[code] HitmanPro 3.7.14.265 www.hitmanpro.com Computer name . . . . : MICHAŁKOMP Windows . . . . . . . : 6.3.0.9600.X64/4 User name . . . . . . : MichałKomp\Michał UAC . . . . . . . . . : Enabled License . . . . . . . : Free Scan date . . . . . . : 2016-06-10 22:27:58 Scan mode . . . . . . : Normal Scan duration . . . . : 4m 48s Disk access mode . . : Direct disk access (SRB) Cloud . . . . . . . . : Internet Reboot . . . . . . . : No Threats . . . . . . . : 1 Traces . . . . . . . : 92 Objects scanned . . . : 1 754 777 Files scanned . . . . : 48 489 Remnants scanned . . : 403 262 files / 1 303 026 keys Miniport ____________________________________________________________________ Primary DriverObject . . . : FFFFE001F4103780 DriverName . . . . : \Driver\amd_sata DriverPath . . . . : \SystemRoot\System32\drivers\amd_sata.sys StartIo . . . . . : 0000000000000000 +0 IRP_MJ_SCSI . . . : FFFFE001F3B6F2C0 +0 Solution DriverObject . . . : FFFFE001F4103780 DriverName . . . . : \Driver\amd_sata DriverPath . . . . : \SystemRoot\System32\drivers\amd_sata.sys StartIo . . . . . : 0000000000000000 +0 IRP_MJ_SCSI . . . : FFFFF801E861F530 \SystemRoot\System32\drivers\storport.sys+9520 Malware _____________________________________________________________________ C:\Users\Michał\AppData\Local\Apps\2.0\HQROWNRT.Z68\LCZLV446.PNT\clic..tion_0000000000000000_0001.0000_095d2ea6c0477cef\ClickOnceSetup.exe Size . . . . . . . : 987 200 bytes Age . . . . . . . : 289.4 days (2015-08-26 12:09:38) Entropy . . . . . : 7.8 SHA-256 . . . . . : E2C722C710646630E0FEF1FFBC9B1A84D34D8948414C1CA8A443A35BC8C10578 Product . . . . . : dobreprogramy Downloader RSA Key Size . . . : 2048 LanguageID . . . . : 0 Authenticode . . . : Valid > Kaspersky . . . . : HEUR:Trojan.Win32.Generic Fuzzy . . . . . . : 107.0 Suspicious files ____________________________________________________________ C:\Users\Michał\AppData\Local\PunkBuster\BF3\pb\dll\wc002331.dll Size . . . . . . . : 963 480 bytes Age . . . . . . . : 896.3 days (2013-12-27 15:54:19) Entropy . . . . . : 7.6 SHA-256 . . . . . : 4693498864B2A4C15EECDD4D132FFDFEDE3F9E4BAFA427F77BC87046A7352D1E RSA Key Size . . . : 2048 Authenticode . . . : Valid Fuzzy . . . . . . : 22.0 The .reloc (relocation) section in this program contains code. This is an indication of malware infection. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Program contains PE structure anomalies. This is not typical for most programs. Program is code signed with a valid Authenticode certificate. C:\Users\Michał\AppData\Local\PunkBuster\FC3\pb\pbcl.dll Size . . . . . . . : 953 886 bytes Age . . . . . . . : 897.1 days (2013-12-26 20:39:23) Entropy . . . . . : 7.6 SHA-256 . . . . . : 6D5E2CD4A7A43EB00B600BA783AD3BEE6B817C030A40600D40367173A6ECEB13 Fuzzy . . . . . . : 29.0 The .reloc (relocation) section in this program contains code. This is an indication of malware infection. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Program contains PE structure anomalies. This is not typical for most programs. C:\Users\Michał\AppData\Local\PunkBuster\FC3\pb\PnkBstrK.sys Size . . . . . . . : 138 032 bytes Age . . . . . . . : 897.1 days (2013-12-26 20:39:38) Entropy . . . . . : 7.8 SHA-256 . . . . . : ABAF3FACF01E10E4C685F79C3B9E5D2118B3CF8629C4277EBE035B2A10474148 RSA Key Size . . . : 2048 Authenticode . . . : Valid Fuzzy . . . . . . : 22.0 The .reloc (relocation) section in this program contains code. This is an indication of malware infection. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Program contains PE structure anomalies. This is not typical for most programs. The file is a device driver. Device drivers run as trusted (highly privileged) code. Program is code signed with a valid Authenticode certificate. C:\Users\Michał\AppData\Local\PunkBuster\GRO\pb\dll\wc002334.dll Size . . . . . . . : 976 576 bytes Age . . . . . . . : 784.4 days (2014-04-18 13:47:34) Entropy . . . . . : 7.6 SHA-256 . . . . . : 81321780DAB94F4E20DCC1AF77F370F7277AE4A4D8771125F7CF435F47D6F9D0 RSA Key Size . . . : 2048 Authenticode . . . : Valid Fuzzy . . . . . . : 22.0 The .reloc (relocation) section in this program contains code. This is an indication of malware infection. