Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-12-2013 03 Ran by Patrycja (administrator) on PATRYCJA-TOSH on 18-12-2013 20:52:53 Running from C:\Users\Patrycja\Desktop\tymczasowe - można usunąć Windows 7 Home Premium Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe () C:\Windows\System32\GFNEXSrv.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe () C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe (TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (COMPANYVERS_NAME) C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbarsvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\Teco.exe (Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (TOSHIBA) C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe ( ) C:\Program Files (x86)\ChomikBox\chomikbox.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (VER_COMPANY_NAME) C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon.exe (SweetIM Technologies Ltd.) C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.) C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe (TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.EXE (Microsoft Corporation) C:\Windows\System32\taskmgr.exe (OldTimer Tools) C:\Users\Patrycja\Desktop\tymczasowe - można usunąć\OTL.exe () C:\Users\Patrycja\Desktop\tymczasowe - można usunąć\06eccmi1.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [] - [x] HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12446824 2012-02-01] (Realtek Semiconductor) HKLM\...\Run: [SRS Premium Sound HD] - C:\Program Files\SRS Labs\SRS Control Panel\SRS_Premium_Sound_HD.zip [223180 2012-02-06] () HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2866960 2011-12-19] (Synaptics Incorporated) HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe [590256 2011-09-23] (TOSHIBA Corporation) HKLM\...\Run: [TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [989056 2011-12-14] (TOSHIBA Corporation) HKLM\...\Run: [Teco] - C:\Program Files\TOSHIBA\TECO\Teco.exe [1548208 2011-11-24] (TOSHIBA Corporation) HKLM\...\Run: [TosWaitSrv] - C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [712096 2011-12-14] (TOSHIBA Corporation) HKLM\...\Run: [TosSENotify] - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [710560 2011-11-26] (TOSHIBA Corporation) HKLM\...\Run: [TosVolRegulator] - C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation) HKLM\...\Run: [Toshiba TEMPRO] - C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1546720 2011-02-10] (Toshiba Europe GmbH) HKLM\...\Run: [Toshiba Registration] - C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe [150992 2012-02-26] (Toshiba Europe GmbH) HKLM\...\Run: [HotKeysCmds] - C:\windows\system32\hkcmd.exe [ ] () Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [TOPI.EXE] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [846936 2011-05-16] (TOSHIBA) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKCU\...\Run: [ChomikBox] - C:\Program Files (x86)\ChomikBox\chomikbox.exe [5979648 2012-11-15] ( ) MountPoints2: E - E:\USBAutoRun.exe MountPoints2: {425b94b2-3c7e-11e2-9a9a-e840f29ffd2e} - E:\USBAutoRun.exe HKLM-x32\...\Run: [NBAgent] - C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe [1492264 2011-11-18] (Nero AG) HKLM-x32\...\Run: [ITSecMng] - C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [80840 2011-04-02] (TOSHIBA CORPORATION) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-05] (Intel Corporation) HKLM-x32\...\Run: [ToshibaServiceStation] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1298816 2011-07-12] (TOSHIBA Corporation) HKLM-x32\...\Run: [VideoDownloadConverter Search Scope Monitor] - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrchMn.exe [42536 2012-12-05] (MindSpark) HKLM-x32\...\Run: [VideoDownloadConverter_4z Browser Plugin Loader] - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbrmon.exe [30096 2012-12-05] (VER_COMPANY_NAME) HKLM-x32\...\Run: [SweetIM] - C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe [115032 2012-10-04] (SweetIM Technologies Ltd.) HKLM-x32\...\Run: [Sweetpacks Communicator] - C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe [231768 2012-08-15] (SweetIM Technologies Ltd.) HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe HKU\Default\...\Run: [TOPI.EXE] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [846936 2011-05-16] (TOSHIBA) HKU\Default User\...\Run: [TOPI.EXE] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [846936 2011-05-16] (TOSHIBA) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dosearches.com/?utm_source=b&utm_medium=wpc&utm_campaign=rg&utm_content=hp&from=wpc&uid=TOSHIBAXMQ01ABD050_32MBFBSOSXX32MBFBSOS&ts=1383778978 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dosearches.com/?utm_source=b&utm_medium=wpc&utm_campaign=rg&utm_content=hp&from=wpc&uid=TOSHIBAXMQ01ABD050_32MBFBSOSXX32MBFBSOS&ts=1383778978 HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.holasearch.com/?affID=121962&tt=gc_&babsrc=HP_ss&mntrId=A874446D5722A0DA HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=66016 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=wpc&utm_campaign=rg&utm_content=ds&from=wpc&uid=TOSHIBAXMQ01ABD050_32MBFBSOSXX32MBFBSOS&ts=1383778978&type=default&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dosearches.com/?utm_source=b&utm_medium=wpc&utm_campaign=rg&utm_content=hp&from=wpc&uid=TOSHIBAXMQ01ABD050_32MBFBSOSXX32MBFBSOS&ts=1383778978 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dosearches.com/?utm_source=b&utm_medium=wpc&utm_campaign=rg&utm_content=hp&from=wpc&uid=TOSHIBAXMQ01ABD050_32MBFBSOSXX32MBFBSOS&ts=1383778978 