Scan result of Farbar Recovery Scan Tool Version: 05-07-2012 01 Ran by SYSTEM at 07-07-2012 01:31:51 Running from I:\ Windows 7 Home Premium (X64) OS Language: Polish The current controlset is ControlSet002 ========================== Registry (Whitelisted) ============= HKLM\...\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [384296 2010-04-05] (Alps Electric Co., Ltd.) HKLM\...\Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe [3216544 2010-06-09] (Dell Inc.) HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation) HKLM\...\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [4968960 2009-07-17] (Dell Inc.) HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-02-26] (IDT, Inc.) HKLM-x32\...\Run: [KMCONFIG] C:\Program Files (x86)\Mouse Driver\StartAutorun.exe KMConfig.exe [x] HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard) HKLM-x32\...\Run: [] [x] HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.) HKLM-x32\...\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard) HKU\Amelka\...\Run: [Gadu-Gadu 10] "E:\Urzytki\Gadu-Gadu 10\gg.exe" [x] HKU\Amelka\...\Run: [Advanced SystemCare 5] "C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart [574296 2012-03-06] (IObit) HKU\Amelka\...\Run: [iStoreAgent] "C:\Program Files (x86)\iStore\iStore.exe" [364544 2004-06-02] (PPHU PcBuy.pl Tomasz Cynar, J-endeavor.com Jakub Wietrzyk) HKU\Amelka\...\Run: [] C:\Users\Amelka\AppData\Local\Temp\nsswa.exe [x] Tcpip\Parameters: [DhcpNameServer] 192.168.4.1 192.168.0.1 Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\Users\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) ==================== Services (Whitelisted) ====== 2 AdvancedSystemCareService5; C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe [913752 2012-03-14] (IObit) 2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7f58c91b65c73836\AESTSr64.exe [89600 2009-03-03] (Andrea Electronics Corporation) 2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2011-03-07] () 2 KMWDSERVICE; C:\Program Files (x86)\Mouse Driver\KMWDSrv.exe [208896 2008-06-23] (UASSOFT.COM) 2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation) 2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2010-09-27] () 2 PnkBstrB; C:\Windows\SysWow64\PnkBstrB.exe [103736 2010-09-27] () 2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7f58c91b65c73836\STacSV64.exe [244736 2010-02-26] (IDT, Inc.) ========================== Drivers (Whitelisted) ============= 3 DroidCam; C:\Windows\System32\Drivers\DroidCam.sys [25216 2012-05-22] (Dev47Apps) 0 sptd; C:\Windows\System32\Drivers\sptd.sys [503352 2011-02-02] (Duplex Secure Ltd.) 3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] () ========================== NetSvcs (Whitelisted) =========== ============ One Month Created Files and Folders ============== 2012-07-07 02:13 - 2012-07-07 02:13 - 00000000 ____D C:\_OTL 2012-07-06 21:34 - 2012-07-06 21:35 - 00000000 ____D C:\FRST 2012-07-06 20:01 - 2012-07-06 16:52 - 00002461 ____A C:\oNAPRAW.txt 2012-07-06 18:53 - 2012-07-06 21:01 - 00142740 ____A C:\OTL.Txt 2012-07-05 06:03 - 2012-07-05 06:04 - 00000000 ____D C:\Users\Amelka\AppData\Local\{F35393F4-7FE1-4CDF-B696-A61194D2E08B} 2012-07-05 06:03 - 2012-07-05 06:03 - 00000000 ____D C:\Users\Amelka\AppData\Local\{8A5E5786-8552-4B1C-B00F-749459D7EBBA} 2012-07-04 07:38 - 2012-07-04 07:38 - 00000000 ____D C:\Users\Amelka\AppData\Local\{F2147399-E6E9-4A94-BB66-0828F8BD7CBF} 2012-07-04 07:38 - 2012-07-04 07:38 - 00000000 ____D C:\Users\Amelka\AppData\Local\{A2FB3AD9-10EF-4804-82C7-DD51941C65FF} 2012-07-03 19:37 - 2012-07-03 19:37 - 00000000 ____D C:\Users\Amelka\AppData\Local\{9FF3180C-7DC6-4D6D-B908-031E7E76FC89} 2012-07-03 19:37 - 2012-07-03 19:37 - 00000000 ____D C:\Users\Amelka\AppData\Local\{59C085BF-C18B-4676-B3EF-65D67DF8599F} 2012-07-03 07:36 - 2012-07-03 07:37 - 00000000 ____D C:\Users\Amelka\AppData\Local\{67CD0CB9-C024-47B8-9F97-56C7EF0B9399} 2012-07-03 07:36 - 2012-07-03 07:36 - 00000000 ____D C:\Users\Amelka\AppData\Local\{CB83463A-2501-43D4-B12A-86A7A838ED7B} 2012-07-02 20:45 - 2012-07-02 20:45 - 00000000 ____D C:\Users\Amelka\AppData\Local\{565D6708-6D7D-487C-8D1E-C354CE7859D3} 2012-07-02 19:28 - 2012-07-02 19:28 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_ssadadb_01005.Wdf 2012-07-02 06:38 - 2012-07-02 06:38 - 00000000 ____D C:\Users\Amelka\AppData\Local\{C8555A1E-7AB1-42C0-A8A4-3F16CABB9BB1} 2012-07-02 06:38 - 2012-07-02 06:38 - 00000000 ____D C:\Users\Amelka\AppData\Local\{B045F638-7C23-4D1A-AB63-40461EEB0CF3} 2012-07-01 09:29 - 2012-07-01 09:29 - 00000000 ____D C:\Users\Amelka\AppData\Local\{54929B0E-DB63-4518-BCD6-47679BC2AFD0} 2012-07-01 09:29 - 2012-07-01 09:29 - 