Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-01-2014 Ran by cwirek (administrator) on CFIREK on 05-01-2014 10:17:35 Running from D:\download Windows 7 Ultimate Service Pack 1 (X64) OS Language: Polish Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Locktime Software) C:\Program Files\NetLimiter 3\nlsvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (BitTorrent, Inc.) C:\Program Files (x86)\uTorrent\uTorrent.exe (Locktime Software) C:\Program Files\NetLimiter 3\NLClientApp.exe (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe () C:\Windows\SysWOW64\{$3496-8737-3294-4624-4253$}\appsvc.exe (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Ghisler Software GmbH) C:\Program Files (x86)\totalcmd\TOTALCMD.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11663976 2010-12-09] (Realtek Semiconductor) HKLM-x32\...\Run: [AVP] - "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe" HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [Application Services] - C:\Windows\System32\taskmgr.exe [257024 2010-11-21] (Microsoft Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [uTorrent] - C:\Program Files (x86)\uTorrent\uTorrent.exe [399224 2013-08-19] (BitTorrent, Inc.) HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673696 2013-08-01] (Disc Soft Ltd) HKCU\...\Run: [Xvid] - C:\Program Files (x86)\Xvid\CheckUpdate.exe [8192 2011-01-17] () HKCU\...\Run: [NetLimiter] - C:\Program Files\NetLimiter 3\NLClientApp.exe [2910208 2011-03-21] (Locktime Software) HKCU\...\Run: [IDMan] - C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3821136 2014-01-05] (Tonec Inc.) HKCU\...\CurrentVersion\Windows: [Load] C:\Windows\SysWOW64\{$3496-8737-3294-4624-4253$}\appsvc.exe <===== ATTENTION MountPoints2: {90562bcd-0aed-11e3-899c-002522b3c201} - E:\SETUP.EXE IFEO\avcenter.exe: [Debugger] nsjw.exe IFEO\avguard.exe: [Debugger] nsjw.exe IFEO\avp.exe: [Debugger] nsjw.exe IFEO\bdagent.exe: [Debugger] nsjw.exe IFEO\ccuac.exe: [Debugger] nsjw.exe IFEO\ComboFix.exe: [Debugger] nsjw.exe IFEO\egui.exe: [Debugger] nsjw.exe IFEO\hijackthis.exe: [Debugger] nsjw.exe IFEO\keyscrambler.exe: [Debugger] nsjw.exe IFEO\mbam.exe: [Debugger] nsjw.exe IFEO\MpCmdRun.exe: [Debugger] nsjw.exe IFEO\MSASCui.exe: [Debugger] nsjw.exe IFEO\MsMpEng.exe: [Debugger] nsjw.exe IFEO\msseces.exe: [Debugger] nsjw.exe IFEO\spybotsd.exe: [Debugger] nsjw.exe IFEO\wireshark.exe: [Debugger] nsjw.exe IFEO\zlclient.exe: [Debugger] nsjw.exe Startup: C:\Users\cwirek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Google.com.url () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=SAMSUNGXHD103SJ_S246J9KB517054&ts=1378158134 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x45966B99DEA7CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=SAMSUNGXHD103SJ_S246J9KB517054&ts=1378158134 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=SAMSUNGXHD103SJ_S246J9KB517054&ts=1378158134 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=SAMSUNGXHD103SJ_S246J9KB517054&ts=1378158134 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=SAMSUNGXHD103SJ_S246J9KB517054&ts=1378158134 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=SAMSUNGXHD103SJ_S246J9KB517054&ts=1378158134 StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=SAMSUNGXHD103SJ_S246J9KB517054&ts=1378158134 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=SAMSUNGXHD103SJ_S246J9KB517054&ts=1378158134 SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=SAMSUNGXHD103SJ_S246J9KB517054&ts=1378158134 SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=SAMSUNGXHD103SJ_S246J9KB517054&ts=1378158134 SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=SAMSUNGXHD103SJ_S246J9KB517054&ts=1378158134 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=ds&from=newgdp&uid=SAMSUNGXHD103SJ_S246J9KB517054&ts=1380212055&type=default&q={searchTerms} BHO: IDM integration (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.) BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll No File BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll No File BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll No File BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll No File BHO-x32: IDM integration (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.) BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll No File BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll No File BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll No File BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll No File Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\cwirek\AppData\Roaming\Mozilla\Firefox\Profiles\fv7adbvc.default FF user.js: detected! => C:\Users\cwirek\AppData\Roaming\Mozilla\Firefox\Profiles\fv7adbvc.default\user.js FF NewTab: hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=SAMSUNGXHD103SJ_S246J9KB517054&ts=1378158134 FF SearchEngineOrder.1: qvo6 FF Homepage: chrome://speeddial/content/speeddial.xul FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF SearchPlugin: C:\Users\cwirek\AppData\Roaming\Mozilla\Firefox\Profiles\fv7adbvc.default\searchplugins\duckduckgo.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\delta-homes.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\qvo6.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wolnelektury-pl.xml FF Extension: LastPass - C:\Users\cwirek\AppData\Roaming\Mozilla\Firefox\Profiles\fv7adbvc.default\Extensions\support@lastpass.com FF Extension: No Name - C:\Users\cwirek\AppData\Roaming\Mozilla\Firefox\Profiles\fv7adbvc.default\Extensions\adblockpopups@jessehakanen.net.xpi FF Extension: No Name - C:\Users\cwirek\AppData\Roaming\Mozilla\Firefox\Profiles\fv7adbvc.default\Extensions\firegestures@xuldev.org.xpi FF Extension: No Name - C:\Users\cwirek\AppData\Roaming\Mozilla\Firefox\Profiles\fv7adbvc.default\Extensions\gmail_panel@alejandrobrizuela.com.ar.xpi FF Extension: No Name - C:\Users\cwirek\AppData\Roaming\Mozilla\Firefox\Profiles\fv7adbvc.default\Extensions\keywordsearch@kaply.com.xpi FF Extension: No Name - C:\Users\cwirek\AppData\Roaming\Mozilla\Firefox\Profiles\fv7adbvc.default\Extensions\p24ext@przelewy24.pl.xpi FF Extension: No Name - C:\Users\cwirek\AppData\Roaming\Mozilla\Firefox\Profiles\fv7adbvc.default\Extensions\quickdrag@mozilla.ktechcomputing.com.xpi FF Extension: No Name - C:\Users\cwirek\AppData\Roaming\Mozilla\Firefox\Profiles\fv7adbvc.default\Extensions\{64161300-e22b-11db-8314-0800200c9a66}.xpi FF Extension: No Name - C:\Users\cwirek\AppData\Roaming\Mozilla\Firefox\Profiles\fv7adbvc.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: No Name - C:\Users\cwirek\AppData\Roaming\Mozilla\Firefox\Profiles\fv7adbvc.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi FF HKLM-x32\...\Firefox\Extensions: [url_advisor@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com FF HKCU\...