-1254071835-2048258796-2156354930-1004\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie
IE - HKU\S-1-5-21-1254071835-2048258796-2156354930-1004\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie
IE - HKU\S-1-5-21-1254071835-2048258796-2156354930-1004\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-21-1254071835-2048258796-2156354930-1004\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1254071835-2048258796-2156354930-1004\..\SearchScopes\{341F3E29-3AA6-418F-837D-7E51F7FB0B5C}: "URL" =
http://www.google.com/search?q= {searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-1254071835-2048258796-2156354930-1004\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q= {searc}
IE - HKU\S-1-5-21-1254071835-2048258796-2156354930-1004\..\SearchScopes\{7321541E-F83A-4D84-AF9B-1DCF1814EF82}: "URL" =
http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=1602&query= {searchTerms}&invocationType=tb50hpcmnbie7-pl-pl
IE - HKU\S-1-5-21-1254071835-2048258796-2156354930-1004\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A79}: "URL" =
http://search.bearflix.com/webResults.html?src=ieb&q= {searchTerms}
IE - HKU\S-1-5-21-1254071835-2048258796-2156354930-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1254071835-2048258796-2156354930-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.3
FF - prefs.js..extensions.enabledItems: {F2DDDB92-1605-4260-9B25-45A4DAE87B50}:1.0
FF - prefs.js..extensions.enabledItems: {E63605FC-D583-4C81-867F-9457BDB3EA1B}:3.1.0.1840
FF - prefs.js..extensions.enabledItems: {8141440E-08F0-4339-9959-5C31C6A69F23}:4.1.0.5190
FF - prefs.js..extensions.enabledItems: {E889F097-B0BE-471B-89AD-B86B6F04B506}:3.1.0.1630
FF - prefs.js..network.proxy.type: 2
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009-03-15 23:18:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-01-09 15:53:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011-12-25 20:11:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014-01-27 12:57:59 | 000,000,000 | ---D | M]
[2010-01-24 14:31:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Monika\AppData\Roaming\Mozilla\Extensions
[2014-01-31 15:48:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\vghy27vw.default\extensions
[2014-01-31 15:48:03 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Monika\AppData\Roaming\Mozilla\Firefox\Profiles\vghy27vw.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014-02-03 18:04:13 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011-12-21 09:04:06 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012-01-18 17:01:46 | 001,826,704 | ---- | M] (Caminova, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdjvu.dll
[2011-12-21 06:04:32 | 000,002,767 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\allegro-pl.xml
[2011-12-21 06:04:32 | 000,001,406 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fbc-pl.xml
[2011-12-21 06:04:32 | 000,000,917 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\merlin-pl.xml
[2011-12-21 06:04:32 | 000,000,858 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\pwn-pl.xml
[2014-01-07 22:10:54 | 000,000,570 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\sweet-page.xml
[2011-12-21 06:04:32 | 000,001,183 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-pl.xml
[2011-12-21 06:04:32 | 000,001,683 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wp-pl.xml
========== Chrome =========
CHR - default_search_provider: sweet-page (Enabled)
CHR - default_search_provider: search_url =
http://www.google.com
CHR - default_search_provider: suggest_url = ,
CHR - plugin: Widevine Content Decryption Module (Enabled) = C:\Users\Monika\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.1.376\_platform_specific\win_x86\widevinecdmadapter.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Program Files\Google\Chrome\Application\32.0.1700.76\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\32.0.1700.76\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\32.0.1700.76\pdf.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: DjVu Plugin Viewer (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdjvu.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll
CHR - plugin: Java Deployment Toolkit 7.0.450.18 (Enabled) = C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll
CHR - plugin: Java(TM) Platform SE 7 U45 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: McAfee Security Scanner + (Enabled) = C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: avast! Online Security = C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2013.75_0\
CHR - Extension: Google Wallet = C:\Users\Monika\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0\
O1 HOSTS File: ([2004-09-19 12:18:40 | 000,000,001 | ---- | M]) - C:\Windows\System32\drivers\etc\HOSTS
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
O3 - HKLM\..\Toolbar: (avast! Online Security) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKU\S-1-5-21-1254071835-2048258796-2156354930-1004\..\Toolbar\WebBrowser: (no name) - {0388BA0C-C7F1-4E6A-BD7A-B59623F33363} - No CLSID value found.