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.dosearches.com/web/?utm_source=b&utm_medium=wpc&utm_campaign=rg&utm_content=ds&from=wpc&uid=TOSHIBAXMQ01ABD050_32MBFBSOSXX32MBFBSOS&ts=1383778978&type=default&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=wpc&utm_campaign=rg&utm_content=ds&from=wpc&uid=TOSHIBAXMQ01ABD050_32MBFBSOSXX32MBFBSOS&ts=1383778978&type=default&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dosearches.com/?utm_source=b&utm_medium=wpc&utm_campaign=rg&utm_content=hp&from=wpc&uid=TOSHIBAXMQ01ABD050_32MBFBSOSXX32MBFBSOS&ts=1383778978 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.dosearches.com/?utm_source=b&utm_medium=wpc&utm_campaign=rg&utm_content=hp&from=wpc&uid=TOSHIBAXMQ01ABD050_32MBFBSOSXX32MBFBSOS&ts=1383778978 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://search.dosearches.com/web/?utm_source=b&utm_medium=wpc&utm_campaign=rg&utm_content=ds&from=wpc&uid=TOSHIBAXMQ01ABD050_32MBFBSOSXX32MBFBSOS&ts=1383778978&type=default&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch URLSearchHook: HKCU - (No Name) - {93a3111f-4f74-4ed8-895e-d9708497629e} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll (MindSpark) StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.dosearches.com/?utm_source=b&utm_medium=wpc&utm_campaign=rg&utm_content=sc&from=wpc&uid=TOSHIBAXMQ01ABD050_32MBFBSOSXX32MBFBSOS&ts=1383778978 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=wpc&utm_campaign=rg&utm_content=ds&from=wpc&uid=TOSHIBAXMQ01ABD050_32MBFBSOSXX32MBFBSOS&ts=1383778978&type=default&q={searchTerms} SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=wpc&utm_campaign=rg&utm_content=ds&from=wpc&uid=TOSHIBAXMQ01ABD050_32MBFBSOSXX32MBFBSOS&ts=1383778978&type=default&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=wpc&utm_campaign=rg&utm_content=ds&from=wpc&uid=TOSHIBAXMQ01ABD050_32MBFBSOSXX32MBFBSOS&ts=1383778978&type=default&q={searchTerms} SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=wpc&utm_campaign=rg&utm_content=ds&from=wpc&uid=TOSHIBAXMQ01ABD050_32MBFBSOSXX32MBFBSOS&ts=1383778978&type=default&q={searchTerms} SearchScopes: HKLM-x32 - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=HJxdm073YYpl&ptnrS=HJxdm073YYpl&si=pconverter&ptb=E3BD0802-79A1-43A0-ACA7-69D62A3E017C&ind=2013012517&n=77fc2225&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKLM-x32 - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&st=6&barid={607F7794-6149-11E2-914C-E840F29FFD2E} SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=wpc&utm_campaign=rg&utm_content=ds&from=wpc&uid=TOSHIBAXMQ01ABD050_32MBFBSOSXX32MBFBSOS&ts=1383778978&type=default&q={searchTerms} SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.holasearch.com/?q={searchTerms}&affID=121962&tt=gc_&babsrc=SP_ss&mntrId=A874446D5722A0DA SearchScopes: HKCU - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} URL = http://www.crawler.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=66016 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.dosearches.com/web/?utm_source=b&utm_medium=wpc&utm_campaign=rg&utm_content=ds&from=wpc&uid=TOSHIBAXMQ01ABD050_32MBFBSOSXX32MBFBSOS&ts=1383778978&type=default&q={searchTerms} SearchScopes: HKCU - {AD072F87-F1D8-43BB-BB12-F546AE696E92} URL = http://search.softonic.com/INF00046/tb_v1?q={searchTerms}&SearchSource=4&cc=&r=245 SearchScopes: HKCU - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=HJxdm073YYpl&ptnrS=HJxdm073YYpl&si=pconverter&ptb=E3BD0802-79A1-43A0-ACA7-69D62A3E017C&ind=2013012517&n=77fc2225&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?src=6&q={searchTerms}&st=6&barid={607F7794-6149-11E2-914C-E840F29FFD2E} BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll () BHO-x32: Bing Bar Helper - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.) BHO-x32: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.8.4.9\bh\BabylonToolbar.dll (Babylon BHO) BHO-x32: Toolbar BHO - {312f84fb-8970-4fd3-bddb-7012eac4afc9} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll (MindSpark) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.10.0\bh\delta.dll (Delta-search.com) BHO-x32: Search Assistant BHO - {c547c6c2-561b-4169-a2a5-20ba771ca93b} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zSrcAs.dll (MindSpark) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: IplexToALLPlayer - {DF925EF3-7A87-44E4-9CAF-8D7B280BF616} - C:\Program Files (x86)\ALLPlayer\Iplex\IplexToALLPlayer.dll (ALLCinema Ltd.) BHO-x32: SweetPacks Browser Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) BHO-x32: smartdownloader Class - {F1AF26F8-1828-4279-ABCE-074EF3235BD7} - C:\Program Files (x86)\PutLockerDownloader\smarterdownloader.dll (TODO: ) BHO-x32: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll () BHO-x32: Yontoo - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll (Yontoo LLC) BHO-x32: BonanzaDeals - {fe063412-bea4-4d76-8ed3-183be6220d17} - C:\Program Files (x86)\BonanzaDeals\BonanzaDealsIE.dll (BonanzaDeals) Toolbar: HKLM-x32 - VideoDownloadConverter - {48586425-6bb7-4f51-8dc6-38c88e3ebb58} - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll (MindSpark) Toolbar: HKLM-x32 - Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.8.4.9\BabylonToolbarTlbr.dll (Babylon Ltd.) Toolbar: HKLM-x32 - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) Toolbar: HKLM-x32 - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.10.0\deltaTlbr.dll (Delta-search.com) Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File Toolbar: HKCU - No Name - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File Toolbar: HKCU - No Name - {48586425-6BB7-4F51-8DC6-38C88E3EBB58} - No File Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - No File Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog9 01 C:\windows\system32\AdpeakProxy.dll File Not found () Winsock: Catalog9 02 C:\windows\system32\AdpeakProxy.dll File Not found () Winsock: Catalog9 03 C:\windows\system32\AdpeakProxy.dll File Not found () Winsock: Catalog9 04 C:\windows\system32\AdpeakProxy.dll File Not found () Winsock: Catalog9 16 C:\windows\system32\AdpeakProxy.dll File Not found () Winsock: Catalog9-x64 01 C:\windows\system32\AdpeakProxy64.dll [439296] (Adpeak, Inc.) Winsock: Catalog9-x64 02 C:\windows\system32\AdpeakProxy64.dll [439296] (Adpeak, Inc.) Winsock: Catalog9-x64 03 C:\windows\system32\AdpeakProxy64.dll [439296] (Adpeak, Inc.) Winsock: Catalog9-x64 04 C:\windows\system32\AdpeakProxy64.dll [439296] (Adpeak, Inc.) Winsock: Catalog9-x64 16 C:\windows\system32\AdpeakProxy64.dll [439296] (Adpeak, Inc.) Hosts: 46.23.70.78 pagead2.googlesyndication.com Tcpip\Parameters: [DhcpNameServer] 10.10.10.2 Tcpip\..