Skocz do zawartości

Zarchiwizowany

Ten temat jest archiwizowany i nie można dodawać nowych odpowiedzi.

vanity

Śmieci w przeglądarce oraz dziwne wirusy.

Polecane posty

Witam, otóż kilka dni temu gdy byłem w trakcie gry w Dota 2 wyskoczyło mi okienko czy chcę zmienić domyślną wyszukiwarką. Kliknąłęm cancel bo nie wiedziałem o co chodzi. Później gdy wszedłem w Google Chrome okazało się, że jako stronę startową otwiera mi sie witryna delta-homes.com. Zacząłęm usuwać programy Delta Toolbar i Delta Search (bodajże) lecz mimo tego strona nadal została. Pozmieniałem stronę główną, co ma się otwierać po otwarciu przeglądarki i wyczyściłęm całą historię, lecz problem nadal pozostał. Przeskanowałem komputer SpyHunterem, który znalazł problem (lecz nie mogłęm nic z tym zrobić, trzeba było zapłacić), MalwareBytesem który nie znalazł nic oraz Ad-Awarem który znalazł parę zainfekowanych plików i je usunął. Teraz skanuje komputer AVG lecz ten nic nie znalazł. Dodatkowo, jeden z wirusów wrzucał moim znajomym na facebooku dziwne śmieci. Słyszałem jeszcze o programach adwblocker i OTL lecz nie potrafię się za bardzo nimi posługiwać. Mam Windows 7.

Link do komentarza
Udostępnij na innych stronach

Walczyłem z tym od 3 dni. Używałem Junkware Removal Tool, który niby usunął logi tego malvare'a, ale wyszukiwarce pozostał delta-home jako domyślna witryna, chociaż robiłem to co Ty. Pomogło dopiero odinstalowanie Chrome i zainstalowanie ponownie.

Link do komentarza
Udostępnij na innych stronach

Przeskanowałem AVG, który znalazł 14 zagrożeń, usnąłem, MalwareBytes nie znalazł nic a Dr. Web CureIT znalazł 2 które zaraz usnąłem. Nadal delta-homes zostało więc przeinstalowałem Chrome i wszystko wyświetla się poprawnie. Zaraz zabieram się za skanowanie po raz drugi, tak dla pewności. :P

Tutaj jeszcze log z OTL:

OTL logfile created on: 2013-07-08 12:39:26 - Run 2

OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Kuba\Downloads

64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.7600.16385)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

7,96 Gb Total Physical Memory | 5,81 Gb Available Physical Memory | 72,96% Memory free

15,93 Gb Paging File | 13,32 Gb Available in Paging File | 83,64% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 390,62 Gb Total Space | 183,52 Gb Free Space | 46,98% Space Free | Partition Type: NTFS

Drive D: | 75,04 Gb Total Space | 48,09 Gb Free Space | 64,09% Space Free | Partition Type: NTFS

Drive E: | 3,20 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: KUBA-PC | User Name: Kuba | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013-07-08 12:31:19 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Kuba\Downloads\OTL.exe

PRC - [2013-07-08 12:26:44 | 000,059,964 | ---- | M] (Macrovision Europe Ltd.) -- C:\Users\Kuba\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001

PRC - [2013-07-06 17:38:14 | 001,104,384 | ---- | M] (Spotify Ltd) -- C:\Users\Kuba\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe

PRC - [2013-07-05 01:00:29 | 000,239,496 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.21.149\GoogleCrashHandler.exe

PRC - [2013-06-15 03:28:44 | 000,825,808 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

PRC - [2013-06-07 00:06:24 | 001,641,896 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Steam\Steam.exe

PRC - [2013-06-07 00:06:24 | 000,543,656 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe

PRC - [2013-06-02 20:55:53 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe

PRC - [2013-05-28 15:05:16 | 000,163,328 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

PRC - [2013-05-08 22:18:22 | 004,284,976 | ---- | M] () -- C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe

PRC - [2013-05-08 21:54:19 | 000,079,360 | ---- | M] (Creative Labs) -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe

PRC - [2013-05-08 21:52:05 | 004,942,336 | ---- | M] (FNet Co., Ltd.) -- C:\Program Files (x86)\XFastUsb\XFastUsb.exe

PRC - [2013-03-15 07:53:06 | 001,266,464 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

PRC - [2013-03-14 22:07:46 | 000,383,264 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

PRC - [2012-12-11 03:52:44 | 003,147,384 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgui.exe

PRC - [2012-12-10 11:11:44 | 001,342,024 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgfws.exe

PRC - [2012-11-15 23:34:30 | 005,814,904 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe

PRC - [2012-10-22 13:05:08 | 000,196,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe

PRC - [2012-06-28 17:40:52 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\Winamp\winampa.exe

PRC - [2009-07-14 03:14:35 | 000,178,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\schtasks.exe

PRC - [2009-07-08 15:32:50 | 001,233,195 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe

PRC - [2009-05-04 19:05:04 | 000,241,789 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe

PRC - [2009-02-23 05:43:56 | 000,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe

PRC - [2007-04-30 03:03:00 | 000,032,768 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\V0330Mon.exe

========== Modules (No Company Name) ==========

MOD - [2013-07-08 12:26:45 | 000,592,896 | ---- | M] () -- C:\Users\Kuba\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0000\~de6248.tmp

MOD - [2013-07-08 12:26:44 | 000,697,884 | ---- | M] () -- C:\Users\Kuba\AppData\Local\Temp\Sound_Blaster_X-Fi_MB_Cleanup.0001.dir.0000\~df394b.tmp

MOD - [2013-06-15 03:28:42 | 000,393,168 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll

MOD - [2013-06-15 03:28:41 | 013,140,432 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll

MOD - [2013-06-15 03:28:40 | 004,051,408 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll

MOD - [2013-06-15 03:27:51 | 000,599,504 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\libglesv2.dll

MOD - [2013-06-15 03:27:50 | 000,124,368 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\libegl.dll

MOD - [2013-06-15 03:27:48 | 001,597,392 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ffmpegsumo.dll

MOD - [2013-06-07 00:06:24 | 001,114,536 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\chromehtml.DLL

MOD - [2013-05-08 22:18:22 | 004,284,976 | ---- | M] () -- C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe

MOD - [2013-05-07 03:05:20 | 000,654,848 | ---- | M] () -- C:\Program Files (x86)\Steam\SDL2.dll

MOD - [2013-03-27 02:16:40 | 020,341,672 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\libcef.dll

MOD - [2012-12-11 19:51:10 | 001,100,800 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avcodec-53.dll

MOD - [2012-12-11 19:51:10 | 000,192,000 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avformat-53.dll

MOD - [2012-12-11 19:51:10 | 000,124,416 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avutil-51.dll

MOD - [2011-03-17 00:11:16 | 004,297,568 | ---- | M] () -- C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf

MOD - [2009-04-20 11:55:58 | 000,148,480 | ---- | M] () -- C:\Windows\SysWOW64\APOMngr.DLL

MOD - [2009-02-06 18:52:24 | 000,073,728 | ---- | M] () -- C:\Windows\SysWOW64\CmdRtr.DLL

========== Services (SafeList) ==========

SRV:64bit: - [2009-07-14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2009-07-14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)

SRV - [2013-07-07 10:26:58 | 001,737,728 | ---- | M] (Lavasoft Limited ) [On_Demand | Stopped] -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)

SRV - [2013-06-07 00:06:24 | 000,543,656 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)

SRV - [2013-06-03 16:21:54 | 000,162,408 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)

SRV - [2013-06-02 20:55:53 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)

SRV - [2013-05-28 15:05:16 | 000,163,328 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013-05-08 21:55:30 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service)

SRV - [2013-05-08 21:55:05 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)

SRV - [2013-05-08 21:54:19 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe -- (Sound Blaster X-Fi MB Licensing Service)