\Firefox\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\cwirek\AppData\Roaming\IDM\idmmzcc5 FF Extension: IDM CC - C:\Users\cwirek\AppData\Roaming\IDM\idmmzcc5 FF HKCU\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\cwirek\AppData\Roaming\IDM\idmmzcc5 FF Extension: IDM CC - C:\Users\cwirek\AppData\Roaming\IDM\idmmzcc5 ==================== Services (Whitelisted) ================= S3 Mezzmo; C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe [4343592 2013-09-03] (Conceiva Pty. Ltd.) R2 nlsvc; C:\Program Files\NetLimiter 3\nlsvc.exe [1845248 2011-03-21] (Locktime Software) S2 AVP; "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe" -r [x] ==================== Drivers (Whitelisted) ==================== R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [34400 2010-11-19] (Asmedia Technology) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-08-22] (Disc Soft Ltd) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-11] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [626272 2013-10-10] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-12-11] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2013-09-27] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178448 2013-09-27] (Kaspersky Lab ZAO) R1 nltdi; C:\Program Files\NetLimiter 3\nltdi.sys [88200 2011-03-21] (Locktime Software) U5 klflt; C:\Windows\System32\Drivers\klflt.sys [90208 2013-09-27] (Kaspersky Lab ZAO) S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-05 10:16 - 2014-01-05 10:16 - 00000000 ____D C:\FRST 2014-01-05 10:05 - 2014-01-05 10:05 - 00118842 _____ C:\Users\cwirek\Desktop\OTL.Txt 2014-01-05 09:48 - 2014-01-05 09:50 - 00000000 __SHD C:\Windows\SysWOW64\{$3496-8737-3294-4624-4253$} 2014-01-05 01:56 - 2014-01-05 01:56 - 00000000 ____D C:\Users\cwirek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager 2014-01-04 02:46 - 2014-01-04 02:46 - 00010471 _____ C:\Users\cwirek\Downloads\two_and_a_half_men_11x11_11x11_n24_pl_73923.zip 2014-01-04 02:46 - 2014-01-04 02:46 - 00007237 _____ C:\Users\cwirek\Downloads\25778_BigBangTheory7x12The.zip 2014-01-03 16:33 - 2014-01-03 16:33 - 00066600 _____ C:\Users\cwirek\Downloads\Mróz Andrzej Projekt 3p(1).xlsm 2014-01-03 15:45 - 2014-01-03 15:45 - 00060209 _____ C:\Users\cwirek\Downloads\swiatkowski_wersja2p(3).xlsm 2014-01-02 16:10 - 2014-01-02 16:10 - 00104690 _____ C:\Users\cwirek\Downloads\Danis_w5p1.xlsm 2013-12-31 09:45 - 2013-12-31 09:45 - 00103572 _____ C:\Users\cwirek\Downloads\Adrian Brocki_ver_14p.xlsm 2013-12-29 21:55 - 2013-12-29 21:55 - 00048937 _____ C:\Users\cwirek\Downloads\pain_amp_gain_n24_pl_70501.zip 2013-12-29 21:54 - 2013-12-29 21:54 - 00016913 _____ C:\Users\cwirek\Downloads\spring_breakers_n24_pl_69684.zip 2013-12-29 21:53 - 2013-12-29 21:53 - 00014920 _____ C:\Users\cwirek\Downloads\stoker_n24_pl_69243.zip 2013-12-29 21:47 - 2013-12-29 21:47 - 00078302 _____ C:\Users\cwirek\Downloads\25755_ButlerThe.zip 2013-12-29 21:35 - 2013-12-29 21:35 - 00060209 _____ C:\Users\cwirek\Downloads\swiatkowski_wersja2p(2).xlsm 2013-12-29 08:36 - 2013-12-29 08:36 - 00026959 _____ C:\Users\cwirek\Downloads\mud_n24_pl_70388(1).zip 2013-12-29 08:23 - 2013-12-29 08:23 - 00022808 _____ C:\Users\cwirek\Downloads\mud_n24_pl_70388.zip 2013-12-26 20:35 - 2013-12-26 20:36 - 19143731 _____ C:\Users\cwirek\Downloads\Age of Empire v1.9.46 apkarchive.com.rar 2013-12-26 20:04 - 2013-12-26 20:04 - 00023885 _____ C:\Users\cwirek\Downloads\don_jon_n24_pl_73793.zip 2013-12-26 19:57 - 2013-12-26 20:02 - 117021853 _____ C:\Users\cwirek\Downloads\Rayman Fiesta Run v1.0.3 apkmania.com.rar 2013-12-26 10:11 - 2013-12-26 10:11 - 00058733 _____ C:\Users\cwirek\Downloads\Sliwinski_ver_4.xlsm 2013-12-25 09:44 - 2013-12-25 09:45 - 10444709 _____ C:\Users\cwirek\Downloads\GooglePlay.Installer(OriginalOriginal_Icon)-4.5.10-Copy.rar 2013-12-25 09:36 - 2013-12-25 09:37 - 03595819 _____ C:\Users\cwirek\Downloads\GoogleMarket.by.Chelpus.TrueLicenseMod(OriginalOriginal_Icon)-4.5.10-Copy.rar 2013-12-25 09:14 - 2013-12-25 09:14 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUSB_01009.Wdf 2013-12-25 09:06 - 2013-12-25 09:06 - 00000914 _____ C:\Users\Public\Desktop\ROOT´óʦ.lnk 2013-12-25 09:06 - 2013-12-25 09:06 - 00000000 ____D C:\Users\cwirek\AppData\Roaming\mgyun 2013-12-25 09:06 - 2013-12-25 09:06 - 00000000 ____D C:\Program Files (x86)\VROOT 2013-12-25 08:58 - 2013-12-25 08:59 - 01400206 _____ C:\Users\cwirek\Downloads\PermRoot.apk 2013-12-25 08:57 - 2013-12-25 08:57 - 00003134 _____ C:\Windows\System32\Tasks\{CE9B9006-6EF7-47BA-80A5-D6E62A3B2823} 2013-12-25 08:53 - 2013-12-25 09:06 - 05261912 _____ (深圳市信一网络有限公司 ) C:\Users\cwirek\Downloads\VRoot_1.7.3.4388_Setup.exe 2013-12-25 08:53 - 2013-12-25 08:56 - 04029016 _____ (北京奇虎科技有限公司) C:\Users\cwirek\Downloads\360RootSetup.exe 2013-12-25 08:49 - 2013-12-25 08:49 - 00000000 ____D C:\Users\cwirek\.android 2013-12-25 08:47 - 2013-12-25 08:48 - 23351008 _____ (Kingosoft Technology Ltd. ) C:\Users\cwirek\Downloads\android_root.exe 2013-12-25 07:07 - 2013-12-25 07:07 - 16597490 _____ C:\Users\cwirek\Downloads\DZ.pdf.dla.EXSite.zip 2013-12-21 18:41 - 2013-12-21 18:41 - 17301903 _____ C:\Users\cwirek\Downloads\PF2014.pdf.dla.EXSite.zip 2013-12-20 21:53 - 2013-12-20 21:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-18 19:28 - 2013-12-18 20:40 - 00030092 _____ C:\Users\cwirek\Desktop\stan przodkow.xlsm 2013-12-17 18:29 - 2013-12-17 18:29 - 00038749 _____ C:\Users\cwirek\Downloads\Juraszczyk_v3.xlsm 2013-12-16 21:34 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-16 21:34 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-16 21:34 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-16 21:34 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-16 21:34 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-16 21:34 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-16 21:34 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-16 21:34 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-16 21:34 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-16 21:34 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-16 21:34 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-16 21:34 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-16 21:34 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-16 21:34 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-16 21:34 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-16 21:34 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-16 21:34 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-16 21:34 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-16 21:34 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-16 21:34 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-16 21:34 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-16 21:34 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-16 21:34 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-16 21:34 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-16 21:34 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-16 21:34 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-16 21:34 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-16 21:34 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-16 21:34 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-16 21:34 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-16 21:34 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-15 13:18 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-12-15 