\Interfaces\{B1076162-7B7B-41DF-B49A-3E13714F7C23}: [NameServer]195.114.181.130,213.241.79.37,208.67.222.222 FireFox: ======== FF ProfilePath: C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default FF user.js: detected! => C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\user.js FF DefaultSearchEngine: Hola Search FF SelectedSearchEngine: Hola Search FF Homepage: hxxp://www.google.pl/ FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @Nero.com/KM - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG) FF Plugin-x32: @tools.bdupdater.com/BonanzaDealsLive Update;version=3 - C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll (BonanzaDeals) FF Plugin-x32: @tools.bdupdater.com/BonanzaDealsLive Update;version=9 - C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll (BonanzaDeals) FF Plugin-x32: @VideoDownloadConverter_4z.com/Plugin - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll (MindSpark) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\searchplugins\babylon1.xml FF SearchPlugin: C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\searchplugins\BrowserProtect.xml FF SearchPlugin: C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\searchplugins\delta.xml FF SearchPlugin: C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\searchplugins\holasearch.xml FF SearchPlugin: C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\searchplugins\sweetim.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\crawlersrch.xml FF Extension: VideoDownloadConverter - C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\Extensions\4zffxtbr@VideoDownloadConverter_4z.com FF Extension: Delta Toolbar - C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\Extensions\ffxtlbr@delta.com FF Extension: YoutubeAdblocker - C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\Extensions\uya9ooe@olvnqjoe.edu FF Extension: surfa anD kkeep - C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\Extensions\vk4ba@aaia-.net FF Extension: Notificatoin - C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\Extensions\{941E9C01-F8E0-493E-B814-E693BC99A1A1} FF Extension: BonanzaDeals - C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\Extensions\{f9d03c26-0575-497e-821d-f7956d23e0ca} FF Extension: gophoto - C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\Extensions\gophoto@gophoto.it.xpi FF Extension: IplextoALL - C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\Extensions\IplextoALL@ALLPlayer.org.xpi FF Extension: putlockerdownloader - C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\Extensions\putlockerdownloader@putlockerdownloader.com.xpi FF Extension: YouTubetoALL - C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\Extensions\YouTubetoALL@ALLPlayer.org.xpi FF Extension: No Name - C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\Extensions\{c9d31470-81c6-4e3e-9a37-46eb9237ed3a}.xpi FF Extension: Adblock Plus - C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: SweetIM Toolbar - C:\Users\Patrycja\AppData\Roaming\Mozilla\Firefox\Profiles\ivqlwk7j.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF HKLM-x32\...\Firefox\Extensions: [4zffxtbr@VideoDownloadConverter_4z.com] - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin FF Extension: VideoDownloadConverter - C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (Notificatoin ) - C:\Users\Patrycja\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmhfbmpdiffkamakhdbcgojfnbnlcenm\1.0.0_0 CHR Extension: (BonanzaDeals) - C:\Users\Patrycja\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj\3.5.0.0_0 CHR HKLM-x32\...\Chrome\Extension: [apfdadfinodckpcehhdhjlgiphgnbfci] - C:\Program Files (x86)\PutLockerDownloader\putlockerdownloader10.crx CHR HKLM-x32\...\Chrome\Extension: [dhkplhfnhceodhffomolpfigojocbpcb] - C:\Users\Patrycja\AppData\Roaming\BabSolution\CR\BabylonChrome1.crx CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Patrycja\AppData\Roaming\BabSolution\CR\Delta.crx CHR HKLM-x32\...\Chrome\Extension: [gkjoindjjcmbdpbfppabdgflnkgbbcli] - C:\Program Files (x86)\FTDownloader.com\FTDownloader10.crx CHR HKLM-x32\...\Chrome\Extension: [hmhfbmpdiffkamakhdbcgojfnbnlcenm] - C:\ProgramData\Microsoft\Windows\DRM\Server\notificatoin_1.0.0.crx CHR HKLM-x32\...\Chrome\Extension: [pfmopbbadnfoelckkcmjjeaaegjpjjbk] - C:\Program Files (x86)\Gophoto.it\gophotoit14.crx ==================== Services (Whitelisted) ================= R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.) S2 bonanzadealslive; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-12-01] (BonanzaDeals) S3 bonanzadealslivem; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-12-01] (BonanzaDeals) R2 GFNEXSrv; C:\Windows\System32\GFNEXSrv.exe [162824 2010-09-10] () R2 Level Quality Watcher; C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe [512504 2013-12-03] () S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [112080 2011-02-10] (Toshiba Europe GmbH) R2 VideoDownloadConverter_4zService; C:\Program Files (x86)\VideoDownloadConverter_4z\bar\1.bin\4zbarsvc.exe [42504 2012-12-05] (COMPANYVERS_NAME) ==================== Drivers (Whitelisted) ==================== R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-05] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [240920 2013-11-04] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [194872 2013-10-24] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.) R3 RtkBtFilter; C:\Windows\System32\DRIVERS\RtkBtfilter.sys [21096 2012-01-05] (Realtek Microelectronics) R3 RTL8192Ce; C:\Windows\System32\DRIVERS\rtwlane.sys [1082472 2012-01-17] (Realtek Semiconductor Corporation ) S3 usbbus; C:\Windows\System32\DRIVERS\lgx64bus.sys [17920 2008-11-19] (LG Electronics Inc.) S3 TDEIO; \??