O3 - HKU\S-1-5-21-1254071835-2048258796-2156354930-1004\..\Toolbar\WebBrowser: (no name) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No CLSID value found.
O3 - HKU\S-1-5-21-1254071835-2048258796-2156354930-1004\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Freecorder FLV Service] "C:\Program Files\Freecorder\FLVSrvc.exe" /run File not found
O4 - HKLM..\Run: [PTHOSTTR] C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog File not found
O4 - HKU\S-1-5-18..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog File not found
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\Zuzia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O8 - Extra context menu item: &Wyszukiwarka na pasku narzędzi AOL - C:\ProgramData\AOL\ieToolbar\resources\pl-PL\local\search.html ()
O8 - Extra context menu item: Wyślij obraz do urządzenia &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Wyślij stronę do urządzenia &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 10.45.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.179.1.62 62.179.1.63
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9134E9CB-EE8A-4756-8E6D-66FE78876A71}: DhcpNameServer = 62.179.1.62 62.179.1.63
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AF590A52-8343-4968-8A83-488A73754F8D}: DhcpNameServer = 62.179.1.62 62.179.1.63
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E70AEDDF-25DB-42B6-97F3-61F5C2EBE907}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\DeviceNP: DllName - (DeviceNP.dll) - DeviceNP.dll (Hewlett-Packard Limited)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Monika\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta z Galerii fotografii systemu Windows.jpg
O24 - Desktop BackupWallPaper: C:\Users\Monika\AppData\Roaming\Microsoft\Windows Photo Gallery\Tapeta z Galerii fotografii systemu Windows.jpg
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{e0befc5d-c916-11e2-af59-002264577ca2}\Shell - "" = AutoRun
O33 - MountPoints2\{e0befc5d-c916-11e2-af59-002264577ca2}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk /p \??\C
O34 - HKLM BootExecute: (autocheck autochk /r \??\D
O34 - HKLM BootExecute: (autocheck autochk /r \??\D
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2014-02-04 22:51:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
[2014-02-04 22:51:02 | 000,000,000 | ---D | C] -- C:\Program Files\CrystalDiskInfo
[2014-02-04 22:46:43 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys
[2014-02-03 17:50:10 | 000,000,000 | ---D | C] -- C:\Users\Monika\AppData\Local\fst_pl_46
[2014-02-03 13:10:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
[2014-02-03 13:10:31 | 000,000,000 | ---D | C] -- C:\Program Files\CPUID
[2014-02-03 13:03:35 | 000,000,000 | ---D | C] -- C:\Program Files\fst_pl_46
[2014-02-03 12:30:41 | 000,000,000 | ---D | C] -- C:\windows\System32\EventProviders
[2014-02-03 12:28:59 | 000,000,000 | ---D | C] -- C:\windows\QLB
[2014-02-03 12:28:27 | 000,000,000 | ---D | C] -- C:\Program Files\LSI SoftModem
[2014-01-31 20:07:42 | 001,554,944 | ---- | C] (HMS
http://hp.vector.co.jp/authors/VA012897/) -- C:\windows\System32\vorbis.acm
[2014-01-31 20:07:26 | 000,000,000 | ---D | C] -- C:\Program Files\DSPRobotics
[2014-01-29 20:33:23 | 000,000,000 | ---D | C] -- C:\Users\Monika\AppData\Local\Macromedia
[2014-01-21 18:48:55 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2014-01-15 15:07:29 | 000,409,600 | ---- | C] (Creative Labs) -- C:\windows\System32\wrap_oal.dll
[2014-01-15 15:07:29 | 000,114,688 | ---- | C] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\windows\System32\OpenAL32.dll
[2014-01-11 15:58:19 | 000,000,000 | ---D | C] -- C:\Users\Monika\Desktop\Artykuły do YEARBOOKA
[2014-01-10 21:53:55 | 000,000,000 | ---D | C] -- C:\Users\Monika\AppData\Roaming\Malwarebytes
[2014-01-10 21:53:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2014-01-10 21:53:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014-01-10 21:53:36 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys
[2014-01-10 21:53:36 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2014-01-10 21:16:01 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014-01-10 20:45:55 | 000,000,000 | ---D | C] -- C:\Users\Monika\Desktop\LITERATURA ANGIELSKA