13:15 - 2013-12-15 13:15 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-15 13:15 - 2013-12-15 13:15 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-15 13:15 - 2013-12-15 13:15 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-15 13:15 - 2013-12-15 13:15 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-15 13:15 - 2013-12-15 13:15 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-15 13:15 - 2013-12-15 13:15 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-15 13:15 - 2013-12-15 13:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-15 10:53 - 2013-12-15 13:18 - 00011586 _____ C:\Windows\IE11_main.log 2013-12-15 10:43 - 2013-11-28 01:24 - 00175480 _____ (Tonec Inc.) C:\Windows\system32\Drivers\idmwfp.sys 2013-12-11 20:44 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-11 20:44 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-11 20:43 - 2013-11-12 04:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-11 20:43 - 2013-11-12 03:06 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-12-10 23:16 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-12-10 23:16 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-12-10 23:16 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2013-12-10 23:16 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-12-10 22:09 - 2013-12-22 09:40 - 00000000 ____D C:\Users\cwirek\AppData\Roaming\mIRC 2013-12-10 22:09 - 2013-12-22 05:55 - 00000000 ____D C:\Program Files (x86)\mIRC 2013-12-10 22:09 - 2013-12-10 22:09 - 01944960 _____ (mIRC Co. Ltd.) C:\Users\cwirek\Downloads\mirc732.exe 2013-12-10 22:07 - 2013-12-10 22:07 - 00098075 _____ C:\Users\cwirek\Downloads\Adrian Brocki_ver_11p.xlsm 2013-12-10 21:39 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-10 21:39 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-10 21:38 - 2013-10-30 02:50 - 03159040 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-10 21:32 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-12-10 21:32 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-12-10 21:26 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-10 21:26 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-10 21:21 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-10 21:21 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-10 21:21 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-10 21:21 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-10 21:21 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-10 21:21 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-10 21:21 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-10 21:21 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-10 21:00 - 2013-12-10 21:00 - 00000000 ____D C:\Program Files (x86)\Medieval Software 2013-12-08 22:22 - 2013-12-08 22:22 - 00000000 ____D C:\Users\cwirek\Documents\wmshua 2013-12-08 22:22 - 2013-12-08 22:22 - 00000000 ____D C:\Users\cwirek\AppData\Roaming\ZJMedia 2013-12-08 22:22 - 2013-12-08 22:22 - 00000000 ____D C:\Users\cwirek\AppData\Local\ZJMedia 2013-12-07 02:23 - 2013-12-07 02:23 - 01071224 _____ (Solid State Networks) C:\Users\cwirek\Downloads\install_flashplayer11x32au_mssd_aaa_aih.exe 2013-12-06 09:46 - 2013-12-06 09:46 - 00011899 _____ C:\Users\cwirek\Downloads\how_i_met_your_mother_9x10_9x10_n24_pl_73362(1).zip 2013-12-06 02:38 - 2013-12-06 02:38 - 00011772 _____ C:\Users\cwirek\Downloads\how_i_met_your_mother_9x09_9x9_n24_pl_73360(1).zip ==================== One Month Modified Files and Folders ======= 2014-01-05 10:16 - 2014-01-05 10:16 - 00000000 ____D C:\FRST 2014-01-05 