Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-03-2014 Ran by Nikodem (administrator) on CDNN on 12-03-2014 19:54:25 Running from C:\Users\Nikodem\Downloads\Programs Windows 8.1 Enterprise (X64) OS Language: Polish Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe () C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe (Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PDF Professional 8\PDFProFiltSrv.exe () C:\Windows\SysWOW64\PnkBstrA.exe (StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Internet Download Manager, Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMIntegrator64.exe (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe (SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe () C:\Program Files (x86)\WebMoney Agent\wmagent.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Murray Hurps Software Pty Ltd) C:\Program Files (x86)\Ad Muncher\AdMunch.exe (Murray Hurps Software Pty Ltd) C:\Program Files (x86)\Ad Muncher\AdMunch64.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe () C:\ProgramData\PLAY ONLINE\OnlineUpdate\ouc.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5618456 2013-09-12] (ESET) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated) HKLM\...\Run: [OODITRAY.EXE] - C:\Program Files\OO Software\DiskImage\ooditray.exe [5059880 2014-01-10] (O&O Software GmbH) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-11-22] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Ad Muncher] - C:\Program Files (x86)\Ad Muncher\AdMunch.exe [595144 2013-12-05] (Murray Hurps Software Pty Ltd) HKLM-x32\...\Run: [ISUSPM] - C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [2068856 2011-10-12] (Flexera Software LLC.) HKLM-x32\...\Run: [PDF8 Registry Controller] - C:\Program Files (x86)\Nuance\PDF Professional 8\RegistryController.exe [178576 2012-10-23] (Nuance Communications, Inc.) HKLM-x32\...\Run: [PDFProHook] - C:\Program Files (x86)\Nuance\PDF Professional 8\pdfpro8hook.exe [2013072 2012-10-23] (Nuance Communications, Inc.) HKLM-x32\...\Run: [Nuance PDF Converter Professional 8-reminder] - C:\Program Files (x86)\Nuance\PDF Professional 8\Ereg\Ereg.exe [333712 2012-10-11] (Nuance Communications, Inc.) HKLM-x32\...\Run: [PowerDVD13Agent] - C:\Program Files (x86)\CyberLink\PowerDVD13\PowerDVD13Agent.exe [517144 2013-10-23] (CyberLink Corp.) HKLM-x32\...\Run: [TaskMngr] - wscript.exe "C:\Program Files (x86)\Common Files\Lenovo\data.js" HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3478392 2013-12-21] (Adobe Systems Inc.) HKLM-x32\...\Run: [EEventManager] - C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1057408 2012-06-08] (SEIKO EPSON CORPORATION) HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [wmagent.exe] - C:\Program Files (x86)\WebMoney Agent\wmagent.exe [210400 2009-10-19] () HKLM-x32\...\Run: [e-Kiosk] - "C:\Program Files (x86)\e-Kiosk Reader\eGazetaST.exe" HKLM\...\Runonce: [ASYNCMAC] - rundll32.exe streamci,StreamingDeviceSetup {eeab7790-c514-11d1-b42b-00805fc1270e},asyncmac,{ad498944-762f-11d0-8dcb-00c04fc3358c},C:\Windows\INF\netrasa.inf,Ndis-Mp-AsyncMac HKU\S-1-5-21-2167699055-471404779-3156854112-1001\...\Run: [Raptr] - C:\Program Files (x86)\Raptr\raptrstub.exe [55360 2013-11-12] (Raptr, Inc) HKU\S-1-5-21-2167699055-471404779-3156854112-1001\...\Run: [HydraVisionDesktopManager] - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [389120 2013-11-22] (AMD) HKU\S-1-5-21-2167699055-471404779-3156854112-1001\...\Run: [AlcoholAutomount] - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team) HKU\S-1-5-21-2167699055-471404779-3156854112-1001\...\Run: [IDMan] - C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3821136 2013-12-20] (Tonec Inc.) HKU\S-1-5-21-2167699055-471404779-3156854112-1001\...\Run: [GG] - C:\Users\Nikodem\AppData\Local\GG\Application\gghub.exe [4028480 2014-03-05] (GG Network S.A.) HKU\S-1-5-21-2167699055-471404779-3156854112-1001\...\Run: [Reasonable NoClone] - "C:\Program Files (x86)\Reasonable NoClone 2013\NoClone.exe" null /startup HKU\S-1-5-21-2167699055-471404779-3156854112-1001\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x00000000 HKU\S-1-5-21-2167699055-471404779-3156854112-1001\...\MountPoints2: {9736204d-a9d6-11e3-82aa-20cf30ad16fe} - "N:\AutoRun.exe" HKU\S-1-5-21-2167699055-471404779-3156854112-1001\...\MountPoints2: {97362096-a9d6-11e3-82aa-20cf30ad16fe} - "N:\AutoRun.exe" ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.pl/ BHO: IDM integration (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: IDM integration (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.) BHO-x32: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Professional 8\Bin\PlusIEContextMenu.dll (Zeon Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Gaaiho PDF Conversion Toolbar Helper - {C7DA0384-42AA-428c-B832-88AC343DE1A8} - C:\Program Files (x86)\Nuance\PDF Professional 8\bin\GZeonIEFavClient.dll (Zeon Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: WebMoneyAdvisorBHO - {E7D2CB77-6E2D-4C1F-B485-D50506B9FA6B} - C:\Program Files (x86)\WebMoney Advisor\2.2.4\wmadvisor.dll (CJSC Computing Forces) BHO-x32: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Nuance PDF - {BCCE15AE-AC7E-4bc9-94AF-2A714A412BCB} - C:\Program Files (x86)\Nuance\PDF Professional 8\bin\GZeonIEFavClient.dll (Zeon Corporation) Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - WebMoney Advisor - {405DFEAE-1D2F-4649-BE08-C92313C3E1CE} - C:\Program Files (x86)\WebMoney Advisor\2.2.4\wmadvisor.dll (CJSC Computing Forces) Hosts: Hosts file not detected in the default directory Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{E9854D10-2386-46AA-A5BD-2218D6872994}: [NameServer]193.41.112.14 193.41.112.18 FireFox: ======== FF ProfilePath: C:\Users\Nikodem\AppData\Roaming\Mozilla\Firefox\Profiles\7dr5kz8g.default FF Homepage: https://www.google.pl/ FF NetworkProxy: "no_proxies_on", "" FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll No File FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Nero.com/KM - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG) FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin-x32: ZEON/PDF,version=2.0 - C:\Program Files (x86)\Nuance\PDF Professional 8\bin\nppdf.dll (Zeon Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Nikodem\AppData\Roaming\Mozilla\Firefox\Profiles\7dr5kz8g.default\searchplugins\ex.xml FF Extension: Internet Download Accelerator Media Monitor - C:\Users\Nikodem\AppData\Roaming\Mozilla\Firefox\Profiles\7dr5kz8g.default\Extensions\idamm@westbyte.com [2013-12-31] FF Extension: MEGA - C:\Users\Nikodem\AppData\Roaming\Mozilla\Firefox\Profiles\7dr5kz8g.default\Extensions\firefox@mega.co.nz.xpi [2013-12-31] FF Extension: One Click Proxy - C:\Users\Nikodem\AppData\Roaming\Mozilla\Firefox\Profiles\7dr5kz8g.default\Extensions\jid0-zXo3XFGyiDalgkeEO4UYJTUwo2I@jetpack.xpi [2014-01-30] FF Extension: New Tab Homepage - C:\Users\Nikodem\AppData\Roaming\Mozilla\Firefox\Profiles\7dr5kz8g.default\Extensions\{66E978CD-981F-47DF-AC42-E3CF417C1467}.xpi [2013-12-31] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2014-01-09] FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird FF Extension: No Name - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2013-12-07] FF HKCU\...