[2014-01-10 20:42:23 | 000,000,000 | ---D | C] -- C:\Users\Monika\Desktop\DOKUMENTY RODZINNE
[2014-01-10 20:28:50 | 000,000,000 | ---D | C] -- C:\Users\Monika\Desktop\DOKTORAT
[2014-01-10 20:25:59 | 000,000,000 | ---D | C] -- C:\Users\Monika\Desktop\STUDNIÓWKA
[2014-01-10 20:16:48 | 000,000,000 | ---D | C] -- C:\Users\Monika\Desktop\ZDJĘCIA
[2014-01-10 10:51:35 | 000,000,000 | ---D | C] -- C:\Users\Monika\AppData\Roaming\AVAST Software
[2014-01-09 19:51:22 | 000,000,000 | ---D | C] -- C:\Program Files\SystemRequirementsLab
[2014-01-09 16:08:25 | 000,264,616 | ---- | C] (Oracle Corporation) -- C:\windows\System32\javaws.exe
[2014-01-09 16:08:05 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\windows\System32\javaw.exe
[2014-01-09 16:08:05 | 000,174,504 | ---- | C] (Oracle Corporation) -- C:\windows\System32\java.exe
[2014-01-09 16:08:05 | 000,094,632 | ---- | C] (Oracle Corporation) -- C:\windows\System32\WindowsAccessBridge.dll
[2014-01-09 15:54:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
[2014-01-09 15:53:25 | 000,057,672 | ---- | C] (AVAST Software) -- C:\windows\System32\drivers\aswTdi.sys
[2014-01-09 15:53:23 | 000,775,952 | ---- | C] (AVAST Software) -- C:\windows\System32\drivers\aswSnx.sys
[2014-01-09 15:53:23 | 000,410,528 | ---- | C] (AVAST Software) -- C:\windows\System32\drivers\aswSP.sys
[2014-01-09 15:53:22 | 000,067,824 | ---- | C] (AVAST Software) -- C:\windows\System32\drivers\aswMonFlt.sys
[2014-01-09 15:53:21 | 000,054,832 | ---- | C] (AVAST Software) -- C:\windows\System32\drivers\aswRdr.sys
[2014-01-09 15:53:14 | 000,270,240 | ---- | C] (AVAST Software) -- C:\windows\System32\aswBoot.exe
[2014-01-09 15:53:07 | 000,043,152 | ---- | C] (AVAST Software) -- C:\windows\avastSS.scr
[2014-01-09 15:51:02 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2014-01-09 15:44:00 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2014-01-09 14:10:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDirStat
[2014-01-09 14:10:35 | 000,000,000 | ---D | C] -- C:\Program Files\WinDirStat
[2014-01-09 13:52:05 | 000,000,000 | ---D | C] -- C:\Program Files\Executive Software
[2014-01-09 12:43:59 | 000,000,000 | ---D | C] -- C:\windows\Options
[2014-01-07 22:12:41 | 000,000,000 | ---D | C] -- C:\Users\Monika\.android
[2014-01-07 22:12:37 | 000,000,000 | ---D | C] -- C:\Users\Monika\AppData\Local\cache
[2014-01-07 22:12:31 | 000,000,000 | ---D | C] -- C:\Users\Monika\AppData\Roaming\newnext.me
[2014-01-07 22:12:29 | 000,000,000 | ---D | C] -- C:\Users\Monika\AppData\Local\genienext
[2014-01-07 20:29:00 | 000,000,000 | ---D | C] -- C:\ProgramData\EA Core
[2014-01-07 20:28:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Electronic Arts
[2014-01-07 18:58:11 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XAudio2_7.dll
[2014-01-07 18:58:11 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\xactengine3_7.dll
[2014-01-07 18:58:11 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XAPOFX1_5.dll
[2014-01-07 18:58:10 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\D3DCompiler_43.dll
[2014-01-07 18:58:09 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\d3dcsx_43.dll
[2014-01-07 18:58:09 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\d3dx11_43.dll
[2014-01-07 18:58:08 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\D3DX9_43.dll
[2014-01-07 18:58:08 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\d3dx10_43.dll
[2014-01-07 18:58:07 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XAudio2_6.dll
[2014-01-07 18:58:07 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\xactengine3_6.dll
[2014-01-07 18:58:07 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XAPOFX1_4.dll
[2014-01-07 18:58:07 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\X3DAudio1_7.dll
[2014-01-07 18:58:05 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XAudio2_5.dll
[2014-01-07 18:58:05 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\xactengine3_5.dll
[2014-01-07 18:58:04 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\D3DCompiler_42.dll