\C:\Windows\SysWOW64\sysprep\BOOTPRIO\tdeio64.sys [x] U3 kwlyapoc; \??\C:\Users\Patrycja\AppData\Local\Temp\kwlyapoc.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-18 20:47 - 2013-12-18 20:47 - 00000000 ____D C:\FRST 2013-12-18 20:45 - 2013-12-18 20:52 - 00000000 ____D C:\Users\Patrycja\Desktop\tymczasowe - można usunąć 2013-12-12 07:18 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll 2013-12-12 07:18 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL 2013-12-12 07:18 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL 2013-12-12 07:18 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll 2013-12-12 07:14 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2013-12-12 07:14 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2013-12-12 07:14 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2013-12-12 07:14 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2013-12-12 07:14 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2013-12-12 07:14 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2013-12-12 07:14 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2013-12-12 07:14 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2013-12-12 07:14 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2013-12-12 07:14 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2013-12-12 07:14 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2013-12-12 07:14 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2013-12-12 07:14 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2013-12-12 07:14 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2013-12-12 07:14 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2013-12-12 07:14 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2013-12-12 07:14 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2013-12-12 07:14 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2013-12-12 07:14 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2013-12-12 07:14 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2013-12-12 07:14 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2013-12-12 07:14 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2013-12-12 07:14 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2013-12-12 07:14 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2013-12-12 07:14 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2013-12-12 07:14 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2013-12-12 07:14 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2013-12-12 07:14 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2013-12-12 07:14 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2013-12-12 07:14 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2013-12-12 07:14 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2013-12-11 23:06 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll 2013-12-11 23:06 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll 2013-12-11 23:06 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll 2013-12-11 23:06 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll 2013-12-11 23:06 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll 2013-12-11 23:06 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\windows\SysWOW64\msieftp.dll 2013-12-11 23:06 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2013-12-11 23:06 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll 2013-12-11 23:06 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\windows\SysWOW64\imagehlp.dll 2013-12-11 23:06 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx 2013-12-11 23:06 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll 2013-12-11 23:06 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshom.ocx 2013-12-11 23:06 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrrun.dll 2013-12-11 23:06 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\wscript.exe 2013-12-11 23:06 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe 2013-12-11 23:06 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wscript.exe 2013-12-11 23:06 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\cscript.exe 2013-12-11 23:06 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmk.sys 2013-12-11 23:06 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys 2013-12-02 00:55 - 2013-12-02 00:55 - 00000000 ____D C:\Program Files (x86)\Mobogenie 2013-12-02 00:55 - 2013-12-02 00:55 - 00000000 ____D C:\Program Files (x86)\DeskMates 2013-12-02 00:54 - 2013-12-02 00:54 - 00124728 _____ () C:\Users\Patrycja\Downloads\Tahni DeskMates.exe 2013-12-02 00:45 - 2013-12-02 00:45 - 00003100 _____ C:\windows\System32\Tasks\{CD78B0D2-CD95-4B83-917B-218CFF785D27} 2013-12-02 00:03 - 2013-12-02 00:16 - 00000000 ____D C:\Users\Patrycja\AppData\Roaming\PerfectClock2007 2013-12-02 00:02 - 2013-12-02 00:02 - 00000000 ____D C:\ProgramData\PerfectClock2007 2013-12-01 23:21 - 2013-12-01 23:22 - 00000000 ____D C:\Users\Patrycja\AppData\Local\Mobogenie 2013-12-01 23:21 - 2013-12-01 23:21 - 00000000 ____D C:\Users\wangzhisong\AppData\Local\Mobogenie 2013-12-01 23:21 - 2013-12-01 23:21 - 00000000 ____D C:\Users\wangzhisong 2013-12-01 23:21 - 2013-12-01 23:21 - 00000000 ____D C:\Users\Patrycja\Documents\Mobogenie 