\Firefox\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Nikodem\AppData\Roaming\IDM\idmmzcc5 FF Extension: IDM CC - C:\Users\Nikodem\AppData\Roaming\IDM\idmmzcc5 [2013-12-20] FF HKCU\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Nikodem\AppData\Roaming\IDM\idmmzcc5 FF Extension: IDM CC - C:\Users\Nikodem\AppData\Roaming\IDM\idmmzcc5 [2013-12-20] ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-11-22] (Advanced Micro Devices, Inc.) S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team) R2 CyberLink PowerDVD 13 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe [77576 2013-10-23] (CyberLink) R2 CyberLink PowerDVD 13 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe [327432 2013-10-23] (CyberLink) R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2135232 2014-01-28] () R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [1337752 2013-09-12] (ESET) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] () R2 PDFProFiltSrv; C:\Program Files (x86)\Nuance\PDF Professional 8\PDFProFiltSrv.exe [135056 2012-10-23] (Nuance Communications, Inc.) S2 PLAY ONLINE. RunOuc; C:\Program Files (x86)\PLAY ONLINE\UpdateDog\ouc.exe [246112 2014-03-12] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-01-01] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) R0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.) R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-19] (Advanced Micro Devices) S3 athur; C:\Windows\system32\DRIVERS\athuw8x.sys [3744256 2012-11-21] (Qualcomm Atheros Communications, Inc.) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2013-09-24] (Advanced Micro Devices) U3 axscsidrv; C:\Windows\System32\Drivers\axscsidrv.sys [293888 2013-12-05] (Alcohol Soft Development Team) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider) S3 DrvSnSht; C:\Program Files (x86)\R-Drive Image\DrvSnSht64.sys [132432 2010-06-01] (R-TT Inc.) U3 dtscsidrv; C:\Windows\System32\Drivers\dtscsidrv.sys [309248 2014-01-28] (Disc Soft Ltd) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET) R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [239296 2013-09-17] (ESET) R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET) R2 epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [157432 2013-09-17] (ESET) U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [117248 2014-03-12] (Huawei Technologies Co., Ltd.) R1 Ext2Fsd; C:\Windows\System32\Drivers\Ext2Fsd.sys [769816 2011-07-09] (www.ext2fsd.com) S3 huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [229376 2014-03-12] (Huawei Technologies Co., Ltd.) S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation) R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation) S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-09-30] (Microsoft Corporation) S3 libusb0; C:\Windows\system32\DRIVERS\libusb0.sys [52832 2013-12-05] (http://libusb-win32.sourceforge.net) S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] () R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) R0 oodivd; C:\Windows\System32\DRIVERS\oodivd.sys [255680 2014-01-10] (O&O Software GmbH) R0 oodivdh; C:\Windows\System32\DRIVERS\oodivdh.sys [44736 2014-01-10] (O&O Software GmbH) S3 OSFMount; C:\Program Files\OSFMount\OSFMount.sys [552888 2013-10-18] (PassMark Software) S3 R-ImageDisk; C:\Program Files (x86)\R-Drive Image\R-ImageDisk64.sys [181840 2013-01-15] (R-TT Inc.) S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation) S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [13368 2013-01-23] () S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2013-12-05] (Duplex Secure Ltd.) S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation) S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation) R2 {09F57980-3432-4AFC-957D-27AC45FAE1F5}; C:\Program Files (x86)\CyberLink\PowerDVD13\Common\NavFilter\000.fcl [130320 2013-10-23] (CyberLink Corp.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-12 19:53 - 2014-03-12 19:54 - 00000000 ____D () C:\FRST 2014-03-12 19:29 - 2014-03-12 19:29 - 00000000 _____ () C:\Users\Nikodem\Downloads\battlelog-web-plugins_2.3.2_131.exe.hpa0p2s.partial 2014-03-12 16:42 - 2014-03-12 16:42 - 00001055 _____ () C:\Users\Public\Desktop\PLAY ONLINE.lnk 2014-03-12 16:42 - 2014-03-12 16:42 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jucdcacm_01007.Wdf 2014-03-12 16:42 - 2014-03-12 16:42 - 00000000 ____D () C:\ProgramData\PLAY ONLINE 2014-03-12 16:42 - 2014-03-12 16:41 - 01490656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfCoInstaller01007.dll 2014-03-12 16:42 - 2014-03-12 16:41 - 01001472 _____ (DiBcom SA) C:\Windows\system32\Drivers\mod7700.sys 2014-03-12 16:42 - 2014-03-12 16:41 - 00439808 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbwwan.sys 2014-03-12 16:42 - 2014-03-12 16:41 - 00229376 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juwwanecm.sys 2014-03-12 16:42 - 2014-03-12 16:41 - 00225920 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbmdm.sys 2014-03-12 16:42 - 2014-03-12 16:41 - 00117248 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwusbdev.sys 2014-03-12 16:42 - 2014-03-12 16:41 - 00104448 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcacm.sys 2014-03-12 16:42 - 2014-03-12 16:41 - 00090112 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jubusenum.sys 2014-03-12 16:42 - 2014-03-12 16:41 - 00073216 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcecm.sys 2014-03-12 16:42 - 2014-03-12 16:41 - 00032768 _____ (Huawei Tech. Co., Ltd.) C:\Windows\system32\Drivers\ewdcsc.sys 