10:11 - 2013-08-19 20:10 - 00000000 ____D C:\Users\cwirek\AppData\Roaming\uTorrent 2014-01-05 10:05 - 2014-01-05 10:05 - 00118842 _____ C:\Users\cwirek\Desktop\OTL.Txt 2014-01-05 10:00 - 2013-08-20 07:11 - 00000000 ____D C:\Users\cwirek\AppData\Roaming\IDM 2014-01-05 09:58 - 2009-07-14 05:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-05 09:58 - 2009-07-14 05:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-05 09:54 - 2013-08-19 18:42 - 01089410 _____ C:\Windows\WindowsUpdate.log 2014-01-05 09:50 - 2014-01-05 09:48 - 00000000 __SHD C:\Windows\SysWOW64\{$3496-8737-3294-4624-4253$} 2014-01-05 09:50 - 2009-07-14 05:51 - 00057189 _____ C:\Windows\setupact.log 2014-01-05 09:48 - 2013-08-20 07:11 - 00000000 ____D C:\Program Files (x86)\Internet Download Manager 2014-01-05 09:48 - 2013-08-19 18:46 - 00000000 ___RD C:\Users\cwirek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-05 09:47 - 2013-08-24 11:55 - 00005086 _____ C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for cfirek-cwirek cfirek 2014-01-05 09:44 - 2013-08-20 07:11 - 00000000 ____D C:\Users\cwirek\AppData\Roaming\DMCache 2014-01-05 09:37 - 2013-09-27 19:28 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2014-01-05 09:35 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-05 01:56 - 2014-01-05 01:56 - 00000000 ____D C:\Users\cwirek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager 2014-01-05 01:11 - 2013-08-19 19:13 - 00000930 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-04 10:26 - 2013-08-21 12:28 - 00000000 ____D C:\Users\cwirek\AppData\Roaming\AIMP3 2014-01-04 02:46 - 2014-01-04 02:46 - 00010471 _____ C:\Users\cwirek\Downloads\two_and_a_half_men_11x11_11x11_n24_pl_73923.zip 2014-01-04 02:46 - 2014-01-04 02:46 - 00007237 _____ C:\Users\cwirek\Downloads\25778_BigBangTheory7x12The.zip 2014-01-03 16:33 - 2014-01-03 16:33 - 00066600 _____ C:\Users\cwirek\Downloads\Mróz Andrzej Projekt 3p(1).xlsm 2014-01-03 15:45 - 2014-01-03 15:45 - 00060209 _____ C:\Users\cwirek\Downloads\swiatkowski_wersja2p(3).xlsm 2014-01-02 16:10 - 2014-01-02 16:10 - 00104690 _____ C:\Users\cwirek\Downloads\Danis_w5p1.xlsm 2013-12-31 09:45 - 2013-12-31 09:45 - 00103572 _____ C:\Users\cwirek\Downloads\Adrian Brocki_ver_14p.xlsm 2013-12-30 12:18 - 2011-04-12 14:21 - 00740096 _____ C:\Windows\system32\perfh015.dat 2013-12-30 12:18 - 2011-04-12 14:21 - 00155670 _____ C:\Windows\system32\perfc015.dat 2013-12-30 12:18 - 2009-07-14 06:13 - 01669178 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-29 21:55 - 2013-12-29 21:55 - 00048937 _____ C:\Users\cwirek\Downloads\pain_amp_gain_n24_pl_70501.zip 2013-12-29 21:54 - 2013-12-29 21:54 - 00016913 _____ C:\Users\cwirek\Downloads\spring_breakers_n24_pl_69684.zip 2013-12-29 21:53 - 2013-12-29 21:53 - 00014920 _____ C:\Users\cwirek\Downloads\stoker_n24_pl_69243.zip 2013-12-29 21:47 - 2013-12-29 21:47 - 00078302 _____ C:\Users\cwirek\Downloads\25755_ButlerThe.zip 2013-12-29 21:35 - 2013-12-29 21:35 - 00060209 _____ C:\Users\cwirek\Downloads\swiatkowski_wersja2p(2).xlsm 2013-12-29 08:36 - 2013-12-29 08:36 - 00026959 _____ C:\Users\cwirek\Downloads\mud_n24_pl_70388(1).zip 2013-12-29 08:23 - 2013-12-29 08:23 - 00022808 _____ C:\Users\cwirek\Downloads\mud_n24_pl_70388.zip 2013-12-28 07:58 - 2013-10-28 06:04 - 00000000 ____D C:\Users\cwirek\AppData\Roaming\KW 2013-12-27 13:28 - 2013-06-30 16:51 - 00000000 ____D C:\Users\cwirek\Desktop\KURATOR 2013-12-27 11:18 - 2013-08-19 16:22 - 00000000 ____D C:\Users\cwirek\Desktop\kamis 2013-12-26 20:36 - 2013-12-26 20:35 - 19143731 _____ C:\Users\cwirek\Downloads\Age of Empire