[2014-01-07 18:58:03 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\d3dcsx_42.dll
[2014-01-07 18:58:03 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\d3dx11_42.dll
[2014-01-07 18:58:02 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\D3DX9_42.dll
[2014-01-07 18:58:02 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\d3dx10_42.dll
[2014-01-07 18:58:00 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\D3DCompiler_41.dll
[2014-01-07 18:58:00 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\d3dx10_41.dll
[2014-01-07 18:57:54 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\D3DX9_41.dll
[2014-01-07 18:57:51 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XAudio2_4.dll
[2014-01-07 18:57:51 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\xactengine3_4.dll
[2014-01-07 18:57:51 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XAPOFX1_3.dll
[2014-01-07 18:57:50 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\X3DAudio1_6.dll
[2014-01-07 18:57:49 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\D3DCompiler_40.dll
[2014-01-07 18:57:49 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\d3dx10_40.dll
[2014-01-07 18:57:47 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\D3DX9_40.dll
[2014-01-07 18:57:46 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XAudio2_3.dll
[2014-01-07 18:57:46 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XAPOFX1_2.dll
[2014-01-07 18:57:45 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\xactengine3_3.dll
[2014-01-07 18:57:45 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\X3DAudio1_5.dll
[2014-01-07 18:57:44 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XAPOFX1_1.dll
[2014-01-07 18:57:43 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XAudio2_2.dll
[2014-01-07 18:57:42 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\D3DCompiler_39.dll
[2014-01-07 18:57:42 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\d3dx10_39.dll
[2014-01-07 18:57:42 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\xactengine3_2.dll
[2014-01-07 18:57:40 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\D3DX9_39.dll
[2014-01-07 18:57:39 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XAudio2_1.dll
[2014-01-07 18:57:39 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XAPOFX1_0.dll
[2014-01-07 18:57:38 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\xactengine3_1.dll
[2014-01-07 18:57:38 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\X3DAudio1_4.dll
[2014-01-07 18:57:37 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\D3DCompiler_38.dll
[2014-01-07 18:57:37 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\d3dx10_38.dll
[2014-01-07 18:57:35 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\D3DX9_38.dll
[2014-01-07 18:57:34 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\XAudio2_0.dll
[2014-01-07 18:57:32 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\xactengine3_0.dll
[2014-01-07 18:57:32 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\X3DAudio1_3.dll
[2014-01-07 18:57:30 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\D3DCompiler_37.dll
[2014-01-07 18:57:30 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\d3dx10_37.dll
[2014-01-07 18:57:28 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\D3DX9_37.dll
[2014-01-07 18:39:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\BioWare
[2002-03-11 10:06:30 | 001,822,520 | ---- | C] (Microsoft Corporation) -- C:\Program Files\instmsiw.exe
[2002-03-11 09:45:04 | 001,708,856 | ---- | C] (Microsoft Corporation) -- C:\Program Files\instmsia.exe
[8 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014-02-05 11:18:23 | 000,001,032 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2014-02-05 11:18:03 | 000,003,216 | ---- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2014-02-05 11:18:03 | 000,003,216 | ---- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2014-02-05 11:17:54 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2014-02-04 23:25:02 | 000,000,012 | ---- | M] () -- C:\windows\bthservsdp.dat
[2014-02-04 23:13:26 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys
[2014-02-04 23:10:08 | 000,001,036 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2014-02-04 22:54:57 | 000,131,258 | ---- | M] () -- C:\Users\Monika\Desktop\S.M.A.R.T.JPG
[2014-02-04 22:47:00 | 000,000,930 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2014-02-04 21:51:56 | 000,035,005 | ---- | M] () -- C:\Users\Monika\Desktop\PRZYPISY ANGIELSKIE.odt
[2014-02-04 21:46:05 | 000,058,968 | ---- | M] () -- C:\Users\Monika\Desktop\YEARBOOK I I WERSJA ANGIELSKA.odt
[2014-02-04 21:44:09 | 000,000,420 | -H-- | M] () -- C:\windows\tasks\User_Feed_Synchronization-{427B0A7B-1357-4AFA-9711-7FB0892DBE10}.job
[2014-02-04 16:43:50 | 000,000,418 | -H-- | M] () -- C:\windows\tasks\User_Feed_Synchronization-{EEB70F66-93B3-4184-897E-95969AAC0154}.job
[2014-02-03 19:27:34 | 000,000,560 | -H-- | M] () -- C:\windows\tasks\Norton Security Scan for Monika.job
[2014-02-03 18:04:21 | 000,000,702 | ---- | M] () -- C:\windows\WININIT.INI
[2014-02-02 22:03:33 | 000,026,284 | ---- | M] () -- C:\Users\Monika\Desktop\GOMBROWICZ.odt
[2014-01-31 20:09:36 | 000,001,781 | ---- | M] () -- C:\Users\Public\Desktop\FL Studio 11.lnk
[2014-01-26 14:39:37 | 000,025,010 | ---- | M] () -- C:\Users\Monika\Desktop\BIBLIOGRAFIA DO ARTYKUŁU.odt
[2014-01-17 17:08:21 | 000,015,800 | ---- | M] () -- C:\Users\Monika\Desktop\Szczecin 1957.odt
[2014-01-15 15:07:29 | 000,409,600 | ---- | M] (Creative Labs) -- C:\windows\System32\wrap_oal.dll
[2014-01-15 15:07:29 | 000,114,688 | ---- | M] (Portions (C) Creative Labs Inc. and NVIDIA Corp.) -- C:\windows\System32\OpenAL32.dll
[2014-01-11 15:57:25 | 000,037,534 | ---- | M] () -- C:\Users\Monika\Desktop\CYTATY ANGIELSKIE Z CONRADA.odt
[2014-01-09 16:07:54 | 000,094,632 | ---- | M] (Oracle Corporation) -- C:\windows\System32\WindowsAccessBridge.dll
[2014-01-09 16:07:51 | 000,264,616 | ---- | M] (Oracle Corporation) -- C:\windows\System32\javaws.exe
[2014-01-09 16:07:51 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\windows\System32\javaw.exe
[2014-01-09 16:07:51 | 000,174,504 | ---- | M] (Oracle Corporation) -- C:\windows\System32\java.exe
[2014-01-09 15:53:09 | 000,775,952 | ---- | M] (AVAST Software) -- C:\windows\System32\drivers\aswSnx.sys
[2014-01-09 15:53:09 | 000,410,528 | ---- | M] (AVAST Software) -- C:\windows\System32\drivers\aswSP.sys
[2014-01-09 15:53:09 | 000,180,248 | ---- | M] () -- C:\windows\System32\drivers\aswVmm.sys
[2014-01-09 15:53:09 | 000,057,672 | ---- | M] (AVAST Software) -- C:\windows\System32\drivers\aswTdi.sys
[2014-01-09 15:53:09 | 000,049,944 | ---- | M] () -- C:\windows\System32\drivers\aswRvrt.sys
[2014-01-09 15:53:08 | 000,067,824 | ---- | M] (AVAST Software) -- C:\windows\System32\drivers\aswMonFlt.sys
[2014-01-09 15:53:08 | 000,054,832 | ---- | M] (AVAST Software) -- C:\windows\System32\drivers\aswRdr.sys
[2014-01-09 15:53:07 | 000,270,240 | ---- | M] (AVAST Software) -- C:\windows\System32\aswBoot.exe
[2014-01-09 15:53:07 | 000,043,152 | ---- | M] (AVAST Software) -- C:\windows\avastSS.scr
[2014-01-09 12:25:43 | 000,010,752 | ---- | M] () -- C:\Users\Monika\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[8 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014-02-04 22:53:26 | 000,131,258 | ---- | C] () -- C:\Users\Monika\Desktop\S.M.A.R.T.JPG
[2014-02-02 15:41:59 | 000,026,284 | ---- | C] () -- C:\Users\Monika\Desktop\GOMBROWICZ.odt
[2014-01-31 20:09:36 | 000,001,781 | ---- | C] () -- C:\Users\Public\Desktop\FL Studio 11.lnk
[2014-01-31 20:08:01 | 000,001,793 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FL Studio 11.lnk
[2014-01-25 18:47:21 | 000,025,010 | ---- | C] () -- C:\Users\Monika\Desktop\BIBLIOGRAFIA DO ARTYKUŁU.odt
[2014-01-11 15:52:05 | 000,037,534 | ---- | C] () -- C:\Users\Monika\Desktop\CYTATY ANGIELSKIE Z CONRADA.odt
[2014-01-09 15:53:24 | 000,180,248 | ---- | C] () -- C:\windows\System32\drivers\aswVmm.sys
[2014-01-09 15:53:22 | 000,049,944 | ---- | C] () -- C:\windows\System32\drivers\aswRvrt.sys
[2013-12-24 18:17:25 | 000,017,920 | ---- | C] () -- C:\windows\System32\wxsmi.dll
[2013-12-24 18:17:23 | 000,484,352 | ---- | C] () -- C:\windows\System32\lame_enc.dll