00000000 ____D C:\Users\Amelka\AppData\Local\{336E4F71-A26A-4AFA-B642-23F26B2EB1BD} 2012-06-30 09:44 - 2012-06-30 09:45 - 00000000 ____D C:\Users\Amelka\AppData\Local\{AC9E6B07-848B-4A78-8824-B5C9F33A8AF2} 2012-06-30 09:44 - 2012-06-30 09:44 - 00000000 ____D C:\Users\Amelka\AppData\Local\{87A632AF-0528-4CBE-8969-3DEFA02E994C} 2012-06-29 17:56 - 2012-06-29 17:56 - 00000000 ____D C:\Users\Amelka\AppData\Local\{E48580DA-C427-4FEC-9E62-E47D4F45621A} 2012-06-29 17:56 - 2012-06-29 17:56 - 00000000 ____D C:\Users\Amelka\AppData\Local\{660C6AF7-3F32-43BF-8E84-8911397A0608} 2012-06-29 11:16 - 2012-06-29 11:16 - 00003031 ____A C:\Users\Amelka\AppData\Local\recently-used.xbel 2012-06-29 05:46 - 2012-06-29 05:47 - 00000000 ____D C:\Users\Amelka\AppData\Local\{0A12AB16-628F-4C50-8757-93D8DBA8D97F} 2012-06-29 05:46 - 2012-06-29 05:46 - 00000000 ____D C:\Users\Amelka\AppData\Local\{F107D4A9-42F9-4328-B206-A204D4357148} 2012-06-28 07:06 - 2012-06-28 07:07 - 00000000 ____D C:\Users\Amelka\AppData\Local\{8A0FF46A-A9AA-422C-8967-E971ED9FFCCB} 2012-06-28 07:06 - 2012-06-28 07:06 - 00000000 ____D C:\Users\Amelka\AppData\Local\{0CCDEDC8-B869-4740-BF70-A0D1EB1FC192} 2012-06-27 19:06 - 2012-06-27 19:06 - 00000000 ____D C:\Users\Amelka\AppData\Local\{92101372-183A-4A23-9593-CD8645D53966} 2012-06-27 19:05 - 2012-06-27 19:06 - 00000000 ____D C:\Users\Amelka\AppData\Local\{64F52DED-A4AA-4DBA-88DF-8443613368BF} 2012-06-27 17:19 - 2012-06-29 12:23 - 00000000 ____D C:\Users\Amelka\Desktop\oferty 2012-06-27 06:29 - 2012-06-27 06:29 - 00000000 ____D C:\Users\Amelka\AppData\Local\{C1DCCB1D-36DD-4A93-805C-ACB7BB96D287} 2012-06-27 06:29 - 2012-06-27 06:29 - 00000000 ____D C:\Users\Amelka\AppData\Local\{90410603-ACA2-4668-83AE-9AE826E5642A} 2012-06-26 18:28 - 2012-06-26 18:29 - 00000000 ____D C:\Users\Amelka\AppData\Local\{488794C8-22B8-4250-900C-AD52A10B62A4} 2012-06-26 18:28 - 2012-06-26 18:28 - 00000000 ____D C:\Users\Amelka\AppData\Local\{B7CBFCAD-8D23-4C21-9149-6DC1AD4AAAF0} 2012-06-26 06:28 - 2012-06-26 06:28 - 00000000 ____D C:\Users\Amelka\AppData\Local\{D0B1BDF2-0C8F-4109-8602-9F91262A5495} 2012-06-26 06:27 - 2012-06-26 06:28 - 00000000 ____D C:\Users\Amelka\AppData\Local\{DB25BF8B-BFB3-4DCF-AF08-C0C6EE7E77F3} 2012-06-25 20:57 - 2012-06-25 20:58 - 00000000 ____D C:\Users\Amelka\AppData\Roaming\NapiProjekt 2012-06-25 20:57 - 2012-06-25 20:57 - 00001046 ____A C:\Users\Amelka\Desktop\NapiProjekt.lnk 2012-06-25 20:56 - 2012-06-25 20:57 - 00000000 ____D C:\Program Files (x86)\NapiProjekt 2012-06-25 20:54 - 2012-06-25 20:54 - 00000000 ____A C:\Windows\setuperr.log 2012-06-25 20:37 - 2012-06-25 20:37 - 78479360 ____A C:\Windows\System32\config\software.iobit 2012-06-25 20:37 - 2012-06-25 20:37 - 15908864 ____A C:\Windows\System32\config\system.iobit 2012-06-25 20:37 - 2012-06-25 20:37 - 00307200 ____A C:\Windows\System32\config\default.iobit 2012-06-25 20:37 - 2012-06-25 20:37 - 00061440 ____A C:\Windows\System32\config\sam.iobit 2012-06-25 20:37 - 2012-06-25 20:37 - 00024576 ____A C:\Windows\System32\config\security.iobit 2012-06-25 11:59 - 2012-06-25 11:59 - 00000000 ____D C:\Users\Amelka\AppData\Local\{54DFCF74-06B7-4680-B4A1-3708ECD996D8} 2012-06-25 11:59 - 2012-06-25 11:59 - 00000000 ____D C:\Users\Amelka\AppData\Local\{32937BEB-4CF2-44EF-AD81-452FED15933B} 2012-06-24 21:46 - 2012-06-24 21:46 - 00000000 ____D C:\Users\Amelka\AppData\Local\{38B654AD-B778-4858-B578-4E205E21925B} 2012-06-24 21:46 - 2012-06-24 21:46 - 00000000 ____D C:\Users\Amelka\AppData\Local\{2BF7A901-B78C-4745-8458-EC3CE01E3299} 2012-06-24 07:28 - 2012-06-24 07:28 - 00000000 ____D C:\Users\Amelka\AppData\Local\Macromedia 2012-06-23 20:42 - 2012-06-23 20:42 - 00000000 ____D C:\Users\Amelka\AppData\Local\{AD29781C-369F-4F1F-BF91-44FED12D8B5C} 2012-06-23 20:42 - 2012-06-23 20:42 - 00000000 ____D C:\Users\Amelka\AppData\Local\{77CF266A-B11B-4906-850C-4E48BEF9A8E5} 2012-06-23 14:31 - 2012-06-23 14:31 - 00000000 ____D C:\Users\Amelka\AppData\Local\{BF991758-219F-432D-91E8-EF8DB3B34787} 2012-06-23 14:31 - 2012-06-23 14:31 - 00000000 ____D C:\Users\Amelka\AppData\Local\{31CE14FC-10BA-40EE-B8C0-3914DDF0287B} 2012-06-22 20:38 - 2012-06-22 20:38 - 00000000 ____D C:\Users\Amelka\AppData\Local\{F65337C0-BDD0-49BD-BC4E-BF8C801D5A45} 2012-06-22 20:37 - 2012-06-22 20:38 - 00000000 ____D C:\Users\Amelka\AppData\Local\{EB8D51A4-45F5-48BE-A9CE-6366349DB2C4} 2012-06-22 07:03 - 2012-06-22 07:03 - 00000000 ____D C:\Users\Amelka\AppData\Local\{A47251A2-6A81-494E-A150-3E335ECADC04} 2012-06-22 07:03 - 2012-06-22 07:03 - 00000000 ____D C:\Users\Amelka\AppData\Local\{40C8A4A9-5E6D-47D9-B0D7-9A41B49109CA} 2012-06-21 19:02 - 2012-06-21 19:02 - 00000000 ____D C:\Users\Amelka\AppData\Local\{71BE43D4-0961-4C5C-9657-B71B9C310243} 