2014-03-12 16:42 - 2014-03-12 16:41 - 00030720 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juextctrl.sys 2014-03-12 16:42 - 2014-03-12 16:41 - 00022016 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwupgrade.sys 2014-03-12 16:42 - 2014-03-12 16:41 - 00013952 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_usbenumfilter.sys 2014-03-12 16:41 - 2014-03-12 16:42 - 00000000 ____D () C:\ProgramData\DatacardService 2014-03-12 16:41 - 2014-03-12 16:42 - 00000000 ____D () C:\Program Files (x86)\PLAY ONLINE 2014-03-12 16:40 - 2014-03-12 16:42 - 00004038 _____ () C:\Windows\setupact.log 2014-03-12 16:40 - 2014-03-12 16:40 - 00000000 _____ () C:\Windows\setuperr.log 2014-03-12 14:44 - 2014-03-12 14:44 - 00000000 ____D () C:\Users\Nikodem\Documents\Corel PaintShop Pro 2014-03-12 14:44 - 2014-03-12 14:44 - 00000000 ____D () C:\Users\Nikodem\AppData\Local\Corel PaintShop Pro 2014-03-12 12:18 - 2014-03-12 14:33 - 00000000 ____D () C:\Program Files\CCleaner 2014-03-12 11:43 - 2014-03-12 11:49 - 00000000 ____D () C:\AdwCleaner 2014-03-12 10:22 - 2014-03-12 00:46 - 4269308156 _____ () C:\Users\Nikodem\Desktop\Spotkanie n.t. wiatraków Goińczyce 09-03-2014r.mp4 2014-03-12 08:47 - 2014-03-12 08:47 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\Malwarebytes 2014-03-12 08:46 - 2014-03-12 08:46 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-11 18:42 - 2014-03-11 18:43 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\MAGIX 2014-03-11 18:41 - 2014-03-11 18:43 - 00000000 ____D () C:\ProgramData\MAGIX 2014-03-11 10:53 - 2014-03-12 14:51 - 00000000 ____D () C:\Users\Nikodem\Desktop\pulpit 2014-03-05 17:23 - 2014-03-05 17:23 - 00000000 ____D () C:\Program Files (x86)\PGWARE 2014-03-04 20:01 - 2014-03-11 09:30 - 00000904 _____ () C:\Users\Nikodem\AppData\Roaming\__AvidCloudManager.log 2014-03-04 20:01 - 2014-03-11 09:29 - 00000400 _____ () C:\Users\Nikodem\AppData\Roaming\CDNN.MTBF.txt 2014-03-04 20:01 - 2014-03-11 09:29 - 00000000 ____D () C:\Users\Nikodem\AppData\Local\Pinnacle 2014-03-04 20:01 - 2014-03-04 21:12 - 00000904 _____ () C:\Users\Nikodem\AppData\Roaming\__AvidCloudManagerPrevious.log 2014-03-04 20:01 - 2014-03-04 20:01 - 00000000 ____D () C:\Users\Nikodem\Documents\InstantCDDVD 2014-03-04 20:00 - 2014-03-04 20:00 - 00000000 ____D () C:\Users\Nikodem\AppData\Local\Pinnacle_Studio_17 2014-03-04 10:20 - 2014-03-12 14:29 - 00000000 ____D () C:\Program Files (x86)\Pinnacle 2014-03-04 10:19 - 2014-03-04 20:00 - 00000349 _____ () C:\Users\Public\Documents\PCLECHAL.INI 2014-03-04 10:16 - 2014-03-12 12:01 - 00000000 ____D () C:\ProgramData\Pinnacle 2014-03-03 12:05 - 2014-03-03 12:05 - 00000424 _____ () C:\Users\Nikodem\Downloads\README.TXT 2014-03-01 14:13 - 2014-03-01 15:02 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\Audacity 2014-03-01 14:13 - 2014-03-01 14:13 - 00001019 _____ () C:\Users\Nikodem\Desktop\Audacity.lnk 2014-03-01 14:13 - 2014-03-01 14:13 - 00000000 ____D () C:\Program Files (x86)\Audacity 2014-02-27 23:37 - 2014-02-27 23:37 - 31356345 _____ () C:\Users\Nikodem\Desktop\15 Gdzie moja wolność.flac 2014-02-27 23:06 - 2014-02-27 23:06 - 00000000 ____D () C:\Users\Nikodem\Documents\Ashampoo Burning Studio 2014 2014-02-27 17:58 - 2014-02-27 17:58 - 00080352 _____ () C:\Users\Nikodem\Downloads\org.jdownloader.settings.AccountSettings.accounts(1).ejs 2014-02-27 17:32 - 2014-02-27 17:32 - 00066064 _____ () C:\Users\Nikodem\Downloads\org.jdownloader.settings.AccountSettings.accounts.ejs 2014-02-26 21:22 - 2014-03-01 16:09 - 00000209 _____ () C:\Users\Nikodem\Desktop\nba.txt 2014-02-26 07:30 - 2014-02-26 07:31 - 00000000 ____D () C:\Windows\KJ 2014-02-24 19:51 - 2014-02-24 19:51 - 00000669 _____ () C:\Users\Nikodem\Desktop\Wgrywanie listy kanałów.txt 2014-02-24 03:53 - 2014-02-24 03:53 - 00000000 ____D () C:\Users\Nikodem\AppData\Local\Adobe_Systems_Incorporate 2014-02-24 03:52 - 2014-02-24 17:37 - 00000000 ____D () C:\Users\Nikodem\Documents\My Digital Editions 2014-02-24 03:46 - 2014-03-12 14:31 - 00000000 ____D () C:\Program Files (x86)\Mobogenie 2014-02-24 03:42 - 2014-03-12 12:07 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\OpenCandy 2014-02-24 03:42 - 2014-02-24 03:42 - 00000000 ____D () C:\Users\Nikodem\Documents\Anvsoft 2014-02-24 03:42 - 2014-02-24 03:42 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\AnvsoftPdfTools 2014-02-24 03:42 - 2014-02-24 03:42 - 00000000 ____D () C:\Program Files (x86)\AnvSoft 2014-02-24 02:40 - 2014-03-05 21:17 - 00001249 _____ () C:\Users\Nikodem\Desktop\NIE.txt 2014-02-21 16:18 - 2014-02-21 16:18 - 00001319 _____ () C:\Users\Public\Desktop\Ashampoo Burning Studio 2014.lnk 2014-02-21 13:51 - 2014-02-21 16:38 - 00000000 ____D () C:\Users\Nikodem\Desktop\Dj Wituś 2014-02-21 13:42 - 2014-02-21 13:42 - 00013223 _____ () C:\Users\Nikodem\Downloads\DJ_Witus_-_Gorace_wakacje_ 1997 _[FLAC]_[Z3K][Torrenty.org].torrent 2014-02-21 01:58 - 2014-02-21 01:58 - 00013011 _____ () C:\Users\Nikodem\Downloads\B248533F9234BE887F17C35012D6976764DFFC07.torrent 2014-02-20 22:43 - 2014-02-20 22:46 - 00000183 _____ () C:\Users\Nikodem\Desktop\passy.txt 2014-02-19 11:16 - 2014-02-19 11:16 - 00000000 ____D () C:\Users\Nikodem\AppData\Local\eGazety 2014-02-19 11:15 - 2014-02-19 11:15 - 00000000 ____D () C:\Program Files (x86)\eGazety Sp. z o. o 2014-02-19 10:05 - 2014-02-19 10:05 - 00001426 _____ () C:\Users\Nikodem\Desktop\ps3-hack.txt 2014-02-18 13:27 - 2014-02-20 11:41 - 00000498 _____ () C:\Users\Nikodem\Desktop\Top Gear.txt 2014-02-17 20:41 - 2014-02-17 20:44 - 00000000 ____D () C:\Users\Nikodem\zdzd 2014-02-17 20:19 - 2014-02-17 20:40 - 00000000 ____D () C:\Users\Nikodem\Desktop\rrrr 2014-02-17 18:32 - 2014-02-23 15:07 - 00000000 ____D () C:\Users\Nikodem\Cropped 2014-02-17 18:28 - 2014-02-17 18:28 - 00000000 ____D () C:\Program Files (x86)\JPEGCrops 2014-02-17 18:16 - 2014-02-17 18:22 - 00000000 ____D () C:\output 2014-02-17 17:59 - 2014-02-17 18:14 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\PhotoScape 2014-02-17 17:59 - 2014-02-17 17:59 - 00001043 _____ () C:\Users\Nikodem\Desktop\PhotoScape.lnk 2014-02-17 17:59 - 2014-02-17 17:59 - 00000000 ____D () C:\Program Files (x86)\PhotoScape 2014-02-17 17:34 - 2014-02-17 17:34 - 00001010 _____ () C:\Users\Nikodem\Desktop\IrfanView.lnk 2014-02-16 15:46 - 2014-02-16 15:46 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf 2014-02-16 10:31 - 2014-02-16 