SRV - [2013-03-15 07:53:06 | 001,266,464 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)

SRV - [2013-03-14 22:07:46 | 000,383,264 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)

SRV - [2012-12-10 11:11:44 | 001,342,024 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2013\avgfws.exe -- (avgfws)

SRV - [2012-11-15 23:34:30 | 005,814,904 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe -- (AVGIDSAgent)

SRV - [2012-10-22 13:05:08 | 000,196,664 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe -- (avgwd)

SRV - [2009-06-10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2009-02-23 05:43:56 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)

========== Driver Services (SafeList) ==========

DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys -- (esgiguard)

DRV:64bit: - [2013-05-26 14:50:29 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)

DRV:64bit: - [2013-05-09 21:32:23 | 000,031,808 | ---- | M] (FNet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\FNETTBOH_305.SYS -- (FNETTBOH_305)

DRV:64bit: - [2013-05-08 21:52:05 | 000,015,936 | ---- | M] (FNet Co., Ltd.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\FNETURPX.SYS -- (FNETURPX)

DRV:64bit: - [2013-03-14 14:36:18 | 000,017,160 | ---- | M] (XFire) [File_System | On_Demand | Stopped] -- C:\Program Files\Xfire2\XFDriver64.sys -- (XFDriver64)

DRV:64bit: - [2012-12-19 07:41:52 | 000,194,488 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)

DRV:64bit: - [2012-11-15 23:33:24 | 000,111,968 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)

DRV:64bit: - [2012-10-22 13:02:44 | 000,154,464 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)

DRV:64bit: - [2012-10-15 03:48:50 | 000,063,328 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)

DRV:64bit: - [2012-10-02 03:30:38 | 000,185,696 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)

DRV:64bit: - [2012-09-21 03:46:04 | 000,200,032 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)

DRV:64bit: - [2012-09-21 03:46:00 | 000,225,120 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\avgloga.sys -- (Avgloga)

DRV:64bit: - [2012-09-14 03:05:18 | 000,040,800 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)

DRV:64bit: - [2012-09-04 10:39:32 | 000,050,296 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgfwd6a.sys -- (Avgfwfd)

DRV:64bit: - [2011-02-28 12:10:42 | 000,069,376 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\Lbd.sys -- (Lbd)

DRV:64bit: - [2011-02-08 07:30:52 | 000,064,512 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronXHCI.sys -- (EtronXHCI)

DRV:64bit: - [2011-02-08 07:30:52 | 000,039,936 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronHub3.sys -- (EtronHub3)

DRV:64bit: - [2010-10-19 16:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)

DRV:64bit: - [2010-06-23 11:10:56 | 000,344,680 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2010-06-11 14:37:14 | 000,015,368 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\AsrAppCharger.sys -- (AsrAppCharger)

DRV:64bit: - [2009-07-14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)

DRV:64bit: - [2009-07-14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)

DRV:64bit: - [2009-07-14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009-07-14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009-07-14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2009-07-14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2009-07-14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)

DRV:64bit: - [2009-07-14 02:01:09 | 000,679,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xnacc.sys -- (xnacc)

DRV:64bit: - [2009-06-10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)

DRV:64bit: - [2009-06-10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009-06-10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009-06-10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2007-08-08 07:47:16 | 000,193,312 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\V0330Vid.sys -- (V0330VID)

DRV - [2011-02-28 12:10:43 | 000,017,152 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys -- (Lavasoft Kernexplorer)

DRV - [2009-07-14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =

IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com

IE - HKLM\..\SearchScopes,DefaultScope =

IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-4209167755-2773275170-760808377-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com

IE - HKU\S-1-5-21-4209167755-2773275170-760808377-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com

IE - HKU\S-1-5-21-4209167755-2773275170-760808377-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKU\S-1-5-21-4209167755-2773275170-760808377-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKU\S-1-5-21-4209167755-2773275170-760808377-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-4209167755-2773275170-760808377-1003\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-4209167755-2773275170-760808377-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKU\S-1-5-21-4209167755-2773275170-760808377-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)

FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.4: C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll (ESN Social Software AB)

FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)

FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)

FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)

FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

[2013-05-26 14:51:41 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions

========== Chrome ==========

CHR - default_search_provider: google.com (Enabled)

CHR - default_search_provider: search_url = http://www.google.pl/search?q={searchTerms}

CHR - default_search_provider: suggest_url = ,

CHR - homepage: http://www.google.com/

CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll

CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll

CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll

CHR - plugin: ESN Sonar API (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll

CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll

CHR - plugin: Java Platform SE 7 U25 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll

CHR - plugin: Java Deployment Toolkit 7.0.250.16 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll

CHR - Extension: Dokumenty Google = C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\

CHR - Extension: Dokumenty Google = C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\

CHR - Extension: Dysk Google = C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\

CHR - Extension: Dysk Google = C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\

CHR - Extension: YouTube = C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\

CHR - Extension: YouTube = C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\

CHR - Extension: Szukaj w Google = C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\

CHR - Extension: Szukaj w Google = C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\

CHR - Extension: Google Chrome to Phone Extension = C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco\2.3.1_0\

CHR - Extension: Gmail = C:\Users\Kuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009-06-10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts

O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)

O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)

O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)

O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)

O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)

O4:64bit: - HKLM..\Run: [RunDLLEntry] C:\Windows\SysNative\AmbRunE.DLL (Creative Technology Ltd.)

O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)

O4 - HKLM..\Run: [CTSyncService] C:\Program Files (x86)\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe (Creative Technology Ltd)

O4 - HKLM..\Run: [updReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)

O4 - HKLM..\Run: [V0330Mon.exe] C:\Windows\V0330Mon.exe (Creative Technology Ltd.)

O4 - HKLM..\Run: [VolPanel] C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe (Creative Technology Ltd)

O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)

O4 - HKLM..\Run: [XFastUsb] C:\Program Files (x86)\XFastUsb\XFastUsb.exe (FNet Co., Ltd.)

O4 - HKU\S-1-5-19..\Run: [sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)

O4 - HKU\S-1-5-20..\Run: [sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)

O4 - HKU\S-1-5-21-4209167755-2773275170-760808377-1000..\Run: [ASRockXTU] File not found

O4 - HKU\S-1-5-21-4209167755-2773275170-760808377-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (Disc Soft Ltd)

O4 - HKU\S-1-5-21-4209167755-2773275170-760808377-1000..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()

O4 - HKU\S-1-5-21-4209167755-2773275170-760808377-1000..\Run: [spotify Web Helper] C:\Users\Kuba\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)

O4 - HKU\S-1-5-21-4209167755-2773275170-760808377-1000..\Run: [steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)

O4 - HKU\S-1-5-21-4209167755-2773275170-760808377-1000..\Run: [zASRockInstantBoot] File not found

O4 - HKU\S-1-5-21-4209167755-2773275170-760808377-1003..\Run: [ASRockXTU] File not found

O4 - HKU\S-1-5-21-4209167755-2773275170-760808377-1003..\Run: [bitTorrent] C:\Users\Kuba\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc.)

