Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-04-2014 01 Ran by Zbigniew (administrator) on ZBIG on 12-04-2014 22:26:31 Running from C:\Users\Zbigniew\Downloads Windows 8.1 Pro (X64) OS Language: Polish Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe (Microsoft Corporation) C:\WINDOWS\system32\dashost.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\pg_ctl.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files\PostgreSQL\9.0\bin\postgres.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe (AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\loggingserver.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Microsoft Corporation) C:\Windows\System32\skydrive.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe () C:\Program Files (x86)\NapiProjekt\napisy.exe (EasyPHP) C:\Program Files (x86)\EasyPHP\EasyPHP-DevServer-13.1VC11.exe (Apache Software Foundation) C:\Program Files (x86)\EasyPHP\binaries\apache\bin\apache.exe () C:\Program Files (x86)\EasyPHP\binaries\mysql\bin\mysqld.exe (Apache Software Foundation) C:\Program Files (x86)\EasyPHP\binaries\apache\bin\apache.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (BitTorrent Inc.) C:\Users\Zbigniew\AppData\Roaming\uTorrent\uTorrent.exe (Microsoft Corporation) C:\WINDOWS\system32\werfault.exe (Microsoft Corporation) C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (OldTimer Tools) C:\Users\Zbigniew\Downloads\OTL.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17031_none_fa50b3979b1bcb4a\TiWorker.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5180432 2014-04-06] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [vProt] - C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2544664 2014-03-21] () HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-4194209175-3538455940-2824723160-1001\...\Run: [uTorrent] - C:\Users\Zbigniew\AppData\Roaming\uTorrent\uTorrent.exe [905296 2014-01-23] (BitTorrent Inc.) HKU\S-1-5-21-4194209175-3538455940-2824723160-1001\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd) HKU\S-1-5-21-4194209175-3538455940-2824723160-1001\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-4194209175-3538455940-2824723160-1001\...\MountPoints2: {3aad5404-659c-11e3-be6c-24b6fd3e58d8} - "H:\setup.exe" ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mysearch.avg.com?cid={9E1EB010-E34D-4D81-8F34-A67754F5ADF9}&mid=85d899ea5a6647d39dddf5ffbbdab12b-c23121d45c16a02b31f1429c89a393ecba0c1617&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2013-12-23 08:13:33&v=17.2.0.38&pid=safeguard&sg=&sap=hp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x2BA45CD35AF8CE01 SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={9E1EB010-E34D-4D81-8F34-A67754F5ADF9}&mid=85d899ea5a6647d39dddf5ffbbdab12b-c23121d45c16a02b31f1429c89a393ecba0c1617&lang=pl&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2013-12-23 08:13:33&v=17.2.0.38&pid=safeguard&sg=&sap=dsp&q={searchTerms} BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.0.5.292\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.0.5.292\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search) Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.0.5\ViProtocol.dll (AVG Secure Search) Tcpip\Parameters: [DhcpNameServer] 62.179.1.62 62.179.1.63 FireFox: ======== FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.0.5\\npsitesafety.dll (AVG Technologies) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin HKCU: @acestream.net/acestreamplugin,version=2.0.13.1 - C:\Users\Zbigniew\AppData\Roaming\ACEStream\player\npace_plugin.dll (Innovative Digital Technologies) FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.3.0.49 FF Extension: AVG SafeGuard toolbar - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.3.0.49 [2014-01-06] FF HKCU\...\Firefox\Extensions: [magicplayer@torrentstream.org] - C:\Users\Zbigniew\AppData\Roaming\ACEStream\extensions\firefox\magicplayer@torrentstream.org FF Extension: TS Magic Player - C:\Users\Zbigniew\AppData\Roaming\ACEStream\extensions\firefox\magicplayer@torrentstream.org [2014-04-01] Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR Extension: (Przelewy24) - C:\Users\Zbigniew\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiicmmpkicnndkhlnnloilpgncbpkbjj [2014-02-28] CHR Extension: (Dokumenty Google) - C:\Users\Zbigniew\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-14] CHR Extension: (Dysk Google) - C:\Users\Zbigniew\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-14] CHR Extension: (YouTube) - C:\Users\Zbigniew\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-14] CHR Extension: (Szukaj w Google) - C:\Users\Zbigniew\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-14] CHR Extension: (AdBlock) - C:\Users\Zbigniew\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-12-14] CHR Extension: (AVG SafeGuard) - C:\Users\Zbigniew\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2013-12-23] CHR Extension: (Google Wallet) - C:\Users\Zbigniew\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-14] CHR Extension: (Piktochart) - C:\Users\Zbigniew\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojgpilphbpmpjlicfhhkgnfbedaeegil [2014-02-23] CHR Extension: (Gmail) - C:\Users\Zbigniew\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-14] CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG SafeGuard toolbar\ChromeExt\18.0.5.292\avg.crx [2014-03-21] ==================== Services (Whitelisted) ================= R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3655184 2014-04-01] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [291912 2014-03-27] (AVG Technologies CZ, s.r.o.) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) R2 vToolbarUpdater18.0.5; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.5\ToolbarUpdater.exe [1771032 2014-03-21] (AVG Secure Search) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2013-10-31] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2013-10-31] (Microsoft Corporation) R2 postgresql-x64-9.0; C:/Program Files/PostgreSQL/9.0/bin/pg_ctl.exe runservice -N "postgresql-x64-9.0" -D "C:/Program Files/PostgreSQL/9.0/data" -w [X] ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) R3 athr; C:\Windows\system32\DRIVERS\athwnx.sys [3680256 2013-06-18] (Qualcomm Atheros Communications, Inc.) S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-03-27] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [236824 2014-04-01] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [192792 2014-03-27] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [236824 2014-03-27] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [324376 2014-03-27] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [130840 2014-03-31] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [32536 2014-03-27] (AVG Technologies CZ, s.r.o.) R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx64.sys [49952 2014-03-21] (AVG Technologies) R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [274712 2014-03-31] (AVG Technologies CZ, s.r.o.) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2013-12-17] (Disc Soft Ltd) S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation) R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2014-02-22] (Microsoft Corporation) S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-11-14] (Microsoft Corporation) S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation) S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited) S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2014-02-22] (Microsoft Corporation) S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-14] (Microsoft Corporation) S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2013-10-31] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-12 22:26 - 2014-04-12 22:29 - 00016775 _____ () C:\Users\Zbigniew\Downloads\FRST.txt 2014-04-12 22:25 - 2014-04-12 22:26 - 00000000 ____D () C:\FRST 2014-04-12 22:22 - 2014-04-12 22:22 - 02157568 _____ (Farbar) C:\Users\Zbigniew\Downloads\FRST64.exe 2014-04-12 22:15 - 2014-04-12 22:15 - 00078552 _____ () C:\Users\Zbigniew\Downloads\Extras.Txt 2014-04-12 22:12 - 2014-04-12 22:12 - 00134278 _____ () C:\Users\Zbigniew\Downloads\OTL.Txt 2014-04-12 21:29 - 2014-04-12 21:29 - 00602112 _____ (OldTimer Tools) C:\Users\Zbigniew\Downloads\OTL.exe 2014-04-12 21:22 - 2014-04-12 21:22 - 00000000 ___HD () C:\$WINDOWS.~BT 2014-04-11 14:45 - 2014-04-11 14:46 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Zbigniew\Downloads\mbam-setup-2.0.1.1004 (1).exe 2014-04-11 14:44 - 2014-04-11 14:44 - 05196025 _____ (Swearware) C:\Users\Zbigniew\Downloads\ComboFix (1).exe 2014-04-10 22:16 - 2014-04-11 10:10 - 01854518 _____ () C:\Users\Zbigniew\Downloads\Łamanie afinicznego (1).exe 2014-04-10 22:15 - 2014-04-11 07:54 - 00002229 _____ () C:\Users\Zbigniew\Downloads\Łamanie afinicznego (1).cpp 2014-04-10 22:14 - 2014-04-03 22:01 - 00020188 _____ () C:\Users\Zbigniew\Downloads\ObrazJPG.zpw 2014-04-10 21:24 - 2014-04-10 22:15 - 01854514 _____ () C:\Users\Zbigniew\Downloads\Łamanie afinicznego.exe 2014-04-10 21:24 - 2014-04-03 22:10 - 00178310 _____ () C:\Users\Zbigniew\Downloads\DokumentPDF.zpw 2014-04-10 21:11 - 2014-04-10 21:11 - 00002164 _____ () C:\Users\Zbigniew\Downloads\Łamanie afinicznego.cpp 2014-04-10 19:40 - 2014-04-10 19:40 - 02869212 _____ () C:\Users\Zbigniew\Downloads\Cwiczenia.zip 2014-04-10 19:40 - 2014-04-10 19:40 - 00000000 ____D () C:\Users\Zbigniew\Downloads\Cwiczenia 2014-04-10 18:51 - 2014-04-10 18:51 - 02236416 _____ () C:\Users\Zbigniew\Downloads\The_Settlers-_Heritage_of_Kings_Legends_Spolszczenie_Sciagnij.pl.exe 2014-04-10 18:48 - 2014-04-10 18:48 - 00000000 ____D () C:\Users\Zbigniew\Downloads\4f525328d638e.settlers_heritage_of_kings_legends_pl 2014-04-10 18:47 - 2014-04-10 18:47 - 00000000 ____D () C:\Users\Zbigniew\Documents\THE SETTLERS - Heritage of Kings 2014-04-10 18:39 - 2014-04-10 18:39 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-04-10 18:37 - 2014-04-10 18:37 - 00000000 ____D () C:\Program Files (x86)\Ubisoft 2014-04-10 18:19 - 2014-04-10 18:19 - 09847507 _____ () C:\Users\Zbigniew\Downloads\4f525328d638e.settlers_heritage_of_kings_legends_pl.rar 2014-04-10 16:29 - 2014-04-10 16:29 - 02607688 _____ () C:\Users\Zbigniew\Desktop\magnes-pionowo.psd 2014-04-10 16:29 - 2014-04-10 16:29 - 02505000 _____ () C:\Users\Zbigniew\Desktop\magnes-poziomo.psd 2014-04-10 14:48 - 2014-04-10 14:48 - 00062147 _____ () C:\Users\Zbigniew\Downloads\wioskarybacka.wordpress.2014-04-10.xml 2014-04-09 23:29 - 2014-04-09 23:29 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-04-09 23:28 - 2014-04-09 23:28 