10:31 - 00000430 _____ () C:\Users\Nikodem\Downloads\[www.tnt24.info] PSBreak Open Split v1.3 [PS3] [PL [JB] [HOMEBREW].torrent 2014-02-15 23:51 - 2013-11-27 16:34 - 03210528 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2014-02-15 23:51 - 2013-11-27 14:47 - 02804528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2014-02-15 23:51 - 2013-11-26 11:13 - 04191232 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-02-15 23:51 - 2013-11-26 10:21 - 18577920 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll 2014-02-15 23:51 - 2013-11-23 12:49 - 21196664 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-02-15 23:51 - 2013-11-23 04:57 - 00637952 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe 2014-02-15 23:51 - 2013-11-23 04:48 - 00479744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe 2014-02-15 23:51 - 2013-11-23 04:25 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll 2014-02-15 23:51 - 2013-11-23 04:25 - 00584192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll 2014-02-15 23:50 - 2013-12-09 01:34 - 01227264 _____ (Microsoft Corporation) C:\Windows\system32\mispace.dll 2014-02-15 23:50 - 2013-12-09 01:04 - 00980480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mispace.dll 2014-02-15 23:50 - 2013-11-27 16:27 - 00809872 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll 2014-02-15 23:50 - 2013-11-27 15:00 - 00663680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll 2014-02-15 23:50 - 2013-11-27 13:02 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ipnat.sys 2014-02-15 23:50 - 2013-11-27 11:54 - 00461824 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2014-02-15 23:50 - 2013-11-27 11:24 - 00306688 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2014-02-15 23:50 - 2013-11-27 11:08 - 00336384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2014-02-15 23:50 - 2013-11-27 10:46 - 00273920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2014-02-15 23:50 - 2013-11-27 10:41 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll 2014-02-15 23:50 - 2013-11-27 10:17 - 00263168 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll 2014-02-15 23:50 - 2013-11-27 10:10 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.dll 2014-02-15 23:50 - 2013-11-27 09:58 - 01503232 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll 2014-02-15 23:50 - 2013-11-27 09:56 - 00218112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.dll 2014-02-15 23:50 - 2013-11-27 05:01 - 00385614 _____ () C:\Windows\system32\ApnDatabase.xml 2014-02-15 23:50 - 2013-11-26 14:22 - 01928144 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll 2014-02-15 23:50 - 2013-11-26 14:20 - 02131120 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll 2014-02-15 23:50 - 2013-11-26 14:20 - 01399176 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll 2014-02-15 23:50 - 2013-11-26 14:20 - 01374384 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll 2014-02-15 23:50 - 2013-11-26 12:50 - 01371312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll 2014-02-15 23:50 - 2013-11-26 12:44 - 02142936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll 2014-02-15 23:50 - 2013-11-26 12:44 - 01204968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll 2014-02-15 23:50 - 2013-11-26 09:28 - 13925888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2014-02-15 23:50 - 2013-11-25 02:45 - 00142680 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS 2014-02-15 23:50 - 2013-11-25 02:32 - 01119064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2014-02-15 23:50 - 2013-11-25 00:30 - 00513536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll 2014-02-15 23:50 - 2013-11-25 00:28 - 00589824 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll 2014-02-15 23:50 - 2013-11-23 13:47 - 00032088 _____ (Microsoft Corporation) C:\Windows\system32\ploptin.dll 2014-02-15 23:50 - 2013-11-23 09:19 - 18642504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-02-15 23:50 - 2013-11-23 08:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\bi.dll 2014-02-15 23:50 - 2013-11-23 08:13 - 00019456 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\BtaMPM.sys 2014-02-15 23:50 - 2013-11-23 08:08 - 00403456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2014-02-15 23:50 - 2013-11-23 05:50 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\SystemEventsBrokerServer.dll 2014-02-15 23:50 - 2013-11-23 04:19 - 02617344 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-02-15 23:50 - 2013-11-23 04:15 - 02295808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-02-15 23:50 - 2013-11-21 07:58 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\deviceregistration.dll 2014-02-15 23:50 - 2013-11-21 07:26 - 01415680 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-02-15 23:50 - 2013-11-16 06:11 - 00764856 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll 2014-02-15 23:50 - 2013-11-15 19:19 - 00669344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll 2014-02-15 23:50 - 2013-11-15 15:59 - 00470016 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll 2014-02-15 23:50 - 2013-11-15 15:25 - 00433664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll 2014-02-15 23:50 - 2013-11-15 15:08 - 00202240 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll 2014-02-15 23:50 - 2013-11-15 14:24 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-02-15 23:50 - 2013-11-05 21:12 - 02551128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-02-15 23:50 - 2013-10-31 01:29 - 00745336 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-02-15 23:50 - 2013-10-31 00:41 - 00552624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2014-02-15 09:30 - 2014-02-15 09:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-14 21:37 - 2014-02-18 20:49 - 00000211 _____ () C:\Users\Nikodem\Desktop\wwe.txt 2014-02-14 21:31 - 2014-03-06 23:50 - 00000000 ____D () C:\Users\Nikodem\Desktop\PS3 2014-02-14 09:40 - 2014-02-14 09:40 - 00001736 _____ () C:\Users\Public\Desktop\Defraggler.lnk 2014-02-14 09:40 - 2014-02-14 09:40 - 00000000 ____D () C:\Program Files\Defraggler 2014-02-14 09:36 - 2014-03-12 14:30 - 00000000 ____D () C:\Program Files\Recuva 2014-02-14 08:22 - 2014-02-14 08:22 - 00004040 _____ () C:\Windows\system32\Drivers\etc\hosts.ics 2014-02-14 08:15 - 2014-03-12 14:30 - 00000000 ____D () C:\Program Files\Speccy 2014-02-14 08:15 - 2014-03-12 