2012-06-21 19:02 - 2012-06-21 19:02 - 00000000 ____D C:\Users\Amelka\AppData\Local\{6334F1B1-0F0B-4BF7-A79B-17A461B49A2B} 2012-06-21 17:14 - 2012-06-21 17:14 - 00000000 ____D C:\Users\Amelka\AppData\Roaming\Softinterface, Inc 2012-06-21 17:14 - 2012-06-21 17:14 - 00000000 ____D C:\Program Files (x86)\Softinterface, Inc 2012-06-21 17:14 - 2012-05-24 07:25 - 00663552 ____A (Microsoft) C:\Windows\SysWOW64\XLSConverterX.ocx 2012-06-21 17:14 - 2012-05-24 07:25 - 00421888 ____A (Microsoft) C:\Windows\SysWOW64\XLSConverterX_07.ocx 2012-06-21 17:14 - 2011-05-25 19:51 - 00823296 ____A (Softinterface, Inc.) C:\Windows\SysWOW64\C-XLS.dll 2012-06-21 17:14 - 2010-08-25 11:26 - 00131072 ____A C:\Windows\SysWOW64\CSVSpecialProcessing.dll 2012-06-21 17:14 - 2010-08-18 13:18 - 00098304 ____A C:\Windows\SysWOW64\DVM.dll 2012-06-21 17:14 - 2010-08-18 13:17 - 00102400 ____A C:\Windows\SysWOW64\SARzilla.dll 2012-06-21 17:14 - 2010-08-18 13:17 - 00053248 ____A () C:\Windows\SysWOW64\RegisterExe.exe 2012-06-21 17:14 - 2007-08-03 13:03 - 00679936 ____A (The Imaging Source Europe GmbH) C:\Windows\SysWOW64\tx13.dll 2012-06-21 17:14 - 2007-07-24 05:01 - 00479232 ____A (The Imaging Source Europe GmbH) C:\Windows\SysWOW64\tx13_doc.dll 2012-06-21 17:14 - 2007-07-24 02:34 - 00225280 ____A (The Imaging Source Europe GmbH) C:\Windows\SysWOW64\tx13_htm.dll 2012-06-21 17:14 - 2007-07-24 02:04 - 00274432 ____A (The Imaging Source Europe GmbH) C:\Windows\SysWOW64\tx13_css.dll 2012-06-21 17:14 - 2007-07-13 05:01 - 00360448 ____A (The Imaging Source Europe GmbH) C:\Windows\SysWOW64\tx13_rtf.dll 2012-06-21 17:14 - 2006-11-29 03:30 - 00114688 ____A (The Imaging Source Europe GmbH) C:\Windows\SysWOW64\tx13_ic.dll 2012-06-21 17:14 - 2006-11-29 03:30 - 00000530 ____A C:\Windows\SysWOW64\tx13_ic.ini 2012-06-21 17:14 - 2006-11-29 03:00 - 00196608 ____A (The Imaging Source Europe GmbH) C:\Windows\SysWOW64\tx13_tls.dll 2012-06-21 17:14 - 2006-10-11 02:20 - 00348160 ____A (The Imaging Source Europe GmbH) C:\Windows\SysWOW64\tx4ole13.ocx 2012-06-21 17:14 - 2006-10-09 01:22 - 00327680 ____A (The Imaging Source Europe GmbH) C:\Windows\SysWOW64\tx13_obj.dll 2012-06-21 17:14 - 2006-09-11 02:46 - 00061440 ____A (The Imaging Source Europe GmbH) C:\Windows\SysWOW64\tx13_tif.flt 2012-06-21 17:14 - 2006-09-11 02:03 - 00053248 ____A (The Imaging Source Europe GmbH) C:\Windows\SysWOW64\tx13_bmp.flt 2012-06-21 17:14 - 2006-09-11 01:20 - 00577536 ____A (The Imaging Source Europe GmbH) C:\Windows\SysWOW64\tx13_pdf.dll 2012-06-21 17:14 - 2006-09-11 01:15 - 00045056 ____A (The Imaging Source Europe GmbH) C:\Windows\SysWOW64\tx13_wmf.flt 2012-06-21 17:14 - 2006-09-11 01:14 - 00221184 ____A (The Imaging Source Europe GmbH) C:\Windows\SysWOW64\tx13_png.flt 2012-06-21 17:14 - 2006-09-11 01:14 - 00172032 ____A (The Imaging Source Europe GmbH) C:\Windows\SysWOW64\tx13_jpg.flt 2012-06-21 17:14 - 2006-09-11 01:05 - 00053248 ____A (The Imaging Source Europe GmbH) C:\Windows\SysWOW64\tx13_gif.flt 2012-06-21 17:14 - 2006-07-03 02:02 - 00053248 ____A (The Imaging Source Europe GmbH) C:\Windows\SysWOW64\tx13_wnd.dll 2012-06-21 17:14 - 2003-06-10 22:27 - 00106496 ____A (Skogen) C:\Windows\SysWOW64\SeeThroughPicture.ocx 2012-06-21 17:14 - 2000-05-22 00:00 - 00244416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Msflxgrd.ocx 2012-06-21 17:14 - 2000-05-22 00:00 - 00203976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RICHTX32.OCX 2012-06-21 17:14 - 1999-05-07 00:00 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.ocx 2012-06-21 12:24 - 2012-06-29 14:29 - 00000000 ____D C:\Users\Amelka\.gimp-2.8 2012-06-21 12:24 - 2012-06-21 12:24 - 00000000 ____D C:\Users\Amelka\AppData\Local\gegl-0.2 2012-06-21 12:16 - 2012-06-21 12:17 - 00000000 ____D C:\Program Files\GIMP 2 2012-06-21 07:01 - 2012-06-21 07:01 - 00000000 ____D C:\Users\Amelka\AppData\Local\{CF8B020E-CA2F-499F-875A-C9A12BD16AA6} 2012-06-21 07:01 - 2012-06-21 07:01 - 00000000 ____D C:\Users\Amelka\AppData\Local\{B0ABAEB7-B5B6-40DC-A4A5-F960578428A8} 2012-06-20 18:53 - 2012-06-20 18:53 - 00000000 ____D C:\Users\Amelka\AppData\Local\{0FAA2A79-2648-4709-B1E1-B63F80D72C50} 2012-06-20 18:52 - 2012-06-20 18:53 - 00000000 ____D C:\Users\Amelka\AppData\Local\{83DE1DC7-4DB4-41F4-A57A-D06112967753} 2012-06-20 06:32 - 2012-06-20 06:32 - 00000000 ____D C:\Users\Amelka\AppData\Local\{075BC796-BD7C-41EF-A843-63DD2920D31D} 2012-06-20 06:31 - 2012-06-20 06:32 - 00000000 ____D C:\Users\Amelka\AppData\Local\{B0E399FA-DB76-4B56-AD1C-98B71DD45E49} 2012-06-19 18:24 - 2012-06-19 18:24 - 00000000 ____D C:\Users\Amelka\AppData\Local\{CED09B28-AD8A-4E58-9792-094272A63FA8} 2012-06-19 18:24 - 2012-06-19 18:24 - 00000000 ____D C:\Users\Amelka\AppData\Local\{203BB1D5-9595-48B5-948C-F48C8265FF9B} 2012-06-19 06:23 - 2012-06-19 06:23 - 00000000 ____D C:\Users\Amelka\AppData\Local\{30E36504-D40F-49FB-8C81-BEC9DB29F6C1} 2012-06-19 06:23 - 2012-06-19 06:23 - 00000000 ____D C:\Users\Amelka\AppData\Local\{058DDF14-91B0-4A22-988B-7CBC9703CEC3} 2012-06-18 17:26 - 2012-06-18 17:27 - 00000000 ____D C:\Users\Amelka\AppData\Local\{98D90070-0222-46DF-85D6-F516230F4628} 2012-06-17 09:53 - 2012-06-17 09:54 - 00000000 ____D C:\Users\Amelka\AppData\Local\{60CE7DFB-BDEE-4CB5-9DF7-9BFE024B5D27} 2012-06-16 16:07 - 2012-06-16 16:07 - 00000000 ____D C:\Users\Amelka\AppData\Local\{C4ECEEA8-F619-4EF8-82C2-5B8DA12F01D1} 2012-06-16 07:09 - 2012-06-16 07:09 - 00010616 ____N C:\bootsqm.dat 2012-06-15 20:35 - 2012-06-15 20:35 - 00000000 ____D C:\Users\Amelka\AppData\Local\{B92ED238-D254-41B1-B783-1137123C9010} 2012-06-15 10:20 - 2012-06-15 10:20 - 00002169 ____A C:\Users\Public\Desktop\HP Photosmart Essential 3.5.lnk 2012-06-15 10:20 - 2012-06-15 10:20 - 00002169 ____A C:\Users\All Users\Desktop\HP Photosmart Essential 3.5.lnk 2012-06-15 10:19 - 2012-06-15 10:19 - 00001383 ____A C:\Users\Public\Desktop\Centrum obsługi HP.lnk 2012-06-15 10:19 - 2012-06-15 10:19 - 00001383 ____A C:\Users\All Users\Desktop\Centrum obsługi HP.lnk 2012-06-15 10:19 - 2012-06-15 10:19 - 00001231 ____A C:\Users\Public\Desktop\Zakup materiałów eksploatacyjnych HP.lnk 2012-06-15 10:19 - 2012-06-15 10:19 - 00001231 ____A C:\Users\All Users\Desktop\Zakup materiałów eksploatacyjnych HP.lnk 2012-06-15 10:19 - 2012-06-15 10:19 - 00000000 ____D C:\Windows\SysWOW64\spool 2012-06-15 10:19 - 2012-06-15 10:19 - 00000000 ____D C:\Users\All Users\HP Product Assistant 2012-06-15 10:19 - 2012-06-15 10:19 - 00000000 ____D C:\Users\All Users\Application Data\HP Product Assistant 2012-06-15 10:16 - 2012-06-15 10:23 - 00211106 ____A C:\Windows\hpoins18.dat 2012-06-15 10:16 - 2009-10-08 02:33 - 00005355 ____N C:\Windows\hpomdl18.dat 2012-06-15 08:35 - 2012-06-15 08:35 - 00000000 ____D C:\Users\Amelka\AppData\Local\{BEA775CE-D31A-4624-A36E-D83DE9CDB494} 2012-06-14 23:19 - 2012-05-18 03:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-06-14 23:19 - 2012-05-18 03:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-06-14 23:19 - 2012-05-18 03:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-06-14 23:19 - 2012-05-18 02:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-06-14 23:19 - 2012-05-18 02:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-06-14 23:19 - 2012-05-18 02:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-06-14 23:19 - 2012-05-18 02:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-06-14 23:19 - 2012-05-18 02:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-06-14 23:19 - 2012-05-18 02:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-06-14 23:19 - 2012-05-18 02:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-06-14 23:19 - 2012-05-18 02:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-06-14 23:19 - 2012-05-18 02:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-06-14 23:19 - 2012-05-18 02:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-06-14 23:19 - 2012-05-18 02:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-06-14 23:19 - 2012-05-18 00:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-06-14 23:19 - 2012-05-17 23:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-06-14 23:19 - 2012-05-17 23:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-06-14 23:19 - 2012-05-17 23:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-06-14 23:19 - 2012-05-17 23:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-06-14 23:19 - 2012-05-17 23:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-06-14 23:19 - 2012-05-17 23:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-06-14 23:19 - 2012-05-17 23:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-06-14 23:19 - 2012-05-17 23:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-06-14 23:19 - 2012-05-17 23:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-06-14 23:19 - 2012-05-17 23:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-06-14 23:19 - 2012-05-17 23:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-06-14 23:19 - 2012-05-17 23:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-06-14 23:19 - 2012-05-17 23:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-06-14 20:33 - 2012-06-14 20:33 - 00000000 ____D C:\Users\Amelka\AppData\Local\{247F7146-DD57-4C0A-ADB5-E1B677D05ADE} 2012-06-14 20:33 - 2012-06-14 20:33 - 00000000 ____D C:\Users\Amelka\AppData\Local\{06954473-D26A-4F99-A803-1EE14AA15EBC} 2012-06-14 09:57 - 2012-06-14 09:57 - 