v1.9.46 apkarchive.com.rar 2013-12-26 20:04 - 2013-12-26 20:04 - 00023885 _____ C:\Users\cwirek\Downloads\don_jon_n24_pl_73793.zip 2013-12-26 20:02 - 2013-12-26 19:57 - 117021853 _____ C:\Users\cwirek\Downloads\Rayman Fiesta Run v1.0.3 apkmania.com.rar 2013-12-26 10:11 - 2013-12-26 10:11 - 00058733 _____ C:\Users\cwirek\Downloads\Sliwinski_ver_4.xlsm 2013-12-25 09:45 - 2013-12-25 09:44 - 10444709 _____ C:\Users\cwirek\Downloads\GooglePlay.Installer(OriginalOriginal_Icon)-4.5.10-Copy.rar 2013-12-25 09:37 - 2013-12-25 09:36 - 03595819 _____ C:\Users\cwirek\Downloads\GoogleMarket.by.Chelpus.TrueLicenseMod(OriginalOriginal_Icon)-4.5.10-Copy.rar 2013-12-25 09:14 - 2013-12-25 09:14 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUSB_01009.Wdf 2013-12-25 09:06 - 2013-12-25 09:06 - 00000914 _____ C:\Users\Public\Desktop\ROOT´óʦ.lnk 2013-12-25 09:06 - 2013-12-25 09:06 - 00000000 ____D C:\Users\cwirek\AppData\Roaming\mgyun 2013-12-25 09:06 - 2013-12-25 09:06 - 00000000 ____D C:\Program Files (x86)\VROOT 2013-12-25 09:06 - 2013-12-25 08:53 - 05261912 _____ (深圳市信一网络有限公司 ) C:\Users\cwirek\Downloads\VRoot_1.7.3.4388_Setup.exe 2013-12-25 08:59 - 2013-12-25 08:58 - 01400206 _____ C:\Users\cwirek\Downloads\PermRoot.apk 2013-12-25 08:57 - 2013-12-25 08:57 - 00003134 _____ C:\Windows\System32\Tasks\{CE9B9006-6EF7-47BA-80A5-D6E62A3B2823} 2013-12-25 08:56 - 2013-12-25 08:53 - 04029016 _____ (北京奇虎科技有限公司) C:\Users\cwirek\Downloads\360RootSetup.exe 2013-12-25 08:49 - 2013-12-25 08:49 - 00000000 ____D C:\Users\cwirek\.android 2013-12-25 08:49 - 2013-08-19 18:45 - 00000000 ____D C:\Users\cwirek 2013-12-25 08:48 - 2013-12-25 08:47 - 23351008 _____ (Kingosoft Technology Ltd. ) C:\Users\cwirek\Downloads\android_root.exe 2013-12-25 08:37 - 2013-08-21 12:28 - 00000000 ____D C:\Program Files (x86)\AIMP3 2013-12-25 07:07 - 2013-12-25 07:07 - 16597490 _____ C:\Users\cwirek\Downloads\DZ.pdf.dla.EXSite.zip 2013-12-22 09:40 - 2013-12-10 22:09 - 00000000 ____D C:\Users\cwirek\AppData\Roaming\mIRC 2013-12-22 05:55 - 2013-12-10 22:09 - 00000000 ____D C:\Program Files (x86)\mIRC 2013-12-21 18:41 - 2013-12-21 18:41 - 17301903 _____ C:\Users\cwirek\Downloads\PF2014.pdf.dla.EXSite.zip 2013-12-21 17:58 - 2013-08-19 19:11 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-20 21:53 - 2013-12-20 21:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-18 20:42 - 2013-08-19 18:24 - 00004626 _____ C:\Users\cwirek\Desktop\Nowy dokument tekstowy (4).txt 2013-12-18 20:40 - 2013-12-18 19:28 - 00030092 _____ C:\Users\cwirek\Desktop\stan przodkow.xlsm 2013-12-17 18:30 - 2013-11-20 17:08 - 00015298 _____ C:\Users\cwirek\Desktop\play.xlsx 2013-12-17 18:29 - 2013-12-17 18:29 - 00038749 _____ C:\Users\cwirek\Downloads\Juraszczyk_v3.xlsm 2013-12-15 20:03 - 2013-08-19 18:46 - 00001695 _____ C:\Users\cwirek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-15 20:02 - 2010-11-21 04:47 - 00014186 _____ C:\Windows\PFRO.log 2013-12-15 20:02 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-12-15 13:18 - 2013-12-15 10:53 - 00011586 _____ C:\Windows\IE11_main.log 2013-12-15 13:15 - 2013-12-15 13:15 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-15 13:15 - 2013-12-15 13:15 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-15 13:15 - 2013-12-15 13:15 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-15 13:15 - 2013-12-15 13:15 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-15 13:15 - 2013-12-15 13:15 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-15 13:15 - 2013-12-15 13:15 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-15 13:15 - 