O4 - HKU\S-1-5-21-4209167755-2773275170-760808377-1003..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()

O4 - HKU\S-1-5-21-4209167755-2773275170-760808377-1003..\Run: [sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)

O4 - HKU\S-1-5-21-4209167755-2773275170-760808377-1003..\Run: [steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)

O4 - HKU\S-1-5-21-4209167755-2773275170-760808377-1003..\Run: [zASRockInstantBoot] File not found

O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found

O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found

O4 - HKU\S-1-5-21-4209167755-2773275170-760808377-1003..\RunOnce: [CTAutoUpdate] C:\Program Files (x86)\Creative\Shared Files\Software Update\AutoUpdate.exe (Creative Technology Ltd)

O4 - HKU\S-1-5-21-4209167755-2773275170-760808377-1003..\RunOnce: [inetReg] C:\Program Files (x86)\Creative\Product Registration\English\InetReg.exe (Creative Technology Ltd)

O4 - HKU\S-1-5-21-4209167755-2773275170-760808377-1003..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found

O4 - Startup: C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3

O1364bit: - gopher Prefix: missing

O13 - gopher Prefix: missing

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5C2E82B5-E543-4822-AA02-672486DF2986}: DhcpNameServer = 192.168.1.254

O18:64bit: - Protocol\Handler\skype4com - No CLSID value found

O18 - Protocol\Handler\ms-help - No CLSID value found

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2013-07-05 12:51:19 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]

O32 - AutoRun File - [2007-10-23 20:33:15 | 000,000,066 | R--- | M] () - E:\autorun.inf -- [ CDFS ]

O33 - MountPoints2\{4516ab03-b817-11e2-af7a-806e6f6e6963}\Shell - "" = AutoRun

O33 - MountPoints2\{4516ab03-b817-11e2-af7a-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Setup.exe -- [2007-11-01 23:24:27 | 000,062,976 | R--- | M] (Aspyr Media, Inc.)

O34 - HKLM BootExecute: (autocheck autochk *)

O34 - HKLM BootExecute: (lsdelete)

O35:64bit: - HKLM\..comfile [open] -- "%1" %*

O35:64bit: - HKLM\..exefile [open] -- "%1" %*

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*

O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013-07-08 12:34:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome

[2013-07-07 22:52:16 | 000,000,000 | ---D | C] -- C:\Users\Kuba\Doctor Web

[2013-07-07 22:39:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware

[2013-07-07 22:39:05 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys

[2013-07-07 22:39:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware

[2013-07-07 11:23:21 | 000,000,000 | ---D | C] -- C:\Users\Kuba\AppData\Roaming\AVG2013

[2013-07-07 11:00:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG

[2013-07-07 11:00:13 | 000,000,000 | ---D | C] -- C:\Users\Kuba\AppData\Roaming\TuneUp Software

[2013-07-07 10:59:44 | 000,000,000 | -H-D | C] -- C:\$AVG

[2013-07-07 10:59:42 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2013

[2013-07-07 10:59:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG

[2013-07-07 10:56:43 | 000,000,000 | ---D | C] -- C:\Users\Kuba\AppData\Local\MFAData

[2013-07-07 10:56:43 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData

[2013-07-07 10:56:43 | 000,000,000 | ---D | C] -- C:\Users\Kuba\AppData\Local\Avg2013

[2013-07-07 10:56:36 | 000,000,000 | --SD | C] -- C:\Windows\SysWow64\Microsoft

[2013-07-07 10:28:23 | 000,069,376 | ---- | C] (Lavasoft AB) -- C:\Windows\SysNative\drivers\Lbd.sys

[2013-07-07 10:28:23 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE

[2013-07-07 10:28:15 | 000,055,384 | ---- | C] (Sunbelt Software) -- C:\Windows\SysNative\drivers\SBREDrv.sys

[2013-07-07 10:16:08 | 000,000,000 | ---D | C] -- C:\Users\Kuba\AppData\Local\Sunbelt Software

[2013-07-07 10:15:55 | 000,000,000 | -H-D | C] -- C:\ProgramData\{48F52499-ADE3-4774-9621-FB173785947D}

[2013-07-07 10:15:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft

[2013-07-07 10:15:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft

[2013-07-07 10:15:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lavasoft

[2013-07-06 16:24:22 | 000,000,000 | ---D | C] -- C:\Users\Kuba\Documents\My Games

[2013-07-06 16:24:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Steam

[2013-07-05 22:02:07 | 000,000,000 | ---D | C] -- C:\Users\Kuba\AppData\Roaming\MKKE

[2013-07-05 22:01:30 | 000,000,000 | ---D | C] -- C:\Users\Kuba\AppData\Local\SKIDROW

[2013-07-05 21:10:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mortal Kombat Komplete Edition

[2013-07-05 21:05:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mortal Kombat Komplete Edition

[2013-07-05 13:16:59 | 000,000,000 | ---D | C] -- C:\Users\Kuba\AppData\Roaming\Malwarebytes

[2013-07-05 13:16:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes

[2013-07-05 12:50:16 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group

[2013-07-05 12:49:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard

[2013-07-04 23:55:57 | 000,000,000 | ---D | C] -- C:\Users\Kuba\Desktop\Donnie Darko DIRECTORS CUT (2001) [1080p]

[2013-07-02 21:27:32 | 000,000,000 | ---D | C] -- C:\Users\Kuba\Desktop\Walt Disney`s Pocahontas-1995 720p BDRip x264 Ac3 5.1 mp4 Sub[X@720]

[2013-07-02 21:26:26 | 000,000,000 | ---D | C] -- C:\Users\Kuba\Desktop\Hercules.1997.720p.HDTV.DD5.1.x264-CtrlHD

[2013-07-02 01:17:19 | 000,000,000 | ---D | C] -- C:\Users\Kuba\Desktop\Aladdin 1992 1080p BDRip H264 AAC - KiNGDOM

[2013-06-30 22:08:19 | 000,000,000 | ---D | C] -- C:\Users\Kuba\AppData\Roaming\TS3Client

[2013-06-30 22:07:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client

[2013-06-30 22:07:41 | 000,000,000 | ---D | C] -- C:\Program Files\TeamSpeak 3 Client

[2013-06-30 21:43:50 | 000,000,000 | ---D | C] -- C:\Users\Kuba\Desktop\Dexter Season 3

[2013-06-29 15:36:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mumble

[2013-06-29 15:36:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mumble

[2013-06-29 11:56:00 | 000,000,000 | ---D | C] -- C:\Users\Kuba\AppData\Roaming\LolClient

[2013-06-26 11:31:19 | 000,000,000 | ---D | C] -- C:\Users\Kuba\Documents\Overclocked Savegames

[2013-06-26 00:08:47 | 000,000,000 | ---D | C] -- C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games

[2013-06-25 23:58:44 | 000,000,000 | ---D | C] -- C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Anaconda

[2013-06-25 23:58:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anaconda

[2013-06-25 23:57:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Anaconda

[2013-06-25 23:56:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Psychonauts

[2013-06-25 23:50:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Double Fine Productions

[2013-06-25 14:37:10 | 000,000,000 | ---D | C] -- C:\Users\Kuba\Documents\Aspyr

[2013-06-25 14:37:10 | 000,000,000 | ---D | C] -- C:\Users\Kuba\AppData\Local\Aspyr

[2013-06-25 14:36:50 | 000,000,000 | RH-D | C] -- C:\Users\Kuba\AppData\Roaming\SecuROM

[2013-06-25 14:30:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Aspyr

[2013-06-23 16:28:27 | 000,163,328 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerUpdateService.exe

[2013-06-23 16:27:45 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed

[2013-06-21 17:04:12 | 000,000,000 | ---D | C] -- C:\Users\Kuba\Desktop\marta muzyka

[2013-06-21 16:14:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun

[2013-06-21 16:14:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java

[2013-06-21 16:14:37 | 000,789,416 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll

[2013-06-21 16:14:36 | 000,867,240 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll

[2013-06-21 16:14:36 | 000,263,592 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe

[2013-06-21 16:14:33 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe

[2013-06-21 16:14:33 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe

[2013-06-21 16:14:33 | 000,096,168 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll

[2013-06-21 16:14:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java

[2013-06-19 19:47:01 | 000,000,000 | ---D | C] -- C:\Users\Kuba\AppData\Roaming\runic games

[2013-06-18 20:16:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com

[2013-06-18 20:16:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GOG.com

[2013-06-15 20:00:21 | 000,000,000 | ---D | C] -- C:\Users\Kuba\AppData\Local\Spotify