00001329 ____A C:\Users\Public\Desktop\Pajączek 5 NxG.lnk 2012-06-14 09:57 - 2012-06-14 09:57 - 00001329 ____A C:\Users\All Users\Desktop\Pajączek 5 NxG.lnk 2012-06-14 09:56 - 2012-06-14 09:56 - 00000000 ____D C:\Users\Amelka\AppData\Roaming\Cream Software 2012-06-14 09:56 - 2012-06-14 09:56 - 00000000 ____D C:\Program Files (x86)\Cream Software 2012-06-14 09:51 - 2012-06-14 09:51 - 00000000 ____D C:\Program Files (x86)\Mozilla ActiveX Control v1.7.7 2012-06-14 08:03 - 2012-06-14 08:03 - 00000000 ____D C:\Users\Amelka\AppData\Local\{F43EF7F3-2E84-4E94-A972-948E70AC221A} 2012-06-14 08:03 - 2012-06-14 08:03 - 00000000 ____D C:\Users\Amelka\AppData\Local\{6905D483-4E40-4668-9125-D9E972392D1D} 2012-06-13 18:30 - 2012-06-13 18:30 - 00766771 ____A C:\Users\Amelka\Documents\FindMyDelivery.mht 2012-06-13 18:27 - 2012-06-13 18:27 - 00000000 ____D C:\Users\Amelka\AppData\Local\{EC9B94B3-EEDA-47B7-90EA-A67B0E7F8A07} 2012-06-13 18:27 - 2012-06-13 18:27 - 00000000 ____D C:\Users\Amelka\AppData\Local\{2403B14D-524B-465F-A21F-769D76D747F9} 2012-06-13 06:26 - 2012-06-13 06:26 - 00000000 ____D C:\Users\Amelka\AppData\Local\{A9017B31-2A7E-45FB-B675-BD068C90FAC4} 2012-06-13 06:25 - 2012-06-13 06:26 - 00000000 ____D C:\Users\Amelka\AppData\Local\{CD8D1003-6BA2-4BCD-9E22-6989394B199F} 2012-06-12 08:35 - 2012-06-12 08:35 - 00000000 ____D C:\Users\Amelka\AppData\Local\{200A52E0-461B-4AE1-88E7-4454B83C4DB9} 2012-06-12 08:34 - 2012-06-12 08:35 - 00000000 ____D C:\Users\Amelka\AppData\Local\{2EEB5A87-AA28-4FDB-ABAE-2A35543F2E6A} 2012-06-11 20:34 - 2012-06-11 20:34 - 00000000 ____D C:\Users\Amelka\AppData\Local\{2BEEB1C3-37C3-4EE5-A571-835526199A36} 2012-06-11 20:33 - 2012-06-11 20:34 - 00000000 ____D C:\Users\Amelka\AppData\Local\{E8C54A4D-AADF-466C-9C22-229CB4F0ADEE} 2012-06-11 08:33 - 2012-06-11 08:33 - 00000000 ____D C:\Users\Amelka\AppData\Local\{BED2CA73-C484-4381-8DB0-552512E7514B} 2012-06-11 08:33 - 2012-06-11 08:33 - 00000000 ____D C:\Users\Amelka\AppData\Local\{7837E3D8-E629-47DD-9A3E-EA18C2AC6CC4} 2012-06-10 19:32 - 2012-06-10 19:32 - 00000000 ____D C:\Users\Amelka\AppData\Local\{D4B48FFD-A9A9-419F-A7D1-D80A353D5ACE} 2012-06-10 19:31 - 2012-06-10 19:32 - 00000000 ____D C:\Users\Amelka\AppData\Local\{6A41E015-6ECA-4181-9A0A-A2DE79433B75} 2012-06-10 07:31 - 2012-06-10 07:31 - 00000000 ____D C:\Users\Amelka\AppData\Local\{9F8DF596-E840-4309-B501-D7B438AF4530} 2012-06-10 07:30 - 2012-06-10 07:31 - 00000000 ____D C:\Users\Amelka\AppData\Local\{436CB6CB-11A5-4035-91F9-0F0E2FD51A27} 2012-06-09 13:12 - 2012-06-09 13:12 - 00000000 ____D C:\Users\Amelka\AppData\Local\{A0BFEA5F-3397-4857-9B64-C8A237CF9AB0} 2012-06-09 13:11 - 2012-06-09 13:12 - 00000000 ____D C:\Users\Amelka\AppData\Local\{16246795-920C-4255-9E65-010F6B6F8612} 2012-06-09 08:35 - 2012-06-09 08:35 - 00000000 ____D C:\Users\Amelka\AppData\Local\{295D0042-3902-4C1B-9343-76D851FDD391} 2012-06-08 09:25 - 2012-06-08 09:25 - 00000000 ____D C:\Users\Amelka\AppData\Local\{7C06553E-768E-4A37-B2A9-CA8D424E0FF3} 2012-06-08 09:24 - 2012-06-08 09:25 - 00000000 ____D C:\Users\Amelka\AppData\Local\{FCDC9304-67D8-48D2-B48A-173480B57951} 2012-06-07 21:24 - 2012-06-07 21:24 - 00000000 ____D C:\Users\Amelka\AppData\Local\{D2B8E439-74AE-424E-BE7C-DB53CB76D1B1} 2012-06-07 21:24 - 2012-06-07 21:24 - 00000000 ____D C:\Users\Amelka\AppData\Local\{5BA7C755-D1BB-4395-8F48-B6682898880D} 2012-06-07 17:10 - 2012-07-04 15:57 - 00000000 ____D C:\Users\Amelka\Desktop\eMisiaczkowowo 2012-06-07 16:52 - 2012-06-07 16:52 - 00204130 ____A C:\Users\Amelka\Desktop\logo PFI.pfi 2012-06-07 12:19 - 2012-06-07 12:19 - 00001847 ____A C:\Users\Public\Desktop\QuickTime Player.lnk 2012-06-07 12:19 - 2012-06-07 12:19 - 00001847 ____A C:\Users\All Users\Desktop\QuickTime Player.lnk 2012-06-07 12:19 - 2012-06-07 12:19 - 00000000 ____D C:\Users\All Users\Application Data\Apple Computer 2012-06-07 12:19 - 2012-06-07 12:19 - 00000000 ____D C:\Users\All Users\Apple Computer 2012-06-07 12:19 - 2012-06-07 12:19 - 00000000 ____D C:\Program Files (x86)\QuickTime 2012-06-07 09:23 - 2012-06-07 09:23 - 00000000 ____D C:\Users\Amelka\AppData\Local\{60882D62-F088-4619-9A42-20053DD2D2ED} 2012-06-07 09:23 - 2012-06-07 09:23 - 00000000 ____D C:\Users\Amelka\AppData\Local\{58935EBE-42EA-4D00-B9F7-F4CE749C9326} ============ 3 Months Modified Files ======================== 2012-07-06 21:01 - 2012-07-06 18:53 - 00142740 ____A C:\OTL.Txt 2012-07-06 16:52 - 2012-07-06 20:01 - 00002461 ____A C:\oNAPRAW.txt 2012-07-05 14:50 - 2011-03-16 18:21 - 00001044 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2012-07-05 14:50 - 2010-07-16 19:56 - 00065536 _____ C:\Windows\System32\Ikeext.etl 2012-07-05 14:50 - 2009-07-14 06:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2012-07-05 14:50 - 2009-07-14 03:34 - 00000534 ____A C:\Windows\win.ini 2012-07-05 14:34 - 2009-07-14 05:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2012-07-05 14:34 - 2009-07-14 05:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2012-07-05 14:21 - 2011-03-16 18:21 - 00001048 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2012-07-05 14:07 - 2012-04-15 09:41 - 00000930 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2012-07-04 18:59 - 2009-07-14 18:55 - 00713756 ____A C:\Windows\System32\perfh015.dat 2012-07-04 18:59 - 2009-07-14 18:55 - 00143782 ____A C:\Windows\System32\perfc015.dat 2012-07-04 18:59 - 2009-07-14 06:13 - 01596498 ____A C:\Windows\System32\PerfStringBackup.INI 2012-07-02 19:28 - 2012-07-02 19:28 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_ssadadb_01005.Wdf 2012-07-01 21:21 - 2009-07-14 05:45 - 00452112 ____A C:\Windows\System32\FNTCACHE.DAT 2012-07-01 12:01 - 2012-03-25 11:15 - 00000341 ____A C:\Users\Amelka\AppData\Local\Images.fl 2012-06-30 09:49 - 2012-03-06 13:16 - 00002346 ____A C:\Users\Public\Desktop\Google Chrome.lnk 2012-06-30 09:49 - 2012-03-06 13:16 - 00002346 ____A C:\Users\All Users\Desktop\Google Chrome.lnk 2012-06-29 15:31 - 2010-06-06 03:53 - 00121264 ____A C:\Users\Amelka\AppData\Local\GDIPFONTCACHEV1.DAT 2012-06-29 11:16 - 2012-06-29 11:16 - 00003031 ____A C:\Users\Amelka\AppData\Local\recently-used.xbel 2012-06-25 20:57 - 2012-06-25 20:57 - 00001046 ____A C:\Users\Amelka\Desktop\NapiProjekt.lnk 2012-06-25 20:54 - 2012-06-25 20:54 - 00000000 ____A C:\Windows\setuperr.log 2012-06-25 20:37 - 2012-06-25 20:37 - 78479360 ____A C:\Windows\System32\config\software.iobit 2012-06-25 20:37 - 2012-06-25 20:37 - 15908864 ____A C:\Windows\System32\config\system.iobit 2012-06-25 20:37 - 2012-06-25 20:37 - 00307200 ____A C:\Windows\System32\config\default.iobit 2012-06-25 20:37 - 2012-06-25 20:37 - 00061440 ____A C:\Windows\System32\config\sam.iobit 2012-06-25 20:37 - 2012-06-25 20:37 - 00024576 ____A C:\Windows\System32\config\security.iobit 2012-06-25 07:07 - 2012-04-15 09:41 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2012-06-25 07:07 - 2011-05-15 22:00 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2012-06-16 07:09 - 2012-06-16 07:09 - 00010616 ____N C:\bootsqm.dat 2012-06-15 10:23 - 2012-06-15 10:16 - 00211106 ____A C:\Windows\hpoins18.dat 2012-06-15 10:23 - 2010-12-29 17:03 - 00017993 ____A C:\Users\All Users\hpzinstall.log 2012-06-15 10:23 - 2010-12-29 17:03 - 00017993 ____A C:\Users\All Users\Application Data\hpzinstall.log 2012-06-15 10:20 - 2012-06-15 10:20 - 00002169 ____A C:\Users\Public\Desktop\HP Photosmart Essential 3.5.lnk 2012-06-15 10:20 - 2012-06-15 10:20 - 00002169 ____A C:\Users\All Users\Desktop\HP Photosmart Essential 3.5.lnk 2012-06-15 10:19 - 2012-06-15 10:19 - 00001383 ____A C:\Users\Public\Desktop\Centrum obsługi HP.lnk 2012-06-15 10:19 - 2012-06-15 10:19 - 00001383 ____A C:\Users\All Users\Desktop\Centrum obsługi HP.lnk 2012-06-15 10:19 - 2012-06-15 10:19 - 00001231 ____A C:\Users\Public\Desktop\Zakup materiałów eksploatacyjnych HP.lnk 2012-06-15 10:19 - 2012-06-15 10:19 - 00001231 ____A C:\Users\All Users\Desktop\Zakup materiałów eksploatacyjnych HP.lnk 2012-06-15 08:23 - 2010-06-10 12:53 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2012-06-14 09:57 - 2012-06-14 09:57 - 00001329 ____A C:\Users\Public\Desktop\Pajączek 5 NxG.lnk 2012-06-14 09:57 - 2012-06-14 09:57 - 00001329 ____A C:\Users\All Users\Desktop\Pajączek 5 NxG.lnk 2012-06-13 18:30 - 2012-06-13 18:30 - 00766771 ____A C:\Users\Amelka\Documents\FindMyDelivery.mht 2012-06-07 16:52 - 2012-06-07 16:52 - 00204130 ____A C:\Users\Amelka\Desktop\logo PFI.pfi 2012-06-07 12:19 - 2012-06-07 12:19 - 00001847 ____A C:\Users\Public\Desktop\QuickTime Player.lnk 2012-06-07 12:19 - 2012-06-07 12:19 - 00001847 ____A C:\Users\All Users\Desktop\QuickTime Player.lnk 2012-06-06 16:56 - 2012-06-06 16:56 - 00433664 ____A C:\Users\Amelka\Documents\rozliczeniaz.xls 2012-06-06 16:55 - 2012-06-06 16:55 - 00433664 ____A C:\Users\Amelka\Documents\rozliczenia.xls 2012-06-06 15:22 - 2012-06-06 15:03 - 00074030 ____A C:\Users\Amelka\Documents\rozliczenia.ods 2012-06-06 14:36 - 2012-06-06 14:36 - 00001158 ____A C:\Users\Public\Desktop\OpenOffice.org 3.3.lnk 2012-06-06 14:36 - 2012-06-06 14:36 - 00001158 ____A C:\Users\All Users\Desktop\OpenOffice.org 3.3.lnk 2012-05-25 11:49 - 2011-05-09 12:10 - 00024264 ____A C:\Users\Amelka\Documents\piczyński FVFK.xlsx 2012-05-25 07:56 - 2012-05-24 22:42 - 00072158 ____A C:\Users\Amelka\Desktop\dowód wewętrzny.rtf 2012-05-24 07:25 - 2012-06-21 17:14 - 00663552 ____A (Microsoft) C:\Windows\SysWOW64\XLSConverterX.ocx 