[2013-12-24 12:50:32 | 000,000,451 | ---- | C] () -- C:\Users\Monika\AppData\Roaming\burnaware.ini
[2013-10-24 12:46:43 | 000,000,702 | ---- | C] () -- C:\windows\WININIT.INI
[2013-09-02 18:57:46 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
[2012-12-30 21:28:20 | 000,161,128 | ---- | C] () -- C:\windows\System32\mlfcache.dat
[2012-07-02 21:11:02 | 000,016,384 | ---- | C] () -- C:\windows\System32\theowl.dll
[2012-01-06 15:47:19 | 000,000,000 | ---- | C] () -- C:\Users\Monika\AppData\Local\{583F2F49-E35D-46B1-8EF4-7FFB3F13D6A2}
[2011-09-08 18:29:44 | 000,000,545 | ---- | C] () -- C:\ProgramData\qcaddemorc
[2011-07-29 22:33:11 | 000,000,032 | R--- | C] () -- C:\ProgramData\hash.dat
[2010-08-18 09:36:06 | 000,000,552 | ---- | C] () -- C:\Users\Monika\AppData\Local\d3d8caps.dat
[2009-10-24 21:17:23 | 000,000,680 | ---- | C] () -- C:\Users\Monika\AppData\Local\d3d9caps.dat
[2009-06-07 14:32:41 | 000,010,752 | ---- | C] () -- C:\Users\Monika\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-02-11 17:08:10 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009-01-09 20:32:14 | 127,549,044 | ---- | C] () -- C:\Program Files\openofficeorg1.cab
[2009-01-09 20:12:44 | 009,777,664 | ---- | C] () -- C:\Program Files\openofficeorg30.msi
[2009-01-09 20:12:44 | 000,000,336 | ---- | C] () -- C:\Program Files\setup.ini
[2008-12-17 11:17:14 | 000,426,776 | ---- | C] () -- C:\Program Files\setup.exe
========== ZeroAccess Check ==========
[2006-11-02 13:51:16 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2011-01-21 16:46:32 | 011,582,464 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009-03-03 05:36:24 | 000,615,424 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008-01-21 03:33:39 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013-01-31 10:27:42 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2013-01-31 10:27:42 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
[2013-12-19 12:21:12 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\AVG2014
[2011-06-25 15:01:05 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\go
[2009-08-29 11:20:56 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\Nokia
[2009-08-29 11:36:23 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\Nowe Gadu-Gadu
[2009-06-19 12:26:31 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\Opera
[2009-06-20 18:35:59 | 000,000,000 | ---D | M] -- C:\Users\Gosia\AppData\Roaming\PC Suite
[2014-01-10 10:51:35 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\AVAST Software
[2013-11-19 19:23:48 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\AVG
[2013-11-19 16:08:35 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\AVG2014
[2013-11-05 15:39:06 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\BitTorrent
[2013-11-05 15:39:10 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\DAEMON Tools Lite
[2013-12-24 18:17:36 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\FreeBurner
[2013-11-06 21:27:47 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\FreeVideoConverter
[2010-09-17 21:25:12 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\Gadu-Gadu 10
[2013-03-02 00:07:44 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\gtk-2.0
[2011-11-28 23:20:52 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\IDoser
[2014-01-10 21:39:58 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\inkscape
[2009-12-02 18:15:15 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\InterVideo
[2013-12-05 13:59:55 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\JTHTML
[2010-02-24 21:54:37 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\maxup
[2014-02-04 23:09:36 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\newnext.me
[2012-07-28 12:22:12 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\Nokia
[2013-12-05 13:20:51 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\Notepad++
[2009-02-14 18:06:35 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\Nowe Gadu-Gadu
[2011-03-19 14:47:31 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\OpenFM
[2009-04-24 19:38:18 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\OpenOffice.org
[2009-02-10 16:57:42 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\Opera