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-09 23:28 - 2014-04-09 23:28 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-04-09 23:28 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2014-04-09 23:28 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2014-04-09 23:28 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2014-04-09 23:21 - 2014-04-09 23:23 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Zbigniew\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-09 11:02 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-04-09 11:02 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-04-09 11:02 - 2014-03-10 12:35 - 02008408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2014-04-09 11:02 - 2014-03-10 12:35 - 00377176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys 2014-04-09 11:02 - 2014-03-06 11:19 - 01287576 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll 2014-04-09 11:02 - 2014-03-06 11:02 - 01109424 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2014-04-09 11:02 - 2014-03-06 08:17 - 00835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2014-04-09 11:02 - 2014-03-06 08:10 - 01036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll 2014-04-09 10:58 - 2014-04-09 10:58 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2014-04-09 10:58 - 2014-04-09 10:58 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2014-04-08 19:36 - 2014-04-08 19:36 - 00000000 ____D () C:\Users\Zbigniew\Downloads\wordpress-3.8.1-pl_PL 2014-04-08 19:35 - 2014-04-08 19:35 - 06826828 _____ () C:\Users\Zbigniew\Downloads\wordpress-3.8.1-pl_PL.zip 2014-04-08 19:35 - 2014-04-08 19:35 - 00000000 ____D () C:\Users\Zbigniew\Downloads\wordpress-3.8.1 2014-04-08 19:34 - 2014-04-08 19:34 - 06373521 _____ () C:\Users\Zbigniew\Downloads\wordpress-3.8.1.zip 2014-04-08 18:21 - 2014-04-08 18:22 - 00000000 ____D () C:\Users\Zbigniew\Desktop\Tor Browser 2014-04-08 18:19 - 2014-04-08 18:20 - 23196204 _____ () C:\Users\Zbigniew\Downloads\torbrowser-install-3.5.3_pl.exe 2014-04-06 19:28 - 2014-04-06 19:28 - 00156429 _____ () C:\Users\Zbigniew\Downloads\wioska logo.psd 2014-04-06 18:02 - 2014-04-06 18:03 - 32039590 _____ () C:\Users\Zbigniew\Downloads\css3menu-setup.zip 2014-04-02 13:58 - 2014-04-02 13:58 - 00024159 _____ () C:\Users\Zbigniew\Downloads\skorzane-torby2.php 2014-04-01 21:47 - 2014-04-01 21:47 - 00000000 ____D () C:\Users\Zbigniew\Downloads\prob 2014-04-01 21:46 - 2014-04-01 21:46 - 00127010 _____ () C:\Users\Zbigniew\Downloads\prob.rar 2014-04-01 21:22 - 2014-04-02 21:13 - 00000000 ___HD () C:\_acestream_cache_ 2014-04-01 21:22 - 2014-04-02 21:13 - 00000000 ____D () C:\Users\Zbigniew\AppData\Roaming\.ACEStream 2014-04-01 21:21 - 2014-04-01 21:21 - 00000000 ____D () C:\Users\Zbigniew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ACE Stream Media 2014-04-01 21:19 - 2014-04-01 21:23 - 00000000 ____D () C:\Users\Zbigniew\AppData\Roaming\ACEStream 2014-04-01 21:17 - 2014-04-01 21:19 - 59151848 _____ () C:\Users\Zbigniew\Downloads\ace_stream_media_2.0.13.1.exe 2014-04-01 21:03 - 2014-04-01 21:03 - 00236824 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdrivera.sys 2014-04-01 21:03 - 2014-04-01 21:03 - 00001016 _____ () C:\Users\postgres\Desktop\SopCast.lnk 2014-04-01 21:03 - 2014-04-01 21:03 - 00000000 ____D () C:\Users\Zbigniew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SopCast 2014-04-01 21:03 - 2014-04-01 21:03 - 00000000 ____D () C:\Program Files (x86)\SopCast 2014-04-01 21:02 - 2014-04-01 21:02 - 00000000 ____D () C:\Users\Zbigniew\Downloads\SopCast-3.8.3(dobreprogramy.pl) 2014-04-01 15:33 - 2014-04-01 15:33 - 05102486 _____ () C:\Users\Zbigniew\Downloads\IMG_0526.MOV 2014-03-31 21:59 - 2014-03-31 21:59 - 00000130 _____ () C:\Users\Zbigniew\Downloads\rozliczenie.xls 2014-03-31 16:06 - 2014-03-31 16:06 - 00274712 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgwfpa.sys 2014-03-31 16:06 - 2014-03-31 16:06 - 00130840 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgmfx64.sys 2014-03-30 18:38 - 2014-03-30 18:38 - 00065536 _____ () C:\Users\Zbigniew\Downloads\Pokemon Fire Red (PL).sav 2014-03-30 18:33 - 2014-03-30 18:33 - 00000000 ____D () C:\Users\Zbigniew\Downloads\VisualBoyAdvance1.8.0_www.INSTALKI.pl 2014-03-30 18:32 - 2014-03-30 18:32 - 16777216 _____ () C:\Users\Zbigniew\Downloads\Pokemon Fire Red (PL).gba 2014-03-30 18:32 - 2014-03-30 18:32 - 00659797 _____ () C:\Users\Zbigniew\Downloads\VisualBoyAdvance1.8.0_www.INSTALKI.pl.zip 2014-03-30 15:36 - 2014-03-30 15:36 - 00820348 _____ () C:\Users\Zbigniew\Downloads\localhost.sql 2014-03-27 22:14 - 2014-03-27 22:14 - 00192792 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsha.sys 2014-03-27 22:14 - 2014-03-27 22:14 - 00153368 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgdiska.sys 2014-03-27 22:07 - 2014-03-27 22:07 - 00236824 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgldx64.sys 2014-03-27 22:05 - 2014-03-27 22:05 - 00324376 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgloga.sys 2014-03-27 22:03 - 2014-03-27 22:03 - 00032536 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgrkx64.sys 2014-03-27 19:10 - 2014-03-27 19:10 - 00000000 ____D () C:\Users\Zbigniew\Documents\ProcAlyzer Dumps 2014-03-27 18:53 - 2014-03-27 18:53 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Safer-Networking 