2012-05-24 07:25 - 2012-06-21 17:14 - 00421888 ____A (Microsoft) C:\Windows\SysWOW64\XLSConverterX_07.ocx 2012-05-24 06:21 - 2009-07-14 06:08 - 00032608 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2012-05-22 10:04 - 2012-05-22 08:44 - 00000033 ____A C:\Users\All Users\droidcam-settings 2012-05-22 10:04 - 2012-05-22 08:44 - 00000033 ____A C:\Users\All Users\Application Data\droidcam-settings 2012-05-22 08:42 - 2012-05-22 08:42 - 00025216 ____A (Dev47Apps) C:\Windows\System32\Drivers\droidcam.sys 2012-05-21 18:48 - 2012-05-21 18:48 - 00016464 ____A C:\Windows\SysWOW64\CCCInstall_201205211948080498.log 2012-05-18 11:15 - 2012-05-18 11:15 - 00000949 ____A C:\Users\Public\Desktop\µTorrent.lnk 2012-05-18 11:15 - 2012-05-18 11:15 - 00000949 ____A C:\Users\All Users\Desktop\µTorrent.lnk 2012-05-18 03:47 - 2012-06-14 23:19 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-05-18 03:16 - 2012-06-14 23:19 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-05-18 03:06 - 2012-06-14 23:19 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-05-18 02:59 - 2012-06-14 23:19 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-05-18 02:59 - 2012-06-14 23:19 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-05-18 02:58 - 2012-06-14 23:19 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-05-18 02:58 - 2012-06-14 23:19 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-05-18 02:56 - 2012-06-14 23:19 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-05-18 02:55 - 2012-06-14 23:19 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-05-18 02:55 - 2012-06-14 23:19 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-05-18 02:54 - 2012-06-14 23:19 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-05-18 02:51 - 2012-06-14 23:19 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-05-18 02:51 - 2012-06-14 23:19 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-05-18 02:47 - 2012-06-14 23:19 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-05-18 00:11 - 2012-06-14 23:19 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-05-17 23:48 - 2012-06-14 23:19 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-05-17 23:45 - 2012-06-14 23:19 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-05-17 23:36 - 2012-06-14 23:19 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-05-17 23:35 - 2012-06-14 23:19 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-05-17 23:35 - 2012-06-14 23:19 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-05-17 23:33 - 2012-06-14 23:19 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-05-17 23:31 - 2012-06-14 23:19 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-05-17 23:29 - 2012-06-14 23:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-05-17 23:29 - 2012-06-14 23:19 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-05-17 23:27 - 2012-06-14 23:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-05-17 23:25 - 2012-06-14 23:19 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-05-17 23:24 - 2012-06-14 23:19 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-05-17 23:20 - 2012-06-14 23:19 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-05-16 10:50 - 2012-05-16 10:50 - 00008794 ____A C:\Users\Amelka\AppData\Roaming\SkrybotConfig.xml 2012-05-16 09:45 - 2012-05-16 09:45 - 22538496 ____A C:\Users\Amelka\Documents\R228440.exe 2012-05-16 09:45 - 2012-05-16 09:45 - 21927944 ____A C:\Users\Amelka\Documents\R197868.exe 2012-05-16 09:45 - 2012-05-16 09:45 - 00562988 ____A C:\Users\Amelka\Documents\R197861.exe 2012-05-16 09:45 - 2012-05-16 09:44 - 07542624 ____A C:\Users\Amelka\Documents\R237653.exe 2012-05-07 20:15 - 2012-05-07 20:15 - 00002465 ____A C:\Users\Public\Desktop\Babylon.lnk 2012-05-07 20:15 - 2012-05-07 20:15 - 00002465 ____A C:\Users\All Users\Desktop\Babylon.lnk 2012-05-07 20:15 - 2012-01-08 18:38 - 00000770 ____A C:\user.js 2012-05-01 16:31 - 2011-02-28 10:26 - 00001912 ____A C:\Windows\epplauncher.mif 2012-05-01 16:31 - 2010-06-08 17:21 - 01616560 ____A C:\Windows\SysWOW64\PerfStringBackup.INI 2012-04-23 07:12 - 2012-03-27 10:08 - 00001055 ____A C:\Users\Amelka\Desktop\Mozilla Firefox.lnk 2012-04-21 08:25 - 2012-04-21 08:25 - 00002214 ____A C:\Users\Public\Desktop\Google Earth.lnk 2012-04-21 08:25 - 2012-04-21 08:25 - 00002214 ____A C:\Users\All Users\Desktop\Google Earth.lnk 2012-04-21 08:12 - 2012-04-21 08:12 - 29421568 ____A C:\Windows\System32\config\components.iobit 2012-04-18 19:56 - 2012-04-18 19:56 - 00094208 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTimeVR.qtx 2012-04-18 19:56 - 2012-04-18 19:56 - 00069632 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTime.qts 2012-04-11 