[2012-07-28 12:21:42 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\PC Suite
[2013-08-25 14:01:36 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\Propellerhead Software
[2013-11-19 19:56:32 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\Sony
[2011-12-25 18:58:03 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\StepMania 4
[2011-12-21 22:09:44 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\Tibia
[2013-11-19 16:00:26 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\TuneUp Software
[2009-05-27 17:51:49 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\uTorrent
[2012-09-17 18:33:13 | 000,000,000 | ---D | M] -- C:\Users\Monika\AppData\Roaming\wargaming.net
[2011-09-18 12:43:07 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\.minecraft
[2010-03-25 13:33:08 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\AgerWebEdytor
[2014-01-09 15:59:35 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\AVAST Software
[2013-11-19 19:43:03 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\AVG
[2013-11-19 16:08:41 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\AVG2014
[2013-04-24 21:03:31 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\BESTplayer
[2014-02-04 17:40:06 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\BitTorrent
[2012-12-10 19:42:58 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\Blender Foundation
[2010-10-23 19:56:26 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\Chromeflower
[2010-12-16 22:56:16 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\Clickteam
[2010-10-23 19:56:09 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\CrystalSpace
[2012-07-03 17:46:55 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\DAEMON Tools Lite
[2014-01-31 20:07:27 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\FlowStone
[2011-08-24 14:28:51 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\FOG Downloader
[2013-12-24 18:27:22 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\FreeBurner
[2013-12-24 12:53:22 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\FreeVideoConverter
[2012-10-29 11:09:47 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\Gadu-Gadu 10
[2013-03-02 00:09:21 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\gtk-2.0
[2011-11-29 00:31:19 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\IDoser
[2014-01-31 20:08:09 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\Image-Line
[2013-10-24 13:30:12 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\inkscape
[2009-02-23 18:48:09 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\InterVideo
[2013-12-05 14:00:01 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\JTHTML
[2010-02-23 20:56:58 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\maxup
[2010-06-10 15:34:31 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\Micrografx
[2010-01-03 19:48:52 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\Mount&Blade
[2009-09-10 21:30:46 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\Nokia
[2013-12-07 16:46:42 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\Notepad++
[2010-08-26 11:50:39 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\Nowe Gadu-Gadu
[2011-04-28 17:43:32 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\OpenFM
[2009-04-26 20:19:28 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\OpenOffice.org
[2009-02-13 19:17:11 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\Opera
[2012-08-23 23:20:30 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\PC Suite
[2013-01-06 16:18:21 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\QuickScan
[2011-12-25 19:36:44 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\StepMania 4
[2011-12-25 18:12:29 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\StepMania 5
[2013-12-23 21:47:25 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\Tibia
[2013-11-19 16:14:00 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\TuneUp Software
[2014-01-09 12:43:48 | 000,000,000 | ---D | M] -- C:\Users\Zuzia\AppData\Roaming\uTorrent
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:6BE50C2B
< End of report >