2014-03-27 18:52 - 2014-04-09 07:34 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-03-27 18:52 - 2014-03-27 18:53 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-03-27 18:52 - 2013-09-20 11:49 - 00021040 _____ (Safer Networking Limited) C:\WINDOWS\system32\sdnclean64.exe 2014-03-27 18:50 - 2014-03-27 18:50 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\Zbigniew\Downloads\spybot-2.2.exe 2014-03-26 21:38 - 2014-03-26 21:38 - 00020480 _____ () C:\Users\Zbigniew\Downloads\1.xls 2014-03-26 16:29 - 2014-04-12 21:22 - 00000277 _____ () C:\WINDOWS\setupact.log 2014-03-26 16:29 - 2014-04-12 21:22 - 00000000 _____ () C:\WINDOWS\setuperr.log 2014-03-24 16:54 - 2014-03-24 16:54 - 00278528 _____ () C:\Users\Zbigniew\Downloads\fa 135 wenecja.xls 2014-03-24 07:58 - 2014-03-24 07:59 - 00000000 ____D () C:\CCE_Quarantine 2014-03-23 20:26 - 2014-03-23 20:26 - 00000000 ____D () C:\Users\Zbigniew\Downloads\cce_2.5.242177.201_x64 2014-03-23 20:25 - 2014-03-23 20:26 - 25543261 _____ () C:\Users\Zbigniew\Downloads\cce_2.5.242177.201_x64.zip 2014-03-22 22:32 - 2014-03-22 22:33 - 05190052 _____ (Swearware) C:\Users\Zbigniew\Downloads\ComboFix.exe 2014-03-22 17:07 - 2014-04-10 19:13 - 00003696 _____ () C:\WINDOWS\PFRO.log 2014-03-22 14:23 - 2014-03-22 14:23 - 00002220 _____ () C:\Users\Zbigniew\Downloads\lista 3.txt 2014-03-21 17:47 - 2014-03-21 17:47 - 00000000 ____D () C:\ProgramData\AVG Secure Search 2014-03-20 22:26 - 2014-04-12 22:20 - 02032722 _____ () C:\WINDOWS\WindowsUpdate.log 2014-03-20 13:56 - 2014-03-20 13:56 - 04822473 _____ (Tim Kosse) C:\Users\Zbigniew\Downloads\FileZilla_3.7.4.1_win32-setup.exe 2014-03-19 13:23 - 2014-02-22 14:16 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe 2014-03-19 13:23 - 2014-02-22 13:24 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe 2014-03-19 07:52 - 2014-01-08 03:46 - 00325464 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2014-03-19 07:52 - 2014-01-08 03:41 - 01530712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2014-03-19 07:52 - 2014-01-08 03:41 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2014-03-19 07:52 - 2014-01-04 17:54 - 00138240 _____ () C:\WINDOWS\system32\OEMLicense.dll 2014-03-19 07:52 - 2014-01-04 17:08 - 00103936 _____ () C:\WINDOWS\SysWOW64\OEMLicense.dll 2014-03-19 07:52 - 2014-01-04 16:08 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll 2014-03-19 07:52 - 2014-01-04 15:53 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll 2014-03-19 07:52 - 2014-01-03 01:54 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll 2014-03-19 07:52 - 2014-01-03 01:48 - 00336896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll 2014-03-19 07:52 - 2014-01-01 03:55 - 01720560 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2014-03-19 07:52 - 2014-01-01 03:52 - 00481944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2014-03-19 07:52 - 2014-01-01 02:56 - 01472048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2014-03-19 07:52 - 2014-01-01 02:55 - 00381168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2014-03-19 07:52 - 2014-01-01 01:59 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2014-03-19 07:52 - 2014-01-01 01:57 - 01214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll 2014-03-19 07:52 - 2014-01-01 01:56 - 00960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2014-03-19 07:52 - 2013-12-31 01:34 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sti.dll 2014-03-19 07:52 - 2013-12-31 01:33 - 00770560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll 2014-03-19 07:52 - 2013-12-31 01:32 - 00303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\sti.dll 2014-03-19 07:52 - 2013-12-31 01:31 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll 2014-03-19 07:52 - 2013-12-31 01:31 - 00914944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll 2014-03-19 07:52 - 2013-12-27 17:09 - 00419160 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll 2014-03-19 07:52 - 2013-12-27 10:57 - 00842752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll 2014-03-19 07:52 - 2013-12-27 10:57 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe 2014-03-19 07:52 - 2013-12-27 10:23 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2014-03-19 07:52 - 2013-12-27 09:03 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll 2014-03-19 07:52 - 2013-12-27 09:03 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2014-03-19 07:52 - 2013-12-27 08:37 - 00588800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2014-03-19 07:52 - 2013-12-21 09:21 - 00376320 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll 2014-03-19 07:52 - 2013-12-17 09:21 - 00408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2014-03-19 07:52 - 2013-12-14 08:31 - 13949440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2014-03-19 07:52 - 2013-12-14 08:19 - 18576384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2014-03-19 07:52 - 2013-12-13 12:54 - 00131160 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe 2014-03-19 07:52 - 2013-12-13 08:36 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll 2014-03-19 07:52 - 2013-12-13 07:32 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll 2014-03-19 07:52 - 2013-12-09 10:05 - 21199256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2014-03-19 07:52 - 