17:31 - 2011-07-07 10:36 - 00009885 ____A C:\Users\Amelka\Desktop\Klienci zest.xlsx 2012-04-10 16:10 - 2012-04-10 16:10 - 00464896 ____A C:\Users\Amelka\Documents\Kopia 2311201_3003775436.xls ========================= Known DLLs (Whitelisted) ============ ========================= Bamital & volsnap Check ============ C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ========================= Memory info ====================== Percentage of memory in use: 16% Total physical RAM: 4092.36 MB Available physical RAM: 3429.06 MB Total Pagefile: 4090.5 MB Available Pagefile: 3437.54 MB Total Virtual: 8192 MB Available Virtual: 8191.91 MB ======================= Partitions ========================= 1 Drive c: (OS) (Fixed) (Total:53.44 GB) (Free:8.59 GB) NTFS ==>[Drive with boot components (obtained from BCD)] 2 Drive d: (Nowy) (Fixed) (Total:100.7 GB) (Free:13.18 GB) NTFS 3 Drive e: (Nowy) (Fixed) (Total:150.44 GB) (Free:119.39 GB) NTFS 4 Drive f: (Nowy) (Fixed) (Total:146.48 GB) (Free:77.65 GB) NTFS 5 Drive g: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:10.84 GB) NTFS ==>[System with boot components (obtained from reading drive)] 6 Drive h: (KRD10) (CDROM) (Total:0.26 GB) (Free:0 GB) CDFS 7 Drive i: () (Removable) (Total:1.84 GB) (Free:1.59 GB) FAT 8 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Nr dysku Stan Rozmiar Wolne Dyn GPT -------- ------------- ------- ------- --- --- Dysk 0 Online 465 GB 4096 KB Dysk 1 Online 1886 MB 0 B Partitions of Disk 0: =============== Partycja ### Typ Rozmiar Przesuni©cie ------------- ---------------- ------- ------------ Partycja 1 OEM 39 MB 31 KB Partycja 2 Podstawowy 14 GB 40 MB Partycja 3 Podstawowy 53 GB 14 GB Partycja 0 Rozszerzony 397 GB 68 GB Partycja 4 Logiczny 100 GB 68 GB Partycja 5 Logiczny 150 GB 168 GB Partycja 6 Logiczny 146 GB 319 GB ================================================================================== Disk: 0 Partycja 1 Typ : DE Ukryta : Tak Aktywna : Nie Przesuni©cie w bajtach: 32256 Wolumin ### Lit Etykieta Fs Typ Rozmiar Stan Info ----------- --- ----------- ----- ---------- ------- --------- -------- * Wolumin 7 FAT Partycja 39 MB Zdrowy Ukryty ================================================================================== Disk: 0 Partycja 2 Typ : 07 Ukryta : Nie Aktywna : Nie Przesuni©cie w bajtach: 41943040 Wolumin ### Lit Etykieta Fs Typ Rozmiar Stan Info ----------- --- ----------- ----- ---------- ------- --------- -------- * Wolumin 1 G RECOVERY NTFS Partycja 14 GB Zdrowy ================================================================================== Disk: 0 Partycja 3 Typ : 07 Ukryta : Nie Aktywna : Tak Przesuni©cie w bajtach: 15770583040 Wolumin ### Lit Etykieta Fs Typ Rozmiar Stan Info ----------- --- ----------- ----- ---------- ------- --------- -------- * Wolumin 2 C OS NTFS Partycja 53 GB Zdrowy ================================================================================== Disk: 0 Partycja 4 Typ : 07 Ukryta : Nie Aktywna : Nie Przesuni©cie w bajtach: 73158098944 Wolumin ### Lit Etykieta Fs Typ Rozmiar Stan Info ----------- --- ----------- ----- ---------- ------- --------- -------- * Wolumin 3 D Nowy NTFS Partycja 100 GB Zdrowy ================================================================================== Disk: 0 Partycja 5 Typ : 07 Ukryta : Nie Aktywna : Nie Przesuni©cie w bajtach: 181287256064 Wolumin ### Lit Etykieta Fs Typ Rozmiar Stan Info ----------- --- ----------- ----- ---------- ------- --------- -------- * Wolumin 4 E Nowy NTFS Partycja 150 GB Zdrowy ================================================================================== Disk: 0 Partycja 6 Typ : 07 Ukryta : Nie Aktywna : Nie Przesuni©cie w bajtach: 342821437440 Wolumin ### Lit Etykieta Fs Typ Rozmiar Stan Info ----------- --- ----------- ----- ---------- ------- --------- -------- * Wolumin 5 F Nowy NTFS Partycja 146 GB Zdrowy ================================================================================== Partitions of Disk 1: =============== Partycja ### Typ Rozmiar Przesuni©cie ------------- ---------------- ------- ------------ Partycja 1 Podstawowy 1884 MB 67 KB ================================================================================== Disk: 1 Partycja 1 Typ : 06 Ukryta : Nie Aktywna : Nie Przesuni©cie w bajtach: 69120 Wolumin ### Lit Etykieta Fs Typ Rozmiar Stan Info ----------- --- ----------- ----- ---------- ------- --------- -------- * Wolumin 6 I FAT Wymienny 1884 MB Zdrowy ================================================================================== ========================================================== Last Boot: 2012-06-15 14:11 ======================= End Of Log ==========================