2013-12-15 13:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-15 13:15 - 2013-12-15 13:15 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-15 13:15 - 2013-12-15 13:15 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-12 21:08 - 2013-08-27 07:50 - 00001332 _____ C:\Users\cwirek\Desktop\Nowy dokument tekstowy.txt 2013-12-11 20:55 - 2012-08-02 14:09 - 00029792 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klim6.sys 2013-12-11 20:55 - 2012-06-19 16:28 - 00458336 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys 2013-12-11 06:35 - 2009-07-14 05:45 - 00367744 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-10 23:16 - 2013-08-22 17:32 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-10 23:11 - 2013-08-19 19:13 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-10 23:11 - 2013-08-19 19:13 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-10 23:11 - 2013-08-19 19:13 - 00003868 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-10 22:09 - 2013-12-10 22:09 - 01944960 _____ (mIRC Co. Ltd.) C:\Users\cwirek\Downloads\mirc732.exe 2013-12-10 22:07 - 2013-12-10 22:07 - 00098075 _____ C:\Users\cwirek\Downloads\Adrian Brocki_ver_11p.xlsm 2013-12-10 21:00 - 2013-12-10 21:00 - 00000000 ____D C:\Program Files (x86)\Medieval Software 2013-12-10 20:49 - 2013-08-19 19:51 - 00000000 ____D C:\Users\cwirek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2013-12-10 20:49 - 2013-08-19 19:51 - 00000000 ____D C:\Program Files\WinRAR 2013-12-08 22:22 - 2013-12-08 22:22 - 00000000 ____D C:\Users\cwirek\Documents\wmshua 2013-12-08 22:22 - 2013-12-08 22:22 - 00000000 ____D C:\Users\cwirek\AppData\Roaming\ZJMedia 2013-12-08 22:22 - 2013-12-08 22:22 - 00000000 ____D C:\Users\cwirek\AppData\Local\ZJMedia 2013-12-07 02:23 - 2013-12-07 02:23 - 01071224 _____ (Solid State Networks) C:\Users\cwirek\Downloads\install_flashplayer11x32au_mssd_aaa_aih.exe 2013-12-06 09:46 - 2013-12-06 09:46 - 00011899 _____ C:\Users\cwirek\Downloads\how_i_met_your_mother_9x10_9x10_n24_pl_73362(1).zip 2013-12-06 02:38 - 2013-12-06 02:38 - 00011772 _____ C:\Users\cwirek\Downloads\how_i_met_your_mother_9x09_9x9_n24_pl_73360(1).zip Some content of TEMP: ==================== C:\Users\cwirek\AppData\Local\Temp\AskSLib.dll C:\Users\cwirek\AppData\Local\Temp\bassmod.dll C:\Users\cwirek\AppData\Local\Temp\bitool.dll C:\Users\cwirek\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\cwirek\AppData\Local\Temp\jna3511637337458952565.dll C:\Users\cwirek\AppData\Local\Temp\jna6373351899977422420.dll C:\Users\cwirek\AppData\Local\Temp\jna6482727157660762553.dll C:\Users\cwirek\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\cwirek\AppData\Local\Temp\mirc732.exe C:\Users\cwirek\AppData\Local\Temp\ose00000.exe C:\Users\cwirek\AppData\Local\Temp\SRLDetectionLibrary8222958922813139711.dll C:\Users\cwirek\AppData\Local\Temp\winrar.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe [2013-07-11 20:28] - [2013-07-11 20:28] - 0027136 ____A (Microsoft Corporation) DFDE777FAF31DC25E3624E8071073146 C:\Windows\SysWOW64\svchost.exe [2013-07-11 20:28] - [2013-07-11 20:28] - 0021504 ____A (Microsoft Corporation) FFB38D8AFD6F4FCA1D46D64F1EDE0B9F C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll [2013-07-11 20:28] - [2013-07-11 20:28] - 0512000 ____A (Microsoft Corporation) F3EF088F45BE326B4EDAC8C1C5A35105 C:\Windows\System32\Drivers\volsnap.sys [2013-07-11 20:28] - [2013-07-11 20:28] - 0296808 ____A (Microsoft Corporation) DF83AA1C4278E2C0E36C0479C1555A9C LastRegBack: 2013-12-31 10:47 ==================== End Of Log ============================