2013-12-01 23:21 - 2013-12-01 23:21 - 00000000 ____D C:\Users\Patrycja\AppData\Local\cache 2013-12-01 23:21 - 2013-12-01 23:21 - 00000000 _____ C:\Users\Patrycja\daemonprocess.txt 2013-12-01 23:20 - 2013-12-18 20:28 - 00000930 _____ C:\windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job 2013-12-01 23:20 - 2013-12-18 19:39 - 00000926 _____ C:\windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job 2013-12-01 23:20 - 2013-12-01 23:20 - 09626319 _____ C:\Users\Patrycja\Downloads\ClocX 1.5 Beta 2.exe 2013-12-01 23:20 - 2013-12-01 23:20 - 00003926 _____ C:\windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA 2013-12-01 23:20 - 2013-12-01 23:20 - 00003674 _____ C:\windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore 2013-12-01 23:20 - 2013-12-01 23:20 - 00003392 _____ C:\windows\System32\Tasks\BonanzaDealsUpdate 2013-12-01 23:20 - 2013-12-01 23:20 - 00000000 ____D C:\Users\Patrycja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals 2013-12-01 23:20 - 2013-12-01 23:20 - 00000000 ____D C:\Users\Patrycja\AppData\Local\BonanzaDealsLive 2013-12-01 23:20 - 2013-12-01 23:20 - 00000000 ____D C:\ProgramData\BonanzaDealsLive 2013-12-01 23:20 - 2013-12-01 23:20 - 00000000 ____D C:\Program Files (x86)\BonanzaDealsLive 2013-12-01 23:20 - 2013-12-01 23:20 - 00000000 ____D C:\Program Files (x86)\BonanzaDeals 2013-11-29 00:53 - 2013-11-29 00:53 - 00001436 _____ C:\Users\Patrycja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-29 00:37 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\windows\system32\IEUDINIT.EXE 2013-11-29 00:19 - 2013-11-29 00:19 - 01228800 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 01051136 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00942592 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00645120 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsIntl.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00626176 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00616104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dat 2013-11-29 00:19 - 2013-11-29 00:19 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat 2013-11-29 00:19 - 2013-11-29 00:19 - 00610304 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00523776 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00453120 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00413696 _____ (Microsoft Corporation) C:\windows\system32\html.iec 2013-11-29 00:19 - 2013-11-29 00:19 - 00367104 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec 2013-11-29 00:19 - 2013-11-29 00:19 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00263376 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00244736 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00238288 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\url.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00235008 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00208384 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00194048 _____ (Microsoft Corporation) C:\windows\SysWOW64\elshyph.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00182272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msls31.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00167424 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00151552 _____ (Microsoft Corporation) C:\windows\SysWOW64\iexpress.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00139264 _____ (Microsoft Corporation) C:\windows\SysWOW64\wextract.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00131072 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00127488 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00116736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\IEAdvpack.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00105984 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00101376 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00090112 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00083456 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx 2013-11-29 00:19 - 2013-11-29 00:19 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\SetIEInstalledDate.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardie.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx 2013-11-29 00:19 - 2013-11-29 00:19 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00056832 _____ (Microsoft Corporation) C:\windows\SysWOW64\pngfilt.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00048640 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmler.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedsbs.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00040448 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\imgutil.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\licmgr10.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00013312 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshta.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedssync.exe 2013-11-29 00:18 - 2013-11-29 00:18 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-11-29 00:18 - 2013-11-29 00:18 - 00147968 _____ (Microsoft Corporation) C:\windows\system32\occache.dll 2013-11-29 00:18 - 2013-11-29 00:18 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll 2013-11-29 00:18 - 2013-11-29 00:18 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2013-11-29 00:18 - 2013-11-29 00:18 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll 2013-11-29 00:18 - 2013-11-29 00:18 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll 2013-11-29 00:18 - 2013-11-29 00:18 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe 2013-11-28 00:49 - 2013-11-28 00:50 - 00000000 ____D C:\Users\Patrycja\AppData\Local\CUSTPDF Writer 2013-11-27 22:05 - 2013-10-16 10:18 - 00439296 _____ (Adpeak, Inc.) C:\windows\system32\AdpeakProxy64.dll 2013-11-27 22:04 - 2013-12-18 17:06 - 00000000 ____D C:\Program Files\ScorpionSaver Services 2013-11-27 17:47 - 2013-11-27 17:47 - 00000000 ____D C:\Users\Patrycja\AppData\Roaming\StatSoft 2013-11-27 17:46 - 2013-11-27 17:46 - 00000000 ____D C:\Users\Patrycja\AppData\Roaming\Softland 2013-11-27 17:46 - 2013-11-27 17:46 - 00000000 ____D C:\ProgramData\StatSoft 2013-11-27 17:46 - 2013-11-27 17:46 - 00000000 ____D C:\Program Files\Common Files\StatSoft 2013-11-27 17:46 - 2011-03-02 12:38 - 00029008 _____ (Softland) C:\windows\system32\novamnk7.dll 2013-11-27 17:46 - 2011-03-02 12:38 - 00021328 _____ (Softland) C:\windows\system32\novamik7.dll 2013-11-27 17:46 - 2010-03-17 16:29 - 00007549 _____ C:\windows\system32\novak7.ctm 2013-11-27 17:46 - 2010-02-05 14:00 - 01700352 _____ (Microsoft Corporation) C:\windows\system32\GdiPlus.dll 2013-11-27 17:41 - 2013-11-27 17:41 - 00000000 ____D C:\Program Files\StatSoft 2013-11-27 07:41 - 2013-11-29 00:37 - 00023308 _____ C:\windows\IE11_main.log 2013-11-26 21:54 - 2013-11-26 21:54 - 00000000 ____D C:\Program Files\Level Quality Watcher 2013-11-23 14:38 - 2013-11-23 15:24 - 00000000 ____D C:\Users\Patrycja\Documents\zielnik 2013-11-23 00:59 - 2013-11-23 00:59 - 00000000 ____D C:\Program Files (x86)\ScorpionSaver 2013-11-23 00:59 - 2013-11-23 00:59 - 00000000 ____D C:\Program Files (x86)\Notificatoin 2013-11-23 00:59 - 2013-11-23 00:59 - 00000000 ____D C:\Program Files (x86)\Level Quality Watcher 2013-11-23 00:47 - 2013-11-23 00:47 - 02033873 _____ C:\Users\Patrycja\Documents\Ziemiański Andrzej - Achaja Mobi Pack.zip 2013-11-18 23:19 - 2013-11-18 23:19 - 00000000 ____D C:\Users\Patrycja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HaftiX 2013-11-18 23:19 - 2013-11-18 23:19 - 00000000 ____D C:\Program Files (x86)\HaftiX 2013-11-18 14:22 - 2013-12-01 20:08 - 00000000 ____D C:\Users\Patrycja\Documents\haft ==================== One Month Modified Files and Folders ======= 2013-12-18 20:52 - 2013-12-18 20:45 - 00000000 ____D C:\Users\Patrycja\Desktop\tymczasowe - można usunąć 2013-12-18 20:52 - 2012-04-01 12:43 - 01957381 _____ C:\windows\WindowsUpdate.log 2013-12-18 20:49 - 2013-06-16 12:36 - 00007418 _____ C:\windows\setupact.log 2013-12-18 20:47 - 2013-12-18 20:47 - 00000000 ____D C:\FRST 2013-12-18 20:46 - 2011-02-14 10:11 - 00552004 _____ C:\windows\system32\perfh008.dat 2013-12-18 20:46 - 2011-02-14 10:11 - 00089670 _____ C:\windows\system32\perfc008.dat 2013-12-18 20:46 - 2011-02-14 10:01 - 00698146 _____ C:\windows\system32\perfh015.dat 2013-12-18 20:46 - 2011-02-14 10:01 - 00135224 _____ C:\windows\system32\perfc015.dat 2013-12-18 20:46 - 2011-02-14 09:52 - 00632414 _____ C:\windows\system32\perfh00E.dat 2013-12-18 20:46 - 2011-02-14 09:52 - 00148544 _____ C:\windows\system32\perfc00E.dat 2013-12-18 20:46 - 2011-02-14 09:37 - 00623378 _____ C:\windows\system32\perfh005.dat 2013-12-18 20:46 - 2011-02-14 09:37 - 00122022 _____ C:\windows\system32\perfc005.dat 2013-12-18 20:46 - 2009-07-14 06:13 - 03711130 _____ C:\windows\system32\PerfStringBackup.INI 2013-12-18 20:45 - 2012-02-26 21:43 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job 2013-12-18 20:44 - 2009-07-14 05:45 - 00024400 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-18 20:44 - 2009-07-14 05:45 - 00024400 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-18 20:28 - 2013-12-01 23:20 - 00000930 _____ C:\windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job 2013-12-18 20:15 - 2012-09-22 18:55 - 00000000 ____D C:\Users\Patrycja\AppData\Roaming\Skype 2013-12-18 19:39 - 2013-12-01 23:20 - 00000926 _____ C:\windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job 2013-12-18 19:39 - 2013-11-07 00:03 - 00000466 ____H C:\windows\Tasks\Sk-Enhancer-S-5499298658.job 2013-12-18 19:39 - 2013-10-25 12:41 - 00000000 ____D C:\Users\Patrycja\.gstreamer-0.10 2013-12-18 19:38 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT 2013-12-18 19:32 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\NDF 2013-12-18 18:00 - 2013-06-16 09:49 - 00000000 ____D C:\ProgramData\MFAData 2013-12-18 18:00 - 2012-09-22 12:41 - 00000000 ____D C:\Users\Patrycja 2013-12-18 18:00 - 2010-11-21 08:16 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-12-18 18:00 - 2009-07-14 04:20 - 00000000 ____D C:\windows\registration 2013-12-18 18:00 - 2009-07-14 04:20 - 00000000 ____D C:\windows\AppCompat 2013-12-18 17:06 - 2013-11-27 22:04 - 00000000 ____D C:\Program Files\ScorpionSaver Services 2013-12-18 16:37 - 2013-10-01 15:15 - 00000000 ____D C:\windows\system32\MRT 2013-12-17 17:39 - 2013-09-30 16:17 - 00000111 _____ C:\Users\Patrycja\AppData\Roaming\WB.CFG 2013-12-17 17:39 - 2013-09-30 16:17 - 00000006 _____ C:\Users\Patrycja\AppData\Roaming\WBPU-TTL.DAT 2013-12-17 10:45 - 2012-10-01 22:54 - 00000000 ___RD C:\Users\Patrycja\Desktop\studia 2013-12-15 14:45 - 2012-10-03 18:56 - 90708896 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2013-12-12 11:38 - 2009-07-14 06:09 - 00000000 ____D C:\windows\System32\Tasks\WPD 2013-12-12 07:32 - 2009-07-14 05:45 - 00287280 _____ C:\windows\system32\FNTCACHE.DAT 2013-12-12 07:28 - 2009-07-14 04:20 - 00000000 ____D C:\windows\SysWOW64\sk-SK 2013-12-12 07:28 - 2009-07-14 04:20 - 00000000 ____D C:\windows\system32\sk-SK 2013-12-09 00:45 - 2013-02-28 18:29 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-12-09 00:45 - 2012-02-26 21:27 - 00000000 ____D C:\ProgramData\Skype 2013-12-09 00:42 - 2010-11-21 04:47 - 00498858 _____ C:\windows\PFRO.log 2013-12-09 00:39 - 2013-10-25 12:41 - 00000000 ____D C:\Users\Patrycja\AppData\Local\ChomikBox 2013-12-02 00:55 - 2013-12-02 00:55 - 00000000 ____D C:\Program Files (x86)\Mobogenie 2013-12-02 00:55 - 2013-12-02 00:55 - 00000000 ____D C:\Program Files (x86)\DeskMates 2013-12-02 00:54 - 