[2013-06-15 19:59:40 | 000,000,000 | ---D | C] -- C:\Users\Kuba\AppData\Roaming\Spotify

[2013-06-14 12:11:43 | 000,000,000 | ---D | C] -- C:\Users\Kuba\AppData\Roaming\Curse Advertising

[2013-06-14 12:11:40 | 000,000,000 | ---D | C] -- C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Curse

[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013-07-08 12:34:30 | 000,002,279 | ---- | M] () -- C:\Users\Kuba\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

[2013-07-08 12:34:17 | 000,002,255 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk

[2013-07-08 12:28:46 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

[2013-07-08 12:28:46 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

[2013-07-08 12:23:44 | 000,001,040 | ---- | M] () -- C:\Windows asks\GoogleUpdateTaskMachineCore.job

[2013-07-08 12:23:40 | 2119,036,927 | -HS- | M] () -- C:\hiberfil.sys

[2013-07-08 12:23:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2013-07-08 12:05:09 | 000,001,132 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat

[2013-07-08 12:05:00 | 000,001,044 | ---- | M] () -- C:\Windows asks\GoogleUpdateTaskMachineUA.job

[2013-07-08 10:58:00 | 001,523,412 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI

[2013-07-08 10:58:00 | 000,687,574 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat

[2013-07-08 10:58:00 | 000,606,992 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat

[2013-07-08 10:58:00 | 000,131,160 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat

[2013-07-08 10:58:00 | 000,103,370 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat

[2013-07-07 22:39:08 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

[2013-07-07 22:07:36 | 000,000,408 | ---- | M] () -- C:\Windows asks\Ad-Aware Update (Weekly).job

[2013-07-07 11:00:14 | 000,000,995 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2013.lnk

[2013-07-07 10:28:46 | 000,000,064 | ---- | M] () -- C:\Windows\SysWow64\rp_stats.dat

[2013-07-07 10:28:46 | 000,000,044 | ---- | M] () -- C:\Windows\SysWow64\rp_rules.dat

[2013-07-07 10:28:12 | 000,055,384 | ---- | M] (Sunbelt Software) -- C:\Windows\SysNative\drivers\SBREDrv.sys

[2013-07-07 10:28:02 | 000,016,432 | ---- | M] () -- C:\Windows\SysNative\lsdelete.exe

[2013-07-07 10:15:55 | 000,001,166 | ---- | M] () -- C:\Users\Kuba\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk

[2013-07-07 10:15:55 | 000,001,142 | ---- | M] () -- C:\Users\Public\Desktop\Ad-Aware.lnk

[2013-07-06 11:38:25 | 000,001,303 | ---- | M] () -- C:\Users\Kuba\Desktop\MKKE ? skrót.lnk

[2013-07-05 12:51:19 | 000,000,000 | ---- | M] () -- C:\autoexec.bat

[2013-07-04 12:00:36 | 000,001,701 | ---- | M] () -- C:\Users\Kuba\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

[2013-06-30 22:07:43 | 000,000,967 | ---- | M] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk

[2013-06-25 23:56:03 | 000,001,279 | ---- | M] () -- C:\Users\Kuba\Desktop\Play Psychonauts.lnk

[2013-06-25 14:34:48 | 000,001,103 | ---- | M] () -- C:\Users\Public\Desktop\Play Guitar Hero III.lnk

[2013-06-24 17:35:59 | 572,075,448 | ---- | M] () -- C:\Users\Kuba\Desktop\Saturday.Night.Live.S38E19.Zach.Galifianakis.HDTV.x264-2HD.mp4

[2013-06-24 17:31:42 | 576,061,051 | ---- | M] () -- C:\Users\Kuba\Desktop\Saturday.Night.Live.S38E03.Daniel.Craig-Muse.HDTV.x264-2HD.mp4

[2013-06-21 16:14:24 | 000,096,168 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll

[2013-06-21 16:14:22 | 000,867,240 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll

[2013-06-21 16:14:22 | 000,789,416 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll

[2013-06-21 16:14:22 | 000,263,592 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe

[2013-06-21 16:14:22 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe

[2013-06-21 16:14:22 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe

[2013-06-18 20:16:21 | 000,002,053 | ---- | M] () -- C:\Users\Public\Desktop\Torchlight.lnk

[2013-06-15 20:00:20 | 000,001,799 | ---- | M] () -- C:\Users\Kuba\Desktop\Spotify.lnk

[2013-06-14 13:23:20 | 000,000,219 | ---- | M] () -- C:\Users\Kuba\Desktop\Left 4 Dead 2.url

[2013-06-14 12:11:43 | 000,000,000 | ---- | M] () -- C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip

[2013-06-14 12:11:40 | 000,000,318 | ---- | M] () -- C:\Users\Kuba\Desktop\Curse Client.appref-ms

[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013-07-08 12:34:17 | 000,002,279 | ---- | C] () -- C:\Users\Kuba\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

[2013-07-08 12:34:17 | 000,002,255 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk

[2013-07-07 22:39:08 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

[2013-07-07 11:32:27 | 000,000,408 | ---- | C] () -- C:\Windows asks\Ad-Aware Update (Weekly).job

[2013-07-07 11:00:13 | 000,000,995 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2013.lnk

[2013-07-07 10:36:13 | 000,016,432 | ---- | C] () -- C:\Windows\SysNative\lsdelete.exe

[2013-07-07 10:28:46 | 000,000,064 | ---- | C] () -- C:\Windows\SysWow64\rp_stats.dat

[2013-07-07 10:28:46 | 000,000,044 | ---- | C] () -- C:\Windows\SysWow64\rp_rules.dat

[2013-07-07 10:15:55 | 000,001,166 | ---- | C] () -- C:\Users\Kuba\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk

[2013-07-07 10:15:55 | 000,001,142 | ---- | C] () -- C:\Users\Public\Desktop\Ad-Aware.lnk

[2013-07-05 12:51:19 | 000,000,000 | ---- | C] () -- C:\autoexec.bat

[2013-07-04 12:28:28 | 000,001,132 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat

[2013-06-30 22:07:43 | 000,000,967 | ---- | C] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk

[2013-06-25 23:56:03 | 000,001,279 | ---- | C] () -- C:\Users\Kuba\Desktop\Play Psychonauts.lnk

[2013-06-25 14:34:48 | 000,001,103 | ---- | C] () -- C:\Users\Public\Desktop\Play Guitar Hero III.lnk

[2013-06-24 17:22:11 | 572,075,448 | ---- | C] () -- C:\Users\Kuba\Desktop\Saturday.Night.Live.S38E19.Zach.Galifianakis.HDTV.x264-2HD.mp4

[2013-06-24 17:22:07 | 576,061,051 | ---- | C] () -- C:\Users\Kuba\Desktop\Saturday.Night.Live.S38E03.Daniel.Craig-Muse.HDTV.x264-2HD.mp4

[2013-06-18 20:16:21 | 000,002,053 | ---- | C] () -- C:\Users\Public\Desktop\Torchlight.lnk

[2013-06-15 20:00:20 | 000,001,799 | ---- | C] () -- C:\Users\Kuba\Desktop\Spotify.lnk

[2013-06-15 20:00:20 | 000,001,785 | ---- | C] () -- C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk

[2013-06-14 13:23:20 | 000,000,219 | ---- | C] () -- C:\Users\Kuba\Desktop\Left 4 Dead 2.url

[2013-06-14 12:11:43 | 000,000,000 | ---- | C] () -- C:\Users\Kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip

[2013-06-14 12:11:40 | 000,000,318 | ---- | C] () -- C:\Users\Kuba\Desktop\Curse Client.appref-ms

[2013-05-25 18:19:08 | 000,282,512 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe

[2013-05-25 18:19:07 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe

[2013-05-08 22:23:56 | 000,178,688 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll

[2013-05-08 21:55:46 | 000,002,265 | ---- | C] () -- C:\Windows\FF08_Render_Spk_Hp.ini

[2013-05-08 21:55:46 | 000,001,650 | ---- | C] () -- C:\Windows\FF08_Capture.ini

[2013-05-08 21:55:46 | 000,001,540 | ---- | C] () -- C:\Windows\FF08_Render.ini

[2013-05-08 21:55:35 | 000,148,480 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL

[2013-05-08 21:55:35 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL

[2012-12-28 23:04:22 | 000,036,352 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll

========== ZeroAccess Check ==========

[2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

"" = C:\Windows\SysNative\shell32.dll -- [2009-07-14 03:41:54 | 014,161,920 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

"" = %SystemRoot%\system32\shell32.dll -- [2009-07-14 03:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64

"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]

"" = %systemroot%\system32\wbem\fastprox.dll -- [2009-07-14 03:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64

"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013-07-07 11:23:21 | 000,000,000 | ---D | M] -- C:\Users\Kuba\AppData\Roaming\AVG2013

[2013-07-06 18:59:34 | 000,000,000 | ---D | M] -- C:\Users\Kuba\AppData\Roaming\BitTorrent

[2013-06-14 12:12:37 | 000,000,000 | ---D | M] -- C:\Users\Kuba\AppData\Roaming\Curse Advertising

[2013-05-26 14:51:22 | 000,000,000 | ---D | M] -- C:\Users\Kuba\AppData\Roaming\DAEMON Tools Lite

[2013-06-29 11:56:00 | 000,000,000 | ---D | M] -- C:\Users\Kuba\AppData\Roaming\LolClient

[2013-05-26 13:12:53 | 000,000,000 | ---D | M] -- C:\Users\Kuba\AppData\Roaming\OpenOffice.org

[2013-06-17 15:58:32 | 000,000,000 | ---D | M] -- C:\Users\Kuba\AppData\Roaming\Origin

[2013-06-19 19:47:01 | 000,000,000 | ---D | M] -- C:\Users\Kuba\AppData\Roaming\runic games

[2013-07-08 01:38:22 | 000,000,000 | ---D | M] -- C:\Users\Kuba\AppData\Roaming\Spotify

[2013-06-30 22:27:06 | 000,000,000 | ---D | M] -- C:\Users\Kuba\AppData\Roaming\TS3Client

[2013-07-07 11:00:13 | 000,000,000 | ---D | M] -- C:\Users\Kuba\AppData\Roaming\TuneUp Software

[2013-05-08 23:12:06 | 000,000,000 | ---D | M] -- C:\Users\Kuba\AppData\Roaming\Ubisoft

[2013-05-08 23:12:11 | 000,000,000 | -HSD | M] -- C:\Users\Kuba\AppData\Roaming\wyUpdate AU

========== Purity Check ==========

< End of report >

A to extras:

OTL Extras logfile created on: 2013-07-08 12:39:26 - Run 2

OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Kuba\Downloads

64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.7600.16385)

Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

7,96 Gb Total Physical Memory | 5,81 Gb Available Physical Memory | 72,96% Memory free

15,93 Gb Paging File | 13,32 Gb Available in Paging File | 83,64% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 390,62 Gb Total Space | 183,52 Gb Free Space | 46,98% Space Free | Partition Type: NTFS

Drive D: | 75,04 Gb Total Space | 48,09 Gb Free Space | 64,09% Space Free | Partition Type: NTFS

Drive E: | 3,20 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: KUBA-PC | User Name: Kuba | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========

========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-4209167755-2773275170-760808377-1000\SOFTWARE\Classes\<extension>]

.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

htafile [open] -- "%1" %*

inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)

InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)

InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- "C:\Users\Kuba\AppData\Roaming\File Scout\filescout.exe" /open "%1"

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)

Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)

Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)

Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [explore] -- Reg Error: Value error.

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

htafile [open] -- "%1" %*

inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- "C:\Users\Kuba\AppData\Roaming\File Scout\filescout.exe" /open "%1"

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)

Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)

Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)

Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [explore] -- Reg Error: Value error.

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]

"AntiVirusOverride" = 0

"AntiSpywareOverride" = 0

"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

"DisableNotifications" = 0

"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"DisableNotifications" = 0

"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]

"DisableNotifications" = 0

"EnableFirewall" = 0

========== Authorized Applications List ==========

========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

"{072F3EA7-F75F-433F-BB00-5C6037FB1C7D}" = lport=445 | protocol=6 | dir=in | app=system |

"{077C2732-65FE-4DF6-AC3D-398BC9B95130}" = rport=445 | protocol=6 | dir=out | app=system |

"{0F41F180-60BD-4E9A-8952-238228F8E65A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{1328E32D-C312-4EB1-B876-E6A5D8213BBF}" = rport=139 | protocol=6 | dir=out | app=system |

"{2BD0EAB0-56FE-4F7D-82CB-10494D3E243B}" = lport=138 | protocol=17 | dir=in | app=system |

"{3E358355-F43A-42A9-97E4-C375EDFBA761}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

"{46AD9129-7F88-4319-AA61-84511E677E6F}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{53E387C1-1E8B-477B-877F-7AA0BE58AC04}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |

"{6DE9AF6F-BF87-44F9-B885-A5642BDBCE6F}" = lport=137 | protocol=17 | dir=in | app=system |

"{7163CD4D-E255-4EC3-BE95-264DA209D58D}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{8CAC17CD-8B77-493B-9ACB-90A776CF0F4B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |

"{8EB0E1B8-8D0A-4F03-AFB5-A91C55A6B51F}" = lport=2869 | protocol=6 | dir=in | app=system |

"{94F56163-7AE5-4076-AA99-45E2BF46C6D5}" = rport=138 | protocol=17 | dir=out | app=system |

"{A7F444A9-669D-40FA-9821-A7A011480109}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

"{AC8A36A1-4AB5-4B35-9D80-225FC743022C}" = rport=137 | protocol=17 | dir=out | app=system |

"{AD0168ED-6C3A-477B-810B-70CAE92BB4BB}" = lport=10243 | protocol=6 | dir=in | app=system |

"{B30BBA30-E21C-4995-AEF5-4C7128C46B22}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |

"{B3D9F7AC-0EEF-4AEB-A629-AAEF05B83A00}" = lport=58884 | protocol=6 | dir=in | name=pando media booster |

"{BEF8CB4B-82B3-4B1B-B694-CD8519AFC87B}" = rport=10243 | protocol=6 | dir=out | app=system |

"{C3390CC9-8278-4EF2-A6BF-70415DC5D184}" = lport=58884 | protocol=17 | dir=in | name=pando media booster |

"{D08C5F64-DB5D-45B5-873E-C991C42A98D4}" = lport=58884 | protocol=6 | dir=in | name=pando media booster |

"{D6B4AE70-E41C-4517-9A62-1584375A67D8}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |

"{DBD77043-E1DF-4E39-B4F8-EC02E82EEF08}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |

"{E63E17A0-975C-4D03-A5C4-9CECAC5933E0}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{E64E0B37-2A57-4705-A204-BF930307754B}" = lport=139 | protocol=6 | dir=in | app=system |

"{EE5D2225-5F30-43DA-9D44-797E9A54E810}" = lport=58884 | protocol=17 | dir=in | name=pando media booster |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

"{04704348-79B4-4E74-9C03-15F96AC27396}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |

"{05E6872F-E6CB-4A69-A05A-671AA9A13F7F}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe |

"{183ECDAB-678A-46A3-8045-3522909ED09B}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe |

"{1E0F6A62-238E-4AFE-B7F2-4FF0109C6D1E}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgmfapx.exe |

"{26E13999-AA95-43A4-9B68-753EDB74E7F4}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgnsa.exe |

"{3842678B-9804-4A3C-AEA5-CBED1AF73A64}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |

"{403EE90F-7F08-409A-8215-58DE60E1A38B}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe |

"{4385B104-4782-4851-8801-A4043ED26D3F}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |

"{44C13EEF-9C31-4046-ADC9-81D20481ECF3}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |

"{4785B1F0-69F9-4551-AF21-B7DEB0842CD9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |

"{484DC59E-9915-44DD-81E1-0E2A2A6DF7DF}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |

"{4A5CCF76-F6D2-4193-A677-8295C3A39030}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{4DA2579E-A422-412F-A9B8-0DCD56278D83}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |

"{5D092FE5-5D4F-434A-B1AC-C1DFEE956B61}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |

"{5F1CB105-9890-4043-B53A-8E164FB14C60}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |

"{64E55C81-6449-4095-8FD8-D15ACAD5CC3F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |

"{6A88515E-FD66-4E6B-A937-ED36135C38C2}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgdiagex.exe |

"{6B7C5F30-5AE1-4E2B-9AEB-027C3FA4DEA7}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |

"{6C57A655-E5E2-4520-B1F1-04F1CE9C1457}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{770702F8-C4C5-4402-9EF4-1B0EC9D7809C}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |

"{78A8310A-A5B7-4490-8FDA-12E6306D891C}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |

"{83B22F46-85D4-4600-AF90-9D1FDA68CBC4}" = protocol=6 | dir=in | app=c:\users\kuba\appdata\roaming\bittorrent\bittorrent.exe |

"{8687DEEB-A1B7-442C-897E-32E255D5E581}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |

"{872ADECA-B1A5-45B1-9ACF-B705EECFAF20}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgemca.exe |

"{89680805-D0D8-4FF3-A913-0CCF5B72DAEA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{8A74F2B5-B375-4F88-B4EF-4907CFB6ADB6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{8E62B897-B161-478B-90E5-24479C004CE9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |

"{907DCC41-E456-4235-A42E-DF8F887816C9}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe |

"{94E2A57D-8337-4636-8E8E-08DB8B5E218E}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |

"{9740D6D1-44F3-45B7-A78B-5E71FA146E71}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |

"{9F2CC7F1-5B45-410F-9EE8-A4A5581D35B3}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe |

"{9F3BBAC8-4560-4C5E-B079-E111A078F9B0}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |

"{A27A6509-C7AC-4A27-B47E-1ED7D5AB8CD9}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |

"{A3F5B4D7-DD07-4B72-A549-6A9F1C4CBD26}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |

"{A9A9A5D9-9658-4EF3-9E8A-0019E8898F9F}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |

"{B4055F43-1416-4EB3-92A4-26D575C3A120}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgnsa.exe |

"{B4162318-827F-4A8E-B47B-E7BC283F37E7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |

"{BDE9D88E-8AD4-4CB3-B0DE-FA0D00E35129}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |

"{C00A1905-EDC5-431F-B49B-0438F6ECEAE5}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |

"{C023FF73-FD46-4227-ACCC-74691056D031}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |

"{C38811EB-FF15-40E4-8637-409DA316D18A}" = protocol=6 | dir=out | app=system |

"{C9E162AC-24DA-4698-A955-DD66C0968EB9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |

"{CE2B1280-5EB4-486C-8A5B-FA3DAECAF6BF}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |

"{D16086C7-827D-4151-93D6-C576D746A6D2}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe |

"{D3F767ED-7B05-4CA7-AC90-5388461B00CB}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |

"{D9C51F89-D1ED-4F82-B7E1-36EFA0A990ED}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |

"{DCB6E7CF-944F-4496-B4D6-A6FF8467F054}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgmfapx.exe |

"{DFA0821C-6BEA-4FB3-8042-B6F7A7615BC4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |

"{E2D32756-F209-40F4-A75C-753D006ADB0A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |

"{E32EEF43-390D-43CF-B5E5-0944CA57B81D}" = protocol=17 | dir=in | app=c:\users\kuba\appdata\roaming\bittorrent\bittorrent.exe |

"{E3395F82-56FB-4722-B106-27E2132D89F0}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgdiagex.exe |

"{E5DB5895-48CF-478C-8358-275CF66638DC}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |

"{E6EA2ACA-6975-485F-9CF6-23CC36D75181}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{EA602F8A-DBA3-470A-9C71-EA14D73CC125}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgemca.exe |

"{EAF9FED2-5550-4366-9A2C-97ED8B3182E2}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |

"{EFF67414-51F3-4DF9-BAC5-6CFFD1E8C46C}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |

"{F16F7AC7-1463-4912-A56A-E8F5CC585FDD}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{F2533E7B-2DA7-4624-A2F1-691B5CE9358D}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |

"{F7175B7F-519B-4D68-A724-1EB3D9450E7B}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |

"{FBED210E-568A-476B-ACD9-95A9594058A1}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{FDC81418-AF5F-4D50-BE66-4A466D8687B8}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |

"TCP Query User{0A0064EE-7B8F-4C88-B62F-C9901832CB08}C:\users\kuba\appdata\roaming\ubisoft\mmdoc-pdclive\launcher.exe" = protocol=6 | dir=in | app=c:\users\kuba\appdata\roaming\ubisoft\mmdoc-pdclive\launcher.exe |

"TCP Query User{4D3660EC-A431-4407-BB26-F08799387948}C:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |

"TCP Query User{6B7FF9C7-C3A1-4C3F-9D58-0F1917843125}C:\program files (x86)\mortal kombat komplete edition\disccontentpc\mkke.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mortal kombat komplete edition\disccontentpc\mkke.exe |

"TCP Query User{7C8CB6F7-3478-43AC-A33D-581AA7027868}C:\users\kuba\appdata\local\apps\2.0\95kddmxo.tmb\48rhpt6v.qoo\laun...app_59711684aa47878d_0001.0021_207224f4c72e4750\launcher.exe" = protocol=6 | dir=in | app=c:\users\kuba\appdata\local\apps\2.0\95kddmxo.tmb\48rhpt6v.qoo\laun...app_59711684aa47878d_0001.0021_207224f4c72e4750\launcher.exe |

"TCP Query User{897F2EA7-8266-42A4-B0DA-7CE7FB6846CC}C:\users\kuba\appdata\roaming\ubisoft\mmdoc-pdclive\gamedata\game.exe" = protocol=6 | dir=in | app=c:\users\kuba\appdata\roaming\ubisoft\mmdoc-pdclive\gamedata\game.exe |

"TCP Query User{8D9FC04C-644B-41B0-9903-3A203EA009B9}C:\program files\xfire2\xfire.exe" = protocol=6 | dir=in | app=c:\program files\xfire2\xfire.exe |

"TCP Query User{999ACF42-B810-49D2-8F2F-E72E0399097E}C:\ubisoft\ghost recon online\pdc-live\ghostrecononline.exe" = protocol=6 | dir=in | app=c:\ubisoft\ghost recon online\pdc-live\ghostrecononline.exe |

"TCP Query User{B71672A1-4697-4874-9215-FDA15DD2926E}C:\users\kuba\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\kuba\appdata\roaming\spotify\spotify.exe |

"TCP Query User{D6BB6443-3551-4E42-B3A4-AAB7716861FD}C:\program files (x86)\aspyr\guitar hero iii\gh3.exe" = protocol=6 | dir=in | app=c:\program files (x86)\aspyr\guitar hero iii\gh3.exe |

"TCP Query User{FA2E804D-DA72-42EB-B1BA-6D2D088D006D}C:\users\kuba\appdata\local\apps\2.0\95kddmxo.tmb\48rhpt6v.qoo\laun...app_59711684aa47878d_0001.0020_9bc09dd3c1a49f10\launcher.exe" = protocol=6 | dir=in | app=c:\users\kuba\appdata\local\apps\2.0\95kddmxo.tmb\48rhpt6v.qoo\laun...app_59711684aa47878d_0001.0020_9bc09dd3c1a49f10\launcher.exe |