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Program contains PE structure anomalies. This is not typical for most programs. Program is code signed with a valid Authenticode certificate. C:\Users\Michał\AppData\Local\PunkBuster\GRO\pb\pbcl.dll Size . . . . . . . : 976 576 bytes Age . . . . . . . : 784.3 days (2014-04-18 14:22:09) Entropy . . . . . : 7.6 SHA-256 . . . . . : 81321780DAB94F4E20DCC1AF77F370F7277AE4A4D8771125F7CF435F47D6F9D0 RSA Key Size . . . : 2048 Authenticode . . . : Valid Fuzzy . . . . . . : 22.0 The .reloc (relocation) section in this program contains code. This is an indication of malware infection. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Program contains PE structure anomalies. This is not typical for most programs. Program is code signed with a valid Authenticode certificate. C:\Users\Michał\AppData\Local\PunkBuster\GRO\pb\pbclold.dll Size . . . . . . . : 976 576 bytes Age . . . . . . . : 784.4 days (2014-04-18 13:31:29) Entropy . . . . . : 7.6 SHA-256 . . . . . : 81321780DAB94F4E20DCC1AF77F370F7277AE4A4D8771125F7CF435F47D6F9D0 RSA Key Size . . . : 2048 Authenticode . . . : Valid Fuzzy . . . . . . : 22.0 The .reloc (relocation) section in this program contains code. This is an indication of malware infection. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Program contains PE structure anomalies. This is not typical for most programs. Program is code signed with a valid Authenticode certificate. C:\Users\Michał\AppData\Local\PunkBuster\GRO\pb\PnkBstrK.sys Size . . . . . . . : 139 016 bytes Age . . . . . . . : 784.4 days (2014-04-18 13:31:42) Entropy . . . . . : 7.8 SHA-256 . . . . . : 2255D5567582FC2038925CA2A47BAB1B2CF81456C83704DED218D7361BCEF95F RSA Key Size . . . : 2048 Authenticode . . . : Valid Fuzzy . . . . . . : 22.0 The .reloc (relocation) section in this program contains code. This is an indication of malware infection. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Program contains PE structure anomalies. This is not typical for most programs. The file is a device driver. Device drivers run as trusted (highly privileged) code. Program is code signed with a valid Authenticode certificate. C:\Users\Michał\AppData\Local\PunkBuster\HEROES\pb\dll\wc002323.dll Size . . . . . . . : 956 648 bytes Age . . . . . . . : 698.0 days (2014-07-13 23:02:16) Entropy . . . . . : 7.6 SHA-256 . . . . . : E88505208F2EA9F150F451C73EEFE57D54A7F50E9D24CB9E647D95A1E826A052 RSA Key Size . . . : 2048 Authenticode . . . : Valid Fuzzy . . . . . . : 22.0 The .reloc (relocation) section in this program contains code. This is an indication of malware infection. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Program contains PE structure anomalies. This is not typical for most programs. Program is code signed with a valid Authenticode certificate. C:\Users\Michał\AppData\Local\PunkBuster\HEROES\pb\pbcl.dll Size . . . . . . . : 956 648 bytes Age . . . . . . . : 690.1 days (2014-07-21 21:02:32) Entropy . . . . . : 7.6 SHA-256 . . . . . : E88505208F2EA9F150F451C73EEFE57D54A7F50E9D24CB9E647D95A1E826A052 RSA Key Size . . . : 2048 Authenticode . . . : Valid Fuzzy . . . . . . : 22.0 The .reloc (relocation) section in this program contains code. This is an indication of malware infection. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Program contains PE structure anomalies. This is not typical for most programs. Program is code signed with a valid Authenticode certificate. C:\Users\Michał\AppData\Local\PunkBuster\HEROES\pb\pbclold.dll Size . . . . . . . : 956 648 bytes Age . . . . . . . : 698.0 days (2014-07-13 22:57:06) Entropy . . . . . : 7.6 SHA-256 . . . . . : E88505208F2EA9F150F451C73EEFE57D54A7F50E9D24CB9E647D95A1E826A052 RSA Key Size . . . : 2048 Authenticode . . . : Valid Fuzzy . . . . . . : 22.0 The .reloc (relocation) section in this program contains code. This is an indication of malware infection. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Program contains PE structure anomalies. This is not typical for most programs. Program is code signed with a valid Authenticode certificate. C:\Users\Michał\AppData\Local\PunkBuster\HEROES\pb\PnkBstrK.sys Size . . . . . . . : 139 648 bytes Age . . . . . . . : 698.0 days (2014-07-13 22:57:41) Entropy . . . . . : 7.8 SHA-256 . . . . . : 164A5F0B9153B75F8955C44BFAE12B594B8D53922AE090132695FF2DAD191C8A RSA Key Size . . . : 2048 Authenticode . . . : Valid Fuzzy . . . . . . : 22.0 The .reloc (relocation) section in this program contains code. This is an indication of malware infection. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Program contains PE structure anomalies. This is not typical for most programs. The file is a device driver. Device drivers run as trusted (highly privileged) code. Program is code signed with a valid Authenticode certificate. C:\Users\Michał\AppData\Local\PunkBuster\MOH\pb\pbcl.dll Size . . . . . . . : 895 844 bytes Age . . . . . . . : 711.4 days (2014-06-30 13:30:39) Entropy . . . . . : 7.6 SHA-256 . . . . . : FC3B4CA8E757E4C9EE740E84419DDB76AE60D20711C49C993B74FCCFFB58F2F9 Fuzzy . . . . . . : 29.0 The .reloc (relocation) section in this program contains code. This is an indication of malware infection. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Program contains PE structure anomalies. This is not typical for most programs. C:\Users\Michał\AppData\Local\PunkBuster\MOH\pb\PnkBstrK.sys Size . . . . . . . : 139 832 bytes Age . . . . . . . : 711.4 days (2014-06-30 13:30:51) Entropy . . . . . : 7.8 SHA-256 . . . . . : 4DA51D1D0A2ECA3357EE2FF80015937CA648D8507F04CA06DE47D59601042F53 RSA Key Size . . . : 1024 Authenticode . . . : Valid Fuzzy . . . . . . : 22.0 The .reloc (relocation) section in this program contains code. This is an indication of malware infection. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Program contains PE structure anomalies. This is not typical for most programs. The file is a device driver. Device drivers run as trusted (highly privileged) code. Program is code signed with a valid Authenticode certificate. C:\Users\Michał\cs 1.6\sw.dll Size . . . . . . . : 1 672 504 bytes Age . . . . . . . : 540.0 days (2014-12-18 21:16:36) Entropy . . . . . : 6.9 SHA-256 . . . . . : 7D298360AD8D8F01C4052B3F28FC138086F2C9923C89235902F546D20998372F RSA Key Size . . . : 1024 Authenticode . . . : Invalid Fuzzy . . . . . . : 26.0 Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. C:\WINDOWS\SysWOW64\GameMon.des Size . . . . . . . : 3 191 392 bytes Age . . . . . . . : 645.1 days (2014-09-04 20:57:45) Entropy . . . . . : 8.0 SHA-256 . . . . . : F65AF9FAF6899F7A8EC472FE24732F871B1E6F2FE9095DE9F4CF5CA1FF18D5ED Product . . . . . : nProtect Game Monitor Publisher . . . . : INCA Internet Co., Ltd. Description . . . : nProtect Game Monitor Rev 2090 Version . . . . . : 2014.5.16.1 RSA Key Size . . . : 2048 Service . . . . . : npggsvc LanguageID . . . . : 1042 Authenticode . . . : Valid Fuzzy . . . . . . : 25.0 The file name extension of this program is not common. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities. Starts automatically as a service during system bootup. Program is code signed with a valid Authenticode certificate. Startup HKLM\SYSTEM\CurrentControlSet\Services\npggsvc\ Potential Unwanted Programs _________________________________________________ C:\WINDOWS\SysWOW64\Drivers\DrvAgent64.SYS (DriverRestore) Size . . . . . . . : 22 200 bytes Age . . . . . . . : 44.0 days (2016-04-27 21:36:42) Entropy . . . . . : 6.4 SHA-256 . . . . . : 05F052C64D192CF69A462A5EC16DDA0D43CA5D0245900C9FCB9201685A2E7748 Product . . . . . : DriverAgent Publisher . . . . : Phoenix Technologies Description . . . : DriverAgent Direct I/O for 64-bit Windows Version . . . . . : 6.0 Copyright . . . . : EnTech Taiwan, 1997-2009 RSA Key Size . . . : 2048 Service . . . . . : DrvAgent64 LanguageID . . . . : 1033 Authenticode . . . : Valid Fuzzy . . . . . . : -4.0 Startup HKLM\SYSTEM\CurrentControlSet\Services\DrvAgent64\ HKLM\SYSTEM\ControlSet001\Services\DrvAgent64\ (DriverRestore) HKLM\SYSTEM\ControlSet001\Services\EventLog\Application\Update FindRight\ (FindRight) HKLM\SYSTEM\CurrentControlSet\Services\DrvAgent64\ (DriverRestore) HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Update FindRight\ (FindRight) Cookies _____________________________________________________________________ C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\03P9J3HM.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\057GNKQ0.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\0BH330IW.