12:25 - 00000000 ____D () C:\Users\Nikodem\AppData\Local\CrashDumps 2014-02-13 23:11 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-13 23:11 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-13 23:11 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-13 23:11 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-13 23:11 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-13 23:11 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-13 23:11 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-13 23:11 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-13 23:11 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-13 23:11 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-13 23:11 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-13 23:11 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-13 23:11 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-13 23:11 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-13 23:11 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-13 23:11 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-13 23:11 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-13 23:11 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-13 23:11 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-13 23:11 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-13 23:11 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-13 23:11 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-13 23:11 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-13 23:11 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-13 23:11 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-13 23:11 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-13 23:11 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-13 23:11 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-13 23:11 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-13 23:11 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-13 23:11 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-13 23:11 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-13 23:11 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-13 23:11 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-13 23:11 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-13 23:11 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-13 23:11 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-13 22:57 - 2013-12-09 01:19 - 00570880 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-13 22:57 - 2013-12-09 00:55 - 00444928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-13 22:56 - 2014-01-07 06:00 - 02397184 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-13 22:56 - 2014-01-07 05:30 - 02071552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-13 22:56 - 2013-12-09 01:27 - 02152448 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-13 22:56 - 2013-12-09 00:54 - 01317376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-13 22:56 - 2013-11-21 07:42 - 04604416 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-13 22:56 - 2013-11-21 06:44 - 03936256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-13 22:50 - 2014-01-04 21:50 - 01462216 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll 2014-02-13 22:50 - 2014-01-04 20:22 - 01202888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\propsys.dll 2014-02-13 22:50 - 2014-01-04 15:30 - 13209088 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll 2014-02-13 22:50 - 2014-01-04 15:23 - 11702272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2014-02-13 22:50 - 2014-01-04 14:42 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll 2014-02-13 22:50 - 2014-01-04 14:40 - 07416832 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll 2014-02-13 22:50 - 2014-01-04 14:36 - 00830976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll 2014-02-13 22:50 - 2014-01-04 14:28 - 04961792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll 2014-02-13 22:50 - 2013-12-21 03:10 - 00009701 _____ () C:\Windows\SysWOW64\connectedsearch-results.searchconnector-ms 2014-02-13 22:50 - 2013-12-21 03:10 - 00009701 _____ () C:\Windows\system32\connectedsearch-results.searchconnector-ms 2014-02-13 22:47 - 2013-12-20 11:10 - 01113040 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-02-13 22:47 - 2013-12-20 07:13 - 00835584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-02-13 22:47 - 2013-12-09 03:57 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-13 22:47 - 2013-12-09 02:51 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-13 22:46 - 2014-01-07 08:03 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\pcaui.exe 2014-02-13 22:46 - 2014-01-07 06:59 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pcaui.exe 2014-02-13 22:41 - 2014-01-09 09:25 - 02804224 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2014-02-13 22:41 - 2014-01-09 08:59 - 01020928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll 2014-02-13 22:41 - 2014-01-09 08:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\winbici.dll 2014-02-13 22:41 - 2014-01-09 08:49 - 00919040 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll 2014-02-13 22:41 - 2014-01-09 08:44 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveTelemetry.dll 2014-02-13 22:41 - 2014-01-09 08:43 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveShell.dll 2014-02-13 22:41 - 2014-01-09 08:29 - 00105984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SkyDriveShell.dll 2014-02-13 22:41 - 2014-01-09 08:28 - 04217344 _____ (Microsoft Corporation) C:\Windows\system32\SyncEngine.dll 2014-02-13 22:41 - 2014-01-09 08:28 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll 2014-02-13 22:41 - 2014-01-09 08:18 - 00870912 _____ (Microsoft Corporation) C:\Windows\system32\SkyDrive.exe 2014-02-12 21:51 - 2014-02-12 21:51 - 00000000 ____D () C:\Users\Nikodem\Desktop\Corel PaintShop Pro X6 2014-02-12 15:22 - 2014-03-12 12:07 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\Ulead Systems 2014-02-12 15:22 - 2014-03-12 12:07 - 00000000 ____D () C:\ProgramData\Corel 2014-02-12 15:22 - 2014-03-12 12:06 - 00000000 ____D () C:\Program Files\Corel 2014-02-12 15:09 - 2014-03-12 11:59 - 00000000 ____D () C:\Program Files (x86)\Corel 2014-02-12 14:42 - 2014-02-12 14:42 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\Corel 2014-02-11 17:57 - 2014-03-10 01:35 - 00000000 ____D () C:\Program