"UDP Query User{0A57803D-824E-46B2-B95A-B47B085BA4C1}C:\users\kuba\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\kuba\appdata\roaming\spotify\spotify.exe |

"UDP Query User{1BAC0600-58FE-479A-8E0B-FDCB3A2DF9F7}C:\users\kuba\appdata\local\apps\2.0\95kddmxo.tmb\48rhpt6v.qoo\laun...app_59711684aa47878d_0001.0020_9bc09dd3c1a49f10\launcher.exe" = protocol=17 | dir=in | app=c:\users\kuba\appdata\local\apps\2.0\95kddmxo.tmb\48rhpt6v.qoo\laun...app_59711684aa47878d_0001.0020_9bc09dd3c1a49f10\launcher.exe |

"UDP Query User{2CDFABEA-FD81-48D5-854D-5F4688F719FA}C:\program files (x86)\aspyr\guitar hero iii\gh3.exe" = protocol=17 | dir=in | app=c:\program files (x86)\aspyr\guitar hero iii\gh3.exe |

"UDP Query User{3D84DA44-A188-47EE-B52E-6340E675F7D3}C:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |

"UDP Query User{47269023-0CCD-472A-ABC0-8D67570E9A74}C:\program files\xfire2\xfire.exe" = protocol=17 | dir=in | app=c:\program files\xfire2\xfire.exe |

"UDP Query User{589DC5D5-C04B-49A0-8FBB-06E61AF56E0B}C:\users\kuba\appdata\roaming\ubisoft\mmdoc-pdclive\gamedata\game.exe" = protocol=17 | dir=in | app=c:\users\kuba\appdata\roaming\ubisoft\mmdoc-pdclive\gamedata\game.exe |

"UDP Query User{5A4BAD0F-9C2A-4C47-A56D-280C0F66F0B2}C:\ubisoft\ghost recon online\pdc-live\ghostrecononline.exe" = protocol=17 | dir=in | app=c:\ubisoft\ghost recon online\pdc-live\ghostrecononline.exe |

"UDP Query User{8910B862-2F86-46C0-9513-7EC143C7CC87}C:\users\kuba\appdata\local\apps\2.0\95kddmxo.tmb\48rhpt6v.qoo\laun...app_59711684aa47878d_0001.0021_207224f4c72e4750\launcher.exe" = protocol=17 | dir=in | app=c:\users\kuba\appdata\local\apps\2.0\95kddmxo.tmb\48rhpt6v.qoo\laun...app_59711684aa47878d_0001.0021_207224f4c72e4750\launcher.exe |

"UDP Query User{DCB9C1B6-11C6-4A11-8151-458C6E2863B4}C:\program files (x86)\mortal kombat komplete edition\disccontentpc\mkke.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mortal kombat komplete edition\disccontentpc\mkke.exe |

"UDP Query User{DEF04C41-5DA4-4D70-B3D5-25BCFCC80D3D}C:\users\kuba\appdata\roaming\ubisoft\mmdoc-pdclive\launcher.exe" = protocol=17 | dir=in | app=c:\users\kuba\appdata\roaming\ubisoft\mmdoc-pdclive\launcher.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219

"{21B133D6-5979-47F0-BE1C-F6A6B304693F}" = Visual Studio 2010 x64 Redistributables

"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148

"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161

"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17

"{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010

"{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0015-0415-1000-0000000FF1CE}" = Microsoft Office Access MUI (Polish) 2010

"{90140000-0015-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0016-0415-1000-0000000FF1CE}" = Microsoft Office Excel MUI (Polish) 2010

"{90140000-0016-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0018-0415-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Polish) 2010

"{90140000-0018-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0019-0415-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (Polish) 2010

"{90140000-0019-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001A-0415-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (Polish) 2010

"{90140000-001A-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001B-0415-1000-0000000FF1CE}" = Microsoft Office Word MUI (Polish) 2010

"{90140000-001B-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010

"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010

"{90140000-001F-0415-1000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2010

"{90140000-002C-0415-1000-0000000FF1CE}" = Microsoft Office Proofing (Polish) 2010

"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010

"{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0043-0415-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (Polish) 2010

"{90140000-0043-0415-1000-0000000FF1CE}_Office14.PROPLUS_{FF5F6090-64DF-4BF6-BADD-71A64FDA70D2}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0044-0415-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Polish) 2010

"{90140000-0044-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-006E-0415-1000-0000000FF1CE}" = Microsoft Office Shared MUI (Polish) 2010

"{90140000-006E-0415-1000-0000000FF1CE}_Office14.PROPLUS_{3A96ABFF-5202-47B1-B5A2-DDE76563AF61}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-00A1-0415-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (Polish) 2010

"{90140000-00A1-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-00BA-0415-1000-0000000FF1CE}" = Microsoft Office Groove MUI (Polish) 2010

"{90140000-00BA-0415-1000-0000000FF1CE}_Office14.PROPLUS_{E363E2E9-6AE1-4B10-94B6-015819AE201D}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{AE7891D8-2340-4CD6-BA0A-6C8C01F7B4B4}" = AVG 2013

"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 314.22

"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 314.22

"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 314.22

"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 314.22

"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.1031

"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.12.12

"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.3.23.1

"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application

"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components

"{F5AA006A-1ABE-4F16-B6E1-FEE1F7D38102}" = AVG 2013

"ASRock App Charger_is1" = ASRock App Charger v1.0.4

"AVG" = AVG 2013

"Creative VF0330" = Creative WebCam Vista/Live! Cam Chat Driver (1.11.01.00)

"Office14.PROPLUS" = Microsoft Office Professional Plus 2010

"TeamSpeak 3 Client" = TeamSpeak 3 Client

"WinRAR archiver" = WinRAR 4.20 (64-bitowy)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR

"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam

"{0A844D8F-A965-11E2-9E77-B8AC6F98CCE3}" = Google Earth

"{0CE1A6C0-F3F7-49E6-8F9D-2431F9827441}" = Guitar Hero III

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25

"{43ADAE00-A4ED-4379-A76D-A1FF5D9D334A}_is1" = Xfire 2.0

"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype? 6.5

"{62C4063B-948A-4C89-801B-A0B64DE4FF5B}" = Mumble 1.2.4

"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components

"{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3?

"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com

"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7

"{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX

"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends

"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster

"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper

"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9

"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware

"{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller

"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver

"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)

"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01

"{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}" = Sound Blaster X-Fi MB

"Ad-Aware" = Ad-Aware

"Adobe AIR" = Adobe AIR

"ASRock eXtreme Tuner_is1" = ASRock eXtreme Tuner v0.1.54

"ASRock InstantBoot_is1" = ASRock InstantBoot v1.26

"Battlelog Web Plugins" = Battlelog Web Plugins

"BitTorrent" = BitTorrent

"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com

"Creative Live! Cam Center" = Creative Live! Cam Center

"Creative WebCam Vista User's Guide English" = Creative WebCam Vista User's Guide (English)

"DAEMON Tools Lite" = DAEMON Tools Lite

"ESN Sonar-0.70.4" = ESN Sonar

"Google Chrome" = Google Chrome

"InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller

"KLiteCodecPack_is1" = K-Lite Codec Pack 9.9.0 (Full)

"LastFM_is1" = Last.fm Scrobbler 2.1.35

"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware wersja 1.75.0.1300

"MMDoC-PDCLive" = Duel of Champions

"Mortal Kombat Komplete Edition_is1" = Mortal Kombat Komplete Edition

"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver

"Origin" = Origin

"Psychonauts_is1" = Psychonauts

"PunkBusterSvc" = PunkBuster Services

"StarCraft II" = StarCraft II

"Steam App 550" = Left 4 Dead 2

"Steam App 570" = Dota 2

"SysInfo" = Creative System Information

"Torchlight_is1" = Torchlight

"Winamp" = Winamp

"World of Warcraft" = World of Warcraft

"XFastUsb" = XFastUsb

"XfireCodec" = Xfire Codec (remove only)

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-4209167755-2773275170-760808377-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"101a9f93b8f0bb6f" = Curse Client

"d8be6c3f847d7d92" = Ghost Recon Online (EU)

"Spotify" = Spotify

"Winamp Detect" = Detektor Winampa

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-4209167755-2773275170-760808377-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"Winamp Detect" = Detektor Winampa

========== Last 20 Event Log Errors ==========

[ Application Events ]

Error - 2013-07-07 04:58:50 | Computer Name = Kuba-PC | Source = Microsoft-Windows-CAPI2 | ID = 513

Description = Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez

Usługi kryptograficzne nie powiodło się. Details: AddLegacyDriverFiles: Unable to

back up image of binary aswVmm. System Error: The system cannot find the file specified.