2013-12-02 00:54 - 00124728 _____ () C:\Users\Patrycja\Downloads\Tahni DeskMates.exe 2013-12-02 00:45 - 2013-12-02 00:45 - 00003100 _____ C:\windows\System32\Tasks\{CD78B0D2-CD95-4B83-917B-218CFF785D27} 2013-12-02 00:16 - 2013-12-02 00:03 - 00000000 ____D C:\Users\Patrycja\AppData\Roaming\PerfectClock2007 2013-12-02 00:02 - 2013-12-02 00:02 - 00000000 ____D C:\ProgramData\PerfectClock2007 2013-12-01 23:22 - 2013-12-01 23:21 - 00000000 ____D C:\Users\Patrycja\AppData\Local\Mobogenie 2013-12-01 23:21 - 2013-12-01 23:21 - 00000000 ____D C:\Users\wangzhisong\AppData\Local\Mobogenie 2013-12-01 23:21 - 2013-12-01 23:21 - 00000000 ____D C:\Users\wangzhisong 2013-12-01 23:21 - 2013-12-01 23:21 - 00000000 ____D C:\Users\Patrycja\Documents\Mobogenie 2013-12-01 23:21 - 2013-12-01 23:21 - 00000000 ____D C:\Users\Patrycja\AppData\Local\cache 2013-12-01 23:21 - 2013-12-01 23:21 - 00000000 _____ C:\Users\Patrycja\daemonprocess.txt 2013-12-01 23:20 - 2013-12-01 23:20 - 09626319 _____ C:\Users\Patrycja\Downloads\ClocX 1.5 Beta 2.exe 2013-12-01 23:20 - 2013-12-01 23:20 - 00003926 _____ C:\windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA 2013-12-01 23:20 - 2013-12-01 23:20 - 00003674 _____ C:\windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore 2013-12-01 23:20 - 2013-12-01 23:20 - 00003392 _____ C:\windows\System32\Tasks\BonanzaDealsUpdate 2013-12-01 23:20 - 2013-12-01 23:20 - 00000000 ____D C:\Users\Patrycja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals 2013-12-01 23:20 - 2013-12-01 23:20 - 00000000 ____D C:\Users\Patrycja\AppData\Local\BonanzaDealsLive 2013-12-01 23:20 - 2013-12-01 23:20 - 00000000 ____D C:\ProgramData\BonanzaDealsLive 2013-12-01 23:20 - 2013-12-01 23:20 - 00000000 ____D C:\Program Files (x86)\BonanzaDealsLive 2013-12-01 23:20 - 2013-12-01 23:20 - 00000000 ____D C:\Program Files (x86)\BonanzaDeals 2013-12-01 20:08 - 2013-11-18 14:22 - 00000000 ____D C:\Users\Patrycja\Documents\haft 2013-11-29 00:53 - 2013-11-29 00:53 - 00001436 _____ C:\Users\Patrycja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-29 00:51 - 2009-07-14 04:20 - 00000000 ____D C:\windows\PolicyDefinitions 2013-11-29 00:37 - 2013-11-27 07:41 - 00023308 _____ C:\windows\IE11_main.log 2013-11-29 00:19 - 2013-11-29 00:19 - 01228800 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 01051136 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00942592 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00645120 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsIntl.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00626176 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00616104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dat 2013-11-29 00:19 - 2013-11-29 00:19 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat 2013-11-29 00:19 - 2013-11-29 00:19 - 00610304 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00523776 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00453120 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00413696 _____ (Microsoft Corporation) C:\windows\system32\html.iec 2013-11-29 00:19 - 2013-11-29 00:19 - 00367104 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec 2013-11-29 00:19 - 2013-11-29 00:19 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00263376 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00244736 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00238288 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\url.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00235008 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00208384 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00194048 _____ (Microsoft Corporation) C:\windows\SysWOW64\elshyph.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00182272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msls31.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00167424 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00151552 _____ (Microsoft Corporation) C:\windows\SysWOW64\iexpress.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00139264 _____ (Microsoft Corporation) C:\windows\SysWOW64\wextract.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00131072 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00127488 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00116736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\IEAdvpack.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00105984 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00101376 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00090112 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00083456 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx 2013-11-29 00:19 - 2013-11-29 00:19 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\SetIEInstalledDate.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardie.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx 2013-11-29 00:19 - 2013-11-29 00:19 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00056832 _____ (Microsoft Corporation) C:\windows\SysWOW64\pngfilt.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00048640 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmler.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedsbs.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00040448 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\imgutil.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00034816 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\licmgr10.dll 2013-11-29 00:19 - 2013-11-29 00:19 - 00013312 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshta.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe 2013-11-29 00:19 - 2013-11-29 00:19 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedssync.exe 2013-11-29 00:18 - 2013-11-29 00:18 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-11-29 00:18 - 2013-11-29 00:18 - 00147968 _____ (Microsoft Corporation) C:\windows\system32\occache.dll 2013-11-29 00:18 - 2013-11-29 00:18 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll 2013-11-29 00:18 - 2013-11-29 00:18 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2013-11-29 00:18 - 2013-11-29 00:18 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll 2013-11-29 00:18 - 2013-11-29 00:18 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll 2013-11-29 00:18 - 2013-11-29 00:18 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe 2013-11-29 00:12 - 2012-10-30 07:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-28 00:50 - 2013-11-28 00:49 - 00000000 ____D C:\Users\Patrycja\AppData\Local\CUSTPDF Writer 2013-11-27 17:47 - 2013-11-27 17:47 - 00000000 ____D C:\Users\Patrycja\AppData\Roaming\StatSoft 2013-11-27 17:46 - 2013-11-27 17:46 - 00000000 ____D C:\Users\Patrycja\AppData\Roaming\Softland 2013-11-27 17:46 - 2013-11-27 17:46 - 00000000 ____D C:\ProgramData\StatSoft 2013-11-27 17:46 - 2013-11-27 17:46 - 00000000 ____D C:\Program Files\Common Files\StatSoft 2013-11-27 17:41 - 2013-11-27 17:41 - 00000000 ____D C:\Program Files\StatSoft 2013-11-26 21:54 - 2013-11-26 21:54 - 00000000 ____D C:\Program Files\Level Quality Watcher 2013-11-26 12:54 - 2013-12-12 07:14 - 23183360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2013-11-26 11:19 - 2013-12-12 07:14 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2013-11-26 11:18 - 2013-12-12 07:14 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2013-11-26 11:11 - 2013-12-12 07:14 - 17112576 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2013-11-26 10:48 - 2013-12-12 07:14 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2013-11-26 10:46 - 2013-12-12 07:14 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2013-11-26 10:41 - 2013-12-12 07:14 - 02764288 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2013-11-26 10:29 - 2013-12-12 07:14 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2013-11-26 10:27 - 2013-12-12 07:14 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2013-11-26 10:23 - 2013-12-12 07:14 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2013-11-26 10:21 - 2013-12-12 07:14 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2013-11-26 10:18 - 2013-12-12 07:14 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2013-11-26 10:18 - 2013-12-12 07:14 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2013-11-26 10:16 - 2013-12-12 07:14 - 00708608 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2013-11-26 09:57 - 2013-12-12 07:14 - 00218624 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2013-11-26 09:38 - 2013-12-12 07:14 - 02166784 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2013-11-26 09:38 - 2013-12-12 07:14 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2013-11-26 09:35 - 2013-12-12 07:14 - 05769216 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2013-11-26 09:32 - 2013-12-12 07:14 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2013-11-26 09:28 - 2013-12-12 07:14 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2013-11-26 09:16 - 2013-12-12 07:14 - 04243968 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2013-11-26 09:02 - 2013-12-12 07:14 - 01995264 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2013-11-26 08:48 - 2013-12-12 07:14 - 12996608 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2013-11-26 08:32 - 2013-12-12 07:14 - 01928192 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2013-11-26 08:26 - 2013-12-12 07:14 - 11221504 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2013-11-26 08:07 - 2013-12-12 07:14 - 02334208 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2013-11-26 07:40 - 2013-12-12 07:14 - 01395200 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2013-11-26 07:34 - 2013-12-12 07:14 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2013-11-26 07:34 - 2013-12-12 07:14 - 00703488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2013-11-26 07:33 - 2013-12-12 07:14 - 01820160 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2013-11-26 07:27 - 2013-12-12 07:14 - 01157632 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2013-11-23 19:26 - 2013-12-11 23:06 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll 2013-11-23 18:47 - 2013-12-11 23:06 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll 2013-11-23 15:24 - 2013-11-23 14:38 - 00000000 ____D C:\Users\Patrycja\Documents\zielnik 2013-11-23 00:59 - 2013-11-23 00:59 - 00000000 ____D C:\Program Files (x86)\ScorpionSaver 2013-11-23 00:59 - 2013-11-23 00:59 - 00000000 ____D C:\Program Files (x86)\Notificatoin 2013-11-23 00:59 - 2013-11-23 00:59 - 00000000 ____D C:\Program Files (x86)\Level Quality Watcher 2013-11-23 00:59 - 2012-09-22 12:48 - 00000000 ____D C:\Users\Patrycja\AppData\Local\Google 2013-11-23 00:48 - 2013-06-14 22:45 - 00000000 ____D C:\Users\Patrycja\AppData\Roaming\File Scout 2013-11-23 00:47 - 2013-11-23 00:47 - 02033873 _____ C:\Users\Patrycja\Documents\Ziemiański Andrzej - Achaja Mobi Pack.zip 2013-11-19 12:08 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Microsoft Games 2013-11-19 00:39 - 2012-09-22 12:44 - 00063160 _____ C:\Users\Patrycja\AppData\Local\GDIPFONTCACHEV1.DAT 2013-11-18 23:19 - 2013-11-18 23:19 - 00000000 ____D C:\Users\Patrycja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HaftiX 2013-11-18 23:19 - 2013-11-18 23:19 - 00000000 ____D C:\Program Files (x86)\HaftiX Some content of TEMP: ==================== C:\Users\Patrycja\AppData\Local\Temp\Relaunch.exe C:\Users\Patrycja\AppData\Local\Temp\SpOrder.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2012-02-27 05:11 ==================== End Of Log ============================