Files (x86)\MSI Afterburner 2014-02-11 17:57 - 2014-02-11 17:57 - 00001098 _____ () C:\Users\Nikodem\Desktop\MSI Afterburner.lnk 2014-02-11 17:57 - 2014-02-11 17:57 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-02-11 17:57 - 2014-02-11 17:57 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner 2014-02-10 10:03 - 2014-02-10 10:03 - 00000000 ____D () C:\Program Files (x86)\Monkey's Audio 2014-02-10 10:03 - 2013-06-26 22:38 - 00446976 _____ (Matthew T. Ashland) C:\Windows\SysWOW64\MACDll.dll 2014-02-10 09:53 - 2013-07-07 11:56 - 00224016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TABCTL32.OCX 2014-02-10 09:50 - 2014-02-10 09:50 - 00001258 _____ () C:\Users\Public\Desktop\Medieval CUE Splitter.lnk 2014-02-10 09:50 - 2014-02-10 09:50 - 00000000 ____D () C:\Program Files (x86)\Medieval Software 2014-02-10 08:57 - 2014-03-12 11:59 - 00000000 ____D () C:\Program Files (x86)\eBookConverter 2014-02-10 08:57 - 2014-02-10 08:57 - 00000000 ____D () C:\Users\Nikodem\Documents\eBook Converter 2014-02-10 07:57 - 2014-02-10 07:57 - 00000000 ____D () C:\Users\Nikodem\ResEdit Projects ==================== One Month Modified Files and Folders ======= 2014-03-12 19:54 - 2014-03-12 19:53 - 00000000 ____D () C:\FRST 2014-03-12 19:29 - 2014-03-12 19:29 - 00000000 _____ () C:\Users\Nikodem\Downloads\battlelog-web-plugins_2.3.2_131.exe.hpa0p2s.partial 2014-03-12 19:28 - 2013-12-05 12:32 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\DMCache 2014-03-12 18:56 - 2013-12-05 12:39 - 00000930 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-12 18:56 - 2013-12-05 11:34 - 01357829 _____ () C:\Windows\WindowsUpdate.log 2014-03-12 18:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru 2014-03-12 16:43 - 2013-09-30 05:15 - 01825074 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-12 16:43 - 2013-09-30 04:56 - 00805918 _____ () C:\Windows\system32\perfh015.dat 2014-03-12 16:43 - 2013-09-30 04:56 - 00163272 _____ () C:\Windows\system32\perfc015.dat 2014-03-12 16:42 - 2014-03-12 16:42 - 00001055 _____ () C:\Users\Public\Desktop\PLAY ONLINE.lnk 2014-03-12 16:42 - 2014-03-12 16:42 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jucdcacm_01007.Wdf 2014-03-12 16:42 - 2014-03-12 16:42 - 00000000 ____D () C:\ProgramData\PLAY ONLINE 2014-03-12 16:42 - 2014-03-12 16:41 - 00000000 ____D () C:\ProgramData\DatacardService 2014-03-12 16:42 - 2014-03-12 16:41 - 00000000 ____D () C:\Program Files (x86)\PLAY ONLINE 2014-03-12 16:42 - 2014-03-12 16:40 - 00004038 _____ () C:\Windows\setupact.log 2014-03-12 16:41 - 2014-03-12 16:42 - 01490656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfCoInstaller01007.dll 2014-03-12 16:41 - 2014-03-12 16:42 - 01001472 _____ (DiBcom SA) C:\Windows\system32\Drivers\mod7700.sys 2014-03-12 16:41 - 2014-03-12 16:42 - 00439808 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbwwan.sys 2014-03-12 16:41 - 2014-03-12 16:42 - 00229376 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juwwanecm.sys 2014-03-12 16:41 - 2014-03-12 16:42 - 00225920 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbmdm.sys 2014-03-12 16:41 - 2014-03-12 16:42 - 00117248 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwusbdev.sys 2014-03-12 16:41 - 2014-03-12 16:42 - 00104448 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcacm.sys 2014-03-12 16:41 - 2014-03-12 16:42 - 00090112 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jubusenum.sys 2014-03-12 16:41 - 2014-03-12 16:42 - 00073216 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jucdcecm.sys 2014-03-12 16:41 - 2014-03-12 16:42 - 00032768 _____ (Huawei Tech. Co., Ltd.) C:\Windows\system32\Drivers\ewdcsc.sys 2014-03-12 16:41 - 2014-03-12 16:42 - 00030720 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_juextctrl.sys 2014-03-12 16:41 - 2014-03-12 16:42 - 00022016 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwupgrade.sys 2014-03-12 16:41 - 2014-03-12 16:42 - 00013952 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_usbenumfilter.sys 2014-03-12 16:41 - 2014-01-22 08:52 - 01490656 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll 2014-03-12 16:40 - 2014-03-12 16:40 - 00000000 _____ () C:\Windows\setuperr.log 2014-03-12 16:21 - 2013-12-05 12:32 - 00000000 ____D () C:\Users\Nikodem\Downloads\Compressed 2014-03-12 16:20 - 2013-12-05 12:32 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\IDM 2014-03-12 15:06 - 2013-12-05 11:40 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2167699055-471404779-3156854112-1001 2014-03-12 14:51 - 2014-03-11 10:53 - 00000000 ____D () C:\Users\Nikodem\Desktop\pulpit 2014-03-12 14:44 - 2014-03-12 14:44 - 00000000 ____D () C:\Users\Nikodem\Documents\Corel PaintShop Pro 2014-03-12 14:44 - 2014-03-12 14:44 - 00000000 ____D () C:\Users\Nikodem\AppData\Local\Corel PaintShop Pro 2014-03-12 14:41 - 2014-01-31 10:31 - 00000000 ____D () C:\Program Files\priPrinter 2014-03-12 14:40 - 2014-01-17 22:44 - 00000000 ____D () C:\Users\Nikodem\Documents\pdfFactory 2014-03-12 14:33 - 2014-03-12 12:18 - 00000000 ____D () C:\Program Files\CCleaner 2014-03-12 14:31 - 2014-02-24 03:46 - 00000000 ____D () C:\Program Files (x86)\Mobogenie 2014-03-12 14:31 - 2014-01-03 12:46 - 00000000 ____D () C:\Program Files (x86)\Wedding Album Maker Gold 2014-03-12 14:30 - 2014-02-14 09:36 - 00000000 ____D () C:\Program Files\Recuva 2014-03-12 14:30 - 2014-02-14 08:15 - 00000000 ____D () C:\Program Files\Speccy 2014-03-12 14:29 - 2014-03-04 10:20 - 00000000 ____D () C:\Program Files (x86)\Pinnacle 2014-03-12 14:21 - 2013-12-05 11:36 - 00003976 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{025D263E-3983-4C81-881C-7DECAAE8056D} 2014-03-12 14:15 - 2013-12-06 12:09 - 00964096 ___SH () C:\Users\Nikodem\Downloads\Thumbs.db 2014-03-12 13:51 - 2013-12-06 12:31 - 10029056 ___SH () C:\Users\Nikodem\Desktop\Thumbs.db 2014-03-12 13:49 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\NDF 2014-03-12 12:58 - 2013-12-05 12:39 - 00003818 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-12 12:26 - 2014-01-25 19:30 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\TS3Client 2014-03-12 12:25 - 2014-02-14 08:15 - 00000000 ____D () C:\Users\Nikodem\AppData\Local\CrashDumps 2014-03-12 12:25 - 2013-12-19 20:15 - 00000000 ____D () C:\Windows\Minidump 2014-03-12 12:25 - 2013-12-05 11:30 - 00000000 ____D () C:\Windows\Panther 2014-03-12 12:21 - 2013-12-05 18:16 