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\0J5L6CZF.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\14BRKPBJ.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\187JS2L3.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\1HJ3RJF7.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\237OGIU2.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\26ULC7LN.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\2LK6XFC7.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\2R4O19WT.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\34MAIP5L.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\49CBEDA3.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\4HCFU6C3.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\4XNJJRH0.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\4Z7E3ZOU.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\5381YEVG.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\5AC07U0S.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\6FYTRWJX.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\6LMFO3Q3.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\6REFX2RG.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\8PA33CPA.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\9ERSV58R.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\9VYG5AGK.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\A0RHXT8Y.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\B24D6RLW.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\BR3MQ2LX.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\C2FTUCPT.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\C9VEHP61.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\DZO82BXC.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\E20EFKV5.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\EYDMD5BQ.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\FDDILLVS.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\FERV0UPN.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\FOU14IVD.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\G61ZX2JK.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\H8VAFL0D.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\HXHH3EF8.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\I7OPNF01.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\I9QMD70N.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\IN0AMOJX.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\JWKELB5E.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\K2XKR1KA.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\KADQC4RR.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\KX8GNUI5.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\ME2O60MD.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\MNTK017E.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\O7MO45QK.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\PIVTQZFO.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\R3D8P6UK.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\RIVU7R2C.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\RJM5YG7U.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\RSNEBV3R.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\S2DJ2V24.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\S3CR27JQ.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\S3WR2NLH.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\SA6R9UR4.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\T6CEL7FX.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\TVWPB82R.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\UK1F49QP.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\UPJO2QXB.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\VABLOX0Z.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\VZRLPEFP.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\WB52PIIQ.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\X29PC9FS.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\X2NA2701.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\X6IZAT46.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\XKKA12JK.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\XPD8MPB1.txt C:\Users\Michał\AppData\Local\Microsoft\Windows\INetCookies\Low\YNVP1KB5.txt [/code]