2013-12-09 06:51 - 18643560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2014-03-18 16:22 - 2014-03-18 16:22 - 00281600 _____ () C:\Users\Zbigniew\Downloads\fa 0044 wenecja.xls 2014-03-17 21:16 - 2014-03-17 21:53 - 00000000 ____D () C:\Users\Zbigniew\AppData\Roaming\PLNcoin 2014-03-17 21:16 - 2014-03-17 21:20 - 00000002 _____ () C:\Users\Zbigniew\Downloads\config.plnc 2014-03-17 21:14 - 2014-03-17 21:16 - 26778624 _____ () C:\Users\Zbigniew\Downloads\plncoin-qt.exe 2014-03-17 16:06 - 2014-03-17 16:06 - 00000260 _____ () C:\Users\Zbigniew\Downloads\dane_kontaktowe.xls 2014-03-14 03:22 - 2014-01-31 18:15 - 00311640 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys 2014-03-14 03:22 - 2014-01-31 18:07 - 00233920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2014-03-14 03:22 - 2014-01-31 18:06 - 02133208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2014-03-14 03:22 - 2014-01-31 15:47 - 02143960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2014-03-14 03:22 - 2014-01-31 11:06 - 00716288 _____ (Microsoft Corporation) C:\WINDOWS\system32\swprv.dll 2014-03-14 03:22 - 2014-01-29 10:53 - 00458616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe 2014-03-14 03:22 - 2014-01-29 10:53 - 00407024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll 2014-03-14 03:22 - 2014-01-29 10:49 - 01928144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2014-03-14 03:22 - 2014-01-29 10:47 - 02543960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2014-03-14 03:22 - 2014-01-29 09:44 - 01371824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2014-03-14 03:22 - 2014-01-29 09:44 - 00408480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe 2014-03-14 03:22 - 2014-01-29 09:44 - 00369280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll 2014-03-14 03:22 - 2014-01-29 08:41 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll 2014-03-14 03:22 - 2014-01-29 02:36 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll 2014-03-14 03:22 - 2014-01-27 21:07 - 04175360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll 2014-03-14 03:22 - 2014-01-27 21:06 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll 2014-03-14 03:22 - 2014-01-27 21:04 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE 2014-03-14 03:22 - 2014-01-27 20:23 - 02873344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll 2014-03-14 03:22 - 2014-01-27 20:21 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll 2014-03-14 03:22 - 2014-01-27 20:20 - 00138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE 2014-03-14 03:22 - 2014-01-27 20:15 - 01057280 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvidcrl.dll 2014-03-14 03:22 - 2014-01-27 19:43 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvidcrl.dll 2014-03-14 03:22 - 2014-01-27 19:18 - 01486848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll 2014-03-14 03:22 - 2014-01-27 19:00 - 01238016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll 2014-03-14 03:22 - 2014-01-27 17:58 - 05770752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2014-03-14 03:22 - 2014-01-27 17:50 - 06640640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2014-03-14 03:22 - 2014-01-27 13:45 - 00386722 _____ () C:\WINDOWS\system32\ApnDatabase.xml 2014-03-14 03:22 - 2014-01-18 01:04 - 00764864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 2014-03-14 03:22 - 2014-01-17 23:54 - 00669352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2014-03-14 03:22 - 2013-12-21 16:51 - 06353960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe 2014-03-14 03:22 - 2013-12-21 10:54 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll 2014-03-14 03:22 - 2013-10-31 02:29 - 00236888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys 2014-03-14 03:22 - 2013-10-31 02:29 - 00124760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys 2014-03-14 03:22 - 2013-10-31 02:28 - 00035856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys 2014-03-14 03:21 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2014-03-14 03:21 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2014-03-14 03:21 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2014-03-14 03:21 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2014-03-14 03:21 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2014-03-14 03:21 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2014-03-14 03:21 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2014-03-14 03:21 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2014-03-14 03:21 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2014-03-14 03:21 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2014-03-14 03:21 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2014-03-14 03:21 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2014-03-14 03:21 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2014-03-14 03:21 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2014-03-14 03:21 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-03-14 03:21 - 2013-12-20 12:18 - 01643584 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2014-03-14 03:21 - 2013-12-20 12:18 - 01507704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2014-03-13 12:44 - 2014-03-13 12:44 - 00004921 _____ () C:\Users\Zbigniew\Downloads\webstar_6 (1).sql 2014-03-13 