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\GG 2014-03-12 12:21 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness 2014-03-12 12:08 - 2013-12-05 11:34 - 00000000 ____D () C:\Users\Nikodem 2014-03-12 12:08 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-12 12:07 - 2014-02-24 03:42 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\OpenCandy 2014-03-12 12:07 - 2014-02-12 15:22 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\Ulead Systems 2014-03-12 12:07 - 2014-02-12 15:22 - 00000000 ____D () C:\ProgramData\Corel 2014-03-12 12:07 - 2013-12-05 11:49 - 00000000 ____D () C:\Users\Nikodem\AppData\Local\SwvUpdater 2014-03-12 12:07 - 2013-08-22 14:36 - 00000000 ____D () C:\Windows\system32\Sysprep 2014-03-12 12:06 - 2014-02-12 15:22 - 00000000 ____D () C:\Program Files\Corel 2014-03-12 12:03 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\registration 2014-03-12 12:01 - 2014-03-04 10:16 - 00000000 ____D () C:\ProgramData\Pinnacle 2014-03-12 12:01 - 2014-01-12 01:11 - 00000000 ____D () C:\Program Files\MTI Film 2014-03-12 11:59 - 2014-02-12 15:09 - 00000000 ____D () C:\Program Files (x86)\Corel 2014-03-12 11:59 - 2014-02-10 08:57 - 00000000 ____D () C:\Program Files (x86)\eBookConverter 2014-03-12 11:49 - 2014-03-12 11:43 - 00000000 ____D () C:\AdwCleaner 2014-03-12 08:47 - 2014-03-12 08:47 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\Malwarebytes 2014-03-12 08:46 - 2014-03-12 08:46 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-12 08:46 - 2014-01-16 22:39 - 00000647 _____ () C:\Users\Nikodem\Desktop\gazeta.txt 2014-03-12 00:46 - 2014-03-12 10:22 - 4269308156 _____ () C:\Users\Nikodem\Desktop\Spotkanie n.t. wiatraków Goińczyce 09-03-2014r.mp4 2014-03-11 18:43 - 2014-03-11 18:42 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\MAGIX 2014-03-11 18:43 - 2014-03-11 18:41 - 00000000 ____D () C:\ProgramData\MAGIX 2014-03-11 12:30 - 2014-01-22 01:03 - 00000553 _____ () C:\Users\Nikodem\Desktop\MOBILITY.txt 2014-03-11 10:51 - 2014-01-15 18:17 - 00000000 ____D () C:\Users\Nikodem\Desktop\tiff 2014-03-11 10:13 - 2013-12-13 11:48 - 00000000 __SHD () C:\found.000 2014-03-11 09:30 - 2014-03-04 20:01 - 00000904 _____ () C:\Users\Nikodem\AppData\Roaming\__AvidCloudManager.log 2014-03-11 09:29 - 2014-03-04 20:01 - 00000400 _____ () C:\Users\Nikodem\AppData\Roaming\CDNN.MTBF.txt 2014-03-11 09:29 - 2014-03-04 20:01 - 00000000 ____D () C:\Users\Nikodem\AppData\Local\Pinnacle 2014-03-10 14:00 - 2014-01-23 13:37 - 00000579 _____ () C:\Users\Nikodem\Desktop\SIECI.txt 2014-03-10 01:37 - 2013-12-07 19:39 - 00000000 ____D () C:\ProgramData\Origin 2014-03-10 01:35 - 2014-02-11 17:57 - 00000000 ____D () C:\Program Files (x86)\MSI Afterburner 2014-03-10 01:28 - 2014-01-01 23:13 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr 2014-03-10 01:28 - 2013-12-11 18:18 - 00290184 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2014-03-10 01:28 - 2013-12-11 18:18 - 00280904 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0 2014-03-09 21:54 - 2013-12-07 19:39 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-03-07 15:36 - 2013-08-22 15:44 - 00545840 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-07 13:59 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-03-06 23:52 - 2014-01-18 14:35 - 00000000 ____D () C:\Program Files (x86)\Counter-Strike Global Offensive Junkies 2014-03-06 23:50 - 2014-02-14 21:31 - 00000000 ____D () C:\Users\Nikodem\Desktop\PS3 2014-03-05 21:17 - 2014-02-24 02:40 - 00001249 _____ () C:\Users\Nikodem\Desktop\NIE.txt 2014-03-05 17:23 - 2014-03-05 17:23 - 00000000 ____D () C:\Program Files (x86)\PGWARE 2014-03-05 14:26 - 2014-01-21 14:41 - 00000522 _____ () C:\Users\Nikodem\Desktop\axel.txt 2014-03-05 11:59 - 2013-12-05 18:15 - 00000000 ____D () C:\Users\Nikodem\AppData\Local\GG 2014-03-04 21:12 - 2014-03-04 20:01 - 00000904 _____ () C:\Users\Nikodem\AppData\Roaming\__AvidCloudManagerPrevious.log 2014-03-04 21:12 - 2013-12-13 22:48 - 00005120 _____ () C:\Users\Nikodem\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-03-04 20:01 - 2014-03-04 20:01 - 00000000 ____D () C:\Users\Nikodem\Documents\InstantCDDVD 2014-03-04 20:00 - 2014-03-04 20:00 - 00000000 ____D () C:\Users\Nikodem\AppData\Local\Pinnacle_Studio_17 2014-03-04 20:00 - 2014-03-04 10:19 - 00000349 _____ () C:\Users\Public\Documents\PCLECHAL.INI 2014-03-04 20:00 - 2013-12-05 11:34 - 00000000 ____D () C:\Users\Nikodem\AppData\Local\VirtualStore 2014-03-03 12:05 - 2014-03-03 12:05 - 00000424 _____ () C:\Users\Nikodem\Downloads\README.TXT 2014-03-03 12:05 - 2014-01-31 10:36 - 00000000 ____D () C:\Users\Nikodem\Documents\priPrinter Files 2014-03-03 00:36 - 2014-02-02 16:25 - 00000235 _____ () C:\Users\Nikodem\Desktop\do rzeczy.txt 2014-03-01 16:09 - 2014-02-26 21:22 - 00000209 _____ () C:\Users\Nikodem\Desktop\nba.txt 2014-03-01 15:02 - 2014-03-01 14:13 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\Audacity 2014-03-01 14:13 - 2014-03-01 14:13 - 00001019 _____ () C:\Users\Nikodem\Desktop\Audacity.lnk 2014-03-01 14:13 - 2014-03-01 14:13 - 00000000 ____D () C:\Program Files (x86)\Audacity 2014-03-01 13:46 - 2013-12-05 12:21 - 00000124 _____ () C:\Users\Nikodem\Documents\ax_files.xml 2014-02-27 23:37 - 2014-02-27 23:37 - 31356345 _____ () C:\Users\Nikodem\Desktop\15 Gdzie moja wolność.flac 2014-02-27 23:24 - 2013-12-06 20:44 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\AccurateRip 2014-02-27 23:06 - 2014-02-27 23:06 - 00000000 ____D () C:\Users\Nikodem\Documents\Ashampoo Burning Studio 2014 2014-02-27 18:45 - 2013-12-22 10:29 - 00000000 ____D () C:\Program Files\JDownloader 2 2014-02-27 17:58 - 2014-02-27 17:58 - 00080352 _____ () C:\Users\Nikodem\Downloads\org.jdownloader.settings.AccountSettings.accounts(1).ejs 2014-02-27 17:32 - 2014-02-27 17:32 - 00066064 _____ () C:\Users\Nikodem\Downloads\org.jdownloader.settings.AccountSettings.accounts.ejs 2014-02-26 07:31 - 2014-02-26 07:30 - 00000000 ____D () C:\Windows\KJ 2014-02-24 19:51 - 2014-02-24 19:51 - 00000669 _____ () C:\Users\Nikodem\Desktop\Wgrywanie listy kanałów.txt 2014-02-24 19:29 - 2013-12-22 20:52 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\FileZilla 2014-02-24 17:37 - 2014-02-24 03:52 - 00000000 ____D () C:\Users\Nikodem\Documents\My Digital Editions 2014-02-24 14:00 - 2014-01-21 19:08 - 00000232 _____ () C:\Users\Nikodem\Desktop\Kuchnia.txt 2014-02-24 03:54 - 2014-01-19 16:35 - 00000000 ____D () C:\ProgramData\Ashampoo 2014-02-24 03:53 - 2014-02-24 03:53 - 00000000 ____D () C:\Users\Nikodem\AppData\Local\Adobe_Systems_Incorporate 2014-02-24 03:52 - 2014-01-06 01:39 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-02-24 03:42 - 2014-02-24 03:42 - 00000000 ____D () C:\Users\Nikodem\Documents\Anvsoft 2014-02-24 03:42 - 2014-02-24 03:42 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\AnvsoftPdfTools 2014-02-24 03:42 - 2014-02-24 03:42 - 00000000 ____D () C:\Program Files (x86)\AnvSoft 2014-02-23 15:07 - 2014-02-17 18:32 - 00000000 ____D () C:\Users\Nikodem\Cropped 2014-02-21 16:38 - 2014-02-21 13:51 - 00000000 ____D () C:\Users\Nikodem\Desktop\Dj Wituś 2014-02-21 16:18 - 2014-02-21 16:18 - 00001319 _____ () C:\Users\Public\Desktop\Ashampoo Burning Studio 2014.lnk 2014-02-21 15:04 - 2013-12-09 14:00 - 00000000 ____D () C:\Users\Public\Documents\CyberLink 2014-02-21 15:04 - 2013-12-09 14:00 - 00000000 ____D () C:\ProgramData\CyberLink 2014-02-21 13:42 - 2014-02-21 13:42 - 00013223 _____ () C:\Users\Nikodem\Downloads\DJ_Witus_-_Gorace_wakacje_ 1997 _[FLAC]_[Z3K][Torrenty.org].torrent 2014-02-21 01:58 - 2014-02-21 01:58 - 00013011 _____ () C:\Users\Nikodem\Downloads\B248533F9234BE887F17C35012D6976764DFFC07.torrent 2014-02-20 22:46 - 2014-02-20 22:43 - 00000183 _____ () C:\Users\Nikodem\Desktop\passy.txt 2014-02-20 17:45 - 2014-01-27 11:24 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\ObviousIdea 2014-02-20 11:41 - 2014-02-18 13:27 - 00000498 _____ () C:\Users\Nikodem\Desktop\Top Gear.txt 2014-02-19 11:16 - 2014-02-19 11:16 - 00000000 ____D () C:\Users\Nikodem\AppData\Local\eGazety 2014-02-19 11:16 - 2013-12-30 15:01 - 00000000 ____D () C:\Users\Nikodem\AppData\Local\Adobe 2014-02-19 11:15 - 2014-02-19 11:15 - 00000000 ____D () C:\Program Files (x86)\eGazety Sp. z o. o 2014-02-19 10:05 - 2014-02-19 10:05 - 00001426 _____ () C:\Users\Nikodem\Desktop\ps3-hack.txt 2014-02-19 09:02 - 2013-12-28 12:36 - 00000000 ____D () C:\Users\Nikodem\Desktop\GIMPPortable 2014-02-18 20:49 - 2014-02-14 21:37 - 00000211 _____ () C:\Users\Nikodem\Desktop\wwe.txt 2014-02-17 22:00 - 2013-08-22 16:38 - 00693240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-17 22:00 - 2013-08-22 16:38 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-17 20:44 - 2014-02-17 20:41 - 00000000 ____D () C:\Users\Nikodem\zdzd 2014-02-17 20:40 - 2014-02-17 20:19 - 00000000 ____D () C:\Users\Nikodem\Desktop\rrrr 2014-02-17 18:28 - 2014-02-17 18:28 - 00000000 ____D () C:\Program Files (x86)\JPEGCrops 2014-02-17 18:22 - 2014-02-17 18:16 - 00000000 ____D () C:\output 2014-02-17 18:14 - 2014-02-17 17:59 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\PhotoScape 2014-02-17 17:59 - 2014-02-17 17:59 - 00001043 _____ () C:\Users\Nikodem\Desktop\PhotoScape.lnk 2014-02-17 17:59 - 2014-02-17 17:59 - 00000000 ____D () C:\Program Files (x86)\PhotoScape 2014-02-17 17:34 - 2014-02-17 17:34 - 00001010 _____ () C:\Users\Nikodem\Desktop\IrfanView.lnk 2014-02-17 17:34 - 2014-01-26 19:12 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\IrfanView 2014-02-17 17:34 - 2014-01-26 19:12 - 00000000 ____D () C:\Program Files (x86)\IrfanView 2014-02-17 12:25 - 2014-01-26 14:54 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\Epson 2014-02-17 09:36 - 2013-12-05 11:35 - 00000000 ___RD () C:\Users\Nikodem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-17 09:36 - 2013-12-05 11:35 - 00000000 ___RD () C:\Users\Nikodem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-02-17 09:35 - 2013-12-29 22:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-17 00:30 - 2013-08-22 16:36 - 00000000 ___RD () C:\Windows\ToastData 2014-02-17 00:30 - 2013-08-22 14:36 - 00000000 ____D () C:\Windows\SysWOW64\Dism 2014-02-17 00:30 - 2013-08-22 14:36 - 00000000 ____D () C:\Windows\system32\Dism 2014-02-16 15:46 - 2014-02-16 15:46 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf 2014-02-16 10:31 - 2014-02-16 10:31 - 00000430 _____ () C:\Users\Nikodem\Downloads\[www.tnt24.info] PSBreak Open Split v1.3 [PS3] [PL [JB] [HOMEBREW].torrent 2014-02-16 09:35 - 2013-12-05 14:33 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-16 09:32 - 2013-12-05 14:33 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-15 21:30 - 2013-12-14 08:30 - 00001281 _____ () C:\Users\Nikodem\Desktop\hasło.txt 2014-02-15 15:54 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\FxsTmp 2014-02-15 15:22 - 2014-01-27 11:10 - 00000000 ____D () C:\Users\Nikodem\Desktop\Nowy folder (5) 2014-02-15 11:28 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache 2014-02-15 09:30 - 2014-02-15 09:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-14 23:14 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\MediaViewer 2014-02-14 23:14 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\FileManager 2014-02-14 23:14 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\Camera 2014-02-14 09:40 - 2014-02-14 09:40 - 00001736 _____ () C:\Users\Public\Desktop\Defraggler.lnk 2014-02-14 09:40 - 2014-02-14 09:40 - 00000000 ____D () C:\Program Files\Defraggler 2014-02-14 08:22 - 2014-02-14 08:22 - 00004040 _____ () C:\Windows\system32\Drivers\etc\hosts.ics 2014-02-12 21:51 - 2014-02-12 21:51 - 00000000 ____D () C:\Users\Nikodem\Desktop\Corel PaintShop Pro X6 2014-02-12 14:42 - 2014-02-12 14:42 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\Corel 2014-02-11 17:57 - 2014-02-11 17:57 - 00001098 _____ () C:\Users\Nikodem\Desktop\MSI Afterburner.lnk 2014-02-11 17:57 - 2014-02-11 17:57 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-02-11 17:57 - 2014-02-11 17:57 - 00000000 ____D () C:\Users\Nikodem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner 2014-02-10 10:03 - 2014-02-10 10:03 - 00000000 ____D () C:\Program Files (x86)\Monkey's Audio 2014-02-10 09:51 - 2014-02-07 21:02 - 00000000 ____D () C:\Users\Nikodem\Downloads\SexBomba 2014-02-10 09:50 - 2014-02-10 09:50 - 00001258 _____ () C:\Users\Public\Desktop\Medieval CUE Splitter.lnk 2014-02-10 09:50 - 2014-02-10 09:50 - 00000000 ____D () C:\Program Files (x86)\Medieval Software 2014-02-10 08:57 - 2014-02-10 08:57 - 00000000 ____D () C:\Users\Nikodem\Documents\eBook Converter 2014-02-10 07:57 - 2014-02-10 07:57 - 00000000 ____D () C:\Users\Nikodem\ResEdit Projects ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-11 08:17 ==================== End Of Log ============================