.

Error - 2013-07-07 04:59:18 | Computer Name = Kuba-PC | Source = Microsoft-Windows-CAPI2 | ID = 513

Description = Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez

Usługi kryptograficzne nie powiodło się. Details: AddLegacyDriverFiles: Unable to

back up image of binary aswFsBlk. System Error: The system cannot find the file specified.

.

Error - 2013-07-07 04:59:18 | Computer Name = Kuba-PC | Source = Microsoft-Windows-CAPI2 | ID = 513

Description = Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez

Usługi kryptograficzne nie powiodło się. Details: AddLegacyDriverFiles: Unable to

back up image of binary aswMonFlt. System Error: The system cannot find the file

specified. .

Error - 2013-07-07 04:59:18 | Computer Name = Kuba-PC | Source = Microsoft-Windows-CAPI2 | ID = 513

Description = Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez

Usługi kryptograficzne nie powiodło się. Details: AddLegacyDriverFiles: Unable to

back up image of binary aswRdr. System Error: The system cannot find the file specified.

.

Error - 2013-07-07 04:59:18 | Computer Name = Kuba-PC | Source = Microsoft-Windows-CAPI2 | ID = 513

Description = Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez

Usługi kryptograficzne nie powiodło się. Details: AddLegacyDriverFiles: Unable to

back up image of binary aswRvrt. System Error: The system cannot find the file specified.

.

Error - 2013-07-07 04:59:18 | Computer Name = Kuba-PC | Source = Microsoft-Windows-CAPI2 | ID = 513

Description = Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez

Usługi kryptograficzne nie powiodło się. Details: AddLegacyDriverFiles: Unable to

back up image of binary aswSnx. System Error: The system cannot find the file specified.

.

Error - 2013-07-07 04:59:18 | Computer Name = Kuba-PC | Source = Microsoft-Windows-CAPI2 | ID = 513

Description = Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez

Usługi kryptograficzne nie powiodło się. Details: AddLegacyDriverFiles: Unable to

back up image of binary aswSP. System Error: The system cannot find the file specified.

.

Error - 2013-07-07 04:59:18 | Computer Name = Kuba-PC | Source = Microsoft-Windows-CAPI2 | ID = 513

Description = Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez

Usługi kryptograficzne nie powiodło się. Details: AddLegacyDriverFiles: Unable to

back up image of binary avast! Network Shield Support. System Error: The system cannot

find the file specified. .

Error - 2013-07-07 04:59:18 | Computer Name = Kuba-PC | Source = Microsoft-Windows-CAPI2 | ID = 513

Description = Przetwarzanie wywołania OnIdentity() w obiekcie System Writer przez

Usługi kryptograficzne nie powiodło się. Details: AddLegacyDriverFiles: Unable to

back up image of binary aswVmm. System Error: The system cannot find the file specified.

.

Error - 2013-07-08 05:25:30 | Computer Name = Kuba-PC | Source = SideBySide | ID = 16842815

Description = Nie można wygenerować kontekstu aktywacji dla "C:\Program Files (x86)\Common

Files\Adobe AIR\Versions\1.0\Adobe AIR.dll". Błąd w pliku manifestu lub w pliku

zasad "C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll"

w wierszu 3. Wartość "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"

atrybutu "version" elementu "assemblyIdentity" jest nieprawidłowa.

[ System Events ]

Error - 2013-07-07 16:11:02 | Computer Name = Kuba-PC | Source = Service Control Manager | ID = 7006

Description = Wywołanie ScRegSetValueExW dla FailureActions nie powiodło się i wystąpił

następujący błąd: %%5.

Error - 2013-07-07 16:11:43 | Computer Name = Kuba-PC | Source = Service Control Manager | ID = 7006

Description = Wywołanie ScRegSetValueExW dla FailureActions nie powiodło się i wystąpił

następujący błąd: %%5.

Error - 2013-07-07 19:38:39 | Computer Name = Kuba-PC | Source = Service Control Manager | ID = 7006

Description = Wywołanie ScRegSetValueExW dla FailureActions nie powiodło się i wystąpił

następujący błąd: %%5.

Error - 2013-07-08 04:51:59 | Computer Name = Kuba-PC | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi Wsys Service z powodu następującego błędu:

%%2

Error - 2013-07-08 04:52:10 | Computer Name = Kuba-PC | Source = Service Control Manager | ID = 7006

Description = Wywołanie ScRegSetValueExW dla FailureActions nie powiodło się i wystąpił

następujący błąd: %%5.

Error - 2013-07-08 04:52:21 | Computer Name = Kuba-PC | Source = Service Control Manager | ID = 7006

Description = Wywołanie ScRegSetValueExW dla FailureActions nie powiodło się i wystąpił

następujący błąd: %%5.

Error - 2013-07-08 06:22:56 | Computer Name = Kuba-PC | Source = Service Control Manager | ID = 7006

Description = Wywołanie ScRegSetValueExW dla FailureActions nie powiodło się i wystąpił

następujący błąd: %%5.

Error - 2013-07-08 06:23:41 | Computer Name = Kuba-PC | Source = Service Control Manager | ID = 7000

Description = Nie można uruchomić usługi Wsys Service z powodu następującego błędu:

%%2

Error - 2013-07-08 06:23:42 | Computer Name = Kuba-PC | Source = Service Control Manager | ID = 7006

Description = Wywołanie ScRegSetValueExW dla FailureActions nie powiodło się i wystąpił

następujący błąd: %%5.

Error - 2013-07-08 06:23:48 | Computer Name = Kuba-PC | Source = Service Control Manager | ID = 7006

Description = Wywołanie ScRegSetValueExW dla FailureActions nie powiodło się i wystąpił

następujący błąd: %%5.

< End of report >

Link do komentarza
Udostępnij na innych stronach

@Hakken - jak tak dobrze analizujesz logi, to może powinieneś tutaj pomagać, czy coś

@vanity - powiem Ci, że nie musiałeś reinstalować przeglądarki. Wystarczyłby sam log z OTL, a ja napisałbym ci skrypt do usunięcia delty

@niżej - nie interesuje mnie jak to odebrałeś. To była propozycja.

Link do komentarza
Udostępnij na innych stronach

@Hakken - jak tak dobrze analizujesz logi, to może powinieneś tutaj pomagać, czy coś

Naprawdę uważasz, że pouczanie mnie co powinienem robić to dobry pomysł?

Proponuję się trochę uspokoić, bo odkąd odrzuciliśmy twoje podanie o bycie moderatorem stałeś się niezwykle irytujący.

I radzę dopracować swój poradnik na temat infekcji, zarówno mi jak i Sevardowi niezwykle przypadł on do gustu.

Koniec offtopu.

Link do komentarza
Udostępnij na innych stronach



  • Kto przegląda   0 użytkowników

    • Brak zalogowanych użytkowników przeglądających tę stronę.
×
×
  • Utwórz nowe...