12:29 - 2014-03-13 12:29 - 00016101 _____ () C:\Users\Zbigniew\Downloads\webstar_6.sql 2014-03-13 11:15 - 2014-02-11 05:04 - 04189184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2014-03-13 11:15 - 2014-02-11 04:43 - 00488448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll 2014-03-13 11:15 - 2014-02-11 04:04 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll 2014-03-13 00:14 - 2014-03-24 09:09 - 00817152 _____ () C:\Users\Zbigniew\Downloads\HST Progression v.1.03.xls 2014-03-13 00:09 - 2014-03-13 00:09 - 00004759 _____ () C:\Users\Zbigniew\Downloads\kalk_kal.rar ==================== One Month Modified Files and Folders ======= 2014-04-12 22:29 - 2014-04-12 22:26 - 00016775 _____ () C:\Users\Zbigniew\Downloads\FRST.txt 2014-04-12 22:29 - 2013-12-14 01:56 - 00000000 ____D () C:\Users\Zbigniew\AppData\Roaming\uTorrent 2014-04-12 22:26 - 2014-04-12 22:25 - 00000000 ____D () C:\FRST 2014-04-12 22:22 - 2014-04-12 22:22 - 02157568 _____ (Farbar) C:\Users\Zbigniew\Downloads\FRST64.exe 2014-04-12 22:20 - 2014-03-20 22:26 - 02032722 _____ () C:\WINDOWS\WindowsUpdate.log 2014-04-12 22:15 - 2014-04-12 22:15 - 00078552 _____ () C:\Users\Zbigniew\Downloads\Extras.Txt 2014-04-12 22:12 - 2014-04-12 22:12 - 00134278 _____ () C:\Users\Zbigniew\Downloads\OTL.Txt 2014-04-12 21:29 - 2014-04-12 21:29 - 00602112 _____ (OldTimer Tools) C:\Users\Zbigniew\Downloads\OTL.exe 2014-04-12 21:28 - 2014-02-22 10:03 - 00001908 _____ () C:\WINDOWS\diagwrn.xml 2014-04-12 21:28 - 2014-02-22 10:03 - 00001908 _____ () C:\WINDOWS\diagerr.xml 2014-04-12 21:22 - 2014-04-12 21:22 - 00000000 ___HD () C:\$WINDOWS.~BT 2014-04-12 21:22 - 2014-03-26 16:29 - 00000277 _____ () C:\WINDOWS\setupact.log 2014-04-12 21:22 - 2014-03-26 16:29 - 00000000 _____ () C:\WINDOWS\setuperr.log 2014-04-12 21:02 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2014-04-12 20:59 - 2013-12-14 01:28 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4194209175-3538455940-2824723160-1001 2014-04-12 20:59 - 2013-11-14 09:32 - 01825074 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-04-12 20:59 - 2013-11-14 09:13 - 00807160 _____ () C:\WINDOWS\system32\perfh015.dat 2014-04-12 20:59 - 2013-11-14 09:13 - 00163478 _____ () C:\WINDOWS\system32\perfc015.dat 2014-04-12 20:52 - 2013-12-14 01:28 - 00001058 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-12 20:50 - 2013-12-14 01:28 - 00001062 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-12 19:02 - 2013-12-14 03:01 - 00000000 ____D () C:\ProgramData\MFAData 2014-04-12 19:01 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2014-04-12 16:03 - 2013-12-14 02:09 - 00028130 _____ () C:\Users\Zbigniew\AppData\Roaming\phpdesigner.xml 2014-04-12 15:54 - 2013-12-14 02:43 - 00000000 ____D () C:\Users\Zbigniew\AppData\Roaming\FileZilla 2014-04-12 15:53 - 2013-12-14 16:34 - 01873408 ___SH () C:\Users\Zbigniew\Desktop\Thumbs.db 2014-04-12 13:58 - 2013-12-14 10:23 - 00000000 ____D () C:\ProgramData\firebird 2014-04-12 08:53 - 2013-12-14 02:13 - 00000000 ____D () C:\Users\Zbigniew\AppData\Local\Adobe 2014-04-12 08:30 - 2014-02-22 10:51 - 00000000 __RDO () C:\Users\Zbigniew\SkyDrive 2014-04-12 08:27 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-04-12 08:26 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2014-04-11 14:46 - 2014-04-11 14:45 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Zbigniew\Downloads\mbam-setup-2.0.1.1004 (1).exe 2014-04-11 14:44 - 2014-04-11 14:44 - 05196025 _____ (Swearware) C:\Users\Zbigniew\Downloads\ComboFix (1).exe 2014-04-11 12:17 - 2014-03-02 22:16 - 00000000 ____D () C:\Users\postgres 2014-04-11 10:10 - 2014-04-10 22:16 - 01854518 _____ () C:\Users\Zbigniew\Downloads\Łamanie afinicznego (1).exe 2014-04-11 07:54 - 2014-04-10 22:15 - 00002229 _____ () C:\Users\Zbigniew\Downloads\Łamanie afinicznego (1).cpp 2014-04-10 22:15 - 2014-04-10 21:24 - 01854514 _____ () C:\Users\Zbigniew\Downloads\Łamanie afinicznego.exe 2014-04-10 21:11 - 2014-04-10 21:11 - 00002164 _____ () C:\Users\Zbigniew\Downloads\Łamanie afinicznego.cpp 2014-04-10 19:40 - 2014-04-10 19:40 - 02869212 _____ () C:\Users\Zbigniew\Downloads\Cwiczenia.zip 2014-04-10 19:40 - 2014-04-10 19:40 - 00000000 ____D () C:\Users\Zbigniew\Downloads\Cwiczenia 2014-04-10 19:13 - 2014-03-22 17:07 - 00003696 _____ () C:\WINDOWS\PFRO.log 2014-04-10 18:51 - 2014-04-10 18:51 - 02236416 _____ () C:\Users\Zbigniew\Downloads\The_Settlers-_Heritage_of_Kings_Legends_Spolszczenie_Sciagnij.pl.exe 2014-04-10 18:48 - 2014-04-10 18:48 - 00000000 ____D () C:\Users\Zbigniew\Downloads\4f525328d638e.settlers_heritage_of_kings_legends_pl 2014-04-10 18:47 - 2014-04-10 18:47 - 00000000 ____D () C:\Users\Zbigniew\Documents\THE SETTLERS - Heritage of Kings 2014-04-10 18:39 - 2014-04-10 18:39 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-04-10 18:37 - 2014-04-10 18:37 - 00000000 ____D () C:\Program Files (x86)\Ubisoft 2014-04-10 18:35 - 2013-12-17 00:24 - 00000000 ____D () C:\Users\Zbigniew\AppData\Roaming\DAEMON Tools Lite 2014-04-10 18:19 - 2014-04-10 18:19 - 09847507 _____ () C:\Users\Zbigniew\Downloads\4f525328d638e.settlers_heritage_of_kings_legends_pl.rar 2014-04-10 16:29 - 2014-04-10 16:29 - 02607688 _____ () C:\Users\Zbigniew\Desktop\magnes-pionowo.psd 2014-04-10 16:29 - 2014-04-10 16:29 - 02505000 _____ () C:\Users\Zbigniew\Desktop\magnes-poziomo.psd 2014-04-10 14:48 - 2014-04-10 14:48 - 00062147 _____ () C:\Users\Zbigniew\Downloads\wioskarybacka.wordpress.2014-04-10.xml 2014-04-10 00:06 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\Web 2014-04-09 23:29 - 2014-04-09 23:29 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2014-04-09 23:28 - 2014-04-09 23:28 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-09 23:28 - 2014-04-09 23:28 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-04-09 23:23 - 2014-04-09 23:21 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Zbigniew\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-09 11:40 - 2013-12-15 14:45 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-04-09 11:33 - 2013-12-15 14:45 - 90655440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-04-09 10:58 - 2014-04-09 10:58 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2014-04-09 10:58 - 2014-04-09 10:58 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2014-04-09 07:34 - 2014-03-27 18:52 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-04-08 23:56 - 2013-12-16 21:19 - 00000132 _____ () C:\Users\Zbigniew\AppData\Roaming\Preferencje CC formatu PNG firmy Adobe 2014-04-08 20:44 - 2014-01-29 15:20 - 00034816 ___SH () C:\Users\Zbigniew\Downloads\Thumbs.db 2014-04-08 19:36 - 2014-04-08 19:36 - 00000000 ____D () C:\Users\Zbigniew\Downloads\wordpress-3.8.1-pl_PL 2014-04-08 19:35 - 2014-04-08 19:35 - 06826828 _____ () C:\Users\Zbigniew\Downloads\wordpress-3.8.1-pl_PL.zip 2014-04-08 19:35 - 2014-04-08 19:35 - 00000000 ____D () C:\Users\Zbigniew\Downloads\wordpress-3.8.1 2014-04-08 19:34 - 2014-04-08 19:34 - 06373521 _____ () C:\Users\Zbigniew\Downloads\wordpress-3.8.1.zip 2014-04-08 18:22 - 2014-04-08 18:21 - 00000000 ____D () C:\Users\Zbigniew\Desktop\Tor Browser 2014-04-08 18:20 - 2014-04-08 18:19 - 23196204 _____ () C:\Users\Zbigniew\Downloads\torbrowser-install-3.5.3_pl.exe 2014-04-08 16:45 - 2013-12-14 03:02 - 00000000 ____D () C:\ProgramData\AVG2014 2014-04-07 19:50 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM 2014-04-06 19:28 - 2014-04-06 19:28 - 00156429 _____ () C:\Users\Zbigniew\Downloads\wioska logo.psd 2014-04-06 18:03 - 2014-04-06 18:02 - 32039590 _____ () C:\Users\Zbigniew\Downloads\css3menu-setup.zip 2014-04-04 20:45 - 2013-12-14 01:28 - 00004034 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2014-04-04 20:45 - 2013-12-14 01:28 - 00003798 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-03 22:10 - 2014-04-10 21:24 - 00178310 _____ () C:\Users\Zbigniew\Downloads\DokumentPDF.zpw 2014-04-03 22:01 - 2014-04-10 22:14 - 00020188 _____ () C:\Users\Zbigniew\Downloads\ObrazJPG.zpw 2014-04-03 09:51 - 2014-04-09 23:28 - 00088280 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-09 23:28 - 00063192 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-09 23:28 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2014-04-02 21:13 - 2014-04-01 21:22 - 00000000 ___HD () C:\_acestream_cache_ 2014-04-02 21:13 - 2014-04-01 21:22 - 00000000 ____D () C:\Users\Zbigniew\AppData\Roaming\.ACEStream 2014-04-02 13:58 - 2014-04-02 13:58 - 00024159 _____ () C:\Users\Zbigniew\Downloads\skorzane-torby2.php 2014-04-01 21:47 - 2014-04-01 21:47 - 00000000 ____D () C:\Users\Zbigniew\Downloads\prob 2014-04-01 21:46 - 2014-04-01 21:46 - 00127010 _____ () C:\Users\Zbigniew\Downloads\prob.rar 2014-04-01 21:23 - 2014-04-01 21:19 - 00000000 ____D () C:\Users\Zbigniew\AppData\Roaming\ACEStream 2014-04-01 21:21 - 2014-04-01 21:21 - 00000000 ____D () C:\Users\Zbigniew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ACE Stream Media 2014-04-01 21:19 - 2014-04-01 21:17 - 59151848 _____ () C:\Users\Zbigniew\Downloads\ace_stream_media_2.0.13.1.exe 2014-04-01 21:03 - 2014-04-01 21:03 - 00236824 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdrivera.sys 2014-04-01 21:03 - 2014-04-01 21:03 - 00001016 _____ () C:\Users\postgres\Desktop\SopCast.lnk 2014-04-01 21:03 - 2014-04-01 21:03 - 00000000 ____D () C:\Users\Zbigniew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SopCast 2014-04-01 21:03 - 2014-04-01 21:03 - 00000000 ____D () C:\Program Files (x86)\SopCast 2014-04-01 21:02 - 2014-04-01 21:02 - 00000000 ____D () C:\Users\Zbigniew\Downloads\SopCast-3.8.3(dobreprogramy.pl) 2014-04-01 15:33 - 2014-04-01 15:33 - 05102486 _____ () C:\Users\Zbigniew\Downloads\IMG_0526.MOV 2014-03-31 23:23 - 2013-08-22 17:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2014-03-31 23:23 - 2013-08-22 17:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-31 21:59 - 2014-03-31 21:59 - 00000130 _____ () C:\Users\Zbigniew\Downloads\rozliczenie.xls 2014-03-31 21:25 - 2014-02-28 09:48 - 00000000 ____D () C:\Users\Zbigniew\Desktop\Tadek 2014-03-31 16:06 - 2014-03-31 16:06 - 00274712 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgwfpa.sys 2014-03-31 16:06 - 2014-03-31 16:06 - 00130840 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgmfx64.sys 2014-03-31 03:16 - 2014-04-09 11:02 - 23134208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-03-31 01:57 - 2014-04-09 11:02 - 17073152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-03-30 18:38 - 2014-03-30 18:38 - 00065536 _____ () C:\Users\Zbigniew\Downloads\Pokemon Fire Red (PL).sav 2014-03-30 18:33 - 2014-03-30 18:33 - 00000000 ____D () C:\Users\Zbigniew\Downloads\VisualBoyAdvance1.8.0_www.INSTALKI.pl 2014-03-30 18:32 - 2014-03-30 18:32 - 16777216 _____ () C:\Users\Zbigniew\Downloads\Pokemon Fire Red (PL).gba 2014-03-30 18:32 - 2014-03-30 18:32 - 00659797 _____ () C:\Users\Zbigniew\Downloads\VisualBoyAdvance1.8.0_www.INSTALKI.pl.zip 2014-03-30 15:36 - 2014-03-30 15:36 - 00820348 _____ () C:\Users\Zbigniew\Downloads\localhost.sql 2014-03-27 22:14 - 2014-03-27 22:14 - 00192792 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsha.sys 2014-03-27 22:14 - 2014-03-27 22:14 - 00153368 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgdiska.sys 2014-03-27 22:07 - 2014-03-27 22:07 - 00236824 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgldx64.sys 2014-03-27 22:05 - 2014-03-27 22:05 - 00324376 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgloga.sys 2014-03-27 22:03 - 2014-03-27 22:03 - 00032536 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgrkx64.sys 2014-03-27 19:10 - 2014-03-27 19:10 - 00000000 ____D () C:\Users\Zbigniew\Documents\ProcAlyzer Dumps 2014-03-27 18:53 - 2014-03-27 18:53 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Safer-Networking 2014-03-27 18:53 - 2014-03-27 18:52 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-03-27 18:50 - 2014-03-27 18:50 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\Zbigniew\Downloads\spybot-2.2.exe 2014-03-26 21:38 - 2014-03-26 21:38 - 00020480 _____ () C:\Users\Zbigniew\Downloads\1.xls 2014-03-24 19:18 - 2012-07-26 10:12 - 00000000 ___HD () C:\WINDOWS\ELAMBKUP 2014-03-24 16:54 - 2014-03-24 16:54 - 00278528 _____ () C:\Users\Zbigniew\Downloads\fa 135 wenecja.xls 2014-03-24 09:09 - 2014-03-13 00:14 - 00817152 _____ () C:\Users\Zbigniew\Downloads\HST Progression v.1.03.xls 2014-03-24 07:59 - 2014-03-24 07:58 - 00000000 ____D () C:\CCE_Quarantine 2014-03-23 20:26 - 2014-03-23 20:26 - 00000000 ____D () C:\Users\Zbigniew\Downloads\cce_2.5.242177.201_x64 2014-03-23 20:26 - 2014-03-23 20:25 - 25543261 _____ () C:\Users\Zbigniew\Downloads\cce_2.5.242177.201_x64.zip 2014-03-22 22:33 - 2014-03-22 22:32 - 05190052 _____ (Swearware) C:\Users\Zbigniew\Downloads\ComboFix.exe 2014-03-22 22:15 - 2013-12-14 01:16 - 00000000 __SHD () C:\Recovery 2014-03-22 17:39 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache 2014-03-22 17:15 - 2013-12-14 01:21 - 00000000 ___RD () C:\Users\Zbigniew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-22 17:15 - 2013-12-14 01:21 - 00000000 ___RD () C:\Users\Zbigniew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-03-22 17:13 - 2014-02-22 10:03 - 00000000 ____D () C:\Users\Zbigniew 2014-03-22 17:07 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData 2014-03-22 14:23 - 2014-03-22 14:23 - 00002220 _____ () C:\Users\Zbigniew\Downloads\lista 3.txt 2014-03-22 13:15 - 2013-12-16 21:54 - 00001496 _____ () C:\Users\Zbigniew\AppData\Local\Adobe Zapisz dla Internetu 13.0 Prefs 2014-03-21 21:48 - 2013-12-23 09:13 - 00000000 ____D () C:\Users\Zbigniew\AppData\Local\AVG SafeGuard toolbar 2014-03-21 17:47 - 2014-03-21 17:47 - 00000000 ____D () C:\ProgramData\AVG Secure Search 2014-03-21 17:47 - 2013-12-23 09:13 - 00049952 _____ (AVG Technologies) C:\WINDOWS\system32\Drivers\avgtpx64.sys 2014-03-21 17:47 - 2013-12-23 09:13 - 00000000 ____D () C:\Program Files (x86)\AVG SafeGuard toolbar 2014-03-20 15:06 - 2013-12-14 02:36 - 00000000 ____D () C:\Users\Zbigniew\AppData\Roaming\Winamp 2014-03-20 14:46 - 2014-02-22 09:52 - 00000000 ___DC () C:\WINDOWS\Panther 2014-03-20 13:56 - 2014-03-20 13:56 - 04822473 _____ (Tim Kosse) C:\Users\Zbigniew\Downloads\FileZilla_3.7.4.1_win32-setup.exe 2014-03-20 13:56 - 2013-12-14 02:43 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client 2014-03-18 16:49 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\LiveKernelReports 2014-03-18 16:22 - 2014-03-18 16:22 - 00281600 _____ () C:\Users\Zbigniew\Downloads\fa 0044 wenecja.xls 2014-03-17 21:53 - 2014-03-17 21:16 - 00000000 ____D () C:\Users\Zbigniew\AppData\Roaming\PLNcoin 2014-03-17 21:21 - 2013-12-14 01:20 - 00000000 ____D () C:\Users\Zbigniew\AppData\Local\VirtualStore 2014-03-17 21:20 - 2014-03-17 21:16 - 00000002 _____ () C:\Users\Zbigniew\Downloads\config.plnc 2014-03-17 21:16 - 2014-03-17 21:14 - 26778624 _____ () C:\Users\Zbigniew\Downloads\plncoin-qt.exe 2014-03-17 18:58 - 2013-08-22 16:44 - 05029832 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-03-17 18:54 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-03-17 18:54 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-03-17 18:54 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Defender 2014-03-17 18:54 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender 2014-03-17 16:06 - 2014-03-17 16:06 - 00000260 _____ () C:\Users\Zbigniew\Downloads\dane_kontaktowe.xls 2014-03-13 12:44 - 2014-03-13 12:44 - 00004921 _____ () C:\Users\Zbigniew\Downloads\webstar_6 (1).sql 2014-03-13 12:29 - 2014-03-13 12:29 - 00016101 _____ () C:\Users\Zbigniew\Downloads\webstar_6.sql 2014-03-13 00:09 - 2014-03-13 00:09 - 00004759 _____ () C:\Users\Zbigniew\Downloads\kalk_kal.rar ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys [2014-03-14 03:22] - [2014-01-31 18:15] - 0311640 ___AC (Microsoft Corporation) C85C075DE5B6D0FE116043054DE8EE02 LastRegBack: 2014-04-12 09:31 ==================== End Of Log ============================